<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.fossati-tls-attestation" target="https://datatracker.ietf.org/doc/html/draft-fossati-tls-attestation-09">
   <front>
      <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
      <author initials="H." surname="Tschofenig" fullname="Hannes Tschofenig">
         </author>
      <author initials="Y." surname="Sheffer" fullname="Yaron Sheffer">
         <organization>Intuit</organization>
      </author>
      <author initials="P." surname="Howard" fullname="Paul Howard">
         <organization>Arm Limited</organization>
      </author>
      <author initials="I." surname="Mihalcea" fullname="Ionuț Mihalcea">
         <organization>Arm Limited</organization>
      </author>
      <author initials="Y." surname="Deshpande" fullname="Yogesh Deshpande">
         <organization>Arm Limited</organization>
      </author>
      <author initials="A." surname="Niemi" fullname="Arto Niemi">
         <organization>Huawei</organization>
      </author>
      <author initials="T." surname="Fossati" fullname="Thomas Fossati">
         <organization>Linaro</organization>
      </author>
      <date month="April" day="30" year="2025" />
      <abstract>
	 <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09" />
   
</reference>
