Muhammad Usama Sardar
Title:
Security analysis of attested TLS and attested EDHOC
Biography:
Muhammad Usama Sardar has been working at TU Dresden since October 2017. He also serves as the co-chair of the Trusted Research Environment (TRE) Open Suite in The Global Alliance for Genomics and Health. He led the completed TEE formal specification project and currently leads the Key Broker Service (KBS) formal verification project in Confidential Computing Consortium (CCC) Attestation Special Interest Group (SIG).
He also contributes to various research networks, such as EuroProofNet (WG3), Méthodes formelles pour la sécurité, Internet Research Task Force (IRTF) Usable Formal Methods Research Group (UFMRG), as well as engineering networks, such as Internet Engineering Task Force (IETF) Remote ATtestation procedureS(RATS), Transport Layer Security (TLS), and Workload Identity in Multi System Environments (WIMSE) working groups.
Abstract:
In this talk, we will present a comprehensive security analysis of attested TLS and attested EDHOC. We aim to provide technical details of CVE-2026-33697 and EUVD-2026-16488, which provide substantial technical evidence of how intra-handshake attestation fails in practice, even without physical access. Moreover, since continuous attestation is required, intra-handshake attestation adds unnecessary complexity. The results for attested TLS are backed by research work and the ProVerif artifacts under the Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders, which include Meta’s AI, Cocos AI, Edgeless Systems Contrast, CCC Attestation SIG, and Privasys.