<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.urien-tls-se-xauth" target="https://datatracker.ietf.org/doc/html/draft-urien-tls-se-xauth-03">
   <front>
      <title>TLS for Secure Element Recursive Authentication</title>
      <author initials="P." surname="Urien" fullname="Pascal Urien">
         <organization>Telecom Paris</organization>
      </author>
      <date month="April" day="3" year="2026" />
      <abstract>
	 <t>   This document defines a recursive authentication architecture based
   on the TLS 1.3 pre-shared key (PSK) mode. In this context, TLS
   servers, typically hosted within secure elements (TLS-SE), realize
   procedures that compute TLS 1.3 PSK-binder and Handshake Secret.
   These procedures allow a client to authenticate to downstream TLS
   servers without directly possessing the corresponding PSKs.
   Authentication capabilities can therefore be delegated across
   multiple TLS servers while maintaining protection of the underlying
   secrets.



	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-urien-tls-se-xauth-03" />
   
</reference>
