[saag] Pre-print and Artifacts for formal proofs of insecurity of RA-TLS and draft-fossati-tls-attestation

Muhammad Usama Sardar <[email protected]> Fri, 26 Dec 2025 21:59:21 +0100
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
[ Already shared at relevant lists; sharing here for wider review ]

Hi,

At the expat BoF [0], some questions were raised about my claims of 
insecurity of pre-handshake attestation (Intel's RA-TLS) and 
intra-handshake attestation (draft-fossati-tls-attestation). We (i.e., 
I, Mariam Moustafa and Tuomas Aura) would like to have your review and 
feedback on the pre-print [1] (accepted at AsiaCCS) and the artifacts 
[2] in ProVerif (under Apache-2.0 license).

Based on follow-up research, we believe that it is not possible to make 
intra-handshake attestation secure in the general case, and that 
post-handshake attestation is the most secure solution.

-Usama

[0] 
https://datatracker.ietf.org/doc/bofreq-fossati-tls-exported-attestation-expat/

[1] 
https://www.researchgate.net/publication/398839141_Identity_Crisis_in_Confidential_Computing_Formal_Analysis_of_Attested_TLS

[2] https://github.com/CCC-Attestation/formal-spec-id-crisis

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.7 KB) - not displayed