[Rats] Re: Foundational document about TEE capabilities

Markus Rudy <mr@edgeless.systems> Mon, 24 August 2026 13:17 UTC

Return-Path: <mr@edgeless.systems>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4FAD512E600E6 for <rats@mail2.ietf.org>; Mon, 24 Aug 2026 06:17:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787577424; bh=E3A5k9Sxjw3VUApLZlUYK3VrR+rqh8mVtbeCmj06L1E=; h=From:To:Subject:Date:References:In-Reply-To; b=CUDEA1uZjP7d8IM+RvN+7GoggA7mEkxezGJgJds3+oH7xvm/DgkhebI6YRnKXWwqG c40KqQKvdI/NhlylYjTbSEXTTMa388IZSNoB5dhir7SZx30UunM70tdTsq22c5W21o /cowotre0XBOcpM6e6KiQjVbPMIa+yvWTHUvlk3s=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=edgeless.systems
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d2UTWTrQeOY0 for <rats@mail2.ietf.org>; Mon, 24 Aug 2026 06:17:03 -0700 (PDT)
Received: from MRWPR03CU001.outbound.protection.outlook.com (mail-francesouthazon11021100.outbound.protection.outlook.com [40.107.130.100]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F28BB12E600DD for <rats@ietf.org>; Mon, 24 Aug 2026 06:17:02 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=HtqAR5q5I7Fpz9hfo+oiRuN2V17NkJZzSyXdnRppMJL065so8+waARRqcotxrXzesuyAze7FmTQGq+l4biSMF630kauU2mvvWXmbtEujv5sl+vKfBiG0+1KMQt4tznCBV1fRHAwFz9dKvWC7z+6CXb9cIHQRRUKYb6755Qxse1cpi8Yv3UqpHnKYsSQg5lLHf5E2AniaOdwbejbR3+JCUsGM2CzscRTxfsi3OgosYBRkNA12n/TG68v35MiMGf0BYF70ipT68u5jNTN2shMksEK5wnGxlYYhIFvNqFNQUfU4f56w1boV6Cd7NaIE0Ax99Kvn2t95r5J03fxPXGAq7Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vuOwq7w7cWt88PrnsUc7dqS79F4T0GtUEohTgaWxFhM=; b=pRe4NNsY1uw3zTs/R9OKhXBVp0h5IWANmIxiXdbrLqRqkIo41UvXuSWi8EyESDYx9lnhdFpdvf+xPdtEuZ7siuV4cD0b2r5272jZmLEJ/o1f3EILlNeiHtFeg1xvC+DK47jdb+m6YgyVJ9Z555ixyGpK2IJdGduF9+/Q1jgKsOMOviO1bxqXFq4aYf2+zGQGE6AnEJAWa/aRd2fsT1yCgJjLu1TigqPW14RpWasWM418BjFxH+d42Yb4p5gyVSeAdFirxxNz+os97SSv69HJX50jSt9hBGYPrqAMd+iKLAVTm0GCz7ZfIMUhkBd7dKJjSD5RfZu5kRLoBzCzuZYlGg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeless.systems; dmarc=pass action=none header.from=edgeless.systems; dkim=pass header.d=edgeless.systems; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeless.systems; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vuOwq7w7cWt88PrnsUc7dqS79F4T0GtUEohTgaWxFhM=; b=A5RYA/0b5PEBsMt8gc9DHL3BUkhaYHB+SwEB5yzAOultV7UOXMz0P+5S8FD2wNRQUbH38/3qMtdig5f+ADaIKd9ARziKReB8tpEEzFxZs6IzpW895kUtQ9z824Sv61cPn6i+XbPTe4dP9oTu1hly+kOvSu8J73I5cAtVSaN93a4=
Received: from MRWPR02MB12086.eurprd02.prod.outlook.com (2603:10a6:501:83::19) by VI1PR02MB10099.eurprd02.prod.outlook.com (2603:10a6:800:1c8::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.339.12; Mon, 24 Aug 2026 13:16:41 +0000
Received: from MRWPR02MB12086.eurprd02.prod.outlook.com ([fe80::98d2:5e73:47ef:31]) by MRWPR02MB12086.eurprd02.prod.outlook.com ([fe80::98d2:5e73:47ef:31%4]) with mapi id 15.21.0339.012; Mon, 24 Aug 2026 13:16:41 +0000
From: Markus Rudy <mr@edgeless.systems>
To: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>, RATS <rats@ietf.org>
Thread-Topic: [Rats] Re: Foundational document about TEE capabilities
Thread-Index: AQHdIvk3B58DIYYJ4EOViwtLqc11KraLXLiAgABMPkeAAF69UIAAIIKrgAAN6ACAIRiHEw==
Date: Mon, 24 Aug 2026 13:16:41 +0000
Message-ID: <MRWPR02MB1208646E8345AE04A045BEFFCB7A02@MRWPR02MB12086.eurprd02.prod.outlook.com>
References: <MRWPR02MB12086374EA1988A80291C88D7B7D62@MRWPR02MB12086.eurprd02.prod.outlook.com> <3337.1785710779@obiwan.sandelman.ca> <SN6PR04MB48167CB5FF749B2DE750397EC6D52@SN6PR04MB4816.namprd04.prod.outlook.com> <DS4PR02MB10844407B0EC655A4C1263168F2D52@DS4PR02MB10844.namprd02.prod.outlook.com> <VI0PR08MB115650D8E3D6E84BA2F0A33188AD52@VI0PR08MB11565.eurprd08.prod.outlook.com> <DS4PR02MB10844DC793F62CBCF0A2AA5FBF2D52@DS4PR02MB10844.namprd02.prod.outlook.com>
In-Reply-To: <DS4PR02MB10844DC793F62CBCF0A2AA5FBF2D52@DS4PR02MB10844.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=edgeless.systems;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MRWPR02MB12086:EE_|VI1PR02MB10099:EE_
x-ms-office365-filtering-correlation-id: b719b352-8e52-47e4-150c-08df01e1efd6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|23010399003|376014|366016|1800799024|10070799003|10067099003|4143699003|56012099006|6133799003|3023799007|15056099003|8096899003|18002099003|22082099003|38070700021;
x-microsoft-antispam-message-info: Q9kaRGCutnEVlSrd+qRk/EvX0kdO6q5GNWZymVUpgJFEFyaXf3xPtzATdgSdelJx4bbmjTYYPm2H6webZVWFEUbKvZixigYoxiDO4mXuJWnKXL9hrmBdJ3MAM0N/tWnc15d3VAUYlqEIdDiJDUvkb9/ydp85zFWGy6yww9OEfJ/GSf1r5txCtG99gFkxdXL+HkvyXcAZY6Vk1ZY6TjRFT2kF7c2fDZllTpRrlrv4u1lce/2duCdP+6oZ0g3iAk8ST03ujCReJru8j4reaLk3+Q6EjLznXFLZZMYH0mK6l5unsneHKwYPZBW8ZgsVIXE8bO6m6ITx84gp2xm3qNTfxnjKYMk5AkNgZ1DWELQGwpnTp377BCuZd1Mdx8LVHWLIb8D0vZ2ud4LQ9xrw6D4ARcOFAna4a5ZCaMWqgOUIR1a5Xd6souQFEMe0ZXC+P1S8iAKpopzUK6kUYQL4ah7SdTSHzARemjo53R6/nlDryMp+kq9FuPpDNKnuB45szTOKTTKnzuSG1vVsQjMR26G8UbVUqAkNvF4ViVY7JCJBOupz1dJpblKn8IsCQFZhk65LbPuZK+8cSe5Ajey6iO9ARMpUKtKXIgXiuLr7BBOJV61D9vbdq9OLuUscQ6FvBIo7s3X4FkmmN2aCaPLpw8893FiAzxRplvGe02OOz6JnN0I=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MRWPR02MB12086.eurprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(376014)(366016)(1800799024)(10070799003)(10067099003)(4143699003)(56012099006)(6133799003)(3023799007)(15056099003)(8096899003)(18002099003)(22082099003)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 2
x-ms-exchange-antispam-messagedata-0: Ci9WGK2y8JgPP1DQm+3wUSWJNvcPOjmS1dOXDXMV3jQT39HudWh/I1RLCJUlD0UzqruncZAG3lpmleFV11J/kcDliFa++dnH5RMvp2VDaIYpUocyN++dgD/yh4oP5cFrKOdh1VgQbvK9w+6YUxKbBgf5N+8sjnCYjiv5KOACMjVXL3TJuYRXZ9S4dhILwsfrTb5Op3PeF9+seBlpIpM/h8qy7MKLZwfSwKF43EZ5WQeao7TxonzzfPS0T4h09LLVn30Ht4HbwsguR8u92kYspMARlFlelDVUk6FGybk8JJSIglEHMuckmba/w9iGbIlFQtSrB9Mj8G0T5oZ9/VKTLaAvQv/o2CaJX5SOCmQyyqoip9kNo6zjsBhx41tiPVHxPSkYh3DCdnzTGHuJkROo2WriQE2WL2yUlotPF0DCtYj+spaG7iLpLebCFBXb+zgrGk3KtHjtrzT2k0u5OnlieCx9E4Qva7WCTGkjOtFX6KcXPeDW32YLhpjYiCl414n4ThPJcTpSTpLPx4kTAsOnt/TCeKdwKdkh0X0rK7i3Pe/466MjOLbxOnVlvwZ3lLkAwky6cZNjvwbK+gUWPhw33LMmMrf0yMtl0EAHFsg4xsCQY0gFaVY/9F2Vuas1TNBeOrktwZpNtRDC8UFfjbXMUbKiKHN626yxKJVBrR3IZ0ZT4wNXaISbWZejQ7aoajffeN0trKmfPNE5D4YCpoivYEXAnqfMkcGDd7Ejudf4EUUSZWEQuE4jcDTlB4uFsCefB6osNc31jGZvmWkNK6Do7ZNdLn3fMrSm7wPMxqUVfoqnBtv/MB6OHngYbfGy0U7eNjuAK7ebXXUNuIHVP2tgt/CjGOyLTrEOcxJkhCHqF4hpAKsk2juX1UdoKDS1czON3VIMXAMSz6bHIZA/nUyg3sv1EGCnvnB5GyVE5Uk/2TM2uXSQ84DHMhdepWwQTSrB+MX+1Ka3bs3uniErK3xJrfMHQ/j3YfWi12cmLof1jad06EMLHxh2lvKDD778TzkIzmHn76S0ISPEbNMVG4C049o96uQ70Abwm+PH2qQ75KUoNI8h/hn7B0yRIAule7BZg0thxWOwoO1P9A6p+E64MNa5DBvDefVSU4+x95XkhygLHK7qKlX5uQ+I/Sl73QSYVnlmbgdr3+t7T8DvEBLLtQpuUiBy1192RUNAloq3EaG/xaKOwli5dm27pTmT7rZnzCvB17G66bz/Qle2U1uqsMBstUhuOYwBOsN7LQp38OnR3ZCla0wOZ9IKzqVqdNfHtyldcdd0sNxtkRdyfFBSSugC7uylIZYsw4uQnqQxEqx95TQfV+dK4VEmdEFsN/kHAPeggaIIhfECgpNH3BncJNHpG/nmSs6b4rtkCuIJoOrHlb62ghn94JrIQr5sPqLks5mH2NtovdymXuR+g7of3LqJ8ghWIUwhBfic6pAr4eBRBDahscdX8OuF1OjsJbBun+tFRX66dWtHzcIJ/hZbl5Z0leqTxE+UiBUtDynUlOWPkDN5VhymGIabR+PV17mOPmaLItVF980zTKCKN8CyPg0PHtXC/htMwV8XsdixFrE+XuWMOH1xCDSKEuBRyKRFdtXXodqPRe9Z4ZAGOp5bRxhH14hU43VLJk9UjArn+I2FU7zsiSS019z2V2DD/lBC0D8lq8RH8Af5dsQf15Evwx2Z5G+mis7fmz15XnyvfwmyL7IoWmwhg+mH4qgsxbUMIbfAgBTSqwCJJTvRz6A1ebltqFwj+mXu+xuf4q9WYWsRVANdQVZpX3VMRY80hs0kmNKimazy
x-ms-exchange-antispam-messagedata-1: kkp5ZorUI/kCnOdR8QBZskGt8Ga5/xZoMIM=
Content-Type: multipart/alternative; boundary="_000_MRWPR02MB1208646E8345AE04A045BEFFCB7A02MRWPR02MB12086eu_"
MIME-Version: 1.0
X-OriginatorOrg: edgeless.systems
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MRWPR02MB12086.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b719b352-8e52-47e4-150c-08df01e1efd6
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Aug 2026 13:16:41.2478 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: adb650a8-5da3-4b15-b4b0-3daf65ff7626
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: p1puB41ehModYnIP1HFBn88T90EvFVishDx9LHyCWLZ0uwUCXzKb11MwwNwq08W4OEMs74pHBDDns+3hoPsy7w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR02MB10099
Message-ID-Hash: E3BIWH5RR2JDC7BIUPN63W6ITYUTBB4Z
X-Message-ID-Hash: E3BIWH5RR2JDC7BIUPN63W6ITYUTBB4Z
X-MailFrom: mr@edgeless.systems
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Re: Foundational document about TEE capabilities
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/h_l-NQldRCW1mOoZfQLEcZIoiS4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>

Hi Jeremy,

Thanks for the constructive feedback on list with recommendations for existing TEE standards. With that information, I agree that RATS is not the right place to define such a standard.

Cheers, Markus

P.S.: For some reason, I can’t find your original message in my inbox, so replying to this quoted message instead.

From: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>
Date: Monday, 3. August 2026 at 13:49
To: Ionut Mihalcea <Ionut.Mihalcea@arm.com>; Ned Smith IETF <ned.smith.ietf@outlook.com>; Michael Richardson <mcr+ietf@sandelman.ca>; Markus Rudy <mr@edgeless.systems>; RATS <rats@ietf.org>
Cc: nd <nd@arm.com>
Subject: RE: [Rats] Re: Foundational document about TEE capabilities



From: Ionut Mihalcea <Ionut.Mihalcea@arm.com>
Sent: Monday, August 3, 2026 12:07 PM
To: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>; Ned Smith IETF <ned.smith.ietf@outlook.com>; Michael Richardson <mcr+ietf@sandelman.ca>; Markus Rudy <mr=40edgeless.systems@dmarc.ietf.org>; RATS <rats@ietf.org>
Cc: nd <nd@arm.com>
Subject: Re: [Rats] Re: Foundational document about TEE capabilities


WARNING: This email originated from outside of Qualcomm. Please be wary of any links or attachments, and do not enable macros.
Hi,

Below with [IM].

From: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com<mailto:jodonogh@qti.qualcomm.com>>
Date: Monday, 3 August 2026 at 10:53
To: Ned Smith IETF <ned.smith.ietf@outlook.com<mailto:ned.smith.ietf@outlook.com>>; Michael Richardson <mcr+ietf@sandelman.ca<mailto:mcr+ietf@sandelman.ca>>; Markus Rudy <mr=40edgeless.systems@dmarc.ietf.org<mailto:mr=40edgeless.systems@dmarc.ietf.org>>; RATS <rats@ietf.org<mailto:rats@ietf.org>>
Subject: [Rats] Re: Foundational document about TEE capabilities
<snip>


  *   When we started RATS, the early versions of EAT had a “security level” claim which we eventually removed because while everyone agreed that it would be good to have such a claim, agreeing on what goes into the levels was much, much harder. We eventually settled on the “dloas” claim that lists relevant 3rd party certifications, and I think this is a better route to take than having the IETF attempt to re-invent a process to replace FIPS and Common Criteria.

…and so I’m going to “+1” the “this is not worth doing”.

[IM] What I get from this thread so far is: 1) Doing this work in IETF "at RATS level" is counterproductive;
[Jeremy O'Donoghue wrote]
I would more say that at RATS we went as far as we were able while maintaining broad consensus…

2) Doing some higher-level work in IETF "at SEAT level" might be required. Basically, we need some high level assumptions to rely on when devising RA + other protocol integrations (for example, "Can this key be extracted from the TEE?", as Markus mentioned), that must somehow tie back to RATS-level concepts / primitives.
[Jeremy O'Donoghue wrote]
Possibly. This question seems to fit into the SEAT charter section on “minimum subset of properties that the attested state must convey”, but SEAT should be careful to tie back to RATS in its definition. To use a couple of the examples that were given in the thread:

  *   Is the key that signed this statement known (and knowable) only the TEE?
     *   I’d suggest that “dloas” is the right claim to convery this information as e.g. a Common Criteria (or SESIP, or FitCEM, or OCP SAFE (but not FIPS)) certification covers exactly this type of topic. Yes, this implies a further lookup stage.
  *   Are mitigations present for CVEs?
     *   Not sure that this is a good question for the Attester, regardless of where it is. Attesting Environment sends Evidence and Verifier assesses this Evidence against e.g. CoRIMs which (hopefully) tie to CoSWIDs which eventually gets you to whether any of these SW versions are vulnerable. While it might be nice for attested DTLS to get an answer to this question without the need to go online, CVE environment is too dynamic for this to be a reasonable solution.
  *   Is debug enabled?
     *   We have a claim for that in EAT.

But the concepts themselves will be defined in documents produced by other SDOs. In the future, someone (those SDOs?) will have to link those concepts up to what we define in SEAT. Am I misunderstanding the context?
[Jeremy O'Donoghue wrote]
Maybe. I tend to categorize things in the following way:

  *   <claim> that is re-usable across many ecosystems: standardize in RATS.
  *   <claim> that is specific to some ecosystem but which might be embedded in RATS-defined formats/protocols: define in <other SDO> using IANA registration as needed.
  *   <claim> about how securely <other claim> is protected: rely on <3rd party security certification> referenced via dloas.
  *   How does <other SDO> map into RATS – whitepaper/specification in <other SDO>
  *   How does RATS map into <other SDO> - informational RFC.

Thus there could be a case for an informational RFC on how some specific 3rd party security certifications can be used to determine how securely claims from an attester are protected, but I really don’t think the IETF is the right place to create normative specifications defining security levels since there are already plenty of these - for me it would be an example of xkcd: Standards<https://xkcd.com/927/>.