9. Main Results
-
All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.¶
-
Early exporter helps achieve level 1 binding.¶
-
Our proposed mechanism helps achieve level 2 binding.¶
-
It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.¶
| Property | Mechanism #1,2,4,6 | Mechanism #3,5,7 | Proposed mechanism |
|---|---|---|---|
G1 : Correlation of Evidence to gxy
|
❌ | ✅ | ✅ |
G2 : Correlation of Evidence to kch
|
❌ | ❌ | ✅ |
G3 : Correlation of Evidence to kc
|
❌ | ❌ | ❌ |
9.1. Expected Results
| No. | Binding mechanism | Artifacts | Expected results |
|---|---|---|---|
| 1. | Client’s TLS nonce | binder1 | binder1 |
| 2. | Client’s attestation nonce | binder2 | binder2 |
| 3. | Early exporter | binder3 | binder3 |
| 4. | Server’s public key | binder4 | binder4 |
| 5. | Combination of #2 and #3 | binder5 | binder5 |
| 6. | Combination of #2 and #4 | binder6 | binder6 |
| 7. | Combination of #2, #3, and #4 | binder7 | binder7 |
| 8. | Proposed | proposal | proposal |