@techreport{xia-rats-key-negotiation-integration-02, number = {draft-xia-rats-key-negotiation-integration-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-xia-rats-key-negotiation-integration/02/}, author = {Liang Xia and weiyu Jiang and Henk Birkholz and zhang jun and Houda Labiod}, title = {{Integration of Remote Attestation with Key Negotiation and Key Distribution mechanisms}}, pagetotal = 31, year = 2026, month = apr, day = 28, abstract = {This document describes a generic way to integrate Remote Attestation (RA) with key distribution and key negotiation, so that cryptographic keys are only released to or accepted from attested and policy- compliant environments. It defines an attestation-bound key management mechanism that can be applied on top of existing secure channel and key management protocols, and illustrates it with three representative scenarios: public-cloud KMS, end-user to AI data- center communication, and enterprise-operated KMS. A format-agnostic key binding claim is introduced to express the binding between an Attester’s environment, its public keys, and a session identifier, enabling Relying Parties to use Attestation Results as an input to key distribution and key agreement decisions without changing underlying protocols.}, }