<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-04" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="Intra-handshake Attestation Considered Harmful">Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-04"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <date year="2026" month="August" day="09"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 60?>

<t>The draft aims to provide technical details of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 64?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
      <table>
        <name>Binding mechanisms, implementations and ProVerif artifacts</name>
        <thead>
          <tr>
            <th align="left">No.</th>
            <th align="left">Binding mechanism</th>
            <th align="left">Used in</th>
            <th align="left">Artifacts</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1.</td>
            <td align="left">Client’s TLS nonce</td>
            <td align="left">
              <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
          </tr>
          <tr>
            <td align="left">2.</td>
            <td align="left">Client’s attestation nonce</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
          </tr>
          <tr>
            <td align="left">3.</td>
            <td align="left">Early exporter</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
          </tr>
          <tr>
            <td align="left">4.</td>
            <td align="left">Server’s public key</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
          </tr>
          <tr>
            <td align="left">5.</td>
            <td align="left">Combination of #2 and #3</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
          </tr>
          <tr>
            <td align="left">6.</td>
            <td align="left">Combination of #2 and #4</td>
            <td align="left">
              <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
          </tr>
          <tr>
            <td align="left">7.</td>
            <td align="left">Combination of #2, #3, and #4</td>
            <td align="left">
              <eref target="https://www.ietf.org/archive/id/draft-fossati-tls-attestation-06.html">draft-fossati-tls-attestation-06</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
          </tr>
        </tbody>
      </table>
      <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
      <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
    </section>
    <section anchor="credits">
      <name>Credits</name>
      <t>While not the editors of this draft, we discovered CVE-2026-33697 jointly with <strong>Viacheslav Dubeyko</strong> and <strong>Jean-Marie Jacquet</strong>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE (<eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>) published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ERISA published EUVD (<eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>)  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation</eref> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="eu-erisa">
      <name>EU ERISA</name>
      <t>European Union's ERISA has independently published <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake attestation (currently under disclosure):</t>
      <ul spacing="normal">
        <li>
          <t>1 CVE of expected CVSS <strong>7.4</strong></t>
        </li>
        <li>
          <t>2 CVEs of expected CVSS <strong>7.5</strong></t>
        </li>
        <li>
          <t>1 CVE of expected CVSS <strong>8.7</strong></t>
        </li>
        <li>
          <t>2 CVEs of expected CVSS <strong>9.1</strong></t>
        </li>
        <li>
          <t>1 CVE of expected CVSS <strong>9.8</strong></t>
        </li>
      </ul>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>At least the following implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
        <li>
          <t>Privasys rustls: <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> of applicability of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t>Pirvasys go: <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> of applicability of <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and disclose the vulnerabilities to them.</t>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation path are vulnerable to <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> and <eref target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">EUVD-2026-16488</eref>:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation</eref>: symbolic proof of insecurity; <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft</eref> <strong>withdrawn</strong></t>
        </li>
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref>: symbolic and computational proof of insecurity (orginially done for -04 and applies also to -06)</t>
        </li>
        <li>
          <t><eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref>: symbolic proof of insecurity</t>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="correlation-goals">
      <name>Correlation Goals</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 of <xref target="Intra-handshake.fail"/> for details.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any security property that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> remain vulnerable to CVE-2026-33697. We have also proved that <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/04/">draft-fossati-seat-early-attestation-04</eref> and <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation-06</eref> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation-09</eref> is vulnerable to CVE-2026-33697. Thankfully, the authors have withdrawn <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation-10</eref>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high-severity vulnerabilities, we recommend that the
developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>From a security perspective, intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
      </section>
      <section anchor="technical-report">
        <name>Technical Report</name>
        <t>Technical report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with actual attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="media-coverage">
      <name>Media Coverage</name>
      <t>Several media enthusiasts have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <t>If you have written an article on this and would like to be added here, please send us a PR or an email with the subject "media coverage of intra-handshake.fail"</t>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, three main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are likely more vulnerable than the open-source ones, since they cannot easily be reviewed. Even extensive security reviews by cybersecurity firms often do not perform formal analysis, and thus remain prone to the corner cases.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research) are ethical researchers aiming to protect the community before the attackers can exploit the vulnerabilities. We have responsibly disclosed the vulnerabilities to the developers and maintainers and provided them our proposed mitigations to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To avoid exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts  <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/09/">draft-fossati-tls-attestation</eref>, <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/">draft-fossati-seat-early-attestation</eref>, and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> for at least half a year at several forums, including CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive) <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail#upcoming-and-recent-talks-and-research-visits">recordings</eref> and the <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail#community-service">archives</eref>. Thankfully, the first one has been withdrawn.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-normative-references">
      <name>Normative References</name>
      <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
        <front>
          <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
          <author initials="M. U." surname="Sardar">
            <organization/>
          </author>
          <author initials="V." surname="Dubeyko">
            <organization/>
          </author>
          <author initials="J.-M." surname="Jacquet">
            <organization/>
          </author>
          <date year="2026" month="June"/>
        </front>
      </reference>
      <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
        <front>
          <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
          <author initials="M. U." surname="Sardar">
            <organization/>
          </author>
          <author initials="V." surname="Dubeyko">
            <organization/>
          </author>
          <author initials="J.-M." surname="Jacquet">
            <organization/>
          </author>
          <date year="2026" month="July"/>
        </front>
      </reference>
      <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
        <front>
          <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
          <author>
            <organization>CVE</organization>
          </author>
          <date year="2026" month="March"/>
        </front>
      </reference>
    </references>
    <?line 407?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>We would like to thank our co-authors of paper <xref target="Intra-handshake.fail"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We gratefully acknowledge the following for insightful discussions and reviews on this work:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Nathanael Ritz</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following who gave feedback on <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis">previous state-of-the-art</eref> that we utilize as the basis:</t>
      <ul spacing="normal">
        <li>
          <t>Tuomas Aura</t>
        </li>
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback.</t>
      <t>We sincerely thank Karthikeyan Bhargavan, Bruno Blanchet, and Nadim Kobeissi for the foundational formal model of draft 20 of TLS 1.3 in their <eref target="https://ieeexplore.ieee.org/document/7958594">work</eref>.</t>
      <t>The research work is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA91923LbSLLgO7+iwn44llYAeKeoE719qLtsS1aLsmTZcUJT
BIpkmbjQKIAU3Z6JfTlv5wc2Yjf2cWP/Yd76T+ZLNjMLAAGKosRuy9O7E9O2
CdQlKysrb5WZMAyjFMnIFTvsxYkfhdwYct9RQz4SrBNFQkU8koHP9gJfSUeE
wmHHPPT6scte7V0dGNVytWnUas12iwV9tnfV7bKW2WAwBlNiIkLusiAaihBe
HShsEo9ZFDBxNxZ2BINRj7a5Dc/twJP+YONFifd6oZisDdCLks0jMQjC2Q6T
fj8olZzA9rkHS3NC3o8MWRzO6HPpGuV6ScU9TyoFo0azMbQ+Obg8ZOwl464K
AArpO2Is4A8/erHFXghHRkEouYs/Tjq78FcQwr8uLg9flPzY64lwp+QAJDsl
G2AUvorVDovCWJRgTbUSjBsKvsM6Fwed0jQIR4MwiMc7rHvQuSyNxAweOTsl
ZrDOCeMDmFThj0VU8Dkq8HVxK0oT4ccw/0vGksGvj/CHXt41zAmIZkf4Ch97
gAds8m/ijntjV5iwE/ich/Zwhw2jaKx2LCv30oLhYGgZDeMeIMiLh9zzuGPE
invcUDx0eGgtw/YL6OZyhBy6pQMv7W7q0U0ZLB3IenhHzWHkwUQlHkfDIERM
wqSMAYG4mhhenCYTsvc4IevShC+oVRAOuC+/El532OV7th8KBTu/xY5E6HF/
Rq2Exli28FuC3NSQ/1sUG47uZToCAPED6BnJCWwIW9xHEyHeoUEfOIXUYvGs
beywYzkYGnTEZDTD/QeaTw4IHInLt129ICJE9jr2BcPuW3oqHg5ENN/a6XRq
AsQCN3wAHUxfRNY47rnSJkxY9fJ2tdKubFdvF6BD4G6LsN0WIMOXt9K/TSG7
BcgIhmx76H8GQA+n5NRk781kQ4pvrky2H/fEbBQUn782oM9rbn+JRfQAeo1Q
jIMfgWN3tgLHCT3j6XnSeSGYnhFTxcUmoxenouOwgy31gwR7e8Fe0E0YkEYD
k4pNYtcHdt9zBfL3ULh8hm24PYJ3kgPHh+URyxfjofBIMmBX4HgqGX4JVdoT
YQIQFsBwIWzgjD9L56cFZsfme3CKFEybUCqhCMgOXsk0zVLJMAzGe4oAKZUu
h0ILBsalpxDqcRhMQKawSNhDH2jfZY6IYBtIcH0qTvvvr9aEc4OE4qeD91f7
+mmlWd/eng8j4oljCl8qboo4DMb4l0W/rYU+G1tsOpSwUEA7yC4QA34E8igH
tsBl+LZAuIfBlG1uEnVtbi6XIKxPiwTiHiNqpC22YAjhs80pUG0QR2w8nCka
mdu2UGrTZKdBKAI4GVtMSZwJZF0k/TiIVWFkABFkGO42nI5QfIklSOytRwHi
jqOgUez7Aufj4QwmQPFzBydxE6bHzQOWFbuRQnnKekBoQFu9GYv0G2Jm7Ndf
lx31v/6V9gJb8jCSfVizeqApMQ9oD7hB2IQR9A3oZ0A/oJjA3WLnYXAFDKK/
xWLQEULWGXMbGlTNMgP+CeJfMCBEAAmoy4lt2ZMurGGLIBjyCYAuANMAvh9M
XeEM8qtwxQT2FmceiWHgwvAqIWNPOo4rSiCmEWocmFQBIGrAuKbqMWIB1Aca
i86CyxSoXbKfsHUCgfvchb0lEseGNjyUeJpYDxQf1BM8ICsQigrOCC4kfQwY
kQ8rJdQUKRP4k5MIVHpW4BuAkiiwA1fBCf3GzgKTfWO7i9PCs/cKOsCE31gn
269v0KOCHfZcCcv8x3/774rG9AMkx2/s0ymc3X9RoEbNzxiXpgdPiQsToDbs
rwri0BbWOJQT3GCACUkOQDCyA2XAeYvEmI9FuIFDIw5EWJkP/Lu4uxWFQlig
S/hWMuAGraq6sKo8WtPVGXMwqt8bjKoGo4ZgHPAQDi6o60EYAXEXJq5974lr
euI6TtwVIXAXWr/WRFBSFOevf+/563r+BuE/8OChRjocjZdVOi0va0UQGt8b
hIYGobkChDpOfwCMwgUyZd0ZnCY4mmAPwfAqWgrQ3t6ekTOeLE8IYNYDZfXc
oKenB0kp0KpRFgjRUawuYmdm2smgBo9cZdi2beRo0Rw7/Y1/BbkIJ7h4zFAi
Kl8ZEqweFTUHBMN0bOBwQNRWPHYD7igLRFrDqlSta4HrDI0OsGw4ZzbCZlxi
X2Pv3dnhyf7B2eVJ523zKJkS5tzbK1iD3ZOjpyx8A/gBd4Ix8h84559hKvZp
BRdbOuYCGqyUoxmIo3Fg5zhE83uTR1OTR2speWwBeW7laETbSP0A5GckCboc
2Ea5WdwwKaI+6TAoOEFpsqRjPTYC2Vq59ba+93pbuN5fd7Tq+dOLe7JBbTGJ
aoEHZEVAKVp/KpPn4v3FX0ulv/3tb6VrkWl5PBWK8ADwB/8HPVnYMSn78AtU
Fq0i9EDPmcvF0hK5SH0floUxShMcq7RUh8iB6xNdjgOF4HkykoO55MT+jlQ2
al0C3SsJqKnmjXqFFMpk72IUvXB+QYOYCDjS0JVHTEZg6c/AHI1A5WAwh5KJ
tg4Ki4SW0CkMAFA+HqeWnwGL6oO+wF6BKiJcVtvIlq8XtWrZ3A18gaoaaBeA
PpwVBIkbwBF3SlonylkJqNTCwgAHyRMQNx4MCTvKbBKGpHyOI2yRKrilfhh4
0MCR/T509nGJsBicthtofUZ3hfmThasYJkkRAhwJNMxIlQALEpQKRyipkYvS
xySSKSHRgJowRo9TD6QhboIboEqCE+TRP3tMK0IDRIEQj7Q+8ynbRO5MpArC
2dIDBFpuyCcycEUUKstGfmulPa2kJ+y8dXTc7RiT/mBgeJO7O8MbDOD8SKVi
mA1mjjRGQLF3glClRoTWojU8oAQXjRbQfHNuPRP1zb0QPWCqdD2UQD2IVBxU
e8USLTJVQWEKwXIku+Aw/BwAqgCfaGSAsn8lUXFWLp+kBuzmJp2Izc3XgvsG
yCUpUgsWbAAEZp/sMxj6qrAL+3qHcKcvpSdcIAjNF7Qm0Zkr2x5pyKBwd4CA
yDy90uhBhfRggqTzje2jOgx8FxRv+g9e4RmTviS7a04bIqUNorEgQTWMUG6x
dzbgAyUecfAFEBCCrHGlDuuyc41PUlMWKCjZxE/opJwTCzqkEr5dZOSWpwZW
yCNlNQe9L3flDzfb1zfhce30rj55t+1XjfjN4MZCFl6pAG59mrVJs35KsIUn
J4azhnDmRIbomemMOBn8RnneLFerrUqz3GjUrbx0yZGwGZLeMbAiIbTMRM3b
ngEUeSxUW+xQ9HLwpHqG1gfVEPbqR5wf9mlzs5v6gH5ixydHx+gqohOxvbG5
+e8Ia027HvLQXh2wV3/YZ7CRW+wqQBopIM17gBxcnHQ7uWHQmQCQfQ8/xGrk
rIDp05z8i1SV27RzpAo1UxbqgaCWojXMFexSxAfaWIOXxqRsbpsVopy0gza3
qdN3cNo8YYFt8v393uUNgoeX1jArxiComNUmTHZvjYPgx6yvUr63QNS/i4rX
71SVHWED48KjvMKB+CSbZnFsaxy7rtXYJt7WWlzB1Xy2JYtBb03wO1eUMEUH
Kb+6YlrtpFmtpM9BAM2To98StKI5g3dglSv7W5UycFWUr9Bs6iMFaRevAuiQ
ay2Ad8+qXJvVimQEpOzUenyY1w4/D2zjs92YGP1pa7iandRTdrJw3ObWQaYM
FFWyvEjOKwN8QQtAE+ElsEfNMUulA+R+oHiw9z6gEixHzUmHHD2l2ZUg6C85
JH0Prqr1oewqlfTzDFKtXRUWCIoQqmWBNwYFSQHxUv93dOt6VbQNUMfbC/w+
Ks+kumCvGM1t9ha0ctATAEuI0ZewZYY9UcoA5Q30Gwa4yTYGAOhxVH9hrk9n
J91LMIWiUNq5c+rDamFxkTkIJhZCayRNLBx0wyzlzoLeJS0xv+l1A4dJZ3vy
mHkFLaeofZqCQh/xMdmXOf6Ye2r1gWpU9gh9DAy9kYkMP/Ej4S7YyvhI84PE
pQFPrVjBjmbEbtjwXIRWXn2yqKORNcm/QxJoGJWyUd02yuVKYlrTnUHndP+f
N/+8BeKYnF9nYNdpOXB5cLCAWFDq8kgln+kCSu8Nsv/BCaZ5Zuea3PYSFieB
iZmVSr1h1ZqN7Wa9boLgKldrZfI7/MDNqSNyynnkoKsWNHT2NpjqlXQj7oo4
dw7ubG4kQix3o610s/Tv21gBJ7gDIZ/gKZXqDaNRb5TbT5fqSQcco26W4c9T
sMtiTwO3Gwo+Oux0Lx8Dr4cN+8i4s3/dBnzkAi0ug7FZabeq68CIHTYQwuoi
hNy56JzOh+pxEFsecsrkXzj3tyXngXuOlj6+lfrzgfT0tUi2oVYPFAL0e1rQ
3FA9o1auNPROos+39gPRVVkXXRUCsb0A4iHvAf8bCecxEPtpw/m/VhNdpfwE
COFhrsNSCJddqRVH/oFxB/lV/n6F+RtJ5W8UHFBQPxYlsI57mtyXwHZeAtuZ
BHYzCYyaCF5w2vMRk9s57YucKwibmwDM5iaZAw/edaLDDkOjEj/g4s09unA8
mpfNRJRMis6tIL1LjbLLweWQK6Q37XlGV18chloxQg6f9JwKdOVFsEh/REgg
pxEY4qRoki8Hb5QpTKxUOoxDQl7ioM3uKFH3cueg9QPXDaYIwTiIUo0G48wQ
HavccK/mMOpL27mOuLFTKhmsQoIKYC8GqiG665ub0KCaBbTdb9GgFg8OsW22
HhmibVZWD9E2t6EB0gg6ikP0aYNe6+ElyozBKqVH2w09tfq2RZvch/eATKXk
wEcfJ76im/QZjQHdXDfBRygmUkxpW3Imy0nR1V4qdWBDwXKNFnbjnks+FLn4
EELwc93O7vyZ4jQeNa4REfevz1Z7rnCJfwa319b/c5he7850mSX7dNw/sx1M
hPNnvgPd+SGeHX07kHpciGdmHjLtAdx5Bl8j3g3qK7LEdv0u0WFPoOBzGeq1
DYI11/V0J+M/aXGlkz6bBTGJCj7FPxEQf5ZoUauEeVHabLExrRMEU8RixRBH
TAVa9ZnSPS6zh8IeEfGkV3n3bvJQVdNahrcoBc+ToCXWzQdTqYeEYRrjVIy9
UlqJW7WuMYcGRdGJIP2JuK6W5M/rwSy3LWAmaub1AryMWnJX/68JCN/HWbq5
mblLiZ8sLA+MlcgQGBT1h1a5fBir3CwsFjdKa9n0+oFQhVcwhfQlRVg6qHKj
9muU69rJiWcZ79BdPAMBPG9uzFcF/b9qWChI4snLWOhnlcuPbRKeoTR64y2G
EqhSxWT7xwzoPolmCOHAvvrL4G72lw04uPAMlP3i256IphgsmYYD+OlFfalq
suPsEKUxCxgw9uovw0jZ6YiIGeHb4WycRs3Mj56HcaYDoUo1k3XmERALo8H5
XjFaLnICI5J5qXSumZESgnWFbbKmWcWGD9pqOGYSdKxv24MQBSaNeBTALmIw
gp3kvpAFpwPlEFkXnctuGp4e5mKEo9mYYncfND1hJtiM/FQA4kEaQ4wOaNyp
rt6LbrJTR5UNRPuKXrkQxvnmXCbofIPoPKpuILqfNkZ+U4qj1DaWIbq2FqJP
OaDnQkcUI1vruInd+RUDcu+H/KQBxDbCjvf/zjLL55HAoPvcvaAdmQDHQgDm
ULhjlQXs6KCcSgoftsfAhCSEyMnF0C7rV833O6HoILYiOiiJAHosxIWiflga
OM4dRya8CwzP2KOjosj/f47XKyEwsJX/Q39SuoiXla3qVn2rWXxY22pstZge
b2HV6IPaMYzVMxQmS1qn/8j+hoGOKmxnFakS64Ie//if/5kM9o//8R/Ff+Ao
1UdGGdnDhVH0v4qj1B4d5S/sgVGSf+Q8V0T7STQ9+p4Wz1LLrKxzll6yg9Rf
kR2o1fHduajued80vH/5vc7K0O/nis+2njX623KDgRndRU+PAn+2CPD8Qp9h
9MJCl8eZP1uMeX5pzzB6YWkrI9mfLYo9v8JnGL2wwsdi5Z8tTj6/yGcYvbDI
R6Pxnyva23rWWPLiIp8WU/5ccd7Ws0aRF1e6bea1BZhW60vc/X7zpiPqZT3j
+LmFzeX5ogjVkS3ovc+8D7C5h1oQK5LYD70k2U4J8ZifjnnkBrvGnDWXdEIA
IlqlB24xFYMRAsbJUjv6bszXN9vnXa2NLfLnLGqoObX2Mp8NqOIBGHhRcg8W
CgwCYMNZL5Rp2D0Gy7+yi4dgpbKLAfsP4mDjx3sPtHPn+1v3ZByAMr8iKfMx
XOVNAswy8GfzHIae8EVfFi8f/9m0ZSKho4WGNlHBJ5mBPU5NGCKoe5SUp01q
8diS0jSFpBMScAeTEjw4lQB9pHNDA8zvmPuIkrtRnY8xz0ZF4/Qh3+P/P2QZ
Yi0Gf8GILjo8aR8p05acYJj+Q6kb/F705fIFGOX6d0NFvYiKxyZuftc9wKtA
zGRAyshIGH4EIV6GJXfyRX+jFzjCNZ8oId523hxoCdGVHuYjIK5hSzBByobp
qOVykmSfXKzfEfInLxgfGUkna+OpIKKVSBA+lhzX/i6O6/uFERZJ8xK4wQhr
k8z0iU3Dc4le54G7j4CbD9f5A85v5DcXwGyiImsij7j0NwnAOffCtQmQAQ73
ByIMYpWWAoBlIovKYla3MNMKM8zn4SBDORhiOAjFIDi/K0iGvUL/xK+/LkSq
/vWvSAyYt3UksYRBOtu8jsfCZJSkBLpA4HnCT/gCpdqhMoHsXfv6kM1E8J8I
H/Xqnb7vXpbicKADTDyM2FkpzpI0s8cIuIMDVunP0qFOe5sLIgALdT5Y8tZK
2JwA0OthpI0D2ibFE3OfDqWws0zDrPIQeUYvs7ISOsBaK4yXQeCiLzpGR9Fi
VmMmneaX5amYooTHT6mYmpOtFIKSA0NMYBIipdqYIjPb23BcGrWNNA9ygXkk
RJVVE9Dc4BR5F2BPx1IloUTE0BBoXRbhU1/eIf0B+pKBHJn+SKuXrPZ3PukG
W09uINSGdAw7lICKnDoPbMngFsACK8SdDciJK4Bhx4phjSjUcmjdEWa0UsAT
wIRk1Qcc4dFaKLnyiJOWmL3UY5uEnzBh+XSus8vS9KIBc0eRaABxWPoL5lVY
V4Q4luMgBrkbiyz7jyIeZC/OZ6zhAYt9UvZm84zYP+EOJKjGEHfMFdhC1OAd
NJ0UXHYKOthrYgm0tIOfTvaNPZqEUWDS48HNrVa7Wt42a63tRm27tbGV3TAU
EyjZq/s5mhuY3amve/Q5SCgnO3R2ELtOGgNGuaBJoRd9aTjXL9Xilpq6ooiX
nCVmDwMJLF4n5qLC7oKyoemFKsbQrbaG+h5ecKO3FphxkWqnBKcOREs0u9V7
Dyf9LMDKP6nGkaZH/umoavm5JuGjeZIPcvy8+8bQqRVzy1/z+j9MTzul0n9l
h8A+s61EXahi1rYKBz2bN5fjsS/7fSmMY+G6HhwBpEUmpA7QxBxYYK5SuI7C
OnjQRo6BsDAKdILCFeveUB0afaH76mBvY//4IMkKx0wSYXOUIVNta8V+wdLS
DlOgUT7BDFdUohZYf7iYuoU98xGuRJFLEItSQucwAxlrwuuBrSe1AqP3ZEk3
rabd55bZXWByIZOYhqjNYC6+1AnWGdMFQUznMTWl5bw8EsBDKT15yXsh0DFe
mj8I6QHOPscMQPHQFY2J93vYmDLok7vrXKQ19j3ovrs42etSXhVJ0JeL6UOl
J90GFeoO3S+lRfsBzCfGK0E6injFbousAtFiPQMNymlWDCGFYvVF+iNQzFWG
5M4wG14rD9mNVGl+N0WxSY9jOy0Zda8c1FtdDkpfNwtHcraHZwlUrSS5CvUT
eg6AD0FEcvRVkSWQCoAHwpQS/W1BzhLL0Tp76D2itJoUyoOKwIUYSAwgKAYW
4WlPXuj43DSUEanFKrfQtM2r7EamsiuDqsAY2X2fIZXRC4OR8ElfBO5oeHxm
wGkwxB3MYDWqzWa5QXEqr17zMfdhJzfYp10XaOWYR2diqi6D0SyXoNnDV3AK
fXhlRvgurWKirEql3a40aLAUyS5YLDHGesCox2Qp+UGe4w+zZ7TWQvzhlIOl
EY+JaowoMHqCVuFilRy90F4QY9WrmSHBSlU+mlwkJTwBpp0DvUGFMOA/isPB
oAZ0ozp2IQ41eaBMjCjRNTfFIH26JkCWdCrN9naj0mrWaz/LnyrlcrnVajar
teq2DgbK1xfopho7ojlXYEDAzsOZwv2n2gJ5EArpiEaSFpJoJ9ZGQlhn4i46
Ej6ysBMtbHJJY0Phw2u0OQSW76DXtOpx7CphgWAlZcXou3xqzBUiQ/rGcqor
mMeZYUCw7MMZnaXLvKBA97z1DC9T4k6i4BGOeVpRcXlGARGkzWgghzKCvQGa
VLCFBgVfG1xqbHT3sAir6xSPmLKn+JCm64VS9B88UCHZ6EuXSEcJWYbRRyok
sajRRjOXK+yXmPtR7OUPTzBQJhWKRdGL22vGI6tcMZKmxolv4xblCq2iyDNs
eGuMhBgbuFaAwJNKwJpnD+yJ0phBNgBnj6gUnRWGos2UAz+inqinafWKDu1F
rIAToi89I823vLeAuuQNcGYzjC1kA1ajVW/UG+Z4OKZhdP1WGIWWC0ylOEL6
lFKQVpKUFGEMP/RWg4YMrEIDuod1Z4hTdaWfc2Rh2oVvCxNMHm7avoUkTmzT
KLcMYJtaJAEpy76y76J2uwGUVTEdnZpGvirAUr0nvxadPPhE8yeQUDYmW4Ly
ZPRBpecG7MUYeQBwV6w5yA3QZh7YlQUkn1wCmhcSKiPAb4ZXqZQrnACzMVxp
+FwN4a8RHdChUKN4FhvxjH+dSA8dHpPCAVnAk/K+Ol6e6anIpGf66Ft8uxq4
7XZ5Eb8Y5ZhnTgikfkYdCUyNVatuAaOrlKvVDJu5cWRf+IOcC8KkBzrA3dqO
3/dn5fNT78uB3oR4MOB+rPjCvOljDTMs4SHyQXYQuMIYy8geohDU4gKPAQVM
kgTEX7YbxICuaWDMwLhS6FhJRAgaTX1ZBOfhWgVjbAMtrKwteU1z9slSXqav
rnAONQ5klE9nVVS9KdZoTmo5YYRxu9poVzrlBlD07p7RKFcaxm6ntm/sVmr1
1m6tsd/crtOILp/cseLm0bbhc3MYp6RsLXBVfX+HFzMg5YCPGphOZmAu2cMS
QK8gGMYLrAKe6FMDplK9sd1stGv120q1Wi7XyxWtdJyjpUingYBzZFTIQ8+e
mTLUxPaQEChKfmCp7X6zWq0Y1abNjVa1XTPaQrSNRqPR6tXscm+7v71wHN/K
03N2dX42n94Fe2cy1ppJeiaLCkEqdJK6OhoU3OaEmYCEMx0xWRB6+IjoV1mj
k+Z5cPb1/I46gFAA5OawSL9NMuC5NIGZEQzpLgHuDPQyFCUjwqC02KBUwAfl
dqIsovlFsx/tXR2YIreJTs8cYJi7iC0lB0Ndx/DnL7EIZz8V6Zn62zBS6ILq
mlfwcg8Jj9V6ebt1r9B4Xr5OQUMx0AU2zw9HV6qPei33QemCtmH2Tqt2/mdg
yJlCtZCxTC8pfRhLId3DFdK6i+5mh8bqw5H1AeicVEmekMByJN5rW83WAoOz
leMXBb2Jj6jPVMg76d/Wq7VWs9KuWmnx/NtKrdxugn44lz8BiK6IkJ07t7mH
abL9sv3UG69PbrK5oVQjLQou43Ak1RAgBRPFQe0DZLTkeU0895imGfIe5u1j
PpWEw1WksgdgkDZwia98JvvGiLtyFoRaD+OjXl4LpZ/auslpJNLPMWXg2rDb
0nVjlSoon7gD2rzN7osk/cLQ/EJYU5CcYP+B+tMHGUHDgU6JFokAc40LQAws
A08IeXnpNwikQQjjcOiqFBVhMAYC9GSr2W62K/VWQ5PayWnsRhJMhXw2pZc8
08IgYQbCBwK3s/zJAGgCjMiNLAFHXzwBwUZYldhnCUdGPxA5L9Arqb0lrhyR
q6SXOgzRRMzSbxRepqAPkp1foJcGi/ZhlbK5h1DFPUo+e6FtXjuxhZcYqqb+
dgDa5ZkOeDFnN3Pr2cbadOQkSpvluNI8XqCQoLOllzz3NKXOIyoJqO3iU9Bt
OPqD+Ki4xSiCYEo/E/7K8nTbMR/dPqQG40XVPasY/bET5CuteqtdrzQatdZ2
rQmHs9ysG1+MTl1T20XghHIQsN0QtjF4FJow7FHDW1CPNP9KSydqZkx2PZK1
HxiIHpCtlHNBUDS2qyAYa81mE8BpVI0P5U5DQ7GLtzznIVhti9U3lsDQg8Yg
jKixUa83KvVK9TbQxwqzliNScR7SmubQ1Nutyna1XQfrtV4vG9O+rKXWZRAq
pNcuILUvVgAEOo+iNpaO/smwboHaDIMhiSVfevgXxXa7J6XS/OehcIjK3mHq
gU6zWWo5v9pF14/iXsT6v/09ZF3UjMOhwFtQn6FTKNdNad/UaIOS2xeIj+3x
EKwGdizdaAt6Ak5m5NlSDHSzkVB476e9dwDrFvSCc/kn8+Ls6NvYvb1iiAua
eKqfFjonx6euxUjB5BLUWCxXPufDySUp/pHWXrLR+4UeX3JFYyYQbEvumOtV
0OWjgzG3JdhHntRbFJFtbmmPHgaFUA0E7QLUMTZ7e+mtLNMuAn3ricWTsM6o
LbLHD3ogcT+ptvtYgGqgfQnoBKfSU2u4YSlywcLvy2R8bkxcWYK9GmWuzKxV
EuuSo6QoVyy/N1uoXpUVpk9utbKq+r6TlAFI36DWhHVVvewavwAHTbt87MRz
mYMhuV1PhpYhC6Z+4Y5WA8B1LlnCH6j66313/zKncQHMNLWL9hu7QkfcZoBg
qnMYMzfXyjqaGFxj8YOrtvP+MIg6v3w99p1RtfZl157uXta4snL+sj820Maa
QNWOJ+WDiup/UJPZbuQ2O4Ob7c9G9/hYTtcDatVA6wLVePu6KdtqEnj+cDw7
P74+F59PW/1T78Mv6wG1aqB1gbq6vfly9P6m1j+Y8sPpdNbvtPfVcHwsovJ6
QK0aaF2gXh/e2lPv+PigF76+vW5cNWcHIrq+9qWsrwfUqoHWBer8du/mcmYP
ym+OWnbvDY8PO8boavCh+jlYD6hVA60L1MfXn19/GN9MPzb8vSvv6+11/fBN
84M8PLhZE1OrBloXqLoKam/vjt+9+3DcrUz9yTAOxPX1QOwdj9YDatVA6wL1
S/O1Zze2J2W74u5f1eLPJzflzofboH/UWQ+oVQOtC5RfPxWNX873JtPhnX3w
2neuxfkMLEA7WJOmVg20LlA9cfH17GwyPZX90UX/9Xn/TthHwfH4cn9Njr5q
oDWAsvvw633j5thpV9ybz/LL3mXU3v04u9o/OxTvx6dPBurRgdbFFD/cC+q7
pxf73fczf3LW7vzymkfnn/0PfLCm7Fsx0LpATXu3N6p9+tFpx+3gtLo7Mraj
Sas/+XC0JlCrBloXqGCy3Tda9sc3bxoXH41T77PdPBledXeNwzVZwqqB1gWq
Gr+P+X5lfzb4fLZ/Wj+6vDXCm970Ur5eE6hVA60N1C0/mrne4XHw1vty1trd
tW+ugmMjPFsbqBUDra0lzGT/aPvreYNPg7B3262cXbQPD94ffLheV0tYMdC6
QO3dTCenrcbXZnh54lQ7tY8fJx9fe8d37+SahL5qoDWAivse/Ky27w4/fmjs
1YPu0Wj8sTP5cHnbunl7Xb2ynwzV4yOti6u4cnx3c922X/evxrK2129/KTfF
cDq+OTpYD1erBloXqO7RbadcrjS58ebU/9AZHUWn7++C0Uc41OsBtWqgtU2H
act4d13d61yFZeOX3a/tluic3u3e+qcna5oOKwbaSIJ4MKLvlxhvUal+3AkF
VIYRBlWFQlCQNfuSvs99Hi3kUmnD/PqoaHXih9kw+iGkIoUYYIfhVWTVXWNc
1ubmvWydzc00VeeVdjSy/7IyiSv5YIxaL4cn6fUzpUOs/kJe+l08XAzemlJQ
tY3Fmrbo830Sv4WXq6SwmHX12Nf0PseA0L4Uzs/4JTU9clKj0hcGFsUuNE++
1ZLGHKG1HlDGVq5NiEEuYIuT7zYS6DftY+L2nv6gCjY5gLZUGJscLvgdjh0q
KfApFIkPZeGa+cEPECWZkZjaojdsgnXAYBvKdbqkwGrVdEvTNKqUxEA7L5M4
3iS1DGNAaRlAEXLgUw6B0vgLl+Q8pEkPi1kPr8h/DGNjKo1vz+592WbjZ9Z9
3lXWzapZT1Jecm5wIP4IA2dwRXOXUYkcITk3eOIeGgN9YmQaOenJ5xd6qaPn
ns9luZPlsdhcXdFT5lykUwzsze4LqIiB9v6MQ7wExwslXTFau2q0Z4zi5TLn
avrd56wEJYyYfXQmyRegSMce5hoi1Hg6Uh7wpPMCE+5iJRSGV3tYg4iuO3Kf
zsn5kNKYTl3NvzePpIV3VGuQZk7SLOb1zNKBMmfWY99SUoEb69Ip7MRPOGAM
HBk5J9Yvmw6DJFKQvkxk6GilpZU48d6G8lIWis8ghLhIYJJ+2h/WOE/rwUKh
CXMTXGHEak+w1K9p0tdy8DOvAhAwKVzBkKMU+Yg968Hepi+Q5NB9iZ77JBwW
th6pZbHwaxoMH6s0LBxI1Bfz1IIQVqH5GlHLAeyJTeXti8RyDedXmsLcSi6g
xuQ3jtKvfaXJV9KfBO4kt7vp8dkgBIpk9Pyh4lKfnodiMXuiH4Q69S79upXO
D034xnInZpq4+LSvT81r1rEVyUvJN8ZQNtEQaVT6vUBYPRgSYsjHEp3WyeGY
Q0VXfXiQ3Vn+K6NZ3kHm3qavI+BNPrsMGJ8EMFy68CTvEFiDQ6HoNDTRQnoj
l82zlDel45B3eg4cjhDi9wHEhJzuOAzG//KI68DY7FFSgpgVeyZTYiss14F1
kLJ4dFxX7OGtZvqYrmFg9ssgkTkqU0dyiWa5jDjcBQoQpm+k0jVkunaEmdz2
SQjAqn1OKRbmmix8WkSxH1Gab+vH5xJvPVsysf4+bVLFcchd4AoMQ7DwoUqu
Xmjr8bODvu3GlMi+pA4rQZjJYJPlCirhrr3CXA9xN+Sol00wUCOkYo14z/YH
a0S8jMfQgaIVfcdILjkj7o5U8iAJpZpIJfGDDmmS0ac0XvqPzp+xPCO5kNu4
n+QKjB/Phy/md2RZqqv+mslJ56xzj3tfFmT8kD6kp1tq1oS8nz6OjB+DxlGK
FVJV6dcdP/Z6KJt/etHnrqJC63Dsi/EMKAhHdHTtwMgdMFJMVhfB0soMJk7R
OcynwSkySe5/4w4e3v+6HUE1wIQswtrCB2Dy1UV1pXMKw8HEPBQOGDuWfggz
lb1BLvWEADkIgY2B8ghk53KEIQYF4hBW+tv/8eGn/gYsw4/A6l+Se6DOAb3y
PjbfDWPA/a7LfVhOhCZOhEUO3uAlbohlNz5zB3b1GDQg3R8UHCCDwAM2CQ9u
gEIA+NeS+wOsa8uxbseZHAV+AJIJnuzBcQFbT7q6/T7sSMBOwQSFMwKiy8YZ
A3/QAxhihD4Y+hiOEP/2v2CyKFK62y6GsXB2zF1BZUtIS+hGPO7Bz2MeTDFk
ICAQ9obCH9wBkMexhkkv6G2MG/QmBr7LZ6wDpkzE3vz299/+929/H2HRPMyH
6trDMLBHtA78Hs0IthbjLeHBGUdiwsiRC+A3uBDRA7IOXDGjLaa75yftM+p3
A5QOfSEcpG/6+E6WS7aYgfv7s9c2suRPIFtXfhW5fEipifgyDjx42IlDJIWT
wAdF+1QCv7QFp5Ir9PpQc3LCNNiEil0qexj0hS8RvTc8RFY5FPjdTvj9lsf6
Wv0tSMUe7DPu2JEEI30I/PcUaHnGPdongDIKxqhEA7oj2ufXYBWT+noczPCz
G5jGjlE4ocN2OWx6LkKI1G80wLM78y2GPHoL2biWLEed+tFxmnaTHGBtBmu1
iY5dsgta4SD9OBSkBCHveAM7MARuMgOQdgEM2Dj8smLx0OjJzoCiPfYm6AkJ
xzbLb+5TDkli7hdSl9GMJVujWsZ/J0l8iRYFzOcTHvEnplVjhE+jTaZkoU4O
Jaih+oYaCq1cB8Fk1iZsbgofe/ViX4DhCUsi/mEPY5BiGGUhk1g388VG6f8C
vRh1+GeIAAA=

-->

</rfc>
