<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-30" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-30"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur, Belgium</organization>
      <address>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index, Austin, Texas</organization>
      <address>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="12"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 228?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>, <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how <strong>intra</strong>-handshake (aka early) attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader intra-handshake (aka early) attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 232?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published CVEs/GHSAs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">2 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 870?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA829yXLrSLIouNdXwDLtvjrSFTiPpzo7kyIpkpKoidR47BkP
CARJiBgoDBxUmdfepnf9A23dbb1s6x/o1d3Vpr/jfkm7ewAgwAESTp2TVfXe
zUyBgIeHh4dP4e4hiuKBozoa+yz81DEcSxInkqHYE2nKhE/SVBKakqWtDoWa
4zDbkRzVNIS6adiqwiymCG3J0keuJnyq3zfFXCZXEvP5UrUsmCOhft/rCeVU
UQB4gs3mzJI0wXQmzIKfmja+4s4ExxTYcsZkB4DRF9lMKgM/yKauGuPDnw6k
4dBi8x3YxWP004EsOWxsWqvPgmqMzIMDxZQNSYd5KpY0ckQ1Ck4cSaom5jMH
tjvUVdsGqM5qBm93mv1TQfhZkDTbBCxUQ2EzBv8wnJ+OhZ+YojqmpUoa/tGp
ncC/TAv+67Z/+tOB4epDZn0+UACTzwcy4MgM27U/CyMAxg5gUvkDAGwx6bNQ
u23WDhamNR1bpjv7LPSatf7BlK3gkfL5QBCFWkeQxjCqjX9s0kJa0wJ/ji7G
wZwZLiDwsyB4wB9a+Aef3wOMCZQWWvgTPtaBEPjKb2wp6TONpWAp8LlkyZPP
wsRxZvbndDr0YxrAAWjVmbhDoJDuTiRdlxTRtSVdEm3JUiQrvYvcP8FnmoSY
w2c+4J2fpzj0lGruBJTev6SpiaPDQAeS60xMCykJgwoCcIjGueGnrjegcIcD
Cj0a8Cd6y7TGkqG+EV0/C/07oWExG5b+WGgxS5eMFb3FOMWCiQ8I8xTH/DfH
FRX+VUphP+0Y/16V5AmzNWkuNNwhW03NXYPXTYs9MGnOIkPiV9JvCv8M12LX
AGdMMsSuZKlMOJPkV5c5uwa4M1TYorbqrHBnXkq6ax0LJ0wbq64eGfMFwekI
LvXCwf3mGvh6arhzfj3TGA9N4cTdNWoPVms8kVSh5UqGUDOAs0cmkJZ2dZ/J
E8PUzPEKpp86Fi4cBf5Zn6iGFMFoqLlMMccGjPnbGJ/to0R9wozxUjWENow2
3oVPZ729I0NIroUbzHp/jLZkLpgh4Kx/2IQnsOpGNpcpZoqFQjw659IKZLgl
qzDuTnwWqiNPItCn8EmK8U9+s+n3lDzZubTMmqiqcKlOTU1S5Yk73blvJkyo
SzPVAfmP9F0eCzXXdlTYRn0QI3ZkcGMNK2WnRvGTa6aEekropoQHVdOYbr+z
osfCJUP9o6GEiIzK5pKc0lMLDua3mWU6ppHSd/JzVwLtoKuaKhnA1ZY6huVR
1F1DX7c74lW32apFxppNVFNnYylluYaj6ix+il11CopzIty4IN1WBhPrpqap
xs6ptiV7UtdMaQqTlknt9hxzNGKacCENbXwIzCQZkhLlJp0P8dsEPpfx8324
dEDkCT15YpnyzoVudjsXnZpwjdSTTe0YR0xFhnKYpP/GiHgz762UBLQ7MPge
mIOaEja1Wwrl+GeCs8dSoTc2bZBDIAgsjkimB4o1+BlMAc9uAEuhf9HjsyD9
LJy5BhPw82M+lGSNmbNWeIvFIgUygKEaHMMHKYM56Zk71FSZpp8uZCq5bDVb
yQ02sEPkBlHcBhHM8MeBagx8zAaAGeEQKC36nwjYg/EA7H6X8tRU9Jf7lK9B
os/PRPjGE/17yCtabGb+GTTWVjE09rQ82hQfsiIIpx9IqehkPejRoWgPfMY3
+QOPenWzbvY8s4yTQVBtYe5qBmy1ocbQ7rWYJq3wHUmewm+qBJYwTI9MYTab
MJ0sZvwU7EDbA7+DK+U5SwESacDhlslgL/6qKr9smIDCeg1yJaGLTEzrAD80
7+4b/NVsqVCpxM2yednp1f4p82TuXEkxQ7VBM7mWOcN/penv9Ab+cVNttXs1
EKCyaYu1TpTbv/9Ewnyfy0cRiWV9VwOgc9XUmGPZaRnRTdtMdnGDpSVlrtrg
cTA7TbOZj8ZjUZ8vl6I+Hpf374W7NVCBKAAOxSZFcpsk4a8J6k5vw6cSugE6
aFduwmwRzWbkTIngVA1RUYKr4VMQDB8URqCf+o1HASXISAXvcCY5kzDxsiWw
F8ZgMXx/6hVmy7y4eMktxeWy8A9SL/8dqCeDgpVkmc0coTkHh9aQmQAG2EQw
VFCnTJ85K3IwwTl2EARKbctpSI6EUhdsG6HWbYDveC/2Lq//VEJaJWDDWaEi
vuSsxbcRsqmMmQbcIvZWQB/djtLzlummE/F0kdfAnUZqqbt2aHjqCebNPDTs
Fc4aF8929k988jKWxRe5OBdHi/Jk/8T9yQne5PZNemMPthhuJVzqmQmWBgwr
KKbxF0dQmMNkR5A0DXhIGjOgxBBsasdFyvw5U9dzr2NxYS3n4qRSrSSaOkY3
RF9OgDXorETOyptrjstZ88SFamzFPcIxIJQmddMY4bZxVBDENQyXqDLuQW/k
yGbIgqI3YowRNFlRZoNRmlKZMyIdiw/Suj0GqkhOeplnN8vTl5vTswuZSayk
FQaX40dDtxtP6Q+bJUTLa0udS0B20YK10jZY3/9RuK2JKDTkCSw7eLJM0E2F
CYqqCIbpCCheI/uD+SIEdgbKBvzWE8dhSuSFHmwhhrGqD3GJj06a47qfQV5K
r3OxkIe9YRWquf0E8QFuEWNs7iFEy8Tlnn7+V6PI2NxPjfLLaCEW85YuziaT
b6EGM+dRcsBMNGnORFA/c9VyXEnbQRCZWQ7oVYyG2sKCWYxTxnSBND+ICtt4
7afKrDiaieNqYQz/0KvfRBV9L1V01VD/5UiCSMUo0uqrDmbJC5glObn0DfSw
HDlKDxCYsEtFWVMxeryDHIHhxS0P0DWvromk+eFUiaK2nyjFV0sW55VyQdSX
8+W3EUVUpD3CZHcw/YPmbYNHTU3DV1NhwpR+NGFmaLoWFyBmR5NijP0aSxhH
dn8EZfpX9f7V3T+FLONx5VXUR5MJmCeW/CGydBpi3VJtFZ42rjqpbCaVzRaK
6Xy5XM1lKql8uVLMV8rhF3eFTMj0wDAIvYEWS8QiqZv6DAw0A1zpUwx4gY1i
SNoKXzVHe4Mml+Y8oFXx3cBJvV4XQ2ZRmqLLmmjPmCyqiigTZt8SM4FfuiZo
fGkkRX/op8DGtPChxUaAe4iCmWq6d53KZbLlFC0z/Cre1qJEA16Q0MQVhq4D
fDOmEC0e2jlsDM/RYbR22P4Gstju6NIeImGsxLWZoS7JlAMDdwSyH6yBtOTI
uWJ6huE9j53TC6YaE1NT9lOqLlmwWobwEH7zA3TsmIb7//3vQlcFAQxWY/TH
J5i/PREa8I8ZbDsW/bUtGQbI5b4tT8wRTGS88bFkAWV6EzaCiW2s0cTUJRu4
zrZhfhuoqqALwAm/NVXnzabDgDpsInZyfRpdqW6nf9v8iy1csoVwakk6W5AN
1qNtCMuEKgK/Ei6kFbDrk+laaHw3KP5uC1cRpVH9iBCQNdNV/G0O+kqVYLlo
9YaaOU7jd2ngMfj/4BBbTLRFgy3EkY+baHuoiYCayIazkaghauIKUBMlVeRH
A7aIx6Z71xlx8CYJW7vmYQEvET3A/4fNbbiwNcL7Lkq5gFq+l+J9IXhebejD
DYc9iJjuZWmaOdEE5m6LgLM6noB0DMem1xSR19jyXSVGzo73igVv6XeLM77g
ILnC/lj0YPlA9c+5vBi/2EiNODeK6EuJDPMMwsh87C0xU9h8EVVE5I3Su29U
33sjm/HfACZ447iMJBnsqYNUKnVwIIqiIIEDjtHAgwM88aIjaUFSdRuV4cwy
0fUQHDzhg1XR0IEHB5ME/5dosPa/f0oY3T08Fr5sREHXMD4eOQUw4VSNluq0
3WGI8QMlK3xCLWsfCosJiI5gbhSBkDhrrOcZuFww0Ym5EI6OKCB2dLSZaMJ4
oklYyI+IQqBFZ0hXVWbHAA5E7hHGxExQF7MJKE8cBU1X2z5CFWWBn8SsY8FW
cdQ1v2+GjsYUWtFge1ns1VWRff/2N1/w/fEH/BG3v//443jnVMKDSApIvaMj
F4Q2YidZK0AHraYl0PMIkEU+AaXjao6NaSDCECwlQGO4IlHqnzYBJrvOYhCD
v/2Na1RAF5cOv5LQt0HO3PMZmS3wPlAV8QSXZETSEb4TuK0AoDyjxDHxFO/a
Mu/RRTgWwBUAaV2bYcKCmEtlBBAwzLAZSTWAa5mKK6s8oEMIWbD6bMH5agL+
jzBkDCOcU8NcaBhtCk1WY3NgHkRqylCfglmdEuquBSra0VbH+JbFiExHR87C
DJKI/DyjY8E0GJm3+LSayoiYSgTfwbvEr8HL1VQ2+rIHonJMzG9svF5OFfgM
tj4ppfICiVl7AjORxhLISoemM7RMCWm1Gfzdx+ky8izFxjVNIB1F45NGlU2b
wldeuhQt8mzmy/YQH3FumUkz+priwTanmOyTUWAqZWDxlVznOmFQecgQAbCC
wB6D6eCarl/gg6yZiyMH4L3h8OgcIAgwTfyYgtaIKTC87hrID9/IPCnwQgS0
JHyuPPb4RQdqI8JRP4QwIwJH6AvieTMMSWoYI5w0WBfE8V8oXg+vcuAhf8aT
8LqqKBo7OPiZPCPEl7Tmvv0peBYlbG5f2uDKAWvAMsFK0ozeGM3no4wCX89M
W9KADBYbg3lJU4I5LyZkOCOwFa05LoF3KGDL5owEMMZd0fO3HHgTyA4efgpM
OVMHDH0zS8D1xIw80NR8m3iMOAXACpNVm4tm2TFh3VFK4DID4qpCVrx3yKOD
BpBAzehgBZv6jud2GMvdGNKmw1nxdwnbKBviY2mOkVr0OgFQvNBLwoPHeLoH
P4ZZcuRaRGR/swFf1EAccalOPGiBYOd7AlHxfcUwL9Bq+46iHDiK8LtIY+w+
L6LV57PflNLw/zdJEPFRE86bkIhMHWdp8MzNyEy9ecLGWMuXLcECv8JLiDNu
AzQtTXc82ZqEx2MKA+sV9vuM72XViCUH7MSfhSuQnCgoDj6wD501+ZDFeRCQ
VDUGijdwieFpfnbpP47HkgtSMIzAE1S8XBl6Fomm+OkwYFAe/A4uf0r4XTjZ
HBae3dkMWQT+qxZsgt/hiyx+UKfAyH/9j//NJpiGiRbQ72DD/y58QWSZlV0b
ht+UbJEGX4Ph0YiR9gAe0vC5jeHD89+BRu57o5HjaOQRDcpYxqxik4RIZOD8
9x44zwcu4MA9YERm0fy580UiMzJ+4XuPX+DjF4n+pg4POdGBh3/OEVv/nI+i
UPzeKBQ5CqUYFAo4/F4FvBOhzTiWzhi6mjZ6/kM+PHiTDHOv7XRXsqaufesq
q5R/bgnuG4YKZTnsx6Vmyujwr+Bw+Yfz80yqkspFPS7bAC/awcOt0phQWczI
bQbeTrszDQw7GyMPxXQ2l35gOF1LrOFBIZ7IYrChj9+K9avL006jednv1C5K
LW9kGLpej7jJvU7rI/M/BONEUkwKz4OseMHD3y8xUmcnzA1qpH0JRO7uzJSR
NGtDyJ0pdPKMknINTlJTOrxC8AiODErGBgNNZukZxlPBpQAE0eGhwIvvCIoL
JBBpjMM1M5a+NzOWODOWdzLjMWyG4zVHgr6IDRuA5ggQLX9vRMuI6N8+8xDR
Lz9tyXow8DYtW0Tcd8bWNtBPfxwc/Md//MfBAws8cclXcvAAJg7/HxwT37yD
v9DJIDdiCG7HWs8d7NBz9O1+3ebaXuDvYMuZROcxhK6heLYroqerjjpea0L8
XlFtcoKQ4XxUwxkCKgN38MpFVQrbHJ0DBjsfPpUcQXUEXVod0HkVUAEW1E8I
AYNHhTfhI8tE72rtN4kwqRHof+ETOJ5ME/KHwfT5pOKmLWlgF6M1BtYC5uzA
qKBvNBM4XDngNlUoEeUYjXM0VA3vCWglHUCiQcTPMvykH2l9RH0w4ma5oo4o
TI1ThMngsD3uBHqfwvjexG3XYgFBQGIZICTsA6CCCkYCWlacuKikUsQyB8g0
sHtnWD4zBKWJi6CZaGLgAJEEjfesHAyA0ZEht0/+9rdIchQGHGzbhd/gPc+J
BU9bARfi2Asj8UAI/xojMZEQF3wfcvW54dc1FabhSl2RaervoG7AvDwQF3UW
Xl1YI2GEMRhkEVwr3VSihiBOCiHBiGvqx819x74ZrgQb9+8KnRljjL8iV8GQ
X0FGONJXAU89QJJSkIDoUfdYAfO2aZEET44i559SRET4Io3H6Pc57PvJowDk
IUXLMIhBEsJzT5Xw3lV2zXWv2wWrRhmAGmorzJfEaIA/R9fw/kp5CzjiQR8f
CXI9fSt9h1tJPECJRGTwhZVlOAIbFfK7g8jEnbT5uNvD9QWuCUpUCXdG6Gzz
E2KPfisMsDAOd46zHT+GMYKgCMxUMxckORemQLEG4hKQCN6u9+X32hUHvwBs
/BPSHcIEthqF0jwdfQD297UJRsdu/pyhPA6+kRTFC+9Y0eg/Uc1z5QSupby1
/QgFFdNLGZihbAYI0XRZyfYieCq+BU6zFykCYW8xB5xmbxfwcSnqA4iqhL8n
MLYc3/18h5E8Fg6PksNljV2d/MDFZCVExiesgigtBex3TAJ47j0qgx7a/e0x
P9+cMD7NoyN/djCjcFT4PY0LiLrGC9bPjFSm8F3QXILGRCYRei5sf4uUvBc6
FXrwoQuysOfn6AOEoYRbGaB9uez0+rCpHEuV7bVIMeZKCjaZkxqb8zSyvui9
kpbntn2YQh+VhDE6PR5Y8Fqp3hHHvg6CohilTfN4KthloigG/wcg/CAt2moA
gyL54MoK/Lds9HHOM+wq8N9YdBC8iTWmwSP/rcL6UdlzT9AP6jJFdXXv07X1
tRNfZJkPhuXQBjs6OoUP0O+2mHewfCy04V0HhAaGRGEH+Ars6AgXLkQmGhHP
eGzE6mdgShHYUkHF/QcSG3/Hn4WA7qe0T3ZRdVv1+mTbWep4LGxXIHIjebtw
UODwt3Szvwjfa4CNk6kfMMLO5FtvnMK+cYQd5M3RR5xbd39ECt0vgtwFIv/t
ILbShz1Qwb7inrGArvFfhVDxMqg0MFHWMCkG/t6cN7JU3yPXty5LKP/zhw/B
zPmfMIb+w8ewHPnPGENUpCSbZDPPjL71JPGeb9dCeS0Tk4hiHqf3hCNYCJ8o
3owvYeEiVdeSQjEthesq7wAPrDGU4j+DU2eBicO9C7KIHP4AM4s1VJ7o6YHJ
xj2VHpNTMKMsQtprBHOTHl4seK+tzwVAD5ywlYkWNloW/JiI5qExmOCYDkW+
YmClef4VTWO/z0Gs8UOHPuBdgAmF6Yl08izNfE8ObRRYbAz/o7WJH2F5s6Dw
NB4MWobwANIzPO2arXh8Ac1jeA0MTk1y0CQL24FU+UTzxWwTjJVR6MwCg9cL
dNMLQ6ahOw52Fnic4GuBewDPw7NXTDSLsVcCjs+bDRxTaWGowAWneV9vnuOq
AFXAAKLzZPxppFr6Ah0+miI4zjPRNVRgbc/g40hKQr9+IngZnOSIamyjV8XM
m+X6OytwS9A3AqXeu71s+bgz5a+Igh+FPF6vHY6HBPjUrB822k3BC5YJc0lz
GQfrrGbIm1pAfz4f2xw5NBfG7TwKTtiUTkInrKGUnPvuOiQjjAGuI1z1cAll
azVzzLElzcDZFjV1aCFTWIAUkAczN0h/gJ/JT7h00wJy+3T+etu8vrrtDxq1
fu0rL7vBQMr69J6PxE+vZNOamRx3StIjXlTHuF/CjMLrPQQ/k4MfPmPSnwXm
s7O9kH8l5mewgjwdAMimKusqKaqcctG8diixG5bWdxmJwMFAHIcgXS3E2cyQ
yGYLcSE54LAtGFVdsaWsAXXnPMTE7LCjCLPmgRSFH6LztQWm5md2Xy+a5584
Jxx+De9FG5DSFO4aAZsx6jMCaKFLINk2+hKKKjvkePKzOkak3diksuTanGYK
G2GdEBj+3tyOBRmjVQp9TvtQxDwToXF70uIpIMf4Efcy17wGb/ukp8mD5wVw
MY8mKgX85KWiWMrB/4uG0iVd4YVFRtoPEttpftroiEH67tAFrByMROiKaA/F
cqZYpL4dh35EkyJlpoEbkAEmhosBHVgWi+fzgQhzNU9Cfxak0Yj3k0FR8Qz+
VtEPpJgUXUB6AyDXwoCW7Y48emnBdvB2JJcczKJgxNfbRq/ZbHwV+EkmlxTE
7BYMpq2IxSUKR9kuJSN54cHALUbOJ01D7h7ARgHscQ9gKvauRWJ/dAhJpFCh
3whP5v0gSBCv386/5u6lwnTYJI5FlQ08EqgwSRP5xAw8fAGmcnXveBU3DZV1
ozxe+AEPOofkSSh/XfODbzlSDRpMcYKi7wqe9XoXf7GFr6KIO4xGgpVlyi+W
Is/cr8KnL95LQj5VBJO0c9nr1y4uUrqyM4Jlwsu2rQX/ptMe7w+RIKTXEA4P
/eAhzgR2wHqZgHbw37e1S/hvktHXSFFEDFZt5oJgVjXYzEQqIHEQM8Y4lzT2
HXpnwrlgAtYJl8CevKCVAiZklN3n6zpfwYV2JnfQL8yFeEFh5q40m3mxRSQ3
N9s9Y+PgVB1jCDcXa0yEtkS/2RSlsQGGAzCHv3IixbMP/GxEShtAz1QSYI35
jwLPytoIRZGM0aWZ7Z0NeNmMyK0gP+j43KRkAT9NGsTFunwXhX9YN28cXlDI
AOaXgtkx/gNPMAVTcA3kg//7PTLSxz6B4cUd/xN2P4773zd9AsMfHV376Ypd
Hso/OgJYMG+RFILmkzMwOfbN3pt58BlSI/YjPny9HthsMLIHq359J7QfhH8n
+gMfugDv3zdS7UdoylguidzwJ1xspXERPnED4nBteP27cNuF35r3/sEF2Bsc
jxvXJAVMBZocEySDcNOMWW4YSEiTRRDG7dN9NzTk7llH7SN/5iHodF4rNMji
FD71G4fvMpNwjbE+TFcCfDYNsPhPCadL5lA2uI2hQZ8CPszAbPt3kie+reaZ
fECn/ejEf4rI8jc20Gn3uun+dYQ0v/PEX7axWXcS4+Ov0mhkEdfOv4aG+z1y
JI4SFCaDHOFxSpOXz22Mi6Z/+h4sK1K+vuvyLvF9izwy/oMnwtMYMSZqrTs6
7IT6LZ+sh7/oh8f/HRQEnZXD9sUvMSHuHZJ+yych33pDDfnCXvAyTbmvuy3u
QYJsyHX0mftecqCfj4FG7cLwA/oBbA6Uu3429/2Cw7UI0AM6hKNN6bmBfuJb
VFdFjMOw+R1VdDxa7WuxdHhpfhduXcNOazA3mx/S/rqTb4T+arYlXna/eRuY
WjQSN3r3qp+PKpOP65x9bxIKKBSadfQ+o0h3uIAwwmJpa2aXMb9GXrzqpX3J
49ldnP1+XzvDu8ePl6S/Cy0SXoFJ+k0o1M79dyJqaP3pqadN/JrddKBZcT0n
KuxvS57geUcQAAkMdH+QLtjh1koECOh2+zLtdyGkgf3h2p5pmQ60GPg3EmbG
b84p+BKmkz5vnAprskb88/UXdYv5MQROup5Put8Fahriu8gx/8NkxHDgODCB
vaoJkjVh0XIRbL6NClHc1bujPChErsGZgyXXd1IOD70oK4FcY/xlk1f+gt0R
urDVD34WGlRaA6/fRxIYGjy5AWVkX9UxdYDxlBqeq1dbVyXwQ0KgWs13Je95
rgJKkiad7REBWfj0BX7C9BTVUAmldVoF89MqKD3D9PIeAEKmLFzJ4Img98x5
M4oCYhC8nC3AvOTQy+HGgV6Y5Qs2K127VfEdLGAJ7HRpPHxdZh6fKg9PVjvf
XRbmVxUjJ7rn46c0pmnxLhk0aolG/eJRC5NOXEMmPEM+Pxum/BFxMPibivQy
uVw5WwK3vpCOVGOuu8GkLJvX9DmM8XQ0DKHIK8AiTIVcWThlwxA+QSbfug5j
+/xL+HJ0FJxT/iK0O602djLjRR+HR0f/HSF7LZrCsO+buw671iPFwS36cEtb
cKmNVggMnnbtPPT6Rvhf1nwUXZ6YJh5YfyPZzE470pjn8WHYntIjs7QEQVE4
JQ7QR7uI8wGMq1TU+K34js39uBZTWXFsZlO5Egy2hfTY/EaEs5ktjOtbltC3
JVxiQYVGeQhfYnqNfShBdhN2euZqWrpYoW1c3pzB/Xq0HZOh6Ow3zsjb/wry
Zi5m2ERpM5RqgyvKq1Nt9Dpgx25A38ow3hIKO058Yxig4O+xLZZ9X+zktvdv
/bbT79RrFx78Kuwsj8H8xlyJRsj/gyMkp1Zui1xbA/KDZ59uhe1Rgy25Ndr2
6fIHlibUeyTZIHS2/CMH4CfLP3YE/QePwE+V//ERApmwXZkHXqKnTdAW0805
N/Nm+/OsfhcK/8hoY/P7jRRLOX5W/gHilf6RQfipenSUbrPRuet645RS+Zhx
1nZ7YDVH037DtmvYapY2zGWeAnXp1ZeiNcqzqAye303GFKYgSsZqfZawAqcb
zFATUfcqVsNn3JGTd8qe/PrApCn2Of56zP+70f5Kx1NfTySlyTXY19TREcYL
wFkzNSXiu1C4w7TxJDnFUscezB4lhxNUmpr3AEDzmWoaMI2p+JEV2y9alHg/
fUrlat553VEPmlhlzyQDO6qbBvglX+iHdyryJ6bOZuD2HRKRook6YQbYNhJp
DsFlC5TzHqwMzDbUl8cv5gN0MRyCKQBAc/qeZ+DeR/Pt9/evES5UB3044Ip1
vtocFIUtm5hJ8Mf3TzeM+nLcOA+S4b74o30Y5mbenOfBfVmAS+tIMzpsCfk1
oafgqINODB5hXQ93khGjT18ohB89BcXDIo1bT14ZETxNu9gVLOhhJMoMj5TS
Yb8qTR8G56Ri+Dd+5JrNiLmKmMlkveNSZNcvtW7je5zC5jOFTAB2PTCSjsrJ
LjE/m2jWbzY36AVOXJhWVPWzQaktII1HxVyEzGhFS0myTm6kYqrpoCNTqVgp
FQopMN8zuXyGaon+RJoXkOaZMM2x+LFI8dgFn0nPkTTmhth7KUuin0G8vsjC
5q/5/x7w1kTgunh0Wh+sFwvFTPXjXUG8DxBGgecAekmviNwJSNTpaa3Xfw+9
Ib44wgagwX8NTGmKvfN34VjKVsu5JDjiB4eIYW4TQ0m5rXXXoIYSGP86ykjv
v3Ds378jm2e9ZAOsosz/ieTKJiVXllCsbqB4Kg1BrE2Z8h6KI//F9X/FM102
8wEM4WHog50Y7jrIjkL+Exvr4yxjMph5znjILNrUlDwrbL6tKSMBSTnQlFqg
Kf2jEnkNMTh+wTq8tSI/OqIccYpa7M0DwNCtvE702GxdjiknOo0rrJjjDcqC
Vo54nck6d2kn5hTn5wmiWOYWlPiHWkIsGJaxOTBJgzfojTQsIcMIG/JQVv3B
gZdbtlXHgRaPtkZtfcwzMx3f8kiaBfppsyUB7yZCs1mbtIef36tkoIE/Xrnw
iWhp6X4u1pxpJhbxHHo1DZXND/aUOsTDqaTKQlwRRHG7CKIqfCoKsUA3CiTK
kV3QXN/RlXAhYqgveDvCa1Izs8C70LGceoXJUqpOzA1rwI3KY2LpkYr5UXgF
C2UU0k8pbu1TYqaDfWjCYxIThsJOnej55cFBzQ6nTcUm1hL+sR1GYLs4mLnr
tQFas/ImubZqey0WqjEDthRDpdjft/r68y75x2e27V28Fx5FPJMV9u9qMk44
fWuA7uCgMxJWpsubwfDkxRH5mVxWx1ZTbSTRzSiyLGB7etcW0I8SbJML2AVP
MpUnTJ56/Ym2C2e36mZVniEGj72KxZoXnEh3eQ00cNwWS/YTsQ51MA5Fj6PN
to6O/HAI1pZZ67jH0RFGPvY1L+Mc+C/drODznxI8R2qGaUhk8WOz/9MvWx0k
4m9QWDN6kuOp4++5Y/8K09HVMQk7YIn4CBhvogdzBIWHMw+CUl7MDggQPoDJ
pTIfOW1aUyF5zPc4ytG8J4KHlD+t+EnRPFSLfzI2N+eQB9XuHyK9dxS1YyIf
iit/h0lEtZp/55bQC7c1sg9qu7VRkOUb6YLEA1ux8vIIc2KPNrQVYvpxBiXJ
8k7rjSq8JtgrfYiXXuzqYvHXjxwcHR0FR0dI5JHDglDkFgr7yppDaOB8PpEK
FTHJecYMkQJbh57NLHnVvLuabnwyLXWMpgvqCjSg0YQSMwUeYKRiCpun/gMt
xUzp8ABbr9YwtYk6oj20qLxYldUZNkmcmRimUAQTE5k9nYWtF7imGoLeSyIx
/IJ7iex4vpqbMooAr9sDhN7ce5fH1lcUFM5TijWzkCjyKAUAKHhoWhZsHQlF
wCH/jEKX/JAwyKHHpbJHqxRRh9rKRQlj+8n3eGvdKuhstrOfBRbWBHemeOUg
eJuf4xWMYN2V16rBb6M38RsjovvCo9Lx/eZoIiHXBpaE416jtFoOyILlM3kr
Q8+X82vv+aSPjhSVFxkAF/tlTrxPANg4ewrpfdrx4Y6O7vY0IcVBVMdm2ijc
AhBrLZhlBLtko+nte7uTxkTFRxZ8eMnVaC9HenF3f9R4xED6+f0+KK/exuYI
jfZGUf+nr+Pl6ushzx0CJzP665A5C7SQ5HXfDd4cBbsptAPx5/eJwTykT18n
ji37EKk0bZ2ohA1ug690nNCY2Qf5lFBbd53ZgCbFQgt1q8GG0NLBwTXf6tjb
wCs8jK8VQJheo2Hyg4Jmvtd8QaiZbx1zJzU+TAu34OE6ph9sS+EP7BXjn81Q
kMFrUiJh5lW/57evt/ySDGRmXs+2PzqSoqYWYQRgNs3QJS0SLmqPL1vPW9RW
9hBXKOarUCO69Tr2PcqfI+VbuUNcmY/BCK9fFEr+cNea5BOtSRdF7y3vAoyq
sRZuvbKra6bX6Dea8rqjC2psA6MtBb7R6ELcbKM3YdrMDvop8QS/rI8fvo/J
b0GXmHXLwl3f5cLfdXjTjJjmTV6Dpvc6EFFTpnWd37q9RqjkiY6Srn1pFPu/
39edhISfs8e548JxKfowf1w8xkDM9fasMaDyWRTjR4gM5r3t/0fwb2z+kBU+
x7EqSTn44r/+z//VA/Zf/8f/Ev0PhJJ7B8pUnmxA4f8VhZJ/F8pXYQ8U7z8i
aeh4/M95n5JAN/ZSOZUlfvcKo4of3VgkPYOeLdQhxYtfBRstvs1mqLnm+lu/
Vffuo8O4Dpw/rPtm+vCHQtfMccpZOh/v8fnD+nuGJ/oDoEcmuruL6A/rIBqe
2g+AHplabJ/SH9ajNDzDHwA9MsP3OqH+sC6o4Un+AOiRSb7ba/VHdddM/9De
ndFJfqiH5w9rzxme6Q+AHplpJRW2ImBYv8v79xvXh8in9QPhhya24/gopOt/
prh3EHqCxT3litgmjb3vR35rcLN/6gdGwIR8wFi3RrZiTCyT7MPjoHb9C/nH
YjQAtJxJoVMLdLqwdm3KrHUBhWLK6X2fpg+PvTt8o5ZryNyN3NVgu2PwER3P
7QcnHx3RyWpoqX7HRXS9PsnRTRBrBPudZHb+fPjRZn7eQdcu15+3j1GUmJtN
3kMybKNjV1Zjtfbwh8xgIzV6YP3PXtQUcph3A0H0hOnoaH1tgudVYEwdV3Nr
GcOMQW+8Ny2/tav3EXLP5mHlcEXxlFCM0jtT511g1le3RHo7bER9vwNPbN2Y
QS50JABJRKRzKYpzUscVhRPiIwiImUIEh3fR9eJPPHLnLxL8YVpMD3IVopFb
CumlPih+LmrnTS5+eqqOhVY4JZg5Nk2WYTh6czfJhS8aLLhoSR/mSnwkeh+l
Dz+KIroghOH74fbt+xu3A8h4zi4ZU4qtco7yqzFoWdd1Gu/H5pGXd9zofcQz
a48IeOjE08YeTStBwR6pluna/u1OgCayf5Dveoydj/EGh3WKykQdT6hqFDMF
lFAu7bek8AifeFvRjXzXP/445D02Qp0fj47WvR9BJGD3R0rroWwT6v+IHZhb
6txrCIp48gtAZC8RJEhj2kT1GM+iQVlQ+1zlwIuWs1BGB89whx2JgXfvLqE4
gdy96/UPXGvME2bwiDhe7Hrto99jQqqszdE/+Zm2/+O67Vq05Sa/4QjzYT55
ded+QkaoIyaeEGCFudfgJmZaKHFV76Ye3oSKtiDeMuULBEu1px6yHUEae91h
GUYlqMGVO0NpbIdj0OEWxLWN0fwO7MGtZ9KQFJ3BYZPPtb4bzeu+hJ17SIEF
X3ldobyYGHt1SdjT6dwYm6QbfjK319kFkF3RuR5wHGzNyDtc3Ho3HWISduim
oBBW/pU0x96m9m+CAXbyrnKxfSkvaTz5JuhnjIdRhsIbfjGv6cxxME6QJ8HR
oeQh7KMmr5sQDWndLBUowRRu3ftf60zCsxEQOhw6Vt/yCjUqHQ4Chl6LAJ/D
Iocg8DKdtsie4vWbzlHvburBxbsK4G/M35B+6NU/Jth5j7gfjA0o4LcF81sr
pYRecCIVPVnfbPw1xKMGXq8tcQlGjYp4EzVvRUmygCjiyycRZ647WIWuN6eM
QCPg6YBaPDOKjfx2X15zPgpE9wO+5KUg3A7vm6aGoX/srrTV4z+wO4LNEbk7
DvMFuAGyVnQqY9Qq38KaZMZ8PUeNmdPVCqiaYv7QvxVgQ22um3Lzu3KifeD9
vJnQ6RwgzY8dv4zUJcp8765m6uzu/+F3qI4PL38ojWTnZbshLwk7hUhpwOWQ
H+CZFDOHZcO+atRcgbfJRkpbDk+BBJxQKI6ARrR9o22134mJ+9sAYaeIPpZn
7LDgtHEROtfBmxSQGYFwyLDYvX3idQbjbcODs1ECS+yDuzZUhL6+8Q221roZ
4b/eCnikxjN8rGqKbqy1TPA6aW5jSysYaeZ5HMiD0G0WVBaybUwd4k0I/KSM
87THBcEGkgMVgEKN7tHit2DyJIJop7fI8uBCAwDdvx9BnpiqzLwrJ9C10sAy
CUm7QI7vmCMu2jE3TgJzJMqBC8KTJ156CuLda7suTbze1reb/e4F/3IcsnuP
kvnF5YsB5ux175zngawN1tTB6RZvfD44+J9JWwfLgtZ5NpU/jmzAAEaoaqqh
goRnYptpmg6siXzl3+M4wnYTqPaYhsodnmuaOsN2cCCP54xuCVxbUsDxXvdR
rzkh1mYx6h2JSKBf6xoR/5bHh7GIMrhhbkMkW5ul4/zoZZ2LTty1g0govR94
G0XHYyJQgYbKzXpO3x2fedc/bkmx4EhUC1p3+ifceGOMyg3JQBgKikl7yw9g
qOt7YAGfgEWjF4gEq8Svh+P9G23vGHzdfJSoYKCPBAT3swuiP6OPMvO8TkDL
Y4UUFkfJGl0azDvBKL4F6V+/Bw7K2LWCnnqg/tZH+QehU/3YLGaLBRf5OcF9
BxufhloU87O4ylbvYkHntphNvA02AtNnE8lW38J5SKE9TDmzkTshqM8oWJtj
fk5LwtPl8gxvxsCFsiPo0r2DfN5rcyVaGnhLyUcH65+jaT9e39nIpYk8BLGT
WCk8n8aX6YIeL00jVJ2C3zZ7V7edeo9Kagm3nzcrKQ+C08z4zo6hawq3b4qm
jRR00+I0xHwSmQVXFm5emMSR6Qa3Lfl4vNdhMhaPtRXmnXoH4P0MZ2+/HNT2
3NO5l95776u84PdV8oQJ8AIloY5iEIzbIFcFbz8PCk/RAqTXAMsRN8klr8Qc
u8yMmR+08LX0nrxtNDUxezlq2JBe4CEKS3/Ht05RIjXKkVs2VjFBJlr6RA4A
/4Fn9fuFavxy+3I6U0iH4xJiEJewReqRJgb+qKja4tAyp8wgAx1UmKhLKxHE
nMiWMEK6mCuVMsXSIWD06UyaSQas86Hw5UQDTmpLziVQsG9OV6HOH0P8CfYy
Ejfl4G9pL2/VTmez1Wq2SMB8mmuSMXYx7QmgtimYZZhhtTwJntFcI1nXC8kW
sa808pTomOKQ0Sw0vMuPTxQEIV6iuRJVB6ZqYKyWVDlIsYmpwNdgs4nwf4jS
F0zaweMARY4UIngP7BQmVzFekDD2nyZEKK0q2VK1UsyWS4X8r+ov2UwmUy6X
Srl8rkJE/hLu0RTkXiGZQ02amN/y2uL9mcIoRNMqvVI7z4RMH3qMdcmWTosZ
KPB4H7UQh6HSgZ/RB2TYhJN+plnPXM1m6SDWNNKkhbi2WkXVEHdzXSSUF3hi
hEsDdvDKn+YtVd+EA5zwo8/cXmkO4rEu1YxOT4wQgvQGR3KiOrA22DYAllCk
rHpRUjk1enXsyqgp0S1mywt8SMMNLZWN9m4oi0KSO6dIWwlFhjhCLiRVxMlG
I2eywo0rGY6rhzePObZT1CMAbSpc3pQ7TWeyoveq2DFkXKK15BBRcYoYohKn
jM1EnKvXKxrmvNqzJjanjHeHFHEpxpNFmxZTHRsOfUlXAZANTJv21gW5KBmH
WD3vseaFNNwgnfcLyO2U5aZRDKSL5UKxUEzNJjMC02LA4QiFpgtCJQrBf0pl
nbEspTLLhT/4UoMbA6KCI1rH7rEkqXqqEYqZYy2YIbMU+JhSSjbSyOIkNsVM
WQSxyRUWsLI6suWlU60WgbOyKYWX++KqIZUKQ/UtGofHJ1w+YWIxFrCDVSyO
wO+SRFiLGcoAkK54ZbIkgpm6Z1U2iNzp98L3aFKRugP0Deiq2rbGFBNruDRV
NCR7Av+a0gadMHvqrlzRXUlvc1XHuOw8skE26GTrb4oeFnq2k6JnfOunpUrO
1KrVzCZ9MTU9LJwQSf6MPiQ0OVXThTQIumwmlwuoGYKjjpgxDsV8UvSAl/Wk
K+7daJW57uqvTb4I7ngsGa4tbYzrP+Y4wxT2sQ+KA1Nj4kx15AkqQa4ucBtQ
cjJpQPxL1kwXyLUwxRV4wDZGsjwVgp7tSI2is78J1gzfgTfSwbt0QBNyInfK
Mn4Ei2PYM1N1wi0CbLo80uVk9q6SxOrqaq5YzdYyReDok7pYzGSL4kkt3xBP
svlC+SRfbJQqBYKoSfOlEF08WjZ8npq4PiunN6QqP4fGc07QciBHRazoFTG5
f78G4DMwJ+6GqIAnfNeks5lCsVIqVvOFQTaXy2QKmSw3Oq7RFaDdQMgpqhNp
2RE8S6kWZ7Z9SiCq+UGkVkelXC4r5kqyJJZz1bxYZawqFovF8jAvZ4aVUWVj
O16o3Wvh/vpyPbwGjux8xi0Tf09GDQJf6Xi9CTkquMyeMAENl1LYfEPp4SPi
Xzs97ZSuzcu36yV9AEoBiBuiIv2doiiLpKZAmBEO/ioB7UQMBUU1I+Jgc7VB
1dh79bZnLKJfTaO3sBiBhRZRGabGWOLP3LSNdRB02/Kvry6zVr9E+Zm+R9sk
pYW+j7aZkVVL1uB3epyORr9+DuATJBlwsjQwgsOmYughrUiukKmUN7NQIpoa
j21EjF6uu3dg4YiBFrJkgPkG71rBb9xINF5AtAem2UY/CfqRmjtgY8otqovB
RUCH4dK4kNj1npBdRzC8M4UI2mBZomxCqN7hAbdl6pIbjWnJ/AFQgwMDZOY+
BWiBJ8yHsNZwIxBJBpAypDW9J6SQFRXzT9Kl8oYAl23FiBoyKXxE3yyYulSN
QSGXL5ey1VwamxCMTWs1yOYz1RLYv+vRTVDNDi12iCyhh36Dll38yhmbSyaP
eemwjjDtu9ZUtSeAqX81A9ggakiDRB7TMBNpiL1esNxYBeER3UV7cFBlkIJv
0kodiVNJU1emxddGmg7DVjb9yb23kMWlGiGlA1oJeJDunAhWWFLAW5GFbZXL
fxC5PGTpBVgG4P2CeTcCHUjgwGZGj4uBOyoxIAxMAyUAHRvQ36BwxxbAkeii
GmrcI44Z+AHpUrVUzRbKRb4BOl1Xc1RwhcI15rr3jCs7T9gxA7adHFSV00Va
4Ojxa1h9A/J2LavWnjid21LoMDh1Xb+2zt2JlCgec/d8HX/0Q4p0nTF3qrtg
GEkYJZSmUfqh/oIhjcBysNM6f3cmTQf7bGg8yt9yqTHiPkdRUi6Uq4VssZgv
V/Il4PxMqSC+irUCX8pbU7HUsSmcWEAj811sLGtILw7AtuIiyz+645KcggLI
M4YpInlAMVPtEmFRrORAq+ZLpRKgU8yJj5lakWNxgmdy1xa4fJvtkHbgMISX
QZPRy2KhUMwWsrmByXkW+zA4ZB/tM7nW2BSq5WwlVy2A61soZMTFSM37rqlp
wZKB5wtEHbEYhMBgsumdNE+BC6ieBps7zVmMuxmrv9jCSa9zcLD+85QpxGVX
eAzKCyt3ut2fTjCqZEu6I4z+/p+W0EOz2powzBgxsK4u/JnNw15T3o5tg/mE
umSByyG0Vc3Bu5OAJnTpq20LYNhNmY0pGDw0CLgew1ea8q8WAvrM80/q9Wiq
mVdg6bWICRp88wwJUBYgbjQhJOS8RBD8R+SCIIyAU8Qao+OwLKFt7ica+P3A
D3i/c2p4zRw5dcyDhZi0QD1sgjYJw5VQr3sDAt6Ua0NBut096vhh3GZbHO+Y
gHn3C6xrPrDXS53iizxywU+/ETTP6Ake7w2bBhcszxjYGTzE4d2enSh6TLlb
6c5t/zSQoJESVy/+GrzlJdWFeNRr8EPFKsPVRjdBvyg2qHn1XuTheUTa/wVN
sBQvs/VjvmE8aNjdsL2AaggHLzfJA61aAt4QET6r9y/k4x4blzxItB3HS7si
3RE0/eJLfojCDymQgeiWq09HR3SRGxpiR0fR9/HsyktpiwmQH/LmGB9rs475
iemT8mm28TKwXuxKJ3M+zq/qs/ytNMs8smb6o/3a3wV0mBApqXlfVe5OTad2
89Y2lGku/3oiL076eclOhlQcoKRI5dvzTDNrjx7t+erE0Uq18VPlRey12+oi
GVJxgJIiVbw4K6lVe27qxmS2um4/XLOXbnnU1R9vkiEVBygpUveDp9fW3VN+
1FxIp4vFalSrNuzJrM2cTDKk4gAlRersdCAv9Ha7ObTOBg/F+9KqyZyHB0NV
C8mQigOUFKnrQf2pv5LHmfNWWR6eS+5pTZzejx9zL2YypOIAJUXq+ezl7HH2
tHguGvV7/W3wUDg9Lz2qp82nhJSKA5QUqYJt5i+W7aurx3YvuzDmE9dkDw9j
Vm9PkyEVBygpUjelM10uVuYZOas17vPuS+cpU3scmKNWLRlScYCSImUUuqx4
c12fLyZLuXlmKA/segUeqWwm5Kk4QEmRGrLbt8vL+aKrjqa3o7Pr0ZLJLbM9
6zcSSvQ4QAmQkkfw113xqa1Us9rTi/pa7zvVk+fVfePylN3Nuh9G6l1AiXXf
ad0snHRvG727lTG/rNZuziTn+sV4lMYJdV8MoKRILYaDJ7vafVaqbtXs5k6m
YsWZl0fzx1ZCpOIAJUXKnFdGYll+Pj8v3j6LXf1FLnUm970T8TShSIgDlBSp
nHvnSo1sYzV+uWx0C63+QLSehou+epYQqThASZGaneSr0vAye2O1C4Navzto
livz5XXfXSZEKg5QYt23PK8vu20m9mrqbdWdXF1pmnVe0O9qCdVMHKCkSPWz
S3d2d7J4fWqe9Nr1/uO41358dpTXt0oypOIAJUVqcrsolE4XY/1eUauj12c9
N3o5H2rGoJNQzcQBSorUXau8ag6mmn7bW16ucu3H0ujNPTWNxsvHhee7gBLv
vsmMdTSFnY6aJbP6Wrqo3k+dTKZWP09IqThASZEayzn1JTMfmmzSG4jzbEbs
XdraUnquJzSH4wAlFp5XBb02ei22z55nTqNxafUMpfzWUB6zCRk9DlBSpB7d
M3mwap5d17sd90me56665ceGOb6t3yVDKg5QYnvqvq0Zw9NOcyLK1zes6zbu
r16Xxaf5Q0IXKw5QUqSW93f5evn17soYy+qsfFJ4vip2z+761ceECjkOUFKk
suO6fL0Qy5fmrHH79nbyVssrp52xmb9NaOTFAUqKlFORzOHbSb5c0B7Uizfr
3rq6fSpPW0+rhMsXBygpUnr+bnVSery4eVtKrsxemgOzcm0Usm6vkwypOECJ
5dRr+1UeDs/n0sBsNcWXZuPZzRXy45GYUCHHAUrsYjUqNyfZh/sL0TEvzXnr
Jteflhq6zpoJ1UwcoKRIzR8vczN19FxsPcr17PJi0Rtd1I07+fQuYdAsDlBS
pLqt00fVGFaKjz3pYvr6ctKc6CfP9fK1nJCn4gAlRerFrt53CtcnldWTPhnn
robS80lWyuVGFwl5Kg5QUqQyt29Xt2+Pg3tFeyre3Qy6D119+awZ1ktCORUH
KClSD/luO3sCztpQzz7cXS9bN+pE6sjZt35CGz0OUGJ7aiC1Vpp+2jYv9NfL
8smJ/HRvtkXrMrE3EwMoKVLl3lPPPankz3Wr+lofZu+zp9WCUX3I5xNaCXGA
EvNU72E0zj1dNmtXztlN+dkeZZda4UqsXSWMusQBSqyQ9dHlQhwuKue2cjbU
CrZ0Ua2evhVUJidUyDGAEkeHV+qoVXm7LkoL0xoOetnL2+pp8675+JA0OhwD
KClS9afFvFsuvpWsfkfJ1fLPz/PnM729vFIT2lNxgBIg5Y50+DNXXZ4+Pxbr
BbPXms6ea/PH/qD8dPGQu//4+r0PKSmt3Gx7+fRQlc9G9zM1Xx9VXzMlNlnM
nloJtV8coKRI9VqDWiaTLUniedd4rE1bTvduaU6f9ZeErB4HKPGR0aIsXj3k
6rV7KyPenLxVy6zWXZ4MjG5ClRwHKLHjbqyGsjSa3+QaYmdyN+rf53KVh5vT
y0lCHzkOUFKkLP3+kp0OX6RlrqTls0ZxpjrtzvLqZppQ0cQBSopUYzw5U1r5
lT28Pj3v3rCK/PYmOnKn+5pQUsUBSkyp5wtJVpXcwmg60tmiN1Q7nZGT72dO
E/JUHKCkSA2mzZOrxqXdf3gZS8qwuDS0l0pJmU/khBZVHKCkSL1e5x/rma5k
nZ7W8r3u8GT28HDmLGv1y4SMHgcoKVLT6cvNRC2s5mcDtbZ4sq4XWdk6nYi6
mJCn4gAl9mdOpsq5c/7Wdwqn1ez9zBqddwxlrPdzCY2XOEBJkWq77qB26maz
J31LWZ7nO5WJvsi9vMwqCR33OEDJw2aGai6nJ4PBzXNnPjk1iob0UHrpPL4l
tBPiACVFSn2w6/WaVnl6FmdX/VrZVi/vWvZIU9sJKRUHKClSYrt1fXdbrM/d
+wf5qjbOl+XecmHW+npCRo8DlBSpC+PiqVketm6u9Pry/vG1ZDvqlXO+kLMJ
5VQcoMQ8NRh2ziZXyknhJTvOGPLb8vp5cfro1M2kodgYQInPHFaF1/ubs5vW
bSUnDu3pzeCu1SmpTMs+JTxziAGU2J46y9uDp1NjVO3cVMr9eU7OvhZG+dLy
PCGjxwFKnFjycN59eso+tbLNnNobtFc3BauhX9mNVsK8oDhAia2E86zR6LFF
bXh/MViwq1m1MjWenuVxKSGjxwFKHOJ4cd8yo85LxXl5MuU7XX1+fpR7i8Vp
OyGl4gAldhye1PvC+fOllctYrHQzbemrh15+du2whFZCHKDEKThP46WeVYdO
aVZQLsrL0+zTpaJlHnuzhN5MHKCkSJUuzsdXs1zu6XbZ6j8NRVU8Ward1lv3
IWEsLw5QYpFgtuXza+fxYnRy91R/Ni+zhnFVYtlTMSGjxwFKnMPRWw3bVXVi
XL5clnsvymTyNHh0lpOuk3D54gAlRUoZtCpW+aLbeqkViifXbPm8sEe6XnPO
Ekr0OECJYwnim1QpDZ7OMvZscfJ4sujf37wt1Ku6lTCWFwcocWZCodNV5vVl
Res1z626etZ5Gc5O6rdWIaGRFwcosT1Vu6quTs/MkXafXTQWC3lSKCr661Rf
JbTR4wAlttEzF6/t0Ylk3+haqfokVp+1gfEyspuVhLsvDlBikTC5amlPK3mw
Mhx93s+AklhqiraQlgmPjOIAJbYShouLqqxopZF6nZmftMa13t1dQ5euVwmN
vDhAibNdHLZoD7ut85Obq/NGzn61xn3LmNWvpgljCXGAEsen7M5LySwvRoXJ
48CtXxSz/Xp/Li5OlwlFQhygxBK9JFcapeuTxi3LLAuN2utjN+8UmtdyIalE
jwGUOK3LOinmy2cTJzdtXtzXe1b/duqAhCknTdSNA5QUqdtr4/xpdFdvDLq3
i/zEqGUyb+NSpbBqJdx9cYAS53B024OMfXFxV+yyqdk03h7Oz4zOmS71EoYX
4wAlRap1Vq/ls/q4xiba+PT61h2s2rVsRju/Trj74gAlRao6EnPZs+55yc5e
K7I5LOnXZqZkXS70hC5WHKCkSFVeXwet036+mu00h63n55s756l7dflYvUsY
S4gDdOi1pMI2gTcuVi7Tjbcd6rhoOcfCCABT62Lh1f85dJutJak2LwXbvPgP
PqBmPRZda45N+7B7GFXqPGAzst2d2r0m7Z94Xbnw77G9873mvnay7u3eV78e
YKNwLCTDppmq4VKzx3CrTtuvuKNOddjkg5quYp857NFe79VEdnJ9+scf8Ee3
079tivUAUrjDIfahxKadKnacDl2Dtdmh/+iIZr3vBmDhxQXyj1Sm/CrcBXhQ
EzKsWnVUfbvZ8nDdUAtrvkzq7h96x8IOToKqU28uh2FdL93KCRMxGO/H24R3
qTM0FQT2YZTPdB/Ul6C39kYPlTAPAu+kVcXrme5dXwEcKfLlnePVvrBomQJV
qGPXMKrAL4m5w5TPJ16NoH8NAXahpGkA/6hjg7qA25x+1o7+5X4D880O5p+o
vhlgY0t6Q1751PJafTDl8Fe6Y0DxOuIfHfGOJLxMkI+3Hp8a0tFlobgI2JXQ
1anikfcT3YSNvXixid8PJWIhlUsViIxt4L2gEzF2mKRF98oSaRMCzkAag2nB
TRCqMTe1uX8ZxNadlr8S9n/7G/bmvK3x9vE4DF0MKglEK2qAHWmELYwZ79yG
bST4ffLCdafT4KWG9XbnegB//MolUstVFewmJPTZ0kGpEdxqhs3RkZ4x80gJ
pyAW8QH8rJh4Z7hf+6gaB9Gmh9utYI933cp6vH0JK86auimrsGUIK175Sf2l
ceTQPP3+B165LX7iV44e+Dc1xmItbGK953r2baRkGJbfv8rvSg81005Gp8j0
cztIkufDn/DrUvng3l22EQayPzDTg41xt26mPt76Ba963n7KzPnux/qux5Yj
73ksKtK+XxzZxZljrXCo4QLeBoz93XCZ1yXEB1QYG2q44DHNDPQStldU8KJ7
qi63dL/wd6sGd3fR7Xt9foUuFlqroWL8BTYJHvrNik3eqhyrgWcW9mrCviBp
umGZl+7ySunozaV1rwerd8H1AV6X6bej9vuIk3yktqmINeo5X/fv13yfpKkk
0D0ihxvtG0/wckrqQ2+HuraD0DEULBRe1xdHe84P11194TeNugNwocE7t4Oc
4yXyPqCg0Jnu84xp6m2bmssbwApgN3EryAWjDFvjmtjKd2J6zS01E3sX8gZ7
W1eEUnE0WhmaOmV07cPGpaCIJs7UxKuuPSAw0fXtG167dWxMy20dJtnYSHfI
hKD8fbiK3sASdNFMgYQFiw6kLQMqzSPdQajSHltew2LFTwLegRHk1RB4xv8e
WRmFHfae8Nr8Akshpn7Fud9k+3jdc5baE/gj4xVHeOsBtgowaHpo+9ANwe7Q
0XY2WhWasPgydSCIcijo9U9qiqV452IwUqktAm0qCe969QrOuQoMsZG/Z4/h
iVevTldF4HyoQQcv9u9613WBkQaqWujRdV3HYGFbqqTDFgTxJY2kY6HvmjpY
ITXXgj/uVdz7tibNhYY7ZKupeSycYZck/IwJZ5IM1jdY4z3TGA9N4cQ9FuoT
ZoyXgFzbldDWaEvmApt7mPjHubSShKYlq8AzOLZtY29vVTKwJYo6nqD458Tu
YAvrnjyxTHl6SDzIPLqFZZSkcmH0bgfWGfzKGz9QL1bqZR0wnWcB+a1/v1GK
+dcWBfdYYPt11eZ8ua9xrNf+YObdsxBzNUvQ8sYTheGv+CgoM4AMqOU9LvR8
Chrd71C+1Y3Xb+lAfpT/LqKGM7Skmap4d3CkiEe9OdINrAr1rw42eGjHrDtY
+He3pIQ+SEfVgBV7C0ju368EAl+hBucEnXai39EnGGqnxvHhUA+KNX4IARS6
hfdhKSRDLYatiSVHWl+JTo9sMlDWq8e/9IbEt/DOS7xkOOhyjlNzdexo7j+m
Ni4wOt0g65uDeOEtNv5a38d2v3v5a+tOEvdrqdpA5WAf9E3PzbADfzV0v0/o
QiNcQ2qHDPxINtSanEgGEgFeI7I4Xgy1tQiJeNJUmxeA7boe6viDt24dx94S
BoLZRodYnXPnD+20oFszo4Y2/g0KBnlKFjaSCTgGWQ98I1xDByhAN8NjI0d8
6MOhNbTfEZn1el0I39zT67S4bPKtppQQuokYyfcJO/2z5URCnxgv9lNp3Q7p
GiaLXznDLylaP/CuKyPqc7fKf8f/E96gniTEpaRT0X8hxTvdXLX379Qi+viX
cK3lCbdGQpJ05Fpkd3hbbMOC4Rhi6zHPxEQb059S0Gw7NO0/8CZlVOVOuo3W
xO/gDhguXgbcgBX8ZOOFk8HmwdsuRdDZe/8Jv3+5UA13CSvg6qjVwz140EEK
NWycySm8wAKMRvpXOpeh6y2vLWnswtapv2HPYwmeFMWycCWDPkMA8LetYRzn
WEC0TD5oq1ZotYVsAS8r0JiBbfG7nCejrvJYKown5CvzMfELcca/oNF78Ik0
Q1vqdyFXAcN15oi590YPNwEKdQUFhrVTY9Mce73YFDUF+g/knJRNqU6a2aal
yja1icKhb8HUPxY6Dohq+CtbELN8/I2RaUi6IO621u+BDQkbTdX9LYgLqFqO
C5sJYewCEEYd23xLwKWG8Jvw5bZz1Rd6rg47bXMq9BBkgumIJu+IGKDdgsXF
m/OOhVNL4vdI82EZMkAw9hfHnOFVQyvDnIEmCvUNNZFMqgEGT2pkpXOzmTm2
cqN+79y1b81x/vZxeH3zK1p2PxOIdX9IX6uh5on0A5TCbTaZMjFlflPr95th
Ttw5R7+///tweQ/IGfb8tOw9l7YeHgtf+JJFmdg3tbCxFvV0DPWkShey+Wql
ks+UBr7TNah5dBqYo4EXPVAG/YveAOi0ftBstK/qhxG+bqBiDny3B7x4o4e3
XOnCp0bvoXe4b29h7HZg05tp3sra74mG3hm/LqalmUNgUnAAVaIpir8W0FmH
LUGStw12AGznT7S19w51GGH4XAH09ni9Ht9CvWKpWiwXB228NKfnXZoz2DAS
BqoxOCXfadDqnA4aDKN7A5hClL677iTd1Lq4yETyNZaunckt2DD1Zpp6ysUW
snKaIiLpu5qRr2QVpkqi1L3UX1rtSfd1acpyti2vTstT+0KTGDtno+VVYdir
5/T29dvi+ub6qcVyivF8m3obaeyprusOyCZzcNnj+yLSgq3WEa65RdXDcIQn
RlE+kNDJhndNJProSaB01ts29yozDPBWaqB1LRLkuaxw5uLNKv76oCH20cMJ
AItkA2OK2WlTGSuDpT55uXlUbwfSxZPy6tzPG2fstPCt2yZTLRZy2erAv8l5
cNsahAkzCHrT8YUe04Uwg1qH05DuM/4hRNqcy87LRsNwMYQIsDQ7zT8V4SHn
Pr+D7fq+GJSddE+umMmkZspoBzuuTNdxU0OWPh0W22+TrD7LNn91filkK1VP
rPpzJnWCd1vBf8xmK6ENhnGIDupUXSPMjAjOE18R0X8hjD3UyYSpg+RZqzCY
1QsLC9+PjfjzRrtvuhq0XBQ33ErsHofUQdz+kUlt7reArX7cttui2Tfvu/vq
yfnz2aDRmj5fK5rxciLdsZXmToavN/+kfdc2ndvT+nehU7a6Safvs/UmpmON
ZOruLInZ4t6rOcBq8Zp0Ru5+yGRiN2Wj/XCrvizPbRM2ZT5XKe7alMSF7xAm
4FY7TVgHzPtRav3ZO/E7rY4/Oi2Qsmuwjbtb3lmR1u3rymp0muPmAlYkmy9k
Dj2b/br1L82nKpuNPS7N7CR6MjqMK68DN1udP75NUV0UMgWPM9GQtCfmLEqA
cJ9s25DkiSMqIDqwp77C0sBRYwtsZO8CC8mwVXhjX/fxbLGI+wCI3eAghB7e
sQpm5iV2Lt+w/d8fnfFN4AMDkVqCJcBbJ4Ml2FALP2ZCRL4r18GbZaNzMOmh
qCgIewPXYhjXLVQjX9LGnTrYyhlva/BO1bAZelzvfpDLUaEmcSEtSmD18qPG
tIf8HtW30yfj0QFsNu0uR3R7FMU7kZf3NbYmMDBW6ALq4Uo4g2UATwPjEeTj
Swb35PDCpGPhrldDKuVF8B6ihMKj8s12z+9os2ylCC5EZdDDeB+4ceob/bLp
eu2mRhBVrgeh8q0oRnjmcvCF5wsBw9exw7xwKVGga03g04B+0enIhjzCSxKi
flQ+I9RmlqrFiJgP0aJQLVRzg1vkJZw+8hK6ThuNeQe1WHdo2w3KO5PniX2r
iifPZxdi6/XFWLTeJmXVGGqOe97RZvcvr13tYVZ6uFW6/edS6bkyEytPL5LE
rkbDyWOqbrZLTyfuVDp3pcx46uBRBs8PUHXERJ8JmcznXPlzJkMLBU4e3tSI
Oo3ulqXbI3/zw05EKj8LZods2Qw6Sfg+bhh8XwzCDF28jhec3mOhLhmSIgmf
5nxB8MdsObIi37YguWy+VMpmBn08FUdLy3t90DRgKNPAUOKgf9scXM2YMei5
4CTGCfhzq2ouZ9mRYmRQ0WUqeXybX9G4jwLBZdGStUUF0dNQIgfhi4xL2J+9
lQ6bUcUAv4Emn9DHUJDtH1T40t0chTrGw2s9E3baRqDHtMW5SbjQ3V5psM7g
2cYGyJY2yb0jtLMHEi0oD+HsslJCn3HZmB6peEsVv/qqQP/OFLKlAcf/33KZ
f8tVsv+Wq+5xzz6CBifkdbMv1q8uea/y7GchW8RwKb8gQmj6F0R4V3PiuRPy
tHdj+3q8EbiPzEmNVdQXGLY3YMPAvkPLoojR1N03ThBAfo+ZwRPyfhfOJUuz
LXcCIte7EYBIL34XZkfpU8zkKE4DXsS+IBhS9NvkfK6cr7wHnUJsm7oAJCAw
7QDtQG9lWv3uKQ8ffxZqhoE86DuA3rHnQ0v4iY8Fv9C1Scj7PrP/tMZ97Ogj
iimnbL4pbNQYxB6eyfEr3vP4C6MVuHDfxB4eZ8I/3TlzrXCMsyAC8buS9Y9q
gWK+nC0m0wLcTT69DRvMxXcN5iIP4U+Y8Qb/h4feeNFDRIxW35nQO5ZzcZfl
DB7dyPKvvvNNpnjbuDM6Hw+vyoULpwCis5QpFnZGkT425U808rtTL/+QqVNc
aTskHz/9yWMZLMTm9LKMLlKpXPJmj5EPfSvy8V0W/h/n5Ey+UC7ky/n9kQo/
JnFRO2/+2fh/2+ppaMp717HtPE6h05N3VvPsbXQxGxoTLVPDEEQ2W94Tmvku
hCj+EEJEYjQeQYK0hnUGGv9rvycUT6gr58osX5pj1Ua2zxezvkfs0+fbYjXF
jVhNLPkK4hYFvy1uUwzFbb63t/gN0Z1967oR3UmEafxqlnK1YuW1na12O7Ca
uVw543t12wkKIf28vogS3hOjSi9sgWaEUzaM4fMQoN3Hhx5436q28cxxiMFe
I0QqP/+M0s949hnX1J6iboEjQBZpLsvPB/66RRBkUCLKkB9zLyRHnvw6/0VV
XhfDzORUm9j/DTMufrm+0EfTuzM5X3W7k2f7sqXPluJrQ3Tr5s2qO9Y6s/+G
bkQpa4e3xa5T7g9yhcq/4s6FJTmglrJp/5o+/DtK8uo7FE8+1hZL7nrLEzrE
mWvr4b3DmPHd7VMpq9yr1xRlBNV0KMSFWEIGvGkrTF8fRduYR+xqLE1z2xNa
AcGisDkIRB1PcL+cXvUaze6Ga7UJGKl7Aq6mzTT7WDhh2hgduN+FfFY4kwwx
u0HubQ9rL6bcj261W6cn3UBXOUDmXYJjE4qXdEKkpjoVexckDiWdK4HOz3Gn
LJfJDkoZt8oyxp7VoT9TmwO6SimXLe4YJCXNs6kFG+rfU3Dkykjdf7rg4EYS
GEVEumyuvEd6BAx9nSk4F2dybznq/vpxcVHIF76r1M3/SxDPI1o2/x7R5J5V
f75cmeXBOAHRKFTzPalWEhpMJqoV36PaBqB0Yjqd8DNsssL5GTZSq5jNZUvv
UWsx6FovXdZeXVcSUKtY/a7Eyn2cVt+ZwyiqF5RtelTL5N6jWrYktZ5F81lV
kvBYrpoje+hvnwVHdTT2y0/hHFw/4ZOtc3Ej2a0J8l9/+uOAJzrWvLzMIM0x
yNuEN3jxJuxtV7JW6yTcIDuV17l4+cz/Eum2VK/A66Awv9iveKISzo10etPy
ah94yqrJC20FCUvIDCxdAV6dYD6T7eUzbdGZbu+bzbCkE0uLZhYWeEay0XEQ
qoCQRizIxlctLHK17M+0Aj9zi22P63J4IAii8IUiHA+hffOBkuRlnt0sT19u
Ts8uZCaxklYYXI4fDd1uPPlgyUr8OFg0vdKl8fB1mXl8qjw8We18d1mYX1WM
nOiejwOweO/kx6Gi3VDRVq/tSXVVHlzMS8Os+jiZ3b0+WbNMN+MDpfDAx6Gi
j57um3NHKy/G87fF2UM/18k9L4yJ2bkynm4CytZqHyerJI3TLyfP99Py06q3
mEmnryulNlo+5PPTy+frYP7XaJDxuphIkQ7KgY+ONfNhiJFCn7RSKj5cS/XM
w/D5drHsn8ia0Z+Oyj2dbjDA4SnXI0fuIc/Z/uJMLCYp2Y8OLa0BpN3hW9l9
rNui+PTm9h5Wj5eXtv4wGji9G0xLhA3gQc99C/Rle/JSqxZGb0wpXV125te3
40W/Lz7c6jWflo1et56IcIpuy+mbek5SOvLTdKn2NUNtynJ5PJ5WSie1YJF2
BA3iAa/DBdcd6yx3Nbh5lS/vaka3YwzuJ7lcR3/oyj70cP7P988ZCgTH7Zbg
sCKC4+60e9v6nJgDeGvn54fzjNvtVnNXykK7Ho4fT+Y3tVljxorfuvYe3NvJ
bdnMtq2H5ajVGI1vz7q3peLtybTR9NCmGHZSpOnCtMvhst1ZVNuD5az3NByP
rgZGWbvvnLIH+xtx/sA9bJxRO5e3H5YkYIulB5WLZv7WzS4fs6XJuHW2sFbd
/u3i1pRq6xUGs2XfKbbnY9I5NN/4USNr17LjRsIb6PfAGadDqjZNiePpbLac
y5Sz+fw+8iWC6V07m86DB0JI92v1b0IULP41gtV8Llv9dgRDsHKZTKlSKWaC
BbiqX0d3GFaG8u9ZaKPBa8G5EszHm2ZoQqY8EyVNS9Fpo83HhY9E/6PIZMrZ
EvrJHpRcYigUnhusD4kwDYnPrYoXYa9B578b6EIlX8HILC2BB73w3aAXc4VS
vgiL0hkJYGJTsVionBiL3OYS6DvcdXgMQnqPukqAzeoVMHNjlRfz8bIgr5aN
jLFjYcbLnzSGPUhoBCpxxQQTSx3y6uODyF++oc3LjbCuc8GQtxhFez7smmwG
U3HSCTybXZ8fUgWf0Kld1rZqc/uRsnG8wdsw+Zu8NBIrew+wMGkICg+h1GS/
No/iPuApGFSmxJRffhqB28TAmYi+w5tUYAWawbCEU7KwRBrrmFfROtMOv+ta
9RvMhP2IEc8twXpMxhREhpgLC0RdCkbiwo1cjYpZdSoP9Wr5tyqevRvQeTWr
wptlzLAEhcxzv3w95dPGq2Wnbig2r7H0XS+svbN5JxR+6iXQjebrC9exDC9U
ny7YoTu6LSAGEAcLPezNO7o/U8HnQrUnXnWjRS4I+DBekRz5GExWuXz3OG9d
SOt5Gmrg1HgVllhSaDvrxkAn4P1bSMdTbPGCDXqApVbCOfKHJFyphgTPGpZk
T03vX3NVhkddyZrCtrh1lRX8dcuGbCpNhCugimJaI3jUN4cq8NK1q2nAZEdH
u+4RPzrae8E4nz5tVKzN5xPEmkCchGyKnCtwVrR0e+EQIXAV55Lmkgcqh7cs
0WC76ptGp/YyY6CD18pDCnia7SC2CrtqPHGQAdcsyX3CCdNm+NwvrTeNvegS
Pk1LlbGrBbCohuQ/cycmrI9l//3/MbZIv1HkjktquVhzrkmGPIGpwJI6wK3C
ucV0ZuHKvEiY09gGhuLfg+YT+hNTt00E/wT+MMzpTJWIH67Bw9eES3VqGibs
KXhSB7G4Eh5Ujb9fM0xjpWMrp3AFn9/9wMIxGrBwptAFCwg2m8dAZ+bEEK4t
5v79/wIcHMfm0E5A+gPjtSWNYTsiRr0Heo7kDnEifik+9r5Z194L2/9DNCPF
+gEZLlyTkFYs2BSAkkY0OXfBi5dWQm2ig7w///t//v3//vt/TuGHcK0+YTCb
qJgqNdFVNqapzVeKcDWVVCI3zBOho76RYO89mKYCAOBR6+//r4WQGCyLwpcB
xEhPcvD9M2nqDvlKYs2nYy7sqbpem1MscgaemNByAPOC6Gu44zEBbrAhiHRT
YyvaZWTRYI8QSwVRxzdYQ+R/fXRXkUDjrbKozYS1Wm+yNayQiInZW9vsGWrC
8GO2ma8eaPyOabgOrPMErDwm7d7sInE/4HTKY007tmAbexzZQt+WJ+aIGSou
/ZNkoWU9YaMRLeiF5PIS3QtQVEPgdeTglmqpygQEfxdQXEk6MSZQEOwbtFRg
OR3i+zPTkKjbSNtcIYugUIUVB5UunEiwCUiGWmwEKoUWlf+nt6K76qa3VIGw
zv7lReKoE3VTYdQ8hiu5XAb/G+M12VTeywtUeRu50JiBJUXRP+o2IdkbQ/it
Pfy+NIHCOQeengDvrWCuJzC/sTSXjF1S6xKEhS6cm0OmwiLj9FsMw22gNQ4O
ep7+JXvP9ushMXB2LKAXfIwF7jw0yNNLeTMYnz15RjNvIUEk8i0KrBghUKTY
U0JN2F31vgZFfUtsMO9gAf4JtQM/z8Cw/iVbRgtvZxsURG6E3RNoyjxDMGiZ
FMpoFj791GCug6eDpGvkiWuM7TFIANVLv0/9dHjw/wN6mI5ELDcBAA==

-->

</rfc>
