<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-29" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-29"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur, Belgium</organization>
      <address>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="11"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 224?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 228?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 866?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA829yXLrSLIouNdXwDLtvjrSFTiPpzo7kyIpkpKoidR47BkP
CARJiBgoDBxUmdfepnf9A23dbb1s6x/o1d3Vpr/jfkm7ewAgwAESTp2TVfXe
zUyBgIeHh4dP4e4hiuKBozoa+yz81DEcSxInkqHYE2nKhE/SVBKakqWtDoWa
4zDbkRzVNIS6adiqwiymCG3J0keuJnyq3zfFXCZXEvP5UrUsmCOhft/rCeVU
UQB4gs3mzJI0wXQmzIKfmja+4s4ExxTYcsZkB4DRF9lMKgM/yKauGuPDnw6k
4dBi8x3YxWP004EsOWxsWqvPgmqMzIMDxZQNSYd5KpY0ckQ1Ck4cSaom5qoH
tjvUVdsGqM5qBm93mv1TQfhZkDTbBCxUQ2EzBv8wnJ+OhZ+YojqmpUoa/tGp
ncC/TAv+67Z/+tOB4epDZn0+UACTzwcy4MgM27U/CyMAxg5gUvkDAGwx6bNQ
u23WDhamNR1bpjv7LPSatf7BlK3gkfL5QBCFWkeQxjCqjX9s0kJa0wJ/ji7G
wZwZLiDwsyB4wB9a+Aef3wOMCZQWWvgTPtaBEPjKb2wp6TONpWAp8LlkyZPP
wsRxZvbndDr0YxrAAWjVmbhDoJDuTiRdlxTRtSVdEm3JUiQrvYvcP8FnmoSY
w2c+4J2fpzj0lGruBJTev6SpiaPDQAeS60xMCykJgwoCcIjGueGnrjegcIcD
Cj0a8Cd6y7TGkqG+EV0/C/07oWExG5b+WGgxS5eMFb3FOMWCiQ8I8xTH/DfH
FRX+VUphP+0Y/16V5AmzNWkuNNwhW03NXYPXTYs9MGnOIkPiV9JvCv8M12LX
AGdMMsSuZKlMOJPkV5c5uwa4M1TYorbqrHBnXkq6ax0LJ0wbq64eGfMFwekI
LvXCwf3mGvh6arhzfj3TGA9N4cTdNWoPVms8kVSh5UqGUDOAs0cmkJZ2dZ/J
E8PUzPEKpp86Fi4cBf5Zn6iGFMFoqLlMMccGjPnbGJ/to0R9wozxUjWENow2
3oVPZ729I0NIroUbzHp/jLZkLpgh4Kx/2IQnsOpGNpcpZoqFQjw659IKZLgl
qzDuTnwWqiNPItCn8EmK8U9+s+n3lDzZBbyZEuopoZsSHlRNY7r9DkWPhUuG
8l/DHRoZks0lOaWnFhzMbzPLdEwjpe/kp64E0llXNVUygKssdQzkUdRdQ1+3
O+JVt9mqRcaaTVRTZ2MpZbmGo+osnn5ddQqKayLcuCBdVgYT66amqcbOqbYl
e1LXTGkKk5ZJ7fUcczRimnAhDW18CIspGZISXU2dD/HbBD6X8fN9uHRA5Ag9
eWKZ8nTX+M1u56JTE66RerKpHeOIqchQDpP03xgRb+a9lZKAdgcG58E5qAlh
U7ukUI5+Jjh7LAV6Y9MGOASCwOKIpPpRrMDPoIo9vQ2aun/R47Mg/SicuQYT
8PNjPpRkjZmzVjiLxSIFe5ChGhrDBymDOemZO9RUmaafLmQquWw1W8kNNrBD
5AZR3AYRzPDHgWoMfMwGgBnhECgN+p8I2IPyBna/S3lqIvrLfcqX4NHnZyJ8
44nePeQVLTYz/wwaa6sYGntaFnX6h7Q44fQDKRWdrAc9OhTtgc/4Jn/gUa9u
1s2eZxZxMgiqLcxdzYCtNtQY2p0W06QVviPJU/hNlcAShemRKcpmE6aTxYqf
gh1me+B3cKU8ZylAIg043DIZ7LVfVeWXDRNMWK9BriR0kYlpHeCH5t19g7+a
LRUqlbhZNi87vdo/ZZ7MnSspZqg2aAbXMmf4rzT9nd7AP26qrXavBgJUNm2x
1oly+/efSJjvc/koIrGs72oAdK6aGnMsOy0jummbyS5usLSkzFUbLH5mp2k2
89F4LOrz5VLUx+Py/r1wtwYqEAXAoN+kSG6TJPw1Qd1p7ftUQjNcB+3KTYgt
otmMnBkRnJohKkow9X0KguGBwgj0U7/xKKAEGangnc0kZxImXrYk1Nyxazvf
n3qF2TIvLl5yS3G5LPyD1Mt/B+rJoGAlWWYzR2jOwaE0ZCaAATQRDBXUKdNn
zoocPHBOHQSBUttyGpIjodQF20aodRvgu92LvcvrP5WQVgnYcFaoiC85a/Ft
hGwqY6YBt4i9FdBHt6P0vGW66UQ8TeQ1cGeRWuquHRqeeoJ5Mw8Ne4WzxsWz
nf0Tn7yMZfFFLs7F0aI82T9xf3KCN7l9k97Ygy2GWwmXemaCpQHDCopp/MUR
FOYw2REkTQMeAsccKDG04SsXKfPnTF3PvY7FhbWci5NKtZJo6hhdEH05Adag
sxI5K2+uOS5nzRMXqrEVdwjHYFCa1E1jhNvGUUEQ1zBcocq4B72RI5shC4re
iDFG0GRFmQ1GaUplzoh0LD5I6/YYqCI56WWe3SxPX25Ozy5kJrGSVhhcjh8N
3W48pT9slhAtry11LgHZRQvWSttgff9H4bYmotCQJ7Ds4EkyQTcVJiiqIhim
I6B4jewP5osQ2BkoG/BbTxyHKZEXerCFGMaKPsQlPjppjut+Bnkpvc7FQh72
hlWo5vYTxAe4RYyxuYcQLROXe/r5X40iY3M/Ncovo4VYzFu6OJtMvoUazJxH
yQEz0aQ5E0H9zFXLcSVtB0FkZjmgVzEaaQsLZjFOGdMF0vwgKmzjtZ8qs+Jo
Jo6rhTH8Q69+E1X0vVTRVUP9lyMJIhWjSKuvOpglL2CW5OTSN9DDcuQoPUBg
wi4VZU3F6O0OcgSGF7c8QNe8uiaS5odTJYrafqIUXy1ZnFfKBVFfzpffRhRR
kfYIk93B7A+atw0etTQNX02FCVP60YSZoelaXICYHU2KMfZrLGEc2f0RlOlf
1ftXd/8UsozHlVdRH00mYJ5Y8ofI0mmIdUu1VXjauOqksplUNlsopvPlcjWX
qaTy5UoxXymHX9wVMiHTA8Mg9AZaLBGLpG7qMzDQDHClTzHgBTaKIWkrfNUc
7Q2aXJrzgFbFdwMn9XpdDJlFaYruaqI9Y7KoKqJMmH1LzAR+6Zqg8aWRFP2h
nwIb08KHFhsB7iEKZqrp3nUql8mWU7TM8Kt4W4sSDXhBQhNXGLoO8M2YQrR4
aOawMTxHh9HaYfsbyGK7o0t7iISxEtdmhrokUw4M3BHIfrAG0pIj54rpGYb3
PHZOL5hqTExN2U+pumTBahnCQ/jND9CxYxru//e/C10VBDBYjdEfn2D+9kRo
wD9msO1Y9Ne2ZBggl/u2PDFHMJHxxseSBZTpTdgIJraxRhNTl2zgOtuG+W2g
qoIuACf81lSdN5uC8XXYROzk+jS6Ut1O/7b5F1u4ZAvh1JJ0tiAbrEfbEJYJ
VQR+JVxIK2DXJ9O10PhuUPzdFq4iSqP6ESEga6ar+Nsc9JUqwXLR6g01c5zG
79LAY/D/wSG2mGiLBluIIx830fZQEwE1kQ1nI1FD1MQVoCZKqsiPBmwRjy33
rjPi4E0StnbNwwJeInqA/w+b23Bha4T3XZRyAbV8L8X7QvC82tCHGw57EDHd
y9I0c6IJzN0WAWd1PAHpGI5Nrykir7Hlu0qMnN3uFQve0u8WZ3zBQXKF/bHo
we6B6p8zeTF+sZEacW4U0ZcSGZ7zh5H52FtiprD5IqqIyBuld9+ovvdGNuO/
AUzwxnEZSTLYUwepVOrgQBRFQQIHHKOBBwd92Ah0JCxIqm6jMpxZJroegoMn
bLAqGjrw4GCS4P8SDdb+908Jo7uHx8KXjSjoGsbHI6cAJpwq0VKdtjsMMX6g
ZIVPqGXtQ2ExAdERzI0iEBJnjfU8A5cLJjoxF8LREQXEjo42Ez0YT/QIC/kR
UQi06AzpqsrsGMCByD3CmJgJ6mI2AeWJo6DpattHqKIs8JOYdSzYKo665vfN
0NGYQisabC+Lvboqsu/f/uYLvj/+gD/i9vcffxzvnEp4EEkBqXd05ILQRuwk
awXooNW0BHoeAbLIJ6B0XM2xMQ1DGIKlBGgMVyRK/dMmwGTXWQxi8Le/cY0K
6OLS4VcS+jbImXs+I7MF3geqIp7gkoxIOsJ3ArcVAJRnlDgmnuJdW+Y9ugjH
ArgCIK1rM0wYEHOpjAAChhk2I6kGcC1TcWWVB3QIIQtWny04X03A/xGGjGGE
c2qYCw2jTaHJamwOzINITRnqUzCrU0LdtUBFO9rqGN+yGJHp6MhZmEESj5/n
cyyYBiPzFp9WUxkRU3ngO3iX+DV4uZrKRl/2QFSOifmNjdfLqQKfwdYnpVRe
IDFrT2Am0lgCWenQdIaWKSGtNoO/+zhdRp6l2LimCaSjaHzSqLJpU/jKS1ei
RZ7NfNke4iPOLTNpRl9TPNjmFJN9MgpMpQwovpLrXCMMKg8ZIgBWENhjMB1c
0/ULfJA1c3HkALw3HB6dAwQBpokfU9AaMQWG110D+eEbmScFXoiAloTPlcce
v+hAbUQ46ocQZkTgCH1BPG+GIUkNY4STBuuCOP4LxevhVQ485M94El5XFUVj
Bwc/k2eE+JLW3Lc/Bc+ihM3tSxtcOWANWCZYSZrRG6P5fJRR4OuZaUsakMFi
YzAvaUow58WEDGcEtqI1xyXwDgVs2ZyRAMa4K3r+lgNvAtnBw0+BKWfqgKFv
Zgm4npgRB5qabxOPEacAWGGyanPRLDsmrDtKCVxmQFxVyIr3Dnl00AASqBkd
rGBT3/HcDmO5G0PadDgr/i5hG2VDfCzNMVKLXicAihd6SXjwGE/34McwS45c
i4jsbzbgixqIIy7ViQctEOx8TyAqvq8Y5gVabd9RlANHEX4XaYzd50W0+nz2
m1Ia/v8mCSI+asJ5ExKRqeMsDZ45GZmpN0/YGGv5siVY4Fd4CXHGbYCmpemO
J1uT8HhMYWC9wn6f8b2sGrHkgJ34s3AFkhMFxcEH9qGzJh+yOA8CkqrGQPEG
LjE8zc8u/cfxWHJBCoYReIKKlytDzyLRFD8dBgzKg9/B5U8Jvwsnm8PCszub
IYvAf9WCTfA7fJHFD+oUGPmv//G/2QTTMNEC+h1s+N+FL4gss7Jrw/Cbki3S
4GswPBox0h7AQxo+tzF8eP470Mh9bzRyHI08okEZw5jVa5IQiQyc/94D5/nA
BRy4B4zILJo/d75IZEbGL3zv8Qt8/CLR39ThISc68PDPOWLrn/NRFIrfG4Ui
R6EUg0IBh9+rgHcitBnH0hlDV9NGz3/IhwdvkmHus53uStbUtW9dZZXyzy3B
fcNQoSyH/bjUTBkd/hUcLv9wfp5JVVK5qMdlG+BFO3i4VRoTKosZuc3A22l3
poFhZ2PkoZjO5tIPDKdriTU8KMQTWQw29PFbsX51edppNC/7ndpFqeWNDEPX
6xE3uddpfWT+h2CcSIpJ4XmQFS94+PslRurshLlBjbQvgcjdnZkykmZtCLkz
hU6eUVKuwUlqSodXCB7BkUHJ2GCgySw9w3gquBSAIDo8FHjxHUFxgQQijXG4
ZsbS92bGEmfG8k5mPIbNcLzmSNAXsWED0BwBouXvjWgZEf3bZx4i+uWnLVkP
Bt6mZYuI+87Y2gb66Y+Dg//4j/84eGCBJy75Sg4ewMTh/4Nj4pt38Bc6GeRG
DMHtWOu5gx16jr7dr9tc2wv8HWw5k+g8htA1FM92RfR01VHHa02I3yuqTU4Q
MpyPajhDQGXgDl65qEphm6NzwGDnw6eSI6iOoEurAzqvAirAgvoJIWDwqPAm
fGSZ6F2t/SYRJjUC/S98AseTaUL+MJg+n1TctCUN7GK0xsBawJwdGBX0jWYC
hysH3KYKJaIco3GOhqrhPQGtpANINIj4WYaf9COtj6gPRtwsV9QRhalxijAZ
HLbHnUDvUxjfm7jtWiwgCEgsA4SEfQBUUMFIQMuKExeVVIpY5gCZBnbvDMtX
hqA0cRE0E00MHCCSoPGelYMBMDoy5PbJ3/4WSY7CgINtu/AbvOc5seBpK+BC
HHthJB4I4V9jJCYS4oLvQ64+N/y6psI0XKkrMk39HdQNmJcH4qLOwqsLaySM
MAaDLIJrpZtK1BDESSEkGHFN/bi579g3w5Vg4/5doTNjjPFX5CoY8ivICEf6
KuCpB0hSChIQPeoeK2DeNi2S4MlR5PxTiogIX6TxGP0+h30/eRSAPKRoGQYx
SEJ47qkS3rvKrrnudbtg1SgDUENthfmSGA3w5+ga3l8pbwFHPOjjI0Gup2+l
73AriQcokYgMvrCyDEdgo0J+dxCZuJM2H3d7uL7ANUGJKuHOCJ1tfkLs0W+F
ARbG4c5xtuPHMEYQFIGZauaCJOfCFCjWQFwCEsHb9b78Xrvi4BeAjX9CukOY
wFajUJqnow/A/r42wejYzZ8zlMfBN5KieOEdKxr9J6p5rpzAtZS3th+hoGJ6
KQMzlM0AIZouK9leBE/Ft8Bp9iJFIOwt5oDT7O0CPi5FfQBRlfD3BMaW47uf
7zCSx8LhUXK4rLGrkx+4mKyEyPiEVRClpYD9jkkAz71HZdBDu7895uebE8an
eXTkzw5mFI4Kv6dxAVHXeAEDE3M2FL4LmkvQmMgkQs+F7W+RkvdCp0IPPnRB
Fvb8HH2AMJRwKwO0L5edXh82lWOpsr0WKcZcScEmc1Jjc55G1he9V9Ly3LYP
U+ijkjBGp8cDC14r1Rvi2NdBUBSjtGkeTwW7TBTF4P8AhB+kRVsNYFAkH1xZ
gf+WjT7OeYZdBf4biw6CN7HGM3jkv1VYPyp77gn6QV2mqK7ufbq2vnbiiyzz
wbAc2mBHR6fwAfrdFvMOlo+FNrzrgNDAkCjsAF+BHR3hwoXIRCPiGY+NWP0M
TCkCWyqouP9AYuPv+LMQ0P2U9skuqm6rXp9sO0sNj4XtCkBuJG8X7gkc/pZu
9hfhew2wcTL1A0bYmXzrjVPYN46wg7w5+ohz6+6PSKH7RYi7QOS/HcRW+rAH
KthX3DMW0DX+qxAqHgaVBibKGibFwN+b80aW6nvk+tZlCeV//vAhmDn/E8bQ
f/gYliP/GWOIipRkk2zmmdG3niTe8+1aKK9lYhJRzOP0nnAEC+ETxZvxJSxc
pOpWUiimpXBd5R3ggTWGUvxncOosMHG4d0EWkcMfYGaxhsoTPT0w2bin0mNy
CmaURUh7jWBu0sOLBe+19bkA6IETtjLRwkbLgh8T0Tw0BhMc06HIVwysNM+/
omns9xmINX7o0Ae8CzChMD2RTp6lme/JoY0Ci43hf7Q28SMsLxYUnsaDQcsQ
HkB6hqddsxWPL6B5DK+BwalJDppkYTuQKp9ovphtgrEyCp1ZYPB6gW56Ycg0
dMfBzgKPE3wtcA/geXj2iolmMfYqwPF5sf8xlRaGClxwmvf15jmuClAFDCA6
T8afRqqlL9DhoymC4zwTXUMF1vYMPo6kJPTrJ4KXwUmOqMY2ekXMvFmuv7MC
twR9I1DqvdvLlo87U/6KKPhRyOP12uF4SIBPzfpho90UvGCZMJc0l3GwzmqG
vKkF9Ofzsc2RQ3Nh3M6j4IRN6SR0whpKybnvrkMywhjgOsJVD5dQtlYzxxxb
0gycbVFThxYyhQVIAXkwc4P0B/iZ/IRLNy0gt0/nr7fN66vb/qBR69e+8rIb
DKSsT+/5SPz0SjatmclxpyQ94kV1jPslzCi83kPwMzn44TMm/VlgPjvbC/lX
Yn4GK8jTAYBsqrKukqLKKRfNa4cSu2FpfZeRCBwMxHEI0tVCnM0MiWy2EBeS
Aw7bglHVFVvKGlB3zkNMzA47ijBrHkhR+CE6X1tgan5m9/Wief6Jc8Lh1/Be
tAEpTeGuEbAZoz4fgBa6BJJtoy+hqLJDjic/q2NE2o1NKkuuzWmmsBHWCYHh
783tWJAxWqXQ57QPRcwzERq3Jy2eAnKMH3Evc81r8LZPepo8eF4AF/NoolLA
T14qiqUc/L9oKF3SFV5YZKT9ILGd5qeNjhik7w5dwMrBSISuiPZQLGeKReqb
cehHNClSZhq4ARlgYrgY0IFlsXg+H4gwV/Mk9GdBGo14PxcUFc/gbxX9QIpJ
0QWkNwByLQxo2e7Io5cWbAdvR3LJwSwKRny9bfSazcZXgZ9kcklBzG7BYNqK
WFyicJTtUjKSFx4M3GLkfNI05O4BbBTAHvcApmLvWiT2R4eQRAoV+o3wZN4P
ggTx+u38a+5eKkyHTeJYVNnAI4EKkzSRT8zAwxdgKlf3jldx01BZN8rjhR/w
oHNInoTy1zU/+JYj1aDBFCco+q7gWa938Rdb+CqKuMNoJFhZpvxiKfLM/Sp8
+uK9JORTRTBJO5e9fu3iIqUrOyNYJrxs21rwbzrt8f4QCUJ6DeHw0A8e4kxg
B6yXCWgH/31bu4T/Jhl9jRRFxGDVZi4IZlWDzUykAhIHMWOMc0lj36F3JpwL
JmCdcAnsyQtaKWBCRtl9vq7zFVxoZ3IH/cJciBcUZu5Ks5kXW0Ryc7PdMzYO
TtUxhnBzscZEaEv0m01RGhtgOABz+CsnUjz7wM9GpLQB9EwlAdaY/yjwrKyN
UBTJGF2a2d7ZgJfNiNwK8oOOz01KFvDTpEFcrMt3UfiHdfPG4QWFDGB+KZgd
4z/wBFMwBddAPvi/3yMjfewTGF7c8T9h9+O4/33TJzD80dG1n67Y5aH8oyOA
BfMWSSFoPjkDk2Pf7L2ZB58hNWI/4sPX64HNBiN7sOrXd0L7Qfh3oj/woQvw
/n0j1X6EpozlksgNf8LFVhoX4RM3IA7Xhte/C7dd+K157x9cgL3B8bhxTVLA
VKDJMUEyCDfNmOWGgYQ0WQRh3D7dd0ND7p511D7yZx6CTue1QoMsTuFTv3H4
LjMJ1xjrw3QlwGfTAIv/lHC6ZA5lg9sYGvQp4MMMzLZ/J3ni22qeyQd02o9O
/KeILH9jA512r5vuX0dI8ztP/GUbm3UnMT7+Ko1GFnHt/GtouN8jR+IoQWEy
yBEepzR5+dzGuGj6p+/BsiLl67su7xLft8gj4z94IjyNEWOi1rqjw06o3/LJ
eviLfnj830FB0Fk5bF/8EhPi3iHpt3wS8q031JAv7AUv05T7utviHiTIhlxH
n7nvJQf6+Rho1C4MP6AfwOZAuetnc98vOFyLAD2gQzjalJ4b6Ce+RXVVxDgM
m99RRcej1b4WS4eX5nfh1jXstAZzs/kh7a87+Ubor2Zb4mX3m7eBqUUjcaN3
r/r5qDL5uM7Z9yahgEKhWUfvM4p0hwsIIyyWtmZ2GfNr5MWrXtqXPJ7dxdnv
97UzvHv8eEn6u9Ai4RWYpN+EQu3cfyeihtafnnraxK/ZTQeaFddzosL+tuQJ
nncEAZDAQPcH6YIdbq1EgIButy/TfhdCGtgfru2ZlulAi4F/I2Fm/Oacgi9h
OunzxqmwJmvEP19/UbeYH0PgpOv5pPtdoKYhvosc8z9MRgwHjgMT2KuaIFkT
Fi0XwebbqBDFXb07yoNC5BqcOVhyfSfl8NCLshLINcZfNnnlL9gdoQtb/eBn
oUGlNfD6fSSBocGTG1BG9lUdUwcYT6nhuXq1dVUCPyQEqtV8V/Ke5yqgJGnS
2R4RkIVPX+AnTE9RDZVQWqdVMD+tgtIzTC/vASBkysKVDJ4Ies+cN6MoIAbB
y9kCzEsOvRxu3OeFWb5gs9C1WxXfwQKWwE6XxsPXZebxqfLwZLXz3WVhflUx
cqJ7Pn5KY5oW75JBo5Zo1C8etTDpxDVkwjPk87Nhyh8RB4O/qUgvk8uVsyVw
6wvpSDXmuhtMyrJ5TZ/DGE9HwxCKvAIswlTIlYVTNgzhE2Tyreswts+/hC9H
R8E55S9Cu9NqYyczXvRxeHT03xGy16IpDPu+ueuwaz1SHNyiD7e0BZfaaIXA
4GnXzkOvb4T/Zc1H0eWJaeKB9TeSzey0I415Hh+G7Sk9MktLEBSFU+IAfbSL
OB/AuEpFjd+K79jcj2sxlRXHZjaVK8FgW0iPzW9EOJvZwri+ZQl9W8IlFlRo
lIfwJabX2IcSZDdhp2eupqWLFdrG5c0Z3K9H2zEZis5+44y8/a8gb+Zihk2U
NkOpNriivDrVRq8DduwG9K0M4y2hsOPEN4YBCv4e22LZ98VObnv/1m87/U69
duHBr8LO8hjMb8yVaIT8PzhCcmrltsi1NSA/ePbpVtgeNdiSW6Ntny5/YGlC
vUeSDUJnyz9yAH6y/GNH0H/wCPxU+R8fIZAJ25V54CV62gRtMd2cczNvtj/P
6neh8I+MNja/30ixlONn5R8gXukfGYSfqkdH6TYbnbuuN04plY8ZZ223B1Zz
NO03bLuGrWZpw1zmKVCXXn0pWqM8i8rg+d1kTGEKomSs1mcJK3C6wQw1EXWv
YjV8xh05eafsya8PTJpin+Ovx/y/G+2vdDz19URSmlyDfU0dHWG8AJw1U1Mi
vguFO0wbT5JTLHXswexRcjhBpal5DwA0n6mmAdOYih9Zsf2iRYn3s6dUruad
1x31oIlV9kwysKO5aYBf8oV+eKcif2LqbAZu3yERKZqoE2aAbSOR5hBcdkA5
78HKwGxDfXn8Yj5AF8MhmAIANKfveQbufTTffn//GuFCddCHA65Y56vNQVHY
somZBH98/3TDqC/HjfMgGe6LP9qHYW7mzXke3JcFuLSONKPDlpBfE3oKjjro
xOAR1vVwJxkx+vSFQvjRU1A8LNK49eSVEcHTtItdwYIeRqLM8EgpHfar0vRh
cE4qhn/jR67ZjJiriJlM1jsuRXb9Uus2vscpbD5TyARg1wMj6aic7BLzs4lm
/WZzg17gxIVpRVU/G5TaAtJ4VMxFyIxWtJQk6+RGKqaaDjoylYqVUqGQAvM9
k8tnqJboT6R5AWmeCdMcix+LFI9d8Jn0HEljboi9l7Ik+hnE64skbP6a/+8B
b00ErotHp/XBerFQzFQ/3hXE+wBhFHgOoJf0isidgESdntZ6/ffQG+KLI2wA
GvzXwJSm2Dt/F46lbLWcS4IjfnCIGOY2MZSU21p3DWoogfGvo4z0/gvH/v07
snnWSzbAKsr8n0iubFJyZQnF6gaKp9IQxNqUKe+hOPJfXP9XPNNlMx/AEB6G
PtiJ4a6D7CjkP7GxPs4yJoOZ54yHzKJNTcmzwubbmjISkJQDTakFmtI/KpHX
EIPjF6zDWyvyoyPKEaeoxd48AAzdyutEj83W5ZhyotO4woo53qAsaOWI14ms
c5d2Yk5xfp4gimVuQYl/qCXEgmEZmwOTNHiD3kjDEjKMsCEPZdUfHHi5ZVt1
HGjxaGvU1sc8M9PxLY+kWaCfNlsS8G4iNJu1SXv4+b1KBhr445ULn4iWlu7n
Ys2ZZmIRz6FX01DZ/GBPqUM8nEqqLMQVQRS3iyCqwqeiEAt0o0CiHNkFzfUd
WQkXIob6grcjvCY1Mwu8Cx3LqVeYLKXqxNywBtyoPCaWHqmYH4VXsFBGIf2U
4tY+JWY62IcmPCYxYSjs1ImeXx4c1Oxw2lRsYi3hH9thBLaLg5m7XhugNStv
kmurttdioRozYEsxVIr9fauvP++Sf3xm297Fe+FRxDNZYf+uJuOE07cG6A4O
OiNhZbq8GQxPXhyRn8lldWw11UYS3YwiywK2p3dtAf0owTa5gF3wJFN5wuSp
159ou3B2q25W5Rli8NirWKx5wYl0l9dAA8dtsWQ/EetQB+NQ9DjabOvoyA+H
YG2ZtY57HB1h5GNf8zLOgf/SzQo+/ynBc6RmmIZEFj82+z/9stVBIv4GhTWj
JzmeOv6eO/avMB1dHZOwA5aIj4DxJnowR1B4OPMgKOXF7IAA4QOYXCrzkdOm
NRWSx3yPoxzNeyJ4SPnTip8UzUO1+Cdjc3MOeVDt/iHSe0dROybyobjyd5hE
VKv5d24JvXBbI/ugtlsbBVm+kS5IPLAVKy+PMCf2aENbIaYfZ1CSLO+03qjC
a4K90od46cWuLhZ//cjB0dFRcHSERB45LAhFbqGwr6w5hAbO5xOpUBGTnGfM
ECmwdejZzJJXzbur6cYn01LHaLqgrkADGk0oMVPgAUYqprB56j/QUsyUDg+w
9WoNU5uoI9pDi8qLVVmdYZPEmYlhCkUwMZHZ01nYeoFrqiHovSQSwy+4l8iO
56u5KaMI8Lo9QOjNvXd5bH1FQeE8pVgzC4kij1IAgIKHpmXB1pFQBBzyzyh0
yQ8Jgxx6XCp7tEoRdaitXJQwtp98j7fWrYLOZjv7WWBhTXBnilcOgrf5OV7B
CNZdea0a/DZ6E78xIrovPCod32+OJhJybWBJOO41SqvlgCxYPpO3MvR8Ob/2
nk/66EhReZEBcLFf5sT7BICNs6eQ3qcdH+7o6G5PE1IcRHVspo3CLQCx1oJZ
RrBLNprevrc7aUxUfGTBh5dcjfZypBd390eNRwykn9/vg/LqbWyO0GhvFPV/
+jperr4e8twhcDKjvw6Zs0ALSV733eDNUbCbQjsQf36fGMxD+vR14tiyD5FK
09aJStjgNvhKxwmNmX2QTwm1ddeZDWhSLLRQtxpsCC0dHFzzrY69DbzCw/ha
AYTpNRomPyho5nvNF4Sa+dYxd1Ljw7RwCx6uY/rBthT+wF4x/tkMBRm8JiUS
Zl71e377essvyUBm5vVs+6MjKWpqEUYAZtMMXdIi4aL2+LL1vEVtZQ9xhWK+
CjWiW69j36P8OVK+lTvElfkYjPD6RaHkD3etST7RmnRR9N7yLsCoGmvh1iu7
umZ6jX6jKa87uqDGNjDaUuAbjS7EzTZ6E6bN7KCfEk/wy/r44fuY/BZ0iVm3
LNz1XS78XYc3zYhp3uQ1aHqvAxE1ZVrX+a3ba4RKnugo6dqXRrH/+33dSUj4
OXucOy4cl6IP88fFYwzEXG/PGgMqn0UxfoTIYN7b/n8E/8bmD1nhcxyrkpSD
L/7r//xfPWD/9X/8L9H/QCi5d6BM5ckGFP5fUSj5d6F8FfZA8f4jkoaOx/+c
9ykJdGMvlVNZ4nevMKr40Y1F0jPo2UIdUrz4VbDR4ttshpprrr/1W3XvPjqM
68D5w7pvpg9/KHTNHKecpfPxHp8/rL9neKI/AHpkoru7iP6wDqLhqf0A6JGp
xfYp/WE9SsMz/AHQIzN8rxPqD+uCGp7kD4AemeS7vVZ/VHfN9A/t3Rmd5Id6
eP6w9pzhmf4A6JGZVlJhKwKG9bu8f79xfYh8Wj8QfmhiO46PQrr+Z4p7B6En
WNxTroht0tj7fuS3Bjf7p35gBEzIB4x1a2QrxsQyyT48DmrXv5B/LEYDQMuZ
FDq1QKcLa9emzFoXUCimnN73afrw2LvDN2q5hszdyF0NtjsGH9Hx3H5w8tER
nayGlup3XETX65Mc3QSxRrDfSWbnz4cfbebnHXTtcv15+xhFibnZ5D0kwzY6
dmU1VmsPf8gMNlKjB9b/7EVNIYd5NxBET5iOjtbXJnheBcbUcTW3ljHMGPTG
e9PyW7t6HyH3bB5WDlcUTwnFKL0zdd4FZn11S6S3w0bU9zvwxNaNGeRCRwKQ
REQ6l6I4J3VcUTghPoKAmClEcHgXXS/+xCN3/iLBH6bF9CBXIRq5pZBe6oPi
56J23uTip6fqWGiFU4KZY9NkGYajN3eTXPiiwYKLlvRhrsRHovdR+vCjKKIL
Qhi+H27fvr9xO4CM5+ySMaXYKucovxqDlnVdp/F+bB55eceN3kc8s/aIgIdO
PG3s0bQSFOyRapmu7d/uBGgi+wf5rsfY+RhvcFinqEzU8YSqRjFTQAnl0n5L
Co/wibcV3ch3/eOPQ95jI9T58eho3fsRRAJ2f6S0Hso2of6P2IG5pc69hqCI
J78ARPYSQYI0pk1Uj/EsGpQFtc9VDrxoOQtldPAMd9iRGHj37hKKE8jdu17/
wLXGPGEGj4jjxa7XPvo9JqTK2hz9k59p+z+u265FW27yG44wH+aTV3fuJ2SE
OmLiCQFWmHsNbmKmhRJX9W7q4U2oaAviLVO+QLBUe+oh2xGksdcdlmFUghpc
uTOUxnY4Bh1uQVzbGM3vwB7ceiYNSdEZHDb5XOu70bzuS9i5hxRY8JXXFcqL
ibFXl4Q9nc6NsUm64Sdze51dANkVnesBx8HWjLzDxa130yEmYYduCgph5V9J
c+xtav8mGGAn7yoX25fyksaTb4J+xngYZSi84Rfzms4cB+MEeRIcHUoewj5q
8roJ0ZDWzVKBEkzh1r3/tc4kPBsBocOhY/Utr1Cj0uEgYOi1CPA5LHIIAi/T
aYvsKV6/6Rz17qYeXLyrAP7G/A3ph179Y4Kd94j7wdiAAn5bML+1UkroBSdS
0ZP1zcZfQzxq4PXaEpdg1KiIN1HzVpQkC4givnwScea6g1XoenPKCDQCng6o
xTOj2Mhv9+U156NAdD/gS14Kwu3wvmlqGPrH7kpbPf4DuyPYHJG74zBfgBsg
a0WnMkat8i2sSWbM13PUmDldrYCqKeYP/VsBNtTmuik3vysn2gfez5sJnc4B
0vzY8ctIXaLM9+5qps7u/h9+h+r48PKH0kh2XrYb8pKwU4iUBlwO+QGeSTFz
WDbsq0bNFXibbKS05fAUSMAJheIIaETbN9pW+52YuL8NEHaK6GN5xg4LThsX
oXMdvEkBmREIhwyL3dsnXmcw3jY8OBslsMQ+uGtDRejrG99ga62bEf7rrYBH
ajzDx6qm6MZaywSvk+Y2trSCkWaex4E8CN1mQWUh28bUId6EwE/KOE97XBBs
IDlQASjU6B4tfgsmTyKIdnqLLA8uNADQ/fsR5Impysy7cgJdKw0sk5C0C+T4
jjnioh1z4yQwR6IcuCA8eeKlpyDevbbr0sTrbX272e9e8C/HIbv3KJlfXL4Y
YM5e9855HsjaYE0dnG7xxueDg/+ZtHWwLGidZ1P548gGDGCEqqYaKkh4JraZ
punAmshX/j2OI2w3gWqPaajc4bmmqTNsBwfyeM7olsC1JQUc73Uf9ZoTYm0W
o96RiAT6ta4R8W95fBiLKIMb5jZEsrVZOs6PXta56MRdO4iE0vuBt1F0PCYC
FWio3Kzn9N3xmXf945YUC45EtaB1p3/CjTfGqNyQDIShoJi0t/wAhrq+Bxbw
CVg0eoFIsEr8ejjev9H2jsHXzUeJCgb6SEBwP7sg+jP6KDPP6wS0PFZIYXGU
rNGlwbwTjOJbkP71e+CgjF0r6KkH6m99lH8QOtWPzWK2WHCRnxPcd7DxaahF
MT+Lq2z1LhZ0bovZxNtgIzB9NpFs9S2chxTaw5QzG7kTgvqMgrU55ue0JDxd
Ls/wZgxcKDuCLt07yOe9NleipYG3lHx0sP45mvbj9Z2NXJrIQxA7iZXC82l8
mS7o8dI0QtUp+G2zd3XbqfeopJZw+3mzkvIgOM2M7+wYuqZw+6Zo2khBNy1O
Q8wnkVlwZeHmhUkcmW5w25KPx3sdJmPxWFth3ql3AN7PcPb2y0Ftzz2de+m9
977KC35fJU+YAC9QEuooBsG4DXJV8PbzoPAULUB6DbAccZNc8krMscvMmPlB
C19L78nbRlMTs5ejhg3pBR6isPR3fOsUJVKjHLllYxUTZKKlT+QA8B94Vr9f
qMYvty+nM4V0OC4hBnEJW6QeaWLgj4qqLQ4tc8oMMtBBhYm6tBJBzIlsCSOk
i7lSKVMsHQJGn86kmWTAOh8KX0404KS25FwCBfvmdBXq/DHEn2AvI3FTDv6W
9vJW7XQ2W61miwTMp7kmGWMX054AapuCWYYZVsuT4BnNNZJ1vZBsEftKI0+J
jikOGc1Cw7v8+ERBEOIlmitRdWCqBsZqSZWDFJuYCnwNNpsI/4cofcGkHTwO
UORIIYL3wE5hchXjBQlj/2lChNKqki1VK8VsuVTI/6r+ks1kMuVyqZTL5ypE
5C/hHk1B7hWSOdSkifktry3enymMQjSt0iu180zI9KHHWJds6bSYgQKP91EL
cRgqHfgZfUCGTTjpZ5r1zNVslg5iTSNNWohrq1VUDXE310VCeYEnRrg0YAev
/GneUvVNOMAJP/rM7ZXmIB7rUs3o9MQIIUhvcCQnqgNrg20DYAlFyqoXJZVT
o1fHroyaEt1itrzAhzTc0FLZaO+GsigkuXOKtJVQZIgj5EJSRZxsNHImK9y4
kuG4enjzmGM7RT0C0KbC5U2503QmK3qvih1DxiVaSw4RFaeIISpxythMxLl6
vaJhzqs9a2Jzynh3SBGXYjxZtGkx1bHh0Jd0FQDZwLRpb12Qi5JxiNXzHmte
SMMN0nm/gNxOWW4axUC6WC4UC8XUbDIjMC0GHI5QaLogVKIQ/KdU1hnLUiqz
XPiDLzW4MSAqOKJ17B5LkqqnGqGYOdaCGTJLgY8ppWQjjSxOYlPMlEUQm1xh
ASurI1teOtVqETgrm1J4uS+uGlKpMFTfonF4fMLlEyYWYwE7WMXiCPwuSYS1
mKEMAOmKVyZLIpipe1Zlg8idfi98jyYVqTtA34Cuqm1rTDGxhktTRUOyJ/Cv
KW3QCbOn7soV3ZX0Nld1jMvOIxtkg062/qboYaFnOyl6xrd+WqrkTK1azWzS
F1PTw8IJkeTP6ENCk1M1XUiDoMtmcrmAmiE46ogZ41DMJ0UPeFlPuuLejVaZ
667+2uSL4I7HkuHa0sa4/mOOM0xhH/ugODA1Js5UR56gEuTqArcBJSeTBsS/
ZM10gVwLU1yBB2xjJMtTIejZjtQoOvubYM3wHXgjHbxLBzQhJ3KnLONHsDiG
PTNVJ9wiwKbLI11OZu8qSayuruaK1WwtUwSOPqmLxUy2KJ7U8g3xJJsvlE/y
xUapUiCImjRfCtHFo2XD56mJ67NyekOq8nNoPOcELQdyVMSKXhGT+/drAD4D
c+JuiAp4wndNOpspFCulYjVfGGRzuUymkMlyo+MaXQHaDYScojqRlh3Bs5Rq
cWbbpwSimh9EanVUyuWyYq4kS2I5V82LVcaqYrFYLA/zcmZYGVU2tuOF2r0W
7q8v18Nr4MjOZ9wy8fdk1CDwlY7Xm5CjgsvsCRPQcCmFzTeUHj4i/rXT007p
2rx8u17SB6AUgLghKtLfKYqySGoKhBnh4K8S0E7EUFBUMyIONlcbVI29V297
xiL61TR6C4sRWGgRlWFqjCX+zE3bWAdBty3/+uoya/VLlJ/pe7RNUlro+2ib
GVm1ZA1+p8fpaPTr5wA+QZIBJ0sDIzhsKoYe0orkCplKeTMLJaKp8dhGxOjl
unsHFo4YaCFLBphv8K4V/MaNROMFRHtgmm30k6AfqbkDNqbcoroYXAR0GC6N
C4ld7wnZdQTDO1OIoA2WJcomhOodHnBbpi650ZiWzB8ANTgwQGbuU4AWeMJ8
CGsNNwKRZAApQ1rTe0IKWVEx/yRdKm8IcNlWjKghk8JH9M2CqUvVGBRy+XIp
W82lsQnB2LRWg2w+Uy2B/bse3QTV7NBih8gSeug3aNnFr5yxuWTymJcO6wjT
vmtNVXsCmPpXM4ANooY0SOQxDTORhtjrBcuNVRAe0V20BwdVBin4Jq3UkTiV
NHVlWnxtpOkwbGXTn9x7C1lcqhFSOqCVgAfpzolghSUFvBVZ2Fa5/AeRy0OW
XoBlAN4vmHcj0IEEDmxm9LgYuKMSA8LANFAC0LEB/Q0Kd2wBHIkuqqHGPeKY
gR+QLlVL1WyhXOQboNN1NUcFVyhcY657z7iy84QdM2DbyUFVOV2kBY4ev4bV
NyBv17Jq7YnTuS2FDoNT1/Vr69ydSIniMXfP1/FHP6RI1xlzp7oLhpGEUUJp
GqUf6i8Y0ggsBzut83dn0nSwz4bGo/wtlxoj7nMUJeVCuVrIFov5ciVfAs7P
lAriq1gr8KW8NRVLHZvCiQU0Mt/FxrKG9OIAbCsusvyjOy7JKSiAPGOYIpIH
FDPVLhEWxUoOtGq+VCoBOsWc+JipFTkWJ3gmd22By7fZDmkHDkN4GTQZvSwW
CsVsIZsbmJxnsQ+DQ/bRPpNrjU2hWs5WctUCuL6FQkZcjNS875qaFiwZeL5A
1BGLQQgMJpveSfMUuIDqabC505zFuJux+ostnPQ6BwfrP0+ZQlx2hcegvLBy
p9v96QSjSrakO8Lo7/9pCT00q60Jw4wRA+vqwp/ZPOw15e3YNphPqEsWuBxC
W9UcvDsJaEKXvtq2AIbdlNmYgsFDg4DrMXylKf9qIaDPPP+kXo+mmnkFll6L
mKDBN8+QAGUB4kYTQkLOSwTBf0QuCMIIOEWsMToOyxLa5n6igd8P/ID3O6eG
18yRU8c8WIhJC9TDJmiTMFwJ9bo3IOBNuTYUpNvdo44fxm22xfGOCZh3v8C6
5gN7vdQpvsgjF/z0G0HzjJ7g8d6waXDB8oyBncFDHN7t2Ymix5S7le7c9k8D
CRopcfXir8FbXlJdiEe9Bj9UrDJcbXQT9Itig5pX70Uenkek/V/QBEvxMls/
5hvGg4bdDdsLqIZw8HKTPNCqJeANEeGzev9CPu6xccmDRNtxvLQr0h1B0y++
5Ico/JACGYhuufp0dEQXuaEhdnQUfR/PrryUtpgA+SFvjvGxNuuYn5g+KZ9m
Gy8D68WudDLn4/yqPsvfSrPMI2umP9qv/V1AhwmRkpr3VeXu1HRqN29tQ5nm
8q8n8uKkn5fsZEjFAUqKVL49zzSz9ujRnq9OHK1UGz9VXsReu60ukiEVBygp
UsWLs5Jateembkxmq+v2wzV76ZZHXf3xJhlScYCSInU/eHpt3T3lR82FdLpY
rEa1asOezNrMySRDKg5QUqTOTgfyQm+3m0PrbPBQvC+tmsx5eDBUtZAMqThA
SZG6HtSf+it5nDlvleXhueSe1sTp/fgx92ImQyoOUFKkns9ezh5nT4vnolG/
198GD4XT89Kjetp8SkipOEBJkSrYZv5i2b66emz3sgtjPnFN9vAwZvX2NBlS
cYCSInVTOtPlYmWekbNa4z7vvnSeMrXHgTlq1ZIhFQcoKVJGocuKN9f1+WKy
lJtnhvLArlfgkcpmQp6KA5QUqSG7fbu8nC+66mh6Ozq7Hi2Z3DLbs34joUSP
A5QAKXkEf90Vn9pKNas9vaiv9b5TPXle3TcuT9ndrPthpN4FlFj3ndbNwkn3
ttG7Wxnzy2rt5kxyrl+MR2mcUPfFAEqK1GI4eLKr3Wel6lbNbu5kKlaceXk0
f2wlRCoOUFKkzHllJJbl5/Pz4u2z2NVf5FJnct87EU8TioQ4QEmRyrl3rtTI
Nlbjl8tGt9DqD0Trabjoq2cJkYoDlBSp2Um+Kg0vszdWuzCo9buDZrkyX173
3WVCpOIAJdZ9y/P6sttmYq+m3lbdydWVplnnBf2ullDNxAFKilQ/u3RndyeL
16fmSa9d7z+Oe+3HZ0d5faskQyoOUFKkJreLQul0MdbvFbU6en3Wc6OX86Fm
DDoJ1UwcoKRI3bXKq+Zgqum3veXlKtd+LI3e3FPTaLx8XHi+Cyjx7pvMWEdT
2OmoWTKrr6WL6v3UyWRq9fOElIoDlBSpsZxTXzLzockmvYE4z2bE3qWtLaXn
ekJzOA5QYuF5VdBro9di++x55jQal1bPUMpvDeUxm5DR4wAlRerRPZMHq+bZ
db3bcZ/kee6qW35smOPb+l0ypOIAJban7tuaMTztNCeifH3Dum7j/up1WXya
PyR0seIAJUVqeX+Xr5df766MsazOyieF56ti9+yuX31MqJDjACVFKjuuy9cL
sXxpzhq3b28nb7W8ctoZm/nbhEZeHKCkSDkVyRy+neTLBe1BvXiz7q2r26fy
tPW0Srh8cYCSIqXn71YnpceLm7el5MrspTkwK9dGIev2OsmQigOUWE69tl/l
4fB8Lg3MVlN8aTae3VwhPx6JCRVyHKDELlajcnOSfbi/EB3z0py3bnL9aamh
66yZUM3EAUqK1PzxMjdTR8/F1qNczy4vFr3RRd24k0/vEgbN4gAlRarbOn1U
jWGl+NiTLqavLyfNiX7yXC9fywl5Kg5QUqRe7Op9p3B9Ulk96ZNx7mooPZ9k
pVxudJGQp+IAJUUqc/t2dfv2OLhXtKfi3c2g+9DVl8+aYb0klFNxgJIi9ZDv
trMn4KwN9ezD3fWydaNOpI6cfesntNHjACW2pwZSa6Xpp23zQn+9LJ+cyE/3
Zlu0LhN7MzGAkiJV7j313JNK/ly3qq/1YfY+e1otGNWHfD6hlRAHKDFP9R5G
49zTZbN25ZzdlJ/tUXapFa7E2lXCqEscoMQKWR9dLsThonJuK2dDrWBLF9Xq
6VtBZXJChRwDKHF0eKWOWpW366K0MK3hoJe9vK2eNu+ajw9Jo8MxgJIiVX9a
zLvl4lvJ6neUXC3//Dx/PtPbyys1oT0VBygBUu5Ihz9z1eXp82OxXjB7rens
uTZ/7A/KTxcPufuPr9/7kJLSys22l08PVflsdD9T8/VR9TVTYpPF7KmVUPvF
AUqKVK81qGUy2ZIknneNx9q05XTvlub0WX9JyOpxgBIfGS3K4tVDrl67tzLi
zclbtcxq3eXJwOgmVMlxgBI77sZqKEuj+U2uIXYmd6P+fS5Xebg5vZwk9JHj
ACVFytLvL9np8EVa5kpaPmsUZ6rT7iyvbqYJFU0coKRINcaTM6WVX9nD69Pz
7g2ryG9voiN3uq8JJVUcoMSUer6QZFXJLYymI50tekO10xk5+X7mNCFPxQFK
itRg2jy5alza/YeXsaQMi0tDe6mUlPlETmhRxQFKitTrdf6xnulK1ulpLd/r
Dk9mDw9nzrJWv0zI6HGAkiI1nb7cTNTCan42UGuLJ+t6kZWt04moiwl5Kg5Q
Yn/mZKqcO+dvfadwWs3ez6zRecdQxno/l9B4iQOUFKm26w5qp242e9K3lOV5
vlOZ6Ivcy8usktBxjwOUPGxmqOZyejIY3Dx35pNTo2hID6WXzuNbQjshDlBS
pNQHu16vaZWnZ3F21a+VbfXyrmWPNLWdkFJxgJIiJbZb13e3xfrcvX+Qr2rj
fFnuLRdmra8nZPQ4QEmRujAunprlYevmSq8v7x9fS7ajXjnnCzmbUE7FAUrM
U4Nh52xypZwUXrLjjCG/La+fF6ePTt1MGoqNAZT4zGFVeL2/Obtp3VZy4tCe
3gzuWp2SyrTsU8IzhxhAie2ps7w9eDo1RtXOTaXcn+fk7GthlC8tzxMyehyg
xIklD+fdp6fsUyvbzKm9QXt1U7Aa+pXdaCXMC4oDlNhKOM8ajR5b1Ib3F4MF
u5pVK1Pj6VkelxIyehygxCGOF/ctM+q8VJyXJ1O+09Xn50e5t1icthNSKg5Q
YsfhSb0vnD9fWrmMxUo305a+eujlZ9cOS2glxAFKnILzNF7qWXXolGYF5aK8
PM0+XSpa5rE3S+jNxAFKilTp4nx8Ncvlnm6Xrf7TUFTFk6Xabb11HxLG8uIA
JRYJZls+v3YeL0Ynd0/1Z/MyaxhXJZY9FRMyehygxDkcvdWwXVUnxuXLZbn3
okwmT4NHZznpOgmXLw5QUqSUQatilS+6rZdaoXhyzZbPC3uk6zXnLKFEjwOU
OJYgvkmV0uDpLGPPFiePJ4v+/c3bQr2qWwljeXGAEmcmFDpdZV5fVrRe89yq
q2edl+HspH5rFRIaeXGAEttTtavq6vTMHGn32UVjsZAnhaKiv071VUIbPQ5Q
Yhs9c/HaHp1I9o2ulapPYvVZGxgvI7tZSbj74gAlFgmTq5b2tJIHK8PR5/0M
KImlpmgLaZnwyCgOUGIrYbi4qMqKVhqp15n5SWtc693dNXTpepXQyIsDlDjb
xWGL9rDbOj+5uTpv5OxXa9y3jFn9apowlhAHKHF8yu68lMzyYlSYPA7c+kUx
26/35+LidJlQJMQBSizRS3KlUbo+adyyzLLQqL0+dvNOoXktF5JK9BhAidO6
rJNivnw2cXLT5sV9vWf1b6cOSJhy0kTdOEBJkbq9Ns6fRnf1xqB7u8hPjFom
8zYuVQqrVsLdFwcocQ5Htz3I2BcXd8Uum5pN4+3h/MzonOlSL2F4MQ5QUqRa
Z/VaPquPa2yijU+vb93Bql3LZrTz64S7Lw5QUqSqIzGXPeuel+zstSKbw5J+
bWZK1uVCT+hixQFKilTl9XXQOu3nq9lOc9h6fr65c566V5eP1buEsYQ4QIde
SypsE3jjYuUy3XjboY6LlnMsjAAwtS4WXv2fQ7fZWpJq81KwzYv/4ANq1mPR
tebYtA+7h1GlzgM2I9vdqd1r0v6J15UL/x7bO99r7msn697uffXrATYKx0Iy
bJqpGi41ewy36rT9ijvqVIdNPqjpKvaZwx7t9V5NZCfXp3/8AX90O/3bplgP
IIU7HGIfSmzaqWLH6dA1WJsd+o+OaNb7bgAWXlwg/0hlyq/CXYAHNSHDqlVH
1bebLQ/XDbWw5suk7v6hdyzs4CSoOvXmchjW9dKtnDARg/F+vE14lzpDU0Fg
H0b5TPdBfQl6a2/0UAnzIPBOWlW8nune9RXAkSJf3jle7QuLlilQhTp2DaMK
/JKYO0z5fOLVCPrXEGAXSpoG8I86NqgLuM3pZ+3oX+43MN/sYP6J6psBNrak
N+SVTy2v1QdTDn+lOwYUryP+0RHvSMLLBPl46/GpIR1dFoqLgF0JXZ0qHnk/
0U3Y2IsXm/j9UCIWUrlUgcjYBt4LOhFjh0ladK8skTYh4AykMZgW3AShGnNT
m/uXQWzdafkrYf+3v2Fvztsabx+Pw9DFoJJAtKIG2JFG2MKY8c5t2EaC3ycv
XHc6DV5qWG93rgfwx69cIrVcVcFuQkKfLR2UGsGtZtgcHekZM4+UcApiER/A
z4qJd4b7tY+qcRBterjdCvZ4162sx9uXsOKsqZuyCluGsOKVn9RfGkcOzdPv
f+CV2+InfuXogX9TYyzWwibWe65n30ZKhmH5/av8rvRQM+1kdIpMP7eDJHk+
/Am/LpUP7t1lG2Eg+wMzPdgYd+tm6uOtX/Cq5+2nzJzvfqzvemw58p7HoiLt
+8WRXZw51gqHGi7gbcDY3w2XeV1CfECFsaGGCx7TzEAvYXtFBS+6p+pyS/cL
f7dqcHcX3b7X51foYqG1GirGX2CT4KHfrNjkrcqxGnhmYa8m7AuSphuWeeku
r5SO3lxa93qwehdcH+B1mX47ar+POMlHapuKWKOe83X/fs33SZpKAt0jcrjR
vvEEL6ekPvR2qGs7CB1DwULhdX1xtOf8cN3VF37TqDsAFxq8czvIOV4i7wMK
Cp3pPs+Ypt62qbm8AawAdhO3glwwyrA1romtfCem19xSM7F3IW+wt3VFKBVH
o5WhqVNG1z5sXAqKaOJMTbzq2gMCE13fvuG1W8fGtNzWYZKNjXSHTAjK34er
6A0sQRfNFEhYsOhA2jKg0jzSHYQq7bHlNSxW/CTgHRhBXg2BZ/zvkZVR2GHv
Ca/NL7AUYupXnPtNto/XPWepPYE/Ml5xhLceYKsAg6aHtg/dEOwOHW1no1Wh
CYsvUweCKIeCXv+kpliKdy4GI5XaItCmkvCuV6/gnKvAEBv5e/YYnnj16nRV
BM6HGnTwYv+ud10XGGmgqoUeXdd1DBa2pUo6bEEQX9JIOhb6rqmDFVJzLfjj
XsW9b2vSXGi4Q7aamsfCGXZJws+YcCbJYH2DNd4zjfHQFE7cY6E+YcZ4Cci1
XQltjbZkLrC5h4l/nEsrSWhasgo8g2PbNvb2ViUDW6Ko4wmKf07sDraw7skT
y5Snh8SDzKNbWEZJKhdG73ZgncGvvPED9WKlXtYB03kWkN/69xulmH9tUXCP
BbZfV23Ol/sax3rtD2bePQsxV7MELW88URj+io+CMgPIgFre40LPp6DR/Q7l
W914/ZYO5Ef57yJqOENLmqmKdwdHinjUmyPdwKpQ/+pgg4d2zLqDhX93S0ro
g3RUDVixt4Dk/v1KIPAVanBO0Gkn+h19gqF2ahwfDvWgWOOHEEChW3gflkIy
1GLYmlhypPWV6PTIJgNlvXr8S29IfAvvvMRLhoMu5zg1V8eO5v5jauMCo9MN
sr45iBfeYuOv9X1s97uXv7buJHG/lqoNVA72Qd/03Aw78FdD9/uELjTCNaR2
yMCPZEOtyYlkIBHgNSKL48VQW4uQiCdNtXkB2K7roY4/eOvWcewtYSCYbXSI
1Tl3/tBOC7o1M2po49+gYJCnZGEjmYBjkPXAN8I1dIACdDM8NnLEhz4cWkP7
HZFZr9eF8M09vU6LyybfakoJoZuIkXyfsNM/W04k9InxYj+V1u2QrmGy+JUz
/JKi9QPvujKiPner/Hf8P+EN6klCXEo6Ff0XUrzTzVV7/04too9/CddannBr
JCRJR65Fdoe3xTYsGI4hth7zTEy0Mf0pBc22Q9P+A29SRlXupNtoTfwO7oDh
4mXADVjBTzZeOBlsHrztUgSdvfef8PuXC9Vwl7ACro5aPdyDBx2kUMPGmZzC
CyzAaKR/pXMZut7y2pLGLmyd+hv2PJbgSVEsC1cy6DMEAH/bGsZxjgVEy+SD
tmqFVlvIFvCyAo0Z2Ba/y3ky6iqPpcJ4Qr4yHxO/EGf8Cxq9B59IM7Slfhdy
FTBcZ46Ye2/0cBOgUFdQYFg7NTbNsdeLTVFToP9AzknZlOqkmW1aqmxTmygc
+hZM/WOh44Cohr+yBTHLx98YmYakC+Jua/0e2JCw0VTd34K4gKrluLCZEMYu
AGHUsc23BFxqCL8JX247V32h5+qw0zanQg9BJpiOaPKOiAHaLVhcvDnvWDi1
JH6PNB+WIQMEY39xzBleNbQyzBloolDfUBPJpBpg8KRGVjo3m5ljKzfq985d
+9Yc528fh9c3v6Jl9zOBWPeH9LUaap5IP0Ap3GaTKRNT5je1fr8Z5sSdc/T7
+78Pl/eAnGHPT8vec2nr4bHwhS9ZlIl9Uwsba1FPx1BPqnQhm69WKvlMaeA7
XYOaR6eBORp40QNl0L/oDYBO6wfNRvuqfhjh6wYq5sB3e8CLN3p4y5UufGr0
HnqH+/YWxm4HNr2Z5q2s/Z5o6J3x62JamjkEJgUHUCWaovhrAZ112BIkedtg
B8B2/kRbe+9QhxGGzxVAb4/X6/Et1CuWqsVycdDGS3N63qU5gw0jYaAag1Py
nQatzumgwTC6N4ApROm7607STa2Li0wkX2Pp2pncgg1Tb6app1xsISunKSKS
vqsZ+UpWYaokSt1L/aXVnnRfl6YsZ9vy6rQ8tS80ibFzNlpeFYa9ek5vX78t
rm+un1ospxjPt6m3kcae6rrugGwyB5c9vi8iLdhqHeGaW1Q9DEd4YhTlAwmd
bHjXRKKPngRKZ71tc68ywwBvpQZa1yJBnssKZy7erOKvDxpiHz2cALBINjCm
mJ02lbEyWOqTl5tH9XYgXTwpr879vHHGTgvfum0y1WIhl60O/JucB7etQZgw
g6A3HV/oMV0IM6h1OA3pPuMfQqTNuey8bDQMF0OIAEuz0/xTER5y7vM72K7v
i0HZSffkiplMaqaMdrDjynQdNzVk6dNhsf02yeqzbPNX55dCtlL1xKo/Z1In
eLcV/MdsthLaYBiH6KBO1TXCzIjgPPEVEf0XwthDnUyYOkietQqDWb2wsPD9
2Ig/b7T7pqtBy0Vxw63E7nFIHcTtH5nU5n4L2OrHbbstmn3zvruvnpw/nw0a
renztaIZLyfSHVtp7mT4evNP2ndt07k9rX8XOmWrm3T6PltvYjrWSKbuzpKY
Le69mgOsFq9JZ+Tuh0wmdlM22g+36svy3DZhU+ZzleKuTUlc+A5hAm6104R1
wLwfpdafvRO/0+r4o9MCKbsG27i75Z0Vad2+rqxGpzluLmBFsvlC5tCz2a9b
/9J8qrLZ2OPSzE6iJ6PDuPI6cLPV+ePbFNVFIVPwOBMNSXtizqIECPfJtg1J
njiiAqIDe+orLA0cNbbARvYusJAMW4U39nUfzxaLuA+A2A0OQujhHatgZl5i
5/IN2//90RnfBD4wEKklWAK8dTJYgg218GMmROS7ch28WTY6B5MeioqCsDdw
LYZx3UI18iVt3KmDrZzxtgbvVA2bocf17ge5HBVqEhfSogRWLz9qTHvI71F9
O30yHh3AZtPuckS3R1G8E3l5X2NrAgNjhS6gHq6EM1gG8DQwHkE+vmRwTw4v
TDoW7no1pFJeBO8hSig8Kt9s9/yONstWiuBCVAY9jPeBG6e+0S+brtduagRR
5XoQKt+KYoRnLgdfeL4QMHwdO8wLlxIFutYEPg3oF52ObMgjvCQh6kflM0Jt
ZqlajIj5EC0K1UI1N7hFXsLpIy+h67TRmHdQi3WHtt2gvDN5nti3qnjyfHYh
tl5fjEXrbVJWjaHmuOcdbXb/8trVHmalh1ul238ulZ4rM7Hy9CJJ7Go0nDym
6ma79HTiTqVzV8qMpw4eZfD8AFVHTPSZkMl8zpU/ZzK0UODk4U2NqNPoblm6
PfI3P+xEpPKzYHbIls2gk4Tv44bB98UgzNDF63jB6T0W6pIhKZLwac4XBH/M
liMr8m0LksvmS6VsZtDHU3G0tLzXB00DhjINDCUO+rfNwdWMGYOeC05inIA/
t6rmcpYdKUYGFV2mkse3+RWN+ygQXBYtWVtUED0NJXIQvsi4hP3ZW+mwGVUM
8Bto8gl9DAXZ/kGFL93NUahjPLzWM2GnbQR6TFucm4QL3e2VBusMnm1sgGxp
k9w7Qjt7INGC8hDOLisl9BmXjemRirdU8auvCvTvTCFbGnD8/y2X+bdcJftv
ueoe9+wjaHBCXjf7Yv3qkvcqz34WskUMl/ILIoSmf0GEdzUnnjshT3s3tq/H
G4H7yJzUWEV9gWF7AzYM7Du0LIoYTd194wQB5PeYGTwh73fhXLI023InIHK9
GwGI9OJ3YXaUPsVMjuI04EXsC4IhRb9NzufK+cp70CnEtqkLQAIC0w7QDvRW
ptXvnvLw8WehZhjIg74D6B17PrSEn/hY8Atdm4S87zP7T2vcx44+ophyyuab
wkaNQezhmRy/4j2PvzBagQv3TezhcSb8050z1wrHOAsiEL8rWf+oFijmy9li
Mi3A3eTT27DBXHzXYC7yEP6EGW/wf3jojRc9RMRo9Z0JvWM5F3dZzuDRjSz/
6jvfZIq3jTuj8/Hwqly4cAogOkuZYmFnFOljU/5EI7879fIPmTrFlbZD8vHT
nzyWwUJsTi/L6CKVyiVv9hj50LciH99l4f9xTs7kC+VCvpzfH6nwYxIXtfPm
n43/t62ehqa8dx3bzuMUOj15ZzXP3kYXs6Ex0TI1DEFks+U9oZnvQojiDyFE
JEbjESRIa1hnoPG/9ntC8YS6cq7M8qU5Vm1k+3wx63vEPn2+LVZT3IjVxJKv
IG5R8NviNsVQ3OZ7e4vfEN3Zt64b0Z1EmMavZilXK1Ze29lqtwOrmcuVM75X
t52gENLP64so4T0xqvTCFmhGOGXDGD4PAdp9fOiB961qG88chxjsNUKk8vPP
KP2MZ59xTe0p6hY4AmSR5rL8fOCvWwRBBiWiDPkx90Jy5Mmv819U5XUxzExO
tYn93zDj4pfrC300vTuT81W3O3m2L1v6bCm+NkS3bt6sumOtM/tv6EaUsnZ4
W+w65f4gV6j8K+5cWJIDaimb9q/pw7+jJK++Q/HkY22x5K63PKFDnLm2Ht47
jBnf3T6Vssq9ek1RRlBNh0JciCVkwJu2wvT1UbSNecSuxtI0tz2hFRAsCpuD
QNTxBPfL6VWv0exuuFabgJG6J+Bq2kyzj4UTpo3RgftdyGeFM8kQsxvk3vaw
9mLK/ehWu3V60g10lQNk3iU4NqF4SSdEaqpTsXdB4lDSuRLo/Bx3ynKZ7KCU
cassY+xZHfoztTmgq5Ry2eKOQVLSPJtasKH+PQVHrozU/acLDm4kgVFEpMvm
ynukR8DQ15mCc3Em95aj7q8fFxeFfOG7St38vwTxPKJl8+8RTe5Z9efLlVke
jBMQjUI135NqJaHBZKJa8T2qbQBKJ6bTCT/DJiucn2EjtYrZXLb0HrUWg671
0mXt1XUlAbWK1e9KrNzHafWdOYyiekHZpke1TO49qmVLUutZNJ9VJQmP5ao5
sof+9llwVEdjv/wUzsH1Ez7ZOhc3kt2aIP/1pz8OeKJjzcvLDNIcg7xNeIMX
b8LediVrtU7CDbJTeZ2Ll8/8L5FuS/UKvA4K84v9iicq4dxIpzctr/aBp6ya
vNBWkLCEzMDSFeDVCeYz2V4+0xad6fa+2QxLOrG0aGZhgWckGx0HoQoIacSC
bHzVwiJXy/5MK/Azt9j2uC6HB4IgCl8owvEQ2jcfKEle5tnN8vTl5vTsQmYS
K2mFweX40dDtxpMPlqzEj4NF0ytdGg9fl5nHp8rDk9XOd5eF+VXFyInu+TgA
i/dOfhwq2g0VbfXanlRX5cHFvDTMqo+T2d3rkzXLdDM+UAoPfBwq+ujpvjl3
tPJiPH9bnD30c53c88KYmJ0r4+kmoGyt9nGyStI4/XLyfD8tP616i5l0+rpS
aqPlQz4/vXy+DuZ/jQYZr4uJFOmgHPjoWDMfhhgp9EkrpeLDtVTPPAyfbxfL
/omsGf3pqNzT6QYDHJ5yPXLkHvKc7S/OxGKSkv3o0NIaQNodvpXdx7otik9v
bu9h9Xh5aesPo4HTu8G0RNgAHvTct0BfticvtWph9MaU0tVlZ359O170++LD
rV7zadnodeuJCKfotpy+qeckpSM/TZdqXzPUpiyXx+NppXRSCxZpR9AgHvA6
XHDdsc5yV4ObV/nyrmZ0O8bgfpLLdfSHruxDD+f/fP+coUBw3G4JDisiOO5O
u7etz4k5gLd2fn44z7jdbjV3pSy06+H48WR+U5s1Zqz4rWvvwb2d3JbNbNt6
WI5ajdH49qx7WyrenkwbTQ9timEnRZouTLscLtudRbU9WM56T8Px6GpglLX7
zil7sL8R5w/cw8YZtXN5+2FJArZYelC5aOZv3ezyMVuajFtnC2vV7d8ubk2p
tl5hMFv2nWJ7PiadQ/ONHzWydi07biS8gX4PnHE6pGrTlDiezmbLuUw5m8/v
I18imN61s+k8eCCEdL9W/yZEweJfI1jN57LVb0cwBCuXyZQqlWImWICr+nV0
h2FlKP+ehTYavBacK8F8vGmGJmTKM1HStBSdNtp8XPhI9D+KTKacLaGf7EHJ
JYZC4bnB+pAI05D43Kp4EfYadP67gS5U8hWMzNISeNAL3w16MVco5YuwKJ2R
ACY2FYuFyomxyG0ugb7DXYfHIKT3qKsE2KxeATM3VnkxHy8L8mrZyBg7Fma8
/Elj2IOERqASV0wwsdQhrz4+iPzlG9q83AjrOhcMeYtRtOfDrslmMBUnncCz
2fX5IVXwCZ3aZW2rNrcfKRvHG7wNk7/JSyOxsvcAC5OGoPAQSk32a/Mo7gOe
gkFlSkz55acRuE0MnInoO7xJBVagGQxLOCULS6SxjnkVrTPt8LuuVb/BTNiP
GPHcEqzHZExBZIi5sEDUpWAkLtzI1aiYVafyUK+Wf6vi2bsBnVezKrxZxgxL
UMg898vXUz5tvFp26oZi8xpL3/XC2jubd0Lhp14C3Wi+vnAdy/BC9emCHbqj
2wJiAHGw0MPevKP7MxV8LlR74lU3WuSCgA/jFcmRj8Fklct3j/PWhbSep6EG
To1XYYklhbazbgx0At6/hXQ8xRYv2KAHWGolnCN/SMKVakjwrGFJ9tT0/jVX
ZXjUlawpbItbV1nBX7dsyKbSRLgCqiimNYJHfXOoAi9du5oGTHZ0tOse8aOj
vReM8+nTRsXafD5BrAnEScimyLkCZ0VLtxcOEQJXcS5pLnmgcnjLEg22q75p
dGovMwY6eK08pICn2Q5iq7CrxhMHGXDNktwnnDBths/90nrT2Isu4dO0VBm7
WgCLakj+M3diwvpY9t//H2OL9BtF7riklos155pkyBOYCiypA9wqnFtMZxau
zIuEOY1tYCj+PWg+oT8xddtE8E/gD8OczlSJ+OEaPHxNuFSnpmHCnoIndRCL
K+FB1fj7NcM0Vjq2cgpX8PndDywcowELZwpdsIBgs3kMdGZODOHaYu7f/y/A
wXFsDu0EpD8wXlvSGLYjYtR7oOdI7hAn4pfiY++bde29sP0/RDNSrB+Q4cI1
CWnFgk0BKGlEk3MXvHhpJdQmOsj787//59//77//5xR+CNfqEwaziYqpUhNd
ZWOa2nylCFdTSSVywzwROuobCfbeg2kqAAAetf7+/1oIicGyKHwZQIz0JAff
P5Om7pCvJNZ8OubCnqrrtTnFImfgiQktBzAviL6GOx4T4AYbgkg3NbaiXUYW
DfYIsVQQdXyDNUT+10d3FQk03iqL2kxYq/UmW8MKiZiYvbXNnqEmDD9mm/nq
gcbvmIbrwDpPwMpj0u7NLhL3A06nPNa0Ywu2sceRLfRteWKOmKHi0j9JFlrW
EzYa0YJeSC4v0b0ARTUEXkcObqmWqkxA8HcBxZWkE2MCBcG+QUsFltMhvj8z
DYm6jbTNFbIIClVYcVDpwokEm4BkqMVGoFJoUfl/eiu6q256SxUI6+xfXiSO
OlE3FUbNY7iSy2XwvzFek03lvbxAlbeRC40ZWFIU/aNuE5K9MYTf2sPvSxMo
nHPg6Qnw3grmegLzG0tzydgltS5BWOjCuTlkKiwyTr/FMNwGWuPgoOfpX7L3
bL8eEgNnxwJ6wcdY4M5Dgzy9lDeD8dmTZzTzFhJEIt+iwIoRAkWKPSXUhN1V
72tQ1LfEBvMOFuCfUDvw8wwM61+yZbTwdrZBQeRG2D2BpswzBIOWSaGMZuHT
Tw3mOng6SLpGnrjG2B6DBFC99PvUT4cH/z+8O07lrDYBAA==

-->

</rfc>
