[Seat] Re: Threat model and properties for attested TLS
Iman Schrock <team@emiliaprotocol.ai> Fri, 21 August 2026 00:03 UTC
Return-Path: <team@emiliaprotocol.ai>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2E9D012D1BA3F for <seat@mail2.ietf.org>; Thu, 20 Aug 2026 17:03:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787270582; bh=WzQjcwoLFGRGwwBTiOgAto7qH/0xYakus1yOueYnRB0=; h=References:In-Reply-To:From:Date:Subject:To; b=XonTwQHjdPn8d52YaGz1pq2S5s8HmApEn9T/teUSIuJZmI8c8mZTUUOuht19yWIZB +28S7e25nchVSsMGRj0Ad+l6NP5FUwD9U0s1shax+hBCn+/gRdk+B2rMQE9Qu1lSZb gkPppRWCRITwLMLriiRpbvHOnRXPPNu2/AUfxozo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=emiliaprotocol.ai
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AFmYzArLJwaL for <seat@mail2.ietf.org>; Thu, 20 Aug 2026 17:03:01 -0700 (PDT)
Received: from mail-ot1-x333.google.com (mail-ot1-x333.google.com [IPv6:2607:f8b0:4864:20::333]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id AFFBC12D1BA3A for <seat@ietf.org>; Thu, 20 Aug 2026 17:03:01 -0700 (PDT)
Received: by mail-ot1-x333.google.com with SMTP id 46e09a7af769-7eb1dc6bd53so419245a34.2 for <seat@ietf.org>; Thu, 20 Aug 2026 17:03:01 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787270581; cv=none; d=google.com; s=arc-20260327; b=RahbQEx1JwNARjMYtPyQC5f+cYK5JonfPainV/ueVGlgTayCq91xoEeTrA8cM58vZ4 65B+Q9NJ/LBfAWRT0nOs63k9hPDha9VTWR2DCKCL1H1ifGpBAJ2rgsJmmbht733MVwjb Cg38ZSIKe50Z1qk2lrl+Szr4Tw2t4Lf5Jd13pivFWpRTy6k/+XgXiQjPDEje3E9NkoqO TX9e9w7YeycdTRe8IGy/SiyjYDurjfF0IQcdkmIriAJI/NJZbG2pc6nkl7/kXe76X7uG m8BskPyGTRZS2p7KpEycJIVKpAPiqEBbdxLV9F+Cau3kPTDsdNsX+L9PRgF9x5TdROPa 3HOA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=WzQjcwoLFGRGwwBTiOgAto7qH/0xYakus1yOueYnRB0=; fh=nonanup7af3odSacD+avaZXzPkTQ1Kb/ongJHX+6ikI=; b=OWfZexAiz01bpkxTKDkZ8a63uz1+W8A/g4axDHdZv/avwctMd8f0bxoP+tNQIQz4Lg HQELA5Vwdw30njD9jppsxY34kMXvSO+HBAbx9kI+FffFVW3Wmeo+zex1YGvqCQ2QlZkX HV4WW5R/XxA9FDeZTQBsnrD8Q7yJVZGqJUR0CHTNNsait1tknITBsJ+Jckv/IqLuHNQD y8Xi1M8pdit3hd0C7O/HrgEMVA6upA8nmaXWASjvUApndQRKlUcLMT7m/xO3Zg2AQ96m L3kyflWdIbyLbEnxxBcvu6ABfp4y0HQfz6HhWuy0ToBeeiN5EzDsl9+g7cw7myWBNqSH ynoQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emiliaprotocol.ai; s=google; t=1787270581; x=1787875381; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WzQjcwoLFGRGwwBTiOgAto7qH/0xYakus1yOueYnRB0=; b=INnTDWBHCDRReZoBmvSQKsof2yepJcah2CtLnm86m7DS0TE73Kp5EBZQEafxkdHp+e 3zXkwp+iDAzqL2U0yW0y03FAq3w5SRIlOFUgnOZGBd45MTkwcpRfZ4ay/o+rA4HoW57I 4yqpLipQh8III5AEzPgRGLIL1/uGaD5No+mVBZZ86Fr986PFbHCUt4+l9aRC60pGRM0z ieqRByp+BDK6FVUTtSvm56L543V0SyQlwSVnBFbUjj3qZ+rRA0r56hCEBiFcqdOo/Rn7 CxGU8QrWvk5UNQ0rGUx0nmO4GVr8fro0CbBiPXOuNCHuyt4AQUA92t5cawAhz6jWVaw4 U2+w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787270581; x=1787875381; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WzQjcwoLFGRGwwBTiOgAto7qH/0xYakus1yOueYnRB0=; b=n4x0QKJJLP02RpATYbMy58aIIYLJqhZeaY4h+AJGZvFbpypMZTE6C/Fq9rrcLnGZ5E jlOWX7ib0zQJ2jSBZrHd51+9Qg3WeCtuPL5TC+cSaMIC9tK6JibrxNsWGpDwc6rdt5gU CVA5JUzxGr9LltJpu3LQuyPT5GLftuP2RSRGYa5GGOi7KJWdTzNk93xRGuJbvDr05MkL dSRjhwngbzTSYjgqMFJiO6fcMUSk7ITTWmDUWJuwt4bMmFcGw0vIwgzgm+KankfHoroF dfduhRPa+BzvW5Gvk8AzxbGNwHW/oYNlSBjeqZ7sKRiNXaV2/wBHQe4gblAeqVEKw2jW yYNg==
X-Gm-Message-State: AOJu0YwBEmFNJT0wZd187Jbztz5M3PGT5Cof65F1pXYL0S6aAC5fejC5 kU81ACpCRCPYCgBj4O0X4C4yjV7/qicEEJFswmFmhtf6JVUGfHNas0d2EcUeo3D7NGNqlQku39k SJHIqaqLPHqRPgnqurymC2tQrANCoJXR/g2LoGW0WoMgnFLCliPd5quSL
X-Gm-Gg: AR+sD10slygMnGAAZqelH4t5zUivGQrmFmpPVh1w/n2Q4qFvy17sAZrJsfN3b1wxLyY ALljVdh7EoG2OxHTOjeLNH+nba7jcSuStoY73TsQf+hORQSUuH1l8ue4zJw3Wd9ArwTgTAhayuu SwZjNrrOHLcAa+BB7vcjOs11hU1GgDYMc4ri0UtPms4cGkxuYVvqZ0DrPg56WMOyEvFXzwKEBIU NE4F6gS0AhcdTRLbzjUHdVRqyIhgd5/TXEdiKvjhA+ErCV/Lr0h1AnswjsU9joZCLIUk0ZJqU/w EYLVs+PzDFjmqxwPbvs1ulotDtG4qmYAWvtw6ps0cBYjLP8DG+F4eSY5wf32mTxBGUJyH5i0Gmu AMAc6+HGCGvO3Tu9Ela26ZmfG+CTVPjVhazCCAHUYQMSpXWUAWhtzDK8=
X-Received: by 2002:a05:6830:3699:b0:7d9:7201:1acf with SMTP id 46e09a7af769-7f4617fc837mr3105068a34.5.1787270580870; Thu, 20 Aug 2026 17:03:00 -0700 (PDT)
MIME-Version: 1.0
References: <fcec2ef9-4881-48a8-ba45-83e2b9110f3c@tu-dresden.de> <CAHxYnaMimQXVxaNLw89fnyUHUYfArcFeAjkEKnXp8h3w2+JoOg@mail.gmail.com> <CAEEbLAZ3zdgL_9i-h6Hxf_Mth6mNY188TN4QW9s2MceXax_0Tg@mail.gmail.com> <CAHxYnaM5gs_389oN0xOtbcwnL5nsRb0Op6hb3dCadi=sY_kdWg@mail.gmail.com> <CAK08nYZgvmjKv74ChRPoM-MbiR-GhuUhZr1aCPJFCKWtN1cF=w@mail.gmail.com> <CAHxYnaMDYhkZGvnSOgZfSvtUtfUfLAS3sydQok4R0c9fmF-VQw@mail.gmail.com> <CAEEbLAa21eKKemkT7KN_yWkLH0NeCDHP2Uz8aHPZiyMckQcYAQ@mail.gmail.com> <b19cc65f-1005-453b-b2f7-14784dd3fdf8@tu-dresden.de> <CAHxYnaMvQfUoOHAs6YvczBrrnghc+CEchNwECnpXEJOtRuQ7ZA@mail.gmail.com> <CAK08nYZ2J9X8eOYKrMYPRu0rWmG2VjThcf9g84tiGOCY6_eKXQ@mail.gmail.com> <727871af-0d59-47ca-8adf-8fee9bc809e3@tu-dresden.de>
In-Reply-To: <727871af-0d59-47ca-8adf-8fee9bc809e3@tu-dresden.de>
From: Iman Schrock <team@emiliaprotocol.ai>
Date: Thu, 20 Aug 2026 19:02:49 -0500
X-Gm-Features: AcwNN1WvzWN1UHPmKUFKJjyZbnJQJNcj8y0nHZovAXjRKG3ZD-cQjhsEQ6wJKeE
Message-ID: <CAOfgHgr0r3+7eLfZdkuNCOKN7Z4gVORgUnTddCcMD82srH3myg@mail.gmail.com>
To: seat@ietf.org
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: WQY6KG32ZIJGPXS6MTNVDF43PI35FHUI
X-Message-ID-Hash: WQY6KG32ZIJGPXS6MTNVDF43PI35FHUI
X-MailFrom: team@emiliaprotocol.ai
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Threat model and properties for attested TLS
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
All, I have reviewed this thread. Dr. Schmeig's point is important in SEAT context that additional protocol complexity in early-attestation must be justified. One implementation point I would like to add is that for EMILIA, we also need assurance that the attested peer is bound to the TLS 1.3 application traffic keys used on the specific connection. The current early-attestation design does not yet give us that assurance, so we would not implement it as an EMILIA dependency in its present form. We are prepared to evaluate the EXPAT draft and may contribute an implementation if our tests confirm the binding we need. Best, Iman Schrock Founder, EMILIA Protocol emiliaprotocol.ai
- [Seat] Threat model and properties for attested T… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Sophie Schmieg
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Sophie Schmieg
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Steve
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Ionut Mihalcea
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Regarding the charter-mandated restriction… Nathanael Ritz
- [Seat] Re: Regarding the charter-mandated restric… Ionut Mihalcea
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Paul Wouters
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Paul Wouters
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Ionut Mihalcea