[Seat] Fwd: FW: New Version Notification for draft-fossati-seat-early-attestation-07.txt

tirumal reddy <kondtir@gmail.com> Tue, 22 September 2026 06:37 UTC

Received: from mail-oa2-x10.google.com (mail-oa2-x10.google.com [IPv6:2607:f8b0:4864:30::10]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 9701B30 for <seat@ietf.org>; Tue, 22 Sep 2026 06:37:50 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=c6A3tqUk; arc=pass ("google.com:s=arc-20260327:i=1"); dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx.ietf.org: domain of kondtir@gmail.com designates 2607:f8b0:4864:30::10 as permitted sender) smtp.mailfrom=kondtir@gmail.com
Received: by mail-oa2-x10.google.com with SMTP id 586e51a60fabf-46dae65dc5cso1863097fac.1 for <seat@ietf.org>; Mon, 21 Sep 2026 23:37:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790059064; cv=none; d=google.com; s=arc-20260327; b=gJ307K1m6SNvYuuiNWTZWRwuqZrwH4D/3vwje32p+6EMwN9l4WmOGjXX/rQpaic451 3mCzRb2pNWP5Y7irMY+6DTGoDU+jbN3g5bJQiomzhoawl9DpjcsJbmHq8xZhL6fY4aB2 jTUbJ4EBSiB+v+3mW+S/pds6/GjkzNpCIDzvvEcx3KiQWFpR9gXnP0eGRQH7hEo3orJc YdSTDuetJH/1A7ycoYyOrEJ7U+vVfU65NCtYT6pWuiGK9moTCVGOndgbu/OaiusPNhOR lywwR4o4DrAJzk0gxIemAWylM/Z70hjPp5h2pB8/+FPuVSu0vLzGXp+RnkeGxc8XGxor NrRQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=2ZX3U6S4dWIWGK0Cf+dbgUCQqYkXJcmmAoQTPaUFrXQ=; fh=FKoVb39+yVG9B7YmnzovK+TdFfvuud8A7jmUqBhsIIU=; b=a1DUJCsXGH0Pnf8ltEQxS61uv4Yp0zy8NEsMM0CrY1KPytRgUc0UzXNh6Z+z1jEjEO JogD7bgTLhT+VtR4GFXCJ9zgaQ/kzt9+kSL5zkRFGQhsqFT6ZlGttX5quFu4ewxqFXVo zZH7Bdr9C7TjVpdErP94UJzXfo/T7DpH/FSyOUYQT+/zPwtVCS+/yc5xD0akolfzOZBt SlvdWp9hCEAsBR7S5yH4qfsbjxc7GRItFNDB7YlgcyvJWWsqakboaUzJMAlLG778SOu+ LfbG/fIu12Pd574dWpaRVpHFhPnEtvLJOXFwyNaqiz4tq4dGZzsC6b32GFvtPNTmKbBZ +hsQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790059064; x=1790663864; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=2ZX3U6S4dWIWGK0Cf+dbgUCQqYkXJcmmAoQTPaUFrXQ=; b=c6A3tqUkS9kIvmVRLQaKI1B8hlFHQRiR6mZB7Jz655N0PFd/+RpPGEZPCphK5z7Z8M lcG4hCJ9LBCk15yw09lGUh0GbR4gY/9jzunREvLH22SF9VV0vzCi6K2t/GnWVoWs9I1T 431j7zNK8slxqJ8txJcVjiWG64CHraB9PYN97d84hUBokJkvLWRrpToj9zAOYAdPzpYj lHq2X9BmCHGjTF4e3cDF1q2S/7B5zESgt9znAk+IDQi0b2T5CWZ/qO9GoXAiXPUJCDIG Hqc2+S5pqSg+45v/4S8M8dk4iOc8sOyjBP+a3Q8soE66XlY8in18JrBmx/k8U5Clz3Wq nFfw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790059064; x=1790663864; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2ZX3U6S4dWIWGK0Cf+dbgUCQqYkXJcmmAoQTPaUFrXQ=; b=KwCJglB40zTdzKh7hvaB01PIgRrLcEajVDgR5/3Go1dGjFO4C7AUDPz/BaGy2P+8X5 /d3aeUqUlNBGEvKeYJ3L6pyv1bxwpwbCOngJ3sZOgh1xW75L2O65KSIg9m6/XolRqth5 L31ckUvFi0UjIh28j75D3HHQPlC8Q97cAhOojvmFzYgyTSt/+roa+QhrJnh+muq3pzQD uJT98Lf6Cll6Q7H1VBxblk5uCEKqfnIv3BEOBOCPzbiFx3fgIOq0dq6BKgaKJr+nt928 r3dHMfZMJpLWxHE844/hqn9aLpGmo+DHwAUhzxc99PEG2WInrVcxS+Cn8JUV6Ff4DPRj jiow==
X-Gm-Message-State: AFuF++mVAiFC3KFL292ecId0ahcUTAH6eo+mjnc9hM3JUEpMzAzG8yUK 6H+S/d9Um/E4viz0I4xWp1VOWGHq0cVyexujXecGi6MUgmTnhPZ/xSf47x6YV80lQXZ/5XTYtBm r4i293+MhMOCjd0rlwmBG4yL8+zE2fJ0M1wii
X-Gm-Gg: AYBFou3E2cZOXiJlD8LsdU/aQ1b75JU+qAqkORBbZHUV1YHmZt6qXE3mQvk2Q73Hbn5 CgSogsZ6qm+8YxlMryKPxQdAMe+Zq1xPclr5BOAqvwYOxCYjM2Jl+lFUna7ISeEG+9924LIlaOQ bNUQlLihJ9w6mhnvoEh/51ifzdGW3T1VZIBSnC8sMLfqL0aA96F90DQGeNm6gYLpxGOpLTm5cSV E1HhuF1WUh5HhlYcy7hKY7QSIMfP3ScMFHnmTOdL693DXUNJkxMPJdcA5R4jCDpxTi18/0e7V17 1Mit2EjoTeXAGci7UopJ4mxCpz1YDY+rDSFg1DgPGdCZwiJxERV3Bisfcvu2vqJXOk+JuTgfr3F DhnDJV8yiTA==
X-Received: by 2002:a05:6870:276:b0:48f:e0f6:bd65 with SMTP id 586e51a60fabf-48fe0f6cea7mr301589fac.54.1790059063579; Mon, 21 Sep 2026 23:37:43 -0700 (PDT)
MIME-Version: 1.0
References: <178991199757.190875.14280427388787780317@dt-datatracker-fffdbdc97-wjd6q> <VI0PR07MB11371BAFE96D20FE44495C2ADAB852@VI0PR07MB11371.eurprd07.prod.outlook.com>
In-Reply-To: <VI0PR07MB11371BAFE96D20FE44495C2ADAB852@VI0PR07MB11371.eurprd07.prod.outlook.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Tue, 22 Sep 2026 12:06:52 +0530
X-Gm-Features: AcwNN1V9s1Nlgs83CwjH87wykyn4wWRhrd9X8Ar3qWg5ELP59zBkypqvRHcxgko
Message-ID: <CAFpG3geL9SWym96AV84e7dqrFY5n+EW8wBMahUpP-eQ8DgDbSQ@mail.gmail.com>
To: seat <seat@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000009c99cc065c0c9a3c"
X-Spamd-Bar: --
Message-ID-Hash: 2O6QVVZE2CLMPPPJEXQSU5FKSMBSBCGD
X-Message-ID-Hash: 2O6QVVZE2CLMPPPJEXQSU5FKSMBSBCGD
X-MailFrom: kondtir@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-seat.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Seat] Fwd: FW: New Version Notification for draft-fossati-seat-early-attestation-07.txt
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/P6I9lLZ_LkbJx1MbqTOggxVSX2k>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Hi all,

We have published draft-fossati-seat-early-attestation-07. The main change
is that Security Considerations now covers the attacks discussed in the
SEAT use cases draft and explains how the solution mitigates each of them.

Diff:
https://author-tools.ietf.org/iddiff?url2=draft-fossati-seat-early-attestation-07

Figure 4 (Section 8.1.1) works through a relay attempt under
handshake-secret compromise step by step and shows why the binder mismatch
causes the handshake to abort. Anyone who believes this draft still permits
a relay attack can demonstrate it with an equivalent call diagram: state
the adversary's starting capability, show each message exchanged, and show
the point at which the binder check succeeds for the attacker.

Please read the draft and send targeted comments on attacks against the
mechanism as specified. As a reminder, formal analysis of external drafts,
external implementations, and external publications are not part of the
current SEAT specification work.

Regards,
-Tiru
-----Original Message-----
From: internet-drafts@ietf.org <internet-drafts@ietf.org>
Sent: Sunday, September 20, 2026 7:17 PM
To: K Tirumaleswar Reddy (Nokia) <k.tirumaleswar_reddy@nokia.com>; Ionut
Mihalcea <Ionut.Mihalcea@arm.com>; Ionut Mihalcea <ionut.mihalcea@arm.com>;
Thomas Fossati <thomas.fossati@linaro.org>; K Tirumaleswar Reddy (Nokia) <
k.tirumaleswar_reddy@nokia.com>; Yaron Sheffer <yaronf.ietf@gmail.com>;
Yogesh Deshpande <Yogesh.Deshpande@arm.com>; Yogesh Deshpande <
yogesh.deshpande@arm.com>
Subject: New Version Notification for
draft-fossati-seat-early-attestation-07.txt

A new version of Internet-Draft draft-fossati-seat-early-attestation-07.txt
has been successfully submitted by Tirumaleswar Reddy and posted to the
IETF repository.

Name:     draft-fossati-seat-early-attestation
Revision: 07
Title:    Using Attestation in Transport Layer Security (TLS) and Datagram
Transport Layer Security (DTLS)
Date:     2026-09-20
Group:    Individual Submission
Pages:    37
URL:
https://www.ietf.org/archive/id/draft-fossati-seat-early-attestation-07.txt
Status:
https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/
HTML:
https://www.ietf.org/archive/id/draft-fossati-seat-early-attestation-07.html
HTMLized:
https://datatracker.ietf.org/doc/html/draft-fossati-seat-early-attestation
Diff:
https://author-tools.ietf.org/iddiff?url2=draft-fossati-seat-early-attestation-07

Abstract:

   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.



The IETF Secretariat