<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-20" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake (aka Early) Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-20"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="03"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 168?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 172?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <table>
        <name>GHSAs/CVEs and finders in chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">TBA</td>
            <td align="left">Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TDQE / quote-generation path</td>
              <td align="left">AMD-SP / SNP attestation firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK / VCEK / VLEK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest OS</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake attestation under disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
            <td align="left">3 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">2</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">7 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">2</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of <em>paper</em> authors):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>?</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">IETF RATS Interim meeting</td>
                <td align="left">Virtual</td>
                <td align="left">TBA Sept, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 735?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8292XLjyJIo+K6vgGVZ306pBZLgzmyrW4fiLonaSK1p11gg
ECQhYqGwcNHJ0zYv8zY/MGYzNo9j9wfuU7+dP+kvue4eAAhQJCXkyaxTx7qr
SiDg4eHh4Vu4e4iieOBqrs6+CJ86pmvL4kQ2VWciT5nwWZ7KQkO29dWhUHVd
5riyq1mmULNMR1OZzVShLdvGyNOFz7W7hpjNZItiLleslARrJNTuej2hlCoI
AE9w2JzZsi5Y7oTZ8FPDwVe8meBaAlvOmOICMPqikirDc8UyNHN8+OlAHg5t
Nt+C3H6EPh0ossvGlr36ImjmyDo4UC3FlA2YpmrLI1fU4uDEkazpMIEDxxsa
muMAVHc1g7c7jX5TEH4RZN2xAAvNVNmMwT9M99Ox8ImpmmvZmqzjH53qCfzL
suG/bvrNTwemZwyZ/eVABUy+HCiAIzMdz/kijAAYO4BJ5Q4AsM3kL0L1plE9
WFj2dGxb3uyL0GtU+wdTtoJH6pcDQRSqHUEew6gO/rFJC3lNC/w5vhYHc2Z6
gMAvguADv2/hH3x+9zAmUFpo4U/42ABC4Ct/YUvZmOksBUuBz2VbmXwRJq47
c76k05Ef0wAOQGvuxBsChQxvIhuGrIqeIxuy6Mi2KtvpbeT+BJ/pMmIOnwWA
t36e4tBTmrUVUHr3kqYmrgEDHcieO7FspCQMKgjAITrnhk9df0DhFgcUejTg
J3rLsseyqb0SXb8I/VuhbjMHlv5YaDHbkM0VvcU4xcKJDwjzFMf8L64nqvyr
lMo+bRn/TpOVCXN0eS7UvSFbTa1tg9csm90zec5iQ+JX8l9U/hmuxbYBepY5
HlrCibcNbg/INZ7ImtDyZFOomsBaIwvmRtuqz5SJaenWeAXjp46Fc1eFf9Ym
minH0BjqHlOtsQlj/mWMz3ahUpswc7zUTKENo4234dNZ76/YELJnI4fb74/R
lq0FMwWc9U+b8ATIbkrZTCFTyOf3o3Mmr0CG2ooG427FZ6G5yiQGfQqfpBj/
5C8O/Z5SJtuAd2WQVIama7IJC2xrY8BU1bYNc9XuiJfdRqsaG2k20SyDjeWU
7ZmuZrD9U+kAyws9ZWJbynTbGI1u57xTFa5sy7UUSz8G0iqp2Hguk42/MEJ4
5r+VkgHfA5MvwRzElLAp3VK4j78QnB2Kit7YVEGHX4Q2EEQkzaO5K5SKoAp8
vQGaon/e47Mg+SyceiYT8PNjPpRsj5m7FniLxSIFLMhQDI7hg5TJ3PTMG+qa
QtNP5zPlrFSRytnBBnaI3CCO2yCGGf440MxBgNkAMCMcQqFF/xMBe1Ae3ZRw
m/LFVPyXu1QgQeLPT0X45lRWXjzm7iCvaLOZ9UfQWF/tobEv5VGnfEiLEE4/
kVLxyfrQ40PRHviCb/IHPvVqVs3q+WqZk0HQHGHu6SZYQUOdodljM11e4Tuy
MoXfNBkMIZgeWUJsNmEGGUz4KdgBjg9+C1cqc5YCJNKAww1TwF74TVN/3TAB
hPUaZItCF5mY1gF+aNze1fmrUjFfLu+bZeOi06v+U+bJvLmaYqbmgGD0bGuG
/0rT3+kN/PdNtdXuVcUaSB1HrHbi3P7jJxLl+2wujshe1vd0ADrXLJ25tpNW
EN20wxQPN1haVueaAxYnc9I0m/loPBaN+XIpGuNxafdeuF0DFYgCYFBuUiS7
SRL+mqBttTYDKqEZaIC65hr0DdEcRsa0CEb1EJUTmJoBBUHvojBiQLP6g4AS
ZKSBczCT3UmUeFJRqHpjz3F/PPXys2VOXDxnl+Jymf8HqZf7AdRTQMHKisJm
rtCYg0NjKkwA/T8RTA3UKTNm7oocDHCOXASBUtt267Iro9QF10qoduvgO9yJ
vYurP5SQdhHYcJYvi89Ze/F9hGyoY6YDt4i9FdDHcOL0vGGG5cY8HeQ1cKeQ
Wtq2HRqdeoJ5Mx8NZ4WzxsVz3N0TnzyPFfFZKczF0aI02T3xYHKCPzn4FV08
MdgsYBK5K5Gv5+bEcU5Vf89o5hvnL+oI45YCZ3iEvOOCWypU0WfUFGREf+QY
R0ig7cw9GhntNhRcYJmlNOaOSNHgg7ThjIEqspte5tj1svl83Tw9V5jMinp+
cDF+MA2n/pj+sG4mWl7Z2lwGsos2rJW+sf7Bj8JNVcSdo0xkXQdvggmGpTJB
1VTBtFwBZUyMSViwj4A9cIPgt75MilIiJ/SAjxg67B/ikgCdNMd1N4M8F1/m
Yj4HDGLnK9ndBAkAviHG2NpBiJaFyz398mejyNjaTY3S82ghFnK2Ic4mk++h
BrPmcXLATMAJZiLI4Llmu56sbyGIwmwXlAuGhBxhwWzGKWN5QJqfRIW3eO2m
yqwwmonjSn4M/zAq30UVYydVDM3U/nQkQaT2aJPKiwG6+Rl0c1Ypfgc9bFeJ
0wMEJuxSUdE1DKFtIUdofXD1C7r1xbOQND+dKnHUdhOl8GIr4rxcyovGcr78
EFE6dbFma44GT+uXnZSUSUlSvpDOlUqVbKacypXKhVy5FH1xmx9IqgR9O3oD
NVBMw9QsY+a5YNd9EZroxYPOMWV9ha9ao52e4IU1D2lVeNcbrNVqYkTNpSli
o4vOjCmipooKYfY9jiD80rVAgssjOf5DPwU2g40PbTYC3CMUzFTSvatUNiOV
UrDMWhA+8mMXYj01shwHHoioHkWG4XMxIn8/9paYyW++iFwSe6P47huV996Q
MsEbwHOvHJcReDSgfFOp1MGBKIqCPHTIyzk46AP7U6hVkDXDwQ0xsy3UJoKL
gTMQJrqgMhdsBlr7r3En9H98Tui1HtLJwdcNB28N5uNO4eGxsJho4H+RyQjz
kTnvrtEOlSLgPbEWwtER2e1HR9uj7MKIJgl7YYak0RQG5vmcmcIRmuuW5wqz
CWwBhIwCxXGOkNFs0F7MPhYcDUdC41IzPWC/TasWbDZ0JfUVMN+Lp9lMPX4X
IVlVHXjJM02G48n2CgZA72IJe/cIhsfFs5kDZr2DZw7CEOxJ2JfDFUm1ILQl
/PWv2wI/f/sbrQW+KaPeQBbZ8SqJEHgfaIO4gbgfifCdCN8JfN8CKF9AuBaG
Ca9s6w7F77EAYhZEQnWGEXExm8oIOlDWdBjZtQDXtlRP0bixfEwYTUChCEPG
0G+amtZCR/M9MiudzWGtEZMpm1g6gHd8tjY0VdXZwcEvZFAjYDo+2Tn/GZLI
ROIF6yPIM8AIcMWdQHN6ZTTsdpePrxN8MbMcWXeOAbsxiCTyCoDrFhNGZ2Pw
jxUtEHKS79U5ijUj1kSfAbWW7cKbQBPQTimhaVsGYBVoDmEGk8QTNRBJ4C2a
9CFCmQJglSmawxlYcS3bQXbD38DzBIMRlksIvHQD9oYMm8kAyWkZW547USy3
Y4grRCd+/F3Cth/jIXwMn+9npSRsQWOypQu/+09gvauwM/huIF/bhg0B3jHQ
CQcOdF90jWkVA8WnhIoPfhdpgD0rzGe4yenwf/IcnSn0VPmEYzr3h8zS5Ker
sZn68wSGB+6w4RlIFT7S+qQTf4WXEGdkb9SgljeevJmEz0cqc7SxKVgznC7R
ZR85YIf9IlyC3JtrbIE6BABxJRKjtj8WMi43S0mooeuyMfoeTuUhpeDxfrzo
VVQEYBOo/hEGPYvFZ4JTCtCHB9/AaEkJ34STzWHh2a3DkCngv6oha3+DLyT8
oEam3X/9H/+3QzBNC6X/N+FrF1Tlv2IEZK3SZC1lwFMyeghRBbjDsTxbYekZ
GnYgTwEnlPCAghjqLxHUm8toqQ8RNNKA2dIa8HeF1tOuzRjGAMy0D/CQZpXd
mFWUrMHsxDUa2R+NRpajkUM0KD0BUwgskjixgXM/euAcHziPA/eAo5lN8+fH
QCRfY+Pnf/T4eT5+gehvGfCQEx22xi9Z2i2/5OIoFH40CgWOQnEPCnkcfjPg
hU4DxdK2IrRp4BuMoUvhpIe6NeTDg43NMNPCSXdle+o5N566SgUBOjBq0YdS
lKh1m5qpo8N/BzPUDzTGDVDHdETNxfBNcUw4LGYiggOmTnsz3ZJVJ43OSVrK
pu8ZztMWqxgKc1G1wubr47di7fKi2ak3Lvqd6nmx5Q8JY9ZqscBcr9P6yMQP
QR7IqkUOKOzzZxhK+LpHim2FuUGGdCDRyPqfWUpEQhR/NHsUOXuUtrLHMbDn
8ZpHQAfudW9AJ4aIln40oiVE9K9fuJv766c3Qh3ss3hw3iHEA1t1bcJ8+tvB
wX/8x38c3LPQG5IDbQYPYOLwf+BTBtYZ/AWmPTelh+APrBXawRaFRt/uVmIe
qgGEdfDG1kbbOoKuqfqmJ6JnaK42Xqs8/F7VwISbUwpViGo0OK0xJyVceqgz
YeOBPTJnsBfhU9kVNFcw5NUBhUqACrCgQUAebBkN3oSPbAtPfmaz4LxchEmN
QNELn8FEZ7qQOwynzye1b9qyDmYtGlpgFuCZCYwKGkC3YG+qB9xcihwEoPOH
AS48XKEnoCcMAIm2Dg+7BIcu8jo6ejDiVrWqjUYM7Sb4BCaDw/Z4IMj/FMb3
J+54NgsJAqIEPDHXOQAqaGANoNHEiYtqI0Usc4BMA/p9hulrQ1BjuAi6hbYE
DhA7G3jPnEFHnaJV3BD5619jh1PojzmOB7/Be34gC9xVFTyAwDXmviH/Gj6P
u+LwfSSjj9t0XUtlOq7UJVmdwQ7qhszLAwZxWx/cWbDcRuiWIovgWhmWGrf4
cFIICUZcU3/f3LfsG3AAHdy/K/RFzDH+ilwFQ/4OMsKVfwe72JbB1gLMfSer
5rMCYMB1u+BbWsj5TfIdha/yeIxum8t+nDwKQR5SSAAeOSQhfI9Sje5dddtc
d/pPsGp0AqujGsHzasDRCObomf5fKX8BR9w9DpAgzzEwx7d4hcQDdIZFJlhU
i0UjRXEhvz3YRdxJm497NFxf4JqgRJVxZ0QOlT8j9uh2wgAL83DrOG/jXDAG
naRyX0PXrQVJzoWFCY8m5xKQCP6uD+T32pMGBwCM+RPSHcIEthoFHbwZCm71
ACziKwusgR0+P8rj8BtZVWEduZSKIsmp5ntpAtdS/tp+hIKq5UerZyibAUI8
XUEmNwu9bXwL/GFA0xf2NnPBH/Z3AR8XVve9+YDE3z7UsTD0XITFAR4dwYQ1
/A4IGg1JvafbAFHPfAYbCwPzKvKbULMx4dZBXwzFGwYP0c5AsfRNaBLm5HeJ
ohj+/8G3bdLsG2UmfxO2Zn8eC2+TMrndcspkUwT7U2NBmpDAB9gIOP6EETbl
OcIv/2j4m2fw/jj5XeNswy1LH1VS0s6PSMQGWanbQOS+H8TGIfJ7E/heQkWO
Z3/6EMya/wFjGD99DNtVfvgY/ZOqEPxzzQ/4wS5+Xdv8iJ2TploE/GDkyw/S
BmCuYh4wRfAtGyUxSCvy8x0wAsdo9P8C9qcN0pgbQiS8Xf4Az991lF9olIJ2
4UZVjykp8JslhLQ3yk4v5v3X1tFJrnHPrYV4ThZzF6xp30xCOct3rI/MQVMb
ozWa3TuY76+gHdxvNER5bILMB2UfRL1EMs0PggMgCm42MUQmgPrkPwoY1Tve
1Kqkpw155vhujn+AhNIfrAoK+VkU0qQAIB2eRTLBkAbRPKYNPyyF4h/ml4LZ
Mf4DP7oDFlgD+eD/vsVG+tgnMLy45X/C9sf7/vddn8DwR0dXwfFSl3sloE6/
4bxFRZ4R9TklgP1ctGV2zt6fefgZUmPvR3z4Wk248t+CkX1YtatboX0v/BvR
H/jQA3j/Flfp5gijNbanuMidkU9gXLF3lcZFGGm2sUBf4d+Emy48atwFrpe9
8oe/6wajRqZC8RihbpE997lfP3x/7XE4JXqYfdd9f+2Pjq49ixwUSq7imCDx
rxtCmqcNiPyEyDeWwOrcPjyfNHyEeMRi0wEJtg5/wVysFMLotTINhr9Cmww2
+9gDKMJlD5fhvCfo2tDGUwCNCqQAyS1ofOxTxJG/sYFOu9dN969iK4LRUQVX
OL4/txLh46/SaL9jGLx69ntkuG+xSBtGYWEyMNNgmRo872Rj3Lta4yx9d944
E/A0A9/DL/f8LzJ+Y2N8LKLCiGEa6CYStdb5wFuhfs8n6+HP+9Hxv4FOoLMA
2LH4JZ7GvUPS7/kkojg3NE8g3wWHqyCu/t5KeBAaG6Ic1WjfP5kM4ruCM7EW
ZuCOhLA50CHTAXFSH5HQQAzoAYUQSBaoJAuc4EQurp4iyk+xbB6FIRc3rttI
29QCxZWOLs034cYznbQOc3N4iOm3rXwj9FezN1t5+5s3gLxlmGCB00j85Gen
xvmo/vi4mtn1JqEQsP4m0h0uIPYLUvDYSHg41sjdJtqib1720oHwqfWubi5a
Pgd+I7nUqNXbje9DISY5vw+D6hnIa5Qd+C+UHv4XMZ2wBtT0JXmQ/JYOlSuu
70SD/W4rEzw3CvSpGMZcgiG7zLDslQgQ7NUslHHfhIgSDoZrg5VLw4UaxJBN
GTMiNmcYfgmTS5/Vm0I43O83javLm/6gXu1Xf498UUPbludWtAJN8U2g5PMg
OrTnf3h6KkSqZwWGWRezMMWFpE5UyJyH23AjSR73NxAgqmP9jY7iBMzyOqUg
AaZ3sQBqnQdXUcr1NQNDl4yH9PnpXXWdP2KQiQrzrIKIofKOOx4rRVnQoIgH
TZxFYw3wE4bHNVMj7luHdVkQ1qXwsOXHXQFCpiRcKu4xpcBx3oqjgBiEL0t5
mJcSeTlat+hHdL9isfI6MLk/eRtI56SL4+HLMvPwWL5/tNu57jI/vyybWdE7
Gz+m8ZiIJ4jTqEUa9atPLQx6e6ZCeEbO1dgwFYyIg8HfeIZWzGSzJamYKRTy
6egRXKTEIGXTWd847TLGz6nQa1RWgEWUCtmS0GTDCD5hmYXvm8FavQ2VCF+P
jnpBidqvQrvTamMlGwWzy4dHR/8DIfslOlHYd41toaP1SPvgFgK4xTdwqYwq
AgZjR1tDSN8J/+uaj+LLsyd/HTOlZIc5aVce80wD9NjnmVQ5JdEShGnnFLik
j7YR5wMYV6gM8HvxHVu7cS2kJHFsSalsEQZ7g/TY+k6EpcwbjGtvbJnvPIlV
GagFjMN+3VNr9qEj803Y6Zmn6+lCmbZxaXMGd+vRtkyGCou+c0b+/leRN7N7
hk0UtqdQP64oz+910G+AHbsB/U3OwRuhsCW+uYcB8sEee8Oy74ud7Nv9W7vp
9Du16rkPvwI7y2ewoDAr0Qi5f2iEtaIN1WX8vDGqtKLqUt7Qk6h00SfVguxF
Cs3jIQP/C6Uonn3IJmYfcu2vrMBeBv1jIeqCxU19Zd3EIxZHo2Ob3++ZPG3L
zuT3Y/7f9fbvVAr3+4msNjjr/p4Cp6iP6ZOY6RkzNshTsRx2LGgpljr2Yfbo
VJqg0tT8BwCaz1TXQWhYauAUOUGyo8wbadCRROPWL4s9aGAOMpNN4dYE3v1X
R/hKP7yTrzyxDDYDC+2QiBTBWV/Flv6tdqA5hE1W6LA9XBmYbaQSM0gQxBMU
8GRkW3OA5vQ9P/q7ix/0787xF841F40u4ArkoF/AaxSVOewnB3wo+BB4IWRH
QGAo45EljPUVKNEXDObamhIRZyYQBOjhpsbWPI3Yiv4raQR6SL5X3IjjWjk8
8/kajPZhmJvHQ77p9nUBNqgrzyg0GjFoIk/BpgbRET7CTB9u1SJGn79SwC2e
YqThIy42/cQieJr2sBImrPMQFXjO7HTUoErTh2L4SvQ35IECCEYxWxYzGYn6
m/iJ8tVuPT6+bKi8pNFMB1mETprnkboh9PQQ9ARmW6XhddEZirlMPhOCXQ+M
pKPMsgs8GCaa9RuNDXqB9RalFSUkblDqDZD6gwoO/xqGqqdkxSD7UbW0dFi1
UiyUi/l8CvR2JpvLUBLTH0jzPNI8E6U55kEWKJSy4DPpubLOvAh7LxVZ9FV4
pIONw18L/j3wHJAJS7BZfDoFZRMFsZAvZCofL5vwP0AY+VQGj1iYqnkGR+4E
JOq0We3130NviC+OsOg1/K+BJU91YLFtOBalSimbBEf84BAxzG5iKKs31e4a
1FAGrW+gjPT/C8f+9gPZXCrwlcSEytwfSC4pKbkkQrGygWJTHoJYmzL1PRRH
wYvr/9rPdFLmAxjCw8gHWzHcduwUh/wHdlQ5FPYmAuD3MbNoU1Py3Pr5W00Z
CzopoabUQ00ZRDmVNcQwcooJgGtFfnQEyIARg+7KzlM7jLXwsk3KNdvsWYEp
IAaNK6yY6w/KwvJFbKMUptJvx5yiY/zUFfPrwrKBSCnJgmH+nAuTNHlROj4E
1uARYDKMsNyJGr0dHDQ9288witcToMWjr1FbR2hnlhtYHng6i+TYlynyebO0
YW27HlLivm8thKYJ6B/qzcaT2hrbckYqlFxRg9fpmA1MaIE/luKPczA6ktE2
eGhMxZCVhYlDPBO2nCqF3OXDiDKckPUf5dePSsLngrAXaDEmrwjGmnEb63Z6
H6DdJsEEn1sxT9TGKDlY/gYmP68ETMsziPGAbNzgOyZ2G2mY24O9qMZ41k0/
pbgljjDgM7Ck+UA284Pqv0R9wU78WODgoAqsBT6+u8EXbzJybRbJDIOlFn9a
VcWXbcIDt8g20/y9oALi+TYrfX/zDcIgcWTr+EejnSyvf1szjfVEvsMbJ8r9
mXPrv/whIR1cwaOjINRydARkCWNdfveMnxAGxNR1nsHte2OUXJI4pIbIajZH
dmwlRPTj8b8fhe1BZySsLI+EjUxnKgjZXPkWwd4Uxpi8OhZmhLiA3W88R8BJ
C47F1fiCCgEEZcKUKS3vtrzwN2nhaIJw7WlsytSgDZ/Qi5bUObtEa5DzE6/A
4yGPvXM8wgSHow1RjEh9XPCQ4H6nGqQCrwnOyhhaOs9Q2iys+PePxBKPjsJo
IphZ8shlYZDqDQq7Mm0jaOB8PpN+AH9RFWfMFCnkcehbU7Kf9rqtDuSzZWtj
VJy4vmhaoaYWM3keekLGxbNpHfnDgufFwwNsTlDF82qqsb1vUR6upmgzrHCe
WejAqoLluSGfYTUA564h8GoSTRDkgMtk4fHV3NQ9BHidsR55c2dnozdfUbgw
R9ntzEaiKKMUAKCwkmXbsJtlzOE85J+569rRMNsZl8oZrVJEHSpUjhMGC/6p
Ah8bWa7COtqtJRZYNIDdATSXG8JkL4NN5gpzWfdo3wfVA0FhNk+i9g1bHq/c
X8tME4kYvbAkHPcqpUdxQOBJgpdAFo9v5Qfp4HzSR0eqZoP+0jGNGp5TvJ2n
roNc2pHbHdCOD3d0dLujVQAOorkO00fRonIF6zptM9wlG/0i3tudNCYaNGQ/
RpccKw08O3QK6MXtXQz2IwbSLyhBofxIB/P1620hRgvh8+/j5er3QxC/WFjh
bPw6ZO4CU/SVdSkIr9fBBP92KP6C0iU8hv/8+8R1lAAi7uHIOT02kwi/MnBC
Y+Yc5FJCdV0ItQFN3gstUkCFjVTkg4MrvtUdxoIE0/05nwjT79FBGqMX0PGK
LwhKnc81TIjR+TAt3IKH62hvuC2Fv2H5UhC1J/fTr5uRsUtXvxc0f7Ej3Tfc
1Ywcp51+c4rqLKIIwGwakZZVMi5qjy9bz1/UlnSIK7Tnq0i18nod+z7lz5Dy
rewhrszHYETXLw4ld7htTXKJ1qSLoveG9+pA1ViNVgNt68Pgt+aI5zFtOkvv
lFu8VeAxgzUFeGzUWk+YPnPCEj+eqyEF+OH7mA8RFi6ty+W3fZeNftfh1SV7
6gn9msH3iuKoTlAIWrJE6lDAV/WM2Tqd+CqQRnv/921d3Cb8Ih1nj/PHxfjD
3HHhGP39q7ezRr/9iyjuHyE2mP928B/hv7H6RRK+7GNVknLwxX/9v/+XD+y/
/p//M/4fCCX7DpSpMtmAwv8rDiX3LpTfhR1Q/P+I5RZqZtCnBkMRm3uplJKI
3/0E98JHNxZJz4CVMZE+DJOEG21/i4dIY4f1t0FDne2HSnu7P/ysFg3pn9oA
Iq1b45S7dD/eCOKnNYGITvQnQI9NdHuriZ/WZiI6tZ8APTa1vc0sfloji+gM
fwL02Azfa5fx01plRCf5E6DHJvluQ46f1fAh/VPbScQn+aG2Ej+tY0R0pj8B
emym5VTUioBhg75hP27cACKf1k+EH5nYllOKiK7/hQ4CwtATLG6TK2KHNPau
H3kjcbynxw+MgAl5j13hdLIVZ7sLmck+PMYIwQSdlq/8Hpl4AGg5kyMhSXS6
sCBhyux1Tq1qKeldn6YPj/223nHLNWLu9qP99xxvDD6i67v94OSjIzpZDW1N
XfeOwzOn2CbYawRj+4CdNDj8aH05DxVtdf3JWgfrek//wfeQjNro2CjEXK09
/CEz2UiLH2X+sxc1hRzm97SLR4WPjtaN+HyvAqZPq/lmGaOMQW+8N62g24j/
EXJPFXuLGLAlYAZ+ej7GUyIxSv+0lbdVWTdb9PsrbI36/gCesBkV4sVdyngA
kohIHRwpzokVORSXkz/WNkLM5GM4vIuuH3/ikbtgkeAPy2ZGeIodj9xSSC/1
QfFzXj1rcPHTw1t5ZPJ+YebYx0eB4ejN7SQXvup4ZZUtf5gr8ZHof5Q+/CiK
6IIQhu+H29/e5fA2gIynvLI5pdgq56ggQZeWdZ26+35sHnl5S5P/I55zeUTA
1zsDccN6UBXbdtiW5wRdVQFNZP8wE/IYm/Fg98B18sJEG0+oFAnPqdVIluX3
JHcIn9E19UPW60zIv/0NlwSb/LS0ud8JA8fl7SMVP39gfXHOxtDHeB4Ewp86
tKgHfvSbRRIBCA7uMAyk49/vCNjuba9/4NljniZhYN7JXjHqdyh6j6mo3ClL
/zzY24d0H24UzDcwX0QF84KyV2XqlEqt1vwmVeEFeBQi64ede3n6MrcQ+pal
Y1DSw4jBZkOsUCKGCMb60ApfA9G43oIaY9RXysYCGsaCHehRwmClDJugkDsM
WmhtbOh1BxveQTLeNIlnBMXODQBpfiDydaQtkRuBfD4gVQv+kNf3QCQ9uv5Q
E+2I/YaFqXIacDnkRwsWRfMYCFHPEaiMjveUQUrbLk/bAZyQrUZAI9xyGz1o
3onWBacUCDtF9LF9MczCc5BFJOKMbceQaYBweAUltjrC1s0khajHTnhqQ2Ap
/0AbetGKKdxgnumf/YTN1P6EK+CTGk8XMRP/GEnD8+1hp+C0A9TBQGdbsKUV
jLWTOA7DxpHWb5TK/FbMH2LbMB7D5zztc0G4gRTL09UgF4iajPl9sfnx5to+
cTaXJ8U7whpBMzFlYmkK8/uzodGngybna08NtsMmTlvmiIt2zMVsKFjjHLgg
PHlCkm+gvNu+9sLChvWBRg9K7f50HLJ9j5Ii4fLFBEV71TvjJ9RrVZricjvG
G18ODv47dfoIlwXtBimVO45twBBGJNO/ro1GGhPbTNfxukDkK8GvDRlhbSQI
PY3pqoO1G/CONsOGIyCP54w6YvsF4/xw7nOjdlhvN/xGf1hPwBQZZfuC296e
GbO8eeQK+G3daXlDJNubdU48KLzOnyTu2kIklN73Ew0Fkesz0RBsf40bHJy+
Wz7jJtFbKRYe1vgR89n67A3bK2q8YUwoDEFB0t4KXCtt3Rke8AlZNN5tL1wl
3jTZITI5/gGdh+253JAuJlpvQPDg3DP+M1pPM98eBrR8VkhhQr+i000AvNBY
pYRWcOKCNtRgOo09O+zaAupvfch4EDlv3NfADkEHDa2pnzW/dSD+aaRJDj8l
KL/pniPgoiMixNtgIzBjNpEd7TWaIRHZw5SBE2ughoxmg3E75idIJDw9Ls+w
jRwulBNDl/pv83mvzZV4OcsNpUUcrH+OJyTwrIl483DuHG0lVgpPzvDl4A4T
8jfWGdX4baN3edOp9agMjHD7ZbP65yA8Z9nfOyjSvPvt9Q+0kcLmDZyGeNKt
sLCR92Z3UY5MN2xNGuDxXg+jvXisrTD/PC4EzxcmPNU5qMb6VH6A3jv7tp/z
vu38KJepmizUUAyC9RqeoptssS6WQguQXgMsR/xmGQwOIIdhSfSYBe5UoKV3
ZIH5BvOGYUN6gTtPtvGOl5CiDFqUIzdsrOHRfTxdnzoI8h94Mm1QXIHclM6U
0pl8OuoxiaHH5IjUkkMMT9REzRGHtjVlJhnooMJEQ16JIOZEtoQR0oVssZgp
FA8Bo8+n8kw2YZ0Pha8nOnBSW3YvgIJ9a7qKlKkO8SfYy0jclIu/pf0MSSct
SZWKVCBgAc11cB09TMgAqG1ys00rqpYn4TOaaywZcyGDo+fNiKdE1xKHjGah
YytqPlG6Mwj2v6iBq+6YGEUiVQ5SbGKp8DXYbCL8P6L0FdMJMFCpKrFEWv+B
k8K0D37XNhsHTxMilNZUqVgpF6RSMZ/7TftVymQypVKxmM1ly0Tkr9GGAmFW
CJI50lEA+6XCjsP1p2YCURTiCV9+eYhvQqYPfca6YEu3xUwUeLxnR4TDUOnA
z+jkMez3RD/TrGee7rB06DWPdHkhrq1WUTPF7VwXCzKEnhjhUocdvAqmeUNZ
6dHQC/wYMLefso54rMuL4tMTY4QgvcGRnGgurA2WusISipTHLcoap0avhk2A
dDW+xRxlgQ9puKGtsdHODWVTsGTrFGkrocgQR8iFpIo42WjkjCRce7LpekZ0
81hjJ0V1rWhT4fKmvGk6I4n+q2LHVHCJIheso+IUFfhVnDI2E3GugIGhOQzm
vNqxJg6njN9wlbgUI12iQ4upjU2XvkRFzG1g2rQ3HshF2TzEik+fNc/l4Qbp
/F9AbqdsL41iIF0o5Qv5Qmo2mREYfm87QKHpglCJQwieUinSXpbSmO3BH3yp
wY0BUcERxcvCuaTqaWYkmoc1EqbCUuBjyinFTCOLk9gUMyURxCZXWMDK2shR
lm6lUgDOklIqL1HDVUMq5YfaazxCiE+4fMKURyy6BKtYHIHfJYuwFjOUASBd
8eoQWQQzdceqbBC50wcybxRWukDfkK6a4+hMtbB0QtdEU3Ym8K8pbdAJc6be
yhO9lfw61wyMMM1jG2SDTo7xqhpRoee4KXrGt35aLmctvVLJbNIXk2ajwgmR
5M/oQ0KTUzWdT4OgkzLZbEjNCBxtxMxxJOaTogc82z9d9m5Hq8xV13hp8EXw
xmPZ9Bx5Y9zgMccZprCLfVAcWDoTZ3itOypBri5wG1DaJGlA/EvRLQ/ItbDE
FXjADkayfBXC76qLo7O7Y8MM34E30uG7FDqOOJFbZRk/HMIxnJmludGyVoc6
rXuczH7fdawIrGQLFamaKQBHn9TEQkYqiCfVXF08kXL50kmuUC+W8wRRl+dL
Ib54tGz4PDXxAlZOb0hVfkKGJzCg5UCOiliFJmLa8W4NwGdgTbwNUQFP+K5J
S5l8oVwsVHL5gZTNZjL5jMSNjit0BWg3EHKq5sbKzMNnKc3mzLZLCcQ1P4jU
yqiYzUpitqjIYilbyYkVxipioVAoDXNKZlgelTe247nWvRLuri7Ww+vgyM5n
3DIJ9mTcIAiUjt9Ih6OCy+wLE9BwKZXNN5QePiL+ddLTTvHKuni9WtIHoBSA
uBEq0t8pirLIWgqEGeEQrBLQTsRQUFwzIg4OVxtUQbhTb/vGIvrVNHoL06RZ
ZBHVYWqMZanMSzuYoU2Xhfz24jF79Wucn+l7tE1SeuT7eGsERbMVHX6nx+l4
9OuXED5BUgAnWwcjOGoqRh7SimTzmXJp83w8pqkXYOuIGL1cV5xjFNxEC1k2
wXyDd+3wN24kms8g2kPTbKMGmn6kgmTsovSG6mLYipZgBeU0EbHrPyG7jmD4
J9QxtMGyRNmEUP07MLktMwJhYgIRIvrOf0KqVNXwTDtdLG2IXsVRzbgJksJH
9M2CaUvNHOSzuVJRqmTTWPI6tuzVQMplKkWwXNea0QKl6tIyRSYUeRi0A9jG
aZwluUzx2c7WnClXUn3PnmrOBDCd+I3VwHrQ5KiPEHlMw0zkIXYWwEI3DbZ9
nP934KApIL9e5ZU2Eqeyrq0sm1NVng6j9jH9yf2uiK2kmRF1AfoEuEfTdW+9
NrIKfoYivFWW/AeRSzKWXoBOB78VDLMRaC8CB9Yu+koMHEmZAWFgGrh3KeBP
f4OqHNsAR8ZbEhxqEyGOGVjw6WKlWJHypQJn3U7X010NnJhoUabhP+NqyhdT
zIQNo4RlmNSEGVw0fttAYPrdrKXM2odWsDk8Bf2C1yLCaJ0PECt7OuaO9Tpy
GAQD6dYO7g53waSRMb4nT+P0Q80DQ5qhznfSBn93Jk8Hu6xfPB584wxjrHyO
QqCUL1XyUqGQK5VzReD8TDEvvojVPF/KG0u1tbElnNhAI+tdbGx7SC8OwCri
wia43YTLYHLnkWdMS0TygEqlegjColDOgj7MFYtFQKeQFR8y1QLH4gRP065s
cNY2m29swWEIL4MOopfFfL4g5aXswOI8i5XFLlk2u4ylNTb5SkkqZyt5cFrz
+Yy4GGm5wKm0bFgy8FmBqCO2ByEwdRx6J83TakKqp8FaTnMW4w7C6l8d4aTX
OThY/9lkKnHZJeb682KtrQ7z5xOMBzmy4Qqjv/+nLfTQILYnDE+hTazViX7m
8IDVlDf/2WA+oSbb4CwIbU13j7F1kkcpJVh7CybZlDl4vsqDeoDrMXylq3+2
4M0XfgZeq8XTV/yiLb8hQdj/kR8pg7IAcaMLESHnH0bjP8IWUhj0wtg1xZox
rg3LEtnm4e2NfrvIA94Ik/oqMldJHfMwH+adUMcEHhfk+TO1mj8g4G2zEcbf
MHdla0ckfoy22YTBD/AzvxHtOo8cGw7UKDLIYw783BpBYy9bhYWPdwY8w3tE
ZgwsBB6c8C+JSRT3pXyQdOem3wwlaKxszo+chm/5iToRHnUjN8oOVxu9q8IL
K4M6uuDqWQqsI9LBL2g8+XeMBtHaKB407HbYfig0goOfH+GD1mwBWwlHT9k5
AjIvUfMlD1399PZgaFuMOoZmUNDFjz/48QIyEGCwED4fHbGlontoQh0dxd+H
74+oavQoSJc55L0LPta5E/Ob0ielplR/HtjPTrmTORvnVrVZ7kaeZR5YI/3R
FqDvAjpMiJTcuKuot03LrV6/tk11ms29nCiLk35OdpIhtQ9QUqRy7XmmITmj
B2e+OnH1YnX8WH4We+22tkiG1D5ASZEqnJ8WtYoztwxzMltdte+v2HO3NOoa
D9fJkNoHKClSd4PHl9btY27UWMjNxWI1qlbqzmTWZm4mGVL7ACVF6rQ5UBZG
u90Y2qeD+8JdcdVg7v29qWn5ZEjtA5QUqatB7bG/UsaZs1ZJGZ7JXrMqTu/G
D9lnKxlS+wAlRerp9Pn0Yfa4eCqYtTvjdXCfb54VH7Rm4zEhpfYBSopU3rFy
58v25eVDuyctzPnEs9j9/ZjV2tNkSO0DlBSp6+KpoRTK84wi6fW7nPfcecxU
HwbWqFVNhtQ+QEmRMvNdVri+qs0Xk6XSODXVe3a1Au9TsRLy1D5ASZEaspvX
i4v5oquNpjej06vRkiktqz3r1xNK9H2AEiCljOCv28JjW61I+uOz9lLru5WT
p9Vd/aLJbmfdDyP1LqDEuq9Zs/In3Zt673Zlzi8q1etT2b16Nh/kcULdtwdQ
UqQWw8GjU+k+qRWvYnWzJ1Ox7M5Lo/lDKyFS+wAlRcqal0diSXk6OyvcPIld
41kpdiZ3vROxmVAk7AOUFKmsd+vJdam+Gj9f1Lv5Vn8g2o/DRV87TYjUPkBJ
kZqd5Cry8EK6ttv5QbXfHTRK5fnyqu8tEyK1D1Bi3bc8qy27bSb2qtpNxZtc
Xuq6fZY3bqsJ1cw+QEmR6ktLb3Z7snh5bJz02rX+w7jXfnhy1ZfXcjKk9gFK
itTkZpEvNhdj407VKqOXJyM7ej4b6uagk1DN7AOUFKnbVmnVGEx146a3vFhl
2w/F0avXtMz688eF57uAEu++yYx1dJU1R42iVXkpnlfupm4mU62dJaTUPkBJ
kRorWe05Mx9abNIbiHMpI/YuHH0pP9USmsP7ACUWnpd5ozp6KbRPn2ZuvX5h
90y19FpXH6SEjL4PUFKkHrxTZbBqnF7Vuh3vUZlnL7ulh7o1vqndJkNqH6DE
9tRdWzeHzU5jIipX16zr1e8uX5aFx/l9QhdrH6CkSC3vbnO10svtpTlWtFnp
JP90Weie3vYrDwkV8j5ASZGSxjXlaiGWLqxZ/eb19eS1mlObnbGVu0lo5O0D
lBQptyxbw9eTXCmv32vnr/adfXnzWJq2HlcJl28foKRIGbnb1Unx4fz6dSl7
CntuDKzylZmXvF4nGVL7ACWWUy/tF2U4PJvLA6vVEJ8b9Scvm8+NR2JChbwP
UGIXq16+PpHu785F17qw5q3rbH9arBsGayRUM/sAJUVq/nCRnWmjp0LrQalJ
y/NFb3ReM2+V5m3CoNk+QEmR6raaD5o5LBceevL59OX5pDExTp5qpSslIU/t
A5QUqWenctfJX52UV4/GZJy9HMpPJ5KczY7OE/LUPkBJkcrcvF7evD4M7lT9
sXB7Pejed43lk27azwnl1D5ASZG6z3Xb0gk4a0NDur+9WrautYncUaTXfkIb
fR+gxPbUQG6tdKPZts6Nl4vSyYnyeGe1RfsisTezB1BSpEq9x553Us6dGXbl
pTaU7qRmJW9W7nO5hFbCPkCJeap3PxpnHy8a1Uv39Lr05IykpZ6/FKuXCaMu
+wAlVsjG6GIhDhflM0c9Hep5Rz6vVJqveY0pCRXyHkCJo8MrbdQqv14V5IVl
Dwc96eKm0mzcNh7uk0aH9wBKilTtcTHvlgqvRbvfUbPV3NPT/OnUaC8vtYT2
1D5ACZDyRgb8ma0sm08PhVre6rWms6fq/KE/KD2e32fvPr5+70NKSitPai8f
7yvK6ehupuVqo8pLpsgmi9ljK6H22wcoKVK91qCayUhFWTzrmg/Vacvt3i6t
6ZPxnJDV9wFKfGS0KImX99la9c7OiNcnr5USq3aXJwOzm1Al7wOU2HE3V0NF
Hs2vs3WxM7kd9e+y2fL9dfNiktBH3gcoKVK2cXfBmsNneZkt6jnJLMw0t91Z
Xl5PEyqafYCSIlUfT07VVm7lDK+aZ91rVlZeX0VX6XRfEkqqfYASU+rpXFY0
NbswG658uugNtU5n5Ob6mWZCntoHKClSg2nj5LJ+4fTvn8eyOiwsTf25XFTn
EyWhRbUPUFKkXq5yD7VMV7abzWqu1x2ezO7vT91ltXaRkNH3AUqK1HT6fD3R
8qv56UCrLh7tq4Wk2M2JaIgJeWofoMT+zMlUPXPPXvtuvlmR7mb26KxjqmOj
n01ovOwDlBSptucNqk1Pkk76tro8y3XKE2ORfX6elRM67vsAJQ+bmZq1nJ4M
BtdPnfmkaRZM+b743Hl4TWgn7AOUFCnt3qnVqnr58UmcXfarJUe7uG05I11r
J6TUPkBJkRLbravbm0Jt7t3dK5fVca6k9JYLq9o3EjL6PkBJkTo3zx8bpWHr
+tKoLe8eXoqOq126ZwtFSiin9gFKzFODYed0cqme5J+lccZUXpdXT4vmg1uz
koZi9wBKfOawyr/cXZ9et27KWXHoTK8Ht61OUWO69JjwzGEPoMT21GnOGTw2
zVGlc10u9edZRXrJj3LF5VlCRt8HKHFiyf1Z9/FRemxJjazWG7RX13m7blw6
9VbCvKB9gBJbCWeSWe+xRXV4dz5YsMtZpTw1H5+UcTEho+8DlDjE8ey9Zkad
57L7/Ggpt4b29PSg9BaLZjshpfYBSuw4PGp3+bOnCzubsVnxetoyVve93OzK
ZQmthH2AEqfgPI6XhqQN3eIsr56Xlk3p8ULVMw+9WUJvZh+gpEgVz8/Gl7Ns
9vFm2eo/DkVNPFlq3dZr9z5hLG8foEO/fB9bqlzj9fD8IqcOdaex3WNhBICp
YZXwEvzMczspmdWWNYcn325e3wAfUGGzTdeWYYMT7LRA+ZL32Lhhe789v9Xe
Z16DI/zb3g6I2HhOU4ML1T7ag8//6jdq94apu9hgSDM9aowTbWvkBDnO1NUD
CyKpQRX25HCOBWxZBK8cHUXak292Tjw6onkcHe3A69kDgo40pv4m3AaQ/Vvr
TCbi9b2x17Ht4HDdTgDzZi3quhh5x8b6dUEzqDOBy7A2gm5LqVnY4ZFeacC7
1DqNkqr7MMoX6tP9lXKmMZt5o4I0ylXADWlN9XvZ+W1FgcdEvmBzvO8IliGT
pyof7JlA9UdFMXuYClbez7MO2kNiDx6aBnCENjapO5vD6Wdv6SsXNJbb7Cz3
mWpEADa2CsSbin1q+YWOTD38jXo/qn6nwqMjXo/JU635eOvxqR0HXeKCi4A9
WTyDssZ5N6VN2NiJDFuY/FQi5lPZVJ7I2AbeC0pCqL8OLbqf2k3bCnAG0pj+
NczY3EUz55Y+D5p0vrlr5DcfLPV0kwWizQrftoGHqEmYjH32x4z3qcCiOX6r
nHDV6dR5enat3bkawB+/UZ56pNgHb7fBrgBI43X6+gElZUeKffxU9RnsUGzK
oeJlS/59ekHS+Zv87+0J3+91h+K3HGqRQpAFtpYaBi2uqAc6z0Sf2VjhizVp
/FpcnjbOs/TjN3HU/M494WV4ADFoYhZ0nyO+omY7iDXKh0AKfkhiwIAneMGC
gNWGeAsKtTQiAjBTxf6N63z22OUxXG6EF3XTTXA+o1ArsvW9WAGgMLGe7qTY
0/7NsXSPtwoSQGtwHeCBSjrmV3fDjrH8Nih4FRYVp9nItlvuBCQZq2tTRq0O
Ny62QDRxphZe1+QDgYmuO0j6jfmwhRGX9Ex2sOXSkAlhucVwFe8iGvZbSQkN
bFPGliA8HFR5kWo0quzA5miwQPsnAe/ACMpqCHwSfI/si7UDWOvkN4QCNkJM
Ny/WPF53J6JymGBkbNNraA5uBtuk6aGeoFtuvKGrb23JIzRg8RWqeIlzJcjA
z/wydSKEN6MyHNpIeHF60AeUi4sIGwX7FFtC+vURwhD4GOdDBWG8uKTrt5wG
hQZiTehRy+ljsC9sTTZg24HGk0fysdD3LAMkdtWz4Y87Dfe7o8tzoe4N2Wpq
HQunWE+LnzHhVFbA9gBbpGeZ46ElnHjHQm3CzPESkGt7MsrltmwtsJjMwj/O
5JUsNGxFA57BsR0Hu8BpsokleNp4ghWynNgdbHbWUya2pUwPiQeZT7eoXJI1
LoDe7dWzvgCVuvZQ17OQ6XxtEbnW7nskV9B6d9s9cztbDPnlNn5Xz33tSNc3
y3HxF/1qfdmof+umz4W+RUWjB73s3vRtCkqIyIoM3kXUcIa2PNOwDsqXces5
0i0iKnU6Czd49CrasGKKGsFitbnQB+mombBiryHJgx7BIORVaoVH0GknBhWk
4VBbtUwAh2qe1vghBBtvqWdzKuVCMNjESnbl9bVe9Mi/YFeIf+kPiW/hvQ14
UU7YDw+n5hnY+y54TGWDMDrdghJof7y0BUvE1z3F77Yvf9Xf2JE3QHLUUTk4
B33LN8mc0FqP9LSNNOXFNaTGWcCPVGa+JieSgUSAX7K+jxflNTIREU+aarOJ
9bYWx8cf7Bx9vLfTNQhmB90BukhWpxvNnLCvF6MCyqDXpklWpY2FiyHHIOvJ
waWME5luN8OWH/gwgENr6LwjMrfci8plU2AppYTIbTpIvs/YE5ItJzL6D9ic
XqN1O6TWwzbv8stbG68f+C23ifrcBA3eCf6EN6gGjriUdCrafqR4p5ur9oE7
G5E+QSPptTzh1khEko78S6b9LbZhwXAMsdQdO02Tq3oTTilsyxaZ9t/wNiBU
5W66jdbEN+GOmR5eaFOHFfyMFzGvNw/e2CCCzt75T7wN/Rx8wyWsAN087URr
PrEmM9LaY6aksNUpGIr0r3Q2Q1c0XNny2IOtU3vF7lgyPCmIJeFSAX2GAOBv
R0cv9lhAtCw+aKuab7UFKY9tLXVG1zh3OU/G3YqxnB9PyK/gY+IX4ox/QaOD
izuWZ2hLfROyZTBWZ66YfW/0aNFppH8MMKyTGlvW2K/9V7UU6D+Qc7KU0tw0
cyxbUxwqS8ahb8C8PxY6LohqvEM7L0p8/I2RaUhqck6Xz3VM2GiaEWxBXEDN
dj26tLt/Ut0GIYb7TeeyL/Q8A7bXJv70EASB5YoWb5gR4tqCFcWW78dCE0vv
iVpingZjuO7hiF+D5ojvw6VuHKA9QcHZzo67OA6Pt82hjgok9CvusZVozwU9
Ygif67373uEuHsAIy8ChN9O8OVdQK34o+O1Lv7Z0awjEBOdEo4niNm3B5A1Y
OpIQbdBXwHafiQV3DnUYW5hsHvTLeE0kPqf4t4FBheXa1CkkUumczku5QrFS
KBUGeJm6GNzsO9hQZgPNHDTJxh+0Os1BnaHHPoApDPw7C9VB/7w32Hb/w6Z2
AMp/JZKvsfScTHbBhqlXyzJSHjbFUdLkJqdvq2auLKlMk0W5e2E8t9qT7svS
UhSprayapalzrsuMnbHR8jI/7NWyRvvqdXF1ffXYYlnVfLpJvY509lgzDBf2
kDW46PHbYmKl6dWOcMU1fw9dZX+7C38RvtLmkKKsHIso+DslLfm8fKcx0wSr
ugrawSaBk5WEUw97xQbrgwbDR0OIABbJBkqfOWlLHauDpTF5vn7Qbgby+aP6
4t7N66esmUde/p6Fz1QK+axUGQS35gxuWoMoYQZhzT5f6DG1uB1UO5yGdHfM
TyHS5ly2XuwQhYvhEIClO2n+qQgPOfcFPXnWHXDRuqQ7ScRMJjVTR1vYcWV5
rpcasnRzWGi/TiRjJjV+c3/NS+UKn3o4ZwH7YGK3bviP2WwltMGAi9BBm2pr
hJkZwxm7Zcqg1k36L4SxgzqZKHWQPO3gy+BW9qQj/rLRwIyuYSgVxA33B/sn
IHUQt39kUpv7LWSrn7ft3tDsu/fdXeXk7Ol0UG9Nn65U3Xw+kW/ZSvcmw5fr
f9K+a1vuTbP2Q+gkVTbp9GO23sRy7ZFCHa9kUSrsbDZqqqLfvCTWzTKT2bsp
6+37G+15eeZYsClz2XJh26YkLnyHMCG3OmnCOmTej1Lrj96JP2h1gtFpgdRt
g210o31nRVo3Lyu73mmMGwtYESmXzxz6tuVV60/NpxqbjX0uzWwlejI6jMsv
A0+qzB9ep6gu8pm8z5loSDoTaxYnQLR/mGPKysQVVRAd2CVQZXgb3NgGw9Vv
ySmbjgZv7OrKJhUKuA+A2HUOQugpGvlKF3Qfe9wgf390xjdBAAxEahGWAO/R
CJdgQy38nAkR+S49F55uzMGih6KqIuwNXAtRXN+gGvuSNu7UxRZX2H/Sb16P
TeL2dSMEuRwXajIX0qIMVi9FnJy0j/wO1bfVUeJeLDbh8pYj6odNcTnk5V0N
vwgMjPV5fRHEcCWcwjKAp4F+M/missndK2wBfSzc9qpIpZwI3kOcUHj8tdkG
6x1tJpUL4EKUBz2MS4Fvpb3SLwNrFHMNtlMjjH7WwpDuG287OnMl/ML3hYDh
a9h5T7iQKSCzJnAzpF98OoqpjLDtY9yPymWE6szW9D0i5kO0yFfylezgBnkJ
p4+8hK7TRmuqQXWvO/TWDcq5k6eJc6OJJ0+n52Lr5dlctF4nJc0c6q531tFn
d88vXf1+Vry/Ubv9p2LxqTwTy4/PsswuR8PJQ6pmtYuPJ95UPvPkzHjqYsid
n11qBmJizIRM5ku29CWT4XdUd5p49wTqNLoth+7D+EsQHiFSBSfbW2TLZnBE
xvdxw+D7Yuj7d/GCIXB6j4WabMqqLHye8wXBH6VSbEW+b0GyUq5YlDKDPnYV
Q0vLf33QMGEoy8SQ16B/0xhczpg56HngJO4T8Gd2xVrOpJFqZlDRZco5fJtf
OrGLAuH1V7L9hgqir6FEDiIQGRewP3srAzajhoFoE00+oW/NMFDgh3cD6W6N
Ip304LWeBTttI/piOeLcIlyoW3karDN4trEBpOImubfEW3ZAogXlcZVtVkrk
My4b0yMN+27zZt55+ncmLxUHHP9/yWb+JVuW/iVb2eGefQQNTsirRl+sXV7w
Hm7SF0EqYFiPN84UGkHjTP+yETwfQZ6e8zDoerwRuI/MTY011BcYXjZhw8C+
Q8uigFG/7Z04CSDvzG7ytJlvwpls647tTUDk+p0SifTiD2F2lD6FTJbiNOBF
VP2jmjeS+Ph75Xy2lCu/B30AMu6NLgAJCEw7QDvQX5lWv9vkYc4vQtU0kQcD
B9A/nrtvCZ/4WPALNYJG3g+Y/dMa97FrjCj2mXL4pnBQYxB7+CbHb3hzxa+M
VuDcexV7eOwG//TmzLOjgce8CMTvyvY/qgUKuZJUSKYFuJvcvIkazIV3DWZ+
Y3ZvwsxX+H88nMUGmDExWnlnQu9YzoVtljN4dCM7aOYfmEz7bePO6Gw8vCzl
z908iM5ippDfGkX62JQ/08jvTr30U6ZOcaWwCXVwIPrO9CcPJbAQG9OLErpI
xVLRnz1GPow3kY8fsvD/OCdncvlSPlfK7Y5UBDEJusj1D8b/+1aPLoD1G8yH
a2eN1m2nmYo9nvev5unr6Hw2NCd6poohCEkq7QjN/BBCFH4KIWIxGp8g4fH7
OjuK/7XbE9pPqEv30ipdWGPNQbbPFaTAIw7o832xmsJGrGYv+fLiGwp+X9ym
EInb/Ghv8TuiO7vWdSO6kwjT/atZzFYL5Ze2VOl2YDWz2VIm8OreHqRH9PPO
2xo3LNCM0GTDPXweAbT9TM8HH1jVDh4EDjHYa0ZIFeRJUZoUz5LimtpX1C1w
BMgizUr8fODf3xAEGZSIMuTHsQvZVSa/zX/V1JfFMDNp6hPnv2FmwK9X58Zo
enuq5Cped/LkXLSM2VJ8qYtezbpedcd6Z/bf0I0oSk50W2w7jf0gV2j8K+5c
2LILaklKBxcP4N9xklfeoXjysd6w5La3fKFDnLm2Ht47jBnf3jwWJfVOu6Io
I6imQ2FfiCViwFuOyoz1+bCDOa6eztI0tx2hFRAsKpuDQDTwBPdr87JXb3Q3
XKtNwEjdE3A1HaY7x8IJ08fowH0TcpJwKpuitEHutx7WTky5H91qt5on3VBX
uUDmbYJjE4qfHEGkptxzZxskDiWdLYLOz3KnLJuRBsWMV2EZc8fq0J+pzQE9
tZiVClsGSclzKbVgQ+NHCo5sCan7Txcc3EgCo4hIJ2VLO6RHyNBXmbx7fqr0
lqPubx8XF/lc/odK3dyfgng+0aTce0RTenbt6WJllQbjBESjUM2PpFpRqDOF
qFZ4j2qbVxQnptMJP8MerC+ARWoVpKxUfI9ai0HXfu6y9uqqnIBahcoPJVb2
47T6wRxGUb2wuMqnWib7HtWkotx6Eq0nTU3CY9lKluyhv34RXM3V2a+formi
QWIiW+eMxrIwE+RpfvrbAU/Iq/r5g2E6XphfiDelUm4+7G1PtlfrZNEwi5LX
YPh5t3+KtFDKq+fFMZgHG9xSEF5gHkn7tmw/R5+nVlq8HE6g261NLLEAXo1f
a75JZ7rVYDbDMi0se5nZWLQVy5rGQfgF8SMWZo1rNpai2Xgp8i+4BGSx7XBd
Dg8EAa+txAjHfWTffKRZYY5dL5vP183Tc4XJrKjnBxfjB9Nw6o8BWLISPw4W
Ta90cTx8WWYeHsv3j3Y7113m55dlMyt6Z+MQLN7H8XGoaDeU9dVLe1JZlQbn
8+JQ0h4ms9uXR3uW6WYCoBQe+DhU9NHTfWvu6qXFeP66OL3vZzvZp4U5sTqX
5uN1SNlq9eNkleVx+vnk6W5aelz1FjO5+bJSq6PlfS43vXi6Cud/hQYZr9+I
FZOgHPjoWLMAhhgrSEmrxcL9lVzL3A+fbhbL/omim/3pqNQzqNsjDk+5Hlly
D3lu8Vd3YjNZlT46tLwGkPaGryXvoeaI4uOr17tfPVxcOMb9aOD2rjEtETaA
Dz37PdCX7clztZIfvTK1eHnRmV/djBf9vnh/Y1QDWtZ73VoiwqmGo6Sva1lZ
7SiP06XW102toSil8XhaLp5Uw0XaEjTYD3gdLrjq2KfZy8H1i3JxWzW7HXNw
N8lmO8Z9VwmgR/N/fnzOUCg4bt4IDjsmOG6b3ZvWl8QcwNtgPd2fZbxut5K9
VBf61XD8cDK/rs7qM1b43rX34d5MbkqW1Lbvl6NWfTS+Oe3eFAs3J9N6w0eb
YthJkabm8hfDZbuzqLQHy1nvcTgeXQ7Mkn7XabJ75ztx/kDPes6onYubD0sS
sMXSg/J5I3fjScsHqTgZt04X9qrbv1ncWHJ1vcJgtuw6xfZ9TDqH5hs/bmRt
W3bcSHgz3w4443RE1aZdPC1MS1IpmylJudwu8iWC6V/Hk86BB0JI96u170IU
LP41gpVcVqp8P4IRWNlMplguFzLhAlzWruI7DCsY+fcsstHgtfBcCebjTzMy
IUuZibKu88ueHT4ufCQGH8UmU5KK6Cf7ULKJoVB4brA+JMI0JD63Cl4Qtgad
+2Gg8+VcGSOztAQ+9PwPg17I5ou5AixKZySAiU1FTZGyVyzGmsug73DX4TEI
6T2qFAeb1S+05cYqLzrj5St+zRUZY8fCjJfp6Aw7BdAIVK4ldKoX1TeFmP1Y
XTBeD2Za/E1eB4dlnAdYhTIErYFQqkpQiEXBEzC3TapJYeqvn0bgezCwyOPv
8GpuLDcyGdbryTbWw2LR6ipeVNjhF2lpQS+FqDE+4gkaWHzHmIrI0AphNaBH
ET2c/cjTqXLRoFpAv1j7TXmrf70aL11UeVX5DIsryMYNapVTAW38wmVqE+Dw
grrAf6G7lXmLAH50JNB1aevb3LDmKlKMLDiRC8D4NYLUj8LZvADsC1X3LTRn
4pey0cV96Aj4FVFkqDNF40LS95PWVZO+ua6FnoFfTof1Y4677oFxAi60jXRs
Yu8D7EUBbuNKOEP+kIVLzZThWd2Wnanl/2uuKQcHR0fbrpc7OhJ23TvHp0Pc
i4XVHGEs6EKkFEvkq4xY0lLshEMTw1WZy7pHbhkmQdnakNd+05zeluzS6NRH
YQzzQi5Bzgt5lG0hnmbS5a/IUGsW447ShOkzfB7URVvmTnQJn4atKdiGAFhO
R3KeehML6G07f/+fJvwJmE5hm9546or/Fa1QxiWyPSwYBj9ZmcBUYIlc4D7h
DC89tOHP/rOMiX5tYBD+PagDoT+xDMdC8I/gJMKcTjWZ1vcK3F5duNCmlmnB
HoEnNZAVK+Fe0/n7VdMyVwZ2IYmWXwWl6zaOUYeFs4QumAWweYghYFLWxMRb
Pb2//3+Ag+s6HNoJiERgpLasM+y7wahwvOfK3hAnEtRRY9OHdeG08PZ/iGas
0jokw7lnwX+feeDKyiuhOjFA6J39/T///v///T+n8EO0sJpGnE00zBeaGBob
01TmK1W4nMoakRfmhSRAoSvD3rm3LBUAwKPW3/+XjZAYLIPKyQ5ioCe7+P6p
PPWGfOWwQM+1Fs5UW69FEytSgQcmRH5gVhBddbpNHRFgQxDJls5WtKuCaydr
tgaiim+ousj/+uguIoHEe8BQTwB7td5Ua1gREbFnL71lx0jF/M/ZVoF4p/E7
lum5wGoTMHWYvH1zi8TtgFOTB1y2bLk2NiFxhL6jTKwRMzVc+kfZRvNywkYj
WtBz2eP1lOegaIbA28ixLc3W1AkI7i6guJINYkSgICh5VNewnC7x+allytQa
om2tkEXg0Q1e5murwokMTO/g6tpsBCqBFpX/p7+i24pc34hyYZ0Cyyt6w0sp
qXUNKalsBv8bgxZSKucnx2m841FkzNCcoBAYtQYILzYOhgj6MASNQ0KFcQY8
PQHeW8FcT2B+Y3kum9uk1AUIB0M4s4ZMg0XG6bcYxpxAS6wvXSajxwmKAjF6
dCygK3iM1cg8PsZzLHnnjoA9eVovr/cnEgUWAZZNEChSzCmhKmwvUV6DoiYT
jvAVb7f9JyTQ/zID6/JXqXQI1sbWnhWI3AhL3WnKPE0u7GkTSesVPn+qM8/F
IzLSLcrEM8cO3lir+TnoqU+HB/8b2KkaPa8FAQA=

-->

</rfc>
