[CFRG] Re: Formal artifacts for attested TLS binding analysis
Songbo Bu <bluedognull@gmail.com> Sat, 04 July 2026 16:10 UTC
Return-Path: <bluedognull@gmail.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 27BB810E89E13 for <cfrg@mail2.ietf.org>; Sat, 4 Jul 2026 09:10:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783181429; bh=e8lqo7l6PO6yOhrAY7WZ65MIYvyFUM/rsD9dT06NlYs=; h=From:Date:Subject:To; b=FzwDeBZRT8rClfwnXz6u8L2foQDW/0V7bsC4U79WfrohA3aLXhiY0zh4Wji5Jc0Pc DVB+plnJBJbAusm6LX+lvAUOUFLquXmKTnmhpFH8GWZXM/yBj6e9nHIYSLBuE9zhRz BGdWAzC8G5RzZzw11GabDHK7y3NIUZzrQaOJMFBs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UStdpSzUdWJm for <cfrg@mail2.ietf.org>; Sat, 4 Jul 2026 09:10:28 -0700 (PDT)
Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EE12410E8917F for <cfrg@irtf.org>; Sat, 4 Jul 2026 09:07:33 -0700 (PDT)
Received: by mail-qt1-x82d.google.com with SMTP id d75a77b69052e-51c01089e8aso12475141cf.2 for <cfrg@irtf.org>; Sat, 04 Jul 2026 09:07:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783181247; cv=none; d=google.com; s=arc-20260327; b=W1rEOJfqlrGXPgAWoFFG9/iMYhEZV2SvMJ5DtzscpeMP35JoKx06hkmmEXhL2X/3aU HognCrY0k5WL3llOjaCIJ4f7bTHeQ7qXheIpMvybl7S7BHnNGvzTwa5zCA4t+lBBBVto cVirgISHzlIPUuFcotgY38MR2lDAjKaLitjxSlzP9ub1oCvXmvAaowspew8c0LsH6sj/ 38h/sVHGXKEwfzDzC7S8fa7jXhdSGWcTg2piSxvutWTTnB9JE/zOLNk6iGve3IHcb1n0 AFf319RgJXlvM7/NLiAk/uBCxSaohLqCIVOIpO//XkTo1m/Ga/NQ/ghVZCwIAa2F9taS td3A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=e8lqo7l6PO6yOhrAY7WZ65MIYvyFUM/rsD9dT06NlYs=; fh=FNNUfIArrVOomimc9juX8P5rY4e9QHC0ZHWigw5xmKo=; b=EYCSU+OE+G/jR6zE6zHUSrGwlbsSj8OBc/ClGnCCmX3BbrY1l7T8zDhfUDXJT1xHw2 CvQU99/bzA0YrrD+kxxHamBes68D7IMjE78Y/wz8LpK6s6XVKiCXXyjCOVsBSiAJKSok lAhXWyg+A7gYgPygFeMFif9eKrl/0oX7zwkTfVRUoVv9gmeOKvXzMKwDF+ni7uzP4gcJ IwM6bDWZp/MaAcCsk+BGADt/L+JGz8VIy2DL3uvK+BjphezNggz5u4J1Fke0NTFDN+K1 cJXpPt7aSN84e+xvmJ6qw6HDLbHptG9SBjV9/kY2d1zimyZ2//DcYyPnkJDqrrzp3A49 rQJw==; darn=irtf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783181247; x=1783786047; darn=irtf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=e8lqo7l6PO6yOhrAY7WZ65MIYvyFUM/rsD9dT06NlYs=; b=ivBbDw6HkVlSjApYn4mGS/u+dR6SaQf6knPlXM3PW6bjYwcBv+x+lNmQ+AeVFeS/mg ls7nb451wPD+pCGMmXgVS6M2FXLxYeXgODFt4K4xP+KX4NXlUHFGAZPyCbChnWOCXiV9 /uWJLbmSW2dED7KclGLEw+W9OGip6LjZQIKbsNa+NioW9y1pznRkpnthLOyLzPRNqCM6 tHWFqdfXhmXeQQOhsRdf1kceqgnGeNhcPgS/8njGls1UjSfvTujv/rSqts2FLsHTZcBE a4oqHObsHYn4z783wTs0QEmN7H9el6+vvRyryBlqD7jScWjW4KDmJ5yszZ8T4CY+S6+m 8suA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783181247; x=1783786047; h=to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=e8lqo7l6PO6yOhrAY7WZ65MIYvyFUM/rsD9dT06NlYs=; b=E9FHrDdkAhBMKynrRAmx/t4YNJJo3x3Os/XdSc5heWgduwCppF9XYaEksNfyz6FfEa SOF45W0xy/GQHKLlpqVecSnqoF75HIXCPFrBkME/alzOuozAJm1+DCcTX4Mq3EOqat3T IEcGyBIb46Ivz5CpxPiXRSA/4xAlfxYIcSrAMulpO2AjU0Gr77VeyKWHTC9tMf3VMOP9 mus9Mu7HYGSRyGzTMzzFNOSaiTo7q0MmP/wID9eHyUSG+pe+BhGhWvjo4zyq44W125VG rZBEN1bxNrxHAzHrYgkHDE0IH+uiiJZnFPUCU7TrUx5PuoCcd+/h23hE8KjNCvltDbX5 6XWA==
X-Gm-Message-State: AOJu0Yxf9gez0XbZKsWTzHRN/0W+eCiDU2n+MfLad+GGsQu18oxcqlM7 gLT+hVmXnGhetybfDo88xaHa6m4hQsnq7GF39mFZrAY2o5P22l3ky//soWj2gsE3xEgKV97XTMn nybXq5Fchdg0JtuVifFpQDCcBko4Wpqu6EJ56KOiy/Q==
X-Gm-Gg: AfdE7cmrEoZS+ybpi8XzOQ9bsSBwnBVVnnV4k8FV1/FiMRpYKmrU3cLnUhlj2JbLlGC sZIoKl+2ELAnDBwqDraG5p48kJip/LUL4cd0R2P8F80xWdglmFdcs1pM3ny3z2kwiVNWTcOJpkx 85dds7ryNZLVY0/O3J2/0jpoQahJXK/o8kvat8wCG268jyhMdxfwp0dLxAFTO6sL6nsi9HQT8cS AGZxPdaza9BfsUKYbgAZCnUCAOdNOlLypH1ITZIYG8TH6WsX4n88VMDL0Wakkb0TH/RR+w0/gu1 qYQ1I8VgXMg9sBdzG/FeSUfDMc/GsI9QrUhm
X-Received: by 2002:a05:622a:4d90:b0:51a:8c99:1f0d with SMTP id d75a77b69052e-51c4c3256c3mr59057201cf.60.1783181246434; Sat, 04 Jul 2026 09:07:26 -0700 (PDT)
MIME-Version: 1.0
From: Songbo Bu <bluedognull@gmail.com>
Date: Sun, 05 Jul 2026 00:07:15 +0800
X-Gm-Features: AVVi8CegU4gow-Ba-Vy9POLvDusrfrKL_A7rHlcVDPSK8JAnKDZa8C4oMMvIUZI
Message-ID: <CAK08nYbxihA0SBm00eRiQrTvs4TC_RkiFmcAid5qdK_uXr9BiQ@mail.gmail.com>
To: cfrg@irtf.org
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: GQPNMGXM3BCDKZI4QZBXNK5DN5APHY4F
X-Message-ID-Hash: GQPNMGXM3BCDKZI4QZBXNK5DN5APHY4F
X-MailFrom: bluedognull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Formal artifacts for attested TLS binding analysis
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Hi CFRG, I fully support the results and the technical direction of this work. I have also participated in the related SEAT and UFMRG discussions, so I have been following the broader question of what security properties different attested TLS constructions are intended to provide. My reading of the public artifacts is that their main value is to make the cryptographic binding question more precise. Instead of treating "attestation is bound to the connection" as a single undifferentiated property, the artifacts separate different levels of binding and make clear which properties can be obtained. I think this is relevant to CFRG because these questions are fundamentally about cryptographic binding: what is bound into the attestation evidence, what is bound to TLS exporter-derived material, what the verifier is required to check, and what security property follows from those checks. This seems especially important when comparing intra-handshake, post-handshake, and hybrid attestation designs, because the comparison depends on the exact cryptographic property being claimed, not only on where the protocol messages appear. I also have a few README-level suggestions that may make the artifacts easier for new readers to follow: - Add a short "what this repository shows" summary at the beginning. - Add a reader guide explaining which files to inspect first. - Add a table mapping each binding level to the corresponding security goal, model file, and expected result. - Add a minimal reproduction path with the main commands and expected outputs. - Define the binding-level terminology before comparing it with related work or draft mechanisms. Overall, I think the artifacts are valuable because they turn a vague discussion about attested TLS binding into concrete cryptographic properties, assumptions, and review questions. Best regards, Songbo