[Seat] Re: Updated Attacker Model in SEAT Use Cases Draft

Songbo Bu <bluedognull@gmail.com> Tue, 18 August 2026 08:09 UTC

Return-Path: <bluedognull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A47A512B75B87 for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 01:09:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787040588; bh=jpzcedGcGtqWVYZaluQFyRwktcsJlSjEwFC6S7UIUs4=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ma5+TTeJaufq+HVs5gtMOUsOupvre1TMP3e7IW/p3st7PkNH8FBe9Z0OfRF+GyZhQ X1jzcrD3v4c2H8aqIHdMK+kLAsmuVd+qzZlDiq0AmWldsCyCWXRaA/maRsLK/N/4Ih 083zT0Uy5TVwZH00G9dGEso3jra2oes7TVM/lax4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qKXM16eN56sX for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 01:09:48 -0700 (PDT)
Received: from mail-qv1-xf33.google.com (mail-qv1-xf33.google.com [IPv6:2607:f8b0:4864:20::f33]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 47EDA12B75B7C for <seat@ietf.org>; Tue, 18 Aug 2026 01:09:48 -0700 (PDT)
Received: by mail-qv1-xf33.google.com with SMTP id 6a1803df08f44-902fc790cd5so26923166d6.1 for <seat@ietf.org>; Tue, 18 Aug 2026 01:09:48 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787040582; cv=none; d=google.com; s=arc-20260327; b=YGXwr/acZKLsEkJ+W6PmoB4SmN8/fmQvyFbNQn4upOlsYYfZ3cEifVwwbwEmyZ4KJh iceF8gHh1V9pAp1u23PNaPmCDMRFpuXkhRFYqt1Znw5JVSejzBtDY4U5arw/W7iD0QmF 0XhNPr++qDOdjmlbSesVhNwVEbE3D7QDnV/DR6YqNIcsXu3TZ0c2jjqn73E20+AC9GgE vNAyYh6aDQr1Qp1Umb1j1vXuZgFOxoyAkLQjtHBeDrT4TFFHPvfli7n2LJldGtZRWXNX eO3Ko/3MgUD8N1z7HPekpU/HnY7BShRZ7rpDqXI++4BT68AIP36PVhiml2+gKa8twkPj bOtA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=jpzcedGcGtqWVYZaluQFyRwktcsJlSjEwFC6S7UIUs4=; fh=Alu4L2r1y15oxOrxGX31/Y0Cx6Amy2xa79jie4FjsE8=; b=PNv387Aj92wKmAh2/AIEtHy2Huqn6OJ/pjxpPqtAykyFqJXFs4M78hkXXb0PGKwFwj RTXW8HXg6QR5u1tSI7obwudzUMj9/iS5eHTZnjuy3WPZjYAcqQw6hiWC/u9RZ6ciCpYE HSchnY0CnqlY8XjZnJbYjiFIl/RMVDYdf3yDxg+q59hvrFa/4NSu1dfx+v6d1+SQzHuH i5dNrlzMVOtjMx+TROo3mU0UmTEAdmzGkGsvZTxPFdI3Bj7yl0G4O17BwlOTeNEp5YG3 ghmK4gPuHbrqI9jfYWvU3xdrdOTyv1R70MAgBAvWfWiYdyEYXAeiZbKYYDxnuyYPpRNW hA6g==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787040582; x=1787645382; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jpzcedGcGtqWVYZaluQFyRwktcsJlSjEwFC6S7UIUs4=; b=K64anGb5+rpYgn6zxe5qBv61mkDMtcEjef0k0elLhIUxCGMt2PtJ8UVRk8YMJ++OWb u7tIlFl55Mo89xt4WbT/7Ui5x8mcrvofvyroYR24QLYObPgYgm1czXGbQDMAbcMuk5WC PwhmmuL+KDfkAXpoMKwFer9FcWHm9Tk8S0XvUibu2CfQmlovpsXonpucQHRi0pxyEWhX Wd4Xw06brqPVGVDIZLMD4p6HblMuFE4j/svZuNhGqbpU+r3lTNqx8DUIQ7P48V6OxGlN lznjKEfnoEeSyKxEwSqwKSdqHy74a1KFcpjBrXUfkR+oGum2XNXQCfOAViKnVt8yL+03 jiIA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787040582; x=1787645382; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=jpzcedGcGtqWVYZaluQFyRwktcsJlSjEwFC6S7UIUs4=; b=dJoki0VAtHhVTmPW1uWcsJ56W648IDkwnNHAuXc50EKnpzJ2dn3E6ZdupxjiNXmOGj sCe33PdaAGyqyqVuEzDjeERu+t2bUUecNw6sL7uZVnDUmD/gH4BvAdZaUeS1zlKvqcwB gqnxuVwUdr7m4DxaNgJ1evzrMrL+ajgkCZlXXLhQqh37+BcABC5l8nXAFGBWsQ8YdADx 3M6XUKMS7OrvukrFwSWq2yjZMzhnPgOEEzYLqE/GD/Nz9tUTHOIum6ljFxnJuhq6SOWS gAAYSUmkIQeB4HEwXIFGRR75ZSObkiJbk452QatklaJEKWyI/+gcJd3Sub6f8JuGosDH bKYA==
X-Gm-Message-State: AOJu0YyHRV3w+yG3pTxfXXQTLl/zJnnV4uYOM3tXeIyrq98j1zvaTtdQ BcfY3Y3pHrkA+b6fSWIodDIjwbSG9jcJyaBm6/p1+WgzAV2Eh+gKGZk+O7Tg02SWlWOwV9sO4EI /UxW5Pr2GaddmnuZ4c01uzb0WVdq9eHos4aEmS7mjvg==
X-Gm-Gg: AR+sD12uHcWoTvPPtLsBPvFtqosF/zc0r7Vapr2COOZ7kgCs4tNFN2QxXnCcIOHqNzj W3HRoLDwbc+on/KDe9CGbpurApiXmfFyjWXe+BXCDwR8pq9GwemyeiuH++p+jAkC23A95DJkPbF kZoydljUaEkOlEZZ2Lm1oWffcDYyEPhvKPV2U0eGGhlSL/wtGqdRT1sgFXHv3katOmV+JEsT1Sr +PXKkbQPGKk4phHlN4Lh1O3/fDa1+5oPzApRlm0DS5CgeR10/HQxR1wf9DUB2XSZteh2m+crcIK JMeaDj1IpEnNTREDhdt67Wuec8+MWAECbwHFxDjdksb++NTJlba191ERdXuYUFCR68veGsUPpKe QcrjpZhU18qqZqb/UFGkyUJz79OdvPRYvhUfCEHl3k3vU1YsOiJ6pyIXFYw==
X-Received: by 2002:a05:6214:40f:b0:908:8f6e:52bd with SMTP id 6a1803df08f44-90c4b3e5fd4mr66070226d6.23.1787040581184; Tue, 18 Aug 2026 01:09:41 -0700 (PDT)
MIME-Version: 1.0
References: <CAFpG3gc1POcpcc0NCOFig=e1AgbeMpre2i++xdmXtQTpAp8vqA@mail.gmail.com> <CAK08nYaM7+2j7RgYduVRYEWkjGMYxeQNzHHWuPsbmP0hVDCC5A@mail.gmail.com> <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com>
In-Reply-To: <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com>
From: Songbo Bu <bluedognull@gmail.com>
Date: Tue, 18 Aug 2026 16:09:28 +0800
X-Gm-Features: AcwNN1Uy5eJMKxt9Osi4GmzuCgSnXqXF9314M7Az_bjvxcGHGKu7NWw_41BCHrY
Message-ID: <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com>
To: tirumal reddy <kondtir@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000000a6fcd06594dcf2b"
Message-ID-Hash: VFNYN5S5YHPPHMAVPWMVRE36JFHPGWGL
X-Message-ID-Hash: VFNYN5S5YHPPHMAVPWMVRE36JFHPGWGL
X-MailFrom: bluedognull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Tiru,

Thank you for the answers. I want to followup more narrowly.

The link between the following is missing:
Threat model => Security goals

The following section is missing:
Formal properties

On cross-connection replay handling: I think we can agree on desired
handling in this draft and solutions can then implement this.

On CVE-2026-33697: This is already exploited in the wild. Therefore, please
make it explicit in the threat model. I don't think "cross-connection
replay" is a standard term in the literature. I think CVE-2026-33697 is
related to relay and not "cross-connection replay". Therefore, as a first
step, making it explicit in the draft is useful for further discussion.

Best,
Songbo

tirumal reddy <kondtir@gmail.com> 于2026年8月18日周二 14:26写道:

> Hi Songbo,
>
> Right now the focus is to capture all the relevant threat vectors. Formal
> properties come later, after the WG concludes on the attacker model, attack
> vectors and security requirements.
>
> On cross-connection replay: how a solution detects and handles it (abort
> or otherwise) is a separate discussion for the solution drafts, not this
> document.
> On CVE-2026-33697: it is an instance of the cross-connection and relay
> class already covered in the PR. What is it you would like to see covered
> about it in the draft ?
>
> Best Regards,
> -Tiru
>
> On Tue, 18 Aug 2026 at 07:39, Songbo Bu <bluedognull@gmail.com> wrote:
>
>> Tiru,
>>
>> Thank you. I have one narrow suggestion and two questions.
>>
>> I think the draft's flow could be:
>>
>> Threat model => Security goals => Formal properties
>>
>> The draft does not currently state the desired behavior when the
>> server attempts a "cross-connection replay." Should the connection be
>> aborted?
>>
>> How is CVE-2026-33697 covered by the threat model?
>>
>> Best,
>> Songbo
>>
>