[Ufmrg] Re: [Seat] Comments on formal analysis of relay attacks in intra-handshake attestation (CVE-2026-33697)

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Mon, 06 July 2026 13:44 UTC

Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: ufmrg@mail2.ietf.org
Delivered-To: ufmrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5206F11028E7A for <ufmrg@mail2.ietf.org>; Mon, 6 Jul 2026 06:44:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783345446; bh=sAfKxNWyx35N2LYYUsXkiU7HvcuppBF74NWA5hiNVtY=; h=Date:From:Subject:To:CC:References:In-Reply-To; b=s0hQD9gpjxSJnPvl0gg11v6nPlf4T4oBfeIWb03fmIxmrTf3KXAkAsigF8kvFcXmt j8KBT7BBIUAvTtZC51Cn6x/xiS8TJegVmqqjruoQsE5eEFSOD43T7TjnTzqAv/NYoU Ow5m6SmCm8xgzWVaaKPKA2DtKaL7QjFamIROKI6Y=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.397
X-Spam-Level:
X-Spam-Status: No, score=-4.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I0a6NFOzhlrX for <ufmrg@mail2.ietf.org>; Mon, 6 Jul 2026 06:44:05 -0700 (PDT)
Received: from mailout3.zih.tu-dresden.de (mailout3.zih.tu-dresden.de [141.30.67.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 461A011027A12 for <ufmrg@irtf.org>; Mon, 6 Jul 2026 06:40:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:In-Reply-To:References:CC:To: Subject:From:MIME-Version:Date:Message-ID:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=CJctTgBE/mYmLo2VK6hijFwvHZAesOdmC5KIl3Oj/bA=; b=EdgPrs/pXxZEHX7INCha4d65eg pP1lkID4NDB774chj1BvHFxQPB87QNgwoTXatbC+G7RavhLmgPcAqG+2oyit3doTBFTlEEkVbPWpe tpKXho7sirtebzpalEfGC9xecsNMDeJbVDhiNUVtGucM7br5To3OJ677MEBBnMVz61/CLeLVpp7r5 04M664dIfF/0J7IZYtM5tECLSRnCHMP730mO6GMXgv0p5qo0r1qZl7bP+OduARRbQiJsl7CaaHbfp QXP1xshXWKP0OYi4Fx2wtoPgdYQT67tAr/13V12B4sgjNWhJlrrF9VhSecvu5RdftCpn3P3IQX8Af tkhnZuyA==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout3.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1wgjZ3-00AMbi-18; Mon, 06 Jul 2026 15:40:49 +0200
Received: from [10.12.5.228] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.43; Mon, 6 Jul 2026 15:40:39 +0200
Message-ID: <8caf22fa-907d-42fd-b3db-0aed8a9fae91@tu-dresden.de>
Date: Mon, 06 Jul 2026 15:40:38 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: Nathanael Ritz <nathanritz@gmail.com>, seat@ietf.org, ufmrg@irtf.org
References: <5f361893-bc32-4737-9578-fdb3ad7be3f9@tu-dresden.de> <9F03163D-B0F9-40DD-A4AB-69C151B872D6@aiven.io> <c4a0c433-173d-44ac-bd48-eed642a674d3@tu-dresden.de> <CAHxYnaOBMnPp7EiRLNYWX8AQDc2zYoBL226nfeBiPXsyii7Now@mail.gmail.com> <CAHxYnaOFWQBLf0Pn8bY=CMx7ytSEkTbvj7xp-s0GCHJohRh5xg@mail.gmail.com> <2b53d833-51b8-4915-82b0-ac3305e89528@tu-dresden.de> <CAHxYnaPDTzHuXyeC06bKWNOQ+wYfc-02AVyDETveL7dTteYURA@mail.gmail.com> <CAK08nYaQb6tQzy_nZrJbGbyu1oLuFpAEjTWqe_hY6cmmGzJFvA@mail.gmail.com> <CAHxYnaPyD+mFBgk-axNXCS+9qob-nhF_+Y6eqz9fgPnDvNF5Nw@mail.gmail.com> <34201e80-edb7-4f99-afa2-0d5b5799c6da@tu-dresden.de> <CAHxYnaOUyvMrMRN2C4wjO_s3hpqXDDMJAOAUYyGVt0JRu4RSQQ@mail.gmail.com> <3f87fe50-f0bc-45f7-8ed5-0a7cc7cf975c@tu-dresden.de> <CAHxYnaOsUBJF1+dkhEuPdhExNmk14cWcauxEw-zo6TotWzxsHQ@mail.gmail.com>
Content-Language: en-US
In-Reply-To: <CAHxYnaOsUBJF1+dkhEuPdhExNmk14cWcauxEw-zo6TotWzxsHQ@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms050304090508020700080807"
X-ClientProxiedBy: MSX-L420.msx.ad.zih.tu-dresden.de (172.26.34.140) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout3.zih.tu-dresden.de
Message-ID-Hash: YGUKMQDW2EFCYLHQJAGT37EOCBJIYPRV
X-Message-ID-Hash: YGUKMQDW2EFCYLHQJAGT37EOCBJIYPRV
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Songbo Bu <bluedognull@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ufmrg] Re: [Seat] Comments on formal analysis of relay attacks in intra-handshake attestation (CVE-2026-33697)
List-Id: Usable Formal Methods Research Group <ufmrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ufmrg/h4ya7LVs9EcnGRuq0ge7mrlNe_g>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ufmrg>
List-Help: <mailto:ufmrg-request@irtf.org?subject=help>
List-Owner: <mailto:ufmrg-owner@irtf.org>
List-Post: <mailto:ufmrg@irtf.org>
List-Subscribe: <mailto:ufmrg-join@irtf.org>
List-Unsubscribe: <mailto:ufmrg-leave@irtf.org>

Hi Nathanael, all,

First, we have corrected the subject of this thread to /intra/-handshake 
attestation. As the title of our contribution [0,1] to the WG/RG 
suggests, that is exactly what our contribution is about. That is, CVE 
applies strictly to /intra/-handshake attestation and not to 
/post/-handshake attestation, for instance.

On 02.07.26 04:22, Nathanael Ritz wrote:

> I really don't think any further effort from me is necessary right now.

In the mean time, we have done further analysis. While we remain 
unconvinced of the relevance of your property for the purposes of 
/binding levels/, we appreciate your review and have acknowledged your 
efforts in the repo [2]. Thank you!

We also thank and acknowledge Songbo Bu for sharing his valuable 
insights [2]. In particular, we appreciate his question of the security 
property that hybrid (intra- + post-handshake attestation) can satisfy 
that post-handshake attestation alone cannot satisfy. We believe this is 
the right direction forward for the WG/RG. We also agree with him that 
security property should be independent of the draft.

Since IETF is volunteer work, nothing is necessary right now per se. 
Whenever time permits, we would be happy if you can formalize such a 
security property that Songbo proposed. This property would serve as a 
counter-example to our suggestion of Sec. 9 of the paper [0], and may 
help us and the WG absorb this additional complexity of intra-handshake 
attestation, given the demonstrated risk of high-severity and 
critical-severity vulnerabilities.

We also agree with Songbo that unnecessary code of intra-handshake 
attestation is not helpful even if it is optional. Intra-handshake 
attestation is one concrete addition in the TLS state machine; whether 
that specific path is taken or not in a specific execution is a 
different question.

===

In the mean time, we have practical proof-of-concept for reproducibility 
of exploits in intra-handshake attestation. A technical report on this 
is being prepared. It will be shared with the WG/RG when it is 
peer-reviewed and accepted.

===

We welcome any further feedback from other SEAT WG participants and 
formal methods experts in UFMRG.

Best regards,

Usama, Slava, and Jean-Marie


[0] 
https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS 


[1] https://github.com/CCC-Attestation/formal-spec-KBS

[2] https://github.com/CCC-Attestation/formal-spec-KBS#acknowledgments