<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-01" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.0 -->
  <front>
    <title abbrev="TODO - Abbreviation">Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-01"/>
    <author fullname="Muhammad Usama Sardar">
      <organization>TU Dresden, Germany</organization>
      <address>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <date year="2026" month="July" day="31"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <abstract>
      <?line 60?>

<t>The draft aims to provide technical details of CVE-2026-33697, which is substantial technical evidence of how <strong>intra</strong>-handshake attestation fails in practice. Moreover, since continuous attestation is required, <strong>intra</strong>-handshake attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/> and the ProVerif artifacts  <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 65?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This draft presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
      <table>
        <name>Binding mechanisms, implementations and ProVerif artifacts</name>
        <thead>
          <tr>
            <th align="left">No.</th>
            <th align="left">Binding mechanism</th>
            <th align="left">Used in</th>
            <th align="left">Artifacts</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">1.</td>
            <td align="left">Client’s TLS nonce</td>
            <td align="left">
              <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
          </tr>
          <tr>
            <td align="left">2.</td>
            <td align="left">Client’s attestation nonce</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
          </tr>
          <tr>
            <td align="left">3.</td>
            <td align="left">Early exporter</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
          </tr>
          <tr>
            <td align="left">4.</td>
            <td align="left">Server’s public key</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
          </tr>
          <tr>
            <td align="left">5.</td>
            <td align="left">Combination of #2 and #3</td>
            <td align="left">-</td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
          </tr>
          <tr>
            <td align="left">6.</td>
            <td align="left">Combination of #2 and #4</td>
            <td align="left">
              <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.ultraviolet.rs/products/cocos-ai/">Cocos AI</eref>;  CCC Attestation SIG's adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
          </tr>
          <tr>
            <td align="left">7.</td>
            <td align="left">Combination of #2, #3, and #4</td>
            <td align="left">
              <eref target="https://www.ietf.org/archive/id/draft-fossati-tls-attestation-06.html">draft-fossati-tls-attestation-06</eref></td>
            <td align="left">
              <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
          </tr>
        </tbody>
      </table>
      <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone.
]]></artwork>
      <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

</section>
    <section anchor="credits">
      <name>Credits</name>
      <t>We discovered the vulnerability jointly with <strong>Viacheslav Dubeyko</strong> and <strong>Jean-Marie Jacquet</strong>.</t>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE (<eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref>) published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <eref target="https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/">draft-fossati-tls-attestation</eref> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>7.5</strong> for <xref target="Intra-handshake.fail"/> indicates that attested TLS is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
      <t>Further formal analysis of <strong>production</strong> implementation of intra-handshake attestation has led to discovery of another class of attacks and will potentially lead to three CVEs (currently under <em>responsible</em> disclosure) each with an expected <strong>CVSS 9.1</strong>.</t>
    </section>
    <section anchor="affected-implementations">
      <name>Affected Implementations</name>
      <t>At least the following implementations are affected:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI</eref>: <eref target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.8)</strong>] and <eref target="https://www.cve.org/CVERecord?id=CVE-2026-33697">CVE-2026-33697</eref> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <eref target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">security advisory</eref>  [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
        <li>
          <t>CCC Attestation SIG's adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>astc</tt>) used for encryption of application data</t>
        </li>
      </ol>
    </section>
    <section anchor="correlation-goals">
      <name>Correlation Goals</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/04/">draft-fossati-seat-early-attestation</eref> and <eref target="https://datatracker.ietf.org/doc/draft-ritz-seat-facts/00/">draft-ritz-seat-facts</eref> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any security property that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>).</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high-severity vulnerabilities, we recommend that the
developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>Intra-handshake attestation does more damage than protection for AI agents.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <eref target="https://dl.acm.org/doi/10.1145/3779208.3785387">ID-Crisis paper</eref>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
      </section>
      <section anchor="technical-report">
        <name>Technical Report</name>
        <t>Technical report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="media-coverage">
      <name>Media Coverage</name>
      <t>Several media enthusiasts have covered the vulnerabilities to protect the community from the harm of intra-handshake attestation.</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
        </li>
        <li>
          <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
        </li>
        <li>
          <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
        </li>
        <li>
          <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
        </li>
        <li>
          <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
        </li>
        <li>
          <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
        </li>
        <li>
          <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
        </li>
        <li>
          <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
        </li>
        <li>
          <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
        </li>
        <li>
          <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
        </li>
        <li>
          <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
        </li>
        <li>
          <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
        </li>
        <li>
          <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
        </li>
        <li>
          <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
        </li>
        <li>
          <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
        </li>
        <li>
          <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
        </li>
        <li>
          <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
        </li>
        <li>
          <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
        </li>
        <li>
          <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
        </li>
        <li>
          <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
        </li>
        <li>
          <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
        </li>
        <li>
          <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
        </li>
      </ul>
      <t>If you have written an article on this and would like to be added here, please send us a PR or an email with the subject "media coverage of intra-handshake.fail"</t>
      <section anchor="security-researchers">
        <name>Security Researchers</name>
        <t>Credible security researchers, such as the following, have attested to it.</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
          </li>
          <li>
            <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="germanys-bsi">
        <name>Germany's BSI</name>
        <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
        <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
        <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently verifying the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
        </ul>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake attestation.</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 341?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>We would like to thank our co-authors of paper for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Viacheslav Dubeyko</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
      </ul>
      <t>We gratefully acknowledge the following for insightful discussions on this work:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Nathanael Ritz</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following who gave feedback on <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis">previous state-of-the-art</eref> that we utilize as the basis:</t>
      <ul spacing="normal">
        <li>
          <t>Tuomas Aura</t>
        </li>
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t>Several others at the IETF, IRTF, and CCC have contributed by providing feedback.</t>
      <t>We sincerely thank Karthikeyan Bhargavan, Bruno Blanchet, and Nadim Kobeissi for the foundational formal model of draft 20 of TLS 1.3 in their <eref target="https://ieeexplore.ieee.org/document/7958594">work</eref>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA80923LbOJbv+gqs8zCxyyB1l+Wdnh757iR20pbjxHFNuSES
khCRhEKQkpXunpqXfdsf2Krd2n3df9innT+ZL9lzAJIiZVm2euOe6ZokIkgc
HBycOw4wlNJSJCKP75KN0yAKGR2ywFVDNuKkE0VcRSwSMiD7MlDC5SF3yQkL
/X7skZf7V4e0Wq42aa3WbLeI7JP9q26XtKzG5kaJ9XohnwDUy7cHbwklHf0s
NLSNksMiPpDhbJeIoC9LJVc6AfMBCTdk/YiKIia0z4RHy5WSinu+UApARLMx
fH16eHlEyAvCPCVhKBG4fMzhryDa2CYb3BWRDAXz8OG0swf/yBB+XVwebZSC
2O/xcLfkAia7JQemxwMVq10ShTEvAeK1EsANOdslnYvDTmkqw9EglPF4l3QP
O5elEZ9Bk7tbwrmdEjaAQRU+LFKRzamIr4tEK014EMP4LwhJgH84xgczvQ8w
pggG5BhfYbMPdMBP/sjvmD/2uOVIH9tZ6Ax3yTCKxmrXtnMvbQAHoEU0jHtA
ID8eMt9nLo0V8xlVLHRZaC+j9gZ08xhiDt1SwEu7Wwa6JeRSQPbDK2oNIx8G
KrE4GsoQKQmDEgK85Rlm2DhLBiTvcUDS1QNu6K9kOGCB+Krpuksu35ODkCtY
+W1yzEOfBTP9FTcUyyZ+qzG3DOZ/jGLqml6WywGRQELPSExgQUrIl9kTWVxV
C/Hf1UM8ID36i0UZ2dwlJ2IwpIpPeCiiGXIDSEAiaSBbl2+6ZnqaLcmrOOAE
u2+boVg44NF8oafTqQX4c1z+AXSwAh7Z47jnCUfTxa6Xd6qVdmWneruAHSJ3
W8TttoAZvrwVwW2K2S1gpnHIFkv/RwF7kJkzi7y3kuUpvrmyyEHc47ORLLa/
otDnFXO+xDx6gLw05GP5W9DYm62gccLdKEtPkh6N0zNSqjjZBHpxKC0cu/il
aUioty/3ZTdRR4YMRCgyib2Ah6zncRJJEnKPzfAb5ozgnWCE38H0HOzAx0Pu
w6ee7gr6TyXgl3ClM+EWIGEDDhfcAT35vXC/W1B9ZL4GZ8jBehFKJcuySiVK
KWE9pYculS6H3BgGwoSvEM9xKCdgjkjEnWEA3O4Rl0dAeGWsUH6cbTIdCoAO
cwXzAZo4iMAk5HpyhBQ4HLsO5ZRsbekl3dparsRJX48DHDVG7ITDLXImQy6B
3baJEggJzEkkgljGqtATUAj5l1iAFd1+dBjmugo+ioOAO1wBs80ALOr1O2Dq
rS2LIFVA+mMvUmioSA/WDJapNyOReaP1Avnpp2VS88svBJ71l+9CeQWS0gcg
kejDlBR5oJOWSOgZg4kNSWfMnCGnVatMQOGA9eQEVCYMDIvjxo7oCQ8whcXU
q+kL1/V4CawVQsYPtEWEtQWqmMUdI85gRTVWWvt6RI25I/qJPtMos4B5MyX0
SuOHDjQKZCPSA/uP5tKHpQXboIBVEKG0GVZMPGyb9afIHSCYbmJXdFtBYGBq
kXSkp8BC/EzOpUV+JnuLw0LbewUdYMCfSScj6s/Qo4Id9j0B0/zbX/5NaZiB
RJb5mdycAQv/ToE38aeXqSwxYfnQqtWPRtSBNVAyDh1uj0MxgWlTwAkZBFCg
GVNT4PmIj9mYh5sIGmnAw8oc8K9Sa3YUcm6DSQ3sBOCmnlV1YVZ5sqazo3M0
qt8ajapBo4ZoHLIQ9Dm/G8swAiYtDFz71gPXzMB1HLjLQ9AAev7GBKOKLI5f
/9bj1834DU1/6UOjITqIxouqlpYXtSIKjW+NQsOg0FyBQh2HP3QH3AM2Jd0Z
SBOIJkQUAF5FSxHa39+nufDD9jkHhTpQds+TPTM8+GYcnXtlg/UYxeoidmeW
kwClLPIUdRyH5njRGrv9zX8mN/sgwUUxQ5MFejRkEyE9Hlmhso0Si5Tt4NeU
CRu6EsCrEBZ1T49BYpkrx6ghoM9n7kTkZoWeWTrdBUTtVOdQnMVYOjkZbn7r
BWyaBWwtXcBtYKDt3CoaZ74vwR5FQmOXQ5uWm0WSCh71tRuAhggcaVu49mMQ
dFCQm2/rW8+3hfP9add4Rd9t3NPeapsINLM+aDONlNLzv28lN34plf785z+X
PvDMHWGp2YIGoB/8D1w47sTaD4Un5nnaZrEeeAtzy1VaYrl034etVYz6HmGV
sIVT2afwQAE5cI+kl0M30Hw5lgrR80UkBnPbhv1doRz0XYB/M1RTpxAtuODK
Im9jNI4gYWDeJxyEDrqyiIgIQtIZxE0R6QEVYFFF4kiCayDgS+gUSkCUjcdp
UEJhUn2w6OSlBx94pLaZTd9MatW0mScDbmmyl5DwYAzHmJnogc7HiXgSDS+S
OD+F2WO2H71NBaYqMlb7JiMEcydCyXC2lAlzGiNM9ISd9rSTnkA9+/ik26GT
/mBA/cndHfUHA+BBoVQMo8HIQC2NMA9cGarUXTWencEH3LGiTws+WC7bYqFX
BeoUIMz59YD3RSD0s3Gg0RphxkJBWP2+e4k5EfyXnL/Vvy8Of3h/enF4gL+7
J503b7IfpeSL7snb928O5r/mPfffnp0dnh+YztBKCk2ljbPO9YbRIhtv312e
vj3vvNnAeUXa95NOjLKmfVigBTASLBUPwRvE6TNVcrlyQtEztNjbf/e//1Wp
A0n+6eJov1qptIEY5mGn0qrDw3SIWQAcTQbAFuYRKDwrAReCT4xQUBAdNhYR
sPI2rr0Czz8gQxADoObWDVLmT7vk9z1nXKn/IWnACRcaU5oVGjXN7rfc62yI
uKRpyTAZNQvtC5Qu4tu5LjyndM81/v57TwSc0MrO938AaUIeCjFlplCwclrh
vjR9lrBCSFqQBQhRrgQGAspjkzSC3drS9N/aesVZQME+C56GsBC54FAHOlwD
6FcFyAdGhmNghUvhc40gQuo4o0BO4fuB1ssKo5xOv891YHplJAc98kOUATAe
BxgPgFmDyEP/gVeowrREgHqeqw2eqo3YcJ+RQoBQbpG3TrSNQWlDG8gFFBCD
7GPgxwPu5D4+TbNHoFwS+b7BZOVcj2BiKjGLRTtp+2pghww8j+ag9+Wu/PF6
58N1eFI7u6tP3u4EVRq/HlzbaCErFSBqoEdt6lFv3hnHkwWBjMHtRjxzFpn3
rHREHAyebexarlZblWa50ajbK/whcLwGdsS5cUkw9HBmgEWeCtUWOeK9HD6p
o2UcYjWEtfotVCu52drqptmf78jJ6fEJJom0stzZ3Nr6E+JaM0mHPLZXh+Tl
TVHRFv2ZJ2Q1Njdzk12FSCNFpHkPkRv0Mos+yK/0Gl3uAJMh2VekeZ7kgC/C
tsex59mNHc2HLZ1Ey83gaj7akslgikD+yhklDOwi5aorhjUZhdX+6hwFcMIY
5ppGPJwLIxim1d6qXSmDBKAShM/AeoAsmEQcxPoEOWwBvXsh0NpiwRMIaoZC
YUKdh+Vi+Hng0M9OY0L709ZwtVzUU3ZsF7GeO8qZxi7agrz6zGtstqCx0VtG
L8UfgzVQwATaeLwFzRgWbABgjwYa3Jk+puW0usZeMcZ/5I0Az4BFMBpi9gKm
Tp2JUhSMFeh0AmNkEwTXosfQG4Sxbs5PwXz7oEyEk+P3YOJa4G1H1kBObJwW
TT6xEeimVcrxlJmt0RI/G9cLJDUd7ckw80YpZ5xupgLcHTbWIUtO6eRa7T5Q
X2VNGMsSTEEleusUfCZvIfzCJiNXwCtAS2y1Y2XzIGMa6nB0tuy8ybB1R5p9
kn+Hqq5BK2Va3aHlciWJ1nDBbzpnB3+/8edfII11xuMcQgWjTy8PDxcIC4Ys
T1SdKFsg6T0gBx9d8BFzSsOzmOMnqkKAMrAqlXrDrjUbO8163QJrUK7WyjqU
/Q0Xp47EKeeJg/k58ErIGzk1M+mC18vjnBzcOYwmxiC3m6fMZ+m/t7Higbir
NlM6paayQRv1Rrn9dFOZdEAYdasMf5+B2xn7Brm9kLPRUQfc70fQ6+GHfVSA
2a9byUYe8OIyHJuVdqu6Do7YYRMxrC5iyNyLztkcVI+B+vctHqe/cOyfl8gD
812jxQM7TeJmeaZsQe0eGFZMdtnwOVU9WitXGmYlMdFX+w3JVVmXXBWNYnsB
xSPWA/034u5jKPbTD+e/VjNdpfwEDKEx12Ephsv2OoqQf8Nd1vwsf7UXSjCh
h0KPwxXM+KIFltoCT+5bYCdvgZ3MAnuZBUaLjokFZw4x2ZIx6S0NXhvKrS1A
BmJCTDk9uB2FOSAsC0lSS4v7lJhj8vW4ZMajZFCMTmW63RVlO0LLMVfIbyYx
APBA2kKuo1jU8EnPKUgGAgIvZqRMhoIToLHSDhv4A0dxqOmVpPnye1FbW+Ns
WwvmuuDyPpLOGzJFPDObNPI2CcPArA+48UqPkm7N4iymwvPIWEZmpjATj7OE
ICHnaMQUeTmfp9m128rFvls5722TcIjizaKxADdQTHC9taWXsG1VdOQOPlwW
d58W06SlUidCFIB+ZgPP8+RUJ/QW06mwhiwBslsq0Wfb+dr9BoL0WAiH6N/f
UFgdyiJi/xBxsPbbfhMSrbf9syzOeTrRnjlKgun8vbaBdn+TiN6k7tJIe2sL
hT7dJnmDOXtVqljk4ITArJJtA4hJyMsfB3ezHzdJrHTaduFtj0dTzsGs6G1i
PYbSO6alqkVOMhKlmwOYrX754zBSTgoRjQcPnHA2ThXqnLA+FkgMuCrVLNKZ
bzUsQAM2WAEtt0WBVSnMhKshEla3HUvm6dSok5RCastkdn1xuhedy25aZBTm
ik6i2ViXmTxoUkGrAjnzQwE2h2lRCu6lIK27hprdhNbHlU0k3Ipeuf34OXkv
E4K8RoIcVzeRYE+DkSdrEUptE0l1xmCCF6YcBXV6x0vM41esSbm/v5VWnzg4
Olokd5mpeMRsoiVZIQcW4LFQDzDk3lhlu1NmB6qS4offY5o42S9zcyUdy/pV
8/1O9VYYWbEVlmx3PbYXpbe4tB2WcYRVQHoTB50NpWJfs6vSmYl3gCUPQUmt
/A893XQSLyrb1e36drPYWNtubLeIgbcwa/SOdyldPUJhsOTr9Ef2LwA6rpDd
Vcym1Qf0+Nt//GsC7G///i/FHwil+giUkTNcgGJ+FaHUHoXyI3kASvIj51Nr
3k9KsdArLr14QQ5TByqTidUVQ7k6oXnftLxredJoZTHRc1X82M9aT2R7cmBF
d9HT64qeraYoP9FngF6Y6PLKpWerWspP7RmgF6a2sjbq2eqi8jN8BuiFGT5W
ffVslVf5ST4D9MIkH63veq7qJPtZa5+Kk3xaDdRz1SXZz1r1VJzpjpU3+DCs
cXmY9+3GTSGaaT0j/NzE5iZ50YSa7SfMWCROrPYtj4whVtpiP/RSxwr6pBEe
/MEDOpRAGNDjnnbrAIlolSu3TVQMkQBECAu7kYqziIK6Z7kY+IkbkfOu9uY2
1pHdczJznullvhpcxQOIk6IkyRZy3GEgw1kvFGmZGBZ3vXSKQrDSX8UCswdp
sLl81mjq/l9bscvB2GXU/DqrYT6HIP6r+Vb7Vk8eZqGfXcadXvTvwR9fUZT/
GK3yXj1WxQWzec1djwe8L4qZzb83b1nI6BhkYVjDpvhLJyVzaI/TKEQz1D1O
yvOm/uKxKWEPPZrpZD1RNN90Xh8a0ewKHytrEAcIwLCS0gFU9Zc3Hh49C9mT
aYJNNOlkbz4VF/TDNSoX3JdRcY5byAIi2NKx75wMeBAHU74uCwY8lLFKT5IA
E0jAPttL38aaS0w4z5PWQzEYYtJa74G7vyqVT14qzslPPy3sp//yC84Ziy2P
xYQH2Wjzs1ULg22TKeoaGAJieNcsuK4xRa2EfGLiftTfEfzB50ckBuvuSnE4
MClsH/cVVspFUhv62Dp1EGBV/11acWCTuBIo6AMtYGV8NtA8HOhTINzJqmiz
45+6su0yO1hkKiaMcbmU0sPkUaywJnahYlfN/J5Er3ie30w3FnQx701azTtn
XME5yKgHmFn4M+VbXUlpt3dqtWajtpnW+C6cokn4JjvLYvj6TLpYvTEwmzrJ
BoePjYi0OZRz0xd3yGKwcAkgV6QP6c7E6vTGk1KTZnCKWFPhUicUQIqc6QcB
o8wGXGCGofS1hIzxdDEeuMKDuqgR9bwjrNYGVh9jxSJyTh9ohNKzcNLtkZxM
WquKsC1Nn5CZrIwWXc3n01xmEOuikWmAcHhSGsbF+lKzN+a6SEHmxYkA414U
JqlFL86XC6IMxYE2DLN5tfc/4AokpMZaGyz+2UbS4JaVlhScdoo6+HZ8CbZ6
BW9OD+i+HoTorZvHqyxarXa1vGPVWjuN2k5rcztLKOYqV3VlzP3a6U2sujb5
WSMHCedkQufI2HO1zeuD0sCvk6N+epfNBa0e4NHEKJGK3JJa5jybn8gScYZS
gBb3cVsRucLxsABZ8wtHjaq32wzW9+iCC729oG+LXDvVeKoI9wFDPOocPLL2
RtLnGuqCY7KhNG8IdQPyNJtggSqmMAHXhzZtLUx74seOw/XWByqc3NY49j3s
vr043e/qgjIzfpbqKs2TXnpP8PEhHzyB+MacQNQaGLf2GcRxQDPQy0lJGCoz
3Q4KcgjyxNAJHjI8hvFAnTMaT3PUFJX9glBqrjU2PPQfMWKW3uNErXHBBwK3
B4qbbCguyQuz3ZluVSHJ7HILvdq8CaeZCVc0CmMwhVkikQpFe6Ec8UAbF+Ah
Cl4rBVYGlw5GsBvVZrPcaG4CRi9fsTELIDAAH33PA4Y6YdE5n6pLOZrlyjN7
+AoYNoBXVoTv0uM8yq5U2u1KQwNLieyBBxPjXgxAPdGOVSDzSmeYtem5Fnah
pgw8j3isg1IaSdrjehYeHugyE+3JGA9ozqgA50wF6LVqReVzcKxd6A36hsIf
ROkGtywwPnOdwj5j0qAs3PExtyTwQdq6JkK2cCvN9k6j0mrWa9+L7yrlcrnV
ajarteqOJvJNvhK8m5p3JHOuFJynxx1CUwWeR6FQbUmTYpZEldmbCWOd87vo
mAcox6fGBOVK3YYQWNxF6KDAa2Fe61mPY09xG3S71my077EpnWtPKgK6nOsK
J7YyL0LjcgAyOkuneQF6lU/zzja8TJk71C81HvNiqOL0aIEQWvUZJIcigrUB
nlSwhHR+QA8x6O7jtRmeWxQx5UyxUQ8HEQrvPyhQofbZl05RixKqDNpHLtTb
VIZseuRyhfwQsyCK/bzwyIGy9NUeGD3h8lrxyC5XaPIpPQ0cXKLc1RhoHShE
QREdcT6mOFfAwBeKw5xnD6yJMpRBNQCyp7kUYxuq9GKKQRDpnmhkjIXXQnsR
K9CEGKRnrPmG9RZIl7wBzWyFsY1qwG606o16wxoPxxqMuXEDoOjpglIpQkhb
deHUSpYSPIzhwSw1mFNQFQbRfWBco6m6IsjFb2CfGYRJFvhHzHICG1lcq01a
blFQm+ZWAGBl0VfOXdRuN4CzKpZrCupw1ZBK9Z74WowJscXoJ7BQDpaIxgGj
fbD/jMJajFEHgHbFY+6Mgq1/YFUWiHx6CWReKAONgL4ZXYVSEOVJLG7xBA2Y
GsI/Iy2gEOKN4llM4xn7OhE+BkCTgoAs0En5X10/r/RUZOk2I/o226lKr90u
L9LXlUFBOSGSpk131Ggaqtp1GxRdpVytZtTMwRF9Hgxy8YqlG0yZg70Tv+/P
yu/O/C+HZhHiwYAFsWIL46bNBmeYwkPsg+pAepyOReQM0Qgac4FioI9iaguI
T44nYyDXVNIZeGIKo7DEhKCH1RdFdB4+qTDGb+ALO/tWJwtyLvJSXWZyYjiG
gpAkyhfhKojmsMUYpDv9hNU27WqjXemUG8DRe/u0Ua406F6ndkD3KrV6a6/W
OGju1DVEj03uSHHx9LJhuzWMU1a2F7SqSQxixgesHOhRikVwFCvgHrYAC2vt
KDco6jwLm7S8T7m4E8FtvVprNSvtqp3e/HRbqZXbTTCVc1GUIMWRAn83n6jL
NabV0ssYALWfSiaRLD6EEyMjFZdxOBJqCJiCt+aiIgZ1JVjeKck162GGrIeF
11g6JIA9iqboARyEAwT7ymaiT0fMEzMZGpPERr28QdaPxtHLKWcR5PgTGJgF
FNz6WKW6+oa54Ng45L50mhdUr7XL7SkoEXCFwRL0QVw0ODCv6Jxx8FwZB8LA
NNDG6OhYP4NsDkKAw6CrUrqKng44uAx2s91sV+qthnGoTs9iLxLgNeXr9Pyk
zciFORlGeQCWyMkq8yTwBPjTm6XSaZ/MZGw87ylotohjCpkkzImRuQ6JdX2j
Dm88MUrPhZpAC73lbTLGSkMIKjHPhLEbeXeBt3th6SIerZtHViru6WqsDeP+
O0lYsMRnt8zFVxiiZObwIpEPjucL9flIjE+yPE04fz3PxRaqH7fNVLNyVpiJ
iExEcAZanXGPvGOj4oqi8MFIQab2lO2bb8dsdPuQA4Apu3vxAIatE/QcW/VW
u15pNCBgrjVBFsvNOv1CO3XDXBfSDcVAkr0QVk0+ik0Y9vSHt2AYKGY6aHqJ
jvFedESDXBxIilQBraKrwTQWjZ1qpVqtNZtNQKdRpR/LnYbBYg+TYe9C8FcX
T0sswaEHH4Ny1x/Ter1RqVeqt9JIkSd8dJtAuT9kL+bY1Nutyk61XQe/vV4v
02lf1OxNzQTJRWK/U2Sve1oqzR+PuKtjnbdYBWVuvVnq5r/cwzhVMT8i/b/+
T0i6aMbDIccUbkAwgs11U6aEdbSpi4EX+IXssxBcHHIivGgbesI0Zvq+HEXA
kIy4wtyqibcB123oBZLzDxZy7ppU8v5+MdGP/qjqp5cW6duRzBFfJKsrBnhG
m+Q0ZZLhxb/S2/4cDNUxG6YTT1hWCMuSE0gzC51WdbHyoATryJJjvDxyrG2T
fvCUNGXm5pIEc5fS/n6aUiYmnjH5XDyfBhhhij5tfrCyHdezh7WPY85DagIf
LJHUp+TWSZzg7oKN1xdmKY2x1psCnOsouxAp++q+5olyV0b18FaE7L5ED8/x
ggM0S7N1jnS5RbrSz/YZCmNp0MX+6cVPSSolN06S/k9Ai5DgWft8htnoe2au
zUjEFgmzpIp+SZamiGZaC6rX1DdXIuBSAgZTU23+tCPYuA9my8lOn7acT69f
Ny4+0TP/s9M8HV519+jRyH7qWe5HAW2uidS0d3ut2mef3HbclmfVvRHdiSat
/uTj8WA9pFYBWhepavw+ZgeVg9ng8/nBWf348paG173ppXi1JqVWAVobqVt2
PPP8oxP5xv9y3trbc66v5AkNz9dGagWgdZG6AgfxeOfruwabyrB3262cX7SP
Dt8ffvxQXg+pVYDWRerd7f715cwZlF8ft5zeaxYfdejoavCx+lmuh9QqQOsi
tX89nZy1Gl+b4eWpW+3UPn2afHrln9y9FWsy+ipA6yLFjvZlfe/s4qD7fhZM
ztudH16x6N3n4CNbE6lVgNZF6ofmK99p7EzKTsU7uKrFn0+vy52Pt7J/3FkP
qVWA1kDK6cPT+8b1iduueNefxZf9y6i992l2dXB+xN+Pz56M1KOA1qVUXDm5
u/7Qdl71r8aitt9vfyk3+XA6vj4+XI9SqwCti1SPX3w9P59Mz0R/dNF/9a5/
x51jeTK+PFDrIbUK0LpIdY9vO+Vypcno67PgY2d0HJ29v5OjT2C71kNqFaB1
kapNW/Tth+p+5yos0x/2vrZbvHN2t3cbnJ2uh9QqQGsgFfd9eKy2744+fWzs
12X3eDT+1Jl8vLxtXb/5UL16Oqkeh2SiklxESmQcYTofXZ+5b1jS3lAuMk38
wDF4V7hfpuNl7dyHfurt3XO8lntaj20v6otQicjFQvqMYha665pt4wJC8ILX
yIAvaU7fG3/NuMB6Fy+LotKrx7NThgAx3TnPLo/ClEEPS6sQa7xaNY1oTFHW
I5etmoONp53zzr3RLgvDDPU1YeZL5qRnMfQFp3j9qj4emV18ocOY0k+75qpx
7n630YcYQ5+b/cAXshu4Wz7ShQyOpOktIoC4pk1axwFkw11mvUWarxlQ2q+9
fw0TNN6/gEkPPsDda7xoe5a/qGPh3CaOivtFg2GEVQy4NRTry9dVlqbBggg9
+GEoHGRNR4Yew3HjoSRHMIm//ncAj+aKRoJ3NJonwXxgFggkWR8/3wtjIOue
xwKYQoRVXBFWjL3GWDDEGsbPDKIMcgK+vekPoSi5HEofgl5ouI4DRPiVYMEA
Ht8xLII8FyMZyFBO8MAeU3xGPgjPfH8AxJbkDMTRFYGEaBFHlMGgBzjEiL0c
BpiIiP/6nzBYFCnT7QMPQRoANxb34PGc4aphBudCRF81XXUM+STiToE+A5TL
Pucu8o6+pySrRVisEfr1VRubWXkK8IonvvJcxYYwnHMZSx8aO3GIa3EqA5Cj
MzFknsOZLiDVr49MgSA0nEDkDsrgUjlD2eeBQJpfsxBTH0Pe7+sVe8NiEx6/
iQO3B4Tm0HgsQuEOWQhEDdwZ83FlhoBlJMcYub8DUmtCv5KBpi05kTO8oQBr
6TABFrpkj8EaqPmmvo75MV+Sxb7bBNWgKQjBg5rJJn8iLiaqNxc2aiZPyG/p
9dNFdyH3ZolAvgbSD0FEZ4DLHowPK4Y3bhXZ1Qx1Drzkk9eyx/H/oSArverr
HevkCFehqgprd/QtRdUy/saqwYpVS06dg6jfoHA9seILs2qNdn3TKv0fZa+G
utFhAAA=

-->

</rfc>
