<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-35" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 24 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-35"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur, Belgium</organization>
      <address>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd., China</organization>
      <address>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch, Zurich, Switzerland</organization>
      <address>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index, Austin, Texas</organization>
      <address>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs, Japan</organization>
      <address>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author fullname="E. C. M. Willems">
      <organization>Independent, Netherlands</organization>
      <address>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant, Paris, France</organization>
      <address>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA, San Benedetto del Tronto, Italy</organization>
      <address>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc, Canada</organization>
      <address>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="19"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 264?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <em>without physical access</em>. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 7.5, one GHSA of 9.0-10.0, two GHSAs of CVSS 9.1, two CVEs of CVSS 9.1, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 268?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
        <t><strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVE has any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">EarlyAttestationBleed</td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>9.1</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
        </li>
        <li>
          <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
        </li>
        <li>
          <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
        </li>
        <li>
          <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
        </li>
        <li>
          <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
        </li>
        <li>
          <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
        </li>
        <li>
          <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
        </li>
        <li>
          <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
        </li>
        <li>
          <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
        </li>
        <li>
          <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
        </li>
        <li>
          <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
        <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">
                  <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5-7 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="ietfhttpswwwietforg">
            <name><eref target="https://www.ietf.org/">IETF</eref></name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
              </li>
              <li>
                <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="irtfhttpswwwirtforg">
            <name><eref target="https://www.irtf.org/">IRTF</eref></name>
            <ul spacing="normal">
              <li>
                <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
              </li>
              <li>
                <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
              </li>
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ccchttpsconfidentialcomputingio">
            <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
            <ul spacing="normal">
              <li>
                <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
              </li>
              <li>
                <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
              </li>
            </ul>
          </section>
          <section anchor="ocphttpswwwopencomputeorg">
            <name><eref target="https://www.opencompute.org/">OCP</eref></name>
            <ul spacing="normal">
              <li>
                <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
              </li>
            </ul>
            <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="5" month="August" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 928?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t>We wish to express our sincere appreciation to the following for their review of our latest work:</t>
      <ul spacing="normal">
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We would like to thank our co-author of paper <xref target="Intra-handshake.fail"/> for his valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of complementary paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y923LjyLIo9q6vQMzEPrulLfB+7eXxDEVSIiVRokjq2nGC
AwJFEiIuFC68aPXs8Ivf/AMO2+FHh/9hv60Xf8f5EmdmASBAUpDQ0z1rzVoz
3QRQWVlZWVmZWVmZoigeOKqjsc/CT03J0tZCzXGY7UiOahpC3TRsVWEWU4SW
ZOljVxM+1e+aYi6TK4nVXDmTFcyxUL/r94VqKnssRN7l3niXz5eq5eBdOVU8
FiRDEXIFwXSmzMIPbXztzgXHFNhqzmQHEKCvs5lUBl7Ipq4ak8OfDqTRyGKL
D+L+04EsOWxiWuvPgmqMzYMDxZQNSYexK5Y0dkTVcCxJnAI29lSaMXEsqZqY
Lx7Y7khXbRugOus5fN1uDk4F4WdB0mwT+lYNhc0Z/MdwfjoWfmKK6piWKmn4
o107gT9MC/7WG5z+dGC4+ohZnw8UwOTzgQw4MsN27c/CGICxAxhK/gAAW0z6
LNR6zdrB0rRmE8t055+FfrM2OJixNTxSPh8IolBrC9IEerXxRzuKvCBtaIGv
o+Q/WDDDBQR+FgQP+P0Z/uDju4c+gb7CGb7CxzoQAj/5ja0kfa6xFEwAPpcs
efpZmDrO3P6cTodepgEcgFadqTsCCunuVNJ1SRFdW9Il0ZYsRbLS+8j9EzTT
JMQcmvmA9zZPcegp1dwLKP32lKamjg4dHUiuMzUtpCR0KgjAIRrnhp86XofC
LXYo9KnDn+gr05pIhvpKdP0sDG6FhsVsmPpj4YxZumSs6SvGKRYMfEiYpzjm
vzmuqPBWKYX9tKf/O1WSp8zWpIXQcEdsPTP3dV43LXbPpAWLdImtpN8U3gzn
Yl8H50wyxI5kqUw4l+QXlzn7Org11AWzbNVZ43q8knTXOhZOmDZRXT3S5zOC
0xFc6pmD+8018PPUaO/4+qYxGZnCibuv1z7M1mQqqcKZKxlCzQDOHptAWlrV
AyZPDVMzJ2sYfupYuHQU+G99qhpSBKOR5jLFnBjQ528TfPYWJepTZkxWqiG0
oLfJPnzam+Ud6UJyLVxg1vt9tCRzyQwBR/3DBjyFWTeyuUwxUywU4tG5kNaS
0LRkFfrdi89SdeTpsfDkWir+ib9fmaXBIop0OQM4Kcbh/GZTo5Q83ddjwxIu
3JGqSSCipzpzhIt//Nc//p9//NdsX/eN7lTVhOsV0EAJsWCka8VKzVzZnf1m
0meS5uqGmgI4e7mNWVNVFa7UmalJMCJ3b7eDKRPq0lx1JI2mfHUs1FzbUWFl
D0Cy2ZH+jQ2slJ0ax9O7v9YWEnAYrBwNAFhsL9GRm6amI1xKI/sYVuVcMqLr
ekTN47tqpoR6SuikhHsVP7bf4edj4YrhnotTGx0gW0hySk8tOZjf5pbpmEZK
37uaz4lMQqPZ7zevrpp9oV9rXw2aV+90jvJrblog7IWeas9ow3Y1R0K0uiBL
gAqnlmTIUfGmMBu2TIPZQxto6jDjN9023iJHR4JdW1c1VTJA2ljqBJaNou7D
q9tqi9ed5lkN2F3CqTKYwhzQPxSmCQMLdn7zWGgDb0T5cD5VTZ1NpJTlGo6q
s/jZ6agzZklT4cYFzNcGE+umpqnG3llqSfa0rpnSDEgmk4LUd8zxGLBBBsGH
IAUkQ1KiYkDnXfw2heYyNn8LlzbsVUJfnlqmvHc5NDvty3ZN6OLEy6Z2jD2m
Il05TNJ/Y0TdufdVSgLiHhhceC1AvxC21ZIUbsCfCY6vdu77IqRmkr5yCASB
2RNtBtIA9yN4DTqcp/CBije47PNRkGIlnLsGE7D5Me9KsibM2Wgqy+UyBcuN
of4ygQYpgznpuTvSVJmGny5kKrlsNVvJDbewQ+SGUdyGEczw5VA1hj5mQ8CM
cAi0DfpHBOxB64OVepvy9Ivom7uUv/VHn5+L0Mbbs98gr2ixuflX0Bg07rdp
7KlnqAx+SP0jnH4gpaKD9aBHu6I18Bm/5A886tXNutn39GlOBkG1hYWrGbDU
RhpDM8ViuLnBN5I8g3eqBIYLDI8sFzafMh0+1agpKPC2B34PV8oLhttYGnDo
MRm2tl9V5Zct3V3YzEGuJHSQiWke4EXz9q7BP82WCpVK3CibV+1+7Z8yTuYu
lBQzVBu0B9cy5/hHmn6nt/CPG2rUDk02n7Jpo/G032Tyh462jA77FNfDdihh
M7IIRbAMR7irgL3kkwVUEoSNO0fjQcDVNFbBsJ1LzvRbZ54GGSZHtiL02dzZ
S43cD6eGDJuHJMuIQHMBVjbs0gIogFPBUGGrYPrcWZPVC3a6gyBQIllOQ3Ik
lCigcgi1TgMM2juxf9X904TJxRBmw1GVfLZaSLYithr/CXYOtf8AmrET+B6a
uT+JZhw1z1r9mkgcI9ba0S3m+0uP8GaTy0dXf+x+A1qkJS1UU2OOZadlRDdt
M9nFXS0tKQvVNsFUtdM0msV4MhH1xWol6pNJ+e0N6HYDNFgz2xTJbZPEW1rq
Xy9owsTLlsCUmYCW/v2pV5iv8uLyObcSV6vCn6Re/jtQ7/sLpr+KkFYJ2HBe
qIjPOWv5bYRsKhOmAbeI/TXQR7ej9Owx3XQifkHkNdu1kVrqvhUaHnqCcTMP
DXuNo8bJs523Bz59nsjis1xciONlefr2wP3BCd7g3hr01ho8Y7iUcKrnJqj3
0K2gmMa/O2DYOUx2BEnTgIekCQNKjMCOdVykzF8zdD33MhGX1mohTivVSqKh
oy9Y9OUEmGDOWuSsvD3n5HPxxIVq7GzyYY85ShMwwse4bBwVBHENncuqjGvQ
6zmyGLKgXRsxFgDaiSizwRJMqcwZ0y6OD9K6PQGqSE56lWc3q9Pnm9PzS5lJ
rKQVhleTB0O3G4/pD9sCRMuupS4kILtowVxpW6zvvxR6NRGFhjyFaWcGTLpu
KkxQVEUwTEdA8RpZH8wXIbAyUDZgW08chymRpz2SoWf/Q1zio5PmuL7NIM+l
l4VYyMPasArevryXID7AHWJMzDcIcWbidM8+/6tRZGK+TY3y83gpFvOWLs6n
02+hBjMXUXLASDRpwUTYfhaq5biStocgMrMc2Ffx7MgWlsxinDKmC6T5QVTY
xettqsyL47k4qRYm8B+9+k1U0d+kiq4a6r8cSRCpmI20+qKDWvIMaklOLn0D
PSxHjtIDBCasUlHWVDxr20OOQPHimgfsNS+uiaT54VSJovY2UYovliwuKuWC
qK8Wq28jiqhIbwiTP2VHN7iD3zT8bSpMmNKPJswcVdfiEsTseFqM0V9jCePI
7o+gzOC6Pri+/aeQZTKpvIj6eDoF9cSSP0SWdkOsW6qtwtPGdTuVzaSy2UIx
nS+Xq7lMJZUvV4r5Sjn84T4/Jake6HukL1BjiWgkdVOfg4JmgBl8il5m0FEM
SVvjp+b4TU/llbkIaFV811tZr9fFkFqUprM4TbTnTBZVRZQJs29xVMKbjgk7
vjSWoi8GKdAxLXxosTHgHqJgpprud1O5TLacommGt2KvFiUa8IJExygj1wG+
mdCRDoY4OGwCz9FgtPbo/gay2H6X7htEQm+MazNDXZEqBwruGGQ/aANpyZFz
xfQcfeoeO6eXTDWmpqa8Tam6ZMFsGcJ9+MsP0LFtGu7/938IHRUEMGiN0ZeP
MH57KjTgP3NYdiz6tiXh0ZEwsOWpOYaBTLYaSxZQpj9lYxjY1hxNTV2ygets
G8a3haoKewEY4T1TdV4BNPrjYBGxk+5pdKY67UGv+e+2cMWWeLalsyXpYH1a
hjBNuEVgK+FSWgO7Ppquhcp3g47MbOE6smlUPyIEZM10FX+Zw36l4oEazd5I
MydpbJcGHoP/g0FsMdEWDbYUxz5uou2hJgJqIhvNx6KGqIlrQE2UVJGf5tmi
acTMM+LgDRKWds3DAj4ieoD9D4vbcGFphNddlHIBtXwrxWsheFZtqOGWwR4c
U7zJ0jRyogmM3RYBZ3UyBekYPhDaUETeYMtXlRiJtHlTLHhTv1+c8QkHyRW2
x6JhOAeqHxXgHayJjdSYc6OItpTIMAQqjMzHvhIzhe0PcYuIfFF694vqe19k
M/4XwASvHJexJIM+dZBKpQ4ORFEUJDDA0Rt4cICH8RTAI0iqbuNmOLdMND0E
B+MhYFY0NODBwCTB//e/R49I/vjjGJ5tHSbwh1GP+vaH5Kbd82Fu34fwkA5m
6cAMEDpTnZY7CjF6sKkKn3BXtQ+F5RRERTAW8jhInBU24wpMLBjY1FwKNGMR
0T2mccPeOEdqqTI7hkYgSI/Q02XCJjCfwpaIsFAhte0j3HgssH6YdSzYKsLe
cPG2Q2hCDhMNurTYi6siUwIxPHEGI/773+NWLdJpF2FJAel1dOSC8EV8JGsN
CKD2swI6HQF6ON+webiaY2PwmzACjQc6Hq1JJPpHtdD3voNMPjd8Z/SmBFtJ
aKMgh73RjNQP+B7oiHiCaTEmKQftBL7nAyhPuXBMPALvWuYdqvrHAqj0IHVr
cwzTEnOpjACCghk2I+kEcC1TcWWVO2YIIQtmlS15pOMU7BhhxBh6KmeGudTQ
axQarMYWwBSI1IzhvgjqcUqouxZstY62PsavLEZkOjpylmYQMLmJpzQNRmoq
Pq2mMiKGTUI7+Jb4MBqYuQOCnoZBeIArx8TqxhaQcqrAx7XTpJTKCyRE7SmM
T5pIIAkdGuTIMiWk4C6ryMil5OPWNIH2GuqJdkbZtMkN5YWG0iTP576MDvER
55a5NKfW5Ne1OcVkn4wCUynalM/kJsITncMjhgiANgN6FSCOc7r5gHeyYS6O
HID3usOQGYAgAKNhY3I+I6bA8LprID98I/OkwJoQUCPwufLY4xcd6IoIR+0J
wmyXviBmt92JtJ2ip5I664BY/Xfyu8OnHHjILvEkta4qisYODn4mCwfxpd3v
rfUpeJohLG5fvuDMARPANMFM0oheGY1n29v/SZpJfByHkYFA67lpSxqQwWIT
UBNpSDDm5ZQUYAS2pjnHKfCc+7Zszkmwov8ULXjLgS+B7GCpp0AlM3XA0FeX
BJxPjD6GHZcvCI8RZwBYYbJqc2EsOybMO0oJnGZAXFVIG/cOa3SQ7JKh2jpo
s6a+57kdxnI/hrS8cFT8W8I2yob4WFqgxxWtRwAUL/SS8OAxntLByzBLjl2L
iOwvNuCLGogjLtWJBy0Q7HxNICq+zRfmBZpt3+CTA4MP3ovUx/5zH5p9Pvpt
KQ3/3yZBxNZMOG5CIjJ0HKXBo9QjI/XGCQtjI192BAu8hY8QZ1wGqCKa7mS6
MwiPxxQGWiis9zlfy6oRSw5YiT8L1yA5UVAcfGAdOhvyIYtzZx5t1ejw3cIl
hqf5GaT/OB5LLkhB4QGLTvECzehZxCvix5KBYnjwFUz3lPBVONnuFp7d2gxZ
BP5WCxbBV2iRxQZ1cnD8j//lf7cJpmGizvMVdPGvwhdEllnZ//7pT0UqpcFm
YHjEYaQ9gIfUfW6r+/D496CR+95o5DgaeUSDX4pgKzwXAl6MdJz/3h3neccF
7LgPjMgsGj83okhkRvovfO/+C7z/ItHf1OEhJzrw8M85Yuuf81EUit8bhSJH
oRSDQgG7f3MD3ovQtj9KZwxNRhst+BHvHqxChjdO7HRHsmau3XOVdco/fwQz
DF1+shy2x1JzZXz4N+FLcMi+yKQqqRA3omFsG2ANO3hIVZoQKss5mb/A22l3
roEKZ6MHoZjO5tL3DIdriTU88MOTVXQaDLCtWL++Om03mleDdu2ydOb1DF3X
6xFzt98++8j4D0E5kRST3OwgK57xEPdLjNTZC3OLGmlfApHZOjdlJM1GEXLn
Cp0go6TcgJPUlA6fEDyCI8MmY4OCJrP0HP2iYFIAgmjwkAPFN/DEJRKIdozD
DTOWvjczljgzlvcy4zEshuMNR8J+EWv+w84RIFr+3oiWEdG/f+aunl9+2pH1
oOBta7aIuG+MbXSgn/44OPjP//zPg3sWWNiSv8nBAxg4/B9MEF+9g19oZJAZ
MQKzY7PPHezZ56jt23uba3sOvIMdYxKNxxC6huLproierjrqZLMTYntFtckI
QobzUQ2f9KsMzMFrF7dSWOZoHDBY+dBUcgTVEXRpfUDnTkAFmFA/sAMUHhW+
hEaWidbVxm4SYVBj2P+FT2B4Mk3IHwbD54OKG7akgV6M2hhoCxh7A73CfqOZ
wOHKAdepQgElx6ico6JqeE9gV9IBJCpE/EzCD96RNkfNB2OulivqmNzNOEQY
DHbb50ag1xT69wZuuxYLCAISywAhYR8AFVRQElCz4sTFTSpFLHOATAOrd46X
BkewaeIkaCaqGNhBJNDiPS0HHVl09Mf1k7//PRLkhA4H23bhHXznGbFgUytg
Qhx77iHuCOGt97i2wqY+V/w6psI0nKlrUk39FdQJmJc71KLGwosLcySM0QeD
LIJzpZtKVBHEQSEk6HFD/bix71k3o7Vg4/pdozFjTPAtchV0+TvICEf6XcDT
C5CkgLlnpdU9VsBLDzRJgidHkfNPySMifJEmE7T7HPb95FEA8pD8Y+iuIAnh
madKeO0q+8b6ptkFs0aRfBruVhj3iN4Af4yu4f1KeRM45k4fHwkyPX0tfY9Z
STxAAUGk8IU3y7AnNSrk9zuDiTtp8XGzh+8XOCcoUSVcGaEzyk+IPdqt0MHS
ONzbz64fGPoInCIwUs1ckuRcmgL5GohLQCJ4q96X3xtTHOwC0PFPaO8QprDU
yJXm7dEHoH9fk82EjUzQPvYz6hwFc9BYUhTPz2NF3flEPs+mE/h25U3yR0ip
mF4MwByFNECIxr9KtufKU/ErsJ49lxFIfYs5YD17y4H3S+4fQFQl/D3JsWMB
v82A6LxjYT8pWV7WxNXJIFxO10Kkf8IqcNeSB37PIID5uu9QGTak/W2P+YHl
lPFhHh35o4MRhd3D7229gKhrPOMltLHKFL4cmivYOpFbhL4LcsCi3d7zoQp9
aOiCUOz7N10AwkjCNQ3Qvly1+wNYXY6lyvZGthgLJQWrzUlNzEUa14DofZKW
F7Z9mEJjlaQyWj8eWDBf6bo39t0N/KDce7r/HflhQW0TRTHyLwD3/biozgF0
cu+DtctNGnqfjb7K8X9JB6zA3/FyT6QF7B/Rx1nvcWHzuBx8jc7cr7CnKKqr
h8BsFLfoKNJ8mMhkH/Toofp2dHQKDdBkt5h3tnwstOBbB+QNelNhzfh739ER
TvU2YfGagI1Y/QxsLAIjK7jn/4HTg+/xtRDM1CmtrB2KH3zds2v7ZNx7N/xY
2L2yzfXr3ZvWAoe/s637E/K9Otg5/vruPeyNv/X6KbzVj7CHvDlqxDl4fyPS
Bfxb4/tA5L8dxE4EsQcqWG/cqBbQqv6bEMr2ALshaDcbmOQ+f2/MW4Gq75Hr
W6clFAL6w7tg5uIv6EP/4X1YjvxX9CEqUpJFsh1qRm09aRzTdvug+xtWx/YR
+DeA2Dla/9MwkuOx2aI2O0SSjYkfeHhbBWhYn8hxjx/h9WlKzkBbrmkpfD/3
zjxBrcU97Wewji1QEbmZRhqlwx9gqLWGygeazKD7cpOvz+QUzG+WBza8YU1w
2wg+LHifbQ5YYFc8YWsTTRXUzPh5G41DYzDACZ0u/Y4equbF72hj+GlyYpVH
Oj0DMw1UUIzXpCN8ae6bxKjj4ZV9xtV2bIT5DASFxzWh9zeEB5Ce4bHhfM0d
NWhnwGcpoatJDqq0YT2aroLReDH8Bp2O5IO0wHLwTgzogxHT0K+BN/ZVNFrB
zoLn4dErJtoXmGoH++e5ao7pgnPoxg8O867evMBZAaqAAkkH8/hqrFr6Ei1n
GqI8Veeia6iw0D2FmSMpCYP6ieCFtJJFr7EgQoQfHc29UW7aWYF9h0YmqDj9
3tWZjztT/oYo+O7c483cYX9IgE/N+mGj1RQ8r6OwkDSXcbDOeo68qQX05+Ox
zbFDY2FcTyYvj03xNXRUHYpRuutsfFvCBOA6wnUfp1C21nPHnFjSfKrKoqaO
LGQKC5AC8mBoC+2mYLDzo0LdtIDcPp1/7zW7173BsFEb1H7n95DQI7UJg+A9
8WNA2U8UofCoReJFdYLrJcwo/AKM4AfB8FN8jIK0wPxwdifyb8T8DGaQx1UA
2VRlc22MrpK5aJ44FOkOU+vb3kTgoCOOQxC/F+JsZkikwYa4kDwZsCwYXUNj
K1kD6i64r47ZYYsbRs09UgqPRuBzC0zNDz9/v2xefOKccPh7eC3agJSmcNMS
2IxRmipAC00qybbRFlNU2SELnh96MiLt1iKVJdfmNFPYGC9OgeHkje1YkNHt
p1BzWociBuwIjd7JGY+lOcZG3Fzf8Bp87ZOeBg+WK8DFEKSoFPji7TtFsZSD
/0XPJCRd4TetjLTvbbfT/NjWEYN45pELWDno0tEV0R6J5UyxSGmfDn3XMLkc
TQMXIANMDBc9YzAtFg9wBBHmap6E/ixI4zFPQoai4gns1aLvkTLJTYP0BkCu
hZ5B2x179NKC5eCtSC45mEVend97jX6z2fhd4EfCXFIQs1vQmbYmFpfIr2e7
FMfl+VkDtwJyPu00ZC4DbBTAHvcApmK/KxL7o0FNIoVuPo4xxMH3JgUHH7sB
6dw8V5gOi8Sx6KoHd6kqTNJEPjADT7GAqVzdO6fGRUPJJVAeL33PER3o8mie
v234wdej6VIeDHGKou8anvX7l/9uC7+LIq4w6glmlim/WIo8d38XPn3xPhLy
qSIo6O2r/qB2eZnSlb2uQBM+tm0t+JOOzbwfIkFIbyAcHvpeWBwJrIDNNAHt
4O+92hX8nWR0FymKiMGszV0QzKoGi5lIBSQOnO/oMJQmvkPEmXIumIKuwiWw
Jy9opoAJGYU7+nudv8GFViZ3cFyaS/GS/PUdaT73nLRIbm7EeMrGwak6QV94
LlaZCC2JQbMpShMDFAdgDn/mRDoYOPDDMyn+Au10SYA55i8FHt625dMjGaNL
c9s7ZPHCO5FbQX5QHIJJURd+3DiIi819ZhT+4b156xSIXC4wvhSMjvEXPOIW
FMMNkA/+8zXS08eaQPfinn+E/Y/j/vmmJtD90VHXj/Ts8DORoyOABeMWaUPQ
fHIGKsdbo/dGHjRDasQ24t3X64HOBj17sOrdW6F1L/wH0R/40AV4/7F192CM
qozlksgNN+FiK42T8IkrEIcbxes/hF4H3jXv/BMg0Dc4HjeuSRsw3VjlmCAZ
hJtmzHRDR0KaNIIwbp/uOqEu9486qh/5Iw9Bp4NvoUEap/Bp0Dh8l5kw5ZVD
cV+Az7YCFt+UcLpiDoXH2+ha9SngwwzUtv8geeLrap7KB3R6G534pogs/2IL
nVa/kx50I6T5yiOj2dZi3UuMj39KvZFGXLv4PdTd10hsAUpQGAxyhMcpTX6f
cKtfVP3Td6BZ0ebrmy7vEt/XyCP933siPI0ed6LWJsXFXqjf0mTT/eUg3P9X
2CAo6ACWL7bEyMJ3SPotTUK29dY25At7wQvZ5bburrgHCbIl19FmHnhRln5g
Cyq1S8M/EAlgc6Dc9LO57RecUkaAHtBpJi1Kzwz0Iwije1VEOQyr39GNjnv7
/V0sHZ6ar0LPNey0BmOz+Wn3r3v5Rhis5zviZf+XvUDVop640vvm9vPRzeTj
e85bXxIKKBSadbQ+o0i3uYAwwmJpZ2RXMW8jH173077k8fQuzn5fN8bw/v7j
JelX4YyEV6CSfhMKtQv/m8g2tGl66u0m/iXmdLCz4nxOVVjfljzF86LAARIo
6H4nHdDDrbUIENDs9mXaVyG0A/vdtTzVMh3sYmDfSHjFYHtMQUsYTvqicSps
yBqxzzct6hbzfQicdH2fdF8FyqLim8gx/2BUZ9iNHqjA3oUTkjVh0XIZLL6t
K7O4qvd7eVCIdMGYgynX91IODw0pvINMY3yzzSv/jukiOrDUD34WGnTXCD6/
i0SCNHiUCMrIgapjDAbjsUk86LG2ud7BD1mBajXflLzjQR8oSZp0NkoEZOGz
KHiFcT6qoRJKm/gU5senUJyL6QWQAIRMWbiWwRJB65nzZhQFxCD4OFuAccmh
j8N5Zz03yxfMdb0xq+JTesAU2OnSZPSyyjw8Vu4frVa+syosritGTnQvJo9p
jHfjaUOo1xL1+sWjFkbvuIZMeIZsfjZK+T1iZ/Cbbi1mcrlytgRmfSEduZ66
SY+Tsmx+ydFhjMf1oQtFXgMWYSrkysIpG4XwCUIiN1dXdk8DhS9HR8E57y9C
q33WwnyK/J7M4dHRf0fIXs6qMOy75r6jv01PcXCLPtzSDlzKCRYCgy7zvUeA
3wj/y4aPotMTk9UELzJJNrPTjjThAZF4iEFxplmaguCWPAVeUKN9xPkAxlW6
5fmt+E7Mt3EtprLixMymciXobAfpifmNCGczOxjXdzShb4tcxZspGsVxfIlJ
vvahSONt2Om5q2npYoWWcXl7BHeb3vYMhryz3zgib/0ryJu5mG4TxR9RzBLO
KL+uixEZuGK3oO+Eau8IhT3n3zEMUPDX2A7Lvi92crvrt95rD9r12qUHvwor
y2MwP1NZoh7yf7KH5NTK7ZBrp0N+DO/TrbDba7Akd3rbPWv/wNSEkrEk64RO
2n9kB/yc/cf2oP/gHvgZ+5/vIZAJu1ccwUr0dhPUxXRzwdW8mGjAr0Lhz/Q2
Mb9fT7GU45EDHyBe6c90wmMMor10mo32bcfrp5TKx/azpeX4AQibXj8qYiof
BZ/7juDf1aX8SIa/oJsPiMfYbjY2VGDBRGPZw3ZE2IKRtkwXHpx35V2aRsuA
x/cZ/NICzQmG00rGenOusxaWUzAJTMTeu4YdjjeIREFQSPDv90yaYeb734/5
3xut3+mo8PcTSWlybeL31NER+m7AcDY1JWJHkuvJtPFUP8VSxx7MPt14IKg0
NO8BgOYj1TRYwKbie7ls/yauxEvjUJBh89ZLu3vQxNy5TDKwMoVpgI34hV5s
NJu9eXanps7mYIIfEpGiIWThxbirsNMYfO2RX+QIZgZGG0oa5d9QBXTRNYXh
GEBzas/Dyu+il0jeTq4kXKoO2tPAFZtIygVs2rZsYlTHH98/dDZqV/M1HoRp
fvF7+zDMN2JovyxVC9bBnA6+QjZm6Gl6DKvEDh7hZTXusECMPn2h45ToiTQe
3Glck/XuxsHTtIsp64IEW6LM8HgvHbZx09QwOLMWw+/48Xc2I+YqYiaT9Y6u
kV2/1DqN73Eins8UMgHYTcdIOrojeYWXDohmg2Zzi15gUIdpRVfZtii1DaTR
6JnzDQRFwZVBpgguD/r5z6R1ScxUxGz2x9G68kFaNx4Ucxmy/BQtJck6eT4U
U00HWdVKxUqpUEiBxZnJ5TN0j/AvJFcBWTMTZk28+FykI4QlH0nfkTTmhqTA
SpZE/9LApnSXzT/z/xzy9GJgbXvMsIkFKRaKmWp0eHGZ4b0GCKPAg3i9yHVE
7gQ2ntlprT94D70RfjjGJL7B34amNMN6OftwLGWr5VwSHLHBIWKY28ZQUnq1
zgbUSAJ7Vce14v0N+/76HTk068XH4A3q/F9IrmxScmUJxeoWiqfSCKT/jCnv
oTj2P9z8LZ7pspkPYAgPQw32Yrgv9iIK+S+sSIOjjLmCwC9/HHgZBEIuoRO6
hREbXry5gfLx9rn97Tfa67ZCwwMpF7sKTcSHLwcKjRYoNP7poryBGJxY4h3g
jb51dAQIga5J4aJ7zD7Fy3/r3zNVeVCWTt0Ia+Z4fbAg+yvWi9tE9+1FlE7C
eEA53qgNsomEss8sGd6YdWBMBs/pHcmNROoqZvuiWzgHB1705c5NMdRDtQ1q
m4PQuen4+mDSOOlP29lPeOIiGs3G0Dj8/N5dqX23oGJuQH0iWlq6H624YJqJ
9wUPvXtRle0G+LiSKgvhy0/b96GKu3ehqsKnohDb19YdqXKEh5ubSqYJ6RpD
TMHjZy+91dwCE07HRAxrjA5UdeJQICnX3I+JQ8cqBgRiaTQKoaVXKW5SUSSy
gxmswn0ST4X8rO3ogf3BQc0OxwnGRpIT/rG5iYD7HQxV91KFbThzm1w7WQEs
FrqdClwmhpI4fN+8DZ/3SU8+sl0T7r3zAMQzWUqQfWUGCKdv9UgfHLTHwtp0
eRopHq07JmOeS9rY65dbUaNzOkoRsECFawtorAq2yaXkkkdVy1Mmz7zMZrtX
7ndu3Ks8JBIee3eda543Lt3h2ROA43ZYcpCIdSiHeei4JJqm7+jI9//hZVRr
4+g7OkJX39HRfspwDvyXTnPy+S85LUJqhmlIZPEPI/6nX3Zyz8TXUNkwepLz
2OPvuWL/BsPR1QkJO2CJeJcvT7gJY4T9C0ceeGE9JzUQIHzimEtl9lJi63h1
Q4XkhxzHUY7m2VQ8pPxhxQ+KxqFavMnE3B5DHnZq/9T0vbPXPQP50EHKdxhE
dFfzS10K/XBCNPugtn83CsLaI/nTuPcwVl4eYRD40dZuhZh+nEFJsryTtKcK
nwn2Wh9h2Zt9+W/+9pGT0qOj4KwUiTx2WODv3UHhrTwIITRwPJ9oCxUxqn/O
DJG8h4eeCiz5mRv2pOv5ZFrqBFUX3CtQH0YVSswUuBeXbg/Z/K4L0FLMlA4P
MPlyDWP5KJfi/RnlI1BldY7pVecmOjkUwcTIfW/PwqQtfKcawb6XRGL4qTok
Usv5bG7LKAK8SSwS+vLNaj47rcjznqc7BcxCosjjFAAgD61pWbB0JBQBh7wZ
+Yf5qXhwaQSnyh6vU0QdSkgZJYzt3zbBYrHrICfi3kw4eJMsqJrk3X/CKruO
d0MKLxp6SV78BJxTP6UqWiPc9R+fqZIGErJUYEo47jWKI+eALJg+kydB9Qwy
P1kHH/TRkaLyWzXAxf69Pp5hBHScNzJv+LTj3R0d3b6Rvhg7UR2baeNw8lC8
XMQsI1glW2mv31ud1CdufKTBh6dcjWaBpQ/3Z1aORwykn58piC6S2JhWpdHa
ygLy6ffJav37IQ+WA5sx+nbEnCVqSPImYw9Pq4R5WFqB+PMzTGHg3affp44t
+xDJuN5E5mHK66CVjgOaMPsgnxJqm3xVW9CkWGihPFeYEl46OOjypY7JULyb
tvGXYxCml2qc7KAgvXeXTwil965jsLDGuznDJXi4OTgJlqXwB2aZ8g/AKHLW
S28kYajhoO8XsLD8O0jIzPwC59u+jRSlwwkjAKNphso0STipfT5tfW9Sz7KH
OEMxrUIpLDfzOPAof4GUP8sd4sx8DEZ4/qJQ8of75iSfaE46KHp7PH84bo21
cNKmffl2vRTh0RjvPfmTY1Of7WzgW5lxxO0EnFOmze0gExuPaM36+OH3GO0Z
5JfaJDvd1y4XbtfmWXZi0r55qd3ey11G6dw2F1s3+XhCd/zovK7rS6PYf75u
cpAJP2ePc8eF41L0Yf64eIyOmO7uqNGh8lkU43uIdOZ97f8l+BNzv2SFz3Gs
SlIOWvyP/+t/84D9j//zf43+BaHk3oEyk6dbUPjfolDy70L5XXgDiveXyL0L
jHfhvE9Rz1trqZzKEr97NwGLH11YJD2DJE+UUsnzXwULLT5Bbygt76atn+R/
//lsXO7eH5a3N334Q6Fr5iTlrJyPZwf+YZmBwwP9AdAjA92ff/iH5R4OD+0H
QI8MLTbD8Q/Lbhwe4Q+AHhnhezmUf1j+5PAgfwD0yCDfzdL8o/Lypn9o1t/o
ID+U/feHJfYNj/QHQI+MtJIKaxHQrV8f4vv160Pkw/qB8EMD23N8FNrrfya/
d+B6gsk95RuxTTv2Wy953fDm4NR3jIAKeY++bo10xRhfJumHx0Gyhi9kH4tR
B9BqLoVOLdDowsuaM2Ztbgwpppx+q2n68Nir4h3VXEPqbqTKi+1OwEZ0PLMf
jHw0RKfrkaX6uVrR9PokRxdBrBLsp07a+/rwo9k/vYOufaY/z5ekKDE1kd5D
MqyjYz5nY72x8EfMYGM1ev78z57UFHKYV7skesJ0dLQpuOJZFehTx9ncmcYw
Y9AX7w3LTwrtNULu2T6sHK3JnxLyUXpH5Dzt0aboUySZyZbX9zvwxE6tHTKh
Iw5IIiKdS5Gfk1IMKZwQH0FAzBQiOLyLrud/4p47f5Lgh2kxPQg9iHpuyaWX
+qD4uaxdNLn46as63izEIcHIMd26DN3Rl/tJLnzRYMJFS/owV+Ij0WuUPvwo
imiCEIbvu9t3K7juOpDxnF0yZuRb5RzlXz+iad1cTHrfN4+83Nut63nEw5eP
CHjoxNPGpGRrQcHsypbp2n4lOEAT2T8IKj72YllCESdTdTKla9IYKaCEApa/
JQBH+MTzEG8FFf/xxyFPKhNK/Hp0tEn9CiIBk78eHWGUBp4DUfpXzN1+pi68
DMKIJy8dJHvhHkEQ1Daqx3gWDZsFJd5WDjxvOQtFdPArHbAi0fHuVSGLE8id
2/7gwLUmPP4Fj4jjxa6XeP49JqSr5Dn6Lz/T9l9u8gxGM+7y2mgYS/XJS7Tg
B2SEEuLiCQGmVPCCl2KGhRJX9Wp88axrtASxPp0vECzVnnnItgVp4qWTZuiV
oIxu7hylsR32QYeTl9e2evNrNwR1EKURbXQGh00216ZaopduDFNV0QYWtPLS
oHk+MfbikrCn07kJllcw/Ih5L5URILumcz3gOFiakW+4uPVqnWKke6jGWAgr
v5jVsbeo/RpSwE5eESjbl/KSxoNvgkzoeBhlKDzDHfOyLB0H/QRxEhwdCh7C
xIHyJuvWiObNUoESTOHavd9aZxKejYDQ4dDxujm/kkl35QOHoZcTw+ewyCEI
fEynLbK38fpZFhHOiJLO8TQa+I75C9J3vfrHBGHG2kyv54wNKODnwfNziaWE
fnAiFT1Z3850N8KjBp6gQOISjDJz8ayB3oySZAFRxKdPIs7cpGzboEUjgdc+
TwfU4pFRbOznt/OyUZIjehDwJb9vw/XwgWlq6PrHdGI71UECvSNYHJGqkxgv
wBWQzUanMkZFNiy8hM+Yv89RJvd0tQJbTTF/6NcT2do2N+n8eZWtaAUJP24m
dDoHSPNjxy9jdYUy36vWTjUh/B9+Svt49/KHwkj2ltsOWUmYGkdKAy6H/ADP
JJ85TBsmEqRsIjyvPlLacnhEI+CEQnEMNKLlG83D/45P3F8GCDtF9LE8ZYcF
p43L0LkO1mBBZgTCIcNi3YeplwqP1xkIzkYJLLEPrtpQ1oVNrUhYWpvsm/96
M+CRGs/w8epYdGFtZIKXOnYXW5rBSPba40AehOrg0H2QXWXqEGuo8JMyztMe
FwQLSA62ABRqVIGPV8zlQQTR1IaR6cGJBgC6X1lFnpqqzLxiNWhaaaCZhKRd
IMf3jBEn7ZgrJ4E6EuXAJeHJAy+9DeLdgn9XJha49vVmP13HvxyH7F+jpH5x
+WKAOtvtX/A4kI3Cmjo43eGNzwcH/zPt1sG0oHaeTeWPIwswgBG6mtZQQcIz
scU0TQfWRL7yK8COMb8KbntMw80dnmuaOsf8hyCPF4zqi240KeB4L92ul40T
L8AxSpaKSKBd6xoR+5b7hzF8PKhNuSWSre1cCfzoZVMTkbhrD5FQet/zvKGO
x0SwBRoqV+s5ffc08wrH7kix4EjUO5eab064sdaUyhXJQBgKiklry3dgqJua
0YBPwKLR0kPBLPHCkjxhqe0dg2+y7RIVDLSRgOB+dEH0NdoofqUXQMtjhRTe
H5M1KhvOUx8pvgbpF+4EA2XiWkESSdj+Nkf5B6FT/dgoZosFJUCdoEDKVtNQ
Tm5+FlfZSdYt6FwXs4m3QUdg+nwq2eprOA4ptIYpZjZSRIYS64K2OeHntCQ8
XS7PsKYOTpQdQZcqlvJxb9SV6P3LHgUfHWxeR8N+vETLkXKr3AWxl1gpPJ/G
j6m0lxemEbrbgm2b/eteu96ne8uE28/b11UPgtPM+FSmoQKnu7XiaSEF6eM4
DTGeRGZBsdPtUmscmU5Qp83H472UqrF4bLQw79Q7AO9HOHvr5aD2RoXfN+n9
ZqXbS17plgdMgBUoCXUUg6DcBrEqBltubveiBkifAZZjrpJLXk4FTKs0Yb7T
wt+l34jbRlUTo5ejig3tC9xFYenv2NYpCqRGOdJjExUDZKIXp8gA4C94VL9/
zQ25KZ0ppzOFdNgvIQZ+CVukpIBiYI+Kqi2OLHPGDFLQYQsTdWktgpgT2Qp6
SBdzpVKmWDoEjD6dS3PJgHk+FL6caMBJLcm5AgoOzNk6lOpmhK9gLSNxUw6+
S3txq3Y6m61Ws0UC5tNck4yJi2FPALVFzizDDG/L0+AZjTUSdb2UbBETqSNP
iY4pjhiNQsMqoHygIAix/O5aVB0YqoG+WtrKQYpNTQVag84mwr+I0hcM2sHj
AEWOXETwHtgpDK5i/ELCxH+aEKG0qmRL1UoxWy4V8r+qv2QzmUy5XCrl8rkK
EflLOClZEHuFZA5lJWN+jneLJyQLoxANq/Qu6nkqZPrQY6wrtnLOmIECjycO
DHEYbjrwGm1Ahlln6TWNeu5qNksHvqaxJi3FjdYqqoa4n+sirrzAEiNcGrCC
1/4we3T7JuzghJc+c3tXcxCPzUXP6PDECCFo3+BITlUH5gZzM8AUihRVL0oq
p0a/jmlINSW6xGx5iQ+pu5GlsvGbC8oil+TeIdJSQpEhjpELaSviZKOeM1nh
xpUMx9XDi8ec2ClKxIA6FU5vyp2lM1nR+1RsGzJO0UZyiLhxiuiiEmeMzUUc
q5ccHca8fmNObE4Zr/occSn6k0WbJlOdGA61pNoXpAPTou25IBcl4xBTFHis
eSmNtkjnvQG5nbLcNIqBdLFcKBaKqfl0TmDOGHA4QqHhglCJQvCf0qXQWJZS
meXCDz7VYMaAqOCI1jFdMkmqvmqEfOZ4F8yQWQpsTCklG2lk8TS/EF8WQWzy
DQtYWR3b8sqpVovAWdmUwi8L46whlQoj9TXqh8cnXD5hYDFmCQCtWByD3SWJ
MBdzlAEgXbHYuiSCmvrGrGwRuT3ohyvw0hV3B+gb0FW1bY0pJt7h0lTRkOwp
/DGjBTpl9sxdu6K7ll4Xqo5+2UVkgWzRydZfFT0s9GwnRc/40k9LlZypVauZ
bfpiaHpYOCGS/Bk1JDQ5VdOFNAi6bCaXC6gZgqOOmTEJ+XxS9IBf60lX3Nvx
OtPt6C9NPgnuZCIZri1t9es/5jjDEN5iHxQHpsbEuerIU9wE+XaBy4CCk2kH
xF+yZrpArqUprsECttGT5W0haNmO1Sg6b2d9m+M38EU6+JYOaEJG5F5Zxo9g
sQ97bqpOOMGATWVnXU5mrwgt3s2u5orVbC1TBI4+qYvFTLYontTyDfEkmy+U
T/LFRqlSIIiatFgJ0cmjacPnqanrs3J6S6ryc2g854RdDuSoiBd0RQzuf3sH
4CMwp+6WqIAnfNWks5lCsVIqVvOFYTaXy2QKmSxXOrpoCtBqIOQU1YnkRQme
pVSLM9tbm0B05weRWh2XcrmsmCvJkljOVfNilbGqWCwWy6O8nBlVxpWt5Xip
drrCXfdq070GhuxizjUTf01GFQJ/0/GScXJUcJo9YQI7XEphi61NDx8R/9rp
WbvUNa9euytqAJsCEDdERfqdIi+LpKZAmBEO/iwB7UR0BUV3RsTB5tsGXa5+
c9/2lEW0q6n3M7yMwEKTqIxSE0wQwNy0jfcgqE77ry8us9a/RPmZ2qNuktJC
7aO5fGTVkjV4T4/TUe/XzwF8giQDTpYGSnBYVQw9pBnJFTKV8nYUSmSnxmMb
Eb2Xm9wfeHHEQA1ZMkB9g2+t4B1XEo1nEO2BaraVjYJeUmoIzMS6Q3UxqHx1
GL4aFxK73hPS6wiGd6YQQRs0S5RNCNU7POC6TF1yoz4tmT8AanBggMzCpwBN
8JT5EDY73BhEkgGkDO2a3hPakBUV40/SpfKWAJdtxYgqMil8RG2WTF2pxrCQ
y5dL2WoujZkEJqa1HmbzmWoJ9N9N7yZszQ5NdogsoYd+epd9/MoZm0smj3np
sI4wHbjWTLWngKlfiwR0EDW0g0QeUzdTaYSZYvC6sQrCI7qK3sBBlUEKvkpr
dSzOJE1dmxafG2k2CmvZ9JNbbyGNSzVCmw7sSsCDVGQlmGFJAWtFFna3XP5C
5PKQpZegGYD1C+rdGPZAAgc6M1pcDMxRiQFhYBgoAejYgH7DhjuxAI5ElZko
Y484YWAHpEvVUjVbKBf5Amh3XM1RwRQK3zHXvWd8s/OEHTNg2cnBrXKqHAeG
Hi/g7CuQvY2s2ljidG5LrsPg1HXz2SZ2J3JF8Zib5xv/o+9SpELo3KjugGIk
oZdQmkXph/sXdGkEmoOd1vm3c2k2fEuHxqP8HZMaPe4LFCXlQrlayBaL+XIl
XwLOz5QK4otYK/Cp7JmKpU5M4cQCGpnvYmNZI/pwCLoVF1n+0R2X5OQUQJ4x
TBHJAxsz3V0iLIqVHOyq+VKpBOgUc+JDplbkWJzgmVzXApNvO5nSHhxG8DHs
ZPSxWCgUs4VsbmhynsU8DA7pR2+pXBtsCtVytpKrFsD0LRQy4nKs5n3T1LRg
ysDyBaKOWQxCoDDZ9E2ah8AFVE+Dzp3mLMbNjPW/28JJv31wsPl5yhTisms8
BuUXK/ea3Z9O0KtkS7ojjP/xX5bQR7XamjKMGDHwXl24mc3dXjOe826L+YS6
ZIHJIbRUzcFiYUATqhJt2wIodjNmYwgGdw0CrsfQSlP+1VxAn3n8Sb0eDTXz
Llh6GV+CjPY8QgI2CxA3mhAScl4gCP4nUhELPeDksUbvOExLaJn7gQZ+AvwD
nuCfMrwzR04dc2chBi1QSpogTcJoLdTrXoeAN8XakJNufyJAfhgXOYpQbf+Y
gHkFNTZ3PjB1S538i9xzwU+/ETSP6Akev+k2DSqyzxnoGdzFgYculJEygfeY
YrfS7d7gNJCgkSuunv81+MoLqgvxqJevhy6rjNZbKRv9S7HBnVfvQ+6eR6T9
N6iCpfg1W9/nG8aDut0P23OohnDwYpM80KolYEmU8Fm9X4GSW2xc8iDR9hwv
7fN0R9D0L1/yQxR+SIEMRGXdPh0dUeVCVMSOjqLf49mVF9IW4yA/5MkxPlZX
AOMT0yfl02zjeWg925V25mKSX9fn+Z40zzywZvqjBQreBXSYECmpeVdVbk9N
p3bz2jKUWS7/ciIvTwZ5yU6GVBygpEjlW4tMM2uPH+zF+sTRSrXJY+VZ7Lda
6jIZUnGAkiJVvDwvqVV7YerGdL7utu677LlTHnf0h5tkSMUBSorU3fDx5ez2
MT9uLqXT5XI9rlUb9nTeYk4mGVJxgJIidX46lJd6q9UcWefD++Jdad1kzv29
oaqFZEjFAUqKVHdYfxys5Unm4qwsjy4k97Qmzu4mD7lnMxlScYCSIvV0/nz+
MH9cPhWN+p3+OrwvnF6UHtTT5mNCSsUBSopUwTbzl6vW9fVDq59dGoupa7L7
+wmrt2bJkIoDlBSpm9K5Lhcri4yc1Rp3efe5/ZipPQzN8VktGVJxgJIiZRQ6
rHjTrS+W05XcPDeUe9Zdg0Uqmwl5Kg5QUqRGrPd6dbVYdtTxrDc+745XTD4z
W/NBI6FEjwOUACl5DL9ui48tpZrVHp/Vl/rAqZ48re8aV6fsdt75MFLvAkq8
953WzcJJp9fo366NxVW1dnMuOd1n40GaJNz7YgAlRWo5Gj7a1c6TUnWrZid3
MhMrzqI8XjycJUQqDlBSpMxFZSyW5aeLi2LvSezoz3KpPb3rn4inCUVCHKCk
SOXcW1dqZBvryfNVo1M4GwxF63G0HKjnCZGKA5QUqflJviqNrrI3VqswrA06
w2a5slh1B+4qIVJxgBLvfauL+qrTYmK/pvaq7vT6WtOsi4J+W0u4zcQBSorU
ILty57cny5fH5km/VR88TPqthydHeXmtJEMqDlBSpKa9ZaF0upzod4paHb88
6bnx88VIM4bthNtMHKCkSN2eldfN4UzTe/3V1TrXeiiNX91T02g8f1x4vgso
8eqbzllbU9jpuFkyqy+ly+rdzMlkavWLhJSKA5QUqYmcU58zi5HJpv2huMhm
xP6Vra2kp3pCdTgOUGLheV3Qa+OXYuv8ae40GldW31DKrw3lIZuQ0eMAJUXq
wT2Xh+vmebfeabuP8iJ33Sk/NMxJr36bDKk4QIn1qbuWZoxO282pKHdvWMdt
3F2/rIqPi/uEJlYcoKRIre5u8/Xyy+21MZHVefmk8HRd7JzfDqoPCTfkOEBJ
kcpO6nJ3KZavzHmj9/p68lrLK6ftiZnvJVTy4gAlRcqpSObo9SRfLmj36uWr
dWdd9x7Ls7PHdcLpiwOUFCk9f7s+KT1c3ryuJFdmz82hWekahazbbydDKg5Q
Yjn10nqRR6OLhTQ0z5ric7Px5OYK+clYTLghxwFKbGI1Kjcn2fu7S9Exr8zF
2U1uMCs1dJ01E24zcYCSIrV4uMrN1fFT8exBrmdXl8v++LJu3MqntwmdZnGA
kiLVOTt9UI1RpfjQly5nL88nzal+8lQvd+WEPBUHKClSz3b1rl3onlTWj/p0
krseSU8nWSmXG18m5Kk4QEmRyvRer3uvD8M7RXss3t4MO/cdffWkGdZzQjkV
BygpUvf5Tit7AsbaSM/e33ZXZzfqVGrL2ddBQh09DlBifWoona01/bRlXuov
V+WTE/nxzmyJ1lViayYGUFKkyv3HvntSyV/oVvWlPsreZU+rBaN6n88n1BLi
ACXmqf79eJJ7vGrWrp3zm/KTPc6utMK1WLtO6HWJA5R4Q9bHV0txtKxc2Mr5
SCvY0mW1evpaUJmccEOOAZTYO7xWx2eV125RWprWaNjPXvWqp83b5sN9Uu9w
DKCkSNUfl4tOufhasgZtJVfLPz0tns711upaTahPxQFKgJQ71uFnrro6fXoo
1gtm/2w2f6otHgbD8uPlfe7u4/P3PqSktHKzrdXjfVU+H9/N1Xx9XH3JlNh0
OX88S7j7xQFKilT/bFjLZLIlSbzoGA+12ZnTuV2Zsyf9OSGrxwFKfGS0LIvX
97l67c7KiDcnr9Uyq3VWJ0Ojk3BLjgOU2HA31iNZGi9ucg2xPb0dD+5yucr9
zenVNKGNHAcoKVKWfnfFTkfP0ipX0vJZozhXnVZ7dX0zS7jRxAFKilRjMj1X
zvJre9Q9vejcsIr8+io6crvzklBSxQFKTKmnS0lWldzSaDrS+bI/UtvtsZMf
ZE4T8lQcoKRIDWfNk+vGlT24f55Iyqi4MrTnSklZTOWEGlUcoKRIvXTzD/VM
R7JOT2v5fmd0Mr+/P3dWtfpVQkaPA5QUqdns+WaqFtaL86FaWz5a3WVWtk6n
oi4m5Kk4QIntmZOZcuFcvA6cwmk1eze3xhdtQ5nog1xC5SUOUFKkWq47rJ26
2ezJwFJWF/l2Zaovc8/P80pCwz0OUHK3maGaq9nJcHjz1F5MT42iId2XntsP
rwn1hDhASZFS7+16vaZVHp/E+fWgVrbVq9sze6yprYSUigOUFCmxdda97RXr
C/fuXr6uTfJlub9amrWBnpDR4wAlRerSuHxslkdnN9d6fXX38FKyHfXauVjK
2YRyKg5QYp4ajtrn02vlpPCcnWQM+XXVfVqePjh1M6krNgZQ4jOHdeHl7ub8
5qxXyYkje3YzvD1rl1SmZR8TnjnEAEqsT53n7eHjqTGutm8q5cEiJ2dfCuN8
aXWRkNHjACUOLLm/6Dw+Zh/Pss2c2h+21jcFq6Ff242zhHFBcYASawkXWaPR
Z8va6O5yuGTX82plZjw+yZNSQkaPA5TYxfHsvmbG7eeK8/xoyre6+vT0IPeX
y9NWQkrFAUpsODyqd4WLpysrl7FY6WZ2pq/v+/l512EJtYQ4QIlDcB4nKz2r
jpzSvKBcllen2ccrRcs89OcJrZk4QEmRKl1eTK7nudxjb3U2eByJqniyUjtn
r537hL68OECJRYLZki+6zsPl+OT2sf5kXmUN47rEsqdiQkaPA5Q4hqO/HrWq
6tS4er4q95+V6fRx+OCsph0n4fTFAUqKlDI8q1jly87Zc61QPOmy1dPSHut6
zTlPKNHjACX2JYivUqU0fDzP2PPlycPJcnB387pUr+tWQl9eHKDEkQmFdkdZ
1FcVrd+8sOrqeft5ND+p96xCQiUvDlBifap2XV2fnptj7S67bCyX8rRQVPSX
mb5OqKPHAUqso2cuX1rjE8m+0bVS9VGsPmlD43lsNysJV18coMQiYXp9pj2u
5eHacPTFIAObxEpTtKW0SnhkFAcosZYwWl5WZUUrjdVuZnFyNqn1b28butRd
J1Ty4gAljnZx2LI16pxdnNxcXzRy9os1GVjGvH49S+hLiAOU2D9lt59LZnk5
Lkwfhm79spgd1AcLcXm6SigS4gAllugludIodU8aPZZZFRq1l4dO3ik0u3Ih
qUSPAZQ4rMs6KebL51MnN2te3tX71qA3c0DClJMG6sYBSopUr2tcPI5v641h
p7fMT41aJvM6KVUK67OEqy8OUOIYjk5rmLEvL2+LHTYzm8br/cW50T7XpX5C
92IcoKRInZ3Xa/msPqmxqTY57fbc4bpVy2a0i27C1RcHKClS1bGYy553Lkp2
tqvI5qikd81Mybpa6glNrDhASZGqvLwMz04H+Wq23RydPT3d3DqPneurh+pt
Ql9CHKDEITivbu5Wq2uPndlZZXLVv65rq7PzydK4Tjh9cYAQqSZPuvA5WTTA
eHU/7zna4KXb1B4qi4fCouKqV6XiIKEUjQOUWLGa3Wae74erVu00W7GedOfp
PFfLzYfLVkJ1IQ5Q4hCFJ115vLjRxlNmjabmst3Un3rLXOs0m1C0xwFKrO1l
nku3c7sxrLPRS7fbuZo1zuvP6/5LMyFzxQFKgJQlOXbathvWU+/0vmCX6n3p
kdWqbb2V6XZvsh9fhu8CSorUdfekPbxXxJ45eH1VpsVG5vzJvNeuztofV6ze
BZQUKWNsKVZ2UO0q81JjOHvONZ38w9NMnF5/3NZ6F1BSpCadzsLpZtsP9sPp
eJR5KBqdaW8gXV6aH98E3wWUFKm1dHZWsO/GhXl9fJ5pXXW7vUX+YZKRzxJO
XxygpEg1pFr2uXFzdSqOlOviSlRmd6P+q9aSGx9XrN4FlBSpuTNrPd02Xvvm
o9Eo9YqvmlFqyc2svEiIVBygQy8vI+bKvXExfQeVfW9T2mHLORbGAJjy9wsv
/utQSXdLUm1+H3q7+i00oIx1loP3VzFzLabQpOuq95iRc3+5Eq9SySeeXEX4
j9gCMl6GeztZCROv1a8HWC0Db1Nj5mjVcCnjcThfte1fO6d0rZjpijKPY7JV
LFRS79dEdtI9/eMP+NFpD3pNsR5ACqf5xWTMmLlaxbILoVqQ22Vqjo5o1EdH
b4zi2QXyj1Wm/CrcBnhQJk5M3eCo+m7FgdEmqyRefDapxE3oGwvTGAqqTgkq
HYbJLag0NQzEYDwpfRO+pfIIdCt+AL18pqKIX4ICE9EMAhEeBN5Jq4pXOMSr
4QSblMind4H17WHSMgVK04KpMykNTUnMHaZ8PvEuyvu1eDAVMw0D+EedGFQK
w+b0s/YU8fCreGyX8fhEST4ANtZlMeS1Ty0v3xVTDn+lQjuKVxbm6Iin5eJ3
5Xl/m/4pKytVzMZJwNS8rk7X/nlS7W3YmJAeM9n+UCIWUrlUgcjYAt4L0vFj
mmWadO9uPi1CwBlIYzAtKIekGgtTW/gVkXYKO/9K2P/975igulfjNVSwG6qO
LQlEK6oCEakGIUwYT1+KuZSAVFgSp9tuN/h9+3qr3R3Cj1+5RDpzVQVT6gkD
tnJQagSlPbFCCNIzZhwp4RTEIj6A14op2GaQAEA1DqKZf3fzoR/vK01+vFuJ
HEdNJQVUWDKEFU9/QEUWsOfQOP0kQF7OCWzip0848MsVx2ItbGNNyDSVCdOg
N7G/Bgi6vQ8pGbrlRcjlKcM8vZuKEsnoFBl+bg9J8rz7E14znHfuFXSPMJD9
gZEebPXr57QSMVmGZod6D95MzH1PmbnY/1jf99hy5Dcei4r01htHdnHkmDAj
lHUINj0Hk5ziNG/yaBxQdohQ1iGPaeawL2GOYQU2GZ5c29L97Bc7iSj2Z554
L9m90MFsI2ooI80SM+WP/Iz9Jq/XgSkx5hYmLMTkWOm5xMv4WH4KpGj57rqX
iFzyNAesGe3XZPCLaZB8pNzhiDXuc/7e//bO90maSQIV0zrcymF8ghWaqRiL
HSpdAkLHUDBbxibJRrTwymiT2h7eaZQihwsNXr4E5BzPE+MDCrJ9UFHrmMoW
tqm5PAu6AHoT14JcUMowP7yJ+eynppfhWTMxgS/PMrtTJ5syhKCWoakzRrWP
tipjI5o4UtCWDB8IDHRTgsqrOYLZ2bmuwyQbs8mPmBDkgBmto2XIglTSKZCw
oNGBtGVApUUkRRalm8G6DzBZ8YOAb6AHeT0CnvHbIyujsMMETF6ue2ApxNRP
u+JXmjjeJF6nHD1+z1jnD0v/YL4cg4aHug9+a7sjR9ubbVxowuTLlIYnyqGw
r39SUyzF0/eDkkq5gWhRSVjw3Mu6wrfAEBv5a/YYnnhJW6heEo6HslTxjDcd
r2YlKGmwVQt9qll5DBq2pUo6LEEQX9JYOhYGrqmDFlJzLfhxp+LatzVpITTc
EVvPzGPhHFMFYjMmnEsyaN+gjfdNYzIyhRP3WKhPmTFZAXItV0JdoyWZS8xw
ZeKPC2ktCU1LVoFnsG/bxgIXqmRgXjB1MkXxz4ndxjoOfXlqmfLskHiQeXQL
yyhJ5cLo3TTkc3jLsx9RQnIq6BAwnacB+fnvv1GK+bX7gmJOWINEtTlfvpU9
3csBNPeKDcXUJwvyvnmiMNyK94IyA8iAu7zHhZ5NQb37ZTp2UtL7eY3IjvK/
RdRwhJY0VxWvEFWKeNQbI5UhV6iIQ7DAQytmk8bJL2CWEgYgHVUDZuw1ILlf
ZBAEvkJVPgg6rUQ/rV3Q1d4dx4dDiZg2+CEE2NAtLAqpkAy1GObnlxyJ80Tw
yCYFZTN7vKXXJX6FhZ+BGptSHzg0V8eyHv5jymUGvVMZdV8dxKrvmP1yU5T0
bv/01zbplO42UrWBm4N9MDA9M8MO7NVQkbtQVT+cQ6oJAPxIOtSGnEgGEgFe
Ns44XgzldgqJeNqptqtg7quRePzB0pPHsaUyQTDbaBCrC278oZ4WlCxglNXN
LyNkkKVkYTa1gGOQ9cA2wjl0gAIayE8BsxnjQx8OzaH9jsis1+tCuHxdv33G
ZZOvNaWELnEKWZ5Ivk9Y7oatphLaxFjdVqV5O6RahBavu8Yr9W0eeDU7ifrc
rPK/8X/CF5SYi7iU9lS0X2jjnW3P2vuFJYk+fiXKjTzh2khIko5di/QOb4lt
aTAcQ8y/6amYqGP6QwoqToSG/cfBwVfayp10C7WJr2AOGC6DPxswg59srLoc
LB4s+SzCnv3mf+H9l0vVcFcwA66Ou3o4ER0aSKGsxXM5hVWcQGmkP9K5DNV4
7lrSxIWlU3/FxP8SPCmKZeFahv0MAcBvW0M/zrGAaJm807Na4awlZAtYsUdj
BtaG6XCejJrKE6kwmZKtzPvEFuKct6De+9BEmqMu9VXIVUBxnTti7r3ew5nw
Nv3ZwLB2amKaEy8hqaKmYP8DOSdlU6qTZrZpqbJNuRKx6x6o+sdC2wFRDb+y
BTHL+w96/sK7jo7I33cx1SBluQ1l6UsXsoVCtpQrlodbCeEwH9wwaskOW+Fa
WfhyqBpDz9pUhmC885rfX6hCa6826IP+Cotc1f3lH04fvacorPdVWuWteNfo
chQz+bSfQRh/IzHuVMtxQSIgId6hQvLO0MYG/Uqz0xyWuO8rSkksid668/MU
00tYPnyDEnHXEnfqnopbYlzMZA6PhS/EMRu812DiuKkRS6+Lw34vIzZeW5lf
nV9yxSInNNYhkUCCGMJvwpde+3og9F0dpOA2m9FDkNemI5o8ZXPAUmew8LC0
77FwapF75KvAqclwcW5I6phzrIW4Nsw5aAkb2CB5gYVVA4iVGlvp3HxuTqzc
eNC/cO2eOcn3Hkbdm19R6/6ZQGwSWPsaB2oFkYTFUjgPOFOmpuyx1XcbYU7c
O0a/ANH7cHmS6jkmJbfsN6rK43x+w3LMVyuVfKY09A3iYc2j09AcR9baEOi0
edBstK7rhxGZ00ClKbCr77EyWB/LcOrCp0b/vn/4ltxDv/rQpi/TvNaGn7QV
LWdez+5MM0ew9sA4V4mmuDWdAZ11EFe0K7ZARwNR+4nE7ptdRddxrgA61eRP
CbN8sVQtlotcUvV9SbWlwKHUOiW7dnjWPh02GHpehzCEKH33FU3f1oj2LFrX
zuSWbJR6NU095WKOezlN3qr0bc3IV7IKUyVR6lzpz2etaedlZcpytiWvT8sz
+1KTGLtg49V1YdSv5/RW93XZvek+nrGcYjz1Uq9jjT3Wdd2BfcMcXnniNpIj
ttYWulzb7aOryNviUD6QUM6GV03EM+yLw6y3bO5UZhhgSdZAI7Jok81lhXMX
S7/584NK8kcPjgAskg0UXWanTWWiDFf69PnmQe0NpctH5cW5WzTO2WnhW5dN
plos5LLVYdezk4a9s2GYMMMgeS6f6AlVrBvW2pyG/WZt8GOIlGgvQrg7Ww88
5Nznp9jfFLRD2QlqHrzLZFJzZRy3h5yOiq3XaVafZ5uwhxSylWp4t4ZOaDvB
4pvwl/l8LbTAaAnRQZ2pG4SZEcF56m9E9DeE8QZ1MmHqIHk2WxiM6pmFhe/H
evx5qx4J1S4vF0V1V51B6iBuf2ZQ2+stYKsft+x2aPbN6+6uenLxdD5snM2e
uopmPJ9It2ytudPRy80/ad21TKd3Wv8udMpWt+n0fZbe1HSssezpetnim7XD
QGvxsohHilPFK3anjdZ9T31eXdgmLMp8rlLctyiJC98hTMCtdpqwDpj3o9T6
q1fid5odv3eaIGVfZ1vF5d6ZkbPey9pqtJuT5hJmJJsvZPiMtJvds39pPlXZ
fOJxaWYv0ZPRYVJ5GbrZ6uLhdYbbRSFT8DgTFUl7as6jBAgX8rANSZ46ogKi
A4v+KCwNHDWxQEf2KmxJhq3CF2+VR8kWi7gOgNgNDkLoYxF4UDOvsLTKlu7/
fu+MLwIfGIjUEkwBlsUOpmBrW/gxAyLyXbsOPN0ag0kPRUVB2Fu4FsO47qAa
aUkLd+ZgrQksJ+WdeGK1lrjiQiCXo0JN4kJalEDr5cfAaQ/5N7a+vTYZ99xg
NQx3NabyluSLRl5+q/IGgYG+Pm3qOo/WwjlMA1ga6Csi/4tkcEsOKzoeC7f9
GlIpL4L1ECUUhjFs16N4ZzfLVopgQlSGffTFghmnvtKbbdNrPzUCj389OMbY
8TCFRy4HLTxbCBi+jiVwhCuJnJAbAp8G9IsORzbkMVZxitpR+YxQm1uqFiNi
PkSLQrVQzQ17yEs4fOQlNJ22HEXDWqw5tGsG5Z3p09TuqeLJ0/mlePbybCzP
Xqdl1RhpjnvR1uZ3zy8d7X5euu8pncFTqfRUmYuVx2dJYtfj0fQhVTdbpccT
dyZduFJmMnPwmInHbqg6YqLPhUzmc678OZOhiQIjD0tJ456GB7xLKm/9m+8S
JFL5EUp7ZMu2Q1DC73HB4Pdi4GbowGziwcSxUJcMSZGETws+IfgyW47MyLdN
SC6bL5WymeEAIxZQ0/I+HzYN6Mo00M07HPSaw+s5M4Z9F4zEOAF/YVXN1Tw7
Vgz0KWUzlTx+zWtIv0UB/wAe9MsdKojeDiVyEL7IuIL12V/rsBhVPHwxUOUT
BugKsv1DJF+6m+NQSRv4rG/CStty9Ji2uDAJFyo+mgbtDJ5tLYBsaZvce1w7
b0CiCeUunH1aSqgZl43psYplNHltzgL9mSlkS0OO/7/lMv+Wq2T/LVd9wzz7
CBqckN3mQKxfX/FiKtnPQraIrmxewUpo+hWsvNrheCaIPL3grv9Nf2MwH5mT
mqi4X+CRigELBtYdahZF9HTvL4lFAHmhVYMHS34VLiRLsy13CiLXK1lEpBe/
C7Oj9ClmcuSnASviLScYUvTb5HyunK+8B51cbNt7AUhAYNoh6oHezJwNOqfc
tf9ZqBkG8qBvAHpH0vdnwk+8L3hDdR2R931m/2mD+8TRx+TvT9l8Udi4YxB7
eCrHr1iI+hdGM3Dpvop9PGqG/7oL5lphH2dBBOJ3JOvP7gLFfDlbTLYLcDP5
tBdWmIvvKsxFfrwyZcYr/IsBCViJKiJGq+8M6B3NubhPcwaLbmz5tXl9lSle
N26PLyaj63Lh0imA6CxlioW9XqSPDfkT9fzu0Ms/ZOjkV9p1yccPf/pQBg2x
Obsqo4lUKpe80aPnQ9/xfHyXif/znJzJF8qFfDn/tqfC90lc1i6afzX+3zZ7
GqryXr3YvccpdHryzmyev44v5yNjqmVq6ILIZstvuGa+CyGKP4QQER+NR5Ag
5GQTHch/vW0JxRPq2rk2y1fmRLWR7fPFrG8R+/T5Nl9NcctXE0u+grhDwW/z
2xRDfpvvbS1+g3fnrXnd8u4kwjR+Nku5WrHy0spWO208Us2VM75Vtxs8Etqf
N5Wy4TsxuumFNdCMcMpGMXweArT/+NAD72vVNp45jtDZa4RI5ccGUmggjwzk
O7W3UZ+BIUAaaS7Lzwf+tkMQZFAiyoiHICwlR57+uvhFVV6Wo8z0VJva/w2j
YX7pXurj2e25nK+6nemTfXWmz1fiS0N06+bNujPR2vP/hmZEKWv/uCiAbEwU
QPUdiifv6yNBAFlP6BBnbrSH9w5jJre9x1JWuVO75GWErelQiHOxhBR401aY
vjmKtjHG29VYmsb2hmsFBIvCFiAQdTzB/XJ63W80O1um1TZgpO4JmJo20+xj
4YRpEzTgvgr5rHAuGWJ2i9y7FtabmHI7+qx1dnrSCfYqB8i8T3BsQ/ECgojU
dIfI3geJQ0nnSrDn57hRlstkh6WMW2UZ443ZoZ+p7Q5dpZTLFvd0kpIW2dSS
jfTvKThyZaTuP11wcCUJlCIiXTZXfkN6BAzdzRScy3O5vxp3fv24uCjkC99V
6ub/JYjnES2bf49oct+qP12tzfJwkoBo5Kr5nlQrCQ0mE9WK71FtC1A6MZ1O
+Bk2aeH8DBupVczmsqX3qLUcdqznDmutu5UE1CpWvyuxch+n1XfmMPLqBVdq
Paplcu9RLVuSzp5E80lVkvBYrpojfejvnwVHdTT2y0/h+Gg/GJdt4qQjkccJ
YpN/+uOAB6HWvJjZIAQ1iKmFL/jFWljbrmStNwHSQeQwv4PkxZr/S4RC010S
fkcNY7/922h0vXbrqoNpefdSeDixyS9BCxJe7zPwWhHw6jQceblDZyovPJ/j
dVu89jW38PJt5KYAdkK3U6QxC25KqBZeQLbszzQDP3ON7Q3T5fBAEEThC3k4
7kPr5iPpSfLsZnX6fHN6fikziZW0wvBq8mDoduPRB0ta4sfB0i300mT0sso8
PFbuH61WvrMqLK4rRk50LyYBWCyM/XGoqDdUtPVLa1pdl4eXi9Ioqz5M57cv
j9Y808n4QMk98HGoaKOnB+bC0crLyeJ1eX4/yLVzT0tjaravjcebgLK12sfJ
KkmT9PPJ092s/LjuL+fS6ctaqY1X9/n87OqpG4y/iwoZv7MUuUCFcuCjfc19
GGLkElZaKRXvu1I9cz966i1XgxNZMwazcbmvU4kl7J5iPXJkHvJ4+i/O1GKS
kv1o19IGQNodvZbdh7otio+vbv9+/XB1Zev346HTv8GwRFgAHvTct0BftabP
tWph/MqU0vVVe9HtTZaDgXjf02s+LRv9Tj0R4RTdltM39ZyktOXH2UodaIba
lOXyZDKrlE5qwSTtcRrEA964C7pt6zx3Pbx5ka9ua0anbQzvprlcW7/vyD70
cPzP948ZCgRHb0dwWBHBcXva6Z19TswBvPbE0/1Fxu10qrlrZal1R5OHk8VN
bd6Ys+K3zr0Htzftlc1sy7pfjc8a40nvvNMrFXsns0bTQ5t82EmRpoquV6NV
q72stoaref9xNBlfD42ydtc+Zff2N+L8gUKxnFHbV70PSxLQxdLDymUz33Oz
q4dsaTo5O19a686gt+yZUm0zw6C2vHWK7dmYdA7NF35Uydo37biQ7NSbcCbp
0FabpsDxdDZbzmXK2Xz+LfIlgqmj1T5h6TxYIIT0oFb/JkRB498gWM3nstVv
RzAEK5fJlCqVYiaYgOt6N7rC8NYub89CCw0+C86VYDzeMEMDMuW5KGlaik4b
bd4vNBL9RpHBlLMltJM9KLnEUMg9N9wcEmEYEh9bNVMMg85/N9CFSr6Cnlma
Ag964btBL+YKpXwRJqU9FkDFpot8oaveeAFxIcF+h6sOj0Fo36OMH6CzepfL
ubLKL1p6V0f4PUNSxo6FOb+apjHMD0M90PVjDDCx1BG/GX4Q+eUr2vwqGN65
XTLkLUbeng+bJtvOVBx0AstmX/NDul0ptGtXtZ1704PIlf6pZOM1fPqSX1vF
W9cHeGlsBBseQqnJ/r1J8vuApWDQFTKm/PLTGMwmBsZE9BueQARvBxoMr9dK
Fl5fxzvm6+gd4LZDT1U/+U/Yjhjz2BK8K8uYgsgQc+HlXZeckThxY1eji8Y6
Xd318izs3Ebnmr/FbxorPJHJHK+gkHrupxZI+bTx8gxQphqb33/1TS+8F2nz
LDX81AutBN85JYDii1ckQ7kDBBvZwTuOtoAYQBy86BG+HUh3FT/TZdylak+9
m6cWmSBgw3gXGMnGYLLK5bvHeZtLzp6loQZGjXf7Fa972s4madMJWP8W0vEU
0+9g8iRgqbVwgfwhCdeqIcGzhiXZM9P7Y6HK8KgjWTNYFj1XWcOvHhuxmTQV
roEqimmN4dHAHKnAS11X04DJjo62DqpTyJZHR2i47Xnxxx98+LRQMW8CHyDe
18RByKbIuQJHRVP3JhwiBM7iQtJcskDl8JIlGuzeyKfeKfXPBOjgpVmRAp5m
e4itwqqaTB1kwA1LcptwyrQ5PvfTHpjGm+gSPk1LlTHjCLCohuQ/d6cmzI9l
/+P/NXZIv5WAAKfUcjEfgCYZ8hSGAlPqALcKFxbTmYUz8yxhTGMLGIq3h51P
GExN3TYR/CPYwzCmc1UifuiCha8JV+rMNExYU/CkDmJxLdyrGv++ZpjGWsc0
W+HblX5mCgv7aMDEmUIHNCBYbB4D9UxjMnMlxAN7YQyvIV9KrsIRnuPd5Jap
wdaBfYCYsyThzNXwhwO0BJtqJtlTQhB+9tcLukWO1AKYHvN1XDbFgEUcx7k5
NaAVc//xf8OYHcfmX5/AbgOM3pI0ROOeUR6KviO5I8TDT8uAeZA2eRiE/7+Y
q9dpGIjBe5/iVBaQSkVhYGIAVbSo/AwgIcZLc8mdSnIoP0V5It6Aia0vxme7
+YFGiAXRKW0l353tz3av9rf7IrV8IW5o1H5delZSmAGEUMEz22BRBo5YeM5t
gvyy2Hxs3jYfK3zR5W3gHbxYR61ZNnEmZlWuq1DdrbRj80KvJJ3ymwbWH70P
IQAfzTbvGUkycINQzI6wda8LzypalYF4Ds3/Fv41X7nWFy5p4B0+KNoFWBBq
p2Ucs+CpCZBC/LOpGNVcQRFfTOYQWgXQ00N591sUcwAV2jSmHMmqFtStrE5I
+wHLu3DoEHL8DazrdMTrX/m0LGBni6rS6P7gcshow54u5W6rB/Jz4rvK1UO+
tD4yqSPTP+mMKnlroogNCrDIuPY1EmMAbJEHz1zmQotEc4MtVjphx4QGUU9R
ZQRzFoISn2pmnpn7ilyEEAmLo4RQFxog4JidmQgpjI0qj1uL9s3Q76Qe1XYb
C2EA5eDEh4aJhCSpHh/RM90PTcYn2z5EJ5SCnTWbyo1vG5l5ROfflqhpXmqO
oibBLeDTFr5X4awXOF+s1zrti5K3CE6JWvjAOBiZjj8zdL2HLDUY3G/zPdeX
eT1/SRd1I0W/ukdEdiBXkdLOKsRAtXtKB7XQibCK6gqGJlRYFBcSY3Wu+hkQ
WlHMYZOjnIQB/mFWYe8FhfzZ5JQqyl5KHNpcREwafGTpSGzoszod1Gp/ODVl
Qf9Gcm5b2jKN8xgRwG3b/cfDg8Enl2XasIFJAQA=

-->

</rfc>
