<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-09" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-09"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <date year="2026" month="August" day="21"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 79?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 83?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, the key decision factor is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://www.ietf.org/archive/id/draft-fossati-tls-attestation-06.html">draft-fossati-tls-attestation-06</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestaion">
        <name>SEAT-Early-Attestaion</name>
        <t>The draft <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation">draft-fossati-seat-early-attestation</eref> is an extension of the provably vulnerable (and withdrawn) draft <eref target="https://www.ietf.org/archive/id/draft-fossati-tls-attestation-10.html">draft-fossati-tls-attestation-10</eref> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref> does not prevent relay attacks as there is no shared secret in the binder.</t>
        <t>Post-handshake attestation part prevents relay attacks, but then the complexity of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>CVEs and finders</name>
        <thead>
          <tr>
            <th align="left">CVE</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">CVE-2026-33697</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ERISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation</eref> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="eu-erisa">
      <name>EU ERISA</name>
      <t>European Union's ERISA has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <ul spacing="normal">
        <li>
          <t>1 potential CVE of expected CVSS <strong>9.8</strong></t>
        </li>
        <li>
          <t>2 potential CVEs of expected CVSS <strong>9.1</strong></t>
        </li>
        <li>
          <t>1 potential CVE of expected CVSS <strong>8.7</strong></t>
        </li>
        <li>
          <t>2 potential CVEs of expected CVSS <strong>7.5</strong></t>
        </li>
        <li>
          <t>2 potential CVEs of expected CVSS <strong>7.4</strong></t>
        </li>
        <li>
          <t>2 potential CVEs of expected CVSS <strong>6.3</strong></t>
        </li>
      </ul>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation</eref>: symbolic proof of insecurity; <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft</eref> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref> that contains a link to our <eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT email</eref> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
          </ul>
        </li>
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> remain vulnerable to CVE-2026-33697. We have also proved that <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/04/">draft-fossati-seat-early-attestation-04</eref> and <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation-06</eref> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation-09</eref> is vulnerable to CVE-2026-33697. Thankfully, the authors have withdrawn <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation-10</eref>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high-severity vulnerabilities, we recommend that the
developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="technical-report">
        <name>Technical Report</name>
        <t>Technical report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="media-coverage">
      <name>Media Coverage</name>
      <t>Several media enthusiasts and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, four main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, and Haowen Song) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation</eref>, <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref>, and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail#upcoming-and-recent-talks-and-research-visits">recordings</eref> and the <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail#community-service">archives</eref>. We sincerely thank the authors of <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation</eref> for withdrawing their draft to protect further exploits.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
        <front>
          <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
          <author initials="M. U." surname="Sardar">
            <organization/>
          </author>
          <author initials="V." surname="Dubeyko">
            <organization/>
          </author>
          <author initials="J.-M." surname="Jacquet">
            <organization/>
          </author>
          <date year="2026" month="June"/>
        </front>
      </reference>
      <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
        <front>
          <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
          <author initials="M. U." surname="Sardar">
            <organization/>
          </author>
          <author initials="V." surname="Dubeyko">
            <organization/>
          </author>
          <author initials="J.-M." surname="Jacquet">
            <organization/>
          </author>
          <date year="2026" month="July"/>
        </front>
      </reference>
      <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
        <front>
          <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
          <author>
            <organization>CVE</organization>
          </author>
          <date year="2026" month="March"/>
        </front>
      </reference>
      <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
        <front>
          <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
          <author>
            <organization>ENISA</organization>
          </author>
          <date year="2026" month="March"/>
        </front>
      </reference>
    </references>
    <?line 497?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong></t>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong></t>
      <t>We would like to thank our co-authors of <eref target="https://www.researchgate.net/publication/398839141_Identity_Crisis_in_Confidential_Computing_Formal_Analysis_of_Attested_TLS">ID-Crisis paper</eref> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following who gave feedback on <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis">previous state-of-the-art</eref> that we utilize as the basis for attested TLS:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their <eref target="https://ieeexplore.ieee.org/document/7958594">work</eref> that forms the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback. An incomplete list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9192XLjSJLgO78ClvXQKa3A+9RYbQ1FiaJupahbNsYOAkEy
RBxMHDzUVW37sm/7A2u2a/u4tv/Qb/0n8yXr7gGAAEVRQnWqpm3KujOTODw8
PDz8CneHqqoZT3gG31W+HFmew9QRs3R3xMZcaXoedz3mCdtSWrblCp07XFc6
zDEHvqF8bd0eqMV8saqWStVGTbEHSuu221Vq2YoCMBSXT7nDDMX2RtyBWwcu
PuJPFM9W+HzCNQ+A0RuNbB2ua7YprOHWlwzr9x0+TY3Ql4zGPD60ncWuIqyB
ncnotmYxE6amO2zgqSIJTh0wYaj5Rsb1+6ZwXYDqLSbw9NHBdVtRflKY4dqA
hbB0PuHwh+V92VG+cF14tiOYgT+Omnvwl+3Av66u218ylm/2ubOb0QGT3YwG
OHLL9d1dxXN8noE5lTIA1+FsV2leHTQzM9sZDx3bn+wq3YPmdWbMF3BJ380o
qtI8UtgQBnXxxyop2JIUeDu5FJkpt3wY/ydFCYDfHeIPOb07GBMIrRziLbxs
Ah3wkX/lc2ZODJ6FlcDrzNFGu8rI8ybubi4Xu5kDcABaeCO/DwQy/REzTaar
vstMprrM0ZmTW0ftL/CawRBzeC0EvPb1rISeFfZaQLm3VzQ78kwYKMN8b2Q7
SEkYVFGAQQzJDF/OggGVGxxQ6dKAX+gp2xkyS7wQXXeV6xtl3+EurPyOcsgd
k1kLeopLikUT7xHmWYn5v3q+qsu3sjr/smb8rm0N+7ay568bswuzGY6YUA59
ZilNC1Z+YMPQxPTXXBtZtmEPF8D/2R3l1NPhz9ZIWCyBWN/wuW4PLRjzX4d4
DVdtHSqtEbeGc2EpHRhtuA6foyX3J4ZgvoMM6Lw/RofZM24pOOtPm/CITZlV
KOYr+Uq5HEcnk7EksCnsB2V1G2WRYXYJ0htCkJ5YFXVbu0pHDEcqSTjhLXD7
gcgJ5BNIpOvTrpwqyQHl2Le4gq/vyKGYM+TecmfNZrMsEJPjfhvCC1mLe7mJ
3zeERlTIlfP1YqFRqBd7K9ghcr0kbr0EZnizJ6xeiFkPMCMcot1B/6mAPQip
s6xykw32Q/LObVbZ9/t8MbaT149VeOeYad997r1BXtXhE/uPoLGx2EDjQJyg
8PqQuCKcPpFSyckG0JND0UbZxSflhYB6LbtldwP5L8mgCFeZ+oYF2rZvcFSv
DjfYAp9h2hjuCQYKF6ZHGpdPRtwkxYyvgsJxA/BruFKb8iwgkQMcrrgGiukX
of+8omuU5RoUq8oZMjGtA9w4uLndl48WquV6fdMsD86Pus3/kHlyf6pnuSVc
luW+Y0/wrxz9zq3g//ZUMyKUWShmMtlsNpNRVVVhfZfQyWSuR1xaIQoTpou4
Txx7CgaM4qGIg51uKDr3gOnISnpKEvnfvqZclS2ywJ5WJrAE8/FJb+0os5GA
iQLxwVACkW95YPzE0OY4DUvjiPfIninb27SXtrfXmyvKgCYJW3mCpBEa3wEQ
oCC2Z7BHbd9TJqOFS5CZpnHX3c4qZ7bDbZADO4orcCQwrDxh+bbvJiADimAw
4ZqDLHD4d1+AebjzLkJM1114yLcsjuMxZwEDoK0zB7mzDcPj4oGA9g3PReNN
6QO7AYf1F4on75DoVv7yl3WC7bffaC3wSeZ4YgBzdt94lEQlPA+0Qdy4ag9U
eE+F94BjbGNHuXTsWxCHgx3FB5XsKM0J0+CBYjavgLYAW5MrwIiAEnCX7mui
LwyYww5hADoSUOdAaUDfsmcG14fxWRgcdKiHI4/5yDYAvBuwsSl03eAZsAkR
awRMdueb850gSSwkVrgeCpsARoArcj6zmLF44TSseNuuxR0ysV2wwncAuyHI
WgNWB7lsNuLkU8AfC1oQ5BwgGgJ0NXtCrIj2tKKNgHbwJNDEsr2s0nZsE7By
ueaTUpnAJNETgX27Q6+DnIB9qAlXcqoGpj6yFd7SAEmBu1/pg0uAFrQJewAs
GdcEVWCba667cezWY4YrQx6SfBaxBEL/pFwAu08Fn6HoAASk7IgIi/iQxDEU
xF8MAlOBwBF9XUGkegdxl9glvAxIbloPfBT3P+g8PTDf6FpCRsOiebZmGy7I
wV+Vczur/KrsrQ4L125ceAEG/FVpRrviV3ijgC+0DAHT/Pf/9j9dgmnZuOl/
VZ7OQEL+yQXPaCnJmMiacJU0OyGqwS5ybd/ReG7iiCluI8AJNzagoEZiSwWp
5vEJAw7YQtBIA+4UloB/l8WQ8xzOc2B+WrkA4BbNqrgyqzhZw9mpSzSKPxqN
okSjhGgcMAfEI3jgNjFgYuDSjx64JAcu48Bd4Gju0PyldUu7LTF++UePX5bj
V4j+tgkXJdFha/xUpN3yUymJQuVHo1CRKFQ3oFDG4Q9AHJOE6y5gN8HWbNkI
3vXWItRqtdRYPCRncg4qcejm+obdl8ODPcIxUOHmwFQZ++6Vry+yWgBUZZ7h
qpqmqTFezE70wda/gPUBOzi5zdDucC1XFZ7ju151SDjMJiqCA6bO+RPDZrqb
A8OhkisUc3cc5+moTVCMsM80xE29xnfV1sV5+2j/4Pz6qHlaPQyGhDFbrUSA
p3t0+JGJb4E8YLo9QfkD+/wZhlKeNkixtTBXyJALJZqKNJrYWkxCVH80e1Ql
e9TWsscOsOdOjEdk2GNgg5XiCcIuhraaryYXTHBvQJYimieg4nJCz70HgcIn
sfnWfvR8azjfv+xKM//nL690A2h7gcaXCWxFSLk0/9DyWRpRX37LZP76179m
7nhkS7NQKcIFoB/8D3yvUNfDLzAMpSHWB2tyqRcza/Qivfu2LvRRmyCszFpL
LYaupQeGDKJnCk8Ml5oT39cFGAZTCmRGqIZeDlpvgrtZ5cJH1Qv7FyyhKYct
Da8yTxGeYrJFBowGMOwUGMMVgWcEppaAJ+ElxwZEwfwKowkqTGoA9oLyFQw+
biilrWj6clKbps0M2+JoEIN1AeTDUUGRGDZscT0jLc+YR4auA0wMaBBcAXVj
Akg0DDVShmTiTzx8InQjMgNpo+liMICXLZwiTAaH7drSnpGvwvjBxF3f4RFB
QCKBHe+5GaCCAKNC566QxEXtkyWWySDTgJkwwSByH7QhLoJho0mCA8TJv3jP
KkI3z0W7TdozT9EiMn0qXNtZrN1A4Es4bCpsg3uOm9NQ3ubCN3PBm7DyucNO
t6lOB8Ohak7nc9UcDmH/CNf1YTQY2ZMUAfdJtx03dNWkryLxAVcj6RqCfR6L
1Etj88zWuYFrf0F2dbgnz6LtIB3Ypf+Cpiq4V2BSDtBNQqbD1TdtPWmKIpkQ
Eoy4XM9N1FyzE8FBcVEiLNBmtoZ4F/kUhvwzSB2P/VmZMIeBEQiYB05AK2Au
wEAaHUpgAuJeapNvozyx4RDdCo//OAkXgdwiFxUuuSRzAo9Hj0sDfd1cAf83
vSpYaxcMBNBvGOgAHM1wjr4V/MoGCziQ7luIhAKbNvIT1ngvxAPolahkG4bq
FX28WOBiRfmA0+upnJ5fq15xaTD4AZt+qYh0W8t9BAzyOAmFOVgXbqAOcWVR
0jPcsbFA0FekATpZAHkGr65Fd1XTFfL/qK4s5ANdiUMHHplh2DNSDDMbj1Us
ybIg8AKhFqqnpdsJbhK4PHukGsFFd6WH7k9QL+kZ8BsubbCZ3nCQUd1E7zBd
B6aSQjiOqFxDEC20+aQSJkn1B65nLl/NwcLYnCQl+rFTRCYZv2Pk14JkEfiU
AvMNlKLDvXBnS/SBY98jSzCEu6qR+r6HgCS0ZZjnPX0PKPnWM5ivsIW4jjtG
aTl4FOiim4ux6V+VNuFGbqyqqvR/eS9+Svqrsvb4aUe5FRjKcQ02DQPI0vA7
5sxSwYAXPAwfJ+wnOlfF5wZydLSKfgIF7cA6SLlOy+/JCyZewMmg1gb+lDqi
y7Us+CcFJMJb4gemDHD3KUQJb90mVOS+VJ+ohq+FiaqES6NNunnNZbzJpDUB
kd4EbUBx2lupu5CMB8QUvyr7GKtIUhENIGEJCj0uFTcPFTcZAHagBwFCvqZc
aN4ORmcrZF6voIAYRA8XyjAvLfZw/AQq0LBPeCi83Ax4wBQIiqTkyJnuMOcw
z81Vh/3v8/z9Q/3uwemUzubl6UXdKqr+yfAhh/Z1oQDradGoVRr1KaAWmjUg
0QnPmIzi/Ww4Ig4Gv9HZquaLxVqhmq9Uyrm4OIvZF1mHnMJhzuNcOjQYFtEW
gEWcCsWa0ub9GD6hEyiddXcEa/VHGDfK0/Z2Nzz0+VnpHB128GyIzJX61vb2
vyGuJRl9j2MLW3CNqbPEfRPcSgi3+gruwdVRtxkDg+FxGGglSg4j/U74T0vO
TC54jJ6XuGDuws2h/wzuPMZqGdgyOY8NZZALbqrTfLaeLdCihi9IbUAvrSPO
BzBu0MHa78V3aL+NayVbUId2IVuswmCvkB7avxPhQv4VxhhZSLqUvzMIoHPN
IJ30tOEY6kPRmlXYuYlvGLlKnQRDbXUGt8vR1kwGo/3275xRIFF05M3ihmE/
YlKlNhVW3s8V8rmtpR2HLCGPCkGjKrjlV9B7FS9LLad4AAFZNYyLvS2oRs9D
TX3WKlN1MKuNNguqcrjhV/bPUm9HmjTpbMb1WVyTshUVKtX8wY2UT5nMAZ7i
gaWg3FhAyj+5gdxC4zCWvwR285JI64QYmbJRFhfFEaJxQQ/GDmAJXWkUtMCK
AvvEBVak96UPcpuMYaCd0bKtATr5pMXxLZ+cw1PwI0FlwpyRPj/BAqja1HVV
V7NB1Ssw04jMgECfoe8EYz2dH3WvwYvxHKHFdp011bPg1XjZoT3NIbZq8EgO
gW5lMzHOljQP7TeaN8iLcLQPw4zbKjGb5WkmwHJlE7KgYpo8djU3AB5wo0sY
C1Xw1IQw+voEphg3VvwUvCR3dxB6has5381xK2JdVYPr3MnFLYkcvahGj8Tv
IQ9UwJ9Ri3U1ny8Ebg2dIDfP9pPjM1OXe8fKhecsbk6eNnoR9FwfxBnGo3Pw
uOr21VK+nI/ALgdG0lHs/Rw9VKLZ9cHBCr3AbInTio5sVij1Csj+vW7P4hLJ
yDLNDOSQAEmTLRTKlVypWqlXy+UsqJd8sZSnsOcfSPMy0jwfpzmeFIENqpza
MzmTrscM7sfYe64xNdA0sRw5Vz4W/t3zXW6JOajWgE5hPkFFrZQr+cbH8wmC
FxBGOZtH7wWcHt+UyO2BTzFuN7vX76HXxwcHKF2jf/VsNjaAxdbhWC00asU0
OOILW4hhcRVDpl81z5ag+gx0i4nJDsG/cOxffyCbFypyJfHIqfQHkquQllwF
QrGxgmKb9UGsjbn+HoqD8MHlvzYz3Wq8ZS2GcDH2wloM13mnSch/YCodznKN
mforac9fKYEt6ayvaEqZGj19rSm1uKbUIk1pRJoS9f91EMEIIAYRMnm2sVTk
29uAzPY2WdVvxhYxJIjZ08G5wmrWFcZsTBpXWXAvGBSD5XaYAeNFyQbrMXeR
gWRAA48OZDAKzBEU2cGbM45HAx5M0hq7YbwHWMMl845CLpgHRJnkmUzbd4JQ
J0XUopwHtHiMJWrLkNzE9kLLA0MmSI5NAZ+vSxxlqs3SMtvazWRUpZCEiLNI
ZrVvbzey9e1teLS4OvjaZwv07AfA1rO1D4Oltf/ws+UPP1vNluBZZEE813Iw
MAvGqolnvgsFg/4mcRO8Ka24HeKhAdyHtXJdMcTQE92i9CqZxgOvGUZAbodj
9guteswPOUqeDGYyTeAX8C+9lcV+dYLo8FjEmNbvs5JJdtdJBOT7dfb2ew4t
4vn6MH5zqAUw+KeI0+z8aEKkS5BY59x9nDSf7BrSuv4zJzzs/iHBDuSG7e0w
CEHCJ4oCybDV7icEyDARQJ6HBw4ghb1TB5sQWeFIZId2SkQ/Hhn7UdhmjgbK
wvZJFLIZ/omQrUVghGw8/EhI0x1lQoiD4PUU31Vw0oprS8thRmkVijbi2piW
d90p+6tDdrR6pMI2VyX+ZZBPqHTjeY7uW4I/TD9MpkW60h7aNMftCfNG2yuK
ApH6uBCTauVzY2T5Rg72prsw+zaeFazJc/mXAIUfE47b3o4CcmBDwuMy7Zaq
El5N9vOPEGNTx0X4SioX/GpdnXBLpdDQVmB10ktvpAJ9Bdk9RFsEmRJNULQG
1XxZhtpwt2GOioFMbcP16lYG6ziamLdCybt3h3TIKDQxwZTpiY2Ovq7Yvhdt
DkwIkVuiDxssjSoMD+0ZWcKIwR+hzgnVZdJCNDYYP8oTTZpqrT56BIZrmJuX
+Ld5+/lb+/hU44xXjXLvfHhvme4+HoElR0SmOixRcgR3cIm0QRbIQ8FA23FA
IMJ6/PZb8Jq3zImODpWRd9zBIktrRfnYyWXC+gUqKMDatEWUI7825wdzTrDY
QXjSfSEvB7w5T5kywyfRGSafhHnn8rQ6cEfkOevmLH+aSMxVAQaRuDctJagn
wbNOBr4dmbSBbxYe4MtJb2/rwgETwFjA9oTrFMyXyQYg2re3E4fo8AhhG9Iu
u9zCwCMvcuNRgs+H9+zKe7l8/j35RFNELiUHIb7kmKjiO5ErRw+uL8rA2QvP
5cYgnsyvYSK1Y6ECCTOYTjHFzcUMi/3OSkLB1z8P54s/b4EGw7wcd+Vun3sz
TKrQlplEMoEMUzI6kQYJc+kwkfnrn0eeq4UQUaJwS3MWkzCbc6l3TJzQkLuZ
UlZpLjPzVqCBctsALZbRhyVJLJO5lILH5Tw80C9uOtAnmEHJESndbkjHS7kg
KAO/tmDvgcFHwxziFtxaxuijban8hvl0WlCRTUGDIO0K6HrVvO6GVXtOrJjI
W0yoyOfNaEeWMmPiCMBsDsJiIzybwEXtymXrBot6WNjCFdrwViwLf7mO1wHl
T5Dyh8UtXJmPwYivXxJKaWvdmpRSrckZKoIrWXqE1kUznky2rtwkqDTCtSHD
S1/nDb+T6/LaBkrY/Cg1VmoIRtyYuFHOqcwrLYT44fOYvhHlvS3LQNa9V4y/
d0QJrsqGBNcgifW9LE1KXFXCCjOm6yIwD5jr+ibtKpeOhi5DabTxv1+XuZHK
T4Wd4k55p5q8WNqp7GC2z+XrWWMcc1dVN4+QGCx4OvxH9DcAOiwou5tYlaQc
vPHv//t/BMD+/X/99+Q/EErxHShjbbQCRf4rCaX0LpQ/K29ACf4RC5YS7wdl
dxjuXN1LtWyB+L0thhiYrHx0Y5H0DFkZMx8PwthWtNE2ly7FCpaW74b1geuP
AjdWNX1W6VHuUwubcoY9zHpz7+MFTp9W3BSf6CdAT0x0fQnVp5VPxaf2CdAT
U9tYpPVpBVrxGX4C9MQM3ysD+7QSsPgkPwF6YpLvFpp9ViFT7lPLpJKT/Fi5
1GeVMOU+tUAqOdN6Nm5FwLBhWfSPGzeEKKf1ifBjE1vq+VUVKlOb8KQnit7B
4ralInZJY791k9Q8tW8KwjRgQt5h0btBtuLk7Zxxsg93MEIwQqdlbWBrPmHp
o2rLV3NbOxQbXbVcY+budbydgOsPwUf0ArcfnHx0REeLviP0ZWm88lVLboKN
RjBWn7xJg63/gIoAyjH68REIchrAyN/Q1eE9WsVdBSygsxbLQEOfW3wgkufg
/9G8lUVGDzoIJOP729vLdgeBcwPTJ6Z6xU1x/qQn3ptWWIUXvIRM3MSaOxN2
JszAkw0mMKwTC9wGR/Wy3HDZ0iKo71kbv//Pw5oOp8KgpIOdDA7TWlK7DopB
Y80TRSnZB4uw1Hz5h5GinCTFewNXf+gaBGFCGWANmRh+2A43oxSRZLifIq/Z
D2qJ0+bJgdQSXWFiOBtpDUuC9b8aDEdPrmdJ5cnAjnMO+/CE8ZIavJTb+iiK
6CkShu/Vfjd+yNnS6x5Lq6x5DdJgTCF0uWPDHG3i12X2doryu3/gfArlzRUI
G2/lME+2XNkmBJfSC+fGQQ/oWJPn2L4b9hMKzjmiVOcdLCTGBirL7KSRGI4w
O4lyVvRYGvXvyd5SvmIUIzjdWKY6//YbsgUWKB+KaVCiNko0QVsZbAfPW8Ey
oOpPPTwa4RkdTQsU9TIiiAIHT1nw9ztq7+yme53xnaHMfDIxlWyjcgvqqd9j
5SYCLNKfmY09eDbhRic9JqaA6WB7UkI6oy5B1F8iKKmPumZS/PQ66lIl8+2l
+Xht2wZGrH0MJ62W70d6annoFiosqux/ChXWkoEF51QF7+BJGOch//qUA9yo
w8aplLbCgv8VMbKsa5Vtc5IF2TLJL3GoBEjL07KngZgj/wH5AkC6CH+EJZWb
o6Ifyt6Qg6uItSp0VXMEkCJm3IOAUlkOcNmS5042hXo5iG7fVbC/aVDXiZR2
PJmJBzghWw2ARrjJVupA3wnlhkdYCDtL9HEC4c+jQ7JZ7DgCmyQg0wDhsG0t
llFjmzKSXVQyGx3pEVjK9hF9P179hxvMt4KDwaj1wz/hCgSkxoNwLB3ZQdLI
TlmwU3DaIergvfE12NIKPh3tqy0aRKHz9ffT6Gu1RjFfz5Zq9UqpXtvaic4h
Ys0tqKLh9TH4FrYxkIdCch8EnBNtOs32DT3MHqSmB0HfOHl6v7Q03dUlzcrW
WWbY3EAb2QKEvexAgea7AWaH5BdqQBfVca+hCy70zoowTnLtjPCUKYyBjbd5
7WGnn9vYSzC0PcJS0386rlq/r0n5SJlkgUa/7J7IBIylws1KWf8P89NuJvNf
lbbsLyGXEq2iQra0k9jo0bixIqF9MRgIrna4YZiwBZAXFS5k5jDWE4NwFdzQ
XewQB8+ICTAWpidPOXWdCxquyRPirwetrf3OQdD+BEuRuMZQh8yk5+VbCb9L
hk+BR9kUUyXQnFoR/c5qJZ88mVimXhNHriEsaom7kUCB5wWM1wfPT0hTRq7J
mtekwfZaWkYnhsGxzWR5AIxNZ4SsEo+ELihi2o+hYy2W3RYBn4itkx1DolWS
HelcIpMbnBL7WJHvRXSx0LYEgoeH78nbaJdNAmsf0ApYIYu1QJpB3TVxEUym
Uy48uPAywY2MsqEvZx+o2aV5cMUxlp9ZXnDoArWhiJYPSPVmeTweVeLD1M8m
OLGPFR7guwfdi6ujVpdqAWn8n1aL5DLRwdams6xEF8DX7UOJacLOo4HEwNQC
jUcdAVf7C0lkzqLmRCEemxMI3sFjadkEB6AReEn86Bgt00z0lfkAvcMUmldN
ME9lE0x5ds51wZQWbnmwCIMiQjSj6DogPgJNzjDAhtoKK+SHPPRjQqX1RqJi
YHOu2AYkJqXH4ZjvGNpZyhXELXLFhwJTI5JFLNQIQ96Q2ehhHhcyTy5fQ8c8
7maokZvhqtSiTY1OLFXhqn3HHnOLbFyQ6KrJFirsYJXPYYRcpVit5ivVLcDo
6zGbMAuWdUt52jOAcTrMO+cz99oeL2I1xn28BZLDgltZD++FbVPcXKHQaBQq
BCykuAH+lo8JLwC1Q36eZce11Ci6RnNN5AvPGHhH/oRYSPVstc9pFga2sJMT
hT2OLSkXqgAf27XQYSTNZnJwTHV4G8weFf6PKD1hugYGgnUtkTceXHCzmFYj
e9zzYXg1JUI5oReqjXqlUKuWS7+Inwv5fL5Wq1aLpWKdiPwU7y8RZd0gmWPZ
ddjOCDYYrj8l1sVRSOSqqUHRVGBR5bYCxjrnc++QWyjRjqTojZVUgjyF2+gn
ceytRbdp1hPfcHkOjAEysNSBwWbq0ohThaWu57qEcx85M4TLPmzYRTjNKyrr
iPv+cDNk7qDmA/FYFt0lp6cmCEEWmERyJDxYG+BJF5ZQpeRHlQlJjW4LP3pg
6Mkt5mozvEjD9R3BB29uKIciDGunSFsJRYY6QC4kVS7JRiPnC8o3n1meb8Y3
jz10s/RhBjQXcHmz/jiXL6jBo+qRpeESxT5sgGpa1eCuOuZ8ouJcAQNTuBzm
vHhjTVxJmaAFEXEphlpUlxZTDC2P3kTbUpqEtGmvfBfEIp4GRKx5yvorpAvu
gJjOOn4OxUCuUitXypXsZDQhMPJ7CQCFpgtCJQkhvEoFehtZSnDHhx9yqcGq
B1EhEcWvAEhJ1RVWLAyHRUaWxrPgprGsZuWQxUlsqvmaCmJT6idgZTFwtbnX
aFSAswpZXRZuUqQNqFTui5dkiAqvSPmEKaVYigwGnzoAN4SpsBYTlAEgXbHt
MlPBAntjVVaIfHQNZF4pN/aAvhFdhesaXLex9sgQqsXcEfw1pg064u7YX/iq
v2AvU2FikGaa2CArdHLNF92MCz3Xy9I1ufVzrF60jUYjv0pfTJGOCydEUl6j
FwlNSdVcOQeCrpAvFiNqxuCIAbeGsbBJli7IgpRc3b8ZLPKXZ+b3A7kI/nDI
LN9lK+OGlyXOMIW32AfFgW1wdSI8bYRKUKoL3AaUlkoaEH9phu0DuWa2ugCH
0MVgUKBC0NEbiCQ6b7fbmOAz8EQuepZivjGfaq0sk4dvOIY7sYUXL/Z2qbWi
L8kcNFrEOtlGsdIoNPMV4Oi9llrJFyrqXrO0r+4VSuXaXqmyX62XCaLBpnMl
uXi0bHg9O/JDVs6tSFV5AolHS6DlQI6qWJupYkr42xpAzsAe+SuiAq7IXQPu
XblSr1YapXKvUCzm8+V8QRodl+jd0m4g5HThJZovRNeywpHM9pYSSGp+EKmN
QbVYLKjFqsbUWrFRUhucN9RKpVLrl7R8vz6or2zHU3F2qdxeni+HN8BHm06k
ZRLuyaRBECqdoK+SRAWXORAmoOGyOp+uKD28RPzr5sZH1Uv7/OVyTi+AUgDi
xqhIv7MUdGAiC8KMcAhXCWinYmQkqRkRB1eqDaqrfVNvB8Yiuow0+iGmofPY
Iur97BCLtbmfczEDnpoM//Ld587i5yQ/0/saQHIMMF3jBl7sItGxWM7Xa68+
7BPXrzOwUFQM2y27J2D410K7lllgdMGzTnRPmnbWMwjkyKBaqeenm1Rcj62w
XtFKjRqiEawBbFkLkI5pleAKKSxd4Ml8rlpbEXCaq1tJRZ/FS/TOjIu5sHrl
YqlWLTSKufBjVb1CKd+ogn241D82qC6PiB3bt7GLYSuKdespF17u3GBxHeGO
pSq49p2xcEeAKbgoOlofoKMFi1viscs0zIj1sasF1j8K2FxJLnsDB6GBlHhh
CzFQx8wQC9uRdhgb9+NWKP2U3k3MIhFWTCiD1IbVFobhu6GB8sR0sOY15bVK
kjdUKS94bgaaE5xBMH8GoCMIHNiU6JFwcNcYB8LANHCHUGSafoNCGjoAh2Gr
UJdalKhDDnZyrtqoNgrlWkWy2tGZb3gCXIV47bAZXJPKIBAG3AIG16JqYfyW
ETiRW7LlZmhgXS338tJP1bC/IEWNwsdiW36ZTpCof9uR7usy9BRGk6gZrnQ6
z8BwYBggYuMk/VC+w5BWpFndnCmfnbBx7y0bE0+uXrmcGKCd4qatlWuNcqFS
KdXqpSpwfr5aVr+rzbJcyitbd8TQVvYcoJH9LjaO06cHe2B7SOEQNg2Wko6c
ZuQZy1aRPKC4qKqDsKjUi6B1StVqFdCpFNX7fLMisdjDY59LB1yi1cYva3Do
w8Mg6elhtVyuFMqFYs+WPIsF8B7ZD2+ZJEtsyo1aoV5slME1LJfz6mwgSqHr
ZjuwZOAZAlEHfANCYFC49ExOJgdFVM+BTZqTLBZ8tuxPrrLXPcpklj/bXCcu
u8CKBVkAt9Yt/bqHQRaXmZ4y+PvfHKWLZqcz4oJacmL4JfaaK6NA4y1qw7DC
fEqLOWCSKx1heDvwJtBkQTEkVwHDZ8xdPAiUkTLAdQfeMvR/thDJrjyebbWS
2S9B6VnQDIMiobLRJaWdC7AR8UMdSyEXnJriH2FvLg1DSxj8pGAlBkZhWWLb
XM6CTiN1TMnNwDqyoJkl97TsjoydYb4IdeuQwTaZftNqBQMC3g4fYJQLD/bX
duOSZzerDUCCCDEWPAHhYtnw2Eq6ReE26dnLA1YEjb2eNR5dfjOKGPWvnXDQ
6DIEEHRKThVMpXSJHH6GMZKgieK/IBwZPRUk2MR41It95qe/WOmbFn1SJ6wG
DL8HRDXOiHR4B42d4IMwYQg0jgcNux52EHCM4RAc5AeghaPYMytxHCwRYLLQ
LpA81FH99cnCusBvAs2wLE3Gz5ExbOzS0QcMZsrX7W0+1wwfz/S3t5PPw/vb
dLKzHWaDyBYpTylqRfdq7cL+c895dutH+ZNhadGalK7YJH/PD3Kpik43AdpK
iRQ7uG3oN23ba3576Vj6uFj6vqfN9q5LzE2H1CZAaZEqdab5g4I7uHeniz3P
qDaHD/VntdvpiFk6pDYBSotU5fS4Khru1Dat0WRx2bm75M9ntcGZef8tHVKb
AKVF6rb38P3w5qE0OJix9my2GDQb++5o0uFePh1SmwClReq43dNmZqdz0HeO
e3eV2+rigHt3d5YQ5XRIbQKUFqnLXuvheqEN8yeHNa1/wvx2Ux3fDu+Lz3Y6
pDYBSovU4/Hz8f3kYfZYsVq35kvvrtw+qd6L9sFDSkptApQWqbJrl07nnYuL
+063MLOmI9/md3dD3uqM0yG1CVBapL5Vj02tUp/mtYKxf1vyn48e8s37nj04
bKZDahOgtEhZ5TNe+XbZms5Gc+3g2NLv+OUCvE/NTslTmwClRarPr17Oz6ez
MzEYXw2OLwdzrh3ancn1fkqJvglQCqS0Afy6qTx09EbBeHgW31vXXmPvcXG7
f97mN5OzDyP1LqDUuq/dsst7Z1f73ZuFNT1vNL8dM+/y2bpnw5S6bwOgtEjN
+r0Ht3H2qDf8hn1W3BurdW9aG0zvD1MitQlQWqTsaX2g1rTHk5PK1aN6Zj5r
1aPRbXdPbacUCZsApUWq6N/4bL+wvxg+n++flQ+ve6rz0J9di+OUSG0ClBap
yV6pwfrnhW9Op9xrXp/1Dmr16fzy2p+nRGoToNS6b37Smp91uNptiquGP7q4
MAznpGzeNFOqmU2A0iJ1XZj7k5u92feHg71up3V9P+x27h89/ftLPR1SmwCl
RWp0NStX27OheauLxuD7o1kcPJ/0Dat3lFLNbAKUFqmbw9rioDc2zKvu/HxR
7NxXBy9+27b2nz8uPN8FlHr3jSb8yNB5e3BQtRvfq6eN27GXzzdbJykptQlQ
WqSGWlE856d9m4+6PXVayKvdc9eYs8dWSnN4E6DUwvOibDYH3yud48eJt79/
7nQtvfayr98XUjL6JkBpkbr3j7Xe4uD4snV25D9o0+LFWe1+3x5etW7SIbUJ
UGp76rZjWP320cFI1S6/8TN///bi+7zyML1L6WJtApQWqfntTalV+35zYQ01
MantlR8vKmfHN9eN+5QKeROgtEgVhi3tcqbWzu3J/tXLy95Ls6S3j4Z26Sql
kbcJUFqkvDqz+y97pVrZuBOnL86tc3H1UBsfPixSLt8mQGmRMks3i73q/em3
lznzNf580LPrl1a54HeP0iG1CVBqOfW9813r90+mrGcfHqjPB/uPfrFcGg7U
lAp5E6DULtZ+/dte4e72VPXsc3t6+K14Pa7umyY/SKlmNgFKi9T0/rw4EYPH
yuG91irMT2fdwWnLutHaNymDZpsApUXq7LB9L6x+vXLfZafj7897ByNz77FV
u9RS8tQmQGmRenYbt0fly7364sEcDYsXffa4V2DF4uA0JU9tApQWqfzVy8XV
y33vVjceKjffemd3Z+b80bCc55RyahOgtEjdlc46hT1w1vpm4e7mcn74TYzY
kVZ4uU5po28ClNqe6rHDhWG2O/ap+f28trenPdzaHdU5T+3NbACUFqla96Hr
79VLJ6bT+N7qF24L7UbZatyVSimthE2AUvNU924wLD6cHzQvvONvtUd3UJgb
5Qu1eZEy6rIJUGqFbA7OZ2p/Vj9x9eO+UXbZaaPRfikLrqVUyBsApY4OL8Tg
sP5yWWEz2+n3uoXzq0b74Obg/i5tdHgDoLRItR5m07Na5aXqXB/pxWbp8XH6
eGx25hcipT21CVAKpPyBCT+LjXn78b7SKtvdw/HksTm9v+7VHk7vircfX7/3
IaWllV/ozB/uGtrx4HYiSq1B43u+ykezycNhSu23CVBapLqHvWY+X6gy9eTM
um+OD72zm7k9fjSfU7L6JkCpj4xmNfXirthq3jp59dveS6PGm2fzvZ51llIl
bwKU2nG3Fn2NDabfivvq0ehmcH1bLNbvvrXPRyl95E2A0iLlmLfnvN1/ZvNi
1SgVrMpEeJ2j+cW3cUpFswlQWqT2h6Nj/bC0cPuX7ZOzb7yuvbyonnZ09j2l
pNoEKDWlHk+ZJvTizDrw2PGs2xdHRwOvdJ1vp+SpTYDSItUbH+xd7J+713fP
Q6b3K3PLeK5X9elIS2lRbQKUFqnvl6X7Vv6MOe12s9Q96+9N7u6OvXmzdZ6S
0TcBSovUePz8bSTKi+lxTzRnD87lrKA57ZFqqil5ahOg1P7M3lg/8U5err1y
u1G4nTiDkyNLH5rXxZTGyyZAaZHq+H6v2fYLhb1rR5+flI7qI3NWfH6e1FM6
7psApQ+bWcKej/d6vW+PR9NR26pY7K76fHT/ktJO2AQoLVLizm21mkb94VGd
XFw3a644vzl0B4bopKTUJkBpkVI7h5c3V5XW1L+90y6aw1JN685ndvPaTMno
mwBtBRWUWPX9zceqFfo6zREV3TvejjLA8mkqCv8e3paZQJT65DDhylSt1Zbl
8AIVmzn0gSUEghW4lF1zh6W765s7BX2dvsoMa+W/bOz6he2FhB5++umjDZ+C
t36h3jmY6IV9E4TlU+1+8sPZQUYcFRFjkQr13cASYHdHwU4M8Mj2dqwl72qb
ru1tmsf29ht4RZ/l/kW5CSEH39eyuIqf0Uw8jj2u+ssST8yysqnFV+wZB2sK
FWFSrajHMZOWPn3QsrGdGD1yAM9SDxhKwcPPXu9Sb9onyrDD3LeVqp44V4n4
B+aDVnrYB0ku2BQ/kwLLkC9TTjh226ak+KpapI43tPJBVl7YiwzbBNA0gCPE
0KI2M66kn7OmQU7YIWe1Rc5XyigG2Nh3ydIWIbWC4hOub/1Cjcb0oNvM9ras
kZGJeXK85fhUEU2fUcBFwBJw36QcQ9nwYRU2NljJKt3PJWI5W8yWiYwd4L0w
gZjK+WnRg0RA2laAM5DG4kbUDk5YU9uYhh3hXvXX/4UyEWPp3PhNCKyuRLos
ExQzlHYXS+cOkhEnsKuwllnH76pQ7qpjhmmFrzL81qf0vdd0Qn5DTcRSfWfY
saIfds6gXr0y13DiYKUUVh3Ij27KxECZh5nsGN8KivtZ+FUugBj2Uwkb4RAv
UD0+Yo17OpRcH9rlMOAeNgJXsP4Du/VT1wMigPyAfCxjMfGRA7nXJX5wjz4g
FSwudUVZfgInBBSlTlLv9A2daFzb8GU3AQUkvZTbPqgR7LNgY1+IkR2UkxtU
LSxLWtd+nIzkoiHGnLourTRgRzRxpjZ+5CQAAhNdtq8KegRhlwMpnTlzsStD
nytRQm1/kWyjFtWtZ5UD7H7C57DhXdhT8XoDyt3FniuwQJsnAc/ACNqiD3wS
vo/si9mhmM0e9IwANkJMVz/bF3aM8V2Z8ByOjH0cTeHiZnAsmh7Kdvoag9/3
jLWdDJQDWHyNcpqTXAly66vI8qxsgwFqlRKtaSMx7KsfNDKTWzzGRuE+xe5U
QQas0gc+xvlQyr9MHz4LWqOCEgJRpHSpNeoOfvBdMBO2HWgpNmA7yrVvmyBl
m74DP24F7nfXYFNl3+/zxdjeUY6xwglf48ox08BeAPuha1vDvq3s+TtKa8St
4RyQ6/gszNfuMHuGJQPw1BbxEw9oEJcxTEhh8m7/guXn/6iTATU5iRgokNax
r1H9HikUNjhc93moN9suBMnRQbMwZUOXs+UHoaQoi7+1/MJ28Cm/gKMCi4ZG
D9vdvGpdESZ8kxUXPouo4QwdNhGYtR7Iq+UcqXO9To1Nos0a/2hllN9OHeWw
Ak+5BkknLFixl4jkYcNDENg6db4h6LSrwnqfaKi1GiOEQxnqS/wQgoPfs+ZT
SrxHMNjHg3ls+SkZuhR8ilNJvhkMiU9hr3D8OEPU/gan5pvY6ia8TEUeMPq1
HdgvbmTaxvraxVrxIcGp0QcwD7WUW84dcaa9F1TvbWKccHvDWNOVD9u/ai/6
GV/t2vnje5jufFoTU2RYFn6BbcToOzxYPI0X3aD6glbefUdorvkIIiEd2UpZ
JfbdB1zHr9hsis9HDK1+bKMsiIG20GbE7whjfc8/2Lr6J38CL1ALAktXg+Iq
jxljN7ggZao6Fa7Ab5iH3c6eAqv0Hx4/kslqUAgk2/uStnc4CRGGn+dKsvUn
M3EhXPiwyedSvEpDK6ZYBsHXeQOJI/XyUfO8+UopXydsRCwGAhuPnpRyFF/N
qGhdAMIIJfmVRTfzl13LN/to2/38ZQDOBn4aOfnM8hNh8Y5VaMAskkrpSJbN
CB7rixXSdyCdAxTenOuIDC07ahMsHgfWDfoLCvpeIuqSwHB/Zeq8/kAPmdc7
JCVjH+cKaBMYseTmBR36wi1G/QqkiydZUpE94qLaLdx9McMULNZluU/QURzj
Ce5quc8uaYcZ6KNAulKZHrVxljxIvgrXBIu3SVxq3aDXpQi/4xtKeProl7eM
YXRhRyyUE2QHplwIi8G1fYe5Yzv4C5g/k9neXlc7ht8fRiTJEUDTWaKBGwOH
0mw1tjeIwps/DyPxxc6BpBnifSBdQva1rQYXXxtrhBV5vUNsSyi/NscijuRr
SIUdeIYjD9lnyVDx2jIqDXwLe0LuwAFlC44nMJaBVDz2wflow+z//v8s+AkY
jsG4vvL1hfwVt0nhyp7jw77bM5gFU/RwZTzsAX6ChYwOdqZ/ZuAnKx1gA/m+
h63XRrYJyhwuPPj0jbpjARYp/Lxk2Nr+XIxty4adAFdaIMIXyp0w5PP7sEpg
MQuDAf/TIgPG9sjCMlz/7/8HBvA8Vz66BwoImKPDDE7d/MkP6HrM7yOWoVmM
7vzSBl7zESXEIWE4R3M89XEdT3wwGMDbaI5McAlO/v63v//fv/9tDDeOsG9g
VxuBrTimEScjWGu4YAqOQI7Z2O9LioKq8j175o7FkkZtNFFgbUZEFuAoEBz7
1B8EycD7IBBtgy+IycMST9ksMRV/v91jEcMmoXjAilBqRhArpsyVGvV6qVEo
F3ohAj0JCb92Hy8S7UVFor02ybReM5BpPXvQCz7xpvdA7Gx9bEO9ZsOYb5Ry
G6GvPUSbMBLP2KM7ali52ub397fI3Io6zMJMDDTPl01XA1M+LoFpoke2BabP
mQBLSeM0zxHNsy1VLTGvBQ69cu1qI3vALYGc9cActIhGfDCgPXjKfFlTewqq
qA9bBzfEoXCEDm4aENPSF8wkPgdEPeBT2CjAch5to2PbYhRI6NgL2OU6XLrC
4n5HV/YY7CkXOdDhA0A5YLx11sYrCS/1Yth8PdGoGCOSpLuKefx30KcxcGKA
MZ5QC3ywiTKW71ca5YD2OIy7MnroxYdhp0jFnMBqj2D3LGDuezBfYBJmrZN4
5yCLTOXE7nMB8hfJccjRTSBFE5YUU6QII9xRMfGOgmbqDlqy0t4+bJYPO2Eb
wYDlpfssPUyiXsCkWfmxTxnx9iJjdvkiBSTAP8Fa93csOJNz3Ju5QrGaM4Hb
YW8Zbs41MLavwkVV8MlQxb4WTM1X1BXDk9oqrvQnyud/mrAh/7lQw77ka+Mb
iBx2PpMTlO0Fovgn8He0PF+/7HPfA/bmpJW0kQ92Otavi6BFR/bLVub/AwFC
ZSWOsAAA

-->

</rfc>
