
From nobody Sun Jun  1 20:48:26 2014
Return-Path: <mariainesrobles@googlemail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 87E3C1A00AA; Sun,  1 Jun 2014 15:02:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.377
X-Spam-Level: 
X-Spam-Status: No, score=-0.377 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p0Ip3OL5IIGZ; Sun,  1 Jun 2014 15:02:50 -0700 (PDT)
Received: from mail-ve0-x22f.google.com (mail-ve0-x22f.google.com [IPv6:2607:f8b0:400c:c01::22f]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B3F531A0097; Sun,  1 Jun 2014 15:02:49 -0700 (PDT)
Received: by mail-ve0-f175.google.com with SMTP id jw12so4301715veb.6 for <multiple recipients>; Sun, 01 Jun 2014 15:02:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlemail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:cc:content-type; bh=ZLRO0/RIO56RwmstCmol+3YTYMXUG/RONLxBx3bLkC8=; b=gvpksA3lx30ZcAXoQXKmExES8VmFBK4rvsepd7bd+ljMI+9+ER4SDcpQHK09Yp5I+T JjVTDstoXyBfXch9NwOAHZN46R4JrpEssneQ+GOVL7WpW11OJP4Bz/9u081Va9nCpy7D ONv4nqSZ5+7dP1nkMLE5fWfkgCMRTnf6WiI2H4W0d23+DFy56Yt8ncBiN2c82dxZInXJ 1rNqGAoTalFgXJhkss8v3wawNasToxnXs7UGemYA1Rv9KNZ4rzKNPe2GlLkf4B2EgABC 1m1w8EAL8chaVIMzz2YRrPyVm4UDt8QnWeb0SX9Pc7Gc4prQML0gEXuWdbGJw25N2yhs 9Wzw==
MIME-Version: 1.0
X-Received: by 10.58.56.71 with SMTP id y7mr26717607vep.24.1401660164031; Sun, 01 Jun 2014 15:02:44 -0700 (PDT)
Received: by 10.221.16.3 with HTTP; Sun, 1 Jun 2014 15:02:43 -0700 (PDT)
Date: Mon, 2 Jun 2014 01:02:43 +0300
Message-ID: <CAP+sJUdPsh_DWdzuJK0GFEQhJO3rapK9VryNsV4uavyksDonnQ@mail.gmail.com>
From: Ines  Robles <mariainesrobles@googlemail.com>
To: ietf <ietf@ietf.org>
Content-Type: multipart/alternative; boundary=047d7b3a9b742ce9d904facd703b
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/PU-yO9YuxwD1PSEFj5CfT5rNrck
X-Mailman-Approved-At: Sun, 01 Jun 2014 20:48:25 -0700
Cc: "ipv6@ietf.org" <ipv6@ietf.org>, 6tisch-security@ietf.org, lwip@ietf.org, roll <roll@ietf.org>, ace@ietf.org, dtls-iot@ietf.org, Xavier Vilajosana <xvilajosana@eecs.berkeley.edu>, coman@ietf.org, core@ietf.org, 6lo@ietf.org, "6tisch@ietf.org" <6tisch@ietf.org>
Subject: [6tisch-security] LLN Plugfest at IETF 90
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 01 Jun 2014 22:02:53 -0000

--047d7b3a9b742ce9d904facd703b
Content-Type: text/plain; charset=UTF-8

Dear all,

We would like to announce the plugfest event at the 90th IETF Meeting in
Toronto.

We call for participants. The deadline to receive topics to present or
demonstrate in the event is 06/13/2014. Interested audience is also welcome
and we encourage audience to participate in the feedback session.

Please find next the plugfest information.

We hope to see you there!

Xavier and Ines.

-----------------------
Low Power and Lossy Networks plugfest at IETF90

The IETF 6TiSCH <https://datatracker.ietf.org/wg/6tisch/charter/>, IETF 6lo
<https://datatracker.ietf.org/wg/6lo/charter/> and IETF ROLL
<https://datatracker.ietf.org/wg/roll/charter/> working groups are hosting
an informal "plugfest" event at the IETF90 meeting, in Toronto, CA, during
the week of July 20-25 2014.
Goals

The goal of this event is to bring together people interested in hands-on
experience around the technology developed by the 6TiSCH, 6lo and ROLL
working groups, with a particular focus on the TSCH mode of IEEE802.15.4e,
6lowpan, RPL and new WG specifications.
When and where ?

   - *Date*: Sunday July 20 2014, 0900-1300 EDT.
   - *Location*: Meeting Room TBD, Fairmont Royal York Hotel 100 Front
   Street W, Toronto, CA.

*Early access: TBD if the plugfest room will be open starting 8am EDT on
Sunday 20 2014 to allow people to set up.*
Topology proposed - TBD

   - Star topology
   - IPv6

Complementary angles

This event will feature the following complementary angles:

   - Interoperation
   - Demonstration
   - Tools

Focus 1: Interoperation

Download the interoperation guidelines:

   - - TBD for Toronto - interoperation guidelines, version 1 (London)
   <https://bitbucket.org/6tisch/meetings/src/master/140306_ietf89_plugfest_london/ietf89_6tisch_interop_guidelines_v01.pdf>

The goal is to achieve interoperation between different hardware and
software implementations on the different aspects addressed by 6lo, 6TiSCH
and ROLL WGs. This include 6TiSCH minimal draft implementation,
demonstrating TSCH synchronization and OF0 for RPL on a minimal network.
6lowpan to demostrate cross link layer inter-operability by means of
bridges or backbones routers. Storing and non-storing RPL implementation
including its coexistance in different sub-networks.

The focus during this event is open to demonstrating 6lo, ROLL or 6TiSCH
drafts implementations, including but not limited to: e.g. - 6TiSCH minimal
draft: http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00. - TBD

Participants are encouraged to bring devices which implement parts or all
of the listed drafts.

Levels of interoperation are proposed:

   - *Level 1*, star topology. A single BBR devices acts as the time source
   neighbor for all other nodes. Nodes need to demonstrate frame-based and
   acknowledgement-based synchronization. The static TSCH schedule, as well as
   all slot timings are taken from draft-ietf-6tisch-minimal-00.
   - *Level 2*, multi-hop topology. This level builds upon level 1. The
   goal of this level is full compliance to draft-ietf-6tisch-minimal-00,
   including multi-hop routing (RPL).
   - *Level 3*, on-the-fly scheduling. [optional] Preliminary
   implementations of
   http://tools.ietf.org/html/draft-dujovne-6tisch-on-the-fly can be shown.
   - *Level 4*, drafts from ROLL, such as:
   draft-ietf-roll-mpl-parameter-configuration,
   draft-ko-roll-mix-network-pathology, Opportunistic routing, selective DIS,
   and others that participants want to show
   - *Level 5*, drafts from 6lo, such as: draft-ietf-6lo-btle,
   draft-ietf-6lo-ghc,draft-ietf-6lo-lowpanz, and others that participants
   want to show.
   - *Level 6* Other drafts, such as draft-thubert-6man-flow-label-for-rpl,
   etc.

Focus 2: Demonstration

Participants are encouraged to bring devices and technology based on
6TiSCH, 6lo and ROLL which they believe can be of interest for the other
participants. These devices may or may not participate in the
interoperation event. Demonstration of more complete systems are
encouraged, for example systems which show the interconnection of a 6TiSCH
based mesh to traditional networks.
Focus 3: Tools

Participants are encouraged to bring and present different tools developed
around 6TiSCH/6lo/ROLL networks. Possible tools include, but are not
limited to:

   - acquisition devices (i.e. "sniffers")
   - packet analysis tools (e.g. Wireshark)
   - simulation/emulation platforms

Important Dates

The preparation of this event will be held during a portion of the
bi-weekly 6TiSCH call (*To Be Decided how and when!!!*). In particular:

   - *06/02/2014* Announcement of the plugfest event to the WG/ML related
   with constrained devices, such as: 6tisch, 6lo, roll, core, lwig, dtls-iot,
   coman, ace, etc.
   - *06/06/2014* Adoption of the plugfest call by the WGs, and call for
   participants at each group.
   - *06/02/2014-06/13/2014* Participants have contacted the plugfest
   chairs (Xavier or Ines) with a tentative description of what they wish to
   participate in.
   - *06/20/2014* Synchronization point 1. Participants can share the state
   of advancement of the implementation and raise blocking points.
   - *07/11/2014* Synchronization point 2. Participants can share the state
   of advancement of the implementation and raise blocking points.
   - *07/20/2014*. Plugfest at IETF90.

Tentative Agenda from 9:00 to 13:00

   - *[09.00]* Welcome and Initial Instructions
   - *[09.05]* Participants Pitch (5 min per Participant)
   - *[09.45]* Participants Pitch Tools (5 min per Participant)
   - *[10.15]* Interoperation (Islands)
   - *[11.50]* Feedback and open discussion.
   - *[12.40]* Acknowledgements and Plugfest End

For More Information

   - *Contact*: Xavi Vilajosana xvilajosana@eecs.berkeley.edu - Ines Robles
   mariainesrobles@gmail.com

Note Well

This event is organized as part of the IETF90 standardization meeting. You
need to register to the IETF90 conference to be able to participate. Daily
passes are available. The IETF Note Well applies to this plugfest, see
http://www.ietf.org/about/note-well.html.
About

The IETF 6TiSCH working group standardizes mechanisms focusing on enabling
IPv6 over the TSCH mode of the IEEE802.15.4e standard. You can access the
charter at http://datatracker.ietf.org/wg/6tisch/charter/, which also
contains links to the mailing list and the Internet-Drafts published by the
group. 6TiSCH holds weekly phone calls on Friday 8am PST. Participation is
open, and is subject to the IETF Note Well.

The IETF 6lo working group focuses on the work that facilitates IPv6
connectivity over constrained node networks with the characteristics of:
limited power, memory and processing resources;. You can access the charter
at https://datatracker.ietf.org/wg/6lo/charter/, which also contains links
to the mailing list and the I-D published by the group.

The IETF ROLL working group is focused on routing issues for LLN (Low Power
and Lossy Networks), in IPv6 routing architectural framework for the
industrial, connected home, building and urban sensor networks application
scenarios. You can access the charter at
https://datatracker.ietf.org/wg/roll/charter/, which also contains links to
the mailing list and the I-D published by the group.

--047d7b3a9b742ce9d904facd703b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><span style=3D"font-family:arial,helvetica,sans-=
serif;color:rgb(0,0,0)">Dear all,</span><br></div><font face=3D"arial, helv=
etica, sans-serif"><br style=3D"color:rgb(0,0,0)"><span style=3D"color:rgb(=
0,0,0)">We would like to announce the plugfest event at the 90th IETF Meeti=
ng in Toronto.</span></font><div>

<span style=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, sans-serif=
"><br></font></span></div></div><div><span style=3D"color:rgb(0,0,0)"><font=
 face=3D"arial, helvetica, sans-serif">We call for participants. The deadli=
ne to receive topics to present or demonstrate in the event is 06/13/2014. =
Interested audience is also welcome and we encourage audience to participat=
e in the feedback session.</font></span></div>

<div><div><span style=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, =
sans-serif"><br></font></span></div><div><span style=3D"color:rgb(0,0,0)"><=
font face=3D"arial, helvetica, sans-serif">Please find next the plugfest in=
formation.=C2=A0</font></span><div>

<font face=3D"arial, helvetica, sans-serif"><br></font></div><div><span sty=
le=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, sans-serif">We hope=
 to see you there!</font></span><div><font color=3D"#000000" face=3D"arial,=
 helvetica, sans-serif"><br>

</font></div><div><div style=3D"color:rgb(0,0,0)"><font face=3D"arial, helv=
etica, sans-serif">Xavier and Ines.</font></div></div></div></div><div styl=
e=3D"font-family:&#39;Times New Roman&#39;;font-size:13px;color:rgb(0,0,0)"=
>
<font size=3D"3"><br>
</font></div><div style=3D"font-family:&#39;Times New Roman&#39;;font-size:=
13px;color:rgb(0,0,0)"><font size=3D"3">-----------------------</font></div=
><div><h1 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-si=
ze:24px;margin:20px 0px 10px;padding:0px;font-weight:normal;line-height:1.2=
5">

Low Power and Lossy Networks plugfest at IETF90</h1><p style=3D"color:rgb(5=
1,51,51);font-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;pa=
dding:0px;word-wrap:break-word;line-height:20px">The=C2=A0<a href=3D"https:=
//datatracker.ietf.org/wg/6tisch/charter/" style=3D"color:rgb(59,115,175);t=
ext-decoration:none" target=3D"_blank">IETF 6TiSCH</a>,=C2=A0<a href=3D"htt=
ps://datatracker.ietf.org/wg/6lo/charter/" style=3D"color:rgb(59,115,175);t=
ext-decoration:none" target=3D"_blank">IETF 6lo</a>=C2=A0and=C2=A0<a href=
=3D"https://datatracker.ietf.org/wg/roll/charter/" style=3D"color:rgb(59,11=
5,175);text-decoration:none" target=3D"_blank">IETF ROLL</a>=C2=A0working g=
roups are hosting an informal &quot;plugfest&quot; event at the IETF90 meet=
ing, in Toronto, CA, during the week of July 20-25 2014.</p>

<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Goals=
</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">

The goal of this event is to bring together people interested in hands-on e=
xperience around the technology developed by the 6TiSCH, 6lo and ROLL worki=
ng groups, with a particular focus on the TSCH mode of IEEE802.15.4e, 6lowp=
an, RPL and new WG specifications.</p>

<h3 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:18p=
x;margin:20px 0px 0px;padding:0px;line-height:1.3888888888888888;font-weigh=
t:normal">When and where ?</h3><ul style=3D"color:rgb(51,51,51);font-family=
:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">

<li style=3D"word-wrap:break-word"><strong>Date</strong>: Sunday July 20 20=
14, 0900-1300 EDT.</li><li style=3D"word-wrap:break-word"><strong>Location<=
/strong>: Meeting Room TBD, Fairmont Royal York Hotel 100 Front Street W, T=
oronto, CA.</li>

</ul><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
"><strong>Early access: TBD if the plugfest room will be open starting 8am =
EDT on Sunday 20 2014 to allow people to set up.</strong></p>

<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Topol=
ogy proposed - TBD</h2><ul style=3D"color:rgb(51,51,51);font-family:Arial,s=
ans-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">

<li style=3D"word-wrap:break-word">Star topology</li><li style=3D"word-wrap=
:break-word">IPv6</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Ari=
al,sans-serif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:no=
rmal;line-height:1.5">

Complementary angles</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,=
sans-serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-w=
ord;line-height:20px">This event will feature the following complementary a=
ngles:</p>

<ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14p=
x;margin:10px 0px 0px;line-height:20px"><li style=3D"word-wrap:break-word">=
Interoperation</li><li style=3D"word-wrap:break-word">Demonstration</li><li=
 style=3D"word-wrap:break-word">

Tools</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-seri=
f;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-he=
ight:1.5">Focus 1: Interoperation</h2>
<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Dow=
nload the interoperation guidelines:</p><ul style=3D"color:rgb(51,51,51);fo=
nt-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:2=
0px">

<li style=3D"word-wrap:break-word"><a href=3D"https://bitbucket.org/6tisch/=
meetings/src/master/140306_ietf89_plugfest_london/ietf89_6tisch_interop_gui=
delines_v01.pdf" style=3D"color:rgb(59,115,175);text-decoration:none" targe=
t=3D"_blank"> - TBD for Toronto - interoperation guidelines, version 1 (Lon=
don)</a></li>

</ul><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">The goal is to achieve interoperation between different hardware and soft=
ware implementations on the different aspects addressed by 6lo, 6TiSCH and =
ROLL WGs. This include 6TiSCH minimal draft implementation, demonstrating T=
SCH synchronization and OF0 for RPL on a minimal network. 6lowpan to demost=
rate cross link layer inter-operability by means of bridges or backbones ro=
uters. Storing and non-storing RPL implementation including its coexistance=
 in different sub-networks.</p>

<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 focus during this event is open to demonstrating 6lo, ROLL or 6TiSCH draft=
s implementations, including but not limited to: e.g. - 6TiSCH minimal draf=
t:=C2=A0<a href=3D"http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00"=
 rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-decoration:none" targ=
et=3D"_blank">http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00</a>. =
- TBD</p>

<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Par=
ticipants are encouraged to bring devices which implement parts or all of t=
he listed drafts.</p>

<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Lev=
els of interoperation are proposed:</p><ul style=3D"color:rgb(51,51,51);fon=
t-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:20=
px">

<li style=3D"word-wrap:break-word"><strong>Level 1</strong>, star topology.=
 A single BBR devices acts as the time source neighbor for all other nodes.=
 Nodes need to demonstrate frame-based and acknowledgement-based synchroniz=
ation. The static TSCH schedule, as well as all slot timings are taken from=
 draft-ietf-6tisch-minimal-00.</li>

<li style=3D"word-wrap:break-word"><strong>Level 2</strong>, multi-hop topo=
logy. This level builds upon level 1. The goal of this level is full compli=
ance to draft-ietf-6tisch-minimal-00, including multi-hop routing (RPL).</l=
i>

<li style=3D"word-wrap:break-word"><strong>Level 3</strong>, on-the-fly sch=
eduling. [optional] Preliminary implementations of=C2=A0<a href=3D"http://t=
ools.ietf.org/html/draft-dujovne-6tisch-on-the-fly" rel=3D"nofollow" style=
=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">http://to=
ols.ietf.org/html/draft-dujovne-6tisch-on-the-fly</a>=C2=A0can be shown.</l=
i>

<li style=3D"word-wrap:break-word"><strong>Level 4</strong>, drafts from RO=
LL, such as: draft-ietf-roll-mpl-parameter-configuration, draft-ko-roll-mix=
-network-pathology, Opportunistic routing, selective DIS, and others that p=
articipants want to show</li>

<li style=3D"word-wrap:break-word"><strong>Level 5</strong>, drafts from 6l=
o, such as: draft-ietf-6lo-btle, draft-ietf-6lo-ghc,draft-ietf-6lo-lowpanz,=
 and others that participants want to show.</li><li style=3D"word-wrap:brea=
k-word">

<strong>Level 6</strong>=C2=A0Other drafts, such as draft-thubert-6man-flow=
-label-for-rpl, etc.</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:=
Arial,sans-serif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight=
:normal;line-height:1.5">

Focus 2: Demonstration</h2><p style=3D"color:rgb(51,51,51);font-family:Aria=
l,sans-serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break=
-word;line-height:20px">Participants are encouraged to bring devices and te=
chnology based on 6TiSCH, 6lo and ROLL which they believe can be of interes=
t for the other participants. These devices may or may not participate in t=
he interoperation event. Demonstration of more complete systems are encoura=
ged, for example systems which show the interconnection of a 6TiSCH based m=
esh to traditional networks.</p>

<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Focus=
 3: Tools</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;=
font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-he=
ight:20px">

Participants are encouraged to bring and present different tools developed =
around 6TiSCH/6lo/ROLL networks. Possible tools include, but are not limite=
d to:</p><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font=
-size:14px;margin:10px 0px 0px;line-height:20px">

<li style=3D"word-wrap:break-word">acquisition devices (i.e. &quot;sniffers=
&quot;)</li><li style=3D"word-wrap:break-word">packet analysis tools (e.g. =
Wireshark)</li><li style=3D"word-wrap:break-word">simulation/emulation plat=
forms</li>

</ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-siz=
e:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">=
Important Dates</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-=
serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;l=
ine-height:20px">

The preparation of this event will be held during a portion of the bi-weekl=
y 6TiSCH call (<strong>To Be Decided how and when!!!</strong>). In particul=
ar:</p><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-s=
ize:14px;margin:10px 0px 0px;line-height:20px">

<li style=3D"word-wrap:break-word"><strong>06/02/2014</strong>=C2=A0Announc=
ement of the plugfest event to the WG/ML related with constrained devices, =
such as: 6tisch, 6lo, roll, core, lwig, dtls-iot, coman, ace, etc.</li><li =
style=3D"word-wrap:break-word">

<strong>06/06/2014</strong>=C2=A0Adoption of the plugfest call by the WGs, =
and call for participants at each group.</li><li style=3D"word-wrap:break-w=
ord"><strong>06/02/2014-06/13/2014</strong>=C2=A0Participants have contacte=
d the plugfest chairs (Xavier or Ines) with a tentative description of what=
 they wish to participate in.</li>

<li style=3D"word-wrap:break-word"><strong>06/20/2014</strong>=C2=A0Synchro=
nization point 1. Participants can share the state of advancement of the im=
plementation and raise blocking points.</li><li style=3D"word-wrap:break-wo=
rd">
<strong>07/11/2014</strong>=C2=A0Synchronization point 2. Participants can =
share the state of advancement of the implementation and raise blocking poi=
nts.</li>
<li style=3D"word-wrap:break-word"><strong>07/20/2014</strong>. Plugfest at=
 IETF90.</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-s=
erif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line=
-height:1.5">

Tentative Agenda from 9:00 to 13:00</h2><ul style=3D"color:rgb(51,51,51);fo=
nt-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:2=
0px"><li style=3D"word-wrap:break-word"><em>[09.00]</em>=C2=A0Welcome and I=
nitial Instructions</li>

<li style=3D"word-wrap:break-word"><em>[09.05]</em>=C2=A0Participants Pitch=
 (5 min per Participant)</li><li style=3D"word-wrap:break-word"><em>[09.45]=
</em>=C2=A0Participants Pitch Tools (5 min per Participant)</li><li style=
=3D"word-wrap:break-word">

<em>[10.15]</em>=C2=A0Interoperation (Islands)</li><li style=3D"word-wrap:b=
reak-word"><em>[11.50]</em>=C2=A0Feedback and open discussion.</li><li styl=
e=3D"word-wrap:break-word"><em>[12.40]</em>=C2=A0Acknowledgements and Plugf=
est End</li></ul>

<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">For M=
ore Information</h2><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">

<li style=3D"word-wrap:break-word"><strong>Contact</strong>: Xavi Vilajosan=
a=C2=A0<a href=3D"mailto:xvilajosana@eecs.berkeley.edu" style=3D"color:rgb(=
59,115,175);text-decoration:none" target=3D"_blank">xvilajosana@eecs.berkel=
ey.edu</a>=C2=A0- Ines Robles=C2=A0<a href=3D"mailto:mariainesrobles@gmail.=
com" style=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank"=
>mariainesrobles@gmail.com</a></li>

</ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-siz=
e:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">=
Note Well</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;=
font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-he=
ight:20px">

This event is organized as part of the IETF90 standardization meeting. You =
need to register to the IETF90 conference to be able to participate. Daily =
passes are available. The IETF Note Well applies to this plugfest, see=C2=
=A0<a href=3D"http://www.ietf.org/about/note-well.html" rel=3D"nofollow" st=
yle=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">http:/=
/www.ietf.org/about/note-well.html</a>.</p>

<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">About=
</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">

The IETF 6TiSCH working group standardizes mechanisms focusing on enabling =
IPv6 over the TSCH mode of the IEEE802.15.4e standard. You can access the c=
harter at=C2=A0<a href=3D"http://datatracker.ietf.org/wg/6tisch/charter/" r=
el=3D"nofollow" style=3D"color:rgb(59,115,175);text-decoration:none" target=
=3D"_blank">http://datatracker.ietf.org/wg/6tisch/charter/</a>, which also =
contains links to the mailing list and the Internet-Drafts published by the=
 group. 6TiSCH holds weekly phone calls on Friday 8am PST. Participation is=
 open, and is subject to the IETF Note Well.</p>

<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 IETF 6lo working group focuses on the work that facilitates IPv6 connectiv=
ity over constrained node networks with the characteristics of: limited pow=
er, memory and processing resources;. You can access the charter at=C2=A0<a=
 href=3D"https://datatracker.ietf.org/wg/6lo/charter/" rel=3D"nofollow" sty=
le=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">https:/=
/datatracker.ietf.org/wg/6lo/charter/</a>, which also contains links to the=
 mailing list and the I-D published by the group.</p>

<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 IETF ROLL working group is focused on routing issues for LLN (Low Power an=
d Lossy Networks), in IPv6 routing architectural framework for the industri=
al, connected home, building and urban sensor networks application scenario=
s. You can access the charter at=C2=A0<a href=3D"https://datatracker.ietf.o=
rg/wg/roll/charter/" rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-d=
ecoration:none" target=3D"_blank">https://datatracker.ietf.org/wg/roll/char=
ter/</a>, which also contains links to the mailing list and the I-D publish=
ed by the group.</p>

</div></div></div>

--047d7b3a9b742ce9d904facd703b--


From nobody Mon Jun  2 06:40:36 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F25031A0217 for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 06:40:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H139RvbgdydL for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 06:40:31 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9AB251A032D for <6tisch-security@ietf.org>; Mon,  2 Jun 2014 06:40:30 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 4F25A20028 for <6tisch-security@ietf.org>; Mon,  2 Jun 2014 09:43:21 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 2B94A63B0E; Mon,  2 Jun 2014 09:40:09 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 178AD63B0B for <6tisch-security@ietf.org>; Mon,  2 Jun 2014 09:40:09 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: "6tisch-security\@ietf.org" <6tisch-security@ietf.org>
In-Reply-To: <26563.1401303435@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 02 Jun 2014 09:40:09 -0400
Message-ID: <32145.1401716409@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/bb_5oQ6sFwqs3-qtn36O3pxZjSY
Subject: [6tisch-security] REMINDER links for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Jun 2014 13:40:34 -0000

--=-=-=


Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > To remind the calls will return to Monday mornings at:
    > 7am PDT, 10am EDT, 1400 UTC.

WEBEX:
  https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

Etherpad (tools.ietf.org copy is broken):
  https://etherpad.mozilla.org/m05IQXtaBn

Jonathan's original email:
   https://mailarchive.ietf.org/arch/msg/6tisch-security/BsaHCRCgVXGZcUw2_1yj-6VSCqk

the slides: https://mailarchive.ietf.org/a/mailarch/data/archive/6tisch-security/_attachments/pdf49MINbpdf

    > The plan is to come up with a table of contents for two
    > documents on the details of the packet flow/sizes/etc. for
    > the two possible mechanisms.   That will be item #1.

THIS WILL OCCUR ON ETHERPAD.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU4x+tYCLcPvd0N1lAQKk7Af+LBCCyNOgJRSCzlDbd+KvjwM9zS8cfGhl
DKnXyK+/HJMEW942tH/M9zDmx+iGOTX4plgcT5Ohr3yggt9qC/GGPJIo1GiR624I
jH83cGEoAvttdxu2rqu89dQFub+CGa2s3tz1Vk4iJrmyA6YzqXm5UbPbRGAj9Zpt
d7Tu3nsWj6zKfWOCcNxdUdvJnZu3Tk3pEsiIota7ikG5OILN5UyA6mDEPXJ21YHW
PSiwx6WafZ+EpPsb2qyvR0HPyjk/wSfH8LYJXOWQYf4qrcS27U7PwY0VyzEdRayR
PpkLLG6jQJnwER2CaARGOppvMGCcafCpJt2D3OGMX/eawxvLS2S8dQ==
=GKJT
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun  2 06:48:33 2014
Return-Path: <mbehring@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A81F51A0327 for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 06:48:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y4gh99h0ZFlM for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 06:48:30 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 188091A0325 for <6tisch-security@ietf.org>; Mon,  2 Jun 2014 06:48:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1321; q=dns/txt; s=iport; t=1401716905; x=1402926505; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=TpoPj8uNNDRCAXbo7YesnUkvZYhbsrx3ZxB1mtLkF4g=; b=i/xOE5i7eJXiAq55pzxGRF/9J/zODdWjnX6OTVaAGV0S48NshgIZD/3a rmoysmOyOLduUn+PwSshiOiRIOlmIlOvDDo9rwPc/2NFMCzQOfUwRvlEh eXftAAgkDvOEZ/Ck/roMinpspxz2VF7pZ+IC5ya8BvUlWmu0niPdXfA1E 4=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AukKAON/jFOtJV2c/2dsb2JhbAA/GoMHUliqOpgbAYERFnSCJQEBAQQ6SwQCAQgRBAEBAQoUCQcyFAkIAgQBEgiIOg021DUXhVWFbgGCLBEBHzgGgyWBFQSbPpFvgzhsgQo5
X-IronPort-AV: E=Sophos;i="4.98,957,1392163200"; d="scan'208";a="329819273"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by rcdn-iport-8.cisco.com with ESMTP; 02 Jun 2014 13:48:24 +0000
Received: from xhc-aln-x07.cisco.com (xhc-aln-x07.cisco.com [173.36.12.81]) by rcdn-core-5.cisco.com (8.14.5/8.14.5) with ESMTP id s52DmOWw004520 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 2 Jun 2014 13:48:24 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.39]) by xhc-aln-x07.cisco.com ([173.36.12.81]) with mapi id 14.03.0123.003; Mon, 2 Jun 2014 08:48:24 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] REMINDER links for 2014-06-02 6tisch security call
Thread-Index: AQHPfmg6482XOZ4lg0qKbhFVBveuhJtd1cJg
Date: Mon, 2 Jun 2014 13:48:23 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF21B94A01@xmb-rcd-x14.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca> <32145.1401716409@sandelman.ca>
In-Reply-To: <32145.1401716409@sandelman.ca>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.238.137]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/M1vms3hQZn4SPW0zsZ4osGh8ebk
Subject: Re: [6tisch-security] REMINDER links for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Jun 2014 13:48:31 -0000

I apologize, I can't make today's meeting.=20

Michael

> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf
> Of Michael Richardson
> Sent: 02 June 2014 15:40
> To: 6tisch-security@ietf.org
> Subject: [6tisch-security] REMINDER links for 2014-06-02 6tisch security =
call
>=20
>=20
> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>     > To remind the calls will return to Monday mornings at:
>     > 7am PDT, 10am EDT, 1400 UTC.
>=20
> WEBEX:
>=20
> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd58
> 0b7908
>=20
> Etherpad (tools.ietf.org copy is broken):
>   https://etherpad.mozilla.org/m05IQXtaBn
>=20
> Jonathan's original email:
>    https://mailarchive.ietf.org/arch/msg/6tisch-
> security/BsaHCRCgVXGZcUw2_1yj-6VSCqk
>=20
> the slides: https://mailarchive.ietf.org/a/mailarch/data/archive/6tisch-
> security/_attachments/pdf49MINbpdf
>=20
>     > The plan is to come up with a table of contents for two
>     > documents on the details of the packet flow/sizes/etc. for
>     > the two possible mechanisms.   That will be item #1.
>=20
> THIS WILL OCCUR ON ETHERPAD.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20


From nobody Mon Jun  2 07:16:02 2014
Return-Path: <ncamwing@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB3A31A0340 for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 07:16:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ly6k6fIRKN7u for <6tisch-security@ietfa.amsl.com>; Mon,  2 Jun 2014 07:15:59 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 437E81A033E for <6tisch-security@ietf.org>; Mon,  2 Jun 2014 07:15:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1637; q=dns/txt; s=iport; t=1401718554; x=1402928154; h=from:to:subject:date:message-id:in-reply-to:content-id: content-transfer-encoding:mime-version; bh=V0t/1i/lqpKWKwpcI69/FmoraxnrdDBZvPik4ydksNs=; b=kvcFZUp5pr2fnpT6TDub4wH4doJIr0pQxP2wL1U1fcNNp8a3olSByee0 Od5oHjWDA8lgykjDLMPpN6epwmbguzIDmrZsjmNOrgWGXNPxPVgsInQmI SV6Fa0xR/pTxMfXIqHRX7VbQn2FNfWScjG7JWB3ohkk8lopTVzxGFeaP2 Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgcFADaGjFOtJA2N/2dsb2JhbAA/GoMHUli7HIZoUQGBEhZ0giUBAQEEAQEBaxcGAQgRBAEBAScuCxQJCAIEARKIQg021D8Xi0MBgiwRAVcGhDoEmgCBPpFvgzhsgQo5
X-IronPort-AV: E=Sophos;i="4.98,957,1392163200"; d="scan'208";a="329837847"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by rcdn-iport-3.cisco.com with ESMTP; 02 Jun 2014 14:15:53 +0000
Received: from xhc-aln-x14.cisco.com (xhc-aln-x14.cisco.com [173.36.12.88]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id s52EFrAQ005720 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 2 Jun 2014 14:15:53 GMT
Received: from xmb-aln-x02.cisco.com ([169.254.5.121]) by xhc-aln-x14.cisco.com ([173.36.12.88]) with mapi id 14.03.0123.003; Mon, 2 Jun 2014 09:15:53 -0500
From: "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>
To: "Michael Behringer (mbehring)" <mbehring@cisco.com>, Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] REMINDER links for 2014-06-02 6tisch security call
Thread-Index: AQHPfmg6SmOkAVDyKUGZG6Mns3LJRJteKaWA//+SVIA=
Date: Mon, 2 Jun 2014 14:15:52 +0000
Message-ID: <CFB1D520.BAEF5%ncamwing@cisco.com>
In-Reply-To: <3AA7118E69D7CD4BA3ECD5716BAF28DF21B94A01@xmb-rcd-x14.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.3.2.130206
x-originating-ip: [10.21.145.1]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <445578C71FC329429F6371F4E0F96BC1@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/s27JJtQJosY8foxQ29-j_VaSOxk
Subject: Re: [6tisch-security] REMINDER links for 2014-06-02 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Jun 2014 14:16:01 -0000

Same for me=8A. Nancy

On 6/2/14 6:48 AM, "Michael Behringer (mbehring)" <mbehring@cisco.com>
wrote:

>I apologize, I can't make today's meeting.
>
>Michael
>
>> -----Original Message-----
>> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On
>>Behalf
>> Of Michael Richardson
>> Sent: 02 June 2014 15:40
>> To: 6tisch-security@ietf.org
>> Subject: [6tisch-security] REMINDER links for 2014-06-02 6tisch
>>security call
>>=20
>>=20
>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>     > To remind the calls will return to Monday mornings at:
>>     > 7am PDT, 10am EDT, 1400 UTC.
>>=20
>> WEBEX:
>>=20
>> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd58
>> 0b7908
>>=20
>> Etherpad (tools.ietf.org copy is broken):
>>   https://etherpad.mozilla.org/m05IQXtaBn
>>=20
>> Jonathan's original email:
>>    https://mailarchive.ietf.org/arch/msg/6tisch-
>> security/BsaHCRCgVXGZcUw2_1yj-6VSCqk
>>=20
>> the slides: https://mailarchive.ietf.org/a/mailarch/data/archive/6tisch-
>> security/_attachments/pdf49MINbpdf
>>=20
>>     > The plan is to come up with a table of contents for two
>>     > documents on the details of the packet flow/sizes/etc. for
>>     > the two possible mechanisms.   That will be item #1.
>>=20
>> THIS WILL OCCUR ON ETHERPAD.
>>=20
>> --
>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>> -=3D IPv6 IoT consulting =3D-
>>=20
>>=20
>
>_______________________________________________
>6tisch-security mailing list
>6tisch-security@ietf.org
>https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Mon Jun  2 14:25:33 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B94B81A044F; Mon,  2 Jun 2014 14:25:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zdcgqgTtSpHp; Mon,  2 Jun 2014 14:25:26 -0700 (PDT)
Received: from mail-qg0-x22b.google.com (mail-qg0-x22b.google.com [IPv6:2607:f8b0:400d:c04::22b]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C13D41A0448; Mon,  2 Jun 2014 14:25:25 -0700 (PDT)
Received: by mail-qg0-f43.google.com with SMTP id 63so11678976qgz.16 for <multiple recipients>; Mon, 02 Jun 2014 14:25:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:from:date:message-id:subject:to:content-type;  bh=ifc31pWHiNpUrZ2TbSlxrC5pe2D+fhPHe1fHtJ72CsE=; b=F4utkPDjHz67vM/UIXfiGC8+MQ3sX3FOzOa8cP5v7wW4/QeROd1wnTanGkZyvDMFGZ lB72SIpdofUCXB7RwNmX7Oz1vmXEB17sj4SBJznhxa6BCCOs3nQb/HvcpYWSoBt8+lQc 5BidtCWZHrHTw1fc9k+nmQSi3lacxjw//Y98PKz1SM5X0D3igkcSjZXejZUD+yWKQISV mw0Odak3S7pU4AG+4m+853VzTWytktaz+NVH0sk4e6rfMvvDmavH1Uh5rCceoC5VuXmP oUu1X7yM9KWOHPQ+mhY+OiJBJAqkT0m6DKCE/T8u2kK8yIG7cAjMxtbmyOud5pU+m57G rA9A==
X-Received: by 10.229.79.2 with SMTP id n2mr53130976qck.11.1401744319805; Mon, 02 Jun 2014 14:25:19 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.140.97.34 with HTTP; Mon, 2 Jun 2014 14:24:59 -0700 (PDT)
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Mon, 2 Jun 2014 14:24:59 -0700
X-Google-Sender-Auth: ACdsvujYzXwWmj6IKysQg__c1Bg
Message-ID: <CADJ9OA8P_jeWY-JN2iq+ut-mFmNWbsyVz1MOi_tCZ0U-j3QanA@mail.gmail.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Content-Type: multipart/alternative; boundary=001a1133a1a03f9c3304fae108fe
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/lzKPrEj8YR5vn3DqyLtvESTa6gc
Subject: [6tisch-security] Minutes security discussion 02 June 2014
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Jun 2014 21:25:28 -0000

--001a1133a1a03f9c3304fae108fe
Content-Type: text/plain; charset=UTF-8

All,

You will find the minutes of the last security discussion at
https://bitbucket.org/6tisch/meetings/wiki/140602_webex_security, also
copy-pasted below.

Please fix anything we might have missed directly in the e-mail and reply
to both 6tisch and 6tisch-security MLs.

Thomas

---

Minutes Webex 02 June May 2014, 6TiSCH Security Design Team

Note: timestamps in PDT.
Taking notes *(using Etherpad)*

   1. Thomas Watteyne
   2. Pascal Thubert

Present *(alphabetically)*

   1. Jonathan Simon
   2. Hank Mauldin
   3. Michael Richardson
   4. Pascal Thubert
   5. Pat Kinney
   6. Rene Struik
   7. Subir Das
   8. Thomas Watteyne
   9. Max Pritikin

Recordings

   - Webex recording (first half, TOC discussion)
   <https://cisco.webex.com/ciscosales/lsr.php?RCID=ecf63d701da3482b80841dd6c8285171>
    *[36min]*
   - Webex recording (second half, WirelessHART security)
   <https://cisco.webex.com/ciscosales/lsr.php?RCID=a29b09eed4b242da962cc6f9017404a0>
    *[22min]*

Slides

   - 140602_webex_sec.pdf
   <https://bitbucket.org/6tisch/meetings/src/master/140602_webex_sec/140602_webex_sec.pdf>:
   slides shared during the call

Agenda

   1. table of contents for protocol documents
   2. WirelessHART-like flow.

TOC outline

'''As outlined during the call'''

   - security requirements
      - threat model
      - implementation cost, etc. (storage of security material,
      computational cost)
      - denial of service and other communication impacts of security
      protocol mechanisms
   - protocol requirements/constraints/assumptions
      - dependencies on centralized or external functionality, inline and
      offline
   - time sequence diagram
   - explanation of each step
   - size of each "packet", and number of frames needed to contain it.
   - resulting security properties obtained from this process
   - deployment scenarios underlying protocol requirements
   - device identification
      - PCE/Proxy vs Node identification
      - Time source authentication / time validation
      - Note: RPL Root authentication is a chartered item
      - description of certificate contents
      - privacy aspects
   - slotframes to be used during join
      - how is this communicated in the (enhanced) beacon?
   - configuration aspects
      - allocation of slotframes after join
      - network statistics
      - neighbor reports
      - etc
   - authorization aspects + lifecycle (key management, trust management)
      - how to distinguish a proxy/PCE from an end node
      - security considerations: what prevents a node from transmitting
      when it is not its turn (two parts: jamming, successfully communicating
      outside of assigned schedule, see below)
      - can a node successfully communicate with a peer at a time when not
      supposed to, may be tied to link layer security, or will it be policed by
      receiver?
   - security architecture and fit of e.g. join protocol and provisioning
   into this
   - posture Maintenance (SACM related work)

Minutes

   - [07.08] *[Michael]* let's work on TOC first. Look at Etherpad.
      - *[All]* collaborate on TOC through Etherpad

      The resulting TOC is copy-pasted above

      - *[Rene]* let's not forget a discussion about the resulting security
      obtained
      - *[Max]* would that be the same as the regular "security
      considerations" section in an I-D*
      - *[Rene]* different, lists what security you receive
      - *[Max]* ok
      - *[Rene]* difference between security properties and requirements
      - *[Michael]* OK, let's add it
      - *[Rene]* what is the goal?
      - *[Michael]* goal is join protocol to have exchange of schedule,
      optionally involving a PCE
      - *[Rene]* we need a sections which highlights interaction with 4e
      standard.
      - *[Michael]* this document will become part of architecture, so
      probably not needed?
      - *[Rene]* disagree, will need to contains elements such as what we
      put in the EB, what cells are used during joining, etc
      - *[Rene]* afraid we create a protocol disconnected from MAC. We need
      to consider the details.
      - *[Michael]* if we have running code by independent people, then
      document is done?
      - *[Subir]* clarification question: what should we add to the TOC?
      security architecture?
      - *[Rene]* main concern is that we force TLS without details. We need
      details in a document. For example: how do you define a schedule that
      joining mote can talk with neighbor. Maybe not question to other, but we
      need that to come up with a solution. I'm fine with bullet points, but
      maybe we should discuss issues one-by-one.
      - *[Michael]* other missing pieces?
      - *[Pascal]* about architecture, do you want to see flows, e.g.
      6LoWPAN/RPL flows? Would make easier or more complex?
      - *[Max]* missing point: how is the PCE domain identified. Because we
      have identified the question of how a joining node identifies the network
      - *[Michael]* also added description of exact certificate contents
      - *[Max]* sure
      - *[Subir]* uoes it make sense to add sub-model of thread model.
      - *[Michael]* what about under security model
      - *[Subir]* agree
      - *[Michael]* Pascal, can you comment on SACM section?
      - *[Pascal]* idea behind SACM is maintaining something within a
      device such as the level of a database, or core certificate being used,
      level of software. For embedded devices, time will pass and root
cert will
      have to be update. We need to discuss the life of the device,
including the
      maintenance that will need to be done. Nancy can help here.
      - *[Michael]* let's do a round table: more information to put in TOC?
      - *[Michael]* what about authorization aspects?
      - *[Rene]* outcome is that the new device gets a schedule pushed to
      it. During the join process, the node will use slots and frames,
we need to
      understand which ones.
      - *[Jonathan]* that would be part of the EB.
      - *[Max]* what prevents a node from transmitting during a timeslot
      that's not being transmitted to them? does authorization cover that?
      - *[Michael]* AFAICT, there is nothing that prevents a node from
      transmitting whenever it wants. I can imagine someone winning a benchmark
      test by doing this in a bad way.
      - *[Jonathan]* broken down in two parts:
         - can I successfully communicate with a neighbor (the security
         considerations for this case are related to link-layer keying)
         - can I transmit whenever I want. The underlying 4e mechanisms
         assumes underlying MAC has a schedule
      - *[Michael]* if we have per-node link pair keying, nodes could
      police who they receive from
      - *[Michael]* lets write the policing point down
      - *[Michael]* anything else?

      No updates from call, *[Michael]* saves copy.

      - *[Subir]* Pascal added a points about root authentication. Should
      that be under device identification?
      - *[Pascal]* in terms of flow, it will be the same flow, will need to
      be merged into TOC. That is part of the charter.
      - *[Pascal]* suggestion about presentation, will need to leave.
      Thomas, can you make the recording?
      - *[Thomas]* starts local recording
   - [07.40] WirelessHART joining flows (*[Jonathan]*)
      - *[Jonathan]*
         - I tried to capture WirelessHART "security handshake".
         WirelessHART uses a well-known key at the link layer for
"beacons". Note
         that they are, strictly speaking, a HART MAC layer frame
type, not same
         format as IEEE802.15.4e EB.
         - a device that's already in the network beacons the presence of
         the network. A joining node hears that and gets information
about time base
         in network, current ASN (used as frame counter in L2
security), information
         on slotframe and timeslot it can use to send/receive to/from
the proxy.
         - New nodes encrypt a "join request" packets that contains
         HART-specific information and the devices it has heard (short
address and
         some signal level info), also a hop rank information which is
received from
         the beacon (used by the joining device to pick a proxy device). This
         joining information is encrypted. Destination is always the
manager. Uses
         incrementing counter as nonce when securing joining message
(counter never
         supposed to roll back). Message does not contain any routing
information,
         proxy routes it on behalf of joining mote, and sends it to the manager
         - manager sends back a runtime key, the starting nonce, a manager
         secure session, the device's short address. WirelessHART does not use
         legacy IEEE802.15.4 association procedure to assign 16-bit addresses.
         - at that point, the device has completed the security handshake.
         The manager switches to the assigned sessions for additional
configuration:
         transport sessions, links to neighbor nodes, routing information, and
         network grooming and maintenance tasks. It the session that
was configured.
         - mote ends up with 2 end-to-end sessions: one to the manager, one
         to the gateway. The gateway is the data sink for the network. The
         underlying WirelessHART frame is laid on top of 15.4. THe IEEE802.15.4
         frame is unencrypted and un-authenticated, WirelessHART wraps a CCM*
         security model on top.
      - *[Thomas]* questions?
      - *[Michael]* the join request/response is proxied, I understand.
      What about the addition configuration information, does it go through the
      proxy as well?
      - *[Jonathan]* It's the end-to-end transport session that encrypts
      that information. For the most part, that sessions is sent
though the proxy
      first. The device gets its initial security handshake through the proxy,
      then initial configuration through the proxy, then additional
configuration
      through a number of neighbors. You are correct: additional information is
      an end-to-end secured message between joining device and PCE. Proxy only
      does routing for the first steps.
      - *[Michael]* So the proxy doesn't know that the joining node is
      sending a join request?
      - *[Jonathan]* in general, this is true. But the proxy could know
      that it's a join request because it is coming through links that are
      advertised through its enhanced beacon. Also, joining device
uses its long
      address until its short one is configured by manager. That being
said, the
      proxy can be agnostic and just forward the information to the manager.
      - *[Michael]* suggest to change arrow in step 4. All arrows in/out of
      proxy are the same, in the last step, the arrow could go
straight from PCE
      to joining mote.
      - *[Jonathan]* in step 2&3 routing might be a little different. This
      is a first draft, any opportunity for clarification welcome.
      - *[Michael]* is the joining node aware of the address of the PCE?
      - *[Jonathan]* in WirelessHART, PCE has well-known address. At the
      network layer, the joining devices addresses its packets directly to the
      PCE. This might be different for 6TiSCH.
      - *[Subir]* About beacon authentication through WKK. Are the join
      request/response authenticated with the same key?
      - *[Jonathan]* in WirelessHART, there are two elements:
         - link-layer authentication
         - end-to-end authentication and encryption.
      - *[Jonathan]* Frames are authenticated at L2. Different keys for
      end-to-end authentication/encryption.
      - *[Max]* L2 authentication of the EB, what key is used?
      - *[Jonathan]* A WKK written in standard.
      - *[Max]* So not real L2 authentication?
      - *[Jonathan]* It does goes through the MIC authentication process on
      the device, allows some level of protection against receiving
other traffic
      from other networks.
      - *[Max]* probably not a security check, then?
      - *[Michael]* the rational is to prevent interaction with other
      non-WirelessHART technologies. Make sure that this traffic would not
      distract.
      - *[Jonathan]* Agreed. As an example, in the early days, ZigBee did
      not use link-layer authentication, which caused demos to break
when in same
      radio space as WirelessHART networks.
      - *[Max]* so technical value, but no real security
      - *[Jonathan]* Agreed
      - *[Max]* we are hence using the term authentication but protocol
      stability, not security
      - *[Jonathan]* Agreed
      - *[Subir]* About the PSK with manager and gateway, are those
      different keys?
      - *[Jonathan]* About end-to-end in WirelessHART, the PCE and the
      joining nodes share a PSK. WirelessHART specification does not
indicate how
      this gets configured. Example include OOB, configuration during
      commissioning. This key is used to encrypt the end-to-end join
message. In
      the join response, the PCE sets session keys for subsequent
communication.
      - *[Jonathan]* May contrast with what we would do with 6TiSCH.
      - *[Subir]* When PSK configured at manufacturing, is there a lifetime
      associated?
      - *[Jonathan]* typically devices can come pre-configured with key
      specific to a vendor. Devices should have a mechanism to update
those PSKs.
      This process is not touch-less.
   - *[Thomas]* we are over time.
   - *[Michael]* good spot to stop, let's resume with slide 3 ("Wireless
   HART-like PK Flow") next week.

--001a1133a1a03f9c3304fae108fe
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>All,</div><div><br></div><div>You will find the minut=
es of the last security discussion at <a href=3D"https://bitbucket.org/6tis=
ch/meetings/wiki/140602_webex_security">https://bitbucket.org/6tisch/meetin=
gs/wiki/140602_webex_security</a>, also copy-pasted below.</div>

<div><br></div><div>Please fix anything we might have missed directly in th=
e e-mail and reply to both 6tisch and 6tisch-security MLs.</div><div><br></=
div><div>Thomas</div><div><br></div><div>---</div><div><br></div><div>
<h1 id=3D"markdown-header-minutes-webex-02-june-may-2014-6tisch-security-de=
sign-team" style=3D"margin:0px 0px 10px;padding:0px;font-size:24px;font-wei=
ght:normal;line-height:1.25;color:rgb(51,51,51);font-family:Arial,sans-seri=
f">

Minutes Webex 02 June May 2014, 6TiSCH Security Design Team</h1><p style=3D=
"margin:10px 0px 0px;padding:0px;word-wrap:break-word;color:rgb(51,51,51);f=
ont-family:Arial,sans-serif;font-size:14px;line-height:20px">Note: timestam=
ps in PDT.</p>

<h2 id=3D"markdown-header-taking-notes-using-etherpad" style=3D"margin:20px=
 0px 0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;colo=
r:rgb(51,51,51);font-family:Arial,sans-serif">Taking notes=C2=A0<em>(using =
Etherpad)</em></h2>

<ol style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;line-height:20px"><li style=3D"word-wrap:break-word">=
Thomas Watteyne</li><li style=3D"word-wrap:break-word">Pascal Thubert</li><=
/ol>

<h2 id=3D"markdown-header-present-alphabetically" style=3D"margin:20px 0px =
0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb=
(51,51,51);font-family:Arial,sans-serif">Present=C2=A0<em>(alphabetically)<=
/em></h2>

<ol style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;line-height:20px"><li style=3D"word-wrap:break-word">=
Jonathan Simon</li><li style=3D"word-wrap:break-word">Hank Mauldin</li><li =
style=3D"word-wrap:break-word">

Michael Richardson</li><li style=3D"word-wrap:break-word">Pascal Thubert</l=
i><li style=3D"word-wrap:break-word">Pat Kinney</li><li style=3D"word-wrap:=
break-word">Rene Struik</li><li style=3D"word-wrap:break-word">Subir Das</l=
i><li style=3D"word-wrap:break-word">

Thomas Watteyne</li><li style=3D"word-wrap:break-word">Max Pritikin</li></o=
l><h2 id=3D"markdown-header-recordings" style=3D"margin:20px 0px 0px;paddin=
g:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51)=
;font-family:Arial,sans-serif">

Recordings</h2><ul style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-fa=
mily:Arial,sans-serif;font-size:14px;line-height:20px"><li style=3D"word-wr=
ap:break-word"><a href=3D"https://cisco.webex.com/ciscosales/lsr.php?RCID=
=3Decf63d701da3482b80841dd6c8285171" style=3D"color:rgb(59,115,175);text-de=
coration:none">Webex recording (first half, TOC discussion)</a>=C2=A0<em>[3=
6min]</em></li>

<li style=3D"word-wrap:break-word"><a href=3D"https://cisco.webex.com/cisco=
sales/lsr.php?RCID=3Da29b09eed4b242da962cc6f9017404a0" style=3D"color:rgb(5=
9,115,175);text-decoration:none">Webex recording (second half, WirelessHART=
 security)</a>=C2=A0<em>[22min]</em></li>

</ul><h2 id=3D"markdown-header-slides" style=3D"margin:20px 0px 0px;padding=
:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);=
font-family:Arial,sans-serif">Slides</h2><ul style=3D"margin:10px 0px 0px;c=
olor:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:=
20px">

<li style=3D"word-wrap:break-word"><a href=3D"https://bitbucket.org/6tisch/=
meetings/src/master/140602_webex_sec/140602_webex_sec.pdf" style=3D"color:r=
gb(59,115,175);text-decoration:none">140602_webex_sec.pdf</a>: slides share=
d during the call</li>

</ul><h2 id=3D"markdown-header-agenda" style=3D"margin:20px 0px 0px;padding=
:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);=
font-family:Arial,sans-serif">Agenda</h2><ol style=3D"margin:10px 0px 0px;c=
olor:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:=
20px">

<li style=3D"word-wrap:break-word">table of contents for protocol documents=
</li><li style=3D"word-wrap:break-word">WirelessHART-like flow.</li></ol><h=
2 id=3D"markdown-header-toc-outline" style=3D"margin:20px 0px 0px;padding:0=
px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);fo=
nt-family:Arial,sans-serif">

TOC outline</h2><p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break=
-word;color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-=
height:20px">&#39;&#39;&#39;As outlined during the call&#39;&#39;&#39;</p>

<ul style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;line-height:20px"><li style=3D"word-wrap:break-word">=
security requirements<ul style=3D"margin:0px"><li style=3D"word-wrap:break-=
word">

threat model</li><li style=3D"word-wrap:break-word">implementation cost, et=
c. (storage of security material, computational cost)</li><li style=3D"word=
-wrap:break-word">denial of service and other communication impacts of secu=
rity protocol mechanisms</li>

</ul></li><li style=3D"word-wrap:break-word">protocol requirements/constrai=
nts/assumptions<ul style=3D"margin:0px"><li style=3D"word-wrap:break-word">=
dependencies on centralized or external functionality, inline and offline</=
li>

</ul></li><li style=3D"word-wrap:break-word">time sequence diagram</li><li =
style=3D"word-wrap:break-word">explanation of each step</li><li style=3D"wo=
rd-wrap:break-word">size of each &quot;packet&quot;, and number of frames n=
eeded to contain it.</li>

<li style=3D"word-wrap:break-word">resulting security properties obtained f=
rom this process</li><li style=3D"word-wrap:break-word">deployment scenario=
s underlying protocol requirements</li><li style=3D"word-wrap:break-word">d=
evice identification<ul style=3D"margin:0px">

<li style=3D"word-wrap:break-word">PCE/Proxy vs Node identification</li><li=
 style=3D"word-wrap:break-word">Time source authentication / time validatio=
n</li><li style=3D"word-wrap:break-word">Note: RPL Root authentication is a=
 chartered item</li>

<li style=3D"word-wrap:break-word">description of certificate contents</li>=
<li style=3D"word-wrap:break-word">privacy aspects</li></ul></li><li style=
=3D"word-wrap:break-word">slotframes to be used during join<ul style=3D"mar=
gin:0px">

<li style=3D"word-wrap:break-word">how is this communicated in the (enhance=
d) beacon?</li></ul></li><li style=3D"word-wrap:break-word">configuration a=
spects<ul style=3D"margin:0px"><li style=3D"word-wrap:break-word">allocatio=
n of slotframes after join</li>

<li style=3D"word-wrap:break-word">network statistics</li><li style=3D"word=
-wrap:break-word">neighbor reports</li><li style=3D"word-wrap:break-word">e=
tc</li></ul></li><li style=3D"word-wrap:break-word">authorization aspects +=
 lifecycle (key management, trust management)<ul style=3D"margin:0px">

<li style=3D"word-wrap:break-word">how to distinguish a proxy/PCE from an e=
nd node</li><li style=3D"word-wrap:break-word">security considerations: wha=
t prevents a node from transmitting when it is not its turn (two parts: jam=
ming, successfully communicating outside of assigned schedule, see below)</=
li>

<li style=3D"word-wrap:break-word">can a node successfully communicate with=
 a peer at a time when not supposed to, may be tied to link layer security,=
 or will it be policed by receiver?</li></ul></li><li style=3D"word-wrap:br=
eak-word">

security architecture and fit of e.g. join protocol and provisioning into t=
his</li><li style=3D"word-wrap:break-word">posture Maintenance (SACM relate=
d work)</li></ul><h2 id=3D"markdown-header-minutes" style=3D"margin:20px 0p=
x 0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;color:r=
gb(51,51,51);font-family:Arial,sans-serif">

Minutes</h2><ul style=3D"margin:10px 0px 0px;color:rgb(51,51,51);font-famil=
y:Arial,sans-serif;font-size:14px;line-height:20px"><li style=3D"word-wrap:=
break-word">[07.08]=C2=A0<strong>[Michael]</strong>=C2=A0let&#39;s work on =
TOC first. Look at Etherpad.<ul style=3D"margin:10px 0px 0px">

<li style=3D"word-wrap:break-word"><strong>[All]</strong>=C2=A0collaborate =
on TOC through Etherpad<blockquote style=3D"margin:10px 0px 0px 19px;border=
-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);=
color:rgb(112,112,112);padding:10px 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word">The resulting TOC =
is copy-pasted above</p></blockquote></li><li style=3D"word-wrap:break-word=
"><strong>[Rene]</strong>=C2=A0let&#39;s not forget a discussion about the =
resulting security obtained</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0would that b=
e the same as the regular &quot;security considerations&quot; section in an=
 I-D*</li><li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0d=
ifferent, lists what security you receive</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0ok</li><li s=
tyle=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0difference betwe=
en security properties and requirements</li><li style=3D"word-wrap:break-wo=
rd"><strong>[Michael]</strong>=C2=A0OK, let&#39;s add it</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0what is the=
 goal?</li><li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=
=A0goal is join protocol to have exchange of schedule, optionally involving=
 a PCE</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0we need a s=
ections which highlights interaction with 4e standard.</li><li style=3D"wor=
d-wrap:break-word"><strong>[Michael]</strong>=C2=A0this document will becom=
e part of architecture, so probably not needed?</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0disagree, w=
ill need to contains elements such as what we put in the EB, what cells are=
 used during joining, etc</li><li style=3D"word-wrap:break-word"><strong>[R=
ene]</strong>=C2=A0afraid we create a protocol disconnected from MAC. We ne=
ed to consider the details.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0if we ha=
ve running code by independent people, then document is done?</li><li style=
=3D"word-wrap:break-word"><strong>[Subir]</strong>=C2=A0clarification quest=
ion: what should we add to the TOC? security architecture?</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0main concer=
n is that we force TLS without details. We need details in a document. For =
example: how do you define a schedule that joining mote can talk with neigh=
bor. Maybe not question to other, but we need that to come up with a soluti=
on. I&#39;m fine with bullet points, but maybe we should discuss issues one=
-by-one.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0other mi=
ssing pieces?</li><li style=3D"word-wrap:break-word"><strong>[Pascal]</stro=
ng>=C2=A0about architecture, do you want to see flows, e.g. 6LoWPAN/RPL flo=
ws? Would make easier or more complex?</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0missing poin=
t: how is the PCE domain identified. Because we have identified the questio=
n of how a joining node identifies the network</li><li style=3D"word-wrap:b=
reak-word">

<strong>[Michael]</strong>=C2=A0also added description of exact certificate=
 contents</li><li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=
=A0sure</li><li style=3D"word-wrap:break-word"><strong>[Subir]</strong>=C2=
=A0uoes it make sense to add sub-model of thread model.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0what abo=
ut under security model</li><li style=3D"word-wrap:break-word"><strong>[Sub=
ir]</strong>=C2=A0agree</li><li style=3D"word-wrap:break-word"><strong>[Mic=
hael]</strong>=C2=A0Pascal, can you comment on SACM section?</li>

<li style=3D"word-wrap:break-word"><strong>[Pascal]</strong>=C2=A0idea behi=
nd SACM is maintaining something within a device such as the level of a dat=
abase, or core certificate being used, level of software. For embedded devi=
ces, time will pass and root cert will have to be update. We need to discus=
s the life of the device, including the maintenance that will need to be do=
ne. Nancy can help here.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0let&#39;=
s do a round table: more information to put in TOC?</li><li style=3D"word-w=
rap:break-word"><strong>[Michael]</strong>=C2=A0what about authorization as=
pects?</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0outcome is =
that the new device gets a schedule pushed to it. During the join process, =
the node will use slots and frames, we need to understand which ones.</li><=
li style=3D"word-wrap:break-word">

<strong>[Jonathan]</strong>=C2=A0that would be part of the EB.</li><li styl=
e=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0what prevents a node=
 from transmitting during a timeslot that&#39;s not being transmitted to th=
em? does authorization cover that?</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0AFAICT, =
there is nothing that prevents a node from transmitting whenever it wants. =
I can imagine someone winning a benchmark test by doing this in a bad way.<=
/li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0broken =
down in two parts:<ul style=3D"margin:10px 0px 0px"><li style=3D"word-wrap:=
break-word">can I successfully communicate with a neighbor (the security co=
nsiderations for this case are related to link-layer keying)</li>

<li style=3D"word-wrap:break-word">can I transmit whenever I want. The unde=
rlying 4e mechanisms assumes underlying MAC has a schedule</li></ul></li><l=
i style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0if we have=
 per-node link pair keying, nodes could police who they receive from</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0lets wri=
te the policing point down</li><li style=3D"word-wrap:break-word"><strong>[=
Michael]</strong>=C2=A0anything else?<blockquote style=3D"margin:10px 0px 0=
px 19px;border-left-width:1px;border-left-style:solid;border-left-color:rgb=
(204,204,204);color:rgb(112,112,112);padding:10px 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word">No updates from ca=
ll,=C2=A0<strong>[Michael]</strong>=C2=A0saves copy.</p></blockquote></li><=
li style=3D"word-wrap:break-word"><strong>[Subir]</strong>=C2=A0Pascal adde=
d a points about root authentication. Should that be under device identific=
ation?</li>

<li style=3D"word-wrap:break-word"><strong>[Pascal]</strong>=C2=A0in terms =
of flow, it will be the same flow, will need to be merged into TOC. That is=
 part of the charter.</li><li style=3D"word-wrap:break-word"><strong>[Pasca=
l]</strong>=C2=A0suggestion about presentation, will need to leave. Thomas,=
 can you make the recording?</li>

<li style=3D"word-wrap:break-word"><strong>[Thomas]</strong>=C2=A0starts lo=
cal recording</li></ul></li><li style=3D"word-wrap:break-word">[07.40] Wire=
lessHART joining flows (<strong>[Jonathan]</strong>)<ul style=3D"margin:10p=
x 0px 0px">

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong><ul style=3D"=
margin:10px 0px 0px"><li style=3D"word-wrap:break-word">I tried to capture =
WirelessHART &quot;security handshake&quot;. WirelessHART uses a well-known=
 key at the link layer for &quot;beacons&quot;. Note that they are, strictl=
y speaking, a HART MAC layer frame type, not same format as IEEE802.15.4e E=
B.</li>

<li style=3D"word-wrap:break-word">a device that&#39;s already in the netwo=
rk beacons the presence of the network. A joining node hears that and gets =
information about time base in network, current ASN (used as frame counter =
in L2 security), information on slotframe and timeslot it can use to send/r=
eceive to/from the proxy.</li>

<li style=3D"word-wrap:break-word">New nodes encrypt a &quot;join request&q=
uot; packets that contains HART-specific information and the devices it has=
 heard (short address and some signal level info), also a hop rank informat=
ion which is received from the beacon (used by the joining device to pick a=
 proxy device). This joining information is encrypted. Destination is alway=
s the manager. Uses incrementing counter as nonce when securing joining mes=
sage (counter never supposed to roll back). Message does not contain any ro=
uting information, proxy routes it on behalf of joining mote, and sends it =
to the manager</li>

<li style=3D"word-wrap:break-word">manager sends back a runtime key, the st=
arting nonce, a manager secure session, the device&#39;s short address. Wir=
elessHART does not use legacy IEEE802.15.4 association procedure to assign =
16-bit addresses.</li>

<li style=3D"word-wrap:break-word">at that point, the device has completed =
the security handshake. The manager switches to the assigned sessions for a=
dditional configuration: transport sessions, links to neighbor nodes, routi=
ng information, and network grooming and maintenance tasks. It the session =
that was configured.</li>

<li style=3D"word-wrap:break-word">mote ends up with 2 end-to-end sessions:=
 one to the manager, one to the gateway. The gateway is the data sink for t=
he network. The underlying WirelessHART frame is laid on top of 15.4. THe I=
EEE802.15.4 frame is unencrypted and un-authenticated, WirelessHART wraps a=
 CCM* security model on top.</li>

</ul></li><li style=3D"word-wrap:break-word"><strong>[Thomas]</strong>=C2=
=A0questions?</li><li style=3D"word-wrap:break-word"><strong>[Michael]</str=
ong>=C2=A0the join request/response is proxied, I understand. What about th=
e addition configuration information, does it go through the proxy as well?=
</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0It&#39;=
s the end-to-end transport session that encrypts that information. For the =
most part, that sessions is sent though the proxy first. The device gets it=
s initial security handshake through the proxy, then initial configuration =
through the proxy, then additional configuration through a number of neighb=
ors. You are correct: additional information is an end-to-end secured messa=
ge between joining device and PCE. Proxy only does routing for the first st=
eps.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0So the p=
roxy doesn&#39;t know that the joining node is sending a join request?</li>=
<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0in gene=
ral, this is true. But the proxy could know that it&#39;s a join request be=
cause it is coming through links that are advertised through its enhanced b=
eacon. Also, joining device uses its long address until its short one is co=
nfigured by manager. That being said, the proxy can be agnostic and just fo=
rward the information to the manager.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0suggest =
to change arrow in step 4. All arrows in/out of proxy are the same, in the =
last step, the arrow could go straight from PCE to joining mote.</li><li st=
yle=3D"word-wrap:break-word">

<strong>[Jonathan]</strong>=C2=A0in step 2&amp;3 routing might be a little =
different. This is a first draft, any opportunity for clarification welcome=
.</li><li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0is=
 the joining node aware of the address of the PCE?</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0in Wire=
lessHART, PCE has well-known address. At the network layer, the joining dev=
ices addresses its packets directly to the PCE. This might be different for=
 6TiSCH.</li>

<li style=3D"word-wrap:break-word"><strong>[Subir]</strong>=C2=A0About beac=
on authentication through WKK. Are the join request/response authenticated =
with the same key?</li><li style=3D"word-wrap:break-word"><strong>[Jonathan=
]</strong>=C2=A0in WirelessHART, there are two elements:<ul style=3D"margin=
:10px 0px 0px">

<li style=3D"word-wrap:break-word">link-layer authentication</li><li style=
=3D"word-wrap:break-word">end-to-end authentication and encryption.</li></u=
l></li><li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0=
Frames are authenticated at L2. Different keys for end-to-end authenticatio=
n/encryption.</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0L2 authentic=
ation of the EB, what key is used?</li><li style=3D"word-wrap:break-word"><=
strong>[Jonathan]</strong>=C2=A0A WKK written in standard.</li><li style=3D=
"word-wrap:break-word">

<strong>[Max]</strong>=C2=A0So not real L2 authentication?</li><li style=3D=
"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0It does goes throug=
h the MIC authentication process on the device, allows some level of protec=
tion against receiving other traffic from other networks.</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0probably not=
 a security check, then?</li><li style=3D"word-wrap:break-word"><strong>[Mi=
chael]</strong>=C2=A0the rational is to prevent interaction with other non-=
WirelessHART technologies. Make sure that this traffic would not distract.<=
/li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0Agreed.=
 As an example, in the early days, ZigBee did not use link-layer authentica=
tion, which caused demos to break when in same radio space as WirelessHART =
networks.</li>

<li style=3D"word-wrap:break-word"><strong>[Max]</strong>=C2=A0so technical=
 value, but no real security</li><li style=3D"word-wrap:break-word"><strong=
>[Jonathan]</strong>=C2=A0Agreed</li><li style=3D"word-wrap:break-word"><st=
rong>[Max]</strong>=C2=A0we are hence using the term authentication but pro=
tocol stability, not security</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0Agreed<=
/li><li style=3D"word-wrap:break-word"><strong>[Subir]</strong>=C2=A0About =
the PSK with manager and gateway, are those different keys?</li><li style=
=3D"word-wrap:break-word">

<strong>[Jonathan]</strong>=C2=A0About end-to-end in WirelessHART, the PCE =
and the joining nodes share a PSK. WirelessHART specification does not indi=
cate how this gets configured. Example include OOB, configuration during co=
mmissioning. This key is used to encrypt the end-to-end join message. In th=
e join response, the PCE sets session keys for subsequent communication.</l=
i>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0May con=
trast with what we would do with 6TiSCH.</li><li style=3D"word-wrap:break-w=
ord"><strong>[Subir]</strong>=C2=A0When PSK configured at manufacturing, is=
 there a lifetime associated?</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0typical=
ly devices can come pre-configured with key specific to a vendor. Devices s=
hould have a mechanism to update those PSKs. This process is not touch-less=
.</li>

</ul></li><li style=3D"word-wrap:break-word"><strong>[Thomas]</strong>=C2=
=A0we are over time.</li><li style=3D"word-wrap:break-word"><strong>[Michae=
l]</strong>=C2=A0good spot to stop, let&#39;s resume with slide 3 (&quot;Wi=
reless HART-like PK Flow&quot;) next week.</li>

</ul></div></div>

--001a1133a1a03f9c3304fae108fe--


From nobody Tue Jun  3 08:58:28 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 86F8D1A02F6 for <6tisch-security@ietfa.amsl.com>; Tue,  3 Jun 2014 08:58:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1sgge3JP4itV for <6tisch-security@ietfa.amsl.com>; Tue,  3 Jun 2014 08:58:11 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8AEEA1A0303 for <6tisch-security@ietf.org>; Tue,  3 Jun 2014 08:58:11 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id A832F20029 for <6tisch-security@ietf.org>; Tue,  3 Jun 2014 12:01:12 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id A21DE63B0E; Tue,  3 Jun 2014 11:58:04 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 8D3D563AED for <6tisch-security@ietf.org>; Tue,  3 Jun 2014 11:58:04 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 03 Jun 2014 11:58:04 -0400
Message-ID: <6321.1401811084@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/7Khgz7_4pL3Bn_lJpBDmJezgNo8
Subject: [6tisch-security] table of contents discussion and draft
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Jun 2014 15:58:18 -0000

--=-=-=


http://datatracker.ietf.org/doc/draft-richardson-6tisch-table-of-contents/

I'm posting the table of contents from it, there is little else.
The XML is on the bitbucket account at:
  https://bitbucket.org/6tisch/draft-richardson-6tisch-security-architecture/src/75d6a58349d396e77ab4620f2d2c4838a92ccd90/6tisch-table-of-contents/draft-richardson-6tisch-table-of-contents.xml?at=dooku

Table of Contents

   1.  security requirements . . . . . . . . . . . . . . . . . . . .   2
     1.1.  thread model  . . . . . . . . . . . . . . . . . . . . . .   2
     1.2.  implementation cost . . . . . . . . . . . . . . . . . . .   2
     1.3.  denial of service . . . . . . . . . . . . . . . . . . . .   2
   2.  protocol requirements/constraints/assumptions . . . . . . . .   2
     2.1.  inline/offline  . . . . . . . . . . . . . . . . . . . . .   2
   3.  time sequence diagram . . . . . . . . . . . . . . . . . . . .   3
     3.1.  explanation of each step  . . . . . . . . . . . . . . . .   3
     3.2.  size of each packet . . . . . . . . . . . . . . . . . . .   3
   4.  resulting security properties obtained from this process  . .   3
   5.  deployment scenarios underlying protocol requirements . . . .   3
   6.  device identification . . . . . . . . . . . . . . . . . . . .   3
     6.1.  PCE/Proxy vs Node identification  . . . . . . . . . . . .   3
     6.2.  Time source authentication / time validation  . . . . . .   3
     6.3.  description of certificate contents . . . . . . . . . . .   3
     6.4.  privacy aspects . . . . . . . . . . . . . . . . . . . . .   3
   7.  slotframes to be used during join . . . . . . . . . . . . . .   3
   8.  configuration aspects . . . . . . . . . . . . . . . . . . . .   3
   9.  authorization aspects . . . . . . . . . . . . . . . . . . . .   3
     9.1.  how to determine a proxy/PCE from a end node  . . . . . .   3
     9.2.  security considerations . . . . . . . . . . . . . . . . .   3
   10. security architecture . . . . . . . . . . . . . . . . . . . .   4
   11. Posture Maintenance . . . . . . . . . . . . . . . . . . . . .   4
   12. Security Considerations . . . . . . . . . . . . . . . . . . .   4
   13. Other Related Protocols . . . . . . . . . . . . . . . . . . .   4
   14. IANA Considerations . . . . . . . . . . . . . . . . . . . . .   4
   15. Acknowledgements  . . . . . . . . . . . . . . . . . . . . . .   4
   16. Normative references  . . . . . . . . . . . . . . . . . . . .   4
   Author's Address  . . . . . . . . . . . . . . . . . . . . . . . .   4


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU43wiYCLcPvd0N1lAQLmywf/fgXprh3IIOYRIFK80h9n9ruvkAzZb1Ah
FO0f5T12zJTLprGG6qw7FKqeD0UUxWfUbGTb7T4Z5EUUaBl5SsOWmVLOiY4nsJJt
bFZnWWM+2R+OMDM2OpS345xh0XIvyRIsOGRVABtAl7PqpDj5v1xwblsO4MSlN1Tx
/gqKf7wOFudHCLXmlW9csqaNmvYIRxIBxIGfQziytL9fBm9YKrZPhzU8RsYk/E63
GZbFybZl7rmlmPZG0ONS7YR0UXW7oO74ulvhjFAyBXTOvl7YSxCgB5EcWYrYtBD5
y6tm++9Y+zBgR0dorlKYjHJsMr1+KptbVmGw+eK2w1ZXXKKVsH05DA==
=HSZJ
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun Jun  8 17:55:28 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE5851B2797 for <6tisch-security@ietfa.amsl.com>; Sun,  8 Jun 2014 17:55:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0MZJRmfs4pMd for <6tisch-security@ietfa.amsl.com>; Sun,  8 Jun 2014 17:55:22 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56C291B2793 for <6tisch-security@ietf.org>; Sun,  8 Jun 2014 17:55:22 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id EE2B720011 for <6tisch-security@ietf.org>; Sun,  8 Jun 2014 20:58:45 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 8EE8F63B0E; Sun,  8 Jun 2014 20:55:19 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 7889B63B0B for <6tisch-security@ietf.org>; Sun,  8 Jun 2014 20:55:19 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <26563.1401303435@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 08 Jun 2014 20:55:19 -0400
Message-ID: <27727.1402275319@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/KhQFwiKvbbJXaQG6deLM4qqHUhc
Subject: [6tisch-security] agenda for 2014-06-09 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Jun 2014 00:55:26 -0000

--=-=-=


To remind; we will continue with the slides that Jonathan Simon posted 10
days ago, which are also at:
  http://www.ietf.org/mail-archive/web/6tisch-security/current/pdfiZJLN6CKg0.pdf

-- The URL to access the webex, which will we use for audio only:
  https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

-- we will use with the etherpad at:
  https://etherpad.mozilla.org/ras5RGrQLA

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU5UF94CLcPvd0N1lAQIa0wf/fmixgMYBfyXFDpiH28jr8bIUbfnkk7lV
2GPo8f/ZGbLaB6zYw80zc6U6ATuCwucGdASZHLloXcFcC36+gAKtDH71MzdeCgIE
Cik7LCfW/TkDBaZ7huB1ySxFtIWGLS90qfhICFF9eWTg8hbeAWjTBQfEBkatYuEb
/EpD5dYxL+rG7dZjhDJteVpY5AFnmC76kKNwEnXe+oypX5WInKRnN3L1pqmjWj1L
XNsM6gD5Z6odgUWbJQCzSrS4hjy8jIt1spQbDHtXRvosAdt8uQA+A9pS2GBtLcyg
z18LOStHrih2xi40SGi+K31wP9NLLCMyX/LjqNxR4ko7yUddNVQbFg==
=kLmA
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun  9 08:51:14 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FDE21A0270 for <6tisch-security@ietfa.amsl.com>; Mon,  9 Jun 2014 08:51:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.702
X-Spam-Level: 
X-Spam-Status: No, score=0.702 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uk0k6pFZmxuj for <6tisch-security@ietfa.amsl.com>; Mon,  9 Jun 2014 08:51:06 -0700 (PDT)
Received: from mail-ie0-x230.google.com (mail-ie0-x230.google.com [IPv6:2607:f8b0:4001:c03::230]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BBE301A0253 for <6tisch-security@ietf.org>; Mon,  9 Jun 2014 08:51:04 -0700 (PDT)
Received: by mail-ie0-f176.google.com with SMTP id rl12so5708963iec.7 for <6tisch-security@ietf.org>; Mon, 09 Jun 2014 08:51:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=l/SaSMhQ24xCiQYVC1f92qZJS4HNgYbxftq575IcFO0=; b=gNv9pqOZK0c1f0EBpIpCcxvCzduZL1NDcwkhwzCT0PaBYh37tMlpIS4a2eUecKSkB8 6+e8pLaIjlc1HnBfijk0mcupZXsYmhxjZupfnVjs6gY9RnhC9uKfoFpoPqV2dquUgJp1 mz4qSFxpuhJN39+3/QkExR/TFVolx7Qj5YqeSzegQu9J5SpQttOCqA1Hpg4YI8dyPCDA DA5wLsb95RbsWDqZPGwR3GvPQLLM+wvFKZSicu/l6Y9RYXxgIzy2VkU+K9tAbxsCn6XY mpcD5xCQvtlDJqdNzcm9OhJIyaYtszalITXEyxujCbvgUMgFypDDCOI8utap4E3JCR0D xCRw==
X-Received: by 10.51.17.66 with SMTP id gc2mr38573290igd.5.1402329064002; Mon, 09 Jun 2014 08:51:04 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id 2sm57318140igs.17.2014.06.09.08.51.02 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 09 Jun 2014 08:51:03 -0700 (PDT)
Message-ID: <5395D7E4.1010200@gmail.com>
Date: Mon, 09 Jun 2014 11:51:00 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com>
In-Reply-To: <537B5C77.5020800@gmail.com>
Content-Type: multipart/alternative; boundary="------------080705040302060201010908"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/iFrEULuXJWSGNEfE4UDsYcaYvlE
Subject: [6tisch-security] tackling outstanding issues --- (was: Re: (some outstanding issues re join protocol -- personal perspective) Re: agenda for 2014-05-20 6tisch security call)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Jun 2014 15:51:12 -0000

This is a multi-part message in MIME format.
--------------080705040302060201010908
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

Please find below a reminder of the outstanding issues re the join 
protocol, as I originally circulated three weeks ago, prior to our call 
on Tue May 20, 2014. {As an aside, the week before that, on May 12, 
2014, we did discuss the w/HART join process protocol flows (at the 
time, intention was to agree to align flows with that used there, as 
motivated in the same email below).}

While current discussions on w/HART protocol have been somewhat 
interesting, I feel we should put urgent priority on tackling those 
outstanding issues. So far, I have not seen any traffic on these items 
from others, so please weigh-in (please include outstanding item # in 
the subject line, e.g., "outstanding issue #c").

Let us first tackle item #c) below on join process impact on the 
network. I am particularly interested in detailed deliberations on the 
three questions on this item that came to my mind here.

When looking at this topic, I would like to encourage you to read the 
email thread on the IETF DICE list re draft-kumar-dice-dtls-relay-01, 
which is related to relaying nodes and potential DoS attacks. I 
initiated this discussion on May 27th, with last posting on May 30th. 
See http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.

Best regards, Rene

On 5/20/2014 9:45 AM, Rene Struik wrote:
> Hi Michael:
>
> At the previous conf call of May 12, 2014, we discussed message flows 
> of w/HART join process, as also alluded to in my email below (the 
> specs could not be distributed due to copyright restrictions).
>
> In my mind, 6TiSCH protocol can use similar communication flows as 
> w/HART where only non-local communication flows (between joining node 
> and network manager) would be
> i) passing join/authentication information from joining node to 
> network manager (and back);
> ii) passing configuration parms from network manager to joining node 
> (keys, links, frame links) and neighbor report from joined node to 
> network manager.
>
> MAIN OUTSTANDING ISSUES (in my mind):
> a) Packet sizes:
> get more info on packet sizes configuration parms, as w/HART uses. 
> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., Dust 
> Networks have info on packet sizes/structure?; ISA SP100.11a metrics 
> would also help, as would ZigBee 2.0 config parms. Does, e.g., Cisco 
> have useful data points here?
> b) Device Ids:
> With industrial control, network manager would look up "tag name" 
> device in pre-configured database. Details on tag name syntax, how 
> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
> aspects here?
> c) Join process impact on network:
> Pascal Thubert asked "when network would explode with join". Note RS: 
> the following questions come to mind:
> - how does joining  node find a time slot to send first join packet to 
> neighbor node (presumably, this would require listening for Enhanced 
> Beacon, but details on schedule in terms of time and channels seems 
> incomplete [min-schedule suggests 101x15ms slotframe and "less than 
> 10s repeat of EBs, but that leaves lots of dead time and does not 
> suggest a schedule that would create a common time window where two 
> devices would both be awake).
> - how does joining node negotiate a local schedule with neighbor node 
> for execution of join protocol (draft-watteyne-6tisch-tisch-00 refers 
> to local schedule negotiation need, but unclear whether this has been 
> looked into in detail).
> - for local traffic (joining node/neighbor), it seems Pascal Thubert's 
> "exploding network" may not happen easily. Nevertheless, unclear what 
> impact of "join priority flag TSCH 802.15.4e frames is [that seems to 
> have been designed with legacy w/HART in mind (centralized solution). 
> With centralized tree-like solution, lots of traffic happens close to 
> the root, thus potentially amplifying congestion around root node 
> (=network manager?).
> d) crypto protocol details of join protocol:
> Note RS: I can solve this (close to optimal design already done 
> [assuming I can do this "without hands tied behind the back"])
> e) authorization/trust management:
> it is here where binding of ids to public keys via certs and lifecycle 
> aspects play a role, as well as syntax/semantics of authorization 
> messages. Note RS: question is whether ACE could play a role here 
> (current charter discussions seem to be endless, though). As has been 
> brought up before, a potential instantiation of certs would be the use 
> of 802.1ar certs, but this is certainly not the only way of doing things.
>
> There are lots of other things we should consider, outside the join 
> protocol realm.
>
> ------- Original Message --------
> Subject: 	Re: [6tisch-security] agenda(?) for call today
> Date: 	Mon, 12 May 2014 09:53:37 -0400
> From: 	Rene Struik <rstruik.ext@gmail.com>
> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
>
>
>
> Hi Michael et al:
>
> Another topic worth exploring more is the join protocol details.
>
> (There are many other aspects, including certs, as you mentioned, more 
> general security architecture, provisioning, etc., but below only 
> deals with join.)
>
> With w/HART, the join process only interacts with the network manager 
> (62591, Annex A.3, Fig. A.1) for
> -forwarded join from joining node to network manager;
> -passing configuration parms from network manager to joining node 
> (keys, links, frame links) and neighbor report from joined node to 
> network manager.
> All other communications are local, between joining device and 
> neighbor (resp. with maintenance tool).
>
> It may have merit if we could use similar communication flows with 
> 6tisch, i.e., keep most traffic local to the joining device, except 
> for configuration parms exchange and authorization info passing.
>
> Most important consideration (from communication perspective) would be 
> that non-local traffic would be minimized, as also w/HART does. From a 
> marketing perspective, mimicking the communication flows w/HART 
> already has would keep all time scheduling considerations for w/HART 
> as currently there and 6TiSCH as to be detailed roughly the same. This 
> would longer term help in pushing 6tisch-style security scheme to 
> w/HART, since from a distance it looks the same (although trying to 
> scrap the maintenance tool).
>
> Of course, this does not deal with the details of the joining protocol 
> itself; only the flows.
>
> What about we look at some of the flows, and enumerate all issues that 
> need to be addressed here, both from a security perspective and 
> otherwise. We can then assign people to find missing information (I am 
> esp. curious about how devices know when to send/receive and 
> contributions of cycling efforts to total time latency).
>
> We could go over w/HART join flows during the call, to trigger these 
> questions.
>
> Best regards, Rene
>
>
> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>> That's 90 minutes from this email.
>>
>> 1) notewell.
>> 2) intros
>> 3) Rene had some material to present?  Did it happen last week,
>>     it seems not?
>> 4) review of claim certificate process, vs EST with token.
>>
>> -- remember that the call is recorded, and the NoteWell applies.
>>
>> -- The URL to access the webex, which will we use for audio only:
>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>
>> -- we will resume with the etherpad at:
>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>
>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>> if you need more than that to get in, or are having difficulties.
>> Please make sure your audio works, and that you mute when not talking.
>>
>>
>> --
>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>   -= IPv6 IoT consulting =-
>>
>>
>>
>>
>>
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------080705040302060201010908
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      Please find below a reminder of the outstanding issues re the join
      protocol, as I originally circulated three weeks ago, prior to our
      call on Tue May 20, 2014. {As an aside, the week before that, on
      May 12, 2014, we did discuss the w/HART join process protocol
      flows (at the time, intention was to agree to align flows with
      that used there, as motivated in the same email below).}<br>
      <br>
      While current discussions on w/HART protocol have been somewhat
      interesting, I feel we should put urgent priority on tackling
      those outstanding issues. So far, I have not seen any traffic on
      these items from others, so please weigh-in (please include
      outstanding item # in the subject line, e.g., "outstanding issue
      #c").<br>
      <br>
      Let us first tackle item #c) below on join process impact on the
      network. I am particularly interested in detailed deliberations on
      the three questions on this item that came to my mind here.<br>
      <br>
      When looking at this topic, I would like to encourage you to read
      the email thread on the IETF DICE list re
      draft-kumar-dice-dtls-relay-01, which is related to relaying&nbsp;
      nodes and potential DoS attacks. I initiated this discussion on
      May 27th, with last posting on May 30th. See
      <a class="moz-txt-link-freetext" href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
    </div>
    <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Hi Michael:<br>
        <br>
        At the previous conf call of May 12, 2014, we discussed message
        flows of w/HART join process, as also alluded to in my email
        below (the specs could not be distributed due to copyright
        restrictions).<br>
        <br>
        In my mind, 6TiSCH protocol can use similar communication flows
        as w/HART where only non-local communication flows (between
        joining node and network manager) would be <br>
        i) passing join/authentication information from joining node to
        network manager (and back);<br>
        ii) passing configuration parms from network manager to joining
        node (keys, links, frame links) and neighbor report from joined
        node to network manager.<br>
        <br>
        MAIN OUTSTANDING ISSUES (in my mind): <br>
        a) Packet sizes: <br>
        get more info on packet sizes configuration parms, as w/HART
        uses. Note RS: during call, Tom Phinney suggested contacting
        Wally Bratt from HART Comm. Foundation for this).&nbsp; Note RS:
        Shouldn't, e.g., Dust Networks have info on packet
        sizes/structure?; ISA SP100.11a metrics would also help, as
        would ZigBee 2.0 config parms. Does, e.g., Cisco have useful
        data points here?<br>
        b) Device Ids:<br>
        With industrial control, network manager would look up "tag
        name" device in pre-configured database. Details on tag name
        syntax, how assigned, and how bound to, e.g., EUI-64 are
        missing. Note RS: Perhaps, Tom Phinney could point at tag name
        syntax and lifecycle aspects here?<br>
        c) Join process impact on network: <br>
        Pascal Thubert asked "when network would explode with join".
        Note RS: the following questions come to mind:<br>
        - how does joining&nbsp; node find a time slot to send first join
        packet to neighbor node (presumably, this would require
        listening for Enhanced Beacon, but details on schedule in terms
        of time and channels seems incomplete [min-schedule suggests
        101x15ms slotframe and "less than 10s repeat of EBs, but that
        leaves lots of dead time and does not suggest a schedule that
        would create a common time window where two devices would both
        be awake).<br>
        - how does joining node negotiate a local schedule with neighbor
        node for execution of join protocol
        (draft-watteyne-6tisch-tisch-00 refers to local schedule
        negotiation need, but unclear whether this has been looked into
        in detail).<br>
        - for local traffic (joining node/neighbor), it seems Pascal
        Thubert's "exploding network" may not happen easily.
        Nevertheless, unclear what impact of "join priority flag TSCH
        802.15.4e frames is [that seems to have been designed with
        legacy w/HART in mind (centralized solution). With centralized
        tree-like solution, lots of traffic happens close to the root,
        thus potentially amplifying congestion around root node
        (=network manager?).<br>
        d) crypto protocol details of join protocol:<br>
        Note RS: I can solve this (close to optimal design already done
        [assuming I can do this "without hands tied behind the back"])<br>
        e) authorization/trust management:<br>
        it is here where binding of ids to public keys via certs and
        lifecycle aspects play a role, as well as syntax/semantics of
        authorization messages. Note RS: question is whether ACE could
        play a role here (current charter discussions seem to be
        endless, though). As has been brought up before, a potential
        instantiation of certs would be the use of 802.1ar certs, but
        this is certainly not the only way of doing things.<br>
        <br>
        There are lots of other things we should consider, outside the
        join protocol realm.<br>
        <br>
        ------- Original Message --------
        <table class="moz-email-headers-table" cellpadding="0"
          cellspacing="0" border="0">
          <tbody>
            <tr>
              <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:

              </th>
              <td>Re: [6tisch-security] agenda(?) for call today</td>
            </tr>
            <tr>
              <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:
              </th>
              <td>Mon, 12 May 2014 09:53:37 -0400</td>
            </tr>
            <tr>
              <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:
              </th>
              <td>Rene Struik <a moz-do-not-send="true"
                  class="moz-txt-link-rfc2396E"
                  href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
            </tr>
            <tr>
              <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To: </th>
              <td>Michael Richardson <a moz-do-not-send="true"
                  class="moz-txt-link-rfc2396E"
                  href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                <a moz-do-not-send="true"
                  class="moz-txt-link-abbreviated"
                  href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
            </tr>
          </tbody>
        </table>
        <br>
        <br>
        <div class="moz-cite-prefix">Hi Michael et al:<br>
          <br>
          Another topic worth exploring more is the join protocol
          details. <br>
          <br>
          (There are many other aspects, including certs, as you
          mentioned, more general security architecture, provisioning,
          etc., but below only deals with join.)<br>
          <br>
          With w/HART, the join process only interacts with the network
          manager (62591, Annex A.3, Fig. A.1) for <br>
          -forwarded join from joining node to network manager;<br>
          -passing configuration parms from network manager to joining
          node (keys, links, frame links) and neighbor report from
          joined node to network manager.<br>
          All other communications are local, between joining device and
          neighbor (resp. with maintenance tool).<br>
          <br>
          It may have merit if we could use similar communication flows
          with 6tisch, i.e., keep most traffic local to the joining
          device, except for configuration parms exchange and
          authorization info passing. <br>
          <br>
          Most important consideration (from communication perspective)
          would be that non-local traffic would be minimized, as also
          w/HART does. From a marketing perspective, mimicking the
          communication flows w/HART already has would keep all time
          scheduling considerations for w/HART as currently there and
          6TiSCH as to be detailed roughly the same. This would longer
          term help in pushing 6tisch-style security scheme to w/HART,
          since from a distance it looks the same (although trying to
          scrap the maintenance tool).<br>
          <br>
          Of course, this does not deal with the details of the joining
          protocol itself; only the flows.<br>
          <br>
          What about we look at some of the flows, and enumerate all
          issues that need to be addressed here, both from a security
          perspective and otherwise. We can then assign people to find
          missing information (I am esp. curious about how devices know
          when to send/receive and contributions of cycling efforts to
          total time latency). <br>
          <br>
          We could go over w/HART join flows during the call, to trigger
          these questions.<br>
          <br>
          Best regards, Rene<br>
        </div>
        <br>
        <br>
        On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
      </div>
      <blockquote cite="mid:19475.1400588783@sandelman.ca" type="cite">
        <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------080705040302060201010908--


From nobody Mon Jun  9 17:52:22 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45C511A02B2; Mon,  9 Jun 2014 17:52:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e0SJwtsYUbgI; Mon,  9 Jun 2014 17:52:15 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 33E651A0297; Mon,  9 Jun 2014 17:52:15 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 4613C20011; Mon,  9 Jun 2014 20:55:43 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id AEC8563B0E; Mon,  9 Jun 2014 20:52:12 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 9B76B63B0B; Mon,  9 Jun 2014 20:52:12 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>, tisch <6tisch@ietf.org>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 09 Jun 2014 20:52:12 -0400
Message-ID: <3806.1402361532@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/N1jDH0OuOwFLB_nhWg6lckOqu1s
Subject: [6tisch-security] DRAFT minutes for 2014-06-09 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 00:52:19 -0000

--=-=-=


https://bitbucket.org/6tisch/meetings/wiki/140609_webex_security

Minutes Webex 09 June 2014, 6TiSCH Security Design Team
Note: timestamps in PDT.

Taking notes (using Etherpad)
  Thomas Watteyne
  Pascal Thubert
  Present (alphabetically)
  Jonathan Simon
  Paul Duffy
  Hank Mauldin
  Michael Richardson
  Nancy Cam-Winget
  Pascal Thubert
  Pat Kinney
  Rene Struik
  Subir Das
  Thomas Watteyne
  Max Pritikin
  Giuseppe Piro

Recording
Webex recording: https://cisco.webex.com/ciscosales/lsr.php?RCID=d930ac29930845ff8e56001fd280f44b
Action Items
  Rene to start a thread on the ML about list of outstanding items.

Agenda

We will continue with the slides that Jonathan Simon posted 10 days ago
slides at http://www.ietf.org/mail-archive/web/6tisch-security/current/pdfiZJLN6CKg0.pdf
Meeting through webex
Webex URL: https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
we will use with Etherpad
Etherpad at https://etherpad.mozilla.org/ras5RGrQLA

Minutes
[08.04] recording starts
*[Michael]* Note Well applies
[Jonathan] presents slide 2
Feedback about slides about where arrow point
Join request encrypted end-to-end to PCE. Routed for joining node by proxy. Proxy does only routing.
Primary contents of join request is the list of neighbor.
PCE responds with an end-to-end session, a short address, a run-time link layer key, additional information (resources, etc)
question?
No questions.
[Jonathan] moves to slide 3
idea: keep brevity of WirelessHART flow, with ability to use public keys.
in the first step, joining node listens for EB for sync information. Discussion about what kind of key to authenticate that packet. Options:
Simplest is WKK, published in standard. Drawback: does not provide security, but allows to segregate from other protocols. No real authentication provide.
OOB keying. Provides security but not a touch-less operation which is a desired propriety.
Key derived from top-level domain certificate. Assumes that all devices have the same top-level certificate, and that is not sent over the air (presumption is certificate is not sent over the air prior to other key established to protect it). After that, other run-time key established.
joining node asks for the public key of the entity that it is joining.
we want to be able to accommodate centralized (PCE responsible), and distributed (peer responsible for this initial handshake). Depending on what's used, PCE or proxy answers with this key -> the key would be that of the PCE or that of the proxy itself.
idea: use a paired-down X.509 certificate. Probably easy to reduce to 2 packets
request for certificate is optional, and not used if PSK.
next step: send in join request. Envision something similar to WirelessHART: small amount of topology information included, also device's cert (optional if PSK)
join request encrypted end-to-end using certificate obtained in previous step. In centralized case, sent to PCE. In distributed case, sent to proxy node. That device sends back a response.
PCE does top-level domain check. If passes, sends response, similar to that in WirelessHART: assigns a node a short address (more questions in distributed system), run-time link key, and optionally a Diffie-Hellman (DH) handshake to establish an ephemeral key
as in WirelessHART, we now move ahead to establish security session with PCE, assign resources, etc.
[Rene] abbreviated? what do you mean by that?
[Jonathan] one of the things that a TLS session does is provide forward security using DH to establish ephemeral key. Takes more steps, possible to assign a key. We can decide if no-DH solution has the desired security property. Do we believe that we need DH? If no, we can save a couple of packets. Note that this is just for the control channel, the data channel will since DTLS.
[Rene] Do you want to do 2 protocols: one for management, one for data?
[Jonathan] that's the HART model: 2 independent security sessions: one from PCE to network for assigning slots and links, one for application-layer data. Proposes a similar model here.
[Rene] security overhead?
[Jonathan] yes, requires 2 sets of sec counters and keys, we would use same crypto suite, so not much overhead under the hood. We would use the same crypto suite for both.
[Rene] if application and control done by same entity, we could use the same secure session.
[Max] you can reuse the protocol, but we need more packets. Trade-off.
[Thomas] in centralized case with PCE, I'd say that the once the node as joined, data would go to some server in the Internet so that's a different security session. Alternative is the PCE receives the data and then establishes another session but that looks like a weak security.
[Jonathan] assumed 2 independent steps: management and second security
[Rene]: I do not agree that these are different things. Essentially the trust model does not have to be different if these are the same devices.
[Max] the PCE is not trusted for the data.
[Rene] in a simplest model the entity is also handling data the keys could be visible
[Michael] wrong assumption. Even if collocated say WIN95. There will be process separation.
[Rene] assumption: any other device cannot make any other assumption about the visibility
[Michael] don't understand
[Rene] side-tracking, want to understand.
[Pascal] backwards. we are not saying that we cannot enforce that the crypto domains are kept separate (in a device), just that it is not always possible to guarantee that they are not, in particular PCE and server may not be able to share keys.
[Jonathan] big different between I have a single space in my device for keying for memory constrain, different from "we want application and control to have different security constraints".
[Michael] 2 points:
observation: TLS allow you do a re-keying at any point, means that if one decides wants PSK, you can do that later on. If you don't do DH.
questions: about step 4, in the PSK case, it's necessary in step 4 for joining node to encrypt with PSK to prove to PCE possesses PSK, i.e. authenticates with it.
[Jonathan] yes
[Michael] in public key, would the joining node sign the join request?
[Jonathan] yes
[Michael] why encrypt then? what is thread?
[Jonathan] maybe little too literal on WirelessHART, but information sent includes information about the device. Not sure what we would be sending. In the WirelessHART case, you also add information about neighbors etc. The alternative is to just establish the security session, then send that information to the PCE through that session.
[Subir] what is PK? PKI?
[Jonathan] I would not say PKI which implies online systems but it is a PK mechanism assuming some flows like in Michael's B draft.
[Michael] if we do not encrypt to PCE in step 4, there is no need steps 2 and 3. No need to retrieve the certificate from the proxy.
[Thomas] advantage is also that the new device authenticates the network.
[Michael] that actually comes in step 5 when the PCE initiates a session. Before that it has not signed or encrypted anything.
[Jonathan] then when does the joining node need the crypto info from the PCE?
[Max] anytime before sending additional info to the PCE. Whether at step 3 or 5 does not really matter.
[Jonathan] in the flows, the proxy caches the certificate so we avoid end-to-end flows.
[Max] Yes, but then you do not bind the particular request with a domain. If we delay to step 5, we can bind that response to the particular joining node..
[Max] You might authenticate the PCE at step 5.
[Michael] device may join multiple networks, is that what you want? I can imagine a case where a joining mote receives multiple EBs from different networks, and want to be able to choose.
[Max] until you have a 'nonce' from the node, there is no binding and replay 1..3 would be trivial. It is not before you have a message with more detailed info that we can establish a binding.
[Jonathan] there is timing info so simple replay is not easy.
[Max] fake proxy could replay a different certificate
[Subir] is the PCE and proxy already part of the same domain when new mote joins?
[Jonathan] joining node checks that a cert in step 3 assuming that the domain level cert or something that allows to get it is already configured.
[Max] it doesn't know the domain certification
[Jonathan] assume domain level cert already pre-configured
[Max] touch-less?
[Michael] not per se the domain for this network, but some domain level cert
[Jonathan] touch less implies no step where we configure anything individual to that device
[Max] we have a trust anchor, but not per-se this particular domain. We have to do something to make that the case. Whatever that is, we want that to be bound to this particular joining node
[Michael] see end of Etherpad, let's create PRO/CON list for sending certificate in step 3.
PRO on sending certificate in response 3:
the joining node can evaluate whether or not this is a network it would be able to join
CON on sending certificate in step 3 vs step 5:
an attacker can get the joining node to encrypt to any provide PCE PK, its list of information. The joining node has to validate between steps 3/4, so the proxy can never reach out to the cloud. (echoes Max's point)
[Michael] thinking about joining node that is bombarded with EBs, some malicious, some correct. It can go through those nodes and validate them, so doesn't want to try them.
[Thomas] even if no attack but just multiple networks, this may save multiple packets if we can identify the right network early on.
[Michael] CON is that, in the case that a joining node has a party of a certificate chain, it could be convinced
[Michael] advantage about doing steps 2&3, even if many packets, only single hop, no extra BW in rest of network
[Subir] do we need to protect the proxy from proxying too many packets?
[Michael] proxy needs to rate limit itself and send beacons when it can not answer.
[Rene] please read discussion thread DICE: http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html , this deals with DoS attacks
[Max] concern is that joining node is authenticating network in step 3
[Max] validating cert in step 3 but there is no opportunity to talk about that cert
[Subir] proxy will continue to respond, at no point can stop.
[Max] step 3 has no response from the cloud and we can fool the device. Move to steps 4 and 5 then we can have the authentication in step 5.
[Max] the proxy does not reach out to PCE, so response will not contain anything from the cloud. So no cloud binding, so you can have a downgrade attack. If you move authentication between steps 4&5, we can encode information for joining node. The cloud could authenticate.
[Subir] add a message between 2 and 3 where the proxy contacts the PCE/cloud?
[Max] that is one way
[Michael] only way if you want a idevid-like. comment about downgrade attack is interesting. Do you always want to do that? One of the advantages of having comm between 2 and 3 is to get additional information as which network to join. PCE may not respond immediately but one by one between queued requests to streamline
[Michael] PCE can be aware of network congestion due to traffic, go all traffic through one node first, rather than all nodes at the same time. Step 4&5, not clear that need retransmit. How does the node know join request was received?
[Jonathan] simple timeout?
[Michael] what about EB has list of "following join requests have been received", some sort of group ACK.
[Jonathan] sure
[Subir] many different mechanisms possible; mutually authenticate would be good to have
[Michael] 10min left
[Michael] add anything about notes (last slides)
[Jonathan] we need to have a serious discussion about what crypto suites are mandatory, and what we want in the certficate, including ephemeral key. Flow is designed to accommodate pre-shared key with minimal change
[Thomas] want to stress that we need to be able to support both centralized and distributed. The proposal seems to allow that. The other is to support both a PSK and PK model.
[Michael] Jonathan/Thomas/Michael put ideas in document, tried to get that detailed. Will need review.
[Michael] Is there a volunteer to put together a similar doc with ZigBeeIP with EAP-TLS? We agreed to have 2 separate documents. Need a volunteer for ZigBee IP similar process
[Pascal] Since work in Wi-Sun, we want this approach to be discussed.
[Michael] what is Wi-Sun?
[Pascal] alliance for smart grid, things going on there, not sure specs are public yet, but very soon. Aware these exist, good enough to have something. Would like to see this documented.
http://www.wi-sun.org/
[Subir] anyone in this call who has knowledge about Wi-Sun?
[Paul] yes, myself, Nancy have knowledge about this effort. Not documented publicly yet.
[Michael] mostly about metering?
[Paul] Wi-Sun Field Area Network, AMI infrastructure, street lighting, distribution automation.
[Subir] time frame? it is a membership organization correct?
[Paul] it is a membership organization. Tricky question to answer. Confidentiality issues. Working through security discussion. Unclear how to move into IETF/IEEE.
[Michael] suggestion: let's pick a liaison early.
[Michael] any other question?
[Rene] quick question: we discussed a list of outstanding items, put in a list. So far, I don't think we publicly looked at this, and tick them one by one.
[Pascal] Could you start a thread on ML?
[Rene] yes
Action item: Rene to start a thread on the ML about list of outstanding items.
[Rene] we seem to design a crypto protocol on-the-fly. We need to make this cryptographically sound. I can take a stab. We need to have something much more detailed than these flows.
[Pascal] are those two angles to get to the same place?
[Jonathan] goal is to focus on flow and get consensus, We were not deliberately doing something out of order. Get agreement on that, then dive into cryptographic details. First step is to write flow down in document.
[Max] we have the email threads and the bootstrapping documents -- not entirely "on the fly", just an ongoing conversation about the how this impacts the flow
[Pascal] we are progressing on our common understanding with this discussion.
[Michael] we should have something sooner than 7/4. We started in Friday but needs more work. we need review
[Michael] Thanks.
[09.00] Meeting ends

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU5ZWvICLcPvd0N1lAQL7IAf+M0eKNgAbwy6X1xo7Ov/ccGrFtpO9RJKP
iA2Z4izOLtGN62+goaxKsP9JeiUYxX4td+ug+k9RNApvyKrClJQNB7uCPGmR9FmF
xGJHxOXyM6o69sYmfs43aNLsW44M3Q81qwcRRdoaOw+bzbBl6MiBWCylpb+ZbUOV
GruqR0ODf0DK/Z3uReKZaPQCB0W0zKIlnaLzUnWgyeajbrThlInzY3bZUT2hQwRK
hS49L9Pg8v3/BOxCJ6tSI7cNbsJ1XbLjbU76WloP3Ph2wg1rD8HdvKtim/IHI1Ff
jS/Et2ZSAlxp0Vr1V+ZbRLfl45kUufO0US/dnIHE2XPD9zuMjwnzTg==
=kQY1
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Jun 10 07:42:08 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B28AF1A018E for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 07:41:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PtN2lzYegmZy for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 07:41:45 -0700 (PDT)
Received: from mail-ie0-x22e.google.com (mail-ie0-x22e.google.com [IPv6:2607:f8b0:4001:c03::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9FACD1B27CF for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 07:41:41 -0700 (PDT)
Received: by mail-ie0-f174.google.com with SMTP id lx4so4017574iec.33 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 07:41:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=kvhYI0XoMXRWCfHMfDidU7QNxCQjmxtRMAM/vDWBFCI=; b=Ki67iVBRvsGWUWG6WU9eCZQ8sBZicFXVK+Ctsn3nhnEDptxvPqRI8doKwlFyaiz6jK PUDmc/r/lVHPvisSo236+xl+5ge7tqQMmb9ZeB123pwmCjIKpTILRUhUKeFP2V+SPhDr uzK5iW5MFLw2cj+F0iSaVKVDUiU+pNs0iRPMv4M489W37elWdoxo1r47SD92wA9sYhvi 9+1I2H2freAcpXh8oUrDdaLwGeJK6hCtedm6Kv/gI9DY/8du59A1TIZyUdpMQKTdYYFe qBMHYytFo2LacgtfQqC+33OONcADQxzXmMi+H97Yn5hA4pggrZImqLWqOadScel7Cm3d Z3aw==
X-Received: by 10.50.138.99 with SMTP id qp3mr41969586igb.12.1402411300791; Tue, 10 Jun 2014 07:41:40 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id pm8sm1680594igb.2.2014.06.10.07.41.39 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 10 Jun 2014 07:41:40 -0700 (PDT)
Message-ID: <53971920.3070400@gmail.com>
Date: Tue, 10 Jun 2014 10:41:36 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com>
In-Reply-To: <5395D7E4.1010200@gmail.com>
Content-Type: multipart/alternative; boundary="------------070504090400030801090608"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/AznmpnwlqbUWmYnzeN900CL6SOQ
Subject: [6tisch-security] tackling outstanding issues #c-2
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 14:41:51 -0000

This is a multi-part message in MIME format.
--------------070504090400030801090608
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

Assumptions:
- Joining node has a minimum schedule (with 101x15ms slotframe) and 
somehow was able to find a time slot to send a first join packet to a 
neighbor node (c-1).
- Computational and communication time latency for response packet from 
neighbor node to joining node is 15ms, 150ms, 750ms, or 5s (depending on 
device capabilities, implementation detail)
- Computational time latency for joining node to compute shared key is 
15ms, 150ms, 750ms, or 5s (depending on device capabilities, 
implementation detail)

So, now for question c-2 below:
- How does joining node find out when to open its receiver again, so as 
to receive response packet from neighbor node
- How does neighbor node find out when to receive second packet flow 
from joining node (i.e., after joining node computed shared key)
In particular, should the local schedule allocate multiples of 15ms 
(i.e., each timeslot), 150ms, etc. Obviously, the denser the schedule 
the fewer capacity in terms of #joining nodes that can be served?

So, perhaps, the background of my question c-2 is  now unambiguously 
clear...

==
c) Join process impact on network:
Pascal Thubert asked "when network would explode with join". Note RS: 
the following questions come to mind:
c-1) how does joining  node find a time slot to send first join packet 
to neighbor node (presumably, this would require listening for Enhanced 
Beacon, but details on schedule in terms of time and channels seems 
incomplete [min-schedule suggests 101x15ms slotframe and "less than 10s 
repeat of EBs, but that leaves lots of dead time and does not suggest a 
schedule that would create a common time window where two devices would 
both be awake).
c-2)how does joining node negotiate a local schedule with neighbor node 
for execution of join protocol (draft-watteyne-6tisch-tisch-00 refers to 
local schedule negotiation need, but unclear whether this has been 
looked into in detail).
c-3) for local traffic (joining node/neighbor), it seems Pascal 
Thubert's "exploding network" may not happen easily. Nevertheless, 
unclear what impact of "join priority flag TSCH 802.15.4e frames is 
[that seems to have been designed with legacy w/HART in mind 
(centralized solution). With centralized tree-like solution, lots of 
traffic happens close to the root, thus potentially amplifying 
congestion around root node (=network manager?).

On 6/9/2014 11:51 AM, Rene Struik wrote:
> Dear colleagues:
>
> Please find below a reminder of the outstanding issues re the join 
> protocol, as I originally circulated three weeks ago, prior to our 
> call on Tue May 20, 2014. {As an aside, the week before that, on May 
> 12, 2014, we did discuss the w/HART join process protocol flows (at 
> the time, intention was to agree to align flows with that used there, 
> as motivated in the same email below).}
>
> While current discussions on w/HART protocol have been somewhat 
> interesting, I feel we should put urgent priority on tackling those 
> outstanding issues. So far, I have not seen any traffic on these items 
> from others, so please weigh-in (please include outstanding item # in 
> the subject line, e.g., "outstanding issue #c").
>
> Let us first tackle item #c) below on join process impact on the 
> network. I am particularly interested in detailed deliberations on the 
> three questions on this item that came to my mind here.
>
> When looking at this topic, I would like to encourage you to read the 
> email thread on the IETF DICE list re draft-kumar-dice-dtls-relay-01, 
> which is related to relaying nodes and potential DoS attacks. I 
> initiated this discussion on May 27th, with last posting on May 30th. 
> See http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>
> Best regards, Rene
>
> On 5/20/2014 9:45 AM, Rene Struik wrote:
>> Hi Michael:
>>
>> At the previous conf call of May 12, 2014, we discussed message flows 
>> of w/HART join process, as also alluded to in my email below (the 
>> specs could not be distributed due to copyright restrictions).
>>
>> In my mind, 6TiSCH protocol can use similar communication flows as 
>> w/HART where only non-local communication flows (between joining node 
>> and network manager) would be
>> i) passing join/authentication information from joining node to 
>> network manager (and back);
>> ii) passing configuration parms from network manager to joining node 
>> (keys, links, frame links) and neighbor report from joined node to 
>> network manager.
>>
>> MAIN OUTSTANDING ISSUES (in my mind):
>> a) Packet sizes:
>> get more info on packet sizes configuration parms, as w/HART uses. 
>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., Dust 
>> Networks have info on packet sizes/structure?; ISA SP100.11a metrics 
>> would also help, as would ZigBee 2.0 config parms. Does, e.g., Cisco 
>> have useful data points here?
>> b) Device Ids:
>> With industrial control, network manager would look up "tag name" 
>> device in pre-configured database. Details on tag name syntax, how 
>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>> aspects here?
>> c) Join process impact on network:
>> Pascal Thubert asked "when network would explode with join". Note RS: 
>> the following questions come to mind:
>> - how does joining  node find a time slot to send first join packet 
>> to neighbor node (presumably, this would require listening for 
>> Enhanced Beacon, but details on schedule in terms of time and 
>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>> and does not suggest a schedule that would create a common time 
>> window where two devices would both be awake).
>> - how does joining node negotiate a local schedule with neighbor node 
>> for execution of join protocol (draft-watteyne-6tisch-tisch-00 refers 
>> to local schedule negotiation need, but unclear whether this has been 
>> looked into in detail).
>> - for local traffic (joining node/neighbor), it seems Pascal 
>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>> [that seems to have been designed with legacy w/HART in mind 
>> (centralized solution). With centralized tree-like solution, lots of 
>> traffic happens close to the root, thus potentially amplifying 
>> congestion around root node (=network manager?).
>> d) crypto protocol details of join protocol:
>> Note RS: I can solve this (close to optimal design already done 
>> [assuming I can do this "without hands tied behind the back"])
>> e) authorization/trust management:
>> it is here where binding of ids to public keys via certs and 
>> lifecycle aspects play a role, as well as syntax/semantics of 
>> authorization messages. Note RS: question is whether ACE could play a 
>> role here (current charter discussions seem to be endless, though). 
>> As has been brought up before, a potential instantiation of certs 
>> would be the use of 802.1ar certs, but this is certainly not the only 
>> way of doing things.
>>
>> There are lots of other things we should consider, outside the join 
>> protocol realm.
>>
>> ------- Original Message --------
>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>> From: 	Rene Struik <rstruik.ext@gmail.com>
>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>> 6tisch-security@ietf.org
>>
>>
>>
>> Hi Michael et al:
>>
>> Another topic worth exploring more is the join protocol details.
>>
>> (There are many other aspects, including certs, as you mentioned, 
>> more general security architecture, provisioning, etc., but below 
>> only deals with join.)
>>
>> With w/HART, the join process only interacts with the network manager 
>> (62591, Annex A.3, Fig. A.1) for
>> -forwarded join from joining node to network manager;
>> -passing configuration parms from network manager to joining node 
>> (keys, links, frame links) and neighbor report from joined node to 
>> network manager.
>> All other communications are local, between joining device and 
>> neighbor (resp. with maintenance tool).
>>
>> It may have merit if we could use similar communication flows with 
>> 6tisch, i.e., keep most traffic local to the joining device, except 
>> for configuration parms exchange and authorization info passing.
>>
>> Most important consideration (from communication perspective) would 
>> be that non-local traffic would be minimized, as also w/HART does. 
>> From a marketing perspective, mimicking the communication flows 
>> w/HART already has would keep all time scheduling considerations for 
>> w/HART as currently there and 6TiSCH as to be detailed roughly the 
>> same. This would longer term help in pushing 6tisch-style security 
>> scheme to w/HART, since from a distance it looks the same (although 
>> trying to scrap the maintenance tool).
>>
>> Of course, this does not deal with the details of the joining 
>> protocol itself; only the flows.
>>
>> What about we look at some of the flows, and enumerate all issues 
>> that need to be addressed here, both from a security perspective and 
>> otherwise. We can then assign people to find missing information (I 
>> am esp. curious about how devices know when to send/receive and 
>> contributions of cycling efforts to total time latency).
>>
>> We could go over w/HART join flows during the call, to trigger these 
>> questions.
>>
>> Best regards, Rene
>>
>>
>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>> That's 90 minutes from this email.
>>>
>>> 1) notewell.
>>> 2) intros
>>> 3) Rene had some material to present?  Did it happen last week,
>>>     it seems not?
>>> 4) review of claim certificate process, vs EST with token.
>>>
>>> -- remember that the call is recorded, and the NoteWell applies.
>>>
>>> -- The URL to access the webex, which will we use for audio only:
>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>
>>> -- we will resume with the etherpad at:
>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>
>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>> if you need more than that to get in, or are having difficulties.
>>> Please make sure your audio works, and that you mute when not talking.
>>>
>>>
>>> --
>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>   -= IPv6 IoT consulting =-
>>>
>>>
>>>
>>>
>>>
>>> _______________________________________________
>>> 6tisch-security mailing list
>>> 6tisch-security@ietf.org
>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070504090400030801090608
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      Assumptions:<br>
      - Joining node has a minimum schedule (with 101x15ms slotframe)
      and somehow was able to find a time slot to send a first join
      packet to a neighbor node (c-1).<br>
      - Computational and communication time latency for response packet
      from neighbor node to joining node is 15ms, 150ms, 750ms, or 5s
      (depending on device capabilities, implementation detail)<br>
      - Computational time latency for joining node to compute shared
      key is 15ms, 150ms, 750ms, or 5s (depending on device
      capabilities, implementation detail)<br>
      <br>
      So, now for question c-2 below:<br>
      - How does joining node find out when to open its receiver again,
      so as to receive response packet from neighbor node<br>
      - How does neighbor node find out when to receive second packet
      flow from joining node (i.e., after joining node computed shared
      key)<br>
      In particular, should the local schedule allocate multiples of
      15ms (i.e., each timeslot), 150ms, etc. Obviously, the denser the
      schedule the fewer capacity in terms of #joining nodes that can be
      served?<br>
      <br>
      So, perhaps, the background of my question c-2 is&nbsp; now
      unambiguously clear...<br>
      <br>
      ==<br>
      c) Join process impact on network: <br>
      Pascal Thubert asked "when network would explode with join". Note
      RS: the following questions come to mind:<br>
      c-1) how does joining&nbsp; node find a time slot to send first join
      packet to neighbor node (presumably, this would require listening
      for Enhanced Beacon, but details on schedule in terms of time and
      channels seems incomplete [min-schedule suggests 101x15ms
      slotframe and "less than 10s repeat of EBs, but that leaves lots
      of dead time and does not suggest a schedule that would create a
      common time window where two devices would both be awake).<br>
      c-2)how does joining node negotiate a local schedule with neighbor
      node for execution of join protocol
      (draft-watteyne-6tisch-tisch-00 refers to local schedule
      negotiation need, but unclear whether this has been looked into in
      detail).<br>
      c-3) for local traffic (joining node/neighbor), it seems Pascal
      Thubert's "exploding network" may not happen easily. Nevertheless,
      unclear what impact of "join priority flag TSCH 802.15.4e frames
      is [that seems to have been designed with legacy w/HART in mind
      (centralized solution). With centralized tree-like solution, lots
      of traffic happens close to the root, thus potentially amplifying
      congestion around root node (=network manager?).<br>
      <br>
      On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
    </div>
    <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Dear colleagues:<br>
        <br>
        Please find below a reminder of the outstanding issues re the
        join protocol, as I originally circulated three weeks ago, prior
        to our call on Tue May 20, 2014. {As an aside, the week before
        that, on May 12, 2014, we did discuss the w/HART join process
        protocol flows (at the time, intention was to agree to align
        flows with that used there, as motivated in the same email
        below).}<br>
        <br>
        While current discussions on w/HART protocol have been somewhat
        interesting, I feel we should put urgent priority on tackling
        those outstanding issues. So far, I have not seen any traffic on
        these items from others, so please weigh-in (please include
        outstanding item # in the subject line, e.g., "outstanding issue
        #c").<br>
        <br>
        Let us first tackle item #c) below on join process impact on the
        network. I am particularly interested in detailed deliberations
        on the three questions on this item that came to my mind here.<br>
        <br>
        When looking at this topic, I would like to encourage you to
        read the email thread on the IETF DICE list re
        draft-kumar-dice-dtls-relay-01, which is related to relaying&nbsp;
        nodes and potential DoS attacks. I initiated this discussion on
        May 27th, with last posting on May 30th. See <a
          moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
        <br>
        Best regards, Rene<br>
        <br>
        On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
      </div>
      <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Hi Michael:<br>
          <br>
          At the previous conf call of May 12, 2014, we discussed
          message flows of w/HART join process, as also alluded to in my
          email below (the specs could not be distributed due to
          copyright restrictions).<br>
          <br>
          In my mind, 6TiSCH protocol can use similar communication
          flows as w/HART where only non-local communication flows
          (between joining node and network manager) would be <br>
          i) passing join/authentication information from joining node
          to network manager (and back);<br>
          ii) passing configuration parms from network manager to
          joining node (keys, links, frame links) and neighbor report
          from joined node to network manager.<br>
          <br>
          MAIN OUTSTANDING ISSUES (in my mind): <br>
          a) Packet sizes: <br>
          get more info on packet sizes configuration parms, as w/HART
          uses. Note RS: during call, Tom Phinney suggested contacting
          Wally Bratt from HART Comm. Foundation for this).&nbsp; Note RS:
          Shouldn't, e.g., Dust Networks have info on packet
          sizes/structure?; ISA SP100.11a metrics would also help, as
          would ZigBee 2.0 config parms. Does, e.g., Cisco have useful
          data points here?<br>
          b) Device Ids:<br>
          With industrial control, network manager would look up "tag
          name" device in pre-configured database. Details on tag name
          syntax, how assigned, and how bound to, e.g., EUI-64 are
          missing. Note RS: Perhaps, Tom Phinney could point at tag name
          syntax and lifecycle aspects here?<br>
          c) Join process impact on network: <br>
          Pascal Thubert asked "when network would explode with join".
          Note RS: the following questions come to mind:<br>
          - how does joining&nbsp; node find a time slot to send first join
          packet to neighbor node (presumably, this would require
          listening for Enhanced Beacon, but details on schedule in
          terms of time and channels seems incomplete [min-schedule
          suggests 101x15ms slotframe and "less than 10s repeat of EBs,
          but that leaves lots of dead time and does not suggest a
          schedule that would create a common time window where two
          devices would both be awake).<br>
          - how does joining node negotiate a local schedule with
          neighbor node for execution of join protocol
          (draft-watteyne-6tisch-tisch-00 refers to local schedule
          negotiation need, but unclear whether this has been looked
          into in detail).<br>
          - for local traffic (joining node/neighbor), it seems Pascal
          Thubert's "exploding network" may not happen easily.
          Nevertheless, unclear what impact of "join priority flag TSCH
          802.15.4e frames is [that seems to have been designed with
          legacy w/HART in mind (centralized solution). With centralized
          tree-like solution, lots of traffic happens close to the root,
          thus potentially amplifying congestion around root node
          (=network manager?).<br>
          d) crypto protocol details of join protocol:<br>
          Note RS: I can solve this (close to optimal design already
          done [assuming I can do this "without hands tied behind the
          back"])<br>
          e) authorization/trust management:<br>
          it is here where binding of ids to public keys via certs and
          lifecycle aspects play a role, as well as syntax/semantics of
          authorization messages. Note RS: question is whether ACE could
          play a role here (current charter discussions seem to be
          endless, though). As has been brought up before, a potential
          instantiation of certs would be the use of 802.1ar certs, but
          this is certainly not the only way of doing things.<br>
          <br>
          There are lots of other things we should consider, outside the
          join protocol realm.<br>
          <br>
          ------- Original Message --------
          <table class="moz-email-headers-table" cellpadding="0"
            cellspacing="0" border="0">
            <tbody>
              <tr>
                <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:


                </th>
                <td>Re: [6tisch-security] agenda(?) for call today</td>
              </tr>
              <tr>
                <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:

                </th>
                <td>Mon, 12 May 2014 09:53:37 -0400</td>
              </tr>
              <tr>
                <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:

                </th>
                <td>Rene Struik <a moz-do-not-send="true"
                    class="moz-txt-link-rfc2396E"
                    href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
              </tr>
              <tr>
                <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To:
                </th>
                <td>Michael Richardson <a moz-do-not-send="true"
                    class="moz-txt-link-rfc2396E"
                    href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                  <a moz-do-not-send="true"
                    class="moz-txt-link-abbreviated"
                    href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
              </tr>
            </tbody>
          </table>
          <br>
          <br>
          <div class="moz-cite-prefix">Hi Michael et al:<br>
            <br>
            Another topic worth exploring more is the join protocol
            details. <br>
            <br>
            (There are many other aspects, including certs, as you
            mentioned, more general security architecture, provisioning,
            etc., but below only deals with join.)<br>
            <br>
            With w/HART, the join process only interacts with the
            network manager (62591, Annex A.3, Fig. A.1) for <br>
            -forwarded join from joining node to network manager;<br>
            -passing configuration parms from network manager to joining
            node (keys, links, frame links) and neighbor report from
            joined node to network manager.<br>
            All other communications are local, between joining device
            and neighbor (resp. with maintenance tool).<br>
            <br>
            It may have merit if we could use similar communication
            flows with 6tisch, i.e., keep most traffic local to the
            joining device, except for configuration parms exchange and
            authorization info passing. <br>
            <br>
            Most important consideration (from communication
            perspective) would be that non-local traffic would be
            minimized, as also w/HART does. From a marketing
            perspective, mimicking the communication flows w/HART
            already has would keep all time scheduling considerations
            for w/HART as currently there and 6TiSCH as to be detailed
            roughly the same. This would longer term help in pushing
            6tisch-style security scheme to w/HART, since from a
            distance it looks the same (although trying to scrap the
            maintenance tool).<br>
            <br>
            Of course, this does not deal with the details of the
            joining protocol itself; only the flows.<br>
            <br>
            What about we look at some of the flows, and enumerate all
            issues that need to be addressed here, both from a security
            perspective and otherwise. We can then assign people to find
            missing information (I am esp. curious about how devices
            know when to send/receive and contributions of cycling
            efforts to total time latency). <br>
            <br>
            We could go over w/HART join flows during the call, to
            trigger these questions.<br>
            <br>
            Best regards, Rene<br>
          </div>
          <br>
          <br>
          On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
        </div>
        <blockquote cite="mid:19475.1400588783@sandelman.ca" type="cite">
          <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
          <br>
          <fieldset class="mimeAttachmentHeader"></fieldset>
          <br>
          <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070504090400030801090608--


From nobody Tue Jun 10 08:39:36 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D76621A01CB for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 08:39:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 13a8oEJ0qEeL for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 08:39:30 -0700 (PDT)
Received: from mail-ie0-x229.google.com (mail-ie0-x229.google.com [IPv6:2607:f8b0:4001:c03::229]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 90B151A01A7 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 08:39:30 -0700 (PDT)
Received: by mail-ie0-f169.google.com with SMTP id at1so3805207iec.28 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 08:39:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=6YBoKLrTNbKEKPVsrRZPPHMrqd3MC4jnUeoYvAOcSJM=; b=p2M+iE58gx5CBjsY8PmjcFtsBYxsFXsY5zd3UCgme3ZL/FC7er8cQHTHDjw1v+uEfx be0J/PvLE7Q41uMjSCmqdgAHI0LBUj55+Fc4rT45XrWxJrotDfyP7QNwFZZt8kl84DZK bvAv+rBRz4PlocjzhX5HxJ03Zd8mX7/n1voW9g9HI/KyXBm37XC808K33f7AQimxdlAe 0RCNNVOuc6iAuCLb1ZF0C8k+fg/LJesFz8hT2BaCyAcAxK1tHh+sSNRy1o8F5WdjV9ll 7H76tBnmYl+GxZBNWHFuthJk2LQxSNLXCcdeYBuMBxJFtmnb+oPrGxt4w//E1sxXReC0 ZIYQ==
X-Received: by 10.43.160.4 with SMTP id ma4mr13554883icc.83.1402414769782; Tue, 10 Jun 2014 08:39:29 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id m1sm66136689ige.22.2014.06.10.08.39.28 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 10 Jun 2014 08:39:29 -0700 (PDT)
Message-ID: <539726AE.1000504@gmail.com>
Date: Tue, 10 Jun 2014 11:39:26 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com>
In-Reply-To: <53971920.3070400@gmail.com>
Content-Type: multipart/alternative; boundary="------------080503050800000602070304"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/d6AQFHRsSRUV3ylNpVoJi0Tv9Ik
Subject: [6tisch-security] tackling outstanding issues #c-3
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 15:39:35 -0000

This is a multi-part message in MIME format.
--------------080503050800000602070304
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

Please find below some deliberations on outstanding item #c-3:

With 802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13) includes the 
absolute slot number (ASN) and the Join Priority flag.

Since a newly joining device has no way to validate whether the ASN 
entry advertised by the beaconing device corresponds to the one 
maintained by the PAN coordinator and there is only one macASN entry, 
joining nodes cannot rely on this ASN entry for frame security. As a 
result, the first message from a newbee node to the neighbor device 
should be unsecured. In particular, this should neither attempt to use a 
"well-known key".

It is unclear how the join priority flag would help in facilitating 
resource optimization when a newly joining device tries and join the 
network. Perhaps, this flag was motivated by centralized solution ideas, 
where every device joins via the PAN coordinator? Suggestion is to 
completely ignore this joining priority flag.

Best regards, Rene

[excerpt of 802.15.4e-2012]
The ASN field contains the 5-octet Absolute Slot Number corresponding to 
the timeslot in which the
enhanced beacon is sent. The ASN is used as the Frame Counter for 
security operations if enabled. The 1-
octet Join Priority field can be used by a joining device to select 
among beaconing devices when multiple
beacons are heard. The PAN coordinator's join priority is zero. A lower 
value of join priority indicates that
the device is the preferred one to connect to. The beaconing device's 
join priority is the lowest join priority
heard when it joined the network plus one.
The TSCH Synchronization IE is used to construct enhanced beacons that 
allow new devices to synchronize
to a TSCH PAN.

> ==
> c) Join process impact on network:
> Pascal Thubert asked "when network would explode with join". Note RS: 
> the following questions come to mind:
> c-1) how does joining  node find a time slot to send first join packet 
> to neighbor node (presumably, this would require listening for 
> Enhanced Beacon, but details on schedule in terms of time and channels 
> seems incomplete [min-schedule suggests 101x15ms slotframe and "less 
> than 10s repeat of EBs, but that leaves lots of dead time and does not 
> suggest a schedule that would create a common time window where two 
> devices would both be awake).
> c-2)how does joining node negotiate a local schedule with neighbor 
> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
> refers to local schedule negotiation need, but unclear whether this 
> has been looked into in detail).
> c-3) for local traffic (joining node/neighbor), it seems Pascal 
> Thubert's "exploding network" may not happen easily. Nevertheless, 
> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
> [that seems to have been designed with legacy w/HART in mind 
> (centralized solution). With centralized tree-like solution, lots of 
> traffic happens close to the root, thus potentially amplifying 
> congestion around root node (=network manager?).
>
> On 6/9/2014 11:51 AM, Rene Struik wrote:
>> Dear colleagues:
>>
>> Please find below a reminder of the outstanding issues re the join 
>> protocol, as I originally circulated three weeks ago, prior to our 
>> call on Tue May 20, 2014. {As an aside, the week before that, on May 
>> 12, 2014, we did discuss the w/HART join process protocol flows (at 
>> the time, intention was to agree to align flows with that used there, 
>> as motivated in the same email below).}
>>
>> While current discussions on w/HART protocol have been somewhat 
>> interesting, I feel we should put urgent priority on tackling those 
>> outstanding issues. So far, I have not seen any traffic on these 
>> items from others, so please weigh-in (please include outstanding 
>> item # in the subject line, e.g., "outstanding issue #c").
>>
>> Let us first tackle item #c) below on join process impact on the 
>> network. I am particularly interested in detailed deliberations on 
>> the three questions on this item that came to my mind here.
>>
>> When looking at this topic, I would like to encourage you to read the 
>> email thread on the IETF DICE list re draft-kumar-dice-dtls-relay-01, 
>> which is related to relaying nodes and potential DoS attacks. I 
>> initiated this discussion on May 27th, with last posting on May 30th. 
>> See http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>
>> Best regards, Rene
>>
>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>> Hi Michael:
>>>
>>> At the previous conf call of May 12, 2014, we discussed message 
>>> flows of w/HART join process, as also alluded to in my email below 
>>> (the specs could not be distributed due to copyright restrictions).
>>>
>>> In my mind, 6TiSCH protocol can use similar communication flows as 
>>> w/HART where only non-local communication flows (between joining 
>>> node and network manager) would be
>>> i) passing join/authentication information from joining node to 
>>> network manager (and back);
>>> ii) passing configuration parms from network manager to joining node 
>>> (keys, links, frame links) and neighbor report from joined node to 
>>> network manager.
>>>
>>> MAIN OUTSTANDING ISSUES (in my mind):
>>> a) Packet sizes:
>>> get more info on packet sizes configuration parms, as w/HART uses. 
>>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., 
>>> Dust Networks have info on packet sizes/structure?; ISA SP100.11a 
>>> metrics would also help, as would ZigBee 2.0 config parms. Does, 
>>> e.g., Cisco have useful data points here?
>>> b) Device Ids:
>>> With industrial control, network manager would look up "tag name" 
>>> device in pre-configured database. Details on tag name syntax, how 
>>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>>> aspects here?
>>> c) Join process impact on network:
>>> Pascal Thubert asked "when network would explode with join". Note 
>>> RS: the following questions come to mind:
>>> - how does joining  node find a time slot to send first join packet 
>>> to neighbor node (presumably, this would require listening for 
>>> Enhanced Beacon, but details on schedule in terms of time and 
>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>> and does not suggest a schedule that would create a common time 
>>> window where two devices would both be awake).
>>> - how does joining node negotiate a local schedule with neighbor 
>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>> refers to local schedule negotiation need, but unclear whether this 
>>> has been looked into in detail).
>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>> [that seems to have been designed with legacy w/HART in mind 
>>> (centralized solution). With centralized tree-like solution, lots of 
>>> traffic happens close to the root, thus potentially amplifying 
>>> congestion around root node (=network manager?).
>>> d) crypto protocol details of join protocol:
>>> Note RS: I can solve this (close to optimal design already done 
>>> [assuming I can do this "without hands tied behind the back"])
>>> e) authorization/trust management:
>>> it is here where binding of ids to public keys via certs and 
>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>> authorization messages. Note RS: question is whether ACE could play 
>>> a role here (current charter discussions seem to be endless, 
>>> though). As has been brought up before, a potential instantiation of 
>>> certs would be the use of 802.1ar certs, but this is certainly not 
>>> the only way of doing things.
>>>
>>> There are lots of other things we should consider, outside the join 
>>> protocol realm.
>>>
>>> ------- Original Message --------
>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>> 6tisch-security@ietf.org
>>>
>>>
>>>
>>> Hi Michael et al:
>>>
>>> Another topic worth exploring more is the join protocol details.
>>>
>>> (There are many other aspects, including certs, as you mentioned, 
>>> more general security architecture, provisioning, etc., but below 
>>> only deals with join.)
>>>
>>> With w/HART, the join process only interacts with the network 
>>> manager (62591, Annex A.3, Fig. A.1) for
>>> -forwarded join from joining node to network manager;
>>> -passing configuration parms from network manager to joining node 
>>> (keys, links, frame links) and neighbor report from joined node to 
>>> network manager.
>>> All other communications are local, between joining device and 
>>> neighbor (resp. with maintenance tool).
>>>
>>> It may have merit if we could use similar communication flows with 
>>> 6tisch, i.e., keep most traffic local to the joining device, except 
>>> for configuration parms exchange and authorization info passing.
>>>
>>> Most important consideration (from communication perspective) would 
>>> be that non-local traffic would be minimized, as also w/HART does. 
>>> From a marketing perspective, mimicking the communication flows 
>>> w/HART already has would keep all time scheduling considerations for 
>>> w/HART as currently there and 6TiSCH as to be detailed roughly the 
>>> same. This would longer term help in pushing 6tisch-style security 
>>> scheme to w/HART, since from a distance it looks the same (although 
>>> trying to scrap the maintenance tool).
>>>
>>> Of course, this does not deal with the details of the joining 
>>> protocol itself; only the flows.
>>>
>>> What about we look at some of the flows, and enumerate all issues 
>>> that need to be addressed here, both from a security perspective and 
>>> otherwise. We can then assign people to find missing information (I 
>>> am esp. curious about how devices know when to send/receive and 
>>> contributions of cycling efforts to total time latency).
>>>
>>> We could go over w/HART join flows during the call, to trigger these 
>>> questions.
>>>
>>> Best regards, Rene
>>>
>>>
>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>> That's 90 minutes from this email.
>>>>
>>>> 1) notewell.
>>>> 2) intros
>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>     it seems not?
>>>> 4) review of claim certificate process, vs EST with token.
>>>>
>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>
>>>> -- The URL to access the webex, which will we use for audio only:
>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>
>>>> -- we will resume with the etherpad at:
>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>
>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>> if you need more than that to get in, or are having difficulties.
>>>> Please make sure your audio works, and that you mute when not talking.
>>>>
>>>>
>>>> --
>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>   -= IPv6 IoT consulting =-
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> 6tisch-security mailing list
>>>> 6tisch-security@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>
>>>
>>> -- 
>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------080503050800000602070304
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Dear colleagues:<br>
    <br>
    Please find below some deliberations on outstanding item #c-3:<br>
    <br>
    With 802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13) includes
    the absolute slot number (ASN) and the Join Priority flag. <br>
    <br>
    Since a newly joining device has no way to validate whether the ASN
    entry advertised by the beaconing device corresponds to the one
    maintained by the PAN coordinator and there is only one macASN
    entry, joining nodes cannot rely on this ASN entry for frame
    security. As a result, the first message from a newbee node to the
    neighbor device should be unsecured. In particular, this should
    neither attempt to use a "well-known key".<br>
    <br>
    It is unclear how the join priority flag would help in facilitating
    resource optimization when a newly joining device tries and join the
    network. Perhaps, this flag was motivated by centralized solution
    ideas, where every device joins via the PAN coordinator? Suggestion
    is to completely ignore this joining priority flag.<br>
    <br>
    Best regards, Rene<br>
    <br>
    [excerpt of 802.15.4e-2012]<br>
    The ASN field contains the 5-octet Absolute Slot Number
    corresponding to the timeslot in which the<br>
    enhanced beacon is sent. The ASN is used as the Frame Counter for
    security operations if enabled. The 1-<br>
    octet Join Priority field can be used by a joining device to select
    among beaconing devices when multiple<br>
    beacons are heard. The PAN coordinator&#8217;s join priority is zero. A
    lower value of join priority indicates that<br>
    the device is the preferred one to connect to. The beaconing
    device&#8217;s join priority is the lowest join priority<br>
    heard when it joined the network plus one.<br>
    The TSCH Synchronization IE is used to construct enhanced beacons
    that allow new devices to synchronize<br>
    to a TSCH PAN.<br>
    <br>
    <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
      <div class="moz-cite-prefix"> ==<br>
        c) Join process impact on network: <br>
        Pascal Thubert asked "when network would explode with join".
        Note RS: the following questions come to mind:<br>
        c-1) how does joining&nbsp; node find a time slot to send first join
        packet to neighbor node (presumably, this would require
        listening for Enhanced Beacon, but details on schedule in terms
        of time and channels seems incomplete [min-schedule suggests
        101x15ms slotframe and "less than 10s repeat of EBs, but that
        leaves lots of dead time and does not suggest a schedule that
        would create a common time window where two devices would both
        be awake).<br>
        c-2)how does joining node negotiate a local schedule with
        neighbor node for execution of join protocol
        (draft-watteyne-6tisch-tisch-00 refers to local schedule
        negotiation need, but unclear whether this has been looked into
        in detail).<br>
        c-3) for local traffic (joining node/neighbor), it seems Pascal
        Thubert's "exploding network" may not happen easily.
        Nevertheless, unclear what impact of "join priority flag TSCH
        802.15.4e frames is [that seems to have been designed with
        legacy w/HART in mind (centralized solution). With centralized
        tree-like solution, lots of traffic happens close to the root,
        thus potentially amplifying congestion around root node
        (=network manager?).<br>
        <br>
        On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
      </div>
      <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Dear colleagues:<br>
          <br>
          Please find below a reminder of the outstanding issues re the
          join protocol, as I originally circulated three weeks ago,
          prior to our call on Tue May 20, 2014. {As an aside, the week
          before that, on May 12, 2014, we did discuss the w/HART join
          process protocol flows (at the time, intention was to agree to
          align flows with that used there, as motivated in the same
          email below).}<br>
          <br>
          While current discussions on w/HART protocol have been
          somewhat interesting, I feel we should put urgent priority on
          tackling those outstanding issues. So far, I have not seen any
          traffic on these items from others, so please weigh-in (please
          include outstanding item # in the subject line, e.g.,
          "outstanding issue #c").<br>
          <br>
          Let us first tackle item #c) below on join process impact on
          the network. I am particularly interested in detailed
          deliberations on the three questions on this item that came to
          my mind here.<br>
          <br>
          When looking at this topic, I would like to encourage you to
          read the email thread on the IETF DICE list re
          draft-kumar-dice-dtls-relay-01, which is related to relaying&nbsp;
          nodes and potential DoS attacks. I initiated this discussion
          on May 27th, with last posting on May 30th. See <a
            moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
          <br>
          Best regards, Rene<br>
          <br>
          On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
        </div>
        <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Hi Michael:<br>
            <br>
            At the previous conf call of May 12, 2014, we discussed
            message flows of w/HART join process, as also alluded to in
            my email below (the specs could not be distributed due to
            copyright restrictions).<br>
            <br>
            In my mind, 6TiSCH protocol can use similar communication
            flows as w/HART where only non-local communication flows
            (between joining node and network manager) would be <br>
            i) passing join/authentication information from joining node
            to network manager (and back);<br>
            ii) passing configuration parms from network manager to
            joining node (keys, links, frame links) and neighbor report
            from joined node to network manager.<br>
            <br>
            MAIN OUTSTANDING ISSUES (in my mind): <br>
            a) Packet sizes: <br>
            get more info on packet sizes configuration parms, as w/HART
            uses. Note RS: during call, Tom Phinney suggested contacting
            Wally Bratt from HART Comm. Foundation for this).&nbsp; Note RS:
            Shouldn't, e.g., Dust Networks have info on packet
            sizes/structure?; ISA SP100.11a metrics would also help, as
            would ZigBee 2.0 config parms. Does, e.g., Cisco have useful
            data points here?<br>
            b) Device Ids:<br>
            With industrial control, network manager would look up "tag
            name" device in pre-configured database. Details on tag name
            syntax, how assigned, and how bound to, e.g., EUI-64 are
            missing. Note RS: Perhaps, Tom Phinney could point at tag
            name syntax and lifecycle aspects here?<br>
            c) Join process impact on network: <br>
            Pascal Thubert asked "when network would explode with join".
            Note RS: the following questions come to mind:<br>
            - how does joining&nbsp; node find a time slot to send first join
            packet to neighbor node (presumably, this would require
            listening for Enhanced Beacon, but details on schedule in
            terms of time and channels seems incomplete [min-schedule
            suggests 101x15ms slotframe and "less than 10s repeat of
            EBs, but that leaves lots of dead time and does not suggest
            a schedule that would create a common time window where two
            devices would both be awake).<br>
            - how does joining node negotiate a local schedule with
            neighbor node for execution of join protocol
            (draft-watteyne-6tisch-tisch-00 refers to local schedule
            negotiation need, but unclear whether this has been looked
            into in detail).<br>
            - for local traffic (joining node/neighbor), it seems Pascal
            Thubert's "exploding network" may not happen easily.
            Nevertheless, unclear what impact of "join priority flag
            TSCH 802.15.4e frames is [that seems to have been designed
            with legacy w/HART in mind (centralized solution). With
            centralized tree-like solution, lots of traffic happens
            close to the root, thus potentially amplifying congestion
            around root node (=network manager?).<br>
            d) crypto protocol details of join protocol:<br>
            Note RS: I can solve this (close to optimal design already
            done [assuming I can do this "without hands tied behind the
            back"])<br>
            e) authorization/trust management:<br>
            it is here where binding of ids to public keys via certs and
            lifecycle aspects play a role, as well as syntax/semantics
            of authorization messages. Note RS: question is whether ACE
            could play a role here (current charter discussions seem to
            be endless, though). As has been brought up before, a
            potential instantiation of certs would be the use of 802.1ar
            certs, but this is certainly not the only way of doing
            things.<br>
            <br>
            There are lots of other things we should consider, outside
            the join protocol realm.<br>
            <br>
            ------- Original Message --------
            <table class="moz-email-headers-table" cellpadding="0"
              cellspacing="0" border="0">
              <tbody>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:



                  </th>
                  <td>Re: [6tisch-security] agenda(?) for call today</td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:


                  </th>
                  <td>Mon, 12 May 2014 09:53:37 -0400</td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:


                  </th>
                  <td>Rene Struik <a moz-do-not-send="true"
                      class="moz-txt-link-rfc2396E"
                      href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To:

                  </th>
                  <td>Michael Richardson <a moz-do-not-send="true"
                      class="moz-txt-link-rfc2396E"
                      href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                    <a moz-do-not-send="true"
                      class="moz-txt-link-abbreviated"
                      href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                </tr>
              </tbody>
            </table>
            <br>
            <br>
            <div class="moz-cite-prefix">Hi Michael et al:<br>
              <br>
              Another topic worth exploring more is the join protocol
              details. <br>
              <br>
              (There are many other aspects, including certs, as you
              mentioned, more general security architecture,
              provisioning, etc., but below only deals with join.)<br>
              <br>
              With w/HART, the join process only interacts with the
              network manager (62591, Annex A.3, Fig. A.1) for <br>
              -forwarded join from joining node to network manager;<br>
              -passing configuration parms from network manager to
              joining node (keys, links, frame links) and neighbor
              report from joined node to network manager.<br>
              All other communications are local, between joining device
              and neighbor (resp. with maintenance tool).<br>
              <br>
              It may have merit if we could use similar communication
              flows with 6tisch, i.e., keep most traffic local to the
              joining device, except for configuration parms exchange
              and authorization info passing. <br>
              <br>
              Most important consideration (from communication
              perspective) would be that non-local traffic would be
              minimized, as also w/HART does. From a marketing
              perspective, mimicking the communication flows w/HART
              already has would keep all time scheduling considerations
              for w/HART as currently there and 6TiSCH as to be detailed
              roughly the same. This would longer term help in pushing
              6tisch-style security scheme to w/HART, since from a
              distance it looks the same (although trying to scrap the
              maintenance tool).<br>
              <br>
              Of course, this does not deal with the details of the
              joining protocol itself; only the flows.<br>
              <br>
              What about we look at some of the flows, and enumerate all
              issues that need to be addressed here, both from a
              security perspective and otherwise. We can then assign
              people to find missing information (I am esp. curious
              about how devices know when to send/receive and
              contributions of cycling efforts to total time latency). <br>
              <br>
              We could go over w/HART join flows during the call, to
              trigger these questions.<br>
              <br>
              Best regards, Rene<br>
            </div>
            <br>
            <br>
            On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
          </div>
          <blockquote cite="mid:19475.1400588783@sandelman.ca"
            type="cite">
            <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
            <br>
            <fieldset class="mimeAttachmentHeader"></fieldset>
            <br>
            <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
          </blockquote>
          <br>
          <br>
          <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------080503050800000602070304--


From nobody Tue Jun 10 12:14:18 2014
Return-Path: <ksjp@berkeley.edu>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F3301A0239 for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 11:23:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9wsHR43Nenqp for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 11:23:38 -0700 (PDT)
Received: from mail-pa0-f43.google.com (mail-pa0-f43.google.com [209.85.220.43]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 458231A00BD for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 11:23:38 -0700 (PDT)
Received: by mail-pa0-f43.google.com with SMTP id rd3so968617pab.16 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 11:23:38 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=kTcEPp/DvI00QHAXXa7r81lxChSCF86bsVtEiyRsjwg=; b=hDu6HCSPsr1VB0hJMhXxIoD/YXJZaO1ys2I7jIlgy+JAoRTNPO2nqqiqSyJT+7MbR1 efSZkld40/+EAx6DyVf7af/2eec2qmPbPXe46DIA4mqHcrvMYZGdJzO+GgJcZnv7S0/b NGnYA/MGMYPMToWpJHxqncatQZs40qU2aBd38SUrBXvUiCI1qZ0VQR7n5L1aq/j6Q3Ct 4MftSSziFlhMMmMPm+eRVVQ9iCueVf80XrO0Bi7G6cLDjXUOTIgd8j382jHRO760829/ RNHetZYJag7ceynso7+KtZ5SUty8+PKrja0IT9Q3ZZQBh2+xkmQtWYP8b59F272HWCcF LPfw==
X-Gm-Message-State: ALoCoQkApHfZl0lG+H/hONP6LMVxYMDWPumFjrvR2iqeDrwZMyLvZPTtRjRSoHh1JzFJvWXhYTEB
X-Received: by 10.68.103.165 with SMTP id fx5mr13629675pbb.118.1402424617876;  Tue, 10 Jun 2014 11:23:37 -0700 (PDT)
Received: from [10.70.192.54] ([134.24.149.4]) by mx.google.com with ESMTPSA id au4sm70771898pbc.10.2014.06.10.11.23.36 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 10 Jun 2014 11:23:37 -0700 (PDT)
Message-ID: <53974D26.5080504@berkeley.edu>
Date: Tue, 10 Jun 2014 11:23:34 -0700
From: Kris Pister <ksjp@berkeley.edu>
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com>
In-Reply-To: <53971920.3070400@gmail.com>
Content-Type: multipart/alternative; boundary="------------090807080707070606060605"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/PHoSSKfewsbQ_ZZEf_tI4_Xky-4
X-Mailman-Approved-At: Tue, 10 Jun 2014 12:13:55 -0700
Subject: Re: [6tisch-security] tackling outstanding issues #c-2
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 18:23:41 -0000

This is a multi-part message in MIME format.
--------------090807080707070606060605
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

At some level, the answer is that the security should not care how the 
MAC layer is doing its job,
as long as the packets get through.  But I agree that it is useful to 
see how all of this is going to
work together.
In the case of minimal, the MAC layer doesn't need to "find" anything.  
Once it has heard an EB,
it knows that every N slots there will be a TX/RX cell that it can use.  
If it has nothing to send, it
MUST listen.  If it sends and collides, there is a backoff strategy and 
it tries again.  Again, this
is all transparent to the security processing.
The choice of N determines latency, power, available BW, etc.  Best 
case, motes in the same
RF space can send one packet every N*T_slot seconds.  Lots of papers 
have been
written about the bad things that happen if you try to shove too much 
traffic through a
network with limited resources.  Minimal will look like slotted aloha, 
(possibly with some
slightly better performance from preamble capture, maybe CCA, ...), 
namely a normalized
maximum goodput of GP=1/e with an offered load of G=1.  Running any 
aloha-like network
near that maximum is very dangerous (chaotic collapse ensues unless 
higher layers are smart),
so a practical useful normalized goodput of 0.2 is more realistic and 
more energy efficient.

If N=20, and T_slot=10ms, the network will happily support 
0.2/(N*T_slot) = 1 packet per second
among all motes in the same RF space.  If N=101 and T_slot=15ms, then 
it's closer to 1 packet
every 8 seconds.  That means that it will take a *long* time for a large 
dense network to form, which
is why we call it "minimal" instead of "optimal" :)
Something in the N=10...100 slots is still probably fine for, e.g., a 
simple static home network.

ksjp

On 6/10/2014 7:41 AM, Rene Struik wrote:
> Dear colleagues:
>
> Assumptions:
> - Joining node has a minimum schedule (with 101x15ms slotframe) and 
> somehow was able to find a time slot to send a first join packet to a 
> neighbor node (c-1).
> - Computational and communication time latency for response packet 
> from neighbor node to joining node is 15ms, 150ms, 750ms, or 5s 
> (depending on device capabilities, implementation detail)
> - Computational time latency for joining node to compute shared key is 
> 15ms, 150ms, 750ms, or 5s (depending on device capabilities, 
> implementation detail)
>
> So, now for question c-2 below:
> - How does joining node find out when to open its receiver again, so 
> as to receive response packet from neighbor node
> - How does neighbor node find out when to receive second packet flow 
> from joining node (i.e., after joining node computed shared key)
> In particular, should the local schedule allocate multiples of 15ms 
> (i.e., each timeslot), 150ms, etc. Obviously, the denser the schedule 
> the fewer capacity in terms of #joining nodes that can be served?
>
> So, perhaps, the background of my question c-2 is  now unambiguously 
> clear...
>
> ==
> c) Join process impact on network:
> Pascal Thubert asked "when network would explode with join". Note RS: 
> the following questions come to mind:
> c-1) how does joining  node find a time slot to send first join packet 
> to neighbor node (presumably, this would require listening for 
> Enhanced Beacon, but details on schedule in terms of time and channels 
> seems incomplete [min-schedule suggests 101x15ms slotframe and "less 
> than 10s repeat of EBs, but that leaves lots of dead time and does not 
> suggest a schedule that would create a common time window where two 
> devices would both be awake).
> c-2)how does joining node negotiate a local schedule with neighbor 
> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
> refers to local schedule negotiation need, but unclear whether this 
> has been looked into in detail).
> c-3) for local traffic (joining node/neighbor), it seems Pascal 
> Thubert's "exploding network" may not happen easily. Nevertheless, 
> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
> [that seems to have been designed with legacy w/HART in mind 
> (centralized solution). With centralized tree-like solution, lots of 
> traffic happens close to the root, thus potentially amplifying 
> congestion around root node (=network manager?).
>
> On 6/9/2014 11:51 AM, Rene Struik wrote:
>> Dear colleagues:
>>
>> Please find below a reminder of the outstanding issues re the join 
>> protocol, as I originally circulated three weeks ago, prior to our 
>> call on Tue May 20, 2014. {As an aside, the week before that, on May 
>> 12, 2014, we did discuss the w/HART join process protocol flows (at 
>> the time, intention was to agree to align flows with that used there, 
>> as motivated in the same email below).}
>>
>> While current discussions on w/HART protocol have been somewhat 
>> interesting, I feel we should put urgent priority on tackling those 
>> outstanding issues. So far, I have not seen any traffic on these 
>> items from others, so please weigh-in (please include outstanding 
>> item # in the subject line, e.g., "outstanding issue #c").
>>
>> Let us first tackle item #c) below on join process impact on the 
>> network. I am particularly interested in detailed deliberations on 
>> the three questions on this item that came to my mind here.
>>
>> When looking at this topic, I would like to encourage you to read the 
>> email thread on the IETF DICE list re draft-kumar-dice-dtls-relay-01, 
>> which is related to relaying nodes and potential DoS attacks. I 
>> initiated this discussion on May 27th, with last posting on May 30th. 
>> See http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>
>> Best regards, Rene
>>
>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>> Hi Michael:
>>>
>>> At the previous conf call of May 12, 2014, we discussed message 
>>> flows of w/HART join process, as also alluded to in my email below 
>>> (the specs could not be distributed due to copyright restrictions).
>>>
>>> In my mind, 6TiSCH protocol can use similar communication flows as 
>>> w/HART where only non-local communication flows (between joining 
>>> node and network manager) would be
>>> i) passing join/authentication information from joining node to 
>>> network manager (and back);
>>> ii) passing configuration parms from network manager to joining node 
>>> (keys, links, frame links) and neighbor report from joined node to 
>>> network manager.
>>>
>>> MAIN OUTSTANDING ISSUES (in my mind):
>>> a) Packet sizes:
>>> get more info on packet sizes configuration parms, as w/HART uses. 
>>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., 
>>> Dust Networks have info on packet sizes/structure?; ISA SP100.11a 
>>> metrics would also help, as would ZigBee 2.0 config parms. Does, 
>>> e.g., Cisco have useful data points here?
>>> b) Device Ids:
>>> With industrial control, network manager would look up "tag name" 
>>> device in pre-configured database. Details on tag name syntax, how 
>>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>>> aspects here?
>>> c) Join process impact on network:
>>> Pascal Thubert asked "when network would explode with join". Note 
>>> RS: the following questions come to mind:
>>> - how does joining  node find a time slot to send first join packet 
>>> to neighbor node (presumably, this would require listening for 
>>> Enhanced Beacon, but details on schedule in terms of time and 
>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>> and does not suggest a schedule that would create a common time 
>>> window where two devices would both be awake).
>>> - how does joining node negotiate a local schedule with neighbor 
>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>> refers to local schedule negotiation need, but unclear whether this 
>>> has been looked into in detail).
>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>> [that seems to have been designed with legacy w/HART in mind 
>>> (centralized solution). With centralized tree-like solution, lots of 
>>> traffic happens close to the root, thus potentially amplifying 
>>> congestion around root node (=network manager?).
>>> d) crypto protocol details of join protocol:
>>> Note RS: I can solve this (close to optimal design already done 
>>> [assuming I can do this "without hands tied behind the back"])
>>> e) authorization/trust management:
>>> it is here where binding of ids to public keys via certs and 
>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>> authorization messages. Note RS: question is whether ACE could play 
>>> a role here (current charter discussions seem to be endless, 
>>> though). As has been brought up before, a potential instantiation of 
>>> certs would be the use of 802.1ar certs, but this is certainly not 
>>> the only way of doing things.
>>>
>>> There are lots of other things we should consider, outside the join 
>>> protocol realm.
>>>
>>> ------- Original Message --------
>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>> 6tisch-security@ietf.org
>>>
>>>
>>>
>>> Hi Michael et al:
>>>
>>> Another topic worth exploring more is the join protocol details.
>>>
>>> (There are many other aspects, including certs, as you mentioned, 
>>> more general security architecture, provisioning, etc., but below 
>>> only deals with join.)
>>>
>>> With w/HART, the join process only interacts with the network 
>>> manager (62591, Annex A.3, Fig. A.1) for
>>> -forwarded join from joining node to network manager;
>>> -passing configuration parms from network manager to joining node 
>>> (keys, links, frame links) and neighbor report from joined node to 
>>> network manager.
>>> All other communications are local, between joining device and 
>>> neighbor (resp. with maintenance tool).
>>>
>>> It may have merit if we could use similar communication flows with 
>>> 6tisch, i.e., keep most traffic local to the joining device, except 
>>> for configuration parms exchange and authorization info passing.
>>>
>>> Most important consideration (from communication perspective) would 
>>> be that non-local traffic would be minimized, as also w/HART does. 
>>> From a marketing perspective, mimicking the communication flows 
>>> w/HART already has would keep all time scheduling considerations for 
>>> w/HART as currently there and 6TiSCH as to be detailed roughly the 
>>> same. This would longer term help in pushing 6tisch-style security 
>>> scheme to w/HART, since from a distance it looks the same (although 
>>> trying to scrap the maintenance tool).
>>>
>>> Of course, this does not deal with the details of the joining 
>>> protocol itself; only the flows.
>>>
>>> What about we look at some of the flows, and enumerate all issues 
>>> that need to be addressed here, both from a security perspective and 
>>> otherwise. We can then assign people to find missing information (I 
>>> am esp. curious about how devices know when to send/receive and 
>>> contributions of cycling efforts to total time latency).
>>>
>>> We could go over w/HART join flows during the call, to trigger these 
>>> questions.
>>>
>>> Best regards, Rene
>>>
>>>
>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>> That's 90 minutes from this email.
>>>>
>>>> 1) notewell.
>>>> 2) intros
>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>     it seems not?
>>>> 4) review of claim certificate process, vs EST with token.
>>>>
>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>
>>>> -- The URL to access the webex, which will we use for audio only:
>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>
>>>> -- we will resume with the etherpad at:
>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>
>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>> if you need more than that to get in, or are having difficulties.
>>>> Please make sure your audio works, and that you mute when not talking.
>>>>
>>>>
>>>> --
>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>   -= IPv6 IoT consulting =-
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> 6tisch-security mailing list
>>>> 6tisch-security@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>
>>>
>>> -- 
>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


--------------090807080707070606060605
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    At some level, the answer is that the security should not care how
    the MAC layer is doing its job,<br>
    as long as the packets get through.&nbsp; But I agree that it is useful
    to see how all of this is going to<br>
    work together.<br>
    In the case of minimal, the MAC layer doesn't need to "find"
    anything.&nbsp; Once it has heard an EB,<br>
    it knows that every N slots there will be a TX/RX cell that it can
    use.&nbsp; If it has nothing to send, it<br>
    MUST listen.&nbsp; If it sends and collides, there is a backoff strategy
    and it tries again.&nbsp; Again, this<br>
    is all transparent to the security processing.<br>
    The choice of N determines latency, power, available BW, etc.&nbsp; Best
    case, motes in the same<br>
    RF space can send one packet every N*T_slot seconds.&nbsp; Lots of papers
    have been <br>
    written about the bad things that happen if you try to shove too
    much traffic through a <br>
    network with limited resources.&nbsp; Minimal will look like slotted
    aloha, (possibly with some <br>
    slightly better performance from preamble capture, maybe CCA, ...),
    namely a normalized<br>
    maximum goodput of GP=1/e with an offered load of G=1.&nbsp; Running any
    aloha-like network<br>
    near that maximum is very dangerous (chaotic collapse ensues unless
    higher layers are smart),<br>
    so a practical useful normalized goodput of 0.2 is more realistic
    and more energy efficient.<br>
    <br>
    If N=20, and T_slot=10ms, the network will happily support
    0.2/(N*T_slot) = 1 packet per second<br>
    among all motes in the same RF space.&nbsp; If N=101 and T_slot=15ms,
    then it's closer to 1 packet<br>
    every 8 seconds.&nbsp; That means that it will take a *long* time for a
    large dense network to form, which<br>
    is why we call it "minimal" instead of "optimal" :)<br>
    Something in the N=10...100 slots is still probably fine for, e.g.,
    a simple static home network.<br>
    <br>
    ksjp<br>
    <br>
    <div class="moz-cite-prefix">On 6/10/2014 7:41 AM, Rene Struik
      wrote:<br>
    </div>
    <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Dear colleagues:<br>
        <br>
        Assumptions:<br>
        - Joining node has a minimum schedule (with 101x15ms slotframe)
        and somehow was able to find a time slot to send a first join
        packet to a neighbor node (c-1).<br>
        - Computational and communication time latency for response
        packet from neighbor node to joining node is 15ms, 150ms, 750ms,
        or 5s (depending on device capabilities, implementation detail)<br>
        - Computational time latency for joining node to compute shared
        key is 15ms, 150ms, 750ms, or 5s (depending on device
        capabilities, implementation detail)<br>
        <br>
        So, now for question c-2 below:<br>
        - How does joining node find out when to open its receiver
        again, so as to receive response packet from neighbor node<br>
        - How does neighbor node find out when to receive second packet
        flow from joining node (i.e., after joining node computed shared
        key)<br>
        In particular, should the local schedule allocate multiples of
        15ms (i.e., each timeslot), 150ms, etc. Obviously, the denser
        the schedule the fewer capacity in terms of #joining nodes that
        can be served?<br>
        <br>
        So, perhaps, the background of my question c-2 is&nbsp; now
        unambiguously clear...<br>
        <br>
        ==<br>
        c) Join process impact on network: <br>
        Pascal Thubert asked "when network would explode with join".
        Note RS: the following questions come to mind:<br>
        c-1) how does joining&nbsp; node find a time slot to send first join
        packet to neighbor node (presumably, this would require
        listening for Enhanced Beacon, but details on schedule in terms
        of time and channels seems incomplete [min-schedule suggests
        101x15ms slotframe and "less than 10s repeat of EBs, but that
        leaves lots of dead time and does not suggest a schedule that
        would create a common time window where two devices would both
        be awake).<br>
        c-2)how does joining node negotiate a local schedule with
        neighbor node for execution of join protocol
        (draft-watteyne-6tisch-tisch-00 refers to local schedule
        negotiation need, but unclear whether this has been looked into
        in detail).<br>
        c-3) for local traffic (joining node/neighbor), it seems Pascal
        Thubert's "exploding network" may not happen easily.
        Nevertheless, unclear what impact of "join priority flag TSCH
        802.15.4e frames is [that seems to have been designed with
        legacy w/HART in mind (centralized solution). With centralized
        tree-like solution, lots of traffic happens close to the root,
        thus potentially amplifying congestion around root node
        (=network manager?).<br>
        <br>
        On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
      </div>
      <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Dear colleagues:<br>
          <br>
          Please find below a reminder of the outstanding issues re the
          join protocol, as I originally circulated three weeks ago,
          prior to our call on Tue May 20, 2014. {As an aside, the week
          before that, on May 12, 2014, we did discuss the w/HART join
          process protocol flows (at the time, intention was to agree to
          align flows with that used there, as motivated in the same
          email below).}<br>
          <br>
          While current discussions on w/HART protocol have been
          somewhat interesting, I feel we should put urgent priority on
          tackling those outstanding issues. So far, I have not seen any
          traffic on these items from others, so please weigh-in (please
          include outstanding item # in the subject line, e.g.,
          "outstanding issue #c").<br>
          <br>
          Let us first tackle item #c) below on join process impact on
          the network. I am particularly interested in detailed
          deliberations on the three questions on this item that came to
          my mind here.<br>
          <br>
          When looking at this topic, I would like to encourage you to
          read the email thread on the IETF DICE list re
          draft-kumar-dice-dtls-relay-01, which is related to relaying&nbsp;
          nodes and potential DoS attacks. I initiated this discussion
          on May 27th, with last posting on May 30th. See <a
            moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
          <br>
          Best regards, Rene<br>
          <br>
          On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
        </div>
        <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Hi Michael:<br>
            <br>
            At the previous conf call of May 12, 2014, we discussed
            message flows of w/HART join process, as also alluded to in
            my email below (the specs could not be distributed due to
            copyright restrictions).<br>
            <br>
            In my mind, 6TiSCH protocol can use similar communication
            flows as w/HART where only non-local communication flows
            (between joining node and network manager) would be <br>
            i) passing join/authentication information from joining node
            to network manager (and back);<br>
            ii) passing configuration parms from network manager to
            joining node (keys, links, frame links) and neighbor report
            from joined node to network manager.<br>
            <br>
            MAIN OUTSTANDING ISSUES (in my mind): <br>
            a) Packet sizes: <br>
            get more info on packet sizes configuration parms, as w/HART
            uses. Note RS: during call, Tom Phinney suggested contacting
            Wally Bratt from HART Comm. Foundation for this).&nbsp; Note RS:
            Shouldn't, e.g., Dust Networks have info on packet
            sizes/structure?; ISA SP100.11a metrics would also help, as
            would ZigBee 2.0 config parms. Does, e.g., Cisco have useful
            data points here?<br>
            b) Device Ids:<br>
            With industrial control, network manager would look up "tag
            name" device in pre-configured database. Details on tag name
            syntax, how assigned, and how bound to, e.g., EUI-64 are
            missing. Note RS: Perhaps, Tom Phinney could point at tag
            name syntax and lifecycle aspects here?<br>
            c) Join process impact on network: <br>
            Pascal Thubert asked "when network would explode with join".
            Note RS: the following questions come to mind:<br>
            - how does joining&nbsp; node find a time slot to send first join
            packet to neighbor node (presumably, this would require
            listening for Enhanced Beacon, but details on schedule in
            terms of time and channels seems incomplete [min-schedule
            suggests 101x15ms slotframe and "less than 10s repeat of
            EBs, but that leaves lots of dead time and does not suggest
            a schedule that would create a common time window where two
            devices would both be awake).<br>
            - how does joining node negotiate a local schedule with
            neighbor node for execution of join protocol
            (draft-watteyne-6tisch-tisch-00 refers to local schedule
            negotiation need, but unclear whether this has been looked
            into in detail).<br>
            - for local traffic (joining node/neighbor), it seems Pascal
            Thubert's "exploding network" may not happen easily.
            Nevertheless, unclear what impact of "join priority flag
            TSCH 802.15.4e frames is [that seems to have been designed
            with legacy w/HART in mind (centralized solution). With
            centralized tree-like solution, lots of traffic happens
            close to the root, thus potentially amplifying congestion
            around root node (=network manager?).<br>
            d) crypto protocol details of join protocol:<br>
            Note RS: I can solve this (close to optimal design already
            done [assuming I can do this "without hands tied behind the
            back"])<br>
            e) authorization/trust management:<br>
            it is here where binding of ids to public keys via certs and
            lifecycle aspects play a role, as well as syntax/semantics
            of authorization messages. Note RS: question is whether ACE
            could play a role here (current charter discussions seem to
            be endless, though). As has been brought up before, a
            potential instantiation of certs would be the use of 802.1ar
            certs, but this is certainly not the only way of doing
            things.<br>
            <br>
            There are lots of other things we should consider, outside
            the join protocol realm.<br>
            <br>
            ------- Original Message --------
            <table class="moz-email-headers-table" border="0"
              cellpadding="0" cellspacing="0">
              <tbody>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:



                  </th>
                  <td>Re: [6tisch-security] agenda(?) for call today</td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:


                  </th>
                  <td>Mon, 12 May 2014 09:53:37 -0400</td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:


                  </th>
                  <td>Rene Struik <a moz-do-not-send="true"
                      class="moz-txt-link-rfc2396E"
                      href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                </tr>
                <tr>
                  <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To:

                  </th>
                  <td>Michael Richardson <a moz-do-not-send="true"
                      class="moz-txt-link-rfc2396E"
                      href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                    <a moz-do-not-send="true"
                      class="moz-txt-link-abbreviated"
                      href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                </tr>
              </tbody>
            </table>
            <br>
            <br>
            <div class="moz-cite-prefix">Hi Michael et al:<br>
              <br>
              Another topic worth exploring more is the join protocol
              details. <br>
              <br>
              (There are many other aspects, including certs, as you
              mentioned, more general security architecture,
              provisioning, etc., but below only deals with join.)<br>
              <br>
              With w/HART, the join process only interacts with the
              network manager (62591, Annex A.3, Fig. A.1) for <br>
              -forwarded join from joining node to network manager;<br>
              -passing configuration parms from network manager to
              joining node (keys, links, frame links) and neighbor
              report from joined node to network manager.<br>
              All other communications are local, between joining device
              and neighbor (resp. with maintenance tool).<br>
              <br>
              It may have merit if we could use similar communication
              flows with 6tisch, i.e., keep most traffic local to the
              joining device, except for configuration parms exchange
              and authorization info passing. <br>
              <br>
              Most important consideration (from communication
              perspective) would be that non-local traffic would be
              minimized, as also w/HART does. From a marketing
              perspective, mimicking the communication flows w/HART
              already has would keep all time scheduling considerations
              for w/HART as currently there and 6TiSCH as to be detailed
              roughly the same. This would longer term help in pushing
              6tisch-style security scheme to w/HART, since from a
              distance it looks the same (although trying to scrap the
              maintenance tool).<br>
              <br>
              Of course, this does not deal with the details of the
              joining protocol itself; only the flows.<br>
              <br>
              What about we look at some of the flows, and enumerate all
              issues that need to be addressed here, both from a
              security perspective and otherwise. We can then assign
              people to find missing information (I am esp. curious
              about how devices know when to send/receive and
              contributions of cycling efforts to total time latency). <br>
              <br>
              We could go over w/HART join flows during the call, to
              trigger these questions.<br>
              <br>
              Best regards, Rene<br>
            </div>
            <br>
            <br>
            On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
          </div>
          <blockquote cite="mid:19475.1400588783@sandelman.ca"
            type="cite">
            <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
            <br>
            <fieldset class="mimeAttachmentHeader"></fieldset>
            <br>
            <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
          </blockquote>
          <br>
          <br>
          <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------090807080707070606060605--


From nobody Tue Jun 10 13:50:34 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1E86F1A042D for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 13:50:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VpRtOMQLyXwF for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 13:50:08 -0700 (PDT)
Received: from mail-ig0-x236.google.com (mail-ig0-x236.google.com [IPv6:2607:f8b0:4001:c05::236]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F1AC1A02FB for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 13:50:08 -0700 (PDT)
Received: by mail-ig0-f182.google.com with SMTP id a13so5652785igq.15 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 13:50:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=XKnsprVfH+MyNESHq1z8jiJFwi2GyRhegKFOXQzxsQc=; b=Px11FOizeLoUNO8AvszIqDB4PXhG/LVBDCxO7K9ixBjzFdDwAhZzr5qMf4UfQHi2eT OgVVJHOKIbqHtdaYgtylmumnt8lZpdHdyB0RVXXbY4wEWG/9m3Gcz3xv/agoKB3bRZpQ 72r4dSD+XS8t1OT0wCAleHCc/OURHgE6Qd7jLQavae602k7gT6/walZx8Sn6vK9nSTai wcdxCwwnzCV//acKKfnRwb/qjX3TluQtwYkTBF3ZgrwrOG8y5a9fpLl2l7a1Zv4JiwEe a6Z0WQZSTUXVxv7ikBW1M6yqrT6NxgWDRt6z7ad/yNkcWm59wqP2JNbZNP5e+5F+YGME J+Cg==
X-Received: by 10.50.21.104 with SMTP id u8mr47539073ige.1.1402433407967; Tue, 10 Jun 2014 13:50:07 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id g3sm15926351igc.11.2014.06.10.13.50.06 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 10 Jun 2014 13:50:07 -0700 (PDT)
Message-ID: <53976F7B.7040003@gmail.com>
Date: Tue, 10 Jun 2014 16:50:03 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Kris Pister <ksjp@berkeley.edu>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com> <53974D26.5080504@berkeley.edu>
In-Reply-To: <53974D26.5080504@berkeley.edu>
Content-Type: multipart/alternative; boundary="------------040600050706010301030403"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/fS9CagqwKMs0fI83ioG8G13f7S4
Subject: Re: [6tisch-security] tackling outstanding issues #c-2
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 20:50:13 -0000

This is a multi-part message in MIME format.
--------------040600050706010301030403
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Hi Kris:

Thanks for the quick feedback.

When designing a security protocol, one has to consider not just 
cryptographic properties, but also implementation cost, such as energy 
cost, RAM/ROM usage, and computational and communication time latency. 
Thus, while one might argue that "security should not care how the MAC 
layer is doing its job", this only seems to hold true if one is not 
interested in non-crypto performance metrics. To implementation-specific 
metrics mentioned above, one should add potential impact of traffic that 
seems to be legitimate, but in hindsight does not turn out to be that 
way (both in terms of denial-of-service attacks, keeping state, etc.). 
Hence, my question.

So, communication aspects may be quite interesting to consider in 
detail, e.g., in the context of message relay (see, e.g., DICE WG 
mailing list, May 30, 2014, 10:29am EDT ---
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html):
>> So, I am still interested in getting more insight as to how the relay 
>> on/off switch would work in practice (which was the question in my 
>> original email of Tue [snippet copied below]). A description of 
>> device join operations would help (say, with operational network of 
>> 1000 nodes with diameter 20 hops, where one wishes to add a newbee 
>> node A at neighbor B, where B is 10 hops away from network manager T).
 From what you suggested below, if one takes slotframe of N=101 
timeslots of T_slot=15ms, then "goodput" of 1 packet per 8 seconds seems 
feasible. Does this mean that if one has a network manager 10 hops away 
(my DICE example above), that the communication latency from joining 
node to and from the network manager is 2*10*8 seconds =160 seconds or 
roughly 2 1/2 minutes and with that between neighbors this is 2*1*8 = 16 
seconds? If so, the communication cost seem to far outstrip any other 
time latency cost (including that due to computational overhead). Please 
correct me if I am wrong here.

If this is so, this begs the question as to coming up with tricks to 
squeeze more "bang for the buck" out of TSCH schedules, in case one 
executes a join protocol. As an example, if one does not use ACK'ed 
messages (which seems possible with interactive protocols) but - instead 
- squeezes an extra frame into that particular time/channel slot in the 
TSCH matrix, one seems to be able to potentially improve time latency by 
a factor 2x and get enormous time latencies of 2 1/2 minutes, resp. 16 
seconds, down to 80, resp. 8 seconds.

This is just to illustrate that there is more to security design than 
meets the eye at first.

Any thoughts?

Rene

On 6/10/2014 2:23 PM, Kris Pister wrote:
> At some level, the answer is that the security should not care how the 
> MAC layer is doing its job,
> as long as the packets get through.  But I agree that it is useful to 
> see how all of this is going to
> work together.
> In the case of minimal, the MAC layer doesn't need to "find" 
> anything.  Once it has heard an EB,
> it knows that every N slots there will be a TX/RX cell that it can 
> use.  If it has nothing to send, it
> MUST listen.  If it sends and collides, there is a backoff strategy 
> and it tries again.  Again, this
> is all transparent to the security processing.
> The choice of N determines latency, power, available BW, etc. Best 
> case, motes in the same
> RF space can send one packet every N*T_slot seconds.  Lots of papers 
> have been
> written about the bad things that happen if you try to shove too much 
> traffic through a
> network with limited resources.  Minimal will look like slotted aloha, 
> (possibly with some
> slightly better performance from preamble capture, maybe CCA, ...), 
> namely a normalized
> maximum goodput of GP=1/e with an offered load of G=1.  Running any 
> aloha-like network
> near that maximum is very dangerous (chaotic collapse ensues unless 
> higher layers are smart),
> so a practical useful normalized goodput of 0.2 is more realistic and 
> more energy efficient.
>
> If N=20, and T_slot=10ms, the network will happily support 
> 0.2/(N*T_slot) = 1 packet per second
> among all motes in the same RF space.  If N=101 and T_slot=15ms, then 
> it's closer to 1 packet
> every 8 seconds.  That means that it will take a *long* time for a 
> large dense network to form, which
> is why we call it "minimal" instead of "optimal" :)
> Something in the N=10...100 slots is still probably fine for, e.g., a 
> simple static home network.
>
> ksjp
>
> On 6/10/2014 7:41 AM, Rene Struik wrote:
>> Dear colleagues:
>>
>> Assumptions:
>> - Joining node has a minimum schedule (with 101x15ms slotframe) and 
>> somehow was able to find a time slot to send a first join packet to a 
>> neighbor node (c-1).
>> - Computational and communication time latency for response packet 
>> from neighbor node to joining node is 15ms, 150ms, 750ms, or 5s 
>> (depending on device capabilities, implementation detail)
>> - Computational time latency for joining node to compute shared key 
>> is 15ms, 150ms, 750ms, or 5s (depending on device capabilities, 
>> implementation detail)
>>
>> So, now for question c-2 below:
>> - How does joining node find out when to open its receiver again, so 
>> as to receive response packet from neighbor node
>> - How does neighbor node find out when to receive second packet flow 
>> from joining node (i.e., after joining node computed shared key)
>> In particular, should the local schedule allocate multiples of 15ms 
>> (i.e., each timeslot), 150ms, etc. Obviously, the denser the schedule 
>> the fewer capacity in terms of #joining nodes that can be served?
>>
>> So, perhaps, the background of my question c-2 is  now unambiguously 
>> clear...
>>
>> ==
>> c) Join process impact on network:
>> Pascal Thubert asked "when network would explode with join". Note RS: 
>> the following questions come to mind:
>> c-1) how does joining  node find a time slot to send first join 
>> packet to neighbor node (presumably, this would require listening for 
>> Enhanced Beacon, but details on schedule in terms of time and 
>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>> and does not suggest a schedule that would create a common time 
>> window where two devices would both be awake).
>> c-2)how does joining node negotiate a local schedule with neighbor 
>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>> refers to local schedule negotiation need, but unclear whether this 
>> has been looked into in detail).
>> c-3) for local traffic (joining node/neighbor), it seems Pascal 
>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>> [that seems to have been designed with legacy w/HART in mind 
>> (centralized solution). With centralized tree-like solution, lots of 
>> traffic happens close to the root, thus potentially amplifying 
>> congestion around root node (=network manager?).
>>
>> On 6/9/2014 11:51 AM, Rene Struik wrote:
>>> Dear colleagues:
>>>
>>> Please find below a reminder of the outstanding issues re the join 
>>> protocol, as I originally circulated three weeks ago, prior to our 
>>> call on Tue May 20, 2014. {As an aside, the week before that, on May 
>>> 12, 2014, we did discuss the w/HART join process protocol flows (at 
>>> the time, intention was to agree to align flows with that used 
>>> there, as motivated in the same email below).}
>>>
>>> While current discussions on w/HART protocol have been somewhat 
>>> interesting, I feel we should put urgent priority on tackling those 
>>> outstanding issues. So far, I have not seen any traffic on these 
>>> items from others, so please weigh-in (please include outstanding 
>>> item # in the subject line, e.g., "outstanding issue #c").
>>>
>>> Let us first tackle item #c) below on join process impact on the 
>>> network. I am particularly interested in detailed deliberations on 
>>> the three questions on this item that came to my mind here.
>>>
>>> When looking at this topic, I would like to encourage you to read 
>>> the email thread on the IETF DICE list re 
>>> draft-kumar-dice-dtls-relay-01, which is related to relaying  nodes 
>>> and potential DoS attacks. I initiated this discussion on May 27th, 
>>> with last posting on May 30th. See 
>>> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>>
>>> Best regards, Rene
>>>
>>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>>> Hi Michael:
>>>>
>>>> At the previous conf call of May 12, 2014, we discussed message 
>>>> flows of w/HART join process, as also alluded to in my email below 
>>>> (the specs could not be distributed due to copyright restrictions).
>>>>
>>>> In my mind, 6TiSCH protocol can use similar communication flows as 
>>>> w/HART where only non-local communication flows (between joining 
>>>> node and network manager) would be
>>>> i) passing join/authentication information from joining node to 
>>>> network manager (and back);
>>>> ii) passing configuration parms from network manager to joining 
>>>> node (keys, links, frame links) and neighbor report from joined 
>>>> node to network manager.
>>>>
>>>> MAIN OUTSTANDING ISSUES (in my mind):
>>>> a) Packet sizes:
>>>> get more info on packet sizes configuration parms, as w/HART uses. 
>>>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>>>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., 
>>>> Dust Networks have info on packet sizes/structure?; ISA SP100.11a 
>>>> metrics would also help, as would ZigBee 2.0 config parms. Does, 
>>>> e.g., Cisco have useful data points here?
>>>> b) Device Ids:
>>>> With industrial control, network manager would look up "tag name" 
>>>> device in pre-configured database. Details on tag name syntax, how 
>>>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>>>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>>>> aspects here?
>>>> c) Join process impact on network:
>>>> Pascal Thubert asked "when network would explode with join". Note 
>>>> RS: the following questions come to mind:
>>>> - how does joining  node find a time slot to send first join packet 
>>>> to neighbor node (presumably, this would require listening for 
>>>> Enhanced Beacon, but details on schedule in terms of time and 
>>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>>> and does not suggest a schedule that would create a common time 
>>>> window where two devices would both be awake).
>>>> - how does joining node negotiate a local schedule with neighbor 
>>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>>> refers to local schedule negotiation need, but unclear whether this 
>>>> has been looked into in detail).
>>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>>> [that seems to have been designed with legacy w/HART in mind 
>>>> (centralized solution). With centralized tree-like solution, lots 
>>>> of traffic happens close to the root, thus potentially amplifying 
>>>> congestion around root node (=network manager?).
>>>> d) crypto protocol details of join protocol:
>>>> Note RS: I can solve this (close to optimal design already done 
>>>> [assuming I can do this "without hands tied behind the back"])
>>>> e) authorization/trust management:
>>>> it is here where binding of ids to public keys via certs and 
>>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>>> authorization messages. Note RS: question is whether ACE could play 
>>>> a role here (current charter discussions seem to be endless, 
>>>> though). As has been brought up before, a potential instantiation 
>>>> of certs would be the use of 802.1ar certs, but this is certainly 
>>>> not the only way of doing things.
>>>>
>>>> There are lots of other things we should consider, outside the join 
>>>> protocol realm.
>>>>
>>>> ------- Original Message --------
>>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>>> 6tisch-security@ietf.org
>>>>
>>>>
>>>>
>>>> Hi Michael et al:
>>>>
>>>> Another topic worth exploring more is the join protocol details.
>>>>
>>>> (There are many other aspects, including certs, as you mentioned, 
>>>> more general security architecture, provisioning, etc., but below 
>>>> only deals with join.)
>>>>
>>>> With w/HART, the join process only interacts with the network 
>>>> manager (62591, Annex A.3, Fig. A.1) for
>>>> -forwarded join from joining node to network manager;
>>>> -passing configuration parms from network manager to joining node 
>>>> (keys, links, frame links) and neighbor report from joined node to 
>>>> network manager.
>>>> All other communications are local, between joining device and 
>>>> neighbor (resp. with maintenance tool).
>>>>
>>>> It may have merit if we could use similar communication flows with 
>>>> 6tisch, i.e., keep most traffic local to the joining device, except 
>>>> for configuration parms exchange and authorization info passing.
>>>>
>>>> Most important consideration (from communication perspective) would 
>>>> be that non-local traffic would be minimized, as also w/HART does. 
>>>> From a marketing perspective, mimicking the communication flows 
>>>> w/HART already has would keep all time scheduling considerations 
>>>> for w/HART as currently there and 6TiSCH as to be detailed roughly 
>>>> the same. This would longer term help in pushing 6tisch-style 
>>>> security scheme to w/HART, since from a distance it looks the same 
>>>> (although trying to scrap the maintenance tool).
>>>>
>>>> Of course, this does not deal with the details of the joining 
>>>> protocol itself; only the flows.
>>>>
>>>> What about we look at some of the flows, and enumerate all issues 
>>>> that need to be addressed here, both from a security perspective 
>>>> and otherwise. We can then assign people to find missing 
>>>> information (I am esp. curious about how devices know when to 
>>>> send/receive and contributions of cycling efforts to total time 
>>>> latency).
>>>>
>>>> We could go over w/HART join flows during the call, to trigger 
>>>> these questions.
>>>>
>>>> Best regards, Rene
>>>>
>>>>
>>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>>> That's 90 minutes from this email.
>>>>>
>>>>> 1) notewell.
>>>>> 2) intros
>>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>>     it seems not?
>>>>> 4) review of claim certificate process, vs EST with token.
>>>>>
>>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>>
>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>>
>>>>> -- we will resume with the etherpad at:
>>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>>
>>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>>> if you need more than that to get in, or are having difficulties.
>>>>> Please make sure your audio works, and that you mute when not talking.
>>>>>
>>>>>
>>>>> --
>>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>>   -= IPv6 IoT consulting =-
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> _______________________________________________
>>>>> 6tisch-security mailing list
>>>>> 6tisch-security@ietf.org
>>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>>
>>>>
>>>> -- 
>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>
>>>
>>> -- 
>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>
>>
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------040600050706010301030403
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Kris:<br>
      <br>
      Thanks for the quick feedback.<br>
      <br>
      When designing a security protocol, one has to consider not just
      cryptographic properties, but also implementation cost, such as
      energy cost, RAM/ROM usage, and computational and communication
      time latency. Thus, while one might argue that "security should
      not care how the MAC layer is doing its job", this only seems to
      hold true if one is not interested in non-crypto performance
      metrics. To implementation-specific metrics mentioned above, one
      should add potential impact of traffic that seems to be
      legitimate, but in hindsight does not turn out to be that way
      (both in terms of denial-of-service attacks, keeping state, etc.).
      Hence, my question.<br>
      <br>
      So, communication aspects may be quite interesting to consider in
      detail, e.g., in the context of message relay (see, e.g., DICE WG
      mailing list, May 30, 2014, 10:29am EDT ---<br>
<a class="moz-txt-link-freetext" href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html</a>):<br>
      <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
        type="cite" style="color: rgb(0, 0, 0); font-family: 'Times New
        Roman'; font-size: medium; font-style: normal; font-variant:
        normal; font-weight: normal; letter-spacing: normal;
        line-height: normal; orphans: auto; text-align: start;
        text-indent: 0px; text-transform: none; white-space: normal;
        widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;
        background-color: rgb(255, 255, 255);">
        <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
          type="cite">
          <div class="moz-cite-prefix">So, I am still interested in
            getting more insight as to how the relay on/off switch would
            work in practice (which was the question in my original
            email of Tue [snippet copied below]). A description of
            device join operations would help (say, with operational
            network of 1000 nodes with diameter 20 hops, where one
            wishes to add a newbee node A at neighbor B, where B is 10
            hops away from network manager T).</div>
        </blockquote>
      </blockquote>
      From what you suggested below, if one takes slotframe of N=101
      timeslots of T_slot=15ms, then "goodput" of 1 packet per 8 seconds
      seems feasible. Does this mean that if one has a network manager
      10 hops away (my DICE example above), that the communication
      latency from joining node to and from the network manager is
      2*10*8 seconds =160 seconds or roughly 2 1/2 minutes and with that
      between neighbors this is 2*1*8 = 16 seconds? If so, the
      communication cost seem to far outstrip any other time latency
      cost (including that due to computational overhead). Please
      correct me if I am wrong here.<br>
      <br>
      If this is so, this begs the question as to coming up with tricks
      to squeeze more "bang for the buck" out of TSCH schedules, in case
      one executes a join protocol. As an example, if one does not use
      ACK'ed messages (which seems possible with interactive protocols)
      but - instead - squeezes an extra frame into that particular
      time/channel slot in the TSCH matrix, one seems to be able to
      potentially improve time latency by a factor 2x and get enormous
      time latencies of 2 1/2 minutes, resp. 16 seconds, down to 80,
      resp. 8 seconds. <br>
      <br>
      This is just to illustrate that there is more to security design
      than meets the eye at first.<br>
      <br>
      Any thoughts?<br>
      <br>
      Rene<br>
      &nbsp;<br>
      On 6/10/2014 2:23 PM, Kris Pister wrote:<br>
    </div>
    <blockquote cite="mid:53974D26.5080504@berkeley.edu" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      At some level, the answer is that the security should not care how
      the MAC layer is doing its job,<br>
      as long as the packets get through.&nbsp; But I agree that it is useful
      to see how all of this is going to<br>
      work together.<br>
      In the case of minimal, the MAC layer doesn't need to "find"
      anything.&nbsp; Once it has heard an EB,<br>
      it knows that every N slots there will be a TX/RX cell that it can
      use.&nbsp; If it has nothing to send, it<br>
      MUST listen.&nbsp; If it sends and collides, there is a backoff
      strategy and it tries again.&nbsp; Again, this<br>
      is all transparent to the security processing.<br>
      The choice of N determines latency, power, available BW, etc.&nbsp;
      Best case, motes in the same<br>
      RF space can send one packet every N*T_slot seconds.&nbsp; Lots of
      papers have been <br>
      written about the bad things that happen if you try to shove too
      much traffic through a <br>
      network with limited resources.&nbsp; Minimal will look like slotted
      aloha, (possibly with some <br>
      slightly better performance from preamble capture, maybe CCA,
      ...), namely a normalized<br>
      maximum goodput of GP=1/e with an offered load of G=1.&nbsp; Running
      any aloha-like network<br>
      near that maximum is very dangerous (chaotic collapse ensues
      unless higher layers are smart),<br>
      so a practical useful normalized goodput of 0.2 is more realistic
      and more energy efficient.<br>
      <br>
      If N=20, and T_slot=10ms, the network will happily support
      0.2/(N*T_slot) = 1 packet per second<br>
      among all motes in the same RF space.&nbsp; If N=101 and T_slot=15ms,
      then it's closer to 1 packet<br>
      every 8 seconds.&nbsp; That means that it will take a *long* time for a
      large dense network to form, which<br>
      is why we call it "minimal" instead of "optimal" :)<br>
      Something in the N=10...100 slots is still probably fine for,
      e.g., a simple static home network.<br>
      <br>
      ksjp<br>
      <br>
      <div class="moz-cite-prefix">On 6/10/2014 7:41 AM, Rene Struik
        wrote:<br>
      </div>
      <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Dear colleagues:<br>
          <br>
          Assumptions:<br>
          - Joining node has a minimum schedule (with 101x15ms
          slotframe) and somehow was able to find a time slot to send a
          first join packet to a neighbor node (c-1).<br>
          - Computational and communication time latency for response
          packet from neighbor node to joining node is 15ms, 150ms,
          750ms, or 5s (depending on device capabilities, implementation
          detail)<br>
          - Computational time latency for joining node to compute
          shared key is 15ms, 150ms, 750ms, or 5s (depending on device
          capabilities, implementation detail)<br>
          <br>
          So, now for question c-2 below:<br>
          - How does joining node find out when to open its receiver
          again, so as to receive response packet from neighbor node<br>
          - How does neighbor node find out when to receive second
          packet flow from joining node (i.e., after joining node
          computed shared key)<br>
          In particular, should the local schedule allocate multiples of
          15ms (i.e., each timeslot), 150ms, etc. Obviously, the denser
          the schedule the fewer capacity in terms of #joining nodes
          that can be served?<br>
          <br>
          So, perhaps, the background of my question c-2 is&nbsp; now
          unambiguously clear...<br>
          <br>
          ==<br>
          c) Join process impact on network: <br>
          Pascal Thubert asked "when network would explode with join".
          Note RS: the following questions come to mind:<br>
          c-1) how does joining&nbsp; node find a time slot to send first
          join packet to neighbor node (presumably, this would require
          listening for Enhanced Beacon, but details on schedule in
          terms of time and channels seems incomplete [min-schedule
          suggests 101x15ms slotframe and "less than 10s repeat of EBs,
          but that leaves lots of dead time and does not suggest a
          schedule that would create a common time window where two
          devices would both be awake).<br>
          c-2)how does joining node negotiate a local schedule with
          neighbor node for execution of join protocol
          (draft-watteyne-6tisch-tisch-00 refers to local schedule
          negotiation need, but unclear whether this has been looked
          into in detail).<br>
          c-3) for local traffic (joining node/neighbor), it seems
          Pascal Thubert's "exploding network" may not happen easily.
          Nevertheless, unclear what impact of "join priority flag TSCH
          802.15.4e frames is [that seems to have been designed with
          legacy w/HART in mind (centralized solution). With centralized
          tree-like solution, lots of traffic happens close to the root,
          thus potentially amplifying congestion around root node
          (=network manager?).<br>
          <br>
          On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
        </div>
        <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Dear colleagues:<br>
            <br>
            Please find below a reminder of the outstanding issues re
            the join protocol, as I originally circulated three weeks
            ago, prior to our call on Tue May 20, 2014. {As an aside,
            the week before that, on May 12, 2014, we did discuss the
            w/HART join process protocol flows (at the time, intention
            was to agree to align flows with that used there, as
            motivated in the same email below).}<br>
            <br>
            While current discussions on w/HART protocol have been
            somewhat interesting, I feel we should put urgent priority
            on tackling those outstanding issues. So far, I have not
            seen any traffic on these items from others, so please
            weigh-in (please include outstanding item # in the subject
            line, e.g., "outstanding issue #c").<br>
            <br>
            Let us first tackle item #c) below on join process impact on
            the network. I am particularly interested in detailed
            deliberations on the three questions on this item that came
            to my mind here.<br>
            <br>
            When looking at this topic, I would like to encourage you to
            read the email thread on the IETF DICE list re
            draft-kumar-dice-dtls-relay-01, which is related to
            relaying&nbsp; nodes and potential DoS attacks. I initiated this
            discussion on May 27th, with last posting on May 30th. See <a
              moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
            <br>
            Best regards, Rene<br>
            <br>
            On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
          </div>
          <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
            <meta content="text/html; charset=ISO-8859-1"
              http-equiv="Content-Type">
            <div class="moz-cite-prefix">Hi Michael:<br>
              <br>
              At the previous conf call of May 12, 2014, we discussed
              message flows of w/HART join process, as also alluded to
              in my email below (the specs could not be distributed due
              to copyright restrictions).<br>
              <br>
              In my mind, 6TiSCH protocol can use similar communication
              flows as w/HART where only non-local communication flows
              (between joining node and network manager) would be <br>
              i) passing join/authentication information from joining
              node to network manager (and back);<br>
              ii) passing configuration parms from network manager to
              joining node (keys, links, frame links) and neighbor
              report from joined node to network manager.<br>
              <br>
              MAIN OUTSTANDING ISSUES (in my mind): <br>
              a) Packet sizes: <br>
              get more info on packet sizes configuration parms, as
              w/HART uses. Note RS: during call, Tom Phinney suggested
              contacting Wally Bratt from HART Comm. Foundation for
              this).&nbsp; Note RS: Shouldn't, e.g., Dust Networks have info
              on packet sizes/structure?; ISA SP100.11a metrics would
              also help, as would ZigBee 2.0 config parms. Does, e.g.,
              Cisco have useful data points here?<br>
              b) Device Ids:<br>
              With industrial control, network manager would look up
              "tag name" device in pre-configured database. Details on
              tag name syntax, how assigned, and how bound to, e.g.,
              EUI-64 are missing. Note RS: Perhaps, Tom Phinney could
              point at tag name syntax and lifecycle aspects here?<br>
              c) Join process impact on network: <br>
              Pascal Thubert asked "when network would explode with
              join". Note RS: the following questions come to mind:<br>
              - how does joining&nbsp; node find a time slot to send first
              join packet to neighbor node (presumably, this would
              require listening for Enhanced Beacon, but details on
              schedule in terms of time and channels seems incomplete
              [min-schedule suggests 101x15ms slotframe and "less than
              10s repeat of EBs, but that leaves lots of dead time and
              does not suggest a schedule that would create a common
              time window where two devices would both be awake).<br>
              - how does joining node negotiate a local schedule with
              neighbor node for execution of join protocol
              (draft-watteyne-6tisch-tisch-00 refers to local schedule
              negotiation need, but unclear whether this has been looked
              into in detail).<br>
              - for local traffic (joining node/neighbor), it seems
              Pascal Thubert's "exploding network" may not happen
              easily. Nevertheless, unclear what impact of "join
              priority flag TSCH 802.15.4e frames is [that seems to have
              been designed with legacy w/HART in mind (centralized
              solution). With centralized tree-like solution, lots of
              traffic happens close to the root, thus potentially
              amplifying congestion around root node (=network
              manager?).<br>
              d) crypto protocol details of join protocol:<br>
              Note RS: I can solve this (close to optimal design already
              done [assuming I can do this "without hands tied behind
              the back"])<br>
              e) authorization/trust management:<br>
              it is here where binding of ids to public keys via certs
              and lifecycle aspects play a role, as well as
              syntax/semantics of authorization messages. Note RS:
              question is whether ACE could play a role here (current
              charter discussions seem to be endless, though). As has
              been brought up before, a potential instantiation of certs
              would be the use of 802.1ar certs, but this is certainly
              not the only way of doing things.<br>
              <br>
              There are lots of other things we should consider, outside
              the join protocol realm.<br>
              <br>
              ------- Original Message --------
              <table class="moz-email-headers-table" cellpadding="0"
                cellspacing="0" border="0">
                <tbody>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:




                    </th>
                    <td>Re: [6tisch-security] agenda(?) for call today</td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:



                    </th>
                    <td>Mon, 12 May 2014 09:53:37 -0400</td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:



                    </th>
                    <td>Rene Struik <a moz-do-not-send="true"
                        class="moz-txt-link-rfc2396E"
                        href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To:


                    </th>
                    <td>Michael Richardson <a moz-do-not-send="true"
                        class="moz-txt-link-rfc2396E"
                        href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                      <a moz-do-not-send="true"
                        class="moz-txt-link-abbreviated"
                        href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                  </tr>
                </tbody>
              </table>
              <br>
              <br>
              <div class="moz-cite-prefix">Hi Michael et al:<br>
                <br>
                Another topic worth exploring more is the join protocol
                details. <br>
                <br>
                (There are many other aspects, including certs, as you
                mentioned, more general security architecture,
                provisioning, etc., but below only deals with join.)<br>
                <br>
                With w/HART, the join process only interacts with the
                network manager (62591, Annex A.3, Fig. A.1) for <br>
                -forwarded join from joining node to network manager;<br>
                -passing configuration parms from network manager to
                joining node (keys, links, frame links) and neighbor
                report from joined node to network manager.<br>
                All other communications are local, between joining
                device and neighbor (resp. with maintenance tool).<br>
                <br>
                It may have merit if we could use similar communication
                flows with 6tisch, i.e., keep most traffic local to the
                joining device, except for configuration parms exchange
                and authorization info passing. <br>
                <br>
                Most important consideration (from communication
                perspective) would be that non-local traffic would be
                minimized, as also w/HART does. From a marketing
                perspective, mimicking the communication flows w/HART
                already has would keep all time scheduling
                considerations for w/HART as currently there and 6TiSCH
                as to be detailed roughly the same. This would longer
                term help in pushing 6tisch-style security scheme to
                w/HART, since from a distance it looks the same
                (although trying to scrap the maintenance tool).<br>
                <br>
                Of course, this does not deal with the details of the
                joining protocol itself; only the flows.<br>
                <br>
                What about we look at some of the flows, and enumerate
                all issues that need to be addressed here, both from a
                security perspective and otherwise. We can then assign
                people to find missing information (I am esp. curious
                about how devices know when to send/receive and
                contributions of cycling efforts to total time latency).
                <br>
                <br>
                We could go over w/HART join flows during the call, to
                trigger these questions.<br>
                <br>
                Best regards, Rene<br>
              </div>
              <br>
              <br>
              On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
            </div>
            <blockquote cite="mid:19475.1400588783@sandelman.ca"
              type="cite">
              <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
              <br>
              <fieldset class="mimeAttachmentHeader"></fieldset>
              <br>
              <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
            </blockquote>
            <br>
            <br>
            <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
          </blockquote>
          <br>
          <br>
          <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
      </blockquote>
      <br>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------040600050706010301030403--


From nobody Tue Jun 10 14:23:17 2014
Return-Path: <mariainesrobles@googlemail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA4B31A02C7; Tue, 10 Jun 2014 14:21:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.522
X-Spam-Level: *
X-Spam-Status: No, score=1.522 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zw3BLi_mTpUE; Tue, 10 Jun 2014 14:21:22 -0700 (PDT)
Received: from mail-ve0-x230.google.com (mail-ve0-x230.google.com [IPv6:2607:f8b0:400c:c01::230]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C39BF1A02C6; Tue, 10 Jun 2014 14:21:21 -0700 (PDT)
Received: by mail-ve0-f176.google.com with SMTP id db12so6053079veb.7 for <multiple recipients>; Tue, 10 Jun 2014 14:21:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlemail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=MIncnq8sQIs7wApfWhyJ1pDH3g44HBtTe1VPntgmmIY=; b=RmQ163Kb1LdwnqbGkLCTHOT5nEJK5pSKnyvSe7gUlIHdaUsfIzYbgNvlAk9qJTuMrm kvMPZJS5K8fot0mmIQTPcLrPuMfUiCc+txP21GjjiqjgB4xy7el0jFXsDkLsB6i25m49 EHelGRsh9+YUfGKdUn1Cg/OtuMvFGgs7uAXLiLI1UQ4hcq9Nv0s9UL9LgU2GZgs9Lz2r 3Wb8hbhync1NgyIC5xgFmmLYFZQy7GN/azrII2s1buskHWEsnavoL5cTV6B2YLSy1M/y UVbXyOBIVEAZolR95qeskC4QFtPiR1uVHHYUp3CfrBbKIlt71foPRIB0r7EcjXgT4mRT DgmA==
MIME-Version: 1.0
X-Received: by 10.221.20.199 with SMTP id qp7mr35108377vcb.24.1402435280720; Tue, 10 Jun 2014 14:21:20 -0700 (PDT)
Received: by 10.221.16.3 with HTTP; Tue, 10 Jun 2014 14:21:20 -0700 (PDT)
In-Reply-To: <CAP+sJUdPsh_DWdzuJK0GFEQhJO3rapK9VryNsV4uavyksDonnQ@mail.gmail.com>
References: <CAP+sJUdPsh_DWdzuJK0GFEQhJO3rapK9VryNsV4uavyksDonnQ@mail.gmail.com>
Date: Wed, 11 Jun 2014 00:21:20 +0300
Message-ID: <CAP+sJUcFC_-mJfTBaR=SZ28LbyzYmEc_WK3hSDsBhsiXqws10g@mail.gmail.com>
From: Ines  Robles <mariainesrobles@googlemail.com>
To: ietf <ietf@ietf.org>
Content-Type: multipart/alternative; boundary=001a11339e2eba82fc04fb81e825
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/kuUH1uXy150jbvPp-I49PoIrqLM
X-Mailman-Approved-At: Tue, 10 Jun 2014 14:23:05 -0700
Cc: "ipv6@ietf.org" <ipv6@ietf.org>, 6tisch-security@ietf.org, lwip@ietf.org, roll <roll@ietf.org>, ace@ietf.org, dtls-iot@ietf.org, Xavier Vilajosana <xvilajosana@eecs.berkeley.edu>, coman@ietf.org, core@ietf.org, 6lo@ietf.org, "6tisch@ietf.org" <6tisch@ietf.org>
Subject: Re: [6tisch-security] LLN Plugfest at IETF 90
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jun 2014 21:21:25 -0000

--001a11339e2eba82fc04fb81e825
Content-Type: text/plain; charset=UTF-8

Dear all,

This is a kindly reminder :-) .

We call for participants. The deadline to receive topics to present or
demonstrate in the event is 06/20/2014 :-). Interested audience is also
welcome and we encourage audience to participate in the feedback session.

More information:
https://bitbucket.org/6tisch/meetings/wiki/140720a_ietf90_toronto_plugfest

We hope to see you there!

Xavier and Ines.


2014-06-02 1:02 GMT+03:00 Ines Robles <mariainesrobles@googlemail.com>:

> Dear all,
>
> We would like to announce the plugfest event at the 90th IETF Meeting in
> Toronto.
>
> We call for participants. The deadline to receive topics to present or
> demonstrate in the event is 06/13/2014. Interested audience is also welcome
> and we encourage audience to participate in the feedback session.
>
> Please find next the plugfest information.
>
> We hope to see you there!
>
> Xavier and Ines.
>
> -----------------------
> Low Power and Lossy Networks plugfest at IETF90
>
> The IETF 6TiSCH <https://datatracker.ietf.org/wg/6tisch/charter/>, IETF
> 6lo <https://datatracker.ietf.org/wg/6lo/charter/> and IETF ROLL
> <https://datatracker.ietf.org/wg/roll/charter/> working groups are
> hosting an informal "plugfest" event at the IETF90 meeting, in Toronto, CA,
> during the week of July 20-25 2014.
> Goals
>
> The goal of this event is to bring together people interested in hands-on
> experience around the technology developed by the 6TiSCH, 6lo and ROLL
> working groups, with a particular focus on the TSCH mode of IEEE802.15.4e,
> 6lowpan, RPL and new WG specifications.
> When and where ?
>
>    - *Date*: Sunday July 20 2014, 0900-1300 EDT.
>    - *Location*: Meeting Room TBD, Fairmont Royal York Hotel 100 Front
>    Street W, Toronto, CA.
>
> *Early access: TBD if the plugfest room will be open starting 8am EDT on
> Sunday 20 2014 to allow people to set up.*
> Topology proposed - TBD
>
>    - Star topology
>    - IPv6
>
> Complementary angles
>
> This event will feature the following complementary angles:
>
>    - Interoperation
>    - Demonstration
>    - Tools
>
> Focus 1: Interoperation
>
> Download the interoperation guidelines:
>
>    - - TBD for Toronto - interoperation guidelines, version 1 (London)
>    <https://bitbucket.org/6tisch/meetings/src/master/140306_ietf89_plugfest_london/ietf89_6tisch_interop_guidelines_v01.pdf>
>
> The goal is to achieve interoperation between different hardware and
> software implementations on the different aspects addressed by 6lo, 6TiSCH
> and ROLL WGs. This include 6TiSCH minimal draft implementation,
> demonstrating TSCH synchronization and OF0 for RPL on a minimal network.
> 6lowpan to demostrate cross link layer inter-operability by means of
> bridges or backbones routers. Storing and non-storing RPL implementation
> including its coexistance in different sub-networks.
>
> The focus during this event is open to demonstrating 6lo, ROLL or 6TiSCH
> drafts implementations, including but not limited to: e.g. - 6TiSCH minimal
> draft: http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00. - TBD
>
> Participants are encouraged to bring devices which implement parts or all
> of the listed drafts.
>
> Levels of interoperation are proposed:
>
>    - *Level 1*, star topology. A single BBR devices acts as the time
>    source neighbor for all other nodes. Nodes need to demonstrate frame-based
>    and acknowledgement-based synchronization. The static TSCH schedule, as
>    well as all slot timings are taken from draft-ietf-6tisch-minimal-00.
>    - *Level 2*, multi-hop topology. This level builds upon level 1. The
>    goal of this level is full compliance to draft-ietf-6tisch-minimal-00,
>    including multi-hop routing (RPL).
>    - *Level 3*, on-the-fly scheduling. [optional] Preliminary
>    implementations of
>    http://tools.ietf.org/html/draft-dujovne-6tisch-on-the-fly can be
>    shown.
>    - *Level 4*, drafts from ROLL, such as:
>    draft-ietf-roll-mpl-parameter-configuration,
>    draft-ko-roll-mix-network-pathology, Opportunistic routing, selective DIS,
>    and others that participants want to show
>    - *Level 5*, drafts from 6lo, such as: draft-ietf-6lo-btle,
>    draft-ietf-6lo-ghc,draft-ietf-6lo-lowpanz, and others that participants
>    want to show.
>    - *Level 6* Other drafts, such as
>    draft-thubert-6man-flow-label-for-rpl, etc.
>
> Focus 2: Demonstration
>
> Participants are encouraged to bring devices and technology based on
> 6TiSCH, 6lo and ROLL which they believe can be of interest for the other
> participants. These devices may or may not participate in the
> interoperation event. Demonstration of more complete systems are
> encouraged, for example systems which show the interconnection of a 6TiSCH
> based mesh to traditional networks.
> Focus 3: Tools
>
> Participants are encouraged to bring and present different tools developed
> around 6TiSCH/6lo/ROLL networks. Possible tools include, but are not
> limited to:
>
>    - acquisition devices (i.e. "sniffers")
>    - packet analysis tools (e.g. Wireshark)
>    - simulation/emulation platforms
>
> Important Dates
>
> The preparation of this event will be held during a portion of the
> bi-weekly 6TiSCH call (*To Be Decided how and when!!!*). In particular:
>
>    - *06/02/2014* Announcement of the plugfest event to the WG/ML related
>    with constrained devices, such as: 6tisch, 6lo, roll, core, lwig, dtls-iot,
>    coman, ace, etc.
>    - *06/06/2014* Adoption of the plugfest call by the WGs, and call for
>    participants at each group.
>    - *06/02/2014-06/13/2014* Participants have contacted the plugfest
>    chairs (Xavier or Ines) with a tentative description of what they wish to
>    participate in.
>    - *06/20/2014* Synchronization point 1. Participants can share the
>    state of advancement of the implementation and raise blocking points.
>    - *07/11/2014* Synchronization point 2. Participants can share the
>    state of advancement of the implementation and raise blocking points.
>    - *07/20/2014*. Plugfest at IETF90.
>
> Tentative Agenda from 9:00 to 13:00
>
>    - *[09.00]* Welcome and Initial Instructions
>    - *[09.05]* Participants Pitch (5 min per Participant)
>    - *[09.45]* Participants Pitch Tools (5 min per Participant)
>    - *[10.15]* Interoperation (Islands)
>    - *[11.50]* Feedback and open discussion.
>    - *[12.40]* Acknowledgements and Plugfest End
>
> For More Information
>
>    - *Contact*: Xavi Vilajosana xvilajosana@eecs.berkeley.edu - Ines
>    Robles mariainesrobles@gmail.com
>
> Note Well
>
> This event is organized as part of the IETF90 standardization meeting. You
> need to register to the IETF90 conference to be able to participate. Daily
> passes are available. The IETF Note Well applies to this plugfest, see
> http://www.ietf.org/about/note-well.html.
> About
>
> The IETF 6TiSCH working group standardizes mechanisms focusing on enabling
> IPv6 over the TSCH mode of the IEEE802.15.4e standard. You can access the
> charter at http://datatracker.ietf.org/wg/6tisch/charter/, which also
> contains links to the mailing list and the Internet-Drafts published by the
> group. 6TiSCH holds weekly phone calls on Friday 8am PST. Participation is
> open, and is subject to the IETF Note Well.
>
> The IETF 6lo working group focuses on the work that facilitates IPv6
> connectivity over constrained node networks with the characteristics of:
> limited power, memory and processing resources;. You can access the charter
> at https://datatracker.ietf.org/wg/6lo/charter/, which also contains
> links to the mailing list and the I-D published by the group.
>
> The IETF ROLL working group is focused on routing issues for LLN (Low
> Power and Lossy Networks), in IPv6 routing architectural framework for the
> industrial, connected home, building and urban sensor networks application
> scenarios. You can access the charter at
> https://datatracker.ietf.org/wg/roll/charter/, which also contains links
> to the mailing list and the I-D published by the group.
>

--001a11339e2eba82fc04fb81e825
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Dear all,<div><br></div><div>This is a kindly reminder :-)=
 .</div><div><br></div><div><span style=3D"color:rgb(0,0,0);font-family:ari=
al,helvetica,sans-serif">We call for participants. The deadline to receive =
topics to present or demonstrate in the event is 06/20/2014 :-). Interested=
 audience is also welcome and we encourage audience to participate in the f=
eedback session.</span></div>

<div><span style=3D"color:rgb(0,0,0);font-family:arial,helvetica,sans-serif=
"><br></span></div><div><span style=3D"color:rgb(0,0,0);font-family:arial,h=
elvetica,sans-serif">More information:=C2=A0</span><font color=3D"#000000" =
face=3D"arial, helvetica, sans-serif"><a href=3D"https://bitbucket.org/6tis=
ch/meetings/wiki/140720a_ietf90_toronto_plugfest" target=3D"_blank">https:/=
/bitbucket.org/6tisch/meetings/wiki/140720a_ietf90_toronto_plugfest</a></fo=
nt></div>

<div><br></div><div><span style=3D"color:rgb(0,0,0);font-family:arial,helve=
tica,sans-serif">We hope to see you there!</span><br></div><div><span style=
=3D"color:rgb(0,0,0);font-family:arial,helvetica,sans-serif"><br></span></d=
iv>

<div><font color=3D"#000000" face=3D"arial, helvetica, sans-serif">Xavier a=
nd Ines.</font></div><div class=3D"gmail_extra"><br><br><div class=3D"gmail=
_quote">2014-06-02 1:02 GMT+03:00 Ines  Robles <span dir=3D"ltr">&lt;<a hre=
f=3D"mailto:mariainesrobles@googlemail.com" target=3D"_blank">mariainesrobl=
es@googlemail.com</a>&gt;</span>:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;p=
adding-left:1ex"><div dir=3D"ltr"><div><div><span style=3D"font-family:aria=
l,helvetica,sans-serif;color:rgb(0,0,0)">Dear all,</span><br>

</div><font face=3D"arial, helvetica, sans-serif"><br style=3D"color:rgb(0,=
0,0)"><span style=3D"color:rgb(0,0,0)">We would like to announce the plugfe=
st event at the 90th IETF Meeting in Toronto.</span></font><div>

<span style=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, sans-serif=
"><br></font></span></div></div><div><span style=3D"color:rgb(0,0,0)"><font=
 face=3D"arial, helvetica, sans-serif">We call for participants. The deadli=
ne to receive topics to present or demonstrate in the event is 06/13/2014. =
Interested audience is also welcome and we encourage audience to participat=
e in the feedback session.</font></span></div>



<div><div><span style=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, =
sans-serif"><br></font></span></div><div><span style=3D"color:rgb(0,0,0)"><=
font face=3D"arial, helvetica, sans-serif">Please find next the plugfest in=
formation.=C2=A0</font></span><div>



<font face=3D"arial, helvetica, sans-serif"><br></font></div><div><span sty=
le=3D"color:rgb(0,0,0)"><font face=3D"arial, helvetica, sans-serif">We hope=
 to see you there!</font></span><div><font color=3D"#000000" face=3D"arial,=
 helvetica, sans-serif"><br>



</font></div><div><div style=3D"color:rgb(0,0,0)"><font face=3D"arial, helv=
etica, sans-serif">Xavier and Ines.</font></div></div></div></div><div styl=
e=3D"font-family:&#39;Times New Roman&#39;;font-size:13px;color:rgb(0,0,0)"=
>


<font size=3D"3"><br>
</font></div><div style=3D"font-family:&#39;Times New Roman&#39;;font-size:=
13px;color:rgb(0,0,0)"><font size=3D"3">-----------------------</font></div=
><div><h1 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-si=
ze:24px;margin:20px 0px 10px;padding:0px;font-weight:normal;line-height:1.2=
5">



Low Power and Lossy Networks plugfest at IETF90</h1><p style=3D"color:rgb(5=
1,51,51);font-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;pa=
dding:0px;word-wrap:break-word;line-height:20px">The=C2=A0<a href=3D"https:=
//datatracker.ietf.org/wg/6tisch/charter/" style=3D"color:rgb(59,115,175);t=
ext-decoration:none" target=3D"_blank">IETF 6TiSCH</a>,=C2=A0<a href=3D"htt=
ps://datatracker.ietf.org/wg/6lo/charter/" style=3D"color:rgb(59,115,175);t=
ext-decoration:none" target=3D"_blank">IETF 6lo</a>=C2=A0and=C2=A0<a href=
=3D"https://datatracker.ietf.org/wg/roll/charter/" style=3D"color:rgb(59,11=
5,175);text-decoration:none" target=3D"_blank">IETF ROLL</a>=C2=A0working g=
roups are hosting an informal &quot;plugfest&quot; event at the IETF90 meet=
ing, in Toronto, CA, during the week of July 20-25 2014.</p>



<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Goals=
</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">



The goal of this event is to bring together people interested in hands-on e=
xperience around the technology developed by the 6TiSCH, 6lo and ROLL worki=
ng groups, with a particular focus on the TSCH mode of IEEE802.15.4e, 6lowp=
an, RPL and new WG specifications.</p>



<h3 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:18p=
x;margin:20px 0px 0px;padding:0px;line-height:1.3888888888888888;font-weigh=
t:normal">When and where ?</h3><ul style=3D"color:rgb(51,51,51);font-family=
:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">



<li style=3D"word-wrap:break-word"><strong>Date</strong>: Sunday July 20 20=
14, 0900-1300 EDT.</li><li style=3D"word-wrap:break-word"><strong>Location<=
/strong>: Meeting Room TBD, Fairmont Royal York Hotel 100 Front Street W, T=
oronto, CA.</li>



</ul><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
"><strong>Early access: TBD if the plugfest room will be open starting 8am =
EDT on Sunday 20 2014 to allow people to set up.</strong></p>



<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Topol=
ogy proposed - TBD</h2><ul style=3D"color:rgb(51,51,51);font-family:Arial,s=
ans-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">



<li style=3D"word-wrap:break-word">Star topology</li><li style=3D"word-wrap=
:break-word">IPv6</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Ari=
al,sans-serif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:no=
rmal;line-height:1.5">



Complementary angles</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,=
sans-serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-w=
ord;line-height:20px">This event will feature the following complementary a=
ngles:</p>



<ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14p=
x;margin:10px 0px 0px;line-height:20px"><li style=3D"word-wrap:break-word">=
Interoperation</li><li style=3D"word-wrap:break-word">Demonstration</li><li=
 style=3D"word-wrap:break-word">



Tools</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-seri=
f;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-he=
ight:1.5">Focus 1: Interoperation</h2>
<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Dow=
nload the interoperation guidelines:</p><ul style=3D"color:rgb(51,51,51);fo=
nt-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:2=
0px">



<li style=3D"word-wrap:break-word"><a href=3D"https://bitbucket.org/6tisch/=
meetings/src/master/140306_ietf89_plugfest_london/ietf89_6tisch_interop_gui=
delines_v01.pdf" style=3D"color:rgb(59,115,175);text-decoration:none" targe=
t=3D"_blank"> - TBD for Toronto - interoperation guidelines, version 1 (Lon=
don)</a></li>



</ul><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">The goal is to achieve interoperation between different hardware and soft=
ware implementations on the different aspects addressed by 6lo, 6TiSCH and =
ROLL WGs. This include 6TiSCH minimal draft implementation, demonstrating T=
SCH synchronization and OF0 for RPL on a minimal network. 6lowpan to demost=
rate cross link layer inter-operability by means of bridges or backbones ro=
uters. Storing and non-storing RPL implementation including its coexistance=
 in different sub-networks.</p>



<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 focus during this event is open to demonstrating 6lo, ROLL or 6TiSCH draft=
s implementations, including but not limited to: e.g. - 6TiSCH minimal draf=
t:=C2=A0<a href=3D"http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00"=
 rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-decoration:none" targ=
et=3D"_blank">http://tools.ietf.org/html/draft-ietf-6tisch-minimal-00</a>. =
- TBD</p>



<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Par=
ticipants are encouraged to bring devices which implement parts or all of t=
he listed drafts.</p>



<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">Lev=
els of interoperation are proposed:</p><ul style=3D"color:rgb(51,51,51);fon=
t-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:20=
px">



<li style=3D"word-wrap:break-word"><strong>Level 1</strong>, star topology.=
 A single BBR devices acts as the time source neighbor for all other nodes.=
 Nodes need to demonstrate frame-based and acknowledgement-based synchroniz=
ation. The static TSCH schedule, as well as all slot timings are taken from=
 draft-ietf-6tisch-minimal-00.</li>



<li style=3D"word-wrap:break-word"><strong>Level 2</strong>, multi-hop topo=
logy. This level builds upon level 1. The goal of this level is full compli=
ance to draft-ietf-6tisch-minimal-00, including multi-hop routing (RPL).</l=
i>



<li style=3D"word-wrap:break-word"><strong>Level 3</strong>, on-the-fly sch=
eduling. [optional] Preliminary implementations of=C2=A0<a href=3D"http://t=
ools.ietf.org/html/draft-dujovne-6tisch-on-the-fly" rel=3D"nofollow" style=
=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">http://to=
ols.ietf.org/html/draft-dujovne-6tisch-on-the-fly</a>=C2=A0can be shown.</l=
i>



<li style=3D"word-wrap:break-word"><strong>Level 4</strong>, drafts from RO=
LL, such as: draft-ietf-roll-mpl-parameter-configuration, draft-ko-roll-mix=
-network-pathology, Opportunistic routing, selective DIS, and others that p=
articipants want to show</li>



<li style=3D"word-wrap:break-word"><strong>Level 5</strong>, drafts from 6l=
o, such as: draft-ietf-6lo-btle, draft-ietf-6lo-ghc,draft-ietf-6lo-lowpanz,=
 and others that participants want to show.</li><li style=3D"word-wrap:brea=
k-word">



<strong>Level 6</strong>=C2=A0Other drafts, such as draft-thubert-6man-flow=
-label-for-rpl, etc.</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:=
Arial,sans-serif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight=
:normal;line-height:1.5">



Focus 2: Demonstration</h2><p style=3D"color:rgb(51,51,51);font-family:Aria=
l,sans-serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break=
-word;line-height:20px">Participants are encouraged to bring devices and te=
chnology based on 6TiSCH, 6lo and ROLL which they believe can be of interes=
t for the other participants. These devices may or may not participate in t=
he interoperation event. Demonstration of more complete systems are encoura=
ged, for example systems which show the interconnection of a 6TiSCH based m=
esh to traditional networks.</p>



<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">Focus=
 3: Tools</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;=
font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-he=
ight:20px">



Participants are encouraged to bring and present different tools developed =
around 6TiSCH/6lo/ROLL networks. Possible tools include, but are not limite=
d to:</p><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font=
-size:14px;margin:10px 0px 0px;line-height:20px">



<li style=3D"word-wrap:break-word">acquisition devices (i.e. &quot;sniffers=
&quot;)</li><li style=3D"word-wrap:break-word">packet analysis tools (e.g. =
Wireshark)</li><li style=3D"word-wrap:break-word">simulation/emulation plat=
forms</li>



</ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-siz=
e:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">=
Important Dates</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-=
serif;font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;l=
ine-height:20px">



The preparation of this event will be held during a portion of the bi-weekl=
y 6TiSCH call (<strong>To Be Decided how and when!!!</strong>). In particul=
ar:</p><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-s=
ize:14px;margin:10px 0px 0px;line-height:20px">



<li style=3D"word-wrap:break-word"><strong>06/02/2014</strong>=C2=A0Announc=
ement of the plugfest event to the WG/ML related with constrained devices, =
such as: 6tisch, 6lo, roll, core, lwig, dtls-iot, coman, ace, etc.</li><li =
style=3D"word-wrap:break-word">



<strong>06/06/2014</strong>=C2=A0Adoption of the plugfest call by the WGs, =
and call for participants at each group.</li><li style=3D"word-wrap:break-w=
ord"><strong>06/02/2014-06/13/2014</strong>=C2=A0Participants have contacte=
d the plugfest chairs (Xavier or Ines) with a tentative description of what=
 they wish to participate in.</li>



<li style=3D"word-wrap:break-word"><strong>06/20/2014</strong>=C2=A0Synchro=
nization point 1. Participants can share the state of advancement of the im=
plementation and raise blocking points.</li><li style=3D"word-wrap:break-wo=
rd">


<strong>07/11/2014</strong>=C2=A0Synchronization point 2. Participants can =
share the state of advancement of the implementation and raise blocking poi=
nts.</li>
<li style=3D"word-wrap:break-word"><strong>07/20/2014</strong>. Plugfest at=
 IETF90.</li></ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-s=
erif;font-size:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line=
-height:1.5">



Tentative Agenda from 9:00 to 13:00</h2><ul style=3D"color:rgb(51,51,51);fo=
nt-family:Arial,sans-serif;font-size:14px;margin:10px 0px 0px;line-height:2=
0px"><li style=3D"word-wrap:break-word"><em>[09.00]</em>=C2=A0Welcome and I=
nitial Instructions</li>



<li style=3D"word-wrap:break-word"><em>[09.05]</em>=C2=A0Participants Pitch=
 (5 min per Participant)</li><li style=3D"word-wrap:break-word"><em>[09.45]=
</em>=C2=A0Participants Pitch Tools (5 min per Participant)</li><li style=
=3D"word-wrap:break-word">



<em>[10.15]</em>=C2=A0Interoperation (Islands)</li><li style=3D"word-wrap:b=
reak-word"><em>[11.50]</em>=C2=A0Feedback and open discussion.</li><li styl=
e=3D"word-wrap:break-word"><em>[12.40]</em>=C2=A0Acknowledgements and Plugf=
est End</li></ul>



<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">For M=
ore Information</h2><ul style=3D"color:rgb(51,51,51);font-family:Arial,sans=
-serif;font-size:14px;margin:10px 0px 0px;line-height:20px">



<li style=3D"word-wrap:break-word"><strong>Contact</strong>: Xavi Vilajosan=
a=C2=A0<a href=3D"mailto:xvilajosana@eecs.berkeley.edu" style=3D"color:rgb(=
59,115,175);text-decoration:none" target=3D"_blank">xvilajosana@eecs.berkel=
ey.edu</a>=C2=A0- Ines Robles=C2=A0<a href=3D"mailto:mariainesrobles@gmail.=
com" style=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank"=
>mariainesrobles@gmail.com</a></li>



</ul><h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-siz=
e:20px;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">=
Note Well</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;=
font-size:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-he=
ight:20px">



This event is organized as part of the IETF90 standardization meeting. You =
need to register to the IETF90 conference to be able to participate. Daily =
passes are available. The IETF Note Well applies to this plugfest, see=C2=
=A0<a href=3D"http://www.ietf.org/about/note-well.html" rel=3D"nofollow" st=
yle=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">http:/=
/www.ietf.org/about/note-well.html</a>.</p>



<h2 style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:20p=
x;margin:20px 0px 0px;padding:0px;font-weight:normal;line-height:1.5">About=
</h2><p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size=
:14px;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px=
">



The IETF 6TiSCH working group standardizes mechanisms focusing on enabling =
IPv6 over the TSCH mode of the IEEE802.15.4e standard. You can access the c=
harter at=C2=A0<a href=3D"http://datatracker.ietf.org/wg/6tisch/charter/" r=
el=3D"nofollow" style=3D"color:rgb(59,115,175);text-decoration:none" target=
=3D"_blank">http://datatracker.ietf.org/wg/6tisch/charter/</a>, which also =
contains links to the mailing list and the Internet-Drafts published by the=
 group. 6TiSCH holds weekly phone calls on Friday 8am PST. Participation is=
 open, and is subject to the IETF Note Well.</p>



<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 IETF 6lo working group focuses on the work that facilitates IPv6 connectiv=
ity over constrained node networks with the characteristics of: limited pow=
er, memory and processing resources;. You can access the charter at=C2=A0<a=
 href=3D"https://datatracker.ietf.org/wg/6lo/charter/" rel=3D"nofollow" sty=
le=3D"color:rgb(59,115,175);text-decoration:none" target=3D"_blank">https:/=
/datatracker.ietf.org/wg/6lo/charter/</a>, which also contains links to the=
 mailing list and the I-D published by the group.</p>



<p style=3D"color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px=
;margin:10px 0px 0px;padding:0px;word-wrap:break-word;line-height:20px">The=
 IETF ROLL working group is focused on routing issues for LLN (Low Power an=
d Lossy Networks), in IPv6 routing architectural framework for the industri=
al, connected home, building and urban sensor networks application scenario=
s. You can access the charter at=C2=A0<a href=3D"https://datatracker.ietf.o=
rg/wg/roll/charter/" rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-d=
ecoration:none" target=3D"_blank">https://datatracker.ietf.org/wg/roll/char=
ter/</a>, which also contains links to the mailing list and the I-D publish=
ed by the group.</p>



</div></div></div>
</blockquote></div><br></div></div>

--001a11339e2eba82fc04fb81e825--


From nobody Tue Jun 10 17:39:22 2014
Return-Path: <ksjp@berkeley.edu>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7DE01A0252 for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 17:39:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wd7vHP8wqgpL for <6tisch-security@ietfa.amsl.com>; Tue, 10 Jun 2014 17:39:15 -0700 (PDT)
Received: from mail-pa0-f46.google.com (mail-pa0-f46.google.com [209.85.220.46]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1A1C61A021B for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 17:39:15 -0700 (PDT)
Received: by mail-pa0-f46.google.com with SMTP id eu11so1247040pac.19 for <6tisch-security@ietf.org>; Tue, 10 Jun 2014 17:39:14 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=717srzsi06S7T0bQHaIsuLgKQQYbnRmMWwiV0NNVehs=; b=NQfv8L6NbUW+8EjNpocZngy0e7PO4/JRcooMwI1opp3YE+i4M9Csh5wphmSlRroD7n lWVqpEMuhxTWUd6nCZxXXp5JgFHBHwcYyPz0oaZ0wtFY3+EP6NPcPV1cn75psRvq8hIr UcbuJS90hXy6YUhRxhxRGKji4DtDKh0wBQukLszYivWnMJAOiiE820F0GygQqAAwzvn3 dvI2pexIdmgS3uzZtA88oIb9xMiTKcW7uN00a3ZjitVvOoVrACtPgyU8kd/lEMCe3xKl sQC4kidUPh7hNqQls8i+wdiPGPfSyhXgluGY5v4rLWYgw/hVgOQb9Z7iiy1hFXKbVd92 58FQ==
X-Gm-Message-State: ALoCoQmThBdmeQtXr3FT7PdIy04O+DQa/tUyqp4oHuu2FUmDAyS0HB7wiIBV4ECQ9kYLy7GvAB6T
X-Received: by 10.68.196.137 with SMTP id im9mr679714pbc.105.1402447154683; Tue, 10 Jun 2014 17:39:14 -0700 (PDT)
Received: from [128.32.32.89] (dhcp-32-89.EECS.Berkeley.EDU. [128.32.32.89]) by mx.google.com with ESMTPSA id aj10sm20306418pac.43.2014.06.10.17.39.13 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 10 Jun 2014 17:39:13 -0700 (PDT)
Message-ID: <5397A52D.30605@berkeley.edu>
Date: Tue, 10 Jun 2014 17:39:09 -0700
From: Kris Pister <ksjp@berkeley.edu>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Rene Struik <rstruik.ext@gmail.com>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com> <53974D26.5080504@berkeley.edu> <53976F7B.7040003@gmail.com>
In-Reply-To: <53976F7B.7040003@gmail.com>
Content-Type: multipart/alternative; boundary="------------030306050705090507040104"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/uICRpl-gmqA5gDkcHGX41ZhX32U
Subject: Re: [6tisch-security] tackling outstanding issues #c-2
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Jun 2014 00:39:20 -0000

This is a multi-part message in MIME format.
--------------030306050705090507040104
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Rene - I completely agree with the systems approach to designing the 
security
protocol, but I'm not sure that there is anything in your email that is 
security-specific.
You have pointed out that N=101, Tslot=15ms is not going to work well 
for big
networks, for reasons of security flows as well as any other 
communication flow.
I agree with your conclusion that we need more bandwidth in an 8 hop network
than is provided by 101*15ms.  Some improvement can be had with smaller N,
but a much better approach is to assign dedicated bandwidth using 6top+...

The calculation on 8 hop latency is more subtle than just 8x the one-hop 
packet
interval, but no version of the calculation is going to look good with 
minimal and
101*15ms, so you're right on that one.

Eschewing link-layer ACKs and squeezing in an extra frame into the slot 
is the
first step down a path that leads to insanity and despair.  My vote 
would be to
stick with what the 15.4e standard says that we can do.

ksjp

On 6/10/2014 1:50 PM, Rene Struik wrote:
> Hi Kris:
>
> Thanks for the quick feedback.
>
> When designing a security protocol, one has to consider not just 
> cryptographic properties, but also implementation cost, such as energy 
> cost, RAM/ROM usage, and computational and communication time latency. 
> Thus, while one might argue that "security should not care how the MAC 
> layer is doing its job", this only seems to hold true if one is not 
> interested in non-crypto performance metrics. To 
> implementation-specific metrics mentioned above, one should add 
> potential impact of traffic that seems to be legitimate, but in 
> hindsight does not turn out to be that way (both in terms of 
> denial-of-service attacks, keeping state, etc.). Hence, my question.
>
> So, communication aspects may be quite interesting to consider in 
> detail, e.g., in the context of message relay (see, e.g., DICE WG 
> mailing list, May 30, 2014, 10:29am EDT ---
> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html):
>>> So, I am still interested in getting more insight as to how the 
>>> relay on/off switch would work in practice (which was the question 
>>> in my original email of Tue [snippet copied below]). A description 
>>> of device join operations would help (say, with operational network 
>>> of 1000 nodes with diameter 20 hops, where one wishes to add a 
>>> newbee node A at neighbor B, where B is 10 hops away from network 
>>> manager T).
> From what you suggested below, if one takes slotframe of N=101 
> timeslots of T_slot=15ms, then "goodput" of 1 packet per 8 seconds 
> seems feasible. Does this mean that if one has a network manager 10 
> hops away (my DICE example above), that the communication latency from 
> joining node to and from the network manager is 2*10*8 seconds =160 
> seconds or roughly 2 1/2 minutes and with that between neighbors this 
> is 2*1*8 = 16 seconds? If so, the communication cost seem to far 
> outstrip any other time latency cost (including that due to 
> computational overhead). Please correct me if I am wrong here.
>
> If this is so, this begs the question as to coming up with tricks to 
> squeeze more "bang for the buck" out of TSCH schedules, in case one 
> executes a join protocol. As an example, if one does not use ACK'ed 
> messages (which seems possible with interactive protocols) but - 
> instead - squeezes an extra frame into that particular time/channel 
> slot in the TSCH matrix, one seems to be able to potentially improve 
> time latency by a factor 2x and get enormous time latencies of 2 1/2 
> minutes, resp. 16 seconds, down to 80, resp. 8 seconds.
>
> This is just to illustrate that there is more to security design than 
> meets the eye at first.
>
> Any thoughts?
>
> Rene
>
> On 6/10/2014 2:23 PM, Kris Pister wrote:
>> At some level, the answer is that the security should not care how 
>> the MAC layer is doing its job,
>> as long as the packets get through.  But I agree that it is useful to 
>> see how all of this is going to
>> work together.
>> In the case of minimal, the MAC layer doesn't need to "find" 
>> anything.  Once it has heard an EB,
>> it knows that every N slots there will be a TX/RX cell that it can 
>> use.  If it has nothing to send, it
>> MUST listen.  If it sends and collides, there is a backoff strategy 
>> and it tries again.  Again, this
>> is all transparent to the security processing.
>> The choice of N determines latency, power, available BW, etc. Best 
>> case, motes in the same
>> RF space can send one packet every N*T_slot seconds.  Lots of papers 
>> have been
>> written about the bad things that happen if you try to shove too much 
>> traffic through a
>> network with limited resources.  Minimal will look like slotted 
>> aloha, (possibly with some
>> slightly better performance from preamble capture, maybe CCA, ...), 
>> namely a normalized
>> maximum goodput of GP=1/e with an offered load of G=1.  Running any 
>> aloha-like network
>> near that maximum is very dangerous (chaotic collapse ensues unless 
>> higher layers are smart),
>> so a practical useful normalized goodput of 0.2 is more realistic and 
>> more energy efficient.
>>
>> If N=20, and T_slot=10ms, the network will happily support 
>> 0.2/(N*T_slot) = 1 packet per second
>> among all motes in the same RF space.  If N=101 and T_slot=15ms, then 
>> it's closer to 1 packet
>> every 8 seconds.  That means that it will take a *long* time for a 
>> large dense network to form, which
>> is why we call it "minimal" instead of "optimal" :)
>> Something in the N=10...100 slots is still probably fine for, e.g., a 
>> simple static home network.
>>
>> ksjp
>>
>> On 6/10/2014 7:41 AM, Rene Struik wrote:
>>> Dear colleagues:
>>>
>>> Assumptions:
>>> - Joining node has a minimum schedule (with 101x15ms slotframe) and 
>>> somehow was able to find a time slot to send a first join packet to 
>>> a neighbor node (c-1).
>>> - Computational and communication time latency for response packet 
>>> from neighbor node to joining node is 15ms, 150ms, 750ms, or 5s 
>>> (depending on device capabilities, implementation detail)
>>> - Computational time latency for joining node to compute shared key 
>>> is 15ms, 150ms, 750ms, or 5s (depending on device capabilities, 
>>> implementation detail)
>>>
>>> So, now for question c-2 below:
>>> - How does joining node find out when to open its receiver again, so 
>>> as to receive response packet from neighbor node
>>> - How does neighbor node find out when to receive second packet flow 
>>> from joining node (i.e., after joining node computed shared key)
>>> In particular, should the local schedule allocate multiples of 15ms 
>>> (i.e., each timeslot), 150ms, etc. Obviously, the denser the 
>>> schedule the fewer capacity in terms of #joining nodes that can be 
>>> served?
>>>
>>> So, perhaps, the background of my question c-2 is  now unambiguously 
>>> clear...
>>>
>>> ==
>>> c) Join process impact on network:
>>> Pascal Thubert asked "when network would explode with join". Note 
>>> RS: the following questions come to mind:
>>> c-1) how does joining  node find a time slot to send first join 
>>> packet to neighbor node (presumably, this would require listening 
>>> for Enhanced Beacon, but details on schedule in terms of time and 
>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>> and does not suggest a schedule that would create a common time 
>>> window where two devices would both be awake).
>>> c-2)how does joining node negotiate a local schedule with neighbor 
>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>> refers to local schedule negotiation need, but unclear whether this 
>>> has been looked into in detail).
>>> c-3) for local traffic (joining node/neighbor), it seems Pascal 
>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>> [that seems to have been designed with legacy w/HART in mind 
>>> (centralized solution). With centralized tree-like solution, lots of 
>>> traffic happens close to the root, thus potentially amplifying 
>>> congestion around root node (=network manager?).
>>>
>>> On 6/9/2014 11:51 AM, Rene Struik wrote:
>>>> Dear colleagues:
>>>>
>>>> Please find below a reminder of the outstanding issues re the join 
>>>> protocol, as I originally circulated three weeks ago, prior to our 
>>>> call on Tue May 20, 2014. {As an aside, the week before that, on 
>>>> May 12, 2014, we did discuss the w/HART join process protocol flows 
>>>> (at the time, intention was to agree to align flows with that used 
>>>> there, as motivated in the same email below).}
>>>>
>>>> While current discussions on w/HART protocol have been somewhat 
>>>> interesting, I feel we should put urgent priority on tackling those 
>>>> outstanding issues. So far, I have not seen any traffic on these 
>>>> items from others, so please weigh-in (please include outstanding 
>>>> item # in the subject line, e.g., "outstanding issue #c").
>>>>
>>>> Let us first tackle item #c) below on join process impact on the 
>>>> network. I am particularly interested in detailed deliberations on 
>>>> the three questions on this item that came to my mind here.
>>>>
>>>> When looking at this topic, I would like to encourage you to read 
>>>> the email thread on the IETF DICE list re 
>>>> draft-kumar-dice-dtls-relay-01, which is related to relaying  nodes 
>>>> and potential DoS attacks. I initiated this discussion on May 27th, 
>>>> with last posting on May 30th. See 
>>>> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>>>
>>>> Best regards, Rene
>>>>
>>>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>>>> Hi Michael:
>>>>>
>>>>> At the previous conf call of May 12, 2014, we discussed message 
>>>>> flows of w/HART join process, as also alluded to in my email below 
>>>>> (the specs could not be distributed due to copyright restrictions).
>>>>>
>>>>> In my mind, 6TiSCH protocol can use similar communication flows as 
>>>>> w/HART where only non-local communication flows (between joining 
>>>>> node and network manager) would be
>>>>> i) passing join/authentication information from joining node to 
>>>>> network manager (and back);
>>>>> ii) passing configuration parms from network manager to joining 
>>>>> node (keys, links, frame links) and neighbor report from joined 
>>>>> node to network manager.
>>>>>
>>>>> MAIN OUTSTANDING ISSUES (in my mind):
>>>>> a) Packet sizes:
>>>>> get more info on packet sizes configuration parms, as w/HART uses. 
>>>>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>>>>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., 
>>>>> Dust Networks have info on packet sizes/structure?; ISA SP100.11a 
>>>>> metrics would also help, as would ZigBee 2.0 config parms. Does, 
>>>>> e.g., Cisco have useful data points here?
>>>>> b) Device Ids:
>>>>> With industrial control, network manager would look up "tag name" 
>>>>> device in pre-configured database. Details on tag name syntax, how 
>>>>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>>>>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>>>>> aspects here?
>>>>> c) Join process impact on network:
>>>>> Pascal Thubert asked "when network would explode with join". Note 
>>>>> RS: the following questions come to mind:
>>>>> - how does joining  node find a time slot to send first join 
>>>>> packet to neighbor node (presumably, this would require listening 
>>>>> for Enhanced Beacon, but details on schedule in terms of time and 
>>>>> channels seems incomplete [min-schedule suggests 101x15ms 
>>>>> slotframe and "less than 10s repeat of EBs, but that leaves lots 
>>>>> of dead time and does not suggest a schedule that would create a 
>>>>> common time window where two devices would both be awake).
>>>>> - how does joining node negotiate a local schedule with neighbor 
>>>>> node for execution of join protocol 
>>>>> (draft-watteyne-6tisch-tisch-00 refers to local schedule 
>>>>> negotiation need, but unclear whether this has been looked into in 
>>>>> detail).
>>>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>>>> unclear what impact of "join priority flag TSCH 802.15.4e frames 
>>>>> is [that seems to have been designed with legacy w/HART in mind 
>>>>> (centralized solution). With centralized tree-like solution, lots 
>>>>> of traffic happens close to the root, thus potentially amplifying 
>>>>> congestion around root node (=network manager?).
>>>>> d) crypto protocol details of join protocol:
>>>>> Note RS: I can solve this (close to optimal design already done 
>>>>> [assuming I can do this "without hands tied behind the back"])
>>>>> e) authorization/trust management:
>>>>> it is here where binding of ids to public keys via certs and 
>>>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>>>> authorization messages. Note RS: question is whether ACE could 
>>>>> play a role here (current charter discussions seem to be endless, 
>>>>> though). As has been brought up before, a potential instantiation 
>>>>> of certs would be the use of 802.1ar certs, but this is certainly 
>>>>> not the only way of doing things.
>>>>>
>>>>> There are lots of other things we should consider, outside the 
>>>>> join protocol realm.
>>>>>
>>>>> ------- Original Message --------
>>>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>>>> 6tisch-security@ietf.org
>>>>>
>>>>>
>>>>>
>>>>> Hi Michael et al:
>>>>>
>>>>> Another topic worth exploring more is the join protocol details.
>>>>>
>>>>> (There are many other aspects, including certs, as you mentioned, 
>>>>> more general security architecture, provisioning, etc., but below 
>>>>> only deals with join.)
>>>>>
>>>>> With w/HART, the join process only interacts with the network 
>>>>> manager (62591, Annex A.3, Fig. A.1) for
>>>>> -forwarded join from joining node to network manager;
>>>>> -passing configuration parms from network manager to joining node 
>>>>> (keys, links, frame links) and neighbor report from joined node to 
>>>>> network manager.
>>>>> All other communications are local, between joining device and 
>>>>> neighbor (resp. with maintenance tool).
>>>>>
>>>>> It may have merit if we could use similar communication flows with 
>>>>> 6tisch, i.e., keep most traffic local to the joining device, 
>>>>> except for configuration parms exchange and authorization info 
>>>>> passing.
>>>>>
>>>>> Most important consideration (from communication perspective) 
>>>>> would be that non-local traffic would be minimized, as also w/HART 
>>>>> does. From a marketing perspective, mimicking the communication 
>>>>> flows w/HART already has would keep all time scheduling 
>>>>> considerations for w/HART as currently there and 6TiSCH as to be 
>>>>> detailed roughly the same. This would longer term help in pushing 
>>>>> 6tisch-style security scheme to w/HART, since from a distance it 
>>>>> looks the same (although trying to scrap the maintenance tool).
>>>>>
>>>>> Of course, this does not deal with the details of the joining 
>>>>> protocol itself; only the flows.
>>>>>
>>>>> What about we look at some of the flows, and enumerate all issues 
>>>>> that need to be addressed here, both from a security perspective 
>>>>> and otherwise. We can then assign people to find missing 
>>>>> information (I am esp. curious about how devices know when to 
>>>>> send/receive and contributions of cycling efforts to total time 
>>>>> latency).
>>>>>
>>>>> We could go over w/HART join flows during the call, to trigger 
>>>>> these questions.
>>>>>
>>>>> Best regards, Rene
>>>>>
>>>>>
>>>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>>>> That's 90 minutes from this email.
>>>>>>
>>>>>> 1) notewell.
>>>>>> 2) intros
>>>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>>>     it seems not?
>>>>>> 4) review of claim certificate process, vs EST with token.
>>>>>>
>>>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>>>
>>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>>>
>>>>>> -- we will resume with the etherpad at:
>>>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>>>
>>>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>>>> if you need more than that to get in, or are having difficulties.
>>>>>> Please make sure your audio works, and that you mute when not talking.
>>>>>>
>>>>>>
>>>>>> --
>>>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>>>   -= IPv6 IoT consulting =-
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> _______________________________________________
>>>>>> 6tisch-security mailing list
>>>>>> 6tisch-security@ietf.org
>>>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>>>
>>>>>
>>>>> -- 
>>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>>
>>>>
>>>> -- 
>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>
>>>
>>> -- 
>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>
>>>
>>> _______________________________________________
>>> 6tisch-security mailing list
>>> 6tisch-security@ietf.org
>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>
>>
>>
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------030306050705090507040104
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Rene - I completely agree with the systems approach to designing the
    security<br>
    protocol, but I'm not sure that there is anything in your email that
    is security-specific.<br>
    You have pointed out that N=101, Tslot=15ms is not going to work
    well for big <br>
    networks, for reasons of security flows as well as any other
    communication flow.<br>
    I agree with your conclusion that we need more bandwidth in an 8 hop
    network<br>
    than is provided by 101*15ms.&nbsp; Some improvement can be had with
    smaller N,<br>
    but a much better approach is to assign dedicated bandwidth using
    6top+...<br>
    <br>
    The calculation on 8 hop latency is more subtle than just 8x the
    one-hop packet<br>
    interval, but no version of the calculation is going to look good
    with minimal and<br>
    101*15ms, so you're right on that one.<br>
    <br>
    Eschewing link-layer ACKs and squeezing in an extra frame into the
    slot is the<br>
    first step down a path that leads to insanity and despair.&nbsp; My vote
    would be to<br>
    stick with what the 15.4e standard says that we can do.<br>
    <br>
    ksjp<br>
    <br>
    <div class="moz-cite-prefix">On 6/10/2014 1:50 PM, Rene Struik
      wrote:<br>
    </div>
    <blockquote cite="mid:53976F7B.7040003@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <div class="moz-cite-prefix">Hi Kris:<br>
        <br>
        Thanks for the quick feedback.<br>
        <br>
        When designing a security protocol, one has to consider not just
        cryptographic properties, but also implementation cost, such as
        energy cost, RAM/ROM usage, and computational and communication
        time latency. Thus, while one might argue that "security should
        not care how the MAC layer is doing its job", this only seems to
        hold true if one is not interested in non-crypto performance
        metrics. To implementation-specific metrics mentioned above, one
        should add potential impact of traffic that seems to be
        legitimate, but in hindsight does not turn out to be that way
        (both in terms of denial-of-service attacks, keeping state,
        etc.). Hence, my question.<br>
        <br>
        So, communication aspects may be quite interesting to consider
        in detail, e.g., in the context of message relay (see, e.g.,
        DICE WG mailing list, May 30, 2014, 10:29am EDT ---<br>
        <a moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html</a>):<br>
        <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
          type="cite" style="color: rgb(0, 0, 0); font-family: 'Times
          New Roman'; font-size: medium; font-style: normal;
          font-variant: normal; font-weight: normal; letter-spacing:
          normal; line-height: normal; orphans: auto; text-align: start;
          text-indent: 0px; text-transform: none; white-space: normal;
          widows: auto; word-spacing: 0px; -webkit-text-stroke-width:
          0px; background-color: rgb(255, 255, 255);">
          <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
            type="cite">
            <div class="moz-cite-prefix">So, I am still interested in
              getting more insight as to how the relay on/off switch
              would work in practice (which was the question in my
              original email of Tue [snippet copied below]). A
              description of device join operations would help (say,
              with operational network of 1000 nodes with diameter 20
              hops, where one wishes to add a newbee node A at neighbor
              B, where B is 10 hops away from network manager T).</div>
          </blockquote>
        </blockquote>
        From what you suggested below, if one takes slotframe of N=101
        timeslots of T_slot=15ms, then "goodput" of 1 packet per 8
        seconds seems feasible. Does this mean that if one has a network
        manager 10 hops away (my DICE example above), that the
        communication latency from joining node to and from the network
        manager is 2*10*8 seconds =160 seconds or roughly 2 1/2 minutes
        and with that between neighbors this is 2*1*8 = 16 seconds? If
        so, the communication cost seem to far outstrip any other time
        latency cost (including that due to computational overhead).
        Please correct me if I am wrong here.<br>
        <br>
        If this is so, this begs the question as to coming up with
        tricks to squeeze more "bang for the buck" out of TSCH
        schedules, in case one executes a join protocol. As an example,
        if one does not use ACK'ed messages (which seems possible with
        interactive protocols) but - instead - squeezes an extra frame
        into that particular time/channel slot in the TSCH matrix, one
        seems to be able to potentially improve time latency by a factor
        2x and get enormous time latencies of 2 1/2 minutes, resp. 16
        seconds, down to 80, resp. 8 seconds. <br>
        <br>
        This is just to illustrate that there is more to security design
        than meets the eye at first.<br>
        <br>
        Any thoughts?<br>
        <br>
        Rene<br>
        &nbsp;<br>
        On 6/10/2014 2:23 PM, Kris Pister wrote:<br>
      </div>
      <blockquote cite="mid:53974D26.5080504@berkeley.edu" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        At some level, the answer is that the security should not care
        how the MAC layer is doing its job,<br>
        as long as the packets get through.&nbsp; But I agree that it is
        useful to see how all of this is going to<br>
        work together.<br>
        In the case of minimal, the MAC layer doesn't need to "find"
        anything.&nbsp; Once it has heard an EB,<br>
        it knows that every N slots there will be a TX/RX cell that it
        can use.&nbsp; If it has nothing to send, it<br>
        MUST listen.&nbsp; If it sends and collides, there is a backoff
        strategy and it tries again.&nbsp; Again, this<br>
        is all transparent to the security processing.<br>
        The choice of N determines latency, power, available BW, etc.&nbsp;
        Best case, motes in the same<br>
        RF space can send one packet every N*T_slot seconds.&nbsp; Lots of
        papers have been <br>
        written about the bad things that happen if you try to shove too
        much traffic through a <br>
        network with limited resources.&nbsp; Minimal will look like slotted
        aloha, (possibly with some <br>
        slightly better performance from preamble capture, maybe CCA,
        ...), namely a normalized<br>
        maximum goodput of GP=1/e with an offered load of G=1.&nbsp; Running
        any aloha-like network<br>
        near that maximum is very dangerous (chaotic collapse ensues
        unless higher layers are smart),<br>
        so a practical useful normalized goodput of 0.2 is more
        realistic and more energy efficient.<br>
        <br>
        If N=20, and T_slot=10ms, the network will happily support
        0.2/(N*T_slot) = 1 packet per second<br>
        among all motes in the same RF space.&nbsp; If N=101 and T_slot=15ms,
        then it's closer to 1 packet<br>
        every 8 seconds.&nbsp; That means that it will take a *long* time for
        a large dense network to form, which<br>
        is why we call it "minimal" instead of "optimal" :)<br>
        Something in the N=10...100 slots is still probably fine for,
        e.g., a simple static home network.<br>
        <br>
        ksjp<br>
        <br>
        <div class="moz-cite-prefix">On 6/10/2014 7:41 AM, Rene Struik
          wrote:<br>
        </div>
        <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Dear colleagues:<br>
            <br>
            Assumptions:<br>
            - Joining node has a minimum schedule (with 101x15ms
            slotframe) and somehow was able to find a time slot to send
            a first join packet to a neighbor node (c-1).<br>
            - Computational and communication time latency for response
            packet from neighbor node to joining node is 15ms, 150ms,
            750ms, or 5s (depending on device capabilities,
            implementation detail)<br>
            - Computational time latency for joining node to compute
            shared key is 15ms, 150ms, 750ms, or 5s (depending on device
            capabilities, implementation detail)<br>
            <br>
            So, now for question c-2 below:<br>
            - How does joining node find out when to open its receiver
            again, so as to receive response packet from neighbor node<br>
            - How does neighbor node find out when to receive second
            packet flow from joining node (i.e., after joining node
            computed shared key)<br>
            In particular, should the local schedule allocate multiples
            of 15ms (i.e., each timeslot), 150ms, etc. Obviously, the
            denser the schedule the fewer capacity in terms of #joining
            nodes that can be served?<br>
            <br>
            So, perhaps, the background of my question c-2 is&nbsp; now
            unambiguously clear...<br>
            <br>
            ==<br>
            c) Join process impact on network: <br>
            Pascal Thubert asked "when network would explode with join".
            Note RS: the following questions come to mind:<br>
            c-1) how does joining&nbsp; node find a time slot to send first
            join packet to neighbor node (presumably, this would require
            listening for Enhanced Beacon, but details on schedule in
            terms of time and channels seems incomplete [min-schedule
            suggests 101x15ms slotframe and "less than 10s repeat of
            EBs, but that leaves lots of dead time and does not suggest
            a schedule that would create a common time window where two
            devices would both be awake).<br>
            c-2)how does joining node negotiate a local schedule with
            neighbor node for execution of join protocol
            (draft-watteyne-6tisch-tisch-00 refers to local schedule
            negotiation need, but unclear whether this has been looked
            into in detail).<br>
            c-3) for local traffic (joining node/neighbor), it seems
            Pascal Thubert's "exploding network" may not happen easily.
            Nevertheless, unclear what impact of "join priority flag
            TSCH 802.15.4e frames is [that seems to have been designed
            with legacy w/HART in mind (centralized solution). With
            centralized tree-like solution, lots of traffic happens
            close to the root, thus potentially amplifying congestion
            around root node (=network manager?).<br>
            <br>
            On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
          </div>
          <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
            <meta content="text/html; charset=ISO-8859-1"
              http-equiv="Content-Type">
            <div class="moz-cite-prefix">Dear colleagues:<br>
              <br>
              Please find below a reminder of the outstanding issues re
              the join protocol, as I originally circulated three weeks
              ago, prior to our call on Tue May 20, 2014. {As an aside,
              the week before that, on May 12, 2014, we did discuss the
              w/HART join process protocol flows (at the time, intention
              was to agree to align flows with that used there, as
              motivated in the same email below).}<br>
              <br>
              While current discussions on w/HART protocol have been
              somewhat interesting, I feel we should put urgent priority
              on tackling those outstanding issues. So far, I have not
              seen any traffic on these items from others, so please
              weigh-in (please include outstanding item # in the subject
              line, e.g., "outstanding issue #c").<br>
              <br>
              Let us first tackle item #c) below on join process impact
              on the network. I am particularly interested in detailed
              deliberations on the three questions on this item that
              came to my mind here.<br>
              <br>
              When looking at this topic, I would like to encourage you
              to read the email thread on the IETF DICE list re
              draft-kumar-dice-dtls-relay-01, which is related to
              relaying&nbsp; nodes and potential DoS attacks. I initiated
              this discussion on May 27th, with last posting on May
              30th. See <a moz-do-not-send="true"
                class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
              <br>
              Best regards, Rene<br>
              <br>
              On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
            </div>
            <blockquote cite="mid:537B5C77.5020800@gmail.com"
              type="cite">
              <meta content="text/html; charset=ISO-8859-1"
                http-equiv="Content-Type">
              <div class="moz-cite-prefix">Hi Michael:<br>
                <br>
                At the previous conf call of May 12, 2014, we discussed
                message flows of w/HART join process, as also alluded to
                in my email below (the specs could not be distributed
                due to copyright restrictions).<br>
                <br>
                In my mind, 6TiSCH protocol can use similar
                communication flows as w/HART where only non-local
                communication flows (between joining node and network
                manager) would be <br>
                i) passing join/authentication information from joining
                node to network manager (and back);<br>
                ii) passing configuration parms from network manager to
                joining node (keys, links, frame links) and neighbor
                report from joined node to network manager.<br>
                <br>
                MAIN OUTSTANDING ISSUES (in my mind): <br>
                a) Packet sizes: <br>
                get more info on packet sizes configuration parms, as
                w/HART uses. Note RS: during call, Tom Phinney suggested
                contacting Wally Bratt from HART Comm. Foundation for
                this).&nbsp; Note RS: Shouldn't, e.g., Dust Networks have
                info on packet sizes/structure?; ISA SP100.11a metrics
                would also help, as would ZigBee 2.0 config parms. Does,
                e.g., Cisco have useful data points here?<br>
                b) Device Ids:<br>
                With industrial control, network manager would look up
                "tag name" device in pre-configured database. Details on
                tag name syntax, how assigned, and how bound to, e.g.,
                EUI-64 are missing. Note RS: Perhaps, Tom Phinney could
                point at tag name syntax and lifecycle aspects here?<br>
                c) Join process impact on network: <br>
                Pascal Thubert asked "when network would explode with
                join". Note RS: the following questions come to mind:<br>
                - how does joining&nbsp; node find a time slot to send first
                join packet to neighbor node (presumably, this would
                require listening for Enhanced Beacon, but details on
                schedule in terms of time and channels seems incomplete
                [min-schedule suggests 101x15ms slotframe and "less than
                10s repeat of EBs, but that leaves lots of dead time and
                does not suggest a schedule that would create a common
                time window where two devices would both be awake).<br>
                - how does joining node negotiate a local schedule with
                neighbor node for execution of join protocol
                (draft-watteyne-6tisch-tisch-00 refers to local schedule
                negotiation need, but unclear whether this has been
                looked into in detail).<br>
                - for local traffic (joining node/neighbor), it seems
                Pascal Thubert's "exploding network" may not happen
                easily. Nevertheless, unclear what impact of "join
                priority flag TSCH 802.15.4e frames is [that seems to
                have been designed with legacy w/HART in mind
                (centralized solution). With centralized tree-like
                solution, lots of traffic happens close to the root,
                thus potentially amplifying congestion around root node
                (=network manager?).<br>
                d) crypto protocol details of join protocol:<br>
                Note RS: I can solve this (close to optimal design
                already done [assuming I can do this "without hands tied
                behind the back"])<br>
                e) authorization/trust management:<br>
                it is here where binding of ids to public keys via certs
                and lifecycle aspects play a role, as well as
                syntax/semantics of authorization messages. Note RS:
                question is whether ACE could play a role here (current
                charter discussions seem to be endless, though). As has
                been brought up before, a potential instantiation of
                certs would be the use of 802.1ar certs, but this is
                certainly not the only way of doing things.<br>
                <br>
                There are lots of other things we should consider,
                outside the join protocol realm.<br>
                <br>
                ------- Original Message --------
                <table class="moz-email-headers-table" cellpadding="0"
                  cellspacing="0" border="0">
                  <tbody>
                    <tr>
                      <th align="RIGHT" nowrap="nowrap"
                        valign="BASELINE">Subject: </th>
                      <td>Re: [6tisch-security] agenda(?) for call today</td>
                    </tr>
                    <tr>
                      <th align="RIGHT" nowrap="nowrap"
                        valign="BASELINE">Date: </th>
                      <td>Mon, 12 May 2014 09:53:37 -0400</td>
                    </tr>
                    <tr>
                      <th align="RIGHT" nowrap="nowrap"
                        valign="BASELINE">From: </th>
                      <td>Rene Struik <a moz-do-not-send="true"
                          class="moz-txt-link-rfc2396E"
                          href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                    </tr>
                    <tr>
                      <th align="RIGHT" nowrap="nowrap"
                        valign="BASELINE">To: </th>
                      <td>Michael Richardson <a moz-do-not-send="true"
                          class="moz-txt-link-rfc2396E"
                          href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                        <a moz-do-not-send="true"
                          class="moz-txt-link-abbreviated"
                          href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                    </tr>
                  </tbody>
                </table>
                <br>
                <br>
                <div class="moz-cite-prefix">Hi Michael et al:<br>
                  <br>
                  Another topic worth exploring more is the join
                  protocol details. <br>
                  <br>
                  (There are many other aspects, including certs, as you
                  mentioned, more general security architecture,
                  provisioning, etc., but below only deals with join.)<br>
                  <br>
                  With w/HART, the join process only interacts with the
                  network manager (62591, Annex A.3, Fig. A.1) for <br>
                  -forwarded join from joining node to network manager;<br>
                  -passing configuration parms from network manager to
                  joining node (keys, links, frame links) and neighbor
                  report from joined node to network manager.<br>
                  All other communications are local, between joining
                  device and neighbor (resp. with maintenance tool).<br>
                  <br>
                  It may have merit if we could use similar
                  communication flows with 6tisch, i.e., keep most
                  traffic local to the joining device, except for
                  configuration parms exchange and authorization info
                  passing. <br>
                  <br>
                  Most important consideration (from communication
                  perspective) would be that non-local traffic would be
                  minimized, as also w/HART does. From a marketing
                  perspective, mimicking the communication flows w/HART
                  already has would keep all time scheduling
                  considerations for w/HART as currently there and
                  6TiSCH as to be detailed roughly the same. This would
                  longer term help in pushing 6tisch-style security
                  scheme to w/HART, since from a distance it looks the
                  same (although trying to scrap the maintenance tool).<br>
                  <br>
                  Of course, this does not deal with the details of the
                  joining protocol itself; only the flows.<br>
                  <br>
                  What about we look at some of the flows, and enumerate
                  all issues that need to be addressed here, both from a
                  security perspective and otherwise. We can then assign
                  people to find missing information (I am esp. curious
                  about how devices know when to send/receive and
                  contributions of cycling efforts to total time
                  latency). <br>
                  <br>
                  We could go over w/HART join flows during the call, to
                  trigger these questions.<br>
                  <br>
                  Best regards, Rene<br>
                </div>
                <br>
                <br>
                On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
              </div>
              <blockquote cite="mid:19475.1400588783@sandelman.ca"
                type="cite">
                <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
                <br>
                <fieldset class="mimeAttachmentHeader"></fieldset>
                <br>
                <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
              </blockquote>
              <br>
              <br>
              <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
            </blockquote>
            <br>
            <br>
            <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
          </blockquote>
          <br>
          <br>
          <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
          <br>
          <fieldset class="mimeAttachmentHeader"></fieldset>
          <br>
          <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
        </blockquote>
        <br>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
        <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------030306050705090507040104--


From nobody Wed Jun 11 07:23:18 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A33A1A0545 for <6tisch-security@ietfa.amsl.com>; Wed, 11 Jun 2014 07:23:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hA6099-ySHb9 for <6tisch-security@ietfa.amsl.com>; Wed, 11 Jun 2014 07:23:08 -0700 (PDT)
Received: from mail-ie0-x232.google.com (mail-ie0-x232.google.com [IPv6:2607:f8b0:4001:c03::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CA76C1A010D for <6tisch-security@ietf.org>; Wed, 11 Jun 2014 07:23:07 -0700 (PDT)
Received: by mail-ie0-f178.google.com with SMTP id rd18so1727305iec.9 for <6tisch-security@ietf.org>; Wed, 11 Jun 2014 07:23:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=WZHfQHw9dlYK7iZmF8ab0Jq/2omwqQlbQ6nc43N0h04=; b=tGF3KjQo8txxSRnSdRyUY8/BaYxaW4/zs1af2N/IXMT4xq5w8MlbIG6tkopjyxGj9Q pj1BFuGcJP4RkPGjKaYlqezovOTXFryRSMEcwFcSB6empylyshzVJ7OXKIR6CMl+AN/F 52vvN8Sz+uklQEhD8iYh4tjWnYoVPTkVap+/e+M43Mxdzvqvcv2w4jN1ewr1DnPsNsfE DTBqHc0bQYIPAQiDbJy2wXVRLt3OeN6padqRCkYujOYh/x/ni0hHq9crLKoL+2Q4d+Fs C8ku+zdtBhJ/QWHZfWks636JsaTvgLhXpBavOThzSOXAXGwIg30bTmjPIaR4HEetOf3v Yk2w==
X-Received: by 10.42.68.18 with SMTP id v18mr44401328ici.1.1402496587077; Wed, 11 Jun 2014 07:23:07 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id o2sm67525452igp.12.2014.06.11.07.23.05 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 11 Jun 2014 07:23:06 -0700 (PDT)
Message-ID: <53986645.6000803@gmail.com>
Date: Wed, 11 Jun 2014 10:23:01 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: Kris Pister <ksjp@berkeley.edu>, 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com> <53974D26.5080504@berkeley.edu> <53976F7B.7040003@gmail.com> <5397A52D.30605@berkeley.edu>
In-Reply-To: <5397A52D.30605@berkeley.edu>
Content-Type: multipart/alternative; boundary="------------050709090500060506070106"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/SYlA5dEF8zLvUJUExGHfAJCcA5w
Subject: Re: [6tisch-security] tackling outstanding issues #c-2
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Jun 2014 14:23:13 -0000

This is a multi-part message in MIME format.
--------------050709090500060506070106
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

So, perhaps, this leads us back to the original #c-2 question: how to 
get this dedicated bandwidth on the local joining node - neighbor level 
(how to determine suitable capacity, how to assign) and, perhaps, 
consider non-local capacity assignment aspects as well. More detailed 
question would be whether this dedicated bandwidth would be 
on-the-fly/on-demand or static.

    c-2)how does joining node negotiate a local schedule with neighbor
    node for execution of join protocol (draft-watteyne-6tisch-tisch-00
    refers to local schedule negotiation need, but unclear whether this
    has been looked into in detail).

 From the example metrics (N=101, Tslot=15ms) below, it seems that we 
can already conclude that communication latency considerations should 
heavily influence security protocol design, in the sense that non-local 
communications should be minimized (my item #c and preamble to my 
outstanding issue list).

==
Some improvement can be had with smaller N, but a much better approach 
is to assign dedicated bandwidth using 6top+..

Best regards, Rene

On 6/10/2014 8:39 PM, Kris Pister wrote:
> Rene - I completely agree with the systems approach to designing the 
> security
> protocol, but I'm not sure that there is anything in your email that 
> is security-specific.
> You have pointed out that N=101, Tslot=15ms is not going to work well 
> for big
> networks, for reasons of security flows as well as any other 
> communication flow.
> I agree with your conclusion that we need more bandwidth in an 8 hop 
> network
> than is provided by 101*15ms.  Some improvement can be had with smaller N,
> but a much better approach is to assign dedicated bandwidth using 6top+...
>
> The calculation on 8 hop latency is more subtle than just 8x the 
> one-hop packet
> interval, but no version of the calculation is going to look good with 
> minimal and
> 101*15ms, so you're right on that one.
>
> Eschewing link-layer ACKs and squeezing in an extra frame into the 
> slot is the
> first step down a path that leads to insanity and despair.  My vote 
> would be to
> stick with what the 15.4e standard says that we can do.
>
> ksjp
>
> On 6/10/2014 1:50 PM, Rene Struik wrote:
>> Hi Kris:
>>
>> Thanks for the quick feedback.
>>
>> When designing a security protocol, one has to consider not just 
>> cryptographic properties, but also implementation cost, such as 
>> energy cost, RAM/ROM usage, and computational and communication time 
>> latency. Thus, while one might argue that "security should not care 
>> how the MAC layer is doing its job", this only seems to hold true if 
>> one is not interested in non-crypto performance metrics. To 
>> implementation-specific metrics mentioned above, one should add 
>> potential impact of traffic that seems to be legitimate, but in 
>> hindsight does not turn out to be that way (both in terms of 
>> denial-of-service attacks, keeping state, etc.). Hence, my question.
>>
>> So, communication aspects may be quite interesting to consider in 
>> detail, e.g., in the context of message relay (see, e.g., DICE WG 
>> mailing list, May 30, 2014, 10:29am EDT ---
>> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html):
>>>> So, I am still interested in getting more insight as to how the 
>>>> relay on/off switch would work in practice (which was the question 
>>>> in my original email of Tue [snippet copied below]). A description 
>>>> of device join operations would help (say, with operational network 
>>>> of 1000 nodes with diameter 20 hops, where one wishes to add a 
>>>> newbee node A at neighbor B, where B is 10 hops away from network 
>>>> manager T).
>> From what you suggested below, if one takes slotframe of N=101 
>> timeslots of T_slot=15ms, then "goodput" of 1 packet per 8 seconds 
>> seems feasible. Does this mean that if one has a network manager 10 
>> hops away (my DICE example above), that the communication latency 
>> from joining node to and from the network manager is 2*10*8 seconds 
>> =160 seconds or roughly 2 1/2 minutes and with that between neighbors 
>> this is 2*1*8 = 16 seconds? If so, the communication cost seem to far 
>> outstrip any other time latency cost (including that due to 
>> computational overhead). Please correct me if I am wrong here.
>>
>> If this is so, this begs the question as to coming up with tricks to 
>> squeeze more "bang for the buck" out of TSCH schedules, in case one 
>> executes a join protocol. As an example, if one does not use ACK'ed 
>> messages (which seems possible with interactive protocols) but - 
>> instead - squeezes an extra frame into that particular time/channel 
>> slot in the TSCH matrix, one seems to be able to potentially improve 
>> time latency by a factor 2x and get enormous time latencies of 2 1/2 
>> minutes, resp. 16 seconds, down to 80, resp. 8 seconds.
>>
>> This is just to illustrate that there is more to security design than 
>> meets the eye at first.
>>
>> Any thoughts?
>>
>> Rene
>>
>> On 6/10/2014 2:23 PM, Kris Pister wrote:
>>> At some level, the answer is that the security should not care how 
>>> the MAC layer is doing its job,
>>> as long as the packets get through.  But I agree that it is useful 
>>> to see how all of this is going to
>>> work together.
>>> In the case of minimal, the MAC layer doesn't need to "find" 
>>> anything.  Once it has heard an EB,
>>> it knows that every N slots there will be a TX/RX cell that it can 
>>> use.  If it has nothing to send, it
>>> MUST listen.  If it sends and collides, there is a backoff strategy 
>>> and it tries again.  Again, this
>>> is all transparent to the security processing.
>>> The choice of N determines latency, power, available BW, etc. Best 
>>> case, motes in the same
>>> RF space can send one packet every N*T_slot seconds.  Lots of papers 
>>> have been
>>> written about the bad things that happen if you try to shove too 
>>> much traffic through a
>>> network with limited resources.  Minimal will look like slotted 
>>> aloha, (possibly with some
>>> slightly better performance from preamble capture, maybe CCA, ...), 
>>> namely a normalized
>>> maximum goodput of GP=1/e with an offered load of G=1. Running any 
>>> aloha-like network
>>> near that maximum is very dangerous (chaotic collapse ensues unless 
>>> higher layers are smart),
>>> so a practical useful normalized goodput of 0.2 is more realistic 
>>> and more energy efficient.
>>>
>>> If N=20, and T_slot=10ms, the network will happily support 
>>> 0.2/(N*T_slot) = 1 packet per second
>>> among all motes in the same RF space.  If N=101 and T_slot=15ms, 
>>> then it's closer to 1 packet
>>> every 8 seconds.  That means that it will take a *long* time for a 
>>> large dense network to form, which
>>> is why we call it "minimal" instead of "optimal" :)
>>> Something in the N=10...100 slots is still probably fine for, e.g., 
>>> a simple static home network.
>>>
>>> ksjp
>>>
>>> On 6/10/2014 7:41 AM, Rene Struik wrote:
>>>> Dear colleagues:
>>>>
>>>> Assumptions:
>>>> - Joining node has a minimum schedule (with 101x15ms slotframe) and 
>>>> somehow was able to find a time slot to send a first join packet to 
>>>> a neighbor node (c-1).
>>>> - Computational and communication time latency for response packet 
>>>> from neighbor node to joining node is 15ms, 150ms, 750ms, or 5s 
>>>> (depending on device capabilities, implementation detail)
>>>> - Computational time latency for joining node to compute shared key 
>>>> is 15ms, 150ms, 750ms, or 5s (depending on device capabilities, 
>>>> implementation detail)
>>>>
>>>> So, now for question c-2 below:
>>>> - How does joining node find out when to open its receiver again, 
>>>> so as to receive response packet from neighbor node
>>>> - How does neighbor node find out when to receive second packet 
>>>> flow from joining node (i.e., after joining node computed shared key)
>>>> In particular, should the local schedule allocate multiples of 15ms 
>>>> (i.e., each timeslot), 150ms, etc. Obviously, the denser the 
>>>> schedule the fewer capacity in terms of #joining nodes that can be 
>>>> served?
>>>>
>>>> So, perhaps, the background of my question c-2 is  now 
>>>> unambiguously clear...
>>>>
>>>> ==
>>>> c) Join process impact on network:
>>>> Pascal Thubert asked "when network would explode with join". Note 
>>>> RS: the following questions come to mind:
>>>> c-1) how does joining  node find a time slot to send first join 
>>>> packet to neighbor node (presumably, this would require listening 
>>>> for Enhanced Beacon, but details on schedule in terms of time and 
>>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>>> and does not suggest a schedule that would create a common time 
>>>> window where two devices would both be awake).
>>>> c-2)how does joining node negotiate a local schedule with neighbor 
>>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>>> refers to local schedule negotiation need, but unclear whether this 
>>>> has been looked into in detail).
>>>> c-3) for local traffic (joining node/neighbor), it seems Pascal 
>>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>>> [that seems to have been designed with legacy w/HART in mind 
>>>> (centralized solution). With centralized tree-like solution, lots 
>>>> of traffic happens close to the root, thus potentially amplifying 
>>>> congestion around root node (=network manager?).
>>>>
>>>> On 6/9/2014 11:51 AM, Rene Struik wrote:
>>>>> Dear colleagues:
>>>>>
>>>>> Please find below a reminder of the outstanding issues re the join 
>>>>> protocol, as I originally circulated three weeks ago, prior to our 
>>>>> call on Tue May 20, 2014. {As an aside, the week before that, on 
>>>>> May 12, 2014, we did discuss the w/HART join process protocol 
>>>>> flows (at the time, intention was to agree to align flows with 
>>>>> that used there, as motivated in the same email below).}
>>>>>
>>>>> While current discussions on w/HART protocol have been somewhat 
>>>>> interesting, I feel we should put urgent priority on tackling 
>>>>> those outstanding issues. So far, I have not seen any traffic on 
>>>>> these items from others, so please weigh-in (please include 
>>>>> outstanding item # in the subject line, e.g., "outstanding issue #c").
>>>>>
>>>>> Let us first tackle item #c) below on join process impact on the 
>>>>> network. I am particularly interested in detailed deliberations on 
>>>>> the three questions on this item that came to my mind here.
>>>>>
>>>>> When looking at this topic, I would like to encourage you to read 
>>>>> the email thread on the IETF DICE list re 
>>>>> draft-kumar-dice-dtls-relay-01, which is related to relaying  
>>>>> nodes and potential DoS attacks. I initiated this discussion on 
>>>>> May 27th, with last posting on May 30th. See 
>>>>> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>>>>
>>>>> Best regards, Rene
>>>>>
>>>>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>>>>> Hi Michael:
>>>>>>
>>>>>> At the previous conf call of May 12, 2014, we discussed message 
>>>>>> flows of w/HART join process, as also alluded to in my email 
>>>>>> below (the specs could not be distributed due to copyright 
>>>>>> restrictions).
>>>>>>
>>>>>> In my mind, 6TiSCH protocol can use similar communication flows 
>>>>>> as w/HART where only non-local communication flows (between 
>>>>>> joining node and network manager) would be
>>>>>> i) passing join/authentication information from joining node to 
>>>>>> network manager (and back);
>>>>>> ii) passing configuration parms from network manager to joining 
>>>>>> node (keys, links, frame links) and neighbor report from joined 
>>>>>> node to network manager.
>>>>>>
>>>>>> MAIN OUTSTANDING ISSUES (in my mind):
>>>>>> a) Packet sizes:
>>>>>> get more info on packet sizes configuration parms, as w/HART 
>>>>>> uses. Note RS: during call, Tom Phinney suggested contacting 
>>>>>> Wally Bratt from HART Comm. Foundation for this).  Note RS: 
>>>>>> Shouldn't, e.g., Dust Networks have info on packet 
>>>>>> sizes/structure?; ISA SP100.11a metrics would also help, as would 
>>>>>> ZigBee 2.0 config parms. Does, e.g., Cisco have useful data 
>>>>>> points here?
>>>>>> b) Device Ids:
>>>>>> With industrial control, network manager would look up "tag name" 
>>>>>> device in pre-configured database. Details on tag name syntax, 
>>>>>> how assigned, and how bound to, e.g., EUI-64 are missing. Note 
>>>>>> RS: Perhaps, Tom Phinney could point at tag name syntax and 
>>>>>> lifecycle aspects here?
>>>>>> c) Join process impact on network:
>>>>>> Pascal Thubert asked "when network would explode with join". Note 
>>>>>> RS: the following questions come to mind:
>>>>>> - how does joining  node find a time slot to send first join 
>>>>>> packet to neighbor node (presumably, this would require listening 
>>>>>> for Enhanced Beacon, but details on schedule in terms of time and 
>>>>>> channels seems incomplete [min-schedule suggests 101x15ms 
>>>>>> slotframe and "less than 10s repeat of EBs, but that leaves lots 
>>>>>> of dead time and does not suggest a schedule that would create a 
>>>>>> common time window where two devices would both be awake).
>>>>>> - how does joining node negotiate a local schedule with neighbor 
>>>>>> node for execution of join protocol 
>>>>>> (draft-watteyne-6tisch-tisch-00 refers to local schedule 
>>>>>> negotiation need, but unclear whether this has been looked into 
>>>>>> in detail).
>>>>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>>>>> Thubert's "exploding network" may not happen easily. 
>>>>>> Nevertheless, unclear what impact of "join priority flag TSCH 
>>>>>> 802.15.4e frames is [that seems to have been designed with legacy 
>>>>>> w/HART in mind (centralized solution). With centralized tree-like 
>>>>>> solution, lots of traffic happens close to the root, thus 
>>>>>> potentially amplifying congestion around root node (=network 
>>>>>> manager?).
>>>>>> d) crypto protocol details of join protocol:
>>>>>> Note RS: I can solve this (close to optimal design already done 
>>>>>> [assuming I can do this "without hands tied behind the back"])
>>>>>> e) authorization/trust management:
>>>>>> it is here where binding of ids to public keys via certs and 
>>>>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>>>>> authorization messages. Note RS: question is whether ACE could 
>>>>>> play a role here (current charter discussions seem to be endless, 
>>>>>> though). As has been brought up before, a potential instantiation 
>>>>>> of certs would be the use of 802.1ar certs, but this is certainly 
>>>>>> not the only way of doing things.
>>>>>>
>>>>>> There are lots of other things we should consider, outside the 
>>>>>> join protocol realm.
>>>>>>
>>>>>> ------- Original Message --------
>>>>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>>>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>>>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>>>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>>>>> 6tisch-security@ietf.org
>>>>>>
>>>>>>
>>>>>>
>>>>>> Hi Michael et al:
>>>>>>
>>>>>> Another topic worth exploring more is the join protocol details.
>>>>>>
>>>>>> (There are many other aspects, including certs, as you mentioned, 
>>>>>> more general security architecture, provisioning, etc., but below 
>>>>>> only deals with join.)
>>>>>>
>>>>>> With w/HART, the join process only interacts with the network 
>>>>>> manager (62591, Annex A.3, Fig. A.1) for
>>>>>> -forwarded join from joining node to network manager;
>>>>>> -passing configuration parms from network manager to joining node 
>>>>>> (keys, links, frame links) and neighbor report from joined node 
>>>>>> to network manager.
>>>>>> All other communications are local, between joining device and 
>>>>>> neighbor (resp. with maintenance tool).
>>>>>>
>>>>>> It may have merit if we could use similar communication flows 
>>>>>> with 6tisch, i.e., keep most traffic local to the joining device, 
>>>>>> except for configuration parms exchange and authorization info 
>>>>>> passing.
>>>>>>
>>>>>> Most important consideration (from communication perspective) 
>>>>>> would be that non-local traffic would be minimized, as also 
>>>>>> w/HART does. From a marketing perspective, mimicking the 
>>>>>> communication flows w/HART already has would keep all time 
>>>>>> scheduling considerations for w/HART as currently there and 
>>>>>> 6TiSCH as to be detailed roughly the same. This would longer term 
>>>>>> help in pushing 6tisch-style security scheme to w/HART, since 
>>>>>> from a distance it looks the same (although trying to scrap the 
>>>>>> maintenance tool).
>>>>>>
>>>>>> Of course, this does not deal with the details of the joining 
>>>>>> protocol itself; only the flows.
>>>>>>
>>>>>> What about we look at some of the flows, and enumerate all issues 
>>>>>> that need to be addressed here, both from a security perspective 
>>>>>> and otherwise. We can then assign people to find missing 
>>>>>> information (I am esp. curious about how devices know when to 
>>>>>> send/receive and contributions of cycling efforts to total time 
>>>>>> latency).
>>>>>>
>>>>>> We could go over w/HART join flows during the call, to trigger 
>>>>>> these questions.
>>>>>>
>>>>>> Best regards, Rene
>>>>>>
>>>>>>
>>>>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>>>>> That's 90 minutes from this email.
>>>>>>>
>>>>>>> 1) notewell.
>>>>>>> 2) intros
>>>>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>>>>     it seems not?
>>>>>>> 4) review of claim certificate process, vs EST with token.
>>>>>>>
>>>>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>>>>
>>>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>>>>
>>>>>>> -- we will resume with the etherpad at:
>>>>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>>>>
>>>>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>>>>> if you need more than that to get in, or are having difficulties.
>>>>>>> Please make sure your audio works, and that you mute when not talking.
>>>>>>>
>>>>>>>
>>>>>>> --
>>>>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>>>>   -= IPv6 IoT consulting =-
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> _______________________________________________
>>>>>>> 6tisch-security mailing list
>>>>>>> 6tisch-security@ietf.org
>>>>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>>>>
>>>>>>
>>>>>> -- 
>>>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>>>
>>>>>
>>>>> -- 
>>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>>
>>>>
>>>> -- 
>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>>
>>>>
>>>> _______________________________________________
>>>> 6tisch-security mailing list
>>>> 6tisch-security@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>
>>>
>>>
>>> _______________________________________________
>>> 6tisch-security mailing list
>>> 6tisch-security@ietf.org
>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------050709090500060506070106
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix"> So, perhaps, this leads us back to the
      original #c-2 question: how to get this dedicated bandwidth on the
      local joining node - neighbor level (how to determine suitable
      capacity, how to assign) and, perhaps, consider non-local capacity
      assignment aspects as well. More detailed question would be
      whether this dedicated bandwidth would be on-the-fly/on-demand or
      static.<br>
      <blockquote>c-2)how does joining node negotiate a local schedule
        with neighbor node for execution of join protocol
        (draft-watteyne-6tisch-tisch-00 refers to local schedule
        negotiation need, but unclear whether this has been looked into
        in detail).<br>
      </blockquote>
      From the example metrics (N=101, Tslot=15ms) below, it seems that
      we can already conclude that communication latency considerations
      should heavily influence security protocol design, in the sense
      that non-local communications should be minimized (my item #c and
      preamble to my outstanding issue list).<br>
      <br>
      ==<br>
      Some improvement can be had with smaller N, but a much better
      approach is to assign dedicated bandwidth using 6top+..<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 6/10/2014 8:39 PM, Kris Pister wrote:<br>
    </div>
    <blockquote cite="mid:5397A52D.30605@berkeley.edu" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      Rene - I completely agree with the systems approach to designing
      the security<br>
      protocol, but I'm not sure that there is anything in your email
      that is security-specific.<br>
      You have pointed out that N=101, Tslot=15ms is not going to work
      well for big <br>
      networks, for reasons of security flows as well as any other
      communication flow.<br>
      I agree with your conclusion that we need more bandwidth in an 8
      hop network<br>
      than is provided by 101*15ms.&nbsp; Some improvement can be had with
      smaller N,<br>
      but a much better approach is to assign dedicated bandwidth using
      6top+...<br>
      <br>
      The calculation on 8 hop latency is more subtle than just 8x the
      one-hop packet<br>
      interval, but no version of the calculation is going to look good
      with minimal and<br>
      101*15ms, so you're right on that one.<br>
      <br>
      Eschewing link-layer ACKs and squeezing in an extra frame into the
      slot is the<br>
      first step down a path that leads to insanity and despair.&nbsp; My
      vote would be to<br>
      stick with what the 15.4e standard says that we can do.<br>
      <br>
      ksjp<br>
      <br>
      <div class="moz-cite-prefix">On 6/10/2014 1:50 PM, Rene Struik
        wrote:<br>
      </div>
      <blockquote cite="mid:53976F7B.7040003@gmail.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        <div class="moz-cite-prefix">Hi Kris:<br>
          <br>
          Thanks for the quick feedback.<br>
          <br>
          When designing a security protocol, one has to consider not
          just cryptographic properties, but also implementation cost,
          such as energy cost, RAM/ROM usage, and computational and
          communication time latency. Thus, while one might argue that
          "security should not care how the MAC layer is doing its job",
          this only seems to hold true if one is not interested in
          non-crypto performance metrics. To implementation-specific
          metrics mentioned above, one should add potential impact of
          traffic that seems to be legitimate, but in hindsight does not
          turn out to be that way (both in terms of denial-of-service
          attacks, keeping state, etc.). Hence, my question.<br>
          <br>
          So, communication aspects may be quite interesting to consider
          in detail, e.g., in the context of message relay (see, e.g.,
          DICE WG mailing list, May 30, 2014, 10:29am EDT ---<br>
          <a moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html</a>):<br>
          <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
            type="cite" style="color: rgb(0, 0, 0); font-family: 'Times
            New Roman'; font-size: medium; font-style: normal;
            font-variant: normal; font-weight: normal; letter-spacing:
            normal; line-height: normal; orphans: auto; text-align:
            start; text-indent: 0px; text-transform: none; white-space:
            normal; widows: auto; word-spacing: 0px;
            -webkit-text-stroke-width: 0px; background-color: rgb(255,
            255, 255);">
            <blockquote
cite="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00252.html"
              type="cite">
              <div class="moz-cite-prefix">So, I am still interested in
                getting more insight as to how the relay on/off switch
                would work in practice (which was the question in my
                original email of Tue [snippet copied below]). A
                description of device join operations would help (say,
                with operational network of 1000 nodes with diameter 20
                hops, where one wishes to add a newbee node A at
                neighbor B, where B is 10 hops away from network manager
                T).</div>
            </blockquote>
          </blockquote>
          From what you suggested below, if one takes slotframe of N=101
          timeslots of T_slot=15ms, then "goodput" of 1 packet per 8
          seconds seems feasible. Does this mean that if one has a
          network manager 10 hops away (my DICE example above), that the
          communication latency from joining node to and from the
          network manager is 2*10*8 seconds =160 seconds or roughly 2
          1/2 minutes and with that between neighbors this is 2*1*8 = 16
          seconds? If so, the communication cost seem to far outstrip
          any other time latency cost (including that due to
          computational overhead). Please correct me if I am wrong here.<br>
          <br>
          If this is so, this begs the question as to coming up with
          tricks to squeeze more "bang for the buck" out of TSCH
          schedules, in case one executes a join protocol. As an
          example, if one does not use ACK'ed messages (which seems
          possible with interactive protocols) but - instead - squeezes
          an extra frame into that particular time/channel slot in the
          TSCH matrix, one seems to be able to potentially improve time
          latency by a factor 2x and get enormous time latencies of 2
          1/2 minutes, resp. 16 seconds, down to 80, resp. 8 seconds. <br>
          <br>
          This is just to illustrate that there is more to security
          design than meets the eye at first.<br>
          <br>
          Any thoughts?<br>
          <br>
          Rene<br>
          &nbsp;<br>
          On 6/10/2014 2:23 PM, Kris Pister wrote:<br>
        </div>
        <blockquote cite="mid:53974D26.5080504@berkeley.edu" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          At some level, the answer is that the security should not care
          how the MAC layer is doing its job,<br>
          as long as the packets get through.&nbsp; But I agree that it is
          useful to see how all of this is going to<br>
          work together.<br>
          In the case of minimal, the MAC layer doesn't need to "find"
          anything.&nbsp; Once it has heard an EB,<br>
          it knows that every N slots there will be a TX/RX cell that it
          can use.&nbsp; If it has nothing to send, it<br>
          MUST listen.&nbsp; If it sends and collides, there is a backoff
          strategy and it tries again.&nbsp; Again, this<br>
          is all transparent to the security processing.<br>
          The choice of N determines latency, power, available BW, etc.&nbsp;
          Best case, motes in the same<br>
          RF space can send one packet every N*T_slot seconds.&nbsp; Lots of
          papers have been <br>
          written about the bad things that happen if you try to shove
          too much traffic through a <br>
          network with limited resources.&nbsp; Minimal will look like
          slotted aloha, (possibly with some <br>
          slightly better performance from preamble capture, maybe CCA,
          ...), namely a normalized<br>
          maximum goodput of GP=1/e with an offered load of G=1.&nbsp;
          Running any aloha-like network<br>
          near that maximum is very dangerous (chaotic collapse ensues
          unless higher layers are smart),<br>
          so a practical useful normalized goodput of 0.2 is more
          realistic and more energy efficient.<br>
          <br>
          If N=20, and T_slot=10ms, the network will happily support
          0.2/(N*T_slot) = 1 packet per second<br>
          among all motes in the same RF space.&nbsp; If N=101 and
          T_slot=15ms, then it's closer to 1 packet<br>
          every 8 seconds.&nbsp; That means that it will take a *long* time
          for a large dense network to form, which<br>
          is why we call it "minimal" instead of "optimal" :)<br>
          Something in the N=10...100 slots is still probably fine for,
          e.g., a simple static home network.<br>
          <br>
          ksjp<br>
          <br>
          <div class="moz-cite-prefix">On 6/10/2014 7:41 AM, Rene Struik
            wrote:<br>
          </div>
          <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
            <meta content="text/html; charset=ISO-8859-1"
              http-equiv="Content-Type">
            <div class="moz-cite-prefix">Dear colleagues:<br>
              <br>
              Assumptions:<br>
              - Joining node has a minimum schedule (with 101x15ms
              slotframe) and somehow was able to find a time slot to
              send a first join packet to a neighbor node (c-1).<br>
              - Computational and communication time latency for
              response packet from neighbor node to joining node is
              15ms, 150ms, 750ms, or 5s (depending on device
              capabilities, implementation detail)<br>
              - Computational time latency for joining node to compute
              shared key is 15ms, 150ms, 750ms, or 5s (depending on
              device capabilities, implementation detail)<br>
              <br>
              So, now for question c-2 below:<br>
              - How does joining node find out when to open its receiver
              again, so as to receive response packet from neighbor node<br>
              - How does neighbor node find out when to receive second
              packet flow from joining node (i.e., after joining node
              computed shared key)<br>
              In particular, should the local schedule allocate
              multiples of 15ms (i.e., each timeslot), 150ms, etc.
              Obviously, the denser the schedule the fewer capacity in
              terms of #joining nodes that can be served?<br>
              <br>
              So, perhaps, the background of my question c-2 is&nbsp; now
              unambiguously clear...<br>
              <br>
              ==<br>
              c) Join process impact on network: <br>
              Pascal Thubert asked "when network would explode with
              join". Note RS: the following questions come to mind:<br>
              c-1) how does joining&nbsp; node find a time slot to send first
              join packet to neighbor node (presumably, this would
              require listening for Enhanced Beacon, but details on
              schedule in terms of time and channels seems incomplete
              [min-schedule suggests 101x15ms slotframe and "less than
              10s repeat of EBs, but that leaves lots of dead time and
              does not suggest a schedule that would create a common
              time window where two devices would both be awake).<br>
              c-2)how does joining node negotiate a local schedule with
              neighbor node for execution of join protocol
              (draft-watteyne-6tisch-tisch-00 refers to local schedule
              negotiation need, but unclear whether this has been looked
              into in detail).<br>
              c-3) for local traffic (joining node/neighbor), it seems
              Pascal Thubert's "exploding network" may not happen
              easily. Nevertheless, unclear what impact of "join
              priority flag TSCH 802.15.4e frames is [that seems to have
              been designed with legacy w/HART in mind (centralized
              solution). With centralized tree-like solution, lots of
              traffic happens close to the root, thus potentially
              amplifying congestion around root node (=network
              manager?).<br>
              <br>
              On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
            </div>
            <blockquote cite="mid:5395D7E4.1010200@gmail.com"
              type="cite">
              <meta content="text/html; charset=ISO-8859-1"
                http-equiv="Content-Type">
              <div class="moz-cite-prefix">Dear colleagues:<br>
                <br>
                Please find below a reminder of the outstanding issues
                re the join protocol, as I originally circulated three
                weeks ago, prior to our call on Tue May 20, 2014. {As an
                aside, the week before that, on May 12, 2014, we did
                discuss the w/HART join process protocol flows (at the
                time, intention was to agree to align flows with that
                used there, as motivated in the same email below).}<br>
                <br>
                While current discussions on w/HART protocol have been
                somewhat interesting, I feel we should put urgent
                priority on tackling those outstanding issues. So far, I
                have not seen any traffic on these items from others, so
                please weigh-in (please include outstanding item # in
                the subject line, e.g., "outstanding issue #c").<br>
                <br>
                Let us first tackle item #c) below on join process
                impact on the network. I am particularly interested in
                detailed deliberations on the three questions on this
                item that came to my mind here.<br>
                <br>
                When looking at this topic, I would like to encourage
                you to read the email thread on the IETF DICE list re
                draft-kumar-dice-dtls-relay-01, which is related to
                relaying&nbsp; nodes and potential DoS attacks. I initiated
                this discussion on May 27th, with last posting on May
                30th. See <a moz-do-not-send="true"
                  class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
                <br>
                Best regards, Rene<br>
                <br>
                On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
              </div>
              <blockquote cite="mid:537B5C77.5020800@gmail.com"
                type="cite">
                <meta content="text/html; charset=ISO-8859-1"
                  http-equiv="Content-Type">
                <div class="moz-cite-prefix">Hi Michael:<br>
                  <br>
                  At the previous conf call of May 12, 2014, we
                  discussed message flows of w/HART join process, as
                  also alluded to in my email below (the specs could not
                  be distributed due to copyright restrictions).<br>
                  <br>
                  In my mind, 6TiSCH protocol can use similar
                  communication flows as w/HART where only non-local
                  communication flows (between joining node and network
                  manager) would be <br>
                  i) passing join/authentication information from
                  joining node to network manager (and back);<br>
                  ii) passing configuration parms from network manager
                  to joining node (keys, links, frame links) and
                  neighbor report from joined node to network manager.<br>
                  <br>
                  MAIN OUTSTANDING ISSUES (in my mind): <br>
                  a) Packet sizes: <br>
                  get more info on packet sizes configuration parms, as
                  w/HART uses. Note RS: during call, Tom Phinney
                  suggested contacting Wally Bratt from HART Comm.
                  Foundation for this).&nbsp; Note RS: Shouldn't, e.g., Dust
                  Networks have info on packet sizes/structure?; ISA
                  SP100.11a metrics would also help, as would ZigBee 2.0
                  config parms. Does, e.g., Cisco have useful data
                  points here?<br>
                  b) Device Ids:<br>
                  With industrial control, network manager would look up
                  "tag name" device in pre-configured database. Details
                  on tag name syntax, how assigned, and how bound to,
                  e.g., EUI-64 are missing. Note RS: Perhaps, Tom
                  Phinney could point at tag name syntax and lifecycle
                  aspects here?<br>
                  c) Join process impact on network: <br>
                  Pascal Thubert asked "when network would explode with
                  join". Note RS: the following questions come to mind:<br>
                  - how does joining&nbsp; node find a time slot to send
                  first join packet to neighbor node (presumably, this
                  would require listening for Enhanced Beacon, but
                  details on schedule in terms of time and channels
                  seems incomplete [min-schedule suggests 101x15ms
                  slotframe and "less than 10s repeat of EBs, but that
                  leaves lots of dead time and does not suggest a
                  schedule that would create a common time window where
                  two devices would both be awake).<br>
                  - how does joining node negotiate a local schedule
                  with neighbor node for execution of join protocol
                  (draft-watteyne-6tisch-tisch-00 refers to local
                  schedule negotiation need, but unclear whether this
                  has been looked into in detail).<br>
                  - for local traffic (joining node/neighbor), it seems
                  Pascal Thubert's "exploding network" may not happen
                  easily. Nevertheless, unclear what impact of "join
                  priority flag TSCH 802.15.4e frames is [that seems to
                  have been designed with legacy w/HART in mind
                  (centralized solution). With centralized tree-like
                  solution, lots of traffic happens close to the root,
                  thus potentially amplifying congestion around root
                  node (=network manager?).<br>
                  d) crypto protocol details of join protocol:<br>
                  Note RS: I can solve this (close to optimal design
                  already done [assuming I can do this "without hands
                  tied behind the back"])<br>
                  e) authorization/trust management:<br>
                  it is here where binding of ids to public keys via
                  certs and lifecycle aspects play a role, as well as
                  syntax/semantics of authorization messages. Note RS:
                  question is whether ACE could play a role here
                  (current charter discussions seem to be endless,
                  though). As has been brought up before, a potential
                  instantiation of certs would be the use of 802.1ar
                  certs, but this is certainly not the only way of doing
                  things.<br>
                  <br>
                  There are lots of other things we should consider,
                  outside the join protocol realm.<br>
                  <br>
                  ------- Original Message --------
                  <table class="moz-email-headers-table" cellpadding="0"
                    cellspacing="0" border="0">
                    <tbody>
                      <tr>
                        <th align="RIGHT" nowrap="nowrap"
                          valign="BASELINE">Subject: </th>
                        <td>Re: [6tisch-security] agenda(?) for call
                          today</td>
                      </tr>
                      <tr>
                        <th align="RIGHT" nowrap="nowrap"
                          valign="BASELINE">Date: </th>
                        <td>Mon, 12 May 2014 09:53:37 -0400</td>
                      </tr>
                      <tr>
                        <th align="RIGHT" nowrap="nowrap"
                          valign="BASELINE">From: </th>
                        <td>Rene Struik <a moz-do-not-send="true"
                            class="moz-txt-link-rfc2396E"
                            href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                      </tr>
                      <tr>
                        <th align="RIGHT" nowrap="nowrap"
                          valign="BASELINE">To: </th>
                        <td>Michael Richardson <a
                            moz-do-not-send="true"
                            class="moz-txt-link-rfc2396E"
                            href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                          <a moz-do-not-send="true"
                            class="moz-txt-link-abbreviated"
                            href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                      </tr>
                    </tbody>
                  </table>
                  <br>
                  <br>
                  <div class="moz-cite-prefix">Hi Michael et al:<br>
                    <br>
                    Another topic worth exploring more is the join
                    protocol details. <br>
                    <br>
                    (There are many other aspects, including certs, as
                    you mentioned, more general security architecture,
                    provisioning, etc., but below only deals with join.)<br>
                    <br>
                    With w/HART, the join process only interacts with
                    the network manager (62591, Annex A.3, Fig. A.1) for
                    <br>
                    -forwarded join from joining node to network
                    manager;<br>
                    -passing configuration parms from network manager to
                    joining node (keys, links, frame links) and neighbor
                    report from joined node to network manager.<br>
                    All other communications are local, between joining
                    device and neighbor (resp. with maintenance tool).<br>
                    <br>
                    It may have merit if we could use similar
                    communication flows with 6tisch, i.e., keep most
                    traffic local to the joining device, except for
                    configuration parms exchange and authorization info
                    passing. <br>
                    <br>
                    Most important consideration (from communication
                    perspective) would be that non-local traffic would
                    be minimized, as also w/HART does. From a marketing
                    perspective, mimicking the communication flows
                    w/HART already has would keep all time scheduling
                    considerations for w/HART as currently there and
                    6TiSCH as to be detailed roughly the same. This
                    would longer term help in pushing 6tisch-style
                    security scheme to w/HART, since from a distance it
                    looks the same (although trying to scrap the
                    maintenance tool).<br>
                    <br>
                    Of course, this does not deal with the details of
                    the joining protocol itself; only the flows.<br>
                    <br>
                    What about we look at some of the flows, and
                    enumerate all issues that need to be addressed here,
                    both from a security perspective and otherwise. We
                    can then assign people to find missing information
                    (I am esp. curious about how devices know when to
                    send/receive and contributions of cycling efforts to
                    total time latency). <br>
                    <br>
                    We could go over w/HART join flows during the call,
                    to trigger these questions.<br>
                    <br>
                    Best regards, Rene<br>
                  </div>
                  <br>
                  <br>
                  On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
                </div>
                <blockquote cite="mid:19475.1400588783@sandelman.ca"
                  type="cite">
                  <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
                  <br>
                  <fieldset class="mimeAttachmentHeader"></fieldset>
                  <br>
                  <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
                </blockquote>
                <br>
                <br>
                <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
              </blockquote>
              <br>
              <br>
              <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
            </blockquote>
            <br>
            <br>
            <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
            <br>
            <fieldset class="mimeAttachmentHeader"></fieldset>
            <br>
            <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
          </blockquote>
          <br>
          <br>
          <fieldset class="mimeAttachmentHeader"></fieldset>
          <br>
          <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      </blockquote>
      <br>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------050709090500060506070106--


From nobody Thu Jun 12 08:00:36 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6563F1B2A8D for <6tisch-security@ietfa.amsl.com>; Thu, 12 Jun 2014 08:00:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z_7tK3Gzp6pr for <6tisch-security@ietfa.amsl.com>; Thu, 12 Jun 2014 08:00:30 -0700 (PDT)
Received: from mail-ig0-x234.google.com (mail-ig0-x234.google.com [IPv6:2607:f8b0:4001:c05::234]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1BAE31B2A83 for <6tisch-security@ietf.org>; Thu, 12 Jun 2014 08:00:30 -0700 (PDT)
Received: by mail-ig0-f180.google.com with SMTP id h18so2122021igc.1 for <6tisch-security@ietf.org>; Thu, 12 Jun 2014 08:00:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=MCUtxx6sblt/K/FMOI27oKquhsXk/Y59ERSX40/tWc8=; b=VK+TrSiKH3ojyZv69Stx+cwJkiHqivo083Diwu6wg81rPBupl8nWV4xnTIqrzKLlr8 g98JJ3qrdABbOwNaQ9HJjc94zgJc74xm3vJh7ccIa8w9O/Xzt6otqYrplVbFL0yaTbgg +a8PWts82ImiN/pfKub5vftkxQZ/1DU5Nlodurw/PVUhqyA+Td7aiPN0TDsQXpESj+e+ FfZHOnP5wCR0T6Xe3YRB79DXR4ahjUv9aE7qQkcG9rtj5dBozoJj21gnmO8+E7v4qCnq H8blPfgKzRFBS5gWWxsCh7tqkpmBwKMmQghIZNWBcT/JkHZffYBLWeK3GTXQ4LWWHfR7 IhWw==
X-Received: by 10.43.151.7 with SMTP id kq7mr36188312icc.78.1402585229261; Thu, 12 Jun 2014 08:00:29 -0700 (PDT)
Received: from [192.168.1.103] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id j1sm6008852ige.0.2014.06.12.08.00.28 for <6tisch-security@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 12 Jun 2014 08:00:28 -0700 (PDT)
Message-ID: <5399C087.3050700@gmail.com>
Date: Thu, 12 Jun 2014 11:00:23 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: 6tisch-security@ietf.org
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <53971920.3070400@gmail.com> <539726AE.1000504@gmail.com>
In-Reply-To: <539726AE.1000504@gmail.com>
Content-Type: multipart/alternative; boundary="------------040500090206050208070605"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/-myRlBxptPVmiwePOnKDLN-Ezr0
Subject: Re: [6tisch-security] tackling outstanding issues #c-3
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Jun 2014 15:00:34 -0000

This is a multi-part message in MIME format.
--------------040500090206050208070605
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

Any feedback, opinions on a) and b) appreciated.

Rene

On 6/10/2014 11:39 AM, Rene Struik wrote:
> Dear colleagues:
>
> Please find below some deliberations on outstanding item #c-3:
>
> With 802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13) includes 
> the absolute slot number (ASN) and the Join Priority flag.
a)
> Since a newly joining device has no way to validate whether the ASN 
> entry advertised by the beaconing device corresponds to the one 
> maintained by the PAN coordinator and there is only one macASN entry, 
> joining nodes cannot rely on this ASN entry for frame security. As a 
> result, the first message from a newbee node to the neighbor device 
> should be unsecured. In particular, this should neither attempt to use 
> a "well-known key".
b)
> It is unclear how the join priority flag would help in facilitating 
> resource optimization when a newly joining device tries and join the 
> network. Perhaps, this flag was motivated by centralized solution 
> ideas, where every device joins via the PAN coordinator? Suggestion is 
> to completely ignore this joining priority flag.
>
> Best regards, Rene
>
> [excerpt of 802.15.4e-2012]
> The ASN field contains the 5-octet Absolute Slot Number corresponding 
> to the timeslot in which the
> enhanced beacon is sent. The ASN is used as the Frame Counter for 
> security operations if enabled. The 1-
> octet Join Priority field can be used by a joining device to select 
> among beaconing devices when multiple
> beacons are heard. The PAN coordinator's join priority is zero. A 
> lower value of join priority indicates that
> the device is the preferred one to connect to. The beaconing device's 
> join priority is the lowest join priority
> heard when it joined the network plus one.
> The TSCH Synchronization IE is used to construct enhanced beacons that 
> allow new devices to synchronize
> to a TSCH PAN.
>
>> ==
>> c) Join process impact on network:
>> Pascal Thubert asked "when network would explode with join". Note RS: 
>> the following questions come to mind:
>> c-1) how does joining  node find a time slot to send first join 
>> packet to neighbor node (presumably, this would require listening for 
>> Enhanced Beacon, but details on schedule in terms of time and 
>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>> and does not suggest a schedule that would create a common time 
>> window where two devices would both be awake).
>> c-2)how does joining node negotiate a local schedule with neighbor 
>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>> refers to local schedule negotiation need, but unclear whether this 
>> has been looked into in detail).
>> c-3) for local traffic (joining node/neighbor), it seems Pascal 
>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>> [that seems to have been designed with legacy w/HART in mind 
>> (centralized solution). With centralized tree-like solution, lots of 
>> traffic happens close to the root, thus potentially amplifying 
>> congestion around root node (=network manager?).
>>
>> On 6/9/2014 11:51 AM, Rene Struik wrote:
>>> Dear colleagues:
>>>
>>> Please find below a reminder of the outstanding issues re the join 
>>> protocol, as I originally circulated three weeks ago, prior to our 
>>> call on Tue May 20, 2014. {As an aside, the week before that, on May 
>>> 12, 2014, we did discuss the w/HART join process protocol flows (at 
>>> the time, intention was to agree to align flows with that used 
>>> there, as motivated in the same email below).}
>>>
>>> While current discussions on w/HART protocol have been somewhat 
>>> interesting, I feel we should put urgent priority on tackling those 
>>> outstanding issues. So far, I have not seen any traffic on these 
>>> items from others, so please weigh-in (please include outstanding 
>>> item # in the subject line, e.g., "outstanding issue #c").
>>>
>>> Let us first tackle item #c) below on join process impact on the 
>>> network. I am particularly interested in detailed deliberations on 
>>> the three questions on this item that came to my mind here.
>>>
>>> When looking at this topic, I would like to encourage you to read 
>>> the email thread on the IETF DICE list re 
>>> draft-kumar-dice-dtls-relay-01, which is related to relaying  nodes 
>>> and potential DoS attacks. I initiated this discussion on May 27th, 
>>> with last posting on May 30th. See 
>>> http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html.
>>>
>>> Best regards, Rene
>>>
>>> On 5/20/2014 9:45 AM, Rene Struik wrote:
>>>> Hi Michael:
>>>>
>>>> At the previous conf call of May 12, 2014, we discussed message 
>>>> flows of w/HART join process, as also alluded to in my email below 
>>>> (the specs could not be distributed due to copyright restrictions).
>>>>
>>>> In my mind, 6TiSCH protocol can use similar communication flows as 
>>>> w/HART where only non-local communication flows (between joining 
>>>> node and network manager) would be
>>>> i) passing join/authentication information from joining node to 
>>>> network manager (and back);
>>>> ii) passing configuration parms from network manager to joining 
>>>> node (keys, links, frame links) and neighbor report from joined 
>>>> node to network manager.
>>>>
>>>> MAIN OUTSTANDING ISSUES (in my mind):
>>>> a) Packet sizes:
>>>> get more info on packet sizes configuration parms, as w/HART uses. 
>>>> Note RS: during call, Tom Phinney suggested contacting Wally Bratt 
>>>> from HART Comm. Foundation for this).  Note RS: Shouldn't, e.g., 
>>>> Dust Networks have info on packet sizes/structure?; ISA SP100.11a 
>>>> metrics would also help, as would ZigBee 2.0 config parms. Does, 
>>>> e.g., Cisco have useful data points here?
>>>> b) Device Ids:
>>>> With industrial control, network manager would look up "tag name" 
>>>> device in pre-configured database. Details on tag name syntax, how 
>>>> assigned, and how bound to, e.g., EUI-64 are missing. Note RS: 
>>>> Perhaps, Tom Phinney could point at tag name syntax and lifecycle 
>>>> aspects here?
>>>> c) Join process impact on network:
>>>> Pascal Thubert asked "when network would explode with join". Note 
>>>> RS: the following questions come to mind:
>>>> - how does joining  node find a time slot to send first join packet 
>>>> to neighbor node (presumably, this would require listening for 
>>>> Enhanced Beacon, but details on schedule in terms of time and 
>>>> channels seems incomplete [min-schedule suggests 101x15ms slotframe 
>>>> and "less than 10s repeat of EBs, but that leaves lots of dead time 
>>>> and does not suggest a schedule that would create a common time 
>>>> window where two devices would both be awake).
>>>> - how does joining node negotiate a local schedule with neighbor 
>>>> node for execution of join protocol (draft-watteyne-6tisch-tisch-00 
>>>> refers to local schedule negotiation need, but unclear whether this 
>>>> has been looked into in detail).
>>>> - for local traffic (joining node/neighbor), it seems Pascal 
>>>> Thubert's "exploding network" may not happen easily. Nevertheless, 
>>>> unclear what impact of "join priority flag TSCH 802.15.4e frames is 
>>>> [that seems to have been designed with legacy w/HART in mind 
>>>> (centralized solution). With centralized tree-like solution, lots 
>>>> of traffic happens close to the root, thus potentially amplifying 
>>>> congestion around root node (=network manager?).
>>>> d) crypto protocol details of join protocol:
>>>> Note RS: I can solve this (close to optimal design already done 
>>>> [assuming I can do this "without hands tied behind the back"])
>>>> e) authorization/trust management:
>>>> it is here where binding of ids to public keys via certs and 
>>>> lifecycle aspects play a role, as well as syntax/semantics of 
>>>> authorization messages. Note RS: question is whether ACE could play 
>>>> a role here (current charter discussions seem to be endless, 
>>>> though). As has been brought up before, a potential instantiation 
>>>> of certs would be the use of 802.1ar certs, but this is certainly 
>>>> not the only way of doing things.
>>>>
>>>> There are lots of other things we should consider, outside the join 
>>>> protocol realm.
>>>>
>>>> ------- Original Message --------
>>>> Subject: 	Re: [6tisch-security] agenda(?) for call today
>>>> Date: 	Mon, 12 May 2014 09:53:37 -0400
>>>> From: 	Rene Struik <rstruik.ext@gmail.com>
>>>> To: 	Michael Richardson <mcr+ietf@sandelman.ca>, 
>>>> 6tisch-security@ietf.org
>>>>
>>>>
>>>>
>>>> Hi Michael et al:
>>>>
>>>> Another topic worth exploring more is the join protocol details.
>>>>
>>>> (There are many other aspects, including certs, as you mentioned, 
>>>> more general security architecture, provisioning, etc., but below 
>>>> only deals with join.)
>>>>
>>>> With w/HART, the join process only interacts with the network 
>>>> manager (62591, Annex A.3, Fig. A.1) for
>>>> -forwarded join from joining node to network manager;
>>>> -passing configuration parms from network manager to joining node 
>>>> (keys, links, frame links) and neighbor report from joined node to 
>>>> network manager.
>>>> All other communications are local, between joining device and 
>>>> neighbor (resp. with maintenance tool).
>>>>
>>>> It may have merit if we could use similar communication flows with 
>>>> 6tisch, i.e., keep most traffic local to the joining device, except 
>>>> for configuration parms exchange and authorization info passing.
>>>>
>>>> Most important consideration (from communication perspective) would 
>>>> be that non-local traffic would be minimized, as also w/HART does. 
>>>> From a marketing perspective, mimicking the communication flows 
>>>> w/HART already has would keep all time scheduling considerations 
>>>> for w/HART as currently there and 6TiSCH as to be detailed roughly 
>>>> the same. This would longer term help in pushing 6tisch-style 
>>>> security scheme to w/HART, since from a distance it looks the same 
>>>> (although trying to scrap the maintenance tool).
>>>>
>>>> Of course, this does not deal with the details of the joining 
>>>> protocol itself; only the flows.
>>>>
>>>> What about we look at some of the flows, and enumerate all issues 
>>>> that need to be addressed here, both from a security perspective 
>>>> and otherwise. We can then assign people to find missing 
>>>> information (I am esp. curious about how devices know when to 
>>>> send/receive and contributions of cycling efforts to total time 
>>>> latency).
>>>>
>>>> We could go over w/HART join flows during the call, to trigger 
>>>> these questions.
>>>>
>>>> Best regards, Rene
>>>>
>>>>
>>>> On 5/20/2014 8:26 AM, Michael Richardson wrote:
>>>>> To remind, we moved the call from the 19th to the 20th at 10am EDT.
>>>>> That's 90 minutes from this email.
>>>>>
>>>>> 1) notewell.
>>>>> 2) intros
>>>>> 3) Rene had some material to present?  Did it happen last week,
>>>>>     it seems not?
>>>>> 4) review of claim certificate process, vs EST with token.
>>>>>
>>>>> -- remember that the call is recorded, and the NoteWell applies.
>>>>>
>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>    https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>>>
>>>>> -- we will resume with the etherpad at:
>>>>>     http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>>>>>
>>>>> I'm at +1 613 276-6809, IM:mcr@xmpp.credil.org  ormcharlesr@gmail.com,
>>>>> if you need more than that to get in, or are having difficulties.
>>>>> Please make sure your audio works, and that you mute when not talking.
>>>>>
>>>>>
>>>>> --
>>>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>>>   -= IPv6 IoT consulting =-
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> _______________________________________________
>>>>> 6tisch-security mailing list
>>>>> 6tisch-security@ietf.org
>>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>>>
>>>>
>>>> -- 
>>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>>
>>>
>>> -- 
>>> email:rstruik.ext@gmail.com  | Skype: rstruik
>>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>>
>>
>> -- 
>> email:rstruik.ext@gmail.com  | Skype: rstruik
>> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
>
> -- 
> email:rstruik.ext@gmail.com  | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------040500090206050208070605
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      Any feedback, opinions on a) and b) appreciated.<br>
      <br>
      Rene<br>
      <br>
      On 6/10/2014 11:39 AM, Rene Struik wrote:<br>
    </div>
    <blockquote cite="mid:539726AE.1000504@gmail.com" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      Dear colleagues:<br>
      <br>
      Please find below some deliberations on outstanding item #c-3:<br>
      <br>
      With 802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13)
      includes the absolute slot number (ASN) and the Join Priority
      flag. <br>
    </blockquote>
    a)<br>
    <blockquote cite="mid:539726AE.1000504@gmail.com" type="cite"> Since
      a newly joining device has no way to validate whether the ASN
      entry advertised by the beaconing device corresponds to the one
      maintained by the PAN coordinator and there is only one macASN
      entry, joining nodes cannot rely on this ASN entry for frame
      security. As a result, the first message from a newbee node to the
      neighbor device should be unsecured. In particular, this should
      neither attempt to use a "well-known key".<br>
    </blockquote>
    b)<br>
    <blockquote cite="mid:539726AE.1000504@gmail.com" type="cite"> It is
      unclear how the join priority flag would help in facilitating
      resource optimization when a newly joining device tries and join
      the network. Perhaps, this flag was motivated by centralized
      solution ideas, where every device joins via the PAN coordinator?
      Suggestion is to completely ignore this joining priority flag.<br>
      <br>
      Best regards, Rene<br>
      <br>
      [excerpt of 802.15.4e-2012]<br>
      The ASN field contains the 5-octet Absolute Slot Number
      corresponding to the timeslot in which the<br>
      enhanced beacon is sent. The ASN is used as the Frame Counter for
      security operations if enabled. The 1-<br>
      octet Join Priority field can be used by a joining device to
      select among beaconing devices when multiple<br>
      beacons are heard. The PAN coordinator&#8217;s join priority is zero. A
      lower value of join priority indicates that<br>
      the device is the preferred one to connect to. The beaconing
      device&#8217;s join priority is the lowest join priority<br>
      heard when it joined the network plus one.<br>
      The TSCH Synchronization IE is used to construct enhanced beacons
      that allow new devices to synchronize<br>
      to a TSCH PAN.<br>
      <br>
      <blockquote cite="mid:53971920.3070400@gmail.com" type="cite">
        <div class="moz-cite-prefix"> ==<br>
          c) Join process impact on network: <br>
          Pascal Thubert asked "when network would explode with join".
          Note RS: the following questions come to mind:<br>
          c-1) how does joining&nbsp; node find a time slot to send first
          join packet to neighbor node (presumably, this would require
          listening for Enhanced Beacon, but details on schedule in
          terms of time and channels seems incomplete [min-schedule
          suggests 101x15ms slotframe and "less than 10s repeat of EBs,
          but that leaves lots of dead time and does not suggest a
          schedule that would create a common time window where two
          devices would both be awake).<br>
          c-2)how does joining node negotiate a local schedule with
          neighbor node for execution of join protocol
          (draft-watteyne-6tisch-tisch-00 refers to local schedule
          negotiation need, but unclear whether this has been looked
          into in detail).<br>
          c-3) for local traffic (joining node/neighbor), it seems
          Pascal Thubert's "exploding network" may not happen easily.
          Nevertheless, unclear what impact of "join priority flag TSCH
          802.15.4e frames is [that seems to have been designed with
          legacy w/HART in mind (centralized solution). With centralized
          tree-like solution, lots of traffic happens close to the root,
          thus potentially amplifying congestion around root node
          (=network manager?).<br>
          <br>
          On 6/9/2014 11:51 AM, Rene Struik wrote:<br>
        </div>
        <blockquote cite="mid:5395D7E4.1010200@gmail.com" type="cite">
          <meta content="text/html; charset=ISO-8859-1"
            http-equiv="Content-Type">
          <div class="moz-cite-prefix">Dear colleagues:<br>
            <br>
            Please find below a reminder of the outstanding issues re
            the join protocol, as I originally circulated three weeks
            ago, prior to our call on Tue May 20, 2014. {As an aside,
            the week before that, on May 12, 2014, we did discuss the
            w/HART join process protocol flows (at the time, intention
            was to agree to align flows with that used there, as
            motivated in the same email below).}<br>
            <br>
            While current discussions on w/HART protocol have been
            somewhat interesting, I feel we should put urgent priority
            on tackling those outstanding issues. So far, I have not
            seen any traffic on these items from others, so please
            weigh-in (please include outstanding item # in the subject
            line, e.g., "outstanding issue #c").<br>
            <br>
            Let us first tackle item #c) below on join process impact on
            the network. I am particularly interested in detailed
            deliberations on the three questions on this item that came
            to my mind here.<br>
            <br>
            When looking at this topic, I would like to encourage you to
            read the email thread on the IETF DICE list re
            draft-kumar-dice-dtls-relay-01, which is related to
            relaying&nbsp; nodes and potential DoS attacks. I initiated this
            discussion on May 27th, with last posting on May 30th. See <a
              moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html">http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00253.html</a>.<br>
            <br>
            Best regards, Rene<br>
            <br>
            On 5/20/2014 9:45 AM, Rene Struik wrote:<br>
          </div>
          <blockquote cite="mid:537B5C77.5020800@gmail.com" type="cite">
            <meta content="text/html; charset=ISO-8859-1"
              http-equiv="Content-Type">
            <div class="moz-cite-prefix">Hi Michael:<br>
              <br>
              At the previous conf call of May 12, 2014, we discussed
              message flows of w/HART join process, as also alluded to
              in my email below (the specs could not be distributed due
              to copyright restrictions).<br>
              <br>
              In my mind, 6TiSCH protocol can use similar communication
              flows as w/HART where only non-local communication flows
              (between joining node and network manager) would be <br>
              i) passing join/authentication information from joining
              node to network manager (and back);<br>
              ii) passing configuration parms from network manager to
              joining node (keys, links, frame links) and neighbor
              report from joined node to network manager.<br>
              <br>
              MAIN OUTSTANDING ISSUES (in my mind): <br>
              a) Packet sizes: <br>
              get more info on packet sizes configuration parms, as
              w/HART uses. Note RS: during call, Tom Phinney suggested
              contacting Wally Bratt from HART Comm. Foundation for
              this).&nbsp; Note RS: Shouldn't, e.g., Dust Networks have info
              on packet sizes/structure?; ISA SP100.11a metrics would
              also help, as would ZigBee 2.0 config parms. Does, e.g.,
              Cisco have useful data points here?<br>
              b) Device Ids:<br>
              With industrial control, network manager would look up
              "tag name" device in pre-configured database. Details on
              tag name syntax, how assigned, and how bound to, e.g.,
              EUI-64 are missing. Note RS: Perhaps, Tom Phinney could
              point at tag name syntax and lifecycle aspects here?<br>
              c) Join process impact on network: <br>
              Pascal Thubert asked "when network would explode with
              join". Note RS: the following questions come to mind:<br>
              - how does joining&nbsp; node find a time slot to send first
              join packet to neighbor node (presumably, this would
              require listening for Enhanced Beacon, but details on
              schedule in terms of time and channels seems incomplete
              [min-schedule suggests 101x15ms slotframe and "less than
              10s repeat of EBs, but that leaves lots of dead time and
              does not suggest a schedule that would create a common
              time window where two devices would both be awake).<br>
              - how does joining node negotiate a local schedule with
              neighbor node for execution of join protocol
              (draft-watteyne-6tisch-tisch-00 refers to local schedule
              negotiation need, but unclear whether this has been looked
              into in detail).<br>
              - for local traffic (joining node/neighbor), it seems
              Pascal Thubert's "exploding network" may not happen
              easily. Nevertheless, unclear what impact of "join
              priority flag TSCH 802.15.4e frames is [that seems to have
              been designed with legacy w/HART in mind (centralized
              solution). With centralized tree-like solution, lots of
              traffic happens close to the root, thus potentially
              amplifying congestion around root node (=network
              manager?).<br>
              d) crypto protocol details of join protocol:<br>
              Note RS: I can solve this (close to optimal design already
              done [assuming I can do this "without hands tied behind
              the back"])<br>
              e) authorization/trust management:<br>
              it is here where binding of ids to public keys via certs
              and lifecycle aspects play a role, as well as
              syntax/semantics of authorization messages. Note RS:
              question is whether ACE could play a role here (current
              charter discussions seem to be endless, though). As has
              been brought up before, a potential instantiation of certs
              would be the use of 802.1ar certs, but this is certainly
              not the only way of doing things.<br>
              <br>
              There are lots of other things we should consider, outside
              the join protocol realm.<br>
              <br>
              ------- Original Message --------
              <table class="moz-email-headers-table" cellpadding="0"
                cellspacing="0" border="0">
                <tbody>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:




                    </th>
                    <td>Re: [6tisch-security] agenda(?) for call today</td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date:



                    </th>
                    <td>Mon, 12 May 2014 09:53:37 -0400</td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From:



                    </th>
                    <td>Rene Struik <a moz-do-not-send="true"
                        class="moz-txt-link-rfc2396E"
                        href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a></td>
                  </tr>
                  <tr>
                    <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To:


                    </th>
                    <td>Michael Richardson <a moz-do-not-send="true"
                        class="moz-txt-link-rfc2396E"
                        href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a>,
                      <a moz-do-not-send="true"
                        class="moz-txt-link-abbreviated"
                        href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a></td>
                  </tr>
                </tbody>
              </table>
              <br>
              <br>
              <div class="moz-cite-prefix">Hi Michael et al:<br>
                <br>
                Another topic worth exploring more is the join protocol
                details. <br>
                <br>
                (There are many other aspects, including certs, as you
                mentioned, more general security architecture,
                provisioning, etc., but below only deals with join.)<br>
                <br>
                With w/HART, the join process only interacts with the
                network manager (62591, Annex A.3, Fig. A.1) for <br>
                -forwarded join from joining node to network manager;<br>
                -passing configuration parms from network manager to
                joining node (keys, links, frame links) and neighbor
                report from joined node to network manager.<br>
                All other communications are local, between joining
                device and neighbor (resp. with maintenance tool).<br>
                <br>
                It may have merit if we could use similar communication
                flows with 6tisch, i.e., keep most traffic local to the
                joining device, except for configuration parms exchange
                and authorization info passing. <br>
                <br>
                Most important consideration (from communication
                perspective) would be that non-local traffic would be
                minimized, as also w/HART does. From a marketing
                perspective, mimicking the communication flows w/HART
                already has would keep all time scheduling
                considerations for w/HART as currently there and 6TiSCH
                as to be detailed roughly the same. This would longer
                term help in pushing 6tisch-style security scheme to
                w/HART, since from a distance it looks the same
                (although trying to scrap the maintenance tool).<br>
                <br>
                Of course, this does not deal with the details of the
                joining protocol itself; only the flows.<br>
                <br>
                What about we look at some of the flows, and enumerate
                all issues that need to be addressed here, both from a
                security perspective and otherwise. We can then assign
                people to find missing information (I am esp. curious
                about how devices know when to send/receive and
                contributions of cycling efforts to total time latency).
                <br>
                <br>
                We could go over w/HART join flows during the call, to
                trigger these questions.<br>
                <br>
                Best regards, Rene<br>
              </div>
              <br>
              <br>
              On 5/20/2014 8:26 AM, Michael Richardson wrote:<br>
            </div>
            <blockquote cite="mid:19475.1400588783@sandelman.ca"
              type="cite">
              <pre wrap="">To remind, we moved the call from the 19th to the 20th at 10am EDT.
That's 90 minutes from this email.

1) notewell.
2) intros
3) Rene had some material to present?  Did it happen last week,
   it seems not?
4) review of claim certificate process, vs EST with token.

-- remember that the call is recorded, and the NoteWell applies.

-- The URL to access the webex, which will we use for audio only:
  <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908">https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908</a>

-- we will resume with the etherpad at:
   <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security">http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security</a>

I'm at +1 613 276-6809, IM: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcr@xmpp.credil.org">mcr@xmpp.credil.org</a> or <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:mcharlesr@gmail.com">mcharlesr@gmail.com</a>,
if you need more than that to get in, or are having difficulties.
Please make sure your audio works, and that you mute when not talking.


--
Michael Richardson <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
              <br>
              <fieldset class="mimeAttachmentHeader"></fieldset>
              <br>
              <pre wrap="">_______________________________________________
6tisch-security mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
            </blockquote>
            <br>
            <br>
            <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
          </blockquote>
          <br>
          <br>
          <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
        </blockquote>
        <br>
        <br>
        <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
      </blockquote>
      <br>
      <br>
      <pre class="moz-signature" cols="72">-- 
email: <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------040500090206050208070605--


From nobody Sat Jun 14 12:27:03 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6917C1B298F for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 12:27:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mFZXD8-PNvwh for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 12:27:00 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CFB6A1B2957 for <6tisch-security@ietf.org>; Sat, 14 Jun 2014 12:26:59 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 19C3A20028; Sat, 14 Jun 2014 15:30:43 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id EF63E63B0E; Sat, 14 Jun 2014 15:26:56 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id DB71963B0B; Sat, 14 Jun 2014 15:26:56 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <5395D7E4.1010200@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sat, 14 Jun 2014 15:26:56 -0400
Message-ID: <10803.1402774016@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/-fU71PWKuK0Xpx3KmSvscUVb6Tc
Cc: 6tisch-security@ietf.org
Subject: [6tisch-security] Rene issue 3c.
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Jun 2014 19:27:02 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > Let us first tackle item #c) below on join process impact on the network. I am
    > particularly interested in detailed deliberations on the three questions on
    > this item that came to my mind here.

    > c) Join process impact on network:
    > Pascal Thubert asked "when network would explode with join". Note RS: the
    > following questions come to mind:

    > - how does joining  node find a time slot to send first join packet to
    > neighbor node (presumably, this would require listening for Enhanced
    > Beacon, but details on schedule in terms of time and channels seems
    > incomplete [min-schedule suggests 101x15ms slotframe and "less than 10s
    > repeat of EBs, but that leaves lots of dead time and does not suggest a
    > schedule that would create a common time window where two devices would
    > both be awake).

The joining node listens for an Enhanced Beacon (which arrives on all
frequencies I've just read).

The EB are sent by neighbours at times when they are set to be Tx.
The EB are not at the beginning of the slotframe, which I had previously
assumed.  The EB contains a relative timestamp telling the node when the
slotframe was to have started.

http://tools.ietf.org/html/draft-watteyne-6tisch-tsch-00, section A.11.

Does this resolve this issue?

http://tools.ietf.org/wg/6tisch/trac/ticket/13

http://tools.ietf.org/wg/6tisch/trac/ticket/14

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-


--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU5yiAICLcPvd0N1lAQK6mggAgne1HDHpb9QNWIPE2QNswgS9omyy1zYe
bnmUCLk+byeXSBMMlhJqLvythNGw/erXXQGqXXrZnQi/Wy3pGIACwmh/Cgp5wSQ1
IHA+rO21IJLN2vlm4YscXnO9D+Ehs8huVTr+xadUIbyk7HVQuux/W3aj7PklaUGQ
HvIl6s4oG3ZItsXRaKeZRBf7ZoszC0BuJ9/KiRpyBjbEzrGkz3Re3OnDo1BgBcZ4
iGZE3YUAeQcWdpi6nfpSUwhz/Hw46kgI/cDQXcvBcAX6Fwd2htSQObbAFq2ovnEK
DOj3tCXsSU3MrPpLTeAhSd19Hz4fn5GzuTyd1duLuTt8OMZkQ/Fl5Q==
=DTFr
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sat Jun 14 15:12:50 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0346B1B2A24 for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 15:12:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mHehy1764v17 for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 15:12:44 -0700 (PDT)
Received: from mail-ig0-x22e.google.com (mail-ig0-x22e.google.com [IPv6:2607:f8b0:4001:c05::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6CC3D1B2802 for <6tisch-security@ietf.org>; Sat, 14 Jun 2014 15:12:44 -0700 (PDT)
Received: by mail-ig0-f174.google.com with SMTP id h3so1663686igd.7 for <6tisch-security@ietf.org>; Sat, 14 Jun 2014 15:12:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=G0XoC7viiCz53XJFh5/bfhKL3Ja14GUeAB4I5m2xZZI=; b=go9selkENlXXKX63xZsxsFwZsi+u1jvtuhBoZhpoGuHK23IKDZCaG3+573iaWU/IEG T1NqXgwgYD/Vi0Hs5o41dzgw39gvCh596+ccw1djegDXKyt8bG97INJHSuBEW7vqcalA I7UMEpo1gB4M/foilx3+LjIaqUnWdsNtONOuVyyVi/S/p3zykR3gx2VLc9PWW9ESkRli PKVJ4X3dB0KQBMxm11UZYKTNmzrLDxQTX0HgEfMXd4oaLeFbWW+8dxI020EIs++f2I0M MRoB1/k7SIE3/jgYieN208MQW55eO+uYZdrerAL0ZQfanTAx4iHyU36jWJ2tgNljC4ve 0l6w==
X-Received: by 10.50.18.80 with SMTP id u16mr14982113igd.30.1402783963551; Sat, 14 Jun 2014 15:12:43 -0700 (PDT)
Received: from [192.168.1.102] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id qo12sm6912125igb.21.2014.06.14.15.12.42 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sat, 14 Jun 2014 15:12:42 -0700 (PDT)
Message-ID: <539CC8D3.7000605@gmail.com>
Date: Sat, 14 Jun 2014 18:12:35 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca>
In-Reply-To: <10803.1402774016@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/4pRgEOo95cJ2C1-_VG9bJWRiJQE
Cc: 6tisch-security@ietf.org
Subject: [6tisch-security] outstanding issue #3a (was: Re: Rene issue 3c.)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Jun 2014 22:12:47 -0000

Hi Michael:

 From the minimal draft, it seems that enhanced beacons SHOULD be sent 
every 10 seconds. Since in that draft, each slotframe is 101 x 15ms = 
1.515s, this seems to suggest there are huge "holes" in sending of EBs. 
Moreover, it is not clear whether the "should" language refers to a 
maximum time window or an interval length.

Even if an enhanced beacon is sent every slotframe at the first timeslot 
(i.e., in a scenario without "holes"), this means that the EB cycles 
through all frequencies in 16 slotframe lengths, or 16 x 1.515 = 24.24 s 
(assuming all frequencies are indeed active). Now, how does one 
guarantee that the joining device actually "hits" such an enhanced 
beacon? If the joining node listens on different channels itself, it may 
never see an enhanced beacon of another device (e.g., if they are just 
"following each other" in lockstep, which is very well possible). The 
only way a joining node may "get lucky" seems to be when listening on a 
fixed channel for a long time and hoping it would hear something. If the 
neighbor is sending stuff on all frequencies and the function "F" 
(channel frequency mapping of draft-watteyne-6tisch-tsch-00, Section 
A.7) is the identity function, then if it would listen long enough (the 
24.24s or roughly half a minute above), then it would encounter an EB. 
If the "hole" scenario of the minimal draft plays out, it may have to 
listen much longer (moreover, the formula for the channel frequency 
mapping may not result in any guarantees that each channel frequency 
will indeed occur then). If the neighbor does have some channel 
frequencies blocked or different devices have different "F" functions, 
the situation seems to be very unclear.

I hope this provides some evidence that it is unclear how one could 
"hit" an enhanced beacon of a neighboring node. What I described above 
does not deal with "negotiating"/"finding" a time slot/channel combo 
where the joining device would actually send its first message (and at 
the same time have some assurances that the EB-originator is still 
listening to it).

Best regards, Rene

[excerpt of draft-ietf-6tisch-minimal-00, Section 3]
Enhanced Beacons Configuration and Content [IEEE802154e] does not define 
how often or which EBs are sent. The choice of the duration between two 
EBs needs to take into account whether EBs are used as the only 
mechanism to synchronize devices, or whether a Keep-Alive (KA) mechanism 
is used in parallel. For a simplest TSCH configuration, a mote SHOULD 
send an EB every 10s. For additional reference see 
[I-D.watteyne-6tisch-tsch] where different synchronization approaches 
are summarized.


On 6/14/2014 3:26 PM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > Let us first tackle item #c) below on join process impact on the network. I am
>      > particularly interested in detailed deliberations on the three questions on
>      > this item that came to my mind here.
>
>      > c) Join process impact on network:
>      > Pascal Thubert asked "when network would explode with join". Note RS: the
>      > following questions come to mind:
>
>      > - how does joining  node find a time slot to send first join packet to
>      > neighbor node (presumably, this would require listening for Enhanced
>      > Beacon, but details on schedule in terms of time and channels seems
>      > incomplete [min-schedule suggests 101x15ms slotframe and "less than 10s
>      > repeat of EBs, but that leaves lots of dead time and does not suggest a
>      > schedule that would create a common time window where two devices would
>      > both be awake).
>
> The joining node listens for an Enhanced Beacon (which arrives on all
> frequencies I've just read).
>
> The EB are sent by neighbours at times when they are set to be Tx.
> The EB are not at the beginning of the slotframe, which I had previously
> assumed.  The EB contains a relative timestamp telling the node when the
> slotframe was to have started.
>
> http://tools.ietf.org/html/draft-watteyne-6tisch-tsch-00, section A.11.
>
> Does this resolve this issue?
>
> http://tools.ietf.org/wg/6tisch/trac/ticket/13
>
> http://tools.ietf.org/wg/6tisch/trac/ticket/14
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Sat Jun 14 15:18:18 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 274091B2A2A for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 15:18:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JBQauZSAAnoT for <6tisch-security@ietfa.amsl.com>; Sat, 14 Jun 2014 15:18:12 -0700 (PDT)
Received: from mail-ie0-x22c.google.com (mail-ie0-x22c.google.com [IPv6:2607:f8b0:4001:c03::22c]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A4B01B2802 for <6tisch-security@ietf.org>; Sat, 14 Jun 2014 15:18:12 -0700 (PDT)
Received: by mail-ie0-f172.google.com with SMTP id lx4so3695832iec.17 for <6tisch-security@ietf.org>; Sat, 14 Jun 2014 15:18:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=lW4ON2km+5eZjLTVVG4XO9PdAd3WjA49+iizR4TO8AM=; b=FF6bI/HrhqE4RzrxU2H5ydyVVSDuiBCKUnEQlOd0as3SBSMgGA0RPZCoMbp3FxYPRg /Hvvkw8tpu5+3P+YcBcIP1Ze1OKI3JrDHzMzff7fB0TH5tJRksFG3pIVazPHmLUhukUM V5L77tK+qg2r4eqqF8FRMNGxRt+1Y47zUKZXkRComltlC3KKXcd6qCh7mkYy5hhqwMKg TIpVkKO5O7nCUCs+XNV3tmpA/CE0nRBNpw0WOiD9xuUs5DsjRidqDfqgBex9pwqVVjMZ 4pfBNd/yHyjUBkGrrVPgmAv9NYYv+7EmvxjK4DinrJwyxQ32PiY3zdrbruCZusR4jpAz AEcg==
X-Received: by 10.42.99.10 with SMTP id u10mr12235353icn.9.1402784291778; Sat, 14 Jun 2014 15:18:11 -0700 (PDT)
Received: from [192.168.1.102] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id o19sm6957568igi.20.2014.06.14.15.18.10 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sat, 14 Jun 2014 15:18:11 -0700 (PDT)
Message-ID: <539CCA1B.9040603@gmail.com>
Date: Sat, 14 Jun 2014 18:18:03 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com>
In-Reply-To: <539CC8D3.7000605@gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/RLj3UGuse19xUIXLE4xPB_CYuIQ
Cc: 6tisch-security@ietf.org
Subject: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Jun 2014 22:18:15 -0000

On 6/14/2014 6:12 PM, Rene Struik wrote:
> Hi Michael:
>
> From the minimal draft, it seems that enhanced beacons SHOULD be sent 
> every 10 seconds. Since in that draft, each slotframe is 101 x 15ms = 
> 1.515s, this seems to suggest there are huge "holes" in sending of 
> EBs. Moreover, it is not clear whether the "should" language refers to 
> a maximum time window or an interval length.
>
> Even if an enhanced beacon is sent every slotframe at the first 
> timeslot (i.e., in a scenario without "holes"), this means that the EB 
> cycles through all frequencies in 16 slotframe lengths, or 16 x 1.515 
> = 24.24 s (assuming all frequencies are indeed active). Now, how does 
> one guarantee that the joining device actually "hits" such an enhanced 
> beacon? If the joining node listens on different channels itself, it 
> may never see an enhanced beacon of another device (e.g., if they are 
> just "following each other" in lockstep, which is very well possible). 
> The only way a joining node may "get lucky" seems to be when listening 
> on a fixed channel for a long time and hoping it would hear something. 
> If the neighbor is sending stuff on all frequencies and the function 
> "F" (channel frequency mapping of draft-watteyne-6tisch-tsch-00, 
> Section A.7) is the identity function, then if it would listen long 
> enough (the 24.24s or roughly half a minute above), then it would 
> encounter an EB. If the "hole" scenario of the minimal draft plays 
> out, it may have to listen much longer (moreover, the formula for the 
> channel frequency mapping may not result in any guarantees that each 
> channel frequency will indeed occur then). If the neighbor does have 
> some channel frequencies blocked or different devices have different 
> "F" functions, the situation seems to be very unclear.
>
> I hope this provides some evidence that it is unclear how one could 
> "hit" an enhanced beacon of a neighboring node. What I described above 
> does not deal with "negotiating"/"finding" a time slot/channel combo 
> where the joining device would actually send its first message (and at 
> the same time have some assurances that the EB-originator is still 
> listening to it).
>
> Best regards, Rene
>
> [excerpt of draft-ietf-6tisch-minimal-00, Section 3]
> Enhanced Beacons Configuration and Content [IEEE802154e] does not 
> define how often or which EBs are sent. The choice of the duration 
> between two EBs needs to take into account whether EBs are used as the 
> only mechanism to synchronize devices, or whether a Keep-Alive (KA) 
> mechanism is used in parallel. For a simplest TSCH configuration, a 
> mote SHOULD send an EB every 10s. For additional reference see 
> [I-D.watteyne-6tisch-tsch] where different synchronization approaches 
> are summarized.
>
>
> On 6/14/2014 3:26 PM, Michael Richardson wrote:
>> Rene Struik <rstruik.ext@gmail.com> wrote:
>>      > Let us first tackle item #c) below on join process impact on 
>> the network. I am
>>      > particularly interested in detailed deliberations on the three 
>> questions on
>>      > this item that came to my mind here.
>>
>>      > c) Join process impact on network:
>>      > Pascal Thubert asked "when network would explode with join". 
>> Note RS: the
>>      > following questions come to mind:
>>
>>      > - how does joining  node find a time slot to send first join 
>> packet to
>>      > neighbor node (presumably, this would require listening for 
>> Enhanced
>>      > Beacon, but details on schedule in terms of time and channels 
>> seems
>>      > incomplete [min-schedule suggests 101x15ms slotframe and "less 
>> than 10s
>>      > repeat of EBs, but that leaves lots of dead time and does not 
>> suggest a
>>      > schedule that would create a common time window where two 
>> devices would
>>      > both be awake).
>>
>> The joining node listens for an Enhanced Beacon (which arrives on all
>> frequencies I've just read).
>>
>> The EB are sent by neighbours at times when they are set to be Tx.
>> The EB are not at the beginning of the slotframe, which I had previously
>> assumed.  The EB contains a relative timestamp telling the node when the
>> slotframe was to have started.
>>
>> http://tools.ietf.org/html/draft-watteyne-6tisch-tsch-00, section A.11.
>>
>> Does this resolve this issue?
>>
>> http://tools.ietf.org/wg/6tisch/trac/ticket/13
>>
>> http://tools.ietf.org/wg/6tisch/trac/ticket/14
>>
>> -- 
>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>>   -= IPv6 IoT consulting =-
>>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Sun Jun 15 13:48:03 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 799151B293F for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 13:48:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xWWe2OXH9-BM for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 13:47:57 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C455F1B2879 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 13:47:57 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 192D52002C; Sun, 15 Jun 2014 16:51:45 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 83F0663B0E; Sun, 15 Jun 2014 15:30:13 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 7407663B0A; Sun, 15 Jun 2014 15:30:13 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Rene Struik <rstruik.ext@gmail.com>
In-Reply-To: <539CCA1B.9040603@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com> <539CCA1B.9040603@gmail.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 15 Jun 2014 15:30:13 -0400
Message-ID: <24746.1402860613@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/MVTLUZFOTWfOwKmx_n0Io3zes_E
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Jun 2014 20:48:02 -0000

--=-=-=


Rene Struik <rstruik.ext@gmail.com> wrote:
    > I hope this provides some evidence that it is unclear how one could "hit"
    > an enhanced beacon of a neighboring node. What I described above does not
    > deal with "negotiating"/"finding" a time slot/channel combo where the
    > joining device would actually send its first message (and at the same time
    > have some assurances that the EB-originator is still listening to it).

I understand your analysis.  I assume that the radio people have this under control.
What is the implication to the security of the various join protocols?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU530RYCLcPvd0N1lAQIcIwf/QomGqugl1g5HcwPxNMLUeQBSNfNYin/5
HU5ybt+rs0V9ZeEhgh5tNb1B3cJjrTFkgsqTZZ0Rs+dIHFfFawELaHF9aJF/a8G7
gCbruZD05bthntQbty5U1+4FnrIatgKtyUFekkLk61uRID764ThwpzX2JHPVRdxF
eVn/KIDn887svobmTGULYxY6cqrVXhaScMK1u5V9guHBYAgXTajFpNZXmUVZQ1OT
cJHrhfrtW18MlBOolpSPrMnvYPTofm9ob4cl/QDQR1FmPJ60xcy4BmYsy9WXxYI4
yBGdQWvxiIIn6GUeRHVaMZOalfyH2M9Jml/c0cJPsrrBIJVO1+dmmg==
=7hyC
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun Jun 15 14:07:02 2014
Return-Path: <ksjp@berkeley.edu>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B314D1B296A for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 14:06:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w6K-GKvLA3s5 for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 14:06:55 -0700 (PDT)
Received: from mail-pa0-f49.google.com (mail-pa0-f49.google.com [209.85.220.49]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CF1C01B296D for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 14:06:53 -0700 (PDT)
Received: by mail-pa0-f49.google.com with SMTP id lj1so3771766pab.22 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 14:06:53 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type; bh=FH4NT+SFqXHpicTISTuBOWxNDI4n6ZtMDYHwvH1N+9U=; b=PoPj+9EQyTAnrwD28pUcBqS/U/nuUjjivlZoYg6Bz+l4StY5Np1p3jBPyHFSEx62tQ IFyHpHLgzT2qGuIc+vaXH1ZjXiNS7i5QgQUoen4cb6Rk6i7dNaP4aTprPn3t00+ATQer SGHUotVeYwJD9Q6nZq6sStnAzmvBMSQxU0VXOIs+bkFyWPEfshczS51sIAuTIdsemECu hya6GpZvtEI5fRyB6iSkCEecZP99y8aA9rfSQv/X8TXdeIHqNasOU45vAmYM6ScOLjkk Z7jS+vfUQmCw9u8WkSMw2yaXnitUW3LAt3K7tduEDEG5uSXYjrL1hKawlT/AGJh9jWus I1Yg==
X-Gm-Message-State: ALoCoQnHgYJr3uHwtRamE3QFIfiaeUJRGeFL+e5GaqpOJmeTg9XXYQqydQBlUaxf8Cd6xEBOiLBC
X-Received: by 10.66.119.136 with SMTP id ku8mr19303524pab.121.1402866413476;  Sun, 15 Jun 2014 14:06:53 -0700 (PDT)
Received: from [10.0.0.3] (c-98-210-76-194.hsd1.ca.comcast.net. [98.210.76.194]) by mx.google.com with ESMTPSA id zx1sm14871517pbc.60.2014.06.15.14.06.51 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 15 Jun 2014 14:06:52 -0700 (PDT)
Message-ID: <539E0AB1.4020309@berkeley.edu>
Date: Sun, 15 Jun 2014 14:05:53 -0700
From: Kris Pister <ksjp@berkeley.edu>
User-Agent: Mozilla/5.0 (Windows NT 6.0; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>,  Rene Struik <rstruik.ext@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com> <539CCA1B.9040603@gmail.com> <24746.1402860613@sandelman.ca>
In-Reply-To: <24746.1402860613@sandelman.ca>
Content-Type: multipart/mixed; boundary="------------070502000100060902000502"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/-7uLIf2g_rkj0lAKtynKJNTeXIc
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Jun 2014 21:06:57 -0000

This is a multi-part message in MIME format.
--------------070502000100060902000502
Content-Type: multipart/alternative;
 boundary="------------060600090702090803080703"


--------------060600090702090803080703
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Rene -
   when a mote listens for EBs in order to synchronize to the network, 
it can either sit on a
single channel and listen, or change channels with a random dwell time 
per channel
that is long compared to a timeslot.  In either of these two cases, the 
time that a mote needs
to listen before it gets synchronized is given by (see attached paper on 
TSMP):

Tsynch = CA/(NPD)
C is the number of channels used
A is the interval between advertisements (EBs) sent by each neighbor
N is the number of neighbors
P is the packet delivery ratio (1-PER)
D is the radio duty cycle of the joining node

ksjp

On 6/15/2014 12:30 PM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > I hope this provides some evidence that it is unclear how one could "hit"
>      > an enhanced beacon of a neighboring node. What I described above does not
>      > deal with "negotiating"/"finding" a time slot/channel combo where the
>      > joining device would actually send its first message (and at the same time
>      > have some assurances that the EB-originator is still listening to it).
>
> I understand your analysis.  I assume that the radio people have this under control.
> What is the implication to the security of the various join protocols?
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


--------------060600090702090803080703
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Rene - <br>
    &nbsp; when a mote listens for EBs in order to synchronize to the
    network, it can either sit on a <br>
    single channel and listen, or change channels with a random dwell
    time per channel<br>
    that is long compared to a timeslot.&nbsp; In either of these two cases,
    the time that a mote needs <br>
    to listen before it gets synchronized is given by (see attached
    paper on TSMP):<br>
    <br>
    Tsynch = CA/(NPD)<br>
    C is the number of channels used<br>
    A is the interval between advertisements (EBs) sent by each neighbor<br>
    N is the number of neighbors<br>
    P is the packet delivery ratio (1-PER)<br>
    D is the radio duty cycle of the joining node <br>
    <br>
    ksjp<br>
    <br>
    <div class="moz-cite-prefix">On 6/15/2014 12:30 PM, Michael
      Richardson wrote:<br>
    </div>
    <blockquote cite="mid:24746.1402860613@sandelman.ca" type="cite">
      <pre wrap="">
Rene Struik <a class="moz-txt-link-rfc2396E" href="mailto:rstruik.ext@gmail.com">&lt;rstruik.ext@gmail.com&gt;</a> wrote:
    &gt; I hope this provides some evidence that it is unclear how one could "hit"
    &gt; an enhanced beacon of a neighboring node. What I described above does not
    &gt; deal with "negotiating"/"finding" a time slot/channel combo where the
    &gt; joining device would actually send its first message (and at the same time
    &gt; have some assurances that the EB-originator is still listening to it).

I understand your analysis.  I assume that the radio people have this under control.
What is the implication to the security of the various join protocols?

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------060600090702090803080703--

--------------070502000100060902000502
Content-Type: application/pdf;
 name="TSMP DSN08.pdf"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="TSMP DSN08.pdf"

JVBERi0xLjQNJeLjz9MNCjc1IDAgb2JqDTw8L0xpbmVhcml6ZWQgMS9MIDM2MTY3OC9PIDc3
L0UgMjU1MjQ2L04gOC9UIDM2MTI0Ny9IIFsgNTUyIDI5Ml0+Pg1lbmRvYmoNICAgICAgICAg
ICAgICAgDQo5NiAwIG9iag08PC9EZWNvZGVQYXJtczw8L0NvbHVtbnMgNS9QcmVkaWN0b3Ig
MTI+Pi9GaWx0ZXIvRmxhdGVEZWNvZGUvSURbPDBGRENGM0NEQjM4QzlDOTMxRTdCNjIyRDI3
REFCNjQ2PjxCRDUwNDdCMEU4ODI1QzREOTU2MEFDNkQ4QjgxNzNGND5dL0luZGV4Wzc1IDYw
XS9JbmZvIDc0IDAgUi9MZW5ndGggMTAxL1ByZXYgMzYxMjQ4L1Jvb3QgNzYgMCBSL1NpemUg
MTM1L1R5cGUvWFJlZi9XWzEgMyAxXT4+c3RyZWFtDQpo3mJiZGAQYGBiYGC2AZGMlmAyFEwy
IMQ5G0AkyzUweQEsvhNEsnKD2Y1g9SFg2cVgsgcsbg4kmWdlg9jCciCSKQGscguY3Q0k/8oK
MjABbboDEgHKDEPyPwPTjTsAAQYArDMOpA0KZW5kc3RyZWFtDWVuZG9iag1zdGFydHhyZWYN
CjANCiUlRU9GDQogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgIA0KMTM0IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9JIDIzMi9MIDIx
Ni9MZW5ndGggMTk3L1MgMTE5L1YgMTk0Pj5zdHJlYW0NCmjeYmBgYGVgYE5kYGFgUPBiEGJA
ACEGZqAcCwPHAyYGpg/8h7QN2Dg4RBmesmkJMDBwBl06LQNSVZJz3GXn4iW3TC6eXfDs4kUg
i7Wjg6GDQaKBowFIdTACaUzNQI0aDKyJB4G0MBCLgkxiBFkp6sDAwPIBqHVrgy4D1xNmboYF
DqwOXD1MPQy9P6dt8KhgSGDQZeDYwLSGs5XB1gHiUi0G1jxriAlMj+Du12ZgLZSFiDJ0AbEe
A2vDawifURAgwABZuS80DQplbmRzdHJlYW0NZW5kb2JqDTc2IDAgb2JqDTw8L0Fjcm9Gb3Jt
IDk3IDAgUi9NZXRhZGF0YSA0NCAwIFIvT0NQcm9wZXJ0aWVzPDwvRDw8L0FTWzw8L0NhdGVn
b3J5Wy9WaWV3XS9FdmVudC9WaWV3L09DR3NbOTggMCBSXT4+PDwvQ2F0ZWdvcnlbL1ByaW50
XS9FdmVudC9QcmludC9PQ0dzWzk4IDAgUl0+Pjw8L0NhdGVnb3J5Wy9FeHBvcnRdL0V2ZW50
L0V4cG9ydC9PQ0dzWzk4IDAgUl0+Pl0vT05bOTggMCBSXS9PcmRlcltdL1JCR3JvdXBzW10+
Pi9PQ0dzWzk4IDAgUiA5OSAwIFJdPj4vUGFnZUxhYmVscyA3MSAwIFIvUGFnZXMgNzMgMCBS
L1R5cGUvQ2F0YWxvZz4+DWVuZG9iag03NyAwIG9iag08PC9Bbm5vdHMgMTAwIDAgUi9Db250
ZW50c1s4MSAwIFIgODIgMCBSIDgzIDAgUiA4NCAwIFIgODUgMCBSIDg3IDAgUiA4OCAwIFIg
ODkgMCBSXS9Dcm9wQm94WzAgMCA2MTIgNzkyXS9NZWRpYUJveFswIDAgNjEyIDc5Ml0vUGFy
ZW50IDczIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzAgMTE0IDAgUi9HUzEgMTE1
IDAgUj4+L0ZvbnQ8PC9DMl8wIDExOCAwIFIvVFQwIDEyMCAwIFIvVFQxIDEyMiAwIFIvVFQy
IDEyNCAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dF0vWE9iamVjdDw8L0ZtMCA5MyAwIFIvRm0x
IDk1IDAgUj4+Pj4vUm90YXRlIDAvVHlwZS9QYWdlPj4NZW5kb2JqDTc4IDAgb2JqDTw8L0JC
b3hbMC4wIDE2LjIyNzkgMjM0LjEwMyA1NC4wNzVdL0ZpbHRlclsvRmxhdGVEZWNvZGVdL0Zv
cm1UeXBlIDEvTGVuZ3RoIDIwL01hdHJpeFsxLjAgMC4wIDAuMCAxLjAgMC4wIC0xNi4yMjc5
XS9OYW1lL0ZSTS9SZXNvdXJjZXM8PC9Qcm9jU2V0Wy9QREZdL1hPYmplY3Q8PC9GIDc5IDAg
Uj4+Pj4vU3VidHlwZS9Gb3JtL1R5cGUvWE9iamVjdD4+c3RyZWFtDQpIiSrk0ndTcMnnCuQC
CDAADMoCKQ0KZW5kc3RyZWFtDWVuZG9iag03OSAwIG9iag08PC9CQm94WzAuMCAxNi4yMjc5
IDIzNC4xMDMgNTQuMDc1XS9GaWx0ZXJbL0ZsYXRlRGVjb2RlXS9Gb3JtVHlwZSAxL0xlbmd0
aCAyNzYvTmFtZS9GUk0vUmVzb3VyY2VzPDwvRm9udDw8L1QxXzAgMTAyIDAgUi9UMV8xIDEw
MyAwIFIvVDFfMiAxMDQgMCBSL1QxXzMgMTA1IDAgUi9UMV80IDEwNiAwIFIvVDFfNSAxMDcg
MCBSL1QxXzYgMTA4IDAgUi9UVDAgMTA5IDAgUj4+L1Byb2NTZXRbL1BERi9UZXh0XT4+L1N1
YnR5cGUvRm9ybS9UeXBlL1hPYmplY3Q+PnN0cmVhbQ0KSIl0UEFOwzAQvPsVe3SkJNhJSMux
KEUqhwCKe6IIpdgFQ2JTxwXxe7JNwqGoWml2PTsej7wne3ItCAMN5EIIBhzEjnAGWNjiGbuC
LI2zWZ6BaMkjvQ8iTp1FfFEKm0TQBvG1A7sD/4azgtUCeyUQlwgFAqyMV87UOHt9NBoODQRP
4rbPwZ/HILT6aT9tpw9tIN6PCz4sIhazNIcoiVPW55KElvZLtVvlgOeTNhlNYCLSkYjOKkZ7
yucDM/0IDSFhbA7/hHeuqY20Idw01mlZh7CuFpMoG0S9R8zTPmZBaKE77/T24JWESpnOOiiV
/7buozu1/nvrciQ29MSYFlU5Ufm5W5h7EyC7FOShr18BBgCNu3mFDQplbmRzdHJlYW0NZW5k
b2JqDTgwIDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9GaXJzdCAzNDQvTGVuZ3RoIDIz
MzQvTiAzNy9UeXBlL09ialN0bT4+c3RyZWFtDQpo3uxb62/juBH/Vwj0wyVoLfH9KA4LeO1z
ErTZpJvcbVHDKBRbyar1q7a3u/nvO0OJsiTLeW2vvQ+KQfM1MxwOhz8+zDhDKHGWMCaIc4Qr
RhilRHABMSNCUog50RxIKJRZigSScGckJBSRTBpIaKIER1pDtHTIbInRWkPCEWuFgxYosc4B
DWPEMQXsjCMDk751IFRYiTkq8VshKcWUxpSBdhgG4YWgzppjDco2EvRCBZjTQMMxpwzQcGiD
W2ibYZeEEFgGMoWSAmkg5VAXlCScRTrglxxrsNNKOJQHbSiJeUExJZGPYcrAt4A2tJZePqbA
ND/+GA/7J/F5Ov83GPj2Hr4eyGk8/AgVPy2nq1m2fIDk9XA0XE1DATEU6D6+exePVssdVHt2
bbEw/lsyvCPa5QRIkqXz2ZZok5cA9YdkkZ58SnbpZpFs/nka3z6u0/hqcBb/vE0eUmz423q1
2ZWJmx3QxlcfQNg1EPw0Txepb/bmy90OeUdnWLXJfKGPKyy/ZOlXKMZoX4p/QZPzNJmlmy30
ZQUqbVv0aW/1fJTLGaMDQt+8d0A8AZr+NUonxhZ2GoxZBDbLwyQebNJkl62WQ9DnZPhHTimM
PBfUcMpkj+ofKP3hNB4RGV8er/5weUKnU2eTqerJe+l6UtzTntX3opcY56y5Z3qW6FPfy/h3
XPwp+Qu/WP1r8HexmX5d3K9Hj4MvF/34mhg/NvH1av1lHXoRf0ynu7HikVbg4EaYSEJvuNWR
ATc0RkWCqwka4x8nH9KvBGy7WJ+WxvHZ+PZklt7dZWlh0/5yudp5w79Ptin6TnybLdIt8H9c
LZLl9U3v/Wo+u7wtXS/+lC37y21W5kfZZrsbfE42hHrnG6bb6SZb71YbP01R8T8nBQVXqtQH
22e5Fr7dT9ls93k75jCV/98B5jpRShEFeIYBcA0QCAo5GBwrPQFWmj2DZ4b6wPRcKOUYug9Q
7gAnDGAPgIGPQ1oD+BmQj0FY52kxjXUOUM/TYj7QQV4pXZPjO1IVKiqdUpaVinklgVmC4BBX
y0ueIm2LdKgveUBRUanzShUG8PUOFgQAX4wVxqowjqroEUagarm8AKSWGWTxXVJ79qqIIDon
LrkKBVExpJCFJXlDgRBQ2aCDgfVLhDpTKYNYhjJahGAEufeYvDznN2ofVGWQmqEcQe8SleA7
UgklU+Ey1YCKBRdpBnSfciRbAtKgkZoBvaAaSk9ok1O4evCUMux5Jh0odaDUgVIHSh0odaDU
gVIHSh0odaDUgVIHSh0odaDUgVIHSh0odaDUgVIHSh0odaDUgVIHSh0odaDUgdJvDZTcISjR
J0Bp8yW9DehUxSX/8ic8Vulvp+lyR6xj8SBZn6fZw+cdDAKPsRms6XGm49E8edgSwb2Y9+9X
38Y9pSzpCWoIp94TuZ7EF7tknk37y4d5Cgh6mW230AHfKGRvdunivIh/IUy5iFmzV27frfiv
hRpSmXfvPIq+5lO4ZESpReSLmNEH6OcruTGRFbwkLpmQWLvIclkTlqNizvMKZKzLLuQexDla
emXBLSOmEQ115Bwv881yzWhk8a1KrlKIYcYAWYGpeVHgcFIAx15SWd+QVFSD/0ZM8aOKhAnc
qp04YmWA5ogWC1LN4kVjstCxmW+jPZDdKLeN8irvgfzcbKKFpbRHifYFi5MRlQKBNOJMlXlA
/4h6DI6oswGxfbrWi5bFwFeGBcErUCsMYkojB7EN8c1mqqqERaMitd710N3AJBtec6wvlXXF
m6PaJVhLIsQKB+5OVW2KBXEFiecCMgcWVNICiS3ZQly2bMBGBulAhHD12VrSQl0B4i0rU813
n4trDl9OwyNxsGpbdNBAYw4fi4PNmjP1ubiY4LV50L4gevIw4s/FYZ4di2vzra3NYnzb5uVB
XJc1qaxd1h1duxQNa5esrF3MUl+HA2qRf+IrR8kimz+e+AWa4KM/v0ST6xtyeXvqKfxTwyML
ONbf7Dbpbvo5/rDaLJK5L/qUq2UobSyPxToo9DNroPbr9IhwG1+t0yW5T+bbNL5ONtjD4m1m
/ppRMx7BxlH5t4vEOMxVXzL6bYF/Bdl8r3h1XYi9ur4kLL7pF9mbS3zQyXPyn77tzvInpqt1
Xu95B30CiF4XQWsisLohYZr40pqgYjhhTFRlPGl1J+KK0awMJo6kf3Ds3y5TVRvKm8fF3Wqe
j90om6ewBOb2KgdzOHx/cXn2+5zw2VGUR0aRto1hfdvXbGhwMbx53AL3xfJ+hUOwmaUb2C6d
XMygs9nu8RQG9SHb7jaPJ/3Z6i7Fx6frdf5Ml1B8dHsxvF2dXQwvk3UcmOLhJ49ShztF7fsd
vAB4kQK15tUN4ljgfmvC2BhwdCIc+tTEsLGEQ40UbmLpGEAX6sUYbDFhnI6lppPJ033NR3CW
wCBA9XaM78fxJfF+0xv0753XDtVg19XPywyIUmLzHpTKPrF9Vbp1+1qFAKXr21dqnsKA47P/
zS5j+ZPzvqekfvLc8LIjQ7Flr3mCq58ZmDHPnxlqu3A8IWNcO5Zq+ebrg/KcpWUZYDvMWe10
WD3RhROe16A4IWKdrZwWAx3y+ssDxsq68pKB86If4Rs//qaA1uPqAbp6LuThHNp2JQLaVO3Q
vDGQ1rdmcSFktTOM32gc+/gzeXFUzYW9/uPP9NJNvnMStZwB3zKJft0l9Nmp9IojeMt84qwx
n2DP8br5RGuzqXKGJTnVa6/h9jKPXb7RF1290ZdfvFWnz0su3Oh3X7e91uMDL91fyRR+72r7
DcNs1e9Z292H1gr8HvZYYfGo+31/kyXzirf7/NsXCvukdyum6s4dWnujN4uGNwvxEm/2Q9pi
dHs4UGGQ97l6fRXvc3wu7nV8G9r/o1VYgfJc3bPzsvz7sOX6bZ1H55D2beUHWL53y1Lb4MKB
Z+9W7R+cJ7mfXQ3OtvjPfeX25WpwOaxvebmuHWHE3gUBXv9b0FvsgGl9B1wDwz8gFP5qRxnz
BAznLb/ppxmu33ALOm67Tf5fhu7Xme7Xme/8dcZ3Lt/J1X+dMd2vM8UFk3vZrzOHUOT/ATn8
SoK44f8PORTkkO5aIL1Dtw7dOnTr0O23jm6CNdBN8LzgPwIMAGK8wjwNCmVuZHN0cmVhbQ1l
bmRvYmoNODEgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA5MTI+PnN0cmVh
bQ0KSImEVE1v4zYQvftXzJEsLK6+JfdUbxLUu90kRsSiaHd7UCw6Vm1LgSTXyBb9751H2rHS
BVoYlobkzJt5b4Z6ryfvfix8euon77T2KSC9ngS+8kPy+eesJKYszFUekt5PBEn9x8QnL1BB
Qvr6zUYcX3YYL3B4DOL7KekVWYt9jhREapa7HNYKYl9llM58Fds0n4Uubpffk/5we0PFr3dX
i4f7uw/SS8Rv8nf90WIGITA9mGF0AvWziDF1xQA313R7Uyxo+XCv76/uP8mIC0Pshalvi7Kh
/+IcccFplqsw/g/SNrWfnJmFAPIyFabR2RN1/NTV/dCuTUeFoo+KZCqWvGO6KX0qedGsDPau
243hVze80CtDp5pNkwRAj1XIxllqoF8f+oHuzHCUsWj530kvFNteZieyTp7gXGOU2iITNYvH
NUZQ1k9neCW0ODQwhmPb4l3JQND8T5hGTVHrQnqxKKUXiJdj2WFRTelqTrM4gRfX9koBAp40
ztQsCcdZfy5kLuYX3yCydFOVRW84/rV9rplaP/DDdDIR0x1bFRizZrnAFs5e+P+3DMUPFYsi
A180EMPg6MguLVbw3cLo1YpD7d7eVYDk2Tm3LfH/Z9u7cPTCBGHwTUNX+BxqvC/0w/wKlv5m
/kDaCaSCKMuhkssW5cjGt2BjSIP8XgaRMEyOCtBkZrlY8XLTWWax4wrPr6aiWyjFp5iDDQ5o
af0gRWt5Q0H6IjTbBbyXXySZpuTlI/x3I4DXBo0LdHJ8Fp2BK/KW7P5o46a0O03jEdPybBcM
erTNshPUm9UB02po1IXMsTw0gFuVwwm4bRBRnzlSSdYN+ZryyWAORrN+vo9BnqWXchNX7bHm
ek3fAyEQpt9Qw1en7baK8L2hunfofFbVB2tQuVohomyq0aTOXJIoDGdIor9j8OY0aaloO35s
XcWJeMJFoWe2sH3uwezUg8r0cHzi4waOhk8qG7GGN6yOELOxp5CiMwg3/EFrcLCzo58I6l4l
W9e2f5GoRsoE5y9V6op+28hfGN7n4EycJFrMH3ihbSn9UDb2mruLz0ysRXUzelUHPPuhq8sd
lXYxMELLfdqXQ91iwzoq6fG32Ap+UjRM/W+b9Wi/OMjfOCthXkNP685+lva44SQ9HqYX67CC
66Zr7aL+ipTWpHZNTVtZjJ5r5RYjysYfsLsbam8Do30etTiDWgS9MjdJ9I8AAwABPrPyDQpl
bmRzdHJlYW0NZW5kb2JqDTgyIDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGgg
OTA2Pj5zdHJlYW0NCkiJbFVNj9s4DL33V/BSQF7EhuWPTHzZU09FCyzQAHvY7kGVlVioIgWW
Em/+fUnKyaQ7c4hMURRJkXwv+z8+/CO8SUUnlqIXYcblJ9A2FKUUsFgUUyFrMdGedp4PFBxM
sRMLTHjjQiqPwkjCTAcjnArZ8gU9h2h0eJzHDSiHesdRerFkr7044g+Kf/efP5R1Vdeyg72G
uuqbYQf7BWooZSU71H7CpKPGjDphsteOckCX1h/pC+EAOrDG2WhZ8rSURSMOszFwpp3iN83l
YqMBxQbsC4qt+EHCjOYhW65htIqpeHlOs97mNJuh71/T7HOWOpywDlJcvNUq2eAhBWCNMQnS
ZCDN6nCwGrwxGJVjRKoDvkA5Bz6MJj5H63O0uhsGiranBi6TdQb0TdP7sXs76lYr5nA5TuxF
XZVFrVM/yG5S3hsXK/iikvH6hk8fn0I0cn1Q0zdv6z4bZxUWpxfW2XSDI4kXWriaM5WxF8lg
1jrLazV77hW9d+TNeD8LhwMcwgyGrc3MHm+F5EP2HIuyEWaTc6wrue3bN5VOE1kGtj+yDHkz
o3Od3cD0yDPCmhLKOTAEWj3HLbfiPIcrv5LztJgKHXFu2Y1do5Dx/4qCTuXziDRtrqjsZP9o
2ndB9n9SAsNAYsXrx+8Fu/Vreg3Cb4vgLBmduP6MoGh0+BwcFZDE5WEfExXu/KylSSanWRmj
5Vydqchy/+3rX/fS4oCtqJPt7h3UTQoLh5P6QnBqBYwGhxkx4hEVAwVpBM7UCNbD6eKSLadw
phhIMUuYMXW6+h9d1caMFu/4ohXHe/i23r7FUNPXKwzOdHsGpbWJuAt8P22wGOEScYgjoSab
LhYrNPyG03sTtsNrEzI4KR9M9ozgYN/UUvbvU8TkN/QswLklDAUYLzj2BDbD8dC3/Lh5xRBT
18oJ2Pl3iriSapc5lcozEmVemSwNtZcIFwMSj7LywZc3ghDrDsi/j54193AZsVJWA0o17EdG
rMd5yY0601PNrNJlpkDcxxbJGlGJMhHR7+Qmh7VozSDJc7m6XttD7p25PpBEpILP+RvlGjEj
BXFlhkmWEGywq0nRVJI+PaqqDs7TLSJDOnDqZmbmYCzonSHYsiZknqgyTAeQLGlPGPfl3TYP
bfdoc3Qh4d8OT7pGh8oT92boIE+aRLEdEqGerLniFAD13WisEmNJ3VxQ1CcMBPBLgAEA+hHa
dw0KZW5kc3RyZWFtDWVuZG9iag04MyAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVu
Z3RoIDg4Mz4+c3RyZWFtDQpIiXRVTW/bOBC9+1fMUSwsV7QsOz4GTQ/dRZKi1iIo2hwUibGZ
KJJWlJNNf/3OG9K2kLQHy0NqOHzvzYco/2sSJ7Mkmc8pLwlWuqL8hRKK9UxnlF9MfkTDTsVZ
1Ld47rey6PZ4DqSWkWzfq3gRYbXCaql0RI93HWxHxUAFOdtgtcWjNmS2PU4YFevIORzsJI73
GmakbhlaIqCAJ/8w4fD5w+RjnmvSlN9PADZZw0MYZIsR7qUH/vfn73RzzcG/Xags2vigHCE5
RdBH4kl6CpCe+QA3Kl5FVukk6k2tgHce4G5M49SKyS+iHiToim/A64F3Xthue348uin7Um55
84nd4UCbV1415e5wFDGY9jyC1y91FhWIgUXbTOnycC0f38HrrTSjVL2VyAtzZLhcvZdIq/gs
moEmfbmCnX/D8/oCz38+yc4X5ORa3r6T8A0ML5zHIfJm/nK9+E1dnVcsUQWiJ8IFZCYVL3mP
ZW9F2z+lIUYeWDCfip6uzFF9/om4j/QzYvsG9oa9rmD8VNQbZwo+Kk4lGzu5yWsL4IsAfLUe
AV8sQkcAawfEpZtydW8ll3wt7sZ2s6WyRcaflE4j05fWEyuaiuQ9/6q9E44CAZsF0/JeXVcH
RcpTMYRjHqOkNtEeZJot1u/UdV1RGpRq076QYSj/qTSybnAzynfMngre63ivqy3fYttGCrs3
/+5tb7xZ2+KuNtPRlToN1ZTOV6ExWQ6LCnkCGYNU1a9TSY4z5R5tzuGqY7vX9lns/pVaGPfo
CXh3I2Krwy1nGrdoPUvWSxRaxdcVjK3k36PEGWTC1ExSpsiL6Wd0To4T4e9+Nq9j/MeC9N0Q
h9CH7CJ+gIWJNviu42t8xfSlrKi2g+mL4cDO7bewtp4kDz0G5eyTrYvek7xjkg8QyZRD4C9q
/9Cwb2djhIF7pjGUg8IXtrYyO40fkEx5MA0nDSvZoqH1fzKfkV9kUmZqb3xq/FFHtal+c0Jm
wKn+A4p0vtZHFJV55v5DW3a+rhsUJ7X3oJJvLpn5Vx79U5K6lo5Ce/L88+5h+mWYftIujYw8
+FR0GQaok2bMxnU+PzRjirH1thm/+i/TcPgWldIs+M6g0oWblAYs7xmU4J6k8PXSkME6dJ58
65T2rgUmbilBiF+bZxGUo1XjZGDDJ8GyvOqW6H8BBgDunMorDQplbmRzdHJlYW0NZW5kb2Jq
DTg0IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggOTY1Pj5zdHJlYW0NCkiJ
bFVNj9pIEL3nV9TRjjCyDYZBe5rdHPZDkaIEKYfZOfTYDbYA2+r2QPj3ea/aBlbZA3Z1ubr6
9atXhWz//pDO0zTNZVtKOs+KTLYXSSXJYMv204eXyNnStoOYquuHpmvFeBlqK2/GNz5eRbLr
nAzxJqrjZBFZget7nDxFTbzA1iM+2DiLvJc/n79u+fUlf42zNJL4dTw8X4TD83y15unbjzjV
tJX8hehvcR49453FRZSm3N/Dct0QZ1nUld0RKz+X33UZJ1k0wFHjJ/0tCBhCnBhnsZAGi3YK
tgDaVvRXskN+zeICvETxrUd8683qzs5yGehpkGgVVe98+sE15ihGF0N3MiCMpobIpebLOvuQ
eyI+X2c5c2c5zAJHbCuS0PfHpmSWVrGLJojX0Q9yPTh74gXt8fqY8Wlic/PEjMmYcqwo0/Zx
sgQOFE73m5br0ibequVJQDM0Zw37TbbfPsdP0Rd6/83z3N/PWkzoF/mEflPkE3pIhni7XtnA
HZSFwBckxFfjxdm9Wkx/slTOXRkEzPzpen27Cw+Y+OcppcElIDzoRLr2GC+jK6tvdgNMC+BO
7I/Jbn0D68yzVKn2jFjDTe+GMfwKiTcUqAqEQfU75VJRdsxReTq7HZ/O6ubkjnhDxKEQy19a
6dIxCXcwm6joei47Yj6hsCpGIgmHnBnhxKju1VaEupu5dmKoZ29DoIJhLNNZ49AYd2RjlwXN
jV22RSOXHTa50BE5ZOEH3h7VAmVecE/WH54vaGPpldEdolU8i8iA97a0qs7WEvlFP+JxSPC4
EDAumi1vdc2L9f/0UaAfCMZyQnvir3C2ZT2TEsfW/GqIq7V60Zpc0NnD6GnwMAbsZyQXtaKj
1NLaSjwIVra5DpLI0fTvbYgKF3+YS6O602Xozf+UsuxOyH/ivbi/0FOKiBYE9MayqGQu9FQ6
iHCN4xii2jrASOgxKPp1nEROnv9g8D8e6Weyd8zEkVcnqCuGbhhUD9Mpm0b3YnGrq+swggo0
Xbvne6ZsYqRyQX2ckEQjjqE3k6O5Wgcdlep1zXAV9iui0SJ4WXeVnoYh8vKgvmEun0Gpbinr
Xwd6mj0SNxU6NMFBOwv/JW+8uG25rPiltars0H0TpcqzpR4K6uE+wEX5aEkW/oaQgxoE62we
h8fBywteC8a+wphRxPeeCDhX2Vqpy1fzzXIlRTZfLbNxAoMzKjchZ1ke5H6dXHvtnIT/PJDB
JEIvtQGes4UGdROm98DSMtLQsrekXKmucTlNYNHhm6ibEgOryE8BBgAv3ecYDQplbmRzdHJl
YW0NZW5kb2JqDTg1IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggODI3Pj5z
dHJlYW0NCkiJbFVNb9swDL33V/AoD0ngzzg9DthpwIoCDbBD0YNmy40RRw4kp0b26/dIOU66
9BCLkvjxRD4ytP35EK/iOMlpWxGkbE3bkWJaJqukoO2Ph1d1NC4qVBMtE9VHuXIsHKIkUzpK
la0MDTjd4adZoBYfEXTTwK6PlqliBzULnqK1es1xvYBAhXzXb7hesbR9+YWr56hUC/hJYmXZ
iG2OTnzlqj5V7J2j8NZS9BbekObJFXqeB+ye9RhjijVmZzGEnIWFIPVRovAAhNrxoaGGT52X
FyDu7xeAeaLj5eG96PZV37HCICgmiCdvgqeWTyRDBhkifxYMu1ttxrzkxKfFlPg4v0u8r4Cp
gJOck1eoE386Q1UvQtf6ViS7bJzBsWhra01HIvbHIy+tfecFZoeDuLByWulhMufPKlrmn3BN
sNJScG2/Ac+zcSGEuPWkOy8OyMryEcAiSd2CtK1DUOMG3UqI7jwhl93gtDvT0E/QbLAOV20v
qxZfzItLjeOknHAl5ea+2qNUtGamSPqlwpa9TByFZGgqaRVtuBrM5TJU62Qv3D3DxULYWICN
MB+1hzrVBt8P00khC3RGHSrOmyvI+DGAzMvH+276YyhaClngqg5swL6NsonsGvtE+JOGDtPv
CGMRktk0QG/81Ip7GtmYL3azg7WqjOUjUdEdJFb6a+oov03n1PZpFpBKmVEMeZQTjndTYHdJ
Ycp9jmsUbcZQh2aVAcDK/qrMdP0vw5WeO9gSkzwYMbQTm4SQm1s6JlNKszIv7+veMHl71MkJ
i4fQNtyTdubkMPZyu1/Rd9E6MGSh2JVsyHQg9NUM0Edx7/ZytdN+DnAUj614gnZ5i/jSQWlW
pF+QwBo4btoBvvRARmOHCVFhge9s6uIWSbAoG5QMeZ6CfGeqwZ0OVGnLL/zDjojpVCKD2Vc9
vCmzubhjG8D3MgkG7jwWKmkNJzI10pTufs54CjdhVqwVumIwTRhL1IcODiPCaNde0h+mD3Z9
c8O8y9wD9e4LetTV3gwynku1oicjjBu5sfl/YE/X/x90xzRqAcrO/0Ay130/T+HAOJnLZdD1
VIuiqIjk0WdIR/GJeGvGSf8EGABA2MC+DQplbmRzdHJlYW0NZW5kb2JqDTg2IDAgb2JqDTw8
L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMjcwPj5zdHJlYW0NCmjeVJE9b4QwDIZ3foXH
Vh0ScrRwEmI4ujD0Q4V2D4mhSCVEAQb+fRND79SBoMf26zd2WFk9V2ZYgL27SdW4QDcY7XCe
VqcQWuwHA7EAPajlIDrVKC0wL663ecGxMt0EeR6xD5+cF7fBXdOkD/we2JvT6AbT+0giPr98
pF6t/cERzQIcigI0dhErX6R9lSMCI+Et2GwWQRDHh/ekcbZSoZOmR8g556ci/NKsADT6fz56
2lVtp76li27VghdE7U4ZkUgDnc4J0SMnupREaUyVl10XzHLBhSgi73l0j/+8dmtfllBDnmR7
p+So3vPhsmGR1+HV6pzfC22bpg9zDwavD2InG0YMX/QrwAAyV4W3Cg0KZW5kc3RyZWFtDWVu
ZG9iag04NyAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDg2MT4+c3RyZWFt
DQpIiZxVO2/bMBDe/StuKUAWkSrK8kMZOhVBW6BAkGprOjASZbNRRENk7Prf9+4o2W7SLhls
Pu793XcUQJbmq/UCqgNkkKhU4fbT7IcIW5kshIENLYPMhXumXd/QvwfXQqfrRzrYnnXA17rT
D3zT2XAE3dOe9WFwLGAXXia5CHIlWG68v0LVBuTP6ussS4siyymZ6j0mUTuO2Z7trGMrcHs2
HmDKk89WKnGZApu3MikExGAyUSIc3FTTY3KwmEhzkoE/smJNh20ak0qyNMtUCVWNYM3L9fIM
VlFEtD67g9mfvAxXYJ+kysSOrjpMCq9Xgq8M+w862FgbVzNCBcH4YHm/IYSr799uQS7FqdgR
I8wmJqNUMX/VOW/2ZtCdnAvYyQLrXAjX4Oa5lmvEHa83pkcN2lr8OZT1nuJscacRFg9+S7cH
NO2B9LaEPVucj8YbqAfyQFcG7figz1nmRUwzU0qde6p7ivVgAPEo0I7sEYN7gSgwXxQFUQoT
oy3qNpo0SJOz1HtzDpGPIbIFI6FUWpQKAakajMXg9R0aHynEgzGyJMjJbbIUfyVwL8HKxSjV
o3yNeMxFrzemIQdn/OdT2MjWZIw7cYKC9yaMGDrqwWOKycCXGCLn1HaaBKRl8Vcjgs8dtQD5
g60nttxKNdbsI2gGU4r2YWwWudhwPwLzq2GJo5tr3JxzjikzSOmqXE6UaWZCpbL6NftQVTlg
n9pZFotbFWUEEp1EeRblcSAWUWu9UhH5NCvWE/B3prM0iAUPIrEX3wNeoXN0fUh2cTXDNU4g
fCzpVKa8vJsav+MnBnsULiYxKyfsiV8vJ7Fh/c7ueR2O5OZg6ZVALI6IntEDY8nhW+IU56lD
GLU72xpo3QC66+jck9g1xv8LyuQllvmbsBwHZbEo16+w/D6+qxHL4zVTk+t5pr++GQwX7WEs
iSp9Mp5VoghiDciWCI+kJ5zc7OKR3qwLcqsTuYtXr8sTdotoRzNB1Ltium2ZcpwRPh+TCr06
HojbPTExKhJTwWvsBLmiZwPusAs3YEhpT9qDG01Yow//ofEF9nHmxPxN4E+zvCqWr8C/6cxv
hv6yAZ6BZ+x2bgjAoNK3p23NYBhr+r5BsMT4J5MwGfVw5E8lITHotrU1FgXwR4ABAHEK0Z0N
CmVuZHN0cmVhbQ1lbmRvYmoNODggMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0
aCA4Mzg+PnN0cmVhbQ0KSImUVMGu2zYQvPsr9kgWlUJKlGQFRS9pC7RAgSbWLSkKVqLy2PhJ
BiU/w3/f3SVlO0mBoAdbErncnZ2ZJXS/7VSulG6h6yGjV2Wgu0D33e69ONlVGkE/J0sRpkXu
BYyyFmF+lroUMMhKeNweRxecbMVEsYAB04w7g1tA/pkqlFRAUepM501b00NX0A07YXLZ/bN7
1XUFaOjGneLQvDEtHcAASPsq7jNMXccoVZaUVOfK7GP4e3Fw/Tn49foaPsqsEmf6szLTItiJ
3lephXPQz/QxjX6gp4tb3h7x5Pcgs1r4uOQ4S5CZEbwVkwyxNwZTJCyqrAiM4uYMEvkTorFc
f316LNJjIuDyI6UlyuzxCCdG2n/i0PUb7BVFw+xU/5M+Zi8mzHXxFXk/T6jhC6kaZvybWGnH
yr4mdSdaRWllI4BeEXMhXGCrOGrkb0evF+LbOXTMRIuZwTXF/bx6U/ylHqEyhDrft0XE8INS
jf7xa8kLs4EuG6Y5N0pvsN9gEVRm+G/Omrxoy0hawZzsKyblCyj6GwC+kPmz+jdbRNdQ08Gy
s3yP2l6hZwfYid3k4wPe/ZLGhdYWB0f34o4Pwm9CKVWzVJnJ29bc/EWVu8PvyO0f6Gk4BRw7
EuWFRPED0b/QBrnZwhhsVFMW4jJT7CeKg3G+W1nrVFCbmoUp0Enl1mWAFXV/Is86sMvC5fCj
93b18wTzCEd7dQEKuipSF2VEnjLd5h6zuWU+hx6viYtfn9LJkgcicNoz/VFFDEFteSdGIWmG
P99yDA8t8JkRr6rH0Uz3RLnX5X02qziaBxdeeNB7Bx/EWxJhPnyQOWc+rFwSiaNZYG3pa4Hl
dE+/eaJs9m2iq9y3G12u9+OVsJ5wqHEs6PqcA2qghV2Xu12zu9QIrjbVRhjletSam3eRiBVv
s8X2yDt9TryGqVVUZCAbYTFYnxzdKybegD5kF/LZZrAmqszXfc8HnznH+ZbTo396+1mVTQr2
wUxmgvuh4+qz28YpiZmE1CxkcOxHPmI9p1zTM7X2QEqVZt7UzQ3oOkcYsSr3Nd06/Mh56O3Z
TVtZsCeGcvT3VnL4deUpdfc0EcUCa7L4EIFfydhpjcRDgAD/CjAAMJHFZg0KZW5kc3RyZWFt
DWVuZG9iag04OSAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDc1Mz4+c3Ry
ZWFtDQpIiWxU226cMBB95yvm0a4CwVwWVupLpaRVKlVKGxSpivrgBZOlYfHGhl3l7ztjs5dk
+4AZ2+O5nHNsqL4HcRTHIoGqhjgSxXIJ1R5iCEUksgyqm+CJDWrkGdvznGmDwws0ipfMdrj4
jN/Aw4QpA+SkyQZJ2+/3gS9YI8lFcpy1vXOmqKFglnZX0vKCKdxtQB+PWUUpd2RTvFoB/zMX
Hadz0cukPBWd+5qNep2UHS20Rm+4oALCBRt0oyzIoQGjMNlWG/TQA6z1HuxU18parKSlbFMP
45qcTgmFSxiSmbuM1SfMtKe6jKKGqHhrYev6XFMUagnWckeAuQpWikzXWzRHdl18RB29q7/B
dVUJEFC1Pn92yn9G0yLxLScR3NxhvsfbXwjZAxfsruIiZr99HowVz7E+ZEzLU8bw1ChaZby4
lEP18OMetkYjKRnrGhoRVESgkyua9JhZgVuXxO4ofQE+dHEILSjyExuNRDRyZluU0IqsNzwP
NbEWM7fQDafxmQYYO/o5D0Uprni4PCeqPCijSC+U0SL1S4bqwHGo3xCqK+TckYOV5Kg+o/E3
EYed0yFmhYbMHZ0xTti0S2cjd/ALsU8fDHS2wU/xlHSNmz4IVgnSzRE/LgS7f6etWMy4LET6
3xu41+YFSJ2oq5RJo+jOoELBSqdvRahZNVgFukWA/OIVyLqejBwVjBo+g3DLNjpn5ABWkooL
sKq1g95CLbdkOUI9KX03voHse02zvb3gJGy6Ha0oBKztajl22jHo7vqRZ1u7DO5EM5HZd4Mn
+YhNMmOTxOl86xjSgWKNo6LICDR6AJqAta2iZUEr2AfK3VlpkkFRRkVJIG8CEZVlfmiycW8F
SWHkJCwcUJAW7+gGvw6n9JDhyzdYt6kdkbrGE4grENMTnSEfrxSngCHELrV/ufA2mJ4Tdinb
4n9LS0d/fuj0tgpeA+HLhjyDdAH1Jrj+9iDg2QbXXzcx3Ojg55lTsiyj/NJPeD+AfwIMAH7S
bVENCmVuZHN0cmVhbQ1lbmRvYmoNOTAgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xl
bmd0aCAyMzYwNTEvTGVuZ3RoMSAzOTgzNTA+PnN0cmVhbQ0KSInUVXlcU1cWvi8bEES2IAgB
H5uycxMVZEd2FAiSsAiKhBhIgJCYBFkHSQZQ6wiIgNXKIiAIZcSKjgsKaFVEQUXRWrW2UxRw
Kyi/Ii7AvIi21Zlp/5vl3d97yXeW+8655zvnAQQAoIs9CEDkwwz0LxiOrAMAyQFAf6+/j69f
rOlaMQBUPcyqwZ8Z7nVz7LteDHcAoNK8gsnyE1jxSQAs5GF6oyAWM6AvIWQAw4UAkIoYTHu6
9iZIAMCWgukjQr2DWDm6+a8xnIRhhwif4CjmwVQtDNcAoFnGEbBFw55JzgB4LMGCSuJslKJx
8pEHmGsVAMrKCaJEweEAAR2A2AYAiLcT2RIRoAAVANbnYvtpJKZkJmywkl3AcBEghPvw1gsy
HhAGMgHhxHUAKi14XPb6qxuWMgAx4rXi/TxMoE3QmgDESIhhM55AmhHznKyFYRaWv0UyV5xa
+aYtChA3YOdBkacIOWz1sasYLpjG9DYCdoZo7iltH0CsscL80VS2gLvontF9DK/AoI5IKJEW
D37zJSB2rQNg+YxIzBUll6y6Cki4WCzfQ5gP8m4pfoE+dmZAcU7YpZ8L5fpZJBWrwoDCl2qI
Eq5Grp+MiRJxCEKbC+eQlGc1OCIRwDgS2ZqEEBC5Iw4h1ITBUGjzGwm11iiPClzfLQaIBxIg
BCmAC6TY7a5YEP14P4LG3B7/hlLy5JDSQKDTD/VoZ42ccgrKcYrbHKexYv71ZX+Rr6buXytZ
p7P2Xh1U+yVOhICFI6uiLYCGJHw4gaw9L4Ir5jP5iakoS5wmkaIhXGm6UJxM04U6CgNV7bkf
DGzQwFSOHc0GWs0qTH/15Au4KFPKFoj4qYkokyveyOdw0TChUEpbAumz1tYhDDQocLlXYFAg
azW63NvbN5Tl62ODWnAsnRzRj98BjXTVnBzhUhodvruiddXgEkiDjvTFS52WOkX/7ycgq/7t
mSNEgJdtx859K04mAzfs0DFejo2tnYz6Felwo+oxTbXIO8zbaYM9i60OD0yoxCwZf1QyrTLn
2l2D6BN9wxNbvqrs2mz+5E9RGpKkjMsbdKYuRE1YfhkVW0GYso3XjJJRL20ou2kSZX+zl0LM
dzhZ1nwkeMWjn1xM/hqxO9d4b0ph1wr/XUlHGhxuvlWxvXHE6QscHiP0J5TAY3Gxw+e6Z3eX
auVqahSZ9A60aVvHjPg8UM2oqs8db1QSG/24erQ3f3BrWdDdEPZoW/0bP7fQJarVooiJIqtN
ulcecjoz+UoSu0PlFp/9/Ky56fraPvIlDZXiK22tFhXnMi3zS+/NnEz0Cmgo0XjQyZ7cy3y4
s1/iMTlVychvCe+f0uRwoJyAg3J8cg0eh+BwGspZgjXC+J2Mk+emvP9O0av8fyQxxlk6fdnH
JHb4hcQ1H+Ij/1N87zNT/beZuUCnWQM6iysWSFBhApom4aJsKcqTSkUSZ3v79PR0u42YswRz
tuMIBfZiEVsRKKTRFkFzhTNe2+j3s4dyxORTHssRdYDJyTg5goCuLPbmJ4cb8RwDa332/bxj
OoY120rc2heV5lOcnhRcsSwlJQTU4xnbRxiNY62x/fbzu3c8P1qVvcP4yqOZwZCxt63lUcc5
tkNFE5Z6faKi0K+fVbR73u0wH/EKvzVR8II0vG03lTaOVx8I2mtmdc/AoFg+fmi0MXiQ0vhD
8a1u3ll2VJN4YBIGML61F3LQb7dekmefXXnK4ryMNzwk92zxc6555eHQF9TO8orO4mZP5z/o
9me1nHB7mtet//LcYpmsx6r8zaZY580llLu9dmkvRpOH3JriOryQZkZzzAEPE1q1ls4ryT4j
+TaC9WM/XJCgeEGoXflKqwxSvtRtR7GNP+1dK9XJjkPZUehJUsYmOpGohNETIwyEHzBECs0U
RcFqIuRIRB8XRSGxl0jZ0jQJVMGKYqiNNQGAPoq/KMENKuqsGlcYgBRO+iLY1tAKWnzYGIfM
o/5etaG2YhdzwhxI/uCCV4aqCqE6gYDHkbr+xRSwHWdw4mz07vxsph7WNudJ26nEgrOmz4r9
1K7qB3eM52ShkK7H21baTt89tvO4iw5pUbY7jgTqjUvztcnnP3/oGXmeaD7S2qqZ1PTQ5fIj
04kyy7We4eP7mZUXHZyduMoSST39emtLZzfRdcb36dcjd8z6r3AOqjS++dFgcGo5OakCmwJa
2Ffs9ewUUAdnwDZX1y2a/e4TnKffe346BEQ0a2g52wgm3kJRppifyJMqWI7SnLCODOZzxEKJ
MEGKegvFIjuaEaTOGut8rBGK2VK+MJVmDBfMNober3rFBECXp0l5QjFfmvn+00SjQej4vqvp
kEZfTHsP/wsR/VGTNuFOnxENubwIMbCo3pURCx/XNm03Xzc5XR5Ud2y6shZ1z1lV+0VtcRw9
ud9rfeZPLRt7WHdePNlbSC2uzk9oO5+cFW96y9D1vjpSOlJxrtM2Yc8e3sLd15xtOuccjVp4
xm+Y7L6swqbJwunA08A/ew3mq7fvSQlnt8hz9sXZpgc92n1kvcueUCpN2YxS3TS8w1pvyO1z
DiUuisitNnQM2/yycbQMd8HgRme4b9vWvE7np6yykINTjVkCaUirXm+FioUxiCyJ4zu2r9RS
co2YiXlTn0BWbrgui4gc/ZtL7DxZOuHORMfBvPLpQ32bbjXqi9e4Xjo1plxnAttIBT1taLp2
wffvm/QAlO2HsloF+xGCbA+U7crTiLkmGuWLq0xX5VIOBxfNXN4n/s/XT/4HHMcralg+otq1
fXyX3tJnxxGz2+ma42vi6NVVqpfdiTu2FPc4Dxm/GIvcaXO0xv9i/Ojbb3pdXKKbHFj8aTOB
R09v831izne07W7VGqKk9mkthh6/6+0170HNaJTxOD67tXn+RWtHc9sO7j6tz8zVOXUvWdRX
xj23dMbDWlK96UpTct3Jh4kpaqsmTj8P6z49fA6+RWkqWwz/QX2Zx0O573H8mcWQfU+W0Fiy
HJ7HUsOxD8ZYhpixtElGDDFicKlTZk5RmqKkm0qMylBajSVluQ5xbHVoIXshjnJE55SQ+wwq
p+V1/7v39vzz25/n93t+n+/7+/1m6Ci6PVRBXnyV2I/ibXp9o6fBZzyIWO9JLuGh1krPpz2a
EErdW/bPusvr9QcTBvPjnsXmAPdDrf/Vti6l31Y63zRUKbTLdOCBMnow3wHdsNEYF+GmLLa9
VDiX3f6QbO3YokzJi+ySNk9Oj8nmtuXAVPgVjg1uLMUGoSKZ7tVA7yWpBx02p/Mrh/8vsADC
HICxgPvg7E0hCA5gF5sgMw8SWQA8GiODpHhBMqAUvyEkI+wTEB0C+1wG/B1JUJzfKSgj6BlE
DadHUD/sTPhbO/vWMfmB8xfHxILqi8dQXD5Chf0+7DT4bt8DbwtTQ+1LmojxaSK0QJPc/XJe
HSKguEnGvLlSzZTh7vD1WLepNvbQ3LW5OqSJqkb9EKeb/GIvkkG43GXkKy+7QQf3au9NHtuc
UGxGiiDXQKLm4TMtLU0eZ5Wucjs6nbWsi+uaUk8+JU6Gd4yetOoVuDeRR1l/xXBbS2KAHYdI
dpZQKHXpTM8ENxJiqLz22z0ll0Wz3Muif1Qwv8RLZl8/eN3NXZUkVWyc2CdmTqXb15tUOKef
uZOnMi2AJW3TSW3Wndx/OvNKfpdw5O5HJrZpF0t31G9WUjlvLH6GjFK0PpVW1vzcEs3AK6e+
MRsuKnRKCNMV344IMIuNmLM6Jegi+wrhOCcH9BOeuA8KDCZqIhGo8yzEWvh/aHzNv6K+D8RI
YlYspZ9yCDgSQAAL8aaKOFoeLauz+ZZSSYvx+O1zfj+9GWo0qBUzWQuu+rhAFokWXS0MeAEx
cKqKB2yXBRQIR1BiIYZBIObRAiAKLr4GMwffp6dt981mVTnFxV1ldw6vqvPhKVbwbvkjOQ6h
Zn7Tt7TP/uB2bjZ3EJeCo66x67tlqHuv9BGmcUy3ql/xwJ6uDUKWr9e0P6gOP8iUs/en/kyt
LTihn9KVtt5ZonTkQUBqbOxAp+a8xv6MI2hv8gmOsrkV6874xWS2Mtsl3r+Y+G6rEc1clXwl
xq2P+hy06KIS7WdmapXtdg3nWDqMhwHZhXYV5VJF3oMzD3N1mR2qpFxKpXZqZF7uTqV5cgrr
DtMlj3NjR0LBSm4Tppowllc0Csl5Weqiq+ajnboPa+NnA0fGNZI3Va77bQT606hza198QjlY
SEtynmFLVSkdIfuBLAEJGGZvFmEmHCAohQf4j8nynyXAT3G+F2jw6WcEmhqZgqCpqQmOTz9j
GH6mcLrDb4JMzn/7IEbfMiPUN172H8OoS5kVZvkK2q/1LEVcrffEGXCbin9ji9WYMx6nF/fn
uFj7bW11cD8dr/OK2KxIGKfUCFlJq72lTI77t/c3nrwD9r73bdA2un+APDJxTPL2lF7lqiHU
GZEklanrZuyyOREVi2itQh+9Rp1cuTSW3NO48zaeqMNZNZHlqqMmf02ZHidRfn77BCxR6/XB
FG+0w/T6NU325VXIEXat0sS2NdHPrIrvC930KlYgXmf2F+/GVHuhA5SUpgYJRxdKE/tknHPy
SIEtpn5ebDTEJzDqF5oPD3/PyBzsVhp9iNfSjX+f0bUmWONXw/smz4ZnNhCTyizua/o/enEO
FZBcEGJT//YpaviewGIYxULYwH/EYuGqVCT4dr6YSHwVhZ+YEtZwd4PaBM+wPafk6r6tWjfL
kj11QGYBfxyLZnJA5rnEr3KHw7jwv+DllwGGM3+rqmg8aAta51jm/JhktpTSBUbtNAj/8J6F
zCsyjMbvNYyMolNjAhnRhnxz4VsLbCkG8MBnVr6ARFPsnAx5drR7okdUNuEdt6h1jmveUD70
/C/UjFcXN7Mg58y6s6gxFkFZvUK26XmwzYp6+WNISivejteitOX6lBHaUnpIhSvITT2/14ES
q3Qy4xhtogc35XToj0ib0q5iSmI1qtagZG23MEu8Hv8swWlLGebQcZudEXXdb0//IVKpLsw2
NC9+yW3dlRyCHSgaVPipjIC4qFfr23Tz0E7/uXb9WnoZ9qbYvMWklANjcgUmU6GHXp2EUJBW
0ZO/5v1HkDHn92DSaxfW5VGJbsS7vm37dhC2NOlHNu8mdWLKItii77evtptO35N7Wfjcfazk
Vbfd2sfoWpUh7/Kss7FjDVm3kyGWgAGMRV0knOEyi78b8P0N3qIYocVrRcK3msOcAWU/+sy1
CEgQBV81PI/vSZdufwUKEsUIL01BItDw7j+1RCBxcPmoHKzajwvRkDRaMmAg74DppZh+4TW0
4n0+K3Eg8+Cy+aJQAviPHFKiK0AGaEA4EAREA2oACS7j4NIToMN9AUAEXLeD6zsBKlxzhGsR
AAOuecPzouAVtIUeNcAYMABAAORoJWos6T4uLu4z3TPiI+nBUQGRIfGfR5BoFgLYXZla0+Dx
bHPYtEx/mHIVU+y5U82FVJV3HINwP4R12xZ5N33JbK2ku9zcCwGBp+IdficRCRV3HN3L3/5w
tPVo2JivL+/PzYoaPdW8aYIHAGbGeetxOznDffb0N9P772L1RVsEY45fy9exvdI60xkYFSxo
WXhUTD3rVFobnaIs4dGYrKkX/HQg20WSzE5LCdzzZNu+U1XYxA4Sbk+UR00WfUzW0/UEqSFL
PVOzql3P7bHQysKXCr14UXt352bxevEL7zse30ya3Zt2eKP66lwLeyhtNW9i3G4uRttj9MUa
q8GVqztfzt0SghJdcNP9Cgov/eoEBcaHirIPHlDSuMdK0J7M4LCQriAL6fTpEjEQC2kGd5ku
iL4IZiCkuoBMWMDy3kFRNL7Q1MhRMdEMNVIQI44eFQatBOUWFSz+YYK+GjEi0ADSB3UXB7Cf
VtLCYbEyAsIj+Wr1CoqKpQUGLZAOMgGNFmfrkdzVXIm2dkRXItlPzRaPd/AgO9jr860CJuvf
v4GUFEoI30zfnu5eXjuHH5BVyPpM8n6gwnJti3xsCCJgaX8cEYAk+OECBEI4IwhabwJnR59L
e+x68xHLG9SRdVYFGrgIWslX9MTOnPk3+1UCHVWVRN/r6ludhCSMpAOd7hCaACGE0IQlmGEg
AcImNAhMRB02wxYCyKozssmOYQkICAiy77sCgggIssgi+6oEEUQYwmqAAGEzU/8nxBznOHPm
zDlzzsyZev3uq1e/fr169er/X11uj2MFVepSv93kmSOuF7eGNlhzeFWFswsGBx1c7rk6p/Pr
gyNDurWJ6pe9bnH9XRNe7Hbl5cwaHbLiD3X27F0wZdOqA3ERfWrMq+U4OF6HuE4lt/EZMyDl
9vCEhrObLy/95Pa784ZlRsy1rczZ67p5xa/Hq9N3ND18ZOiuLY3qe9I3Nu/bbEuDpLIDB8Vm
druO0ovd3a/WXdxm9entTXav9ra/fetK5sOTD0ae87106dL5tUsH3kC9baeqtEupWN2/7rWw
tNb9q9XcH9DoWNrltNG5kw6tDqizqO+QB739lhz3jZ6fUm1Qeu6UPlnLej6ttaell/of3Txk
f2pkYhlvpdgOs64db3t2xqL0/Rj5s7xKtHR/lUcWFWLJtGQpbbljyVFkeSSvG00+5CPoR/6C
xaiYInKRS/hSFC5YnmoINqKmIh9MQ4QfSkOVhYbRMOGH0wTh0ylb+Pv0VPhcq1JktRplvNXH
6isYYBWbVrs1WNBrba60NcWaqjSiuKfS3I/Hio+Gl34qXi1UOrlfckflIzPdrG4rt3LKFZsS
P8V7kpHNOZs7MyRW4X1S+/fuqaqaGJfaK/UtFf9ml86pqn7X1F7JqomJLXqmpiSr1v1kUO3z
46LyVzYsGUgmWk2EGS+WtYyZrKGKqUjVUC8nPyTZ5vp8ad6rRW6RLvswZrhQSOqviLtzSZpq
WOZS7ObSha6uVUlUmipQZapG92g8TaYZ9BHNo0W0jDbQZ7SVdtBu2kcH6SidpG/oHF2gH+kq
3ZB2DxUQBS9aIAmvoS3eQGd0Q0/0wVt4B4OxEEuxEmuxHp9is2h+gZ34CgdwmE7KeBpncR4/
4Aqu4Rbu4D4e4RlrBvtyALwcTKXZxT24Btfi9tyRu4rHSZIN5akSVaFYGkuTaBrNpDm0gJbQ
OtpIn9MXtJO+ogN0mI7TaTpL5+kHukLXxNc7iEQ0mqA5WqE1/oT26Iiu6I5e6Ic/YyDmYzGW
YzU+EV83YQu2Ygd2Yx8O4iiO4yS+wTlcwI+4ihv4CffwEE+Qy8Q2LsIvcBCX4BCJbXWuyW35
De78qwiHUxTFUHXKpgk0hT6k2TSfFtNy+pQ20zaSeof20yE6RqfoW/qOLtJlyqSb0rIlwhXR
DC3xCl5HOySjC1LxJvribQzAECzCMqzCx9iAjfhcNLdjF/biaxyhUzKeQQa+xyX8FddxG3fx
AI/xM1uY2Y8DJcLFKZxDuSe/yLW5A3filP/OCOtwNZHcFEnR5KGqVING0CgaQ2k0jibS+/QB
TadZNJcW0lJaSatpLX1C62kTbaHttIv20td0hE7QGcqg70n+PNB1abcpi+7SA8qhx/TU3Fdt
JKAuEtEAjfASmuJl/BGvog06oBNS0AO90R9/wSAMxXCMxGi8h7EYj3RMwmRMxTTMwEx8hDmY
hwVYghVYg3VyZp9JHLbhS+zBfhzCMZzAKXyL77g/LiMTN5GFbOTgKSu2sg/78++4GNvZwU4O
y3uSuQyX4/JcgStyJa7MVbgax/Lv+Q+cwHU5kdtxMneRKE00T7Vi/rkOp5E0mt6T802XE55a
6IxX0CpaQx//07O+RT/RHXnTPqRH9MSMTy3Eow7qoT4aovE/yIJ3MQwjMApjkIZxmICJeB9T
8AGm40PMwmzM/bfypGhBppTMj084l+UIjuQojmYPx3BVyaA4yaF4rsP1/vczCRf/n0n/wUyy
Kl8zk7S2SOXgVH3UerVN7VXHVIa6rG6rHJEWV2EqQkWrqipOKo36qolqIZUMyVv/et7Ipei+
VDAj6KHgKHokmEZPBCfyO8qCBB4oWJcHCyZymmBtsypwiN2yKkr++tRQteiBaSHHtPDYtPDU
tDDAtDDItDDEtDDWtCD1Br9raJjc0AJuWAE3vIAbUcCNLOBGFXCj8zk/qRQu4pl8cbR8cyBf
HV/2kwjZ8iKkapojq0Bll0i5jZhI1Wex3KFGgnepseA9ekkwm5oI3pfaz2J5YDyrlod59ZJZ
o/mbVZhSsGSRS2q6blLVKR5nk+p7miyaYbUJypnazDGP7HZTVq6xk4NaxbvjOMGeVDSgVUKJ
wDD7iJg9iRlsKnu9Dq9jWqi3svNxbLpXKNbJ3lfunZn5hB+bdsDPjdqe0y+L5Bp7fmYuxxIE
W0ODDfbXmnNtthc4UIStWLdkiQ/btDkIWfKYNm2O5zJnyQpAvn3BctxFtqVZd9J2l+wt+7GY
kVzV+evr+NC4QKfH4XEEM3u80rQnyBHksMcGanuIIQjwemI9sYHOMB2mjXlGdka21v20S5fR
uTokeIbOo5CtBoTof43khqpCIcaNFU1JFfnZQ7S9uBZRiLGkOBdktvjQ+NCwULfXnRBXzmyV
tTPhkbbHerxa/DQ8Nfw0tyEtZmriTplojw7UMVONJvNC5AkuYTTtaayDMtxxCTrJowPcrSLD
Eve8reMStS6hXRGCQaZ2hDdY9jwpV7u8rlwRFQ2MizMvxLg9yY21Duqk3W6tk9xiwhMW022P
O6ZmTf+SyUXFhWhRcyw1lP39tfjq2LfzxCytt28PqrxB6wBHsNbOyuWcTp2gd/9mqCJ+YUvq
SuZo0e4yuqjWbh2une5CqhERhXRNRVPPmOVf8ZFuN+50WX0LKP+W55zruY0K0osUyZ8Uyxui
zV7+tV+7WdEl9PfeB//mvgqRU0dFOf/Gfp2HR1GkYQB/e7p7opLhDBIChJ6BDmSIJBBFwAiB
QEQN1wIryH0qt9yKHJEFQW5BQE7DISAipwrLrXLIfUtghhyc4Q6ICsyQ8p3KsQkLu/vsP7sP
T6qf+s1XPTXTNV/XVM0oFWSUeT2fMiqaq2YVzntZHy02xRbmq4bhVEJDnYrNFhbmdHK0HLLN
Jrs4nc4K4RVkX193xZb1Uo0jNwJ8H91XKv0nY/4viu3fd3l8CTfjHn8UC8x7VA+vHm6Ly3Mo
2UdAXEDcP94yZrbvMOOqm7a4gJwj87nO43waSkzBmII7d0QoEXH+gba4AopTTojcJSjrcMrE
Zt+0x9U8N/IxN/XJJft2573lmTead/rRGsqSPUt9MyC7Zp/LXX2zI3f1zRKbLDLOHp7zkcIp
FO4767NCeK4vkKI/ZuzZo/Vds2KYr/jOlHcottwH38MGRe1h2QKdW9QcPZLblpn5qCagm6Wo
olssz6h+um5RNWDo2Hi5mXFnZGnYt09f7oyG8Oo9M2KVSD+7sjkaihDCt/vxeculWAvUZUBd
XY9j22jevXfXAUbdLoYswteztsho3rBR3YgIFR/73lSFmvmhVJULiYJA/XqBHbj3jOA1nxUZ
/AXzHH1OWgAFqD/8xUPYpAVRkBaSFkYh4UURaVEUpsVQRHi4nxelxVGMPo8AWkIaiOK0JAJp
EH2AUihJSyOIlpEGo7S4j7IoQw2pHcHUgbK0HHNxj79y7NSEg4agHK1A/0BFlKehCKFOVKCV
UJGGIVT8jhfgpJVRiYZLIxAmfkMVvECrojKNRDh9ERHiLl5CFVoNVenL0uqIpDXwEq2JauJX
vCKNwsv0VVSntaS1UVPcQTReoXWkdRFFY/CquM3ffLVofd6Z24hFNH0NdUQ6GkhfRwx9A/Xo
m6hP46QNEStuoRFeo43xuriJJvQWmuINxn/Bm7SZtDka0hZoRP+KxuIG3pK2RBPaCk3p22hG
W9PraIPmtC1a0HbS9nhLXEMHtKQd0Yp2knbG27QL2oir6Iq2tJv0HbSj76I97U6voAc60p7o
RHuhM+1N09AHXWhfdKPv4R1xGf1oGvrjXcYD0J0OlA5CT3EJg9GL8RD0Zvy+9AP0oUPxHv0Q
/cRFDJMOR386AgPoSAyk8RgkLuAjDKajMIT+TToa79MxGCrO8yvxIR0rHYdh9BMMF+cwHiPo
BIykExFPJ+EjkYrJ0ikYRadiNP0UY0QKpkmn42ORjM8wlvEMjKMz8QnPzMJ4+jkm0NnSOZgk
kjAXkxnPwxTG86ULMJV+gU9pAqaJs1iI6XQRPqOLMYMukX6JWcKNpficLsNsulz6FebQFZgr
XPga8+lK6TdYIM5gFb6gq6VrsFCcxlosYrwOixmvl36LJfQ7LKXfYxndQBOxEcvp3/EV3STd
jK/FKf7DWUm34hu6Tbodq+gOrKE/YK34BT9Kf8I6uhPr6S56kv+NvqN78D39GRvoXuk+bBQn
sB+b6AFspgelh7BFHMdhbKVHsI0exXZxDMewg/Fx/MD4hPQkfqS8Gj2FXTSRHsVp7KZnsIe6
8DN1Y684grPYR5OwnyZLU3CApuKQOIxzOEzPSy/gCL2Io/QSjolDuIzjNA0n6BWcpFfpQVzD
L/Q6EukNnKY3pbdwRhxAOlz0Ntz0Ds6K/fgVSYzvIpnxb9LfkUr/wDl6D+fFPtyXPsAF6sFF
6sUl+hCXxV5kII0KXKH5a3r+mp6/pj99a/q8/DU9f01/6tf0sKdwTb+Vv6bnr+n5v9P/D9f0
U//DNR1Qs2ppKBQFotli5B8LrUB5QCnNhh+fHaGMVKYo05SFyhrFrQhLK8sey17LWVVRVfVZ
tZw6Qh2vTlQXqoc0f62x1kZrr03XZmnztcXaem2zdlq7ov+kX9XvWv2tpaxlrTWtLaw3rBnB
Y4LvG4WM4kaw4TBCjMpGhBFp1DSijFpGPaOvMdJYYiwzVtp1ezH783aHPcRe2d7c3s4+w77c
YXFYHYUcRR3FHUGOso5QRyVHA0dHR9dylnKFy9lNmBbT3yxsBpiBZmmzvBlmvmhGmb3MeHO0
Oc6caE43F5orzXXmJnOLudPcbx42T5uXQqJCokPqhnQI6RzSLaRnmp4WmFYz3ZJexWPxGJ5q
nihPLU8dTz3PWs9lj/B2elj74Z0Mr/AKwbQZSJDZSVBWKweVB8zObmYnUUVOdkYzO5PVxZqi
FdSaau20qdpMbY62SFulbdQStTR9jX5ET8/Kjt0abe1gTQ+OD04w/I1iRgnDYHaczE5Vo0ZW
dnowO4uZnRV5stPM3to+NSc7RZidko7grOx0cHSR2TGekJ0mOdmZaiaYK3Kys4/ZSWR2auZk
p2tIjzRFZkdJ1zyKp4zH6anO7ER7YjyxnuMer7fdw1rMTrwvO1wvoc4QAZZ9lq1quHBbDgAZ
hTizpilDlJ5Kf28C2919cy+jUoYzIzSjIsNhXL25rnO/iON+Ce8R735viveY9zCyyvm2wDl3
ZpwyhnVGauuU0Sn3U5enDGFrA+tU1vEpw1MHJfdI/iBl0/mwlMnJy5NnJs1MWpQ0AUha6ntt
comkfknt2YpIik6KTCrvjnXXd0e5a7iruSPdEe5Qt8Ndyh3gVlw3Xddcaa6LrnO+V7l2u7a7
trl4Fdcu15eu1a76rrquOq7yLofL7goO2hH0ICi18DZAZ/Wb7zfPb67fHL/ZmaO1XrHW0ifp
UDv7vmdKEPIUy77Mmqd9wvIgu602yNtfjc4Vt+EM26gdA7TrvPY8PUFfxcc1ufvrK1m/zaxP
KvoCX9UTslrzntzzn145UB+cE/f/lz1b5h2ZvtI6yroiTxeVe9lojPmT/fJsi+paw/B621JR
EcXeEARBsZdEo8aOHbF3Y4xJbCFRY4kFgw1Exa6o2CIq9hJBxQaKvWKJHcSu2MGuTN7Ecz6c
8xuYfa35smfWnr2vZ577fqmXEvKeUjhcWbtE2RWlVhmmj26CsvS5duN0ZWeo0uO6duZSpVq6
NmWG0nCD0uKwMq2POslMNZLj6iNHlB2nlRknlRX31UySlBNnlXg/auvOUiqcUz70035OU8YP
UE8ZqE4ySI1kufrIYLWRIeofw9Q+hqtvPFDbGKWuMVq9Yozyb4U6RZAaRbA2+2OzC+bDAkAg
YBBt4Y8QAQthESzWFs4EC9kgu3FAJCyBpbBMe2MF5AAnyAm54A9YqZ3+BqJgFayGNRANa2Ed
rIcNsBE2ab9sga2wDf7Urr8IYTAVtkMMxMIO2Am5wRl2QRzkARfIC/mUTqngCvlhN+yBAlAQ
psFe2Af7IR4S4AAUgsJK+S1QBIrCQUiEYtr1JaAkHILDSpD3yrPb4AalwB084AgchWNwHE7A
Se2301AaPMELysAZOAtJcA7OwwUTB97gA2WhnNLvLlxUrqYoSa8qQZOVrjfgGTyHF8qOl5AO
GfAa3sBbeAfvwRc+wEf4BJlQXrliEBCRkFHQYjbMjjnQCSpgTsyFudEZ86AL5sV86Ir5oSIW
wIJQCSpjISyMRbAoFsPiWAJLohuWwmnojh5QBapiaaiGnuiFZdAbfbAslkNfDMUp4iJ5cTqG
4wycibNwNs7BuTgP5+uxACNwIS7CxRiJS3ApLsNnFEwTaBKF0BSaTjNoDs2jhbREibeK1tJ6
2kibaSvF0C7aSwl0iI7RKXxOSXSRrtANSqW79JCe0DN6gS/wJaZjBr7C1/gG30pNqSVf4Tt8
jx/wI37CTHQoN4BQ2cH4mER8pLzUljrytdTXzzaUxuInzaSF+Es76STdyE16SR/5QQZIoAyR
4eQtoyRIfpfxMlEmS6iEyTQJl5kyW+bKfImQRRJJvv/8wyVKomWDsme7xEqc7Jb9SukjckLO
SBJVkPNySa5JitymKnJf0uSZpMsb+SAOSzabzWnz2LzW1RaiNFvEllBulVJyeVhPW8b62HK2
vK1oK1MNW9VWtzWV+F8r1RraxpTdNrF+tqltZpvbFralbWVbW3/bxgbYtradbW87qBt0sp1t
F9vVdtMz3f/7bMiJclKuz8/G9lBC9rX9bH+O4lW8mtdwNK/ldbyeN/BGpepm3sJbeZvax3aO
4VjeoZzdxXHqInt4L+/j/RzPCXyAD3IiH+LDfISP8jE+zif4JJ/i03yGz3ISn+PzfIEv8l98
SSl9ha/yNb7ONziZU/gmp/Itvs13+C7f4/v8gB/yI07jx/yEn/Izfs4v+CWncwa/gttwh1/z
G37L7/g9f1Cj3oZhUF0NOtYchLtq1dvVecerCYeQP7WhdhRAbakjdaLO1IXaUwfzCu5jPAep
SS9UTzygbj8b6pkZ0ACGwyxl6RwYYXbCGHgCT3kwD+FgHkpdqRt1Vyr05Ik8jEfwJB7Ok/k3
DuFQnsJhPJWn8Uiey9M5nGeokcz610kWc6R621K1twheyGN5GS/nFWoqK+2vdpgdoWaTjCl4
E1PxFt7GO3gX7+F9TWddTWN76SAdyY1KkTt5aCa/k77yvea0jQRIW03pN9JbvtXktpRW0lqz
liiH5LDm7aScktOa3aFKkGGa4p/lFxlM3uRDZamcpnm0jJGxmuQpmucQzfNUzfc48qXymupZ
VIEqUiWqTFWoKlWj6prSDHklrzWxj+WJPNWcumhS8/1zTc1pSTtAszrQDqI0eqTrseaygSaz
kSb9pqTKLU1vWc2wt2bYV/xsZVtFM+2lea6gKa5t69i6VIO+oHTKUH5b81mc9QWob/h/oNOT
xGKzZc/hlDNXbuc8LnnzueYvULBQ4SJFixUvUdKtlLtHaU+vMt4+Zcv5lq9QsVLlKlWrVa/x
xZc1a31Vu07dr+vVb9CwUeMmfk2bNW/RslVr/zYBbdu179CxU+cuXbt179Gz1ze9vzV9vuv7
/Q8/9us/YOCgnwJ//mXwkKG/Dhs+YuRvo0aPGRs07vfg8RMmTpocEjolbOq06eEzZs6aPWfu
vPkLIhYuWhy5ZOmy5Sv+WBm1avWa6LXr1tOGjZs2b9m67c/tMbE7du6K271n77798QkHDiYe
Onzk6LHjJ06eOn3mrEk6d/7Cxb8uXb5y9dr1G8kpWZNC1qSQNSlkTQpZk0LWpJA1KWRNClmT
QtakkDUp/O+kIOHGTVr9u4rTXFPMGEeqrju6HmS2cHyUgaZ05gDHTXJV0nt+Xv95eSnbPJUh
881+09OcQDJNoKLpYlhbuYiWYC3TElxMISPgZHxMadPSBJgCpoU2a25t7SrmEfiZYPAybUyk
8TD+pqBpoARbDk0dD5VA56G/Wa/fjob6xtu0gmaOFNPWBDh26DWMqa3EXATOxk3POEFpR7Lu
MNSEmDjtbIfpZiJkue4SYNqZQMcO08MkQTfo7ihumisJg0yEkm6vuQOhEM/i6G1qKGGHKM9c
wYfGO6JNTbmcI8aR6DirnA7Uz8aZx+jLfo6npr55wODop2R3NdX0CFRKx5rrUBhqUCPjbKrr
tXoqSzeTj/7GZsrgSKXKaNhMzo4ovZsvleTjzE0YCfHoLpfluWOUyaf3V11/aZh6QYI5aNJ0
Nz/oQD9l1nP4q2FlN76miV5pohrEJn1yB/RIVEK6Q3PdOQGSIZUC6Z7uvEb/V6/NW2VYfwjC
ejheqn4KdsSYMnqH9XWP5qazusAGpV596K7fjcQR+Dfj1R4U1XXGv3POvbvLQ1lEBHYB7+YK
PnYpvkVEWdhdghIMKNpdAuPyStG0M2biOFVbtRobc8UpjYlNazsx9dGHnfGi1lliVUbaJk1R
k9pknOik2mAnrTJxOmqnCnv7uxck0j863cNcvnO+8/jOOd/5fr9vK98mTovr0jTpC6PI6CUb
FaLvDrCQ0+AZV4B7t2BNNfuYbxUn5e8aW2BvIRjGNthzhLrxqmXgfjIwWmFz2ALsbAvQ+SYw
TOVh0SyOyx3GJmMveeArjeAv7WAlO2kX2MZl4PNtGgB2K0DABayU1bC9yEF+yy8jZjSI/ZIf
r/kYItygnCpfiH8Yv4FTN+eZSdUojWA/m3HWMZRe+gQ8xQ3sL2SL2TLMtIY9j1jSyd5gh8BB
TgP/P2B/B4L/GzjbAZQ8w3/HL/MPRI6YIYLiLdEneRAbH9mbhnLi5+NfGEmG15hjdBo/Nq4Z
A9YtZMPjSykA73oBHOllMLI3wOZ+hrh3kYa5gln6wege0CPwozTwEjeYhwpW4cPuvsrCyBc0
xLnD7PfsJutng+AKyRypDvB8Pl/GG/gOfsdCCVWUiW+KH4g/iYfSJnk2yjH518iu+u15jr7B
A0OfxpFxxPfHDxjz4Is2eF4a3txcKofPLcMtt4LrvQiuZ7K8zSg74YfHUU7QGXDKPpz9ZbCa
65a9ZjH54j2L13Hcp8wcKMO2z8TNBOAtUdaGux0uW9gO9irY4JvsALjf2zjfYQb1F6DEfeyJ
eAEv409jRzX8Od6Isoa38O/wPfwUyiX+Mb+GyPtQOEUqIu1UERJfE7uFJnRxSvxZfCTlS2VS
pfQCEO1D7LxSXoqo24KI+bZ8SL4gvy/3A7/32X5qi9k+tyfa59tr7HX2V+2/sJ+xX7cbjqnw
p2pYP/0JJr6PPScV8k6wsxj2fY5vEH/kr7NjY/i8BgtaaQ2PibP8J9/qFH8Vv+I7kIkELfVi
RLE+YFeffEVKlz+nd7kLjJvY66KJnwPTymTzxSLgUx+izibYeQgIY+fH0eM2bmMNrWJZ9E9p
NRj+e3RZ1nCmFfxTdgxYtAyefJUO8zPAxYPUxhbAulbg6kP6PusWCjsNv9sGjn8HbHj0JxUO
lfNSWybfaCvGDXWzWuNdPt24jVd/k+2ia+IhfH81W84K6Sh9hlv/iM1lk6W45EbG0M9y6YCV
P5zEG3xfmoIXdJ+6xVyql27gzguH/hAPyhvETvaAl+E6M6zI/awZjRGD30SsMuPoeDoOT0AU
sV70bbrInsIpXrF9Qj+i79E7Ip3yxBG+HVzwPUmh1+iGeAarfhvxKRu84efIS9ZiH4rxt/hh
zLCOiqiINbN6CkJTSbnGN2D5UcQiv9Fg/FCOyF66xJ5h6XQe0SsTp7hfTogPoOcpvMNrVMn2
0Ml4K/UAVzLB7GfDmwbkjUDXX4IbnpMv2mYh23kZFvRhz/eAGgprwVn8A3mKg5Xj9fjwfspg
RSUw7Os8Is5SALntesTAaYjb5TiDetzkS5hlB3XgPR0Bhlyiu8hUGugcXcXLycA7b8H6DsxT
Ratw6y/RUUTHnch1yjA2l2bgnB4ixyniG7CeGWf3I872wKbryBDvIp8y7fKxRSyI22uhf5lv
GSvMpxrWBUw+TQuBlEHRR7doCtC1HG/0MMZF4RvjKYcWyp8xTr74cqOIrxVn2SSg4Xh4VR2Q
fTF7EVakYB9DlM6epXnxpzHbMcSyGvmIv6zOX7pkccmi4oVFC+bNnTN71szCrxT4vDOmT5ua
nzdFfcqjTM7NyXa7sjIzJqVPTJuQ6kwZPy45KTHBYbfJkuCMfCG1Iqro+VFdylcrKwvMutqE
hqYnGqK6gqaKsX10JWp1U8b29KPn8//V0z/c0z/akzmVEiop8CkhVdEvBlUlxuprw5D3BtWI
og9YcrUld1ryOMgeDwYoocz2oKKzqBLSKza2a6FoENN1JSUG1EBbYoGPuhKTICZB0jPU9V0s
YwmzBJ4RKu7i5BgHo3SXGgzpWWrQtEAXeaGmVr2mNhwKuj2eSIFPZ4EWtVkntVxP8VpdKGAt
o9sCut1aRllr7ob2KF2+Hq0j5qTmqDe5VW1tagjroilirpHqxbpBPWNzf+aXVUw+IRB+5Umt
W2ihzLWKWdW0VxT9YG34Sa3H/EYimANjeV5FVKvA0h04xKqVClbjuyJhne3Ckoq5E3NXw/tr
U0NmS3Sdoieo5Wq7ti6Kq3FpOq3Y5Dnhcvm7jRvkCilaXVj16KVuNdIUzO6aSNqKTSez/ErW
WE2Br8uZOnywXeNTRoTkcU8KbaM6S7K6m1LVitGTZaZF6lI4hK60KLAkrGJPReanrYi0liJ0
wy/CMEpvxY2s1RMCUc1ZbLab43U5z6kq2n2CB6gDd8a2NI202PKc98kUTT8ZdTXoH8u616vP
mGG6iD2AO4WNS6z6vALfxhh/S13vVPAPx0c1ONumSHEhjt/jMS94T8xPzajo22vDw3WFmt0n
yF/ojeg8amp6HmvSV5ma7Y81o8OjKjz5FOgJUbruyB/9S3FOSgu1F+ts0v9Qtw3rq1aqVbX1
YSWkRUfOtqpuTG1YXzSqG5H0tEBYuPmIxN3C0sIpG0Y7m5Vwsi7l4c9mOXVrzO6AV1otTKnQ
ndHK4W8k0eP5PwfFjLvmKOvfl8NGzNSLvWPri8bUx5iXrAkYLOXzqrp6TUsco6tABNK0ClWp
0KJaU8zY3qwqTlXrBl2Zqq0PRR/faMx4Z49br+iIYBPtrBjeyqm8S2W7a7v8bPfK+nC3k0jZ
XRc+wRkPRMsjXVOgC3crRH6rlY+2mjXFrCFxgqef4A5L5e72E223tJLVYNVbYoysNsfjNkYt
MT7c5rTa8CvAzQtwV07jiBkGZM6ygdLZstlup/JTnPXa7DHh8KeRLPUKSrRLvYyyHDa5l4vf
sDJKAJiupkyv80HJUMly572S6qESKoXsHMRn1kxPqic1Dx+WLdGgInoG/TI9IkXqIax63LjF
zBzSCfa89SzXAVEuvo9y+WsncxIYxUSW35W6NCOpM/dgLs/NyHAlT1zqIn/W5Ll0gbGY0eOf
AJklp7gmu7jLl5I8OZknx1iaP+G8jdmycq5ezvTCpsbqgcb+xgkLvYUDXufAcmfoP4RXfXAT
xxW/3Tvd6etOd9adTtJJlmQRCRDyydbJn8I6sDAYx2CYYhuw7NAODCQNBobSljZpQgImE0yH
NBDCdAZIoEM6nXHBJigkAWpoIC3pmHZSOkzSwgzD5B+1w+CSliLRdwICSf/orXf33du987v3
3u+3TyuzN3JEprN4I1OTQG3Ztmx7FoUj0WgkpdUla+EAYxiaNGY6XGXo0HdnMFFN7Zs/b6A2
5atqHRhobR3oR+9teOvKuSWd/QPtT05c2Vi6NJAtrzwFX/ZrfIk8CV9mh8phQFewuULUsFnx
awSyUiwnCwRiaM7FYS6PNuseUWSQMDQo75ex7FWsQ0EKUR7vI/MX8LdznUXwK19YLzQ2IqGi
sdHoYH4shsLkI8O/fpOrWS32zGxb4EYv1K50L22Z2+HFl9CLHY0tPctT8f7Si+iF3kRTb39N
eLURj6n3rpOXTauhGgigQf03NpOtUjEplRQiLFiiCAspmggLLZgJC8PbFCvD290swztkjuEr
ZI4WnDJHii6Zw5LHzWIJvgRLPsVKin43S4qVbpYWAoqVFqyKkiEsIkFYWLc7I3OiLHNCRUVl
ZSBgMtEZhjGbbTa73eHgaY5lrVYLQVKUz+f3O51iRpJcLo/H68U6Qkhxu2WZsEqiKAi87vBo
Dj7AqzzJJzmaxEaGzABlEMCVJNwj8jZ2JMMhzhuyblMs25QRFQpuTOiOCo3wBAdfKbs7Bv6+
zl8vu7wwWQD/x9Lp8shDM2IATc2lyzO04kMhnXls/MbSkKk69hx/bqjabUyOb1wQxpzsDKeS
5Z4kQ9CTUrjcw84Q6Qw5Q8u6t7/V/PmXPS/3omj3y707Dqev3ene2l36fNlGFGkqXfGhI1vR
lC3oaGmh0beUPtta6kVHSr04jqYAmhfe20SeNq0nIkQ1kUJL9CoW2eJ+pMQ/FkwpSTP7CJ85
jqoVSxyJFkXSUDyeJy16VNJESdLiSNIor1WTamUUp2KBgD8YCln9LOu0OjjOa7bk8YVjVp9y
CmpiL6GivcAeTrR3jLlkZSPvw62fiKK9o34vFcqj3ceCwcD7sJMiHGj3GMexl+Q8njwe0wVR
i32Ib0ECUniSqL13ZhQ0tXl8S/ebzQyjqqkUQUQifr/PYrVCMojV1dGo1+vLoz6dV4JKQnlK
WadQSn3dP2+6Y4CQnFp4FI7/bbdjBejFScAVbwwQ3QJfyFyHAfgL/ioa1TS8RjW6cfMV8gih
Qm4c4qpj3IN41iSIHHIZ1S/NSOFUJBIVkpVYFiIGHOtTScklC2HQAs3QDC0BTJx1dSktEsV1
/5jdO/Fez9OHnp4udr+04ub+Cxd6fvmrqH+RXtPV0z6jbdbmnu6uuQNk6xudq4f3fcp/by0O
TEOta7fPMaO/v3H8B1vOe1TVniv97dvPx0Mukq5KdVT3L7o7Jq5oz6xtAzondt47z2wANiKh
vo8QtUQ76jp+ljhL4lj+3r9GvX7N/GBWYdY5EDiz16fVuIG1QPXFKMyw9QudA2GaoeWMwfxg
yW4sWUCgDW2HgToHCARCI5gUMYbyP08K78aj6XVJlMxjTXe0pGdUx1mAtTX9EwUpho7n0yYH
ZeoAmp+YfnU6np7Hn5zIXp5ouNqAG0Ae088kUCKP2t4NEiNnSETCQ2MMGtFxWTfBXGUwYzwT
ujwhXZWwBLJuOcNOsJj1zO/4AF0mQsRm+G3ojsUWAKkWN9wubvAWvW5IgZy76C3mvO6yboFx
PkAmwFF2O1fg04DodFmafAhjg3aJ2GMXyiEURqHHjgy5iqEhyjJkRLK2vq4eQg2hj6D/v4V+
4u7MbeT4XX3n2XO7fvrh+E4X5/EIVrdDdLGyTeBtHjs1fdfZj3a8evbULpFzex02Lys57R67
AHxsNz1zp8906OP9b//+3IHDn6RYef3R4c4ZLtYuqU++cqRDc9uKa84ffPvixQMHf6fZXc/u
OzQvKdttstb++s/naZLNOPkX37tGL4J8SRAzifmoSf/Rm/RuZU/2cOuh7Fj2XC0z1X7Eh49n
x7O/nUP+0LklixvolY5NDjKDMriJIlVVTUTbyal2Na5WkyrQgYrJ2LQauoamW0S/KIr+mmkx
mrI3+1vaRSoWpGGRarCI7S1+KtyGx1FiHIpSoeFIGLXl8d1jss2ax0XdItgSA8QgMHaeDOmi
HQ+gQYTRDPu4gw1AlE97IyfxvwkN8s/Ixoy2UMNaHp3WbWpzpnlhMxloRs15fEdn+eCBIA4e
c8wOzMaz8/g/x73dHQb987cLuclcIQcDMEMxV5zMGdQPrF8wmkECQA0G9I2OHgoPeWCIO2fk
Ru7+ReRyKCRxmLkfYBlgD4GP0g/CXx/56qCmYUuZC56oKydBuMogCPI+T8CzsJfaiQ60db2w
cZUej81PT1ucm7t8wfDK5z77/qmrf77o9V4bGT78zon1V37W1FDasGZec7RRbQ2OdYXUZ/d1
RgYabpKxqDVzY2ffFM8K18FssrXvWx1/eHXPXxfN+nHTgU+H+9cfbD1/4/Cm6c30d6JLM+s6
k/MzNetKf6qKNMzpP7kqFPqSgPpxB/4jGi3XNJFRwkohqFwAf9Yh6gPUBAXkfWiBB8FZBk2C
I75WizQm1ohLWuZ2yvCa5+emZ/X01cWXG+9dXFqFX4P3VhBd+tQh7oQD11N78euWI/iwxYTG
CdI+zjpZux32JkQHE2BUhgSg79YtOo/4bufgHuPfQtSgBr1/REOoynScQxL4kKEFKE9cshQh
BJ7Ar62uyUYSPR1a7mbpKFpgeqY6O2vZ8Ejpo9JfSvmVbanaRegWyiIdFcA2D9i2tGzbYr2q
jhoybXfkHdQe/KblF/gdCwXWOcE6qJV5JvjAKmGhYZUI7Ge3swnnYiOtJh8cN2DkY9Y5U3UG
7AUeA+7/y3S1BjdxXeF77q6k1XtX75VlS1pblu01skHyQ7ZirWyMg4kb2gwJAZQah6TQpuOx
A6SmaZqGMCGQFKZTpgNpC51MTNpCTfAD8Uid0plOOiWBTDLTH6UNtG6T/tDwo4ZOpnjpuStP
i8a6d3d979Xd757vO99pC7DdydtX9iUrm4OH9Xf0p1P9hU2vnYEuaIABY3O6U7+k/0b3MuTG
6VPc93F368g/NactZO3tDnX38jEveEt0z5wsR2MDMPAu3UMKnERypIGTZklGNEixZiZ3zQKW
Evo8n4tEJ1OT5PJ3c/BpDnKWGzawMRGXnVLGVnDdQjOq4SVfIAGtqy2w5FptSHxX2+olorkm
yWT0cu5yAp/NNacyhxOQKEGvZu3Q8O54B3TMQy+JkRRtIg+RTwB9mCqLd8LlcZX94ScUFpkv
V8UFdYx9SX68WJZv/13MhcrjSMIFcbE8JjLri7CNQYr+jzZmSzvil17WVMYbC6bcZYVN1jOu
WZbp1kM7koplmXo4IxiAMicVCkk13yOZOltb8l3NucFuXzoUSaxTW3eHvV2Nar9T8EbjAcHZ
29zYvWIi1fyNiNwdyD7YvSK/UwpxN7pyL9Sm1hQyjTsfyAWVVX1dDWovB/zKRE6Rk2r3wObu
9kxbV/vm1Z3Jhnyf0syAxJW+5ZTY6TWQ/fw3+feJnTw+zRxqCXyaHaZslil+KsaOAHwz1pgJ
THhxjhPyNGYFKxskjpIpNK4cK+pkx1eeNGzrWHEIhWopt1AkLYvFJVSvheLKVm9cSktxf1yq
leINcHMv3NSje/Uo/Rxu6LGX9Tq4znbSqx+Fd/FkgqRDk76gYDEi+4pnrcPGr/NjsOC+0lE3
uAuh06+zcC4uLjGaLyLRjSKEhfKyct2HMZ7D0zt3WLCYclSr3Y9tG3h0z2n9aPOq449IVsEi
benp3bZv56G/sB2sglE6QXsw94Q1B/0TIWETyDz7sS+JC+I/SMsQcgbibXE6sXSeDsDoVTZr
073P4CRkEEFlhqw12zlW+9lj1lYrtcqOip+/iy6eMMbdn3qBrNk60t+/dStkjK6/f4StR+/d
pHnDJ7Vr1UjgfMW+EA6A2rkptqkp2sxf6mcYsKKMLY324P+2AF0Azet9L8I85uHdpgOsqhrE
qmoWq6oAUWFQk61V5qg5YW0MWkJV/pg/EWq0WgR4Tqguge2sx5TEbtrs9ARLnE1LEK2uPkM0
NYVNuh2b7gcyGllPTjCkVnjcSlShChvpOuQEp+b1Z5xyM/O+uDl1HOvevo1aUNHqkhmFLaKw
RRS2yKgCY8y5PI4DjYuhct/G8ySIlhsHB5HM0zje6HEK62dx1nBwedayivVNaCPQFItH49Ts
dokuaq6rTdRSs91hc1gdgoM3+wO+ADXLoXCoKsSZKSA9gDM3qY0qNddIygipt2AT8QZHoMGE
TdxVPQK1juQICQXwSgW8MhwWa5qWP99DGRgDn8VFDZ4n8Ug72iusNonsnoUhqn4wUHFW3GxW
efYHj4789IHmuNqTvrZz9wetffoV3lYvd6pyIuxzd6ZWyU1mOvmHM88c+PK24uqxo2/++fzR
N3+2/+J12NZ9cGUsVPvO0i39xshAa6xzF4uVV9AoPYmnGiR7LxEXnIY2IsBbc8pXLaMWCgWn
8cQCX5BaEoC3sND5N/HjkwClmsstEJNgceDDKDBvjInM5VrvHnVPuTkRaSaHXL+mhAj0dyRE
g/CpkVexIl0sFnNDqIisCs17srfLd+E2ek8VA09iRiHtj7ehW2hvkzL1DINkgr4RWDMUXWqv
e2ww7FkZS6/1wL9M2//zy+/0NycSDWtepPNPtMRjdQsGB/GNfoxvFCGfa3X76a/oKY5LOo5w
1Ga32YGYqjwnAjMBGohQ3JPNLmDVNTznaQmeCdJgCZSz4BFYuNidWBhwdTMuEziQkItaFTGJ
Jmq67vnYHYH5CETCNW6AeQCQqy/ARjhMDJYXxzA/jg0touCTfL6s9m3ZqHkFLeDMC1rQhY3s
xsaZNeIPQcD/V+IVRxhxioOMvko0+rMRKW+MXZCMko15kqKU9WTxVvw9Ey1SjMfbiAeNF8PK
CCDmVMxo5DGvpLn1d/8Koz956YljGxLt1w9/7RfDg0/ppyDxTKFJqQvALKQO7zh4zPleafjk
2n2vntdnPWo/wzF+72/cAcRRJVe1qMUddG9XJ9R9/n2BN7xHAj/3TAYueO0rIvkI9QnoodDG
EIK2hJC4vWCFYSKQOL1C6umHJEwEfB3MvAauHj/29MM5zWUKO4mvRL0zMQCT7QIcIXYIz9VU
YEYxOCd9TBrFRtrIhEFyByEYXuGugRomDzVy832YY8K9M4YqsYjmaXFJyrbI4XKOhPL5cFlV
MYOIC2h5i2XDzCFc0NZD70fLcK7YkriSrGi+wThmZaFlfKM2sem1kcSDNw+8fm7D5l3f1j/Q
9VMPZ3vVeLX42w2DX3+Pvl0bz+7KPfLcD50n3z717LqDbdmTL3yi/zHbkE8VXMLxXZte/QyB
SWNcnkY8bWgyj2qhvBPSABzhqcVqMwlOB+EFp9NuL8EWTSTgwyOwE7AIdifw5CLcJSZio6Lm
EMAkOJxEEAUqXOSsuLAFhrVQC5/nqZuP8pQPuwmDiMiuioIuMFuJaTVnMC6PLu5ODoOHBZIn
+0pK5VHz3W53BRsvpKW0H9OsFO/ApEtf3vP883pZ92+FA3CP23H3R1f1a9B6lQYxQvoxI0yb
HiIKrNdSLjNYbbKtAe0Z77P5q/wRrtO81nzOxNlNEK6yRfhqEdtqHsI8x1XeUsG3VFD9gSii
kQCsMx6C7qIEt+Y8MW6eozhQmQbCh0twTLO5vVEv9V53OGmJvj8NHwnkIjUThVTDbS2sCeuF
EwInhOvEjw4poDAMFLm2gsEiZpEFDJIypuFFJGa5WM7nDPJpPk5DinEa8o1jDOUYVw3G6WMG
OXmMWhzB/5fxag1u4jqj9+5TK6+ktR7WYy3Leq1syZaN/DaOtdgyIAdPKE4wnsRgG9JAGaAO
SaBQ3gE7MAnNqwGnKWQGmEza0gZikB0oiUjbEJIyzDBtp3HTdMpj2o6nf1xKA1b63ZVsw59O
pdHetbza/fbbc75zTo6UTI6k2gqHkvWUVdR+Eume6CE/Uot85KQ+clIfOamPnNQHYQ825rzs
sZHunOCimRRGnGEPfrpnAHtpL89oHpDxT6MSdMGexWXA6+NxPbX1yam/V+HuscMvZTLDJ7qb
50VCi/seKvOElmzMHM1MyrXsokxm0HBkz8Vt/9zVXFYfaSlOhCVx86O/GAeXgBbB80trsz8E
HBesNP52wXMFFJjmO6oNkmeYDth+Y6PjOtbncHhYQbGdpz4FP/E6QkjAwyOKIiHWA0L/vmTw
jYsp/JfTyFXqSFGXRkwuj4tyEeLmWcmDsDpLph8E8FTzHFrCgvFfAVH0uobFbNwCMY7KQb0l
oBTKbpnizEGjEtT7+nFRvqsfFZtgz5+n9GPZ4ulHXgNs0LSwRsKRXbtQD2gJRCZIrDOumvgl
oLw5gCGKmrNNlIi+0umRL3b4y9zzWg5dXv/pxm3XNn2BX81c0tVEveXRha2RZAm7ujD68pXD
RYL1Txf2fbXlBax78zp+4W9T6/er+zOZ6uDaY9i6JpFjwxVggx79UM1DgpOlOB1QG/zvj1VT
ltB6jGiBxzqe6IloLqYuUBSiJIoC0+w7Iwg6Bolcirqs6gWX+APINbfz/jWKXya6ebOH9IxI
ShOIRha4FMEYRTBGEYxRM8C9bs7CaVCD17S5ZTGghuP9Fi/Ga/FA5tbxzkZF6adLMg2FzIpI
USc+/vUhGFJoIdxJil0JuAiAo12oltAiY8kXrZY2cbXyPYUP4jr70tgmZg/1vHPY8GbgXcO7
gZTujFV8j6NaHwWnJtA2U3iOTxaDDiRWV5GF8UQ9WWcYheU9zqBZrxngy2pFBMVRtUh3iouD
K8WN4h7EBkWDIeYIBJBocgTn+JBNDjpgTHLmGA4EiN2wGWJWOAQHaF/MMMdkCOAYw913mVOc
Qc5puZyikeq2Vc4ZV+nF9FGapl3VWds5bqoMq4KhOkyOMB6EcEIAKzirCGCJ/ZyIEF2B2TE5
FdGqzhatqXHDoDEaGTRum+Gw9qW5gTdKTYNG6eOPQW16uoHWsOCCWedep8yGC346cwA2C2gS
9WzWnP5QYwc3/PvapfEdr739+K1L6asDF4OB+nB76/I15R6DtbiyuyK5isqsGXn22F9/fXDd
scTWHz01dOXszt5XdbHvt+9uq+lbmHwr80mh3b8vuXxH/dqeNLA+Dk/3rObjS9CHqqynXXSY
pg8J7wgp4RORSehYu5/V2T0h/IHGdB0ePh0KIdJWVTSxyGC/ipySk3ISdpstrrB/PO8qJj3D
ztIZkmdzRc4EZUn+IMdjLkUwe4MGJT8ouwpdbhfNBZVio78fFUnOfqwIsOcTPf3YZYZNQB+6
j+dh+BCi4x47SHkdl2sq6afZZqUYrDU0659tEqF7/MStQbm5q3L48w2/3bDp2vbPM9/Bpfqw
o8JZEisMtUSSocJC5bU/vlTs/PKjfX/eOpTJHP9dZvMENfTdx8681VVaEJl7IvMPoDn07+eQ
1u7RaUhrdhQbRc5vPlSdZks1l0S8mDTnmeikUHbBhm1Oxx+uaM0A6Z1qyiUNSAL35TfL/Vlu
qRbg+voSuUxHp/uyma5v6unZdEehQ5nDlEW7vh91j6IgXL8Yrv8fI7bYJAMpI19vSIufFSUd
eqilUpYe9qbwfNVkqDLJHvmCTMvOwJbhmdImIANCdZMT8KA0WJNZ8UCZdM00QvncN1ng4sfa
evsSbX29nc+s4XmeE92RuV2rFizd8jM63ZutuPfr35fFjnTmCzo+/4nmllV7nzn4JczKUjTK
rGMOIA4NqUoBW8t2sTTHsnGMrJhlQO9hn4RWlqNoBoKrjgMjEHmfSuM0CztnixF4CIQ4ILdq
Ae6qHOZcOqxSmHLyS1Zq9zbQRCJhkwRvBIawY2piYiI7FXVRh2Z6ZnbIHQdxDbZhzKy7e45J
3DtNd4ziX34LX9yfOZI5Dl0vwReY9fQQTEcetat6hkcsJ2Ae1J8OnkFgGiAHkGqsUA12CSrc
pGpxggnTZcshHvVmZABVdEzczrZZ67TFa9PeJcz8u2PkQw/t/tXuBzr0ihqoZ5eBmvyP/vAc
erA/9Gx/9EZzNWe3u3hMkT/zBHM1ZbdP19X2ZOI2NAmWyf+/VxboVA3GpUzi7jm6495p5kCm
dUnmoQO4Fz8Ovdr2zQ36RXYtGLMoel4187Jdpt4wYOGkCx+1YsDNGO1Efpw4U5qH0hiXpXBC
LUCKpFBkU6zsVBhlH+IkjuLIvwwed4U77v7KzbjvVOansH8E2SUIa+dwI6pA13CVlivB2t3u
gQjQMzAF0wbFp27GezTGEcPvV6YdP8xW+yyycwOY4/j7mXizlHKu8a5eUBsstERaY/WLPjub
vrz69VVxc+vy5a3wwWMb1n/07NK9290FDsnXUTun5ZF5z50a3bPi7f6Wp+7BIStWwGHQiScy
8/kEdKIVLcVvqHNZLJkkq+SWfF3yT8o/KNd5JMlitptdvuYDMtcur5a3yPRPda2Vlagyilo7
cR7jcIYqWxMdaIzOR5g2q1bV2Aut61X5wiYJpswOvjcCk9itmjpeqa31wHzUt6Q7N0fxGH4H
HMdKVWYOSVEcjXYtKzmpPxma53Qtq5r3yJ32vQ2nzClcN+Jxdm1Y6Ujhsr2ENB0gcjevk9EN
gyFfS02TMCBuoHgP+I4b0tQkGGd4g4kmGM4JHtHChkHJ2KRN9oa2RXVxtnxhckFyfpLm5jY2
NT7U2NzIcKWKEJSCXiUYbIu3b0eL6tq9iCtjvEgXzjuPrW6oZ+dpVCBDNTvPYpfT7jD5yHeq
GxkCcESyMbEdP1zf4UVsOe9F+hL+PLIU2bRf2V3ZNb/YCOsIFhXjeYwiuReoBsF2ZPYVDu8i
CkJkuY4mggt6a66RIAIylA2WYlRXRZElXzIHvDFG0xUNH3WAl9wcBO3RbHmI+KrsSeoI0EL/
Zbpag5u4rvDelbQrraXVrqRdPVZr70O7kr16WcI2IrItIIAhI4xLGDC1IAmNeTUgE2JiSgZC
iBlIJ+Y14REInTaAm84EqAsY0gbKMGFaOgMzTUqfaZg0tMzgadNQkpR66b2S00YanXvP+aEf
57vfd76jW1+/d64upcz4w5B5xPz4vrnmLjgPFoAgeLfU+rzZZN4wN5vOL8AlwPwJPHZ8xPzX
oWUrAvOT7W2x7Kwnp5b39qSaJ892PadrmVyvxnsj2fVzQl7LEWr8uysmSamjIHoC+MCyv5od
/zGPm7NA8kvz9+ZV8Cl4ARDg4j9Pm5d+fN186wdPFZsX7myaJXN9z5Rv/uy1xtDMhQsaci//
fXc8HY5e+PiJGREBTRQGw2ynoCOQsQhIF/YqTI2nvZfpZzao25lB9S3XOYZ8zTXiwkFExTFF
VWWKrhEpvxwQ/TXQLuF20cGznMjDKY0p/LOqm5FUTGZkXFZxOcEyPpZlVFyV8Rjt9tG0G++n
AU1tZIHMMm4rr8osDWe2X3UrkRh8swD8hSkwbouf5ynKYXfzgL8AtkLBSBZUiQqm9TJUiO/p
N/SPdEJDelHQ58HKLv2UTg49A0Wtjyndq4hYCQu0V0StPR+Crjk/Dvfe/1nOkidXqtg3O5I3
GsobvJSuGCx6zLkAxowB5lI1lr6ekEw+T+bzE57OAHJVU/ycDMdkC8gCvprAt1C1IVFoNh83
5Vw4KawyW2cvmQE+8YI7MxNK23hZ6JR4Ag+v+uUNsHXbNCMnMHZNq1n2unXKg+E36utsmsYz
tR6vY9pn4NdmAk4fA2JFwy1DgN68ESwo7D7gB56nhX68P30i8KP4hdoL8V+Rf0x8maJiYDLo
ALOFBXi38DQ+iG9LD4Or8ffjt2v/ptyv/UKBWtph17VwJBKlJdGhKG5J9ClqWqu1RLCklG5s
wLTaSBiuer5wUtMcvkiSgyRoSNrtDjsmMRIufRg84rGGspFGd7QuikcTbjqYyY4C64jcuihg
GHPv5ZEDRGoyfdFZLMkk8WTxTkk4nSyOdUNPjUFwxtAPCc1YEMWKmLBVmwgxgn9CQlnJV4Ul
YyRklQ/YSL+m6H6N0OOaykspoKBgkMkUkAMRFFRYUxO2hhS0jIj14CvWv/hi1Tai9cmzMX0n
getxI51TuuOD8d/AIYrMOgw8GhEkIctNGeh82Em6rjbJmYp9t6EKLJAsS1ZEo5JZhn4+t/yd
/eZH451LpgvCoyV8553L5VfHb726vWPWtj2gpXne9o5Fh/DricI3dx/81oCmTl5jKa/JKdr8
Y6WnDnoK6xcvfjYPxg+bxUxzy6zt85fuz0MmYF0Pb0FrtBryUjyP8Q+3jDioSeHR6klMnC54
FrrhxRlyCM3eYmiQfyU0JOwI21ezqz0D7IBnB3uCGHYd81/1XxMoAk7a6fzU8Bb+Zf+gsC18
zvpOLZXSV9RtIPpd/cKg94KbbKFZT0TEFuMiNDXAB/V3sfxD1kPbVokWehXnAEtTLGBDZR3o
Hm3NeZDBkJWYvqjgcFN1FE4Vg8F7COiR6m2sey5Tul9C2yva+XK5u/cgkeBgwZhfNKYfmz9w
OmOH8Eb4MOFyQmDtDtKBE4Lu4ikNI8Iw1ARoDXOEbBqogtmAoASlPqzUV8EWsKqOFihERQ9C
pYVDS0EEarEnks34KyXbwmj8Hwc2v9/Y3nPl8JYP+td9fux35slz10D35aGjPUEpRdpWmw2j
V/b07z9/1vzgYHnHcxtWvw1mjl4GPZfaIqks0koomLa+Cv8MUFPoCW2BjVdRYFAwUFjuXRFY
rh2qH43ZlrMrYbKfPcC/6SWW0aQkYopil0RaUcNJN40rTYKA2T2JsFusE3GxzZ4mwTwSkC/E
W89UDXofolC+iJrLVCySXsR8jC/ts/iaYUthk8/qxTR0VSgb656g1JhhVBu7BDV2jmowIY+X
9eJELFofbYhaiP9nOMFzfi7ABTkrEdEMRtdAAwpqCIaoN4yCAWuGxina1+jUgD5VNqE024Ra
PEEWxBY/WsVoHE5KC+vjEQItzSyDtjIh8Ui728FPzyXwpZ/tO/NOz56LO1tfWsx4heyJRc9/
Y2pvh6ZJ3ErLphWTotq0LnP0+tCnR5aGnNaHDz58XKfc6w6BR4Ht8MZ4XcUnY9Z/QzwawdzC
GG8NOnApm86Ws7uyw/6bvpv+2/7P/Y4Baj23KbnDssdn20EdsByg9nLDlmGKkHwzuEJ2XnbA
YqMsFIVnCz5n+z7rYceb1rcdx302J8DILqfzml0kJUkMKIrR1dh4Ky4aRBcA12wiIUtivaIC
AnOSLoxjOJzjDR/HW/yknx/xJAONsXqQdDoD9XjATpBuspPE22EYIk+S18k/k4SbXEviZCZ7
0rho4Cmj3eg0lhprjc3GkHHUsBsvMXyZ38Vb+FAhC22u21Xnwl1tshTMTDyPyuOYIFepD2pm
qW9dCu6a7UhQGfgdy0/Mu1ypatUMSLy7GDM+cXyVWhjbxEgz+krwg/UBFgGaZdUkrkIA+Wwl
tVTnWgVohCWCGnEP3vCk8OJ6Rtedxd4nvZOmdL37SUZrffDtxCOREF1jowR9WsK6VhdXPjH5
kNUc/+333xifsn5f1txazkinfmJ2aRytBHotm3o4FT46c+3eLbUeiG8S4nsc4hsHcqFIWh1U
3KLUzKmxETaCgmSwwFWB0mt0Z6dlJtVZ00v1U4MUvbF+V/KM9Qz1nvU96rb1NnXfdp+i6Mp4
EyWRUxS9Kx4fxWOFVVFRd9uBHYHsEO0YpF4Xjl8jRLJWEiOKaidJHXd2uvBOoF/UgBY6Ba00
Blxuuo7G6TbRjdVBTWirrRWDCR8Xj0XwGIg5Xa6IjxZzqKBhMS2Cc/ZE8qcA2kmsFZBQKw2I
UB7h81++qze2ifOMv+/539mOfWfHsS+2z74/Pjv2JXaaxI7/xlaCmSgUgqCD0ni01RjQQpdk
E6mE0kUVrVvUrtn2gbXa1GytaCs+kBE2jNRNqQgq27quG92HVZuafqHSJKp+yFi1YmfPe7Yh
YzDJ53tf3+tX9z7P8/vz5NfyRPXy17UJ1jLKXq8Qr5Jv5hXm19hr2qJWrv5ZueNOsE64sJky
LWcEg82kdW1IWPi/0jUY2Te9o0OWO99+IuIBMNZzzVQRYOqfitq/czT/c0jU1dTc0fqed483
HiVwbGeJjBvHXzjhYyBHu9ZXjSHDETSIj5TcFtYQ0in26FPB54MnQieUl6LPxyxyS6s67tCu
GNGuMRgcMh2yzlhnQhd1v9HXjBdCF8IXYpZN8uZoKVaNPhczvBI+FXvT+LrpLetl5fdR0/12
ruRji5McDlzhuQnJQzpbF/zyPQ92XOE9kjy4Qb4ktK//bTUQxGzQ5uE4yZBUdbakZAZv76Ac
IzjgTZL/mzvYoaSzp3so+Q7eBbl6Eq8izcUQ98KYg2bKrLkXsyZo6o38A8TCgKKR5JBmCC7E
trVNJbwIF4CKEHGZEPGAEDMyVgi/EgkBCZuUDtmsILvIjmIhyLDGGMwsEZuCGME2iuiopndA
t63eJaZqfDulES5JtxwOgehRbc1rZxi0D4TQYST9CqSadDVAx00NfFYZa6y99uPf7Z74w0v3
HUy5y/fJ1I+25ljzM43PTr27fml4MwbJO7Cz97LT3+8CQZRW3j/T+OBnlxofn+xyYe94Ato3
QzDUeX/jWjZ3+MwTJ8/gAXyapbdGM8SxgD81ugCvY7hYco5J0AeAU+RpSeJKTmuRI3G2D/uL
iGO5BU5HWLVG/fWCNCDwMUnKksedsC5bgjVMNpg9m9WNCnwW1vxKMpEdTLd2MLGmBZMOC7yJ
7CA7BJL2aHuHqLZDNBg9G9XJwNKwpvQNeVDgM5IsiT1jiEC3CIbaFItGOc5DZTMZmjbRMhpl
R6nRkQFmEMNnP/DuLCo/UqZK5fHyQnmxrC8LDA5iCo84EIvhM85idnZT4VhLr6dbgl2ZutGe
oHYTQr6dGWDoel6rDbX1vWGoETFLuBjfC8BdcrPddIj/88ud/6D670Q2dZmMGSv+xL0p00ut
9OZlmJFxPd8cUy82Ju6EenPcmMNzt2c3T9we4zdQU4upzyH3QXSy1CeSBFgEnpIkr8A7Jckn
8ODKrQLvkGSng6Iw7WV8QR/lG7FaSNa4zXJx1YL7LSXLpGXZot8PX5SlWxDJQ5+PH1oV8aS4
LFL9YkncL86JizAxanGHQKta7NV2vIsEL4QXwbbcO4AkXNTndwsPhE25SwS0M8NJ3euf6tbg
pDG0p2RpHjIMx6tRH5U4uauLoTAlJhlzGCmsQikjltes2FrDjy318lDv+FtLzh3qyxc1emFv
XM8kWOB57b3BugGZaC++8TWJlw0nh1KDA1pfovWbg7daEyxTf+rNh7oZ6/b3Xjxz9esjhV0m
/bA3XFDTHjiHof3y9UOXfjFz/ujmPdsz/i7LToe3099b+Yj6CzlSU2mN43CmHH70IiqsLy9J
PUMFEvufsI4hGlts1oQ1twVvsT1pO4aq6FX8qm2hUMO/7qjZLuQWCzeRcwHULe6J5/CIbVdi
d+5xfDBOI3suxzBMLh5P9DEgrzZa01a3JPUJfHhCGs6l+WEjBi8FNNE1IQcFXpFkJoVTiSSf
ei+BE/HLORzvYXIu2AUjhFhQ3D67zWW321AOmp/lJSicHHnRNBkkwFfbMKIL7K2hezgVVih3
l8lIG72lAi70MWyQpdiR4EIAB7rzhXeo3Zo2dzf5fqptq65BJeXz5GqaKE9GVenqA3G1Yp9l
V/TVONccVTjEAusvA4C1e3PWmlRYOk/ntTZWM1iEvjFpMQlQSfsYwSatEu9SqK0CwGRVONJk
dt2D+O8HtiRz9ZGxyETjtwPcpq313Rsq+PUyFHAH/tdh1b2Hcnxt5w915fqZp/sERTEG3LHv
4mqs8f3Hh+6obpdd7D7Y2IdPPTgYdlt1QPHRY1ATYeh2bFATCnq5lHoMz+Dj8mREPy/Ph06H
dLfBvU1qwhrUSOeTQ4iU/aQypywoBqWGL5ZYQeyhAPOYpmjlz+inAJSzJfdt+HeH+yOlyEJE
V9hL0NzytWtrdfBJwJr1/FolD/rqIPFXtSBWsO7/wdqj2VWQO9vgV9s2xOZqTkM3J3c/MnVk
/nAC/60RugvKFw5l7OZtbyw0Oc10CCKQwjtK0wHW6ixaA9gcOB6g+tPl1Hj6TXQFGRR/Cs+g
Gf8M/xyq+qv8K/xb/D/4f/Mdk+nVNBV0BjuDLjbEKgbGyXQyLhRCijll3EiO8SwfllpRDGYJ
BBICn5TANz1fGkO8X4DK7/H7XH6/D6VSCPXxARfPBxBO8X5dEHtRKgmcE1Z4v9NBIzSc9rFe
7B2x/NH6iZWyetOav/EHhrQXShPXZe5yD6UDwZ5EnDxzkGfx1Ti1HP8wTsW7h9M1vHtJBHat
4d5nCSgqGrkCKtRpldhSSFA3saWchpEmSkifASChq3HVALCgCUDIQOVUtcXHlco0WFXoLwAD
99YtLIP6eVqYcKc2Zln3IZ6kepp815YtMq5/ydW/MNj2VBr99r7tPVYKHqpUDH+gexqyKnIH
bj6zQdWuf6Xq379Z/qZnoKgoODiUsD6s23dwMKIQJuTXPzWcgpyLeOqc0wn68+U5W4bcSjMd
GdbvZ1g/zzO2LLE1PmI7JCrLmyRiQdzbwPGwIiVCnyGyfg9meH4EYRdsy/sk5GDsGPMeEZyG
CVEeN82YMdVjZ2x4vw3bZseBy1lHjx/58LgPI9+3AR6zUstaTFWImyDO4kZzRJqItqfQWjyt
wava42pVP7uC4EeuzUqqWmXzsytVdgWTLIztvYjQ+mJJ7UwihmWG0bQwKc4Jc+IP0DwzL8yL
59F50aYX9GJMH7FKnTGvka2tP3yuMwm30+CvknpwPi7MsvN4wb/ILvppRFgNqO2hsYm9v2Rp
l68IS1dLZidXRLS9s4hq61+0ZoyryNTWP1uCNXD/+JzdU8RaeSBVfQhj0liaAM12qstByqBZ
GUTs/sN21cc2cZ7xe+98/rpz7nyO7fPZjs93uXNskziAndYhhKN8ia8lsPKRrB4fayEFFggb
CQ2boFr4KtPGx4oT0XYqAjRYVY2VD0O7CiFEO1apjG4K01ZUlUidJlx1EstakRx73othrTbb
97zPe37/ep/n93t+vwSo2RwyyVfVxh50Zfm0uDK2ceMc2YxtWRlNP9VKLxq7SM7rTzeTmsao
basfFG3Pjx3fthQK3LmJ+l1tk0JqMDvaobpf0BsJD1GDfm1M7eK7fIPuYWE4dFu6HRmOfia4
HKKjJkiKbFAKRhJ8wpeorpPcNbvApgRx8FfMC1dZPZXViWH1LHY3+BTCQSiio+SQfch5lC16
TpGn2Pfo91zXo8No2OMhbQ6n3WV3B1GQDLJBTyDqWhdaF9lO97G9od5okbsgXogOh79wMsur
qnIEFcg5XAITinWvtNoBTIkRIsI8tMhig0KUlJFnyKTMCTGBFMCnYPfYg/2KwX3jgLC4PPFX
ucMyL5MbsT1Zgu1JC6rhtaherbs0Wg9JokTaOY+gwT2FNeR3Qha0Q+ZlqzTkiZAQkc8d0AjJ
BiGdboGvVciUVc0XEaC8AO1wzmkX8nTp4X2DEfKkKORZeMjSw7//1psHQ3gPFhrvPHkX7M56
8kS68ulAjzJoLVQLfs1BxuWE7uUJGpjDy2MZ9ESTkONJnQqi2ejl4vvmEfPw+6+hY+jJy2va
+pcNrZ+zcu2zx+hVrNlt3jLNa+bYl9eQBzWgI4vefcX8m3ny1A+nGCj0KbxjukHAElmCsJ0E
9EtA0x9eImRAP5uXMfqfYfJtOiqKo8FR+SvFlnJGCMSC/1AUcCF2RfVgKlfDDQLREInYfQIJ
goOPo/id1YFdgV8GqMBLGR3p4Qn7UO8hWJ4l29nVLMn+WNPfQaSlQRwTGqTw2EeMFiyf2WJJ
wzJffmQSAMYvGDUxtVoSg6EgaVer4xkUkyAo/toMkoM1GYLA7jGdsmxjAW8eCY3H4jEXl0FT
AglTXiwpc1ldJZPhOc+Mt313Vjg8u0C2oVrzxME1n8W9/QMDPyHXmfu684qmqU92U1twdvOV
gXcUkRwcv0AeGiz+FN9gu/kz+p+AsACho98bc2xMV6grsl6zCQzn9s3n5vv2eg5w+/n9wgHf
Xr97Nprl7lLWa0OeIl8UhvynxDPyCf0Gd8PnCWAMyTiwFYzVVFa+sooYczMg0S244UAQLpfb
zTI0a+fdgjswk18g7OH2+dg+to/fHuhTerUD7qJ4HV13u5ZUvetGQE23DZHzZpk6CKeIu8Q9
hiIYNRzMeSnsN9/SJmUdJdR0jppsz9El9JzhZWK3CKd9hVAVStRtimNIQs0wJD2Eyqukurha
ulKH6vBoZTxCtm5C6liwTBdGMSwvfu3MeXwkjIGJ/yx3jAAyW0bL98vpGWVM7Hkg18IEUBdh
oDaxehyAGtI0XQ6oGqphwxoh8hB0AbaKP6bB5Uc8sLCMxAU1VOuDAA3At+DfY1gBRnse5USh
B8Bq8B7em/fDwwFKffAQE0gs0AEMNj9YkdqEDlAk4jKO6GtA9PIJnfqo4erhuvpi32XzrwtG
zY/QIGpGeXTUvGp2n1u7dMfy4uCyHYtXs7v3OKfrF36TRf3IjhrREXOT+UfzS7Ofpt9+1bxj
nvjVth+cRAvR3MMl6CisQ/8CmFSJerTdmLFM2ioN+imnKqoLpXmRecqayPcUh0DQhJ2nebut
MbM+3BfuU/apH4T/oN7MOIcCf5K+Eh+EHkh0xsmWyD+fs1BrJRi4kBh5DF6QVxal1qtKtaoq
O9UDUEwiFYmHdykjyn2F4pV25aZC3VSQEkxFFFXXGsIl9KkRVME+1dY3+AD28q14XFFAqjvB
vCLacLFEik+RqTvBEkUaAbZWA5lRYQGWbceTv2H6Jct9YCfIA+7xVOfHywUej/mJXdlSwsAB
LeXxFmgK3Bg9Wwt5L576BTz2LS8iWjoLmkROTKqW/FpIr9MmVacyKCFBSAfqMygp6hlCCkMj
VDphgh8wV18i6oDoGDafdrL5iOjzt6KJsVyAE/+HPKYELEfqwH4m6I8jymv5UswiMrDH+IIK
i/SOjhzcNOdHaK4RTjaZy8yFHfkDL7Udep3cYA58k09mX9xxdG1rzMx1BGKURm4gh8bfnLp7
47FfYGW24eEntjgwSx7VG3mxcUWyL07Zq5CLc6TtjSIXTNdzaT7pzShyunZSU6opvT65P7k/
dTpbSl3O+vJRopOMIlRC8w0/0ck1xZrIptOTQUd3ytGYHEOxEnTX3JpOQuIlUjrtT6Y5p84x
HBdhIpytl+tNHuNOMueZa5w9neQYm0rnJlNqzu9qQ6vQZrQT/RzRaAWh8zqplxBvVAnSNMB/
dhrnjIH1gVfnYpMbQs0llD9bmeIjZUwJAPrCSMGax2ByCj0W6PMEf69wv1xAPDDBRG6lZ+3k
rKdXGjLFUBypJfX0BuZ5rp95gduT3J1+mXuDeZu5wdzgPADoDmyWesAt+VQol2L3g6ie+Pqr
baqiJ/BLh+qdGqiQv55oIHPZpqlTgtabJ6irTDJ6d2Bdnz9qZM58/u2l5r8/MLYub4xJzYKm
TXpwaMvuqV0Dl46v+Pz8U62ZvWGpxkNvNFvOfPj9efVqpiH+9Laurj1n/iXVVtclSeL23f4l
jZ1LZn5n12urjo/w7Ex5Oq7qAkA3C+iWiTcuEQrwrShlFUyd03ghKysGQO6KYmuEhEQfOxxj
UENRjvKK4pKjHPiljyVprCYac0h1hEzynJPYgnCRU4YC+jrmIl2tIV5EstguHhQpUeZjSI61
x3bGDsZsscsoRYjkm29ZHM6P3i/0tPDwYPtZaLGm7ngL3Po9gh8HtEwkYGN6sNz1wqXCDar/
Y18sW6N6abZW/tZsfdVzwVnN9ePN9Zb3XLu/dUVQpxeZh3ZujgsP/vFfU2ILNC85ijbjG2l8
+Al9Am6kAVHG6/8hvExj2zbPOP6+tHiJEkWdJGVTokSRuixRh2NbjlPRzenAib1mXdcGQjLs
yNnMcVK3a5AmaBYYCNomGdBsw76kA7bUQLF4CeDYbne1wZZ8GDpgC1AMG7CtO9IP6QrUWTek
kveQUgJnAzYBfPmSFAhIz+/5P/+/5JOThOROJ3PaMe1l/hXtsvZLbUVj4XsE6hKwQAhdkxCK
TkROiIv8jcx7mdsZntTCvJBUE4ZWTjyVpN9O3NWI7/PzPFFlaFXByWRcVaRkMqcWFZRM+e0U
o0miiOGdnv0pFlKIeiKOd8VX4kT8eKlklSZKk6WLJbLE+Og4TdCPZLMTOZw7bnbSiW1V7vuV
w+10cqctXPn7gpRMZFif2zB0Xud0xkTpjFcTwK0k2LTHRL4kLPZf7EyojigdnoIBNRW0gyLV
iYkd8Unb6mPfduIjBVMJ0oGjSnSJeEsbXysPvLD70He2GUrhMXyrpzbm99aXfz23+9TBqPU5
ckxPDB1t7p2f3v7FH7xHZHduhxmpF4vqjmbz77+5Ylo3ZolvPVNLYrsWAuSFK04aVBaRBlQO
RVN9v9Jw1fXNMCFoeFDENXGfOCsuiK6IKIYlWRYRiRUkg7CHecXrYTjFk5AhEFoLKy9Z/SJN
qQyiwcvSdEGElhTDJEVlRBl2cpihKZeHlMHShRmSpBNeDwIfyWrQD9cKo32aKEbREi4iEb9o
BVSPBfd2e7BHTmoHE2eflhZw72nHP+aj8rZmU9q+8csb/pp3QB4eDog1DMICEjOzrZi3pwU5
U5TsTeN6PiohJy6uXhvt04zAD9tHW3muSSrj74PcApnPFhgo0hTYCBym7EGgYTul2aWByoQi
QJQzD+x6kVe2DuV2tAqJlvnZ2jhxJvJ5VRSKOIE9pYgaz2+GsnjWVxbvLbv639nA6nrEpwTK
B5oN4smnt0ZjRY9ft+sRWPkj/SHUo0xQ1tWz7D+zxKi0T56VFqQb8gfyB1m6JmG6V0Q66kfj
lV2VieoByJwVoWpVJ6qT1ZPVc9WL1bkq+zZ+t/I++hitVMgj7BH5aOY0e0q+iC6F59A7iJXk
LABqVmtoVN1UnkJTmEVCt1A/iTAryzRYTFmWolGGQ93QhX9xQb3BDfkJvxhQ/GomoagIOtPj
U4R4FLSpnCspZcuVdSFuYeXrVyXODYnimLUvC90YRYwA04EpZDOhbDbjQZzAERxXkMSQJIms
m2XcGUmGvUzRdCabgy/lRA/ndgmZqMwCLxL1OLRiNpeFa0n0QKbkymocvBnBuRmardrIjLjx
j0Bgs8QwskDw6rAXVn46L/j7BLlSXSD2XF1NjwNPVGpG5Q5ByMbHPu5DNGVTFPgPkJiHiFrF
Vh45hqX2PxhbfXG3MSMww8zx6zPCMG7kO9jlVNbbp2Y62IFfaRw+jKYgGIapDnkP4KPsSYeD
MMxslYCn9nUw2CZxDf2h0Reiaq0n0q251it669EN/RYxttksY/etwWJlpE6c3xgLS4VPfq8J
g+NAZVdK95y991rX/k8vuHZc2kTpOpFWjGPNQwRxbnoc3At204mwON18gdj41KM9WZNwSOVh
ri0CqXV83vpFYNS7RRiNbY3P4H+to7ID2cGteA/+SvF59fnEc+aF3ln1GrGo/iSxVFwqLdU/
GvGHhFBMLnX5MJv2mXHc7YqbVMnE5Vhc5csxn8rXBWTiukDxtELJsagin0vjtJlR0rX6kFIj
sUshkYQlQVQkQ4W4MFgeUAZLcR9ykc5qyHVByMTKoVisjM2XeGw+ovIhFV5cNtWYwGOGfLAz
5BGgiNxV+zGRh5/2IjLgHCfylk+Wrdpg2iBkiSIZa2QB3+qQlAOSHmCDba+zvNxcXm7j5Hco
Anx44KcB2IB/lfJwfvDk/5HSXvFD93zwaZOBbDNrheKC7KvzzpLhg3WsBqQ6bucZHLEN6xob
ibSR7mqLlWNvYYQPYAyK1dExmx0xOODYIwcnm7auL+Dpxnh/88B4keYHf/5uo2SGR5qfPFld
/xz2ti497unuKxKvJYeK9MbXzx6KD63DH6/dko3u7epu3jqzFgiiUtEAH3sM680jWaXCwR2v
VvwG3oLvHecTPbSu6z0RYe8KujzT312MAmLdunTc0T+gag6oKuCdiyi1cvtqKFGH6fCR9bq3
Ftd7xV4pl8rrZEgKyfHUfsN1xvge+d3UPLkgzacWjDnzbym2Jm/SLHNP7Evas9p06mtpRnel
yJRh9BqFftSPKy4mnMpLk2aXM8ciqsKPJfMKVlIxRQH34B3ThB7cI3UrPUIBF4xepZDSfTrW
C6IUEnVDlAxdz1BkiNJTFAk/VUSFgqL0EF6eKRkYrHH/VYvE5ALhtVgqdTQujUsEEGNYYZGi
xY7BQBErMhmZi7giS8RtZMLg9foCfX8wcdF0Jl0+38j/o3HHyUrLjTv20XDmnG06sAyCY84w
bQW67mza8eghlBr51SfH1znw5O9Ps/+ydng1FaAoDj1ryLn1qcrB1m8jI/1jTXrzsAZGr/Wz
XdtHiDPKWnPi7vLOaHInCAkby73ZCrcW9lXvmz5wbxvfWId1PRlMnW/V8bcvlLsDMunoRwIq
XYFKh7BocVgIxOrIAIAjtjUuBWJ9XsyRiFOwnyMvk7PUJWGZde2mpqkZ8jT1KvkqdYmcFebJ
Oeot4U2/p5MafG4OIyZIRcKcwAp92AaHgw2XQQTOuBkng9jeFlqw26rSTCDIBT2YITiEMeHv
qeOCmwu54S0E5/lqBHKfGLWYCWY3M8mcZEjmCbRA/M6Khpg5BjNu5MmEQogg4MWhXcFTbjkc
WcI7wEr1/dAu4HbQhD+3jeIdO8SaWGgtNxyFOIzsMs6QIA/5meO2LNgxFws3hZtOqIEmhzbG
OAF16R+odiUwGA6eoLWg60+fvo+Ja6PPvpFID9wzumI3n9E3HfvMv6ku/9gmzjOOv+97d/Y5
ie3zr9zZDr7YF9uxz+YSn53EONg3ElISEjBV6aCbR7YVloJa7KiNRgoNHbC2rK1WGKQlk0Co
sGpQBTVdCNAKuo1uSKiLJrWlk9ayKUJTt6xlC0ijxNn7ngNq/ce9l8t773vP87zf5/k8GPCY
3q8A3/De8XItg4zmvt0/gC9hL39U3o8GsJc5sPVddAbYAEQHgR0d0EQbez6JdgZM55PcTglB
xAE7ayL9XKWrmEL/0awABwoCyMF+WIQ0fAceBzb4OnwRVKi4pGOxXOkkCAfDrs6uzu5Oh+0+
0/L6CfsIHoiviPO0qXlVvLzf8NuoN7X5zq1+S0OggXD+wt9QDve9FGjT6igEYQ5QTgAovDPC
beA4ijFwHMTod85R1Xhnbg7LYV7f8zlmKfFfc5NDhRJ6Bl58ltl2Z4icro7yfvihbvd6zflN
S+0YHUwsOWYmbG0FT4i1FmCF0ApFvdetGGsHb2IvktZJ75q+bqmNqEandZxKJSkFPyw/cd9G
pvd/2ZCn5VGmpt8iSY34ew6iI7STGQAGUNIc3cxG5jGG+ge8gRCCFG0ADAFgMZhkxiENpuCu
CUiPU1OUX6uxIhEpKIdo9DAkDxyG8XoMOXnwc/AZYIDbOHykEoy+2bnbhblZoNzF503m9ERB
ygUoOKBK8OEgHHsQ/uJo+ZPyp+gI+mA+gUCZBHhhttxFO8pXsP89Wg3IUdCD16V7VpJ1Z7gb
QOmbbW6i/C6/gw599ZfylT3YnhAtwj8ww/idNPlG0llZgYhhcQp2TY5QkEI/xk1q5wRe6MFz
ug9JjZyfAUolqZEvc/gdUgjGn1zPDJdP4Fe/u/Bf6lPqd6AZtKMezWXguDRdz6UTWntn8mep
g8axFJUlYfv+6tRkGj5jPBk/3X42/n78mv/j+LXUjbgpZVxp7HH08N2pDfwW9hAYS52Ak3CS
rVGNcHf2NfpI/JfNNMjmsz+s7c8O8odd4/DEsovweraKrc1nn8xQq1jksrtQhuzyez79RQYm
VBZDqBxrlGNBORZpV0+pF1SKVperfeou9SX1qPqm+q76gfpXdVatLqpQzThZP7uZfYqlEZth
e9lh9gX2KHuS/SP7CWuqZr04k1BOO0sJ5pAo4xUjW5TMKpQYBQVFQYIWkZNWQRQ2CduFo8K4
cFEwfib8S7grUIKgWbikgHD1qLbGxJgSy8XoWGekwxoUgyj4OQCKKWcaMV000fV4QMDEERXD
CxqnZXdnkZbtz6LsGy7o8hLrGvONuQUv9MqglWtFrQlGk4LJ7cyXDGpiNCbP9DM0417eth4X
ruZ9FbHLfbOluZL8XoErlOYKhcF2rP3bM7gq5expWcH/J6Vqlpvl5udmcMbj07i5tZOLLY3p
GHdm3BWWa7e0t+MKBAcrGfvtGmGJgEABZ72OHVqibVmdVMVRtBUDnT9YHUqHLD6bD9TUm3ww
IC2jWn2AqzP7YFUAX9rojA8AkifxznLl9yz+QUzNOjmXZFDCz4IGKRBKJVuCOuLojRtf63Iu
Pm1RE5iMXHopTLTyBvI4bDNUZqkJ1H3q+fzWKZjitcZvRT11oe5Mbv3g1Sf2jfGWKqfZ4/Ul
tnXmH6nakQn73fHE/tHH1m479fL3trZGltgFlyg3Nq/sVVft6SqtiI6WD2l+Lij0dKw+BNMP
rGtpXSp5AT738sIM7cW5igdhuE6z2rtYwHM8goLb1iDyU/DfmlcK7aWMvlB1tWXQauWqeQC4
AAxoRo89gqP51uoUGbS2zPJkPjIdQU0RLZKPFCPHImcilyLGiAXnNrfoRu6oza5xsInTuDx3
iZvmGM7duKZUSXCYKc+RtmnC7c9xeLkJoV4f3+LFHIFKnADb0wpXGJRlfWqkMjWyODXytam3
78HKjF5wKQuHIblQibEnSJuZYEPI66nzIIMJw3uQDoThkhq3D5gtYhW+lwyhMPSYfT7gZ33h
b8Q4SmLcsUGTdjFFU7F+pOEw+yvmJHuWZn/C7jOhEXqkakQcCR5mRhsMOPeVChuhjYSYBFwP
rVHSM3Y4BSvFKVFhZCkAx4de7P91//DVPb1D6bGAsUpW4V5DVW9G7W5uCa94mOmdnx8uTT//
2p09TS2b6RPrHHVeFJx/vdw/ImW6l52+/nF+Gak8axZmqE04i0ngpvb4LQNsMMGNppO+y+iy
dA1+Dv+OjFUsjKGo89viFtOPxCHTUNWgb9Rx2nHaOYXOOyd956XLvj8FcaV2OQBlqZsG1/EZ
mYbXIaKhEyLod7gEt/ClDdr+KYSqjf5VdLXVAi0yJIFIuHNk1LwmWxKXs2PwDH7DMx78AucI
a51Yh+oSxsV5ZJxslJPTRmjUq2GNJWl0N7S9rOdqzJ9Y8IU1XAEfDXw7M6jD02yJa8d6tmFd
p0s6R3FX9CqD9TZYCur6QalkK/F5RWOYIBdVRzqQRAuliSsub79wfcvT1145tbIt02cy8LzY
FEg+1N26unnDTWHnDuh5/+Ir4wceSXeueTTndqt9R/fezMhLiVbWYq2sxFrx4Q5hWJNeNb9h
Pmc+W0vb7a0s8HE+xItxEyscF32XpQpqY/28DY8bRHzznbOsvLemhq0Wp+Amzc3v8IecRrwU
qEBAFAgcRvWo7kAL9pAVroXoDITQo1RURoYJLDIyak7sr7wyraCickxBiojZXyN60Vzk1Xsq
m+Zozr207VnhfhIlPsUakm9X/sLlkGhldk4HRe7W7F14q1CRzH3RNAaiZkdDUAoigz3UGI6E
kcGCmToUBlEzvgRt/jAMW2VdKlBXSVRXiVI0Fx3FQDF6RrmkGIqWEfsQPyIVI0/Hf8rvj79q
Hq0di52sPRU7H7Pstr5gQySKhY26upWKupVFdSuL6iarb8SAqouHdzEpEvDw/URaoaGUQ4/4
vZC3Un82sPG28lMPbO+aGHho4DcDHQMZU03Tiud6tgWFoJKM840b1mB+vfq48/9sV39sE+cZ
vu8uPsfJne/Ov51zfL7zxY5zts9Ozgn5ZX9JGppRQlMhaJPWjEGK2sKaJoWlP7QVqEop7QoT
a/mDTg3bH2yVJjLCutCtItO0TZ2QGjYJsaIJpGVTi5aWabSatjns/c6m3aZZuu+9+3z+fPd8
7/O8z6vG6tTRb28tzh1898Qnz1gDqGl3oDnSVjn0qk9549SP3kp4j1SzgCkDx/xUDBXwA6zn
Hl/ZN+V7xP9w6Gmfs6XhNP0r+j3pEn2JucJf8f+N+Tvf8Jwf9NLrt7Yyu5gpbZZ5TnueOeS+
wX/od7XV3w6gepfLIGkQq2fqy45YgELrA4uo9Zyc8Dodiyi6wDW67N6kEXY3gMOaFXiUIgwi
mw20Jzg1ui0ScUgqUE2mVtK+rH2i1WmxFHGVNGoXa8yzY9RTjYmcZWcNB+m0LCIxrNYYSFoA
Y7RSXiEcNAySLAZxoMDCW5VqX7gCLcO0nSFQJptbQsFwkGYjHiVKNfkCURSV5CgK+mGo5kWb
cQCVDbLJ00itsrFa8cgGemD/nNYdsvqZcuW2a2L4K3071mkbF59e3r218tarlz6Ot/jjltqL
Pn1nz+ah+wMnD8wduHAD+T/67qmnFE/H+Mk4QDEI3n0Q/HwGGfghbCLWq+i0wFJOhRWddW0G
9BQpSeQ5zgOCb4gCpyvOX2pIV1jgrKzIJZk5A9akPXHQjzLu59NwC9TjBhMH3SXBVMxrJmNC
Y4ZCdqsYlq1QNKVhiNqxlPnBtQzKXKaoVA30Nm5ZQMLlZVDIyzzvSXEEc1iIRGym2q0Yt8zR
YDG4HLefO8bNcSzFidx2+3SZu8k5uXDMzJl01vyN+g6aRCx4WWN6E3B5hsgi1LjplWmwQvbZ
n8XPjFs/h90jXR5ATYpgX99oBfi9SmRUBPsDxHaSWBsJxUnHZ1Oqy68WinRBihc6CknrCxEl
ilotU6w/6O/wo2u+2NbK70sF3+HD6Hfnnp3d0G/1s3WcGGxO0keY4crstlALo+tIzm2kX9ox
bB5bemhdZrBTdUUkwd8g5ApnZnfANlGja+uZq8CkHNVPbUQX8X0tYqNQSre86DqcOZ76cd15
19nU29mb+qd3NTR0uApsN9sb2+SoB9qmXCllnTKivFL/QttJ1+nM6aFGPKIPqnwqJFJMj1P3
FVO8ydmOvQmSvYg93UWcSFpFHFVg8IesXBGRrxc8Iau4yNRhv89HKOpr7jrBcc0mzWAzb0Eb
FMEcZHD+hOkcTjQLIzbVPCUScQM8bWwEjYyEehZvL9vSy/egnvbQjJNGM4oTmaS6MSxOpQcx
/AgGoWQOImFQGaQHR1SRTIr2pIgEURFpcZFxYF/CysFStIUES7FoC6sJI03+T4HZNG5NWWli
mIX0VPpomhlLL6fp9Owo2GXbSQFvV/rIfourZWBxbayUp6E1W1m1pw2jSuS+itEH3thcJR66
5ol9WFEtY3zVsBXAqM6ep4rw2i0AH1HiZsUCHSamGg5Ui+SQuu1sAgdsINUfDwRrxiepETXu
6Gq3J5wkp4hod1UHMna0O6v3tNuZxlRLdu0qQX8H9S7kvaGpCxvYmUx/V/GHv713+pEtB77/
jeWJ4W0HH3vy0FPX58sbesbu7ewby8T27VK7v/a9l98U5K8ybzyeb+3snTy+2dGb0rN0Fr+w
5WU1n78/l/1SGM8MH8zl5x596b3ivsXXph5/c2Eg98+/SkqhY/OGobAUDRBHtZ6i6tZBzU+j
a+cp9vbNs43dWZu99xQsx3qaHssuZ2mnw8EG2ARbJ/CURqUVXtTENOs5477gpmVEeXXFvUhf
xZKW1BUtrrl0hY/HI7qiLtIf4J3xVl1Jx+NIhp9SoV11Tk1V3W6+oV5xIVebz4vVgZIXD99t
eXF/wYuH4OjugYtcHoZkKwxGBgZNhwGy24tFyXrfiwQvinnf99KiF3lJK+ZZyiIlO5+lzewT
BIligbzIAixlR1jNjrCgHWElO6azdsRuIEeWqtq4ttakPQUPdjOJzORScjnJkKmFrh7LjsAd
O8JD2be6mlUrGc5sqloRklmQoaBN5T6x1j2BpEFjR3Tt8w8x/aBiUG1AwkrE+tnTDJEuVLad
gkoY3FhS7f/wcSU3OKPqlTfAwxWIrRuHBRhkseQm2av6SnfWHyfyh8ozkLMGpKzUWTXr0I4F
QQo7QfUku2tjnUQe/2MODPwvRvcPP/D1VGv/WqI97PEYcuvGtODtXUv0hqVkEfz6H+8bmnxx
bu347oJT151q08Po1N5etWt4rXEyrNXrOhsL7GbefsyqbwFP0Qb2Mu7YQzVSEeoqDkT3S8GS
IFEeKqJIokeMsEFd8RAzqfG6IpGTeEhXIj9FH4PVZ+FtJavTOsMiFlOIi7AeqcFFMIjALOUS
XbQLMymOE3iFp/m2UBDD8kECRk+BhIVY3LKjN2hHbGZy1nwQHQ0iuxkMPoujY1FaiW6PzkXn
o3VmtBQ9CidL0etRtnnTEggPbNxnZVt8qtsm3lqtVaDSqq0kNtQG+qKmdHr/G2fANDEw8SDG
ExMXs0NrzmLUlx107LEnMH5wrbci7+yq03VaC+6kNTgF3G7/em09qkC1b6Ty1B9IA3kTRwMh
i+pAu3K78ntze/NHfAdzB/Pzufn8Usf1jsYO2+24JYvKi3k6rSt50uK646Eb2gmPkOdYAiLc
8xNAjoDpX2QY7KNkUY7JORnLY/J2+Ql5v+ySFxnnQsIwbJyD/w/nG2mDfCe5RQuS64Jx3aAp
QzRo42f0Zaqd/pNdzEUbtc8RE1fWpldBnI0yAW61hlp5mvpf5Jxs7dyu0kQtg3fkMpmUumw4
J/H4RKk0MX5RCr/2zLP7+lOJNKJFMRxU2QbEIGPYsXu8RNAtja/1/Wvd4YFtM5N3pwcyGU70
18clqbXF1z8VXKUHrZLpbAEtvAu08BBoYRb9BQ/RMX/3efpd9xX6I/ofvKPZ1dSYiGiaFu+K
bOEn+Sf5WWk//035W/zrwuviD5rO8ueEK+KHou/fhJd/bBtnGcfvvbPPjs/xXS7n2Gf77mzf
+S729WK7dZqGuMt5rRL3R9IISmhamXYbLRoUKWnHj7YMp6xbASEiFTQ08ceqMQGbhBqarQto
op66so1/GoHWMUBaJQJaNSIQiioExON5Xztt1yJhRe/z3t17b3Tv8zzf5/PQPCN0xGJir+ht
FRc3hdRcVsoW8khVeE/G72h9FAfix0qRdEYzeowAFoG1q1evDq9dHV7BfR+pOvm1ctw9ThlU
n2AIfQXdy/OCoiRUNYQQDaMWCHFaoCcR0XqyhmaA7tKwa1iQtLBmaLqu5wytT9cZ72s0sFoD
3hpRQxK8KPD8p5WEBHvxnaqSEPgQjfwFjeqjAh1s6BgPRH5ROaACobtRw9B7woH3Cn8r0PUC
KgAahrcH0O87FtH0QjaAAovowsXQMeEXKETxSHV7EhO8oim08mVV1XhKw7mfy2VxoAggkfls
I7uUvZH1ZOV84VXEUClqHC1j6APmA72EOg4Md6u2vLa8ulpb+4uwOo5hDyouRj15TFhdja4t
47RD+Jj8Z/vs0OPC656zfVG7hmc1qmswiqkACQ2KjHfPBX/ZXz5LRmjFIPRg4xoI48BmiCwI
qVSYZX2+7p6WGJJwY3zhe9P4tXe3pTa46Ifl/U8c+eOT0Kw0laSS+3m594Gm0lbH/5x5u/Kx
eNzwZzLMptnPNH/5ejQNuR0NRR5A/NBPiGbeJZAQezYopAGxJ1AgayLWx0MimhcR76VYStC8
AisILAcYT1QSeN5LVBLwXsAZ3qPDm6w3QK2DOYc1kGtpIDYLTqnEtbUQW1cHMZzn0ByHKE7g
aO6UJp4X50UmLw6Lc2JDvCF6Rby+WCphe8npK3URKcSl7CNaSGRwXQLhPrpP+BbuCN7uf3/p
tswxbz6MZQ6+fjdFsV8EUh6hx11tlEaiqLkBdcDPd1NlakTrhhI5wqLNA7KhSYv0Oy+lHUPr
hYkrpSuGVtbTvKF167probShWYv0717R3SE0YGhDMHdz+oOGNqLrvrSzOeVDHrW88YhHPRII
eHzUCFse6rWk7kDVBfok2PtJNV2iquer89VG1VOFiA/xvMbTfC4mA6DImEaelS/L12TGledk
Wr6ZSuf6HHjkkEfOZeeaw7jOnEM7Nyl+QBugB3IPVgiqK+nSocqNCn2+Ml9pVJg8DEsVpiKP
VhfpTyykMD7Yre6HsAPB3fLauq2VW9mA+baMf/jgx4QV4bZmYCfgvzsUQRpYI1+MK1ynly2Y
CbPo7VMR61O4mIqCnXl2o4riQbXVxgplW8CuPA0/asfeE66oJf0dSb9qebWOlEUlU34fwrwC
PHH69LZ9rnGoeqNKs0EjWAq61eucd493j3+8Yw/XqHq30HvYPcF/sR7cgc0cmyJAU4WQ6lHI
QS8I4WGoRf9cAKQhFkAHOse/37Zdna37YMk1z7Wu+fZzof0eWHz9M26QugNXCPgH/nGYQE/k
/6MP7gzJLR++d08AvzX2xPj+k6mJ7048dNyxIM8H46JkK/Y+pytSaSYsh5fy8d5Uvh+eqUQD
mB+f2rtt7+T+ialvPt08fbQEROS14g+hc49vTw0PNwOHYxmcBXrx4+hc3TXC2q5m4JFhlsjC
UVogstCi8wHIC5v2YDp//2VusINFDo6lLbv6JxzkBTLPsMy79HXm7RgTZvuB2Znr6L04LfIh
UFdbCwkpwb7AX+b9KJ6QDI1vkboJdK6nA0DuhNSTmNTDOvC7reupZJLnQwH5iJfx+OKL6ODC
EkJo8cOX3cloPzpBUTYbIOweDksY3iWIfV5CSemaREsY5CWAeAlDvOT2b4YB2FvCuSFhnJcw
yUuY5CVM8oKEJIzvvObMO3TemYa0AXZ32uxOLGzitBneaTO702Z5p83y5Ex4YHgn0S47lmXe
hngT5c2GuWQyZhvizTbEmy14N0qmvOEOvBN2F+6Cd7izWrsTWyQdhTa9r9ozAO/llRbI30fw
yRbBJ9cJnscEn1wneB4TPI8JnscEz99L8NBwHoOOEyDepkBZ29H8PwL5/pi9Uj2z+8BXJAFC
0uqPCKIdm9xp9TetdnieGB89vGvwueb3jhKAz8iPoPPHy6lTTe7RLb6PhCEc5s4Pl5lXIA47
qRTa60bfiCEriMRP+UNmJ6J8EdPX4ecU10POG2TU45p2ifcgT0zHH7Srn5jRlhkmZmFwawlb
1+i1Sw19Sacp3dUP6XjqdfVndVrnRU2kRXeJQ6Rwwb7EwtbYXgqGSpychj1mX7L6t8xg5Ww5
b2ylNi6sd1q3wFVjK1TLQeUVIofbUUrI0BlNTao0K3WHu2mWNeOJWEJOMCzfKVrwlYqKejpE
lYr6FAt1BUMWUpmQiroDEZVKeCMW1dYY287ZuRwoJohhsRcNoh1oh3Ai6J1m68G6MC3PsnPB
OWFWfpP+lRao+6Y7p/l6dM432znLz0X9CPhjZgowBGF1As7V03R/SYykWUK8gLwD4FDsTxM1
T/7mC4dPvvPb5ZvXNu2IhLhqn6NanZKZiTFXvvb+t9546jnUe+UtZI+O/enXn6+N7pTTWw+i
1It1JYw9aDV3emAhlaby6DFXFvN+nqV8VJfGCj6hi+3O69BZGZoPwwSH+YK9qrd7MTeuO2ci
vi4R+i42Y2oc6wsJWZR14zGx2PIvNgtDW0vYugXIwoniUpEuFN3iRHG66CmKbSzpFN0gKgTd
4ESwEVwKeoNyYXyGdAkzJFmCsI2cwmreWIgmib0Y0XA6TJHyJ9SwV8nSYmtpsb20eNfSWxAB
GEpWWv0ZTsiQgOtluxwmzQ1RVc7YpmJamQ3RrIVMFYZczLFQbyJjUVTbtXaryA0Z7vBoScdD
PVpX62Z9g+cxqS5PK1/Vp626/aT0bf1p6fvRZ9Rn0j8wfiS9kH7RuCS9aojbw4gC39Zgv6kM
JGjPprszNBWGKSlLEu52oLMh/sY9DuQzuhApjKx9QKgJfaO4acfkZ1/Yd+CnnxvbtnFg8uHN
emnQdA9XDjafr5aimQydihxi/oC7xlPVZP7rfz7znQ9OpWPPnxzc+9d/TA2dwxEwDhGwEyJA
gf7mUfe/VFd/bBTHFZ7Z2x/n2/Pu3N7d7v3cvdvdO/vu7LuLWWOb4NwCBZQGYdOqJFZyoSmE
oNC0hqhVgLppAiqK2gZSFURCUUkqlaZ/FGqnYCJVMVJCG6kSlpqKtn+kqLLaiMZpIhyaKLLd
N7tr2trSvJ3bN7Oz+9773vclFGVTWNZQytBIitVRXrENjQa7bOWvGqm3TLscFXqOsGJKk+T9
hMQEWY4ZBsoTIPfVmLJS6rIyojDAU5VM00+FZpAK1ALUSc5oc7bJjDfPNpmm0Q2SIkxvROjS
MJ4NY2/aAX7hdGMwQGDAV7+IabRve2gM0Qd+06CAO+eFdj6IahDTvkKNk8qlSLlYMAsMXy3z
pZLY3YWsTkPHklzj4Lqrw+7CBcnWcUXo8aIMYfYhuxqEujrOjYvjpfHaheZMk4cijjxdHq8e
qj9XP4Vf5H5c/zl3vj7NvVF/uy5RVuNzmqafis0gFZtBKtIUGivxghdbkLIedA+sWiEcfSA6
Yl5pU84R8wUuc3m4f9OWC7u3Hbr+1OhE7xmTZEYW5+4ZTFqNVGlLdf1Q1z32g19xM/aZiV++
sHx09cATn218SCvhUilX34x/g595eU85vuGxpfeu3393H2XW9yEU+hpEvYK73IhYFofERJT4
QAptGOw/prKGUwuYPtjvTBr93jSv+z/LxLNuV0J1SA2fFI/XGDHdGXPkPNJRxcgTnVR4nFQ1
DZmvGLonULSrRt4TKJZtVGha5a1In+zqa6HP5QZa8mOUWqAKr+cjchtFXsc7EIt3XDouzAo3
hBCg0OuuiCqyZmiMVrVMP7VMjwM4jmezBc9CIqvOjInHTYxMYjLmX6pbv+Qhiq9QADZASc7P
kzlPptAeUKtRSBA8SKDZg2o4UDNArGsrTRaK0jKD4Ah8MqlRPPY6LC3frrJHC9vfXze4YV29
f6sQ6cxnKskCFqKNwSVhuBaOlJuhc++8sGNja8PnP8fyqtl65BvXB4dINh0CKjh0kOFG1VyG
oyxv2/Ic8w7EqI856j4kNpOkxZLOSoLkKyyfUBNXS1fLfyY3yadEqJBSdZCsrh4VT1gn7FfF
n1rT4muWyEW5znAlGd0s3hflXdGNMkqfgU4zBsaUbWBXVFo/oRQOb3Tj6LTSgB+cxq1aykif
zhqZDG2n4HI8gzPTeK9rpU+rtxSFK9cERS8rYoDerpJ08IMKKpIiU6SfXhRlx5+ZEp3XoagN
CUsZ2cENZ8TZ4Xzdedo57/COIoeNMBN2YYF/ZWYq3fSpFAYAFFYwoDu9inZyigEAAXPz7Rrt
C78OF4AbeUChwYKwmyi2wmuTFgxqCaZw9IAu0b5/ez8FD39hsQCvD2e94XbADsWHYTU9+RRs
4FnYw7OwDbWTd3aqjc15O7hp7Han4AvmYjCQLAySBkOn6juOodY8fZCu63JLn17+21Q04Vvw
oHYS3D1Hz+8y4oBFK+DL6eDI6eDFJVZcyPsLcHBM5hfmEXmftjlXbriRWKvhdsgwwLtQN+rk
e9Enl3rhaFDHs1O+hVcFNlnqBV4Jsz+4HXBR6gWqWZpe/mgKYAns3CXaXHOAWf8VTGNoH5QC
7VbQrnDc8tQRJSHsnf4EpWCFVlFWAk0KSsNDtVV9HnANMD+SzeHD6yprEgVcbm99fvuGcV0s
qkVi9p7Z1Bxeu+fF3vUnfrBlczamqKnQlaUrz+8ZsLPpym+/t33rydGq2IdHjxy5u9rctPnx
wS/s/Or5kiwDJUHl5VvMSXYRpdEpVzomHosy3iBGUXoaX4TwsIlEKHmYwXxBbIquGBL3dzwq
iUxoGktunhMvRjNZzLJI5gyO4apxNXkgkYi78PHjNJ9I3nQa8Zn4bDwUT2cockDuwecF+r/g
MXyg9FsJEAqYotbiXLu1dpH+BlNM3r6rifehfTi2Kml53b1vQPNBoz9mAU4M4Ol335XLZN0a
fdvFsUOxyMFv/2o9u7j0i52Lb2xr5HeqMzuHzZP4U2vszQMUq1vLc+xdoXPIxD+8jGw43c9A
49mzNtMRzUar0Xuj7FD0pdyruekc+y/hgzBjumKnU6SDzKG4wZE4+1cBLwsY6BtnWbJtxC1L
tw3Tsjiei6Qf7RAjIjJN+AA84qsBJ9N5Ktl40HA8yDaeyjaeKjaeijWeijWeajeeKjaeKrZr
PJZ5XOCv8QziCc/wVL5FbKoEbVBudqDc7ECx2YFio3ay6t+Gne1AuFHrpoEyztjYsC/YTMMe
txk7YSRxsipTXJmCjaVAt0mBbpP8zTzYiYN8+1DCDWlGmpVCUtoKhFwA6h53uKMH6N9C+39n
tEXMe0oO/j2d4FGC9j7aG6CHezWxv4YDgUVLoVwOGFwQ9dUD3jT0++7hpcMbvvvFkUPVrnvw
RLyStfPdg1RtLdp7QWZNjN77yLOv4CeprFp8ZtcaPZ4ZwQueyMIoDhrrA4h+Dh9xMwqDGKwg
BbNNfUwbS43ql6I39A91QacdurNfpy9ezhlOSx1Rt/MhQQobAqthLQuEzo8K5gxeJUlDnV5+
zn1cRrlCNpfbJJOELBOM0MOyBFdSTsKI5UkBAIJQsGwSlzAkq8lZIkuYy0HTEwSezyEx+29y
oCm78qgcktvSTezCEq+9FPBZzNBkuoZDeJSebGrtiOOdMGt1ObrbKTtE/7J+Vr+hs0THF+A9
mDzwhNBU8QpUXM2PxsI+qLvF9EJ7ITXv9WoaD0UbwsD7huAWXB6t16QJ8uZRrp7yLmopROYx
mfHH9v8bL3jtNkXRpE4Pq9PDMiSWa2E6QO7cmEwMeSZJzSeTotzCK3DIYYpwQNKh/wMMxuMe
5sGc56HA/rn01lBB68UfNWKpnpcO9fcO4b6ewcGl3+WYPx62Mh2lUkzVS7uXXsaNZ1cbXUyp
xK8+smjSKo8tz3GTEOce5v7XFBTDPfBk95yScFAIsaIqagSREGGFRqKhNrRWoqW2tJHEiDqi
PcA9oGzXn+B2R3aJe5S96l5tl77b+CY5qEyo39Ke1A8Unuo6Vj9V+xP/Hvq7dLPnE/Rx5GPx
tvRZT5mP8CIvsYSLsf+hu+xjmzjvOP68+O3se3xn+xz7bOzHwefYcLYvBickxjS3khhGGkbX
jJVRUyqgAdayhjWjk6haabQZjD8qutGXaaLd1hVNiAko1EAnVVo1lW1/oE5TO2kaSEPb2imI
IVa6QZL9njNkTG0t3fM899h+ZN/z+X2f7zdtl9eUN5YljEk4HIpEkF8NcD8EIh535XHeLPA8
klSJSC4fl2KRDPyySAePdWVyvMtuzX7rRIiSTGv2m/Y2jooZs1hs8IzGeSaCJOThBG3gabhN
u6hEMd0QUrVQSAWdQaQRCsM4rLoocUnFdCSMkScUyOB/ZG5kSMbMczPDYTakurC/mO+Kx/yS
p0gJCpQF88WesqMBfVWnz3Q6vR3XE9WyHQhWEfwn8osyLsdiifxEhrdw6ZS9MfRYiITO4hLK
IAk+HRV+Q3pKmpVot2RLayQq6aVyi6x1SGzh4jOmuVoIR0IH1UjEpxP6dHz10JbBvzbbggFg
1oVIwGsOzXEYhQDOkbLpAyjdk0DnePDTI4dYM3Ens+ZnottuJ1Vf3VcXR0yzCSLkuIf07MUT
4FHU1lz/CfiD/g6f1h+DC99Gl2bpbXrb8Dp+VbD7KZTppVl0o/rvvry+GH/QbWT27vGnSxa+
0JdO7Xki0bUER8u95sx/5pGj018mP/uhlQlC1giHvjLzPH40PrzAl8tRPdYxDLdrVibyhgtI
79k9rQvSLcgeF4D0GnnHHs6nXuIkMU+tkfDraVxjT3SfrtFwUONdfBc5GHy5cg5fqPtUr+pT
RSKNx3xeG6wL967xXoFE4PXo1Z6unGpgw3DsqjJg9GY9AoGnI/rAy71nekm5hK1UmjMrFeSs
pqASrileBsKopxJcN0o5bvTWlvDeMx7sqGMc8kU8y+fzbI9V5T3ldBCk0Gmz+iHriEUesPZb
b1nUSr2gHKm9VaMP1PbXriv0q8qkcqhGUw2lBhJaKwkeASzo37WfBZP8lxK+r/R06Ujp9yVX
CYdZAUrIjaM4h3fiPdi9l/2KX+d0lH+HP88Pc9dP2J/Yx4x+D7+Ez2L6R/DpGxjXGOM1O5wd
ULDCFEupuTjmjFu85qpZJZ5SGPZ55kZ6b4+R9ehxr8f/Sv3tOqnDT3pTCVXrUAziGZ0CxwnH
tucMDiKM08et51K/xGlUIrvQUlQnjROdV4UQX5v6eBrcjwO82Zxj3SE91j8+bk4GAfKmeI2b
DpAYQIRdwgLIWKnda4V2r6Sd/jh4rTaXwD+gDItAMcASzi0KidXh+j8pv7PFzc97R4FX0zzm
IctH77e1VNwfrCqiCYomLRrH3q6DGoJCNZ+0mvF6/c91GO+2mmYchmB2x5FzRCR6zCGTbEfb
AmPp7eXX8RF+JHOa/5Z9yPyQDtfBj2jiSEfsdgKs5vNOLBTnP8yA/11C2yXmdY6LjlhsyR1V
Rnb8eLSStKavL0tl7h2yPL5IZ3HmwOD4IyOvfml1N/Ekqz431b/YtSZbwsPLtt9Nls387lUz
RiApdkTm1V/cMsQiAKtiGMOHduKFB+6GMsNhr6qoXuu7vTuK0ZQ7lyMrHnbOl5kGnYKqs/Cm
kwrjjMgiFByNRO9yYQ2vQqvYysS6xNeS95e3J7Ynt5b3JlvJd5PBQqSg9aG+RAM12JhnzDsm
v2gdRocT7+sMVmUWk62gR/ZyT1Tv4FHVjd3YxSG7RLi2MJovGGbQshoJXUskdJmxOAQbtgFh
DTFBXKeV0INMRt5o3kKGGGK3O2F8ZD6XVoyP0lENEobbk0CBjZWLlSsVWhF1zbRCtQIAK1Er
SqJgF+yYe8GCTL6aH8zT/LlOE7nPg6fXuyv/sxIg3iPXppuXwLq3Kd45ZyVG1KmBqSmBGwCA
RR/un/SVzbalCN4SaNR+s/+znEW79frUti4LWW6CTfg8ZSVeYRWdiCTAaRtFfHXmvcEvlPE/
K4VFrzy6tHIX7i/XBmf+taUytPW+sRXVRcsw9vmUeLLQ20VO/mglqC2ZH+96bOYATr6wNFcE
J+Fedmx6eOZmffTB5bV77OVdgUBq4UGx81HQ20dg58NkoR0II9pBP6Q3qIu1Zv9uS9lclWYS
qaq4O5HOiP6KPawnqzWyimylT9EJeR/ZTw+yG/QT5h+mDXmQradr5bP0N9RLVPj6hHyVEMtn
SZlQJrxWfl/+m3xd9gWIS04STXbdqsOCTLSInyTIk2QfOUnchGG3HJUn5GfkM7Jbpn7a8HtY
A/vRAOwHPOmmuJyTNHkahWHf+0P+AZ8UCofgL8gsvJk9zvaw77OfsjfYr9klkEqJbSBUI4QS
TBmSZC1Agpg2AlKLdtks4EdhNQzeBvs9YTFTYA1ETiHs12xQaaRhTfgFDcgK+E5Jkn89phOB
BWETOYFQ60c26PUAmkXkG/BQWyR3nE1g8Z5fuAeQZz2itfDwHHHj5si0EzauXRMxUZ1arTro
jQu3AMlx6vJAuN9qqvXL6tQtusS/DQs7u9NRUQZqKQpGqCaoJfRnxPHu3KvRdq848xePByMD
txzq5JPviLXUc+o5JEQOCVXGO53Ug5vOwhS+KCkDsthrCTwviUMDy1w+FusHM2Nic11nZw/O
zgdes6HOKF4MSraYLr/5HiEHHxqtzsvSyAyx3/65Oa+DjmZHNmE1efONHQcEba/NPETOu7+O
KugPdp/hMySSVZZKi5VhaUhZJ40q26TNyrelXcqu6K7kvuQPyq+VVTlXNwwUq8dxHcwuxvFY
C2+yZc3lZFgXdxFXi1y1g8ViyutMebmXeMUUKxRCzkyIg6ETM3Kn5kxoXCOamEh12iG92rk4
tUI+mkOGamSMi8YVw23oiz7Y2w6EsBvXLplTTVOFqy4a9ZrT1EEfgEdrCjZqql88StzETk13
RDXQeS+UrxhFRQbMeiD/VW/Ju3MWiCLvXdJLzm9+sPvee3oe3923alVl/Vj24TebPLZ548bN
/yW86mObuq74vff5M47j54/YsfNh59nPfv4gjl9sAswhjySYEEKTllJqwONrlCC0pum2snYi
6lAJaleSaihihLXZJBq6bislH2DYpFWsG61Saftjg2l0bVdFlbY2CmMRq6Yl3rnvJS8u27Q/
/Hz9fH7n3vv7nXvuOU7vA09lVmuPrLIfamm90dF2SvR7Q8GGF9an3+nYdMgRx3vPbNr4zWym
q5dtYr++rW370fUbBh62WyjPo4sZXAs8M8gv2QjGDNIeIUwz/HVE88xIRZS9l2YX0p+gOOS5
RL3d2mAdPb6Y0fOf36boXYv7yYD2q6DSp1Jz2BJjScCYNKYtbcZOyyPGrOUx42HLUeYp49OW
o/Hn64Yrz1deqbxRaSsNpEd5zPNUKdCLgYaxwvUzfAA5oH95SzIC88jKKlJM1NYKjvzyWwer
6DFRHYvp1bd6FoS8Ru4iofDWFMgkNGjU/zTsku7OGEgXsPBePs7P8QVey3saekeodPdk6UCq
+agq2pJ+xdL1LWtnl3WhskDKhUqYjmS5GldTHfWKkHLOprKCwrsO7K3v3kql29KR2HnIfzAP
0h3Yt++As2YrSLe4vw6ka7nRsfGUyPmWpNvc/lh5HQbt2tuodk9YlrVrObGkXQgf1/SQXyMP
2jFlYu2upAdO4iR8Q15hrOPsRUhZNeOaUjP8kowVFzWlb5jRG3KyKTXakthTZXZX/nYjpWCG
vRelyQTFZyHH/GthHsSG8gY36OgtEwrCGdb7V8Nd41q6bFZr4mt1Zx9PHZ3+7oa2XdZ1htOH
Uw0Hx/c21Pg37SO/Gj3PbW/atvf8aFl1Z6TM8OVCAbEIad/UvU+CKACL16NB/CJ+DolTDE21
0WvkLApDhwRZQ0n1UyhZZ2GlaKVU8oO6N+tIHetvj0Zz2VRK9XVN9XUbj+Bq5JHKoKGrEwAG
LhuZcF5xGJUxDy72a3dAcAdRUMa8j99FCPkvY8SzPOGBlclSa5IvzxdmL7dHMeYNYYqN5lII
0GGENP/UVwJakNGn8Hb8QxSbgITdcJWuvXjhSYRg4ZNsCqci+UXHJWXh4KW68GftGZmDhOzl
Fj6BjyOnVALtDF9ZJmEsLDuLUvtusL8j24tLnE0DZwGpnCF7BBwXmoVegRFQe3sUNsyr0Fyf
vOP6wkfa8zJ6TRHjVVIpwahNjHglTEiqiHiFp92FvzMfaJ8BVJuyU/Q68OS7QnzSHYlI3nxh
ZhLmw+uvkRFAJmRk339DtsrIkGQm6yUoBdZL5c7kehUvFeOjUZllxcNp1cNN9Bp48EyANeA+
m+wJ3TevismqmEH0EzgbSSWuWouMFXnyhbnJTMZolCPLkvFmSMZbsxJZirfdqrdb6FVEgHE7
6W3CvqbupkIT0+Sdoxso9k0pV9Evq+jbMgPCOCwE4mvcXpGE3UvG1lavV7pvdVGF/QcW+5k9
zC/BQ0aJUvQ8jVLJgj8U50QyKl4UfyEyIuS3z+QoDShRmlOitKsww+RkBdoBrUOnvoGQa5wE
7Mukc1fpjLLW/2lPFXsZZqu5RDiaJEyQPzl7CcUFVJwclwrutDrPza8VzdPzv+bJqvMMoiHQ
SI7jrsieCLFEvBESsQfkOA6p2KU4jiBEuuVV/l7Z1TRC5ZIRO0qfoxTYvjBX4W9g7S+ybp2m
a8M2ki88MUntHV+0/xPY75H3otjffAehKD2RjjkH6YJ6jmYGY2nSAYlzL2yueEK6QurjY/Cx
X96f4mPwPYz84wR7ZKwp6YHqb2wKJifEVcSkzA3orGmUI+7BpYj7I0Rc/BKOUQ2sZjbZHMMo
xsZ8sQ9jmhjK45fkbYhFNCksdwDLV+SdP1R0cv2Sg/C0mPHxeAhuXYSooP7/i25FPwK0V7KS
uB92w/qJv6yKQvlifVaQp1XkTXQBUYVKwBYZ6JldmW3FPqvaD6IfQzS4pVLI3omoSUOPhrAi
UtEcu1XMLXQeWBKlClLg8LPcbzji47o5InFY/uaAJk6O+BVHfX05OCbgq7kwo0nIO310iaeP
lJ1iXnJWJClJDiQfrpWdKhzdj2xFED0ocAnzcnUPYAv/LFwmNTI8WAxX0adV9E30AaDlO0Rd
5fIdIgQsSE5RQanKmwx6UA8tyle8ZFUvg+hjYK95Coo3QsL3+xFjjhrwcxWJtOctsya9YrNI
JBGLNfnCQ/Rm6nsS/KZoPXFgsZf5vrYTSejslM8AXRyY3KHd3Jp84XPJZfckNzc92kTSIqez
IsxVpXU6hMuguJhMuQRjKk8mxtddF35OJpCDsaI4473sResEo6sljx8fFwc4MJgSrrusAy46
qhrf8DuonNn5mRl2YX7mE1YuteZn5hdmYMTOxNNr42ms9DLwTNRj2ntgf4oNBUNQEENZRWsT
qL0aRKdrqQyDoVJx6WnJ3Lj028/BvyGnC95bSXnCXy4mEoZVLu5bgpjZGBde2aSP17AdYrKT
TZuN2nijFDM53anMxoTHbRnYbMmlyysXe3fiY3PDL0YPb9MaTJm2RKLl4ZLsV1rW1DR3dbZw
a4+u8q3W2Hm3Rtcm1rcYtB2673VdeuW9xUGI0i+RSTKn7UFm5EbfkXwlpohpjpkzaUbYYduw
c6RCM4bHdK8bXjNrmgyOLfo87r9ctgVh1xaoW9dcsW4pcXt+ekruMbbOLsxCObowm6hvfVqq
w+7SIOEtZmstcmNXLbYbYFSugxFrKqvFFQw8bEZHLXJq4SF3bkp3922cQ7k+LDoVduQOw8XR
uhUqOyhl8fCOsdz00NB0bmzHzmP92Wx/v7Yne2Hn0PT00M4L2ePyG/hA2kPPLp5kXtK2oVoU
wS3S9Ueqz1ST2/bbjjthxhQ6GHk1zLAQkSdqzkQukAu10+gP6C/I2BcZiAxHmEz1XeFumAmy
nMCFGVvIJtjCTKOhs6qTG+P+Ua09F8EjVeeqRzjo50xVJo7xGOx2R1W1VqvR6WwsFzEYjHo9
BCNGvsoqv9um02X0Vge86rbiqkrERMJOwWZF7k8DQYu5TO9rJxrGpNMjAUP9ZBG8AhFaI84o
9sQif0WmbhMxuaPX8Dk8hJSebusstAdboTrOPdkn90DpWfqBhxyZrrW5k3XRY+zbSInTtZh9
9yRrSJel09o0DN6GgQFK6QpQi+VDpeYgz5v/TXW1wLR1XuH73982YBuu3xdj4zd+YPC1jR9A
DL4YDBgnLNg4QBonbHk2pAWzBZpMW7OwNGHVlKxKl1TtUqhYIHRKVJI0hkTqmmbVtK1tVqlL
q2nKIkVr18nLHiwa23B2rkna9Fr3/uc/uras/3zn+75j1xE2sUWHChrwPSgFXJlMhhiFJxqt
ojm4YrOcw7MMDLe8Dj8qkw2iOi8GN87NGDQeMTy30tfzUnSmr//eki34484zA8m2gLdV8Wrt
7tanrxnsjNln/Cf9b2f+GXSh8+bB95GDhybz203D4fqouyG/tWc9+U7QFz++Z5KrpBk49nf8
EfAuG4nbrLpLNaDaX4tN9qoigi/A1TCl2e1TNmTLkjdYkZXEuKrKanXJOpewidBj5YKQAjLQ
vmkQIkaIhEDACzJRdxZXsCVqke92eNDF90CSpYKsVOELDkXA1YnLfChLvsNKcSSCq23WGi2F
R/AHGOMseY9VVFcnesquT1GI2pGID2t39CS2cyNpDuqRgxNncmkY0bhAsuwMwQjDNUcunAuv
pjMwxiwX3uHIBGbYdGGFqtFrU1yd0szNatyBAlHUrZ0vEMTjlGIz++tg9yWNFDZ+X2EeUipk
2LoWcF1Dqn7/PunxP1W/t8GucLwx0bwv6XTUsxt3jWxXebV8Uccni1R6ZOHwhVhjU4xESpXV
7Pa9bfdWMj6vxdqOqdN1FS+cFIuNtP+NG0y0UW3cEekcKi5prrlzejj02ndOvbylef36ZqFD
TnlourE5ll9eba2UM0a9qw5qtyXfjmf4Q1C7JHqd/YGoTdNms55KLmqzldmmq83ZrpLJron4
ZBLvYnfHJmK4P7lb+2QYR01toWgcj7Fjsf1duCHRkNyjxQ62nm2IYmuxzeqoxqKwqEuU0MC3
+efa5mOzPfh06znNXCs+3DOR+H4SH2WPxQ9vxOPaseSRZjyG9ld8U4OjBNETN8aMsViW/Igt
YZsULNuk0Wq5XWMPoejpIZrYxkjM0qHV6Mp7urExHiV4Anvc2GGJEt2YcElg5KPEevE2MRYH
B+2UclDAp7Jk/lJJSaq3MUs+YIWWQ5YTFtKS6i0vbPFx/ComcarXA6+xlJN1bnSSh5wnnKQz
1dtdeIXQSXSkTpfq7eC2Yiqij5CRSKp3GISIw8oaqgrPdIYpLI89GQ5e4RyTZtKF7uduggMU
t3uY4JajZS5nGZACrOWFoKgsdLRMcoPD3dqF0o8u9JhsrUEP6LcAKlpF8yBZVGj+L2EJm0c0
DToIH0gHuRTNDzzMIW+i/b3XTi22eD3N4nBTfJfD/iLaMzjeH940P3xmHgSqRR0K93/dWPuj
y3tTgz/b1hhFMn8NXRUzY1vs2Y6DV18aCLQ1O+Xr5Pbg1iDrD2y9/ceBFxOpb8eSkxtf2FbX
wdroDlrj2tTYWrOuf/i7u7b1TdclnvDsrP+NJ1nNONgGLecnNqDnyGP4OiEirKxccJIoKqXp
CnyyRC0uzRmHQdGc3f/bsNod3dn2VyK8ATQNPXYMaGj87OzY+OxZfH12fGxuDkLuN1G+nZcC
j6ImUguILF8iWwmMJoBhzlOS61QZQWXR9ssqFT2iLs+iUqg4GsEEKSFJMovevlykrrj5wZqS
LqdDq6H7cEuWiXAoJ8mt3m3gTIbULHWRfl8zCV1vVEIlgGohRz67Y+nTA96nRrsG76BszboQ
JdrOJ1ba8e7ifX+Y3HXkQKRUVmMxqfet/F2wBP+z8cF9Xin0Y5T4C9svKP6Xj/xM9KmPPCI/
4iP3+47IyCrxuJy8VXnLRE6YfmoiBfS5olkaS70hgRRJg9ZAQN1ySohu6mHyRXrbKbWQfJNA
QkSO8gedaMqJ7oF6cKazBJy9BOIT5ixqYn2sFmlvEIHgAeC6kHek9FApWfqExIM8nxNKpKzo
iFKEHujicwHLH+Ef4mO+ur178ZHcZUIbgCdB8UD30svp1TSQ6P306p/S4PRHgWm5g+Lwnwnn
oBtWGwptAGeWzhCZApqNRj+AUApuooBUsGE68ivoVSmLANhfoNcPYLfa/N7AI1YFT6dEC/lj
wdrBX47/9hdR79jub61Pnt68dY+/ptJkLKIoudxskZF8dVtno0/IUxm/5tBUaS1FoR1Y98Mz
fXOHn4kwCuXmpaeP/WrnlrArIHMJNvPFYrumfCgoNjQeH43X8ppqXOVPPl/Dyis6D8LwRax7
cIf/LtSKOxqW6EIvs8/rA/+1rthwURSpyhQyhUpbodXpHXrGZpt3zLsXHUtucQlZIuDJeCpx
hVhHOShGTaoFKqFIb9AH9fV6ltcSmKy+JL1EL6mX9B9H/xxdcawwQsZg8BsCTJCpZ1iP3xNo
8ZcU24naYveke85xjhE4DCIq7DYoaR9jcDh9oenKYBY3XzY1TbOVBojYMovL5aitdB0KIO90
ZQBSF80Ouz1LLrIaN6Nwuxm7g3HzqryOWrvH7Yl4Wj40QPU5pFhFsvAFiD2Brg8NxqDLFQgQ
hFFiJI3GYskcgcrnikWun7RzP0X9rQoRMAZ1tbR4PN4mL5fThqrWhhteiAJsibVzvIr1ijmx
Ov6FOeW8EiAjw0jhluTWlDckyaRzdwvMyXGr9KEic5uMM716VxIC1mwoCDNHnECX5U6UISQ5
JPk543QCvMCwrsELUIa8PJlSQfLMJgt0qcxCm3iAMBmvzmuR+X2khW/00hyJFAF9qmilGZs5
alQa/aDyAEyrDT20uGYzJi6i3reu5c9ns/kL195CvQuv5G/NziD71DSyzZzN31r9DO290rFz
YPOkzkBp//GeqzaeH2iWqc0BpDfRLem+zVb+0JX864vZ/PmrV1Eiu4hSVwam8h9NT+c/mZlB
tulp5Jy6WRMe6RhW/yegKeWb0Mi7KTc2mZSVm9DHiVpB/hX+NxK9fQSBv4LCJuLXLDuunPdf
lF4sAEggV2kqNDqHf1zO/z/jZR/bxHnH8Xue851f4rPPr7EdO/bd2edgxz47PsfEMYkTnIS3
sJKFNCEEqIBtgpQXsa3lrbRqAwW16gsh0BYWtYOo67o1EFIM3VbKVhBoDDRt2qRN+6PL0kVq
VCZBhTr52PNcXqB/dWffc89zZ8vy8/v9vt/PD0HqfOLhpLNZ9USMjVVzMZ6L7ZbpZTEQiy+S
A0VwdIyXOe4SLCMC4Oh4FtNWtggmx2PxaChXi/TxQxz3aC5RJEN5oxr/hMQ1oowogqYLOMCN
VSdS6HMXcJwbUJyLoHlAjXXpKzXapa/6UGjRAp+WurovondR3KbvThPsdWR3O1Wn+7aYlVuE
hyCVccyrhSoUmW8N0znRfqh32+Br/YM7d3/6q6mvf9O1PWCyusn/IzaXlfubd33w6xvvH2k9
8M/zH9+vMroqEAk/KMGQrkx1mQLYepFwPriTf8dZIV+tuOaFH7SOV8DG1u+0HkqQHYnHkxsS
ZCKRTzxeQR6WLtRcqyHdSJNlqA77aPoSKUPbpGwa5nWTMjMsuPc5HJdcsluYlCuH+fikHBnm
Gyfl7DCfnyzInuFgcFJeMCykJuW6YQER01Syxp70+pI1Pq/3CK5wL6pzr1RDViS9UmJBJJJI
JuvqslmGMRVhU95P0Fqt3e74LVHp81VUeDyoNYI+SQhOSfHfJ0YQgP/gQk3qSD7QCBqL8Gze
oQPkFXhQq5uy2w66rhDukZbbCIbYe7npu8gc705jB8BOqS5ZbAHs3Kv0jQt6zQD2DBMd0sWj
FIYgHYIgSq1q9UDZ8QXB3ntkouK4Wt9REjkuSgXBgk0CFW0DTFuwBQshzmbjHDxyB/wI1zP2
GSAAvFTX+KPITASS1AuaNZtEq7NRydb7zMKGXi1HPgV2fP4v0JsIWsyuBiW1dIFy2aVcoXXx
jPJ5XdBiC2aoFZ91d5XGVzu8PK9hI8vhko61nykW8KVor1qmVK2w+zQ8D6u/C74ubYSnFEOB
dXoAz5O2SBv4U9sCO/L8CY0fDlB7UC2jUiMggICccdsiaD1/AKBIFEHhPPk0dGuK4MHZjbMg
UiKkvna1P8FWCoBggwPKeNcPqT3KGdCLvu7UrIRDVDfiqHKiNu+lBwjrgNFIEG6MUwNmPdDf
Nw843K6OIddsbfapVDWJgtXOIrT5Jllxj8yhZWH7ykxm5Urlk9kJ1a1eHjnRPzMrf0fUtZ2w
Eb/ILwMExUANQRlJrY02kjpWbyTLzAYjaTIbGGhh9Qy02mgGmllCb3BQpNHYyEA7g0DESEIN
RRjNDD1KUbZRtB3XEITrRw0GdtRMQgZ+BNcSRoJCZmXUW2XK4yDc9tvqv5pgJ6OE1I49RULD
NFvCI0q2GeNQfUOFcvQ2zx7JhI2zpVBOceop2Lg0Z+PMsPv2wZtgs7JuL/SVRm4fuqWcBG/v
LU2Q6yFbunNK+fRk6T/QfBLUYyWYIgjtaaQEzUQLGLpI8EgJsjaXTPNAG9NmXdkwWUtmYpns
buv+ysNWg49bXbm58kdlOwI7uINlQ2VvWI75R8res474GS0EXPHBs2MmM5Lm+eudfI+ekR06
bXRxdUuhEAtwplUOR4/ZZ4oEfMJRvjab8dUyq3S6HqOPScdkX7q5vsnXXJ/NVsUK9lisUJ+N
kZHWygBH8iaeG/PGhVdQpuXLzDIoAnGcprXxZtNHQCQcBAPEfIsu7nAIzURzbTotVMdbWoRm
KOgYs8lvgqb1pu1obHOir1tl8PwO7lVkBZ42rdnpd0JnQyGSiIBIW627tQhePzuuhgX3Rg+p
cSKqNkt9SCYacb80Iwu4dUI+P4GVYiLax05P52a7poeWP+P3M6MqDCV1OqsSJcBeP8Tu/12O
xBqTI7CO9M3oxs4oQvY4RJqBzSKFrCQ8pyDOFLqF7pFcOqUipoUjMc7bZwUkAzAIiEIaWIC2
EPZsHhzZEly31y0IpqqKTYuClC7d+dgTY5tEseG/a1Z0Nxs0ytKPY9qytl5lSW3vEhgq+Beu
Aw3Kj6kVyrYXDteW/jZwsZR9qiPTpGzstvkDvUf2KatDUpjdCHqUW212r0dcCEMhevEuckt/
hStqDZVaYH9pELv/qgdj1JfUS6jCeUICz+UNrfwyqYvvkTQ+lCx5vd4gh59Fgw2vBtGExqtj
8Bj1hnUEjmj+EqHNlS8ajsMTmqvUDSvdoCPKBCEoSdUGAyg38jzncrkZxpkHTuBkDIzBAoCT
ZBgD6zQ4DdVBu+jm6GgAtRhlRsZZriNZXnBJmmigOhiIokeid/6R1q4+Er1pOymmtXor605s
656RnsXdeQsRZaMw2k56kuaAPwAD7VN9GBWm+io+VO8GZkGxR2VCS3kdzoP5hJg7FwFJIiTJ
hUu8DptK3fJV3aNrPD20ib2JT4+W1eV0OVMuNz9JJhbvzkdoWzji81tsGroyZBUpcUGkKgJp
ny0QIsJ0NAT8Fm8IRDRiiEB5hOAygrLpOXTgH0QJhU0KXbVOi4osYlgbzogqt6QC5RkgzrQp
KL9wgs11LmHq/Jt//kR57+zWextOZU4+uRMhx1VAXnpT+WM691j/UN8u3lv/4vf6T8lhLWWh
es/dVm7dVM69X2gaS45tBp7By6D9/GvnlNMHpMb9bylDwz/p2L/pwOk917cvS/fi/EgTW6ln
yFHCRYhEiriSb6w3tSBz6ALHNSd0x11au9glwiZdkAgyQXdQDIapsOhmCCodm7kmIu86U2Ri
A5vyvqvnN+iLsDnPkLQ/R3vSsZzNLaeLsGOMwygfXTmH8ihA0xjm2Ls4TGp4+tQ9TkQlH2dx
aHRRR6yT4DT+TiBZ0MynQ7Nqe6QTBCi+E8StiU6iUuvtxDut7vXsTvehDZ7tEZERoe17pEW0
OecIHRk/rX2EDGvhy4V3Xnr7H38d2Lh64RP5E/2vXivu7Xrh58tf79175pf9Ld+PuG4mn1m7
5ZWXe9YvleBbp57+98UL00sTZ/Y9+YefnrnRo/zs5Nazx45ebm2Pdf6P72qPbeo64/c7915f
vx+JnetrJ/j9SHx9r5PYSRMCvrCSREl4BmjoZhCtKEFFMJqtCDV0UksLYgM69mKshf6BYC1S
eBeTqoJtXbNNSOyPSZ1Ep5UpdOtUa2gymUa4zr5jh4ppD9vy+Y6f93fO+X6PHaM/2PvayXVP
MFTdmAPcOu5XdNQcDsZiM/BGc141zWHEK8L2q4a8ys/xhC+C+yrLBsk9QgitmXzQcc9BHPgZ
zWTNW4Kme9VvuDULKxvzJGi7h6JH56a/WcAiOWtSVi4sL6Olmp4uMCqVapzga1iVAMWLahgV
Lle7C0ULTU8oEXKFnHDnVbhTCQB8Ovs+wJ8qAfIX+LQS3Ff56b5XYQMqFWOf6+PW88AYGDNz
QkvH+U6+j3+K5ww8fx4YN/AcMBzWhHUT3kBYjmVYq8FsOq8JxveJmcFTBjcukwmYQKA3NHuQ
EWQwygzHsgxjoAHShpps8FmBSJZ5JGgOU1WKX47sPs2okk8vlUpe50yPT++BRzaQe2QDaUE9
Tgxy4DERxMatm53keh8eZl+Yvcb1zxY/gZuH4Oa7lWN4/9qb/4Eq3s/D/8NjMJnPa0aBwsGL
fhxOfZA1yiDINTRonCxAKCYLYiKiKFlriNA1UUQ4lGu4/gus/4WqHjyIC6jXcHC9s5PsrodH
gILioZI9VMm+C6MwOnvoTTxxdLEr6Cq64bD2pDcUSPSpfd1bQ8+lDQE5kD6TZhmnw+V0Blxc
R643tz63Nfdijs+p2WwuHo5l48c73um41sGiN8h2JORkNmFaYoYgk2WcoDMRRqzWLtAvh4OK
LBchqm0KB93hcFDtZphhRXUriurz+3neMCwIRqPXq0ogve4iLNvUtGA4EAgGFbxGxaEEFFXJ
KyuVc4pBcSbQMiQSceJ0mYEQNBYXjYEFC3w+6aIXU2VBM6dVUM8qljCEMSZeScuLZIJ/ntc8
isI14lYZjaYWsdHv93pXiSAWYcelhXTVacB4LEhI1C7M7PKWChK2hbfkrO3E/ICWNv/IVKDz
cM6fvvkMUv63X9rPK6n99r0fosfwpvbze2kEecxmFB73HIUC3cIC4OYJHnzy1PyDp2odEDha
x1wCn1jk/0Qu5MEk4hbr6ylP1aYC+QCWVE7ZYFvlR0a7NhTVu8PDg/7KG/B1e+UE9F2Vow0t
UFoUb5o6lQgvhpiST5JtQ8kDQ/JX/bISiyWXPJ8cOpAcAn1PXORkGRpdnlX6J3B7TG3yE1m2
9Y7hyVlZ6eP2sGcYhbmuqeczICvNoUggQJrllnCIiwf4BkEygsHe38A/19jYYIk7HBGI7CHN
Tyr1RbBrQZPDHDAT81+NgoZHKS/AEQE0AYTPIYCJpU3BprjU2Z2tjmprdbzYkqOD5mqKZu8p
cEP5rUIUSV2xrsZmuyitUws4U8C6B4syZYMCekBq1Ev5niqr1QS+q/ZozRSQ4ijTd7pCLrFG
753tVRmoiUHC3fBlTOnEHTiGxiXV/PQgNlmiSazzG1Pc957v3yoNHlyR7Gm1ZJbm2rq9QRd7
Rh9YmdtDfqYfya3OeaNrDx0fWj084Iks6jsbXty76Al5497vnqN8OTD3OfsRfxwDmsIc1eKb
xJ0iMZiFOiEumsU6MR7nY3W5ut66EWVUsXomIqkJq0Ussp5LGi5okXVf9AIzyXqYJnigBTk2
eNohBkQidkoTDlxOn5qBDPPzDGgYA08nixC54pTUnfOZT79fQIUtoGPWpZnCXcab18s96meF
6XwtrVF9jNQE0kkEugi4CotJe5tYdRuoiBCv2hAyr4ywoyV7ZezY4d/t27x/8xuDL12+XjjV
b/xG38urt8DH4Z3LepeuH+tZ+OyW09zLRw/e/KByTP/HthUrf7LmlfsXNvxwTfrsxu5kxbR1
w6JVle+f3tz3zV/gSUtVevnvoCP1MG+hulmBcze4iVCEkGaxWDYYmwSb1Wa3FmGzFuBYN8ex
NrvNak9SOiasjbVbrEmDgwfeYaefMTFgF57yHBTZIjmnmQjPcYSA1DAJT4PEzIvJvJDMTGOX
6z0YI/QeV1cXbWMjJVse25gW3loouA/VnoUQki4GuwiuSAgghKvR0SnyQw/+SN7Sn+Uq/qTz
pR16I2nTv8229Q53DUrJSm+MfY3dHaucO/iibnl4wV+3edRInYBS6TWMIuYYs0Xr8E1lA+OR
2FQ2OB4mU1lhPGKbyhrHw/apbP14RJrKusfDDEy40ekHkUbtTEyK3fZRwjMnyG277c/xNbjd
iKvknCnVqIsiVBFVqnrDqw+53F+yTM6FnieCZEINz+Ovc79/eHdgJKqfjYwMDmyIGLojIwMD
IxE6H+AX//PXw/3xeN9a/pfD/bFY//CDhbU5xdM6N81ZkS3amD9oMT7aECVFEWxWxuq0Bq2s
lRjl9J4kkrlXkhJJzIz5ZJFMalamzWDc6rIELNZXbJPExJC5G++Z6rNkE+elPGDC2rvpJAdc
kXyo+dzn3eCWgNHcDVkHtpOK2uvLnkRJoW87ryduJci3EkcSRE3kEyRRhHc0R/gF+T1HOpAm
aan977uq279reWm6XCgUSjQtFFK48wV1eanwRcr5RaqMVhTDQo+equa/qhrUBGC+WTwRQhl7
nkWER7TRGcHumZ910Cm2jICN1dnRzlk/jvrdSVlKmGPCstb1q3YawfeRz+3virWmF223B7hw
rxL2x5Jj2eR29sytyq3dG6ONC5SN10eWHL22/BnP3crBsRNLUz0tuRtLD/0m5F34+o/dTgbm
9LkoSQt9yCp3LrQbLxjIV9aOXDEFM2qTAfMMpcAuvyZGY0xYbgabIyPKLQ1uzhp1vm0YsxbJ
Mxeb3o4jzWi2aDRiDsqqwwQmX4auezieymZO1WveWLZ+olnDWTMKQFrMSINpmekLS2qmCLsv
hdYsq5n4clmfdpbLqVKqnFrxWQFbix7Bsl7WS/Nxq+tfXJd7cBPHHcd3b63H2Xqc3jpJvtPD
epxl66y3ZAv7bBnZjg3CNi02qexMgyfOYGBMICRtwTSQkJKUxzTTJqWDoQN9MQMhQGzc0BIS
0rRAp/0jfU4aJjWZznSUzLRA0ykW3ZVsTPuH7vb2bkZ3u9/f9/v5LdpxeriM9XX+gM2h01My
uw9RuD7lfofggjqZwQUCNp8L6CnGBZeaJgLyOACTD3N8GdUtepMRUYploi/jPI5N31W9st4+
Eor0xv0ewaLTWWgvoxxIrIl1RP2BZqPOTOtoFZqiVn53LNueDYjpOmOtRxgvjd3LLXxe+uN4
tjPemJAcrvrVB9/5N/HwEOKop2XjoAmTVFBa0af8knJC+bT7JeX3lKeUih70SDP1kesz1z0X
et79ivuEe8b9C/fv3fJGa60vlmdH2S3sFHuQnWbPsAp2FtVKmoikYtoiV2jaGQpfASQDtca2
8lljqJzVusoZPwcuoVqQBkGkBw1Id154LBRKz1HvAwpeldSajBMGf9DQXjflhd5ZqJaMoJqm
IxEA8mGoDU+FqfAJmRnfmHE0Jci/JvD4guxoC9k9bBhB0nYVJhcJhyGpSvqxBewkC7fnmTvE
QIoElYrBW8QHe1/nB3tfD/SvH7qIy/7mWehMgdQwnmbxtAtPn9U78XWwMAkmC/BBgWB+KQcJ
qZ7luMWbZjbhaCEFZSmncVyuqHRhcPPmoWQ2mPpQI9QKDsZgDfmD8ZaBqcEJTq6mdTpj29p4
WpH3sd5aN3r20famWGPLSKrNZTNUa1QGm4WrF/lUQ2u6a/RPfkO1WfOFxvU/rY/wvMOP9zOF
TNRWvJ81wA5Sbxgz8ll4dUaVAXAKQUTWh31jSgd1ZDnpaVwXRx2kYcV2USzcLhbKy4OXIvLg
SxIW99J7Y6Hib4WDO78/vXPXseO7+EaFJi5wDUp1RDZ+cu8LJ04+t/dHwTpv5szO1T5384+/
0Yv9k8a9gkv2KVaXQmKNBqPlh/q5hrm0rCZtT1O8MyCoaqh6MAtLb0K/77CHDD+W6N0quEG1
TUWp5pAZ1OCZauVuHm7gt/EU/xaecsKPgQd5zweq0GHlLPJKdhyFAUGAykjIVK8VIC9ArZAX
qGkBCrPUTckXACIjUuI2dl1gnd+Wz2zJTGVQBoQBZCAFCGMcghCSR/WUNsEnqMQ23TpqHWJb
Dm6qEMc8Xh8sosmt84Q7li+3ZoBYbFvUGI7ghTufFgoMOdwpIzfpd5aaUuK0XosLRc3YaTGL
+EMoHtPXRSNVuOLxOssVikSUrHQUueKtKM5QRFk6o95ipn4FF/b37TRp+XW9q4fUm/dPPHIB
Sj/7K+yZXpWNTG1SjXT19aVMO/sWXlo70BX/4FtHRnfkV4Ru3IDjBb1PZdN177219w+w98RM
6dxb+/7Rl27V2VRNY6VXb7i79997BXZA01deK713ufS7XAzHz/r787KX0TsgBVaCfrhB6jEE
avQxPTnsQR/kP8kjn/m9PHVN82fN3zR3qCq/8jtJalj5Ey+UK3J9FoegycNcXpOoVgSBnJE7
5UheqAIwtzI9CwPn23wJRdUs5KRwdY0gSBomhvdM0Dl8oqKvW1ezUtBCHlNfxGrJ5YwKbZpP
30+j9JOXsaCIczCGGDlLRpUmBgCDZW8b9DYEQQ/siRjL+YpvGNmB1IHy1gVXFSdvv13OxGAB
jzO45jOYsrGZF9uK+vRkUCSD2xgrsGHMk60qOzsgzJ2GzC8JJmFzb890NqZYPtvZ0dneieQr
fJw37LX5pPhKDsRaky0crA05OWBvsnIwEu2MtXEok2rjIN/o4CAbcXAIEM+BDKGXCsHU4wgA
uGkq4FeDrkW3KAdBheFxAXqXDcZMHGYxFrBoLGZLOToUi0hLglohky9VK+bvlxfmTUce++aI
a3jmwMa1bcknrz765W0n4Zh9IN4icEq2zi02pwYgODw2EG5qfmrN8Wt/h1F3ym0LWnhY+ter
I71R93CSt8N/Xj/9muXYjnBd35r+ie7hi8dXPd4d5i2sQmPzhho5YU1iy7TPkliRuHnaxRzt
CRs9HUPPBMYmupq6OK79AMCK6rw/jy6hD4ENs2EYrr0I1HgnaSamIRtmxwObhA+gfLCDMGNn
wil7t12unn3oue3/81xGCcI+NSZrm92r0WpZXuBED2ZqLWsDUCkz2L2+cJXoET0C92CWNpdn
Bc5nMZkVgk9ZTdeIkswmRWFU6+E9lEdqMkiGNYZDht8YZAY2kqrAFRZOoVz4OEMyGVzwmQWd
JU0oYFEvyxe9/UNStQQxvmlVWtV6m1zD3CA/2/A+RpOp2vnuu5rM8ijcZMXaaqgP8W6jSa50
uZ1uSq7wNYYaQsEQkvMmDwfqlSIH3UaOgyG5wIElgCDq+XpZUwVYVpairJBK96fwJzEwYHvB
CrEkUUVDRCEmc4XyiGrQpcl2k33jr58Z2pffKG6JGqyf/Hbwa9kt/6nOifUWp6CAlGx1vJH1
6K0Ind0z3No/caj4bLLzqw3P9bf2j7wPg2Jyd+mjTYNa8+hu983RFzcYHSv6T1X/nLDFU6Uc
2oOu4ywi/aGBDtDBVLA7WCU6odN02qdVq2YRe06UQxxSnZIaqK5o1byaUqs9AiIzVi3N0xQ5
iPRB+jNaRr+g1fN6Sk9u1jCCU2gSkPC5WEt6w8rezcFm0ASPnL1MMm2yWMm1wmQ55gtFIC4U
7mbaiiKuZ4y8D6WcIWrWLHWCpJgq2PXgNkY0ypsdGe3Ijo6kBco27hrvSngdhmA2klx1febK
tSe+vaEVXR/JZkfIrxTcvPnt7V98flet2cq4VyXDHfn2Hefm9owee7zjCbIyZ0o5eA/dwCvj
ANvfvGW+a6TUOOtYIIc53DyYtIe4YxzFndKriOhVLB9TXVFL+KSmZ/ETOqRWWwFiEIUallYk
N3PIesxKWU/VzsEL8C+A9E0F7HEF/OVMkcEIy8zjfBcX7paJ//8+3vIQuyQTcG3nyH/prtbg
Jq4rfM/dp15oJRnZsoxlSWhtaY3kWpKFsbDWD2yJYGLqkkAb1ZiBYSYmAae0IWlKIJkQl1LM
pJRHf4SS0EKmRAbbgIA+Mh0eNTNMUv6EQjqdTmmakjEwHcbttFju2ZXx+E/0uOfsPVdHe8/e
c77v9La19faGF/HVschzy9O99fEK5kZvO861tfcWal967/bl1V296zJP/fH2Nq1PCsLv2C3M
bsKR9hEO+R1sU00MmwJgUioFqm1jvsESo+UCp+Jy1eGKERevtXdagUaSNqlg+5KUtGeEDMTh
tfltXJDt2PW4idldaIQM1f7l2ekRdpPQRQSyR02YkRlgpvCckKJMCaWMQBgWWXcPx5dwHM9y
RBB6KKAFBJ5hOYEShuchD2+qDobHOsljv2LgXKLhiHfLwbI81L6FpP+u9DlGrAy7pa4JTOtS
RIBG8e2wwv1AuoyyTBHnKnooowBCdQDYBcsLfyhIV32wCH4qdP1nIzP1LfXQ43HsaKYLHSxw
m0kbUFU5JOfhYoA5TE/CB5QZhEE6WMWUi2Uldok1OQMtSxNxmY2o1ppYJA/zzja+EYQ2Xx56
VUML8Ut4yHmTFs7mktIYRsCUdcqctUGp3RSpT9XT+svJYEohLdlWpS2r9ZKU3PMW0fRelV/x
Zb0vVSlua1DU0LfEvt8V3OKGIfe0m1a569wP3Iz7Ipwm7dRWTKFsduDu5ITWAyFj1gmPpjx6
hHmF6Dl1N6uksgibqClY+/QKqEOltKRJrllSk6wk1XJTdWMl6Ki3axcCXRYYys+2NkVEKyLW
TOIlHP5EfYM9MTcDdeqp90ba+qhAr21c9vz5vuVfTyqhBU7WIFkqvsYzFvcL+1zrN/Rn0ptW
9jSH5Xo3J5kCSwzzflbGSAVzIfevdzoXVSddDp/FVMaL85qXlq+olVe+uJuWvdoNVY2NmUS9
Wu+d32DkRUtne3V/eXjlq1q+Wsgjdg2bQeyKkxFVSlgTISqXOUpjJm0oz09/MWovjcVRqk5U
GqwNoU5rZ2i7sN03KAz6RKQtjG1EGjbkmcoR1mzBq3Nlw+ynSoVbMyjDCzWDp7oGr1RjdNhD
cuDOQYX2nO0Ge6yiPGHOWSzVuRpXwycHi3xUSxbkNEqya0LLGqQv0mONf04+0bQap6MCntAi
JGgRFPwNeti1N8bc8dUm1pWix767+PtX97W0PmtXxf3bG+MbPlxXV+lv/7YRTdsWv3b1x62t
a2xoenlJbEOuL6KZ2PT7Y/5vJFf1nTg9r2JF0CI+V/gmzvQkV6375Rmre0UIZ7SYLiCEvcH1
o8aR11TVScFAwMCASJ2UshzLcD1ASwAoi7nL3CG0BH/FAWUIy1LQrECMLMuTcgFcvJCH7lGv
Vk/mpHCyC9l3qkjm7I2YxFrKcnNzN4uE3Os1MOyN/3XTbdBdGCikuf7//oO59rgR72whEZk7
zFG8QxP5i2o/So7yp8gp/hK5xPPjMC7Q39DTxEwE+hNioe+oy80hYYynQRKCIM8cJ8f5McLI
/AFygGdc1CXKhDFQg0gTbMLYyXYar7DXhCtG4TAcFq5hVog84Y0kx3FMTi+YBpMl9hEWz36k
yv5RvT/BZtfI50wmQ06cXSGC2G/EFaphvwDCBvNMUc12TSHhRUqroeCMOoUxSen1PwsD+quj
vaM9045gOBAAiDIOrz4y+wpZOJn+8suph4W1cOLpBw9EuAHXCw2FqC6bCmGMjozR+fNMdPaq
8mJ2sTHNpo2H6CFxnL1uFGUqixTRXXBSp8hS0Uh47Tn51flGMWcwmHK8ivf/Ma7o328E46/B
QgD8hNWYvbYxFtj+YjisGIXt5ot0CdyeATbci7alyeyTPc5ubWAg60A3Dsarj9+B9wpr0/fu
UQlOFNY+ff8+c7QQLTTAdbihyytwU2Onw9N/F1YBFlRSSvyk5WxZptKcsWM6jlaSDI9yrNLk
znjzsHnEmpmP4jyTMbgW3vq4mIxTk1OTSAwfTUj4QfyCufjKfYUOqzv61i9b1tdHH+JQVDrW
6QrEdMOyZeuhr6j00SfK9DS2PIQ7LbipjCeUgIC4sgeOkeA5Kqsud0zGozFmsMZkCQvSWFqh
UHORHkGIrn2LaMRRiZMnPvjbsz4+hd2wkzSfoYH89M6RefGAxruttpguEbo1qVrK46cDEJAm
Na/KXK96qYmj3+7pv3IP+c/Qb/2M38vwBpFVK63y1Hmo6un27PQwHqQIi/R7C1zQvOgusnE8
Vcun7wvvcr0kRjrg3+rWTZ5tniHHYeaA5V3HkeDByHHLh45feE5E3k+ear3AXGRHPFdD42GH
xUIdhhLF5C/hQmwju9m82bGDfd38eskrnj3skHmv5UeOQd9hz5HQkfAHzb9SL6hXfePqbfYz
z63grcidpXdaPvd9oU76Kn356YejSLRqMAijBmOsdUYmZ2QEpboQlajoFIUqrygJTltplc8L
Q3AUhoEB1WSNefRcxT0LNtXmiNn0ORvYLoFMnETCgOIsPp2PzqFBkkDCxedF307vJ17q1eJt
tsa8ebpDXVUR9gs1MTHsdMb8Yow2PV/HtMWrDdabkv2mZLPawGrz2KitM01v4j/bY/DmVu9+
dFKeFqylnlJa2hzvqOuAjs60vdbV+eLZ4nFtW3POmvKkaKrrn1n3GWQ6a7FEZiPJqWwSISXb
9UjRGHN2IJLUsCU1ge8UllS8kCYmlGwSqaSizA5ZvcDiFz/SuJRMEp0DLEy21kSWBsJyixxS
ggrlk5FUgLTW4NC8qCkAqtIWmG1lFI0cKHorQwbQoT9M/X4b0vFmmoja/Ni9+G0lGi5pnW2U
8WIv4/dVyzQuJRq8iFlRBslDtd7j2CQdvuJCssax/uDGY1XhOjkaFGTZ8/KqKpvDnV56/G8h
uXnKWvnUD3f8fs+Z/M9/C8lXdsZ7TnKmQHTl0DNbX3hm76bV3IrC5u/tS0396f+MVwtsFMcZ
nn9mn/ad787n894e9p3PPvvOXozPeM/G2HAbnjbEkIJjQOGCokIgJBU2BSKbIGgLcUmQQ+iL
pgRoUClNKYaoBANplCaBluKEUqlIVZWiVigPWpdWos6D3Lr/7EEFRES1vLMz/97u/K/5/+/T
/dP7FmVbTm+2f/aDVL731cP2QsnVloEHXwfl7N8LRPvEE6VN4ZrePfa37LM71y57nteTWWNX
xAH2FoliHltgWFO3sm3a7uih6BntbPB9bVRTntS2+elK7Uk/fZSu9NMuf5dG4yokFVlRjDIZ
iOyVqZwRCAL+1BAkrIJIeZU+uSoi6/L4Kp/AAdyUfF9+fn5BAZSUJK1qsJLe5JYktZJHk7Qs
mUzSZGBzClKWXmLuSw2maOoxheC57yZbyH6s2vxAF7gKTBKa5olH4jRuBZymgqKAft+kgRw2
d3jvKAYdJ0YPZgWmRfYKZoOvuQ5RMk+JdJpnxnUEgliaM1fAe85JgPJJ6dLo1PQULMxMaglb
YVJa0lzWFIZ06eQwmxSdHAYn/IgMkcliD8rwP4hyftrYpOWAieTEGaslh4OaM1ZyIhsoyqEU
DgzjVZDDh8hupYA4YBcV7upsWWGWPXDs6/O7rfYNXR9uzPRc6n2o32rZOP/5C59vrC2Nj6+O
hWpNKx6vLKEroa02PC7mDcG1c0dmd2o/2tQ4c7Z5+Bundlz95vS2tun/ejkYPfTR27tKA6kf
j73x7bBmn5hU9N1VxaVNC5/FIjd2DV4UvLQY4z7OctM0sUlIBF2YM5O7EOEIwSOGTSGaigre
G5eFKLzYi2/9A/Yo/v/rLcX/8Z+UOOzpw/r4FXqB/QJxk0bqEDf5RuloiMoqCJGoXgJvEocK
uoYJ6G8Ga3D+amw4CJ4G4LwxT5jrCUDgk3iDzpeBkrm1VkA3n6sFT22kltZ2Jfu257BDBsOe
5Sg/ex214D2N97aRWwe92eE9AR4FHoQ7oHpj5T3k7NlVG5CViXll9c2LV7R19h20/3C3RHy8
vurAYr8qyVrGmv7oM+v6L933BQlHjwvRC4M3vbDOKvuUfhqi0UiJLqsCt3w41l4D6I1hbOKA
ZjrW6w2eOMQ/EeYG+NIPDR7Heg94PBEP9XQl15yEP5P/OeB6dmQ0gwPynOsj/LrDen+q0SEs
FU4lypEZbqt4D/n6lRskJor5ZcnJi5a3L9x4ECbcLaEXJuZMVdDUGSu2o6nTviAhQHbTi9Tv
2D77xCiSWww+Rn0GHtxhNPlWsAvRTssbND2BSIAG9GDfCznLnMjy1Lpp0JeFEq6te0yWZclV
arQsWj67qw8Tb/zEfQt9iir7lk6dtnzbuuf+codG0yzfZ1wl4Zbzb3q7kHuba+O4+nZtHA93
OO79cs++drcu9CLq0ulVldt0YVjfPhEeFJYikvOQcWTRaazGlQTx9yuuQc8pphMvq7TU4u6C
LQW0YLN/CF6yVL3bvcVN3ZsZX3nU8d36FoTrmz1NJZxseUevYxpcyXjxInUO0kM1b/dSNBC9
HddR02jFktbaakvCzBunaYWznNIqLG2tQSle9o6te6fU5MQ8m+tQyd+IA1iTVXLa2tgnrVco
BAs8ppobEG+oRKW9pJduF7bLkiqpitRNoIhIMkGALalytyAWCbIiiKqC6dJNoYgqMgXsJvwZ
w2cSUirCsFZIigKCIgmYOBLDPSlTYG++sDePB8X7Pi88CKULNU6ctOZ+Jceb8B68x4RHDTs3
yai0AkBTKa1E1P3wGrsX+pvtw9AJK8WBbFO2hZ6h5x7J7s7+kK5EpOizZ7ERcQkixaUOUhwg
ZzCX5h6nSPpo40n6ggMLj0l0eufi42RmgxiwjHEnSRp7FCIuM215feb8NKTTa9LX0mwMZ/LQ
2PljbYghetYaxpKUg3MLHZzL8Whrbhc4DVtJY24X8xb4vLnLxOn1moS7WHneJmiy3F6zSRoa
O8q/aWSWpEwCdv/YGfquuAozzbLCv2XAkLQMUlZEKWO4AVXZIK/jgzQrnKITqM4JS3YEW2jH
iOPXfnGC0b/J8RkSFKDvfj5lK3tLXPVZRjzAe8lHY1fYZfw+PrdK+ydAfxmAXAtFciEkqFIb
rKXNeFytIGMcKOoxk9+tZtVlMgjXWeMUCEIbLAahABUzlKryRMJCMqAkgolEgvlIwlhtlYuK
O+imKep2ufhXiktM515vOnerusBnyi7NRX/qOuH62MX4PO5iKnEpitWeUlb73KJAkkmWGILv
Hbfibpfbzd/zqGHTPbFOUliQUZWwIZZnlemWEg6GqcYCYV3RoZ7olj9g6np9cYlW+p9/B426
1vcQURqw7OGMr6EBx1DQ25HF+5m3vWcN8DUEvZdCHSMIOd659A6iUYMEvWfxMQ+yQXz8jWA6
1JHlMlw7ODRYh4vWEH74LP7G2xoKvofkEGX4DzhynCEFonK0kNc8BBs5PBmvaGpImU04NvJK
qBVrDvbkwCLKFth1DF7X7IcKR9beH++Y8EDr6oMjT6/xr9Dm0K9qneU7X/rgawuCy+L5W5/Y
1DElAH+jf62pnmfT9sqnKgYaH/n1/hvzvOHKeR/sfyWs1tt/3PGTfZvPYcRJhsj0frYXT+JT
v6JHiYRJ9B0U7bLCUpMwS9gNZwRBBR0S0EsEKpE8ckQU2RHqgLV8t/kGBfo44sGK42BVVJrA
5X5MXYz/TtgPv0dS0iWtudnZewwD2WrGQKyWRfiGadiTmTVj1oz2GZUADcxPiZ2BQ7OvXpVh
GM7bKRs/Q5ahOvMcDZdZ1RIUQxWsJ8IkYY7wfRgWBEbzRCLRI4yJRy7gzy1UijgaWQHgh8gD
Djm6zDWRuSYdyDJ6uCJGBhXJHQx+Inr8eCb87OdwwF6MOrC9tmmn4DwMcz+1ECLMwi4zmVy0
GvKMhGGMZ88kXk68ljifEFbHfhf7MMaUWHVscqw9JngkEohI3oDgikXkivJQLIJ96J+/LKex
iIQTa0GFJxYpqqgIe0J15mA1VF81q8rBXTJUGi4Fgt1QlvJqJ1YZWCVq3JYLXP+lvdpjmzqv
+PfdG18nvo6vHb/txMn14/pxje04dhzDtX0TkziBvChpICWBkAQaIC0khTImlaUTg74oj2lb
I22qVqGOtZ14hcZCdGwMjW7aH/1jYmiaqk5inZCWaX9E1dY1zs69zoNkTEKb5msff9+953yP
c757zu/3kKmsOmZbXyxgAXvYhm3WtwUsTNLxDcIHbOfLFilHdM4BUAYaBWgYtigjYml3giD9
tPNCZnZ2QCcl1qTEdfBAbQSNj+OJccxK9MbIxuHcxXXQMa/0XPG6IvwtlhgZDS8VSMC7+Bbh
8IsFW8bKFP6uMTUVTM2VzKFDuz89P/TtbHtTxury6WwZkeV15eQ78+5dmRK3W+k17SSOzZ/a
YXaVu92k1zhMHBv+/k8Pxvr4aJuZ5aoSGhNdYa6p5Y5I9akePN8InudQAj0UGaRkHFpltaMk
XCp5V3LnXqfHXV3tcmJwr8tldVc7XC4tVputHn8dY+HrOAPmNHnG5/VqtQxV7XBAJVeF91ks
1oBf9GDPQ6xBjBY8O6FOMLgaEzhQHgavW99O4iS4uCH5GBcPLPlYcrEWrqKU3fwAXIyLuUDy
tExIaiL1OlPcU8HVcjF9woGixrADA6nQ1TlwxAQCIgJkhC+yUWCha6LAFUlIHYSqeF9+4GHj
EJHEckggIIwhXTBtsmnGxvDA3a9zg+vvM/5goZLny6jCPCbtZo2+KtkfcJDi/Ku7bc5SCIjP
uJs4+uw7lycY7T9f6olUE253CWs3bIGbM3a72WfS6dT6jZE34D14vrCfPKdoR4fxBlEzlZpK
f5z6OH0/dT9NpfMLvxeDGn1GoQWRKNXbYnfxvdQXKfJV6kTqRPpkU0lTo5hJpygFvLRY3auU
sn65TiqcPxPXqbUZJRrtF0S4I4jQE7LtvcozcMgPCt8Qzgik0IYms59kiWy2LX4DaokGrOmK
jCZPXJtOqm77bVIjbLjgapOeHoBOy8TtrYM3iGuoi9SJlpELfUhlu530+1t0wdGaYD8X7I0G
21/Mk+zV0ZP9kvXE4O2WrdC42n6y9yZuRUfQb3GdVEO/eCARzLkHnwM1Kl4Q6nkBZeYWH4Tn
BLnBPwBmOi7okgMgZYjL80UJaEbOd1LZGMdFyAs0U5kmlkAvVADOC8TSvILmEpSSegSImswc
55XiDrQT4k+tfrIMVouDmldGhWFNxCkhVGlYn/KVtU76LdEUpLyOeoeBo5R0FZeK1qW7aE+F
vb4nXiuk/ZbwWZHmk+tNVaFMfW1p+r1QSMjw1ujrIt3TFIo0asQyf+z16qC3Sqi1m+hQOr5O
ESL+lNi/45tN4UBDNlomqJN8MOm2lilI3uxMdQejQiocfL+VVJRaPclAIK0RFRs2hoKh9MjX
DsX9HfUlXamAL6XJKFKXI9Hmxogteq6lRNvotvOBBoowVmqViU1w/vpwAV8kOwBhB2ZQG1Vu
NtsAOeuvlVnV5dI/K2V4vnOuY76zec/Gz1G4Yy1gxs1DQ80tQ0Nkx1BLsSnl97cKUwSwsiKL
+Mcyi6hoU6uekEXM/hcsojAlM5pVLAL4ZWGKvITj/5FfBtrcqqXF/c/8Epadmf3/88vCVG2R
TSqBTWb3vnb45O8a/+0OUqINC3eVdyDbk0gH2DiBugChHCEqRZUSmzHRwLQyRB5rRF3pCvLd
L2zbKXTfwMfRNlL3Id4o1DYIgTw+LtK1iCRLHAJdIQAeOD7N0JiuzZO6aair6qOQdWY01thR
OEE9N3EGHcLr0QjOXH2mNyR1N0E3jTNiZUzUGWOxyYZ4bDJeH8vEumJEVwzHRkrRJTJP3BLV
pfhSNzFIEESjplSydIOlBSxpjYRFNNYXf3Ja9rsEOWa1cxOzWviTIAjPS4QOLvmo8lBHOrQP
wgPzs9rZYimRGnOSlHC7zHUsUEk+VRx5yjMx/sI4QT1/8LmDBDU0vHt4cJik+rm9e57dM7qH
pIKe9s0dmwlKSG1IrU+RVD3ndLEugoLKYTaYSUrL2ax2a6WVpMRMY6YpQ1Ktbbm2ljaSojyc
x+vxeUjq8JZDLB7rBbFrYIRF+7aD6OQ3sTiZSLOoRuVmsV5nYVGVGkQ2CveaI/DUr4AH41uP
sPjg0wdYNLxjJ4v39O1n0eZ1XSxOxRtY7CqrZpGZqWCxtdzBokzdRha1hUF4lHAP8Y988KOd
AB8ISD/5K7dfhlQqMxl2CaBIh7LeXAQnUoY1yRBbPrVeDj+RlueJtEp+/dVTp8gr8/7O8+2X
J1+61vO9nFZjpjRMqZnWa1UmSq1WGmlibMu5ro8mnrvT9Z12PW1Q6MqVerUBvlQ5Q+lp4rtb
znf8Ymzio+4z3RVqo4JhlKBlUOkVjEZpUCkOfNmvuPDMxeErP//lj0Y/6I2Wm/x7f3Ms4zKq
VAZv7uJ0jtfT83t3XByZvvnhzNh7PRFVBTf+1g82e3U0beD6bryx1V1RFuq7MHLn8s1L+97v
DdN6z8i757Z7dLRK551493S3u0IFPFUr8VSlHXiqW+ap9/Ar+BXkuE5c9mGfNr/wl+lRHlDR
DYmw4uC3gLPyA3Gw8wM2+1K28y3abQW7mhkcSUwmziaAHf55JlHHBkSME0tst2i5dsbT+DX8
Q+QQNYRP1OpjPga1wozcozPyyzNSf1ie8U28DZ9AvFhJ4MEcjuTE3GTubO6T3Gc5CuXi0swE
0bAy9Xg8jh6z7ix+GmY3XwMWEsgXtNOtXozjy1aLFsRfZYtgcb0oDhZGsQw7aUMrIHV2WT3+
OP17qA48YxJVGHlY2gYO8awYLOnL+yrqv4kSsK/W6wTkKoJbUr1CEdme7ddR3AVD8HbReiuM
w2IgFAuLrBuExQ5Co4uFbfkF95XW4msz0RePP2ZFWRST9nwVO21SgKU9uFbvoXvhj4q/yRbR
xRj9CixqRBXBOHc5zzhJJ8ovfDUtBapmdXTXWt7Dd2H3RrDETqQa9RLYvcq7a/Wz8kyyfg3y
tYK+c5V+ZOEzxQVZv2FxZS+AfkC04KhoNMeiYmU1CLUuFqUd0sYiq85R8SStHeMe/jGssRnO
wCr1RZe7YpFAteTyyqholwan/8V2ucc2dd1x/JxzX/HzPnz9TOLrR5xEcWIHP+IGnPhCSuko
plMGJGG7EI21ZIDKsy0kE7RZO6ZVAgqlqFSoaA+oNimFENqAGKBuk6puqtAG09Sqgz9SRqea
vQLt1tnsd64NLdUsn3vvsXzP43d+v+/v85MyF1J4b+pCilxN3UmRlA2NQIFAZX0o+//W2Id/
BmuM6DLWOpOdZFcn7rS108Wl7gurzVmgkTY4qyhzHKLkFV29qmARSlwkaZzESxJvq1aRU7Te
4ehDFAohiRZCDVEk8TxnRbUqxj5s22QjJ2x4L2Q+StuhSIbedZvLk0E2yUZsYwrtu1VPRlOG
lRMKk1QKyl6FkZdeBO6F3dwGYjU2b8lD0QMJqpCvVY5mhfJFgQJAmsWTib6K0BtUEwuY4+X6
NTmo9UjEu4ZE4DEGu3KzbnKIOwBb6Tr1MIPxOUZDHDQGa7rIMwwEBb75OucX+l82E2bxqbLh
7076ULL0ySdQrBrYFW0Roi78u98Wb97qv8IdqIy/9w7eTvlNZReQV7mVyIf6pzCyOxDk+VOS
Zz//SygGHEjCGrIwbj3gQG+z7VXz5AL2CWe7w+8P3AzTGSk1ztLMPFtCyf9C5i1VOR82m64l
hGiEF6LNXRSuaTboIo9l8fcG5/8mHGytm8vuMoJqw4Nr2z2t3KDqfOIHq1oz4y/xdaFkU3WF
feRl9jqQTUC3oxMMDnDIz1a3OiPVSNUVdodVMl7eyV7/CbzTwsbJc0BDDjR0BjnufKY7/PUZ
dr9NqMOIHinToIOQQmcC100I1W1N4wdPi6zGEpY+CX5n/5qqNctG2QCgMOvVGYMCBkwIPpc2
64iWtMfcUd98YXLb1inLAv/6b29cx63fMzm5p6D30h38ik3hj7lBYO/QFL8bIQDvyUkA77P4
p3gPqk1CSfgrxL2iZ8WKHmjcoHmDBu6NnmP+Q1q4IzCaF7XqijLM8/Zh5B6+xGDGIg5bRs9g
HwyaLEkfGnAgpXTyK+N6I5CW6ZqhHMLLB0fHBlaMjQ4+UFya61pa5I6MDgyMjQ0MjBaLuZzZ
YAcvVnbij5Ad2HK5Lsk+iyPzqowl2WkjE8gCHqPbbXkrspJjyPYLJ1jyL28h7qizE/mVs/g0
fqG2R3CMMpCa9BEqJEszUpWdaUjEY2nBZAeBbzFRuTmKBxYk84XeziWHv7Mo2W7/mrU4N7NC
9uMk250KtlI7bGLD5J/cKPiFgDbcOzlA+l0c5kSkwV9oV94F0cFNiAIWtt87Xl3ijyE8IYLJ
tt/76ynir7t8Bt+orbZkzBgl6ZZ5Q0kD+kmjRCMYM1FXGBqemv36NuL8x6NbuNHKcTxEG9jq
8UqKLARLSWi77nuSPC09T3ZLB8lBiSeSy5dZT0YkYp/Gucm6t4VpRtM9yCoKmrBaYIRF1BNX
Y3BxRaTyIrm8GXE/k6su0S8r5/BfURjH8HJkhp1RvF2CtV43ijMGKsyWSqYxkRFL0xP2eL18
rd7AwYHVi5/qb0xFuuc9+WN58SO5LQ/gcMzhPmQcQPcpzLxTi0BhzoO6YCZ0v8qAWW++jr+k
MqV7KlMyZcbFpL25NHP13SV/u9X/R9aNd773TuWHqKrLnI1bguLoiq7ta8M/bzvaQTZ1vNBG
gkEtHAmHnEFNc9jCoZDdOk2uTDWSSKTxPLmCGpGHXEYRJJIrelOjG2g86LSx7rjmcLTaQ6rd
HrI7WrWQG6G4FD8aZ+LT+IyuAHwlSDxOPG5C6uK/R0fwNHlDVyKitVGMaBES6bX621HPoC/+
fDXAaVDPgnwVCnmlOymVoGfkoSiF726zgkCy4u0Gm8cFKZ/fDT/8mqmT8nVU4wwDBJYJZ2uQ
mxWyOZD15mg0G3ZT3ePdcs4tUNH3pCHocpwt/Xl/Rz7qd1jPnfP2zOsgl+Yv7LEwN24Empzr
njj4bjf+oBKLqWLIt6V8aNUrhN+Yi7W3z2kS11b+ffpbb1XUDXMd/KkPqV2bIRCCYFcfel/P
agGcDBQCewMnAhcD1wK8aEFW5NMsklXy8S5RJYokqoyMEacQFnEyIzZpVjMhck2axUyIapPm
ownRGVVEWbYqTEBF5FPQq7N6s/KpDPNYLVaRYLKv6pJtqioqSMbyPpHTOMK1ibVsabqvDO67
V8RIlEQijvnNzHjbgLxYMm6bJi/D3UyOydJsSe7GcjcoAnzBziJ8qvlyM75rP0iaKZo0qxaG
xPnGxo2J+RVnb726dWuiwC0pf7Zy2cryn75LM2jItwEvNpYZJPBYjiSAK9bducaGhTBwRZfJ
FVfRn0F9NR0ooUfrWd2zsYftmZMaAbDQvwRllEgW3pkhl7kD8CYIMObR1U6EwroLd+muxkyy
q9BFuuJO+mL3GXK49mKVBMPg9ylzzp7qnHgZzJmgrFT/VTZ116sIQOlN3XfHR3zqNJ49ScFo
iDIX+DezwVyBUVv7IYRQmo7jvzvn3XFUn9VGgct6zfN3D0l6sAcOecQcCwajyvla5SEchuxI
lfOhkzyw0M5JlgEJ3KnXY4F1Ajtb1hMGilqhwGLYAru+bvQwHN5s3jw1eslfNw+OdsoQBS45
LTPQXhsfHycvkvfLzZ+fJh+UYzBbFAbYAT6qAckH9W1r3SMNh9yHA9OdXCgSiq7tOOY9FuCC
z1ismTi9qPSSppc1TiHUiCIRe6hRiUQj1taoRbLolk2WZyyspS2UzrpcCmnLahqqsz6aiUYz
WcUXyIbEmBYjsV77ReGSQAR/hob5UhrPNM6XSreLfYNvooSUIInix0b9yUSxNCTToKcbkkq0
QddI5suAbHM6H/nGjpOr6vp26IvjaTUIPuglfGdyTjKVZPgveoQP+Ov9Df5GP8u3x9JqIoZT
9BIPwiXpDdFLGn5Ld/jbYiBVMLTJ02308+yz5jPISDpLBQI8PJpN39UQQCbFrToJKDnDAOW4
TCGBOJClluaW5mjHvIJovXjR29fdQYb/9dLps988cOFH+e+vxLij8gcsKQ2p40NP9+uPPxyL
hTwj+PxivO1/fFd5cBPXGX/vrVZaaXWsVivrlla3dVte2UbG4A1XOBouEwrUrtsSioFmQNAm
DZmkDpOEpglNpzNNaY7S0LQJDdQQuyBwOxCXtM0fAXrSf5oyg8NkhmhKMoZkEiz3eys7KW0T
e/T0dr3y6H3f97sGSsn4vFX16vkn332u32vWTU2+u7TesSZhsu18Gi/A7LO7syE6J0unxpkT
MCchVEQXT9hYg9EFXrAKduqbVqFk52BhGNZoNJhMBJnNFp7HjB4RE6tn9a5gwGxEbD4WkM1G
FulMPvBdJrxIJMQEZovEXCbelucJZkw+PTZhOeHTpxIOPq/avKqCFeCmGImpLS7VRVa6LriI
y9M6q9LoJNXi5ULfDWqaavDbTclZMxP0xQFjczOULdL79K2MhNdtBoHrsnbRVWPuDEglNiQ7
EskOEMsOl4FWmlDFBMnsoG41kTBE9Hqn4NI8HtQcmoIvfhS+tnina8WW5e+E/njy+MC5wQfP
besZGJuzNqywOTXuMC/IZudZHZG5unueKO+9Y1U0OKv9kc6vP1Uf/v3P6lN7Bi9959ieg4E7
e/9evH+ofrWns9wxZzVGYw+2ANJFQMtRLf10TSe0E5B+4iqPUREXVd5eKsarU1UtdhYaASjV
SGcVjXHs9UVMjd0Nn+9tfB5dAaaIqE5sK36r+GTxdPF8kUXFIuuE1FD8hK/aoN+QdHXPAVJz
qIz2qcX9ukO6n3NMf+dLxUPtDMoXeLNfDkiRSE4OxDVYOiLRgByIRaKFvM2EgWYSx6VyHgEr
wVb1xGMOKUYkrvSm3js7ZzOHzMScC/gf6KziDcfWUTHomoYkVV5KKhPguOBF4cAIbBf8UAWA
LtHkQA2iPhp1NpTU+bHiUi2YkVsD1VunXUORdpsEF5/cOPjMjr+9d7vkj8/KTPYUu2MeE+v0
xkF5j+TUKFw8sdkXu3129mu6oCdcHdw2smHuva2CKx73iXFxPXPPvW22pmjUI8alrY9PHlNK
S+7f+jiQNVQsWV+k8wJCIqiALqvpZ2Ivx0ZjzA/dPwqSAucoRBG26YFk7SG9YBDsegie+tdo
6jRosmuJhexUbU3R3FddbhhBQ+EU7kcO8qaaF0U7ir6P7otXQzJ4JN6gtwrQatXnLYozKdV8
wYItnpbllRmCE2bK2VBVmlQmKKNpC1xoGZSxCo3CAqnJiaw76IlnEoFEMp51p5I4EYQl7c0l
cbM/ngRb1SCqTOahh1BfXxxkuEn5z/AatrdTpEw3JwKUpJFTWwlqHzHgIVfLosmrWrbF3y4q
S9ZuPrTuC0e23jG/tWPtV9qjpXJC3XRbf/2FpW3uRIKEXRvZn2xs18UnX10sF/a89fB3r94f
8b6wu7zmnffWz/4+dTzN5C7d3eRt0K7icdTNqHTWwGpIEEkgGKrwhOrwlGhA1NLbeKYiXMlU
PgmJzbqFH42Stx+m/+tpdIO5qaO57IKaBEfEQCBkidHAMbzexOuNhGT1TJblGJTl+KxRzxOj
sTp1SfW7cyVjN8dIHPyJZWW4ZLv1PBSAN7JVxvmKnqBRxgnfkSdzhzm9ka+SuSNEfxvLwEa1
yBA9v8cRxMkc4ahhsjtLXJW8MWymKusRbmT6Ku4ur2fS3eWZ6IIVFbo8k3TjEWDZa81nMlZg
ONi4GzvMCZeES9pCjRMcFWMXxgaMkxi/D6ZjTW/9CF7TVz9c/2UvXlU/rFtXP4x7euH6cB9e
Ux+CmxAqoCZLyX4isQPIiyrD9pMlsIWBkQg+WeJ+gwMg5R5YRTL2irvkqZJfqFavF9vdnMfb
ZEQc5sBBjHgRiwD+G0fEQfCFv8YHkQ9t12IueD8QVZhMKsTA1Bo3Ay9fr93E16nWYrtEifZW
aNMxSsbxjw1sOBOszwuXJAtr5JrsfkXERXZg8rfzHGZRlk0G3jkPb843WaXQfXAON5yjDc7h
Q6Oq/DoBF3OSeVVizkp/li47LkvXEHvMcUw662AkhPkqI6q8yYQ5r+pb6SM+2jwnIkzgBJaG
nKedxFklu0YwrQ81SVZumZVFinfM5sM+hT2FN4IFzqhW0xjfgodA3Dr8q/c1zjtRm6xNVGrj
IFRwaBo0alq0AMMxTk8Ph1521N+z7Gh21YZ1o0iaOoccU+dmzVoPsaICvAdIo0RGa9BOYQYo
M2hK1KEQQ91+efWC0p3FtPxo78Dg5jP7l8RElsmT/eLVp1Rl4WrLpk07F8558aAYMenod7eR
x0gaatKM/qI6k+KLtmrzH5r/0Vxr1htEl0hEpBXCZjKpFqFkcnF4DCFLEHqpGqN7XNwy5MIu
en6LBVqMeZnFOyATVvEHvxIEWSBClfxJ9UmmsX7+AD/E/5P/F88WQPVbfHIC70jgBDypRlok
VdohHZB0BalbIpI3vd2Hbb7zPhKCYnpSF2jhruysgMDfqFChrwgTFaoKlcm+ir1cgPmpwWWt
BhWkRi1TGLcrjaDgaGuwvlYsrVYGWi9KSm2ldk1BoHTwwNDnXfm5yuc6UxuGv7j9y48ef35H
ayQbcTbxdxeSHduY6z6nlCg1d66wjvTP7il1f2PL82GX7EkYdSvKmfm7wIqjxVOvsW9oKAmi
TjxfDaLQ71rPKsyXlKPKmdYzyl9b32q9FpponVCMNg57Tt2CmhHvNLDUnIasA9Ggz+8fCgSl
QCDoNnqavF4R+YItaX8A231B1h+wzKBrGHnZNG2SMZWSk0O2HM7B3ROhTrW8skzKwD3HlaHS
6RIpjZJd4NvCTEA1h2RFkUNyuCU1lj6FMygGDbWjFtyilMc6FVsIhz7oQngUpphGuYPDs7fv
a2hzF7Rggo4vzLA2ssBDNaoxMMHwNgntGO+mQ03F5mP/RTFNY1x5L5vP7H3gLFBUA+J9/zXs
rTDsyvSwVz4D+2EcxZ8FBPzs/+UG5uWbcx5jzmJmGiatqVth8inc8WEf+9MPtziu/kAtLVht
vWtTZeGclw6KUYogndb3i9N9T6EsLqtu6G88lkqEI9F0IpzJJtPR5mQ2FfvUnqv/2/N0Ntsj
hyRZDmXTMgyAtyndDP3Kwhj8m/FqjY3iusL33plde3dtZvblJ/bMendmdnf26Z19+rFjHBtK
YhxkHpXCikhRK7eo8m5pKkFQDQlp1aQJ6SNqElAhbqQ+VBoItllDGlOiNH8a0SRt1YYI2sql
/cGmlYKiosTrnjtrG0MUWsmaGXn23HPnnu/7zvk6A+0hzyoOPJyIRcrA9Yq3q0tVhWAxEPD7
JGnej/0bFUVewYneCDIsBF7yh1TV71cohTnZ6xuQPF2S/B+Y0By4plpTZ8ITD9FqV+iA8BHM
BWDylh0ePCGjvNFeqll8zfst3+l/bxXdblwcK7U3HmAMN9EmBT1qLQpofyrcVeuh3haSsCfc
XjcMdelE8rMK/PonfYeZ+eoiPvTA5s3T1T+N/eEuNf34Yfybaq509GjpJq1k43Il/SiE0sDh
Y7rzJ9x1P5Edl/1kxo6Vet6tNVCv8yDn0FiHi+pjTIvGMwktmgYZyaW7s5l4MhcKBIMvqyGX
qoZymcxwOOIKhyO5TCSTDYfSgWhObQ+65Eg0F1RtgZDJOmrdbZ2wTlpZ0NdwJspFcITWqz0Z
j8Wy2UwxnU51JxLzKZzaqCXx7LIAz3gfXRHfdfVfaDSF0y8lc9ksUIKWtl2Ldw9o0VgsoT0D
TMYm6yyy8TZyCcS3jNXZW0KtW/jEGjHmOBemMjzqmnQdcZlcZXxBt8yDDh/r+fXTRgNbBO0t
gAgUSvQJJMAACX8nSqC51RQ52nsLKStA4al2FKIrIrGCj1W0UJ1gKVJMNahQhKCaqNPxs1T4
/5Ud3wmdk3eVenb9pxD0v9QfP3EnmDCMCoh5F3wT9CC99xcR/FTku4FjkR8H2P1dewP7IwcD
rMnCWZ0WwcqyoAIHvI43NeuBLkGICnlhVNgtTAiTwnGhXjhP/oYkJJEF3SZqQvM5reMA2B0o
8StOTOB2lglfDIWCF1U68ip2l6bDdL5RvCgI852480fdMqPEYghxjMAQpt/hcIbAVJTxlO6N
h8Jh3eHUwrqF08KWmIqCfJAE7w8+CFdZYV+2RM8zAHDkZ+y6FPulkldGFaIguQkGhzHCOJ3E
PeaqYYVxdVisVqnM2M/KY50dhE7aVCigF9A6V3pXym+UvbLAL/AV49GYe1Q12osBRAaClrHS
S0cl8CoFtWIMSPSlivnKdRgOC9SzABIKBXCBbq/rdtFIepMJQzig3HZvhID/sKegJ9i9sqyQ
trfeahnMhBd7wgO+dlvd/IXmwWyYeS1g7fvi5vj415+0e738oUPYc9/OhCxJrU5P06D1PmZw
XFOk6iOFfUO8DS++yz7x7OLOqe+sQ0tLaGzpL2ZfHSIyCsK51KE/42v4WdSur8MZvV3SMmr9
JhXjzBx5HtoDdU5JGjVSHWYum/ZA1OZaFHoNIdSl25mtuq1RO74Vb43ym1QGbz1HXkABHHqc
xhbUJMQGwGZ+YL4MsSEj9j2UxI+hFr0Bo4DX1qZjjnIZ8uULSWxEfLn6DdZjZEsZEe+j65At
dBrnKGp4HlCTO5IjYg7DX85dXro+Szedqzd2XCiVjFW2VifJ75nXYZUdsIoZvZ/AKDSLxUQs
QRLUszS1aPQ+bXFoCcfKIonaIqpaMtZY+qtpZ107rCEbO3kKv4NfRDBUc37BT/wdoK7TNEpe
Pa+CcV5blhaY3ab9EDdci0PPwRf4dR7ziqiQIwqOAj6JYoO0xgLSHD03Y4HCmsye1cxX8VWw
IJLehP1623ptwo93+yfoFtA4hKur+UsFdc0Ovr+6g6voNOwAdn5COVVLfHOaRgZvJU5CodDo
0gI7BEogIQ3v0hNF+6R7MliMfTtxNPFT/mRijj+fsBb5YlMxUIy/wD+nmtP1RR/26Tan5nuj
0yv4rGX8wTQ7BVJRxg/oWVtnWNZYmya3NbAmf3enz/vHDrK+jLkOoYN0dDT7kF9urus+zHE2
G9knSRwrsIQNtsMGL7yyK2nc7jVuuiuXFG1HbOR+W9F20MYYDcJ2jlxCKXjZ0LBOK6ZOpE6l
mFRHGdfPCDBZ6k4ax8Gr3zkx58TO1mTmUIu6hQ7kKni4v/MF9aMCPKuq4WzA5AB785U8NALq
9PhrVOKbDZeXXTF6i4ivYH5RBUoP7tP9gTjfpIaCIWJ2y9FILELMdinQFFZQnIdLyOVXcMTR
rSDaCCBPUA0CXwvIkAJjgmh2m5LmlU5Ae0Nz0pP0yApIQtKDaccwm92upmZoEGnmnb17zdB1
qw9vnBg+M75tfGZ8cLynehpvwebG+AA+Xv3n5j1SixTVws3+z29hj2775O2vuDwi6xn5wY7+
E4/+6of/2q8N3NzWy4nrg4vffNolHHvx9M9l5xMIL1VMs6zTnAVvIM4BZD6cZXCbCbWy5/D3
cCuip7bAX0PRkcV4jPG4PU5W/vg9c/Yx6NZnSZ7MM8PIhtrOoMfNTJk0zFhaG14dMo56pIKi
FRiXumsNj34l6UmPbEmlR0aY4RF6S6dGKGZ5hEynDG3yLWvTkzVtIgHd0aQFOOsmleDAHdq0
a+lD5oqhFvcsa9MZQHrbGYIHhPLSP6Y3KfBUk6W4IUs0U7XbdMo0vprpCrMdYpog0wSIkR3R
PNKynFA27qp2M1VDS2o5ruA54/cNBPdHEM3QZw2Ub63fDl9SMtirLLO3COxthd/rURzlhsdh
/e61mgGnPra0YHrTtAc1g+oN4ZAeLUpFtZgrbviZNCfN3HOT1JfkyeBkT2ngecmUro+mhzwi
SvEpEpsSUm94Bcq71qlOQaC8axGzcqhu8LDos+GL6LcNn3PglhRi73WX8bA+iHCC0zm7xulO
N1ya27UJDnPPtHCtQitpDYqxaDSdHhryeEZFzIt58aB4Sfy3aIqJulgUT4inRJNYJnG9kesX
+km/7m8dzmxfrnXhRqH01ZWeaPTHaglgf6N3sQLkyi/eqOR7gWE1JkFfZNbxMLL31riU2yCp
vX09fcQclPX8QJ6YZSmn9itogwSXvkBWwXll8HYuAZMK2LBWisGVGsJq/gp/BsHsmsEu5+3k
Yie+9iVzXZ25sUPt2fHQpu2PnKy++mmyWRpiG761lmTk7VD38W32+vo6+3/5Lv/Ypq4rjt97
bcfxj8SOf/slz+/Zz04cO/7tFwOxkwt0I6IEkq78WpclI6XN1ooExDYBE3TqqqqTtjAxUakD
lT/oflarUprUsGpE2zRt2irQyjZtE1AJ9kenIVY1QuVH7J17n+MYShvJT8+R7zv3fe85n/M9
X+pf9+QL+2eukA13//zJssPCMx7xgbID4iqQKweAuBLK4QDd/7R7suNl9yvCj70/E8ppoxyS
lacTusBzJnM+zi4udsmxy0SrURZRKGSVRUdICZmjisluoqZp03MmvSkm51Sn00FiqiShZvOW
vKLkVYdPUGVbRIqQSL91wXjRSIz+fGkHP7rRIgCxuNl+a2j9jnmUtCdJcuiD0fbZ5NCNnYC/
FNQ+h2OxZoUAj/F4Jv3oFw7MfrkZDm9jPOcKgNZe0pROZVLZlK5p5RtpEvzt/g6/6Nc39URy
rmQEZ9klHoBLyiuzSw7+l0v4YxEUtxe1A47H2B/wkt0DM3Ngmvig1eCZwDo73K5WAiev41yq
nWZvmx2sVKeS6BuwmRe4byLjH/1w7twTx85/t/j8FzFOVN7DdkdH9ic7v/kYfWowEpE9k/jX
G/F+5p7WjVTKF2Y+PDkGfau69OHGSuHxTrNt3yv4EWw4cbBHYuTprmT1dwyboMqjGhUAMgg5
wNng1V6gAsZZjSHw2y1AkFFOkEHtt+gd+G37LAmyFtUCE1rQyrETNDewDbyT/g7nSLTGkSJw
5PO0G6u0Q8yrVFbyNhVfUK+q5IJaVckR9bxKUuqUSpBqV4maYQZj8j5HBzYUSjTOPRJ0e90o
dwmDNZfAfIoX2Bl2Mm8zCWTrqjsEtiNwI4YW7ohSNWfzdc0RdVNLW75bKFdPc0PT9QCl45Dq
Jb5ui7auWoZ1bmrCTvbeGDvOkh9pC7gP4XE4DUvoTere5T/Ud6Lvp8XbxBCSRSEUyspirEwu
0Y6QIovdIaXYt0aX6yuu9qGSvTRdeq50qmQolfFZ6l21anVUiHUTf7PQvMxCDYRzGCOUs5WJ
ay5b+ovvpL9M3qCOrC0ngUPsV0L+fjqAeXmMgp1n5bG4eMN+6zrjGtCMsWxggA8KUD1tq8Em
eGE4gKL4dCI5dXXjv5zAbvYbY5O7jScuJHhvQfcqI1FzkxVItP3Jwa0HX/9t7u6mRF9YaLV4
WCK/1wf3NotP8Y/vffboV1Mag+ymBgZV/l4JR9ytId9Tum+xhNbu752aXN1q2nT6FNMYJgDd
a1zjKPoOdd0m4MpQAEUl0R6wR5uUsBRgTSXkD0siu1HCYSkKN9Sh1JtKFAVEc62vSKBnznZo
uY2EjygzCvDNrhDlUPdm6BAwJI0yo3VrUVOwqHWEuDYgfSbHgSVBtSZbl0qGuECGBlSfS66v
GPsDruS6h4gBQP7GREEfDpOQd0L3h10FfWQ5l3n98lzGGI9VL6E8bcGsSwt3WFr24DIZoJ7B
rqPoaISMo/EIGUbDEUIRjRA20o0uewTIcB0FjtcyHLT4dvUa8lILxgKeZjTwGuBZs4Ndy7Uk
gsd/mddEpjZdPA81EaBt+EhkJnI1okORSEcLxVhpsAqwDhy9vsCni5FaDV7k05gFp9g0JsHm
YSia5nWYWPH3vOK1mMF6zKv4BBDFQ814OVi0Hmwl1rF6rKvoA4gVm4dQHYF8ig9kDlcepaZT
JIVeZKjJNoTkzxiGmP8zCvCMLH/GZfwnfAqBO9eRVHAqSNLBm0FiD8pBEkTlqm8OMKgjcgOw
9qqcIRuBVm/z935Mew76BewlSE06cjNcDZMwrBa11UrDWKMuc+sfXGu1pvULoHXyDCE4tRxp
tomsf3xHufruW+m000nj7dS8JTOWIRnn2kHoPzvZuzwKp7yH72Ernyq/twfxqSxBO6R8gra0
5asweLg50uL3CbGyi2B9F1fBW38fxdku8g/u4q9vJfPhGOzibZrBGWd2km8B1fdwrLYHdiYv
gg4SdWCUsCfkRDqhT6BWdhTpxukOVn6t+r4+yFXorWXO30CFLurDJZY5JThLuLg9+VJGZm/Q
t0Lx2huMVK+TS/z9t2nvH2Yn4MRjvVO9pJeaHPneuJ4tzddDx/dyom+sOAxWqA8wrejaWVSo
LpzxCfkCyyAVwsoFWhguLBT0abgh+LLReI+I2CeL9lDIJIu2kCJdFoR7AVEKjQ0HxyFX3tFh
FIdPRuekFrtRiCKZ2G3NkbLOeIbmcb5M3qWWYGg+mfGhaSjuMo7RULPNJJmIqd9v92HZN+w7
6tP5ZLuEZWlYOiIdlfTSORxDPvLLM4U9OxixwM8W7fBh9IcRcRGc7KiGLuB+ZWlxFIbBG/+F
0RAgpt0AydhIiduUTmZAYMrzANfdK+DnwFfaNNp1KvezzmANy5sf6Rzb7V2/JrG0JsFBv+ul
/u3eTvzvr1CTodUt9RQ/10u37TVsqvzgyFTQcfc/K4DXe9aMHMdTH/9eDA/lW60GSzESXbt9
w/bDrKdWHOS4fgn5URr9hpot1vaxYWFcIAJTMsLVbH+zFfnLeB5Yone5dO4ywU0WdkRmSA/L
PtPuVkuA65vESaZvi9A+H6Wmtnz0CSfRlXEr9Rks81Yhi/V6ZDNIBmKIOT3uAy6Xk6NCDOVT
zgXnRafO6c9s1oaG0XhxyL7IZwUYGZgDvcG+LsZrUi9djzOx2TixWJf8j6ByW86tiZsteJmG
YPDBGbL+WVP2wTZSvnLF1mlfuyYwMr/zUJv54OHZdSeZpAZTXVP9UuXnE0vnR1LihGdhohQ6
jm8rO3934Lb7QT0Zj6CarbyaC7Vq3grVLLD+EcYoHPY300YjBCVIUKT6kd7Be24GvUpt0HOV
cL2ZZpjyTn9HT097oiz4m5R9wd2dllp3dbHuOmN7w3bedtNWtRlsJwShnSkui+F55Z+iv6PD
ZxMlkYixeDJxoKcnBTH92WWRGzW23+IK3xqt9eGl6ysCs4asyfsZ7fjThCe/ajQuG7YdfL0y
8knNH9Kg8ccPlZ0RJ11933DauA5UXsVV/hc+jV9DPmohGK3KdkuUYLUMGg+oKrQsxuiB6nV9
xnASVuzQVqBrwEc/tcKKnk53gGJCuut40vqDFkWoR7mMD0OPClEnwWOpqRSZgaZqDQDYCEmv
nOjehngH6/Eu83gCuGglAFk/x1eFGwLCmiDkTpaTuFTrR88AidUzwCnP/Z1gDnk9VivrRtYt
vjEfsfkkH/FBUU7Psq5U6wlu6AnP8j2M1sj+f6qrPbap64yfc+71ffh5r+N7bV8n8Su28wKH
XD+SYOKLKIE0DQJKiJFi2mqQEoEIpogU1qoPWEdHR9vRJrRUKv8U6FQmaEUJooNVRbRROy2D
rQiQtj5o2dR47CWY1OZm33Gg3ZL4+p7vOsfn/L7f+f2+72lYQ57O57n7zXfnUzwsS+fzDCsz
CrlJL88rhxSCFKyw4zP/mJ23WJqdubJS7tr3K72KN+FdqOYkBtfwoXFz57uwP1cABypJKKbv
es3sigrfr+gqOggrmmeEsEq9JqTiSXVGJUn1CZUMq6+rRGU2U+Pw/+BZJehTqFFW+qA/gnf4
0Y+MwJgFiyFPyKWEEMMI9f4aRBxSjUtgagjVmKDdlSIk4IyIflfkjtojD4a/5R7seVwD2pe2
lin1r8t6sonSP5cvT7cmpevS9TLlfVVYjs4l0TBQ/I5uV8rOaLSBfSvm69l0yJxatCY6vSBe
MNJrm0CFX9izJfTtF1vzsdiizczRgV7EoF6oecpwzh3IB3X2pGEIdt5HrkhX3VeqLimfqpd8
t9XbPuFV4VX7R2TC8qH9qosrkALbL/TbR/GohRMsOC7F/IbgSPn9iWg13ZoIg+pqqLOD42Tc
yCQT5xIkmcCJBOdMI8aT5sRIrCZZl4dSqM5b7a8xQloLyLsme3tFptAs94rWzWBpPSsKx5/U
1kAr07OycNzQApURgFHUpnP0bTqH8uV82d2eLBWni63JJhptygE2bWBtxSIq4RCSJRSO1JF0
yl3njRBZcuutblnCUVkH2AAxXY6mohGOY8J4AX7e3Gme/rN5+tgHuPvDX/7m1Ik3fz09FY8v
GVzfHYsdHFgYtWw0HzavwG/xHO5+/yLOH7/PPG+eNS+Z4ziDs+SZ736C/7m0o2Op6dyt5IFa
aBlCXB9wogZFoH/53BgWeMHGq7zm4302r+rVLscuJ27EbiTsY+oB7Sh/xHZEPapN8BdsF9QJ
zbrBtkFd798QHAxvSBzgx2xCP1+wFdTVWiHYHy4k1gmCRwiEUg56qa9N2xVl0o7tdrerRiLR
SDrA0YR4PUqK4xAwT5BRJCCRCNdYiHf6xpmkIRr2CNcpKtEAjE6FOqHVFTc3SLdKZZDaOymA
O226/HXF7nKUiBRroCO9KeaS0FrOa0GVw4iLMdoAZbJ1KJ1CMWgdoXOMcDwLpxlZVBWzsmQJ
g15LMfbt6dyjXdg8aU5hN+4lvVvI+eEeC+7A9eZfzHdxt7nFvIH9uGvvC+ZXsVgMd66VsH7s
LdzsXtERi2X6rOblU78yP3GuzbMNgvmQudNNzl/DYzyt4vpB63qYD5CGEuivp5F/5jNjGdT/
Nonz+ySvn62vxkIC8pUN9JM+tT8wqG5Xd7t3q3vi1gD8TwLKP7wN7YaZQvWNKbQWE/A14mJ5
eMrVxr28OM40GTX8oMPmqIvLNi2QYMIWggnrYlDjFvwkJpgi77TaUhiLQZcVz1ixlYZkuzNl
tTa4wkEoDo1JOOxUfCHoaauXbjUVy0XK4mKpTK9lr16Uve3Ac53aXzmv67Ku/9QyF8rVovNx
6TzvzFHCg1YgaPHCDMdX/E7nwPAS8KLEBzv08pCKCCdXOJ8lM9j9QCQktteusMRId3ogPnzj
9JefH1q5tS3Q3teeNhrm1/fMYY6YXYf60l0vnXhsYgKT336KO4Z+/NgbG/eax98/NvAHWitD
p3MJ1COCmtFhY2Pat8TX7+urZpeSxZbVXKF5kNvQPIK2c9urd1XvCp2J2hO+N/wkitpJv+th
14hrov6ydsMvRKHf8NbmHYccxCHHHTxuiBu1NhsKwFdE41ZrkyFS4S7N9cRZNm5MhnH4DmTh
tjkVyPQkqETprmDoSbm9vYjyGsBVThZhIFUEs4SKJZyI/1AhAEQUFcWjemsJEDQaqQNicjSg
t8opfHO0a94z+0cv5Bq6Vi7v11c99MSp17aZ35x725zGF/v7e+49yqwbaRvQV44MrGie9+Da
bDa1OrNs45c/nzSnvv0Y35+MjZ7/1z686t/gDQsBq15gZCf6ypAzzBJmLHsk+41yvR4OBwY7
++wd1ZfqGJ+ZNESPL4WlUF2KRg3NH4BRlQKnqaYmHPbHYzFLe0j/u050yqZ6uSql6+02mydu
4Rri7TaEVKq8QUEdbsEtLZlhJ3Y6BSEDH35Hi6Tou6GKvlQmYxCSU1VXIpggCWMyh3N3QM21
5SmoVFFBWikZm/QkyC2VXBki9KYivHrlYSUG962AOqBMW7AmVCriuv+BGSCHjgJ0toJsFuKK
ZxZ8xUNFGKq3//90Br9u/u7M1cP7s5lUluPW7ZvfFUi7bVkwuCrXvl80LSbcgubM/PcOfDJ1
AH+tj6/bt64r0aH7RU2zzTu7aZEF18dYfOliQ7XVEXI3tuTnLC+9/Mj9P6Pa0A3aAORG0EKg
ncace6TdElklrrGvF4fs28RH7QeZw6KgxHmbixAnR1x5KE6wr9FwVfIE6EGiWliDXc5uYeEn
4G4UJ2fPNkXP2qZR9O5ykYLWVNIAn2JrK8oDkHngIiriElbCbGW7oJSZujB/h3YABjvHPIq5
v539wvzuZezC2otPvbRn2eIe5sjU09de+xNeOPHiRw9OkWfe3P/7Y6MnaN1BgFu7YEcBtOOk
15vwEi8w55SspDweP5JgYadER0qS/BxP1x+wuVI8b7NY4IgxkoMPCgLDOBxKpTiC5zZRTQUC
NR4X1FnJkk5zXIIUUw7AdmSd7oIG8/qs41Lthyqc4WguZ5UH0p2Fg8UnOokeVsgSJ3Nfjz1G
nnrktKduz8ADoUjDjk2v4KvkjHnrnvjHY88evrn2ObMp53ruleAUZGi5eS97rKLeUfSesTLD
ZnxdbJdvDTfEDfl5odpX3Rjczm+37vXsDfKDzCA/JA/5dsgjykjtbf4/HrFD7pFXM6v5NXLB
x6EQDoWqqsSgwAeccY3YsFP8L+HVGtzEdYX33n3pYcla62XZsmVJlkQi2bItWQZLQbLNwwbL
vA1kYiMK1PjBw9CBksQGm4YpJTMBPwC3JbTpNKSFWAwQW7jTSdDESWibhKZpw4ROJz9SWqb1
dKY1HrBZueeubDftTFuttNq7u+c7955z7nfOIcvUZef5CyDZyaGpRI5Obx7KixgSdElEmekl
Hrd7wbIwfisjcodF7Jx72cWFEuNAh1LmPRASJ5rud0o+psKkOQlPSJUJYRugm04oM5yEgSv0
4F2NUYBd5yuDVMhxfHmA1GpAPvjOpS8fTv3yuQ3vP30kehoxB7/4zgfNZXZ9ahX6vha5f/Y2
sjJO853PUnvteOPBE+tS4q+P/X2ADjvR0XtXtv8IInp2IrWC0c6ehWqDp2ojKj5cwJQwmGI0
DGYSdHbETIctFOxZeIFjWYxRiZxnGJp6XbZqebZb83C+aYWDgrJqqqkJYpS36qVDyzhnPie/
tt7Vx0nFHJ/9I+MA1ndSDFTKPMVgqHvBVm7sxj9lOiEXXIxUj7Dvsfho5v4CfFS934J/UHy1
GKsjGr1fHcnO9etu+tWTNudNv3XSJrvpV03azTf9BZN2102/Z9JuLShQq1UJNH6dzh1GCTov
YjF5qGHTGzQv69PrfuWkEMrNNfe5NE7kfFT06Q5Yw1QTWF+TXgfUhV4RRg8nNOl7EicBMxG3
HIBEifSEawx6vQ4KMKhXgJEC5eV+kiJ5SJHkVqCCFNMup6scWTZu9UXzZcqi1CdanUKhyNGW
e3SO1G+KlDK4yWxfudm/vu2zkEIts9szOFPpVLUla1nqXmUub7fL1IoQWhxUqmSFYHzn7H3+
h1AL1lObqH3o25GWa63vtr3bTr+R/1prIp8+2T4kDLTSrcIR4aRAV2rqhOcEGkxbjYu2xWKe
lWP+6ou22rF6P3WxMDjmr3rRLphUHFoi+LTbYyWxY7HTMTqm0hu8hlegUaENDpVcJkOqfY0J
1AQJVaFwqBqGKyuropuGEaIonZYzDau4ptWlO2OOBC1EskuV1VWKTqMxx6ZN6koMSb2PatG0
4BapqAfWaLGdtiFbAr8Qse1xJz0l25OxR5szzRYzNsOu8ZttexobZUm5XKFobNycQIU3yqEU
XDeGVlAcoiLKaENDZWVm0BLEwQS6caN2pWl/ZwLHrlufBw+6GyZDUdhVxF+T4hJvaM53Gsjs
E+5OOE2CO5vgchKuGjTLdy27T4VD4SjchlwEV0SCpCKSjyAGpD84NcGZnKCPyloCXwgFXq0J
hVAT4WHy0VqhQDIYAxU+wSoFBqExrd2Zrg3y6YVKgbe7OJ4kKGe5wHEuO4kVg++r0cIKhoAU
SEggsUWQXD5DmtaLaaBFJ5Zd+l1VsaHBZ0VsoDjf1WooNNrVtpyztd5nSv7xbPj1w+u+bs6w
maxsobVo8TO7ytZ9/pOipxZlrxKHq81aY0Eluniqry62EU/I+Uy5OjdPbqt+KVKxrO6L9T4/
W782Gtix+sXUiF7mKE39or03YDEvPb/+hbojl4oyFjeXaU2RPQfQn6trUOrgjuVKiFBFiWU3
fWKf5SmZU3wT95/bc8qXKhMvVeQZMmTFr53tqPK6tpys212zsY7s8TXUBf4q3UFpYABMTzjC
YARLucDR6K/1wWCUCz4e393c0DO2Y3OS7ji0Lbar4/bpwZIix3kiP5TaQO9mg0ReC10CmMao
d7oEO5iTHzpzzlHsHTx9u2NXbNsh+tWXko07xnqizS3TS9lkfSj4n/qJLIjZAxXWcitMgdMu
SDwe54IgQXcAZFGJBLm9+dC/6zeWAwDks0CFhOJ0Dh1uTk/WW+w4p6kPhurZ5PTSluYorKUx
mdb+KmjfC3mWQvOqF5YPmY+3Oom3+avNI71rl3dN/6lr+drekeb0iDVJI2wucvcNXDl16spA
n7vIc2aQXA6eAfTzqU10Czsqoc8bZmFyrnKYLMkaAfQApAYuv/zy5YEzHoIlXfaxo82joKZ7
+n73sjW9o80wWrOsm83pBqWjkFPPiwNz6Jb/gw8+/S86Ur/HH4q+/6np0YWvATxqg663nZml
WKJLIIhtO5kL07PM7MyunbDWEYpiFewgZYVckXmbfU+FP8hGK2RZAvBSApVG8nNWy+1ARBpt
VlwQNIPYSsWhATPZ7IPWux/PsQVhCOk7xwbe6IToDZF+qOZIZDFsXFVevjkfcwzN0hzN0wyX
Ae0aJnWWzqjL1jFcrszSTZkU2m6UT+d0I50KTlKmeBo+PT2QKZqsdsFfsZT2leVjo0EPkep3
FdN2mxrznB5V9HAZVa98crjz46FqBXOMU5S1/3jLljf3ejgGb3hc883vnW3a+t3LPf6/wdZ6
9u7Svcc666JdgzsD4xRkAwfKZdoZt5S1ldTWiEYpg6xMKeQcy6gQFaYTtOMaE+bhb0QWVkag
JpHqFqjlUI4qAlaMaE1+ypSxHuizQfMlkOR9dydYQZwSpyaQkGVcAt/SEu1cIieHg1kxM7bw
c/eOw0Fq4iGKYvxMD2R0OUX5BIQEhxXOQ+hD9NGTEfw4dTz1Lfw85sXH4ol1mEeXU5tAvx29
zbTSJ8DLtddQGBz3jRGaYekwK9XJCnWWnwEfAveny0qYrNFo4tPTBY9NuUPkb9Idik6QykMk
XZreATZmWp9UHqNPHMOpUfQ+hBC2iSJ9h7tNGWAALvhK/0ZoGUhZj6+fud5Zs9LnyM/N8hoF
tYLhRZHX3vtDlWeRP1NRlyHTWtsgMllRxNfnkHzCfLvhKzNKtE+IHNvSSIUWc1ZxGom7/Wgi
jaRR1Cpl+gJAmn2ADewtPA7+oxAwEHtrehF7FxviJP7fEfvxPr5WegYcg96Ji/3yt6ZWk7V0
i/1sEuTI3tBbYbVsUmyP4/H4TBdbRnDFftoz9xxwBTvuEjvomjhAT39E5EFvErDZNDbU191x
PAg3y2a64ul50Z6550TeR3ue/BwPEHnm+Lx+eM7Py1sFCUFsJ3MEjJmu+VnMvyXBCGQegCP2
M8cBCRYjvSXZgE/r0s/Nlr1LVmSIE6h5S81hpaEka5E5DUqzmtcovaX811vzeNKbaUjyMoHF
sw/QFvYWfVzaP2mJBS9Invg0Lv42TmHiC/ovki/+yXrVADdxXOG3dyfJlKZghC0SCCDJlmog
MSNZ0oAwLiQm/JUANoMJAYNDoAkYJ9gWBSRCwA7+pcZ2amgHDAHToRREWgrJlNQplKQdl1KK
bRqYtANpGkrKNG1piP5Wfbt3Op9/mKGTyF7pbvfte99++713e4kVYxOnsFF5U/jGKLygv0F8
xXK+IDPik7G1Mjm6z4IXg1Gvsr98DxO2uItW3GVJoBnBizjmQIhSWaQO5Pgcp46vzMqrYTL7
EUqCEomeIP6gUMm904qoVyoLJthXsOCqXKoOhGauBVKAUMJDFcvbChIjN2NI2gnNkAiDgnsV
/j1nWJBtVSR8V2WFid7oCYnEuug4oRJJ0U1D3yIKso7rFXlmehmk6iVF0RwjBgc/i3oRDWNF
USZHzV4V+U6fi1AcJldlhXIojBW2e1ylgxMcsidPslMoERdG4sJ40h3bEjTMDLcHeQCpjCuJ
FHBVanlR9M1VwnkRLyhZcLvHUkYj3o7ESTeaKELCfOA64pYyEiejha/TJXqDkbi4kFYEY1sQ
yNAg8YsXInVBTQ4N1nKi5lEilzgvKBhZA3LO9cxI6JBcpRmKFrm05TohqnNEXMMQeZaRz1TY
epezGtssvIbzuZB106QyjBluRxFxnapZrOSUXWZCVtLrhFOW4AyDKgpRcRpV4mRFcerU9Fdw
qnM0OGVtJSvaQl3HtpBuRVxyxiGN4gWkFCUmyJnPM1nBmaglcjZHzyYqCk9ptrSeypPAmaJR
vu5PchoiUDUPRU0UGacSJ9lq5nzKsSKUwyR+xqocL1In06lUHJUdpUYlqg6vUUrhES9Evaz4
aGrfYK0O5frH6WR5oWgRE0NUYzA1DknMIWokYT2jMijmxTbjVDUcwyiH7KmjRm2OqBJVq4hS
U3ldVSSQ0GtvHxoV9GJZga9SnVhEUFmLpHpha0kGE8PDMlzOLpl7uRKKn/JsjyHfCaEIE7Aq
iugV18Wzju8Ew6hUSKGY++ZP3+TE07dYuq5qo7j3GGK8plkZjolIqYkNKE9mNiZ0acaEf/Q8
tbvVbGTVKlnoVgdHw2qapPg08F0z4lrZOdsKdhgPmeAED3ghB56Ap2AOvkXkwWJYCoXwHKyB
tVACpbAR34ecKdZ0pek014YH6Dd9CfvVgQD5N7b/BAKx4ezX72f3oUCAPoTtG4GA9Gf26/ez
+1CPdWjA3vv4CPX0GmYG2Mev+Q742SfwAP0wJX77K2B7C7wCO2An1ML3oAla4IfQCofgR3AM
gvAzOAO/gHY4D+9DB1yCK3AVrsNf4CP4BD6Ff8o75Rmg6b6C/sTu3M8+fQB71m8foBnu48f0
f9qv8ftD+M83Mcyvw238RrnnF5HWflaR/X1MLHxHB/DFZKGaRUei5IrkMTkMvw70Cxl4ABtF
bFoJ9b+WZebXiO3L2wM8Ho/H6nTdqNRsmAa5MAu+DQtgESyBZbASnocXoBhehnLYBAF4FSqh
GuphN7yO72L74CC0wVE4Dm/Cz+FteAd+BRfgt3ARLkMXfAAfwg34GP4Od+BfrBpZU5zaxkqs
y9qnOVMGataU9AH6TejE3qcZBrDTYb+nbx82MzaDq8e3Ea+tfdpA/h7UTtedID+coeHeH5D/
UXiWnrvecgipA9E9AdUG7YkPjZgM/QGNI+1d3z7dH2mNn9YE5G8/KQ+gD/W75xMKDHzTI6HQ
fYzR7UDm2m6N4oBAI4A0XTzJnlFGfO41iiej81lDkeB/tiEutLMxdpIwxL8gQjvdiqf2iQD6
s7paEADMBG+F94T3dLXhcvaeMzZ+Q9+hq2ZjgwQyVncsvEhXHZsQm8Dm4dhZ3Tp5TH82Njk2
WbcuXI6ees0jyUTfwaaFC4ROPPnDT6FasopheAirNhBHamrKcLBawJXldpssen3K8FSnw+3K
stmEtes7fZSePkOpr7Nk2Ymi7paWrqITYnhD5wbsI8KZ0isb5i4/ubylu7sFf9D3NmQgX+zE
VeLZiR2ZiKXH4Taxk6bm+zbm5ft8Ymd0gnDKl5+3kd2i/TiceVxip8NkfJYk5uJkcDqAoTFw
pHqrxcaQjpN2xH5ZcsVHhNNniOC7UrI0WNTVsqeriB+DGMTS0wzi6dJOhBhc0dLV1bIiuBxA
R/bEq/XNUgUiHIPPKw8+p5AFaVjKcEGyWtIEV9awNJNFElKGD5OcjrRhriwhDVlSQ5s118SD
S/OY9OxWSj1AHD85Sv/QdoRePnqMOA5W00hTA5Hq64nU0EQjdLslM9NinjhR+Jp8kUmTpj69
d++8HEfTyqJGqaKNXjzShnOPksy2I8TZtqyehnfV01hDAxHrdxF9PT3F55sVP/hLl6c1NKQV
rloFEnkL13WKr2skPomd/VclavbCrLkmqezCY8dV2CV3n1XkKwHJ+5ZMfhH7taOxaGWTI2fe
3r1P9wdNF/fHiPgKESfqY2jcbJihX4SnhBz+rpeaaiImkmpKNeHJVG8gBqLXG/BIarPZiZ3g
Nx5S3W4P8RD8VtTJwHJ9iq/NXd1aQCxZ9Oas0TaBzKdvGv3k0Un046LGtXNf2jufXnOSR6c/
OZieJPMHTc+lf51I0p7f96z11c+rd96trLxbVfO5fhENGnKeIqNc9Gbh7BXLct/ZTz90kEdm
Tvo6DZIFQ6Zm09tOMjr/8Iu5L7bmkzGT6N9mZCfNqrjHplehk3sVLKfu0lm6wbqP4GFkHohy
TmcHbIuNy9Upp5nYS9HiKNJBXV6aRX635r+7a7+orgrV0Bt3fDe2EuO588S49Qa5SNd76Sxy
xksad0TqqsI1taGqy/Sy2Lnp5ubz9A4xnt98cxPGL6Fh3U59PowAG8Y3GQ0i4dnChIkAMKKJ
ELuxV3jp3bRDk3bRHzTvqQmx0MR5fV4B+U7skxFjNRD0+UNjq4cIuTGYQ3dXhWoRwAfEMVIU
6T1X7HQvGFjlJmMW66VLeBYEBCDJmWK32UcLJpPZ43Db9XLmeHA73W7B/Mg6kjJ72zMLZ7oz
yZzD1YboLcNbHdJjlXnPbB/7WMfE2U9Il9b9OLIzt3DbpHFLm44/Nyg9/WpXYeH2JbO9eUfc
edtZTA8mdRLGRMWbzR7m15WViIPEm2zyL2Ix4KAzkb6IKpUJT5odPZnU5l6whmQHl5a90bx8
yppxD+/fWH4wNz95pGVV08GXp1Y6rFnSkmenHrRYLc7frB86xr/hDV9ZqzN3Zkbpvn0lBUXf
1CXtK/vuoWxnekHr29kZYxBVTvyW9CqiGoXobCyYAgMjqigM+CcUjSlt2zTq8Yzm9cULsm1j
p+StK25Z/MrhOd4RvkvXDoyfUT6l5PvzJpe+5F3QvHrpuQOXKl9A79+K3xK70Xsy4xldMlc8
iB2d/4/tqg9qKrvi99zHI4GE5IUAISF8JSFAAiRAniFCwtsd16KAQmwVWzJQP6ottYu0FRUV
dv8QZ62rjtPqOm3VrorrR8V1kbDrDn6s7c7OtDC77a6rHRcdqs50UnXKWMclSc97waDdzczL
S9675/zO+Z1zzzmXJi1//TetC0/s8Gc5mjcafrf60IaEsf1nPl6zaOLCHtcrGw+ZL//8779H
LQXRm8xNdgmeoHAvipZhzmDXd6Ees1mT9hyHcNd62r24ptS10lO1YLlR+G3rut4DPYva2SWq
NI/trR+tsc9r0+dNf7ipv7ln1Y93l4lx+V60j61gH0jaC57XlqHTsC9opxmMsXZ/27rXD24u
8r4SPhNXn/DfJ1+f3rLNv3Xlqr2qbPq3kemLm/qbelaKCNEoKcYut4ttwJwvQQwZKaVvEUKs
Q+CogIrkIHwspNbZCUmG9uTO5IlkJrn+Xp0d7IH1vD3Ao7wtMp+5jh3UShok+Ua4ifIeQcPQ
V+vgbN1o3Xgdo66DOl2QZgvpKEvydL263TqG6Dgd1S3eL6kL8Kgv0MXzok0HsJt/l+1AnRck
nc00G3X6BTPk+SZ8lPg6fXt8g75Lvoe+xCZfH/655Bv3sZwPfOogzRN0aDGndqoFdae6T81y
6jx1r5pRzwtGw+fixgfWd/HI8J/op1SBWMmkYgSb/mZBxwKU0P5aebu8U/5QnkDknJzKDcog
HD23K9O+iHscCDSGJ0ltqNypNWvnzGyLx04Wtix1eufRT2Hb7l9V26u2oCeonQmJnsAu0RPY
BXfQk5whaFeCEoJwR1CgrW04smRclywTWSUJxB39c2I3yjHEQpzEC6yQVw/19KT1pO1YyTHn
+9YR21DJkDMZLT5LmTSK1yiYiYokMKmEZdKJCR4IWk4uyKkg75Mflg/Kx+UT8kR5EHqEVEON
ijCMii2oIeVceWc5Ux6krnfdQIOMRkh119hTOAaYs4QUfVX2oIyWBelfhl1ffDX3wVw6F38L
6YuLoMhQi9BUkXCcdY5rJjRUI75JOasbxaB2jOdM5NAcfDKk0PvOSLRNNYa7HgfCXVMhfarH
kRkSiRQfhbuIxuOAUAAZfVyDD0O1NVwNF54KrA9PTXKhfrbMvpX7qNwJAQAzgO65TfCsClnN
JhlWZZ3Y1tjnZgvdbIcutLIrpr3bmSvh7TrnXv+2wYs7OrZWFpVUyVhThkVvbapssgg08sYH
wzt3Bkd2eh1eu9dp0rMdT1vZo+F/a1pbLh86MdbxcnGlZ6HDUuD55emO+aY11wZOXL329rFP
XBunj7RufHqsslDsZIboJL2F0TNiBt8RXkpi9AxNAj0UA5NNcqwpyhSrwggkhxqyjAoDVeDu
vmpUpBmNipzsXEWKPMdEFCypNBpZXZpWy5mC8C/BxgJ3VqcwXiG5f3TIa+VULc/FvLxn1V5p
SxtNG0tj0gxF1uxspTIlCBYh20DBkJUF3xEI5JFRMiYOzRzapi/0r5TCgRugcUpkGrmWblJA
QuKLEBfCYNSGME41GvyaTPXgDTTSrV9VZu9Xbf1IjZ9yJwlAQOvWPNsFOHhIfLsrY1HiZSCO
GVJ4DP0wvG711oqCIzWlJf70CtPbr3btXwldHzryS4wF0LAX/jk1tLn9hx3NVyNvvOZvXj2w
7w8Hu9bC2D9OL/CWVr8vMjt7OpDFzgdanHGlM0IDkykdFVZN32cycV+3wq9pD/Oe6DbOEhra
E77NvBe+TXNRy+w7Wewti5rEFfBZZBP0x9Y1RKRuPDvp/9+c/8Jk/+I8L1raCNvpDuYKURCd
JPltOWmFju7jAxu6B45vbNncs2xZTw9zZaB7w4kT+KhB+o8XVhEO+99gYj+dg9UAJxNyHd6E
I8QoqKlQBKSoUM0JVI1bMoi1uzbAQ6wyt0b/w9xKuItS82JS5BjWngwhmaYJtVmY7CCM0IOk
mGDdEdc3R2+zy2T1uF6af8jncBGC4nogNkwsAcA2ggDx9Yuik0wbuw/Xzxc7KPm8l5BMrKHR
vw4XFygUuL74m/oTn8T134DzcJhkiRKfCcllRSKEGtfGvZB6QQylZQYFpQhW0hjOzeHSQgnH
9gJOMebIU4mtohm2liJbNsEIebyTp3n8Hn6Qv8RP8CzGMd+GoDzws9StF3UsRtSAxF2d5Nv1
9THmiMXMEWTO8k1EWWoc8UtEHCDl58ATjF46n6RwSXeVVroLSm26i3gqRWSYE2cUP5K/EjLb
EUf+cssMcpFJQi74Fl+fxJFvIPJhUiIoIK96T/V49UR1QrWIqVJxLlLNS95WQVXc21imxDBb
ZjBFjnEgl/Jr0HbJRonNIkEXxqElqSXRiUSLzIVStpl8eSTxnAydnj4P7fNAzF19FrrL2+3o
rmfW3RjPjTg93JRyaGFMBzmJyMXDjNoPe/zgRwXvKpSuYPTRsH8RlAgM+ONGiCrIMzskDmwz
HIwjB+ZhOOQd9Y55mWD0lpDsdYsGqOfC3Oc2CYlb0BK34AY5FdslDFnaVCJDxCWzjGM9WBLp
TbTgvMOTaUFYm7/WfEDFyFRyLkOl55Zza8zdqm7zfs2w6mL2NdUnXIorUaGANiKrSXRZSy28
0lGSPVoKpaWppFyZZAxCmvCyPjYIvaMvz+VTGYWQlOpSyE4xh5OAS9K4iPQFiqQEpbJSrc82
ZmcJWZ1lUNZa2YuKTIW+pMogTAhKt+AGtXu3+6GbcYu8J6WoXabGJPXP5nBT9c0tg32G5SGk
jHtc728ZFAxZ4oPwZICbDNQYuFBIrPO6SrvdEZp02LH6T+KrUC1WfkcA20NY4/E4QlykwlHu
rBJrPivDipZv5rGKmd0WouFIPs6kWNbclRqz1WI2UQ2XX+HW4BnJbObz01U0XZPINGm3RO5W
n/rB8sjdSDu8Aw2rt/7k+6lec0GBEHl0+NYXcGHFTzXzeTPdt8Cr/zo3J6PnvCOhY36vArZh
8yyFU5nFphUR0+WxyNHIrfCuYjAsKLcXFCTkehZE7v4C56ZYND8gWlKD9cIPbwqt97T3s+6/
9D+qqz+2ieuOv/fOd7bjYJ/tS+LYyfnsO/9IzsYmPhsnduIXIHEIKrPW0HaAl1BGV6lTm0Rb
J3Uw0Xb9MTaJDjpg3VBBm0QnTUq6qCwtqoraTfw5/lmBVRWZlK0dIpRKGZ06cPZ9Z4cE6/z9
vvO9H+f3/bzP9/P9yv2V9799wk/9L/f+yn+u90/+d3uvBq4Ofua22zK+TJc/nopnNsfzqXJ8
JGW3ettJuzfGWax9TaWmQX4bP6yMCS/ljuXeyXE4iCbth+3EjuwgNt+gALpmLg1yjmt2eZ7x
EE9PtJxTCh1lGo0ZZSoHwbT4jHQZlxkLeHxGeZ6z0LYoBR6IRpNbTnZ0FB6KJl1tNLXJaJvn
Omi3pPefLFhHKj2jaSXXrbZJQ63T7UoFV0Zo9/SGITzU4wi241Q7bp/nBOrOj1IgmdGRdDqv
spY6z/E0TA2dUEypPU/jXUaeqhHDlX8mfzTPVfKX8yT/w4ch10/p+io4ppb9SzoIATD3qlPr
f62KNz29LPezr7sX0LG8pJvygH11gBWwV+MxTk1lMqlqyp1JoZLZWmLSbQpNVatV3AK5DzCy
pt2yBg61qKs1rspyY2azmWcbRW7jCyOs5kPImyK3LoWSx886LU0tcqpva35wF87iwtzer38s
9OVIYuAHz8/8Yf+d2x/987cvfFr7z2+qO7aMvLRl9MPvfuvg6RfPvchf6Oj9np93lMKRbY8N
vVcLPv3I99+Y5Uih65tEO/jwkbf2PfpknE6e3vvI4qn3Bl6YXXn2Tdzxvy/T2VxlZCgXB+6A
ukiQzIypNxjw0mrG3D7k7gHC2/5AxoQMZsmb/Xc02G4R+vvpBox64NoYs8GQnvtDgKBIfQ2o
zwqohD3U0e7rkA3RF5CNDfMrn88FNYMHT4PQkBVd2agUlGxnEdS5kxBrf9yVDCZLSS7JCEEB
ZCST2VZvk7VTshE1msl10kjWFnFJQWkG9OM8uUZ7XJsG9AHZHghAFRv2b3LJGK5xGcuHBtHg
xCChg5XBM4OzgxYD2UX7GTtnZ8PanZv6Nw4U7ITYsmEOFTBclQIuHKIgKqemi8vFnlQDUaA2
F5erRcZE8GRxuQhIWUdJjceoVPTfKxaLpSKzDGXTS9CxyG7FxaVFABViOdOrZjMNigHwWEPr
2pkWFcRoaybTEsoCVnJZEHoP3DPld2NuDvePJclfkruKGH8K7QT5cwLaf5wThwYS94oJSr21
kHuoP3mvkKTUg4fxdUt5bHg4EhnZVrdjd8+Ob05GIt2Fb+Pf1fautrnx2mm8n2lIM+4QwyQ+
TwcsNsmm2TbbLvFX+H/x1iabzxa3XbFYyvwdCyHReeyKBWMkFksIokOTtICmaYrT7XTLoaDS
5J/H41T8wrJiIaIlbSEWdqotLLreXNGwWHxPCFY9mEAz4gciEefJJ3QUikPJqVJHd5NLwqKk
mKUC7c9KdKhsSHQrNHr7oJHNgUlvAqMnwcTiYMIaGGAwiYpuQ5rHF6iYCqZmUySVmgRDB7Ip
xmkw3vQwhelhFtMnNtY9zGV6mMn0QHxQG/6dKsgS6NbssaOJmQRJ0CaXkVDU+G0Np7SL2mWN
01jnzX2G6YEcmX+nUzO0nRvFOzoTAMW7Rb1aXENWcVFvfABfy/raBwhtXdrz3wQsQeYzq5xM
Stenp5ZKDGgNcJlVTxWwxgqcKSg8Qy0hNyOt1haAUBsAiMHJrGvW3ZtQjGVD+CMs1m6/8rMn
npPDW2vRXCzas2tHuFCLlqIHDpDQFnzI8uux2uevP/f8a7XjB/psmmbrfxyffWHnwZrjOwW4
FXqf5A6OVQxbBNU1Hrkl/BtYI2GyxhWUx0frLJNUHX6gjOh6lln5GPpX+d3Q/2+mgrzyIUIy
dWNFnpAnZQ7JkgPDoLYH1Vx9lVfur3IV9YKa89FmDAUPW8WlYnVNmsM6n7B1TI1cX+fqJYQe
gnVeky5L5LK0IBEkiRKRTO0rGqaXWuu+M2x62tylG0jyNiN4IWlN2ZkBm87e//emtq6/1zV4
r3NMm+LrsS9iBMVC5hZo97eA6cqVWzBqh6mi6+92Dd4t/jb2mRm41fCZaythA/k85tot69Zm
Ki9R6yFfwontQlep/VQzxmnI2zobFQ50Ggs6ntQv6iStU31cP6zPwo0gdLr4IE943taAOPM0
BP/c5lIVSXGGlRYl0OnvDJC4qxM5bXxFmBCIYGq1Vp8hCFBiOthdzNtmOI5ROLcd8bA6INkD
zvCChNMSlSali5JlHAyR+rtNAl1eQ/8y40nI4ZkU5F29mkGMPAHWAGm4Sjo8qNaT8TTsb8jM
oW2NNLtKkcYagQotDbrEb4/+/OXOR6cmz52oXWccKAIbAmMCMzJe7C/vfD1UPr7vSMVkvYOr
/Hf3J6wFgUAx2E2dfwo5UBeO0LZTPryB7WerDTbHE3S5g27idkuNbTNx4WOAcQU1NaLJmj8e
CDb7m8JBVTB3y23kjBkBCxRhd8UzAZJrdQ89nvbm5jaz4IE9bDtGXU7sdEZku8mQMMxO7VxX
XKWRbtmu+lWZ1Rd9WebmFNUwPQxkniaSaWNWxkdljGRRJvKPuqle0UlQn9DPQMQtKb2kHzVD
v6ALsKUQDaamdP3uWkT8N9ekN6OUqQeis1QFEcViZAZoLT4QHLymj3LeBwKlNqgHeMakHqzS
PXtoac/effUgPf37ExeGu7uH8avx7fxTuyndvZtueezrX9aj9Iv9ECVrboKE9+WskXuBfQ2O
aV35B7dsKpNkQ8n0gjJhtZyYxt9IH06TtHlk7E4DpRPRJjgy6QdqOURWLtWGyQn+OBJQFH1G
HSiOjzgvxhfiXNxkALfRNL9y+zxEaYTD3PsgowUuCODgQUPHQlpHJBgVPDf8J5tdHAfT41tv
vcnP8ETk/8pf5znKV+BssXcIOF0GT1MZMNuGwZSyPD8ZPRydjXLR9/EtpCCYAEmwZHsIwMRZ
z9MO3XbDrrDBIuAKKRgpovKBsqBYlHfJxyjGDtJ9Gbzor+lL4s0qSwssMVSfXaq296aQr7QE
yQJqouJdJj6qjDinsFeNWVUvdktCI1qZ//Nd7rFNXXccP+dcv1/32s51bpw4dmxfO/gRJ/a1
c6GOc0kBUVhTLzwUyiwor63dKKRrYSCyIFoV1laFtSrVtIplXSXYJnUwCoR/tox2K5s0NZvW
dmjrxIa7qdJ4SE27/UFu9jvHlzw2aZGT61yf3zm+5/x+39/3kxebrMyoFpVkgvP20qPCv5oa
un17aAq7Mif3H9jft2QIk6Wq3WLGnavNL+vHrl7F39Cb7qrPjz++7YH0wGanINpWPijWlmMv
GVCW9ZpkOKMuIM+q+QtwRl30jPAtDKKGYnBG1crWCqlWcIU+oqO5VUGVSsCilVHOOByIXqGP
mZ5l0YONaFSHaM8ljJYW4qKWo2Op8q0Gr/Icdxpl8Jc0aaPrpIus8uBdzn3O19yveV6VTjsv
Oa1ROEgtaSXYqsF+Wq3jfuz3SwTjVUFXUzDocvNuZ5bv40kfj/kJbqm2UmppkqQWF3HjYIvE
25rsCGxNZ2s8Fo/YLalk2Npp8UeaGh7H5bJIba6AtKRlk2R5wfUt6buuH0qXJTOI9p3zQFIu
urof8ghmcpu8QRfBe2zYZvMaboFeL2V6FK+3awmr5KDTrbTHgp2RWEzDwZR9MjYVI1qsGiMx
I4ReL4DBiA1mqbEYqRnJMFMOCnfLYCSoSWX1ySCneSndVsQcg2BY1IbI0s+OerrgU9uo8M5R
U5eU9sAb7C1IuVo+l6aJo1IBxt5eoBcoYtFisVr9gYaJgDucVTQchVHlMAD/8tqOr+E3tIcP
7/rz032KHupLXS5HV+ihXdEV+MaKKPlI//T9bcU+RzxuKo3u0H82WTbLMk6IFczfd2bHMpss
23eSNdupt7CrNBsS+pjZzbIhZ+TSBsgG6RxmZe6ADUPd3QRrCZZC1B+k9TESZxEP0Y6Kb0Hy
+TUnPtGKUWsrOAovHVpjuRaC2V9lY3uM2V9kmWqHxipkTmS4DNVdF69MzP7zQibT6tGijVRl
0asgU3u5tyH6iwsyNXgOl2iUww1Rf7tQKoEIZRrfjvbr2b+ar0CHUdC/tGynqWR7wcT1cptD
u0NcFW/D+/BT1qetdfwZtoYjmUgiGym0t11Bv0ekrSFrTgW1ES4fKhCe3njA4VR4UbO7FJEX
7fZ4MqQlbC4X7xv3nfVN+kw+X7jlQbsGPWi4VEhEM0gW5HH5rDwpmzUZC3JV3iqfoP/JNMFg
N2UKSYISrtihsOBVzeDMaJE18LlUq1OxEabLwucLvepNLzjRQg71Aw71086Ro02jUEjXcgWh
LjAQYhbVB/bUJwrongwFRCpChk3l/ouEjDZPek59cuz66/rHv9n+zZW9lftTcvue3ZPfmacd
1unNpipu/Yl+/k96XX/00EOlwY2Vrv5Vz5N91yf0N2cyc7xzqNHvMVqrr+I+5N4GqD12/n0v
Vui5rS2KE7PXtaTdrVQVLImd4peDnDn4QfDvwc+Dpmg0lWjjcdwRt5isYYsDAeecn/JiqOUL
ml8qeg/wPbv8VmfcE9Z4SzicoKe0uqUVnkMCsMliIRvJvgegC2CTpWCTBbDJUrDJUrDJUrDJ
UrDJUrDJUrDJUrDJUrDJMrBRwspZheSUvQpRAGwUA2wUA2wUA2wUA2wUA2wUA2wUw74wGJPg
yE0xAaccdt4Su+PAOcekY8rBOQy9cRhA4zCAxjFYMIBmgXmYZ5n/CzOUX1h+3KxDe5pOM5Kh
fg8+uGf20AhexC1UVu7hzP82LiNn8NW4qif7Ex0r8OiRk+tH8l3j+w+OlVO0d8Wbkt2byC+A
V8pWWQZeIQKVmQOvrD98aebMcz/Y/cja9PJhl8/vWNn7FLfsyCDUdRVq9A4jjHyDMPDVBmEQ
FO1wchrhozi6kDDQmtk6d4kRxpDBJD8GJQDyIUiOO00awfKcby/eW4GxQmOFa/hdYAU2PhGh
K+DYQlJqzM8oYchgi7n5l8TY/IlF81PVvMZ0rWjo2vdhfKvmJ0gVVE2tqndUM1JVa4fWNa+G
a/Ux7nGmZxsayjkCWniOVYXmtPsUpCiBgIZTNCe68koK5dJFJmsQ+9jsdVMH82Wlhi9DN8CX
Ufrh+8J9JN3X19MDZqky91iM5QZn6+QP5pchaiOjnw+WIhTVmnBO7VeJqvlbFKQq6TQEqvPc
U6M6ugYhswu4R0bnLqMkfCEpqCTpF1UFnxJJaslqcjJp6oY3RCSdAYydYYf7I7/f1OkkUkSO
hEORUNgWCEi+u56QtteN3RM4pfnao01SRbZjLJvv2kNjDuygtz3hKBcBrTwhc4JMj/JNlADx
q5Xr07WbdbDLC0phuhZkt5CR3PB3ukwtNTRfyPKRWjqNO8ASU26xxrzwpovE4Cp2LFY+YtV/
h3Pbtj2xzpMwXYmHq49u2YkL+m+FgYHszLLs8gGBvL6e2EovbcJ79G+P7c3P/Hu9vuGR5d2y
nL1vM+yQPPspecU0g9rRKU043nxcIm3UVDbeUYUTl9+vNEte/I6HUHdEiGh2P22fwBd/6rAw
NPGCODQ/Ie4MOpsvatKGCO+awB7N6fD4AEqI+YCJmRZ3KKrk2ifbp9q59sGwMF1LlxegXrlM
+0TwJmxHPd1fnylDl0jDVmDh19AP0iM4PeKPFQtFoIXegrcgxkT4hZ0o5HsZSCSK3zt48OD0
aMdf4Ccma2r70MXhQ0HiWXcjduaW/qPtN9bpn20e2B6Y3LrtJGRU9+x18xuWTyCjVJaHH+JT
+DitFIzKPfE4ZFJ5UWX1z9ZNPeaHYfxwYzy60agsjLoTPILxSxZVVmP+o3Pz/xEfaWgDRnk2
P5/H+UXawFZg2jBsaMPH1CVobowS8JLZIvPlW5tbhemDaujDi6APEc2Hf156r0RulzAqdbOn
KcwX1Mj883x1brVrzJNk3sKHU43CBVuSYlZCBPedirPVk/PF1aiugp43n4bqKuG4prgE3qfg
bl5SpEiySCbi7xb/UeR4m9isDBe/UtxffCb+TNG8kV9f3FF8MvL1+JNFS5zml9vJK5YQbw4D
D5ltRtehVy0C6Wbjo48htz0fSUZCEW8k0JWWxFAmQMxTYFboYDDQ9PqWG2Zx0vYDvOt8idD4
lR4R0tVt4bagEwBmqCCMgU2JJjq1bHSsgLcUZgukMKp2M6Xbq46D1jULzXubueZoe8UuRqsC
/g/b5R7b1HXH8XPOfTjXCfb1OwkhcezEjmPi69eNG8jjkJfDY+MVljTDS4CmojAgBsYjlJZW
aruVZ7VNGdJUaMdGB0hBBIIRVDBY2/3RLVRbKWpHu2lp6bZ6oI3RP7bE+51rE4iGpdxrxz6/
37nn9/h+fvLuGKTq+AOmGU8kGOOMF8M7VqwJB4hVGhDGn4igKW6Gco6kmzS8ZjTDxir48/uF
aYOvq8KkYQtIFytym1bXOZhx5/6ryRnXFdz78qyu5MZf9n85ebewfRm55F5OZc9Lz+x6vbG/
tQh/WPLkgth7jsjcb/yoPP7ammeWfYJ58pNNzaWVlb55/RNrj23r+97pXxPfq22Vlb0DExOf
//bnjGpaJsO8CpNRDR6llnLZbI1mjPhhFBV2hJ6F6hLlukIsQeAcT1GZt1gs6zflzy6DUUsv
lj0maue0oOVrYqCFYgnBRNBCZc+GivbCxCvOICJnRLgXNoIMs93UVy15KXQSr9tlYMBjAPIx
APQYGPQYGO8YGOoYGOoYGPkYGO8YGO+MGbDRgJFBNjgNYwbeAPhzTlGAeZQc8yg51lFyrMPu
Z6qzX4NNJYc82hPb4TmuKLhMOa0QRRlQSEm1vthty4GOLQc6tqwFdqMyAM9dG1ZsV2zXbZzt
mwGWIgxrvsqlTVpjluwLsunhB78fmOgR9Jko/oolVdKRG87SfpRLo6Z6GQCoKSsOfmYAJfzl
0/LJrWYbYRaHtN5YG5v64LBxSxcc3gFptOmtIXXwzWXrnmAc5An52iKuFrzb1dIQ//Yr5fEf
rnp1ye7DnRuv4S0MgCZeGFikxvE97X0FuzIVN2f+rPuHpuJzsipOToCKl1ITfj42HLsc41As
IrOOEZuu46bMuHBG0/Ge7Dq8H2WV3BimYRKmpc4oCgcgETAOP6rkzCco+WnNZ31u7XCOHOTI
nghBEcWum97oNI9A7mnN48ocbzAiKqUyHlCxomKkhgQbLFMfNtYk62w6hDg9zF9OtJdKKeja
FVKFYNWaCsxWVussjwFzYpmgX+zADmorijoc8PQHTUdMR02cyeTi3BRVS4IbSUel09KfJF6G
2xXprsRfh09EAkvnJUNUolSVWPdIbn6QLJADpoiS3AwpkGRwwLDXr41FOFEJQQXh14C2VhuJ
rLng16pRt8vmwMfDXRMfrYjU/erAlj3LatW5Ah9uJZe+M6eioq6XCw78eLCrIdxQ684rdOiV
9W+xWMrsXPNUOKE12gntxwfIRTSLWnjYXGUl5VEjRo3Oxj2NXCOC3GRyxdatzPyL+1QXgHUb
s+vQ6/gs8tFSXu52dhOpu7uhgfLGrqau3q47XXwZ3I50cV05E0lmI/NXhHTHNBuHsjbIP8EG
xJR0UEmOujo6WlsBWjumYqopZQ9k0T5hEFYdfbDjrBZzrs7OwkLK4eXTtHhpZkS4o3l5Lff7
3zAvI5wxhFOZm+dDIasVFoWnZ04rsPTbmpc3cs/HMqeS5nNIlVViVMtA4zJfn1dVgF0OR6cl
EGTQMNmG/wszYz6adVacj3RcCluoJFFPVfSghCUl4QfYYVF9GMVavKJt9eq2tlVruGur21pX
r2qL901VW2Cq2lrISdi/xh6RbJmp01glW2WDU1XWop0Py3klgC8HMApkKyz46JYf42e/5ocR
iJEViqq5ij6uoh/6ysaCVbQcxMbgpuDzQQ4Fg5o/5XH+xI+n/B0g7+EXkZ/OJHggjuV4b5wc
ig/HL8c5FNecE9L6CMZsVrU8zO6ge2oHB7QdhGg5wah5cXNvMyc30+bPmjkj3DLNHGrWdkNI
0yPbydnK9pjAVI9pwW/ACZSeg4e5G4Ro/+V8MCiK8Cihx3WZwaku06Llioc6cG8IQ5ah0OXQ
WIhDoWyzCU/zDLkyRD4gZug2NhQ8f9+KbVfR+8DQrWdFLEVsKdxO9eaFB7nLHOEG7SAu6Ylx
6Az3tJaAPdlZN5tEXhhzQRNgkjt5amfXwr7O+ppZBYJ9wwD5IPT5D7Z8/+nGhl6TrnzFmwGE
Mzf5FvJ7/gvEIdMoOs0RIiAFWg9SwDAHg0YV+c+EwH/xMwTs5IZquCEMoCY0H0ujPfn4vhM7
U5m7NGCyRA/n3y4g86NPRrcVcIoFWz4r6ZshlOuGXUZgNFo0KyqKXjzsgUpmWDZSNDPK7qMm
K9BZSXOKc43Qelyf4mwjcgAHUlzJqHM2VgDVUth1JhzuSHHFtKg2n5NhZZ7AocbqSrdT0rsW
e3u9xHuRXENVSMYuarJTsGlfX1pqrBqoGqviqlLkDrUZ9WV6otfXBa4qTy0U8ey2TXVPLZDv
p9nEkQa9TaYTdcp9fxqkud7sqAPNTdfLE0B5CRjb4Hu/Pwm6C104Uc/acToBTJdFOgwjicfL
LmrU/P/t2OqAIcXOLqKOTSoRLUS5Wo+EHR6dhzEeU2rsy/xBMrx9En9ybNfo/Dnz2gheurzm
bzdEPPY73r9q55UyX+rZHS8t3dXVu/a71XW81PREQI2VdRN+r6t9n9M0isWhvsZFS+bofRZj
74629L7G6r0vPF+44cKlrVvXz23aauq8FQy43NUQy57Mp/yzfAdkexH6mPp8fB0/n2/TL9d3
Gnpk3Y48PMQPGYbk4/xxw3H5I16HRFn8UuQA3UapGUIgSkiQhaXCKoFHAhZSmVM0XjwzKnBF
7Qjk5AokFJLs7UauXZKE9jpxkbhS3CBeFN8Xb4lpMW9EfEf8EMxRE+BgnwVTyBjRcsecMRMz
E1iHVBA1m2cWLcbwogWHCkgBBc0tAD0EEqo3MWGMwLskBCTJeqjCgpRImyL+ZAIuufAksCk7
HcJ5IzWKImFk8ZrgwHUmPG/Picn9Hf1jR9KTf8Sev9/Awfzbe04N7ySWyf077/sPvIzpv7/G
jZPjk7cXYN/Owcmb0BhQR+Yd4ZawFllRIapBtdCQttCk6La7PW5ul2s7fcU/5P+Fe9T9rvvd
pjw+YA/MjHFRd6v7W95u+rR3fc12766ai7F7AX1PSY9zhXeFf13JOme/t9+/3bvP9VNXfqHN
bh92FFodjsKAEw6hiF3c7BIocsf4ueGo0Yd9Kfwctc2Nls6wFQp2xwwhL4ovFFxAUGkX8XOw
txnk6og5Si0pcoJarIK7PNZYVzQ7EFT/R3nZxrR1nXH8nPuCr+178cUYv2L8ho3her7G99rG
AcwlL4Q0GSZryAiNlXYNJCFbEtpMTkJTonaMtcsKVTeladGIuo5taqVEgxC32ZpGy5gqTUo/
TdpWaa2UTvkQ1A+hW7TFsOcYGrIp21JZPD5cH/vcc8/veZ7/v8oeAcGTKOA70FtD0+PpqTSV
LtAtM8iHfQV8dc51KjYRo2JwaU6LTHszOHMZ34EDdREbaBBV1971FpuVxpXtPHYjHpZ0E6VE
In4S8fgN1A4JdUO8Id6CNBL/Jn0hf4cWnQs5yKiF3OK9S+Z0GgxUBQnmNGqDGbfIjBuQYeS1
UMwVKyAXJWmMjUpjJ6+VDvUpDAdLlC1RQUp8xSr5dXVBHw7gyrX0W6uJulImQo7Z4I98Qw3h
SXdzzdJ63wav2V2tmHEj/dbd1hfoq7MT54aPn35tm/bKsWefmQ/0+RotDU8E1UF2f/E3Xw15
vYFuvE/xWDzH/5Fjf/LPv+8+lHt6X9fAlviO5m0HB7THrQ2dw1Kw91p814txuWU/8OIBXj4C
XmqhPLWiDtSNb2p9ZYpVCSn0cDzfPdZ8pvlnwrQyp8wr81l9SPxz7a1amslYM67NtKpsVHam
ersHUgdb86nh1subFzOGvkhfrCfV0zwYGYz1p/qb86nT8cm4McCJVaqhsHxHi4J5Y0SLSIXq
wuHzwZAlGAxlCEH1JCgkZOqVzczW9aopjdOEpZqtalQIhtlQnZDl9nCHuRGO4biqMhHPIWR0
FvCTFz3PoSpcRSZby/o1I6s0bu7aUt+S0TYFwy3yJrxphank9PiWqS3UlhJTjbiRMCWd0iY0
Sisx1TLt7cJdMHdWvAC9j+S6HbCS9n4tVGe2YUxzc0gv6qnrII8KWJrVvDQG1XRnTixXvH7s
J6uIYE+xbG4zZ80j5nEzay7g9y9eAQ0+uR0aY3Eot8bcfb5qYcgJH5EyAbgRMnNfAk0nsLhA
vrugVJBC82A+MSk7JSGPc7mhygQhjaC5iuEKmytU2qyrIH4JaK9MZuLdqfq+mV1Hn/juzJvX
ZI/dm0jKkfgAfetuZpT+FdB74sT3z25t/2Ge0LurVq5qeDyYGKQ/d7kHwuuy5bO7M4+qrfmB
N3tdtaZQXSaYOYFf+O8oR/1rKAPL0irLNDiiBMqgTvy6NlwmWaWQdMnJDDfkO8eUs7ozyi90
09I7ujlpXprfbGSS1qSrjValjdJOubdzQD6YyMvDictti0lDX21fuEfuUQZrB8P9cr+Sl083
TDZ8YOAxRdPnEbaAkEoSXn0kSCQkfVIbs2Gdaiqx9axm3KCGBESzmBJqiK4QzWrNu3QL4mDc
kFQ5ojHKzSrH6SyrH1sIzfbnUDkuhx+Yua7DugL1tGZlGKm+raPdpyabWhGtyq14pBW3Am+X
otPj7VPtVHuJ6VL1vToXONU00UQ1wSVNr057O/CRDtwBk2e0AA4QqmuA6sDeRzBlrOB0TBnj
ZVmjy2UyYqOxwuutkBUis3KlCIVyFUlQIUOLX7AI4/+gcCFHKJRI95MWpP9XI4EsEGA+nXXN
W4DeWOUOsMQPiR1be7d1lP713To8vn5p3nHhk/d+9PUjco38aEs4uu63P7aGWd/E1PCDuGP3
E7bKX06zE98afF0NuQJKbUt4xyGqOLT70O6j/ws3FkXu0SYgP5JQAr+kdZXZrfaQnR625RNj
3jPeafucfd4+r3IMdGBXhFbtG+07q3sTA9UH/fnqYf/lyGLA0FfRV9VT3eMdrBis6q/u9+ar
T9smbUaWYQp0qxYReIsg3E9cqduWk2AvNd9ye4SJ1ammGlxDiDPH1MpV4gwGVkAMZt6FpssS
uiwqW2KJZ+zWiBIt9wWCDYj2yQ14pAE3EJZc0+PRqSgVLbFkxVbCkngqOBGkgiWWfNNeBR9R
sFJiScQiYUkGlsS9KUwZWJ5hrglYEAxd/Pf4V3naxHv4cX6Kv86zvJE36lVwhAZQsyCOHDIB
CBizy4Shh+FLKpa01YPJGovapZPivwOGKwEWXSDlww9LE7NMStWVu9/406s7ehxfyeDPlz6j
l6Bw5V86u1U7OzTyzO8Cu3zxqtW2SwAq+qgWT+OnRXnpD6RKDWT7HwFsuvc9oOGCFjm+ZMYv
Lv8cVSLtHVS5fHPG5iBW46bmDNWr2ING9ON6So/0JpqOmbHZzGPM38tGJBNVScwPcWalCg6Z
ci97YEsTb5gYvbUmlt7Q1N6zZHanv+lkjZovuLG34z1Y/eWlEfzp8gegjLTLiF6+DVzc1txc
C9HPVFkZT1E84niNN6s8xzPnRHJaOXJa0sracCc54umaUJMNFqyy+AKlm/gkXFtY+uu6tx5r
Yc/MyMyBTnCcNxgPNQqO04p+AE6TXv4O46FD7AnIGBNyof6LJtoDbpFYRyvFiKNWq8FAOUYr
Kynd6IRwTqAEYOuiUVAFAYHR1IwmaLXHKC0QLlmzS4mUSmltCQqKjbSYK8ZBaoO+lhfgPuFV
bBGJCQIIKtk105P03Temti/N9hzFJ5PZrlSqq6s4tTLIsieWfoof696WTmWz8D9572pKdcGO
RGgzF2BHSdBLCMO+PkbINxsIYsiO5fd/qXepheXipWAwENCoIEZtCSxJiRx40+VvI1TGlfYe
w+c0m44zClbOJXQKvcIB7pjACZxYSbrBHS0CA97G2ettCkrbDkSfR6+g39s+st1GxhHbcPRt
29t2xhbzBNQ/RjEqLH84Y7SqGB7ijB5+nDynNHlIGxKUpqbUPRT+CzhaTQ+MabXw4Pjton47
GxbF6oC33u+t9jpiDuqU40PHxw7aQXL5Nd6kOhzWsNtdzUW2x8Jhdz1VX+3363m3ljXiw0Y8
BT2CmB2jVi5C8IVUo9HJVGT0Jn+3n8r6sezP+q/7P/Mzfg2knl8L1Kn+Kdd5F+Vy+Z0R93np
igSH1iZlpT3SYWlEGpemJE563uEed153Uued2OTETm19wnkxborjuMaXq3HNbFFBuZAakXtq
4V90V31sE+cZv/e9984+x7Hvw3bsO/ydcxIuH1x8hgSc+CADwgYCtipQNi/SqAJrq2bOGNCu
HdnUlq37g+0PPsWWVUUqqNqqEsooXaEr0JVJKx1MK0xa2SakVW2zoilrt4Ive96zAxnS/sj5
fd57L/b9fr/neX7PNAxVkpsJrpupu6JqUeqlYoAdFeifLkLFqN4oTU3l6RQGlv8GlJsqfCD6
2Jhh3K4ypVlHBVIxynAM/FHFFY0E9WBRXsrmctks2Hnw8zRmXU/vmnrYL6SlbCfOoojz8tA2
9kvad7dJuVzjIz/UxJ7e9e++26L33Xq4w7YVccDuIKN64sH9h2rierx69dmJ6uLvvOZ8b2Rx
5u19znp9/pKvso9vWtylO6N7d3XVNeNJuZopoS9PsswduumnHZ/Xai1IZVOplJKKman+FJeS
U/50q01IzE8FYYdAEUarFo23xfDCXl9jvMfvdRWSY3fadU3oLRYVC4jkEkYTeAZjrDINYsPP
GtiGU/gaFHyuXxZi/gwdeyc7TYt+2vMXLbYWyLY8Ib8uvyPflPkuWOIU2N135I9lIstmW7An
2fNiD9tD/0kh099vCvMXZkz4qqA5al4y2aBZMteau8wZkxs2J0xs2mbeMp9YutSGnrbUliJA
NzXBlTFjulgnSawWp90GUB6rGHT7rnuu3eqqjJVBAOrtKaZUrBaLxfp1lmTqjdUp8cbUjdqF
km6MUbpRjeLwPfSGoTvwYSl9T/y/Z2fpF5f3t1eL7ZRvWOHzdIWuS8v7OvAFqgK6qi6hq5oI
qrLzleFFHXqN+tmVM47GZ9e3n5xdoSN1RbCOq4gkc26uIly+o8C3mmpMKWE5rmAt5U/xxBPn
a5xvcDkfKAzjs/gSZt3CQNm+WxomFKTwGX+/JoRJRrOLBQ1yMKhNaJc0Nqjt0vZo7LCGtCfS
u9IoTVlK30lKytJcmqaL9cysUQHJeGOqfp2bbzXk/w/mFOMasiTsoiaLd5AEfGsQfvbCPei5
iEGv+f7MX7kpFymZiTPn7JatTVu0LfG9/L6GA40HAwekT7VP4777+ft9GwIbpK1hziuhtyTk
4ugHHJUCYWMFWFHsVtbyJQBAiRG4LBuAS7FkMXgYj2IWz1sj2F7k3ZjsSpaSOLJGCNLDQXo4
+EgiSYMkDVxFG7MIAG6VufNfF2i6rt2p0lygwM/AvFbrZEQOhzDJphjJkpubMlgS5Xy3LImo
zdVg8x/R0pO/cM6+55x0dpxDq9489utfHj9+ogZW8FXn7Pkzzsk30CHUdRn1v7TaOe+cca44
p9AyZOCnZ/vUH1zc2tGv7ECeX8Gv8AzxQ55/MrxbdiQ5YklJKQU5YUjtB/TabneDZAliqRBL
wV90oNDgG8nhllyu1SeEfDndJ+i5YC6Zw7mOmBqK5Vpiqou0DkhbPiuGY76c0KKrnrjSkIqm
ZFGJy17OSMXj7QnsUtBHm5oOKrWthVYQd7nIEzweLezBH7syDlt4PFLAg+oW9U/qhyrxqRH1
YfWiek3lVNpXvw1iVfVEjBdGhOeESeGccEXgVwgnhDcEtkUgOZ+ciYkZ29cvjMauwy+KkQTo
P2ELEStBvzRhd5lw0ZrBac8kMNht6ri/QcbJX8hNQggcJvQcoecI6RzufLHzbCfbSTPFKLsz
kVHuGqvQAmUYUIgqs21L/Uj8yHXA5Qqds6DD0eQxQA5365ibPBJMYuU7wtjt7TTKAXC8sIga
gZr1hTw0aCOr9bAwz3s895Y2BGnmZhnYXkUB89ZSqOUZ/+G6rUbauRYaGFxS9eRXDkad1zeu
XoWfiVTWfjK9aV9NRZ26Z3x1rxN2Tn1tSQ6sTt9mJOLlz67S9Z70j50SOrivc7mgUy1tBy0l
XC11owG7m1X8YUWZFyZeNapmmdPyy5GL8puRq+b75n/ET6INujeqWkd9R+WjEahsIsJUIsfr
pmZF3fzVkjBq1R1Oj1Xzg+2FENtM4rYasBtgOAr4NX+a8Ype7PWW/Mjvz/BeTW1m3clXDUWt
YDaZXZcdz5JstnWN0HQ5FbeZDMrQ27bQaGUylkUT1qLfRwKNLMOJ3DC3hyOcHWqyOG7BGkG6
7I3z9D5Pn+Dpz+DpMzwl2pianmWX+tKmvGFQBYypc/fLBli8UtE19uWiSBubUQTnUppC7v+g
rhZqQZlWAODUpRQpaSmfwPl0Sw4XLCadYqAeeDxpYBbMSlrph13gl1bQUAQ1UVrxkXT1MKRe
bi0a8HzwPnoAbURb0NDfP/CgZV9oa8G56uH0is8Zgz/Z8a39azfUSL5123kGPd5naOtbUeLE
VbTWef7tSedvbeuj5mLnSbQ9/cXXDv781Z2VU2f+fHFmZmbzzA2Wo74YzAP4YnTzOsPokyxG
HRTRQECymA5NxDadYiOv4ENMGx1fjEKhwNxx1VthTgBXDbEBcYBbDTHIiMGMyTDkMrcVlADF
xn5oEerBPWQlGsSDZAd6FD9KdiPfD7hTHAZ6eIaIBJMOjEIYI47nCN/KMiEWGGRgiVkvYlie
YxmCUTzHDDEjzBGGQFvFdli15uNN+EF8EAoL9togOPrrJdjn2QibY4fYEXYfy7NAXIWaEJrE
MIPS6RSGU9drSL10GPXSpOQgKcve+kCKyiiP0jpCeJuGB24Ns73OYecgjI8HBtkNt4/Rt26D
t/zMfetWF4U0oNDtxn2zqPAhNzaY+nn8Dzdud+NOuL/OjWEFzkCA518A1GLMW3arwKEtnmP4
34QVeJ1r5e/jNvI75d+Kvwl7R/0o6R/17/Kzfn+UvvBmsPXRaEhWgkpSwUoH7wnxSoj3KCFF
DrUSLkQIp5CQ7AF0WV9jFMVhZBzyjHAj/FPcU/xebi9/mr/AXeB9Uc9DnklyjlwhHAkpHC97
PDYMlD4N0XG20tRbKd/xaU29uwN15Gg5cwsbkvLRLgMSpQJuAdxEvgAqByAjkSaoZt20dCEE
Qs+Hhc8/cB+6kka/7+8frm4vD/Y57zn/WvmS7t92mgi3fvejHYKuJ5qTe/Bz1ed/mv+6XsPP
s9XFa4GLXxwcw343Num0ynyzxgfTAF6rgzlvy4+FHtN2JI6Jr/yX8nIPbuOo4/ju3kl3p+fd
ST5ZjvW2ZEeyLEc6WX4I+Synduw4sY3bJmnjODSPQgJDZEoJkLZuEqApddMZHsEZStphOkkh
NG5CGicdWhhKph0eybRDGzpAPTTQlBljTwlhCqMzvz01Tmj/gbFHt3t7e3vz3d9+f5+faPLa
6MG3zTCtJ32Kg5IxdB3Q1byaPCQTWd7lm/CRlG/M96KP8flI0ITOMa1IwOHnBEISoXBshjaD
vOL1Vc8wOUDCwYSPHQwmMUriZDJlc/oc9L4FDYZ9eFAL4mBq/HL56rWywb+lSnOpfAHi6ryJ
JaBLUXd0HB69moBSKJEHBUuuCGRtWtCEwmZoZyAthJaKHLiHK9ZS8ZLpKLs+ZuoeKNf03/KT
WIzJ7MAbBrrM0ShbGNZ/cMdKvRxlavs2kEuDBTcTZV7G+/U9Xa258rN4Ptfb2qNL3YWW8r/w
+bvz1dHCer2dajwEGi+YdoLG6esxbJap5qTP6Kug+VPGHmSMGLZB/33YAwli2GlGCiJtfJvU
x/dJrI2GqugNqYLklQjP8QLiMDfDtGsRJLkRkniB54QGUXKLosSPSViSBIbhGjRE7HYB1Nf8
gsgLHIKxCYlIkh0xPqJZIb84idPuo7uqCRYnJBMXQmIqQ0M2MQdFJ/wa4maMY3/DzjtroND0
SnTEOPwfdYEEBLHrgx3AOFSpJ7Gb3RsPHfi+/hge0NeSnRP3hWOxf7cRzjSg3zP1tB4v/2Fk
Qq8jD4M+/XCmbYY+OUMv2XBO2s8bfQf0zxr9DkO/gJGBN6Ie3KZZCyL4sI3+ZGYWF04p1Soc
9wXNDY0DGdzbfns7eaeAM9WClQ5c0ZqhUQzyQZL0Z7sEIUpaXTmXz+3OKkx9nS9KqF68MxfI
kdxbq2bBjWdwh+bPpVbgFYUH8hfyRMxr+c356Tw7kT8C/YU8m6eirujN5vMBPhDFURKuJOlC
Y1GM4RgOP1C8UCRiUStuLk4X2YnikeJCkSnCrJPtWePSaVw0pTdbRG7RTdzuYhCKksJbjlkH
cZzFHagXsHpuFPZp1CCu0vjV/LiYL48aF9hCuAPDfymlRmlhQv/h7hxNv7CpeYOzjLKwNI4M
II8ugVO4iSJtJMxlWzJpP/GADX2oZimQXIFk0p6q+jDYkoNwBnqxe8t5X3efMvLngylCfCpv
zWbWf73XxZruWmvTNtSQl2pG87bVaz0su+LwrkxWVoPLxn/5uHTLqijwVX4rHlv5yJNH9/Xi
mKO/dM/hb30a49duzWei0Zb0nXqS79l9/75vlBwxvGb3/qmpjVb9yU0dcbr7q2H3faad4F5/
15YzTpvkctZKLK9UK+ccp+VXHOflS41XGt+3XXNbQgZ7OY7JxEy3PrHMpzZkRSaIfJpioUhl
sfAe3ocYkYEU3gnFDu8nfFDxMIElpAoEAkOBiQAbCNStEVyv1gJSASDT4UYAJL8/hQSLAXZj
+CBmMQUpjBNrBPurLBw8eKSCcqmPwtP/g05wzhIVWvpfSQn2iDwKiBQlsfq1gEjvXsFb8Ab4
2/L7f3C4myJStPy4gUjfu/fbv9iI772Zjd7AQ/r0G8f1PzZ+iI1e1+ff/dn1PG1+k7TQPI09
6FHUiveihpMEZ6k28l1bVS27K0tQNmKtAUIi6bNkqgJIJSCk66fceEO+8gY8CW8IaTLBQ91Y
7Maoe4XHTKdqS1NHSxW2Wrd4mV1NyQw3GXMn0Z/AGRTNQlB8ucejERxf4jG6VheQ3Brj+WZK
cmhyB0IRTcBiEXcWP1skM4tzZ4pFoCOMu5YmwmKGG+n9rNegwOoP1lqAtfynMQofDMPMhTPh
sCzDzPCNmXTNxsXL5PM36BFNvm18IQ4qiijC48p/faEFvnDWeDpCV8EL6BysUqs5ADfdHctl
1qDMuhtzQAiCtuv9zBU4C5SOLmk1rzuwYDZZOKnaXGXxSLsdDzl4u2h1Qk5fnNUSUFfMmHHM
b2eCdXXBIC9jh8fthXSger2yNRHjIX3YJSgTPDH6vFrXqtpjfqYhZcVWa6ABNzTUxjWnFkuo
Tid2lpqPNE83g+ACxm5PXBiCipGwBjXYVRYi/HpcQzzflMTnRsHJEjUQ7SUIcglqCBrlUBB0
wiWT6aR+lUlBSVhJLTTkQ+BSagu4k1Ll5ljJbY6E66vckpIxWAl6WRXcCdo07qvwHv2vdYXn
v3v+V69hy8vP7NzWNnTbcF+iaWQ4vdzfPrwyq/fvm2fmTzz9yeMP/mjLPv3yM+XBQ+fxi8PH
f3etr7q9Tfn4wW/u2HoUnIbRe5hnmZ+jIDqhSUdNx0RSw8bZKeY77CHeJM8slrXl3ixXi01i
kLEgs0JPuzLk3gz+rbhrOItDtJu44GP2J+zEbuR1SD12O8cFg4oILyWIimUTVeNa5YEr06G5
KkUiDisBpwcjj+ghHiCjOcpH5URinKZi4Edq+SCVDLm6s5IVOkEzXEoYTIlDVWYOg1wgTiyr
5nIVh4+oVESX4vGQ+7Da26XPe2/Pqas+kSu0r+m63x3dtumObVmWjzNHrfu+Vv71ubu/8rlN
xTt/e98/35786ZsnjuvvucNnQJci6LLStBe1ot9o4U/VfxHvrj+AH6qfwscwx1gwsVgjsmVZ
JB75guWVCGeh1rsOghA1xLSL6dk0SadVb5W3yukUBL/fpAlha1MgmVRxsgk1Cy41jRqa2JZm
WY62tNTGnFDofqbd2YybmzdDOIClWlWSIM4ovgipFpQ7bXOo0dY28RqEShqc1TBPUS8BtoBU
EqiSSIGrQja8TjUwAlxDmYdiDfir4a4lqGYIuGYmnauEWkU7aHsqkQYCVm7JuRgV1QPJ0APD
8CSefO/hEamxJ/LUgy/tya/LJMPpplDbwJdrbx3xT/9w/JGV635sHR574fCqebZLf0HXD21n
TM8/MX2mpymcEcWej32JM//t4jHce1oY6fhqXV1yYMz6Tu9t+0Frw30gBgPoudO+Zu8yFU7Y
7CnBRq8Lp6CmqTnHJFA1E9ccflnuQdcgrEQjliDgUrFGYE+/uJ1AMLotIlQpcUEEQeOcIDi5
zdwRjrkAfMlBVeaqCSybYRq1UKU++g/h5R4bxXVG8bn3zj5mXzO7M7Pj3dnZl3fXsOuyxjt+
YYPHz8UYjF2bBNpCnPIOpdimLQSHQJCCeRRCI0FK2wSaUB5NacxLCVIViIgotFHjRgqkSFWi
lhCksorVplKk1ku/O3aBVqr6h/fOjnf/2G/Od87vpN+XPpawIEUlQxqVWEolUemAdF+ySFmT
Nb6gijShPZcVYKkLAB6NjZQkAU9gtBO3Td7IIDpMv+yVlFgK1pjKEHBdfyBHdGvnK0s2J1LF
z5LJqt55xbulsVZ3cuuWn5LYq197ev/Ej//0+5Nf4J3beoYnGnH/gboXnjlNe0wv+OUfwPnc
4H1RZj+EeQVskp2+QNaP0bUCbx4z8vSuxcaVWBSO3RUc0bBiVez4Kr5mueoinvY3lEuwYIpN
TTFOMWVDQsTgYUyD8SNxVML7I37sN8ZYxE4Jja2NUaFNLG2gNkarSqGxAI41SBN66RCsHoUr
SxzCWWBylcDs2IpiVYKZyLIsUCVVe6uwf+jGMCKX30F4+MPiOJq1uD2/6Outmc5k6Ceo5s9o
LVpTPFQ8/GnxvZdxoRn1vvub4rk9rcV9v+i9hNytlILMdCEnGJHZceFp9y43dtBfy4NA3Abn
1YWEGGGsNqoNC0mfdzptETt9uhqPIxjjNFMa5cd5PMBvh4Mc5Uf5MZ7wpnk7dXqenVNlHnMn
j+4qnnInxcx7AJ0FgMzbjYXbDLWbDKV/c29y5s6Yj7msHO3Xylo9ya2bO9ekKjvIiYkfrF9w
cNto8/ph9EF/IyATk4AetAW0HUdLjHS7+JiIOWwXuUAAl4iBQAZPD9biOnEu7hBdv8XXxV8H
PsJ3sQVRP+mt1HUs+sTdKulDKxAWRTmoBgOqVwwGhAAKLJNFSZZFpHq9bxEkEYK61X51QN2u
HlZPqedVG6u2qn0qUVFQDopeYhc0s3rVwOq4BCMS0wWXAHsRiVuVSCCgOerlTnmY7CXskuDa
4HVC5AD9mlVVOK5bQYrp5F6dnoYqKrqiJOKlmoHUNDeuoQrN0C5rYxqr0c/VzNLNMzvTPC9o
CV3rKgVZ0fE+CM2gcI8GYwbKLvWwQVivBqFAYxLuZjP03tDgiGdGZoTdOlXIRjxwZRfetZu1
bJD2siHkrTHh3bSzMipDmwiEL8fQ1BpWoQtn8zMXLcq9WJ8sKZ+ZzLY23RlYUFN8sfhpQ/Fu
rp2cKE6/+0RzV+g7FVVKoHlx8fipXksSnespvoLf+56RhOcYuv831gq7GEYeY58v/JVwBTbw
j8I/D1tt7hI2717DsDwYmIz8rjJU5qoKt4UXh1a51oYOhk/gE56fhW+6brhvhu+47rg/C8th
JqwxyxCWEMIet7udaPD4NI/mZnHYavXeClIngoYUDDLIwXCI46y3nMiuVWCdVGsGbiXtWh9Z
QY4Th0abYEQQdRwmbo9mleyMgaTIqIxkOWqPcNwoQoj6aLpcR1k6ampqQwWhYMYGjByiYikF
chopE16ljg7cA73XHLgdLs5YcUvfYsPhruZ43UNfmExmiRnCzNJYDE0Frw9SBOYO21+Tm4qW
MoIai39EZz1yvnOXnPSN7qu9Fu6cM7sXJ/Gy/p6uRB95s2rh8Eto/if/vLOpZ357lN9yZMUB
1AETX1dsZ5+C7U8yHxi+SBRiwGFML9cddi9/wPxJl41lTg8UkcRcVlvF2p3REisTMZDB++Cm
NZLm+Hg23h3fBjZn4c3j/fj9uKUfLsbjJG5AU4ob9VXxeJnDoXg8ohhMOxYq3Uq/MqCwG6YE
D1ZhnpJ/8owldIW6xODQw6AFlKvLmkIGMT6CgZQKM0HwESiqMG+KM43eXIYmMcpZqVbpn1+Z
HBakLTDglMvQM1fJtiXRziePVG85MifrjgSaG7fLYVSSzHX1oJL6JmQ99P3Dh8t61ixKNPZt
n7Zs9xkSm3husPMZfGmifYBB9+9BfqwG7wkxr19kyP0vz4FzMlQu6wKazhLSLomSRBhJJAxh
GUaAWE0rkPdMSJEJKyqsJDvVSCjEMC5br9Qr75b3Ka+JR6Wj8jnxqsjtEQ+LGD5NZFa08SGH
A4i5AjwW83yYCQmhitBYiA0B/04G6IMN91JMaQCd2WdkllJ9wUWJqTgzTZFfEWso9KYo8lIc
BswrRabGqlBrW/Rkl1Ye2lZXv1h2F/+RLb6dLovbBXLlSr74/LHZNfU9VdmtnQ2rX0sFJ/6K
x5eX4yTNktnAc3uB5xagnFHNaQFtmkZwytXkS4Wa0lppanpTdaquaatnc+hLj2vE+pIVO4UZ
lfq16PWmDx03lTsOi4NOzumVdKclYnR02HzUoysCcd2nthFpAxhyYJKLrRB/leV8MtnQEDM4
w4kiDGNDvjaV+AVTth1eBRRKLJ4OwgnZbEsdZ3hFneMEqE4u3e+vS/FQRNYvFFJ5niBCOjuZ
PGLyQh7nwxQNw/kw34LGWlDLVGK31HY9goaDk6tcmOTDDGgzQwsHnb+3btJV/wcqNlKspK4A
nwsWciYyZmjgI/khB1LZ/scbePcIUP43Uab+jZRCDQVK+j+kL8jvOvvYxWe8se5VZzbvfeHb
T/Z987trN6Wfqo4/e6rz1XlN36hNKanZmfrOOTMDZSdn/e7Y5+vm7V5u2ZFMzW7w/6q5aSPe
0L4gtbq7Zn6i4Xz3/CELOXls49GVrbnSmS5vW2NNA3EUDyF8Wn/i8fWhlbXdtOPOg214k1zB
fuar0DoxsxJ65eewHSITZg5cBIMfP+cv0Z30KbfBxR4bqg0iG6/we5z7+D1BC/JIPqg/9AEJ
TjXF2QJpw20WRTdyD0YHoqPRyaLok9LcJ5M4ZULs/6uJhYfFcMpTYQnMPkhDDbhSwjBmLJrz
FMz6t7lYSAS/9dazB3+5+i8vP9fGsq293XPf6ITa9/oYGrlx4eDjAx//8O/FieXFt9Hxje98
hE4v30G3oA62YC785gqgSZlA+CBnwIfUQDqwWtuErgXsJnjUQpHhnbzTyjOMJJUbXIkzmqhI
4ERi2rQwULUai/lSVJnrKzNUj5l/kV0msFFcZxyf92Zn9rJ3jr0P7+y93vWuje0d2wsGD7GD
OUzsEqA2aAspLmeLs7QBiqqEtCEmbcGIVBAIUSE00JImzcHltCqGtAFKlCKVI1hRAxUNqdoN
VkQgbeLZfm/WNpGysufNjObNm/dd/99XxXnRRS/yjoWjt6m2FI41VRM9Cok4ojNfi7mxvuR+
M/L1XoQab1U0bbfbSLBh/0tbzmyd1tnrr02G2mY/6VtU7f/1MMp+unFJprZ6Xpucf/9DTupE
plP7X3x7Vnq+wHVm1+npU+/cRn09mURrOnZ8z3mkA5uYIC4ug02C1GbFZDC6jL8JngzqBIKV
HLQcdXY7JSG9L6Y3IyUUyXAIcUhCAwjM55YEaamIRJFzS27sTu43o4tmBCE0dBwcb5YkDalJ
DOjCRB9gu7DXAsmyAklJ4BcNrptLnUQOyXUlbwNfljIn3KCllSYKJJnwqqc+vvHHDUdafYmH
zVF9f9+C7ZNnLFrZS78Q++Tj6+rVVU+v+2LPnH3PHVy/X926K3/n3UuvEL9z4Pez9FEqgBzK
coPL5cL3dMiEGHEmBUVFmGXtoRYKK6nleDm/QrhqKr9lQk5/3N9ofdA807vCzPICsnGYlgQU
kGiRsto4EYwjSTNsnM1m4ygk7BFeFn4v/Fm4LDBCE+wYkDSrLBEpmwj/EkfrWI9z2OPzIYoF
ljGWJQTRYqZ1th56ge279DIbqz1kcAuUiDgDMkhdhHocKIZeQ3QP6D0KUVBiJY+HE91iQqQX
gt21WlcYF5gcnInZLKlvRGbu1BVqNKwp1BCoYapBnvsBHi0gNoQiOfhp+QYJl0dB5HRoeK8V
sHic/irWOJxOvB9R6s7myu7YT8xRvDg3a37igRH1C7SrMTRX3mqJlR+f/XBllj785X+v/SKz
67cHNz57R2Xorj/8oHE3mr1s+3vEC0F1NrMUvJCkzikDeovTErfQDbpsfIZuVrxf2C1c9d3y
3fMZKYvDGksgc9AYMEomk99Wpu9MbU7h11JoSerD1O0U9DiQdanWgEepiaBIRAkMBDAfaAmc
CtCBgLWLQr+D1Si7khxIYi7ZkjyVpJNJE8dLPOaVAItY1qS0y5yp07TZRN+GVrC1ir8DwVin
2ZBYs3niQOzKf1SVW5cHm8KdQjMPODPaXKpVSKimwU5xmYQpkIzoFOqFaVjDcaedZfUWWi/g
7z19dO0ksSydmDlt8dqkyM9bcnhKs2x3R1c9MmVmvNpiTT9+ZpU6G+2z9x25ePnnU3C0vGfn
6WPqv930wJd5+9wLr14YWFQexU3PXzr/ep9J7SXW7CzeZH4GeVuLygapIJQtoz+QqXbBoQaK
2JswBsZGuP78TbuLXH+uZOBkS3hLCseNdto5ZEGUBVksPiT5a/VONprkiHmS5jnAzwEQe7vQ
BoF4snhdscKV0RyPC2afAvrg87kFouYn4BwhM11PlN0CckDVo/o86c+U0Ek6fcxs5gQE2ZBW
zJAxNKaVi2mUJtoAz6bHKma6qY70RmD90VxdzWgh91Fe0+zSYSo5ukSAdVEDdqLuY16oq8kT
wSa9EGldCT6Rz9YgvCTDJYCCG6RhJW6iSnpC4hxrtRX/SL3b2Vn7zWxv69Tmthav4fvtB598
RrLeRcy1Zw8M5DY/dOivqPwzC30mpk59ZfihBSP931jRu/jRg23Ol9D24Q/YGFIvXXlH/dfZ
DV0oMvgBihWLxZHiTfwY040bsAec5aC2D1PUgmMYLU2ghCaMQkYb3b7SGKgsjdA4kvGNabI2
PNKbIU4zJpwcUhDGsUG8l0pQZKPab50sE23Xari2WhhWc1LbqbdA44OKFSOuUWrsa6QDjVFR
R96QmXhDrjRX4wJmE24gXABzt1Evw1zpdRwlHi0DZmajgJAKhr1NLP6VVTdNrLpNWzWk2NCS
cF8Y8+EdYWwKh10uBaHw/WXzMszVolebGyvNRc/B3OhxRMldMpbHl6Zl2WKB6fe/Gj6brJ2g
KN3/2GH46srSjtF89GNqssJjNKldad/cvqP9Yvv1drZdM3JFhoxKuRTOUO1yMEkM0TaI94yb
kpgCUdOLI2yA6aCqEaPwek7vsDOuVISpTDU69A7CRYLdmSFE1M9tcezmDnOskdxt8oQyCQ75
A4lApPoJwALFVZGhaZM+WUlhQ4XXS5l4034TbWLFCqvVLvPGULRCiRhC5JPmGMszoZBfFP2u
uUZCUt2T6AoOt+AhfB2PYIbHAaxgGmO9PxJSEtOMkh/d9iPOL/lb/J3+Pv8v/azfn67YUY2q
oVKRijXemY16/sNDwcpD/bo7QWCAIiSlqBYPlLDROqBgUGMgr9Fmwsa5Zv5mAZIpX4VyVXlr
UAiDBoQFyBqxlDXyfaiFLHPU24My0L4shFh9eLruh7GKJw51Hho6ffcfR771YFpurnuqe+Nq
sbZrdFn3PM+BbYko06GeXv6kyr2q3vrL2+o/s5MzJ45e27tarexI1EajoewDurrcT8f9e1nv
xQ2oaiw+GtAByjUIbV3hhM9nMEBQ+CY8SLzXUbzBlDFrqBD1ltJqKGMcx6x0vDzq6HavdOu8
vNf6vJVOcit43Cit5zc4n7HuYl9w7PQc8gzyg9Zz3DnrVfaq97OyezzPBaDLFQgJTp8ssyC3
WLSzglvAgsVQaTb7LLLdiDHFyD7aaDSHcAVCINs8PMYDIIlixMCZJTM2z3WtDfN3oaIR9skB
7I02i4QEC+CVlgKcFoT6PPwRBIS00BoNzeIhrA/ag7xIqpgTClWAEjJipASGjQyO+P++b+hd
A5ZGb1w5+/jBtdWbPt2tvqc+9jfU9OKWX7VXTPMwa9SOA0PqhWK3+r56pTtfuasX7US1N9Gs
vc2ehcS+q4vXdUFmDXQDDdSYvfEnTAdcp+5fa/mVGqsoTZBflW9gpOWm+O3ejCI/KmNKDps9
JJ3qJpyRr5JJhjuKN+g72hvTWr9RVhzR/4lkFzUZIWUuy/NCBpODHLAImWxTuZDRM4jFLNtj
/Y51eXC9dX2w33qPMSbYhJxls7LuPHsh+3++yz62ifOO4/c8Z5/tvNhnx2/Yvtz54ovPr4nf
4vgF5xLyQgYhodBAAhkBCskGIXMawjqahoql2gZbxzRNGpMGTBPrulXQsbYgdeuK2gmmVVul
bQX2Ki1CVCza/kDQouS233Mx0K7T5NNzL4/Pkn8v38/3d535Y+4WczvHUHJTU8gExtvrdfCk
yUvtaXJWur2BNM87THEhHBBCZiGVqeJMRlYORWQuhEOiVVYGAr8IYCUwSiy9mQuLVHPJZFKg
E03inBlZzJNmbL5IpxQrm0XZPgVmma3FNg5xnFubLO+WCafKC5GHY80CIVR5xLN4h4JOYsHS
Li6w8CFjTYQYCrK/TChVhiRrpEoJOm1a9GdKOGP1W1n88cnRZoU2A2L5wUU4rCtII53XqHv/
p+DWmPkrl5dDu7rr1b+suXZsz76O4qEqfWz1sZR33R5dZF9nS+/GnYWJebzw6xenX3hMwt62
fl1A3aNeVs++O7a+9NhXO86gFArdmur1Y0nCpb1qtTq2s7/70Jap74BsUUGKMlyGbCWpEior
oQhJVJAsOZKt1SRbTBgxQUPkbpi2uBO5tLMZFhiBfnuBb0wniPXI5tIW0kWf56X01ciV1dcj
11bfitxezYSici4Xbc31RvVJAQu1giEgeASXYBZsKOWW5JQih9OplEHg7Fau3oab9MZsxsgp
cYNRgA4rJU31caWYiSudXem40rcRFp8Ii8mRjscZz1wSWZKTSZwkOTQphb6q0FaljiE8LWbI
6QK8p53hVXJW6sFPvkGMjwuXak02g0jVIjgGav9Wi2tn20A/y1N3ipV0s8R2aHajyN796Djr
gaLQZFTbe/TtBXCOnsVFtqhZliIRgQhUCdHahUWyEMXVfjDyoDr8JOEgri1EbjXnslIH/sq1
GTusjyoICgN9pELoM+rx4pblMZd+tGvdDP72wBo03XoQvzTa5l0pnatvLrcfaEPdPa0Du/L7
5/FxdcvERklC7UfoL011knpYM6huReUTbXCNxORu9WCljEr70Ovq2HSxUifATIpiUhoz6UvQ
4h8oPwRG0jWOGizDv6g1C26BF+T/AmOIgLHe53sERgdBoj1gnLOfsp+z03alqjZtt1MNbANu
aODdpSob6cw2YlWBjzzegf+KaYLJf5MTDxf9eBLP4VP4HOyAOht4wKUMuOTRP3lk4Xm+je/n
J/lTPMPz/w+X8ABkuak8tVB5Tu7AlBLjWfSQ9H2SmISZrQhSSIgZxxowtaG1AkiSwRViajmF
ezMmvIxJ7s0TE9975ehbznzH8qsdzYUNB3bGepfnv9B1+MCQQ6Pl4HhItf74zOvq05vznCT1
bEbl/TsH1dgT6yFN7eO6ABYnNEUPU5T+JUJM3Fkh5gkgpk+xoDnleQVTikLZAJqlhzoNRgpT
NqDmO8xtykEp4HrCM6anal8oXirq4qzFlg5yY/ZDdjqYR2EPuhFDbMLC8EShqxupn8HPmOkM
VUcZ6YxSpuvqaDopy4o4IGJRjKVSOaezkM/nYtFYPFrI5/IFXc6ew7lYPGaPx2OFaFTmvHaO
81IxNibE6Hiu4M3Hopwx7FbSCc6ZxIqEpLAU5k2ZeFf88TgdjXF58i1j0uXqSDZBWlYmXQBr
U7nSWfAABtyIeZZdGXRHjHBlMLJFYxFZU27yEkmntqaa2EV2EXAMDxY0bZ4irgc9VGFtilgZ
IRgD6T8DYh6KtFODcRataHSD6LC7ECLtF6QLv3s5FxmIuntL67q55g2R/M8R+mX3UI86vPvE
ExOT/bmWZFVNoVupU72lbVvw9z0zTrQJoUzpiP435fWhls/k4vHS7mx8w/hRiRk+vvTW5e0z
vYW+1t7B52S6PNkBfrzVEVr+Fro/HhOjNHRhSJ1mKOjCDHVDaT9sOZw8ZjmW1EGemgVJ8AlW
wZkQAgInsOBR5epMDYeqjdGQ28GFnRgHTJyeUxiGs4T58LkwHb6IryuxQClhimRESwLBsSOB
ErNZKjuaxUp2IHs6ez6rc1aLLOViXaddtIu8YeFKJopFcAywiJ1t0UTzQW8tjLB3iiPlB0L6
SDRZ2AI99ECXWVPUShbJCqlZuHlzQWsuyBVRSL9fhBSQ/vJnKrLY0KDFniG9lvqfzxhKPXPk
m5uqparer51UT0Y+nckNR/Db4mgbv/fKXF3biIh/4t2eLWz1tp958fSpPmlTmT58CHqrc25p
elQI7qXnjqyRpP7ppfmn10KXsdBl5/Xj4GoCmqsR4d4IkfdQEvWm4rcQRFaTRWiFJaBx0oyY
6qf0X9bfNevchIerCQ8tVwLXLdcCtyy3A4xTsLkEyiubTJSNpo2yh6Mwn6njbEaaUzAObhX7
qj5HiDQKOCJQczoVk6/kNFF1IuVEcAw4kXO28ROc8rCApAc6djMFYYZyJ+4EGoD4T+JRSOU/
4E5Fvxo+zhYS1ApfCF5E3Tca64afPvLBBSSuwCT0TM/aWVzd0nvw0P55EK2v7302sfyvCjLa
PkuffrJzeQ+xF9+dAWpAFMHT682aN5Soh26f3BO3D1Gl1Gn9Noiql2qkzinsKtZbn3bbcjr8
FduHNgyD040LXi6tDVBDfCA95n/Nj0+a3xbfE2lng15AjMDaa2oaZLbKwbFGDnDjhZA63Y+L
r4A61VNivay4UbMbud0OC9XINuLGEoNquCqRmZXrOMrBOrAD+MCqS4tFljj4HIBh8R/W1Aip
Us3ikSXVpBWqNZVo1iIIGgIx1EhNxF8z834yG1nBz4E06P0wRoG5h0De1+2c7fQMbZBqbv1K
ff7dZbt07/f9R/Ez6o86pnagv+9q0K+XdB0TSzODnRG1//yf3nkDvZzAOfTnJ3tQavqO2qze
2+b9VCV297VYyhA7RPHg3K7qt1OjaEkZN64yrsVnq88O4kHfUNeYb7zrmPzFwnXDNe69zj8M
VzE+Q9DU5RrKelu7e7zdw8aLq171vVa81HXT937XXd+94IddJmOxsT4qi4XQmuzgzPBzwz8o
mrYMDcnda+3d3WsLxaIiBdPFi3ReqVM67IrSUWU0yt5Vdq93lRwMEpMF+8H/sF5usW0cVxje
2Qsv0spLkRTJFbXkaLmr5Z2UlhItiqJWtC2JulKuA1uOGMmWYsWVnVp2El9SpfEtCuo0adEm
cdEmUBsUrfsiI0EAube4hYsALdL4IUXR5iFpqz7kwahbpEGKmlRnRnQstzDgAgVGOzOcXT2c
M+f/v4PPx2TolGVo6avZ7e0TByzu7RJn5LtkGDRFVBZOwukoTMO2B7ng1hciK5G3IkwkMt3m
GHUPjg7W7WLAlDRNZ7W2nJrUJaPNMrC6/qHxlM2eYgfAwO6JPjY9LEK0rRWB6K2xsNEGNu/M
09fy7+VpI5vvYtO5WuiF9K/h+5CWNRhko+pYA2hosNmu7wf7p/zqByrCnWlB9+u0Lk+mc1Er
RSVtSTops/7oB1E6Gk0OG8P08PD4eO56DuSm9qFWIIGNBPHBQvbj0qbKQxsEEWsL5LQe+dLC
pmcpsvGkeghQYDAsI9VDRpZNZEkrgRWQsCF+sb6zEz2XuHjkjrGRBYcWd/+E72FpYQH3GeQW
5uh0jt5wsICsIQgxmZGG+mi3m7AJdq87mIIqHXscXjo6OtLoDPei5juW58JfYTVo58ZO7Zgp
9Pq0wul9+44Vuo9ZuZh/W0xr6xwa79j9WGowX9lb+WdLqFvunC0PjY3I6Yhc+Vtl70OFr8zs
n93apsW3+aNczdHuwSOzM18abAnPnRo+im486H24MsN4SicuXpw4PJYdOpsfenXpLPR0j3z3
t1NxlXaNQKYyOBv0q6onsxP8FDRtL7+v7ga1Pz4I4ZlnXx3Knx3qHlzYe/Hl10bAKwd6VVwR
IdSJ/p2bpxLUN4ztJqvLOiHN1T3snAs+4VxyWiymUAMtKMFAwBUNWhixsSloIGU12CJLsywF
mEYxEKCE0Ii1ttY/YrXvaaVXwZ+MmoR0BP1vShSThCVK5TXUDVSlVk9ssrgyVg8sGyi/pQRK
eZvecwOrbyd2NVBy1OsYJaqgYTK7yISCrqVvS67WXl3hBM6rtVFn2/mT1//cufTi7y+f/MvK
pV+Ohi9886mvTZ55OuB+7vETO79wwcL8CnxnwJn6zTM9pw9qyrvH596cnjwYfum1s7NfTzB7
wLdefP7JlWUcHYgIvglpbSsQ32z0IGuqwb0bmkF1bsGeFUALwSOItIdqbQ2KHqcoekSI2iYK
1tSmRGh3pShckK144WkVWSlUCzF9hHnU2CnQb3NIULL7LWY2FpK4MG0XOD+3wjEcZoekQXly
vNVkkwUeoDHFA35Rp/RpnTb0or6sX9bZsF9WIpTP5lv2MT78ka1VRMShADSKClAW2+4iDlyB
92QOBPKl7CbaQDW4RsqN1Bt2wqV4ZGnxGvFG3I+1/AdWNFQRBGzebGYPlgf6gRj9u8RD3blS
ohyKTXVV5OTnySqbnMcnkzn20KMjqjpw6ta5xX5VHTpJf1i273sAr5gvnhpA1HGsLCI3JBki
jN4PJg37ccTon9YxGM3pJE4YrCbKXZ2zOGFOnLC4kKDvDe3NBNozcVd/fzARdyYS8QTOqAtn
NIEz6rqdUVe8P8HqPc2wD3ZBQ4YxmIHtLSG9Qwq2W6TGfI/kNeig4PV7V7yMdyOjrnhOtja1
yIIM0JiSgbxYoArTBdooFAvLhcsF1miXM71UypZaTjEpktH+BMpoBqBRzIDM4sD/P6OkC/gv
8ic5Lt0D/R3/c/KZxndWM+HxiKfQM9jnS4yGu36m3sd14N49XLxN/x2J0Ucqr9zH9UAVTDo/
5PhZsO0K1YzuQKaL3AnDjxZb4QCkVd97kNakE3VP+J6tW/K97Pth3fdVi291/dM3XJ6Uf3X9
228gjELz1dfVdjRdNl4KtvM1NdUWLRyiQ3b0F1Nkp6LINbzkZUW/WZHDTEwzwa2QiiPn1s3B
ldhbMToWo3QKGavYIAoMnUXgFdK11pSkWyakgxIiMb6GdfNyk5yVh+XHlHOKSQnJYTYedLvt
9mAwB1rlOKXLaZMQ98fpeI5KAzSKaZBe7CapL5N7gAYRXoyyyEzrSS9Yxm6KzRQ3hSVipTc2
G2nVR0t3mSZA2UfGGSkt4JvgqCYR+eH9eCe+AFVGDoTpX7hntz23a6AZ++L0Y6OZo1Y2HDNU
JZU0dmyd/DKc6KlkKh8lYzvGD5dzjxcycxIyvcKByrzjwTPY8oq5gXP5A+dOn47aUp+79Em6
XaUte1Sm0r6/Q1Xp3nnmwvGdKOP8+k3u50izI9Sq4VhyvO14W2acNl5ICU2gqckFMXblevEl
uGrEvUoKQpeVhVuglcGKbK6RrBZbMEyFpDAdluuDRlG5qlxXmK8iGcWfaLW2lKL4BKvfSlvl
LTnWGmk1ywIL0JhiAbsY6/EBn0/EtrdRjGufkQ9p51AoG298fAeUSQZ69EQkglJWIrEGG9Xk
vk0ezfVO2vQZarhxAdrr64n3NXM/edQwjpV37dzmq/xIXHj90P5D+dwxnov1PB/3jsywY5zW
N3Vr/JCB+M2bG2O1ynyl8slfT8wN94y/YFwCQSAC6nChmVY3eNn8COHlJOk9UMdhcpJ9hOyL
63/kbnLzaN9GeBq9b7KjWKvUtStUw/pNQ0fKytrQw44fEHLQAh1wix86oTkoej2SSCuAFySD
2mIREI6vUAyF1S3G5aC1UZEFCNCYggAuapQ2rdGGVtSWtcsaK26RHRRv45d5hsdfCBYkhw6A
RtEBHNX+7rYcrpXuKYZrqBKyBC1JBkj0124goUMXvSpXzfX3Ei/yOzMamUlWmo09oXJXZCLT
UYpwHynT2e2TUN11hK391z/O9qrq9qeZJ08Oqurw8Vvn0R7FLoV6ke+RWOokluMolrtJLFvI
fhApFU/O0yS2dnT+DoptmLpunP9By5UW2mMT7CnNDDQFhFlQq3iVP7gZu93gizzN825JClCU
qigBt8vtcalKQFHZgDNAB2Iet9PjcasuV9DMOc1mjnLb3NDNeAIqp7hdZouTDvtQE9hEGwIQ
nILTam337PA84GFcbrOC37I0ARBtQqCWsBMpwQqysGEl+AekFndQu2RBK7PFlrVkiaGgj/5N
ebXHNnXd4XPOta99kzi2Y8e5cWL7+voROzeJjR95ObVPAiQLkCaMFcIjhEc7KLSAU56D8CiP
ToKtndSOdpXWVqu0jU5bB10amLrBSlkjTVqlTh1F1aptEaq6uau0DlaaXPY713miMNroyPdc
3xP/8X3f/b7vx4Qdj7AwyQ7gPiWL2RhowNOSdjBNNzRgTdEAdam9DGPW6ap0BnylfWWHumrj
9x58dHt3U32soCjVTm1qRXr1CvKyc7cDL8M4mT4MXsGvOjV2+Xdrdnemuho7l58IcdntbXwg
0FgaHv8+vrW5Vq7hQG6LQbNPA65eQDaO/nwemSAN5lW4EzoRPlaIP64cKhgSdVViR0G7yIGv
FQqiUOkwOAqh1VUaOw0ryghn0g3fvkWtcjxZ9KLjVQdxOGzVSlLvZg5h9XgTbrcXSl2JkXjB
4pPs24KOZHcSJ3uDaWGYi1GrgyKb7I47oNphi6yXi+Dbs5G0E86+1pF0bktYbig5APizGYMT
3Dgt47nrWYXZBywAVmnRLn1wAe9obMz2oSw4dR7iGOvLyAtTTFneimU/A9wfB2QxsxbmId5i
UspOECt5Yyc1XP/0FXVUfd5LV43PP0D/qf7n5BlM3ut8jJCNh7/RtX+7euHoQFvP8Q0AOGnY
sOW95y6q1zraygFormPtsQ9OPJnrW50mX3x636WfPnGhDeseGPruj17JYFB4MSj8vKbwVN49
1J08Aibq0Lu0sJbNpzpW2SpYPEdhU1ODApJTskq8VBiUoEeDnZSGUDV2IaPXbSpwUU8hMXs8
nl94OI9WrMrTQUGqcdFq2RzEsPqDODgYRdF1UUKjPdEXo69GdYVI1s8ykhIwEj2G1aPH+sGI
5bO7GYkz1zLDyu+wkQkjsWo6B/yV+Nz2Mdd3Vh/xhv3fTDSvVMhbFRsWuDe9vUNuXFVDzlYs
o6neisAS9VSgexd3YF9nIEAfH/vWQ7L7Qe7kxN2xA19Tu/EphmgRIPwaIBpFfzqP6ljj9Sd0
DM7dAOc1+7VqUm6R/YkisVIMi5+LOp6Zs16qgSGkQvLYkxmlW+lXOEUJhx0OD/h0sZFEvW6w
aw9h/kvZUINqbGlewEWymcew+nnMD8Y8shNJFolIUiAtWJzUSZ5yYmekLzuJZAzicHTOdhqL
KJbRGWhCRmpDYx5QCzNnMA2UF3UeMnALJug0SVqZhwQ1SJMznjawdPRxVeQ7R5ttmXShPJ5Z
M1/65OKWZzI9W8iptkX2+9MHv21tSYOKkw+NzV+S8mEoEWI6jYf2LzxyAN83QAOBhhXq0+n0
vHb80ioaZPguR8j4GOCbQTdoZp7oCyaaRV8VDAQMP4tkkFokHJV8UqVkhuBLSfWewlB9osFV
b1RCZXYOuWi4FJMwFYoS4WEuQc0+0F4rhtXTilsHqy9wCRTl4kPUXOopJaXsiGCGIw4LWAx7
WMnFz6Uorv817FOIQJWBnyLaT7E8TGFYPSmcGqSz81CxaNYx2jctbOf46PVZR4CCPAd5TWvV
ZErXExFpu5eU50zM6SRdTraIi6Lh1Qf3VEQXl2k3pdtf6LOzm4fLFkerl5bd/HvZamneIn1V
ILBo79jWB3xVS7ln9kKUdu4bO7JRmbeUO7l7CRT9PWNHBroDgfXbuOy+TsaNulPjZgEupp0j
rVdb/9vG6Rg7rSLEJqWoSaqTpvykGea0SU9BYXCVNHOVZCzvK3EwljhjKc6gtdcCtO0YVk87
bh9spq5MJsHYaNaoAgMiHo2qcjinvQTsYRCo0tNCxKgCw8lTVaRRNdtxFs52nDmpgkqfs3wl
uqaMqO8rGNHc5lRHfMs1TsruzV5APPnzJyZI+TIEqt1Hr8xHRGs/HwB7TuiSb9JImA9LTTzM
Z7yeJyP8iP99/pr/I/4ffgNvsVgThH1IUrE14W80WRMWGNZoPdwZ9PimHpugSkp2FKqosAs2
W3HI4bITTxJoFYylstNZmRYE+ZAJm03bTcQ0zMWpncpdBbreqkgVLnH12NbZdtg4GxgQFPgJ
vHPO8b7sZJFnUKOMM5fL5HJswmqK5ICdUWZTWYX9Qc/BcUkHwxHvy09AMoSxz8oMClBlsMa0
7OXIOSxj/bGRS+Phgx3ZI71cgDuwdokz2blr7yMnyOgfzuz8ydcDJLNF54+e7MM7AvL8lapP
3bS++4e7B54PQZuBymc4B7iJsMugWzQ+jY+b4SMzfABC+aaeA3TCfMjdxDe5dSP8+/xVGRCV
9WYWEIsgIFIQBIAdezVEGIhKUKi8XEjG7FZXvIS4koK/CjAMCsaEX07Fg3JNWjAzq2l9pxVL
XQU7dBjp1umIjiFaYKI2WXSmTULJMP7b64KMTNjETGnmONQyCjqfSgiG9sCMZBjXxtiJXIBR
Kd82GdZ5lecdCZBmdQd0PhvwhNYkodnMQBvnjUh7OiXyicQgdYwJ/nieidQhcmFdpqK+c9ee
R47rC8dbaii1WRama8jlid0MbrjjT7HhCsuxjapripvx5wKB6tRa7kB/Q622GzsGO1C6DEo3
TjB2gbrm5EuPeXJDTzRmGoCZEf5teZIvHiiapgfIYdxo4g70/n8aaLHGA6wexob/zvH0Dj6u
5zU+Pgk6Uzik8ITIvwTepPaumN4TPjYRrYcJyKvfipeRiP5RhC4iipAdHFWkIhad/m29onK/
5UbWmgRUQ7f/ahzSb4U5tR59QV8+7T3tezb0bPWVqivK54mb9UZBMlQZ44Z63cPS5rrN0U2J
TfU/kE4HzkhXlY+UgpDU6++tWq7oapIy5w5hLLjAxx1iqctBYsmwQCDPBYMGcqRL8CBa6Ukg
6gsl+hE2I5xB3agfHUJPot+iP6IP0b+QgKD2dwkU+mdvY5lRdpG0WXAA/GYMqwfGrMGGyTI0
BT8I/kZ2xhuQA+DhiKLMLEw5YEXz+gyjBq6MnYzWkVjzxz5NzvG7SD1egrwxXUmpBXklhGVi
tZTEYyVWC1f2sXXhfbXjqVpKSyywI2/BzvaxiF/Alddw+8/U/ep59bK6h1w+c/H1X579FTml
rplU9rTG1cM4iNdfVi+9oV5V1+KD3EX4n9+o76rDuA0r5ASwevsT0P9L+iV4GUrqfz/Bqpva
oLzSog+LSH8RLhqMRt6JkEiXpQ8iz5pMghbW3P439xfuTZgdFvyP7aqPbeI84/feh+/8cbnz
+WyfY+Lzx52d2Imd2Oc4CaG5lNSJMXKcJYSQzgtTUbWuqqjpSrVJBcZYWzY22k3bKlVatqGJ
adMoawiEVRsMKkDa1uUPQB1TBUwBMQSManxIEzh7Xjsa+2OS7ff1e++d/f6e5/n9fg/0DiRR
WF6icLxVop24fpxQlu/O2XnDigvmSzB5txWxlJfaKD8vb5f3Ne2Tdss/tP1WOaefbXe8IHxV
eEt6V6ItDo+DtLt4lPBz3CiNaNPtNYJ0JxQP7SeCUZ6NRl12O/YBdruHUBGKm4KIRDOaMMRq
MrmwvOuDWDaJu7tAa8IgkmZyc/JkcjHJmMnZJClE1AgZMRc9yANb5uAmPM47mgxPTwd0dwkQ
GFxLMK2CjmDFBlHHcQXzm6hmUuId0BZcc9V6zaEMVFs4FoVIst2ZNOGWyQhE0JDgixdqDoFi
i55Mo62j9oRtP/2uOxX37jwlfP3aAiKunv/45q6rV5u1Dldf7XcbVj81kRl29zAvFs/R1IcX
79c++/sfa5+iCGq/gfYeIqla59kbtdqByd8/eO990JkCQdAcdZCQCR/w1rV5qwKoUBjuSZhs
CD7veUF5Lvgt5Y2gZQ/7zeCb4SPs0eDR8Bnr6eB16w1lKWj/Aftzdp6lYpZZywH2PHXBep+6
b2Ut7nxzs8OpEaIWyPOqw+bLyyphsXgxqmlJNrxe2pRcxgy9FYclFRoIkaE4V9Xdgl/1k/64
SDgid0WUEk+KiyIlYqRzfUZ9THXVx/kWzRBLGkYc5OIRWKUKFNrtCkYZIM8A5ljJl8QlXEq9
dRknMOCuUNrjlllMc09YDgG6sSckVyDpn318EYVu/unxw2dC+iDad+dOID2x/RvUwVdfea87
vLhjh86mC2RHtYep7WF/eYiqzdT+nIptf3bzFO4oRgiC2gG4uolvH73uQLTGiQuIm6M0tx0j
kKvnnpBnVc7iIlS3za4KNiTYUrYBG2Xb4JUjgqiKpBinOHfkLoVS1ElqkaKoFRioFRioFRio
kud/YbglPqpUgVAe99edDDjPaw0bk3tC6RHMH3Bc6LdG+pKJNVS37i1XjyfzNYdOZ0fJzw3n
GP3etrWPB/J9pA6VSSzbqNNwIh8RIk7NFZtQALJkDioLxitmUyhhsC3elhGJ2t2EmvDSc7xo
2DleMCSV1ghG40WbTc3znFPlbf68Dymqz7JGQpK8JoACq3yRVXlZdjqIkIgzgSFsKhc5zCCB
GWVmmJ3MfobBrtqE0zOliKASTtFJOnE3WUtsq1Ye3cYHTzsh0recmQq88PHFOpcCBNhmLzkz
gAEGCZxcFa00lV5nJBoKBcHFdUtY3GJZJuIW2VA6S51+Wu8CVGpXap/Vbrbor3/H09aNDj/8
MTK+SB3Uh3oeHxjrImvXHjxAfhs6fH9dUUH6wPdrYzdewyo3CkxWqTMb5AJkhAP48Q/UMWKK
/MWxdc3rzY05Sl1YvmuOyB5jkpsSNjqny7TJDnHFcmnsAnuBu1S+NMbFyj1ct9AnZkd6C7ky
y/Jc0csrxVaOyWkfcguFI+WzLDOMUXbCw+ZgLGPsraLL4IL4A1aPwGphBP+WRAqiSEZ0PS/J
siTJLIevm9ZACHbbHbCb6jVdvCDzvJDLZvP5IRneY+XGM2FDWYStZbzr7WJBLhYLWT0XyUtD
Mrc27Rw21XZjYBitHkbDw2leKBbo8VKX1qq1T2iQAbE0k86PjqPOcTQ+3k4MtKX8A1DpawmP
6CE9fk9viE0m1HYLVyZspY1INQmbMCTk1SE1n8gz+aFclp4YJCRCFiVR1iVGkiM6rdCCLJDn
QXgXlhfNXrtg8JzA0rTNXvAXyL8VUEHEp++E/14sF8boidLWwZ2D5ODglf67/WR/vzCtTl+e
pqahOM1sqjRbIksluiM41TlFTkUm2lNgvkki0krHrV2pidkJcmJis/KyQirKIiRtAGrWdhxx
xCbxXjWdAmqvwGf/f9uJe0BI8AYBqF4HWsLXnZK3N5GoNkYYvL31aaWu/uCH603fQH8Gtvan
KkvOulX4jYVcOzF1ZLwTWINIbLrd+H6cSC9f+aCxBDfWndxt/DCfE9+U6MfzN5mkAsTQ9Lr4
0ZtNMK1P/s8aVIa3x9uD6n1OpVqtbiMS1ZUeh6VC2XR3ztXdnYvGgDbCLBasaNYAgfJ4wZVk
G5QCRsQNKgUkk8EEi0XNwJtZj8cL24BpqGisTjnofi6lrzpTW2jVld16eTLb4QvIPpqJd7UN
Ta8vTEe71o6lDbS0pi1d0NpbN69+estTnTOkr7UtkXm2FP+aW4/XFs749aipo9Wj8M9rVd2X
Quy6DN//vQ2d5lDfwDPm5i3Vd4oPC8BeOm1M3Yrnd726fmqkr/BGbt873Xzv5P32ZlJH+3Oo
dnG4jdNxjfqXl8hl6jT0qhfMzAE0h86ic46L6K/MdfQPhvuE+YQlVdEPHtGZb/CzGLJwVqu9
1WL35ENmC6Z2ydtstLQ0sykf8vmaQ6yVw2Jlila7IYrKLPzK266fuEgXXozDost1WfunRmpa
k2kVqMsUSVVjfrW5WVHf953wkT6fwCGOizob+YMNBXaTK14eVoDfK5kK5EnCCZKHEwd8RqIZ
qA+uZnACbcPiB+FEFeRZiUuuIXOxbBpiBzGKuDKwkmsEDv3r0Bc+Ovbvreorr2368l/mx4d/
FI82RZ0+W+ylsb2/Rg/b9xa/MntKqr70+UOOgeOTWz5FWqstsOPFX8HZ8uAnNoBKRFFwXlBC
HQaJVULrMCzYU4BJMfrp9aD4itebZ2iZYWgvzSghTWmoIm8omkdr0pxhjdJOYL63NhkgHZrV
7wqI6iqnhbDqiLWpVtuqGWK27stpYoG8ZOqKCE4vHg7okcNhJIRHwzPhneH9YaYcRmGsGuFS
q8ThnQGvwKgMycR5pzVi8mX+ZX4XT8/w6MR/SK/a0DbOO37P3XOy7iTrxXc6WSefT/LdSbZk
6WzpHJ9s2bm8WG68xFaceU1SK1pDStnGiG1G127tnGWhIXRgtg9jZIPsQ9esbIF8aZKuBXe0
0HVfYhjkSzOWDyaUUY8yTDpYpOz/nGQnHQw65pfnTrJk0O/3/738Ozc66U4SqfDyztk0RGpt
pV0soMO3cqb1qFYm8UL02tpfQXnZmivAzSxosFS6mM9efOWDllAdnu2GnMTkoLLZE+66lc2C
qEbCiMgC1AWxrLUkFEYgsfYttJEI/dLJ5jY62dRLQ99Ad6008qOMie7uscxx41X0p+aeHzGG
4VTpfT82DNqeb9poY2YM9i5rpnHtmE2S2+WEnYcuUkZfd8Q9aCpCv+H/deSm/0YEG4Sk7jZJ
PYQkgZAkH5bpUNCjemiPx5cChC87ZiAgeOGbcUojjDOQs9YYFGRU5iz0EkaT87lcJS6L8bic
k+P5UT2/w2heH9R1PW3rMX09juKE0biu6erwgJVSC2mPpI5HlYSq8oW6dEVal25LWHIZzYdk
JGfs4rh23UZBe86u26v2ms1WbWQTRu3Zyf5el9FcuzRqaVVztKq2pJ3TcF1D69oGVPU2o9rs
RGj7/2UUhYvdxFyzIDQTNEkRldXKbUrR8gpqGyPxRTDNthUyX5LrhV+9b+lzqfD4xHw+NDBn
WDe+91/Zx/aZhZz1sj04WPxhMb9w5l9//FLzgKhpmIfz0ESK6DXndx2+tG/Ux3hDBypWSh6R
aV5LKxX5hSimtJBm6rb6lPpd7ZLydtzLe72VWFSMxaK6NqbNALKnVEVUVcXLx6JY8sTd/AeK
4x5F1ZOsPqRTKd3Us57KnI50ncpSXaEuuqsV+F2Sv4Muwk6gZZMDg2oW/gfvxaKqIJ8SV76v
vKbgC+ovlN8q7yp3lU+Vf6gdKmkhPWC/qqboOJUUHSlmiQ7UTFEMBq8nUZLUYqHbItebfNhK
JkfQABnDuC9gDWgpKquZbDClpuhU5jMTveduo+1KbbYrtdmu1Oas1a7UZK2AIdnOkiDPkgWO
XNwAry2vQIK7gxNyg5vYLwn5krm8tRPIJTeQl7O7cVz7j+CF/wKFVNgJ0CfzsxW2rQCF4UHt
xt5eWrRpmARj6Vhq5Nun5l6YGl2mUV/RyiTSzz0zc6JypPnz5t/KmeGmbo7lytBYafuZ+4ee
/8nZE4fsue8cvbQ0pokHX1pb8Rjow+bD4wdgbNDQabq/NkXa6qPPcIH4OPXQEQxulJvmPpJw
gphFOBhBEYLW/kOWezVt9+qcB9gi4YjP10fqXhL0rhhIpXhPRVF7VMWjaB0VqjtE2hOuCkgQ
ApQDxFAaBtN2+jIcdiZGghhROIQT+DbG2JmatrBzYAQ7pTG4GdkDx9AwHNkcHOl+OPp0OHpV
OEJhC99C77zVH+w3++kaELb7BYLdKWUyULmZBQpJZNa2Hj5eE1y6CIPkDSZJTFRrIZ0Mi48b
T0QsFna3qNYKEaEPFPY1/zn4g+nqs9P2t6KDQ4UJxj6TGTOQOU//ofn8X35z8tm9E0fOj//0
HgotHgSk6ZcbV6f20m7rOASbQRqw1lHMufWxhL6GnkMvii9GfoYuM5fFN9CbzB10Hz1AfhEt
INqDJJRCdxBmaLoiCqJII1FANH0qIokRmolInN6lR/WE3uPVkzq1ISFaEhjkD8qKGhAjPTyr
qw6DPHdEFIH3MqwU0IQMx+FO7Tp3m6OD3BxX51a5NY6tcohzRksWN5sKplBckyoJqkdzEtXE
UuJcAtcTaCixnngvsZHACddkS1Zi1ngcm5u10MOWxbbRh6dABCvU3rJMWm7ZdVryTAv8za2L
3nyWJfLwgjzYljyWV2pEHYKw45M7AkAa+oIc0ofQxa0t9MpoPjvWFCYLzd8Xmx8MOs1PbDNf
Yq423qUPGsz44cY7c2Uy684R+umHD+hHjdf3jRFGxp+iF6bGGardYr4KjGSpD52irIehkbBQ
QUiMkdEOVlIpSvRFvWqE8ySo3mSGjHmknrgCcNwmYJD4CofA9DLxaK92PY6C8bl4Pb4aX4uz
VRKC4Djx2RyfdeMrEEyraTqdwRylObiKl/A5jOsYreMNqErt+MKzg/9DfMFwtxB1j+GhYit3
dtIGMGvd930B0aSbQpUxMz+O7hYGkL+3jD4mj5pGob+5PVAwxo/Rk8dLgNbQwuefV/YZRulA
49pxCzo2yp1AsebfT4wY1KNH1MyjTeYm8z4tUfMU9UQvVKlrTj9LGp4u6xLW43qooqJeVfXw
ktcnRlWJr/NX+HX+No95Ao4WCqBAhkWcdp1FQXaOrbOr7BrLVkk5BFjY2WSEvE4JhtUwHc7I
qqQ5clVeks/JuC6jdXlDpuU2hvJs4olSt/kEgpu1XfyIH+zihp6YucIuQrsGPIIX9vcPTjb1
yZ7mtj7a1CcGh22w2o7SYuPPx8nqsf8r9I3G0UUbACqfps3FogHopJszWHbROUYRtGYBrbr7
uOKiBbbAfARoRalf3hDIxAV4YrAKbLE838VWfB6JTFwwpsbqsbOx1dhfY57YLSbvOAHVhD57
BZosdjrvddLVTtTZiSVNoDRiqzTOmMKScEXYELAj3BNo14c5FRbZs/wqT/NvM3mw6Ae1Zag1
gA0BaTPs3m7ddyGCH3BI4pbDQy1ItD5PBxklDbpMK58QXc7VTh+WDOZ1o6vyzXqubEwu0m9W
zm5vnznaeLo+htwZCTcrzBZzFT71InxqhppvzrA2exg+fZ4apT5xQl4v7Efe7i7R8pNDIS0V
rjHSUo/AzaveV/2XYpcUzHk9fk+MUwa8KX8qNqB4U0NsAufSQcnEewYudHd2FHIXejt8OlKT
LpwhXVAdkaJKqLRsOVz8FjPsCNjQkiIoMJgyYZVw/NJQEp6/6WQdboNHhIG3/AGLt20yQzsb
GBjZjruBDsskXj4NNXb+en+Z2itvbe7d3Gq4wiS/0UI4WoR4gX3MDSfkDhPkCz1idUFxbEVL
GKKmCwwaSkAL0zB0gXCoWED/pr7qY5s47/C9Z99hX/ztnM92nJzPd+evi3OQOydxEicHlEBL
44SPFArNnG6jY6MbOO1YP9YmQxo0jI3uj6nT/mHa/pg0VRMbqgaq1KQfCKZpC+qKSiUoaEqr
beAFbRFlE77s99pJIMDaTftrkfXee77zq+h5nt/ze35eCJZejxhD7/akNm790S9Ofbe4JrIR
ja3eOfHWG4c394trzQNB5chEArVHmg+93Gw+JJPa15C4CTW+ex41bEUNDw5aZVPcal6/8kfz
75vMSyOrSZnMk6+0mHvNH5K/rXxZR2PoOWBIBVouVxnaWavieaZaxSniDWNlQmKliMRIdFxq
lOqlOslNksE+mlgBtSy4xajXxbtpqigcEyaFacEqVE3RE0GRdEIkeUI8nkDuxECimBhLHE1Q
gwmUwPWcKCieWj2zPEuyacZFiwYzyOxjxhlrkUGTzDmQ6UI9M4X0feq5XCtobVlFa+qCHc6U
QbmyF6t1IYzXOnktgmvLbBK+sQ7FmaMnK7u7M63t6KKWTPW19SblLLrYpaZk86OnD8i9RTK9
S0XgiZnHKhc/r60cIfliG24ohcrZx/IYNx3cLwu4pYlzRsOj/mf9pD9p9+jYBxmrFJd4GHrD
7riMi7wFHshr3SIP+Vr0esO2Op5h0mGUioT4MB0/lp5MT6ctacPl0SfTKI2xUhgRJO0iaz65
jxqnjlOW+3plcwN+3xflEZ8Oiy8HEBGYCpwLWAIw01xb7ojXZkrKHV2lglsKpKZbylJfAXdU
Smh5U87inBTPZpdAZQHU1vbqvTWrqYkuM/ZA9Dejm/cLUi/6Q0qVV3c+GcOWSenbKu/vURlZ
Zlp3XzX6dwy8WNRsskxnhl/abvCfbMsx1bQE0wv9HGDZjrYaazUpCSEnILlxVbdKKYg9XK1Z
g/EQbdgkMw12tbkxXGfj7fRkbipHEjkjN5jblxvPUUWof4w5C+DkClpbi6hlDDCWDEY3g6FS
iaQnSSbTqnZMIzWjN6vhKKpqA9qYNqtZ3VqvNgLbo9q8RmtaIIJ/4xAa8CEN+JAq3s2BtApl
MC1YVGFAGBNmBatb6BVGYHtUmBdoAc4V8LmCUGt6vNvNu0l32mq7OxBMQSSw3I4EHXdEgpna
eDI6XJlRlKprw1yhYAuHW3jjr5jaGp+Y0WpZVGPvUky4MyjcWxOf+g27vk9MGej9VXK05QlN
FrPojC7GskUNigxd6GnOZuX+HLl2Sw8kLVtPoXKiMxXPkz07DDu+f6Tyeo8sdpMPDvXAPZl7
vHJ6s15je56pst2FHjfW/3u2Ozruy3dXcjI/lSeJvJEfzO/Lj+epYh7lMeNBgC9f0Dr4tv8/
0rv/C9LLNdq92j3ELxji/0591Uo/g/5VuXjdD34m93eSa/5jCfx+qNP86JkXCYIkJPDPPaCC
EBEjpk8RFuj/dogGNM4H9Mn5m0aKDeoHoxMxMhaFHY+XFXghO2AJSaxTshPxcNhe78fkN9kd
Okyf8QBfTzfFGd7OQGYMNcAQJKqQl05a2oyEKiDBsBpxRXfDKErCWGotSUVI9Ab82Me7IUFd
91vwcScigu5XlVJZGfbcKA0rZUD/2mIk6A5fI3rLZfgAT95aKvfMYOeEPwIHAKS1Blg8X9ZC
5WKawuBidAFunWzfMFv5ylsTJt2ZCgzt8Mrk/s5Uk1p4irS+9OKm0S7Zlt9Mvjq4a062924x
PzQvZdU9O9+ERFWAyXIOcPNBx25F2imCmr9yQsjojpPzV4xCLKOTSbhzR2FHybYEKwcTB1dO
tNKtGDsVL0m8SBhFTvILUlCKxOLptB95mxp4X4S2t8T9K5h63s/oGFhjY3ZQR8gG+k07GbtP
dBr5rNs56ySjzuPOaafFaaxbrzuNtVmnkW2DjZKBpYmHxZv1YOjR6yf0VUYcU9DANYqGoKQ5
e8QvruTGuEluijvHUSMc4jDs7R06vr7WKOhcQYMcoIzeOWkC8p5K2TNXC1nKcEm54yHEtFGl
WhKe8vKJaTk5CrQ3dvmQmUVLu1qDq/EnWhbZouZ2ZTpMPqs2d9zq6kwpHejD7sSGuZsXL4xn
ooWn8HTwrcpr61ZbZdna/RC5cV0PJd96tMph9uFuEL999dDl7zz/9GF02rz0QBQzSRL9kMRu
AZMBmKB+ZXRSPls96wvWH2yc4Omq3CN4YfHixWzhkIuN0R3nOKLqhQ1x7I4CpqkOVE2AvktN
hh8jXW9lRMMVhPkTBlD1tt2cwHaDr+qq6hVDba2OUIDnPVB/XFKqUq/cB0rtMzDrvxenTwUE
smkEZqZmy9toC/mC5esEMUUYBBE2PETIHUIhXLehsNhRCioF+HdL3ixg+PD8DPWe5W1CIDLE
nHHExqAn6vbXkYfREerAigN1p9HZxNnUmYyNj0JRRKWIC7qLHxQv9DmdEX8ybq/zYqXH4pYV
oH4jQssGQ/COouOywzLgGHdMwmbWQY05kMPozDqgGBwOl6ogxTBoIwVGQl+mSbqkNvrEqGtR
1ljSFm4BbG4B7JquJdB1y71gz3WDzSjhyrA3p2Jdjy4+K8OsASMGZqC3vOQ1ZQ9YOwHvoWHU
tjRUkAnxLlkDMSyLYrTXgynxeuLk7sDVX75zY/bMm7P0jzPtZhQrGl35Irm90Nez5ZGuDaT1
d38z//zBefNj5Dhv/mW5okHkN9CzPzHnzX/+/NcIguZBYEAEH6dBxU1ECoWNgD2IKN8n/n8E
LUwoHBr3fTt+M0SBpV43XIGgLnqwd3tYDtvVn4y8lNG5SCJC0pFAJBGKR6xBn9//OS5Yz3FB
q9RESU6J4digz9WXStULfYhvom11LG8w/nqGq8p+fXYr932OPO3DBnLBcIYk3Rf0c1a2iMc7
aMHtvDNN2QkbZOjj1PRdGXovRS6kaEUywobLr4fDbhbNs4iF9Az2Xl5Mz7e5mhn2cTlo1lAZ
MBuCzUCBADGV1lZvrkrNIapFOeR64R2gCN4Cv8GEIjZ223WqkTphgV27P57VgUIOJkG6lqut
tKo1t5niFyTKHT1mfu+rLU++t++Vqb1dyaFtz3yjjgWzaS1Wru7eCNRQP/2AJM0dMnoeiWte
3f5Nod/1pcJICUEtDUAtDVPbyX/xXfaxTZx3HL/nOZ/fzvbd+T2xydm+l/j9Evtsx4mDD1aS
hpclpYMBwgUGDUMdS4I2UZU3rSsFtrV03apt/FG6aUjtNgm0qS3dJrVdq7KJPxpVK0xiaPzB
KEKjZBJD3Uou+z3nBLKtWhLdc47ik/P8nu/3+/lWqQcBuiLUs9R3oO91GB4aU1WZpwxM4/Ib
+ATECHzCSoWQ2Yg5RH/ErKGyaM0blBNmFoNJsTwMjuWFoG5nV7JzTvqiA5ksckLe/MrL63Ey
SBkG6UnEu3QeiIdRVRvXLXbj7m7kismynOhKigl351m0xQjccsw5MO/oceAZB3IYkqI7rJSp
NnSHIzruclCigSibzcvzctBw93jHvJjzJrwG3BzynvTaKS/vnfbOeG1ebz5vuD36ZP5MHneR
USdoRywru7qPo9MII8PN6SghpWdkpMlvydMyLc9LUp6XpDwvSRn6qSXJqcbdBhSk+7OGYeeA
v2B+q9ZuOGN0xiwAAJHCDygTGICgGoAbESgMnyi01SBaJfrMWQqFJQBKhG8BpBr2h3gGBOq3
KmnKsUixUqWsqyPoEDps7nvkqfGjoyb6Qiudr44NF/Jmemlm506FSSunmub1PRPmJ7+d7diu
xvehL32KwvvHJ2Z/t4b0LFd9JX22uUIjbgpzpw8yT+AqbsFww9Qz+ygqZQTRlo6JDtxhcIJO
dXRwnIFQ5N45yE1VyDmAs7PRctVfGAFnLBo7HDkce49jdoUOd+JA0E8mphNm8vPBsGvI44nz
lTCr4SaGL4pR4w6OFVnMsh5MiQjRIgZZcxhh8ka/S9AxllycR/RgjzEN1k7mQdydzMPj0zv6
UmQewFwlgsKgwzIPG93eXcgj4NxWk2juplAmf+Cvw24TLywHJKIje6gckrowaCkCDJbCFd1f
LkVAW7RD8SljLzU3xy5cQGJrbO8R8eHvTnx4/Z8/W76pyav0O+bFP33xqedWnHxx7JB/fANa
8sElFIoFYC8fmruKIWdwmFpPkb3NAsJKzFfg9Wryeu4yvG6r7UNrr589R1F9r2I0qSKV/Hfw
P1trR9xaDW+iW6fUoIcyEMaLth+Ap1KB550zh9As8xg8HygBXNYzN8OY4LJZqgw5109HIc4Y
p9MdckbdT/ceg85CMKGHXFiLlAkwhFnFqbBqpOaoRYYjDpGTkEQ+xPIR3Vq1Pms1VoMGJFHq
YP2yzyZ3yzBBCHhN5USfOzhE4axI2SkpNESpkCCq6h8DzkjGfQYr6D7Jj4AM81k359f8TT/t
J/Dh1UrNEi4ZnAu5pioQbYSfF+EzfzWnwQzJOG/eJcjG32ybaBsxmmWiqlxLA9ZozXNbIBlK
LTDGAlcnBXKfIg5aLoWCCzUGLRDIv+jy9pGPZ3e9c9Rk+jPm3fzB4bFtw32PRfI9pUE8TWgb
zPRbtxcBt7nz8subtjUH1zw58PwVxG9+gDY/t8DemBqmKHsSpqBRfYgztjE+Jx/yRfmnq8f6
7H1k2ysWrJGLlwyAEcICnDjBFpUtH3RD1yjKipyhWLWzpyfhsOXSIpOx62qiK5QUgwm3Xepl
tgQngieDp4O2IDE1H4q6xV7Um+WiWhRHyfaGtRqqGQZnNRkOcVP92TERieSv+SJxwExC+r+W
lwTLq38GhbTaGEKmNQv31i+g6zQspr6H1A3L6tol8/6EUOW/UXDRmMJl8Lj7LROiLsTca0J/
1DWCiSO3ZnefP2AyA2nzdrbXlJelCw30554clkVt5HFs+3i9bm9z49GDo4/XyLyQy7yxoaQo
yzfi0vo6UpSeDXeaZFzjW98mebYK2GSQWU0V0C+Nho0JMjJTY87hi/gadriZKJNmLiLbML6D
cEFS85wsyliWM7TXKQtQi5LyEtYX6xKXAGpAdPG30BzCPOoh2QK5hYh0ApBbCIXGaUdazFCn
vW96sfcsvmSsFPJ5gZUMJwhDQLyQEN4XaAGak0DakgBtSTDq/XADlUkwenrhAr1JMLrTcEnJ
cIEGJRi8oAvQnwxeE7UzGta0SbgYSysaGSe831rhEdYKT7HWfLG9wrOsFZ5krYGQHrNiMoei
2aRLOp45ncEZEpOZJZIyk0Ra8q3kdJJOzp+Z5PyZSc7HZHKBXD8jJnO5hUrG387d/2pNLc7N
zr/B6eGvEgtvB2c7Nxvt49RYCE/CTcTNrbgM/2dV+5/EVK0DlQyh3x/59vonivIyU+2X5Nro
56V+U10uPfooqhXQAXTEtst87/ubn/q5+b2dVagfbP829OODa/eb7PZ+eOkp76RfbD7czSg/
bYK7g85tT1rJucNip2eoT8CFVSOKqCpfnazSx6t/qc5V6WC1yjCQn9V7Bt6aIq1EAI66yayl
QtQg2mGoNYSixVPeU6HXvK+FmOHi3vAJ7Yfl1/O/1i6IH4k31Gv56xqbIxzlHajwnF2ESmFn
VeosPmEs8/kCTvg+RCOajlHxrXEcj6fTUiqVDA+GI4NSMsWlxBROPRKOBMMpKRyRBgeHioVg
sVgYHIhFCBZPGw/VwOojyUKKKYbZbPeSTjEds9dujA6gged6OVfEXcC2CFUMF9XCpuKXi18v
nIi8ULhQ+GvxTsFzvnCpgKXBSDKcKjhiW5tXmjNNummFmJjWm+u4jJjRMnTmLKKNSCxR76k/
UKfrfxB1pOeoGB/DsbeX8rdbt1s3W/xs61puD+DzntYUHII9857SbBCg9teP+Io53wH+3SPO
YjTXIncOJ99wNpBQjmolrUVIDKJBg5UiB6hFjkoOEbqeD4FImHhKrdo2IBqp8yUoGAkEwGra
/uRA91ODUEENJ06+q8ujqr9/8MFqIDMqVV4/b35QXjGA/r6x9NLu/q+ierVqmP/YvnfXqokV
1d007lo2Zuvbsa6g7+/LK/3fKGnrt3/6E/zq1yY5qEt1ZdJ8HsV+UF9LK4p9xcuzq+Ze2LCy
OvbNxmXwpKE5t20dZEiRumI0fuNEx/CPHK/gV5y2nNwhJ2SfnJXdSXAfTg4wTHzIXWRF5HYr
gW455BcD9i3KSeVN5X3Fpvyb8SoNbuI8w9+xK8myjl1L1q6t2+u1jLQg2ZJtHBS05jQ18QHh
cECBlhKnbUIwM6TptGByUNJhGpOWSZsJM+RXSmY6BWxIzZGETMnZhqbtn8z0D50ytD/ihKbE
nRQk9f12ZVUoTdsZey/t8T7v+zzP+35MynVCBEfiCS7Ms3q01jkzPB9paluknEpgd2IosS0x
kZhM8MNswQqKTgymjJ4SdDeFYQSMuxrsiu4adu12HXBx21z4ddcHLuJicoebXYNJkDvMtrez
ULdr8wshplJYFsGVPDLFm2VVZAMak7Ewe+3aLJt+8zgfVaBlK9AXlGrztxjroHS69orEbfj8
tvqd75VQpguc/8NONTYSX9WqxfGHWeDynz2eB7+rZjaRlZsz4PT1y7cWbn1DW/RV4t6es6oq
zg4X3tyymECGF8DcW7A8gprQ/aDYiCNidUYaJAm1i8EGwtuCVpsUZKOmHnbCrNnkt7Rg0dri
xmEw9qXIgeFv2IEd+5qFOaDWbP4m+BMbM2cZXphTGFCACq3PwAFeVMaiKF3Rzu7unrRIFua2
qIW7E/f1du9Qyc6JvUtllbt56/r4ClUd2EKP7R1QF+56uniQzdow3n3ObUU+NKHn3qq/Xj9X
T7lWm0hbfU6nsMoatlm8KOxzhlmn1+s8GfcG2au4xbBIxDi1+ZQbFCfpJfoBpbRs3LRs3LRs
3HRQKhu3UcqPoJTjsyg5D4bhY328p3u+IgaIxqjptGuWqZk0nt68OuFSi7+N6cVm1dZzH+nZ
miRqcOCem4WNo3dZVEDSh9+zXiJbEEWSbscY7WaWxSMm1zyCea8jxdZBfdYJ/N6zzyIOOUt/
sr7Bb4Fpagk47gB26R1r+JX+ByRaJzVJm/lNfq6Jl/xxntoCcuDbS2iEqHxSjvv/4edlTZOI
pGkz+Izeh4kXY7Is293dn80eSL2YIimrJhMqSUEBRt52pT1Y198/YAs7P4H23OBssNJkEBMO
e6GZP4k5o5MH1VgGExnZBbtuH7ZzdrsUJO0+X3//mjXp3hmcm8rlVsJOl91pnN4MY7ncjjRB
07Vh7arGa1qEjbQsn3P5QidbmoBlwZ75FGgmYXQ95l75XDppHghZUerN5dmts4cWJQ7tu2wV
zO63B0zNE8ViprtsZUpLrI0tbRpFBVdPvT7JGKJEMDpcvpH9IMGd5fGqDUN7fBn/HV9q2f+1
h3avXLTdD/xP9MYKj8Yf3/nw+Opk1+KG+tTizuH7h/m/PPmLU48/du7Yc5oUaIsFgsXLZGHh
D/zaQie+60cvfWvXcDZ3IBbK//K2ixMLe3545IFHv9LVt3xt574Z8vETC2jx6MmfHr5w8ujj
7/buPn5+ZMczbzxY6Jhmk5i7dI1LGeuXK9PPt2EPa3ZuwZsRBcEZCUVCrTJysiosAAtzOhst
ra20bjKOP4mX4iSui3ImrgfCmXhclq/6b0BL8cfY3XUrumIxBHp1GCvSJXrG4TgOX0P4OLoB
fRhZIuFo1A1NUNKOW3DOMmSZsExajlhetFgsggUmMzE5DqXIj0MJxtNG0SD5oPW8CC7H2k2S
zSnje5BRtGQimxXLHSht9h5MzJT3LCU9UB9rbClJRxsVaua/J12uSI8H/7pzw67ujfHlXcPh
daPbIi3t41//AXnhqogVbY1D3bd3+2iDSi4UlX8uyybTI5t+tz+RdR96oeWj4h/F0Pd3/mT/
6T0T+QO4DuwC4+Jq/HLpN8iNwujuPjvi6BBy0BLywj5Ai0img1OCZpuhg7qgo2FEUugU2+iQ
EwZw9ibzsjmwMJ4xLEQaTUq1SSbhfPPnGHtiTbLq86lyo9pEKiewPdTY2ox9qgSHnrY34UQy
jn0q4lGg2E+eKV0x4oNWjYbQzrOyTRNQ60WIUINIV9ChqbVrM+w0CwH3Q8C63v46HUQROgJ4
BpEDLYaLqVTgPJx46cjZlEN3EEcyP1dg60SIHnoOaAocbY6tT7KgHP7fSEAE3UoVEnZeA5av
AavWgt9QQe6JvQ9bE7ik4iMmVjMdxZ/NI2e/4lFzb247Kxlqhgx528rpgwfWwz/70dcKr30H
TiovqTqGRoY6IZePGbn0IAUtP4cEun5KFLm+unLRZdhHIIcBSJfXy4p+Fun1zgyaoSOnPUIy
OZcwUwV5Aj8q17wKJw+uLN2ZGvx7E5sZSHE7XnuvecHcHqwqt3Ns7EKZCgYWFnNDcRV5HmJ2
Qv0Xoj2nXZ4ZOjTd1BTyz0DwgQD3GsRsh9hbYR+nxTOuJkGKQeRTkYiV1RvREb0u5PaHmdQl
xuN6JGBBSIZyIRJismQemxcMEoC79pbRFbKAsLcCsdFnoLHOH4AOu6BHNypSlbEC2k8BTKgL
dyiS6vs0jjtaoNiJ4/jwsb9ByUJdKXb9INyjxZSUT90sdygpSESHPDA29ipgNy8j6EHFt/GJ
0sNQq8CrUJshIPI9yAYFmZceI+wXRIdJtciuV+sKHposvk38xjvDaOk5eNvQFLQeJhwBXg5K
OevQwTQd50E3QIHpA17sZf3f7sx4wcdm5xKmSth3a/RQqw/8Dnx/vq5XKoT3xH5czdzKMQQK
tZ4EfvorWl93Ggl9dgjOBrw066sBN9vp4JlIxBvgZv6feNmIafDVWAz+r6g9tbL9MhS91fbV
+WWQiu9XexkGfJ+R5tJWQBq6ALxcjzBdp9sFmG0QEoyiJvNGVdlwM4kPFz8bG2Md74iRl+dQ
A1pxBjksoptR3+UC3EPIQotnG5x2USSM2g47cmGXKwVzB7Eb3BaAyqJBaqAzm7hhPKvCXCYx
nkiYIRtULV6TO0yBGrxkbOSm8Ql+tJqN9/4HNuLa/JFqqfMWQ9WykRSm7Tu9fQfzo6FpWdbA
boZ0wabryzM2vbMLNmElY+sT7mSBYe9e2AcgokGICHSeCugBcjKAA8nx/Jzh7Kz2MK/OMh50
pKSagn/hvAbAI1VWXaiYmCf28zucubr+uyvmCzB/VW3AkEV8GZ8g3wS8zRfNLNbkMFmTQ6uR
w8q3WN+sOLsPe9vgndFiP366dBSyGX2FZZEgehHyQ4BdFKQA5k2N5UYyD/RPw8gXHRt7qHgG
WDVK3iJHuAg8GZyiFL1GIQq6CloupSsRB+uS62xSATJGxego6Sm8y0WKLzEWc5dJM5+oZvGG
/8Zi7rLJ4o9Lx/BF7ikW6WkCQerw4EZESpdecYsZQnjOXA5CqGw5pIj44hXuqVsy91f0L7ar
NLaN84h+H5fiIR7aJZe7FCneokh6SfFakqZFiavDOkidTmxJcX1IctXEjR2ph9Moja3EsRuk
DdAGqF0EttEGLtKkhxFRdmU3jv+lLdAgDQoURZo2LiDYrWEB/SGkQBFRnW+5kuOgf/bQLlfz
5r15M4NVV9QVai/oz4S4d1G9oj8tcfe4ojyYlWom3KpSXSGmp3htnQYSJoT9SUz6Cd78qrqC
6C9+CcGXtMqXqIf8/IfQbl2ZjGtLvkI4FAXxqtCVzbv4M7UIXLpQK8xNOmocPiOBhMcRT3XC
Z8eXjFF2hRqv0E7sBHbJoLQmx/pF16ndK7d4X6IUbRlKwzFabk2Uo0fbd5RSh9VirBSHCzjG
S7ENFCslRsbhtd4pktvo5l+pdfUx1I6fuRqgIZ+Rlc3bksXYIIYiIJKwp16v83rDGK9QE5JT
52V1Oq+QC1EpSSd5VTpc74l4NXmuOd5poAZQnupHKcCiARw8NYg4qijVe0M6rKb8uUwb+bTZ
6hLb8hEhVm/xGF3CClWq5PMZC3FftlGUz2ZGPv9aWy9aLDFj4gZ8KU6VJbYhhmMSPI1J+nox
FjNmMpTmHXhYR5VBe72SsdgoNUfFxkYXxxmJq+ldkjcqulz+4E14rRle84NEO+hP18mULcBa
REZs5ZaISJhfl50fCh+ekEsmLx8EOFj4PCGiuLZeINfzsDh9xwwrkxl2JnOhUNCaYQAsvK1R
dT86cR1FCCK/CDvCbXLGK7V7BOclcoZ/IUwCp4KAeWBRG8jC+kQmdr5Gqi8Di1OIOK18SGs4
Hmdz8iXHy7/QBMjr1Jx/etFZFxCqrblkR1+wlK7+dlhjvTi6b9Gh9gbxBZPnjRavZmrodWtH
MWLHS/7p+ZNHUiNhfF1o95Y6Bx7x7cwETW2JwBPRXzw9uOfEyZl4OVhdGClm3hqf2mnSWa9K
HXR5JBkleoFNhzqnPoLsaLbTAGUwAHrtRybgnIVm2wesFyssw9kI2sYmkZyv6hnRZkO3qBJi
qB7kQAbgop4qL+vsPK+7DoQ00p+m4ml6fQ1mKbLqpBnSdgrFtVXID2yPgdr6kubSpL4AeZry
WVVL7XOrc1P9buPI2qWTzT8e/OxvZTz906mDC6UXJnq+//fvHni8eglPQ8y+zXuqP4HGW9AP
lj1utV8va5XEbYS4/RC1jyoiF9Upmbw+j9ttwy5JbxRdK9SgZGiSTGaxqYlhHFACpWs2m7bB
gR0roDZD2O+TDIzo82nribz0IC8t1Y1CW/JK03fICkc6CPEngQgrbQFopJpXycSowGvZYpXM
Y9qaBogiqADgTKdgKHqvLfnieHeTbmo2VQqHzYnx5Cj/qvrF6geDb/cUwqpgS1uX+ZsTRw8X
DIY6996g+O3srtzQ7O7JEyfwYvUcno5NQh7aN+9R3wDuvOixyqQDI5jeB2D86YfaAfqgZG1Q
rnre5KQY1mazr1CTFYbx6OC1XuQHzx0E7svIA4T5CET6DoCD4SDPkLogZQFwDliBJV+NJQ0g
IUBgIc1mQmI25yM0nnEbRvF6OXewp1TvOraHZtVfyVUX56bUR3raeoaf2NE0uifb+tLg7tN2
zjX60VtXvQulRdg35eg/lqNPobNLySY/0LPs8zUJSKZzC4cVZvlOEKNAsFg5p1FNs6yMhaaD
sJj0VkS/Pwj3kj62IyYIsZgH39yG1o3SCnvED8gItIVSBlkoFmrMEVKhT30O6+egQtUqWLFN
Y+OhG2sC8Gew6HTqNbdxVNU7lkyM2Z2H91lonVYsbvzr+AwOtKtwLDXSZvXOHxQgF13tw32J
sS9LwxNPdb/Cc+xk4nvnb/U9PbS48YmPObnYPtYY5rhdP1t4nlTlzs1/4/+Cwq1I6uTlqtQo
VYkgGRjUDW/J9deLbFv1B51nN2JlJmGdlRmEeqsLMWJLS2jbZzgbw+LX7M07Dl3sduPjk/u6
aVoV6SpyrPDzQ0dyFpNpZmojsb8WxX3VHojCg55c5vSM3SQLzA6RWB5EIjVwLKL0DnudG+NT
WqyVqXBLeoPodhtYWWw+ZIYQTRCiAUL0botN2DiQioPzMkq0tRLiQ1tGKQftVqW3zZFQcp8J
6h17/tPtptKX6Q9MfQveHMuy/qFU26/Es8/wHz75JWfQarvZleOi8fj7Y9m/AJJu0NofQGsp
dOo6pHJgSY8CEFk/1LgEBhYFKE4UAzDGgCficPmtat7p9BCR8XzELIssiCIysng0HovF42ot
EZkGIKkB0kMiW8vnt0RGsFkUnW0UaGJ/29b3/4qqprSHyqwli9X63V/vhypT9ZZzQqrZ7lwo
sBadNtNRLQ+qTS8/woZUqiHVe+PHnj1ESq4zke9v6xg7OPvYaSPn2Jt8+fy7fQPPBoUzu751
xshFyhfO/UNmFxhcBXZD6HzF4+GcNyAdfkpaotUWOTU64NoA6eHATxGkxhQK8o1uC0dTZqSG
HaO0xLJmaAfXDEbRbNa4ibvqPaSTezyaRqjhEgoC9xHI8SB8rAzJ2o3CNXmuEfKJjwqQpny+
liZG7sarcF8kz5OJ9LYGaj1U0YAP8hTwa7QBWh7PaGo1L1xq99bNnxo25w+wrCrfcLp9TJ96
dfTw12Y/urb8QuTa44ezLL/QW9jlHBkamjvQcXemH/v+/M8/Vl+v3pFzgedVrZALHnVVMEK6
dwC/GfAzlAQDMjaoZTg2gNOIGgCOWZGy/QEcCH6VmCdQHMpChKTmyBRHqOYJ0xr8nLcY9Hr3
n3qqyeox7bv8kwk8n4oN9wTCpnrz/hORRV+fyXT76MWX5Iiql6lZuS8PVywsgzqNEA6reCJD
dSEGml0JCnG6YjLxWrnMHNueztea8Janr8k9apV54HGK8qycFlTGyN62SHz87tlg2BnRBxzd
7uqJ49PgW3PP7Aj5xczGhVf2d4dBG+BYW3NDEeLjUW+nFa4HkFUJzgh6MYBD0RCeVs6YEtUy
ZzQYuOu1tCnzgTIKr9biSqcsNhomJasvRTiWw/oRzANvfvzm+7+rPlfGv5/peaN6R+4t1bX1
6of38PTMo7+EAQHm+U8271NhjRbl0HHJnPM2WERDUpNVmxCK3FLME0YCCMcBZe3xCDBCkvz1
ojwos7ScTBoEfKMW6VI2a/gNPBUg1p3yDFObIhWqa+lMk+om8541zdbmN9I0lLLWaEl6/0d2
tcc2dV7x+7DjV+xcx3auHT/uta9fN34kjl9x4uDrkDjBdkKAvENIYlJCIRQGU3i0bIVVowy1
q6ZtWumYOoYAaX2sIQmPCoY2BG0nbf1rW/tPqbZ1mqpW7bRJ2wTOznevDakaJddfLCf6zu+c
3+PQKMujGUgit4B64InOMR+SNwfbNFM0mm1ZfPjASOvW7lZeFvGODmd3bT1afvWFRk7l6c7W
KCJ1nDXrS3XkGkOLPxl/5shgV6Srpcg37x1ZjI3mejy7zw31ZPqN9U7KYd+0EXx1M1TwOnRG
D5K26zpmXvtCUNOWGEYBTzEaBrkPJGsTtEbArNAqHbSKhtCOYdZ6FOm0EOnskMCL8KnCEkFY
ERA6MFIbNAsBUcFA4mpaCryPJQ3sxamPJeUoBjkBEBOufhtpF950+fmND27GiPPbZsv/2Rsj
7ppfe3aiO/3Dsw/z+NJC6t9Ls1uey27cXlWmL4GNQey8oBF43ELJ3H6/u0aUJcQDSry7AAtA
7xLHYdfIzKrBYqU5dxBk6SqGudVWq0d2Ay5Or90W9CBJNK12I2lyu9WQFkQ2M9D6MJRbhH9Z
AP/swULUvyTvFLeI+opEocY/FLcGJOQU7At/RQDAO9B97CCIFJWM+cIEgsBYTfIgU4m4mP4U
MM0JL+ci9KZ52V+6twptWUcrN3BMpVT/9tDF3bzj4d8G8OvUz09cKrfa8L7/hev0rpnswQmL
v0aj/4YzFNRwmud/1/CDT0+/e+8FvPTynfKb5SVWUgjRnV1Y/xWFrsZ4C4DRAUC0uK91rdQq
apwyJfIwkqy3iQLhBgkrgooUYO57ME4sVxQIep1A4AbJe0ivOKlSYaBhqJoaVBn+YINqW5bV
4GztsTkYPptiet9oIV8fs+CvlS9H2hdXGjXEp7ndnvpurcY527d3KqtWNu3pCm+YiXfyKL9D
/IvCzSG3ZtViQxVw7zq4NwsDyZCZZYcNI1E8XzGb1Tab8aYYWCutWlazDKO+LqXW6prRilqG
nCRV1RMcnDNM+L4WxcX+OA34RVmNUmUNMt8Z67EqZucjed5fR4VkD/9ZxEsJ4WCKt5DaxbF9
U2ICH/K2nEy0JAc/ObDTCysIsKxv7RPyWWBZA8ZhI29hZnE2q7yyQRkUmV0xO7FGoxPpTC1U
4AHlyV8Bf5LflNiFEVCEuxIdRF49NkEglmE9qygCLU3IUDwoH0TRFgEcu32kgMhl++kzwpv3
OgoXnk7j58sfd753eHCh/Unirvfl46Xupx6cK39e/qj4/tn5n3lGh/7gG+md2ypq+Not8k/Q
hw7YjzTQFpYlHAzBstfICUHL2I0MAG2P+sJxdVYrNmiTGPzicA7AOSw1bIlhiBtQsB3FJzuh
1EYjvjjrYZzQv+WODm3Egw7xeISnkLzWgapotREIDoIKCBmJ8Far8gY5Djkjt9zJMHwQoRMA
dHhAJ11B5xErU1Uprj700HOJm6BOgBz6Rr+fUoYDuuPUHSp9SkbdSevSb9UQG4fGBPUgNogP
soNOGY52WoMrhlVenZVXFl6X0PsB+Joah1FKJhLJhMgG77ocLWW3GoXc4FkXV6sKwBnF0IJ/
XoomvVq/NjrXn7Lo8ttz/XF/+Nh7ZQYkcfJA43LAriyNvVpbmPS1JXl8i6Ym+IRrM2MO6ZjR
bfunN2ip2sl0Zrrv8i8XVxqS+Lynp4E+mRz2vL0wmtJpzSvZ5oaIx2TMb6lkhl/ATDZjp4Q6
c5B2uex8MEjzPI3Zb0HT5NA0JTSNBnWwezEmHIDMthoMhr1eC4PYFg6TNGWCZpcwCwwtBVYQ
AS0pwl8WwNt7sJbKdgG6KKki6kl1bNHUwq8VyZTChvfRDDsIGgChkbgo0ErCoSyHLB/cEkZb
wcEn/zi8KceqJ/CBfKnHIydwnPBpnmO6X1pzdnrZvm2HooY2PXHXdLBzca7b1tFfpH7UbS23
nxj/8VYNGfrWQiqTTuT7Bn3Dk68AGkFwkSFAowl7RbA9SR4lCUxht5s5n0/PcXqzUEfFzIKq
NvZV6upF6mauIurqecoLCC35fI2AzirPE04nYfp1hc7BqkleIWCDQnoUQDpEVR0SzefjERVZ
/VkgsA4gpLVTVZJHRZKvyz5fR+fWnjxw/cPT3x36/b3yvgL+QannUvmShg36BtLHglreQPw5
fhxWgIN/f6P8/j/wUmn49UbaZmpLtlh7/U9I8yErAt/bsF8Jmia7O4hjVqsKC4rsdgIAbgBA
tY7pGNklWO2swRhrCvrtrdYkDtNgIex2P2OxmAgX4rOTLAgaiP1aiP1+k4lAhpNMav2i4bQD
liLlQbx7sNRjwxFRCEhUln7QFigSOYAmqcLiZonbSM0lO/JW/Widz0q8M9KPdgSFtFShT+BH
PTqZp7apZcdgNOOQ75q8GWxSn33jYgc7Pzu209R6Yqa/Y0e+RqksX6CI77+4390QYRU638jm
+YmMWlV/Jrd9fDbdd/VI7ML+8bRWo97dP5Cgc/3pmZcyjDsdD92v5pWPAdco9o5AqxQWBSEX
aCZWkE/KiRDrb3ZoyeYsBbh6AFc/4IrwNsC5AWEMxOoFJ8ishgLNchkXgVG74nBwzUg1WTbA
qa6RM8uNjZzei+D2ANy1HIoyMMSwmgCFcytxkiD0RqSbBoBaD1DHqgupaJH6R1hLD+lHWk0/
Sz1CuwL1VACbwkkYxDiSu2RiPeYNJgUAC5B/VesQ3OSN1IN3ivgHh1tCBNFcHJ5Ih+za0d7R
orz9m65Nc4M+VjFdOl+bKiykcWf5I7wkm/a1+VqbmpRK90i+tKtNpVRNdhyeDk3lJ60HZobm
OtTKuuuDbtue7YkWcNyNoG7fAz5zWABbWOXr/W53PQNrUZ+4faDNox7ivR9WIx1M3PhqnRE3
Gr1WlAKVZO5KyO33Imh53oXfrKxJLkAqWPXfVEri7ZQY7ysh7/HGVE3160N9JdUDFoaoXpS1
M8iNb89Pdw0cGpZHvGO5mac7PUfLJ5/aeYbf4YK1Zc+F8dP7N+zo3oIifH6xZzLUZvfshqWq
3PTgyzHeSPzmJJqotS/IItRqwoQsLY6KVqxTAI3KQjkZTAHPPChQDjYw47rGN1QUWqxB3KvQ
1fUVzXW6Ko37L5489+0BrvNA+cPs9mifo1bGvnj/4bszAR2hmt3RMtoJOiJNtjwPk92LBwVN
gKozxkzoYbi2dl9AB5VKlSLqGX9CZnH2Zhvgnlm4JwH3DMK5Dc7NcEbvO+FsgXM7THAv6GdG
aOj4P+HVHtvUdYfPOff6Fcf2vY6fsW/iR+zYsYOd+NqxacAXMOAklyQLr2SJVRJaxitq3Gqp
yspjVSuKKFLH2mzao2EtrCvqFBEWCAiVTapa+KdFnaZpQxOrhPbH1GgVY/9MxN7vXMeEQKtJ
1jn3cc7xud/5fr/f9+lTYnp1MOQNNDKC2c/p9dmsSoTie1lnEkUxl0aU8Jsp4Y/mpnN3ckwu
p0q30odReFhjasEtLSGhttYP5zrLcQJMvVRjEgXBkqanHoJyDsYnRB9brGIoZFEpSakLCqAM
m+oB4DaivAIYTUoRRe5HlLRNw6RQCZmljmZu5Tlvz1Rih9a8xU4AufLjK3awAKIBVwID1DLR
eB/TBssBk0h1rBSnkLm8qYf2MNXBblR1r3o9LA3vsDy46ubb34t5ue+u3yA71ndaxFPHpKlY
Ize8MZF1Odd1dg/iQym5IeoZEBvY8ahgTv6oc2DocOneX/uu7199+khqdnxHxqjT7ent2mR7
amjghZmLbXPjO1K8XrtaboVnt498b1+LL9xoy7zSfjQAZ28DDl4DDgbQ/gvIRvWDGs5RB2fo
BdHnifJXgYagci/bGhsYHvmcNGH5/SzHX1UcY26u2eP1shoabGoAmwUPGVxOS4sZKh0yFE6g
6v2qmfT7llXvQ9r6adiBerCCcE80BzvwPltxtEsw9OLC7IF+/7bBL4R2wrgNNaXJ3p+ymh7y
yaHuo8O52WuLN0dbgNFHJXE4E0kWM2sv4TH5wIFymUYYWwBmp8g5SOF2co7shlTcKFmw5MZn
3LfcBLnjbuJGkhZrcayYjBUKxSRamjmpzPxgaebLMNMuGfEZzy0PQZ64h3iQHsfolMoMXGTP
PzLjg+UZ/t/7Sdz/pp/4l2cA9m/gP+BZNo+0qHmWENVVJfCHZxkGU/YTIDbUWwL+FPIWyiZi
ABzjr0uBXLDggzNtRvW7E4xQOouv33gxTHcA6zHbYb0U+UjZwUf4PdiBS+Jxv/6WnsT0WT3R
o36CCY4VlnZB0GsQ/SdZDzIgF7pwRflboUEkVCbbHUovmUAbEMlgFKEAmUy8ep2eKYAn0itK
qoB0wIMsZOMRSc9xGHFx7nOO4egCNrtIe4nj60QTPO/ndnEsx2nB9Y1IOiLBe0K0VgjYEeQA
HSpAvhsB9m1AbkjTlUytxCvEW/F5AKFzAX4VdUV1OyDC+5WUBx1wCfMJnior6CB/s+6bPQOl
n9wgh946sfiXG3jvs+mbx6fI/dLrePuh7INJ1nPqwTg5u3hvYA/5YrH2VyfL5fLp8tf4v6oh
UmXMVOlNwNB4EVuwY57ZhrJJOEB62lCn9rDPwLjzyrhTyEl2oqDkJBg5+5zTzhknC9cTAkYC
J8QFRkAU8CRF/pvmv11eJIPILwF+zf3N080zzWwznghhmtcugg4IoVikoMyGky7dK3/FhNQa
mP1hZZeLX8Mu117AaYq2MSGKaaneBY3NISqPLHpefDo9nZ5JM6jSpXFn9XsKRYpl8vF1UUdl
Xbp++asH/0IvSwYSy+Pp/Eye9OVxHhae0/Ji/lv/Nf7kvxIk4z75unxHZibkMzLccrJH7pd3
ySq5uiMahIXlfcGHF59PUicLtfHPirK9KNWwHj0nWrROW1ARXVWraoPrWrg2wbUbYahCCHS+
xay1YTUiNHm53WGzml7YbOaa6NWKDZ0Nh81Vs2o21ySTTdSstoFZXY1QjYFmt1rIbjVVfft/
zapSNB7aVOBpJFHnDX6LgdRoEu1Pek/6mtK4uQdH8c5HTWRg9bMqZnBNxqeKGxKj/Yrj/HFy
xxuf4bGkxfmD1ArjuCpkDZ7oTg0bd7vcUZOwc7viN+tPZJ/+eRn9cI5ykdZ/hfNXKqdN/l3h
fB7Lj3I+9vi4ciuME4CzecnpEuN5ygzmkUmFSCUzPpz35Yr1yVay85vX/3Ll+mSrsv7W6a0z
W5lHJi2tHy39h7nPjsO8M8q8t9Cnlf2vxdl5ZuDh+tFSfsW4t5VxVkmHp+UZmch4S3V0UcmM
0fJtOh51gDJ6/wpqAjmkqzWJU5qf+QlQte/i33M4R1lj0wXEXK7O7G8Cre5z6bQat9uHIckN
SjaN26LRuIPtPqZVg3WuJrdaNHtawIx1IRG42go8VYPaqwOGmSGLSkyvVN+/FCyQT8V0Wm1y
+zSYZRra4ykqyYx1gpgSm4Ihncmld1K5K+lEMd5nmjERExVWGqdoMoX0EcrtFtBQThPkEcnI
iyHqKEIhfTzOqOm9+hqMUAGvGWaTVNtllZqiotXqNJv187ANnVPyREWns8FL6e+BYQ1VJQX0
p1WJsp/eRuBeycjFJRVV4KuRoDQR6jrsmcoryOILIFrvdyqP7JnjxlWR48bDH2uMnZ2dGiMH
LXIoQ4sLF9Rkw7ZBYBskQYtP9MPn0x7PV+6boJ+FHtE8MaTIMqzEjT/VjKn4gmu/N6mEFUSV
0iTUdpzqeMLYYDEFhZXqNjUI/2CQmfCNHXNpv1Na1fHcwcOlT3vVdb/s33GsXteNf2FofD/o
UY9uebdubTZcumMP2K0Bpy3ggBbP+saKR54Z2YKvRNakX5jYMh4wPNXm2x/58EV5YPLI7qFN
pUN92eT5naPge/jL0lqup29j6YgjYKtrdiot8I7muSnQZA4UQu/M7dO9pCMBoNtlJGBBYB01
80yXxLGS1SaykomDRlcrsutqgE0GYJMFKulmEL9ZUOK9l7xerYW3WSlgTrdI+zkdD4eMroN8
46HktkAZlyGx9fxO67DbtVfgiMOKneSow4BDjkTAWdLzrOhgQPouPZ3iAsUbJ6lwq6q5hOKf
NAmwlR2P4Ulm+wt3dxXBg/Qt/Pa5pjPyg7/1fAaYwTcvITd27vvde0deGcz9+sbJwt7SO3hs
rvIS8LUEaTx6y/8kf4R49KA4+tPcPvVLatIKuEi1AUlfKwYCrnqmQUPBAWEC4DAUHAa0Sh4+
TwLybkaCgso60La9l1FYCh8LM2GlPAKC4TBWuQVXfT2PnRRRULqypHdQ2eNwGAw2COfuSzyv
MtmwbR7iRd/eIEhQ4ARBpaUBooEAUYFyaasGSIL7hxIHZmopIhAkcJEwZ5aoDXJ4gaJJwczQ
90tw+ldQ00rLAyU04wdQE+2Bx2DFnxy8vcGtHd1zNmSMjLT120+zr5Y+ly/8pnS3QigAD1oS
CB62f7x/15oavflk9NVV62N9BzcOTU7iY6UpwNnW5Kzg/D/Cqz62jbOMv++dEyc5Jz777PPH
XRxfzt9OHMc9J3HiNtcua6O0TVIYWj8IuF230LGOJCC2FWWLoNqmSqgVQmOsYlQMrdsfqF3T
D9qtJeKjCKau/QcYBa1U64pAK7CBJjQ1Ds/znp2YDIlIzWs57nvJ7/k9vw9fFPV07dJf+a+w
bPKSpcMktOgiT79GNaTR0LDBzuI664wkrVNts86uHJ5zpqszY2Q16tRM7ZrGn9Ss/y262KdM
R6NgaNSM0myURvEHLT4jajmwwyDRUpSLEiv1gRynMQGk2Vee8Oz3+yPsRxs4hkmuvA4GPgbq
DAwPMUk4B1dEIoNKN0zwdDarFAiTWwWIwAMRJKis62FNCkCGMOhcUykxlTiWWEjYWNhKdbIy
aTp9QdDKbkkOOmyixwPpb8e8KBoNMPuzG4500+5uA94yGwf6BgqFgYEQRRIQppL3kPXVCgS6
KC7muiZY94QXIHishCIBioNF1igZR1gz7c5KlVJkDd/ql3EUMK5XwzX7L53KcHZvPTAFJAw+
A2VyTe6FkGOc2zjcn93mVx7e4hYbWg4s/qU0TQ8AHSyVAjrcP8hxtH/rXim8+9G0be9QYePo
puy2B83R7V8aO+iRPTu0o1Q6tG/XXLkZqCHFgkANKkd9mnt27rPdG2S5/5XJb1daEv2YOWol
LS/tvfsb0mc6qMfUdMNjyorhYVNtcRoeuuCHEA0Qw16yEzjgJzhdNmNMoMSx9D73KGtRL6vW
jU3Avd2v0TBeE1dbjZNhOhY+ie3rsPB3gWsTxgRuXKCCWVxrCKbQYgg0wvioMjKYjZLPIJFS
hGPvgvhFMErD0/CZM9NYhKbTzO8hp/C34NlRkifXz5McSItGUnMpLpUKEbPRbRASGtPpYZ3q
KC06qoR+wWLVOX9zEN01yPTGBXTzVDSnEWiWAZopMdMXMGJms2TEYkRuqG/ToqGgn5cbm8Fu
R86oqiw7oyg6jQRvJsSpwWUjEA82QgRxA7tcwC4nCHQPsgv0udqOgFmFgmWwLktf0sxlby2m
CwUUmekZ/GhVtQ03CrXIazVpdNkIfRqwTW+321cLeObxRya/+NDiQ4X0i2vDddNXWgoTHg9X
cD4zpe+1JNyiGPfMC9T50U/LPyjfvn729NeTZ79Q6vFETxX7lbGtW6cm1v154ltodLGgNxIE
XUcW0Wkuw1j0aoVFTy6myIQpNyUcLQY94T/p5076l/ycH2MgYw6EFzxNH1KIjqvfV7msekzl
xtSSekPlVcYyt6FWWKYSS0Msnk1M59Pkf3Sw50js7iRJmS3UGWgLcAQ6HBegrex5otFaaWKt
eBdrJ/mKVw+CFskkRg6e2Sc/IXM6epKLKCXliMIvKNcUTlHcDsKMyY3EceN43VB6LT1yAEkE
IImPH51va/M60ZntMPME1BemKKe9DkHwojPHa5zZsuRlD4Hfh1mIZPmwy8PpmqTlYJaf1A0Y
5/NgxK/+YuH438qzm+mvjh8v3waRsFmeYU0TdOGf5ffvlt+le879CIy5LCzbhCe2tLR0Y3UH
ZR1xg9lMu/oo5ldurM9qhmEoiX2UFOlY8SfFG0V+qnisyJGiWAwXx4ulYl2RVBuf1fSsTfwA
NrGTrCX/PgcjSY2n+H6WgXJmrpTjc8y1JdnI5ZJ6QLTpSVy+ZFKvZ7BiAxQBWgX+6Zbg6Gx8
sLA/5jedam8nFwDxHn70zFOZExkug9c1Q4jIZHQpoPjadQgWI+cI0ZsUJWa7ABPxwSdc8Ayf
r0nHZ+l6k6bF2IKGYFiDkL1WOuI6tqDVguiurClOaZEtKPMAZgEijG8QWyK84apuL06SzKyJ
5cVeI57hcEM9K4nA15OX3fDSDvPtwfzVzrm8q+c7aXt3aHT9wPpQPjx6oLGh6WenriZDi++N
0vPcoUO/fIduqh11TqXDH2ecrnDpnpmdwaRNcE37OjpkXXj2zfby5YVrC9+kewL+qTfKc+Wb
Ya6xhgeYykA618CsVNJBXrHSahI3oIloJY3TtHrVCqz1mMnqkf/1yH/oHlZeVa21Ut+ANVBg
KK2glSKJmtHxKB+N8g1Bkdh4FEiPp8HvFy8C2JmVzKoqCsusnSubkUPQURALVk6FJUl/IrdC
F+i1WkFN1mLnquya4ejLNp7f/4d7FfvuyR8mnGKnbfHDLbFqXsfvdE9Pp759VvBe3j9hRayn
c0bPtvemH4gtpytQO7BQSC/DS7f5OVAMiYTgD5k3BSL6VGMf/wTPpRnD9ZJ+BPIeyyIdjLem
G6DT9QB0VYDPi/B5LwF8NqC5HSAMWBAGEEInZJs4Qlhqo22m7DdAUlTic6sXgakOAC8LQjMy
73ZzdRhYbMBYDvDrqgQWpixoI0DDGQs6cJF0sRJaWMeSKnEfcorbK2rAv7wR1QA/EB7gY90q
Ki48vjkkjFP16FPryocGTrxO3ynfXPvrxz7aU/5wOaOib1yOfXd2z9DUEvnO4hVqP3Fx//33
Xf3557afr6UbagOo9kuAX4r0k7fOk16gWiPpon/q+kcX14VgyQBFV1eg1ROXWlsDkXhcikQk
EmDCUEVM4jeQNYBSS9ps1I102hvQiJKMgfvOx+NJllRDVp49S7yGpnkVZGAyyUkOF4TJHcTL
0BwiRcj8KygOVPYett3adQANdZohymQAYv+tRUSzogeuSiFg6l0DrOzz+CSkY9yFDcsCF1Ih
lC07VoTVIP/2xY3hpp109BuPtXN8XDjYdu/hJe2B8PCnv7xG6nPRmdqqxV2Of++re4d2zl4a
Usr9czuf+5TAdz75SGFwZmR4PP6ZXUfttcWLg70m/H2AeBxiyFtnGFMN3PBgR0eQ2INBWYtE
RE0TZWSnjOyUa9kpWuwULXYOkgTgLpEszZpNDiObleQQ8YsxJwjzllORCOTskXmIGyHEvkk2
QiFOQkcUgLqFKtjznNPJ4dr34bov+yEq7Z0VuKsiixy+wwZRBZ31WeaWy80VmFy/7Jj/F+5L
D48Ap6+/+fzlq+X9m+nvwUCPC1vio8UDHc1JaRXcb+dnv/b5ofK135Xf/gDNNOjr7uvNKpsS
D06uarjoezdBS7PEhATtrDN9bcbmul11+8QnRNtawHz+WJ7mkZ3egJFnLQXQzucdfCoU7VAd
fAeqajsAH+VNU3Sg5DpwKg60LMf6lppsCo+CgXAwkG5+lBTgrpaAbhQKDc5UoqPOFs7gIFQ1
3AHn6VAoEW7AF35/2AmZdws8ZLPpCOO14bCTUJqAXnRmA89xTvfFmqi6XISYPuNE/nWHNZ5K
7WHVp7oEOKsCmxVOzHq3kmcr0kN5GFE+Huvt7YnFY8vyLdvt0IN6ev9DeLXGNnWe4e87V59j
x7c4x3YSO3Ec24lPGsf2sR3XAZ84V3IhJAQaLkkgXNZxUQmsRVvFZalaYFsFu0CHVK2XraIQ
iQ5SWIBQVVM0ddoPtv3ohopUVNHtl39MapFaYXfvd44DgW6qlJzzfee8tr/38jzv8z7G55qa
DTyROPp6+sFHA/j2wUmKoqJ9rw895Sl7pmftWpplVv6gbtX7oVp+cuptU7p/T1vh+eU9EvuK
n+IpZnLg6VhY5i37Bqd2pkSDsGHFwU3R8b5NLTdGt6/kDWU31tRX79qcbDn7GGvRqANY6yeA
oToUA9567RqKAIDM34RwKOSNt9pT8bjdq40OCNJDVKEdeDwFLOUHjSKr5Q5FJoCAbMuy2QKD
51WLAzsciUqiTQx091xbPJUgGWtt9T2cRH1LlESIPZ3WQTKeT5cGhJLuKEV//LHpk9MiKkHM
YKyEaCeWhGT5soDyENBQ3KaR1E8Jx394YG3LlgMbWZaKNowNPfPi1A+LM1umC8vRsL9xog6k
5Yu/3PD8/qGJvv6BQHz36LS6aVU68CxMnIWvliAhYUew78F/xhod1B9n9FmTHtDU+nxJrW9+
UEBtl7CkdUgzoR4YsJBUK/1eoiVcqc+dNgVVvllJVZYmgUpt+CPyHUS8jji2DxCXQyN4s2ps
tFocioNc7PPf3FUFWAgGIUH1aJp+iJT70JCStHmCMcZVk2t3QbZWQNYoyFgY1gqsn4J1Baxr
YO2CdRJyqCv8fmC+YIfqqFaOduAO1WpTOjqUlBhrUZL1wRq/h66y+SyimMmwLXDcPwgWoEdV
QQRuOQK3I+ob6qcqIJtVZPIwDA9FSwNuaAhWGY0+SP9li6VKI06LUlVVrpDiCILjZPAkjx0V
MHuWs9AKu9EokuArKqBMyqFM1mqd619axyKwlDUm1epCB2zpRlhULxlnuoRcjWfHSUEV2rL5
e/qfTR9HAdMabmUZ67DkeI726cLr22CNfwvBvC8JtaeEtA88qXGZLrav+Xig85z3wfVqW+y3
EZ91Y+6kK9fmUF49qp6J1Ng2dr3qbm/rG8M/Sgx6m2pHRor3l9cis7fJY0/8PLFu/N/FmXXX
9im/OJy8vHd9xiQ4zq/qljIbRg68Nxe9snd92myU3oEnnxzesbvRH/ZKrS9N7yi8p3+RJgMJ
e0tQoQuA8QBKoNPXUAzE3NHwqfDdMB3W0ikq4bAPab2Rg/oQoDZ8MIzUNtkWoDisAPhmKJAy
SxAHg1KNl7ahOjfhXL+fsdpIKs1Asalan4/hCcI5SB1Dd6DkI4otaI0tTZKjK9/sF/mS3pAJ
vrG/7pHEqLAtqQsN6k6JTBRx4FbnE3HG35e2Tq/ylK3G47P71/gz03/3KMCeHistFl9Y/WuG
6/ubHk89GNSfnt18ZFPnhcXCn7eGzZSwbbMykZQjB3OJq3hqYNee3z3UzVJAxzX+mt0AuH4H
cC1RZ+4gZJ7DDgxKYBRlAaoJsIIA02dYGaze0tD/K/Rj9hboYQHXute4KTfAvWQ9nkAl+6xm
P1uy3w728L0u7F7+vZq20ezeL9ntBjvnJUzo9orRrMi4ackeCANhmHvv0F9wPPDFWdXEjOD2
Wku50j2CESEMm8mijCBHRcVwtMYbiw1XVMzTY6rHG3N4YUuZhxnBW4Fqoqy1YTDTqzJCLscB
7ZNptVcriEqogkZIbgOdVcXYsLeCcSbNJo2MzOUexW5FFFMTiPoiFCF7q9UUIMTmcCvaHdgu
UCq1QIDx8df1MlElCzPEUIwK7xnCYQzjM5mclQvw2g1V5KS7VdOorNY3QXeJNDQAk6yei0SS
HTd15kEq6gX5m8kkVXXwBhRiUmeMfJyMWnmr3mC0jVwqRr1plzhjmQjWLjLpOM40dPssUAUY
O7U9VO0xc7N8zHxo8Zh5se2Y2dq22HaJozpGx66hCuJmnTICkSB3NK/vHXC/TPbwI/IGqHBg
IjSN/5cU0JZ+wia4NOv5fQmyJaahoHZ7RDbx0gfIXAjYcFK3TLXnQjXc1sG3y1euDKf9W49U
U33FTNdzew4VPxrkymdVakIOeoTGzvZsrTw54HBJzhVNYWqwV01eWD/1tFGwX82utPb3d7X6
t75weJuD7ezHf0l2pvfvG9xbb840B77XPDeTo/ob1qzf2CNZvXavpy83FbX4q9qb45mUx+vx
uptIBd4p5lE9K4CqkD4ArTAB3WcS/rcgHCkA5KGN2/y2+l5W+OoeVw32AbD/hH0ZmdE/1Soz
y3FlRooWWa6MEYy0aOINAsObRJqep7erAiM4GEYo4ziyq+ZNEAGTgTdTrIkxMSIncryRLSsT
BJ6+SW8Dfb8NsQChSRWelQkiT9M8J4qmeXrbnIHjGHLfYjCYr8HpqEjenY5UFmKuiNtKrrZ4
3B0h10gEubLuSB4KxxWJwRP9TSwGb9PQZqAqXLL5kHXx4cJisRxjFs1ajTCL4LHfxodSoZQz
5eSdfKi+95Xo7Gz0wgVyfaWYZ/cej55/l2zePR89XoohvggxEdFpVXwDnaXPGmiqFAKEHWAi
GAxkZ0Ei7ETEU5gB/zBMfzsh8gw4pCIR1jwMJZPIAKGYUAVKoA2iiDFaoHegD+HNFsRFCpUP
wPF4JJ2Ox8HRtqz1XmWh7Z6uu8A7tll3ji05RzomBnd8kEZfKIUv3o6eKN7vwcMnoszFj6Mz
X0+xn89E4YjFYcisX/PipCqeoU9xZ+D3BUHzguOJQqMZhuwg6w6W5RiWowy8yLabNCcozQke
1gK4MoEw5FFgDLTA82Csu4C0uso/7kK2bckDAmcCWpY4sOz8kBAfJALS4fP3FO+fiN4GJzCc
l/3NTPTjf0RnEEazQMZ5+mfIhtapLoMB1Nnn1JcU1WrCVittVO2SYjSKC/QC1PguJBI1J0iK
KBqNyLJAvwbE9hLEoOblSKFgI2eTQYDENIESbQEKgGHBwen9LplychqOcX5NdnDnmLzel6lJ
3cZvJUZP7T69L7UilWzoSSZboIe/iSX8GXMXzuRBz/3/U83TC1csNKbpqgX6PIioXaD0js7Z
7Uic/+5zErLUzjr+XeelS09IO8afLT97VUdLS093NJqjvnzCiWJdpKsr0tKZA286sIt6nb0E
3TCOzqn2YH2yvtfRU8tYmJPQDhh32Tz9wWU14L5J/xW5YQ68hWT6v4RXfWwT5xl/33vtO5/P
Pp8vvrN98Vfss53YSZzY5xhIgCMFQkjLZ8tHigvdmNSStUBXbdPWMToSaLVqdKOCMaEy8cdW
tdCNOA5Oppb+NVFtYmh/bNKEJoRaqZrkreoyStca9rxn86WtWiTf+977nvK+z/P8nt/ze/ZU
Q6GgqkL1fa1qBnEwCI3gi2b8D1RmovhBCdzwahzHnc7l3HqO4UzoRDkzHDU4+pkzBr3rPoAW
KtZwcgosLTey2fLiXK4MU0tHNkCZgN1gNvhgbOO2Xx/Utv8daIG2JuCIMqZ8bRldBG0St6ja
YuI00LPR5Gnqj/t9w5zSu8z88LOmsWJzxhQzzqXYvvaAa2xm6ttvzI4a/WtGjcJq29yyXHG4
e+VKNZ4ZLfY//Hz86e8Mb8Ky01g0vE/cvvfI9MtffL0wujZvjK4FZXAAPUF22XyMSg4iyhjz
OImPM0WwLfAOIPKPkBkT8PvTeTvOSQtQywD2Hd4OfPyWjq/Ct1Cp0Wr7N/Ep9ipwhAcdrnok
j2IAQD42xXzJII50t8HRJQaWKrCCauRcBTGYmSe/AtScmzZp8s5Mi70Oa8eJne/CjkjOIRfZ
C78z0w4HfHFmGiFvDSemmlUYakB9oVxvuVa6ldPoK7iWlsgsdS8HEPO3Rnyq8Pil7s1/zu+A
J3u1N5vckO1MLOtrji0bPmQ/Qzm0BItzKAL1N6obvfTOPTkjR83xw+SEfjLNJPkex2JSsAcC
7ovQnsKtqyHowYwQrdZKoDmqEWucjetGKOQurBDJW8BCPeQLdBAI822g0gRY6CAN5CZ7TWeS
72IXF0kfClBlwzkM+OcJkMOHURRSzZXMGdGou8vk2oyuGjlSLZqSzyjSc+BSxYvkU9RHjkAA
3eQG+PQmuGqohnPUVdDvNG5At0MzMFtf7KWZ2ZIoIE0+qEt1raHVm/ol29jvtdoeaxd8+VwW
U1+ynGpBE9I1YXUqgFjwK0wBlVR5wLSpLOgCR7ctPA/gD1VVlLktvUtGtnbaXL42n8z5OMHX
G0/ZOLJquVfS0tlie2ok4FNle8TNziVXxJ1+d67roYGIPsy3g9IOOBOro6XhjKKEPb6c5A3H
cjkj9Zg/FZJ9bHsbjd2tf+BT0OlR/P18DvG3b1b0lIFrzdEOo8kDCv8fMO/CjwLTRYEpir8h
M6iXorTisWEbxSUDUUPkn1+KS8p593AJsGzcB0v4S/4XMo1xikzr+WiuO7GxuzM+mOtJbMpm
EpCRrexaBdaNzCE73J7/0ox6t5lRULb3wo9ejG9drJUtzXvgu0dDOnRtYVdBOmzsSSdod7cG
TjvHdUFd6ERvmpIohXXjghvb3MSnpVEHPek9inlAnls0fPPk3wjBvKvbQPPkLDDGZ7O8wYkG
D97ca3psbuRN61rE7zVh0Vsjh6s6ha7egq5OoRsB6Jogz29Cb3CjAjyUqeEUvTWktNYC7z3I
DmUXGtlGtgxUegemVlFpwpPis3SXPRUKXb+avkOxgMhzLNmcl9fmR4sjZkdU8j3So2UEn+QV
xlKyUwh2O9iQV5fzJXlNcFEh3aZo0eGvLeps6yqJbqHc3ityaiDus+Jye6qFuqXVB8LB1v4H
XB4MRwskVjiSDwLh0b7uBHBSvBX582wNIvGzOcTAP/dphkbx64nFDZk6VJaFMNeRWsGT80Ar
HXCeCSf9C4XBu7AdvmitB2BdAEjIZLJyxYuBVRaAXj+phDgu9A6ZRGHyCVBHkkzOpFKW8/30
jgXa8jRADwWkhYX9cOO6Vs8uaHVKFla/Q2+Ps61CZjnfKlSlko8W9UIeAlEC59NJsaSq+LwW
LsiRNkWOJTIZ0a3YZDmruWTFYXeFUqqs2Dh291jfgMuty7HFeS0f4x26S00s0sbYfiGa78yy
bbkWU29kzyIBBdAh6pdrJi/5DVusPUFDAG96xnDE4OG03vr6DWcMoMbPQyg84BgHb3ho28t5
DI9HpUEilnOmEAtUK0hthsTGWIZlQd8fgaBpNVxqJXc525Q0AEnahLVKzb0Kzd2t5YX8AN64
46GBgQ2DA2uH1rVreofWH4yz6rKvDA088q3xraGVPYGEKIgI45fwL5jr5A3oXNbPcpyAkE2g
+srldIMIy9mWUxFDF3yiBj0tEkzRBxvcToAI4iBO5SANB+V3FKAKJEvfLcGFISpcKpWmSQGh
YK7HWXfb7h2bwoKsb0tmmQ8mtYE9xWUjL6SWPTUWBszhDbibuWZ/D5jUnB0RMc8ToMNvgIcm
ZpxOyE/QS6bA8Dyznp7ulSyxQ3ubepBOqWqmp1viHvpQA1IxlW5T/RGGuda5LNqT3PbkC1v0
rtFO5uzU52/Vvj9x4gDOPzu48vJ1yClsw0kybr+INDQ1h2y3P6q0R2lMPzJFp8s4Qk6QS4Qc
BUFaI78zPUeV0wqjKE6/1+v0+2V6TSeZqBKZRchfI8eqAVlmvU56Yyfv5b0BwrKhdnpL/937
BmhUYQINZSEXBJ8FLIPqZWrAvdLHWpb0MmAJRLZYAM06vudgMuj2LlIU+87y07sefm7dm0tY
26evvBL5wU/Gl0zu2/1jU/r8l8dw7JnNtSHqrNfBtsv2Kkqi9+dAaF2p8BKtUVcq7RGDpzYq
YCzru+RgWIfqYOxBxvR4wXpyZjYWix91YAe1WgqaHtkIBkOK4lHjoZBKzfaQiVm7PeFQhRDY
XQmH1TiMpgiMnjBB2idUVVDEefIafPnTC4KSUAQhnaKWQuSkxh1XZOkL+KAOr8FWMAu5oeau
JR/KMGsA0sA7+8sU+5KV+vc7yQo3hX+xQIcSPMnl32eLenJgUPMF9AFRi259avfQvtWjm/v4
/vwTcobY7T23ToW6Dd1V/u6ara++ePLkrsnqMZx/pjyxc9PK4+3rKDZ6cCcZtL+NOtAP5yCP
PzbDasA47MEXPHi7gG2SAEUnJrgNnkeahoDkfosksr9CqXqevA9d34TZxkdgSzLhU0nynaYI
jtTI69N2O4i409WoO+Zm3DWsTQECmvlOE4smUwHor7y8YSHkDveVrW6GtIRPs+jIJY6l7Oe3
HGIxARncdC31o6j+vXWp5/86oy99/MkRI/7yV4/1M2tuXUsImfHR0opDitQ/9BjWjt4Q+xWP
4W9TxOihF/3xdp7W5L/hv/yH+mqLjeI6w+fs2dnZ68zsrL339d4veNe7a3t214vteOzgC8b4
Atjc7IATaLBNDBsMuEhtIgJ2EqUtoo3bUJLykBRESwkYsCE4kCpVKGrEJURUrVShSK1aNW5f
Giql4PQ/Y3PpQ6XmsVpr9szOzHq/8//f5ScTjIiKURA1TiJQ8Gny67OCC7tc/vcAmhZZySHZ
kIY59jodSsIA6tDZDYa/G1QGKuapwiwdUWZRCqSroPQ2iDZIwwPFzlLtsoF6QfUU/aL1IxMh
a1IovdQx/N18ThpqrH0927lv3TPLY6naF7ateIocXrWqtodPt4ysa/zoxZ0D3fVPf1aazvvz
ZdWNLrrpn+IKMsC8j7xoTDYY06JLQvrv6VV62sVGq+xwWGW9QbJaxUtkK1jkb5CP1gg5qPI5
3LTFMUYsCwlrQjb9xI15N3a7OYT8FsptUdzAYY6qHcVGOVuAkYvWx1wJnYzqnI5ZO3Qv9LRT
UCDTUiloKWylZlJOaVH6iVKoAenVVZy6fk1wJJllSNrYuCOzcq9TKImods1d3PDLG+3fSZkM
JcH+xPedZa0xg2PT5mVH1m6nWA8Dt48xM+BIA3Kx3oKjtipzprjF3Fh8VP+RnuU4PE0+nkQ8
jyhdtWQImpZHnMWiperEe9kUzJgst412pJObxpb9KfN89/VRB6YxZ4GNApSQahNMkISKO5Au
QqdFqrFWiwh9mCXHtM/EqsMxb0NtPtNcsTU0tH5D/8qcJAWZmbm3x5sHxg9+Pvvavs3Nu/HW
ZR9+PPcyHjzxdlOK4rgINbvCXEVW9JLsYBgz42dITJsjebaZtLLHLFcsLEIGikWPaU4eAort
mMLYgPRwt4JFEHyCShD02xGmqkdHIDuUHtn1NPKZLeDKFF6cDiKFPjMV2/+OEIARlQpAWgCX
COWCocJKrswjGpKCyynS5QtAVcfnfgB48OjcxNzJplQa9wJW7JjHSnn0N5wgg+BtVujJwakW
8k39ThPRUi6VlKQc2AEx6goEKI4MPOrH0xoNeMkh2WKxILkqL6UQFK4Dvgz5QWsPTV43YANA
oNUqxEEcAcV86znvFypSNOHNw4hk5skmVlYo2gAw5qlWWUEGW5bEQ971mYFXZnb3hmJiif2c
+I1E64Gkas3cLcuapXdG7du6p3BYyh+88d7yGvzW82mxBoi+H/2cnNFUQRLikQu9IBdbTWFT
o2mzSf2sCWuNrEnFG02maXLjHMcXcRwPtnn8jE5n5B10YbGYTNw02XKGNxk56zTZe1YQjEYP
DBN7pzSaNHeHU0Enevc/4Fil4gs0gNMslKqBwziTjI9/60NarcLzj+egMA5iy2Pn+ExbLru8
LZdrU6H7TzynurikrSrXuiybbWfO59o7spnWluYvx5g9X/4z29aWzXa0Q+d8gNL4tiqAitCy
KVbWiRLLamhsM3KSRgNufxwy7eA5kDHWYODhR8s6KJiPMshKf7ZSEShHBfxwEG9FCeLzygcv
mogyD8cEfDvirQ60ljbaFpWHFy3L5nvwoe6l1Xl/LpdzlMUsvhBktk4o+iRZTDYx/0DPoh3o
r7JlN9mdHifjafVu12jXuOvlLnUQIuekXpBMNHqWwmKtDw4N9JDIa/rVQyxvLin1Bk1ae6G6
aWP3qua1Ddr2Ifsl8gkqkFtoCN7bUQQe5uARPX2ulx7qFr63mQ6zQYj/Zq0vKDWvKjE3ebt5
7fBGtl/Tq9egLflEaXVdRFM5A180DG38CdpCbsHWDKeHVcPDO0eUraG6cndWmLVBkLfl4W8+
yYI/3J2lnzz2KXV6VFBqG42yNupqsFKmquIHBc49DP+KDT6cBKipPBrGgLr/OZjBtfkl+3DN
SI/5z6aEP9Paqt/VE3ZLgzqjVWf2+7z+kOgK+JNpd6hHW9CSJ/3VcX+8NJAYqiTa2pqekDuV
jLkdKpvL7/X5w2ZXHUkmPaHupUl9vb8mHiydu2YVzVar2WxTT3hCDmfJ4lTWHb2mIUsCNYmS
WNRbNlypk+s6I55sUp0TOJteDJZ4Q2FREN2esqwn1tkmaXVPdpWXxEu9Zc9V6PcwXTFPpixk
DdgNRUGfCIYm2G1IBX2IGHgBT0Ez/Wa/OQwHjNTono9cvicz6F/Ip76M/vc7v/oKrcEq1bA6
orKSv6Cv8SSQ4h1wqF8xf0IJ9AtZr5XtfokpwjYnlWdtWHI6TZAZrk7ZbAJCMQyDzznZZJIT
5dIR07uQiUwCaONliP9/Bk3cgWIg/EUQMHUM48chk9HonCYHz7owDqEoTZkx8iPZEKLy70Kh
ULJsIWn2PYqawMdKRfNhnqqjExVMVg9z5qwyzsBV6toWamwL7WFjaT5hadyktm1TAkz0QfZU
RSPvjKYT4RXGnNRaVWh0eJoC7alcsHxxcmVfhY9/d8wS9OlYezgjNSTVE7i0vzyW29fWLLeE
tII/sl7UxxZrT1/DTKYl/vTP3vgCCzu7gPMzsHOnwDXsaBF6Uy6xshF2nbDaerKYsS7CDisy
+ji3ZAwIHC8FwtPk5mmdzvs+uUlDORTmJt0w2eWwRiHCIiR2GrHRyIidgQOBIwESCLij0+SH
kwwTBzd569x1ER8QsTiNBZBdJbXN0kjTpzCWbs2CVYJTfk417X5FvBLiOGwUcLQPWxRWKvSL
ah4xMmLTLHAqp4wvUgSf6Pzjto1PNPZ6pEB+ZWLjqy31pwzx4fXrGioXtSTd2WDTG+oj2Pe7
2+ePjux4kbNF/WNP7dk/+nt9YmD7hcZMU7g84K2v+i0U+A+wOz9mPoVk+qYs2FW4v2ik6KdF
RG3XcZLnAsB3g+vD2k07zZGW3G5qQ59NITu225EIBjQzxcvuoMTzEAQ/AE0fgV0bgo4Oktdl
6EY3w3MezpOm6S9cPE0OT3YwmFEyxLzt0uGT9hJsBlJaKU59CnIu7aL4rJLUYW9Aph7Luuyj
oAs7tJCk8Gik5l5na/W3k5nRDntDT+XIa/1dvUv7tj1RWLI6W+PB4Rt3xpxj9UfXNK9Y3R+1
87VSaYXFLs99UVXXteulq1+Hkf8vdxLUxOzCp9i7cB+P8rjqPBJh9tIVOSVe4IshzdGzipxE
tNGExChnsGDpNRWcTcKlOH0Hz4JocWIS/rfqAjmJNOTEv7mv1timzjP8ff6O40t8Ob6e45PE
seNb4pPEiX0S24khJ4yONUFNyriEUhc2QajooIqUjcK4TrAyymjV0ZVVrEhoNGwrAmySGANl
F41mEtPY1nUwNmmTsqqqmq5CAU3r4uz9zknAsP3ZL6Ql0neOz9V+n+d5n+fNyQyk+/M5S7Ne
OWOkkfIM5K/TY7JJrvJJ0IfOy+bmgKyzSIFAVTMXT0IfOof2oDhcJ0MPuoOagV9wuvmKcrwB
jleR5+F7n8gxDDz2xNhuqjhvoED25a/X4boimUZecjvfxHFNl8k+1ExuIxa1k33nk0mW7Szg
wH417LDTNHrz7PS0IsQhOhFCkBCmxGkBVnuaskzsXTZwVhZWl0Rhajo71fvkwNk9wmq2FFM+
Uu6pfzB9UJsDOXJlW0Wn960z6bzHyCQome60gWLxscSaicYv/iH+NKwfCzUJQMvp8AUaRL3W
4mLsdlEw2V0GxlQddttdjE53t1kM9Yv1gYUt6vbE0pZ2s6nO4Uu3CjX2oF4fNLkDKU+vrrXS
F29oqnC0PmqW/f9diWeLOMR8oGmDK/nLiEAnRIohvH9Oi2PsNDAJ3A3uZT7453vaRhzC7CNX
ero0rI2Tj5AfnK4JzY4G9XZBqqfitdqkCJW2G3YCLCxBumh5g1ma0GKxQEZGm5qC9QHwv5F8
XwRHLpOb0MBHQKMN5HoOeaDPj+fM5upuEynAYFVDtiB+riSNZCeKgjnAA6PRunCB7MgFg3Ww
OV9fj3Q1BXJwtFo2VEr03lfgrtdpEVEMmckBaBWHkY0cHYX5wCbpLpAbqJmdFmemqXinRc8k
TzVKhQvWKVL10tksw7OTqmyrVLEqWgVXVeY1nFWzsIj9dcrcpnhGUrVQGN0Sfjgaofp0YV1E
F0lySQes2vi/Lmzra162SW+yRdtSYu3jnYGhhZrfVdtdsad6OWfprWePLB/bcrj/u4PF9Tik
t1W/vamhu7F7oLe+7+mm9BqLwbjUF+788LnVTxwttf2s58Tgtf43SxuurbtOc98cMpD7agFO
MlssDWsayacw+TkQh26NWihS9jmkbBQpC+yYKUgWurgoQhxnsZutCkI2bKMImRWEHApCujlo
9ADNPFvdAI1ThcbpNLEUGosFmvIO2XrcfsZ+xU5ikFbsCOspSjqKku4SgERUkM55KNPvAzGU
fRiKMhj4h3GYR8E2V3C3i5TVW9M4c1hjqayxJvt7k+wDtcXs4pggf7KiOF7qLS/k7Ox83aCO
/v8pPz9qZUqldcweJoW8KIyimLmAQirUwXmofRRlP108hdkbcp2FlfQeh0skne5vMacqKpbr
BnWasHucXIWfrsoaGBGN+kO+OoURQRwsAiPCZGTM58M+n+AskqtAjT/nLSaT/iKZQBb4Ipdz
Xq/wDnkXQu1GUPZOFFHZEYnUBig7/P5ayg5LKMQ16jN6jVNvQshRILfyWpOJu0TeQFryRwDV
tZ+9C1xgIa1Bes3aHhApHJyCMEepA0eGZspIAVFuaE6gWq0vErZJ9iSdB+z+ODVMHYNcTsYP
vpko5wqzp7SrdOzU2z/IbV3j/2oLjjf/tv/okUxpb2kz7sVJ/ct98t0yBuU+OXAIN/4aL9gV
MLfjYZfWeLel9PffT7xn0Go2P6BMQKaltF5BphWl0QJ8/gJKATJ2t5SkyDhgJ8HCItGF+Mys
ZIEcLHsMrPSS+xT/GSHLPYMeTZtxzH3VeLWSAfA+lC28IEl6rlbqlH1+qbNATsrsggVSKtFG
P7fJDVGpDQ6OJ2UW3pNMwxPzcELZwrk0vaFydwK3JM4kPk2QBH2jFaSZSPj0LXqNPmoNtxZV
hee7wjhMgQ4B0D7AlgLtQ3YA2mazFgFoJ9koV2boizP0xZki+TrqgAfa4Ad1dMTb6Zl2eqa9
QLbnJCk+923ic98mDodl8/EUTtGLUinGhC5C++5CTTTeM4ypUcgIjwskLHjt9hBlCuf1mihT
OGDKwv/GFHZSSV7ZKVEE0oiiQhvoFWXEmcp20SEgnaXXDc2IYly5RKWRqMSye0QS8Xz+giim
0ofT6nyIcgtmhHvcojxT56iEtpxcLxw7u0dPzJOHXsGr8OfWnrOX9q0r3Sr9/Mpr7uy27U24
K3T9yaOvZjqjqSaifWb390vtA7u+8EZ22+LdK99cgUOD3+7qcPa2feObP564YfdNa3ADdvwG
b+gPdOFhrqLyts5kcLSYl7QXTnYdXHV68YulE6eXnZ3zAKaF0SAXqgHH/tsFmLSUnlBFmcfD
DkfbAU+X1cxHWg1PZV9LZe/389WcR5F9Fa6iRsApRlCjGIG5QH6R1xmNum4j+RM8fd4MfCB3
ryp3r9ctULnzvJvK3VBdjW+Smw6NozD7l7zDJTlUGnuA8rA4iNGIIfu/fy4AfjAJcKXTUPaH
VZ+5C8jdT9APmAEd4RSoVDegsKhzHHVkrtyHmZbPDmre3bZxzSpBbEi+uHLR9qWZLb19faVf
PeQRO5OtWsOuF+Qlqa3L47aS/J9OQasLTtFAHRcZZ79CvlOxFwlKD/6YduB/5KGgoUJZJ3Y9
0IlPaX7IjmuIlV5hskheWnqYYf3BMC29DF2WdtwgGRmXrTCY1HGGAnlHNviMxufNu80awOGn
OVnrvkyKIEmObAZ8duarqso7bR4arbFAXh3rM6w1aAxcgRzIud32S+Q1JSTVY34/ewcUAQYc
y3ombQl+vuRQcfBfPibMZOMx2KOnsg8ZcHbOgp3KjKKacCIOcahNgg8O1ZGT89UnXzv0zLM9
AxsGLkaf2iI/dnDrW76glFrcc3L9pUG8AypfBASwZcEve5bFxb0LM9EnNh3pr+/uacWWz48N
k79eX3+tlAcEBgEJmnnmKg4IiIAARg04VGHR/gjF0U9knvCcR3qdxRreYJJSXtzmHWks1BHI
IeNypU7ncr3sxm63NUR7W5AM5VpbrbTlxclzstcluzySywWnhb7Q2pAmFJJEGcZTUQaUxG6W
HEcCmUJWcgw0EYcySkgHWZNGo8OoknxvlJENvMQUcN3+GGRNWkb2jjA1Q1tRAspMu1MiJiKe
NqQuqGcsm4hRDIDH2SER2g6GYtJcqYZKNVGGI7pwRO1D6r9LaTguJ+U4Z8OjN9auSD+WiXCH
J8hwJORNpFO+1ba4xdndsUhaWb9X2/fljuVLvrRo82Ic6ln0Uja/49/sl1tsE9kZx8+ZY2d8
i+P7lfg2vsQex47tsR0nFhkIJCbmvlkS0LoNpX3abVFKy0tVlUqE7UpI3afubi+i4gWpW9qS
EDAsN1VVo7JqqVS12X1pq1VV1Epm6SqwtEtCvzMzpiGBkMBKfVlHmcl8c2bknN//+//PSWyr
JsYG09y6jmQyPGotDX0p3tPZEfRwpuwtT8AVMms3f277t48s/EOZXVaj/jUawBZxYy+dXY8J
D2ZGMkwPnWKXvcNesBTChej5TdedM+3Xufe52fDNsKHiOGA9ZD0cm4hOxN50nNLUHVqnBYuU
g7avDx3zY79bSxPI2O4XtFqkC+gYnQ65KRgXOSRqUQ7ntDxKokvApwg+o4XBWmmwTmdsqZPv
ieY2GJNz+ykkP4XklyC5AZKR3AJISYBUQX0SJBEg9QOkMoVUXgJpviGlQLrWcJubkBplU9lc
qkmgxqFkgZTJybTGa8CKIssWJdUvZyQhakKiMZEzS50SjdnYlmDwUc7E8UpxT6qwKc5ts3YD
uGKt+vLY/pe/sf0VbF+3d8PXD2SGNr7+nepL1R2JTV85vDC/8O7/mDN5tcbpzXt3Orgt9r4t
FGU0EYqHI7eCMV/C3NbidAUGhIOfDwkLtzfkR1Kjp17Yu1gGyo6U+QA6KIImRMcbKtxtwXnL
qUDdQbTa7+qwTkcULOOTkQhRlgiiT0v7hdIgRjedfbc7tgjFFSBhBBIE2oWu+WPg8XeazcA/
vhmkRsC15tp+ZekzH9x/j3ntKYrHpqfqXJkB1R5QeQm9J/Z6LHgwN5JjXM4OZ8FWiBbi190z
/uuR9yOz0ZtRfcV1wH7Ifjg+0TERf9N1Sld3aZ02fAyc2qtvClqvR4aAgTEYsJfOnEcSdB7n
9Z04hS8pwalXBK3XGwwmjSxoGJP3hugshugshiBrTyAvTKMJBJ0COffC1zVMwFSuUrKyWkGs
xJx7RrUO/GRt8qSzvnZRIkZ28pab4OTrsUYMNL18pjxbZpYY+okSLr1DrsE2t5t8OL0zN5Zj
cu+QX0HPC2R6MuxeyfAvyYYPTx4Xg4IQWe774sq+Lz6T75vKLtPf0FLvV9Y10i63NqdcNcbl
SKg9WyYQO1yweenWGvJhZPZHr78YevHAwdfWnBTqX/5lx9Cm0vdDPf3lIZkkq2EJGkC78Uvi
0HPnxszO2Z3MiW14m8x8K2U+ODbIDMrMK8Dc5X56uFySwwWePy4aKhX3p5Uxw8+ZMdhUptJY
mjQraePTTSC8SDHPk0bkykMNPW8wqX63WFKIkVMK3CGCMui3S3JqJj2bZk4kcVLWB0/1ER2L
MlFZHzEyLepd7selWdOMeWoGsZh7eajlVgi13GNDbXmnL9q9LAG5+rxb3NWryL7F3byKFFS9
/UgHy4kIHVxCm3FAXP9MmTjTP9vPnBCxKFPpo1R6xnqYHplKL5k+73E/Q3D2keNTvb3yQ2sO
0MEnBqiC7TEh+mR8z5utixtvrTnL3HgE8drbTf3nRcxhZ/XGgwnVW+QM7Kw+RHSn5Vv4oWqa
2QjXt2GnxWA4qOEHdr0sQqBZcwQOGKnQ/QC5dl9Uo09QQHXts5Gfjfx/jCSoS30Y39DYUSfa
g76Af3wBtT/465Q/LCTrD25PdaaFLnq2eYRO5boCZ9EJVvFG6K0Iw+l47X6yT+10Gq/asK1O
Tk97Ra1R8ILNTNld8tnhk87nQmHB6zXu22Akb4OT8eQ+OoLU5GdIi4LkNETEPNKSf4nGYVEU
WaMgiqVqfsfwBi05A+N2kJ9LC8k7qApvhNvVq1J9AOolchBWEUenft+H+y6SOVQmH00N5fND
l8lRVCUfoRR6gRyF9w6nUjquJba/RkaQE77QeVYjwBcPmi+SY8gHvmiIpAWfzxgTWasQq5NX
p2uiySbU6P8A/3ntKvkYjZBXYW6N5C5qIfcmEfpiHacnIMfmGqb5uzzf4MEW+UaJJhsEm7kE
h1IWjLJhmmu4S2mXaW5uvAF+6Wnwcx44WuiINO8xLcAbGp55Wknz8JkfhzfRp+kvuOZXeR5D
GdtaWIfDDscYmCAn2ScXYlmwwlxWqheKipnCNQG75EJRaWhIWrsUbdLahTpvkRor/JEvOhyE
vkU23AK+Aat6M1HtSfUMjoRtNqvd4mH1tlQoymo2iwGtJZYUvFGfpz1n8Vlt1gCXSBhb7SqL
hfcYLHaN2rAu6rDYVWzcadcZLGpfK/vHyEbOYG+FAf0FX7gcaXdEXclBX7E/YeaCtlTA4PKm
0/nowteqXQVDa8ga6M56skGNJmxwcN3urS0ZvT8bT7ZYMzjsipoNFluL10y1O6D+Mj7D/gHF
YXVTwt0XIIIlrfJUq+GoUKRa1cLXLZna7IJAq9mikG5WM7SaVKpeWtWDrq1UfFarry7rzHdF
0plb0p+e3JlkQzHIR1oLSTUVOQsKS5DTUwjWUpeh1gVqFiE3/znZncrW6Q0BC1fgRjfcKIBY
s+TkZKGQqJOT576VwqmU0Vqn8rVgC5WvEeTbzrLtVL4+kC9CUXL0bCyGUK6OOSo2SU7zD+UE
lfEG1EBWc7XGotydq80rVwuy1qjk5nkQGAiKVz4YNPWoSopPlAkLI1m471TO+AyoANzFaqMq
0KiNdpXZyntazXatqimDNmHvb/jh2dw+OLLf3NqVbzWErP7ujLvdEqaIncFu7xZAHMjGO1lX
8k+pJLc7GQ9x6c7wLj7OgZsB58PAeRS8LIM+voB0MmVcf3CPUlY3ebKUJ6Pw5OgZcCIJAIOZ
iwCghZw+J6pEbwB2nuSs2JryUtherzXalkgrTpOQqBrAaaKyAqKy0wShbgV4iFJTYZXK4ZWo
ebCHUnMAtUhbW4RSiwK1DAjg6Nl0OpNZidpyJ6juHv2FCMB4iq/R5CRDak796mDhkzDznbv/
LiOSG1VCtKxT2dFUituZiId+AA1I8dAGVPAs6UDoOlGi8S5s3YbQHly5gDiZh0tJiHKzk9pU
DjTc7t9+hZyHGXWQ/8As+mFO40nBXyc/FXUIhsEE6/Wai+TfMLGfiMZKSqBIBCHZ19FfUZD0
S0gigKRPRtJ3War3QD1JDoptqjZkHd7VXnXLzUutexe17l2Kde+i1l0F6xahke9BG9+dPoJQ
OihIBGGzSgmmgeD6jo71lGAfEAyiQSBYqQSDo3W87nEEgRdQ8ijG37T7JzIFj8+6wetdpgZP
nd780NwlwHSBK1ON0aWt5OKyqQN54GpfNfmY4uZg5tCiXEzDlZzlbqO3bau/q8epNw92tqd1
5L/sV3tsU9cZP+cex9dOHL9ix6/Ejn2TXMfPxNdPktQ3GAJJMIkTkQfhEgdMEhghOFoGYzRA
CsuKUMekQeGPwtC6h1S1Ha8lC2KYKqSlUtZupfSfRVm1IG2U0I61TLTE7FyHwR/tNG3qNE2K
r+/57vc73zn3073n/O7vUxUJs//Z2ni6fWPGfFKoohAp/I2YyK6QlopFFpnGnC/TaOzrygrV
GpKS5SjOfPXCaSA9/MJxClUV99RWqVhdmEcqn+7owQxz33rC2/9VZv71Y2Z24T1s+zqZN0O7
/4Jo/xOSzZDrk0/sV+9cGaZVRwtZ0OD2Pf5wYlqlxGL8+M0Bff3TffsnTKdNdiv1f6NMlyKX
Ir+2SKAGV9BdwWFgBDbwCltzwvhz47jxFriNbpG3sz+S38q7rb1lyJkCU4YPwAcGgVVVZnZQ
IXMV9QuH8E30Vvbb2ps5AhFDMNYGsgbVZGHVzxosDUpGx+TVaGtYdZN6p/qoWqButYsZBZM9
gdRAjtTnShpycegFyOgZwGMGpP6lqaGQbD6utWPeuHNnbm4h00L5fY638wt37szPzVWUwyQH
khwMaEie+DVY7mfog6QDGR1PBzT420BaFhmErwJQzuGOI21tBzaMNCVr64dWH2p/rt3h+B53
aO/z3z04MjZ+YGRsTIBG247sOTw6sr/zgIcqdR/o3D90tPaIf3TD6PqRMT5i5MAYAHL8YIEI
ZF3FD1cMcoEOFAIKU6kXBMEKsBqsAc2gA8RBH0yzj34mG5MRu2SjshdlaE8pbCnZjMvCEqYk
UoI6qrdWE2XVoeq6atRRs7WGKKsJ1dTVoNbKnkqitNJfWVuJWiM9EaI04o/URtBUD7zWB9/e
BK8nYGu8J050dG7tJH5iu2gjNtvgRds12/u2z2yCIdsh2zEbYmwRW4sNbV6uXW51tg1wMMw1
cl0c4ji6tckK3dawtdGKrG5J4yq4CnoY0oDcogIBk6fulVdtbKKhjG6ku2h0moZFdDnN0ohu
zqm1NEYDDUXN/npTtHtnaH/oaAixoaZQPIRMIRii28o3wo0m+gpNmPDYAfo020PP0h/TQrp4
nXOLkyhx+pwrncjZchpzfpdyQEko1zcVw2LNUSkckO6TElIz6Rf7KARM0ETBHDPIpraVb4Fb
BsL7woQsbAqHw41hQVhfZ6hf65ZFYXRtxcqYp3atO5WaSaXkM1xKfgNfubnk9KD83UXwxmNQ
fjPJTd/gpqe4G8lphuNwR3JmEMMcx00Dd6qqagafOPRmBuODUzPvTj3pmEnd5Pie5DRWLcnk
dEg+mZJPV5TzoVwSnxwHuSc/7EPKR/nMWWafGVIKBqooCx3Ay9GHr3nM7GN8GDXjPg9exPmQ
UlMKc6ZL9bggxfomM9TMT6Ng1Az0UpSa8WgWTYmcsijkjEcEErMwsnA1fRlGiHAikb7/Xqu3
Tmft+ubDIzwmGE5fnk0sfD9995OPHnTs+uLCbGIRxIOOvXzy5JkzJ0++vCBNJJAxg+GJErNo
4scdW140vjKw99TCm9enpq4LhmcTicTDYRhJf/gXZ6P+MJyDhsTnYXxvyW+JyYlOv4v4Ic4D
I8R3Xk2lXn09lUqfhZGHwwl8u1mk2/zGO/2/fwRz039Nf/a/5rylyKXIpcilyC9FQrAv3UKU
C1cDDYiw8l4ZlEpzMZybC/Ec0gn0PlCi06wYkHKSKCchOQ5LDuHvzfxClYLR4RIIaN3YZhqs
UzhI4lKVLlXwJY0/oMEFjlqlwfUMUe7oY3pD9fXLenwJ1/ZglaUgWJDe73x27anX5mDW5384
e6rl27a7tx/c+/SNl4434Lx6cV7aTF7LWFmfHCoUSpIUCoVKJang08pFp88BoOPzwZUXzsej
c3u+lI4cl09CkuaTwboIp8YXVzgdbV2wz7PNES0MFliqgttdm/xbKhuIlvSDD187Fd3n/Oma
Yy9dvf/JF3/+2PatdafO/vHfeKICrI0msurJDVg0ucBOsIco+BXIwVVrAS5qs5qFm/I31bfX
d9cPCv8WhoPJsD4c7e3pGUe72Owd/aoduh39He3tGbc7rurujkdjzc28KwlHVeFwVCCAWVlg
HF1m1SxkxbleCIv1vNXrlcUy2nEpU/PS6PXzrERSPP4odR73FS+iRRgtx+Utj9ofeTOWpLBF
t1lTvKd3B+rvTnS0x5tjwXW+5GA4Ulu7OxKPx/r7Y4PjKDUWje5mYzC27hL6HagCu9Fb5yOR
qgTvscCHtl78R24H2eyix7lReuye0+nUl9A9LBvt2HE4xOPo3vlimayYD3VRVH9HTN4O27vj
vUM9O/qvRN+JEtHwUHMMBOVBIhh0x+P9Xfi+seAQHBpHP2Jzalml2lvb3+927x2HGv79Z166
fZ7DlsN6Bf85RUgRCuE2pMQHf6HF6Lwu5NbKP/W45zMNv4bt+juMlh8Bwvp5Bi8lfPBz4E4e
1Slww8+FbWZKbDQhrTxttw/O6+ftjFuPjZLvdtvxEDuehB83KnXZR6XPTmKrtUuflU+O2p9c
yCelVRXlAAsoO94wpTSNl2ReRgUtKnsfv30Cma3D6/lAPjY8kp+PtRK5KP6xfWr4KoA/Atjm
8dH+ACpdnCbjLnoZJwvfYrFOQBJVyTOR4lWuZ97zOnIN+UZ3YYFLIBJKoVhaZHEoJVqtUyqA
SpEQHjfJxI5Y0+qimrrl9dH1VLDEa/rGxd1+iznkJwzUcF4gyPRZusVZSqnxBWdkjVu8R5Rd
WHgiX/nwBcuK5na9pExoK25rsh/M99elr69sEUmYshq7UmnSCXOEJpUx1iD0W1ZpykUm78Mf
MBdCZlmxZ5XZuH4wbHYxupJ7K50qY6HX2tWQrlwR8pTCZSaD1FflCqVrn28wwlGDW+bqrU67
lrev2F7AaoX5aswgw2AjigtUwAJOsLmlioCC6FRsU4yYUP44mmRVRRpW5PZqNHpJkVjiLZKI
EAkn0DUAHqXYbJHEC8DfSS/X2KbOM46/r19fYh9fjmPn+H5LfIl9nNg4J869eQNkCUSUDLRA
GSZhkaoV6IKjtesuZewD1abSburaMi7qtg+TtsEHhFPmBMqQUNcNTVqnbe1UVTRS05YPWENa
NKXtEu95nKQJIcDUJtJ5fXwulp7f//9/n0f3FzcF/b5xwaZzFNmpgiT5aJG9xKUUvJ2Eq6oC
eiP9rXHKqDISH/VNsp8TS6qUb8rlM00pkEJuBvUzA5mUms9bQR6lakebjDpxu25hPOVpJZ4g
oJAUIqrGJtgBmqirTHOObJaNDJ4e3bsts7+z1r1xX+epsYG+g/yZ1I5IYMPO0SNHVL/+MJqG
KWNM2rhJ+cq+oUQrlR7tfPhG84Y6R7C3qbMOJ15CpulN7a+IDSbe25MkXL5dcHoUSIfbXArW
KW5nuF5xi96Acl1PQ06LQ0lUosEMK/vwYizA4WOgx8A+ILXsHPGxjyBgzoHpHWxiwnXUQi1F
dvOCWs2m2AxJlG/yanhFoPKegD0YtF/FO6CqxmBYsViIkZvsivESe59oCWMvFoJqtbbITnPR
QugIKRPVIDkPCyNFWo97zfh8JuV2lcC2sgurmIN4B4e1yTLpbkp15wZ27D7P3Z7zR92PLLhL
s6VbsnhLhvLKOSLDH1omBuEPPlvyAJht0UNYZrgGE8aiZ+h4orPTaffXGh9q7QyZDE8md3TW
9jT6YlZz0tzYGe6O9wf9yUZV/yM//Z7z6GDXrY9+0VoTeOnAwivXXxxnb2yoN9tMgtm8zW0V
DTaiKl+jEZUO6l5DkuS/kyS6WPco1t0Hdfdi3b1Y9zosFhP1ZkUVlHxKcqn8SSx/PITlD/WY
oPxhKHsAyh+vlN/FJoiLGNjkRPCoQIUr7CapgTAm7CBJAgUfvLNCMxmSamvfk/4lqUYkOi3R
lEQlAX/CVqMIRfYsNxm40awYDG9qpjUqDUpdFBvIFHuLNAICcRaqPp/LpGTXjOxMwbA3/ln9
S9050PIqAs47EcA9FQYwDEabrcsbcE0l2ZrY+hRUuuNPKO0eU+pQu8PjldLH966PgUZGDnxK
ffuz7g2fDD781ede/+uXe9Sb1kAA9e8D9X9TpyJBotDuSeIvlwsxWXEXyzcvwno9Qb3FcplL
yQZF4qkOOASjiiQRJ483KM4pqLTIprmgCVSJrqgSqNKRy+wsUbP3iI6d5S4NdymKhuudikZz
OD2dVnE43E6zNBbYalfS6I1IBPa6mUKginin2DPQDlzl1lhcEbjgVAR4tY3abOQSuwFQNfBY
bVjRoGHMVocS1KSBieZqmqaXPZROhxrQQw3ooRiIAjwUicSm2GkSYm9zfXYs+/2sypKlRdp+
LJ8T/7PWQBmgKMtu+DqPaQS51NZW8ZKcyzfh+WwJNjo5Jc7Py/gAQMS4ApQU00qXXQwr2HEg
rWrAX0hQq8NdxbaO2+i4YBEc/7T7Y16XaOrhNofenKmurjYaRmpMXXdaTjvqswi6jWGPUB2w
mELiLpdddDhceq3BlP10dj3fgc8+oRE6DYRrSJamJ4lSnivEGqDy5WkehA+rjIWAkwg4mZQa
EXAjAo4iYE+zHwE3+30SAnYDYB8ANnMPEvYgYY/HUGST3Bw8LEwLKg6H2wITlkALl1f8V2j2
SxkkHUKKQDqEpEMhTzwuTQFmDzziCioefBRaGVxfFczw/rW2NK21ZUvFlq0A9g5bQgcDNgOg
q3iWECe4s3LNfRfTij3Jvb35ANB0esmlBzsWXfo3QwVyILIO5FVW/Xj7slUb/RXSLvPdpCH8
teVvsDOarcRDwqSXDk4SM6Snwag4MD0DvoDy96qZKpXeJdEo3W36uunbqu+YdG9bPrB87GIu
8DbX6wWl2mmyKhKcFaodCsdVbsD1KpdiCaUD1dCBaujoiHShGrpQDc2ohsTmBtEVUDY3JCOo
hjioIQlqsPBEwmmxdnup1xuwUphEDhEtu8L1QZ1O4AYzgrt2kXX7t/tV/iL744RzU0OkB5WQ
hh8VQQlpVEI6HWilra2wvd4oRCJ23SX2AmyGdnbqdz8O0VDIYvFeZidBSG+RvgppAJtJ5UrQ
TFiBJjSY+c8wp0q51Ly8aPDuHDQd1iYr9qR3W3gpkHN5ksNdkWD2IvFKb7ncdiJn3VL38WAR
sDML7z6/8/U/Jw71tvXvHz78VMI7+kTvwMjg4ae8Q4HI9p539YvOX1cUB84tnD9wpr3fac/y
57U/GHv52RPvnGr55QZfOKV6MrgYA+uJo1xeVodKYsdIJePLA3Rc834l4zUFyHSI97kCEMWV
u2P1d2S7cyXLr6xkOdGw6VcXU7/IznEjESkRRVEliuF7hbhpJcRtNnDoDW7ihENEw4j4RRJ7
dm1iI/bKZHFHXAPofK4kzy/DXgU6p/lcSX34PrzWJHXm3oRUP1o3qIGTGzhNAydIavJvLqwk
c3qJV3qZ1+qoblyJ5isr0Uw8wGsxxIHXBI9GieH3bBI0IPx/SYzu83g0nzdzkcnaxIW4xa/d
60P54mG73BIp9/PVOn3R/Mn7+Am4nCgfU59UD5NuMkL3ccmbBi5RR0t7X/uutjlJ87JrVlZV
F8vvcKO9Xml22h3KXI7uQWYQqHuwgPEErnMQrPXKELIbQnZDQ3w3EtqNwTqIwdo73I/BOtzf
xzFYNwPLPnb2Qm9vbZFdnAiFujxNEKHcZebQHAfMKfOwecysNptjjBtEhTHtFPsD6WKPcyHG
/UElxg0mJQYD3YRnXz/fi6QHlpJ2AEkPDAR20p07e5E157X6Ijt5oaUF/Pwzrud2ZmeEfC1U
ZD8sBGtrI1PsBAxy7ccwYcF+SLKpyZVCnk0pOF2bvLLcDQLAfM3LJWtl2MN4Xid6gT7JQ/bS
XGUeWZrvMHszLdD31thxDFTXBa04CDq0cA074co/OLQiGhQGKiPyILGoT0phT6Qu+1rU02bx
WR4PB+ozw99aKI8t/KkudqRx69Z/DP5ka/qhUW3DfvspJdGR3vLCl9o3z99PUszY0t/RJ383
Iem1VLK1HBp9unnTDup47tHxa/6nr215zee2epLMaTNokuH9jcd7Hzu057H7K85ablW/os7A
ZLSNjk+SetjVPdAKiait0/HfxFVwoygZ3GK9eMyg9eOObgBR7jLSua20r1h+swAN+xbo3AsJ
GVdUXlz5H+FlH9vEecfx57nHPp+ds8/n93NebF/8ksRxnBonTkwKR9PCaCgvGV2BNhXdutBB
oQ1VN9pSXkpbaJGAqUzQFkE7TQJplQbJsjgh3ejEgE2dRjcNlU6T+INOdGqmSmuraSNmv9/5
QpxigoKcxIpC7vv9PN/v9+lG8rqRvO7u1H1I3n1I3t1IXmZJG5K3pC2bQvLuAvKy7OdDmYyX
x2UQDGXxs+bI3ZPliaSGVE5VSQ2yDUsCCvk8cbDPiY+NDHq9zWNGvPS0pRYjdB3GpO9A6Do6
MiGNaloKG8GdyfgYE6II6vbo/igXjYZOQ7trRIDVB79aEGD6XyLLILIAQ59PGWNHiDyNYcB5
FUY5rvW+JDAGGH5juMO3ytXA/Amkrc8F9zIk9XYQAoB9A3oQ8d46DskB7krdXwIPCIrqzOlv
AXJz7jj6TUfXpRK1c5wrErHiGy+PX5sz73jXD1acGl1LV760dHO12xP7aPPGyZZZM8tUJdu9
/kW/C4RWHNn2/FOv/rFp+zsPbFi3MCh6Mv65jY3f7qePzkrUjTEa45phMVYBU5+Nkjh42pTK
xqfQUBENFdFQVTGKaEQRjRpEQ056EI2kxy0iGk5Aww1rz6rJmlXOyrLlN6wAvSKwTYQZxjd5
xAY03m/MAD8a7/eHQjIOfBGoCahZEej5lShnRZEIBfb6sEUDv+GXHYBfc0jfdy2EotPQ+FD1
+roDV8trHjtlotT+lSddRI7E9Trxee/YI1zz5D7OUVUr5Zb35Opm9YM6700HtX89ODbC7Zx1
i03pDltsL2wxSvaQK/oWc5PvDf3BSiXcTiYTw+10RoJvjU0kSUTETSTiJuJBENhEJhOPm4jg
JvJKXvqUd7uX6xu49QZLArh/cOfQihfOmVOF+1blPUJJEG+O+h55rHyN2BbYvjkkcO/NuhJ8
ZBT89Du/KpsI8Gfqm2CW7r+l2ivVN+Rl543N5gz7J4mQGBnXHOaA1Z69YKbRaExV60+zE5An
MXZxkCiOAiSU3V5TQrYWkA2UnmC4vl6FDTvGthH1xpkR0QEHwUJqkcsa5LJmgQhgBgwwE8TO
9kDi7SMyO4zgylnLKPuYxJ1fJye/nDCADWDrJSeVTpw5xtNOdEFi9fSuOqkFq0/uCK52FoPG
D6BfSRqBe4cB6FTk+H2+OQbFIAy1JHLmzPXR55a19K4XRLmprSMZWjy3fmAe95calze9psfv
KT635doWGhPkmvfWNy5oXrCqp2HZI6nOhx1W25JwfO61DauXHi66rmy7ircFQzsgdD/Rk+LG
Zq6ZfQFJIZHXhh0OSRTtJQklXcJbj/uw3S5KkgO1g6M9AvdQUaTlZ3p8+kyfkml6NnnKpAnM
0Kb8JIMEMw5rv/6404ey2FB6tqlngWf7MTwbI+2U4zbx1cRC6kgjDYzCVek/Wo0rmG2vXVh7
OcKO20fsnII1W8fOi3+t5aD0vhiS5KwZPmsyfEGd8MLhC8+ZLQV2fEijlI6xy3BBOq45GVPU
hFdz+7JeDc6LF2abJmrzfct8nE8DYWBWnx0OH1OokhgH8ST2GVywtg5yHCmwrZrM8y5BUqka
rfImvZzXFyqwt+HWFBaoICTPKBcVTimwQ5oU9mlQ7D7NKsGFTQBqDxMXDUIn6sUHMup3or4g
ZOIA/oO3caRBYMKbymRyIBi4Dk3YqXdhH2apfghhg20mUIDAGEjsz+EtCD70BmzPJZBIpNGS
jSdKXdjOdW3at3zsiYMrr7mlmk39a5Y+kr47Kuf939XyvfMO7u3W2mKZl8zDHy4/2v/b+396
fWfXC4kl+fYn1/Qe3RJo2ZXKJ1LzNr7r3pL8fne4JY0OMRpjvfx1cChFumis5JAbHFofXB/i
fi9eFrkawenKzjDGN8OYSLpFUtVEQ0OB/VCzSapHktRKZrkZnlvGGlJqItKSlvKK4h5jF0ge
L0Ownlvz9On8jjyXz6cL7Ixmmx+hkYhwIEETv2ZPkxTYJ0Dyldnn5vmEKikNCa0KZndC6MzR
3PvsHaLAD14i86j8ivPT9ESfgiZ1QluhR4Yt82GapPtwxQwYJ8LVCa7JnRkoN8Oi3Y6W5G7H
i2d3O7rOdhl+Qdj33bRLz1D40C1L6DHi0meyUXmY/pCpCd1Uy5SDG0oOPkTf2hWtyze0O++N
52Lu2ueXRveGFC2+sI2x+tRafyzQtKv4gifsykUCTs9C1dfKHxsDW0/e/+Z/G6XaB9YXVtbP
4QNOh6uahtTqZLAx5Ki1x595cPLAG1mVxrZI1lrFI/uqHE4FE5vGzBmzBj43kiu6y0Ng8gxX
q2e4asdM31J9wc5V8PKXGmMxX0Ffn1GoJwyoGARUeKZJY2wr/E+Q7vYsz0tCDBMqigkV1dM9
DBGFTiVxbMKW3UcUSHcJKZEw3ZuMdP+qLL6m/DOSHQ5UcPpE9ekWkWmD7pju7CPjPHH+2SPe
9Ilxpv736awxryd8SWtIwZ+Q6S1YAO3dZLSy9neOOqsGx8cOx0cy9HaC3lW3Hgonr7k82TRP
W3nK81bBiaJLKLqEtVBV0vyU15ou1xWOQZmyxsIrD6ppUd1lzcDVGPKdK2sHc++UVBunK2J6
mxVAl0N6O3TRuDnDR+CrKmj4f48SW0kZm6GMdSprzLoo+OLUl4ZMYcAdH6bUxlurdKHM1IxC
WRFNi0X1I5q+5oghlQpS1YFUIkjFsReHCDFBW24d5HkTImorIWqzuUUV1YqgWhEd0Tr4U0VA
tBHw3EP8gGgQEHUjom5EtOE2iEKHTokZ+LKc0kx6YiaouQqwGlefCMzIXB3zMvvj4/106xSp
yvXBV1/OZjo6F3c01R37BXfJF2tb1RCpF80fXHz8w+LQlPqfh5ua9/Q++u6z0e+sbnzsoUWL
7vlHTnvmySeAUEN5cOJNdKLkDH9Md8JP/lTZCccMJ27vAKBqQVQtFrehvwf0lyrrryNr05G1
0VYbtdnsogdNcKMJbkRWKnlwSrFXQrZM6XJsSzrfqnI5vXRNua7lCPPzZyhZiWP+GKj3Np5v
ki2uNe0wdcDGUckHo0S58bGmOpxZQXF7k2yu7zXTCZ5faem3cHHfCDvnY6FQOBIB0k5o1rBm
FbPhcNAzxs7BLe/vQw5RFE5DKTrAlvcH6+qCY+w8oWzdcDgcUtVIgW3T5OUhGgr5m4UugfMI
IiHuAvvbkFkU/ePsLciKT0g99b7i/BrUcULDQfH1yVh2N4cfvDmRhhcn3uFuLsK7WmGKAJlm
czgRl6HJ8J7mimSwxCwm4vWYIhm4xaGYph3FbcUjJ9772eCPHo4820ozLX9efvhgV3FncSPt
oTlh/zKteOn/pJd9bFPnFcbf976+tu/19ffnvUkc4zgGxyH+dhIcyIUwUqBAQdlIFwLd1qaw
tYBUVEL4LB0pXx2MAYNpXaUhDRiaBgmJ09BQJrSMtX+MTVs1tIkxRCsWKZu0Mdqui7PzXtsk
pCYE7Z9wLVvY53nO75zztA9t6/r73oO48jd49o4yfRJvsrP8/XDmH3+49nuOxXc/3n0HtAtn
nle0i6AE5nqIR2+KG/pAwCIQUCDF5IDjjEvVJLaJTILvdQzygzqV2Dd6V+ZcUjwej0WjCaqj
fVlsTey52MaYKhbzaMNaRlth9Ef6s+dyd70f+6m+5aCvBySl+nqQBfQ1m41UXxvoG4tFE4k4
1ZffEN0ZZaJRQYUuAfrVcHock00qlVAp1UkLJeKX3BZLOdXc6XYLVHMnaJ4soPmw6SOlUwtK
31o/DG/Wto69Dw4EFQtoOoNBAJeEcjZQ4Z2sxoOoK2XeMVeoQ9lRkbWl/Yfnd2mJ/s7Bw3gl
blhzwZL59nOZP2WuvnfM0bqlYyauL7++/MSRulRFzUzCrt75VibecQcO+bY362fZFid2d567
9keL5x6DA9j6W/zCM2X1eJNTrfunRuCsYX1jMvOXW7tuKollrSqsYiCniugHsu5Z1RDLuFyi
w+HM5hZRyS36PvLLbg3PawbIn+Gj+ezidDpE0UV15hwOfIPcsDLWvtFbNM1aqbEGlxgnHvhj
JTyPYaV9eKEIIswd0Ke2lh5gVNcxPevug5jDi5c358Ld8Fgz5yIMFSyZjFHFYPc7FaHCn+9n
frXlxZaVUjBQ/cZX5nU8Xbd+8bJlme/s+HgrDTbbqyMst6NdbqzZ3BQ1Z+y3t91W0o1SN3D/
NnCPx3H/Rpb6ksmofyzism4SpEsnthca30tTZHcK3E6CLFQ8RuvVcaw6oWzKKVOAUz1w+oRE
vpclkqZXFJsafNHC8KFCvP0/lD0xYVOHC2G6V3JctfYoUD0CoSlB4wRoPnoADcqT8mgwHgXF
F3nI7cAcC6fGdiD7CVwQXjT4DirJ78ASqxjUpKR92jO8uknXpmP8UlozKBHgh2FIdl5g0tNl
EV20IZzQEBaTSaANYYGzdqDL63VTPlgY0RiDBAwdHZZD6G34UlQp1AmMS4D+cNKW4EymItoS
XH4H3hvXEo+awwVnB+0P5WyYHCjmWvtQO/Pjx1LFbr3VcfuzlZOwlduEioIJzPRoKF2WB3RJ
Z4qZppK2EiZh6JUGDYNGVUl+C05QUhZ8okcIC4wQslYkKHAqClwFrqD6BkBfH0hK9fXBTTsA
Ac5K9XWN1/ciQt6AKrv8IpQ/rdZU6a5zL3STCrfX4QhQsYu8XhMVu2jy5Tc82e4rpH0eTqr+
EwNKDdnGHH9CShV7Pq+aMqrZTKcKs++DWyI6ATtQO8QxDIOBz8t5J+AdM/CrMxh0lF8RabJm
9BCCMFb6mEOIvaG54WScOZqdeZo1lGanxmBgVcoKZMfTDA8jE1bgSE7Khzcg1bAg7MyP2oe2
MFsLE88upXK0TMQ+Tz37PlB/WtmA6+ASvqz6EDnQit60DRvN2NxHPrjosWi1+rmG7LiCsb4P
hPgu0tPYBz3lAj6PpLVaVtZwcTYUhCPedG/knngn2yMhuORbaUaCQDRdiUNwq8eUo90Kv93O
XM6k5pUFOc6vrZ6Om521oaandiejuLzYu6SyLc6Ueb7XvDCBa7528s2/waTK/0b4zWeVSaW8
Vl8F5yTUKXNpF876Bndkr4yx0Y7tSg0OQTD3T3QMyFBxDog1+5AdSjJDSSooqRiKO5IWBI6W
xI0ryfUFBJTyIKmM+YRzPhWu1to+tB0fLliyuhF8+s/XJ6tbfRXqPqd4xY++RF4l56HqDekz
zFlTmiFGGu8EA8Q7chmyCM9v0O/U063ziy6ZdQyQfljKTvIy4smR3mXcGo7hYMzu7XI4LO+S
Y4qXxdi1B0JZNASlhloVC2nkDUkjrVFaKc1grdgGfJZ5s6krFk1WJxNxpT6Hnbx6cPXaRc0v
NF+q+Op6+Uv7N//E44vXzF+EDbN/vWhFNPjanLqKpd88+syMuYsi2LCgdxOtLFcJVPYzxVHl
NXsAHHWjc+kz6rO2tJpYaWTloLgH7l4Ed4v02VINhg3mnWbGrJTKwf1BSy0iL+ec7ic7EBq9
0svZYLyqDH20fv0akKaI1i9JDlo/Nd4zoX4zzaBjfj+khflh14NZ2yfRpqF9aDN2FxaINVJG
X3+cSuwBUOnniv/y6A5NlPwUzcFGuZTTq72i3u9VndRjvUssihNZb46TcnUkXllZnuobvXLR
aI6nIA/9rguh8gHgQEZqgNlK0t0Wi6402xweaA6R3E7rCAlVVkZm9JPjKDR6pXv6zHgI/g+Z
txXFUQiHQtWed8l+VEoOo2JyXHZoTL6Qjznvu+675SM+nyGVQtXV8bkCOQFfQ/tKhqmxF77A
Sg7BljrZY5A5IxybuHgPyDtCZTX9W6KyA14umm5bYxQ3KjHsjuHavAOhYcUD+BQYVC/BhhoO
BeGVpRbADCouwJj0+qer1WVlNo16mtenLBxndp9EwY0ciMqzQqfdpoEJGs/DatdE16/eNaul
5dTR1zL//Vfms4qqzrpvzP5r+uL9YGNzo9O26vubjcUhhjFVtQaiGv3qIif226oC0t22Zy+c
OvDKzg8qzp5Yvm7P/ufndHRiQ/vS+d9qXDWj3DbNOpevbjGKat9ak+CwdNa/uARczbkIrl6g
rioT+SY5gmrp1WUd/VR2w7nwSQJwx7wafpw9mXW2RB2s8vtLkjlnk1XgbDdC5pJLYK2RWtvF
844+clTWI5iAdiMhAb8/OI06Gsg6GqCOGqmjARwIRJJJFIlUDYBl1LAUMlJzsiyAwBOcUDwa
iYoUirqRuodtgPdi8CF6mcPVlTOD/gNklJljcGglcn4oz9Sfh2zIvVbd3Hj0KepDw9LS6vmz
lh86tG5ByzxGtWDm1o54vZEr9oMH5atiUQ1j+zKYUO4pC0gLljf5SrEpteQt3rMiGpvvDWx0
WXUOtyK+RdJ4X7JKBlZ6RVE/rzaoD9rBvFHcUEfgSYcW4UPvAHSfynqLFOdEdZUo+qtUPB2x
IDhHx5EDHlgT/FHTPydFLCro9ZHTcHvxak4HT90yi9l+cgOW5GnZrNHUGKl/xohltlxTE2nM
+dcoUzIFIZIl0wJklgKZbrczOJdT0KwENMvJbeREDNkOv1al7SPbutRqOCe2ySbEe3iG58OC
0ZiqqZkdpzansjanHoCbwqlUQyUFNwjgzqDgWk3hUJg5H74evhUm4bDU2Cg0NMg5cAXog6eR
WwG3FMD1/o/0ao9t467j97s7+/w422fn/MrZPr9iJ7YTx/Y5qZ2kvmZpmxTWtPQRRmf2zpYK
bQ1UI5QKAlpHt1UrqtLR0o0ipAEaf8CWxc1aqpQyJJAmUVTEP4URCgg2KdqkgUCq6vL93jlJ
mz5YukixfYpkKZ/X9/MB4zajcZtXa1ztbFbRrVgkqTu72AmP/6ouQJ+EgqlZGjpSmmoUeC4J
r97uT+hxY+jRn4+S/U++uOX0E1PbiWm1jjf87sKj79Sn39nyvdHzm35w5Y+fzP/GHChwBhWo
K7KhwPWkBxW4rDf7DXoDKf53GrQpw3sNU2IduYP0JI7LUx7icUWjkUi/LsI2V3c5n2/rb4iw
v4whwvPBNlShpKnwZrHNWCy8xxPVoyVCIhHJ4Sjm893tqLmirrniUrQUSbHY19/P9/WVMVpQ
Uhsp6WNFC35YksztU2aFXCjcGiiYW6ll9SHE/LghlJFpFEpqVZG0QiWXVhlQ1GJCafo4pXUj
0ItpkjVRGapI/V4Nx30Wq2LijMFE8FienWg52HKcYzhMoZTgbVZS2qi02JVK51wn3TnL/Hpm
spW0yooeM9jmbRAzPG/w6wWgGVKmibk8YyiE2+VmjAo/RIUHosJCHHJWpmXZBESfwBvxRrfK
n9XCwQbhIEA4mDAcTNeFQzOkwwJaXw8F4OimE361F4IB9wEOITR55E6W9riBrG4CtaqQB4Nz
ijaEImHT5JWLU5P1KyvN280FveuKxioZ3Z4q9+xRNz2zf6T/1VeIkWwlLe+NfvYWht0t9O3e
HmH7CdXjDgzvOm1OlHeM605F5IGJt6jGYjRmgIkY1U59X/VKyMSIdCxFTwQOBo4amQgSEEEC
3EAAo4JTWUoQHI5MpXWulW4FMmqTMpEt3gzebDOyoZrTvrgosALrQH/xJ0UiQulVRNEcP6uj
TmUps24fNEYaQrUAVslq2KJJNDhdujeuR7Uhfc7ZndeA5RrIXg9msoGmMXPlTxt3hNRyceTw
4b29G8QBhrC9udy2+8hoJTw0sOeezYc29gzpQA6Rlo1b7gsHCRFIeeCHlrinv7W0trVCqPam
zPD9b5nbA94d4w0tI2KA4JnFa2uaNFyET51UiZjUcKumZqsxkogc62In2g62HbcyVlRzB4LZ
sajmpQmgWh0EfirKnEIrmrozJBNbo6sbhh4MulPTgmAO6uoOgbq9zOWaeWn/ganY7nguFkKp
B0HqzSh1gyOWjdGxGJ+DS3hC+ypsRIImdieIXQSx8yh2fsUlvFHsKPKrt6muuu4L8LK8IBpc
aevxblxg3Dfx/lfoD1ZtBcMIjo/P3IUfDBeBzbOLl8uY0dhMUjnIJq+sOUI+1kFPhA+Gj1qY
FiSxBUm0A4kcOmKZySaNyZiJFcWmps5KZi5DZzSLxEjMLnWiRWxI6cwSdyoP5GUDrT6TaBKb
dL/4iA/94vPZWtEvyFuBsq3wS9afvYmdldZx3p6Z1TiJLSMjl1ZjpwYZq/GUxsLcYiqxncZJ
yKQu6u0Zg8lmV9LQD1QzfDBaEhY6iEWC9wUUPmDzegWbTZpl/qJaBC5GV3JzOTqn2QgWAV08
DZhjKCWUDpblaEG1uRVB8HbxXQE6wEs2W8VLvF5Jil3g5jmam2W+Ox0Ok47FoFoDPPGLwC9U
S5BTcOnHC3C/S1U8/GmndskB/KsN6JcIcZa08BqHMx7RjnU3SD+RTHYB4CInej0IO5fEQSQa
OcB9pRXYzivPH/A91bLBJRpyZW8o3cE+Eum3eKzBuOxmOKW4Vd2eeXrjlhem1ui4byItRNgm
lb762v2eX8bHdj3sMoqxTsG/eSA6yL/4raI1GIklEqVYR9/6b47F+pbQR7QB/V9Q//e50e6Q
HQYcUibcjBn5yS7xY0/Y6QjyYwZ+lq3h0KzRLoSdkiQ6nbJGmGhNGivFuSJd1AhrJ+3GEhKm
W4QmhEKLKPQkfDGNnqBpVl6TN0G8ikikKEpdQleYDguy01mRiCTJcvKCdd5KW5HIeNyQX3RQ
L2X4WERqLT+dXvbUrWjV2t51zhpvNLW7o5mZAn+RA6vluuGx1RF+A5+/WsHvLZ4pQin1z7OD
7Hlg+82ZlKlsooXZa/M1oUkZYwnU9vlpn4T1/Z+qMxBWzGE79HyZdiTkBJ04DVsveu1czd6k
RKNZ3xnmPOUCPZx9I5fLIs8087gqmnlZiiYS0SjldvNULkdRBbDzK6d41e5SeL5tljk2Y1D5
JsUAN6oAvxBrBQy/rB5zQBu0BujhC9mrmI4aWRB2Wo0mVYOBC+snKKEtpy5A3+OF/ItC5AE5
QBPyw1L4FMEIZAfrz47W36v/NZl5KP/pnanoc8NPnlZDXaHfXssoe5+fejngcMXqF+ovH/8p
edrX0z1Ye5/+4B9Hv/iNB0svZUuXs+nCYw/QdH9XKpXP92ZjI60dQ4P1+pHnhrYzHOC5ob6b
DbMqpNtrM36DP0EbAbxpr19x4rvHr8RnmTnV83XuMOQRZ1E9AcVisdts8jU/8QPeqlV0K/6w
4FT8rhC2BBk6gg5re3sKISfM4zUu7mfcbtssc6Rmt2dZipLPar0rCQOGJfsOZBeEv+soAqbe
RQArgCCcCQQWkMa5CyimNRTDcafi6gbJopgV1DAODSMHp7xQcMaiSVwnbpGNIILh+rfrZ+qX
Dr3EpwQzb+1cu+Fre46EIqX8YC596NDhnQ/eu2cfKZGtyt7O2vy/iaFGEs9sMjt4ywu7Rvc/
3FMsB8qSq/7hmrUnN8098vpPaJoiqEvmXfYIFaV+pDqNdqvL55pwTUUNDnKS0GSW+Y0qUHb7
d6IkakbZUgGzb5apqeZzAJv/gQAJzDJvv5mFMmo+o1UrE4SM3Rmlwn4ASRXCPp8Twp5SzU6F
ouLhWeZEzYkPTlNWF11axwsKELxpkd+8ACuvms9WoQ3hnwC4KqSCT9DGQJUwLLc81XT9ofW9
XELD0S0amHf31D/62fGxezd/7gtBeyiYj/7n1aceq6ZTw9WB/bu+RDwMXf/btvakwwpXlKU/
VS0f/fPQwEPxkEv0Z9efpHRc6MusBTr8ITXE+MhHPjLk2yl9WWJYs2x3qRDDLpdbhUXoxkVr
gRh1u/0xC2VBC5rhNton/ef8837Gz7KyPeBGOByUh3zoIR5VEBVPIAA5/IfXW8xZ1Az0j3Fc
qn6tEFYrC71CL/oujYopaYV9nKqOk+uHKvzzeptIKrpwQDcgG/ry1PBEy7on1m8dG9t2Tynk
kYLWpv9RXvaxTdxnHL/f/c5nO347n33nO9uXs+PETuwkDvbljTJyClHpQFODhgJ0ykDdSl9G
WcM0GiE6qNQBUtWACi1QYKm6P6DdpCGSkBBgMLRVnYQmpqnVmDTWSmhdMyGxjbK2I+me5/yS
uAkF/rmfX+PL832ez/f7uBtf2P3ycHqxt0U+QOrM5b1xmQj+6ofCuk/ix448uz7f3xuQcY+0
yMTvBydqZT4dS7sXu9kgDogb4eQgs+bj9BEdeoTIiSKvEiVeeZBXngTvS+tp1hqeZIFXyWQ+
irySwT3On2ptzWOxePrkHF/SL7AEXAmjvOoREnoynU4mOVUVuNZWjmvXEWICQkwQmhBiToSY
8+4QQ+Ppn2M884gG3xkou44FN8t1Hhhw7BoMdH95QMrxIfCbz8YfgHVsgXW8ZGWFf4+pTjXN
VhVpJ1mLEOCuLNNpKyLI9QX8ufaCi7u8iD+vV/D7E19qRCvhT0P8aXIN4i8B+CuotGhRMypo
m6vSyHoQCfte9PkhQ1RhhhBd9RpVVT/CURTzDo5LnLdCdgbg6JgPR5z9ecrMR2WlPJmyPA9C
Tnb34NQ29sX7x6ftMKjyeev9QbSQrek1fiMokmQ+Bo6KLlmRB+UDSdvsuLgtIRSfbdjG2iyw
cqJ4MEmSsLwQjot5ogWwgiDa+hiJWWCFrcWDM+KuyG6SuYPdy15gKWu6cVBEKcnVagXgRqMS
Z7NxyFiOq69F4Er4RHIvDNycAvMRnpXh7vCtUKIow71ZzC4fnNrBbrsHkG1TUPA7R7+eymyB
yrzb2iSvmAEaJf+Jkm9G+/TndTpb6SAhmsOTEGWktCyrSGm1RGlV1VJezotF9ViU1i5qH2pU
m9/b/tneDjscCbFgaT4mTG6GSRgZHo7FOGR4g+erDMcsO7e7FyA6lHO2mhbbsaD3wXfyEXQz
+eQekLftwyCr3p30lMkSjhf4JVbXZsmiM0wzwgMYUC/ApRlREpBkeAaXrbFdMdajhBQjjqiJ
RJH2V0xBgnVRcXqMek+5/iOE1IjQy6N+v1KTgkqOhBoNPE83NRupVCR9lr4HeaOK/v6UokTO
gRDJ8nYCWYE9S38CQYKBz4MLMEzSf54eYGKMSIeYID1sCl7TKRneSFc1qTb1hFE9SY8xTfAr
PtFowl8LV1vnWH2j0dSUOkePWqvKIiCQ8ClABpA/ndkC5/QtnAEUKnxjtv0tDN2whML+V6/j
J2aF6iDw/Uw/g9eiYHaeQ9ygS4Qsc8i31eZxFAoriT+FswBvyLZLg1ODpGPXr67tmlktvL9+
bWNv9yOrHvvrYVLz0wZ9zXcHnmnJHE001wW0PttFUO+LTxy24MqH929559fVv3j0yaac0xNc
lN07dPjArpl/7nh8qRbS22C3KOkIu8UfS7sk+xx/GXRVmFrmqumSHU6XIddDPwcs0QIhY1fg
qPy2UByas/QEVJzQK6ZbUlU16mqpMWvYmgn6rumFarvAK/googYQdXN0WCISP3+h9LCmC2HE
+VWXHVzgDdOT1Yd1Vkcz13X7efq6JUQSdsZtuDOiFv04L9ZyWEGgGxnRcuhOFV5auWrtyZ3h
dYowE56Dn0x5O4wbFuthcgolF6VyxWGGyN8Gp3aSH02vYNfaHGps0zd6Nz/y6KqnJ69GGpTq
ljotlOV7sdbriLCmrjO9tPuZ3q1vnZp59fI/snVttSE9UqroIWtSgozG3DnDRGEGoJxRK/GA
dS7X+jT2tkbEnC9o4Co3IoXwvGkG4wnD44CLKpK0QCoLPmqKqmLWZ40fKkRXSFYZVlgFvQG8
eaef9bdAqSWXa4Fq+0vVtrk4r6mEDS9UfDxi2quMSAQjKd6AdI6+YdVcLzR/Brs+47dqmJnr
vGoWmrwf6t4/sCVTrHdFtQew3xk8ikW3KF/k/ZyCs20QgsjK6ZrR5obNr7z2/N51TxzcU7u2
MVj9YrGlicC5ffFnnzry+czP/zvYtyEsZlYhz2duc3+39TB2ppnpJO1nGP7Lz0bEsIHBBprQ
Z/gUQTTqFCg6bHY3sfg2LG8MHhABSY0Xh0/xHWo41HjCd6LhRKOdZ232CXp8xATjnaRXIcMc
N13UVNMGRUukk/RfTJq+ZzpzJmSnXK4dUvr4aDCY9rRPFjLQGBMRImzkLAQgsGm6/RT4/Vm6
HcTjwSE8kbjBm3hLvCMZnKB7RmKSpFitL5hO1WgRiJCNVycnAFteppXsayWtOEatrdXn6Guw
K33APFTGUsE7sv2YZAFMlvtmAE1gE0z2BvjHLI4y07czmRu3rOEpzoKlD4oD8oTaA2AVfLwY
YEN8YRTgGcxJeUxCclk2GBPu3Oah3smnDqz+sPHbYzNjM1MzHzTnX17ynW/duf4HsoTYns5v
3r6i9/FNXYvHIh0pVVtdHeWuXe792cZLK97637u/29E9dPqd/YMv/Sb90um+bXve3OiJBqo2
f3//q8eODP1p+1JDV7spkKqoMpDq/TmkugiqR5l6wpVVr5BYqZA4jCwLI8tCyDIvsix0NPx2
kC6g9sg+SsCSpkyXqmkxX0vSTLJJC2siYk0Uq2KoR8zCGmy0VehGsMKWpJ6g201vlifDPAGJ
JZ/mkgpgSwwn2ASCLZFwIdhQyjTjtMB2qwJsICsqOI9qgLP+r5PwnmBj/UXFiFQBt3XLK+D2
WFGkL564K+BKfFsKOihMHJNAUYfYRIFzeJpu5Fy8L87ejpMKgQIVAsmIwGARgUF8XwT6+S0E
yiQdJAtNpQZTGS9OJY1aRIwSPUqy0eEoGy0QUdopsVILqKT6fAsJJfNmRDN8vM6zIJbT5xCR
iyJyUUcu6rpa5KKKXETJEvO5aM0f6PUVKOKyMkeugUxJMOvhHNHuBsZISa38gnD8c0mmjxcE
JGx9DaSOW83nmDjTQzadgTB80RScPqOuBdJXUgF+5XO5CbrVdPcsC/b0LHtTPimz8gQ9eUpV
dfy/IfvqE/TSOBi6DwwdJPjlacrzMZwQyFr+IFQ+l5mk40za+tMeI53uyOWXGV1dHYbRfYF+
xHTQHzM9TA5KX0N/MKKqDOwcB011g/CcwDKCILACD2sOINEfACQKLlw+zBjTAnePdxBUDDzH
7X6Idc1GGoA5GtuQIfCjQ0wzMDKeMl2KkeowRcXo6Ohalu/OZQ1idMfsLqPb6O7q6pkE0R4m
tSBaDjZENZsBhToxcuNkIRhv9c+ycwDgibrBDE6j03VNL+kqup6/s7PwoSJQB/JZAXTPYCtc
799ta854XxB+C0qjuEEcwVQ7zBwStAaDXltbO1CVxw0nlJNJvJz/rOGM05QF3qAd0iC8Zk8F
2Oljr6SybW7xe8f/z3aVx0ZxX+HfzG/W671ndvaYnb1mb+8ue7Ae7+LFmEkwUO5DUFIXE5IU
KhMgOLQBTCEJFEhBoklpGkxRjpKK0ksB10cMtLSilFBVrZAqhbRVAwmk/cM0UmmVttj0vdm1
g5JItkfrla193/ved7hCawvZQLXKsuW40tFeYlaNPfL2wytbZ7elvIcvM9d3aE5vJc9lEstM
MU98E2ff9yJn1ioJu4WuaDuyID/FmVodc/glp9tUuvun+Q8e6ur/WmbRgszauezJzPS2hd1S
gxwJB6Jab9E+9iKobp05oLrXIFbfq7Uoww/hdeHTrwlDYvcG6fGGIimQdzTeIAFxDJLoVlcx
jByAW3xqMJNzZTI5WO+Q5jCbw3JOyASCyWQ4GEyfA5qEgSYCvapFaBg3GQ4nM4F0jsgFqLZp
3OUTaSYdTCeT7p/TPoz6GM+hDzw3qLxhuWBhLZjeQZYtFgg1RwcaNHMAHAG2XsDbzOob5v+F
zogU6KlzYIIFULZGZ45Orhk3rRvnAXtemthqF26VqwvrpEHCelXccDIF66tFeX15Lid4JT0+
fuF3P/plPL2tffGDB3a+8WebP5strc5z6RlliycWanUFmPZjt3/y3Rc29p7OfPXHK7/42HOb
RU9Das2R0dvxR6947M4mXzT8+fnzrY7xt3q+F8PkXkcakP8LIo+bYN6FG3eTZ89wlOI5O9wu
lxu+OQPPmwwGEe/QBAC7CYU7JFBh/SZE2WTiXZxICwbGICLGokHkefdZgNYLpSqOvvQZJ4Pp
r+0+tID5kyCBAX2ax8y7Y+8wP/0EReFT85/NvYmJYMK/6tyKjC9mb9AnSYxc1DJRBYKdS7I5
1FCT6FF7xW2RA5FjkSuRa5G/hW5FGg0is829382aQWcGNVNA8wbVQMCr6J0yiLb9awjQ+Fuf
z4ve4fVCuo6dBWAwXT/e7/USIOy3hpRgkPBmM2je0TNWKwePQV4zh1SevAkAJfhbOrMQBl0V
ZN+YpAsGcgzNOosaUbNv3/sSJGLSw/ToFSQV5dwejxvyFvKmxicQB1R9Y6oMHuDxsjf2DI3f
Ss3wJyxJm6rIbr/yyomlbXJeLU55dtGs1zcCRO1N26+u6VhR+voLza+vixTmtE4pVZ1bmjqk
vu8fO4FMqeMGOF4HHFnElS6nl2C5MfIVzeKWQL95/CEiKEJASxbUgBaIAF5RzmyCLnf1DCFm
jLUm+vgZjnOM0JdICJTe4pbVtaEtITYUkkboy3iNpxOmWj/ryqINYicDdAAZQbdBXRaZKIYT
Y0MsBpaHQ09kSggtsajR44WDosu7D+96uLoyPffSpc6WDrn1C0sqzQuWnM0WYym/6l9m9jDJ
dHzqKr+N4T2B2U8vn3fsxDdWeMptnS5zqK5MOCVM/R5OTdrv7eZWcDehL0TJJS1ktkiWLxu3
GbkB5ZICqaIPtEPy+dVayRqmP9DMGoNBj2FC0EiH+uGEgufpCFFIiG4iXnpj0EQpnAcLlWrw
CaAnsYYesNCDJEifJzLkOk2vT3HCo1UpAiOM0G8SF+0bsGomXrUOMwEUpbEJSRq747uDzOma
LFegRfjex9H9vlYFkZ906X3KZWdj0fgnxSiZEj2oPBboVGypvHN09z/H/5PJ7297bMb1oZ/9
Ozv3oTl8iOuGWnW35+DJ9Q+cPnFo69O/zZw6uqx738EvtffuZ+xPF1ftB/bUcQMcb06why0Z
bgCODrJtYBIujGSWX9BhwMdKNxPjZOtEiEbobnCLC4MgzIRw1mF6cMCC2FrOAVZGIBMgdVow
IHHuTNjq6GTH1GGAX903Pgwugsbg3VTghNgSjPne2GHWbgk6KksXVAzrYbL/zWL4joKs3V45
MjThVfDJYZIPdEY8xLDsZi5JPJCLhrRE2T3Hfc1HTxqGDKyvUbJ6PfQ33B/drBy2aaAwNozs
NhQTqzbTvsTO2jWzVQWXuTigvALbDeN9GOnfNZtDBrOz2LI21mb3Qo7RbBBkUFwuCH8QWAFz
j0Oxa5msWs9TJDBCjxIzI+8rjNaam2+0C0HokkeF1h740jsASAvkEuluFuImGtGTECAZbGvG
Ws4vV0A1KqC2Ho8R61o9628WHYHN6zsXry7MiAtV76NadXn7tw/N0loSpT3s8badqYXV8sbO
5S9vl/J7c9VUrn3Ta+L27LpZSr6AKFG8I8NhkiAqOa9JG5wbvOxb3DWOdTXyTtWXShplOawo
6DdOo+wyGmUlIYd9yZSxJAiWEXqZlEAp7CFFLZaYLaVnSmyplBqmFwZnYhwn4XN0C0nU7YiX
jYIS1iw2MH7SWmAK5+mrRNBNvswI+/ibUGZ170Fr1pmBLQnFpidbOxsnFiehVTfsA/ZdFw/Y
2y626fcC5xJD3akpTzSVwqDt1NWnomfuCl5MczOT0hE11uGjy/fGQ9WmMt+RrCTEYO/i+KGw
T0vOaaE0llvrTUiZveM7XYqzEpF415yop8gkHMFFG4ZXxJobJN7u9DPhqD8rp8P2oC25deXY
80fUKJPY7jAFfS7BY7HzPuxQ5ENaNHAkTKaQMvmVJqTz8/Ld+R15ruyZ47nsps3YhdxwMc3p
6bEF0B+VoKJ6Y0XaIkH/HHrGz/iVFqZlmF4BebYjE20Ap7Ox0eaV/FiP/H5JImJzEe1PDqjF
YdrXryg5WESfZiPi78V/iPdEThRtOTA4zUQ0yPCETLMVULZHdZTh8sayei/FJCA0148T1L0L
3/W2Zrv0ggNQAy11jD9W+XJFVygkKKDsTKgo9BiTAH8DkrXBiKJfDMaKmUe27Ji1Zv6izs7Q
bDGanF+0uv3f2bV1z/hTQX8uLK/2WCKMa9XMBiG8t+Jk/jtv1Yam/MLpAQ/DO23xHZ3r8vFl
q1d2v3Ro/IM9za2RQLApYzZ6XgvtnF4sVT9HEO17JXqc6yVpUiLTyUdvkqn33u6Xk+rUYXi6
vPj8SLNJPnUD38v3lU+VORnfsdjVgr6GcFJttKamlafRRr5POCXQQpWpIrD+sFodppcHHJUK
h/3miiYszX2YY3O5V4tMsZhwpcX0SI3qA5yzMREpopH64C99cRUL5qBDhDiSqdT/WQV20e90
itB2jp+JRJrh0d/YKBJMZjOIyDghmb0P+4Ad4HZqIQO3BUsCxfg/69UC29R5Rv/r/8aO7cS+
vn6/33bsOLZj38QOCfF1/EhIIAkpNDQjJUB5LpCQ9QGU1yrSsrUFxjoYkNGObkOTkAYJBRMe
ZYUOVWKTJm2dWk1aNcGGNqIiFWmdVpx9/7WDum6aJjRbsa99b5Kr853znXNamJYYSCMONVQF
ZQbOD5b7JxLyB8kZxCQ0hO0wLlFD2Y/Zsh+TE5BD4sK0yKEaDNqvI4OauKWPRjwel1ysD3Yk
X/3g9kBjMmUcWdqVinsd4dgzC7bGbxXX+zSmXP03+oP8ou8w319mg7BCazWmgD9k5Hc+RXl/
RTEyRQVV9/Jzzzy55Nm+gWCV5KJp4ZZtNU0Px5OxFtuyl2D/iGc34wn8CTKDlV65iBSz96dg
7+rJJOxWO/ebytuVIqkR0gC1rHp99TbR9mrJ75R3lH83YkD0Li8F0bCGahWnI58UrJ5TqlIW
ymKxC448jMT4Ki91SCRyXga1oYCvn8cpWw9Emquwugyw0Q8hMdj2sQsHnJTTqVRaLkPxIBvJ
RxnGhaQDGM+ARRPDHoyQFkhcO0VwV8VLNZCYNakNSCiDQr4BmMXlEgFBTyshCJONA13h9/uf
eP9WcDjX1LFyxejWoGX1c7muod7RrZYn7d6eNLXxdPHMxol5HQZNI79f/M2Rw68e+fhY4of1
Vk+EpL0yXuByM0JqPjI7Th/FZ1EK/ZzXWaJgYj59Yl77vP6mz3UVh40PakVsYfZjXqqp4RoM
wH6Ie+fPOZ3zzUC367xRwXtqOLsiolihGFHQCoUf8zKGw1g8DQlyPt7Ey/087HY/L6vm/Jfw
DZiTFB+dTCSiwiLhNViDEUo7C3jflMPl8hLGWynbOCEt4ERcjjQL4u6wSRCQtDYFmILFQTsj
uRGQhcwMGELzIm7nKyFFMIwl5lgqpt0O1aMIRNaN8GwgxPULy13I0/RRncfsdTde8ZmblFbl
Jo+9JrbiheLsSPEDt39XuLPzt70HO6Otq8V1KzXHuGBzdMGh/Lwsrkp0NLfXvhjUScWUTp0Y
Xr2zIdNH6V9fO3bdtvP6gitWk8ocwga1rCLkWRl+LbdheIAgbytO0O+I2qCfTvJylQMA+oXz
Q6eoujD7yRRYnAsIOQXjCAs01Ru5g2JKjHxkDbAazudDtkv4JmKQAV+Y1Ovrp+c8kqYlAYL2
7sCBgCgQcE8DHyXQeqVaTiJBBfzhZJzXv4v3QRIzQOI0w2k1ZQTAHwLeJgNzBza6kM9ZUlPg
iNSSGdJU2KZBAWrAWtgOwEetpuyGXy28AKiAbglcIHGcfucVb90qp1W3ZvhbP3j95E984f3J
p/PPr999aO+V0dDGVr+5bWBN70nKWyUX+2oSx1ujrW2h2OGDJ5597Y/Bt64uX77R717tkNGM
tXGrozeZAu0fKY6VudtOLfxv7FXPsbctn85ls5kcz7dP4x+hNOAC36bTOfIpA0FERtwvsycj
yjwu0auA6JD6eIsSXJeXyTlzOs1nMm3Z9nY+n8vtyX6aFWULePuFfP4A/wkv4uH4XFubVSMt
/LswFvyPwiBCmIGV8nBwPsQctvwDnRNFarf8J81AeCS9tPZh+XpSTpv+b0KCAA4RXJ94PEEV
/9Z5rPPYwsOdj6Osf3y0r3tv37e79wA/VMVu+oRoP6QmjopdRDXgCWZWC2UWZn488NOASCyr
ZnQyE1PDjMvENiI0BijUX0VF4uH6+li0ro4r4Lcnw+HYZfw2iuK/wvq8O2Wyc2LBLRJtnBgp
XXaXyOVCFuLK4CZgADeRAt9DOhCmVhuaE6YyHK6LRiP1HFcHiMbrC3jbZCQCeWobrzsYp+Jx
FcaVHkG5ngMekcdjvwTS5FEl0a6cq6wUfL0RaQkhdDrjNJ5AKso+RwgDcxvGaZpTLmmKxPeN
qn/hAySykqJTM4QOg2wTcIMQyDh3CSEBEIDEAEHjNpGgcfqrAvcIMxe+Ihng0cRPrKvzW+PM
Yr+3+N29l+/GW0+1bFh89uIQteSl7jGzWuP99dim4spVG7t3Pb25m/LSclW1Vt/+vsG+eGLX
9pGXfxnc/dair6/Lm6o0MX1zIPDE2i+Oj7YtyW/NDwjtcvZrohC+j+RIjd67iNjZz6dYEwca
vz+lVHEq4voqOKhm4EUhvLDVygI+NdUDdn4FfwS59xRgqsbnJpFRkpYJhbQSCikuTQkxeMek
QgEVdAevirJvsj9j32XpCEuxLIUqSTGVkGIqIcUUgyLB6M9qqQjzQCimRESRLYOCU5VqaVff
sjO8yXxmj+kpA1M0zTwYnGFLKRgeqJb6UknFZQRFoS8VVWbz/t7p9W8sgWj0qKsWu271nlj7
XudJ0llLeICbfwZuDgsDvUFz4h+jFpRBA9Qwzyw2KPWcIkO9ErhpuFGHlxCkDGaOvPMKh5vr
NMBa62Qsdi4DX513BbmbJmqAUFmi4AYK+E/n+3t4OOy5iu+gPnwaLcJ/Rv34NK9vb/e1VurC
tHW+PP0H66dWkdWq9FG+Ah7lpTEoKyhJ08kCvsvL1Op0uodAKL8MKCvxBjQA6nHBjfWQuxvo
yfb2ZtPzW3WVYXEVo3aoRWp1VZUbVcAmPBeL0Q1NBXyIDyaTDHQYuoEeQqMgbrT8mpWy+qw+
u5ti3D3uA+4zbppxX4P2Q25fZ+DcBapmPALpaqy0KSFvRbaUD+d2JnkhOtBDbYnAaGAqRA+D
5GMqHjGWNFGOa5Cc9U3wR2YezNyrZe7VClIhDyIX0mkkfk0pM5NlKXaroM4IjZKUnbAI1iPJ
zcKTLM1SrdTDisWk4DQ2UuRC+AVSfvzCtaRiJmhOIdZ1JFsTUgMzNnV2TX9+jAu2MUqJoa2Z
d1Zr/S+s7U3Fw6vqVDKPyWQL2gy7oqFI88J08bNQX4srHbb6VYqQItziSQU6HLZQuGJhvt3W
Y3n+L2OrVWGv3TjV6KBquPb+g83RlFMb8M5788XG4OjQUC43/3tL9/aOqJyWlh1ZBa9VfTHa
WR8IVqrps/U1CnW1XKFYZFIxMnWJe9foG8A9HUqgbqqV1+fIdPPWpfQ6HdZqKQJMpwZ3lCnY
MUfBVkLBVkJBLTnFqLkKEoHgvbvMw27Cw64M4WGG8DAPPEwDD7uAh0xzM4sxK5WyUal0BFg2
jUeRC1+F+mpJEL7pQdXdwDcT3EyG3FF3JpnNJsVixgEhDNUyjBP+De8ymjneOeS89k/2ywa2
ifOM4+97Z9/ZsWPfOfFXPn2E2EkO4mBfbAdwcyF82CRxAoQmZHh8bVBg65YoQxuTUIsKpe1G
W0qhqKydJq3bYNUKUSBka8YE5bMMyjQYUlXYtGqoagTrKKUqtve8Z5OEAAmkoeukxMr5Ht/z
ftz7/t/f8zzCGUGFhDKhQTgtXBXUQk6OJJaVeUpLxS761b0ejwTenZCBSZK1G4DcABpTciaA
rSepFxJO3aAIIiiCWHe/tGIeUA8RkxtkRNB8m5gULYFe+yIwyInEVRdRCoRVqwUrYZZiGcFV
7usPvi7Jb8kgdYP3HhKip5psUzYvyTTlNTzqzM52TvloxWW8KVwZmNr82o74O+2hnxa8G3qi
ojrX2C4ZNFrukXBs/N21Q2fleYs37PKKropgwLXVHXpuyblY04rHN8c/X7qIku2TTCvc876x
+tXoW03Tz+yOf3zo0Buq6kFiodE4tJU+zFIKp76FXz+AliZuyIai4gGoIjzqAB59E0LtPngC
XCK3HSUTyU83ZLOrvEV2T5FaZIdTammZvlAunigt7AZpNNKXZF14WS1nd0rLamum/4HejUL0
RZDLbrkoLOcWSWFZmy6Fw85HHCVl0p0Ue8FJDc2x7iTHOpbVTl/STW9E9SAgg6tYqpd1Nqm+
PtzUBBneBx3hcEEV0Za1ZII0LN9y+vj2faLL5Sm6VQLagGh48oY+dg2JMZFXhAi2KJJYMxzO
iD94XoMMv0J0c7EYyQtIbErRbdTQBl2wpFEySyRFLZE4yJRhST5BHx4p5E5ojTrr3zLzCnPs
XHqVnGHVGjwmk0mftticPgqk2+kw6thp47MNpnxjusA12TM5q9WuhdTRR6iXBdRrBCUT6jXj
ebI5BTz2UdzPvIFg20e+5+K5oGGi5XlEy1muIilCxBwhYo5EGppkIt4muTJAxDsVxFtJ794X
bCAabyAaD4HG84NyrlMKylq9FAwSCL6uxbc4+IKJuo2E3UkSdjTJgUai2OqUYquJYqurgzU1
oPEPZFswOBCMw7CvBVR5N/b1gc8zSIq34S+a5J8oxnpF7pYAB4ivTUFhW3TkKBxGctS7DwrF
m18MobWRkLF0CHEBJRNp9GH1RylKbpN1t9Mxla0tItESdLGIoIYoaSAWF/ZjsKcfgyhMX+pM
AvP3ICYZkNkJpZH9HjwcJqsbQMPFt2jID6BhfhNOAhGoLBs4KT+Mw+GvHoygOBHk2Hr/aKyZ
00wyd5K4g0jvVKhSJ40CHDMeGhytD5WNsSPDsDGRpmpkHCk2VsimO5LBwRmfQkWQ5dxhqNjT
T0UUBC0nwdhF8sFQyHHPfPA+KWgPBoXRxOAdIfluaeBdFZbMBr9GBIzVjy4BY81DSIhK5okp
Al4dzD85PwnAkVHrVi1aNUIOzRjEIe39cmhY7IwiWUYMji8PB9g9JTdKnf83hzn9Mgc3wx1c
2fIAx7ICm4c+lneewy994h78QI3gzCAKFgCp4QOMZRESeIEvhAtGKnTTQR+8KavRF8ihOoju
3zORQDPVa/BOZgZloa6hfvt9sP+NHqCnhzi7OcxvYTY3+ma3h+kC+7OHMzsYIwRjvMkWwxif
9o35IfM52J98TVZkD9tMWehw/4qw18E2DbDbwK5J2d8F+y9ghxRbVp6fBHu2YpeBfVpjBnvW
g7wd6TmxAe9EjbAu15Mjxa+k7P/8r9dpzHPMc8xzzHPMc8xzzHPMc7Q90Qlsw8fV+5EJ5aFZ
VQbEJ2KIo9ugHUt3IjvKoU8jC70KMfRLe1kWddFP7k1Ptx+gn0QZpCzphdoQ6pCaOc1vPZG1
IO6unFSGA0rhx5gLJFJ7KDWehSalSOoeH88S1VkV9rTCrJn+ijATkjwh8q/OrV5zKGfLpnU7
Ju9bNzEYXXjTDw883tmzoWI6CvM8TY1DOmTpQVp6F6KVSa1HiEygF4YdOMLper+vtq48EME/
89VH/PBP3vUI9HFK1QR9WFFxlRa62IW0yAxXI3Rmotfv1euZA8k+vUq37kEd8wMHORUJlNfO
9gci9f7y2hpfIEKfDUQiAX8kEtvaP+r/ixLGPMc8xzzv4YnRSlxI9ajakAUtlg37M3E+j418
Pf9Hnua76JP7HW4TNmk06VU6+iySocPVwJNnkAPx9Isond6+F9m0XfSWTo3GqMZqdxTwwp2J
Xc+y9yJbZVavx+2Own20FXATxcI4BZt+v8XiFQChrgyL1WKmeuJTphWIWq1T43fhZmuFuzG0
3ufBhTnj6iYsl6gCx5LplQIO1D3/o/0w40Q3LsSIKod3s70NqDurTArR5/aosZv7NMlM5W3j
3Xgm+HLJNpr7aKNBn3VrBrTh7tkm1teGQ1e6uWQbCjUk/s60qD9ELlSOuuSV89lm7QLjM64d
9A71Nt1243ndZS7twoRz7nPe89K/sPpX+Nfao96/0heK1dvwK+wrWvqx4sfEFWUrvCo7l26U
nLlGU76JMplU+ry8onI9XVqu0jrLtAaJd6LsbEFAHs5zzkN7uhIfy3lWm+SpQ81+t7/ST5Vk
gmksyS+5UEKX1Gke93HXe6NilLvWK8Imed281yvCO1RCQOBNFe4oeRsxCn8oijmWEhwuJ8/5
fYLHaiEfv8/vI1HP7/NZLRYSBgss2MFzVovX4/eVcy6n+ur2Y/GX4luOvfbnP+HAxtaJP5jr
m5pj16lVVtGmS5tf6puUaYt4N52MeePb1s7f8f6CSXsi1O54/HD85o3DOB2Xnni70OBzYkrD
2rWszl3sLHIbuVXyrHzzcTwrtj7+yzfaEz/5B35vnR9Wenbin6rfqMyw0hXok848DayWpitx
WTawGknPwYUjF9yVOCi3CAWSj53JruGeZlXPaZ7SP8UdYY85j4rHyo/6Narci7YrNsomg7tN
5s2SzZZmGj++1Glifc40nVXvdElWVZH8PPM7hlIuMnORoRi5WJQY0r1F8kmMzJskhnF9T8CC
wLnKXJQLHnXwFol8y3xgquRyTTF68j2URz5jwAb4tVNvkAyBydx1Mdob5b1ukWxMlK+AGzHa
2tZ7+waJYivZomgrPBWRiJUdMENCUqAcKj9E7rvtFFZylYJxkLZkJvdKtdVWJ631fXvt+ZNr
29p//M7TS3NmuDwuS7aW7JQ1jeyUJ3Y5gyvKKmnP0Bssq5fbM+m6WQ5z+7NHN/5i67On3tv8
8rTMGcUYa9IsaYy+lGyUgV8Vf/nn4aDD3NN24jsLX/zhImBLWeISs4dZiWaiY7LOWaYzSgbO
bCWbcrXDliVVdyUuycty/8t7tca2ddXxc86999i+flzbsR2/X9ePNE5y7fg6qds8TmiS0q0l
HS1uEXXddn2MjtKmQ6NM7bqto2ISQtU0NoqgCuMDEproaBm0FahlKqrUfaAUIfFlJAikSUhR
8yFQicUO/3Ov0xYUQJsElnz/5/oe33N+v9//dVJ6MJW35EcHRyfHa9bauOXL6qnc1fwti/hV
65kcOa1hFHQHjwWFeFIPptOepN6ZVruTupZWJ2PayIimBTtJ9rDd1t2liVNiQxSKIhOPiS+I
M+KsuCxaRC5B2FIRxU+ydXjduj1shhGmxBNxEh/xnNrII4NnrmnOfX2a90ejQ0OgiHseuMb1
eqmIptvMY86kx+gDOfG5igcIzlkqKb9qPuESGCHBH6iVVL+px4ogfvOv0teeUZ1J9dnnfvv2
npeOOOUNNfJz9WTYGQ2Mj+55f1tuQ++n8e/6Cw6rJOKKwxClLgdq1d1Sflf6iWbz/r4jtc9q
7NYPybeOZMMZnM2OxL7UfOqtibXd+Ws7fk/WvJ7uzPpoh0xJxtedy2uu6IFIfEMqAKqMQuTc
F26j9XiSxRypaIqk3HanXnJ7ffps7F6MLMdwhNlkvZvzNgKDtQyeBzKJiKqWM4m1qprNJLpV
1eHo9semOKPR6tpCN41E5eKBhD2Kyu4yKXcHtlZxlUfB49t0w/ZUTBsvGPaStWLcQp7iliVk
t16t2pjWr9sYzLGxQAwuzg7dZjumYIXP6QzFdEUZLnTvyWKW3Zo9lj2XXchKWf4eNqYbdt16
bl+4PFg177WSaZOqYZndH9KL8F+S/dSQ+2/1gvGBeOMhWOdhWCgYMQif40PN+pDhDuAQQxCF
08YscAMehLyqIYhV3I64f5I4b7iCP1V5xE/ylZTHjML2nX9A3OiwiaKYUeSgbN+u7ZIDU48d
93lY68wL39kyOlyAIT7V5Yts2mmMniC/BFEt1oDshajrM1WNx3Br8lAibMmcOl/qe/lN/Myh
WNiabb54LqacxIvmjYhw8zQ903rfkoKK9nnmUAQmNIQ5YUGQBE5PKq0bFhIZt0y12HQ+h8wI
WEDM5dYbaA4SL7M5dAXciH+v4XEolDfesXl0jAlUlUJzGmnThXpBO87Dpc5LZKfaPI17S5+x
pC4g/OF1eqb5orGHA0w297AgiKvuILXKDvDHWf/D67j3m+b6Szeku60dxvqPM5dC8Dk0g4iC
EoDsCgRERBGwIiRgV7PCPUFqCEeFi4IgME+nLlwj56H/GL9ETmDtz5AljCzNswNvbTrUpRu4
9zCs0voxzGou0TPL2411DgHXhJEGmSMLRCJtpKSNlDzgGuaQGYLJQ66VNlzEG7UrePxnAgOk
gvAAaWH6EaSCpA6+1WrVCgCUI70Dar9i7OBJYNrYwQIRV10/tcr6+KOtjmH11iut79a+biwP
DMxId5erK0yjVZgmWCEJ2NUsuUekBjlKLhKBcKbJQ6aFB0w3TaYFrHbcav2i9gVONJ5CuBWW
3luesyRRDDxKJZLs9Qry/rkgDgb/VcuLwnXQ8go5/xOn0/20nyP32ey63299ek90IUqiUfHC
HfA1CHOoxPAtzFc1NAqLQ3GYh/D3VKvAM6UWFUK+oqtpqKoQ72qat7W8APt9z29LSwO24Z79
alEd7io9v/fUcC/dUsoVasM9XY/5bFZVVhPhNYP5WKbMWXoH/GQNsJRAP2DxSYJtwep63RYc
GdVtxEkDgQijDTpHF6hI28oZNhwzm48iSDhDMXUWI1w2JYIbkbkIiXDhIh5P0Yd9J1hwK+9v
QlFobewGaFdEt5+IM5dHj8cps0R1Wpa0+QIHzC/T89OAm9fCwrx2nOvLsXurVciIpSLh6c1g
YMDsLCwmBwYFMLrft0Fxir3EK+zAwu7egBVHS2OHprYfptfsioPaO+ykV+mBrCf5qT8dSmUi
HuBBk95r/fX/qCL+jyq23vgoMuKl1yHWZEPF77Pov1NxgQqrati3iob4f6kg+i8KNv/yMSRc
Xm5ukJaWb1t8OCA+d7yEnJcQplchktegAqwJLAWBpZ3AUgh9hblk2VdbyYpmVoIG/NHsxAaA
lwdZqZPWXKy7V3cZFLlwwzXnIi5Okssryp3lIB9C6162a4bkILKJvzA/1E5S8DvXnddjA7Q6
0G6ay/0Dg+VAi/UfnHxqcyLptbp7xX0bswlvfWswlHX2YHpzrJB0W0s7JixiOhYqDXM0v4G8
s5P+CQXRN67DudCD3DiBbIIfOQUPiwVeVShWaAJ0n6X3qNSgR+HsIFCe3yg4L1PQu2IPZuC5
mHlD5klFKVagkDl7XD9ysL6K7uBsBEOGZU5vh+5gcGZwMEvFYTYozcV+PlhcKUaLS81FSFBl
0BBgAkoAmXsI8g8VfHLn2K9S8S7rOvF0Pe6Ljh/qCXTRP/pcXzy7u0t/6TVqTWoZyKn3pZuo
SWvIjS799KzlrJNY4HD1dwaMK1JDmpUEiVkrkuHEYd2wsYxpdd2wl6rGYxYeqUjX5V/Ls7Ig
jyE8hclRjBU8hwkHfFnpMIDztxg2ljZtJmvakRGTGPvYJ3TsKiuK4eZlbR61OzSOenplPFQq
dq5F016ucL7cbsQHy3T3/ic3bbYXYurIrs8Nr/H2ydLNQs/6tKMzoCTXQwMhSO+iFt2OKHqN
uUSqoAaahbIFEFF7c9yyjlhWh5/pFCVHubZzcApsg6DteYaFE40R11FAQaEvERGionABHPkD
MSldYJR+kBRDWrgZ1MLz4ZDbsB4zQDUTGMAa0syw5Xp2qnmLWr/2veLd2xrd/ur4OPhf62Br
y/Ll5W8jO3qWdXBPI+BxGuSRTW70Ni+ysJXRUWPrvCc2bLHftL19plVzpg0lTIheaATAl93C
HUFAAk5CGr2KO5BNm4cdrXBeOM7vSkVLf9vPIG8sTu7dNzGxd+/BvZNwnZjYB29Bb2C3cEHa
jFKoD/Wji0y296U7xUyPlivyxfLQThSLTptstcpyT87pTKT8OJwjIWaHFi/UCJFQKJnJGRm+
w8jwKTGZjIRCXZ5IT1Duu4LfZIrY/w/mqz62qeuK3/s+7Dh27GfH8UccYztx7MSO7QQ/xyQk
zXVsJzQJhLAVGK1LOqBE00QSSkFtB0RMtPSfFW1jq9pqy9Y/si8N04TUodLoAG39kFaGpn2o
VZm0bGJrjDqBKtZge+c+P0LbhADVqBZF7917fN495577O+een4qBf9bFcWIoVHcK/xjp6ZkI
oh6qQDgE/XqbORwKhYRcW9usFGV6G9ASAeOUvy3XBkJAVBvIDS16qXYYzPSGCFfUFJt4vtjE
R8QozaVITSTskbgdK9WRimJLj6GdZ+MDA7w6lp/buOXAmtVHOu7f1POvf2JOvwZXnxV7W6qE
hFDVHs2bWSV3vjX3mx6hgTM379w5suXwxYd8A79s9al99nxy25bm0T+0lA3m/9TaClFcUzjL
T/NDyIxsKIEfJlXD3gn/RMOMZcbGe0JzCWZvAr+bwIkSoUKsyxSuEa/OIHIhY4ixWazW45U2
Y2Wlrd+z1TPsOejhgIq4Q/bpqqr61gzeRlTkUMS9Q1eP6zP4ACmPlFkryyw2XqES8Yx2Bimx
8jV8AEzrmDOvVIimDPMzYjTzFltT1G53eaaRV/Ay73ixN4P9U8Tpwq4MvjYtBMLOOI7DkAgC
imJntDFKoiPRsSgfPYVfR030QIHtjTUdbUo3sU3bu8yVVhabYhpsR1owaoeOs4Q+8TakhRNN
Ch9lZ4VZYQ4OhlK27Giqd2BzeqzyK9nRq70bNqdJpa04q8yNprLyXYc6rmbnhFwqO5trowyu
A4ZClv6aDVMgpJ7hg/5n9p/DKZnHjaZSWCJoYeBttHZIrA3O2FvrwjWYjUj9giSQ+wSlxPbk
m1OuslDCX1Jqkivyna51GlW5Wl8VNuAm9ufX259lzz2y0RLsWNnXWr9l8sHV0UeefnDwpXMB
V4XJ5erw1DXzQ7mzccMKp7OqohPv7NAojY4nPk7xL8//1mas8Ij1Lf3aqcZA+5fEjsd39a3f
bPWoTCZvi38cUGKRUcKiBtSDXzvZWmKxibFM4dLkCqcYzxR+N1nVIHbKb5i/MWk00/kbJAAD
FNjbMNP46zg3rJsonzDOoBl2KvZmp9Jjnmv4MMC+GXq3gWmgABMWAGY2mhkWTgiadiPDsP3a
rdph7UEtp9XaNWZ+muP01RLA6g7ZNTt0eqynAFPZyzBThli+JcMaJletag5lWPt0kPSs72F6
MmzFyePx03EmnmEem0RBHKSfmJp7V/OItTp4XqWdRjpBx7yjw7oi4FRYJQGuIuz0Y78MOAd2
OhodxDHiGHPwDgo4KwDOTgFnPWpNW1nr9j7MdLTEQ4Hw/Wd0PbgnHD4FSOvAflK66kxL4/EQ
DkV7AWhXs7ns1dHsrL6F4ulukJfNpXKp2ZRAJbN3BL4U7VXoH74rqLmW0FQoaUcDNx/vvgPQ
Xb+c1/9+dX1CfKDJR85sT5Bw/MTz3R6DggnyQ3eCPvw9w58fjvWEkxvK3mppXtPVO3hMX6Nm
6R3VzzkKl/hd94ADWigH5HcVOWDuW2DHe0/s/OVTdjJgp/+GHd0Sdj7DVYaBrbAstcPetIMX
7GSLdrCrvCaXwYGvPUAN0d7yPOfI77wndq6f/4SdvAn28x6/5wtjXeyyrOvQEqSL+9EtSBec
RgCidOUL9P42nPHYXbhfKMx/wF/P7wa2ZOaeLFSiRXwJNF4GDV9RI39hSY1nQUOQNTJLaVz/
O9dZ+Dq/hWogY37fDY0Xbmo8ynXms0WNwrElNZygMSFr9C+pkcmvzfOFFxgztz+/AVFJT35t
7vtFSW72FpLdIDktf6Whkvn3QFIv6+xF9Iwz/IVCP3DGe5VxSlcxE/bxF5Bww87/rIKUQwUR
aAWhZnB/oZA7wnUinXwery4Vy/mPIQbdcgy+S6OS2wvRPVuUFARJ8jb0/hZZsoNK8htA8kOQ
mLj9czS2+2GVt+TYmqVvfgGr/Ef+pkuSPASSn8o6H0knchkkq2XJEUlyDSRJWfJtSfIDWPkD
WbKKntH1kOKb+WGInRXtI7rS0vNGbNxIIFQfQoQou1CWiNLbVS29yUq9QdQxwIfGGcyYLwJl
2aglWkHUafFWLdYSlUbUGrhSc9hChxZLaVgdknISshBICFyU2dG20G56X6ayo+EQzUzaoNNu
HBL05v0YDZvym1Y+2jXU53AaSoQA99XuWochtd5irS1rwIpzMb9TKGnalFRy1XZrU7uEdcio
CTkr+xdnFMLzb8Nu1f+nu81duavdzr8Ku71Prh//WGq3yIcQU8NOIAG9SEwXDX81MDoeKZDg
4AWFICjUbocigy9PVWO3g6eDGo3bIcCAVNUgQaHgS5EOOzCDfZpB9YiaSavxc2qspvFxVov0
TdTl0H+qBTWjfspA51BYRYdh0JA2sCFDh+E5A6tf97rFL0AgoAGjydWWS7Uh2lTRbqmYz3oj
8LRiL6QXPd4IfiUYzyvvW2EMdrITOdu2KOd2M9XmbUw1DGsLBSTk1/JpfojxIDdsU8ntZ58H
LBtPMkeD40E4t3NTwbrSCoL9qQhoQ6aw77NnQTtR1GaggiED0TC6LkcXg7pIdOUNXchQPq10
Lqy8h1OArnqaQfV1OgG0IoiuWLjCvs/vWVjxMOsELR+pYlBMiEmPkdhYbDyWjilQjNjchMEx
uU6AodGbllxFS8jLfYP5t7TWKJeGefAEG6DxFCqroL8P1HoIM+5P+xk/FaqMFhH5vZI//tGI
3x+54ZO0XoKuh/6IfiKt9xh7DebrTrDd9FOD1SaS7qPd490s6u4mhDBEOk63SN+ktNwkIiKA
1JEpzE0N+Rl83ynqN246LLkOtuCxnP+7uD6Y+0k5GyQVVhEFg57bOI+W8X6Eg/qH+qZZXdKR
ZJIS5FR6ESWTn893/+7lfH+cgyqJWk+wCbqgVVUmjiUwSWB4okTv8ocA0P7EOTgX7WQvB1ZR
O1GxaPNgvP3zOC9F6la+P8H/Cua1RMuiaGJ5V29GXPG3RX4+yV6C+XqiYQ8OYDSQvI2rRDfk
ZwdIIiGeHsADn/I6BAGRPS9GnWat4suLPC9mb/AkezQyHqHZSzSREKTvcsFeyGv+O4t2UMxv
NwEWs7YbUpvBclC9nwnqkjh+aiEPX4R5iJhYIdoYZYajB6MMikZ9ImHSPuyTvNICEn1i0asU
hcCSWP4v7dUb29R1xe+97zmQ/06IA4SAHSdx/K84Mc/G5vk9X0hojRuHgFiHUDKQ+mFaS3FA
tFo7TY0mTdombSBNmir2ATZ1a/kyCDDBpm3Nt23VJJDGxCZVDUPdJk2CRJpUpG4jO/fc+57t
/CuRBjL3+jn33fM75/7O75z7F3JdZeKnqBJerXXMP8bI2NiILYQBwP3jRgHA7a0BN7kWulM6
dA5k8IY2m6VZgaVFYMlm14KnorYKuindB8/PzWij4t3m+gaDjI6uCXBlPn6tJpfyvE27U6Ln
S5dKbLp0tTRb0koIt6HZIKUvrA339JmqeAaWIX5DW3DO+cSX10S6ViRl3sRntL0urr1jsV1r
4EqtkD0OJpk9iOno6H7r8zBhRry0DJPMiDhkRP5SHjOiIZ8VGbEq8yr58OoyTDIfkHdH/EcY
OTKGSbEm7yJPSvpnnlHYK6wQTWEdpMRMbel06uBBsDiJlbWgLP1KVctoX1OTsypCiP4Znp/c
6yzGSOyVTvXE3b0WP9EmsaYWVE3thFW91xjtv8UuXIuwfuF4Ezh+tZ+S/j4vETUb3o25Nuo+
cmyQe/Sb9BukkzdQkt8ljNC86owoRl5am3CskXvkB3BZgPWM7AzC1ozudOt1yvWhR+6P2vVz
pRJn4XnfDNuDpUlU6z17krs4zYjnQBOwKRPIDGbGMycyHm9mIcOmM+cz9zMayRg9UeGBKBux
Cia0UVB6dkHpxj/heWRGQymMQQUvxyiJxfqgrVgIUR4aD02Hzod0HroTuh9aCOkkFNy0CVwI
VrUcZ5y6vZonp/SU9ATlpLERkGfNzP/Xkym9Hp75jBYRe4YbgcSRyHrdWNOL17H7eH6GHcJs
hgp+XlSxL67/SCarPAks8+QN7T+obs9p5dxUbjqnkdzIQM86z6MqO5Z78qbnq9gvNLGA6D4O
VTyof1oPKnmFSlXrwVvaXXgu8ayWEtX7XOpKipGUN1VOzaZ0koqs25szKtuFcmCVr/VHKkiW
1zOyLyckZH3HUdEbrPi1vkjd2c1DGhmKgfCsC7hzCuwRnnNcahR7X2lUKtfY5WgU3qdQo/4k
NYoJpQ3PUJ9okCAxfahRokH1dTSBQFGfa0vx9kmJPUJdjSvk08pOpLdhm2sHVvV6TsKqUbWq
XelqKLC52Vk1DtVjAfU+KVdhhylWhYMbNjirihCzm6jRh9Vej9SqWP/Gje5ei3/1LKD/SXXv
6VOreoKEuHsBl26i/4er7j1+0OiQ1OgQFidvh0FC/fiao89y/x65v2CFeBP1cw6egzPagHhz
k9DPgQF/gLOEEPmeRg0vZjJ2aB33OKxO/z2lj49FteTbNW/8SpzxeDk+H9dIPN7fD6fdTzaK
xq+3chDy/rUaolP6JXjeCn0LD1ESCvcDGAeJk1OrIZnSO7H6d2o8ejEKVTC6GoS1ELyu/1LG
xMaYiFuITYk94q9BcqYqJoFlSORtQyCZsq5ajFj7w8H1I3nTIzosP9+seYcGh/jQ1JBOhmz/
ahFBlanFIfshDjqZSL+dZiTtTY+ny+mL6SvpOpKOVkBpabxDpGm6Ak9eIEBZUg7bUVdqMUrW
+8S9JxEB2ldBq/AfNaMWmcyDHXDOJBmHRFgpOCo2dcc2bGMh/RXsFL5Lf09/RLp4MyNZCh23
kBuacZuL0+pU9Muet+CdV+U75Hdgq5u3wkF4xWlY7e3wVs61dHolS8MVS7spXD3QUta1NLmS
pWFyWZzYDDNRiUQVN000ZlW5RVxrAccaZPxOlfHFw5XeTe5/1tm/KuNtmfG2m/G2cKom4+uO
iY5MeXOP/kF2ZIwMS1eGazoyaWnC9eQeueF0ZC9ID16o6ciAD3XHPH9z8VfUL5/V9Sr10y/r
Phd/Rf2GrYYGZ9UgcOtdVOWMqlV3lSpnktCeqFV52GtIew9WHVWrAmpVPOTb7u61eN/zLmZk
RnW7f1erhl+M+t29wNshVNKjKq6iou28RukAxpUKPbze4jVQF1vaO4zBAT7AyECoYwfscRrD
LK3VzSBnTip2fgc4E+QdtFykHxTniotFjRSLbRAQeqBCHeSbwPAYufOaYqnI9p28BXpmb34w
fyKvj+dpHokEtY3k83AtotSuEg/MzKUYhuk5wBDnTTRRoOcLlwrzBa3g0rFQ2AFVnRZdMKug
Gcacid+gJyxqiWD4thiWW14tC7Hkq8prFZaAgwVYfVZF/8WisFuJ/mNk9WtLos9l9LmKPnej
z0X0OUZgSfSR4ycVx7/t3DqOFDDmR2o4Lu1OuD7eI3PAcchwunCAkgNWf1Ye04WqDAdugo2v
uB5VuDlebGys5uZj7UPXowo39+fjSWdVu7hvIs9zatWHatXuoU63Y2h78rz2EHk+UZNZlGez
XW4vBB2J5yryPKd4/onD82I3qdkLeT6hIl0nlBAibUCkeXOEDo7wEUZGRj0+LPUYV9wbb3M5
FddvOXE1E2JzatbEVVqZcKxAXH8qtYMSa0hsXKV+Yr0XscdgfR+un6M/pO+g0nLRdsRavaIc
1CrtxOK/tI+xjozId8j7UmklKQNBIOXwtr4VlFb2ljGn54M3TWmNTgUoCYREf0kDNRVkEaom
ewWtiU6zjsz9kZDoDG1DXrYZYr5W32TcWvz3zbbN2Gm2Lek0ZU2POR0d+PhbsIp66he9GaP+
pfpbqZOI8mfgH8YkSEkwjK8El3ATtS7maB3YuKw8O5igJJESekcTtbVRKt/3HeUDOx/jvZP2
Ct+SKQPn7h45Q+qJmbc3ew1vLyXiE2kV/lbKNNw8lM8ST4+Dx9PEHsDeXl6vMUiEXVJ+Uy6K
um6JArqC75EHi78BNH8mD2ia3OEvaTa3bcPmiSEYQnEYAn0whKOGPb11O3zzbYZvLS0wNDXB
UF9vzNuLNmu1j9sX7Tlbv2hfsRdszW8n7IN22dZtylhKcL49onntQXvW1qBkJuMQ1aTwtHTI
wHkwJebp69GofA5E5AyRSGIkQJYGkxQ+RHziIhh4R8J/KWgMIYcSk+4vq8Wm+XNi82OWxtjs
VrHZDPXhUxomj/ghzeL2XsPiiV0w+OMwhGOGNb1jBwzd3TBs7YLf2kCvRYAsESBrur7BmLcW
LZawDlpszqJiLluapcJyMwIRf/llQ/QT1/N5OccTcg5EccYy1GXbzyBocl4WuBUj11IduUJ6
WeRuL2PVHLAqR+4Cq0xuDxsmTwzCEIjDAIQyRdBMETSTd3TCNwiaKYJmIqtMmjAPmsfNi+ac
6XkbJ81vit/Kpm46rPIBq8yr5qypcRNUcu8ziNHkUzKrtYZZiadg1jC5TcO0/pkxKyeYlRPO
jo7JeV9Bzrm8nLN75AyMw7k7ijM0G51GVy73rBi3CukI0RbrPT8hjzf0EI20km3kwkzz1l/r
hGwgm3SNUJ3yUcYZz5gG4+EkDN1+g003NBl+do5dYR+w2wzOwc8S8HibzbG6fWUQfPh9js0z
XfzlOCvD3+ZZ3UZGGm7phDfz43pZZ3M61Wep9xdgrDPxMNf10eTproe5r5PEli8BSvgvEJKu
Ld7Sw3zuv/+jvPxi4jjuOL4zs7t33B92726PuwPv7e3dLVxY8J7v9sDH3zUO2IFgQyjYZ3I+
I2pE5Ao4l0btg2MkPzh9sZWnKA+V0z7UquTIjh3X54fWW4lSRRYyD7HSyHXxg+UkaohdyXKq
thydWcDGcVK1Wpjf3MxvgfnM9/uboW1H0idnZI/AxqK1Gb0pnapitvS/KXvB1/gKnSLf5d+n
YjGd9NhfzpU/i+/YYU3EUqkYji+u+W9XKeAN6aC0tmY4cAfZwy/p7hD+Wy8bNl+JRkYfRHOI
QEAEAiIQkAUBnUUX0Q10CzEckpCGO8uI6ZpGQMKjy+ghosl4AU3jxIeItSNE4U27ik9WCsES
DS8DA5BdrMFnbAQkwSVgAvokvteeA7fAMmAA4C1mri3MNpGtE/NkNYwKEE6rdxdV6oRW+Ba/
xc626n4CkJzYPlusGXwPxIWFgRTwv0jRJn/wwYsYn1Fk8T0qDCo/5LdZyBxVBFmOgXMU+n+h
XdzAxnwLm50JMgkGMQyANMZmONbfRAiy5KMblwEqQqEAluw60Li3SgdEufE6LFqfX5+BcxBS
kIeXoAmXILMb+twbZG3TNrhsAzbTR8iGNsny8xZEgnbRau9isv0r/N38isebbdfymPVW1EF+
vnoxuwkbg65LB5p938P6r29f+HnPb94ufDftgYH/xttpqfbT61QlFmyFL6S7AW640to/PsLC
rVgXLrKE+5qLm+PIHnBkDziyB5y1B9xZ7iJ3g7vFMRwncRruLHN4Dzgg4dFl7iFHk/ECN40T
H3J4B7hKA6u2knMR3sKMe879vvuSe8nN7HcX3NDt5tkNmtQ0BZcpQH2HTvP/k0K3UKrDDNFW
m2/iOj+wcP+NTWLMPzdYjWCZPnU5vsBRFH2beRXfvd82tr8Lgb0mUUFV89Wwupr1OSPBiFeM
xABgE1ExBnmf6LXb7ZSzOgpEYlJDdnE6RdXa+Kgz6otyTskJnR3bqCDAXwNBEDyh8E/wOsyV
/BOTf2B60pqKNYOloVGdq2bnykpK4+/z9++Tkby5auLl5UGstq42JntkPy5lgap02i9n0qnm
pownlkl7dDwXy8j0beWlmab3y1+BRPnP26Sx2Gp7bUGqnp8PhV9X6QvoL5/L/Oq/e8vJiVhC
UepjPwRLveDMETmhkFVHcYF7C52nJOratQcQsMFShX/jv0wSDa7Cqfv9DB+Khx1CnLPc0oHL
DwBMjyiFWTcvcQ673YGVQAGOwovBZXJYZitjnENyQEe9EAjzQT72SACaYApLAhLIj29u0a2I
77EkXhXjurAvwj/BO5ovfm3y5jy/mv/K5Mv54sozRJgZ//iPvMVIVZ9Bwhw8aX/MI1QFMKGm
DUAZDKguI6O3lMBA8friotZddhlV3jNnvFUGaoJXZrrLfxoq3+xpgYpCx2p6gDa09HJ1hLG4
SOVZ28fM69Qs+MyI1rP1IqxnFbG+TvnRoQ6mo60t0agKjY2qGA4bSp0eLqEWwxdVhGhUGRoe
TkxMChMTkyzDkDXieYbM52emhJmZqcaJo0Mdw22TKns0cWxfVBFnpljWMdsf6YrsITLz7duV
CJ11XHTccCCHY49vLHV0e2r7oSx6pUfcA8OMLzIreATRB4DPrgYDIV1NbAvrjaW1ewbPe3W6
saTCxrYOlQ4mJ0trXxg/xSkTETzjnLg2CScmh4fohnFaERQ4r3yiwGhYEemuiHOqZgrenLoz
BWeYKZZ2zu4fB+Pjhw8vvQneBKIhzS7PwtnZ4B5OkAQoRLuCHc6KvZSH90BPtF9yLmO1O5NJ
IwmTyUxmKQIikZ/wC1oxpaW1fEorLj3Om32DBy/NVef4VfNJnugf23yhmCYJHm8gW9zS5lV1
I6hUZ1rjVxZ5E2vCJCow02nN1EwigeLSqokdY5kmkPVks7jFWaeZ7apaeYKfP125PaiSyOD4
3AjRDbVhL4CbOmIvbDCsHsterI21AatvPSSjNha1rZeWZlxbSDbOtzyYkf043+9pan76kAQ/
qUTrr+GH5Fuv2D6O1+Xy58v/ivKhXYxTE8dX+85IntaQN1z+e/lQcTCbHdnWfbyllmnY3d/A
OI639xptB387GK+Lq5nTqjIFrxZj6qFQU1yS5Orte42xQ62dr7T/uIJpfHV3va2u5USLcHi2
QazvL8/ePDwOq3q4ICr39nqVal5RMuJr4HfAz7Wt3lFOHi/+SjmoyEfd737ZdaqvfUTf8eve
986qTeAXb8iiooCayLHyOGIr040/O9V+LNWQ1A+2957q+vId30QkMSReuD0QihOvuNYczB/Q
NaoAT149YHdzegQfLldwxBXkCxIREWcDL+j+CG5sNfbRQE1wNI5Uv45a/X1oP20IL/tdpUOf
Mp/7v/HTB3OltUdGEIphiUdpXe+Ro4IsR/2CwIdlUjDuXXG6cERZwyfWCKJY09Pd3TMyLIyM
DNPI+m0VOAGRbESy3hvNCaOjuW69Jz0iD0ftQ12RA+Qi33kAtB4ABw501YijOZot7IrvjLfa
4p64q7nL29WznwVJFrBsq2u/luhMwMQQFefjMJ6I79Vs7S1SK+tHrkDB4ZZcALgc3DA3Ig1L
I+qwOsKODPd007ZBSsYlNs3LfFSRlWgmapejaZ2upUVBhJ+IQCytLRlZJ6fX+EWB9gScuZoc
vJMDOR5jyyXxIkZRjqZthenBk4NwcPBe36M+2NfHjUljy2NorATsRhZIhlY4V4CFgqct4kxi
J8ZsrZqr0wVdsZ2e+opdmu2cDdpsR2pnamFt7VIDaGjgAiBwhF/A/iyuG3TTnasmdir/eNOg
D/JpK4MYTFXX3UkCNqflUMueq+Zz7sybWt462PLFD1m4+wcHP2KT+MSg1NzK+ufrVNfavcvr
Q/hF/v7KUwuHyPXUJP110z7v40priHneyIGdgZ3/Ib3cYpy4zjg+Z26+rT3jXXtt79oej+2x
Z33Z9WXGlxl7ZmzHNjEGFkhTUlhAoUQhqRrtCoFEIARESChIKG+ojVQeKlWkikCtFIhUCVI1
6UMf0oeqqFWkvESNckFErbq8sKbnjM2y3CtVOjNn5vibM7Lm//2+/weG7iBNxRI8gbL5XiGI
WohhIk+MMnmYx8mhRxjlMSwVoyz2Fob5C9PXci9/J4fJ66M+TngH//50WhAag6A+6RaCnw6u
pLxu7/F4OvF8KSPGAqTth3J4ald3ixTlUxPZ7S+BL1te115xPNM81tkNSb0bAL84ky7u2JA6
5GU96eVlcLYMBn9rZa0w58RQG/6jwaLgdqaA5dmg31l/9y3jjZl4ufOjdnbP4VDr1jES1ith
uv/dhvjRj7e3ZWHmZPnMuyWn8oP/pJwMjjIyNdhPfQCrVwcUDEdFX6fjKSusAPUrd5YNJ+uX
krXr1a+qt6qkduXOe7/j4hKcr/1WkOF0yXhPlJOiKCqqR1FUksCJcXhkWw1Pq9VIiqpCVrRo
q0ES1g4f8UambRFPhImKF61XrbjVOs1gEpAqUiVLhKZC0zgABNNxsiHGuk15WbmgEIoqJsnS
WCPYqDX6jf2tEy26RTRI0tYplfJ5EOp01gWdUds0A1OesXE23KZhHgDHvAd4jnRNE7WCJHqN
XUYivYEqiKlFt6nHFaTFwhwSI9QiUi4sFDfWlomhuNILa6WFrCQqCrDgwLKA86tFoXhXRyO3
5Y1FIepNkYw/ifSTReqDeH/w/uDrDBN+Nhd/ZUVbjM/4I/tC+B98e545NLFxJt4KIHy/UNP7
tSUbmdrciDLx4r6K/ac/C+/QBvvBGdy6hQkSA/lFzicIeDj6E+L0UiIvCL29g1cJu5QFdA1i
OS9tq/VONL95PbFzbmqr65NluYw00L1jJ49BKuvgnHHRIiSFskDwbKsjJcpyGbdTSbVTPlAk
MYql5uhKfV39IHVK/ahi5WOxTlH2FIsyTSlUj8KpnXXVU6+rxQIfk4lCuGKSswIqlbBap/VQ
fDzusyJmhhEwado3hs2ys/gsVmALeGG2kLAEJjkfDR3jmI5QaZeLMZ7McSpwqNPq6+pplTxR
/4X6G/X36ufqd+q/6pY6Inh0mpPqlEqTVj1nTAakHFSulMulUoC7pN/U7+iEjtzVhF9C82W7
W9L1ht+ODOq0wyXZY1bfWMwNhcdBXaa+d4Nr7r9AtzJyn+6R+3SP3Kd7ozFyn0hct6G40qZH
Ty+aAhsaEvjrElTZgyJbuKcyNOC1SbJF8xn2mkmyhQfcx+JSGlukhgYEGlffWpndh6K7ErM8
wk2QxxKOhefeGnxT2z6IN32sa7INPtfGHa/OicnZGf2VjRWdj5cXcQBrjkBPp1/Kpja80F2/
fNhQwJ8Gt8/REDipcA8XN3MFKLDsVP+fCX7fG8VNM7PrK0lx/+ZTLzrLSU+UO3x2iTa5gmEm
V3rgpMHixnRIqrTWtfBZBJfGKlyM6/Wv6rfqZHMEl+YQLk0El7+KMg6odCYjarpH0/Q2oHAw
DnCQ7bY93W6bNFi3xJAciUMksFiCRSUrmM7oGllrxqgc45Mo0eGUum0KJ229aGQyErRDDLEx
8aLtKqSFLchiUJu1Si1PhKdDQRywPZc7xFoFShRxAz6K47KGZh2dtmkvaxc0QtMzaVIZawfb
YrfW7rf3d090LV3QJuw9RZHlXq8fckXtQTbqjQ77Gg3zAjjmvcB7ZP1DULqPSVA7sF2B3cpI
N49FEwqEE6qcZvlMm5h623VkVTkYXF+LqjTPE7DveRqs3EX3/8KrgfJlj2MnOw/Ralux5/c9
GVfgwk1wUHaOP4ZWJHh7cNoVegqxMIw8DonVxJPGDouYFMsiETeJpQA7SGod5UDpQJ3CAAsg
sYx1xkFwSvtIteIUxE48keiUKp5SqaIBWgE9KKmdhuYxDE3nAW+EIxJvMF6J5wNhEuV+ICKh
2dgDF0nSTsciM2GcAnRJjsTiiQolh1WTcypQ1bBm0M1HcS7P5vE8JrMyLuflmRHnxpom5SJU
J5bDwfc4wNF7erwg4QYzAeWXlSrgW6jRAnx1KQJPlVIiThY30a/RrxlHDdJG24yYUYW31CHj
58b7xofGn+mv6W8NCx1hPJKBurpwiJMMoNEUTlubRcTHIuJjsZjNXmqC5oiMzREZm81n/g8y
th5DxjVgHJERzktI7OnFpYf0/hRKmvfDw2/uam7zUAawFrJWWwWoKX85+XiAykXv0xh6fHDu
cs/7AEFzfG9GeDxC+yBz8k700QSlb34m7H0CQ9OD/bSH6kOG9ozwO9AgAbJHgVBPcebyrrnZ
cCTkj0ZFY9yhi+iLucpBHRNZ8bxIzEZC4hX875ejzUhIiUZN+U7AONKAMYiZF0liLBIiYcyH
UR/awbe6g4/1nfcRTCTkQzvEuEgoGY1V7+5QNXeoctWLVSIfCVVhjPF8LDcnOl2Mi3PpLsLl
U6pVUUzipN/vs+axMRa2F1qTaQE4drVA6wjW393Hjf58/3z/Up/szzIMx+CMxmFhAMd8GISP
rK8f8Kc3wu5icam2YWWhtoFdWFy+e4PpNbaGDrY2Xl2aq63U0ghy6eF5zSXBUjUYBMcNDEYX
5vI507PF5KJZMWU3j2AIcYh4iNZMVawiESoDRty/gtZGz9AeoT8480VGEaYYx4AnbZloJbui
ZveFHYQ9xStZ/JPsPs4BviDsaV7J4H8cRhK2TKySQa5N8DJ8YC/41WDH5vFiwCMI7akfE4e3
uKXABLwO7B28Cd7cypp3ZuTtE1tZGIe00YGe7Tni11gJu26oOSuflfKw2RTiU3GuEHfEXfFA
3JPoOJ2cJ8PPhbksB10V7SlZxr2cx57dRf+Svkp/RpP0FfwfRlJkHcCRKswBrhS7VABMYVNh
V+Fo4WyBmi/AvgCmemFjJTKBYsMC+sy4KxXgPDEjMP9fzss+to2zjuP33Itfcj7f5XzO+e18
Pr/bl7tLHdtxrq590KRvS1/Quq0ZdSuNdn3RoE1U1nVbpapjShlFm1apowNtrAN1FUF07dQ6
2WAdoIqXoiHQNAETrQSCIpGqQGhBKA7Pc06a9EX8wVl+fs89iWz5fr/P9/f9BfcGDwXJrUHw
fvCXQTyIlAD+e3BdH4S/MToCRQBqAWx2LXV0pNGaat82fmwD33ZGF9EOQYxYRx0OLkt6MLVt
eRKlhTyhJBXuJlcpzd3F23khN6Y8W9ee2Fbl6da0x1eFsHZ1sl0D4JMqzwAPzS8Dv9vF+Qdu
ftU0UiAdWAWCresrw92pVDa6Cq8NSVlIZzo0eOvWygDcPjvz3aFwCp+dxXjoaM5QQ3gXVsVQ
BnytNcR1mIEsIKzhYDC2Pg3S6biirKBIgVJiFBlTWEVWcGUL7xN43reH2sPjq6nT1ARF+GJx
UuEppwdLh0Q5E3DAPuBADcMbU8Q0WSbxI+Ql8mOSgOTesFgo13EySw37dvkO+Ahfc/Zf531i
0SfyHU1w/QJLydB65z1wb9E8L17N3sji2Xy+OXvoLFOywXa7vcVYviePi9ArqNylESi9f51p
XIePXUVai/wqXLH6H6egBNsZQZ4EiirX9qOuAKdSaPopBKA49xpvO/DlGze9E7fcTBFTh6HM
IqEk7AzM6yuBzAZKDEyTIPp8ZZipkkJcX5b1KJfZrqGWsxYVfqUrgW7wN50PxL/1vPo4KBCH
XZZv+8x467WHIxkqmcTj4ufAQ/imw8mQO5XqFKXMtpYfvPtcaYBMwSzMZQUrgWcmMG322jlB
qXejhzbJ9Mt6d6xbyWuqTgmKEA9quw3yBePb5EntPNlUzmtN40zfnzV3f3xFt9W3I7ute3/3
k9qBHleKSJJJI92bLpaxAlEuufyaquztI9yRrOxgZVnGZVmISTEXVSIxqRSOSb6huJoBGS0r
ZTpiEj+U4GAxKCkpzcER1+iViprO6kDXYooQ042YYuh6FpWJrlGkrlOxUrGYyaRx3ufqMYDR
BOVzFgmgOjOWm9L2ycp6WEZNkLb8MaojNm8rw1Z4b/hMmAxP4tewPphlhuWLV/tAue8J5cXP
B2CHVW82phpIJ6cbU+gNh9453QRBRNyYC7ZKe7hFG3vMDWDcFOAuNuaCujhwl7nLmO03q9wM
aq0jDXhBb6na2Qd+Bb7u1FNYByUFvsBcLSTii0qBOrM8md/X+i2otz4g3GqsPDTjXNkW0w/Q
2Rpu2SP4C9LuDf+c/uwr4DUq444mftjyDww1bRmcE8XmkAcfHBPWgVSqFD/WqoMTJ/TlrtQi
QntA3noMeI3OrNfr5hejqmuCrsRQXu5Eld+j46v10/qEjlDVFF53unJzqDrcMp5kki4bVa2s
4Ue0S9rHGqHdRlXL6vei6kB4MjoG9YLVZTj05l3ohONZVvTeprZQuJvaQk9hMbUX4ePnILrt
+H/za6dxBgrwPSAr7RTOQWwn7/4g+23i/RDo1sl5mltfB9vvIdrmHWyZXuB5eo14f6BTbfaT
SF+9rX1QKoewGviG9Qt+dccqZnVoTXjM/HfZkVuSK6wxH8/uMJ+OPC09lTuePh2ZiLwvTWYn
85OVC0tvWJ0CI4SCecId78ixppyTzXDNAaQatFD5nKmGwhFaDXkidIXpz5kVhqQpifSHuiT/
S3EQzyWkeG+lKPXWzJpEYgIQGJ8kKJGYpBTUJVIhH/b0kzV7VfwVhsmGVCEUUs3cURrkahFa
iMAPVnOREEObrtrtneK3RDFU29r7A1zF+sFhTIExjKuW1x+s9xbiCu4XSFfdaoKPziGAmyD/
PBzd6lXIbLUKoBtaOz09Mz29bnD7wJ8w5IUBfI951+rtHC9Mfu2/zKG8eG3cewTuOGPhhUGj
BIwpZJ0R3cs3b7KEMBdk67S9ZL2+uhnjA3U0XqrDbT+FSiKdIewCmR8u+8Ad1Iu+vnJpoXM7
AUC+mppIQg/19kGnt3Lpw8bWQG3m1nDvwH7AtE5tZIx1+Bvxnc7Bt178QlVaBv6xYzC0szUL
nhwMLFtl+yf30k5WehCkZkbznw5Ah80k9JfBKvCfZ7iKJ5X6VBe3cxb73lh5aZiBTb0eONj6
2cxHO4LLXai+jNkO4gpUhxp+xlqbiZyI4qEwV7kQI/hTEjDpp3omKgTvEaLp6P6lxz2vLvmp
ecVycQ7Oyfm5LrLL73RYorcuOzY4bjgIh6Mm9hbTKS4JkknELkOz9WQpAWRYco4aOjnkC9Zf
LU2WcF0zjYgUpY2IJ4oKUIMF6KCdskOMBGQxqaXkZKlSlkuTNQALUHZ0MX65KxGNywnYSuSi
LqHqs9eE+LoxbuCbjaPGewZhRF5hxivvVYjNlaOVWwzxCDPGvF4hIiuYisAwFQ1Na4VgHcaf
WM/z/uIfNPCgdkgb136tkZrJ01leKFKm30yZo+aXTOrL9I+it6LExuhz0WPRt6Lkm/Qn9E2a
+Ip5wnzXJH5jAnMLHRVoOlqx+ESdpVmDrbAmKdOyIVdkk6wYWjTSJmB+J5aKyYRD7HJ0fNO6
aOEWmjnZzqKNBdyfj7L1D+GPngRezATRs8ZLke+DKKbh+7E6ZuErzil/fwi2tempmzPTDdXG
QG3M84GKHs6VIyNqmwh0jaiweCcwc/bqOZgqs4mi1o5Cth3ZqB3PeoS6atczJKgB1damCX6E
ffu/kLofRXcT1VAXmEKSfdBoBKrV31fh/lko7QG4hayNtFkLldRBFd/l3iHt1nf3j0fH5VPm
RPTn9F/oDjjLDsNvaty2xpCnjD2SLLjjvr55uXa2z0Wx77ZgO32IOeKKbZGPPRr7zGAP5Ury
+dbLm9dn1q99w/T3D+KOcNFFkYHV6Q0bwAMH9j528mEj1IPsctKZiVS/tn2Fh+c0zpVMrst8
cRTknwg/gGZb3smxnFs7Uh7N6lDXye8cb11+MyfikDQP9GjvQCWvA34C02evWY/Kyf9SXTWw
TVx3/L07n+3LXezzxWf7zl/nr7PjaxPXH7FNvi5QwkhwAqzNEooVqnVsJZTWwPhaG6jUMj5a
oN006CYNWk1q1a0boqxAJ8Bdi/jYVrJRjYp9aZo1VaVZ0dSlReDL3juHjimO3/O7O1vv9//9
/u/3y16jr7USPOfxZlney6v8GP8of5M3K4oYbW7mirJVhgVZlQOyIIuMjeYSsSid600OJ8eT
ZDIZjXKcCHsJP7Rm7/N6/GmRiLMJTWnGSutvbsmi5APD1rRGM9l0WrX2FOlMb9hehOg1XoTF
p/rsYhDllbATSJxESJIcRFJlOafmJICTcx5wks72cmVw2ejRHdLYdDndXuZqZQ5H0Jnq4PLR
o5rkxVe4ejXTrnI1dJqqValeBY3DF6UbfMBm0F95Gh3M+IjmajWcbvCt+BpuryryTqFGr0R+
2WxxRHLmSDiuoITTiDSNrOnKZxwZR0d+LonOncRGIkq7qeP13gH3PCe3cvnAqpG/9MlL1hHP
lXot7LIu28ADKwg6Gughnt/iT2TkbiYcI0xsHPWkt1I+/dNb4s7522D3YwtjMW1I/36XJ56B
cEovcG3w5WEu70axs8W79vaCJ308xB0zC4AphzpmJ2zRUmP8Vp5wpFg+qyhSzM4EmXaGZBhI
sxZbIhnLR81R2BFVo3JUiEoWJYkLU6S5bHKBPRaMEbGYzSbBTiIIm1JSut0nBiVzvKk/lmI0
hmAYWT2cupwiUpqNy55NwZQRU2EEmDkzYU7m0yCyIw/t+eH8eH57fn+eWpqHeZxT80PdyA5f
AzL6NT+DQ48UeUKAB4QjwlGBBMIq4YBQFaYESkDVXf9JXa01kqmRUz+pVdRyFZmschVXspFQ
vyxl+bb6ZUJFK7ik2ArP1VKthOYck9kizJURFdI4Fu9EVSxGo5B3rzZCa04PDzjoQnJgWc/8
7vsFB8P3wyvzeJZt6RtIzGvie+AHPYK9ie+PMXGhfJ1nzr7hCIaLbUOTD7gVJDc6LvXvGvLe
S0BWv2VxfF4SW5lYzBz3Lapf/ZqnlUXVU5EKryAVdoDT2uOk1R3IkqmWlJKaSZkysklmZVF2
qrIkR+7J4SIsxdWk6ba2iLOD4AU/dFpjYb8WIQisKYIw9dAd4WBmOEMczsBMQY2FWcBzPMHz
bI9Ih4UwECF6LRWh+FQehQ9DOA05cdOGnKrcB+XKP+8SE1pGdke642D/pyDOEE6tZmgG4ZzO
YSlEwhZHI200Ol9uTh/hO+YUgduBFOJCGLsy1JX6xuc6ld7JXSQdCfTUN2wOJEx0LNjLhIl3
FnuQgP5V/WtfcMm62D649omYp18fHxAKLqQBp3eCPD3f2e50oIhBUAzSjz7wnWd7J/V3H1sI
ZmdBP9JFgVpCuMAgAIAAS2f/Th2hJoAXhMGEtijvggqrSK1yh1SUV1ObqN3U7uBeualF5Hmx
KeHzichi07acSDodfp5uAj7OR/hKYDTaHoV2f9BP+Ev0ugg3M10u47c090dMz+le1Fnap5GZ
56oYGFCGHAjJccWRzYcMHMyWiCODekRHRgYwxCGgZOqIPqlf0s8fe4MkP7IMPfL7w38KRKNS
j//zrVCBT+o/qk+G+y7CEeI1/YJeOVeF97uiH+//1a8Pw+MjI/oa/YR+fcOHeI+F2RrZT74L
BBCEplOgZfbGmy5P1ozyjpZBk1HmW8wW5rvmPcxNxjxiWm3aZCJ3gwuAuOGBdo5T7fYg8guk
vdzs9ljpfuR1E8d9iolpPgkDGstb6Fbg5tyEOw2wL0CuxY4YjA0Mw2XxeMyRw4MWbBGyQGoP
9YbGQ4+Htod+ETobuhz6NESHPBp6yoOfFsNZz6Ocdc7+GGOAb4xKKotHjWVt2SkrtIpyYZ9H
RU67jL1AV6muog/lGTSvqKV6uWag/lm9i+tCt9Qgd7GCYDdYqUKnpSH6BvaWOI+pB3Mho03n
O8j+ic3nfv7wcjMB6RULH97w9fDef09NjOhf6De+IkQy4U74j9++8MrByVNvr/3qD13Qd+Rp
/fXIrW4+swKQBqNuUOPADlwgCF7V5lsJ6CEecUwI3wxsDlx1XA1Y3MBjJQ6CQ9ZXwWtW04hp
lD1kOsieN11lza6Ex8OanDmW9OVMNI92uW7U2GVpwajm5RpIlzSEsIEkEfLYXUEX4SrdLHfh
7VfwxKs5uP+/yVWqz12ud40ZyGDFTiMelisYkwrkLIRBSC7fEZLdLopAyMgkFeIbkFA3Dl7Q
v6e/eOHH778DC3DZmUv6D9iflFbrr7cQv6unTZsefOnPYynip7r+nn77i/dgM2y7dPr0xf/A
/d/O18+N6r98eePsboTOAOLiCcRFOxBBFFzWgnuJZ8zPNO21mcR+r5c1CQrTzFpCCkmZGMmh
GcSxISoATVGzmFiSgik1mDOGRY2h1xjeLHZn8ajFEmq2qkwpBFA0ZZWCp5SmHFYIRbR7g17C
q2H+3M0x9N14fAtRyyrG0JfsOB7PFSoeTKnPEKPKiFAYv8p6w3jOVFREsS5sZ6fxv4ElhvEO
sXLZPOpmLheV4wyCmS1UyCncYdeJb2y7+ptt6yvbLk5OTejXBqXkxhaagLL+N5trYrXIwSvn
d77y4p7L7z//0tO1hwKwqUs48+Dqnqbi2pUvbCnh070IY1Sa/BiEwE6NW0xBD5WgCtQFykRT
0H+S3KPRst0X9LX7SN/b5AHgIQ8eA5HmM+QuYCP3AQd5CFjIDzVH+LoNXrPB7bb9trO2yzaT
7SR54pjW7DtLngQy8JPr0JN/AJCcwIyRxOkpyYP6Gupden1mmpuqz5TR4n0pvBQKIymhfaNj
tSPvNiM3i5q9K4MFFs+jqUClb5/aOty2fI2VdSRzBTW4uDNS6SGu+HihfcWg2wljVofvZ2ta
++7pGx1MDK+8t/iQjW5aIiudH02MDR1Cu579L+VVFxtHdYXvz8zc3Z3Z+dnd8c7uej27idcb
1nbG8Q4xDml8ZdoIpUUxKVAIchyB4yYtOAkFGtKkTiuCglCTChpIG9FEadWE9gHJjp21FbWU
0pBKdmRRgkqrSBGiCCGl8QOFVqrXPXd2HRMeivoy987M3dnzfeec75wzhQukjc4hFd0xiUI1
lMxlHqNMoKT0pbMcRTGrmR8C8+lN5mPHM2fTi1bjvFW3rsEmbfOHia5mja6+r3bhAja/7KX5
P+6dOodI8K+7ZAcl4JuvTSJj4S2ejyf952LHY+QVDT9j4Efj++OEGnE37sVpWLIZjVboz6BQ
8gxnEd/L9GRGMrQpg6mRwSrJZGiFvsgNtAzbtsNQk9lENNpUoRd4LMIjnKl+JEJ7nI3OgEOd
Cp07e8LCFp0CLCjAAlW2XzSxKO2Yd10b2NLfbXWnvAAdlGW4H4CpCAcvofFZ1YGCRzC1wFMA
LSqvAmFaj9KYDY6DAgQeg/JDds1vIPfLoDuPfKlv+M6Nd++Yejdzi9PUUcgmPcHMNwrdpXW9
3+p78tRo9fnpD73C6uakm6nzdEw6iUzI7D9wrueMhC9p+H3tY438SpvQLmj0TLgSvhimtrPN
ecKhl52/O+SXDj7oHHXIehUztC6C3YgXIV4ERwSDCSPpJnuSlCWTyDKtnEVtaokXNkcZnOAr
PH9nArsJ7CVOJEiiQv8EPWj0QJREO4AxizGyRFpnyis7Xr/gDrK4FgoBeZ3eFvFstyWYCiZR
vHs3jKNAlagKySCqb6KJHJtfdnblLcM/OvrdIw9se+lQ8/1tiaYfCHIkzcg/uv34v6u/+HTP
fVvTsda7Rf0tVj+RPqATqAWtQh/zErJxXGGOGfePNZ9pJsfyZ/JkR/ap7LNZGmFpRsItZDUh
xVQDhMRPubW1fbadGO1uu9dONdre3lChR8c4KmsVemgsB/OXICQe4iEeTflGyA15IRoqeiWI
wXM8lUMa/rF2UiNHNBjuTK1D45qkafKyCr3INaOEr5cWSqRUSnmCqgz99jiKm3ESn6LvIRnv
PYi8a/0917qhCdx9TXTbQA9kDwgeMLgYZGUPHplCHILo669FXf8WQWarCD6cgAYvn2sWAVcX
h3In3EEc3ghDkIhFgiEMpQ/avj5eHa9+VH1nZfm5tQ/e9Z/3L+G1WN5RHt63oe+hR3rWjGdu
K6ay9zQ14sgfR3oPT/z6hT1P/7709MR9ew+dHIo2xiPDgy88//Lxw3/et853U70UVHPbwgh+
E/0NqtA3xyklGLoU+n0eIUSWCKGgMBV6ZpRyKipCvsUPVsetrboVrFyFhM7RDjhFKfKCclBL
Q8hA4AcDM45Xv1nVUWDFLvzmno+eGri69z2woGHhQdIIFjB0cRIpC3M8HEv7xISLLLqxsGb5
xDEs0ZvN8ZWwYXgEHUHEBO3pALsVme6SDkjElTypR6ISIlilRKJEwXKFnuYG2MWXl3zK4UtU
ADo9yjirA2J1QKwOiN0AxDrgFGWfBTTffWERmtUNAoOFa2f6+7u7LwdXOAf50toKEAFksos0
bv/JPRPDh/ueeH3DqaHpvp+LyG+oPh7gpaDZvx1XTCPtRwKggFg1AR/czY3BGhaALdjI4qkS
vFLCKtg/DmEYpfIUfRdq1unRcDgA9QVe0kJLXiIVun8Muv5Qhe4bVRQJlrFIJKoFRbvsiai+
dpMnO835TwBrLYpxUPBrOLtwHSvePHh+CO8DsFMA+nuzg9PVMUA8BMgFagtQJwMvq+j1wM8C
oiwgxmGDBToSXELAQ1iAVFVwIRU74wZc/MXO0wEnYibLMdpKGWjm/lEQAtHJwNdDISTAjhKC
BGZFuQlzPXeRcOsS9kXgnaKfQa0B+kUPx+FKknUvvzg0Nbjo6eq26a2zgPuO6in8YeBthrYD
bnp6Akk4TaX/12WyAALqXfNcOBSY/Tk3zb8jTK2lWDzJivhh8MnBqcHzgTs+3To7CDXpreom
0h94wsCzkyhcz7ioyLggx27kX2gx/6JOPRzrPvtcVp4TkamFVVXYvKb3K/5OdUQlV9U5lSDV
VHMqaLTKw1E9ZEQNDu+3GrsMct1YMEh9jtKoEeVR8fNIEkwhDCsoaHPF6Z1oBJGraA7YRCLp
4TTiCpGpRKTga9IuiVyXFiRiSEIE4D1ol2USRUZMsIw5hm+Ng8lYkpdo5w0x2zdpjhKDupSk
KA1FwyE1Ik5ARaj/RDNCQkVyOtf5ylW+zt1lcFF139BdnfToG/UBaBUlHXn9jy0J34XFDcSN
eQG88tjigzc+80Yoozcj3kLZgH23Y15O33z/RhCT/+tMkIw13VmKS5rsSoot/ks9Nh+o5eXE
jfh8pZabQ4hU56QWbCpjqIBWYjyJmheucsPJ+W00m0obtq5rti3oup1Zvp3mGodVU9M8zVnC
T1PMsjzLYUrIZnELKpgFXqCRArbhiGSkINRTQJ34vR3SfKSDOOuYu6aR9JlLli8XiQnd3fIS
L4lDLtP9UjsBl/EGx8ccfuNiPIBH8An8OwxZE9RfaEUCGq/MXgrWmVYUUCH20yJ5UZ20JGj0
26DRsXpyz1jdM8HmSm2ZCThMeTFQc9gIbcP5W8VE0iVawqIozWJGSUKxZsUG206w1aIy28wP
hphyJzbnr3LNb8jGcKrRgLHTU5vliKxbKbnYt8I+0Ntsr1i7f//LUssPi6azbZM0aK1fH1YU
KynrRVdvVr5TUuxUttywr7NRZVuEVhryX/GrLIfiKI18oME0owmksqiZUmUuc9vx5YZYBZeA
iJnpAOqlK69hb6bzbYFzBkCIkWv5MmE4g1aiXAaLmV8z99UO/87TLhT6jq85Tz6+aXOu695N
m5Xzt7Z1tMtRTVnl9554uOUhmCz+Kf8LD7Mm1IJjkygnUrPY7mfzmUIc5Sv0Gd5uQ8vpr/Ft
3twKF9Asw8YetW0tk+GprJ8ZQDsRgfE0RpGWD2ZQ+ICdt9xC3Ey1+IW4leX+7X6WN7f4RtbN
Eo9msy7o8m/4bYSkFD3Mw+LbYYur/6W+akPjysrwOefeczMzd2bune/P5M5kPpObJjOTO5mE
drenra1FdAxFEcFpo7ig/th8yEIVoQE/qII1f3T/KBO7iAiFxrbZZAtLK0gRbWhZKtsf1gSU
WoQl2cWF7brk+p5zJ9OvRbpsCgolM0zP+7zved7n/TiKwkqmpbBMztIUQxlR2sp5he47oUyL
bzeUdUXRFaysShvLBhvYYxmXpXMogT/FlzXz76053tBRXL+WXHMKcI2XHh/jTq+HcW6OCAnB
DncLfpq9Zjp7izMKui8HIRIYAsAwf9ZyDZT4sxYk01naQCJFh3tg+8Xjn673uPUJNZBUy33h
Siga/ER9755qzMgfqFfjWeXb5WwyQGI535GoL5c3xp+vxorpvlAiBpvRgvwmQfR1pKCjbBAW
soqEZSks5fk0wFTZj7CKUsiE2UIVTcaiBcqUoJE7d1qzV3Fi5E5rLg6SSOidL6CMnlxpFBYT
dHrq9EuHDtHX7949eRI97osSqSJjWQ7LeVioiELwQ74I1QjeJDYhBMO6dxV8rX24r1ypJ9cY
JQgcvXR6Sn7z5Mm74AkpBr6n/ApFUYb5okj1omjIq7r9Ugjk/Jc712r6tRoeGb1eAwTxJBMr
sGA5FuXPsQa+N3RsX/+B4d5SwD/kH96X3z9wNNM3NKycrJb9IZ/q938mGdA9IX6v49TGc6Di
DP4iLPmu2pgVTYcMF0oLCatM5bpSmSduaSoel1SVhkIs2WuF1tEmV68Bq6bkAYYZ5RLW4PQM
xYhmKFElmua/DYKs1XRP3HBxWX/d9S0XMVw9Ua7tqNB2lHcFKRqNc21fkJnMZ3wwbsmi4UFI
k/KUTJCsy1flm/KGTCt8kJGaJMt6Dy+HAV724JkK/VODjtA2PU9B/3RafLtB16miU77wbizH
uf7jXP/6Y/rviJhr+vhOC32kBmYfFAGvAadTPlENTxQDb449Y2MN8SzkNRCNwOuGZ03p4c8a
PKdqaux2uK+UTui+AywUc/trwWDQ65mK+JRTvZraczCfUoOG5svqX0iE9Vgs4VY8vjGRQduH
59AQZPDL/7cZfJU6SVmVzl3Qmc6tIQz+yTKQUqTrekZf0Bd1um9SnxLfruo3dcXQsX5Z2ui8
Oh9Jo6k/g0zSj5XJb/6XRGL7T3IR7VV+iDT0+deQz77Hqp4hywcrovRZdAKmHlWRD7slH2ES
IXz4EzH8CT5BTpE2uUKAYGfwB0Y70x36xNrctcDErTXYf0Jh6BF1PrV5I45F91bTasClKeO9
KfmNT77g3Vs+8N29R9Puvm/85hfItiGODT5lyZj0Y5BZlFoIIesCwWJUBdxeayG7mF3KSigb
9mpM47+6fQELtmaCE2i4Xof9y2yZ9bpt21dwAW8IrDMO1hJCRaZPe055fgKPUYxyUY/G+H68
7IbFGae4PZgDCFi/C5FAj+pGUodIBpiG1wc2B+wBCQ0MeL1OAB532NrQtqABJwFBBFCHu9hr
wn9f13/9NkKVZTUTCFuw+v6BuU1TVdmMinkIF2Npi39eAjCcBhzTnIVQTOCk1/4c/hn9WyeS
GERSvv8lFGBu7AQh3MJZzp8bzm6Is2c6Z8Nw1mQG1kzDXDclk/lDlsnKppUwTUoZRmk9TcBh
q87fUCJydBptkK/Qd7oeJ9DW9i2UYgG8mFhKkMlEQtMY1hOccm7nWCVxgRSF1ZmO1SWw6r+E
Z1I4JR6BwZSVSaWEbYrTLXy2IFfw9HxR+oCeAdu3HFvyo+0ZlGNxwgoYFfBUoYAQI8bgicH5
wfagPNhxPCs874b1nx1r1HCscYy8i97fPodeuCBLR3iCQHz880IwZvHLTBw5Eo+zRxzI0kgT
72/eaK437aZsNPc3p5rzzcXmUlNpPuZ8uDU7V3dCANbr/1NxvGx/n5YFm3WHTelVYLP0W3wY
/K3w59nhzGGyat9nnsOHn3uOYWMST3YYdVTYt/1zeVnaBoSxTj7e+2AD9b0GDeffTKvVqlWG
2wfxQXixWgfRsMlNuQomcIHWlItkjJaF3ShZBiYyUP/8RXIxHLdyouJhrUXQ/RDDIuiPY2lf
BtUOCcsBxxKqDyHfCvQHrxfxg4KVpz3XiSTbjaSKF+gR6BwqwZP5+fxCfjEPA2qL+fIlCINg
rdwukzKnTxTSbmF04m13463at+nvoSZiBEcDAZeLmwXhnxFsB68E5SBYC/NdsEYT22dpTfrn
Q/H/C7iKMmiRlRIrLZakyVJeJKHlZO+jnbcvb58lQ9JWJ7oore5kwh8IP5SxpzmFJhCjNcpA
qz/lvsl7JPj+H1HpktbAEoj87ZXKoIxg+k2I2tOsiVWpB+03ncu2dgXBvgxJHKKrgPCyg4DK
gGCuaFlAOJWEaXFnJRne4wKQXAck9wCktZsoT2ivIrT3PPMBcUVWnCwuFbeKlGMV+4X4TF5Y
wUjSYiYMmYrJzEmzbVKTS2IH+dnhPqHUir0JSj0Alc83ueVg2KrocPW3WFb3xjnuSGR/hGgR
rEWMSCXCIpORduRKZCPiinDk2brTxj60CnYRu8PHoS4fNeDjawK7KDZij9/SgZWpojQPxICO
3lkp7hHEVPj/q16/pVVYpV2RKoDtEDL77LEFJy3ld11OagjRu2iU6QQzfVInSI+lOVJSbGwc
KWkkWXI+2U6uJ5VkF+8ZoEEfOfZIH6nh652ar4n7PehPT3UOOsgx0nqog9R2OoiI6iOdQtb2
lDxP/wrV+UtnJuKF7atocAVX8iy/lJdW7X+wcN7QdZin+ZH8TL6d38zbeSW/s2IBRmX7qx2M
s49hNFhjqeFgNGr9/YDRGGnMNNqNzYbdUBoPMDjjcoWeBYxXOhjy9vdQjc/mNdafSvl8DKeY
W7W0lJE6lZJY6kRqOjWfaqfOp26mevjWBlIQ83o3sRx+lFtdfqpYpvfRCFeCq1iEnZHgAoOK
K3Al+LgSCkZhurBekAtcBeaD6SNYEkhnH0dSJyayWUAa50jjXaRxY3x6fH1cHn8Uybmf8uvu
/aroDXod1AlzmPb2wu0IFk/VKAdJG2nC/0yn2+nz6ZtpJe1c79mgOXzJ412+hvF38BAqcu7f
ZtGcEQPp9bNkn9XPtKjVP+/2WP2wapk7fAuWhL3D0jDaQovoBxczfuxf/Q/z1RvbxlnG3/e9
s+Okce6SprFr+/40/hf74pzt3TnxebbfqSMtRVMMQmhSSZMP1WDASBNVYxqIREKAkCZqAdIY
ArUCvlAJJWlom25iCfClo4iU8UcTKlm0L4gPGRaaprUSNc97d3GTdkhZSSb64c5xH/+e9/m9
z5/f03xjqfug4V9ublABPnCFHhk2P3jgAjthvGROFhYKpF7AqCAW1MJUYbawWrhZaBR83YV8
J6FHbJQN6odf4zUTC6ZiEtNeAo4dN0waUuDREzRM+0hMfU6zHjOjMRmqTTO2mif5LE9abA1h
HurqwBXcEeqT7bJCu7V6gKsccHUCMuIIFOmRWEB2cuuQocT1+FqcE+LYSS4ubrft+3NrG2s5
dAcX0KeuclmQstA+2FxNDBrsfVnpN+byMB4WaSKf53kn7foMZUQfmRupj/DCCGaZR0dqkH2z
I96Re87sLNQcDbMjvpwdn91dgmF5h9bZjZ3DRBtpMaHjT3qTSFskcM4/XU0mu7qoOyTswoAh
sZLYSPCJrUa7jQUb5ccPoPz+qmWpKqAUWyjFWnGluFHkiztQ3Hr4c+vMOrrluYNKrB4Cbj1I
DEMGDEXSJSJIikSlKWlOOi/NS6vSTakhdUjvW2V7jPpABuXxT3EdajdB8OFo2s6gDO2Fy83o
mWrmQmYt4xEySoZmaplzGU/mPrQdWYSGvc9A5b6AA95n0HXIyxfpIYFTOJ3jeE6wRIsQbNGi
abHcyhqGZfcISC7RUq2sVbP4BQsr1qy1YcEAeIuWLQuSTfSr/lU/h/yif87/za66/8WuC/4F
v4/nlKpeJagqVteqjSpfJfaoIOLw2nBjmGOTAmSK/Rh3S5LlYktj3v3EjjzL46CbZ4dDRxI7
ZuJu7NAYzP9X20AV8k+5W9UE+iKyqEbwZPBMkKBgYJTN/yClphDUg2PBiSDPPqwF/xnk5+FF
guzIM9uU5n5gPg0/eJX/C8TzM1db3wJtHaddQgwT3CsFPMgtHCarEw/sCP/z75uz238PGfWC
0+eEw+ynbp/bndUYs9riBw07/LSsj9L8PZ5OwN4iHB/17J4uc0uLfThenmJ37b3RingI1TwN
lFzC2TD0ojeuhO24bfXYzgoelCNxVCO72b1BeLp5cgfrQy3WwzvuZldWdu6GW7mro9Neikqg
3MNspBzoMubYsX5NI+EwYnwhWZTn5LrMC7IiU7kmN2SP7BTxvV1jf1D1+1CzSAbUx1inRWER
pN58mF9u/pHGwoGoDaqKqq5W1Ql1Tq2rbYKqqFStqWtqQ/WqLfD9x+6/DzuPaoBdpO0Eq2Fc
D9uk0MgBv9Ee7k/a6HExTpgkoPFavBH3xLcQmXLZN8yO5he4Z71LkDE/d/oYeRwy5hH31i61
dxnLzXUadK9MiGAUUSO1yJlIPbLg6kUbb9/QPJ0ttAL+bHMM6YsuWB+A/YsGbDDAoo6WrQLa
mxGPg8Wg9hoJaotb2EIi75Enb68iChFq9vYoHjREbVUjSNMIgRjT7Nveji5DTG+kyZn0XHo1
fRM+etKtcc1SfX+R757jD9xD9mTI400RFRdtjbIkdBu2VpH6osakhCVJ4jiKI6DJjQnYDIga
yUZIZGuLmtniYV8wp7h3tmEW8Du3v48GlvCkDI3jPXpIlhmMLmEqrUhvShsgojySez3j5h4h
bIsLJoodlz1RruOvoC8vEsUen50Ge1OxN2hQpa4Qv6KIIt0ZfGF78C8KmKg03G+ojISqOqYS
FXoHUf8LK0PjjJVxhxxt+v1Y//87HVTZdz0/aLE/hL/Er6CsU2VUgeoXw1hyqwx6vmp3/TPy
vLwm+1jnh0uY1sy9R/L+pIWUxwXPdTRyyV1A+hlUAkuJhN2RxBSupbCSUlPZFE3VUmdS3pS9
MJkO4P4g0uZX2/Keg4C46NwqH+JH2K3yC0zFXEOkeZvqHznaBtFWQSAYehWvVXG0Wh0YgGSm
VTpGpygvUAVes/QcXaMwF9ykBh/O7XwoXpovN2f5ddvLkuMF1x0v5En422ReHqOxSoXdnO9R
qy8F0KVqaaw0VeKFkgKv2dK50lrJW3Kh9xcX0btn2/LcRYcVpgFsNnqYBtCPYnS0yuhw9fkH
sIXd5Cy/zn3HOS+ztc9p205WMKpYD2frnMGbA9vLO8/Ac/oYRmMfO9j5MLbOGWzbqzvPwHOT
JzA6MfpwtpB1J31zvA9srzmV7HnOVqQkaRVwS5Huygpy4KR30LZ6xbEibzO/S2QiD93977/I
D2GHqA9myyrDN+ett7zr/ILnMjIWObLcvEWPVCxlgHIElcWyXuaEMhbKSjlbrpWnyrPlRrmt
3Kpnc8/Rmi/juHfQRnPi0MmnAS1HYwBRyPcpDMoUTd3kBBMLpmJmzZo5Zc6aDbPN3AaF9h6L
z3rXAetXLlavl0MmTQJGSSzNl7jzpUYJPpegIjmiV7BQyVZopVaZqsxXvJWWXJ7eFzxk3D3F
H2ebIfeau42MekfRBHRpi3Xpw9ajhkV9XYZqLVhEsBRLty5Y/IqFmRKMW1ZnJzRvk1qmSbu7
DZOGFXhEE8Z5h5mayTFGYPxpjtKantlSraN3P8erbW3g+beu54veQXQMPBfYHtThN+oF8NK4
Wsh3HQInOTaVAyGDvWkPbH/13HyOCLlabja3kuNz9sTVtu1EjCtu3Y7thuvhOYhtnO0BE9qU
Vte45ebfqF9LAv5nDp7uI45YvHTMtDVjrFwx0jQsGQugGAlKT6Xr6fn0StojpJU0TdfS51wN
OWMHN7610zC/5C3vH8Dv71y/suddmMoEwnmbyoMDfRGIR09iIakks0marCWnknPJ88nVZHty
64IAisDmxXtF/jTqRxo+cA0pzZv044ciRiwYkuExdNR4XcNf036jkbMaDsXSMXIxdidG/hrD
N2L4WzH8fAw/G/lGhBR9H/X9w3fbx3f4Qr60j2tHKTzIBUIhqkSN0DL3o0swcxm9A5phv0OK
/b4s9BipVHSZ++ESRRn/L7nvIRV1cd9GIvfSUscgjYLNlcCwEY0GEsvc9Usy7VrmrlxW/f5e
2bvMvbbU29sfeIV7HSHu8/j5r6PqZj6vb+o9RT10eDMUFDe7izocPCiuP/Hvd+Er8WYouJnX
gU725RObGu5+ZOLUeC57atz5Nz0DD/bf0f42Lx/t/w/zVR/bxHnG37vXd44TJ2djO7Hj2Odz
4rtz7Phs38V2UtK8hcohoU1MRymFUko31qpQEirEOrVr/EdL0f5YIg21oFGZaUyTmLQEQgvt
pIGmDU0aq9mkoXYfJKq0SVs/wvZHtapN2PPeOV+l/2zq0GT7zu/dvc9zz+/5+j2K3G3k8i28
z9vSrOc6dBnW+ZyebWl2K7LcHoUbzbzryNSNI4tbXb/fvT1Z2rBpy44/n2CiL8XFhx49+FQ6
cbI9FfOEtjGxOs67ufjdZ878LPzjkSe6so5Gb0ab+M6JY0cW3x9//O5Qi5ijUavdGqceYXPc
Wxafx59BvQyQetaVjCTTyemk7eKtmfPJJLLK5n+5h/Zxdozzw55O2NPMda1HKHSWpYhfAK+4
2iPtUCc/ON8uNZqblrs/e9x2CnYllndBd+DaWsPLPcR8G3699TYmN95ee6tPuT1o01mcpjrq
nUY5PZkGHeeInE5TjhZNJoEC4wwJRI0MpbtahhEyJHMqU83MZ7ilBKSUYZfJKe+YJgst/qqF
FspRu0227+f+gR4n9dilPKacUqYVwPm9N5SY201uQ5J0mlBimbS2GTKBOyMys1selStyVZ6V
OUEWZQJ/5mVOriW9VWqW+iggzxct5Fe9wSi3Dw3MYFcEcv9vJBUJNzYS6o8oqBLpJCGSfC8c
/Fk4CC5DExlBHBWr4qxoEy07lyy1vEcrAv/Jcixp+DIPRN7smldJm4kfZilYpcyoWRmrGXuG
VjFAjRaoWvf9kuSYtW6Mf74Wpy38AYT40yj7ug2z5QTYfJ34EwmwGdajnZVOtpOsa4GqCrQZ
SmeCCqL8vntZ1nFar83opXUTQb0eOQ9boyDqW8QZpfBhVoJ+I5klWssYEn0pl8QgaVQqS5PS
lHRJ4gUpIpWkOemmxEkrJXqpQiNt8dCajEzjT8BrjRegiday8D96jjK9NdmaVmtPxaSutU+t
zs50ofZUuFVepZN6xu5e1pnFL/I5lDM981vSns9bnimkC6SAhUIETqXCeKFamC3YCxSLAnXQ
wbWe/vLk1Tz+91qu5fmnUZb7FXj+6Vtv80fQwXOcTaOp5RAMzM5p4LefkA2aBCnH2VKkQzFS
xNtsCKnxFCukxBRJYZJiUpiVycaNkHftChy8rca0zPRD8rFIHpPnZCyvOLGWe5YzVzr9msjJ
olaInIJp4zukIx4zw0YlrSGjos6r7Kg6rl5SsaBG1JJaVWdVTrUULKOmLH5s+yv3DZCYtGoW
W7adRPfS+ekkyWSNaJSwOsnohk46u+AQCMPB0Whoer8+rk/pNkEfhT8VvarP67y+OpPvjHQ+
sSxdY8tcCd1novHqhd4cSMdsnuZP3Bcw8uX27nw5CD9Hd55ANe7Pj+TH85fyttF8BU7V/Hye
yy+p+BxC/1stiAGiEuObuK+hGDpOmrx+p8towEGcwLheAFpCnEgRgkwQQdXE4kVcmfHZ6+ov
4hOkjZOJJAohv0s21BATCDGhNjXABOArBn+Kr6A2JOIrxOl3q+5n3djtqbMLb1lMBfUvXM3+
qWfXwg3gJ7t2rYNfArnX9dSISrbnxgKQkqu7XNc+pMwkwUgmD1miIZIck811Dj4+O1zkmlua
W/imT3/0+iPPDa9veu6uU/jQ5sX7373vzabwzMAHN7cyf/l4/xYfE8tu+MHLr3R2aIfaXcoD
8eDGZ/bGt+3o2PnRA1F3/RPGznsPIgsRex0goqNpEpYiFBFn0Jlw4vrWNObAGd2ayqiRJIOT
FJCoy+2hgESaDILSTCOfSif1TgqLv1OFehz3y6rMykmVghJHSQClqRDeHn4y/GzYFo64XX5K
4BxIx787hzjHRYqPfu1D18Lb2RtLGAFEJkI9gMtqlChIl4Hj9fT8xkKKMjbFa+elz0GW7Tbg
xhfApuv2uqP3PLL37FOHFxcWf70MIDNZ3VH/0kf5ZQT/eP7N7xmTTOye7a++XHp4FZBRMYDb
sp6NB1ew9O2JvfYiYiyeDkgG0LeJq05t9BlOV6DNQC2MwPsu3pqbAZAwjTIBBYVjntMe9oiH
OeRhAM8K8TjYFhxwx92s2xVojDeyjR6BQuhCHoCwwcEFuDiHOXsAr4TVSlSto19Gu74AfPaq
GUjA8AE9oLaSW7oNihYaQex7n73D7pF+eVgbrVn99WP1lRITY1xdD2Yjgw+uWNjQv9O+/zVk
2WjbBjaq6A+kwUucIUPwMCE+AuaRCNjnwjGOE1GnEOwPjgR3B23BH4rMYfGI+IpIE+ou4iCC
j3FgX4NEt7TC9BGTVCEkhrQQDrUJATGgBbBjTVIJXiJ4RI/mwU7e4/R6aQ2o9/kN4i15Wa/T
iif1tniyYghAoNzfhOlRC6eeBOPXrtMb9wNeq2OqBtpKXLW79Ww+1218UQZCMNm2HX1oMjB1
AILphTPfz+9NfPWfSwFUt/fu6At9IxBC+z3H933lYcbFOaTWcOeT31yBNXDUSAX2G7RL07rk
487AjNdFqx/7L9svFjehLaRfIAzLQLFuMsb1CajQ2KHr2Sw5nYLLu3MTuWoOa7nRXDk3BX+5
ao7pz5VyY7kKrGZz0JhTdMqxpkk6VNZ0QcZfAV2pmq5DoGsz6RW2gtABU9fAxEBlADsHBgIB
crqD6hqaGGJLQ+Wh6aG5IVv/UGloDBaVoSos7UNmt1ujpZYN1CLN0sI8v3g32kiygg7i0klm
JMkoyWQoBLPr7vhEvBrHWrwcn4rPx23VONMfL8UrcHE2zsWXjGBM3rAkHeKQ2pCuSf852DBA
8sIASO81beid6K30YmdvbzBIdfRN9LGlvnLfdN9cn62/r9Q3BotKXxWW9r6aAWtRsm2lHAC/
a/VU4D1FtO8sW6QTLfAYeibNQOzLReax4ljxWhGjoqsYKV4uwlxw5Y1i0ecj5tPEb9wytGJ/
kRWKIpxGitXibBGkYTrwtq43EGYwvEGCkhFzDDApyf/NW1i+tNuXfAlziMon0dBZRqFyGwSv
MaYw15Q5BXr1+0RWFNDJKCTYbgjKiDKmzCrzCicqmjKuTMDgVIULdgUtq0l03xkdFpr83BKa
/AEmaa9DW2ZgmhikWjqBZU4Onhq8PIj5wcFmg44ZaHh6+PIwHhkuD1eGq8OzwzeH+WELs7bI
v8kvu9goriuOz53ZXdv12l4w9ngxxTYGloLw7uze2dkyXu/d9diZZSx2LWN33EC7D/QpClCU
hzz6oSj0yZYa0aIiGaWAmvaBD2NDqra4OMJtXoxQEpGiypukpKWqlI+StFYtb8+9c8fYxnyo
VJFKkKVz73Ln3nN+c+Z/zl3GTHXz5/6b+3LOctjRW5PDDm5N2+DWpI9J8KHBw+PQ6k1GoHX+
JWmIbK9ugEYKhcnaehwmFZX4UHg0LIbpxju+hF2Fbyy8BFyiixkdQd+Bvr+BrJFEkj2cHQIg
nmi2K7SJsI78v3mC3Yzuaw/cjPbTm5GIhO1bo8vvT49d5Siz7y+wSlmhzD1IElNMaVLDqdGU
VJFKOcosid/NDGdmMlI4cygzlDkHQ+9MBqUy+czhzCjMZjO+zEOVuUyCs6IrlLkAm/axs/qG
+0b7JH9fn6PMcNbA8ICYHxgaOD9QHPCkBvIDh2EyOjAD07KBhykziyi2QplTsF0kgXIJFEok
QJlhc3VYnVGlsDqknlM/Vj0zKkqpeXUUfpxVverDlJnFgFcocx/s3s1i6B7uHu2W/N3doMxw
RnY4K+bhPZ7PFrOeVDbPXupodgamZdlVldlXzTSRvRHfixL2/Ub450VJTFNRTHZhsENj0Thm
c3kDs6TBvxYL6UC6OT2U9gjpU2lRSOfThTR8XvNkazrd3k5weWAtPqtP6FObp/Tp5G38RWwO
l0sG8dfgcwYSDbrf3hKm9vKeHDZIVqXjix3MjOnt7L9ILTSggoFyBhKMvFEwJANh6tK3SxjT
dd2DjsUpxwZD1P6VVMPxAYyu4Zv4HgZ+bfuPONcXflulQ1Ay6FB28B8WcxTypsXNGyDiByKf
AZF+un2HgZmFZpRaUlO9Fuf6J/tv9EtCf6QfBPUmwf39+TwxKYCT2RO7z+YmctfXXZd/1zCV
m+59p+62ecv6vO6L5+bMGslmOGwk2hyHzXHYgMN2cNgch72Iw0Y5Gwl23i7Yko1MjsPkOEyO
w+Q4zEUcJrpm3jTvmZL5SBxHGIzFOtLiZrfvRUEAFv8AFlHGohNTS1ogG5qjQ9Hz0cmoR4gi
IXoKxpIQzUcL0WL0k6j3Suka2RGNKgp5OfSDrcdCr0R+GjrbNtE21TDVNh25HXq3bS5UJWkM
hobY1ZTC0DgMDWBoDgyNw9AWYWgopyFBy2sFTdJohWMwQhxGiMMIcRihRRghdC10M3QvJIUe
CoOmBivc6v2vscX9GoFGHmjcBRqMdEcXI04CNCPMSfOGKQkmgr8rpd+TmGl2dpKX9WP6K8aP
6n7c8BP9bGYiM13/ZnBq/VRm2ritv5uZ0/+dXCNZDIKFRItDsDgECyBYDgSLQ7AWIVgoZyHB
ylsFS7KQziHoHILOIegcgr4IQUfX9Jv6PV3SHwnhyOLXUXreV31fwb1t4laoH5UTYmtnyhOl
Qs9XLdVebxvaC6uq3xDE0qeXvtXXHqMLKdHS80vUs97bZrO9hHh0l8D3omuWaCCsWcfWbNzd
vUddPG/htWVeKcyrqsuSuDFtOG6565b5paARvm5bv+14xavZa8v8UvY5qwSs7Vpa815b5pnC
9/KZluOauprCHhT/VZZF5bR36aJvk6jUjK3/OqaW+KtlXOxCn3ShVBdkztvjXV0gpu30hamg
OXhboB7XJmPJzuT7yc+SXiHpN/zm6eRHSe9x7dVdxzvm8Lwxb/pg91kDFQ3EJPV7jqTag46k
VnSbILcZg8/akzDb2MxnDRtgBp0HnY1XB/ATye0NUg2PBHArFo+C3IpL5XaH+4+WHpXlkiu5
qqquorgHxT8DoRZKaJAe0W5iZuO7mCVVgIgMImEwNXh1ECrOb0nl4CAVXMomD6SoOPdeKRVJ
R5LgLb2x3g97JanXb/v3ne79qNd7YveZ2tetM3uuZN+wptdNy3/c/Z41Z85l53fP2/P7aig6
GxVtZDvobI7OdtHZFJ3torMpOttFZ1N0Nkf3RNLM0ZmbTfEoSLNoPhodY+egE1ZR6IOlD4Dd
OsouQc8w85hasqY6iKEbERIkkU8UEsUESPLfSGUiEQ6TEOUGXegtyi1CPYon07guXBvZElEj
U5Fi5PNImTfs1/z66cgHMPEd3/7qzuPKXGhem9dZqmmoqCHN4aVxXprLS6O8NJeXRnlpLi+N
8tI4rydSb84r1BwSj4J6i6HH8zrCM+0BBT8obARaa0kdxHCuBwk9qZ58T6HnVM9kT7Gn7Erp
F6Sypwd0W6eEOnlmGZQUADKoL9801Vpji3HHkCTDb/lzPzM+NLwnkse7ztS93nGpdrr+evDt
undkKu3z1nyuisKyUNFClgPL4rAsF5ZFYVkuLIvCslxYFoVlcVhPpPIclr5ZF4+Cyov6Y2Dt
cJpP+lW2liakk4zVn5hWxhFBB4TRC0ihnlfUwVd/d1xRmprIVnpeRQlv4XYzt63cbuK2hdtm
bptoXJtggJpikdhQ7FTME4ABgeFIbCbmK8QOxyZjUoye16nGWD/agZmFS1FMoBHQftaNA+1w
qsH/rec0P1GReT7reF46Bp6fuYBk2gNU12NBDsjQYn46LssVFSTA3anhtprbKm793FZy+zVu
K+67H4wEh4Kngp4ADAgMR4IzQV8heDg4GZSCjvtB7n6Qux9cxf39z4T/D2TOTuTxdQtv8czp
VKkZ27YdM9u8lVmypmYNjihEGVJGFE9BuapAgEXIL7jzPU1+XaLxsYPyveygi8+x80kzxKIQ
6BdyynllUpEOKTPKrCLVKE3KMAw9iuA2cEsDdH74asRYurAiD3eWeiDG98m6H5afKL9bLhXq
D8gHghKSSUaVWZybMbN1MrMkUFOLh+QRWQzIqEYO05z9O6mSZa+XvFB/SH6hQXqa3GVhyzxs
2QlbdsOWWdjyeXlSlg7JM/KsLNXITfIwDD3yg2Hvv3993X9E+GrHvjK3fQfR6bKs8NaYJKI4
PcPvD2AhPhKfjN+Ie2gViMeftgpUwQC2n1VRUUWqU9RVXtRVt6irtKirblFXaVFX3aKu0qLO
noCirgoryvIyiVqtLj+LMa6sI9DVvgkx/hruVkjYcHUDZOQfxjdseNoK4obViIqNqNEJq5GH
1eiG1UjDanTDaqRhNbphNdKwGnlYjY8I6xmOSmhd+Ll00hdZzMfvC++VEkKYBGhYuyI+gcCg
ycmbsTU8Dfw1ThrQXhPxu8z/bqfSrxZeQh/7opx0vTdySxCqLsMu6+s3CYQue+JVQsfCHs9e
zx1YdYfXy/aFGSF+WQxuaYV31Uqb8GQJwwc29B/mqz7GieOKz+zYe2efvbv2+WPX9nn3bu3d
O9t3/lrb+O5ghzYhNC0NjUiCVBlDoQVKIJB+KEpV7qqKiEJCaJUCh5BCVVUlaSsKR8CQkEZK
RNtUBJSSKK1CQukfRa0sojalBSnnvl37LqR/VQlI1Z12PDM7v515783v9x71wQ+cU3Ma46I8
+INJNMjfkFnKpq1kA9v6e4vxWqdaE0zBeRnw/mKfYhgh1HOcQX4h4LAOgf6XdxBGC1pbHcvI
syiOvk57XAS7uqSuqS4SOU12IAVJZDcKkT3TFCmeBtl+TFG82HuKPIkEMjXdLVNvg5yY9nic
0q/IKXg9QjaiXnIZOXFsG8o2zYjU9FfFrNTEEVF4p/l+DQaE8xHxg2vwI59DtRoOcIw6kCgZ
lXIlzLLBQKhYKJcMTe8NhUNBx7Lyt5pb/zFzPTXy2Pjq+X86cexa+q7li4Q4vn/HT7+y8MiP
d35t4nepZ/Z9Yf22HWsWPPoY5iZyDzxmWbt9KibE8gjN9tnVTNnqg/WLzPLWL1H1KINtxtOG
bOaj0R6vsVvBK5VJ5ZJCeEXujlMIDFmRGRl0yAq12pb0bITcDsyZqZujhPk3XnZdRXcc43OY
AFH8nnqHVI8DLsTmwmSBKXRytoJ9h6U+o0BBze3RHs4otO/wlvYFqd1u9NYpRG+KNkBHd994
FSUpx/cBPAoJQxa0bJMWDwpDNiAz3VmOPvn6tj+c7835I4vLziDK0X5wiI5ZXbUNr026SxqF
XEfQMK8t1c5pRLNSjLQNVbO57dYhGTMrHZPOf8GZ9M6tx84YKp9EpPU+1YbTnl5KMhSy7GzG
zNQzE5l3M04+I2dymaWZc9BpZboyNmapzSK5mTUdvMH/xrtONbognqTEtPFM06ybE+a7ppM3
ZTNnLjXPQadldpk34Vlc6Mg5XwW8oTYeettxFY1Pk3oCN1o/p1oi4fVSolJFNVQqxeDB+43N
KuZVWaXqUvW8elVlVYC08jH72LcLFS3HDLPJuQtQu23UKhqf2YzmHWF0S+3cHqPRukHjus5x
lNEn/SWdQtXH6/geva4/pB/Wz+tOveMf3K6JCE6Se51/B8S/dhDRzAWkHmHsZMfVC4jfoZ5S
CRIpZpT2DBijEPT2Yos5I2gniRCCgqBVnN8puBwcCns5zouE0+R15EJBeCIrSptvN4XXCjh7
VnjJF67mc1gd0DXrTx3oYrt0f7EQDhWLJLL4rvLgaCyaHPj8yoF7q1efqS5bsXAcJ1VxoRxX
95UPqcx9qzbCvu0vO85AfMqdfT/+wSGk0xj+XCgkCBRHqctjyFFcj05Gn44ejp6POqNzbkez
CM7eOYQRtMYxD6Wm4VTgoddoOGLjZCXMS7JEpUnpaemwxEoWyKw/2NYmcoBcAus1O2zC3dgO
KsLxhSXcZ3pr3EbOSRi7zPOJ7Xqyz8sZSh4LeYzyeQiBMX5MGPON+ddab45ZRjdLYzbtDBt2
q2rtNiq3W1EyxjqpCdx6nLbKgDa3/R/tBjGzu0E5NIq7T6JU6wp1+cOGV8MuMtxoXaKay2uk
tFHtbo30aFGNcbMM9mZ43MNH+Z/xhOcHwqLYPdgg+6mb8mXsI+VyHrL1957zS8bAQL4B+kvR
uKtBfkDdSjdflIuMhxQb5DdUyYiRcDDC++JUiSfi1O0z4nFvwszjfH5ATuDEKfIg6iYvUk7J
uzByCS7FRVwukPWXkQOLlnAXsjVLqkWzVixmaz5/NZtG8AQRP1u4cPGMr5pd0qyvqOFsR89h
QRr7imIWBiNLmjBf9FdX1Gog8Stq0KYxTKRxoIu1I78C2l4sVOwOXAG9bF+AAqQA9pCVDFgj
wS6YhZQA5siB7bsOrN2/4CepB++sLn78iZh8x5J5fVyGGxlPmEsX5hb0SqnY2tHKnZ9d+aXy
4COx++NaebCAv3rw2aOr9K2ji8XAw2x/hOOWRPqlYB+7aOH6PTv3fn/jNys/ysrpsO+m+Amx
CTtjsPvO+2bjyVnGK1r7kHISMa3L1DeYDEQpQ3VsArkc1IneuRilT76Src7F8D/x7paAgrQH
5K88HrAS4WE00pY89LHf/97czsaYScgII9bO3qSeVBJWMEhXdMba1Ef29DHW3GSBykcsMNS2
gIZNra4d7IjmLVq5d27lCF7neAFVjzBJuKnPuThDSAKzXaGxZBLBljUakdvCLWuKRrUJraWx
mq04ALgl/aG9bgcmu30OM4vXOX+BFh8lzNAs6JAFemIItBMcmGrnkDCcwiiVTZmpesrBp+TU
ROql1PmUM2XZ4GE75YAvlG7/F0D5PtXa5pgiR1AZCzQpGYC4rvhIcXuRhIt6sVIkh/ob/W/1
EzaIewgfwCILle0faTgwaGTFQNhYo2OCQtjvjMl9cRoHUqNub8CIK7JcEocb5GUa91IvTQwa
vFf23uOtex0R4vXqLEPdgsEw7PPkDKKoRDbSnoRVwyZgvZF4kbyCROQmUyiP0mQfILT82M8o
aF5MVgYaZC91Rw734c19k31MXwPHt2VrW95pvlKoCm9GpLPihVqkebEJ5JdOI9EEFiu0Sc8m
tTQC7gNiAyYsnrU7Z30g5DBTr6VtdoP/GggscFxH14MBi9GAxYD1uhyq4jMqXaVkuDNeqUCV
8yHZOaZGRZeYKtZWP6qKD8ijg4X6zLWLM7/97ltYST/1xq4DxbH1w9/Yb6Q2PPXEVuL5Yn0B
p43OH0li7A58esOab5d+iMN/fn3T/D3CjSdPV/yRrNjLZxKrvrz/DQiB1h9mDjgeYkpoGCMq
8AoYK6z1BAwujN0EapQr0+DBIasNS4bbUicf1CxleZHMQCXnJ84ESkCMHPcHjEQCxRrk18c5
f7A3QAOW6zx8wAhQQAiEgsPPQ8pDraSH+glhdd1yDK/LOiMQvR806yhLWSvcYq6gwbOYJyzK
+kO9QjAUslJAPiSHmNALUF+K4EYBS9v+Q3vVxrZ1leFz7vFXEju+Tq59fR3b9/r6K/H1t0/i
uG7rQ9qEltIqVG3XtUu7UjIEaEqK2GAIka4MQQXaJpj2waqmGpuAX+uYSlMEqhGlmkTDqmli
0mjpfiBQgaoVA4mPxuE9x07WTpWopiHr2Pece87xufd9nud93sK1P0yJ1CJD1pGb50Ue4bFY
OicuRYAQhGvpzfKitRKZgshBInwwq1SEGLVTkAXWC2pMv+JwQFQcEBVZREUSWQbiIqISh6iM
QFgqtpmd2z9p1I9OTx97vLXwAx6MF1n94Fe/+9jPj23SPnrkngd2zOKk6kona0/PbRoxyjiF
+67zMLSufv8ALaXjB41eV3Lu2OgY5/4znDe2HDBzuJ0Z0GvgYM2f4Cc2YLYBOPkn5t7AYlWG
vWP6mDTWVlSQOFgbhRieItOwdmRlLXi+6KvYGIaF/wCbWlbzsJA2qEQ7C4UXX94rZYWivgvr
AvaRwWdRifVI9yuzymGF03Nh+SbzKwpXMBbA3kAh0AjsD5wI2AMrbu/QMPowd+ro6q9XFSqH
d9huIIsZUiOZDAaZJHOJv5KS2jo6mZoBLT2Rcgq9//yKh/1wdnmmdYRr2UpMHLN4x7IDjbwi
wdO8dnpsLBSCUm+cuz1ZofyXeaBgkcfxyXFcHMfjqDDVtn0iyRLU3doGXBtDQyiHSvhx5kXd
cveT3aTL0Zvq8gmasRDwzJlUk+kkUTNZlJNzRo7ESM5iFv+Drk9NU4vtPkBFL7h1K/RCcWpZ
+SIqySWjBHNLrLBA/sIG7DrShdlnHpl6dV0v6HP6Fd3eR/QOZXUdDQBlWdjN3HzSfveM+7p7
2W173X3FLXndoNFu/wI5/WNDGXqPvvlSoZjPs0SV5lmxmLOymQzvZFg2m5WB2vG4oDbUa0Dt
eOQWaruB2jOOOYfkQBXlLPkmMqAQegKpq4T+OzeNzeD5OxAZSFsILYpOrRxcvRR6vPRb7ki5
GMP77sgx57igtRDqRmgROrCywB25kALRLxX3dUR6hf2c+7GO+FbVtsU0bmM+dqarKjShALIv
snnp5RPb9kxkZ0dfZOsOSNuP3Wdv03/porkv8TA00AEpl6xt+UT96ZH1T81/Z+/3Mlcf3ZTN
7OwIwM3mRHDiEWiCS60XpCy5IY3YhwSXSuCpPKcljHp9YKg6fu3uZgGCn7oNwYcwW06gGvMQ
CXSEA5i0Ecy66mvpOIvF2zjucgfozPjyuMQxLEoYgWHYxHY7itGwZLsjjhOAY5SUkwbg2FGm
leEK0+Pww4aZotHh4WwmZ+WE3MMwRzfLV9pYRhamxLKKADNeip2C+/9vRAeGK7RMGRyZslSO
0jITEOfMhrG8YDaMc7iXBd47d4Q9KsGdTJZlWX4DzTLdgi+ow7JZbxkqs3L5rhlR/QCMgE6F
I5rfgxQnGMFrrdBK55bxu2eKuOAka4/CrAurQ23utLvC5HxQ9qTvhkGt9eYD5kZoKrT/yaJf
TkQmHoWmQAO4o43Li4458guURHtYrMtIFemabjwh75KlQDBoorRp79EHdEsnesiTCC2QN5hc
DD4ZlIJIwV5lXpGUxBnAiATGD5R8cepaX81Xg8p2UW76alqhUioeOmQlnfx50yl43tVPpQxv
Qjg9/gFXF3PMLf1n5gtaGJNw2Og/uvbhzLeiUSt+b8+6ddv3qlb5uS/ts+9qvtsrG/e+9KOM
tsVg6vNmPHP1ofxXjmdoaNu6QIQ/0XjrHsccuLUQWs+C/qDHR13duOZ5xHPUQ0YV3OXX/JL3
Z3BmmXwOaeSNUxKSw6oDTnyxCU/RuAZ+Z2oKH7Ls5JZTo1jFFzectvcdVeq3tI1T+Li08Ne/
tb72+9afLz0Eh3yh9S845cT9b6U+/TH88daN4rqXdlcjoDXibdvOSyMOJnJuDdvAhVRewSnO
YrePohTkzbdYMJWSZXAjlm41rP3WnDVvvWxdt1xWx5m0c694UtKC3T7S3o1sv/kOSpwBy1pi
/oGB3l6GDa4Fs8ZhY964YdgMWG+J1I3RIE7iwxLPuf5XwaeSn8IrwfBKGtdwQf5NqYhjvhg+
3Poh3g0TZYSk1pAthd92BkDR1uDxM6gIjjcco/1cyqx+lfa73L2UpEezWZQGw8C6ZJpKITOk
RVWVOfuoGogxIxqLck6Xnf0URXGQRGMsxkCUlmM45kembBrmSdPWZZrI7ZbLqEtGBZwgBcoo
X1Z091OaSo9GYS+b0dTwpIaRJmtFjWmTWlO7qDl7iIYJtkz/KLNjzBclAir1Yh0XMOkm2M1r
o0CQ6h7cgNJozjPvOeuxexbwl7/OvUibu0JBkNwMBS83m82+mnxJqMEFtSZfqJ1bzY0A8zcX
oaYBedg3tdjRn8UV9YHry50MLLSofRfmLmryr+D9ck0ChIHymQJUfg43Tv90mlZVUAVVcabV
8jBNVwNtdw2ccVJBmUoZv92aNgfi4wfrD+ak3UufmcRk6BvTel1TfbrX8qj1MWckIPlzgdk9
ax7cNpK2tniOj9m1aHQi6jkS2cxe/7d7fdUe9ti89Zjrj2U1HtlpL3x21/O4FCk7IIe1vg3R
/iJEmyAnomit5GA9KVe/QXtd0Rjt5UF3+1XouRXqsDEbf9OsP0RtEiQM8D8UoXfQDUQGCMoN
G9FEjdVY1KTeWqHWqO2v2TyklvMrWl8fh0afL8wGtLDGN5GdOtXCLMxREZYjLMITCSQ+/sum
OEcickTaiTqlKO8ZkRORkxF7VySSoz3eaCHaiBIPieZYjhdWOW8JB0s9qC7XjToZJHWTmcwX
pV4TG8Q0q5EqG8rT6iAb5CSMp+mg3cn/a208RZ12ZmfBELUTzKCLSZ9PC9sGmgqeVDBSZKUI
Zdyk0lQuKs4eJS/DqYIkkmf5VeDl9XwhD8DLUxdzCeC5cMO13zXnmnedddlddwIeRw5cNOVL
HdRdhGwSlM+tJJZbLgWyVhZ1MLlv6twqEmWOT76LyEJ88HwnE74PorDnSnEIS2rv9S53FrQR
a/VDTnJCw3dEa4UCnk2e2SplNeAHSAtokxTPfZVyK7E1rie2JnDlDoD9XXcmep9ulhq6v/WY
QPVCIBXJ+B3/rEfrm6Et1f9LeLXGRnFd4XvnznMfnlnv++H1rNe762XXs2Z3vOutoR4cFgIu
Li2hBMPabeXySHGApDQUqq5DpErBjaK2/Ijyx7SVmvyjKqKlNMJtRC3ZYSmVjBXVNuF/1AB/
UIrw0HNnDbUTqu7q3pl7Z+7R3HPP+b7vfClu1USkXy0Vh8pbz0Nc4x8l25sBqR4n2CRa4A4i
N4qi48ZzDqU9pbtoZwegMIQmPRgUPB4Dztojo1bEyBDksr9FNJAg0DMSDBEUlIBHhJowKUwB
7D89phVYmJuv49wc+Ki+ojRWOckNSS1AWnfTnF3xREqnXGfl8cKhH4bTPnV4eG/AlcjGA+3J
vRlXs9OrJDk7m9yYdgpnetLr9O2DRoetmBH5JrqjOOxoif8dYG8RXTVeD9svtE61MqRVkTns
4DsVxa+nuU5yN4MzNyHxGNRdcKcErs/+dTtjV8RwIMx8HsYfhRfCn4ZJ+FTqbGo2Rd4R3hcu
C0QSggKTcgOo2F1CdwzUMmFRJ5ZIZ7diKNQfiuUPBY8oNWVSmVJYZZU/6L4tT/jL0y5/+fjx
ahniDeeWqv7yXLUOvSV/aIBVXSCI3FQBpTzUGV6qhuLdxRLQrOUzSxZRh8G/2E0lEg0tAs+K
Szx2tvV4JYe4581t+fVRP7CvjWsttSrunlRXT388GvY02Xv9LZki/71ElNecrx1MNPsVWRhK
n030b4yHQwzrzkdOat2J0qbR/vEmf+9GIWoTzYFke5QHfnsIiMfznwHihdCS8fas959eBthR
8apew8vaON4AlkvzZZ45zOMc38cz/xZxWiyL20TyWz/GBA5KYRiRMIxPcrrdrNMnIAYTg9CF
iCiEsRFCAh6P5JadhjeoOyUkq/JO+Zh8U74j8xKRAxRwwOOc5XEOj3A1bpKb4ljuGR6fmwYA
KMB/DQiUy4AB09fKueZysyV/61SGVqvHqxRlYDxSpUmMBdWllyiZFAttEJcC6/XE8qWXNxzZ
gNnL5qXf9GRdJf8vQld2bIqYZ/H6zHe4Xx7ZcMScfRU3//VVFx+66OBO5P7+IXju8SmIzglu
K3jOjl67JPKszbBRBAz4E7rNIgR/m454GycRLNlhi/RhNJzQOUkw/n/GNWDLuijzdYpWOLcG
zG5B4rkbopn2pRZtnzajDUE/pHHBfdq+8/vW79GgIWzuhVN+j29DXdhu6FIAQEEKuHw6asIh
PhjoyOik9Vg7Ru1KO+Mi7RlNQ5kOugOXB3bgcKpO+u2dTT7dKV+wTcHuoLBjJFuED4X4yeCF
IBPkDb/T4RCDKgphGwlxbXRFt71JB1WjKRojaYTraEGc7G5159wkQNwr1CBaThDxE3ZgxS84
gZ75taVrrsK14SotSQIKDYNQsE4DIFjHtKqZrlLhHVD+NjdcrVrgHVTqlDEsML/WeDgPy16p
Q1ggKzeBGtqSVIl4LPBeKUoAvSzx4S2ACCmVaOkCjJZs3OP3epJGZ2Xw8f2XIl/bWqw817uj
uK6YHff6GFFvC9iyAfae6Fdnfn3iV54zX90Q9QfUcv7A+L5v7WiVFXfIr7k4RedtstGzASER
5c2aOAtqo4D60Ga0E72MTqEamkDXjIN7v5I2tBOH7aePjrH8br2rT8OahimxMto30FtDlcRm
dfyQ/OOfjvo8wwPRLhXHVIxURWXU74Z2b+zaMzwY3T+0uZTOPJ+Ix1Ob+1NvjPoOvDLGfv/w
6Tdl10m7JDlP/8SJcks3QJwV6jfzdWVpKZ+Hm3z9C5P1AtwUqO6DGsEa5euL0JRFGEBsPmsa
OIEiHriP4hsfUylFUi8mV2pAWvYB5hVjqh+uDTf7MCUMOAc4hmKKcoewagLrFC/BWswyCUWJ
gqmJGO3QmqUx6BOrJsTZQ6MXyWCpI3bP/Jd5916sozRILo4eejqL3dj1dNYc1FQ1p8VUbX7u
7v25ck5VNU2NadzC/hcnW+I9qUcdqZ54y+SL+/EuOiQf0yHeZX5A36Jvzz86OXf/7rKb2qC2
mI8eLM6/2ySXdvhqNd+Oktz07vzigweLt9bO3VpkDjYMaIWxMXfjG7RHHy5MX51Q0mll4ur0
gtlnfkzvcYc52jCuNY2NNz4whxwQUzPiacGNZNSMvCiAwqAGYqgdZVEO9aKtOGlUHOFIOBsm
jkAkkA2QlANKHTyj4JkQ9oTaQ8y0D4d9GR8z7cViCxbiWOpUoHSSmZwR9GVRVs0yCsnS9C6C
qMh2tbCOOLuhX5VF7CKixMcMryudNgSnni72xxUHVB+2diPgSaGUmoKlKbq0AEtT5U6kimxf
pUVmYSnLMVEj2JzJ0KWZAqrgLWoFKxXcVTlfuVMhlSe4ALJu6QaVJI1ShQJEXrntL9NJqv6e
zFfzwMc3MvhZL+K1LwImAHCs/DBtGApBqAafXl2xxh+7MOcHHvHjlAAPYAjPU66EpxHfNJZX
B6142pw1n4c2Y24zZ3AJ/xFaEV9+eBTHzE+4LeZt3GbeXv59/fqjLfU6uXK9To6ZP1j+h3kC
TzA5/DPsv778aW1oaHx8aKg28EJv7wu0MZ+tsWf1dGZ5q2XzExx7eIXaHwCTf240cx2eME8s
36SGcaBuHqg3bNaGenftomYRfnwJGG2A/QD4TDMiCJgZSBwQmlgITfAIqZFJMkVYsgqdARao
uvnv7geyra1Z2tjjjWsWLP8BLG9nrwBXgmUCtaqBqWVsWcZ4BNfwJJ7CLP6SZRCU28+dY5Pn
gMXuAYsp3BvIhd4yFJngCEeMWBy+ryOvy1CcXWxR6fWesUkv6UhWQGaQJk4mgoAMzBn9W3Tu
poRlqVXKScROJBfzP79jLQct/YVSDpW9lGygmitb/JGxwgigLtYdo2hVXBFxPj9Wlu/gb760
26MWdpYr0UJM8XWwyTNjwgkj0tNulyXwCXAyep9/B/Lz539CLY8/N+KRGEgCyRNEclA9GqqF
3g4BkcoyAkJFUSMU9ESjNHfWNQf1qM9AESXy7cixCCuRiCTRbUjWNiQ8Iv2H87KPbeI+4/jv
5Xxnn+2cnYt99sUv5xjHiV+4JL68uAT4tYSsAgKhvCibGl5URimdBkGIMZW3biutENLY1tEV
pKUSbYeotK2QQog0wR/QblNDKxpFVbfQCaFq2hSpmrRVW8l5z+/stKzrpLKzkjvdPf6dn+f5
/p7n8xz2jHqueATPPW7U2ubMNX55fSp6/fPZaYp3U+iW0CandAfnVfBGDPGqzCGVZ5aXbFC1
lOVOnl3S8+C2tqSrXowqmi92vDnmb9C1/KrF21xHPH79+a6uHOvT1phBbYlaVDqDad8LJysV
++v2evwLNEg1cSVC/1qIPK8j9zh9Fi3tRBCP4xCPvcJ2qFx7WMwlE78gKYhJbphUFJYZsBQ/
cUuyizlzalPmhCXBGJChLkK478TxneDN5DAZJVeIQP7D7xpJBct8tOMDJGSSh+CP0euA76Az
LmBwmrvHIWBvphgeUOoCoh5XVqmJhDCYa5SkTKMfcBch0OGY2Ic0yN1blwEFP74g+60GUN6F
UMwKcQXuBHLS5ZxMumg/3UipoiQVE5RIlRiLMV/AinkjMHgZouJNek0v1ak3wRLME7DgXTpT
BdFAUkAiKpUgt5Gk5RGYwP0UHD8FvFk4LIwKVwRB+AIucY+nq4AEruvgsvkZR2GT353SZ67X
GNKR78gIV3KDM4l0c+fvnWal6hSLx1jfimVnGtYt2fpEyPd4rMkyo2rZ32r0uSIDgxsONnYf
oHt6l61bXirrqzJZyCePEvlEdMOo+Z2LqopiDOQIkVnExwIPbhQ8OtMNWbV0XUn8UB1ViRpS
FJC6kiDsf6T0S8aBGUC/+ntcrG7RSQA+0LGUaqpKt6s6k3I9c2VLIO6GUop88t25qUf0gMxi
ZXVZWzDviieyeW/D1nKRHBNO7U3kfh7yp5WEd0XnrnJo0cqGaHvc60eg5GdAAQfAN03cYD+D
+KwqgXr/KV6GCpdAd5nXE0kDYy9UwpYITl9UgKPBK67crBrmTm0huwkcgqzrwq+iV4CgNaYI
SYF4qCDPE3fCIW4ZszaKEW2juymULep2QFs3dKcHA2IjPQCxpCrV3SoDmP+/GJvr5lp1ngJ2
rrJ1de+M6FCLP4fqahmpErczhI3sqYqJF4583hmzHDH9N1SDnh7lo5anu++og9Cd/cvLgNCG
p048yOes1U8t7HHgefHiRFhLLmrf/vSiaCtDIuoAPZ0WjwM1B4FqkqgZFdF77Ckjm00llSA0
q0C9Ud9WT+ujUVVC0K8fVNeqJKAaaptKVZTEyVSxJdPaGltQ58OCN6mZ2lKNao2NYaoAoiTD
S8NrwjS8KYaVmBkjsQW5Zj0iu1pamnVXQDbkQZnKEd1NAn4B59PxUB20iByEcGZ6BqYzrQwX
w3xQw1Gzgx/TEbgxPDMMd2EHwnnmarDMlToZDTjPZoa/5Fl7WyqlBinGNKhirAWlVDbYLQF3
ZD1Ug1P1ulvLSlqwFBROf/rCnTvEIp13TtpRW7/5En3ipR0n7dJJfABb9tv25CH8ZGbI/nTo
g1dffWXFRewiqzAlPXO/tefmxuga/Bc7PDv33KVLZP/sa3c/oM2v4YP29/k3j9/9G607vnUu
Qv689cMPz51bO9dBblQqlSH7l+hsxcaa+A2o4M+h4HnQJcjwglu2gArynZ18LwzxzubaB3tB
Qs8zmUouLIgCzJNcsMGmrKVAAk1E/RSJzq6osLpwo0WQQERBgqZOnY3CDWmSmhQMqfQVW/Vk
TcO82GtlbFal6dzEtZtQ7aVqDM/CsQMO4UbtCvZ2BboUOovehC61dr5LeWpdqlJBrHJI6hDb
oa6/AUVOcxWFX8P+916kaGCl6mM4/9WtKhOVw8Itx+pS1YoM1awe7r9PK/5G9xHXe2D1m6qV
a33NqvcBl3BfVvyNYsGxulJ7Y6VmZXXcpxWy7E3Cw+JPwGqyaoVPoJOonaUJ6mE9pNjTVRTY
7/KYdLNc0epmjc3wTwlaScBatJBDVucwzg87a/XbOwVDDMFaN2prNaF+1P86scYrR843dloO
Hck+a9DabR2xTlgC/JR8mm0s7CscLUwXBGKWcIl5fFYJWo9VQgvz+RFneXhL1SN6S9wO679T
W78AHtXxDv+nsdZWSeJOVe3IbdEHdu+CXdhV3Faz+sdYrqVQdZ2iQ/b7dIvQgJqgVuXQu0zr
SGI6FbwTJEowGSR1QmuG5Zql8Di9xsKaoTG3aWmajnwG/EDD5wbJj9Pr52vbRgbZIyS9o2N9
nL7FvKrUAt9fsAC5tXF6aswIh+Ng/lMWNnnrLbjdyXO+CR/xQG1DcRy/TEeRYs6OlEaGO0pm
sGQOz0K90aOzTgXXJ6cnkQmP52FhYLZeKzucFDGdhjAwC1RxVZ+5CkWeo/DmYQxtlH+yFkdD
QMR6jk6a1FwbfrSuLhxMQ7lKB+mWwdOPPTrQsbW3SX9oU++pXSu/9iQ7aj6SSbave+zQIfsP
+/GO/eTsR81txeXFXeGHllkbNm3M9eDw9t7Vtzrb05qxvNSbnrtpP45f5H8IopuyV5PbdA9K
oyzK4wFWbjLqFKshIitWogVa7LHUROr3Kbo9tS81naLvJ/DfVSyrO1UCLB0KhIjhyjWzfBbJ
8XF6kfliRoxpcSsW06IGr2dwbUD0WSjKovxBNKppzBOEBEF00xP0JsJUutCaYzlunW+znLMe
d84sCRmE5ZVMMmNmqJzJIEnReMuBSqZpKDZOf3zJiMdRQJalcfqz8z7mg6+94a23fD4BbjA5
wOCTsAKoGLharWEDs6X5i/nGy9MHJ8gHbx7QlSff5CTHyxxayu15i4YsliLzWf1CSs35nHI2
5GmFg6+QbRJCYaB/cR7/OT59NgA4eZ7PLbn9vUv2R9nFjRlvs98y9FCjMXpmsFdfaLUVnh5Y
9vK37L/y7OIMXtKy/+amvvUdP/hR6eVvpsz+cqHjgfrdLX2RF185dcbunU8u7PMhTMi3gR7D
1O2w1YQ9Swr0Y+QDttrBFA1IJUIiqp/FYphPEMeYx1CkpGRKVJqgBURpaYwhA0Nsx5nXUNym
m7gjAY06ecM90C5mb70NewAC+G/Sqza2qesMn4/re6/txL5OnDgxCXa+Qx1iJxyD75wLZyPY
TmnTG5FlbTM3EQJUiiAJg6qdaJVOXaf+2LAG61ZNE9HEJq2aVCCggqZt0YT406awqZq2qhJM
6491Uxk/YNJUiPeec6+NyfZvlo7Pxz33vc/7nPec87wgF40b0Qf/Klb3wgerHxaHRVIX6hDe
S9VC3QQXeIioQjw2k4EH3yMBf3sobU9uaLyS6d86mm0biWwO9ZwCX42vDLVbt2eP2T99EO9P
z+4+sLsr0ftYU6qnOy79+Top0X7UhgbR6zzSh/rn+xf7aX9X+0BTQ2NCy2pEo3Dn/JC3H4y8
HHkTdAqiBiW0qakOpepW4hiOiMaGwGX6B15f1x/si/WRvkibp67tV+AgQnXSxRufG5+ETPDF
ePDhMGxsUP8G6IzkB0WzCHFT/OOq8VHFV6HxQf33gvTvCgm55ig3IZq3/A/fS8MrmyY2NdXb
J5999qXCjoFCLuzZYx/q//GjNPxg7+/2HzuLjS9nvtnwl/nDj786tef+6+vpgHwqWT6Gr6F9
Ui8w3qp5VAX0LohjVZn3YM8ZDWsaQTCUXDXN4eTC6lETbvYtomdAGUr1wH2uCd15bWspsxNK
5uDAwe9AESdFdu19fL38J2ndj25yhinY5m1xFiQ4RAkcsLwwyRC3dsEJq3r9us8nn/rgqU/n
Ao4i1TgMIgUGFZWrfHgXU3lLB1NV3ad7/dwvDoCOXiZqXtcQYX4/qB6PJvPV5e27mFZ5cOMR
f7YkK8rFNOFcrraFg4lqlpbAEJzmIx25rddNGEp5gAZPhY64+a2tmMHfJJQnZrtnvwrlBBTB
S8PaZ/hT9JLDC57iI36vT/fx+hA76TvjI6/68FO+Gd+cT3Dwsvam9rZGX9CwqY1pz2j0MQ1T
seVIg6fKj3iVK7ZChhSMFEOJK7TZ4aplg6DpDfwWJvvxcUy24hyewrQHdC7CBgYjFBMk77md
YKSElhB5DWEbzaJ5JFZLV9QgRIKm4bf0n+vkuP5tneT0Kf2ATtM6btZ7deLTg15YG3cleNPQ
NubnnT2wDGCZwhMKClIshTfAgPlq3iMiKlHTk4cgLMRq0Q0ycSZKcuHxjPOwJVnlff1DMVwd
dCJTqM0+sRyfPn72iUUocSiZV/gra7fhbxsU2APnyyfwblAzYjVO8CFJKu/exhSuqpIc0UGg
j4OemCfpoR1UhBbfW2Iaf/JrMriWCwUnyIwNXUxE2CIt0SVKZaAtiEiDs73GU5xcdWAOCwVQ
izgi0A51Ptf9IpTBXEvudSgiZg6X5/FptM2NmQBvdmIm0sp8vHczq9ktyzAmo6IexoUTemWJ
xRO51K3wBIH+54M7GeGxBPw1tDJYbF3M6t3JdJkvNLUyWH7N4+GxLlbZT4NbHFe7ol0sqGFG
ITTENvSKSSIG4OaWS4+pSCYuwqikQV6AZuVCdLtiQcUWqh3DcnM5e8xZ7MTDbRetdGrGHzIn
1/p054HOUSgRKNFce+41KGEoQsduwj1qQD0B+nGz0JnqEfqCehZllinBVkU+rFgYWVY0ymFw
hDc0sxHu9bO5kTMjZASyHRCs6bQQrlA5FjVdWhx0LRoVixNVixMYTUwEAsKiLSza0qJ9xib2
f1vMoAkyqBwmW8kvhEXyI4TWvotaeRCjeBxCE8+34VQbboM3i2lH66/9XrmKByHRi6A/r72D
3hZCFJ2iNvoC4qVxmXoQuUL3wFjyc3EVDaXS6Y4map96/nn5vVPKO/J7MjNRX8SQYaIo9xI0
PDwwwMmQ3Lt1bEikmY4Ov4dO06vaRvD6C6nDIflE4UvEtks2JJX3Ltr2oUNcJA9y7ooyKefe
r87tfo/Yo7OjpVEIkXs8MDo6M8ORTWdh21AKyUfaeRd1llV61fN39zsRTxoP/DuAuFD8v+F1
MzOGwUmRxztZUWDs6XPqDRtlzesbm1iqyIv/LJaLStHJaVwPULSsKpNq3EUFltE+sJzk3SQ4
uqcjxsm0MBucjk3PTq9M35j2pKb59BmnOQ2mFhIu95BlABfqVBWjiT4pZ9DweTImMMTrggyN
LY4tjd0ZU9DYaH+ak0luNLLgZGwyOUknBSxn9QUqwZW05aAy8QTYmuIhErOSFjGslPi7YxER
rctgRUZtDyReyBoMD3JSEKZjhWSBBAuiooVHaHVxJxLFhaNpF/straOKfSu+hfehX54nebnm
ISbqC63tkN/d5UZ+NI14KpMyybnMOZMgd86IW2fd+ktubbp1xq23Cayd0CCxfCq/mF/KKwY0
ODRL+et5dTY/n1/JU/nJnWmJwNrOHCR+lhc5o8SdcH7FBeFIlTXpxX3Xi7vgxd5lciML984/
uDebGRzmdgqnBIJubxkQZFPZxexSVjGgwaFZyl7PqrPZ+exK9k5WyToYsi6GrIsh+xBDsRKh
wODtGgY3kz41h352nuTk7vcFWI4PbWHlHPbmBH2xTMxMZpLmTGbGVB0Gyy6DZfc7ZZfBsstg
WTJ4UcCWZNgTzrLkJUe8U5DEo3H2VP6c4G8u/y6weTOvBPOx/EloKnkRr0dl8LvUiXhzonc9
d5vxG4D/ObHD/sq9mUwqxZMOcRKA6QIwHQBmBYApAZjnzBWTzpnvmtfNm6YSNGPmSWgqZg2A
orP/5K55yJt6BN/VxtDKskLJuDAahANncbw0Tvi4PX5nHM6Jj3jjeOH/YZD7oAH2b41hsTUv
7E+LavnpZ5iscwVZc++Ixcb4xrjba2mDXkPYmRMw2JiMAflbgAP7IaEL7vm9jlH1CEmBZ8eF
Z9vFZyGOLpc/vrR9O1CbqoVlyTsIYFkuLMuFZVVgWQKWVYFlCViWC8taBwvLW0WeT2s/qT1D
1TlcKl9EMd4A30zkcg1BDo08D4TkFpNXkftmdO2z2jNSnSNPw9ndeQHmXy7/jQcymUhEvGyJ
l63alzE6insUv+cS6sTaFdRW/pj3haMMNRvNxKe201hLSziq8/YO9lsdU10P10s1imms/tf0
fRRDUfoNFKaHeLC9XfOjoBEkPk+wJQR55fffExpjY6cj9+t99Szox1Hq96NQ42V6ivvDPMz7
Blg4xENiRtvGXoZCGIUMGLBDs6FSaCmk+WgohFrgdLgFJjaALEXcCwd1N+Sk14T4kMpCapMF
V4OI/ydFouoIlmoXevDfmkQtO3b8h/SqCbXkqML9uv5O/fS9d968efMT0Dd5ycyEoBOTmYG4
8Yo8FxLjzELdZCC4FQPusssqIpqVC8GVS8GdJjARVIxgECQGIcRNBMX1gAjibpLvO9V9b7++
9w1vtOpW9+3q6qrz/53zu/uL9569q2vuajJz8TouqPK0TAhXDh83qONY7h0+HvbP7IXD1ly5
euu5Z/fP43J+3+Z08yvfv4oiZVb8udc+fe2Ny9fL75ev//SPR6+eufa9z99c2r8svvngo/hS
mf1z76MH//j5j3de2Hnl1Z/de+H5128soaTmN8098w7kfrH5ya+ai2Dv/NkLNy66p1wb5eAL
9mu2tfP9nWj23zZ/+uVS/K/Nt5uOwv74728icdt7++N/LffmZ28c7D2z1zZ7iz0IXvYiS94f
Lbtu2VG23e5uEy1m3jTNY/H64sMPVDAjIT2vknuaQnn30lfv4+nd7166uHgPsoBA9/w5CiNc
vXX21s3n9s/vn1sEFYB5xz/xzG//fe9Lf3jty0+ntPjhiy/+4LPf2vng8l8v21ee+vN/d77x
/vtfXH7n6w8+/I90j9FG5xpHDlaZCArJ5nPLC4gvh80TzZPNleaqvXb7ydtXbl9Npr2jDrgL
B7z/1p07h4dLdZPmbt2JfnuwylO402d+0TCJXe52uzcW5sC0BlXr0e2jl48w/be3jo6QgBAI
biqK44PmAgrZN/J+bAwKMO9TNBZ3Y43xq8YZvBKJ4n2M1ktALo8RvEgJEiy/xc/xGqwNNgV8
4ZwNTrgB3uNrL0nqjq5ui5X6GNCcrfMi2TqfY78SX4EyEd1ZZ7JIyuKz0uW8oNKx+BxHYFbq
timBWrE4V5sBRcEFb7iAuyC9wHsfPaYjOr7iK86RHC62AsaSFyeoW1FWeD4HfB1iIqHYDmxm
z86T8RjkEVvIbGA+F9CLDZRfMT5alSIoVOLYYu0hBts30EwaKp2klBUVn9gL9gO7GfvZIuxC
eSmJ/BgVEE5PEAM5goChzRRBAT7GIxg0VCBERV6dcixCowBRoBh7ZSgJJoEdBMdH/EsRW1DN
IUopMZOMXqvUbpBe97xHskLrQL3mQBCe1Shy9nazeQejoE0aR2Ks6YlylFowTjjvqEA9kItt
XasXrtM/NHls59rWtNrWVu5po5afq27alZI4ghpMpd9JwtJEe5wqVLfc1DNt9uQGZYiDo4LA
1sBI8Y/nWccrhx8TSerRUgqBo0CxHKsFsAEO6ApeoX6J9djNqjKNfkzbpTRhMOykW+qlNQMX
rWzj5DSN1nXCm528D0sJzaSBgunUZqseuqVPmwYAv73TNeKqDztw/eA4otQFR4dkhNAAwFUw
7OSpFwy2pm0RWdq2gSlp7wXbK23b2CB1RPHx5iZtUPdE5apoMXY6GFAHK63xu45hbjxoHePh
/UDocLduC0XVhHgHb/DmGNteUaXUe2shR9wHmkmtYzBW8UkyjesNcOhkqFxQLEIwQHRixJpi
EVijPyFeBGJRDDkSi9gwTSwKD8MiZ2jw0P7DsKiSgv07eGHhUWQX5xgGKiznM9aDq1SiL0qX
P45FhIsxFtkBixBkKLXoNXYFjX2M7ZgeYVFkQNT4DjelsVYsQufrHosEJHk1z2BL8eygibuG
+IgNKkLDh6XLIAewQH6jCcmNsEhJ2opFCgqVzp7SFRblikWQI8K7sFcs4rGKRbkQCWnKoBvS
ALAASKjRlLALCKA+oNbgQ8UiHxVRJFTZ+lJSJAJxi6LWmBWLICBYCrAImpoNWOTUPcgIN/L0
KhiEi2GFRUml6yCPbVjkB3+qWNQT56s+Cd5jLOoX69pqlgw4fo1FXrGIESSsGhZANHFQo1kp
SZk0+kz7cy5mGzhkQ+HqZZt6phpObuBdmB1pJBCNdDzPEvv1H08dxhComMJwdB0cpqN/1Ebr
5eC2tHOOAYsqwoEBRwvRfWtyFduWscSQgYELUyf/h1ada+ubtlxA3NjEohj/DywKk74Fi8LQ
NXFbP52IReKK9HhFt1K/IxYhzh/HItxN31wVbK+0bWOsyKlSH45Fg7qPq7wqmgY0GRqMeisd
rIBjmBuPKRZV4GSr9+pzG62aEO80WgTcNGBR19W76bFooJnU+hUW4ejGTVRHg+wuJcWiEOaZ
AEEssmsvrbypPykWIdwg6iB0wfNjF2smpLFLEQMPFYv4NGAR3XaNRatsYIxFSgq4mgGLOoIp
J5C+Q/050sWE0SyAq9TF0CldxKJKHwjuaDHbsAhKUEtWLJKKRVjCuC4a4qlT/kmKRYo8PRZx
Gmn/EOP5fapRE0+u6wI7T6YVPqrXSscGSrtZITkgLWUgQ8hwAPwq/vRYtMrmBp5AMw5F9EyK
RcrbCos6Yk/0HYo42wk7XQ7JEpoKpMeiGLUQIo6Ae5Y5UbGI8ibkamSjihyTHz7gPCzDXl3H
OohsAFSp35TrFkgVYprNoKU4rx7jk2JRrHsNWAQjSXVG9aHqp0iPe2XllWmK+pOaC1G1urHC
p/Ga/1WkpdXUxbpWL1ynfyoWOT/EjxEWgVNwTrOjjJJJfRM1JjWYJOqbKbvAUV1w3HTP6SQ4
6zbn1g1bRyWImShPqldiESsM+pYafugtV1kdkmOImaJOa0ilppDWp/ptTfJqoNSvNQ2ksdIa
qm2RbsYS0/+poknbODlNq8619U2LSAPzmcIMKDgFFkW/vT8yFsnQKxLFbVjkS1pjUaw7EIsY
6qphMmIew6K1YE8cI0VOlTrNvY63Qd0TlauiaUCToSllb6U1tNYxzI1HrX/WY4j39a7kaZ43
aZQU6eRVGEqy6RU1n/VY5CBHrZMqzaTW052reRGLZBOL5p8qjdq+zFGUOMQmV/mpDZkgAs6M
5yXEMC8lzTPS3gx+Ew6JzrooTsOxyjzaohkqkAgaJ7de+HEuufcY6aFifUhkUouR8xwUzLE5
J0MuAj/q8MSwSfuZ51zmWeaki8Hb8C7ROFnghJSq6goD7ajGhbzg8KCYeXvUTIPFAkSZ0bEX
b6SRRmppeHxdJPvMSsAlrS1o+knrTeE+bj4XdtCk2JIfscU5Gz6cLyBdBXfwi2KlQ0GEikhp
6n2nFjcFHQm8drEFcd/WSVJKOnO/kLq3GblFETdL7ClQszxWE60yk9IViAH4gdouzzMYi4wY
KPYSKzKUOyiFIONIfVFShSZSEnATOYXMoSRolDJP2AwPc8g9YmKWSt7dzfOUzlC2+CXWTaJI
pdEgitZNnlom7lmUmExExUOkW7MwD9jF8U6NxzlNTKh+JgAAb3UfRdq6IxfrWlf9PQlXaBRk
VDZ9dtbKyMxhe44EqW7MSkm0Cvi3/te6K3dYipFkqlDdc1PPtNmTm2a9CriBsFRzKYLGEFk0
5+vHEBaG5HixKIVjxQWDJwa3pZ2rrLQ2gsaEu1JQTCThfLFGX9INOlpcjB24MHkbJ6dp1bm2
vmkRaaRsFEGg4BRYVL1hs6+xpXb6RpHtXX0oDr3iUw5cn1edh6UwQ2aVueaY9yUIMq6wyDlY
UbPKDatgt0DDNkVOlXq8TSP/oO6JylXRakDHhwaj3ko1TvZjmBuPcd2khYQMYZl3JW+oF8aN
UuEHvCZ4cykDFp1Z9FjkmyZqnVRpJrWIQX12iaMbH4OMOxlaHCgW4dzFyVhEf0KyUBSLFgwl
UFRmDOuxSIOO28QiWWFRqQijC7djUcSuC5zH/ZlwQ1qRWFQqFsEygDi5LIoslC7sfwos8sCi
SCwqNKyoWIQljOtxhUW0tU84r5LtxnEk6FcSse8QbdWr2xzmMKf5/6+biARgSrS62x5AECkK
BBK5RWQIA4uAC2q6rwqYE56wKFnmZ87JxbCbAlUgj/8waKFGNuTPUrNkcWT6aMNmIyiYEjj8
jLUjnh6xyLoj7CDngUXAAYNj0AW27Ngd9eToNIJFMduY0sY8K1hUgh9Y5AN2h7ZoT4DDxrJH
AOUTiyLCFJmtlDj0DK0X8cYysCgkLNVagKVaIKEwFI7hMbAIwtLONhoNNJ3EMETDf1Up9jkq
DyzaFhZJjiUbMLQCohwGEiyiVicWbQOL7HBLzNsOLFJmYdHloUjdcIaNbhckssJsVBkTCe+t
iBuSshzOhlOTRc8PYYLy9dnR4IvevMAi/ZnCWK3OMeobrRc5rjUEjs8woo9icFnnGLmzjsQ3
QPsqIK5Z0GJdJyrHKURofl2ucoN2Da9O8p02guvlP7+QaWz8UgRB8d/BIvO6fwOLPtGH86Nb
feHMKyySDDexSPBLViIWub/DIvu3WPRgyLNRn9s58y9zP5t8GJoOdBpCKaeX0gPWWM8exxmL
6CUjIsaVMfcKi8SFeKXTRrSFRa0eWERTL5kprVELi0La3vR0wNWZ4eu/omAR8CsBBJHglPya
DWkRCasgwSDzJHB2Zq7oIwwlOcwpcDjsw/Xo/Khpk5yCvDoSky7akkKHePA3QpRSxybIfjJi
rFigRiYFOAISP7gcf8GazGa2eh9rsFX0CxJ7ET3bi+I/aINGME0q9ckvPBM1sMiy+mCMbphi
kyXOSGpUE4vEHQUE6IhRXBBzcD5xTAJETBTUoKBQpVp2W4MbFcXPGkyEhhdrKxAHqA58IBal
hUWLy6HQsewRfZ3JMnF6FeQhJeURV9AVlJIApgpsUyWyI+RgWTqNKCQVm3JGfQQsiUpwJEap
XeGgnrBGA4JnWNKJceJApwgeUEOd15rwjtjVF9gtYBMsgeSdYOjWYvWhU7esgrTohw5MODMS
VdHqKOgEX99wcPIEXatVXxtAighkBVroYiRsXIvwyUJyICeVSsfj5FHZ8cvIPLl5wqIruvts
OClUgwQlOorXOBt/kmvKPSykdczKcngbT02i7PwQlq1fnx1NqNYgZqCL8E3WYBBSL5bLXddY
FDWDXHBAzZHjgNSBRVgWUbtJBuK6A4u4KkMPlJ84NVMB0siFueTKA6xTXMfD/6ON4HrV1C9k
Gpu+YBEk+GcsUn+FRecuCcC+7gyN5FY/3oj2wCtuJizODdrlmQQcqRNCFBp0Ay7eqFRi0sKi
qdgXZcorQ56N+tzOmX+Z+2RyMTQsfR705+Wlj1i0nj2OUf8cw9pt5n5eRTzheadGvZAS8tvb
hHadhuptkoeJRUvmgUVqG1gUM7DIP2MRyIHt/85v5Mp4pyB9O082ekQpFekdVksphpy0S6Gl
jDsPRXQkIeR8AJJjppEA8KDiaIAbh/yJZHPRiOgUU44z7sdRHzcRgqudT+mmjOs5yUObCoBR
8ZdQeOR8bJh7cp0VEJP3hVeK7EbED9NlsZFetg0b8/qF+S8MvILyUCzokeSxFnkSnonDbszs
dNbskkmkUmoQKSFHGaUg8mBwXt26Y4dMAoM/DNrkOxte7LcKcYDqLhWPYqWgHMIHEk38iXYU
NxRKb6M7lQAEW3Lzrwc5o+s4ycZLdqondoIY1ZuSBGtpvtSiCCEhgXe1FDOxBdrNOhKQYSYD
s8LpkPZ54pjo5JgHBAIh6jASFMYVYqfusAaWgJkrPGXfMyy104xwiyglS2QJBcsjpj20mB3K
N0EnRDg8lhlS9+6eo5KBKYWa2JmxQ8tbEhOan+BJ8CaBExThhmOyzGUwyjymaMmCWJAFgkTE
5ahS4cAJisBdkshKswUOcE3e0wWNSRUhgBF8OjVZ8/wQlu1fnx0NvghbbYORBs877qfNYrnc
dY2VFhY5vt1y5jgg1ZGyai5LNsY3rBBY6o2rWuET3AcKp/od5YYcF3xdt3WKa3p1ku+0EVyv
mv6FTOOzP8MMJPhnLNqOeubUT3jD2MjuqfvVOf/h13jDcf6xHjcLtiM82ccOuEMsZhc25pID
i7YHLJqKfVGmvDLk2ajP7Zz5l7lPJhdD04FOg5xseSmXX2M9exyj/jkGvWTl/SkeaJ62pzZc
iFecDdGc88KifZ9YpIHpuC6ZKS2YHLEFLVX1Rib52D0ccv9PARZpZOlbQ+QjweGNI0q1ZsFw
434pFeTJmnouqSAnQStI+1rhXU1S7UjmgEVSooCWIucwpW2G0qZc8oz7cVQBudWMjFDKjijc
sTj2DC7XcFWa72n+Rs7fcy579rvIBaZwFfn8BrGwAxwerZSC/TZR4qhxtwBWszH/jYpJYYov
WNTQWSG9eCdkZLpHfk+GD4rPJgN/mJ0/nbfUwKwJN9X77tkhU2BGzj9scWdD/tzfO8RJMAAW
zyo0A0iNlGniT3KUdvSFRV6h8Ehbno8pZ9QrzGh7BS1lzL9ldgCv9hHHLoLW9eZra0BtcISi
awawlAJoyblWncEPaU94miYlBHbwxBnPfCbUBKy17xWmgM6JPB4aLzhEwU+sVfLHR9lTutPg
cItsJDzowPA5KJxRVbwtgk7EolJZUXmz7+E5KuWb6O9ZKTB2aHlHYkLsJgHYXCFyWsEGbjgm
y1wGo8xTdHbGCJZzn1h0FKlwYKgGdDhQR+VaZqPKGN+8xyxvbWnGc6RQTk0WPT+EZfevz44G
d80SDKRnKZA5cj9tj8wCzjGHnmmhA+g53t9L4TggFUGEUYrSKEQ0o9AKgaXeuCrJAAAW+yDP
Uv04tgh9wdd149HZtvLqJN9pI/5e/nNBpgn1SxEECb6BRQeGPPejzkmfXO2IFulhdc6vcfWF
VJx/rMfNokOaCXm+gTm4FsQg7RIHSXojwBOTttnsUOwLaHhlyLNRn9s58y9zn0wuhoalz4Oc
bHkpPWCN9exxjPrnGPSS4Uq8injgdOYs0XAhXnE2RHOtC4vuHxOLDPTIOmnKTGmdAVaItkrT
b3Y64OooRf39v51sEVn69w2QHBJqKX1EKZggqOF7LbWW3LoNvXzUnjuMWetHqdlok1AwRBBf
HaJGSuxMzd6a6AGKqPIspS211xn3A+I0twxCxkGZcWNZfd6NiffOIgfHrTcElGl4T6MoAyUP
91r7vYY75cLr9cor8pEJv7FDKcN0HfuBAy5eUTQqC6tqQKqPglettdCwoa2++hgM/6qtiutq
DEdn7UH+tdXk4bxYJEO3wUU4eDbv98AOmaAhZvEftZbvbACl37/fUcUW8O92i03HG/bBp8r2
I54obQsddShYv/RgYGTASGyQk5LiiGaF2QdyvYaWag/mo7LXQMvi2E2IVn+Pfe8aFi25244J
pRNDeLEVFRksCfiJMBHLL9SEwEk6BSbkEkGI7jBS69A43vlAlNT2Ab3nmtteevvzp91L+QPD
RQBQlZqzsGrCYjWwbko9uEafQR2jDbRK97b3e3xihMOE8CUfwFEiETJgBoME6oJ7Qe/KNz53
EhL0JZksc1GQkatiHnFUsiDWBJcb7Oz6UKYa+J5pkS6ItrXZMgYTLO+T1F1tt5Ejx/Y/zqts
uXEcCSpiWjxAEvdFUrJk78wv7MM+bez/f9RmgoQl0Z7o7qlyiSYFEYW6supA5Z3Hhwi0/PXZ
gzqEN/Ke3R/GQ8nOkft1osAUhLtWoTHYyMWoFGVZnKN8noL9EgRtRocBF5mxYRCGQ0yNfCtT
D/0C9oHBJzL1hh4/8HFu6inO9ruT/ApBw7/75g9Umsl9GYJGa3+ORW3J0G/4gDsDc4MJ8cRT
5ZLUsnJ9A9c/EIqbqQEJI82+Ro9W2skObqRf1AYXJwJ8QyxqNt4MW532nTw78ujUVxIHqu4+
uLw4Gp4+ChvdGqWMgCr12bNsmPMQRskWSrwW9di+DAdCCGEBr2hskf3OnXdHrcvePPSnE11d
daa2gIS2K1BuQ3sSagvAyqj40/rvgG6xx1CxRAAg+t++Jf7shLKIgWF21ntrQhAy2NkHE7yy
3l2c133Xa4mfoZFAhnYoiRHtssL4oCRMhhMO0jlvffDbG3eI6zpVbsuMwKa25/S5onFeA8cw
qScXVdP1/F3HwQo1f3UurF6uRa9p8uei39T0+MY6a+k6TBve+ycstx3Hh8ZLP6GZV9gZ38sw
oSnyox+V7BmbeFZKfsfA4ywRZPl2sL2VvGeom4DDsWWSul9WSZYLq7jW7vfI65WEzuZymaGO
Rf/to/KdikIL/Lmy/YZCYSqsgkLXX1j26N1sBy2hJzWlntsM5BXcMnVOrj7I/uLIHrEoNY7o
C1rHWYYUO2eN1UEEN3uLQcfCozEKD1ciADAMwuxsADBuyNE6BoWzESiKSWNdo/cBFjfOLpIW
n2F3AzdnF/zbW1itfYPjFCDGo/VFHwOb4WUAT42swtw0BsbMyN4dVsUIIod1VS/9l9i7MDHJ
DpMC5yt6HkkCr6FRxDQHiPTb3EWrMry2xWVtz5aG68odcwTvnAoWoX78eAypCGCYhmFHG/nG
72QYFbZt+T+mQMSuz0JRjPIHKll2fAjPrl+fPajvvUPDxba5aQxKFhIV+/UDPynctQqNwaNm
AD3leg2BUnNVsdmHMPqNQSrCU3wvhsMB2IS3sv0zivvA4KwoOMX5DD1+NDxAPUWzPfwHBA3/
7ps/UGlU+DIEwfA/x6LugSGvbMdXZm4wIZ5YVS5JrSv7iewk19fE8YqbmXGBtz3XSI8aVr4Z
g0Sd782ORQR4zkfNTmMxbHXad/LsyKNTX2k8UHX3q8s3R8PTR2FPVqOUEVClPnsWRsezMEq2
jOC1qIc2Txw1QghhAa9ta5DNMTa7o96u27URpxNdXXWmtpNgp0DyuTthRFXPjDKurv9JxCKt
1C0DkpVpxYatGwmBoynkU0DliUmo7C4h2Ri0DX5F+YH3jRJADo3irjuhuoyqo8dBaHhSjsAi
xbIV0p4zWx/KeaXcok5plBbsxOnzKgZ9TYHFy8iQddOLiKrbsYW3Sl29T9egrtQLPw/nop9q
hLp4550jFqWUUBY/u4teuA4gMjas2hbjHbwN46mIDQeWeA2fQlP8prRPDPuBwZpkGAMaLy9s
CWE2STYlFFQ9oWEW16siY2eOOSjmv0f2SkJn83ZboY4DTMasQ6fzAEi1gmgZ9o6O2kaVdNIV
i5TISrsu6Ag9qSmGJ1HTjCDUeXkNSYnVk4OkZxk0NIlPi0pzQuRitEkih0vwKQHLQ4CHgx41
ypgctUKXodEeYQqcUEzQDniXrAdUqiucFJJnj+EuChaPF9jdBhtmOPp+j8C/dzicFc9zZNEe
rabGWOpxydkkNUXGzAQsgss0vlXD9apfOsKhfKJVmTgqKvZ5+ETjgzEL4hXs3k6Rz6eCDaWv
wWKxrQV+TWVduduxSDas/aCz/iRMvDBN1AxBZlbcyUKc6zr+jxBE+xNnoSlOxwOVlx4fwrPX
r88ehFj0mFIadKFN6wya7Zb7iZGfFO5ahcbgUZfFWsrtFiOl5iq8JSh8rbV9r/U2D7GYaM23
Mvmc5j4wuCbjsFT6jI+m5dFJbfzuJL9CW3J9R+IHKo1O5ggzMPwvYBEz9Dt+TD0bMzeYEE+s
K5ekNpU3pPKS6x8Ixc3sdGG3zTVbq8dvpiRdx7620IkA3xKL2o2nzbC7076TZ0cenfpK04Gq
u19dvjmaAXQQDqE1ShkBVeqzZ9nmn4cwSraM4LWoN2IOOmqEk2IBrzgbsjnnikXvtx2LBmA6
rlVnaosa1G1YFOf+hHFTP7OG3P87n7pusFq/rxjGtO0GTDqfNKBDs/otRdQbn+dBL+GWZj+j
7qR0x8OhHxxGBgyyqF62H0y/Wm1xg1eicCPHJkN4QPHb3riPWzBauaXpON0CL2zO92Gyd7wc
e+Lni23FwN8NvPdaY8P5nvS96KVVOuPqnOoG/YEdQuAAOc8z9vucK8UQek4WDcJRocnl7ATj
6YyXjgxWq4cSq9CR4YmBA4Fnk51LlcdPB4Ql7gkNfl4tqyacMdzvmqxvrOLOpd8kdyehl3//
uKI2B4fGZ7Gpt+vocCjqRJApTG1nPdvZwtqF9bAYG3poCT2pKfWklmRYSfWwUpr1cE/kpOBZ
x6ChSdJyNfNlESmiw5iHJd1SnDHtwqPzgrdIS4CfrBGwOvCEJ05RGG1iWHy0eNf9vmAxIMjH
cDOweL7B7h5OWPH4r7/yLcQ/4TiDnElTSY8SFQqwbu26utnIzPfKse+HGRGrrBnvdzs801g+
DeYn5pMRbCUNwKmMWcBug/myU+z/pCzYwL6Ji4eyFh9oYbgOd6pUQeCbapqOcNSe7ScZYWCa
jP9oo9zmnTwkhL7n/1hlpMyX0VCCzQcqWXZ8iEC7f332IMRiUl3XYuhsuwD8wCf2GyZ+Urhr
FRqDyXO9Okf5+JhniqmkDFvWka/1nl0a58gOQ+E0sQcDSuPX6Bewj3EoNWCUkQZ6nKF529VT
tNvDf0Bbcn1Hww9UGju7I8yglP0ci/oHorzyYQaSzA0mxBPbyiWpXeWkCmuur4mTLDfzCgnD
tXbfBf9nOevQw6zb6ILufRg6zEdtt7HcDLs77Tt5duTRqa8kD1TdfXB5cTQD6CDsyWqUMgKq
1GfPwuh4FkbJFkq8FvWmkUH0SlsI8YqzASOXpd0d9ee/tms7nk50ddWZ2qpx6EWB8nwRp8lv
AVgZFd68/28pWGTMB7HIOGLRZ3Qb1npnUKxyjn5eJrPEe178nG3MCWkWiUUGWKSsAppsWGQI
L3glGk25YVGOecl7D0oqWFQ2KKVg4k7WzvM7sOh9YVFAsuS1YFHGd9DBYv54T2l5z+adegHK
clP0A3yaD6Dl/0mvtsXGcRuah87Ekijqwrt4kWjLScbZyfQ7+tzH/v939ICKEseT2e1sgSCS
KUoEARAH0HorIyb4qHr3ra7GVvOvdrA9GgHqnZA2Bze0Y2s7ixxYsAjvlPajgrR2tOM0lKet
bvRAvzXXXE2EReiTBtkseSAeFouODP3a75GVmQhxczwl50aN3QHoLGGRZPiDRlh+64hI22mY
xmlsq40HwiJdWRwYPBg2PUlL4gUNFk5vttPQLJoYwNsMEtt2GxalYYqERUrrqZ3sYvUEkIGP
4WE7ckFYxAVhkUD1NhIWWYwNmKf0iMyW4SQ7weLK6DzA4m6B3SXcHOHo89ktWp8tIqzDqy1C
SGgxCPyCpYUAFk0DdxQzvEWORPVE1Xqb86+waKDMSpgzjE1NBZuAmEFKdehcwSIqeMyGRUPB
og6Qimgr8/BrwyJ8s7tH8iD6It5oaICnjcMd2cjdu1cik1EioXtRsMhFNpKo0d1Q+ebtIAIt
/zz2TiidNizqOqCQeMMivqcwWnWXPVGlJCXJ6eQcyX5WYU9G4lzdAItwoBjrOsIizqlPajgd
PSQSrIPKjsq9kfSGHl/w7/6w7+LefbaT/4W2WvDTJ/9AphkneQszMPz/gUW6+8h0NuhAXPG4
cznUcmeq7yy+QPP3g2MLFqkuGyusmARSBpIG7kfbTQOwqPkVFr0a9k+w6NqRt079cyza3f3R
5Zuj4elbISzao5QiYJd97FooOq6FomSrzuha1ONIqd0NbVhEV8IiD9qx6Ly+YxG5eteZtCUs
agoWuVjfod0cr1mIfjz/K94hTJUQj3PNmFAVq+r3U8qYUkocvfPemRhbEd3qo4leYeTsvWU1
0wKvoZFthaqZqCM5pecMiEmV8KFD7sH70W9fLIBEvagqm1b0/Q7jrVQhnFkrz3GCOQVeT7Jq
WMB7DeZIIwQWjGcvzqQXehz/tegnDqxo6BxhUYwR69WMAL2Qq9FZ8IMXfkTrRL1TCEFE0Sru
e98rwfCo6EhlVI3E33nlVRzLU+6YE/Tb4iM2zmhg5GCEbk9nQSxWpGfK6b9HXp+JUMs/PB5D
QBYXIiTpazlzQKpuoRGW32q7KAqrqNp6Y8GiUK72KkBP0pT0JC2Jz0DMGlbyUbDzROwRi0Jj
24EM4tNRxCU18KizsY1+9S5GY+HRkFoPVzZCDp2C2UeFqJfACe8bdH/eJetU24rzOcEV3jrr
3IOExcMKuxs4Ycbw01NYrbt4gfpB9L4jH7sSFQLgqdQ86yj6IGHJntc1i1FRhuTns2TX1FJF
zyT6J9EwIZth6AVm0CFRECe0MdUQaLwvKIK42SaXuZJRSUPz8GsoWRAfHO7vK4Kjw1f1Rgjg
ENqAO7JROIRXMhCqNekesxC7IbeSxKpwQ+WU3Q4i0M4/j70TY2FCDUrV36Gyqq7xH+u13V7l
0qq7UHTT4ckoyUgeH2Mk2c+qHGRLEkLDjIER5NYPUTKhPqntCLGsonXQ3kriEO7vocdXaH6o
9l0ctsG/QXDaL560X5BpZNS3MAPD/zUW1eWEfsI3PVBPZ4MOxBXLncuh1jv7sbCg+fvB8YoW
s8ODL3NVWWN72sfR1jBrXeiOAL46HO4O1cavhv2kTfnMkbdO/Uj9De3u/ujyzdHw9K1QTbZH
KUXALvvYtWz9z7tQlMhCdC3qoczjww1tIURX7E0l0OHVUZen7Xrgd3fk6l1n0nZo25oVKA+5
uevMFoA7IwPIy78zqkWOLP18Qv2kbMMb9n5KOUfDoB5TTCm4nHuVw1PK7phMSOmS5sAZt4or
I4zAf/xgR4MmQfRcyySVGKpBQ9mQcno99xvEMWbKppGNtRpoJWPm+cI7c8kJ5sR208lULV/w
XmeNMl6pS0r5ktSF9ILG8z1djaq5+gMrhLC5LmO9t76y5QE9RhBVUrOajLXw9rIsKisURUkk
YRRPCjynIMAsyDAkk0yW5WkfeNAJTE99Phk9GmCT654vilh9iyUjp9+j2V2IkD+f/3hcFh1Q
fy8nMzNz6l3XuQ4aYfmiksiqsMmmZxsrnq0JLJkFepKmpGfSG8MtisFKKSt+ScQz7KQctr2U
Quv4oPN6bFOcQsh9Tk8p5Ox8mFM+9rMZbavRp1ndwguIej1qgTJESx3D0QfT9+pyOaY5J4BQ
DN80LD4/we4uhfmc8vzjx/Ithh9JoX5QIg0IIfRL0hohVZLWHo82q3GhmBl7VO2IWIS37i8X
86Ei7Mp/LToJeFYa/dWoNG/pkFgtRdRumhqx0PiogIURsVQm8zJXY6Yo86gzK1kQaVkeDvWB
8se9fSPdaphmwR3ZaKmWV5ogQOGG7i26wHFczp0h8Wa5oZpO2e0gAu3y89g7IRYTOhiq/qra
2wZ3tB4n7G9IaNVdyBhUvj08TBPJ9+/LQqJfCeeuI8Fn+TS1OBkdirwaTeGArpG+KmEHb2gd
46QhXpbDAXrcQ/Oqpq0T1dvg36DtcH1G/Asyjck/NUEw/F9jESsn9BMO4iPT2aADccVmZzoa
2e08K+KkaP5+cFKJES++pWSTzbbMkLOdzSyy9A3MurUuqN45h8PvqnpjsRn21WmfybUjb536
kcYb2t390eWbo+HpW6FKd49SioBd9rFroei4FooSU4iuRT2Ueb24IewUE+iKvZkjqHp11I+X
7Vr1d3fk6l1n0lZ2vGkLlC/n9m6YtgDc2VppXv6zolrsJmP++YD6yUzopVrzRl2HrZnnPOc8
+3UdzTo/59WvecLIyzGnru286bSTTnJjWWfZag0q1BH4kTWSTTVapKk5r3k7MQWBCP9tWYBS
gRlpJTcdjy9Iwy9rRorGdvODY7w7AVq7CSV8NOYl5/UlmxfSy6FSOOCK15vOfMcK80yuW9cV
6131lXM7jUlUFI4Bm4G3T6eTWQ3aNgrWyXRZg495lmA263nMCMS1ZPlpnLvZ0m+Chrg+TlY6
hYK5//5iiLHyFP7LeZU1N4okYT/N2gJxCqibq6AAWT7ksbaPmH+zj/u4/z/2SxC2rHZHT09m
JIWKUlVW3kkx/fegUQ8EqGwen6a2ZUYWRdvzZsv7GClVReAIx88s7WwxI7M82c7oF6FlovRr
1jL6tPBZswUhpWJb5w+1LcKHmrAme1S4dksCqbuJ2aEL6lKXxia2hnqtlUguTdcltdgJFCB5
KlggCpFlBU9ZVjUBK1hTdrpEt1s8PHR1YyFxXZWPDBJv9pC7rMvGNbZ5eWkPZfkn1M+zYtck
6DlFCQPmu7yocimGQbZs18Jmsl3ib0PbcYqQycMDDy8hDsMoChlKFYYahQVZtmNYgW4oEyzP
KiaV9rOW5ndzbqC6aV48r+VYmc3r8Ctj5CPYML+78+4ofty+d6ksZG0btXgjGbWb9gwkMtQ1
Pr1LAXfZtUPMiYxor2D2sutJGNrDj3PvEIZtlXv+xsuyjWekjzc6L0rpSUSnrkSVFjnPOCpF
9PzctkRrRuU5j4naNgiVCkLOYxR5HprCFF0j7ZpDDkbQOVzmnLBt7+7Axy0433jrLTbL5D8A
KO0nX6I/EGl490MTBMH/OhdtZw/9BMvdRyTfOHvLinxFco1OrXjOUHmyhfuwFekwnT02tawl
zBkrmrwRDWvgg6hvQ2r8ADeU4D30RxtvwWwR7Flpn9GlIq+V+hF2V7Cq+6PKF0VD09dETehq
pWQBK61zl0TWcUlkJXwGGmf2UOYl2RXgpsL3acTdRAfYnBX153EZN/HNDal65Zm4zePID+dU
3g7BDVWSlyhEzo//cagWY8X584RmjCv0UgF/gzjG1fijbRBvjHMpH+on64yzqrb2aG0VB7GG
C6hc5RFXKOi2o+JKoSFS3DIEG28nKD1YZ5cd54RE+V/NP0l0xY5OkqrrjnEij84ieHHN7SiD
MO7xv0hJLkvOcaA7Wn4kviTn9nbmj/sxf8EJdU1J2zmH8976yiiuA5VWmUfmWOIwuEvf99xx
lFE2t+hI4tlWOzub9xYGuLPKKsdtZlF41XEt6HeVAd2kRIaamJv4eOSE/NmiIzPmN53WmuMz
AB3Sy+tD38vaCN6PygZqSk2SmAQcgbnF4xyfUTmVBgvyeJCq3lrVK/q08ElcEkJKPICUrOPx
0RJaskeDa/ckEjschNsPkW3KunLpYJ9s45xBnrf9kFqVqQj1R6ZEBE3mOZfoJxsbCS5sPVSN
QmQ7HgfbOds0VVMfBSTePUHuxtbdvXXdly/9c9N8geJkwfN2h45FNZprlXPeMnRSo3Yy72Uu
izwNgtgNCl9FejzK+BKS+SlQqogw4iJCnSZkFKELRVXBigbOX26LHmUfuKTyjOomWhzPayVW
FvO6sMgLQT4SRUmx2fgUb71b9QYiQtUZ93gjGfVef4YSRL0kvWsUMnne3yeSqFL9Fcxedj0J
Qzv+OPcOUdS3hb/1fFSifqWDAE+cF2f0JKJTVyJhkPMcDsYQvb46R7RmVOTzhKjvw6gsw0hK
VA2F71MwkZJ2peKvUnSONEwS9v1mAz5uwfnGX2/hLZP/ABBKf/Il/gORRg3mOs1A8L/ORcF7
RvmI17mJfOPsLfzdaxYk1xjMiusOtH51HDtnyqo4tlZb7fS8Yslf8MEqgFiX1gW5KI599Eee
v+BZsGelfUaXirxW6kfIr2BV90eVL4qGpq+pBKxWShaw0jp3SWQdl0RWImegcWYvQ0gtrgA3
VUFAI+4Gbx7HNRd9OS2jl97ckKpXnonbIomDaE7l/X10k5WLAa6oFJOn/0436AuNlK+HEFyX
QRKE8g2SBFej9IB4U49TJif74qZ6QtyBVJxrkzAp4QKaaRZLHSY63GuhNcsSLXtILPMzRenB
TW7ZcS7hqOrVswMhTmkEJSlTbYbhlKTmhM2NkaV09yaIkhH/S0sjTSPlybnp5OSJ+ALH7g4j
/r9N5CtOsJaS9jRNOC9M0rXHtaHJ4PBOOkT8soS7QHhylJnJHHPoSBL65AaHxoPZEOaXORji
JOavGRoHRb/boi2a6WBUoXkj6/R0koTytS8r9Ii/6bSuPr0C0CH9++szYnNbKTneGxeaww4p
tU7BEY6fWWLE7SQnPeksXFAmkzY2BJfgkzglPolLwtfeyRBScpNMXntCR/ZYkdGQQNz+WU2P
+xi5xLZTNrkX101T3UKj+33mTFFSgs9LFUMLjAldKN67GN2fs/umM4hsp9PeDRMk3nT2VUPi
wwvkXjs7PLpp+P59fLXdX1Cc5pK5HCZkulKUmknZiRJeVU6qGGEzvMjCMJn2upSlyk4nk1zC
LknSNFHon1QE44o5Y0onsUClYpRAkV3VTcDHiOODpPKM6iZanMxrNVbyeV3EGZ/jDFoE7nnb
OeDemTdQMTwqHfFGMhq98Qw1iIp9ei8NiqZifEw1UWvGK/Bpz+tJGNrpx7l3iOOx59vA3zLm
b9syDPHEeWk+t0wgOnWl9BwWnp/rmujr12kiWjMq8nlKNI5RUtcQgk5TxrbbNM1zrWlXCIW1
hs7RldCEuCwxfYeHt6WrE/jjZzf5O4BQ+pMv6b8Qacy+uk4zEPyvc1E4e+gnaNlHJN8gh7hA
syK5xr5acd2B1q+O4zQd1nDEtdKVUzmvEMhcemCTaEOINZzhxvOSZIv+yN8uyBbBnpX2GV0q
8lqpH+E68q/q/qjyRdHQ9DUhpNSrlZIFrLTOXRJZxyWRlegZaJzZyxFS2RXgpiYMacTdzD3A
Oyvqr+/L6O+Q0zGuPBO3PE3DeEswPsY3aDf1JRoj9Lf/HW5gppXW354icF2HaRjpN0BYrGuN
9IB4Yw+HQh/cl+lgDxNahOnbNPVplDZwgUpUYqfLKC2jpxIFgijSUo9Ks8IvDKWH6TAtO84Z
iHrRcnYgSuO6wPyurP7PebUut60bYf9rJ7EkihSvEkECJMArJJCiYJp2nMZKm8SaM50502fq
I/R5u0uZsa3kzGn67axIAhCx3At2t6oGy44HWcRxHNKwUPFiaeH/LBqHcQoilqUcynBAuUDi
8t0oH5lb4T3skGVoOikl7GdYq8m2mRG7wrvGozyJKYVwAeWFMnRjF501Di2cKqsyC4AMcD+3
BEeUm3HWzayM4LPwhMflLiZ+vE7CZHU7hEjhbUETmiS/GLRlMtwCoEO6+3Co60gwEtYqLo1Y
OYltJ/ZzkhlJhiNFMnKNM4WWjOLMAClBTpQU5UQpkYaiDA3QUilDayiQSvTHBJ0GFVJuD0S2
WxMsmgnpyrIvMylTARaVW7eMfWqSaO1RYsYbGgSbCPJ1VpjQ/RXZlmex64bDsC0rWYqM59lt
BBqvetB7WkKaK2X18WN9K7JPYLgI3Kx0MTxyuqFxsAnzDaVKMUn8GrJT4LuGYcltRAkl7jDE
b6ISarLVyorW9poszTAy14FPIkhOUL1QslnnEPzpYl0vITf5YQ7AugkXW+PaCFaux3XLdbCO
MEbgnevr6/lYnb2j3xFZUV2varhDHdXX9TNSYCz28Z7GhPh+vbcjZB7XF5jhOy8HwdGGH8de
YFl1sZ4vZvMgmM05NYzZHPdbeWPLBIy7TrwC+ICuSxLkhwcpkaeMCvncRq5r00pT04oi2w6C
+RwPE6zBVt4aQo/HuE+UbCIk+FgU+h38XM/x0xGz+mdf8r8AjPYHM6u/wEkTb5PLNANH2Z/n
ImOM0J9QFrwljA0MiFcUT4ShsU0mmt6A66fAKUcf4QEcnrSkko4rNhWtoiqQG2GAWo0RV9fX
ljWfza5m8zMFo2Ino/2MXxvy0qhv4V9gMvdbk58NDZa+5BQweSl6wMTT2GtG73jN6CXRCLyO
4nnQmQUXABeKDQOvhsHjHeD62VCfPj7nIufqCk09yYzSru2VYY1tZb03r7z07IATUbqJjv/u
oFp0OWOPPdRPTCydpcW+w3GgiGcPSioli64LWCc/qq7oFIeRx52qHcvJmAPVMicu41DQWZoz
zkngcNpQRoJ5kCj4s+rU+Y1j2OBJw8dHLGejNdy4KW/bo+PxI7ycc5ZRdcOXK2cP/3MFvLNg
7KhUd1TsiHJxytR7vHK6dNhn2EFKVFTXdbCf5bjnDtd2pMUD6LAUU6zgQoC127ZlHQt4oIgi
nDk4pRolCRAc8nKtuOIdG2cD6cgEn2tSk6rreRKmUcly9/ORIbFHJXKR57tfQ5MfHwFwfn7+
8qFt0zpnrL3hjcV7P/e83FPj9qNIpGMj8Y4H1pmY0yVcWiAlx6mznCgl0mOjmAVaUh1zHhsk
BXpiOXx2iypR+kPSDdpWspR1F3Tqo5JdV9RS7fY6UDwUdpJEG5HYnApCWLpJol1jJyxppK4k
DwJ2POqm6VQtq638BFHStB9B74WSzbDrmm/f9o+1PIHhUsKIWkOfKrYZyzihbEszcXubdWm4
T0lKwgCq9u7AYTYJjkfuvAbEges6SeRHbGWzxI5IyFLHjhmF3B3DwZIX5TLar6CaCdkWAKl9
XOyMa1M7ptG4bhWRaDwF4ViOZjNjhufH+5cuNbGTtnVbuEMdtfP2GQUwxLeJ9xlPkjDc33kp
csXbCywwyi4HwdGOP469wLbbXWQsFwYhC6PKTHNh4H7uBn+RcdeJsdLCau7+viiQv3zpOuTk
GWkErQHwfr9yimLlpKnnEWIY0E1uIDfBWyMIvYrjPmlOU6S2nc1Ajvcg+dzAT0cszoP/B6CI
/oMZ969w0vBDfplmWNv+eS6yxgj9CUnyljA2nqOFvUTNmTA0DvlE0xtw/RQ4iuNmFfmkmqzJ
ugznd7QRDW8hBmsT1GqOuJrPHceA/mhhnImMip2M9jN+bchLo75FeIHJ3G9NfjY0WPqSsdKd
vBQ9YOJp7DWjd7xm9JJ0BF5H8TZwpJILgAtx08SraVZcA+bPhjp9O1/n/tUVmnqSGaWNPNe0
x1S+v7OvNuXZAScSgqan/wxQLfqlEN8ebN8XFfRS9kuU+n5VVeIfeq91ux2GUNy1X/WwvdNl
qw9PB934tl8Lnxe0oL4obD+37wteFDT0C95ngpIlyUDYVg+ajxgLUfBZuxgfUXUJwZ2Ksu9P
flCcBg1jouKHh8J0/EEL4VWlKHZCnLQeTlqcUC7IK3oG17Lkpi9+gx3aFk03DAPsZ/vBVFe0
0GM0dKmFFlDMV3DG9X0vBgFFj6aalsLXHOhGtxTIbpOW6EIXAx9nw9ZvM3xuILWq4aHM4iLZ
Chk8nQSS+HaoZCXl4ddwI09PAGgmfvvn3/s+b6QQ/UNxYxcPG7ley7Uetx9FooMYqYCW0D6T
8O/ysrU1dj0cJUU5UUqkp14LW/OTHoT/1CNp0JOQ8Nk9KkTff86GT/eu3u/aZgjv9Fe9h0an
AYsO96Eu48rN8iSqoD/kFaM8j7Oku3Eznt2092oP7Y44ne71zaDbverapxw03n8FvW91e/O3
w3Dz+++3T+3+X5qLggmqCbhQuQcHLsDluqwqHx7qIY+hocxZHNq2P9yXlaiy8HQq3lSE0O4E
gZ+zTSIcT+Quo1RAok6hMoGeLukyud1Zya3DcAJyYQepfVzsj2tzL4WSBtc5jLLxFPS8dbJY
mAs8P67L78i8rO+DHu5QR73RP2ML3DSrFd5XZZbF8e3jukBWZX+BJUbZ5SA42unHsRd4Xn9I
TMswGTNMVa1Whon7BRH+IuOuE2OlFf+X86rfThu54vzbnj2JDRhZQiCEJUAjaSRmAAkzki3J
mLEdc5yQbXYTsm133dM+WZ+hj9DH6r3CSjDxnu3u73euPkajmTv3Yz4ARUEpysPD+TnK8AnO
mdNGmc+VU0qVU8dpwyavXm+3DQPWJmj1DPZ8IcF+HN9ykHH8+jXo8R1oflTHoSOOd4V/AKcw
oJeh/QlmGiL8w2VmEMe/vRadlBn6Apn5nJgbmBB7JBUxNYRfEacDoI31q8SZOdhZ2L+dzdyZ
e+5ijekwIpETmef2uAlm3R1dakdHqlqH89FRfcd+adjKaS/JviMPnfocvQNU7n7u8p2jwdOH
gnuyKkoxAiqpyvYFo2NfMEqcEngv1YNtXqd/AAgh0mzivdkMSQI4enLU+7e7+5Feq6GrK51R
27O21jwtl/J5rtSMYBeAFQmxnM2/M9gttikhm6Wi6yQ40U+Ur1mq67CJJ/ciFiLil1mPZNGD
yPiloJEQGyGmuqKHRCfUpjZcFd1XCkootXs6JYlD4NBiugJ+FpnYtViuQLj+0/IVTTcy4aHj
0zTd6DrdZALKSOgsrmhLbV/Cf+0A2uSgohDZRpAN6kUdIl6V+rlNnbyHHqIIXZdlGfQHQ6kQ
KbQ3tY8FEYTTIIA5Lk1Tckl6tCdsYVOi4yeRiMgGKtEwMgUVNCPl116kRy6+T21gtqTumT/g
hHXebQiSvD0PWMDY4vchYZt3ANgwfv/hDczNszEh6RVNFLo0YEllHVF2X6pkX4K2GcloRnvK
jkTPfBopgl6Cnqgp6olaIjeJIApYSWRE3yRIAXYiDIadokFEfudmMtdEPImmWS8TDyLOMj4D
j2Z5T9CzQHO9YT9wNeoEtk28M3cwF5pLXBHl05j2emSzyUWSiSiezqO3Hlg8fQC7cxElK5El
nz5dvoviz+A4f0DshQnn1GAOAUxtl8ydMFitwsyzLnzbH1g9RdGznOIM2dtsfH0f3fLqDbpD
V9WIpw1si3htbUScQeCOhnOX8cnJ4EIdDCyLQGLOPW9XWS/retoItjRYTx3YAw9zBPZ4w6Pj
5jGg/urrKdXTPDBNCk9oo7SePoGDzGaKgs8hdV3Lurjp+igzmh6ggVl2WAiBtvm27Cs0LT0f
Nk/qDduuN2ahosAV+tP7eEXBXitBY+Ce9e6Oc5Qffri8RHGf4A/haABycaG2OVfbvt/t2naj
AUfbvu9jq0NIvRnFfvzxyEem6fEx6PEKND9u4tARjV3hHwBMpb/yRf8zzDQ0/+YQ5Kbpb69F
SpmhLzCynxNzAxNij7QipkbOKlYtYP0qcQTFzqaDtwsRijALyxpOEiQ0sTMyU8Csu6NL7fhY
15twPqo3drR3hn1y2kuy78hDpz6HdYDK3c9dvnM0ePpQ4LDEqyjFCKikKtsXjI59wSjxS+C9
VK8PU6p9ABgpVRS8w9hgjSyK4ydHff64u9eNWg1dXemM2g67utIul/KLG63Wn+wCsGIQjPzt
f2RNUQxO6ad7zTDoRDEUjX6BYcB2k/4lT/M8ma+kRWXyIZdzmfMkz7d5IQzNmFKDcoc7Pco1
g2v3nHLuWNDklU9HVtMKc/g5l/muxXLZxfWfl69oOs/GnhhfLrdGn2+hcc7p1M/f8FO9u4L/
jAm0Oad0m+dym9Mt6sV9Wrwu9QsUg/4VekgSdJ2UEvrTjJ7xhETjlhg1c1rQmE8m4O3lcklX
1OJW7uQOp0ZOgUWeOEAtcRMr5zmXtPxqJUYS4rsYidFCvuHhkJE5jXvbLUXSj9kkmsQwmf8u
FPH2EwA2jD/9/f1yORZRQJdveKHx+7PYNGMzL7svVXJWoK2kkktuaTtSQ3KeaDlfgZ6oKeqJ
WiK3VwXVwEq5pMb2ClmAnWgEw16iQfLb96F8uO3k6XkipCXzD3kq5VwkRb66tQo+nHTC0B1M
wg73J45Dx8PQvcw6IQ2z5HaRcsui2+1tcSVzkS4ukh/HUhbLD2D3eZ5crXN59csv1x9F+i9w
HCOBk9lwDpxcTOmUOz5N/Onk/n4mx6Nr5ozJyNI0Q95w+Bpa2y0z9mEaRq9nhKTvBu0OHXeI
MwrG3Y4X+GQSeO5FGMXzU3LdJmQ0CiAxL2DRKysbZd1xx/NJWa9NHBJijnQ6pltvtBqI15Mv
CDvhctlbwhPaaNlYPiEGEUJV8XnKw3A0un5rMpQFXx7gBNs8LIRA235b9hWdzjJzW0qzRUiz
tZiqarOF/fUGeEXBXivBnRac/EabTRyj/PzzaoUSPoG5cDQAub7Wu3GsdxkzYZPXasGhccAY
turCnm/BsR8W+QwJg0WlX8Ol0cKhI06WL43k/wFson/lS+87mGn4TXS4zATL5W+vRVqZoS8w
cZ4TcwMTYo+8IqbGTVSxoMicYv0qcXKOnS3Ij3kxLaZyWtbwryZX/MqRVKhgVrVErdEwjBac
j5qtHUlp2MppL8m+Iw+d+hyjA1Tufu7ynaPB04eCh9AqSjECKqnK9gWjY18wSlgJvJfqwTbP
IgeAEOKqindVXcAaeXfXeHLUPx9392a/VkNXVzqjtq7ZUzstxPXbTm0w3wVgxcnEZ4//XddU
1YwZ+8dGB63nqqnq7AtME7ab7LMsYL4R9+shuy9+kmuxljGUPMK0b+rmOaRA7MVen8W6Gevv
YhbH3hCavGHMG54MJzBNFXItdy16CFz/4/IVTcdG8NCfxXd3j6YVPa5lFEXsfLx6F6ld8x7+
688jFqWMQYfrR8keUa9ozOQx3iN+arK/QQ9FMQSs12voTzf75hMKPR7m3olkkiXxfN7tdsF4
7J4N46H0pBczEz/JG1l4QL0IipGMZbxm5ddhYRYTfM+9/7Fe7cFRXWX823vv7oYaSMBsEtgl
2c1rk+wjyWYfdzebsmFD2EeyJIGmSLFlYI2VCC1mqDoIthWnpYK1VFuqTO0w1keipVZtlalM
mM60+gfjH06Y2tpmRqxT+qDWqY5jh1x/39l7w7LEgXY8d377u/c8v3PO73zf2bXeRG6TGvTg
ThyIN+bzAX4C2wei8Wg8vv6jpXQ8vwMJ/+DGP7c1mw2t7ekOZEcjaUdkY0u8sTHemBLDC5O8
Q7A2F8ipOdXtKDwB15CqJh0pdQh2sqVsJ1vJTz6dCjiwSqlcwJVP85NiPcZZNLwgqeFbgrmx
4fpUck1ybc49lLo11Z/LxfuwoxuG3SnVE60PhjraosF6tSvq8wXC7UH/QKY+GAhmksOJftXt
DuTzw+l0DiueWJfMh3K5dPZWrHs8lUyPpXLp3buHtif792Djwr5u7/rWWCym9scCMdUbCPSD
RkdjuZBnMOwN+zxuh8OVG1Zj3bGgO5+PuIpTk8vV0OAK+Zv93XXOQKje7/N2h1zOzu4u3Co6
/euC8d4bV/kH6/x+r1fEBgQ9Udkl6oacnV1+Ua/O7/OH+Iw4nU0dVVW1VVW2KlulupBCzlA2
25DFG69R1pbVUy/Q12e383tMDQY9nsHNTWFGIpItSTU2pNJMCC1/dd7l5HRmBzpqV1bjFlpd
k4jZ7dU1PF5DO/8yeFQDDUj8/2fLlt5exs6dQ0MMI6KGO8JNjMHBOmdvb50zHG5q4hsuO5Nw
mHvtwI03EeFxwvGuMD/ZbFUV7KiE5bZanjqnmkLmx0hwpf+jpGEpPE1kOF4aZuDKrh2LHOKE
LvIkvVc+fDb4QBQ9EePhozEcNx6jB65vHJyUyoMlfPlUOpaO5WKFGmk1rWa8uUCfHctqF4ls
NpertrqaqmsKj08srLFpi6F4I0s39crkKUnGdl+55YWNxk6XohfJUCkrwICRV4zC/5/LYJWE
RWIW5rXDpfpKEiQUsduZ7fZEZATJpm/UnZ8vsK2ZiLfasJmt7WhqsDtrOQ1urqe2GwsCNB5V
7QqTCU1kom9Pn9l/W0X8n2Ury0RvJ86HBph/M/ur9IeHLh2upLIQ6i4BuAVgdc2vo5sr6cND
8y2VIqc4WR6wRE0OfpMMTNFJZQ89rRC1AhswzjctUzQqRemwxDxFK5H/BeVBakX9tfgOgLeg
XEJ+BrgPCAAuoBtYBwzqnALW8BjAMfTRxv0IJtpv3UNbzS9RpXmMPOARwI73NuU8+S1R2gh4
5NWibjXe/ShrsR6hNtRbje9h1Asy47tFmaSdKM/gvZP7xDxWgJcBK5Dvwvjn2GZwUvkhPayQ
9i7eW9D3VrT1yEcoB94A3oD8tcgfwvcA2rRLU9pLeO/HuwdrM8j5Yu6T5AZyaJOFnSOiv0la
g7JPYtzl4A5gOcptspueNL1A3wfforRRuZg36oh5j12eE3i9sGkRsI1sXzHYJimqvQ+8BpzX
bUtfBbarGEQ75G7qAd8NNHL/0lnMeZRMKI+Z/0M9jDLSLmFefwWqlTxV4PsC7Bwx/5JC/A0s
E4CWlOOw6QPKocxjeYT8yA9KXdDYOPmlH5BqaaYlmN8W1O0HJoX2WAt52oT90MBLlTdoFcqa
gBbs4Ul9nSp5bfDN+4v5ae/BjndQZwTYyNoS+spTJcbnNee9X24am4c2tQso+zRwG+bVA4RR
vhsa/pRog/bot0fXYdsCA6y9IrSyDQZ4nwwUNEI2oEqHG3gBOAg8BNwJjHMd9NuO+qyTCfS5
Dt8NrA/WBvrifcjo2lkOfbcJjRXOzHexjhmgFqiw4GzpWIq6Nj4vrFlxXnAWWI+sLdaMwaxv
oftp03M8T97zIrabX6eNbIOYO7RVxC2sM2Z5htoFt1Mra5b1ZrA4kwX7W/hMGLxgD84nnxFm
xUPNfFZZiwuMc8prscA11IY+hywnYPsX6WbFTRl5gvqULZSWn4b/mefxtHeVWXpK+h15rDNC
M5gjPVbCvM/HrLOmneYZehZr2aycpcfAjcqs1KDMmszmae2CeVo6UIDxXsylMM0UypgZxWUf
Nf/jQDpnnqZxvL9lnsXZmaWjHCOsb5s6AafByH8GuBtoL/OYjpVNmH5tvQnniegD4A4lgbOe
oIgyA59gowTWqRn5N1m+A81NkBt9X5IS9CLeX4bviyAoreKxpHPwFwD3Dx4q0tEVmltES4IN
vS7CHl1LglnP8Guv6PyqzhfBXmjSzbGB/TPHB/bRQGpBr4Yu3eQFZw19lupU12dO1+fVurzM
3eCkHlvYd6/gc4qxrPqZ3cr+kX0c+0j2c+zjjPqlvNB+ih7FHF4Wfvgs2hbOdT3gAbwo/7Lu
R+CHtYPCH+a1vdYBba/i0/Zaotr9lrfBt2t3Sfu0XQsxVaEu3Ze5jFgq4ujztMSIo+YJmtR9
GsfdoLkHsakQR0X8tPTCjttFfPPiu5rPoTiD36AV0j6sq5tuUCI0Lp8mWc4hbiJf8cEnc9ke
apIvkkM5BF/3sPaO/BD1iriZos/I2yjKbeVnqMJ8D7nMf0Is26f9XfTH8QrMeWy/ZZz62BeY
d4nYu1P3x17e+zILlZcp5BZ1zsI3zdEKnotYgww1iHXgtvcQcV/WC1SvRMU6OBmizb+onNeD
1+iKtSjE5ozoc074s2Wi7zmM+XsaY1jqKWN9FT6Tx9pF25ZI7Be1N/WYnUY8TcsncA8qx4WO
9X+WyuUI2RErB3SsV/ZjzSdR97h+r2CG3xfx/iJ8FTRiPkSj4j7BZV/DvecMrWcoU9RkWQP/
2APfv5ccltVYo03UKHQ9WBgb+WlxP+E4xfcEPi+9VG7ZhvY4F8IGjjfcd5tY2zQ02ld2A2LL
dqqQpkwmaM8h7n5T2PcpE9+jHizCt/Q8R4FNLulNEV+57KJ0WjopndYmRLyPkFf+KeLje/Dx
z0EPK6lX2kGq9ACpyhLczeJ4/wqp8k+Ao1iDfdqcUgMf3o/87wH3od0fsZ4VKHsfdX4MHRxE
2zq8v0ZJ+VlSzffiuxlafRE8B/wb7T5Bh+Wn6LClkr4u7dCOiv4Z++b/weD+uB3QYTDbamBR
m39E5Yva23/ZzgUbF7GP++B+RTuuE9HmiLQ/A80Fnh+RjtA08IT0CtrO0AHTI9opE/bJ9AZw
XMfPKCX458AI9vCA6X5gGFCUA/Q42Ad+C5gFjgPPAxeVENbiCJ0B/8KCvwoM6TRtZkb5k8Bv
gdeNsmLwWIvlF0P5m3aq+NscoChD8mqnGFfVf5yCypfgazu1Uwz5LvgHwLIM57YMfv8vyB9D
u5Jvcys9qtxBddey51ow/YE6xRoWkLieOV4v+I7G8fn/1d/1Avv7VeCzYv2f+C/35R9bZ1XG
8fOebmwtw3cdy2Ad3ep2WShdd20vUO/dbenktintXctqy9aubmBglh8FRgITE62JMYEIQkKC
CzHExMQMooksW10ICSQMjTYLIn8QghhFphgNcYTNXYo9fp5v7y3ljlqH8o+5eT7nOec873Oe
8/tct1lr6G3e5EvCC9Gzbnf0+/B+xffdeSYzeVej8XyCe6k4T5Tfr/Ky+WOtXFXR7yrKy9Gz
JqV8+bwulMfvLXOltA5KsqTZtZss+h32SHl+6Tddu8l5tsY2nZ2fbXc+GXBXME6diwaI5c2z
85whSRN/F/kD1P+Jdwgymx/g/hiYWZ8mjO0GE8b6GRP/Jv9HkYp+6vpl32YyZ1x32rhWPG/f
6nvNT2mdl88P37pFx7hf3nLr0WvK09n1XTwvPrLmt8+s99m8nSUnymw+3BMf7g32ynw+/5+E
vfMr5BfIzz/VdljnkWOtIssRvVHv4K26m31x3F3t3D/HnZt6zrkPnkf/gPTXpD/gjqghPYIk
KXuM9BrSi5GXqfsH9whP9um9i2rc94rvSuqm+7D7LnJ0xs/0KvRG/P8V+SHyAOUnkL1IHWJ2
3UW5m/rfznw7vZ/0fvLvk96LTFLWj83X0X+MjKC/g5xBnkCSM/6msJv6mb1HPuZ/6P82nef/
x3+azvzfcJeX0vL/EOeU3rFwWv6fozT/C6Wl/xIfk2ociv+b3p7z32e+/zgfSVk/lXOFt/QG
3pTr7R1tb1l7P9v7sZTqfxvnQbH9C+ekn7H3q72d7f1Kqv93i//irmOcPz8bV+kemXO2+k3u
ZmRVUTj33DXY/Ia19vfooIujg+HUzBvUPWJ3m+4xhHgnSWPO3OeiZ8Mp0uPka7nLKkt3Wuls
PeuMPftO+1Tz53pHfoI7ta8ot5RJqXxvUcrrk0VZb1J+F5+rLHR3f+K7fJ47eu49/d/mS/d8
SRZ6l5a/AxbKL+TvXPPl7445+adN/k298uXvklK+XM6qP3vtzbxnathvJSnbd+cq7NMvLLoz
vFbar6UYyvZx1ex+K+bPG3c5pKOUcn5cxjlSjzxY/N+1AZ37LHyNdGjpB6556U9cM3nu2DBh
Zw7pkNWRPhgd5i3NLUv+2+SXcBab7c6iDC20nsvXrb3P9T5kzBT7I8zFey6JbEFWIE8jY7Nz
zX9P2n654jregPzPrXgrnMLXqfnegvOl/M+72/7vkY/Jx3Qocm7lN1xUMbrMucqld7kKlwgP
w5bwOkyLGTEbDruK6KTVRgVxyugjsdJsfJXZ+BiudCspT7gKsSWMwvT0GZgJtTAbcnBI5cPi
iDgB6/nqMIyxqXfVYoLypLwl8ZaDaTEjZsUR1U6gp2SZkoeUPKTk4Uq+PQrTYkbMiiOwha9e
hzGWLW45X7Xwrem14loxITbLMiebTrFLzKu8X/qgLK+XvlMcVon1NK220i5mTNK0ZSXV0mux
TNOWMaGS5vAqzKmkS8wzPmm1klYraflP4znnMvKcUd8zeD4Mq6XXMiYZPBsTzEIGn6Z3iXl9
1S99UPpOcQQPWc1IVj6zGpmsfGYVbVbRZvFpzOE5i09jXl/1S/+iagek75Q+hH4tP4dMuH1u
UJEPqpVBRT6oVgYZYSvvEnuwH8Sn6QPiDpUMi7vEEfFL4oS71A3h82FYDYelD0sfkT4i/Yg7
wkhOEIPxelqf0Gp8wTeGFLxKzIvbp8fhAPox1R5T7THVHlPtMauNGmzcYByWwmpjdMZ9Bxam
34VTYVnU4CPTfQ1nwCZ21q1wynR2Fjp7ahLGsJHa3qiRkhMwhkmfCH+OUuJJW/PRyWhTeAA2
8u1Jv9h09mYaVk2/D2NxVRiHrGeYCD+NTqmVU2rldLQ5rINJsUlMiWfcGCxMvwOnworoNJGj
++VW61eEg/BC+nvaXyy9Rlwj1hLDaV8ny3pYULQFG+GooJgLirmgmAuKuaCYC4q5oJgLirmg
mKfkYYpvJ6MpvnoJVoZ9sCq0wDi0eEftQdgYRuDm8BpMik1iysi32NAL0y8SV4vrxDpxo1gv
NsDIYvaRRQuJFhItJFq/2OYRMo9+sc0jZIQhI+yXWOQwDp2w2siovgKnQtIvYVRf8Uuj5vCE
r7QdATmR4HIsK+1EgrXiWiORYEMfjZvNhj6OwM9JbxJT4hm3HxaItpK2xnwlsaHTC771F4hq
xVeLq8w/s/kYrFFtrXS1y8iYzYbwKEyo5FLVXibWq/Zy9Cr1tErxV6m/VcRvXGsk/gnYyCxU
2dqDSbFJTImsPcjag6w9X2VrDy62b4l8Ei43S1uHkHUIVzHyVbYaYY1K1khnNcI62bMa/fma
3/M1s8uI4QGYFJvElBH/Rlsby/jW9I1ivdgAL7C9CdmbPla/YvUrVr9i9StWv2L1K1a/YvUr
Vr9i9StWv2L1K1a/YvUrVr9i9Si2/QXXiNajWD2K1aOLaPEZmBSbxOZwD0yZjk/jivAiXEXk
F+HT9NUqrwkvwTXiWtXWqXyjWC82wDW08iJMik1iyoh/4+rwR1gnfb24UawXG+AlfiU2l7CK
jJeJl8N1eD4Ik2KTmDLi2bgivAJtt64jctPrVF4P6+w89AnFllBsCcWWUGwJxZZgd78A66Sv
FzeK9aLFtlF+6sUGcTP39QlYLT4ZxuFT4Tg8BK/gNHvcXylmYN5n/FbKM77LSvy10nuk51W7
TezFT4Zb45dwh2yGWT8ZvyscgHtUMir9Num3y8OYeEc45Lf4DPZbfJv0dmy2+A6xK7wLe8S8
bLaFo7A3/AH2yWY7frZwW9m3Q+FZuFvlN8t+DD2L/3Fo/rPyn8W/6eYzi89h2Kdy85bF26Nw
SPpulY/J8k5xHyWtnAmrYbVoI9mqkWzVSLbS4mdhG+PT6re6FOyYnoSdeGilX2bTI30o7IXD
shwhqlZatJI94Sb4ZZXcbK34vdK/Io7K/lZrl9is5B7p94pfJfJWfx9+2tR6m9/mVsNeWmzz
O1SyRyU3ol+NzWrYQW27ZrxdEbYToTEf3oDbWNXtjMzf4LDKd9FKO3EegKO01U4kN/mt9Ppb
sB1vW/H5I7gN+62M7SE4JO5Wic1RTm3l1FYOy1dhL6dxDnur3UFsOa2oHG0dgjdKH6X1nFZU
jhVlHBP3U9uhnnYQoXEP66cD++PQbDpV20m5cVQcE/fhv9Pvp8UuZvBx2CbamumiL6b3qHZb
eAj2Su8LN8DtshmSzW68dfkbqO1mnThYLda6PFwrPsXId/sMt203rVwK21nb3ZqLblbLcdjJ
+dDN+LwHe1SeF208u+nFG7CPtdqtdrtp9xC0fnWrv930xVq5j3O4Rz3qUY96tL968HMC9ql2
u0oGVLKLVnq0Qnr8beLtKh+TzT7pNkp5epeC1eKTeM6zCyZ9Xm3laWscdki3lZ+nL8ZeTrz8
v6gs8+CqqyuOf+8rMpRaNkPLLhVKKSJZIMBQDKuRCVkQ0ySS7QEv4ZG8JYkRAkMNKGZSmkDY
MjRFZVARGcCQUmrVtmopRVGGUqQgVkFlKVILVBhKHejnHvtPmfl+ue8uZ/mec+8v1gmZ1kuZ
dL7fU2oz82wmZFxm8+U2Dt9+Hl5oeyqMK42jtidu/KjNPGbjRea9zsZLmM/i9fPc03igzQwy
fonblEXk9bC/v1nUZQmcdjsZnkLMWVTkKuxfwizrzyzeOj//iD9Lp2GHLArgYuOS27xWZDQE
DnrL9K2fn2c83/aHbOxvdxY5+vEC47CdWmjjCuNKm4nbuMq4xvhR4zrjJXjMtrcu216ebJQv
h2dQqWxu8XtwFjc0m1r7Pb5nsk3hHLv1OWS3CZ5JbDnkWA37HHOI503YvzOzrIIPB6LYzOUb
UR/Ixc5TgTwb5+F9O5zG3y159LOfmcKpPCLZDacb+/ueZ/c9j6jK4Rz+lssjqv6w95iHzfWB
fOzkwv725du9yMdOPTzDxtnqCucQcz77K+AS2+lflQIi6YDTsF+AhWrY92GBnS0wNQo4mw4/
ZDtLbCZoq97CnECZesELbRyhq+egwCa4miwKbX+h3bVC6uvHZcblvGCF9qoUmmKFVM1ztXGt
7VkCF9nrVGR2irDwR7jMZsq510VYuAr721dk71sR1l6FY7wGRWatyKwVYe1soNi+R8X2PSrG
ZhvsYyvG5ia43Mb+TSg27yW8/H1h/z6U2ntVar5K7Y6XBmI2jpNLqX3vghZt0GwG7WzQrAXp
zFPw13tqWZ2LtVNw0NjvnIv3T+Ewkc/F/vtwjOzmcuqvcC35hriDhwIhXoMzcCHWQvaXQ8he
+5DpGbLXPoSFT+GYjatvt8P+zS/n7FU4bGP/OoW5j+/BJWgbthqFTeEw8ZyEIzb2NQqTqV+t
Jobw/84uYU+FKVNhWVRYfSs4ewaO2HzU2OdeGZjDnkp7OSvt5ay0b2ul7akkWs9xY591pXmJ
ULVyuKdnsxAxjxHrw4j5jZjfiOUVCVTYTKVx1GZ8BSPWA1F7jaP2Gkd53/zMIGP/rYnaNzRq
dYzipR4u5V5HUcbPeC9R65OoVTaK2n41ZmPfMzHr1ZjtjFmfxMjlbdh7j5v9uL2Ecatd3GoX
x5qfqaQKcevkuGket7/94lhog2tt7OtYZVkvYmcHXM17tRi/rXCQb+5ivJ+Cy29/Afu7sBhV
22EfQx07fwb7WtdZnHWWUV0gjM06q1qdnaqzU3V2jxpMtwbTrQGt+gYamUmFexoPxE4jSnr2
X4pGvhQdMF8Kff0v8v9w6eAr6RsnpDuOSV06SV37gRrpW93ATunbFeBLqdsiwO9u7O8+W+o5
HNyU7poqJayTeoek7w6V+nC270SpP3YGzAEfSAOfkQbNAm9Idy+TBjdIQ0ZKQ/E77IA0vED6
4QXp3oPSfcSVWCcl10opJdLoFCmVOMfOkMZjdwJ2J06Q7sfOpMPSlOPSNOKa/jspPUN6EH8Z
K6VM/s/eL80aAdj30D2gQ5qdDZ4AnPsx8/mbpQLyKESSIuIswUbwC2l+rhRqkspYC5P7QuKJ
8DueIFVxtobYazm/iHyXrJaWLpWWEffjQWkFNlaSa8Or0k/RaVULYG9TJsBeM/k0s7/5FXBL
Wj0KkPfqreBDac0ggMZrtoCPpJbBAC1a8NOCXi3XpbVjwDyA9muJZ10vUATaALVcTy3Xjwdo
sR5t1lO3DdRqA/lupJ6tR6VNjNvQfvMl6enJgBo8u0HaisbPbZNeIJZt+Nm2T3qxXdrRR9qJ
zV3s2U1tX06S2jtLHZz95Spp7w7pV2i4Lyb9+hPpN2j9Grm8tlv6bbn0e/J9kz1vUZc/tAJi
2r9XOoC2f6L2B9Hgbey8kycdIv5D1PwQGhw6LR0mniP4PfKO9GdqdRS/fwkA5o6hzzFyfp+1
48R0fDngzAlyPIntk2h+iv//xv6Pqf3H9MZp4jmDfp9Rx7M9ADU7y9pZ4jjL/nP0zTlyPPc6
oB/OU8fzaHW+EbwrXaB/L4Slv6cBNL9Ib16sAtTzc+r8OfW/RA9dQtt/kAMm9E/OX6Yel6nH
5RvSFXS7Qk2voMO/0PgaPq9x366R63XiukFMN9Dp32h2kz77D/fmqyPSrYNyWicX+EiuE+NO
t+TumAAioANcl+s8ClSBdnBBrssnct8cAEKgDRwGnOvKvq7z5O6cI9ctAUwGi8Bxue5dAL+7
Y6fHMbmeoNc9IBc0AXz3uiF310SwErwhl8CZhHTAesIBud787j1V7jv75fpgv88Mub5LwU5w
Wq4fMfWbBbaAm3L9U8DjcgOS5AaS492cHxyT+x4xDxkKyG0odr/P/8PIZdgyuR88IzciCLAx
Apv3DgYl4HW5kf1AI9gudx8+R40H2Bt1Qi6RXBLRLJH1xOcBMSZ+JpfUCeArKQOQe1IrwFbS
Jblkckgm3+Qw2ADQIPmqXMoggC4pxJ6yAxDH6K5gDGDv6E3gXbkxPQCajqkF+8BFuVQ0SCXe
VPJNfUtuLP5579zY1YD1cZ0BsY5LA9RpHPUZT5w/Yv1+aphGjmn4SUPHNPJJI5808pnE8z6J
vpjEeDI6TUGXKdRrap3cNNamEcN0YpxOfNN3yz1wJ0CbBxinBwDjdGJ+kHhmEFcGcWZQ2wz6
JQPfGdRhZi9ArDOxORONZ6JrZjdAjpn0RCb9mEmMWSNBDWBPFjpmU99s7GdTu1noORvNZn8g
9zBnc4/K5aNTPjbyyTWfMwXMF0wH2HyE9UJiL3xFrrgPyAPoXko/lFKrUmLlGXZBNJnLeD4x
hcgzhBahCkAvhY7IlZFvGb1ZhjblxLGAei6gBxZ8KRceBtA6zFyYuCqoXwS/UexE0SDKmehe
uRjnYtyVODWIo398OaCucfqzivir6J8q4q/6UK6aWKupczW5VnMfa6hpDXZr8FnbIvcYvbSY
+izl90+4B/XEWs/dXU5fLSe3FcS0gj5/kpie2ibXQA6N3I9VrDfRG03E1MS9a9os1/wEoJ+a
twJq0IwOzcS/ml5dQ23XULeWcoC+LQ0A3dZicy2xr6WufFPceu77RjTYiL2NaNiKr1Zq0Iqf
VnJopcc34ffn6N+G/V+g02bwNJo8i+0tnOFb4p4j7heGA+7eNvrgRXTZzv16CRs7yHcnvnfR
Y7uY38XbsIsYdqHfbu7fy8TRjt89YwG678HXnv8yXOfBVVd3FMC/3J+KC2WooqLjVkpdkX0T
hKEuiBR3VEIAAQGRNUBYTa2lal2rLEOttYFaCaCUIlJEUAyBQBL2AJEtgAgMKmSQWgeFof38
cea9d3/3fu/5nnPufe/R7EOafuT9v/n+secf4/GJGstlarmxFbxZQccVevhMFj6Tp2J6r7JH
Ce1LabCWz2VyWGasjHdltC2nX7l+y90V5c78eud9g6xv0NPGE1Frs3lb5LcS923q7OBF1Upw
Tnd6v7MCaLAb9z203yun1c5fNT5f9oxaB2XvkDv3CL5HnaOv3cPf2veYucf4dNwdepyvx2lb
w4ca/Z9wPk84X9+5y0+eiVrf2+sHXE7R9Ed+ntb3afqccR7O4nf2+UjxMLwWqVYhLISVkVJd
uCZS9l6kc3tEqu157Q2RLjga6aJucCpSnRI4Ganuvkj1GoPnFzcAr5esiVTf+/rLIl36FmyJ
dJl9LpsX6XKfLz8WqcH10BdmQmWkK66CgaDmVQ2hKtLVal/zTqRr1bmuU6RfnB+poXm/vBGW
R2rUC9T61feRrl8a6Ya9kW5U7ybjN+N/S02kxmciNdFP08GRmuHWXK0WnSO1uj1S6ytBf61f
BONt1G9jn7bdIR+WAD7t9NxO7+2taz8EZkNZpA4BuHToGamjHjuZ0/lBOBHpjslgvzu7Rrqr
ONLd7aAgUpfxoN+uz0a6l97dcOzeL9J9FZEeoPeDRyI9hNsjL0XqwYsehyI9Wh+MPToy0uNq
97wuUk4r+ClSL7xz8e2tF/db6qPPPm9H6kvbfsb68aq/sQFvgl4G6nHg7kiDjA1SezBufp6k
IWo9vSjSUHoP48PwOyKNuBjsN1JO8jzLs270OYDPaDqNmRhpLL3zi0D/+WqMawT3g2cT9DXh
FaDjBF5OtPfEFtAbaD5RzYk4TOLPJPpMGhBpMr+eqROp4C7gTQGdCuSmgGYFnj1rv9/XizSF
FlM8+wN+fiqlF/T7R5xfsu5lWr46I9Lr/HiDJlP5N1Umpg4F41PpOtUzv4XTNLpOo8U0+kyT
qWn4TMfHb+I0HZ/psj9dtqYfiDTjwkgz10Z6i29vW/fOc5H+hlOhLBfyvZDnhTws3AR0nyXH
s3gzi+ezZGYWXrNkdbZszpaL2WOA3rPVnK2Pd/k6B5c5uMzBZQ4uRbgU4VKESxEufmOnIlzm
4jJXBubqe66szF0M8j/vPGgG+p3Ht3m4ztsZaX4C53Q+Pebj7U5N87fD2Ujv0/QDPXygh4Xm
/utgpA+tX2yfJc75Us+X8XCZc718eKRPZWClnoqdgRJnosS6EjqsloM11q6Rs1Ial9JhXV6k
cuejwtoK+63Hcb0zu1GfG9XYRK9Nam/W/1bvK+lRuSDSNvfRdjV38H6HjFfJ1k7vdxnfpafd
7pPdNNnD2z247pW7vfSo9rna5/203E+HA+YfMP8rn7/y+TC+h/E9wosj8nxU1o66U772/utv
Irlj07c4H5PXY87mMfoc50GNXmqM1RirMXZCxr+T4ZPq/8ed9t/2kX5w3k/h8OOUSKfxOI3H
Gb2ctf5/30cW50RW67XIsmaRnTsUJsMr8HZktT2rXR+OwA+RXdAEOkV2YSNoFdlFw6Egsjpt
oEtkP/O57pbI6pnz82ORXXIVNI6sflFklx6NrMH5kV2xO7Irv4GfIrt6fGTXvhtZQ+salUV2
w0uR3VQR2S1eGx+M7NY6oPatat/6GDwH78N2OAT4N7kGukJPGALT4FPAuQnOTc+Dy+B6UKup
Wk3zQK2mb8JyUKtZXWgHA4AezZbCgciaXwh6bd4X8Gq+GPZG1kLdFjRr0Queh4WwM7KWCfTc
Et+W9miJb0t8W56NrNWN8DDQrBVNWtGqFR1a07P1/TAR6NF6A+De5jroBvlQCDRqczKytnRt
q4+2+mjLp7ZroCaydg3gDqDnbXy7jSa3bYJTkbVvCN2B5r4rsvZ0bk+/DvTrQL8OY+AdWAsn
Irv9SrgLRsJbUAI87UjLjp1BVjrOiKwTHp1kppP+O/Gssz1+bf2dL0Z2t/67yFAX+nSx9h61
7sGzK23uxc9v8qybPPyGzv52Zt1xvY9e99vvAXo8oM5DPHukd2SP6vsxWj+Gx+M3A597PhhZ
Dt9y+JBD1xw65cyEZaBujj1z6N6rHui/Fx976TEXp1x5yOV3Ln1z1c+lWe6zIBO5PMhdArTI
5Wnv98D7PvbsY7yvfPSVm74y9oSMPoHHEzTtZ59+ctKPf/153V9e+vN4AE8GWDtArSdxf5IH
T/JyIL8G0m5gcWSD9DGoB9h7EI0G02dwe+gHvB9Mm8F6eUo+n7J2iIwN+RPIydN8flrPQ+05
lNZD90U2TI/DeDNMX8PsPczzYcaHGx/ufA6fAriNwH8E7UbQbYRcj5SHkXwbaf5IuRlln1H2
HOX5KPP9N8jy6J2HVx6t8pwT/w+y0XI/2v6j+Tba3NGVkY2RoTHmjZH1MTQZq6exMjVWzsfq
aazcjnUX5NMtn8/5uObzJ9/ccfIwTv/jZGbcIpCR8daPl9Xx/BhPjwl0m2D9RGdokjM02X6T
1X/GuSgYGNlvZel3xp7j8e9ldgqdXqDPyzL8qvHX1X7DXtOc6RnqzTRnJi//XBXZX+Ttr/Yt
xO3vPPoHD+fgVCSDRbI/V5/z3DPz5ewD53SBmgvk4p/ysVCtRTK+iN8f8mrxysg+otMS3Jda
/zHOy3D8xB7L5WW5OSv0/ym9V+rpcxw+p8Pnahc7I8V6KaZ1MV6r+LVKnVXO1yr6lThvJe6X
1fZfjdNqmVvtjKy2x5qLAY817og1uJSaUyoTpfJXqn6peWvlYa2xtbiv5dk6+VwnG+tkpYz+
Zbwsw7OcNuXyVq6Pcs8qrKswt4KGFfSrkM31dF7vTljv+Qa52UC3Dc7JRj1vlKmNcuB/SLZJ
JjbhuYm+m+Rp8+0go5t9R2yhwxZztjobW+25Vb2txitlq9L9XolDJY238W+bmtv0sB2X7bhs
p9t2e/iOznbweod5Vb5zqpzvKlmoou8XfPxCr184uzvV978n26n+Lut3yd9u9/3ueaDnPXjt
sd8e2dtLo70LIqu2V7V61fj7X5RVe7aPJ/vcJfv4tI9P++Rin7twv733u3P263e/+3E/Xgd4
d8CeB3znfOnZl8YPythB9Q7S/5Aah9x/h+TysDN12D11WM3DMv5/1qsuNo6rCh87N47t2I6d
uMmurYQBpW4a7LUTp/kxTfPjn+Daaxt7E6CqqNa7s/bi9c52ZmzXEX/ioUU8IIFAAokiBAil
IFGBCkI88EB5AAkBDyhCCAmJh8RJKmh+W1or5Tvn3pmdtd0khdo6s9/eOffcc8537rl3L+Hc
uIR5l5Hby+h1l1ErK/B7Bft3BbleQQ9aQZ+6Ap6v5CCYcxX1cRWxX4Mv18DVNdTKa4j9X9jD
/8Z+eh0xv47auI6ecB01cR083sAeuYk83IT+Tfh0C+9uwcZt1P9t1NNt+HobvN5G7HdwDt7B
2XEHNt4Ad2/A9zeh+x/UyVuoz7dR22+jn63Cp1XU0yrqfRW1u4q4V+HLKny8ixp/5xO4iTxP
qupnpKoLpDZ1QC6RUj8khfuIqimS2vJpUrU5UnVPkqpPkNqqIH8j1bAXgvcNX4f8ilRjPeQp
yOcg3yPV9BzkS5C/k9rWA/kK5DVS+I2omrFW8y9ItRBkAvJdyB1S20ch34Fgzo5zkG9CgFvh
Q+ubpHb+CIK1dt4itQu+7PoUBHZ3/QaC+TGsE4Nu7Nek4tshPuQiqXbEuLsJghh2fxHyB1J7
dkKehsDXPTdIfTAGeQKShfyS1N5pUg8fgvyZVMceCHQ7sNa+z5D68FFSnYi3C/EnLpDqTpHq
uUqqF/MfOw/5C6nDbZAVUkeQqyPw/SjWOfY7Un0/gCD2x7H+8W9D4PsTX4Ag7id+C4GdE82Q
wxCseQL+nsAaJ/5I6iRsnoT9k7B1ErZOg6+BaghiHfgnqUHEMYR8npkl9VHkYxj2n8T4COIY
QQ5GkLsRxD6Cd6P7Icjx6Ncg4CWJ9ZJYKwkbY4h/HHPGkecJcPWxIQjyOAm/JsHRFPxMvQK5
S+rsAFUR1XyZbtDj5BB+dVAzddNZoi0vtKDX4DvRM+o8npuI/+7Kk3EV7ZFvjKuptrrW4E1U
qLposKJ9VSsGb6ZY9XaDa6iz+rTBW+ivoZ1a6qh+y+A6er7uQwbXbz5Xd8HgreQ2BfoNlNtW
Mrix5pXqosFN9PS2ixyZ/H2++aDBVbSt+acGI/Mthw3eRIdbdhusqLWlw+DN1NDyEYNraGfL
lMFbqBDaqaUdLS8bXEf9ra8aXF/944dqDN5Kx3YF+g3Uu+uqwY2bnmrJG9xEidhueFKlOOtN
sTmDFcZHBG/GeH3sWwYr2h9bFsys1cReNVhRR+z7grcwL7ErBoOL2O8F12K8Id5isKLO2HXB
dYZfjTW/Gmt+Ndb8aqz51Vjzq7HmV2PNr8aaX401vxprfjXW/Gqs+dVY86ux5pdxPecqftxg
5Cquc7gV49vjcwYrOhjXOWzgWOIvGgz/458V3MSVH/+TwYp64i8LbhY7LxrMdrT+Ds55/B2D
kfP4PwS3sj9tDxsMf9o2C34I461tUwYrOtTWK3in6L9gMOvPCI6L/s8NZv1vCG7nGmi7YjBq
oE1zultq4IrBXAN6/AOs377DYNa/KXgv10D7cYNRA+06b/s5P+15g5Gf9mHBXWLnqwbDTvuz
jGsj+a+N5L82EldtJK6GiH5DRL8hwktDwEuKlqlENuUoTRl8WvQSJEWzgpPoV0WIb7Qs6sc3
F5ifaYznRcPCSAHzE0ADMp7+Py11h55ZNIU3BVoIdTyMDeNTr3eAjuG/h7oMOiijpzCjgM9J
zJmBD77MmoQ9D+LSIp5ZrJGneRmzaAyfS6LjYCwN+z8R/9m7LN7xmEtzGHOQrf89MgujNnzK
Y1VffGFPLHxnHd9YPYuoLZqQ+RZ1yHpJPMexdk4iZA95ng2rnvg+a6wl1vnUd59ILTotOc5C
85xY8UKve2GvB/8W7YPdPCJw8caTLPj0aMSytlu2OoEYukLLSWiOwf8UuBuC9IMjxuMY5biG
8ByV8UGMTOHJLJ6BvUH8J2U0RY1UL8LZz0s0/roKDsZ1Jkvib0miYt2Av/W86YpzwA3zVsL8
5Uie86aGFiTbFk3L22XoL4RrZvBtMcLpgszl72V/NOfzoq894b1SkMzaUt22jM2IFVtyW8Qs
5vyTZrVZvF8UPQd+8G7j6tFr+vfITMDaktSyLdWTN56xj1l84/EMxgoSX06yN79hvhwTF2fM
jlhZMjY3Wi9r6t7F57Tsae31tGGmaCxvxNAjElVlprjuEhtUxfqV9TjnehFP7idprFow2fbE
mv+uaydkTxZF3xNLy+u40DxV7mjOjl7VEzsZjOYkggfh3DK1WJQuUsS38rrclbKSab1T09Lv
3Ei/6wy13Ujd6vj8+2aqIPs6HzKkIynbWxL+54TNaJfLmbooazrQ1f1vQTLO9mfDeLRf0erm
7sHVoPOvd1XJ1EdQpWtr6F4RletjWGJfzxxnmO0/i3FbbAfRZOQzI6wW13Dgrsl32TLHx6gg
mWMfFqGnu27QBx6E/cCe3pO8VxcNG+U9Fthbz6POlo7Alx7gb7iPA8bSa3Kde0/elrO8foWM
OWWmzbeoRzoerqC+0AKffqcw2iWnzlE6REdw0lh4HsC3LpxGh+RM4hvuWRoxmj14ewBvDhl8
BGfXEZl1mB7DzYCFrTNbPjzrwy2jG/ni/wTiWLvjM9L53u2cYDQgu3MprAt9OudNt2WfpiRO
3TeWTfZdqVO2yjv0nOj7hoNRYS8bVgDfaXpxpyl3NjdyFyl3sPW9Pie93BMrfJrx2/Sa20Zg
Pfge3GmitwVdB6Pib9bsiqLUMne0tDlZOyN1tCS+ZqQ687L+knRYS+LyZMfo04p3Pd/lfLMb
9e7lLsFVpndjMTyLpmUXOOLZ2rMiqFPdlXjfedJJHJMBtpqRzHD3zsnetCoq1JX8lO+Y2rcg
I47Z6fmw02YruPdkbdvsvHlzZ6y8Ady7Fh4xGSqfwEEP0mfjvetE3xPX8xfNsM5R0XhaDMdc
6TIzwpfepzY9JzuzKGwtmlNBn206R4uRu1WQVV1Fi3LfWwz3RE46ZfR24Jh7tK65jU/5B9tj
OrrTUjm6rp3Qf12X+bA/eesyrmsuG3akrNRI0JEWJHa95oTYKskNYUH6ZHArnECs5fO5M6z4
oJrnw7PFMaeBJ5EWTNXNCo9BJ3TNycbRecL8QsX+YW95x1WeyTMhHxw356Ug9jXDjGbkpMxL
F9d34IxwXpK3lefJDN445pdFxnAzjzk61x+HXlZWWKbg7C73k2mZO2d81Rmal7MiTefNHdWr
6BVc6/qXUnBjcSp6aFbqa6GCxcByWn75OBFr+mZQEk6WKzSz5l7ui4bmNfEeT4Ju0Z+H9W48
fekE7Fe33OafEdt61+n+6Ia/hBLhzPd3xSVhIuiJ78cqwbvuNSd+aDu1XLJz6YxtvWSlZm0r
6RQdH0NWv+OWHDft552iVSpkEtZA2k/fR6mbjVlTTmGBRzxruIh5B44d6+nC42DCOlUoWJP5
mVnfsyZtz3YX7WwqP2971pi9ZE068+niBSvlprP2fNqds5zcPRezXHsm7/m2a2etfNHyoXp2
yppI+1aHlUpa47lcwkoXs5Zd8OylWaglAkt9axa1TjuFbN852/XYdG+ip8fal8xnXMdzcv6j
ogxdUZ2Y6mLlZGpsPDU8NNx/KjU8PmaND1mjw/2DY1OD1qkzk4ODycGxVGN9Y31qNu9ZfpBg
xnCy5Dol2/WXOb7/Ul7dcU6UW/ScuwEFRUUUFQuDqIDAFlhYFgRpiggqShOkTZLZZGSSCTOT
DWvvYu/12Xt59l6xYO/P3nvB3nt595ssCyjvF17+SGYm937fPeeee+e7bdiUOD8T2IVsSxyz
qwwVQ8dKtlgtftF4pvzmGGkxn3aCeB1FngvNIrbluSknr+Z2JnCcnJOPqq0Z6pa1mx3LT0a2
m1fPaKVgDLSSHTiW4+pigZV2AycVeS1WU+Dnlsfl615+xolNSmq53C+t3Adushjp0hqmn3dW
BNQrXBaUE1a3UdHmrNe21Wx7RTvpadhh6EQreldbU/OeE4Yx+BiFYmpNdOSra1hwUm6Tm/on
cktZzEduPhP72um0a/Rie1YQ666feRzE3Op+0d+D8tycawDpJrFdyQ/mh1FZck3KRfzQL6n+
iknPDbNmH12rTHfObrE0fk1VocUQt5yhlTeK+RjftBycnW+xFhSdMN4m5edTTpBvRRC0xh0b
h1m/6KVV982uStdo4J/wjZ1m0nG1tsoZM3ZtGDUs3SCyU9HyHBtgdmvUTateNg65zSGlJZN0
li2k+9jRUGMwdfIoq7/Ve0h9Qx+roW5I/9r62toOHaZO0Ie1dXX19frdMLDBahg8qHFQY6eO
2SgqDK2pKZVK1blliU/5uRVrwrHGBnbJcKHlrEHpSpMjW7XRouEHbujn+1nT3FSkCCbaQdoQ
UNc4cEAstiDuIrHA2lTf5AZhZNmFgmO3tg1jbn5Npym3BeVgop9PayryTiks2Fqs/WKOSlk3
ldXStEp2aKWd0M1oWVVb1vhI06jpLSZDR9OYN1WUdBSJs6wqDKcqJS8dWjlfAwiLqZTKu6no
WWVCAyfWWKirmUAUWsY1ok2X0YdWSdWvAks7rQ3gbyxouZUL2ChIq/FvnGhPbMNXDlgjyuui
eXMV+MVMVkVoOQsjTbsqR0E6ptE2x93KhKoUNftes8lEUzEotwOtDcPcCiW/iozpdqPtULn2
zfrKpWv0FC4LXJlLGyGli7GQiqHxnOQEBScq2nErnOTF9dzPEG9ozplq0RZshVGLpjaVtQMj
Ql0tclOhpeUW58dO24XWSs4YHM7ClON5BrCnr42k67nagVN+seAtq5OM7+vLQmPxcy0a9XQ3
7Wgii2FZJ0nfnx/GAeXsjL2PdtSwrIrA0ZeSaSx+WaFpP1UsQzTGthf6sZk2g4Jnl7u7ndZe
HrkGa/X/KIKabJTzanJR3s45NblwbmRSp3oMzEuo2vy5mo4lxzNKrOxi7mpaCz+2Xmlo3DU+
AFnYo+0IVH6WiQ98ZgyqZK0HbXbSq6UVLZviI2glqx3jfaNKdlWLqu6pWlK1WL9vWG1E7moh
mqj/m+O+GZDceJCo5DEuHg3C+AAWxYf9yiiX6sFtPn7UXZaqdyX7afHKlax2io/azTHTla0n
6bVhpRiPHH58aP1/mKyIMtE9MSIxLDEmMTgxJDEyMTwxIdFYcYcpq62nCQYt6/S6smV5fJlf
OWZ2xntVPfWuskr8eIyxIYg/f/XAg1jFp/3RAIVVqEIC7dAea2BNdEBHrIW10QnrYF2sh85Y
H12wATZEV2yEjbEJumFTbIbNsQW66249sCV6YitsjW3QC73RB9uir45h/fXAX4Na1GEABqIe
gzAYDRiCRh0phmE7DMcIbI+RGIXRGIOx2EGVN051Mh47KysTsYti202VsLtim6yYp6rSpmNP
zMBM7IVZmI05Or7MU5RJHTLMQNmk+c8q7r2VTU/ZMINKAQuU4TCulWZlaqEOJ/tgX+yH/XEA
DsRBOBiH4FAchsNxBI7EIhyFo3EMjsVxOB4n4ESchJNxCk7FaTidCZyJs3A22+EcnIvz2B4X
4EJchItxCS7FZbgcV+BKXIWrcQ2uxXW4HjfgRtyEm3ELbsVtuB134E7chbu5Bu7FYtyH+/GA
5mYJHsLDeASP4jE8jifwJJ7C03gGz+I5PI8X8CJewst4Ba/iNbyON/Am3sLbeAfv4j28jw/w
IT7Cx/hElfkpPsPn+AJf4it8jW/wLb7D9/hBq/kn/Ixf8Ct+w+/4A3/iL4JrsgM7ci2uzU5c
h+tyPXbm+uzCDbghu3IjbsxN2I2bcjNuzi3YnRZ7cEv25FbcmtuwF3uzD7dlX/Zjf1azhrWs
4wAOZD0HcTAbOISNHMph3I7DOYLbcyRHcTTHcCx34I4cx504njtzAidyF+7K3TiJu3MPTuYU
TuU0TueenMGZ3IuzOJtzOJfzaDPJFNN02MQMs3S5N+fTY455+ixwAQOGjFhkM0tcyBbuw325
H/fnATyQB/FgHsJDeRgP5xE8kot4FI/mMTyWx/F4nsATeRJP5ik8lafxdJ7BM3kWz+a/eA7P
5Xk8nxfwQl7Ei3kJL+VlvJxX8Epexav5b17Da3kdr+cNvJE38Wbewlt5G2/nHbyTd/Fu3sN7
uZj38X4+wAe5hA/xYT7CR/kYH+cTfJJP8Wk+w2f5HP/D5/kCX+RLfJmv8FW+xtf5Bt/kW3yb
7/Bdvsf3+QE/5Ef8mJ9wKT/lZ/ycX/BLfsWv+Q2/5Xf8nj/wR/7En/kLf+Vv/J1/8E/+JRCK
SJUkpJ20lzVkTekgHWUtWVs6yTqyrqwnnWV96SIbyIY4X7rKRrKxbCLdZFPZTDaXLaS7WNJD
tpSeshXOkK1lG+klvaWPbCt9pZ/0l2qpkVqpkwEyUOplkAyWBhkijTJUhsl2MlxGyPYyUkbJ
aBkjY2UH2VHGyU4yXnaWCTJRdpFdZTeZJLvLHjJZpshUmSbTZU+ZITNlL5kls2WOzJV5YktS
UpIWR5okI1lxZW+ZL57kJC++FGSBBBL+l8F60LYDAYIA+DLdPbFt2+bGtm3btm3btm3btm07
e3+iTlln62JdrZt1tx7W03pZb+tjfa2f9bcBNtAG2WAbYkNtmA23ETbSRtloG2NjbZyNtwk2
MWiWTbLJNsWm2jSbbjNsps2y2TbH5to8m28LbKEtssW2xJbaMltuK2ylrbLVtsbW2jpbbxts
o22yzbbFtto22247bKftst22x/baPttvB+ygHbLDdsSO2jE7bifspJ2y03bGzto5O28X7KJd
sst2xa7aNbtuN+ym3bLbdsfu2j27bw/soT2yx/bEntoze24v7KW9stf2xt7aO3tvH+yjfbLP
9sW+2jf7bj/sp/2y3/bH/tq/APfBYAAIwREcIRASoRAaYRAW4RAeERARkRAZURAV0RAdMRAT
sRAbcRAX8RAfCZAQiZAYSZAUyZAcKZASqZAaaZAW6ZAeGZARmZAZWZAV2ZAdOZATuZAbefAf
8iIf8qMACqIQCqMIiqIYiqMESqIUSqMMyqIcyqMCKqISKqMKqqIaqqMGaqIWaqMO6qIe6qMB
GqJR0B40RhM0RTM0Rwu0RCu0Rhu0RTu0Rwd0RCd0Rhd0RTd0Rw/0RC/0Rh/0RT/0xwAMxCAM
xhAMxbDA2EZgJEZhNMZgLMZhPCZgIiZhMqZgKqZhOmZgJmZhNuZgLuZhPhZgIRZhMZZgKZZh
OVZgJVZhNdZgLdZhPTZgIzZhM7ZgK7ZhO3ZgJ3Zhd+CEewMz3I8DOIhDgSUewVEcw3GcwEmc
wmmcwVmcw3lcwEVcwmVcwVVcw3XcwE3cwm3cwV3cw308wEM8wmM8wVM8w3O8wEu8wmu8wVu8
w3t8wEd8wmd8wVd8w3f8wE/8wm/8wV/8YxCD0QiSojM4QzAkQzE0wzAswzE8IzAiIzEyozAq
ozE6YzAmYzE24zAu4wXulIAJmYiJmYRJmYzJmYIpmYqpmYZpmY7pmYEZmYmZmYVZA8PKHjhW
TuYKfCtPYFp5mS8wrgIsGNhXYRZhURZjcZZgycDBSrMMy7Icy7MCK7ISK7MKq7Iaq7MGa7IW
a7MO67Ie67MBG7IRG7MJm7IZm7MFW7IVW7MN27Id27MDO7ITO7MLu7Ibu7MHe7IXe7MP+7If
+3MAB3IQB3MIh3IYh3MER3IUR3MMx3Icx3MCJ3ISJ3MKp3Iap3MGZ3IWZ3MO53Ie53MBF3IR
F3MJl3IZl3MFV3IVV3MN13Id13MDN3ITN3MLt3Ibt3MHd3IXd3MP93If9/MAD/IQD/MIj/IY
j/MET/IUT/MMz/Icz/MCL/ISL/MKr/Iar/MGb/IWb/MO7/Ie7/MBH/IRH/MJn/IZn/MFX/IV
X/MN3/Id3/MDP/ITP/MLv/Ibv/MHf/IXf/MP//KfghRMJoiSXMEVQiEVSqEVRmEVTuEVQREV
SZEVRVEVTdEVQzEVS7EVR3EVT/GVQAmVSImVREmVTMmVQimVSqmVRmmVTumVQRmVSZmVRVmV
TdmVQzmVS7mVR/8pr/IpvwqooAqpsIqoqIqpuEqopEqptMqorMqpvCqooiqpsqqoqqqpumqo
pmqptuqoruqpvhqooRqpsZqoqZqpuVqopVqptdqordqpvTqoozqps7qoq7qpu3qop3qpt/qo
r/qpvwZooAZpsIZoqIZpuEZopEZptMZorMZpvCZooiZpsqZoqqZpumZopmZptuZoruZpvhZo
oRZpsZZoqZZpuVZopVZptdZordZpvTZoozZps7Zoq7Zpu3Zop3Zpt/Zor/Zpvw7ooA7psI7o
qI7puE7opE7ptM7orM7pvC7ooi7psq7oqq7pum7opm7ptu7oru7pvh7ooR7psZ7oqZ7puV7o
pV7ptd7ord7pvT7ooz7ps77oq77pu37op37pt/7or/55kAdzczhd7h7cQ3hID+WhPYyH9XAe
3iN4RI/kkT2KR/VoHt1jeEyP5bE9jsf1eB7fE3hCT+SJPYkn9WSe3FN4Sk/lqT2Np/V0nt4z
eEbP5Jk9i2f1bJ7dc3hOz+W5PY//53k9n+f3Al7QC3lhL+JFvZgX9xJe0kt5aS/jZb2cl/cK
XtEreWWv4lW9mlf3Gl7Ta3ltr+N1vZ7X9wbe0Bt5Y2/iTb2ZN/cW3tJbeWtv4229nbf3Dt7R
O3ln7+JdvZt39x7e03t5b+/j/3Ndpc1t40i0yhJJHfYms7W/Y0u8ydpPjuMknsnGU5O4sjPf
IBESMeYh87CTfNj7vn7zNq5HzbrK7IcGul93A2xQv3V/5/7e/YP7R/dP7p/dv7h/df/m/t39
h/tP91/uv93/uP91ftmMVfW8aZuadfeiOXR8GLtmVo/+7Cj82W1Zz6/HrvWKmu26tlm2j7zr
d23H3VoURTu4l9uOP3KXKeFdtoe24fce09J9uWNk5RZavOwr1pfetVnEzaJrPcu1eMt248Dd
Sou3WlkpMX9LjPNK0r7T040W7/SqRonlbbHV1svWIvc7LToz0us7Ld5rZa/E4sOOF6Kq2GIw
wP2glw1KOHcdlckZ5XN5B6YRTD9o8UWJ+Q8y4i/0cF6zumbOh5IPbPZtKRxWHUvmFLwamMeP
vajIdy8ONZsNbJwdS3ExNoUpNjlf8k+7itUSNf145J1oO/fIe3K3ZF3XPlV8P3gKjceVkp04
lIOeLNqnRqNtO5RLs6xozoG2PV+13VDKPWHVuWgG4ua7QbTNmj+M4pFVvNlxp2zHnl/QZlft
QexY1bTDSi4+dKwajoDbYfH+lb+RfxL4BmwAQgsCCyILMgtyCxILUgtiAyLrJ7DmsaWIrefQ
+gmsJrBrAusntqFGdnFowwgALHtg4wkB7FRkKXyQWs+BDTXCYus5svFEyMt6jqx5jAThR2m8
8bit2t29R3sopaNH1V7LbjDjoS9ZwR319Ip7JZd7OuB0utpPK4062nFv6AQ7jEctOzMuGi2r
vbsT3a7iS9E8bql58EEio+trQeeQ7TgdoEcMZv3YuHte0xGay4fTH4l8vqvGrVNyRhSFYHXb
FOt67M2h4j87wXTqz26+PhM/rht2bPuha4+l7ECNem/5jkyXbC9E4gdRZlGWu29ox9PQfeNn
caRF7CsRhqv2yBsdv3epm5vHtFxfyWzGel/xT+vdhOdX8mXe0cO7NhZcS/dad0GuxPxaruP0
WL8+8XQ48fRarjjQY/HatpuDAes3Jzblic2bLevmJT3cm0FUBXeFEt6NiUWYWG50LEJ35BvT
bIWW669PvP844cU3No57A87v6TLgTcWaQuwWb+10ZcE7CxoDZtfNYcabg3drAmpNQLc6oFaJ
xXfWrrMJvz8JqT9J+INMeJAJ3+mER53wnfE/Gv932v+oE74zCY8m4Y8n3p9O8Pcn+POEHerD
h351Kfu7auHUSy30Lq+1ZFzJ9a260DRuJ7xk8tBWXDD3IzVDiu1Ji4/6bnjSqz4Wgne8F/3y
ySL3e73wsxIXDyP5kVlRKy6WHSvkC8E/qRO+yfLIX/J+oH2nN2RJyXLZ8MvzoaSN07hf78Wj
xec9eWrsxK6l+4jtdrwZnqub5kThDG3T9hc2KjVaXcoLS8Hza31fqcHietDa5U1r0PltLeTO
6MHdyeLVbc0PetFXgpb/hMFRDPMXdKU5L9W9aHjmP8hLk3jmksL5hh2PjL4T6m3Bzn49nr0b
z34jPMN59q2YfVe2znt1lX5go2f4Z1elmH3bi/ObE95nZtKOV2xKkp8myW2Swib5i/Gnpko5
38rgD/Kqn3+RQcvhIO/8uTR07lXolQ69Gc8+CXpLVNyzrmxddf/7nvE821HEBJ1WFu38tF7P
/o/8vD2t+Hha8RYVV8eGbpogtCj2gQKgaTYCioESoBQoA8otSjZA4Egshx/Bnw8vPrz48BLA
SwAvASINEF8AfwHiC+A5gOcAnkN4DuE5hOcQNQjBEYIjBEcIjhAcITgicETgiMARgSMCx1SX
CBwROCJwRFOdYZHAIoFFAosEFimiShFLilhSxJLCcwrPKTyn8JzCcwbPGfLNwJGBIwNHBo4M
HBk4MnBk4MjBkYMjB0cOjhwcOThycORTHpMXy0EYyAfC2d2EQBFQDJQApUAZEDh8cEwxx1Nu
2kK+APZzJowD+nbjj2xF/Ynte35oKw2P9CjXCj7QF8zQO6XoxIMz9NQbHLXQUWtcO91SA3If
xu049G7BDrwvnZrTd7tTswe2n3dsz8mi5w9eX4pG/tzqlVj0LbH148OcbqH9jHqdcxA1r5yC
xsNZyWeP7NH5wj6LZkY9bzbQ/+e2WOwF/aS4Z/sZ/TvEzY2q5vWM/vWgGZsZ/dPPsJrfl3Pp
xFMTR3525CsFh546oKOes4eWIqXQ5zJG+s30uCzacVtRhR5d+ideoyDkHmSbLJck6Ir+LOqL
hj9RNR94RS23WdF6k+mFjVXV+md2pCu3UrGr8j2foK6gR9HJmNfSkXG2UljBr5RKrTSTz080
SrGURVUbtZJIUyplzY7iYUnl1svXqugGq9JrvCi5BkvKx0yrzTDawS5cUkk0QoJmAmit8jNa
2iODaIM0OtfbpAcXZp9MGBas1UYZS9oujVZyJwycSrAYTMgLil2V1aN85Un0KCYp6ceuFKog
Kriff+H021UUQ9m0zY+taHj3DCozprXD0Hbyk6dm3f0zhYZWquVYvVtxGppOE6eRebslSoFy
i0xHJ2RuTokCINiam1OiGCgBgufY8oZ5ABQCRUAxUAKUAk1eEOkGkW58ZImYzZ2chH4yxWJt
48hGEIfIw8SSBJmZlWjS6fiSKDAVkshy5KhGaG4DORtYW0QVb7AusbGE6QYIeaSoVYpapbBN
p1oh33TK3PgLAtQ+Nj07CXKjk8jUmVCKdTFizoFSoMmf1eW2zuQlh26DdWBLbEZxMtmajILQ
8EqUwHbyN1nEQFgXw9b4S6hAIdCkyy1KMJsj39zuZTbFbL54SGfuMtJhV3Pz1SJnrb8smJDl
zULoptOUTWcDZy2bZqddSGA7odwbGxFsgksjXxj50shrI6+0TK4XWr76lVEYw+SFmbiyE8rD
q83m0sgXRl4ZaecVw6tXr67s+d9EQDFQAmTrmNs6EkIdA1vHPMJZCnPoQtR7QvAcTeca72I0
nXBb+TwG77TOdDWJpnXwHCNmnBt7riUyXiL7FUvIWkT2NwIhaxFtpvcEncTPcP5tVwtsV0uC
dOq1vg8duhXql079155D0qET+xF0OVAKhFvBt2cuxdsb+Ql08Iw8UrzRkQ9/yRRfBt00O3FM
8SGqFJknky26fYDZFLGkiAX9MgomHaJPUQN0zij4H9tVEyPHUUZ7t9bGu7Z31/HasTCwkYKC
E+Rkuqq6uvuEe2Z6JZ/WB+/BXNB4PbFXdraDvZuwwSROuCLwlVNQEsTPJWbmYmM5+ATkBIqQ
IAIRiSAhpGSNIn6EBISa7levaid76Pm+/rrqe+979TvUL/UMyDSlLpJoGXWRzOfPG8naMs+F
DDKOpSRG5r/6fJ4fNeBOnGa+r+fHrzkryqmVPx+Uj5Fpztp4DmtF/XIyyMmUJ7JW3MFavgfP
DH82K+5vLe5vLd+Xuij/leeNP414KmjuEX5P9jt2FtxjiMFVkcW+L8fIn/Wxn5PMHHM8/N7N
GZtx3mcxx0OTM2dYxrmbSY4Hd65M+h7kIjkemhiSGKnPx/HgrpdJrwGZKn+rY18/MhzzzI+q
Hw9FfoqcFVkp4iqiaWLY0bp4ZevZS/bPZby/YWDvXiflfsdGB358UrJ1Qs+472kctM0CP/V+
HubLAz8JfOlxbJXOI6JqEOsTGb3qO1zgm8BXgZ8EviSivfUF6CbwlWdi54Pz0kApFSilAqWU
a51Q4UQGSqlAKRUopQKlVKCUCpRSgVLEsaeC84hoZKCUCpRSgVIqUEoFSqlAKRUopQKlVKAU
maTULFWBUjpQSgdKcYTt7u68LFBKB0rpQCkdKKUDpXSglA6UIk7GkcyImGWBUjpQSgdK6UAp
HSilA6V0oJQOlNKBUmRid3Dn5fDiVoteTE/SU/Q0vYSeoZfSy+gRIyZGTIyYGDExYmLExIiJ
ERMjJkZMDEkMSQxJDEkMSQzuKbHfU3TLr0brq8DXe5YvVVfX91T170r9uzn6dVm4d8TcO2Jl
cEN2NoXNH1qtnjm/tr62fvFSVV3una+e6zef4hasgo1hcemOkwV23Vi7cqHfW13tr284RE2V
dNZ0kJ19F6r1i9fWLq7vq9b7G5fWrl6Y3ni+qp1r4ENFE1aRJPi2BGAJq2FRU4yaYuDFOSz+
NcT41xCXsMgnUahEgVL6wi5e7T2Hwnywt7q5gSAydQ/x44Vq43z/SvU8ckE8CS4SXCS4SNQg
UaNELRK1SKcd/uFIcJfgrsDdnpSFQ57uOW+m4JjO9OjOF6trV1c3n3n6Sv9rdSnzvfFA0KJW
IGxRBxaCFky80NslGOaqp0mYqw4cDlo45od7n4ztL85f7Y9GwzLc3wv8Jl7zQrz255o4mcz1
dr6jX80B/Wp/tok72Nnejtfpkh5jM6XX2effW9bp9jZZ58txkfvjgXJc9f646uVuqvd3U70c
V70/rnq5i+r9T8ZmTvva1uhOn6YKa/SW6VXsvex7V57d8njp1XhgeVyLalyL5d20qHbTYnlc
i2pci+VdtKh20aLeeWuCM5V362hNqonW7mwdJYnZasdr06cGb/rU7sE66tAOVuHb9Aq9TfJZ
8Qk3vbviqW16d8Wz3PQsV3ay3NzJcsWz3PQsV3aw3NzB8hy9LbI85xNu+dVxrlkdW7UZ7WL2
ZOnClrBLje22YGNYCatgNWwCa2BT2Aw2hy1g27AdnDUyl/QUPU2vya9zCatgDWwKW8C2YTuw
TX26QP8C/YsStqlXt1uwMSzat9G+ncHmsMBro56sySMTfC/RvnS3FMVbiuItRfGWonhLUbyl
KN5SlDT0UnoZPWIoYihiKGIoYvC+olSjr0kUrIZFPG3BNid1O4nxzqwaPVNm165v8qk6olO8
swqdI8JqmDfbU0fw1pzhbZPCZrCufwFWS4i3YF22Nr4rWA3rGLpZqAyZGOpKlK6LpFTV15+6
+h0HYBlgGWBl4JY4Th3YLr4zd0YlM45T5rIQl/8oVEbGGRhn4JBCtxS6pe47uKWunXt3KJx5
/Leg+W9Bt6Bu5rI/3VhXYea+A5WsfC4XKVwkdn3ajEDXDDpRgS7e3fcS75hl2ZLLIJEzJ3OJ
PjlmcwbtuQfp5jZoI4oRcOWepJXLmzDi8hpGwDZPGQE/r6hymamCjumRkVtfOZXRxNXEc2ss
7zBCnIT1u1WWdxlhnbz9a7c68pIRVpFk9Bx76u1WXUE8w+yG2d16KFxrVsqVpw25u/2nYCau
PJ36GHatwq05rDGDuWMwzgWVy8iR605nEq0MemFFp5jXqWNMNZoZbiNknju+HFM/t/ycyh1f
jqmfOX7G5C67G9OEazBpxfQca6yLLjRoTmZrMaOLkj0yek7nJAbvNhFiSU/RA+821k8OnXPo
jNPWtNmXp17CUy+RYNzG7pNjH8mxX+SYWW3NHmTMsy5RjnHCCFF50iXKMTaMeC+lB6XbjGjy
5ppMtONNNpoMuSYTDb3bZKp9e8YSxx4nWL6EdyjqVkebY5+QN1djkjjebj0nxuVdYoSqcDUm
Bqp0MLMLrMkOUDuotIO9p8M63RroYHaV7h1rBvc808GY4h5oOhjbbgfvONlLh+DWS+L29Q6U
6EKZDmt0O32HM5onS8K9PskdMyqBu6PpourS1QDuJfJ2OeJuJja3X6sTuHQxc3FbNLgNG7fW
ui4Tqu+6PFAHt2Dj1Ohi3XRLWOCUGE2ncolxcaqVwC0xfiXwXSW4hZoS+CXwS+CXwF1y6huu
L8O7pHHn3VKbEUVP0wOHpQ4jKb2MHpgsOWSc3m7PLTBPCvLgyjI87YxmZq4tw7VleN6ZBPtU
jL0xLvkFu2S8xAizc30ZnnYmYXbD7CamJ+lRGZ54xrACQwzeNw1PPcNTz9666RGD5569af80
Ovvx/SkxLEt56ra1X3yytoMTj8s7ow+DT39G3psSk9+NvhAt2sDE4Ojx+ks0aLfh2Ktk7Qyf
OCnfK2amouiBfSanoqmJ6ETTa3jiSfm3n9n3CfG/aG5iYhQV/xnOL1g08d/h3GF5qpgX/47O
2GcyuiV+Et23z2RUiX9EL9ln0jZ/c3AyHgGJN4czs3Letn8QPWKfG/YR0ffs70T9fso+o/YP
hoePjtL/ZTB3qO733qClG2c4f0yeKRbEHyyft8U70aPRoviTtZ+z9hfWftban4tfRgdrnm8M
5+blDYv3um3+utiKHrefvy9eiKS1PxQvRsfrZu8OZhucdwcnnpDFjPiBuF43uSa+Gmlrr4jL
A7n4yF3xhmV6SnwwnN4/4vfBYP6IvCf+Ki5HC7bVn22rhxfn7on16Cn7jCq5PZw+KG8WB8Rt
W+ZtK8ui5TgRvVr/nhLvDGwii/cjcSM6ar/9SrwcHbH2x+KVwZHF+3fFv+pm/xxlsXivDfap
kRkenJX3i2nxmv16S3xkFf+oRvv78LFMRsVj4ltRyz6TVtT3rfe+9ebFtvW27TBt26HZtkOz
bVlsR3ujSHxov3xo2zwl/hg9K34f3bTPq9afsim3BlbBO7Xz+RPyjviGuG6VmL9rtZuw0ReH
07MjZtcHDx2um10fHpiVX7onfhst22fSkv/d8OFjsrorvl2XcnN47Piow28G0wesdF9vxsJ2
fGE0BvfEDfFKrcTLtQK33rKvE9Gc+Gbd+ePhgUPyJTv6Z+1rZX+/Y59f2+eBfaZss7O2hrPR
V+wjbPMzw9k5OXdXfLnufHowq/5PbNXGNnWd4XPOTWwn5hInMEgJ4Ti2cc01IZkhJA2Lc53Y
lNW9IQS22SUDQxvzKQhNQGp/kDAJtRXqiMa0NukG6SqtqKzl+rgCQ+gWadq0D6HwD9puJNOY
trFpsE3rNLoue85xBq3Er/3ZTd7nec95n/O+7z33w5e/p23AqW9Qu7VBfM6nen48D2fThJbE
TbJR6xLPcDS4SWCxjHblW1ojjRNalzrhLsH9xWmx4BHlrBdlxZunM19eKcvFlTAsXPPVdHju
udOM/MLFEY6bsVWd0mog0ZpxjZqx/814GFarHY/kPVW4xZ/RIqrtCMnAxmE2rAQXMgJ5BBcy
QmbUTIW2Fue0lszCNFzAteQujGH+86QddhL2Q9gMrFTNZmAM842okAGOwBgyNmDsAZqwDGwY
Ng6bhN2FOcmUVo869VA3AodhNmwaVoILshJ9rESsSvOST1yEcDLERs1WOkSG6BAb0oZKhkqH
PEOVLrNp+cqIuVfCKgkhQHOmrL9suExrLDPLuss0T5m3jBVmJ4WzdTXIrHK0rv7Aum3ds7Sq
5hHHiJNNxebRSjINuwPTyBT1YOTByGO+oE1Fp6N3otqUNW3dsbSpm9M379zUpuqn6+/Ua6ZV
0xpp3k4P0iF6kpZw2kDb6UZasl07qA1pJ7USrjVo7bgXSjLufvewW2t0m+5ut+Zxe91sxD3u
tt2T7mvuUtsx6bjmmHHcdZR2OzKOfsewY8Qx7nBwZ4Oz3Wk6Su7GOtmH2NRxoA1jZBg4ojyP
ikwCr6nxiBpngP1qbAK7lecHNkoP5keuD6AbBo7ApE6O/cBGOYb58Qp/H3P9wBEYY++bS32N
ATPAPAFvgJEAvRug1wIzAWYHJgNsMtbKbqgub6DLG6rLG1h5Q9W+gbzwYH50e13prkN3Xemu
Qye9h81lgP3KM4HdyvMDG6XHrgt/c0VsMXsNGbcDz8CmYRppALbDDqoRlwr2GtBkY/lHV0aG
C2xMBPEiBPmKtKxISxXlH1kS2R6rYGNIOYaUY0giRxzWLkezk2xUxKV2VLQVqXX1dKwZP5Wy
lVFyHsbIRuAZ5TUA25V3Xmkq7o9t4Izy+oHj99dtVx4H/netxsbwNwqvgj2P2edNNyOLFhFC
qipdVQV2Weyp4gX2rgh5QPkiCUmxBUzD3uv0zwrfUXhG4TcVfkVhhen26//06z/262/69Vg5
e4IEMH1X4R8U7jXnB/TfB/SfBPQ3Avp3A/oE/Q3xIVBnLvHpv/Xpv/LpF336Wz79lE/v9emb
fPqTPpkqRLxEZ7US6TaFS83FXv1fXv3XXv0XXv2nXv11r5726q1eyOlf8aOp028rfEVh08U1
Ol+j167RLzO8mehWUUHKJhijW4mulQsjygtamSJWJ6zloKXCioFqhNUDWiKsZ0ELhHWKx8pY
Bc3hi4Sz+TTnkjxPGMcQdhfJJYxtoFJhPMYL9N/C8IM+Ftla0D2RXQb6SGTXgP4u6Qr9G8ky
pKF/EdnTSE9vk5BMS39HguwcuCCsdqgvFqvTd0mULse0IKbsgn5fGGiOnhVGCPSmMAKg7xXp
DWFw0Osiuwp0WmRPgb4jsrdAYyK0X+YbJSGV51USVDwgrBqEDwlLZugXVgPooLCaQPtE9Cpo
j4jekkt30RzFnU2zxFCd7hBZA+HtcyfyVRJS4V7SpDI/Liy5JetlkphOE3MnEqed8sOOdtCc
ymIKoxGyqDCCoLbizn1BZMOgFhHCHtNmETqNnVs7V2CFvD5XaABtyER+YZyDiIvsCtAykU2A
auRKNLVgrmoViaqmKoUhVR5hePkPqJtkVcZyEqRjF/gnyPtxtEC/LPg9s+Cigv8jBLrA/2Tt
5H+0Cvis5bfxCJ+7wKchvRmFa7r5L41b/MOsj//cgMKs4T8zVvEfBZ/jhdAEz1vLeA6N2dmd
/HxWZXgniGWCnw0VGMXq8eyT/FUjzF8JFmQP34D4BVkDiY4bz/GvBY/xw7gVBq2X+IBRy/tD
2/jekCy0mO8xevhunMgurOnL7uI7jFM806Q63mZc5Zub1Dkks+qMvhhVgQ3ZHr4eHSDQLgPo
YB3uywiWrmqakHtE6mln/ir/UvMVhl9hOgx71lzlfM951LnTucXZgd+bR53LnXXOZc6FriqX
xzXfNc9V7nK5HK4SF3MRF2ELC7MzZpjg7bXQ4ZHkKJFYonwPkwiQ3ySMuhh5gtgLtCRLbu6w
m8PJgnO2x24JJ21n99ZUjtKvp2nSnnyaJHd67Y82+wu0fNNTdqm/g9pVSZLc0lENsc1eLFCy
JVWgs3LF8Rq7qjN1iVC68vjLNZLXH385nSaLjrRXt1dFKx9bH38IZOYwEQ8/OKrD4c+Mau1v
JTen7Ldq03ZEOrO16aS9YrO3N3WJ7Wd7E/FLbJ+kdOoS3c32J3rkPN0dT0O2TslIlO2DjFiS
IGO9JCplmO/9lIzmMB3PRaNF0UaakyI8NBuV6KmiqPPTIu0E7VSiTu2EEp0uFjTQBwqakiAr
3U8MVdAo3a9k1VKWCwaRKRuUklwkCEEuGFHhTQ/CoWL47WL4bRkuUPog3hQsdhsiQVUhyELQ
hP+PR1/H/7CI5tuOHEgl+vyJjD/RB8vYJ47srraHd3q9uQNHZMBra8HMzqd3S97RZx/x98Xt
A/64N9eWekg4JcNt/niOpBJbUrmU2RcXbWZbwr8jns53HWs59JlaL92v1XLsIcmOyWQtslbX
oYeED8lwl6x1SNY6JGt1mV2qVrKngya7UzkX6Uh39hY5z9zleFoyNXXpjkWe/qh6dNbVVR+t
uVxC6FniDqftef4OW4fJUH2sPiZDeKRlaD6mK+ZC1UfX1dVcpmfnQh5MV/o7yGB1Yk8c/wM4
BgcP48AeDwwU97q6GBgMJ1QcgkF4g+qAEr60ATU7Fx8khx8c4XBRSwbCnamcZSWq98Rr8BGf
l9/d4fQACYeLBcPh/xBZxTYMxCAwL6Q06b/MAshVinTegAEyh+P9GIEmrUWTEdLnwMnbFpI5
g+GQizuhJlin0N9T6F/O++0lb/kIaSp8g3kqfIW6N5hD4V9Jq1WvpGLiiB02fJAWK17o/usg
Sj02dLh259YD5i3ZJm+4T24clP8zgMeBxlSwJp55jFf4yOV1aPOyZ8pE2/rAXwEGAP+2WSkN
CmVuZHN0cmVhbQ1lbmRvYmoNOTEgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0
aCA0ODEwL0xlbmd0aDEgNzI4MD4+c3RyZWFtDQpo3sw5aXhUVZbn3vteVaUqS1X2DfIqlYWk
UtklqSSdVJIqEggJIQmYYtFUNhIMJECIpEGlYVA6CMbWAUdt27ZpF2j1JYAUakPapXW+1hm/
ZmTma+1WFBVtY/PZEUeh6s25r4oItl/3fOOfeTfnnnPPcs+55577lhQQADDAdmCQv6Q1r/Cf
/np+I3KeR1jeNTIsZb90aRcAiQYQhd6hNeu+yH9pA4AmHscRawZGe+N8trsBTKivyejr8XS/
/OSqHoDkUrSf34eMCBv7ETqYh+O0vnXDW25uXliJ48UA9PLAYJfn1PmTawDizqGPHes8W4Yo
Ex9De5wfpPWedT2Ke6kRIKEP9Z8a2tgzdGvEb3D+8HoAtgGI8DoZBxFjuV8swhnSA5g9DL00
MpSJIqFEq6GiFr51NQ6uHwTHBemCIt7pX0CKdAbywvZZqbgaCsTFkIKQzO6FJADlbBDO+d3K
tHgTWPxrlbczI1D5aBAClwfS4QbIgkXwAlyAkyQbmmFKeQO6oJ3eDDbk3wXHYQr+BE7oBgqJ
ZBtIyoNwJ2TATngY7EKicgwWw3ldBMRCGpSRQdBADKyBh8jbsBAacI5yqIMfw0bslyL/S1KK
EgJ6WI3e74UH4CT8G7wDCThjLpwhWvKl8hzUQivGsBVOwJ/EGnEPRMHd8Bg8Ab+BD0guOUg+
YZ8px5TXlD+jVRYUwHxYCZ3YfgI/R73H4HfUwn6hJCpblceVVyEZoz+Mq/4NvIy+LhKJLCdd
9FE26v9aWa8cxjyEYswYPbZqXE0TDMMvUfMMXCIh2HZQiVbRLr9JiQMtpIAEVoxvGayDW2E3
7MVV3A8/g6fhPKkifeR18hkNo9vpKbFZ26RtCjnle1OpUy6ij1AwY7TXw02wBS1/AvfAfrT8
Ofp6CdsF8JH5pJxUkoWkhdxFbie/JP9NrfQteomFswiWw9ysg21j77GvdKJvif+A/w2lWdmC
uSSYcz3uZC2usw1WwRBsgpthG56S3bAP2zhm7zA2GfN5CtuL8Ed4H9uHcB4+xZoTcY16ko0t
H1s5cZBFZBm5kawhm8gB8gzxkpPkZfIJmaHFdD610yW0ha6hQ3SYjlOZTtBT9Bz9K0ZZxlxs
E7uNHWYvsFfZ79kfBBAWCR6hX9gs3CvIwpvCBWFG8IsgWrDlih7xYd8j/gb/SiVDKVc6lb3K
OLbzmOO5uJoMyMT1NOOudkEvVs4Qtg3YRjF3u3BF++EhzB3P3jPgxTvAFNbwy/BbeAP+gOv7
I7wHX8JXmBy+vhhiJjZSgPn9AanDtgL3aYRsI9vJPnI/5nmCHMM2Rd7GVfpxhcupm95AR+g2
upceoA/QE3SKnsGdUJgGdyKe1bEGdj1byW5gw2w/u4/9C3uI/Yx52RT7rUCFMqFZ2CjsFMaF
R4SnhVeE08LbYr5YLo5hk8Vj4q/FDzWRmiRNsaZV49VqdKO6j3R+OAKvwAQc+/bZJ7uJkUzA
k+QjJrDt9DXaTg30DNkh/DvJxB2oICDug/XwOUY4h/yelpDrWRdZgfnbQXrJSvgpS2aPsEXw
mrietLJm0g2twgG4LL4IHnGMTjIqjjEf+Yoehj7YR2/yPaG4STi0koP0UayYW6ACsoREOEPt
wgmSTrPoKe1TxAuVWg2zszJdBI4OsvcxzFZdBPkEPOw9PD9n8Wy10EfxnvAheVu7BKPzsadR
5xaoJAf9JnhCdNMOkkwPksW+nb7/Yg8oPyMJ9D0An8lXTWux4pYph+hJ+Asc8H8lvAsn6Vuw
DO8aXerJ+RzP3s14p1kOl2kYnqdWvI8MOaqqKn9QUV5mLy25rriosCA/L9eWY83OmpeZkZ5m
STVLKXPnJCclJsTHxcZER0WajBHhYaEGfYhOqxEFRgnkuCwLOiQ5o0MWMiz19TY+tniQ4bmK
0SFLyFpwrY4sdahq0rWaDtTs/ZamI6DpmNUkRqkCKmw5kssiya87LZKXrFjajvRep8UtydMq
3ajSQoY6CMOB2YwWkiu+zynJpENyyQtG+sZcHU6cb8Kgr7XU9uhtOTChNyBpQEqOswxNkLhK
ohI0zlU2QUEXhlHJiRanS06wOHkIMkt3ebrl5qXtLmeS2ey25ciktsvSKYOlRo6wqipQq7qR
NbWyVnUj9fPlwB5pImdq7E6vETo7rKHdlm7PqnaZedzch8mKfp1y3A/PxX8zxMkja9vvuFqa
xMZc8f0SH46N3SHJDy9tv1pq5r3bjXOgLU1f0DG2AF3fiVlsaJXQG93lbpfJLnQp8ZXwVQXW
12NxcU7HWkkOsdRY+sbWduDeJI7J0DJqnkxMdJxQ3oVElzTW1m4xy1VJFrfHmTwRDWMto0cS
HFLCtRJbzoTRFEjsRHhEkAgNu5romZWplKrOqYaW2cwSHpFlIVaELHVJGEm7BddUyrueUhjr
KkU1vNwEreRu3JF+OaS2Y8xYxvncXhbTjRZp7AvACrBMf3otxxPkaNKNXwAneZ3M1hrKr9Cy
1SpnZ/MS0dbinmKMler4OlvOiJdWW4aMEiJMHzRjbj3usjxMv9nMN3iP1wGdOJC3L20PjCXo
TJoER57VLdMOLpm6IolZxiXbr0hmzTssWMlHgb/Txci6jNm/CGNslKuvTCaxf0fcE5A3tFoa
lq5ol1xjHcHcNrRdMwrIS2dlQUqOqm1nSTRI0SSmSrEoV80q80F7qCyk459GLepur1aHValy
iLRANnbUB3q33mz+Xxp5lQvcSkXfmAXDlMus147LrxlfE17oGMOAhQza0LZibEx/tQx40nQG
P7676pb7D1/O1Q2rabz6Oim8jk9Vfn2Nb6uI6CE4Jx4FjwCQLnTDUs0hqNPYoZ7thDKUtSHY
UHY3ytJRf30Q303tioL8RQgXEHIQWhEkhE4EN8JihG0IS6kdfoWwB20ruD3HbC+0c1p8BaLF
5ZCKOFL4ABKF9yFTkwT1wmmwIC8D/ReJodCEdLp4C0Rr53Ab5TyOF2vSUeczjGETZAjPQyna
lou7IBZjr0NZqZgFNZpV6O99iMV5HtN8RNYiXiQ6kQfKXwRgf8C52zCOUYQFbAZcaLtQsEId
W4TrOw02+gjUInahPAahQHgQ12SFeUjz+EuQdiPuR50mtLWivA7zWY2xNrPPYSXiPJx3JftP
OE3uh4OIz6B+sXARosjXqt8KgruFNvMxV6DRwAmNhuQj/hLhom45ZGk/gAacf/UVzIqgl+cO
n/D9wZyOon0v+qlmT8HaYI45pHFfOoAPhdPUrgNlL65d0uzHPb8FbJibG7QfkB2YqyYV9oMH
cSMHnK8UoQShPAhl4lGiRzCgvBXHizQt0MVBmwKFaJuLvtp4baAsH+NUIRj/4mD8KsY48zCv
1VfsNYsgG22sLBJarwKYhRl835jB7xwVk4NosxntK2kBfgfdQh8NANSySOUeFklXBzBYkP6R
itGWHITk6hiIpJnYMmgGDJJYPB03qv0Sta9S+zze07zJvJQUL82dfJijnMk5WYjSHIaziSkF
mZEpFZl8HOcoH8hKefdQQspZhMOZhSm7KwpTdiLkIYzgmOtlHspKGcwcXDd4++AdQgnExuIu
R5p0Di95/5ll0SHRISXjXnLKYdeO/1o7fkQ7vkY73q0dv147vkA7Pl87nqsdt2rH07Xjadpo
XaTOqAvXher0Op1OoxN0VAe6aK/yrsPKD3+0xsiRRuC9oNJGynt+0PFOQImO4tedHMUaaENr
jVxqbfBqlRa5xNoga5tXtk8Qss+NXJnu9hJoa/cShbN2JfGn9gkgRNm1NymI3W7SIE91QUOn
JF9stXiJHm9UoqWGyJEN0NBWEw+xI1XxVZGVJvsC53d0HcHe+s0Vb736amgefR5SyGb+8UWG
j2hT7tFybityx1XuOOeOq9z4OfL+htZ2+dAct1zICWWOmxypPubYyt8DOiyuHoQOec9IX7y8
vVOSJhzHgi8IGR2dXX0ce3rkY5Yep+ywOKWJ6q3fId7KxdUW5wRsdbW1T2x19Dgnqx3VLovH
6T4BTaRzInvfNe5+fMXdCcgmnX87o5d08imzucemfd/hcR8XN3GP+7jHfdxjk6NJ9ejqb60h
Dc3tEzqocePDR8VHqEGPW9WRZHbXxBqHKtV9KzfH35r0rADkcTDgszgU3+vCELjIVm2r5iIs
GC4K5698QVH8reXmpGfJ40GREdkmSw1YN1u/dW3iF8S7+p0cMJITyhTdPhmZUmh18+cM5Y8g
kf8DhOGmlTvmarRdyBOFLgZ6jdjFGE0M0QpdBBJ0WaXx1ibjTEWjr6LJeLGi0eirgKoKXwWH
gnyzyWxKxw5rGy5LbOqyQ4RL+MSZ4rXtX0Dn4TdRBDgcc+v19eH9If2G/rAt+mfoK/yQEK2J
RPHHo07rJTnHQ0eE54zmefFW44xvpsKIDaqqTHZ7QT5ZTWLSwGSEkhiNhsZER8bSef5L/j+S
wotbH2qqv9e/wbqDfEmspIQo67Odn/r/+eV3/PdNBx6mIMjiTUiJMOqYJ+A3hmgjNJoQKjBB
ZJlAo1FP+FiijEsI6IRWyp6j9TxDtO0ZciPchdbPEj9mzTdJ3tQ8S9fR9YBhXkyYObc63jjN
G6YEE1OVmDB9h5gbb9XdYnxplsAsmUOYIF9qpsOk2b/BXy/e9PVH7JXLdjVC5Sxbi1nKghLY
7Jj7w2ySZU3Gu112yfzrillSWJEtO4kBFfNT0ywRXmJ2hMUW6kh+ocVgj4tLDPUS7fGi3dIX
GQmFIh54h8GWl5FQav/CnN2HZ7dppnF6Ztromz7X5OpxfghVjdNV09PGigpTnJ2YIuMwubCa
ZGRmZFxXPL+okH+TaSypOMzMsKRqYqJj42I5DyypXGF+nIbzigoxMtQg3nm59yzf/4tfr60p
SI81JWxNy3O4b1z7zEctLf6PT/7q4xueP/3gTx/s3bonLzWR3Zhp2bD1uqaReltlar4+4vbI
uMbcnHXrfjwycufr/ncuyP3/ukOT+OLx46devb/1J/lp6r1ROUsvMfzSgQMOy1jRA0UUAt+L
+OGojzUUFpfkpUrAErOMUeElH1SGe8lcR7x2bl1iel1iYVZWXlShVptXWGlwYZ7MXhI/aRgv
85Jah6Ga5cXW5eRVJzhdOD4ymyofT9W5q1NlsudNnzOe4ztsirTzhCG6kjmyOornrQQTFxtI
3JW0xWGOVHZMtFbNZyCZnMnbrIAn9dJIc9PaJ9ccLC9OLVkYn2lfsTYnpxGfaMnWlLBImz6u
2Nx202B7nS1xTlSolJZdtmTT5PO/W0f+nNPtWl25LL8xNaXoLmNi/4r2vDxBGxsRoQtj2vUr
+jdbE5YUh0plVldZ66M99TsC55H52L1QCHscsWmZ5pxsIynIMVKmj40qzNLkDkTpvXTUEaIZ
CKuLMsyJKPaSpCNE7wzxks8doaSwoAJIRUFW9rwCL/nSEZaZmGc+GLs2e3dmQhGqLjxifnFb
sOR4zZ3jR9iHNwnjxWkjprNqxod5rKow2QO1Z+f55Fk0Ybp4TZUUadQUBvvZWuQZxrNgKjJF
B/RMrMwQkhadYNVnmTobFrWH9B6vtS3PoklRJZa0uJTQZG3o46ntOcX7FrJ7fb/ckp86t3DR
7b0rBje4Lal3DzSmzHckZ9iTs29YsKWNzfGd6l1RXOmik/wsEibQPnEtGCAONh8t0cWkMC8p
cxgiUkIggZ+2FMDxscgUTUJ8AlJHzPzuqC7ZNz1bNr7pgvzaUUc2iTPqItMgXB+aRqIFpGIp
UiZtRBoJM2AXJeJdLY7f2vg9m/DuRyQ6WBZYI9ri2bqZT/uO3rb96NHttx1dtmP1qp07V63e
IZTcdvTobQi3BsY71DMDp+lb+L5pAPMJYOSoIzxEC4lhmoTQsL8Egz1nVKPEzF/li7515sB9
Z87cd+AMrQ7gM+oXSeF3tuH/Y3v5+zXSQr6+ttE937t9enVjUf+/mroHerh19pvxtsBbI/An
dwSOArSA9L4grUH6pygFIQRHfvhVkCYwlxwK0hTCyatBmiH/TJAWkJ4J0hqYSyPbRod6ej1d
PdITUltfj8R//hhGllQ7uHFocKNnuH9wvTQ00JUrOT3Dnn+glMcnk1oHBzZzziZp4Xq0K7Db
823YFeZK1QMDUkv/mr7hTVJLz6aejSM93U5nzcLGOmvr6LrOwYHGtr8/hDYYhSHogV7wQBdi
CZ5AaIM+lW6EQViPMBzUkvC5Mggbkea9B/n9qoaEnAG0z0XKqfI933OmvNnIJGhFyQBsntXZ
hLyFiAP+CsCOLR9sQapQ5VajxQDiFrRZgzEMq1YtON8mhI0wgn03xuqEGpyrEerUX0VGYR10
qt4a0T/XXoN+BzC+jf9A9/tIA9U5hb5EtRopGHH9DqSmxYjAv9E5dzscX3w67saIii90c3Qq
+xf1z5dzPLn4P84qir9S95HOoP7CGKz8/xFgAI2r+loKDQplbmRzdHJlYW0NZW5kb2JqDTky
IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMjgyPj5zdHJlYW0NCkiJZFHN
TsMwDH6VqGfKOkFHD10nQNoJAeqGOJvElIjGqZKsjL0aBx6JVyBJM4TgZPn7s518fXzWq73q
2YjGSk1sybL5aZExJK6FpC4AD9t1XmVs1dSP4NAoMK8bdM6z9rev8r6mXmtyjEDhMttKhfYW
31qtgE6udC8yZuXBM/PCa2fN4qzMq6KoNxx6ZCP0u8BFqm61AxeSExzBuwG4dO9/pDeaT1I/
Wg8eDuC17rVhT94YzjGpdlP1/GUvO1Lol92RdMHEXrSRhxRdnge5v84lIL8oFwGKIgjmsFNU
/HQhdhgQDBBHv43lBpFitqbBSJrmPMs9itRG0z102AJ16J9dxFjrwESW4XhMECKdNvv3Dc23
AAMAiGSPUg0KZW5kc3RyZWFtDWVuZG9iag05MyAwIG9iag08PC9CQm94WzAuMCAtMTAuMCAz
My4zMzEgMC4wXS9GaWx0ZXIvRmxhdGVEZWNvZGUvTGFzdE1vZGlmaWVkKEQ6MjAwODEwMTcw
ODA1MDYtMDYnMDAnKS9MZW5ndGggMTE2L01hdHJpeFsxLjAgMC4wIDAuMCAxLjAgMC4wIDAu
MF0vT0MgMTI1IDAgUi9QaWVjZUluZm88PC9BREJFX0NvbXBvdW5kVHlwZTw8L0RvY1NldHRp
bmdzIDkyIDAgUi9MYXN0TW9kaWZpZWQoRDoyMDA4MTAxNzA4MDUwNi0wNicwMCcpL1ByaXZh
dGUvV2F0ZXJtYXJrPj4+Pi9SZXNvdXJjZXMgMTI5IDAgUi9TdWJ0eXBlL0Zvcm0+PnN0cmVh
bQ0KSIkyUEhXMFBwB+JMIPZSiI41UEgBsrIUDBXKFQwNFHyBnJBkEAHiAqkqENsHRBSBiGIu
pxAu/ZDM3NRiv9TyoPzcxDwdp/ycFJDekDQuA4V0INY117MwMVIISeHSMDM21bUwMNBUCMni
cg3hAggwAITvHjINCmVuZHN0cmVhbQ1lbmRvYmoNOTQgMCBvYmoNPDwvRmlsdGVyL0ZsYXRl
RGVjb2RlL0xlbmd0aCAzMjU+PnN0cmVhbQ0KSImcUsFOwzAM/RUr99FVk6YhtZ1gaAKJoWkb
B47Z4nYRbVyl1hj8Ggc+iV/AoS1iErtwqf2e/RI/p5/vH8n0WJVwQN9YcpCCii+GCtDtyFhX
BOJxMx9MFEyz5Ba1QT8nYvRrZJaG5rd0ItIsmZNjcLrCVG1shc0Dvqyo0m65HlxTaRYbBY19
k2o8lP4oS2ZUkodtqgIG38WijVJfaF9YB0x1Vyox577bFnvJR8NxQFtipkrguFVe1TVqr90O
odl7655FpSC3RzS1wHBIaFvqAlfaFSi+TaoGsUzI2nOb4gGdDKuAjAmxEwDleYMcfI8ug+9A
3jmDR8jJV5q73ijwWXKjWb4L2c3+pB5J5fVU8SQz/zDfA0atut1/ltyLfyHbMEPHgYz6ZBVW
IriPvap9tzPqfzg6e2F/UfTX/5J9CTAAcZbFLQ0KZW5kc3RyZWFtDWVuZG9iag05NSAwIG9i
ag08PC9CQm94WzAuMCAtMTAuMCAxNS4wIDAuMF0vRmlsdGVyL0ZsYXRlRGVjb2RlL0xhc3RN
b2RpZmllZChEOjIwMDgxMDI0MDgyMjQxLTA2JzAwJykvTGVuZ3RoIDExMi9NYXRyaXhbMS4w
IDAuMCAwLjAgMS4wIDAuMCAwLjBdL09DIDEzMCAwIFIvUGllY2VJbmZvPDwvQURCRV9Db21w
b3VuZFR5cGU8PC9Eb2NTZXR0aW5ncyA5NCAwIFIvTGFzdE1vZGlmaWVkKEQ6MjAwODEwMjQw
ODIyNDEtMDYnMDAnKS9Qcml2YXRlL0hlYWRlcj4+Pj4vUmVzb3VyY2VzIDEzMyAwIFIvU3Vi
dHlwZS9Gb3JtPj5zdHJlYW0NCkiJMlBIVzBQcAfiTCD2UoiONVBIAbKyFAwVyhUMDRR8gZyQ
ZBAB4gKpKhDbB0QUgYhiLqcQLv2QzNzUYr/U8qD83MQ8Haf8nBSQ3pA0LgOFdCDWNdezMDFS
CEnh0jC2NNRUCMnicg3hAggwAA3uHWwNCmVuZHN0cmVhbQ1lbmRvYmoNMSAwIG9iag08PC9D
b250ZW50cyAyIDAgUi9Dcm9wQm94WzAgMCA2MTIgNzkyXS9NZWRpYUJveFswIDAgNjEyIDc5
Ml0vUGFyZW50IDczIDAgUi9SZXNvdXJjZXM8PC9Db2xvclNwYWNlPDwvQ1MwIDY0IDAgUj4+
L0V4dEdTdGF0ZTw8L0dTMCAxMTQgMCBSL0dTMSAxMTUgMCBSPj4vRm9udDw8L1RUMCAxMjAg
MCBSL1RUMSAxMjIgMCBSL1RUMiA2MiAwIFIvVFQzIDEyNCAwIFI+Pi9Qcm9jU2V0Wy9QREYv
VGV4dF0vWE9iamVjdDw8L0ZtMCA0IDAgUj4+Pj4vUm90YXRlIDAvVHlwZS9QYWdlPj4NZW5k
b2JqDTIgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCAxNTgxOT4+c3RyZWFt
DQpIiWxX25KjOBJ9r6/QI2yU3QaML/s2M73XmI6ubXtiYqO7H1Qg29qiwIOwvd6v38yTElBN
RUUZIaRUKi8nT/68f/jwt91CHd3Dh/1+oRK1PzzMFvPFItmofaFolGWp2t9UQsNULehPRvlS
rdPNfEMfXx++RraOZ3nUmfbKT105peuSh6qL19GJRxf+cfEsjVTR1P2L32LiWRIpg3nTHvlx
j2nmuR/pa8NjS+NSjsMqEsaPqrLOjsTOVfx9/88HXCX3V9lsN3yVhZolc578SIr/fjLxJqpx
et3EeVQap+LZKtI0feTp1hjFH2QNf7rR24nfhq1F80r3fI2TLLrUNl5Ghe7ol0dNjU0Fy7hU
NFGqpiho5wXSafZxpOvS67pOB1WXS9H1ueniZBGdlGO5JZ9Ouq6i5qBYW9Xq0vKCRlX+7Jr+
X1ShoeeSVpiSHhc2UGGUSIMTeHGrvqVpRksbnsJ6uQO94WaGvi/nfOLv8WyN24vmszdmXm22
EzPfbFUpR2eRPW6qw0B3LErGBm5cRg5zGB74R72yjpotZdm3NU922uJp6yPWiAjrlLtjvuDl
mFM8KSKqCtEy6LsIpl4k0Hf/J9KToha+TJLoHM+ySLcGJj5Q9LWaBs/VXXWN0m5w2YrliMgE
qZLM1zRaqH1JEu8sC0FSnMjX7O+G32oMcokCnHHGNzilKRp2oWMLf6XZNS96pDUbHnynmbka
BY1cZLVOEDQzr0AIHdZifzIt/GXjjMRysHNoso81h0TJ8x3987OpdUUP0closkZK96YZoy6O
pZTIYl5aY0QL97tPJOaJRuOQAIgk8zRJBxN3LZwvqQrfWEep672b+5QHHtwbDyI+TmhanfG8
O1voasaSKrqNvhtIVd+ip7//+1s8dnMPZGna69CaPy6ImdbA10biyj0qjVEJYZryaCPBeKPb
bmS6MoqwppMtQ9hSpOlCAtFcEdKktMi5WYlQytIkfROCW9EtW63X03T36dJ2KuUBFHUKIX+J
UwpNkd5ZucJc/VQ5aPOoLPTpWgtNrK7UAV9a5URvJ2FIMxzlbuyzLKRFOkVL3XX+ksYfTqjX
BDUM/NEnYS45CE+WBK6MrF0z6LyI/IZOM5y8UvycR/lMmLSOxKvBksCBTo+xPRVtYTTv3Cdd
vBhGLlWaAIRXoBy5kHPsDigEQBsypFME0SWvOtBH/ufZ1tSQUZwCetZGcpKS59C0wEYBT+W0
4KMoK7oly+126tO6CcitzhqgG3MJwxF8zatuoR0Nb/wZ9YIP4QF/eQTUQ4lCA6M1lwMyZn2s
cKHNVGfV/GiCwYJpgMEsn7i7i7neks3peiyaMOHr9jvpNufzf4Ypc0YQrjsEaUdVxFspjZoG
NZ8u2XtiqDvjH1CeA/+OyvaFlTeUCBUcmvvDc66fXQBN9ZFnWlN0fN5wiYDlVHreSaQdZbup
C0PxpHaMaCWrtDuzmG3UXiZMYbXZrDyS5+k6IDlXeAKYj7sdDXbf4scx7iURSMLhECzsePWk
rudJngSMZtHe2Cz+AIAmTdl1Bft6xnQE0QuhzghWXzUi0xMU8akERIMwPPMkFa4SIYpiLkGy
DDEy+xGiebTNJv4vgLW6rntEpiIudAtsrvOMa84gwtb4q21dJ/CDDwUZ23Hae/CmJYOs7gZR
LSXbS0B5YL+OfSko6VY3ixIAGjmCqRC2ySpfTT1eyfFGt1SuZdzrUEP1V/K8FJpWEX+imw4m
WQfRy62Pgm2ahiiQwjWyiJurnSl8pXrn7iOdA1hl+TIEAUseBUFrKquhl61sdx/RX+aQ4g4+
9SpU2JtTiLDR4i9YuRH79cyaa3m/27aeNb+yGS79haimdkx2+1JMrOmdUpov8mmsnJvOiD5U
SKnikOGPTUNsKl5JHdAMByA6pYFtrLDnJcFAdzIALb+/MJ7WjpzibZet34NVajxehRNSqauk
JDsVaGTmO46lSGc1i85eyb5ztZeSLbX0EWsdF56gB+oUuELVwUSzs3DX0xjsybdJsE26nNjm
oANAMhxaoAMl5YEUoaTfIum3SPqckp4NRK9nwxBZohwR0eqkUVhFFzfAJ3C5kS6FtsCGW3wT
6MUxA0quvI6ZNEKolrYekhQIaQjD2DyGSiS9l7aRQX3kz2Sx3acnPgjovn2vA8gWm+XUR8Jm
zucxc2d6ztZ+tZVue3LgOwLXUY02WHjne4iD2QRfkwUPv/Os3yREkhKlC03icWAMxtvAQ12y
nZY6W1MMHfiGrWmd8rEpqLZZpPMkkci92kI6Au0UVYIdpUhTw250F1u7y+FgC8vc4U1zlAZW
leSD6TtkmmqugkM+JcmmBpgdACtkMSE9UlhROPVTzvdLTFwSNoPPZ47WVWQl50WSxyXcszWC
UUbMyWP8fCchY3oV1F5ukqlHf9Wu8xxFqMmJecb5LHSEhihPCkVJM8qT5Ub1EvMoTy3FGm99
vjDB6kLn2fg2YyltRuBrLSgaqmUtnWxva0R52vd1U5Ti/q5ld5WXQkJeWfQ3Z110zAPZmjTb
EmknLDbOcUcDB1O5al/4dWyfUD0TIfBw677x3RyJusIWJczsKSY1kwbZCt6Dywpxy6jOC8OU
lqrhtepfTCt2j2pPl9yR2T7RK8zH8jVtglgcSb2q9CsJxQAV1gLvPSHN83zqQzYIa6sLWvrC
W4U6Hyr0oSTmJg2qlv6xQQ9LM0dQTFzvf0Q1vJf4QtjHNUfmCMPM2ZPqGtRXiDWdemxZCCjh
6Q1ave2OsmQ9cSTBRuiJgB0c7R4KPvHvE0fGrztVcTUl61bU2/20/6QK2xbS+nG3N7RA6h9P
6JVWEHFA43eb9hnpJhkcXYGFpdFz3xhwPYGvDzzT3BziuBVCvPEUHIxcYwGSRLWgt9TVdb5b
QVgf3zJApn++y6CsPxn3Zzb0SMMkhGL6DvieQ08EWnqEF0AqWa1qlMTqpK/mbWrCo+h0pOFo
gobSxoREddKGPHthRuGA/8LXJyxaCjVVWvz/Y8JmSTr1M5MaqgTmDKAFU7BM2hWy9sKuqzo7
OzVngpALIf3tZGkHITGXSnymIoIsHkUWCiGG2TtsQh817e8QU8JSjhWThhlnGyoAQbCtLmQb
pA8tI35xNI758Hxca364Dumw/8/Dh/0+UeStg1cm65VZpsOGVSrKZHP19OXz/vMvnykWfkWG
0Hm7/ZfffmFI+O3LX94/UC7Tn7iQE9+A+jodgXq2kfNGAM1NaON71Je+2DwjTM5+PiCchG2A
fI4q9RxC36KJpW9IjWfEIVDFIA6RIyeEDCPRieWjWyl0NY5x6peSSXyU0vNonM9MnpVG57hk
Mu1LBpFBbo7W6OEutQgP2YZ4VojtMpQehLsBMDfHoMsQtMs8T6dx84MuQHvPvWuvSH/1Jhjn
BWk+40ZnVCp057ElAPHNgXw9cRvEut094gy6DWV4dIFJa7tYJ9uJEW9Ta5FjToCt2pNN/gAT
WH+yEmCCc9mPqCNcd84j8OdRsLOgF1LmEKqI+YNGfcvLHUcgveN09QGbrKVvAvgCGKjiXSj9
CRfIqR27H52EtBwZKz8ISXshoAVJOt8uV6GrIy7LBE4TiB1R7UsilsrpzrrDfWRFX5IWqVDI
mZcSooBFBd9lg+8YfTzRh5P/z3m1NLltHOE7fwWO2CoTAmaAAXDwQVLWSVyRKg5Z5YM3B4qP
XTp8yCQ3kn3Ib08/5tEDzpQT67AaEB96ur9+X7a2kmvuhbBC/g0b6/PUmzjyx/Ja25OhMhU7
GjFIFI5ewHxxc11b6ByKXd14+iyeM+zM2wTtiM4x1Hq2O57ltuQRyndqUnawgD5Hv7EK1/Pr
hWcxO7xx6G+2V9HXIKJC3kFkiWEK+xZ5qFFjGKb2tOMgVXZxwv68weO/96Qi0LopZNx1bhDp
rBKEvq6xbYA+KOpmtyq+HMqjkgV5dHoYSvJGVwa6vo2U2/4IqwnvmDdMFieiFiJctoEIGvd1
NTY+1qiAP5W8w9DecnW7Da8+ezCyT+yWdc3xP2962OF0FHWfV5+RicvTAwbbgWzv7MK5tTvh
GVnCX16cb3Y0zhUrN41SCl7tropCqPvDdrk6ocdhRqbS2nnfmRIGHtwCw434iM0zrIW9XTtt
v+HdB0TiwnEFmdA1eT+5FnyiGviF1x8cQOwidN2eePGBVdF9znvf7epBIe7dPDR0/tYjzcyq
/Lp348NQ0gn058nq9HyD00vhB2KFA7HmlkZTj+0R2pXYyxaR+O0eR3j68UKlbI21/YSV/guJ
5x6IyyVG4FhWk6mkd0Fz31oeYQD8FVPrdIYOsT9RncO+sqW1BI80C9NoC/l2X/ZqrlgQfqvn
y5Y+Pgcxr/T1JyyawC620Wnwte3Q3TUODgcInJCkV4oEfHHFSIKIWGMQ2aDbFp8wPp45xE42
0njbsSjMzBF3Lnz8wvuGKf9VPJXh/TyTumrwtU7M6W8/0SR3xr+HV9oUtsWCnui3W/GRfj0S
bnv5ppjkdKhOJNpQeRorZVqX05xHbxfgoo9PDxUO2ShLZoGbuvRAms35e5nDMHr9HZNgQxsL
rV3Qjehhw+WBFxxkCw+fGQc3w4jLuwyXEUoKCgVojoQ6QFek2rI6eRjdcIDe8251hQ0uzONu
qR1NyByIlaubPXgV3NCk93bx8ZuCejFvkbhljHK4770wY9sutHPLGtgKOQ19G8av4vN1+7o5
z2Ej6WFPPHNaBjmu82rjO28dl8D1y+oEfbwi5pdOWbiDaiPsOsXrFbJPVUGo7Th1yyNBXY2D
csq1f/7LbzBK9HaUQK1A+pW7nlUP0+evj4+Pd7sF1p22YUVZqs2azawcagXHqoW1Bmah1WVj
CfyyhxoG07oceSBsuAc1OP6GDmLK/6gPoB9kzZ8Wi0XxiVn7st8g/S/VfRkc2Ma5leTV8RM/
b1RQXrBW0YD3Dzh8V1zBq9TVV1ee6wm34v6n3YSvy68UD+cdtRCUcUZV5uAVqpxuZzzk2q5t
E6ikEtaW6+3hcJ1sMYhsqkHZnspbzly6FMY8ire50pXu4kB5Kr/bP+P2BjQ2kK3FEvsbNyKI
yDV0tOlu2vTtyOVz83qg+ZBqEBTiDa6jux30KQhk0rXA/JD9u7bTgBqGML8+v6LLONpv2y3N
m6fzDUTethcUhyIwJHx2EZ8v2wvo+4IjCDydb3NRYZQbE1SofS7rOeMPXBpWt8v+K1WKLf13
o8ba0kh59lMJ5va3tSs6e1QUTzt/2t9+rbwrtVgwjffkUHWmRy/VeOyhtemhqbQpTNtUWK2P
NFLRZoa1l7bMh2aAysxNbKyMtvWiXLyimx+Xs19mrYGRSoEUYNUUbVtBKR0quOmynf1YnGbv
llInVOdek7ZvY02goLL8Hybfg01a5YSMUD4ic6D797T5YXIoGHiPHE8g+M37RV28X5CAuigW
7z/iXqu7ApgqPsBt3xczPWi0pleq6oZiPtBfqHYQO2Cc7rsKSox9e5y9zBYsdX3FEQviVf6F
YD65T8xoUAbJw7UFpe38bfVY9a24bZSX8Uu8zMKtrIxy9q3EDznZZgLsIU+zcukloUcooUZy
pCQ8YlDig5VKaBJRIODCyoR4aaXFDznZZgL0VqbkeisXE72d6xi+m7V1jT/nIiXiCOU5fNrX
0VUCnvN1xJHEJ3wd+JHAtK8lRYweK8i+jJUxBxKftDKmQMAzVsYcsFMi9Sfp5KTdcyDYkdcm
OYhu4Et/mTVUM6CAwq/DgJ1uBLN7AGKH6Yr1cWbLCiY9Ho4zM1bNAKcDnjQWLvgflkjoF40K
Z3iznvmnDu3F3+DcEwpk8HkNcvl0wJ6jWvvEMvhbfyap/qkhlGpt7VuDVWaoWoN9HDTtVZBz
sG/mCv8egFYqyHXxPCnKSqeLMmYSxrIGhQxOQLLL4P5gy7EkVYFuTGSvwNl6HEejkVRfXafk
AhVtD64ADfE4YIlCQwd6UJ4JfiAqjHiF5vqP6IGEEa5X5DR7sh+AiYHZQC86mH3r6UVyG4p+
kAlEHJ0buqZqyXeKSg+/9QTH5LY8Tjh655bbutBdX7UDRDIkasvcwpTR0G6BkwFugocwlig7
uXfwMU5hY29Xph36AvsktHxo/H15c35pmx4zIVPe44LwP7XAOMlJnshZe1uyOcTVhDKX4Znm
EN8k8ffNQRQLCUw2h6heEBqitM2XxYhBiU+XxYgCAc+VxYgDiU8UvmC/BKYLn6TAVttI77sW
qLssBRFBdDWC0/ZHlzhszviIGg9OWB448ai02ZITgrYa3Z9LgGC0BKfjN9gssLngDUZb8r3K
05yxchJBbbmQt6Uj2ssmaAfVJOvKiA6rWmTJtA2ztLSvI7rC3TlvR/cIeMLfgRSBS3tcMkNg
AwU+73HJjoSnfS6tF+ic16X5Ep5wrjdd4tLuFdZbj0U632UyzBn5chaxw3cTPO3h6KKAznk4
YkfAEx4OzAhc2sOSHAL3MKsNeQuF+RKesVBYL9BZC4X5zhlB9WnyWFkp8x0v8s6M+UE+gQdT
6Wx4R9RYBSOLpuWHpaWjPyIu3J2L/ugeAU9EfyBG4NLRL7kh8NjidJfzvmRHwtPel9YLdM77
0nwJTzjYmy5xaQcL663HIp2n+d3VGqf5HAERPSjP4dMMRFcJeI6CiCCJT3AQ2JHANAmSIUI3
TTUOuTiPOZD4ZCTHFAh4JpRjDtgpkfqTLHLS7iNdsCOvTYZ6dMN0WW1xr7N7lelaWELgDCtP
almFXbbhvQdOGg6K9gxecfyZ1h7/ZArC8qLEApKbqt9gUQJ/6E5+TS08Dlcqv0jxZ7QwwR6l
w4p74Fe0aB0AiEMcPx1nupbrLL1hEbxsycUT5voBOGnH3yVo5P3uAIcWiRort3DaE5liz6Yg
FFs9hp1zQkzYRd1yacLRU2MCN3bFZG44oNhkCIh+8CZzkCRNbhsgEU0GgabTldEj/GuTJs+9
zXBq0S1ztK8mR/OJleQz+oZxZBJ/7Ky2RrN78Uzf0kf2RKLsGUMxDgSX/BWmro1/ay2/UpgH
dw4eYQ5Cp+oerB0q1aGxHVrb1MUHQPxcWGNrW18OkEIRYXUtkuiPiYB23CDNZvyjIjjPMTj/
T0PeLeGH59mb5VIDaLmDp+WaWkPXaBaOZ2OKrjHoFzMM1aiK5XFWPqm6e1j+DE6BcDH4HQg2
vaHP4Ng3wPDQoBdM21RqwK9+Km/7h748PsxNuX2Yq/L60Azl4Xx7+Ofye8wPjdcuN7Ny8YrC
H5dgZms0XmpaCHFTtG1lsIfBTVDifixOaMXEgntN2r6NNSk/W/k/TL4Hc7TKCRmruo3M2V7A
nN3DvNHl5UE15eq4JVNAsB40apppq7rvqtrEg9Wb9wuI5ysGfq2iv5R39pP0XuVuSzZld1lo
VxaeacrxTRJ/35QddgJMNmWH9Q2JUzDXlGMGJT7ZlGMKBDzTlGMOJP6+7Qr7JTDZdiMK2LOx
3ncLFlWRbKREHNH0Z/FpX0dXCXjO1xFHEp/wdeBHAtO+lhQxGvppfo+MOJD49JgZUSDguTEz
4sBOxVL96aZlpSWG0MCOvDY9hMobpgOYhl8HO1/0MCC5PpJqttgjBmq2cMImCJbYcadR4Uxd
0j91aK+dEHpC+Vnrd0cNL+9+1lB3s4YZsL1y98WpMoxX/GYu2u99y4GCq3Suf2iKZZjZOlM3
cQfpSl9qJakKdGMiexjuBpxgjEZSfXWdkgtUtD0uCwc6Dlii7FAFD8ozwQ9EhRGv0Fz/ET2Q
MML1PDXbk/3gv+RXTW8cuRG9z6/gUTLQvWTzo7uPa3tzCLCAjRWwh90cBEVeedMeAbIC5+en
Pkh2cYYctSzHihIdNMXuapL1qop8L/KZTlKbSG05txleBJc4HM4JQHxKafAGGSRMTDQuvs0A
l+A6us10greL2GplPXH1MEGjOsb26ubcuLPLPSC8R+t6IYg7StJM8/QgOZBqmXnEi/q3s9sP
mAu8A+E6h0t9PLtPeXFmxE5oHO/lgbDpCiyb/EA0pdWql0N5mlDnsnvjcihXkv7Hl4M4LKRj
9XIozgvyRgnSPhYLBKV//VgsIBDurWOxwED6Vw6+NX7pWD/4JATxtC32fXQFWt+EoACIlkbn
evzFIsm3FXwBTXauRL5ikr3qYUtMyNVZTH+rAdagpXO9fteYhW+reNegI/h5y4c9E+epFHXE
Qq5Wr+g8N7l6OE2aqSzgiFsrIjm8hnm2eq4LuNa1W9ku1hHulXyvoAi/esYlMuQc4IBvZ1yi
I93rOZfRC+9W1mX40r2S3By69KunV0QfM1bs+aiTgWe0j7MCHV6b3OsZLhZavVsZLtAR7pUM
r8gIv3qGJTjkPAJXm9oRivCleyNCEb3wbkYowk/JWLd+2Dxxrlr4CRe5ZiP8dX5ynkJvm+Vd
QBM3WER0ePzwbPXqL4Bb125Vf7GOcK9U/wqM8KtXv8SGnGeH7K6VfYmOdK9nX0YvvFvZl+FL
90qCc+jSr55gEX3MWLHnw/722iKbbwFQwIPzJf86AsVSwr0FQQGQ9K9gsKIjHesgSITI25h+
nlp1XmIg/auVXEIg3BulXGLASSm2f9BFabbjShfoyGWrpV6scChWHeq6qKuCdyBCwAbJUxOr
oGUN6x6wLBgD6QyWONkm2ZNHQZEvCyWeoKpUs4LFGfjDZGWZqrIfSqospPgzEkygo+wqcRd+
RUJrAUckcTz6tLNayll6w1Ow2JLCE3j9BJi4+UGAZtZ3CxgOgZr7JDijRaFEOyjy4qjnVXMe
ALNq0SQuw2pmaMKKTZSYjA0XFIcMBTFOOWQukmrIzgCIGDJMGLztg53hz1VD7nLMYDlMS4fx
aUo0W7xJtjE37Ech8ccp6hg0pxdt+pY+ihZNFW0sxbIQUvP32Lqx/mO0/GrAPjhK8Aw8CJNq
R4h26gePwXqM1mj1M3j8qWKwOp4vC7RQAZjWoom+bgq4jg3CHOavnYL7HIvzkYG8voAHf+x+
uLiw4HTxAUYXV3Q1eGN5crRDUN4EzEuYpn4e1MWn3dnvg/bnF3/ix5o/piMCP1He+t7BHlRw
UJaB/FV0NnGlHvY74HIdmm5UF1+UATNOQpa1BlpQhcH1M83y29lfPv7xz7trqOxzD1N24eyX
5fa+e3NzHs4uzzt7tt9fL+rny/u78/Hs47/I48PtnbpU++v7L7d3/6AnXz7e3yivzv928dcd
La8t7gQtqCvYCGR1xnoyXl38HVa9urnEiT/36qfziRe6ghVvzjtzpq6ul0VdXe7V1e3+/vLj
XsGb2/01/sA2YF/7z7Q7+Ob+4+2+53V/uijOmqkfR0AMriwPZ80wYBMOmMEf3vwCRf4Zt2Qh
J/00Yo9Mc9GLjnHrRkQbTkI8O9im/9CFPILbYoDuI/fOOOwKnYyrnXws/YuZxBIuZQu78MMr
qkkLl411KmjfD8Ay7EzuARkJ3Ei/vlJ7cNJqhN4D0AMeFmDTO3q1ARHobAgfq6Ws7f8GFG6o
r95zbx30lcbKgjvFQ21puiSs1SNE6rG1POhOx631I7ZKUR9Ou3wwP60+7LAig/aKDI5OI2Ox
Cx+BDPkf1MeGiDbk99miuEnn5prb44w6bXBykdHXRxkt6nuCkDH+0X51x9t2qU8CCj9EKPwg
S90PSvpXobDfr99LPDb3+3fHoNHt9R4HOuLhrvdcEW9O9/iTKoK7w7abo41Gbo5taGzu8Edn
9Jli2Nzfpsjm2+P+nuxKLqE5DIkHszmbpvd0ag2oYmGEu2Wb/gMU8Y1jIp+GoTdO8dedAS1G
wODv1Q5+tIujZWemPiQfM6OIjB+nQUQzDmn6JY1oPzwDBEvz/ifOhDaGzQp6kbg1zpFuJcmV
I2XyvVceMIyE/Md31UvGo4aDOmvRhkNdpxVQfAwUV2KpFVUqKUyyohSLT92UPMGij/E9ScKF
jS6KNlaraSo20dcMWb9G1yTsDPb7hLcp5hw8oJVJvqDWm2qqDo+d4QEq/ZiY7Rqyyw+9S45g
5ZBRrlLI3uWQXQ4ND7NNEUOJ5IjtwwHbKUAbxSS7Uaq/ZsBQgbxXuHSxFCdqAtpIMuGg3iXb
4eORkkfxBhfNq52O1rLrUlQ+pbYT4ccZ84BdjbxLpx60IUYPspUZHH6z0PMOwz+KfMZ0QHo9
NII3kAZsF3cy8s7YPuChhG2z0BBGjjs82rh0dHN4kF3xVwMO2c251bb0fJhSV9C/WPg6dwi0
cnylyXFYS6SAgmuA5jMDnhO4ZY914PGewh0POBW4TMPpWhhhb3hiWvPUWqCi/bbFQFM+XA0A
rqiGwZ0shxEPVr4ukHCcbgGjMcEBF11wQDaArrEw6DEsC1WBZAEsozzGz888xs+eHuNfE+oG
Sj3HwyefDqvNz23g2M2kDhDQIcc/I3QBcw57tch0oLVxq7gXh21SO/kw97OdKX4dydfpdtB4
5QVceaFRiECgPeIOrMqP3UC9oLEXAqUWbIdOgUwbH1MnqIyGi2d/tMyUhjpE1xj6MQodZcbh
8p+o9EfEIVDr0lkMhPC4Etww9lMs/dYd8BhxxUKzrizaQlM+3iI0a/JqQ0Sb5dEzRFGh07pO
Z9xASfbOYpEQnzlWSN4+SGdeWFrbEb2wtFYy6unUExl9fZxRWdZP0rxJzTWhaOtF+XiDXtzc
po/WvM8Uw7ZsQn/CSS8075vT/fm/kM12PC89m56uYZHNt8fZtENvUEgNowra9wbrOpjN2TR4
TUNQA/FGIvbRpv8ARXxDYS55COwDiQV+3ZmxJ4lEv8DDRubpOAImhHQvjsyMZCx+nAYRzTik
6Zc0ov3wDBAszSsqwI4GiT+GjUTczrT7gGTo7nr36yu1Byetxhm4uFUBaQvY9I5ebcCwWUEv
EjeuuveHlYdkDiRZ48q3dPt4AHGOV/674yp0UFix7/wEW0aCH8YHSS1wiS6Se+aQXWa1GAa9
ogG+IVaLvLrzjCWxfBiM+YPI87uk6IYsckjjRP5KQs9EuovU1mQNSE8lsyWC30WG3zHFh942
JJ94N3Waf4DIhBeOmx8UOxQ10Xxm9oxBwsaqDBqx/PwFbBI1ApqkeewUnwr5ltCwQeX/LPZY
4vATHWWPVUkUESZC+PJmIttnsg+IeNzzHHlOje1b32sPTQai7P9O9DoHmzEQvAfGEUaA7JgT
H/eHpVTDz8wNYns+UOiUsNQUaeRoZfLELoFhoPEUlBiFSbj6lOjAjbCkrLspZx07RbQJtYw6
rgiUfC4TVdy6p6qAHxasjlIBXvYYGri+J7y+AzRK8JmYnYIGkjn1MyIO1rymiMUmhcEmBejE
C8z5LPJP05CX50qLVnRxg9J5yrUyTHysDxqDboEpYkC7gPrwE0FAqaB3RwgME9xPkcB8KwQG
9+0hoBPyQQygLwQG+KUEoYWBPB0ckCa0nX/q6WC/+eFgN50NQ5Bngz15NIxhvShKcflIOo7A
J6FpB8llcXRaaFq84B4hNMm/RcjbEW0g5M8WRYWS6wYlgutrhDK1WBnEiI4IkddD71M9Pymr
ebNNhdLGQz7egscpmXUios0y6xmi2Ca05rl3cALLnL4+Jrmyrkuh+VWdatsl3haducS3ic7N
fVrGs7lPv3sM2/IJDergLp1xBUzmm9MN+qRkpm02K7sNhHy8AYjN7fnoZD5TDJubc5DJfHvc
mRMIsRk55KyC9r1BBhXM5mQaVFEQ04BUqGMax/aA5AGQiG8oyiUPA+pA/rozoHoJF/wFZTYy
MccRaDmgG3FgZlKq/G0aRCzjkBZd0oi2QxNAqDSrSL8dgXA5ChowN3amvQdUinfXu19fqT04
aTXOA1BMFZCwgE3v6NUGBJvl8wJR44J7f1h0KHs11GX9tp8s6iAPEM7xun9XqcB5VTET7Dgg
fuMDAk+TIgvIIBca8ghVmiZ5R6+woRAVakmwgUh64rTxOWgt/mBAO6zqlZjrksm6Z7KOmi5K
uSjrpn+TXy07ktxG8N5fUUd7gW7zXayjd9dHAxI8gD5gIMEQWjro4t93RmSSxX5UT41mrfHY
GKAnyWKx8p0RhuR115VencITkE3ov8pHHTu9J1JWTRL8fINpr7xRQWnS8tAbcEbAxxzuk9Wc
zP4ux6l7LDHw7RWxTOTEQwVibNsDWG++iKQA+qvI3td1xxV9J6onjrdkV8OUoIhoHUh051OG
1kvDrfdg/rwSnI9P8i6J7l6St0h0Ybg4PBdRCR2nhheKJDL68m/R6yPul9r3bbMthi0UiiwL
11XBhq3mNBwtobuOCXBuoU+d2fHZWiyoDvURpbFYJBdSb0vQPDM35F/hzfIAnFOOxXu+yado
OZFnySrkSsqPfUMSy2iS2TJfqpV3E0lYTU7cxklLCryuZeJUOB+GZtF7iEmRHlg7xQXxPRrD
DdoriNDxylmfeIThtk+IrwR0l94tHnYIFBms9Qii0ys1Sk1k3raFeJknj+x5fFtFWKtSa466
6q0illUOF02k1+BqeER4oV+myXJnxkh2U0YN6Okm8rK2kK/wpH6cbzf9eGdTMZpu8hvX7hVX
LXE+tk/xtJtMKyhI8AUFe7pYtjAr9K0m8ra2kDt5Ur/Nt5uCCuhMQU4EXcwcEXy1ibyyLTxA
oocWphUU1PyIKBpjgnzrfLCUutNNF2mybcCUJHXWyeiDTiLNB9fZ+DopSsBPXMWU7AhaCFPG
K8C19KmpnZKpVG1WlKF7aM1UmyU6bodZ24vpeqwIfslEMRlzRbAyAfPMocX/+K34XQaxHXom
mudembqYwnqICihIkt9ggKzykx4/JXVRFQlB3+B+5G9an3ZlqXxWVOJZ/AphihZ/YeVwYl/9
ZhvqzweO7f5aKQYD7Ey22aV1k5gOR62cxPrmd1dZz9AjCyc1gJHKTU17h6rPBBECUrSjztY5
2bfgnsWmJ4SFalWDtwsVtlMml7SeIjqVm/HlGTlzxqqSFkV+c06rrFqkpO/k6eKn1GlQVMeN
UxwNfL62XPxLxfBZ7HOZ/8K4KqmdVVQ563JaZbvNDnqec1BHfl1DrIn2LtxES2iyqeaCveYU
1F7+I1sczWhzlHMzrLgT5t8iAGe4IKyrdfMhCCgXFygKALyt/Ky6j5/nUNfduV6sgh19Puj/
i0381jRdmqLGkTSJkzDPRAxQAlO32PC8bnXZhQ4WcxYIgbaHgngIHL0CUgjFAAH6KAayZwJx
rusW0LOeopS1UxlOVKSwQqFjxwKttbehSJh4vOhpHEPUh+V2phCt+7GccVHWJOT1tinftIOU
fFcpMjgmJsM00TrwFIc2q5vDODSNZkUonH6BKrG6+c6iLTuqYCrZpnzRDlICbFU9Zo2ayc50
4sDDVbPWgI0+bNopfdGSImDUJuiFCLFWzwpksH2dE3GWPjUDPFfmRLgz/k5zBJCtMxSqy8Uk
TKrHUad4NNYSiv2yAbE2tQkknYCJsWnC82HcHs9f3DR8wr6qyfHTJ1oUZ3ap4gT+CEaLC48X
jIXffjz88Gn6VQ6JqxapkzgVZJrIfMZHOzyCxrJM/xJaOP1dTv48/Rd54Z+Hf4gb8Pf56fCX
pyeJ/fT0kyj49Cx5F/O88KCI0c1iJBlFTpzsT78c/vTXPz/9fPjb04iMnEDqxrHelBoxrE7R
CdWcEsNLTlHQsd8pPH+VGjss2hHad7NCQ3sR1tuIJscJPET0801EL1K7ismwf46/u9jjdpbX
wRU5mCuIYsbt8fxdV8Q/rtQv/bG71P9wH2wU+v0aBzEsCz6DjPjyuMbflBFaHXG7OLa90Ytj
nzd2V/irI/pONuyub38Rza+39V2jnAHAm1kcHmCv+N3RJGJzk1E7QolO85Sn2JOkqKIti+Ju
5bhCPOgY/H8+yD9C45nYw1dSMq78QjajL7eFedOWQdlTewh99AYxlvf+J3rCtg83M+hD+m2j
jwjsFoPDBmyoWVhbFh8uhhq+uztkMpiF5NkWbLhlGQTEgNCL8gNCaNID+VkaPZB2ZrsCxe2k
SHyZGLsa0wC1MqYh7zSmEdIeqiEOk3qvmKaIuZxQqksUrfvXKBptJ7yAol9jc1xNTn0zp3aw
EYhvRa46aygDbXhocKxFysiCnKSvZTDJ/NBgyUDVVYYuUrGyCKhIE6VRH5qcsD0zeLS3JBPF
FJPOh2OzKrfQHgfz7ca+0KN+nKX15CevPM4QHN45c/8I828sXxAOCW+WQshewoBySQ8tP3oh
jWhKKJszl7JKWuEm49N2LKGRPetbAUs9ltIqR+6H2qqCP5b4rleIMxJaaOzghStXaA7wPh/Q
J6ByRh5kzCloHHCVHCHRfZALs+iGjhn9W3OBSfttk4FXvpwN4twhG0J6mA4zGquOCwCOxyXg
HQJc8NEzFpTF6Q6JwW35rGQFwIJIfsqwX/cy7NeTGfavAU2BoVd7tPO5ssq6H4va7ut05QFX
uv0LXFcQc9E1AulIaUNV6JJQJvc6H2K/xIX2OwNfj8vBYeQVfPnMVTFHQJ6hQZz6dgqsBYda
KAytyAmHCsVo26yEqXsjWe83yde2dMWOmum3XjgyMgmf/4WpP8MPhaXLXiyA8DYTUphP1VJ/
awa8hlwp0bzPLLaJ5ri9h2jeo1c7LNpNj97Bijtw2t2HMykwyDlFJAnxzC1DyvFFOPPBwrpt
0QcL652IZna9IaKfbyM6pvWbOG9jc5uu2OaL4/YOvri7TF/Ned/Jhn3RlPqUTj9w3i+P6/N/
IZrb9nz0aGaO4SGaX2+jGcPJg0iFeSounzzyuvjd0fQY02JUIG4ksDeZv+IKe0Izz30p6APA
Am8f/XwiReJ/wWGz4nSsBAkB7tnKLwBj9nJbmDdtyevPbUV99AYxlvcOGRBnD+APswHE40Lt
C8DQbz8efvg0/SqH3DQvgsXjVABbROYzPtrhw80M+pB+06z7/jrzAOaEkm2M/Mjpk8WJi438
726zMEliWd3lKioD4Jf5RVArWOJo4F4x5LGjWpjBR1zgCVEtcPUxqy+J8mUx9xcM5x8bowud
5JDjGH4l0fMGdwFtfeeA3B2RLQH+0RD+USG+1LYnfVJt7sP8K49UDJy0vEh2aDVhviJ79UHz
TZy604jy+xuiJDgCRHKeWG13oG/NG7FM/VfJnlIc3XFGe+LUSBF9MhBfVcbQvoJ98UiGzovh
nHtoP+aTy1JkQsr+70hvSqKMF+OzII4yi8tuMfFtfUSGWv4tWiDxpA2FXSKyKNoq8cs8iSqR
ZeG6lmlYlToczS3QRQvh3KKeao86KmUoE5bMdJsRoHypA1WonpkV8k8Ja2Io5FS8dY2M74rx
XaRQSu7A7JFrJJj1tMDjIi1riJRs0gwVaWAaHiDmyxB/XsNTWTPNJDuSwuT6lWtmeNt2V4XB
KVDNB9RC8iNXuoCh4LMbD4Qq88kAzLfyQEjf3gXskC/6QOpi8AHeHJ2w5YOxOyQBTZBTfmt3
iN+8OcRdvSGUsTfEh61hLuuguCSXr4TjcHwjmjGMWBarx0QzYsC9gmjy/BYg37ZoByB/Nyvu
QHK3AYlkfM2SphGZQUR0A4iyC6fc8vlNUe3KbjKUbX+M23v88YhmPbBoN816Byv2Ea1lOSXp
wGNMP9+C3DGvL4nm76rUuJ3i26Szp/g+0rm7Ti/t2V2nf7gN++IpBZpkli74AoL55XGBvimY
Tc3NzN52xLi9wxG7y/PVwXwnG3YXZxiD+fW2MqsQsQUYcpmKyycPBFX87mB6sCixKQAKHRXG
qRwAHsQT9oRWnvuygAfq20cvrJd+wX9hZrMCc6yEywncsIVfyFT13bYwX9qSHz23FdXhBWIq
bx3CH2cBXIlGi899XKh7AVP87cfDD5+mX+WQm+YlCMScCgCLyHzGRzs8uJk+H9BrmnDfXycd
aK+TvLw/7WsED8riwsXG/Xd3MnBZWUwVjQv8N79A8BwZWQGCPHOpK7A0R3rHRygoeIUlKbIA
yUxMa/vCtfSFALms7JXI9dzBelawDk5nVM5oXTUkr7uu9OoUnoBsQv9VPurY6T2RsmqS4Ocb
THvljQpKk5aH3oAzAj7mcJ+s5mT2dzlO3WOJgW+viGUiJx4qEGPbHsB680UkBdBfRfa+rjuu
6DtRPXG8JbsapgRFROtAojufMrReGm69B/PnleB8fJJ3SXT3krxFogvDxeG5iEroODW8UCTx
33xXTY/bOBK951fwaC/ahr4l5xZgJsAudoBgE2APkz0osmxrIkuGJLen//3We0VSUncjF5mk
i8Vifbx6ZPTl56DqY+iX2g/dopssllAoMs04L5Rs2FmeLESzyLuOCdC60Cf+Zcf/5mJBdaiP
OFoWi+RC4mEJlqfMDfnJqFn+wJtTxOL3fJPuY5sTaS5ZhVxJ0l/7ho9YRpMvW+ZLYcvbDflg
teOEy5C0SYHtWiaBDtoPC7DwGGJHMT0wI8Xq4buzL9xIsYIMHVta/SdEGN7ihPhKSHfm0eKX
CIEiw21DBDFQlRolN2Teuol4mZI7Yh536xC31ZEDR515qIizeRytQMTX4HzxGOGFfSmvLDpT
tOTApKgBlXZDKnMTOYWSejh3O/uo05kYW9vkG8/oFc9WQj52R1E6MNYqGEjyBQN9uthsYVbo
LjekNjcRnZTUs7nbGaiEzhrIjqCTnC2CW92QKt0kBEkMYYW1CgZqfsQoGvsS5K72g02pd9D0
ICDrGkyWSJ35x+gvkETAB+ps+9orS8AnnodJYkUAIUyZUAmuTZ8icVLSlQrbK7IFemjNFLaX
aLtd9FpfTK/bivCXlCwmRV8RrkzCnLNp8RffAt/DYuiEKrJ5rmXGD5NoFqIBSpLkG1lCVvDI
EJ8s8UM1JIp0B9djfpP5X28sjU+VlYQsfqUwmRZ/xsphx371TW1Trz6wbfttWWZpgJVJbe/S
ukmYDjutnIT1zXPnscrQIwd2ahAjHTsz7R6anpNECElRRM0tchK34J6D7Z4YHGhWYentgQZb
KTvOklmK7FQ04+QcOdNiVvBZFPPMPJnHakWS6J7UrD5ZYRaGarsJlEeDn8+Qi58ks/ws9n2Z
P9FyliVOVlllrlMzj602KxhSLoA58g0cY0143wMXAQlubE0LIrstUFK7/uFrcXkN10fZN6OZ
d+L6bxlAYHlBNM/mxV+SgGylQFkA6G3BY9V9PJ5NXVfzYjWLrGj1QX9Xi/gWiVlfRS/HR5M4
Cf1MhhGMQNfNbPN8DXVpEHmymKZCIQB7KIhfEsdQCSkGmSUEwFE05JAJxL6uS2DPKsVRqkhl
eaIyhZkK7TwXcNDumiJp4m6FaWxDtIfl1nIQW/RjOUNRqklI9XZRzrSCHIXepJjBscPEcprY
IrCJFzCri4t2aC3KlaGw+0U0idXNPQeF7FgH1iS7KCdaQY5AW9WOXKNmx4G1iQ0PqnKtAdv6
sGildKNNigitNoFdiBBrtVUig2XNCX2yBvpkDfBYta6GM1GZkhcmjQvkPp6pBq9U2RHaHfLG
DWNsc6/dh9EKpQ6O4kgSzKQRaiIIoeXPzedmm2zO96E222wT7eVjvmLpui02t224aWVcb6ON
OQ+yUt4u23wzyvre/Jv/FJvTtE03H00lw367i7iDu6oJirjWQfu1Hi/mJMKD6OtxgCmdsNn+
79u/eAkJh1wC/TVIQ9xCfOs6e2K+HcXmrj/Wo9hhtrtsM/VmutTm05e9+aM5Htv6o/kxyJ99
eaxKSE0Uu8qoFrthwtBf/W5unU8XsHIutIcXGflBmOrZUw9rZ7s7HIUrqkl7XPQ/cke69ULX
bHfhxlzv7TYMNhMm+K8SH1jz4BfYc4KH1S/YdxFrxTgZfYH/scSD1Nids9H6Cr55cJis7b0M
dW3osSdTdkdT8t63uoaTdlO/w1BdxPjQd1cufDLi3N/2euAiOeW4SP1kzzwUDFAe40zZZlMz
Unnax9QUssWypWVnHDFsdzGzan0Et4Q2FFnBuwlLKQ5us2lG3EQUiE+SzR2fqenO+DXjJHcY
uFZhyNGwjcWd02VONK8fdj8ECYq4cPrLyZz64boNo81ojs0gyVwfTS3KOtFzhN/mnLFlFxWC
ZHCI9JooS5ZRqMXxWiDJputEmfxqcchcbiIHxZu+O+NGx/rZ/lvV4958hsxg6r9L2U+5G6tL
ommOJRSVkh67OSkil8KxXEfM+fYPMaASN6WbtkVRdhie8cFxHAySa4gC1lT0TnmY4wT/4rru
lgLAf5JXmFGkFktG03RwMaamq6dHP/yUHOKOSeTtP+o5tTJMUmJV4Cv8NzH3UyV3H82Xvukm
833z6cv3LUx4XBCBAVVQm1sp45d2DkPkNDJd/gQCiGsF2U6udAYZPFCBJUZHoNfRTA6kOLpQ
OWrQKg7zQzEbmKp997GGhr352jMkRMix0fA4EKyZjOehvEGvmCJaB5xeGyl4OfQhKjqDSHc8
/7NcSOEYIa8l483vJdLmskLIMHOJm84Blvp2SdXxhnOK4ZBHQ8ASBCJqnesOdxw8jr2IlLmU
z9tU7wJxaBgxsYaeCd3QfQM8PSEiP+6QMiO0PdfQJ0eYNzUmnSd/G+Wxvw8SZ1Mhkp0ZNUME
D+Tu0/agE3FWea3hRhG6SfFd9uaf3fy/AEHVd1P99yQVQVi3ULJEnyj0cLWKo81cudModVFi
NjXM1+4d0MMuZlia8jaJ8OPYI5LWt1QO/Hmkc2qp0VFDwooLNQT0cNczBSHXD5CDC+nM/oRF
+//IjoIusEiAwno1Tok3ascCbk53BKxapUCpgRc3Hja3CwPM4Faawbd+lPMF4yB8kuKCwCBH
7yR1xGbI1q9964Gdng0P7NTWHzfJwDCUvH8X2jN3A4ftYeZ3WgQpJx/NFVwHuba6SHhVnq6I
gSQCwNXUZXVhOvXIECSZsTSB+EoK4/WmXi8vIaakvkchKSQhOmkB4raB6Hl2im5l9bNGHi6M
dNibHLQTqLZFaEpr3aW/CYj2s7ZH+bI3n940d+pKrWVRlHvLXm5NVbbm3jViW6G29RJlXyly
84s3blkFCFrmzIPKJV2oh6tCfDlJZfYcti9GzHa4bmsmZcmopCsZdgb+HM2Ra6JDe8RkNKiy
79kXnWk1RgLPN3zH/cJaD3OH4vBOh0Bh5Zu5l7WkSygcr176jza3aPNz1e5g/SwmqCU3dO2p
JBqYK5Jem+DU0LiWIKRNcgReP5mR+q9a07gP5yfi/pvETaIsfQNAj0tTyTUupn/2ra0tb2Rq
zBPkHSlH89wc7xJeZQjcBT4r4ElyLdhdz/ViPRdq5rBBXFGNd2QFLuQuI11pHPuqKUFvkIXN
6wSU50pxiHzaXdQsxO1kmknCWzfny49+UKD6dqnfr9o4jDXlVN2yan+UY1MxNovMHbEgbfZo
PSBr5tvXP2T8hZ4uZyIAwduIQtSFkrSNLoSz+kc3ToOszlY5phAe4oV/4NBYHgj1+BFQeb8x
x9mKRbdyNMcWxIKBYI85uYi/sVMehaEDlMgDChADZUWrgQHyU7W90Aki1Nz0FmHIXdcJZ1CJ
spULr2VXnkXHo5kYG8ZoEneyHATpS6KD8Qtr1+gDSfIDRgz9fapB7uYrWYIrGH3w/uIrCn4m
fqkCedJISqopuAvhF1xRHyDayuaTCak2WsxG0McFABSO0IX+VAUh9PxyrJH7rGsgAavw5pFg
u8OSxKZT9FmhgrBStGcHDr2ve2JbRY4zTsajxxoN5OjpabtbQasDqygLsrdg9VDoHOrXIGqJ
x1sUlRt+j6JYXCc/yZNDVce9KfkYDa+g+CqXVv6uoMSmNzOGg38oBskbEJoz2XMVU2rVwSWi
89RaGtEfyQY6cMFFLQAOqkq23AmozB5Z6pzURWmvrI2lJcwx0N8T1nzzU9LjnV4V5XPK/Ved
Z/uMufmwoargMhswye/mPD9WAO9vACnKs8KWZzC/KivJRyChtDtgmxLUJ6S4RzUNt+3zYaC8
dqdqliUpJFns4KeVlEH5sS+05YtUR3PEpO703Xpq/s92lSynDQTRO18xR1JlsFYQlasdV25x
OVW55CJLI1AiI1kj7PD36dc9izA+mDIwanp6eQvxZAu9Y6jU/TsK9XvZWILL5JIW+mVeMjsv
mRwA2AXWkRQd8sbZxlfwsX8iJ1UKBMgD1JLTMHSSAQOIBFTNjAqcxaVgUrV4vd16wfaP72L3
R2I+CFPSm+93Chc7SM70A4QGe7w5cZ/oq9o/Pkc9p7VjMTkr+5MzrULpioJCqy7obQVkZRwT
3TcL66E/z8Ul6lBWKilreApyZJNRSljwrDnMtslV4xNdAg4rluz4bryLsmqbLkgymw3BMxvE
4DjZrjkYTXER0gFuI2eOEsaBrA4OH3p8ZTCYMExm0BUON3jRdfBhlw2Mkms3S22RkTirQcaN
tohwjjvU0Q+Uo3LE0VMKoWFf1ahrPibzJ2GqM5axlv7GLE0R5Yzsn0Pru2nVHtczVs68laBh
BVH8/PPBbEj7YnY+dvhoevXYAHJKNO5FfzRu1mlsokI8W575Z5FmSQ6o60Q9W1lT6a4zdLOB
wAB6H/W5UDWOmfJdIg4sXxfFRycC9UA3Rq9KQrsjN23kRgP91gDJ+zfNn7MTK1lnKFMdNED3
JH5RTtc0KtRRQdsDe7gBp4/KQfYsOwtO6S4P8oaP1Xh9YwSHlkRCdFe87dyAWjxGOsqcMGF6
hCMcHW5bZSWTixk+avz/DnLAyb922Lef0WO0SwKcV8J3Tbs/edzWQnFT7/S64e+GQaDduxDD
a6vfAiFMRvSrHBBygM4f255jtlU7nZV+ZXL0zNHNKcdCQ5HG13ttM3L8TVMX/AOKo1WngxmR
Y2uQHCX1i05F1IGN/ZxKG0fiHHZiJZQRSp9uMI80fqp1LBeYa+tWOLpeYYqXLeWPwq1MJ+qL
xs91EXq5gZgVwcXeQUbczBvlYSK3OF+kHudRbmrRyGYpxv8Ri0uqMqyrz5vpwzDi9yM5ytlo
2jvQ/sbeDqQXqG5Yd2POruZOBgvhKXFaloL3RjaotKvGE44AihaZH+WdIYB8BjAfsVnvOFTz
Qh3I/1iYRhtCsT3BJ5+AvKsbV5L5guI3Iw1XKhykhbnT5UTSg3YdZAL3ki5/sJpAU1Jercxe
0XaEAAkkcC04POUkm6vmk9AXld95UYDbe9ql2ez3Do0r8pC1FxVTuYLg4N3hJ5sviUx5Jsy4
90QunUVQPhgOIcn7n4vXRUxpAXWTXbHOVbpR1cvi9uEpVnuzuP32Eqm7fvG4+C/AAKYL1jwN
CmVuZHN0cmVhbQ1lbmRvYmoNMyAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3Ro
IDMyNT4+c3RyZWFtDQpIiZxSwU7DMAz9FSv30VWTpiG1nWBoAomhaRsHjtnidhFtXKXWGPwa
Bz6JX8ChLWISu3Cp/Z79Ej+nn+8fyfRYlXBA31hykIKKL4YK0O3IWFcE4nEzH0wUTLPkFrVB
Pydi9Gtklobmt3Qi0iyZk2NwusJUbWyFzQO+rKjSbrkeXFNpFhsFjX2TajyU/ihLZlSSh22q
AgbfxaKNUl9oX1gHTHVXKjHnvtsWe8lHw3FAW2KmSuC4VV7VNWqv3Q6h2XvrnkWlILdHNLXA
cEhoW+oCV9oVKL5NqgaxTMjac5viAZ0Mq4CMCbETAOV5gxx8jy6D70DeOYNHyMlXmrveKPBZ
cqNZvgvZzf6kHknl9VTxJDP/MN8DRq263X+W3It/IdswQ8eBjPpkFVYiuI+9qn23M+p/ODp7
YX9R9Nf/kn0JMABxlsUtDQplbmRzdHJlYW0NZW5kb2JqDTQgMCBvYmoNPDwvQkJveFswLjAg
LTEwLjAgMTUuMCAwLjBdL0ZpbHRlci9GbGF0ZURlY29kZS9MYXN0TW9kaWZpZWQoRDoyMDA4
MTAyNDA4MjI0Mi0wNicwMCcpL0xlbmd0aCAxMTIvTWF0cml4WzEuMCAwLjAgMC4wIDEuMCAw
LjAgMC4wXS9PQyAxMzAgMCBSL1BpZWNlSW5mbzw8L0FEQkVfQ29tcG91bmRUeXBlPDwvRG9j
U2V0dGluZ3MgMyAwIFIvTGFzdE1vZGlmaWVkKEQ6MjAwODEwMjQwODIyNDItMDYnMDAnKS9Q
cml2YXRlL0hlYWRlcj4+Pj4vUmVzb3VyY2VzIDQ5IDAgUi9TdWJ0eXBlL0Zvcm0+PnN0cmVh
bQ0KSIkyUEhXMFBwB+JMIPZSiI41UEgBsrIUDBXKFQwNFHyBnJBkEAHiAqkqENsHRBSBiGIu
pxAu/ZDM3NRiv9TyoPzcxDwdp/ycFJDekDQuA4V0INY117MwMVIISeHSMLY00lQIyeJyDeEC
CDAADfcdbQ0KZW5kc3RyZWFtDWVuZG9iag01IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29k
ZS9GaXJzdCAxMS9MZW5ndGggNjIvTiAyL1R5cGUvT2JqU3RtPj5zdHJlYW0NCmjeMrFQMFAw
sVQwNlSwsdEPycxNLfZLLQ/Kz03M03HKz0lRMATKGCgE2dkBpd3y80oUTCwgfIAAAwDFTQ9m
DQplbmRzdHJlYW0NZW5kb2JqDTYgMCBvYmoNPDwvQ29udGVudHMgNyAwIFIvQ3JvcEJveFsw
IDAgNjEyIDc5Ml0vTWVkaWFCb3hbMCAwIDYxMiA3OTJdL1BhcmVudCA3MyAwIFIvUmVzb3Vy
Y2VzPDwvRXh0R1N0YXRlPDwvR1MwIDExNCAwIFIvR1MxIDExNSAwIFI+Pi9Gb250PDwvQzJf
MCAxMTggMCBSL1RUMCAxMjAgMCBSL1RUMSA2MiAwIFIvVFQyIDEyNCAwIFIvVFQzIDEyMiAw
IFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dF0vWE9iamVjdDw8L0ZtMCA5IDAgUj4+Pj4vUm90YXRl
IDAvVHlwZS9QYWdlPj4NZW5kb2JqDTcgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xl
bmd0aCA3MzM1Pj5zdHJlYW0NCkiJpFdtj9vGEf5+v2K+FKBakeGbJKpoCjh23bpN3AJWPvWK
gqJWIiOaZLnkyYei/73zsrukjtcgcJFYt1zOLmdnnnme2e8OD9/88VMIF/3wzeEQQgSH80MY
hGGUwqGAMNgmaQaHG0Q4GUOI/8lok8IuzoIshsPnh797Xfm8Sj1d4U+R1/gLxSrz2pUfe59X
O/wXJd7YyOsBf2nUNqDxXbGKvVKdcGIkc1qscApWW+/c4kNPI1pT0msFjRpWUejdVn7k8Xsa
XHEQwOofhz8/+Oz+VtxP021M7ofgR0G0gcM7dPbw3K38DfoQkbP18xpyWPlbr6FZRdsNt5bG
PfpxpQHcqrqGkoY5vX9ylqDV9NDj0XceXGStn3o5f6jUuH7ANyV+UZxkHzPxMd7sZj6mqTh5
ohCdz2q193r6aSgEoMeOZyg4fc5hVavEA4la4jUXjpQO0AA+NHgwCleK0dp4La264gDaM77g
ZDUXXjmPXCJeJUkWLSKnRzpVp3r5eCjHXkPZ0vyNQkF+4Ok5phjS1i/4XV1XuuJRAxfeJe/z
hv4OSkGRN3CUtb4NEXsTmzxG6Y5hePg1ejH01RPlq6LkceY+Y0xygseJnhSNaL+t9wy51tWl
YfPmQn/IrZYncLEMFCjeUPHTQBad26iHQtV1AO9bmupN/sStMNxtlqlTXyg4kdfVag1DqQAD
VrWnisEGXduNtQMBlpLdKeE6i4PtLsINDyfcKR/UCXSZI3bwZJRrM2CfNFQNvK8uY0/zM2Cl
ds+QU+ibTU0iaeOIS48rqmV4cNgRVIQTmh1tZUHxTIkuGCcaoUMAyl11jj0++7QZGfBSA9QV
AwXfTkDFrDx6Eb7Ygq5p15Zs9eMqmJyPxfkX0PPewOrwE3FUJBzlT7ZREO63NmJ1xVV85f0m
ShNzA+0oTrYc6yDdu1BDpSHntWAqmh8YDLoopcZT7zTSqMa0yIcsmvCtwQlOfBigkElNAan0
oNmOZs7EAfkryWKX/DjYZDuHphPXXGcocRHMD+/WoFuXqkLRCdBHOClkX22JtiEn5rT7ATd6
Ryv0mvzKKRupJAOakfc/qn7JVEkURa4Ke2XIqSno74nBwtTcWjQZ1o4wNkeyuVT0umnkz4Wp
iM4EkyFaITQz73WeW9MBN3jAnOwmmgh3JrPJfu8cLMq8aVTNkT+ftRoCOJSKiFFXUp9MTEoP
8KR6pEMWLCIoggJYBM0BZwJBn0CGRtFyMsJYQVS8ijsmsTgKNvFuhtMr8clvYUEF6T5LBAuy
Yg6GtuFSH5A7NZ4BsTUMmKm8OQkQFf3pVaEqPBJj8U+qJxa6tdC0J6Xp+FNeN0aBYqExCVv7
qmIrJlpiMk7xaZJ6+vdsc9kYIHaEwJ5ZZpQxEccMvAF8OE8r3B4zIbLyGIb7JcdyLU2CzRHh
gmNZoqis/B06gKl01bvxOGFSwZg1dSJ6ltp1vEE1jYuK6QMDmcqokln/3Cs1oyxbHXNHjWIe
R66qT67AOJZUL/AGc8HTZY4CSBKPVQIUVw5Sx4xLuVDNYOT9hKq2kUDhqRB/fBoJn6n0yLu8
iKOpjWQbT0nmKJlA8ME6obVZHLFjYUz32lId9Qw8urgI3scND4SNTmmMj9wuFVehvfO8XC3S
t3G2TG1eX9oet+EahfxMqUToQJcXGIwr6+AA57yqiSd6xnQAf8AVVBs9iz/XPNJKRrSC9lpx
CSxld7NZ9ocUWi4uhUfU3JxgJRQ5EgX6cFXC5kMrAblg1LDiKE9oTnUHqPPtraKMXua9TOQS
MZFU7lTkzdu/wFnaTt6+4sZmFnAnIdSW4ifriribo1zV1YCdhUM3WXRsq5UO4AfJtMuyb3uY
RdPpCkoP8uUcMW9cvOfDidjSYBc6Xjv2eOyWHDsV1JShCM3WhksuDcJMRCUNEhToO3ok/cTi
yXsFo1NTYV1pQDhS/+J3VSEYxMj7XXu7ky9DcxF/E4l1H4TJvBtiMmO57Gl0tGU1k0wGFB1F
EED2rFqtuQQg0jDz5upTVoYWqUBRIFlkhaJvRHn9lYfKsufM1b1xNUrSBS7PvJZPLs3WhnnY
aSn12zxH/IISZo1o8sJ+smx2K7rFJF5vj1fgw0jGOW9+IdXNyarEf1hZOWWyNPouS4TG7/oY
d+NKlrhy/HRFFzLpVjjmiFNsKuUM0liy+NN7cuCu69nx41quFUTmimyZ3sXyNMo1KHu1GTnS
izkJ2W6QuseXobYSKn1bgzKBmkCgRP+35D+dnqWWAVj1s30jt29qOvp9FltgTx088scw9g3w
7qri0Pf5iduQFzJtySqNY9vP05YzBBO6KLLcyOeV0RkMZ9c6zYnlDkkvc3xg4Dk0A8szrW45
t7Ylw/wgupsTd/LcQAnYG24xe+0uHneXxyjabl/VbJaolLXjmWUF/RkqvOYY4UmtgGt7W6Qf
qM4s1HgKpALpzrbSvrH/cMurQXa7sP2Z1/b3CY/dVSvZLRI+6x/29utG/8EQoG0VLn3OPFpi
Cp3slcJB5Z2lZTGGn6PWujWcjiwbLJvsMEsmnT58+gHj/je6M0waj3KrgUDfdhwHTfU+UkVQ
Wfg99xL8yKmc+jPWJr7QSM5RIl1p86KGKUmvovSuUiJ7RYleue2apvNenXP8HwZps0kWmUVK
nnHndbuGiamTFOnP1gmun7HGmf6S1O+QAI7zmyZjFHWYUIOMMBH1/068bz41q5+XbSCKfl2I
ajI4zWusT85zC5JpwczUhta28TD22Et/Hp0JthDDDFfz1t/mnm8yL6AJ8LakbH0L3+Pxf6Tz
Hh49OiL/vqGJT/jdjzT4DdU733Ywn4+rX2EJfBy5mXmLLF/C48qI8dv4n0aNQ3enIfbmsMTE
5qeH36E72e8PP5F0x1b2020kScIQy6u7u07kYi0MEGTZ1ib1bWnbaxcgE8Z5CBuOGNWh1Ez/
Mx6jr0nKV6SYsvxVLlvSQuezhct/5Vhal1MLkdS7PuIXNTz7T0xD0oXvSLrIqGqcvaZp5iO6
SPhFKfYbTy6n1OQRdnmHoa++MIH9ohN/TZImqXal/eLEDJcE4YK1BVakrRxEInuN2BxVP9Vb
/pRzEdZGX44sxphh0iWiI0su8S883tcn1DZRcRIvjvf9jxTgg6hI3bZXn55HZnTfZkm6amzs
b6JQpWVx7E8GLOJCem3pRxmup9YXybHJ5UncqhUwz5u8OHPxjxLj4D6b09FnDFmOa7qu4r2w
KZMWhrrpm6IwKyJGoOeSn8FadiNNaur0znwf2rGkowMhm7e0Eyc5xSTjch8tIvi5nMRBnG7+
P15w6hYmySInbz59lApD1ufIa45aPcoN1JXQhpNjCeKOHe5aOkRAZsC0w+ZuFtj3eGVQX3LW
pa5WayrUHPixJelq2qHFqx6FCIGyVMBIesUoCfBAxvvDt/9G90Jazs1ptIbHONzgaM3aFG3+
szbYUX2lpt7uDqyxQMGXrWcu87nPzAp449sJsqbL0Q3RSbsXIixaiWwN1ZMwrK5d4BDxBpYG
zYV0IgzjQd5xgFshvVtV12CvilxQm128bACK56Imiezb8cKuUB6p7MnXhMpeU5jd4ddALQON
auSC9rVmYRYeg5tkEy679O/qXG59daUHjZotjdrUai2vjVPLht0E0m0xOC2iI8+CndcSuf8S
XjU9biNH9J5f0ZcAMjBSRIqipKO99iKL2F7DM4AP60sPSUnMcEgtSY1W+fWp96q7SX0EAXbH
UotsFrtevY9TkY+E2iNstblzEHtb820RTDOFrLihv6Q42P46K8zh2B7o7gtYv3TyY1/K2YnL
++ZPbIdLr/y/d9Ubza+XxnXw6csvIIJ//keevdY1Uq/yLoma9lHWUQn9O4i7Y07EPg/mg0uk
x0LDLX+QTfejPWtZ3TG1abLoAJmB3Hz8WURRsLERXCwLu3abEZp0QFSLXFSL5NJU/p8rXZX4
BXxYCJa6f4DaTFtI5EJe4Y9DvNXr5du+ZyTcTFq3NsUeEVIQotf/ywS+od2ZgMpwe3D7nXqW
Agb76GSi1kGa6hBWVak2UX2+0dXXV7r0/2EGZ4Psj81xsl4mt7CXk4DCdkAm4inaO+BAzgot
EUBjrT1m7ODRuWcga4QZiDl7fYI0AA8v2I3yjmfUdicUW960GbWwzWm0Cm2WRxywjeqfEA7u
cz5gyx9kkZizHX/b1bQM9e463ehH9BRFHxWsjKiA9KusIc92RlGK64q6QwRqixD6LtCYrqJ7
0QV5yaNGAWJyQaUuvNHvtJqdtjiq3OJiK+dvtpV701M3G/C08M9bxQsnFPM48Uphnhr4vdye
STqpBE3oXo6PQFAKfIpilPyMqBZ4x+F0OU+CTGDjkU5kRS0htjI0+1aaxdaRZT6WoLrnI2ko
FwTLP/uCFxbUhaw5VoLOnKSXIfEMjV4NZjG+gSKb24AbXkbRKyPjDG4vnWxxUi27zHZJvLqC
mWyxK/gdna3R2NlYfK67F1zG4sb56WSP5CKNtdrETZq07+unpx+/f/8X/fe3T99/HWn94M6U
EzZB6ye/f//y/usvn8yXT0/ff/vlkSWMfNLmQrrv+yAPkHi9GApcuAJ/Y7Rw0UGQIWouJFGb
UwGQCDq3zgEAqNZsi5NheCigZJ1h+BC1W1HtElU7+edP/mB5X19uz6Pupq6caHMbPA8FZnWL
frF9jkVdx7JiZr5eUYczkU9P0a0d16Nciv1z09AWVal2r6zK/hzuvTguTzOxZrNkFm82foNR
KNu2NiOdJno6msdMCyhjdMMcOTuRbFYrP0drOf3RHHXHLCs60A7f/FiRETbCCIvJm7AB9xPU
ALEHePRhc0/amzVJO4pmm3kY/koZv55W9iyUehDrUvQQ+hn56wdm88ptRbHWqPt47DMgFLYT
Rjdlz6hZtDRPHWlD6pPNZbcXqVgeIXKZFeWbisXzmTbbxc5oIIoRZzpJXG8WgdlzEPIb/uQF
iYJbYdaHYIjEcR0M8fcAscfLgg/MDtfV1GaLFch6bnQv62nD1I5cc+7cBU6fjslQDigJFeIY
9l7PTk37MjOfeAp7lXzUgSLuHnEUywSETgkb1j20Za03i5LCmr1KHNwX8hCkKjn5y6J8Qlim
2vuEuErT2UZz7B8TQtV2Ch7+jbDygY7bhUdUip9r/rPG6jxcdOAG54oX23xmHF3sOAPKCjC2
tnowyiBy104npDV+3BKOG8bufOU5loEL1uFYM5SC5GksHSAgULxBZNmaAQde0b32ezHHgvK8
qn8xSL1Khmr7rc47LQglXgYxMte1ntueGMiarscUlHC/ONOslXGh9gUsNCe2cXaXseL0SnIc
IT6iKT0OMVXOuktZjmLiOGFGWMwWceA84zhrOXAW7d8FXw0ZpKNfJB9t1WsCB3nIN5VLeWAl
vSu+YyIj2lwhEi1lxHUfOYKg8+lnbVgiJP7Znikqstyan5OP0o7Pn3++8zMEBOgsPzv6x4wW
tWHakIWz96P8pRF3TN5Ah2ej6hLXymh9x5r9KhEKYPiLkYNYONBIPtAbbl1USBATtC54EHpa
re1UCNRogDVvrDX5dNzKR5dekyHNKa9r+LN5742lHOeHMfxczVGyvE2jts7NmtWcOIZCG0fX
uqo6g4WR+24YI0pSz0HJJgraNvD1hweiuhPgqVB6QbuAW7R0xlC3GTX5EACmyDPvpx+AwzW+
zPHn7/hxZh77CzkGyPG14zGI2xjCCxORxy7q8Zg+lUIz8srX/lHGYbla3LZZQi9IwkXUMZ6Y
+MRmjIGUY5UqlDHlPLhgEqMGFRPc0fHmehQO5DEAwK644mwvdYv1bTvzQMm260W7pYcPRnrM
wSzHzAvNGZEvzpbfydM9JtYKJ9X+W8v1qnIeTVmdtzovh8AFDp2PZ9lr3mqzCeT89PhFXvEb
noAQJzfoQRH1yFF0/+87JVe0UbJrMnnA6ujekO5kRpnHdjUJfjQEhZ8fnOMzPlRKEVf07CRk
Hi83t83el7u9kyGFmFPqjh6GajvstPI7pZH3UmlQaCFPm9HZVc1pNBkH2+8ljk0v7cImWO4o
+Kn0Ijs9hh3AzyqdsUhnL3ObNa3ULMSM/HfpHuJVcA9LX1rfmMev342TIme9WmPp2xd+h5GY
8WOS+OGVncZGr2qarqh0GuFmGgDSFZRzVR6YS76zYsjhIGWGTgU+1dLOtxL3MOPNePGt858n
q/UN9gUywMdS8SEvvrfUaho0EdOckv9cOFg4DI1Y+hWPrf1I5qbxtkCGk+6h1QDYAk80l7jC
VxfNV4MD4YbUKQ2RfIqMfqZcfSC9tx7DTe1yqAm1McXsWHHGOjgNqPDQOytClqhpY4S2Q8bJ
B74YYzJOkztURgMq8Dmg1Qc1iTiyTACUl/VOwti12RAgrqIQZ1q5xcpZbMB0R8Fids4QPIp7
LmO+8LUo74vPXMZ+p5l5onGVauQ/e8c/RZuFyxbrWbq6kAsfLcjqg0txp9qXI/pc+M0UvoLe
+Sb1Rbw6gojU0mpS41hoZGtt7j2qplSUKo9605+HUw8+YRH5IcFjRiX/nBSl1Ara1ImTU3uT
N2hN39oakh9PJCm50BNPmrwQOyO1WLOT6azFoeQF3clj6cboRr+iaJEGTLbok7xew1NR12o9
mOh6DfwIYdWpH9FZEEjmPjUR8TmDjlwWfElt/diMspV6Vrn2pG4ZzuDIfASHjStw7VjaNp4/
NSNdjHepui2b/KDMPAoxfe0enIqXasvxsZUqGlrMUk0n0ZROjsEXFCNfmrU0oV03Pfg122+5
1r7603eY6NsyEzXFb7kWc3ngfAk1RjxxjCtdG0NGOCJNU6NzwuEXcHTkCkeb69ERj/hCZpL8
czLuaEEUowjbzW5QeD32kydkzqd/XyeIBYUwmq3Xfhwqy0oR01CSTOfd9BACzgpbnEyMLaY+
PcgAWuNyLJNEIdy/3ZJsyPkiiuChUl4hIu87PahH5+unNlEnMU1mq3TEABMJuXijCOCR6qU6
flqshK1MslrOYJZe/yZpYi47jMaQBsF4b21Oqhk778uK1vohyM1zCAlwJJIuDwefCzM70LI0
ibGCG1qfJEyw8/kl6p1JigNVzFLB0KjEk/pUxX/JQ1SJ5rIi0XHUUqdOPFGv82KFBoMDnvkk
+dn2xeCJz8ZW7qIIg4ntbo8+Xq8GLtkRgwechMlsrT4YupMXyK3wuT4KYHqMxTvnPq3teOZE
LJ2aELc/x/oFrAOW4jVuSGJo6YW19FKiJvOKKlCdyJkQxP5nHMed1CGxRuVNpAFvSEoF1sQe
76zAz3mfYFe63okHeLnGSka0WvgSfbdDc+KW44nz5jyNBhr4jbezP5S3A/05K5QP3OLhWmUV
Gcswv3+4HNQ2R3ZofyCF9ffGMfLjmMYcxwiuz4+0QGcrLCHCTv0ahK2negqkafQlOxA5iaaE
6fCGIbqlzv5x9wv7906dyNkNUSvTj89Yb2wOJyPH/Q5HghaRkWHj8a2U/4Nn9wtNPTPfLCjx
hRfzXo6gzfEuQHxw/bX/1EvjxmPmWrNYDFkkI+yPHAXpf3OyLcepG1Sl5yW9rR4wyNOl6hiv
arwgDWE1e+EM9pjQP9khyZY6oVt/dxisddCM+SKUVLs4Kdu3svWLN3ZOZylDPFc5J9rnjUDY
K/PBC3PlFtRBPsufI5ZLdiFB+f/lu1qW2kai6J6v6M1UmSpb0dOWl4Q8SBUMmcFVs0g2whLY
hZA8tJ2M+fq559xuSbZJFjGSInXfvo/ziHraH2M+SD24UByT/HFj7GMsVmmWq+ANGyo66g1d
ebt7Ma2KIhHNtbgdNBid5x4iwVnRe/zuvKKqpTFUXjV8Uw2p2i1cWZxl3bWuiHEQNm+WaN9B
rT1dZPPsBB0U+fwcsTb1unnq1IFkYOpqq9Vkz218sZvumQSmeiMa8UVnE1l1+jJRwhO3lOoO
101YJsJFKJ+GuPhDkt7BSBQPo/YpXfiOrBXZn7qA2GfP3BdykvOgLz/yjzixUuNn2E3Z08nW
tEornjxgS/sDMNoH2qnDrhU6mM+jk9Ruik7VWIHS+bGEUcfjZMyxAJJO61ofzfgkjCnQWx4p
ygYtry9OIv8mOW9Djjjo0uNG4Ii9r/ZKd+Xg6BDytdLg8oA0x9psZTlYNetWnRFgoyAVDeQQ
dj38ukDG665mll6tKDsJWek0orHVugwmzDOcovjE7TJE2p2OBf0iCv9zXdd+eCQlblBssZTE
z6SQ4B9RW/fqauSRZEw+3Ut8DxURKhWEqsmBMbSlqVUpyITtfX92nCTJHHkdmQzlYNwB2wAb
UtFrbJJMwPzv28Xt5a3U7hpogCn58HFx8eX6zhwRWnioYNOEixxv2+sU7prlfWdCjuuuGDrZ
eiWn27MHl7J3ATg01/JT7EVK5xpMgQ4tebkgHEpfPVe27qjFnsQ5dF15NrAvSe7m9+5GzvsV
w7RSkUnFJCoXseiMYIMKrqFqvFkoiczEfWPxwQ8g6rkW+LFqDm0c37X85EFdbDe3zltlWfgG
uKyKF7KaGApp0LGb3exXoxtz4HADHT+HjpdJpd7dYKEW31fWksIsSlxgxKmakvMD4+RGKY5n
p0jd7ZBjh9ztQOlZ+tNaSWhgxNFAc6KbTceTS6RJDSfBo0MXEiKhCUu94AJHn5xnZEek/UfF
HIsqoXfzJaB2OXUl06jXFPeFVbfQahxDFUsAW3wxN/LgToL9Ksul+I9EHoS4+CRPIrlJ5xQW
MHftUjLJkUypNaf0bw+I68UlgHnZ6b7c8ciYQgtms9OyD5BVorqUO/yLZNUwxM85nQUWn4fh
DezZ1atBCr1f4scmCw3EGW9Y6EayJyPDyouolJBnU3kc5OfgrWx0v7EctQ7rnFMNkllyKuer
YrkSLpiqDC+NvGLrdssZ2lTUY3J0MahtU0orKPslIDP/FK/seFc6KX6gFlJvLgcO5/IyBiyn
sfK081hxkH7G9RV+XjXVUzCRpER5xOR8OZboablSPlzy/4qm4wUycW2NPlIGUOLdmpeOOLbV
uMvTcFoiospxNQtyJShQS2oLJ+EcxCp+sZy+zZtHz5kL2QjzVBYQe+PBsKC0VI/Wy0wglLm4
+4JmEaVLdZlRSw7py3de+EZJBQy/jo3XWT4jkc+m6kEQlOY0zjrZxOyGT8zVptdsPsH9Ukju
ln17hQVfuXzhOP9o5x6RonTaj3LuNRqbIBCBcljU1jnJUCMR8aeiChiPZtGvpOHSz1evnNx/
JIrQHVUaspNdQrNbUPhQjK1tX/g46r3C9LTym2JDGA5QmEG7TLvhz09LABDxWktNBlsDJvDE
BMTD5iEToKnsCh+jS5oedc0n0uXjjoYi0/ZLePo/2WDVsdftOT6OAhlB6qjRhaP4A2cb+wPl
zALtAN6bDKcjSXLKjokuNxRMYkOoZiyrtt6yXGpGVDU5ydS0NCK/CXUeJEKkGur7t0I9Cubb
iP3+kzCRkhDxp93gjyhG3hZgIGeOREYWtQzfZCakJONcDKxj6L1snqo21GhcdXHQ5UpmoapN
YW1lAZByYOEfWajZBubC2t3zGhp8pZq6LfmWqtP6pSrKvfTToJPSDnj68RBbmMIWKt19HynT
xiPtD+HfHS5sVarYUfUkqPL9fPzrvIrKzbLoN4n1Z4+iTBVDMPWF+CaOrWl/ig6WmGZKF1JR
U/23qZZbHPZN+g7TOFKFDdQ+bBilWSKfufeshxnxQAtS30jCOCj3xFU/6bMhTWJc2kM85p1k
nkrjgfRu1P3I29hTdphQyKik0Mg/Ls7+PUOCkJR4ngeZSaZm+Xz27vNdZB7t2btPz6H50J79
dfa/AAMAKoL6Qw0KZW5kc3RyZWFtDWVuZG9iag04IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURl
Y29kZS9MZW5ndGggMzI1Pj5zdHJlYW0NCkiJnFLBTsMwDP0VK/fRVZOmIbWdYGgCiaFpGweO
2eJ2EW1cpdYY/BoHPolfwKEtYhK7cKn9nv0SP6ef7x/J9FiVcEDfWHKQgoovhgrQ7chYVwTi
cTMfTBRMs+QWtUE/J2L0a2SWhua3dCLSLJmTY3C6wlRtbIXNA76sqNJuuR5cU2kWGwWNfZNq
PJT+KEtmVJKHbaoCBt/Foo1SX2hfWAdMdVcqMee+2xZ7yUfDcUBbYqZK4LhVXtU1aq/dDqHZ
e+ueRaUgt0c0tcBwSGhb6gJX2hUovk2qBrFMyNpzm+IBnQyrgIwJsRMA5XmDHHyPLoPvQN45
g0fIyVeau94o8Flyo1m+C9nN/qQeSeX1VPEkM/8w3wNGrbrdf5bci38h2zBDx4GM+mQVViK4
j72qfbcz6n84Onthf1H01/+SfQkwAHGWxS0NCmVuZHN0cmVhbQ1lbmRvYmoNOSAwIG9iag08
PC9CQm94WzAuMCAtMTAuMCAxNS4wIDAuMF0vRmlsdGVyL0ZsYXRlRGVjb2RlL0xhc3RNb2Rp
ZmllZChEOjIwMDgxMDI0MDgyMjQyLTA2JzAwJykvTGVuZ3RoIDExMi9NYXRyaXhbMS4wIDAu
MCAwLjAgMS4wIDAuMCAwLjBdL09DIDEzMCAwIFIvUGllY2VJbmZvPDwvQURCRV9Db21wb3Vu
ZFR5cGU8PC9Eb2NTZXR0aW5ncyA4IDAgUi9MYXN0TW9kaWZpZWQoRDoyMDA4MTAyNDA4MjI0
Mi0wNicwMCcpL1ByaXZhdGUvSGVhZGVyPj4+Pi9SZXNvdXJjZXMgNTEgMCBSL1N1YnR5cGUv
Rm9ybT4+c3RyZWFtDQpIiTJQSFcwUHAH4kwg9lKIjjVQSAGyshQMFcoVDA0UfIGckGQQAeIC
qSoQ2wdEFIGIYi6nEC79kMzc1GK/1PKg/NzEPB2n/JwUkN6QNC4DhXQg1jXXszAxUghJ4dIw
tjTWVAjJ4nIN4QIIMAAOAB1uDQplbmRzdHJlYW0NZW5kb2JqDTEwIDAgb2JqDTw8L0ZpbHRl
ci9GbGF0ZURlY29kZS9GaXJzdCAxMS9MZW5ndGggNjIvTiAyL1R5cGUvT2JqU3RtPj5zdHJl
YW0NCmjeMjVQMFAwNVQwNlSwsdEPycxNLfZLLQ/Kz03M03HKz0lRMATKGCgE2dkBpd3y80oU
TA0gfIAAAwDCJA9RDQplbmRzdHJlYW0NZW5kb2JqDTExIDAgb2JqDTw8L0NvbnRlbnRzIDEy
IDAgUi9Dcm9wQm94WzAgMCA2MTIgNzkyXS9NZWRpYUJveFswIDAgNjEyIDc5Ml0vUGFyZW50
IDczIDAgUi9SZXNvdXJjZXM8PC9Db2xvclNwYWNlPDwvQ1MwIDY0IDAgUi9DUzEgNjUgMCBS
Pj4vRXh0R1N0YXRlPDwvR1MwIDExNCAwIFIvR1MxIDExNSAwIFI+Pi9Gb250PDwvVFQwIDEy
MCAwIFIvVFQxIDYyIDAgUi9UVDIgMTIyIDAgUi9UVDMgMTI0IDAgUj4+L1Byb2NTZXRbL1BE
Ri9UZXh0L0ltYWdlQy9JbWFnZUldL1hPYmplY3Q8PC9GbTAgMTUgMCBSL0ltMCAxNiAwIFI+
Pj4+L1JvdGF0ZSAwL1R5cGUvUGFnZT4+DWVuZG9iag0xMiAwIG9iag08PC9GaWx0ZXIvRmxh
dGVEZWNvZGUvTGVuZ3RoIDc4ODI+PnN0cmVhbQ0KSIl8V12TmzgWfc+v0CNsNQwIbON9S3oy
u9nJpFJJV21tTfaBBtlmmwYPyPb43885V4Dptnurq42QxNXV/Tj33A8P7376x/dIbft3Pz08
RCpWD5t3URhFMUaFwiiJEvVwUjGGWkX4c6NFqlY6CzOtHp7f/e4VtZ96bfGken/lPfmB9sxJ
+f99+BfFxoNYkUhhabhaZRyW77wH/+F/75ZhmolwGcTRKkyXkL8KE5HvbbnplYJ6UlDfUjDG
Y/VCR/VoLLQ8+UHsGeNnXvO2hkmYrfWg4YeXhwc8Xafj6UnG/Z7Km1ING6+kee9v6L/gsnd3
66MkXC0Wt0/nkXFKobiQPXRNr1rcY+lVtledKUx1NN2Ne53UOoxX6dtG11lKS71t9NcG1lk2
M68n97hcLNBJmCwSFcQhJ0rYvzdF6y+8pmSMwBnwwAbvLf3R8U3RPTtxj+L7n3tTcIrjktMq
x6jrKswdc0YcL06ZG1m9fE5hG27rsNj7sccl9cgZGfHcjjvbZz9OvJtxoHWo9Wow2CsHeiHf
48EctMUiTBCxMYz30hrMHgZKEi2Xb+VRtAiz1MXop43KFe5WlWoPm6y83A8WHpTU3qMfJF5t
JNB6m3dW9We30NYq74wqjYW9THn3dljjTqv0jbh2OgcXFzLU9JqfBcN3M2fWVW9N4wcpzIts
V7blWNkdH0ZtDnzWtdrzmRdPMm3H9UYd5SmurzaV6acv9Qd1/+0et+RrKUJT/n6AF93FxKyj
hrEoGI2q/QzVfv78WfnB0vvNT3BC7PV9DkNujfrUWJp021X2LMGDTfdtadQP2fvp/ocfKnjg
kVjGW9mdGJb7nE84orCGq6XIoEZitGgApDhbJRed0tQpZXdG7fPCoWNCU1S9OjRVkff2Tg0y
Ewno9/e/Xm8tOpPDt1w/VdSLOXQ5PB7CDFpkVwb57RPt6WwJ24bqYbA1hG05EmflzAm3yVYS
dXBj202OGTTDI0cKHt0n8F+tCucsLj1Obp0rl43htBaofvgb0QCxG1HCimHSVw2PLIwct8Bx
TctnicigC2y13dn6jJB3+3iC28hRORy98M6MklEE9YSZjnwbVBW8CAgYehZN8WqMplV2w3UX
VKJbMroFL5wO1S84wCEYzAcrqwzPCP+akyHOizlYYCZMeXxHDCuJRO0c7zi7x6Y95bQcCczl
gn+ysWLMCVwZKt9LxbUvY1APlo7jLL4KA6boEjoWhQyeEfLP/tqTl9JFNmMeukj6Lof0HeaZ
wksGI8NPBBWyqesIA0vP8nIAIFlrRGjdbvk4M35neTKUzjhdLKdoyPf7rv2zwvVi3NnA03Ek
L3B/r/pde2pmyb8cJCSZw1QdrofK9rtXNeqXansQ8ATRYD7LHcbiiOnuljbReiVQ54SN/p9D
XQJlmBD6TXi9TWbWYZSpZRQNIH+LzIxVAptvcxnUoiVk6DAZCoWUAYAKryN0i0ZuWmWOFXxa
CnA0hWRtuxHXEIAAIq5k1GaoEtFwsF5JagYoRXE6B3p81yD+MgYqZDoz4pU0Q/gHZKt2swnV
x4uD9CR18E+UZpODILGjqvhwDnMYWISkOtHhfGusaueuige369S5PRjkzn01pn5fbTloAAd5
LSJryfveqpLPg8+kszIn7ElgJZc184fbMaIGMuL7l2+IJNmj7HnPZwUJBWRfLr0eITi6xHVj
eKcTc5qJ/dTfESY4txOvkQqh/midVJgra5YsxV++OuLi8r3BHsEPczSNlUXEd+sLeGvZ1vDl
mUhoBIwmsNKeaNGHc5cPKnoj/9SvqemAHUsHHgtCmQ7VZ0GiFIfRb7EXfBYYP+NAePU9Hve0
2a/9RELmnHeAp3SRznCWDJpHwL7QmrCWQ1tH/HCrgrKDQpAKHu250OWig2GoAzrXDjprqsKF
IreDmm3T3yluo+wysNwhcB1Mk65Ysbhh/6g3tE1XyysIbTdOLXyqKsHifdsTnim2VTJzoMBi
p6jt0bHRtdftaKC8DOUkBPiBFxLsv+PUs1A93Pb8f2wwS4WhYOk4u1GweiORKsSsstXRpYQL
cWs6eQLIgbkc1eAgtpJMQDORH9sxuksX7tDMJZUU7NAP1p56b6ciC+X7XJYMa/lkvnihrytQ
NbDZyNXtO1VtXD66RCNI11UulbyqwdIEuoX9VO5bZNzdeHSj9tOnrE68VK9cacMJhyHf5bpy
KevH3sQUDA09qwPxhMDplL2lqc1Aug6NrWq6rTB9vznUxEHmLkRWe6t2QBjJPDMxOZAlU5Jr
QX8CpgDlFYGNs+Xy2oM4A1leAV5YcPDhv7/j54uyXb5BTGyqQp0G7J8EppPAlWsP0RHkMGkh
5JKfHg1uYFwJHJHLhdMIXXpOXQen7Zz9Ym/vggqEo3Uh1c0c4MKE9Vro6dd89Ai1/9h14oBO
fUNx78G3v3789sNHSE5hZGcxe03MkmQRT15pN4JubPK6gmCYen+nVpxohA5KsgSu62MaBuZ1
piM+kOrSTjr+5ZO0SB6rETueBZth/0mwGfdvz+Qm8/DJJv59Rf49s4HDKmgK+Kyap6DOz8TK
+1/7sUuM06l2xAMBWGUTpZFKKbwQxR0alqRoxPZ2ooR7jmTLNMUr9CZUcy3Hrildu75uOGdW
7kGXZsWefHWgTeCIUlGWU1eCIcM+l7geOyTXu0nKsA9D6yH4lje3jLW+wVLZYyBjEK6uu3yu
LJ9IQ+kxTtKNVLVrEFKmGdSVT3rXj1qyY+DK2LdQI9nakV1cG0OnPPp1BrJnQqgCUDZ5VTON
zcggO55U9so4JsPbKZQBIq3jWy9Iy4gry/Q6tURfIy1Ybl1LNfVZ+QZQDT+7Rgumldvu5Y25
ha320sldzCU10A5Qj2SsZxRlZFCJTi6NWNuw3EjdAd5JxdFD5dHevEWRwsth3vQuwjgz7iwF
eREhT9IZKSap7G5lr5LNvfrjYA7OSs0lheYAHK3W+todNP0eVapR7cjnJ5PTWqddRTjeuYLR
lKxpxhUDEl9pVIS4rr15C/AS6BjMBc/hDmHXak5QYe4vXNnm47GuN92axnQ56wSi7nKfl5T+
VUt5iSYqA26npX7AOng/CJlHkXHwLxegabnVVsWhzruXipGTSr8zna7jqaNNr8KO+UnSBN0P
PdkJjvIdD94QLjuF/pS10ycRWAhN2h5kykFD7Ka3gpqG204S9wQHVQhN21LuJAF+2xBLuIuf
P0PONcrHi8ViCsuv/8R3/1GmG1At9jqeHqoPAuoDuosyagB0iVAG8t5MPCBBedJoQYtWCoXj
jVI/ONo6IH9k1EJ4OXECsWE2tpnL9IYL5Wpyl5gZgJDvz7QHqJ9YZwOHtJ2s5jM7cNgi0150
X4mLeTY06+UI+wW6NZJLuP+ZWuYor922alC6i7a3Y2s3WVHUDcbYG/ojiJuh+0gznRUGG76Y
kMFWwkPR3u5dYGH0djr2M/S2dZx7LDpkq8Fjzrozv+BC68UtpBdOJJc7MJJxqUejirGnPe9t
u+3yPXI7r+szYLc4dBLn1nWP8nIcu0ehXfZFZI1JqOPoBk9+rvqqAUpCDrN31GfTEbKAfX+x
X227cRtJ9H2+oh9HWalDsnlFniTFC2izDrLWYBMg3gea5Gi44pAyyZEif31OVXfzohnJzgKW
gcVAwIhkk305VXXqHOiBYaJwmCgwkVJBYiOlpZgYGabV7qw1kD007S09OT1AxXHi2mDRjJNg
7Vi0MOBFxr/cVrXHglXRlcb1saOkt/EsjeqpT1ngoNiHOqjMcIbrstlRgEVqWRxFoO2J2Dca
5tiz+LGMbm60zha6tJnzUQqZvm53rBB7qtCIurT1IBpyNhhaOd8PSpJbXTAK9UdS7VYmGmuT
WwXfThA1sXZU6O7HOmt2bA9zRIlCsaMEq8zJhUl/xHxsYJXmGW/Zdbarh8vhRRwQ3bDVgaHK
x3OSZJtxrrWVY63Gf/Sk8hDCoZ/sQbwyx9Zwcm/X5ohRGGybxYvv1hwA0i/geR4hBTTYIsb4
UWAa19UuTPBn9wOkt9p+Ge8xsKGF13dHKf6BJLOLQxOrbazZBYj4JUpNmCZ5I2wlpy8RabvL
n7DtU4rwB05jTuG9V9/i7uqSnpf0TUfCpKWRjzt+0BY8/9q2l3awWgyxZ0ot8g+QQNY+6hxt
bob0BeUwBtmQsOMYXOnpgKxNS0IYLbstPnI1lK3J7bWxPRPVaZS+5yX7jTl2PFxLH/He3lVl
Wmfg0RXpbC3Huz4dGSmyE8XKMJLvD4xU56wW0OerrhGU8OwQiqxcl2iOqfAvCNixeKx7VFFs
6Yime9I7OLdLTmccNNacj/D4yyvC/ZJrgV76VGgq4dJZ77hLcMm11GdxEOKbGj952mprhjpj
BQNa33VsJn2tPhttCcNlR4+aVgvOeIaqjbB/KMJ9qZM/0eneVRwUKPtUc4moUuM+M10bNqq0
ZvmpEKasvDHeth6TaTmamBeD2Z1E3bP+jsr9SdSzTZHdltpjqiV6b089n8B4e34ptFnEVh7o
FVTlB5KOJFB3WZHLcQ1tZ3Qq4L9D/5AcEgrADQOp0HC2iyXsoPWc1gyGQWI8p2M+5KvAF26g
JOwhvqNuTT2H48nt39Ip03SgzULxB4sv26w46lyQ2ivec+wr054e9LF+eYOH72ywN9pfiGr4
lMWnZoJYG4oD1QTyP6CyNZd3zGMpKUCqHzTkXlyUvXizpxIwC8sw2I0Wn7xDWoj3y4s3796f
SOKX8xzqJi/JhpAewc3pIBhnltJR0T6Xs51oGwh1EsIkVagSoeB6LaqpwLNNWtdFxZ6ynfSI
2M476MQgCmytUz5U2j8iDqST+llnYMZvH0WjX5jlZWIm9hzflj3NbFHUdc+Uy8CTnSqJBflh
sW5T01dwg1eQsr8nNPwfKVD63Y6us80p1w0pSGBp+pSPggJ1pKIq2bjeng2JDh02cpPZX+Kq
oemAaKvmQUuuATvkDAFsF1hj5hNrR6EaSB72VFlEi6Kl3zpveOOiL/UBdBcdQTcKzfXDeFgb
YgWpo8s9K7oubUsArmm+wq6IWrtdRkNrbgUVq5c2rTuozW4SFUm7NhyZTojYplCsDlBZZb0P
E6jQNSlaU38dyUCraTpaeJD1gjo1yovYmcqWiskknym6QlhxSBV3KzYnAUvGe/uIi5DriIqc
bNbpvM3aratA+48n2a8zgCLH3RHbL9ZrcAXlrc2NNWeGyQJSjMw3m6K6o+d8w9nCKd1zerVs
DSYpHVqq9UadghXBlvR5vkNjzaiykRvkYHhxkESpE8iodSn0lG9Wi+8vrx2RdZgyCtTsV3RZ
vVBhItF1IvTtWMQyCoXnEue2xWK9+LhQni8ihNJTNH4GUsXAr9+JGmOOiBJYNCVCUPUZrnkM
Q7zk5TWTsSPE9eXPyI0gEA8iFm+FK/4hFujTkqZ2QplgXszuYY5haeUr4nAzvF1sFteLf+Hv
YoVVbxbfr1YK86zWM94iuCKp3DDidSPpJdiYCgIZhCJMIhnGjstd5N1v1EXOLMpsOxOsh4B7
9ArxxnUPCqNGCw/whVAmLkSHCOOA9u4q6b0SmL7jy2jAUi88wVJv6/NYMo9y+h1AMeFWGuKf
YghXNwTh50HRezOY6DC/DiYqkYn3bILNIPuy/NoHxXcjid72XGoFkUmt2ItnqfVLSgYWpasc
1K7Nrq+IRaxkMkCB0qJ/IxQzpGZYzHFw3WdgCNynFfb78t8kVj1WPETL7CfPVLR8PPG8iXB3
rDRww1B3cOlGaoYWmZO/cacD6b+9ws/l14cscJEfE35yKPsnmE0RfQYyToGXmMmPY+k/ge0S
2hiwpdwFYU6KiUmwLmGWTSQ3xF4pBiSFJ79ciuZMphZ9X0I0vUotBgEaSzwmIK88gjnH+mWC
cnzvcBIGCrt7UoursRZdW4sqDp6gZ8D76vSsIuque6dXoSOR+2b4hVyKomeoOfLBMCLyKJt0
El2iSM7HzFGeObxjZbJUtIdJkQGqMxfSUne9kMUJZNJ+5zuYWeaErCG+AccbZJ/h+APAHuB4
/6VCBc9TiCzC08QaSJ4O+E1JHpnvjlg4VHETLMIQxPGZLHu52UWhDP0JCGOnc5/XUNwE0kkr
0E9Y+n6prjIn4+yiSLwWaxlaMojqlSeITvF+mbRcz3+GtBxXRt40sW72MPX9eTuEsTiDBfrp
C8Gzp2D0vgHnP8N6c3Bfgs/aIfdwbQaegr8EhD41NaY/JCa4S5yTZriEjdRQcW2TNvYUf49L
F5SK80sqbVBizCE4pwjA+3lQ0YrM3/Ji6BCu/lJoSY1a8QyyuHSUK7LtC9C44r8aGhrY0hIo
Ulivio/+OW+h/dLEW7yST5uZB/YW0941c3H/q7WIHaqsv24t/n+s69G1Hl3r0bUeXevRtR5d
69G1Hl3r0bUeXevRtR5d6190ravvjmb125hVfOxMIo8XGXsEOkhklCQJwNC1Iszr3pS8vCFd
Io437UDPwFfKiygrwxDJ6VjN9ffyZtcW4iRcKil+bvJCnIuyw61IxUPT0lV/lqVdISr0VZCZ
Wvb8et+eRMu0phe2yLOy74uWnzfiYiJx/bH7Jtx+HemphKVuoGv6/bIq6psTRezoLTedqBu6
ET39E9SPuyytivcnkIWS76+xzCbFaF7WY6PXKse2fBzfQ7oT6rzKDZdF2Yk8pav2VqwbvqA9
r3CU35hZTkVV3mx6ejiMDys4EymhtJbAGomanobqL1lK7FWjSfu94N8Ci/xB+N0VGS75tJ3o
N4W4a2mMsd1+qPQ32zJ/OEmW6SPeIKQbGt3dbPiDEV53CDmLG2wnjng7SGB97t1JsEzbnENT
bgtRrnmKGo95zrzoaCzlPQjeZMr7qx5F91hnG3qUSzFp4lCbAeVkJGNUn4dU9pCYaAimxj4u
PB+U4mF/keabCO9Q/iIe+muHIQyCELWH56BB4pGrrSN+bJ7pzfEgUmIZKDMxXaK4lfJZALvh
QIRJwC33wvDfmSeVjwz5EUO+Px0i8HTl0EuEKL1zlVejBfnmx371E7/ARIrWNSgcoCJOSzWk
pXeYiWJqgIEPTOKnPORL8ZbrocODXLS2NPIS9dDQG019RqlM+bpuuIDvU3qtbHaduEuz26Kf
lAiflOIyq9Ou/IQv4DeXnRT/LGtUAc9RiLwBlVHOaxKgh4KLIyvK+0KkNQ90TUX7yfUORp86
FKQKjdtAoKcL96T+SA4SeW5LvpXiquYCRWFSFAOijHDJTFXz2aFeLqZMFNplPNdwXegOXEd0
3aG+T4liuNp3d3dg565oS5yzpLHpZP4QrcSyWpSEMxrZFhwObIpPn/Y8bVswJi23C+CCZ3T5
AQg22/E9etYVdV60P0yXjYczMJlCDc4ixMxogsntJiTEwE0hYagQ7ZqOMkI/tD9l259KAovJ
n3RXTW/ryBG8+1fMUQZsrUiRlHgJYLyXD+AhiQMb2MPbHEYUJRGiSS1JSdEe8ttT1T0cUh85
WCaHMz3TPdXV1Y7uy1L+nQGs1UVKgpqLJjvaFABSZMaTH1OOmkfZMOujxPC88twJN3lYlAMf
3FCCO1MXE825WG4flWyuDziC+SRL4xjvTX2wW45bOSD9vT3NuAQki/mwAfUcN/j8+Ps7jR1b
pXkB8vZYWvxrBB7Hw9p2+Ngxu+QAKOdsW1DTq84WFYRAu9PysJbvLR+rVg5Zb8x9BQ6i2dhX
PUlXMKqwjY6Q6Deo3RL/10RHj3I/XfG640ON/Q/9Bf368Q9k6bstmtdzgY3ttsnzr1wMCDpq
zRRYtVlXnPg2rpKOjgJNlplHNs91sN1O9I64faSHbWdW4p3NsmOD6IyCg9HzCMOBtyz1Nwim
SZz2mCu6HcLXQTcN4HIpQ1LZHlmXwWTU6vmLv9zgHmpq1icHBAuQllBJk1TlYR6mJNMIdSlQ
Yr6VlP6GvJh5wMwoU0v0u5C7iWPmF1ODL4Sx6IAIh3UOp1rTFNA5LR738rXEG+e2HOa8rQxn
mFDziUMVH7g6ew6ReIA1Fwn7nfnIoZ0s6wgKeZTAVTk/nbl7g5/99AHwZkkaOJG5XF7xF7SY
gILmgPXGCnZaAZ4AsyN4up0iZ1M0xABfis4IuDbCBm5C0RjBpqW5bC9jnbGtyZReWmZWTgVL
APdWR7CJ9bzzaD6/S5RindvStJ1tOiOKDXYPddsWKypwCLgxpHASJNYS/Gw2jVUkTc3n7mq3
vhqjaHM39Hc/exw2RtcIu6sa7QFpkNu2wRUPhtLeUDJ3DWXClk1DfMKpa4rLQpjGxRDxw4GL
rh3SMXDniYI0UnirnfF91bxoOqoA+RJloi6yaocTdRIJCueRo9mFirvGz8aBR2AUThShCy1A
Ba+72hqLRRU+rO/EPbqTMA1volRgiYsKH9W/bV4xixtbQiivcml//L1YAbQ1G045my6v2jFb
XkXB8bbsR+944qyp2zyjO9W6dwBJImGopXGggwa0zM9nsvMSiWqdUwkkQEUOkwUW4VqPAREs
e55+wIet8PAK+FN6LcYO/pxz7N9T89bxSHLXB0F54ci4B7tGzuecqLS9zKnPHgthtFzcFwpn
QRK2wDabTd4o12fKBitvtjvneTUkWHJfZTQrZn3mI2MXE7G1JiLkQTPWZze3lNf+kPPZkDbq
pmsNxbDtCld9mOsrq3SA3PfHumGbTgKFYLoCyJyD5FhMfryYvHCLxpqyR8osXSb395X/h8x0
4E9ZZAXbNhqO1PDI91bFhLyQ01WGRkLqQ9QGQ1KOL+YsR6I5cSPq3QAhiY1qkEly2tgr4CR5
KAJSkJVTO4DQp4acozz2kjVjOWGOtfyy4xuE+SuzHovWollqmWnyE//lzcW8ccI3Zt4PnRpy
5lJ8O4gJLoaW5D9Rj7r7KB0dtwXBPPK3/c8jK5/xDHRghcuFgiomoIVyG9WwQyNSJOaWkPdb
C9XAz6KuOAtnV/6aE5i12BQBBIklNXMrG4xnS0c2n7wOB/WSI3mQvV/SLTl+yJuXgQhV2uJw
7zpIcjGW+5VCnVpu8+ZZJdc6PwkR5eSeKUe+uxEWIe5gRvUaBpRckfbd8xUefPVhg3KLh7d3
UxbVvjXQpyYXxbUToLXUcQgp0qi9VBwclzyU2QyLmGN+mBLuLkjA4ECub+9TTvqEQ6PSEEh3
BzVzLOkAT98aFTCEGksF9mPA6Ple1IwsF7Ldcumo7ljx/pan/6+yC5bTRRxpBX0k6uJgMY1S
NJBhtIAgo9y8F3ZXnA4J9FDYxdCFyUIspRCIaukny2JWV0qB0wcNZhinro9Np0mYXtXoj4LZ
pGWxtE15eTFnoYq88mKJ4M/Nb2E4Fz3AYMloDQQJ1eBTRKqP5AZP0ujgW8acseVeDdVje0Uz
umcn/ODd0t9ztiscqtdSenhF1Quv3otLubWbeXLVa+rLg+RCO5ouPKJVVhIfpw4pdHHSMTgg
ShQdwaRXxqOzOtE3WwSpP2veKo+Ek1XpiISQ3OXt7WHrKuODUIuAivJMIits4RQSD9mfMHoR
Vb3rs3bXywFE8cI0X416pF79LMetW88qa5pAGQafNfyRHYYDWgp7HKYh9x17QpQGQAMn62SR
MMnnTv2U9ErVpQOZtrYZ3lX++ynk1IrBuRBp47oY95Stl3/FLLWviqLcUKfLoS4KjrT+R16s
y6iFXO2k+tyWxFzklZYgGClEAFH+aCENdceTIjl2ZREM9YAJJVlvY3yumz2lsjVlXR9eN+hw
Bymu12q2jZWCNp/sXLIOVDLyHkFSggiHzi8cGr94mJ6Eunk8hTeRXM43B+cUXPeB0f0zEZii
80ICWVAF3P4ujd+Gestz25iMwr4fm48V5txtJr1YwnrOKrL3z/mBj4BVQmGC7iqTbwIAPmyk
RSv4+IUDyRpqwWRyQXrw/7HibweR7i3txLy30SJ2WVGWqtrYzcogCojm05CtidcD92Xr9yO5
oiGg/zBZc3FU0KeyFFS2rFrhXTFBnvTVVrJPS8U8JDMtEows8fc3zvtDEnfFZPLZ/pz42l4d
N6iOROax0Y6Gs7ZSuPX48TIZJKtP3qWjQnKr6Ay82LUTA1j8XzwEeJgdRMLEqj6MUwJ2EDrC
a3r8jCsrT2LVUO4EakFPz2F0j/gudykmpQDs1dgOXSi8fFE+rtZGvlpcPAQzOhFIrPogbRcv
vyvgSWapHU6Wg4UV0XAn6sJFfHeHfwpm9JWuHtTR+iQEN6b9nsfWx1YCLrin6pMrhk7Z5n1f
l0xeIxr8LUxm33p6rMURXmyMP36CK/w69XLluiNbhkNteIME0g6qVIAPfBRPtHdpbZdL8SYK
0bKVptZuBtFRmGunwjC5BiU3Rz/FrSWV1c/BuFb1aiJYLO4vbp/nhAeQgXjdgIMOV31pJDhO
EkmNKpWsCmkd7AUybl0qgYTa2O0tqiWz8UnvJ7i+t+mDkjCLovTuxn91DJ8rSTe+EChN8GIp
F9ZnkG1P9hfTnVV9VLWqFOresjTDgpPvqsAfq/qoTRGlROgi+ufPp9+fAhVjJkyX09jME5N9
Pf3y14/AbNunX/7yNTPf66d/Pf1PgAEADGGN6g0KZW5kc3RyZWFtDWVuZG9iag0xMyAwIG9i
ag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDY2Pj5zdHJlYW0NCmje7ItBEQAwCMMi
D0HIwUulTAor+03C7pYHtDkAunuGEqKW26qYdAtIeac6nCzPg20lPperxOfzFFuAAQB5ySiA
Cg0KZW5kc3RyZWFtDWVuZG9iag0xNCAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVu
Z3RoIDMyNT4+c3RyZWFtDQpIiZxSwU7DMAz9FSv30VWTpiG1nWBoAomhaRsHjtnidhFtXKXW
GPwaBz6JX8ChLWISu3Cp/Z79Ej+nn+8fyfRYlXBA31hykIKKL4YK0O3IWFcE4nEzH0wUTLPk
FrVBPydi9Gtklobmt3Qi0iyZk2NwusJUbWyFzQO+rKjSbrkeXFNpFhsFjX2TajyU/ihLZlSS
h22qAgbfxaKNUl9oX1gHTHVXKjHnvtsWe8lHw3FAW2KmSuC4VV7VNWqv3Q6h2XvrnkWlILdH
NLXAcEhoW+oCV9oVKL5NqgaxTMjac5viAZ0Mq4CMCbETAOV5gxx8jy6D70DeOYNHyMlXmrve
KPBZcqNZvgvZzf6kHknl9VTxJDP/MN8DRq263X+W3It/IdswQ8eBjPpkFVYiuI+9qn23M+p/
ODp7YX9R9Nf/kn0JMABxlsUtDQplbmRzdHJlYW0NZW5kb2JqDTE1IDAgb2JqDTw8L0JCb3hb
MC4wIC0xMC4wIDE1LjAgMC4wXS9GaWx0ZXIvRmxhdGVEZWNvZGUvTGFzdE1vZGlmaWVkKEQ6
MjAwODEwMjQwODIyNDItMDYnMDAnKS9MZW5ndGggMTEyL01hdHJpeFsxLjAgMC4wIDAuMCAx
LjAgMC4wIDAuMF0vT0MgMTMwIDAgUi9QaWVjZUluZm88PC9BREJFX0NvbXBvdW5kVHlwZTw8
L0RvY1NldHRpbmdzIDE0IDAgUi9MYXN0TW9kaWZpZWQoRDoyMDA4MTAyNDA4MjI0Mi0wNicw
MCcpL1ByaXZhdGUvSGVhZGVyPj4+Pi9SZXNvdXJjZXMgNTMgMCBSL1N1YnR5cGUvRm9ybT4+
c3RyZWFtDQpIiTJQSFcwUHAH4kwg9lKIjjVQSAGyshQMFcoVDA0UfIGckGQQAeICqSoQ2wdE
FIGIYi6nEC79kMzc1GK/1PKg/NzEPB2n/JwUkN6QNC4DhXQg1jXXszAxUghJ4dIwtjTRVAjJ
4nIN4QIIMAAOCR1vDQplbmRzdHJlYW0NZW5kb2JqDTE2IDAgb2JqDTw8L0JpdHNQZXJDb21w
b25lbnQgOC9Db2xvclNwYWNlIDY1IDAgUi9GaWx0ZXIvRmxhdGVEZWNvZGUvSGVpZ2h0IDE2
NS9MZW5ndGggNzkwL1N1YnR5cGUvSW1hZ2UvVHlwZS9YT2JqZWN0L1dpZHRoIDU2Nj4+c3Ry
ZWFtDQpo3uzbi27aMBQGYJJ0XDpoWJNu3fu/6OI4rdKrWuB4LXyftEgbGsb2j3OSmKoCAAAA
AAAAAADgq6jr2jEdDx+/D5IaqZEaR6kBAADgC6nP0af6Xx16fS81UiM1UiM1AAAAAAAAAAAA
AAAAAAAAAAAAcA7quv6Gx8M7+0GCITVSIzVSAwAAwDmrv4LPfd4DjkiN1EiN1AAAAAAAAAAA
AAAAAAAAAAAAAFyEuq7/+xGpkRqpkRoAjrM4jzY0UbQNqZEaqdGE1GhCajQhNab0ElOz4CJV
AAAAFNQsFlc/YptYroarvXV4TzbXP0Pff7tbLG5iu9AOA7UP7cOv21NMejP87yY2NsvV8P5t
9IAPIxGbmmZ4+64P7UWbJiMyNl1/d3uCSV+u0hqwCR2L7S6NQzt+3sgBiU1NHqnQXixXN7GT
MSwx6fMfPellZrSa8h36Pb3+HZqa7Z/g83h8aprFukkzffSk57FoCqRmE9vG0JHYuqa5u++j
q7PwM1Se6aMnPa8A0etAznns13QdXA23aXHPq0HkKAVfmoxROXrSS6WmCS6G2yExwam5il+V
03q83UV+vU6TmkJnqOCVJncjODXjGOWSIKoX8UXmac5QZarhNvpuTTttAQic0jzIoTVxgYX/
NNVwiSvvYU5D71w9iF1run5fBa/KeTab8LXm+EkvcJcv9kxdKjVj6ZTHO64HZeqaE0x6G/5E
YTp9hFfc0U8UmvjnIpvoJqaFrC0wHQAAAAAARXT99Azz7r5/78HXdvf6XtHlyg3Ty/SRZ9Jv
73ZopEZqpIZPpCbtauj6v2mfbzdt9p09ekypefrqeG7bS43UdP34K6x0mP487EHIqZm92vXr
IltG+AapWU9be4aUjH952CaQUzN79fG0JjVSs68eD7mUmQqanJrZq+OPQ6VGap7lopnvK36R
mrwbSl0jNc/Wmvml1SupGWzUNVLzNBe5rnk3NelfpUZq5rkYfwO3yaF4kZqx3kmlstRIzZPV
JFU2009GXq41213efS01vJks94aRGoqkxjNvADg//wQYAKY5lVIKDQplbmRzdHJlYW0NZW5k
b2JqDTE3IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9GaXJzdCAxMS9MZW5ndGggNjIv
TiAyL1R5cGUvT2JqU3RtPj5zdHJlYW0NCmjeMjVSMFAwNVYwNlSwsdEPycxNLfZLLQ/Kz03M
03HKz0lRMATKGCgE2dkBpd3y80oUTI0gfIAAAwDDDA9XDQplbmRzdHJlYW0NZW5kb2JqDTE4
IDAgb2JqDTw8L0NvbnRlbnRzIDE5IDAgUi9Dcm9wQm94WzAgMCA2MTIgNzkyXS9NZWRpYUJv
eFswIDAgNjEyIDc5Ml0vUGFyZW50IDczIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9H
UzAgMTE0IDAgUi9HUzEgMTE1IDAgUj4+L0ZvbnQ8PC9DMl8wIDExOCAwIFIvVFQwIDEyMCAw
IFIvVFQxIDYyIDAgUi9UVDIgMTIyIDAgUi9UVDMgMTI0IDAgUj4+L1Byb2NTZXRbL1BERi9U
ZXh0XS9YT2JqZWN0PDwvRm0wIDIxIDAgUj4+Pj4vUm90YXRlIDAvVHlwZS9QYWdlPj4NZW5k
b2JqDTE5IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggNzg1OD4+c3RyZWFt
DQpIiZRX227jyBF991f0SwAysXrYzeZtMRvAO4vNThYBBli92UHAoVoSY5lUSMoe/X3q0rxJ
tGeMgTVNsi9V1adOnfplffPhH38GYtfefFivA6HEensTyCBQkVgXIpAqUKlYvwgFL7UI4B+P
IiMSncrAiPXTzb1XV6LzVeDt/ZXyrPBjb1P6xtturZ96Df5UfuQV8OXf63/efPik/9OfRcdM
Twil0Yl7UjqRoZ6c9DEITPr39X8n1q7IXNOba5Ilc1WoZDKzWJSVvzKe6Pb4H5nc5J0VeSde
6FVZ7KcTykYUhxqHBfr42IquLB7xWfqhx36xKQmbEsShQlNWiUwgWisltYYXGzj7N9gn8hpR
1Rsc2Fa05wqPgzFuTm/Rkq58wqj2YVuv1VXUlAxCHG5uvM6HwMTSpOQ4DVScSJ2KRBkZot9e
4M+CRwbr3mAI1FLskkBGuEckU47drXjB2+3gD4zWYCo4gIaCExhI2zRw2zV+at554zoKZWLG
w/DCE3fharQ5ULjL3FcdpTKOJ75iUNFdOvHSKw1eqYlX3q1/DSsT96GJ0eBA6khzsO8ZGGl/
N6tZJANNKFxpJVMd490rY3jZS9203arIWysgTHUDOJxADILX0kPe2A3Br7WE03ZIrHo7wMJf
xYDj9ic2YZK2ZCxDDgz59cYTgry7uIWlC8ggmpke001fRP8yjlkswe1xCaPwtTvKUpmmMBsQ
xbOf8m/9fE4cCuQrQAwyGafTs8TPl34Ny99kFSWjuZcmhVUh/P0y93Y1OrJIKfHM81U3wO0i
DU0gYzP1m/KQds96vlBq2WsTcsz0wF0Pvvgb4EF576VTyJDMXHj+g9mlYjAjnrrwZnqpJJLh
/K4W8mug7TSNKGGUlko5stScMGsiXUGIzzELmLi73BE40HHi0ZyKXtiiK5+JwLvzLTATvax9
7VE+Eb/yZifKq04QiVt7pN3eyVYmQvfiJBvY6nv5oiMgg3hc8na+IB1mkF5J6jjN5ctlHNUQ
x0UM6djIRE8OFR/767iqKN76uozoFNZPrNjNbbg6DvE6njUkuGPTMHWVUYcyjMIZPR4PUFTy
AstLtfOxCqJwECf4OR5JTCAHfuXyojx8jxM2dK3IjvQCH1x1AtaEVfRUYkGCqw/hFRQt3AQH
+OmFJtqKCPiMexSwaj/hdqiyM2ZFpgVitc+26pCBr6MZyigLBxKG+rx+kxkjLLIxJDuy1zS9
MHLZSI1mmRoTqWC1kZF2+uZn8eCBN+gd8BIViMGDi9QGJlPTo4mcrvkO6qqZnAE01NuXhQuE
ESZzj+4BvH7mfRuL1XcJ36TSmLlbH9GtCGL5pkdxBpCaurQb+Dbs+TaIXpE7mphr9FOsFqvn
6zSbBpRtww7vodk0okpxjYMfMz5LiF0mxj/4H95lvQ4iVGBz69Nr61lqXKW+Ilk1NUAsSE7n
BvBnyLyP6E9mvP8baCNM3W+YmjmlLZGDnatPherzQcdK0ZQWMxt10e6UI1sM3HBNALciCt5J
92GMNBhq1NQcmShY6EYC1buXqEU6NlqayT5eK0DVUQ8ghqsOBjGpWEwq0E7wcsqWpCChyPkJ
kl7obfpYBMcj+AluQ89SPIq8gBnFqcmL80+v9xIDYeHV/iBfAe+k13T1fSVHdAV6LrwoRxOQ
aD3sEnNTJxUA08nvBw9iA15lETgKdRzIaO7XrDDCbqTgPfFh6aR0iAHANsvGMzQwaAB/FE7j
XR2y6C1ABvKUe7Jeoc7OG0vJxCXPpO1CFVEyzKJ+s4VM6hWUyVJGSSKDJJ2hZF2LFuGfn31s
KPCXyxtmEwqjWzG0cphZrc+1tIJxvaGmg5LmhBNoJ3E6bvLOLacsfcZvtqETYD76knhSfOZy
jC0iVmFH/WGiqIqt/wrWVZYLMFR0zNZHXD5JcNhPwU8wpC5Z1yIT1DijvRWuys3tHwY5fm/y
TYmar8aHzQmnk6kF/hZEK9M+rkdNpkc7PwYoECX9qr9IcddiH2YxbfFVQW0bHLuKPJKXpCcb
zEoSp8+sPmM02PV70AICSzXc5/U9XYtyFhjucMCdpkaljlTiIB1VCN7xr2Addo0RHocsR2wA
oaQdOp/kMYz2p2ozzLLMjBF2ltpJJ3jajmIbAuYVDavnfp4taFzBp8ninI7bsMExCfTILbXY
6HZknEXDmlFlr6aaEJJCXWire6+xh5zEPCwGuYb/MZ54sC07UfPXRhwbsmzwtkDWp9EBjG0h
omyFOPQzQF/Sc9l2lvZEh91LTHkc0JIczmptK8WoXHqrFSozB5D1n/+CiV8Ic4gogiha8QJI
wYCSyCQE1kcuR4jIqsU3WxSuzUR+7nF8OuItDZnWSngn1nsrtgjvhnORka4J6b2BfQWCrk1d
g6XYl4fNqgQxVpVdmXd2I05VWeTQDDUWwvO/E8BwVL5m2Is4VCloBHXPkZ3YQqHOGb+goZka
8M6b+rTbDykfcne7cquHKnPv5aS67z79IYr8cABbcvRykc0H3kylypwJ3iP0bvmhfLYLjZFx
QiMMI2ow74GT1u5iUzC2ZSxh/tb4BhMkZRDTJ7AF8XrEtznEuMHsxKuo8E2H6F+NkdJDyQ65
ZLOZE185NVzQ6YCvnJGaMYlQ29BFnI5DTlHXCyEt6qcnl34I67N47HOR3r4gfNnotsfCvFLp
MYAqk0nc3+FXCwIhc72TWxZcKj0uxLhWyzR1ayGco2LheTBKTMb9nQYtm8xq0eeKCbliDkLH
XmpmSo2ExeWDk5XHjd2dcHzIGwHIyleNPdZNV9IOO9HR6h6AQKAr2DRgCqbAQXbjpTUkDMem
wdl7wTh3X6icVFD2IA9alE8tPAOca0A0lcK7L4BTpFjRWnjf5NttWQgCP9iZQXLxQ43U31hQ
dh32lWM6ZT13mLG4dHvIAugl0V9cd35dpRlpYuWiPyo0vdBKBAb1pYFeKOXmCUsVhKW4uGM2
q788ri5Xik1RVwCCliUbJhLK7DVYvEeLsZph2Fofaw4ozUf63pHOwO/i7ssDiPvWSVL8iNdM
g6qeloQ+QKmjjBioZ657882QHJBLdTVkyWG4kBeuOZwQPTYw31Oo/C5RqEZwVSjbgfOxDOyo
DJy/ghu0zUbU1byaHmEwNTrpdVg8VgRXUQF4kzzOxd0nWPsH1JPPHZ6LW7KxDPf2OCZ5y5om
8YgmykPZncWkTk+WjoAfo7Fz7KagsnT1pHz1+iYy4YKUKPao6DYnlkUo5Ej5bX06VpHGKnzW
WsSFVIYOVNFAWj62JCdrkgZPsNqSwhs1JgDF2k3LmsPwngv9Wa9U93IaZwdTpeL0KnuBXJg3
+DaBOVgPKaYDisQtMi7qkqImBimrHQs3WvIC1Gu3zDewTIpPfN9gBwu4prWH8y0inSXcJKiO
/LVO0gEBFBCnkVgV5A05uCItUB16IdqrYBItpBsV0KEBc6G6VpZ72T5OLop0SztCDbSPuWCh
gFNX17LRmNhc3zVyKRWgrhyVTzXApnsh+dewkhwhdhY0xykusGrEXAdd5gFqUzlgmKudsOOS
iS4YwRhqLpqzG+36WGBSI+wctLCPuWppGLYSXfjdXkmhUJu0ly/BIF+AoKn6wS1XEAJcW8BV
faWE0gOJT+jbAVCnmRkETTAr8rayze4sLPJQaasO63GL1P5sITaj564cw1bxYFnUG/Z/1qts
x3Hjir77K+qRArppkSJFKRswmQmQiRcMbAN+8AQBRVISpzWkhqS60/n63HNuVbG6pTjIAsM9
FNeqe889i3i0BbwraU4GuIFbc62WY4EgrjUQI3tlh3uCwtqVrqHWbqX5Cx51XpOFM0Hqkm73
HWugsziO5aGBdSKbw+bVajsL2qL6EagjD5QWkCSLPFjOMnU2cibIHccQdYdKFxFrPpr90POI
ktuiBR3+lDslQKEyodBt9I1aid3QQ49pm3wB1I/ZzifZ/ElSvKP1CU5z7F1AMWfnwQZvTzrF
uNwnuOj6yTwojp+8V+GztPU8p6YDmCxClWnq+JorpCo3CPg7y6R/J3scgHBidEPgdz7Y4qjG
d8UBy8UzWKF0NPy4mOnpPqy/apWgLQ3ngJalXGC0d42zOrOPEUPq4RyHNkqBlb4cgchYK54G
3jOdTWQw5yLs3HMeS7ny2LypZScyJ9LICQMwUmfAJKmYPdkygPqXnqf0/AYyl8yBITSuNqZl
yyJIQSv7yXfNIymlIfN/6hnHOn3X2s4Boe64Wbo8yJ8Hgg6TI2lp1MIn1jzbaVXaz2VleeTE
UF57bgbNfLVy2YyHzDnn9IoCy/oR3R0m21j0vtHB5MBpTtljZT1Pqw2D2sinhqasn11KVCVi
FvVCvNhEt5WHPPozqQFAu2HQ0mQeqznYnNp/aLS582MllhklU1nJ1Za0zoSNeLkaukd3h8jR
qG88mMvopEl0Bf9r2LHx6ZpeltsbifcyNsM9nPy5qdp9K36uEsfdNSdxYdhjYYMP37RxFiPL
7aBkuedljQeYPNTYyXIjHC8veXZFro4opRvX/jKeFiv4zmXIz9YypkunJPqhQEnOQNUT2y/7
zdU1XBa5Qu4OrDTjlIjc4eYDm42V4qELZZlGQ95Q4S/c28m6t9o7N8za5Dydco8h7QxYxjiq
gTnNu3gZHLbJtSObq/zG56o1a3hsygHED18kCEfHG/INBFOCSoV74CQ3ykAmSBJzCbeeVJY3
3I0b3DUGV2jy7sZWVxxU/DZ7bHMwvQ5IM1BnUcHHRc47gxlMX81gKnAvOf9BRyDMHPyRh/Wo
yh1M0sqHruvafbJ+KWMAoFkVwvlyUeMp0aGrnb2tyqnlDYdQleSahNHOS1l74MldP4ymncxR
bMlRvfDAN8Wsszz8fu+SRRZW2zmp9eZGrcGfW9Vp9d5fLo3q8bkcR0wYTFClYUJKCSEX44ET
DxjMO4oOZR8y1ImPGK6lPE3z5KpQVO1BWtCTQIQ6NEDJB/vPjTnoZUjz+ehDFYvUKkOZk5IN
kkuvMc8y185bYSm4mGVtidixSeaxuBpmL7SWFbsGaIEKHHfgZ3UWsAf0SzisF/m13sjFJ3Xi
8lCNn2ZHDKZ2tiE7IM0cWhmichYxfDVMTmnhQl96gyB/km+vkfbO/BfsqnPa42APv/GJh6jU
WlOT3sA7G/m8Ponadjw3mh2fmI7+XXzWTPZbMvf+EWV8/9IBieEKeMtitbrWx652fqW+AFTP
1akx4pJx8tTCWHrD7SxQkaSW2aUWltitncitnbClR6Fj7D6wvgJSDI2EzfaznA3TQQCDdONI
Xb4RcPpeAh22WbKguVNOq3Edz9VOCHmnxaSQotrJPFLUevi6KgOxYXjr3WA88JZ2/I13SUng
knLv5EJMREb2LDZubsA6lgS1lP94sM5iMW/Jah2vZKefv4pI2vLA/UuHm6rblMOUD+tRsZbv
yNNFvOHTIqy/N2/ffP0x+v7Du48LT5Nfv03/5hxdYDjjYo2/KTpaf/W75bLY/EEt58ptLFvb
1no36veMQKSX3tpLoWl8PclCeOtZ/t2gBTTPSb1QDnYgLWa0yuGFky4ayOdkai9WbsSD/NoW
0xg1/G/3eB+OzbzdN+blfl+K0DZd6363uc8F7chxhQ6owkzN8CghdudVZXpqGhUnzrM96/R8
GenFyUxDyaORZ9uRLJ1ZXQvsROJjiqZWMFYWpNaonCT3wUnoZv5F9dIs/9+ql65eV+97cwMt
+RxrbPGStS+ei2oc0IDgZ7AIUgKRkP93LkxYofhViKTr7P8NkQ83ITLvUgk43qxDiDgCAkzO
VFosvnrgmcnUHhanViGiFEiW/xgl9x/+9MPHxb/ZKkk0BSj+84GXbmavN/ruVjddDmNh2M3i
upthgFLVobkWGGPocVDRXFOEXt7rU6YqtvhfqnwWEc7eTCR+52kWJ0Vm1mvXZOTWSlLdqC86
XDE6Hs0EhW7kb7XTJZycAU5YrfceyTiRF6XhZ6ww3foMVxi9u1FH94F1QqtYxLkAx1HoADf8
5dLy39FwFmQBhZhGQQ89b4LUs42GOwbHy/QqcyQuc+TLrY9OwmOBzDo40i6fphabIPMQmoI7
5aVmoGV+BqNLSCRSLdPZfvE4dNfzW54lHk0Xj/fT6dlCnZVrsKVw0a4oWeINIs2A+KtSbMqg
Hww8gdp+cSTm7AzB0PY0B5Kofvrxuw8SyU584mn0nvXiPa68Ej7eWtrL0M0QW6VXRoq37aUQ
ezjLe8Qe91GaM12JrLHh4ST9kw2Xe6xckmERndR8wB/Xs282XFa58O+Du/KllRO8N7ZiOONK
6uMHOQ0pK/VclIVucE3Tksfr2PwoGtVWjflBQ8h4a9JtM4Tmi/klcDIoxc/HUtPhFotOUEiX
JXObJTm+3i1iaADdQcNjX4HBQQKhsjlLtFJlE8zm223AosAfY9CAuGTkTAnVrJv7fr8P2MEK
U6L25N6+J8D+zq4VK0d46FDvY/nouefgEpDgtMZOTo7BysdSfxPjabRTJttpXsnQ2FRyEy7X
ym0uyqRyLfO2yPJd1Y/Tyyp4is2Xm+sYMvWeg+Yxs8ajtGPZTjFveG9dh/7z7Ydvg6gL2D/h
Vz88uFn+5Yb3tT1hO7J4tbI+L2riQ3yDOJcONVmmASLOspnXNvjSXxcrybLMP0ddAOaDosi9
nSRrHm7VY7WxgSGPi2ITtnM2XqSak+BCmHJovuAn6QdMMVjyshMvR7PsKh95J3cS3eU7K7IY
XCmf2GtBSSlysZwsA2XRIYCfq0GSFFcc0jVPIoJbpfDP8jTJ/dIBU1XpgmrfGUBU+msxikFC
9JHk04zo1dORT8ibjgbj1khVxwuwSDjp8GHwjoTi4Ui1WKyjkEXEA95IuuVjM5SyMpmBlYL0
3D9h4IbYvO9k5H6SUz/i5UKvc3S0Q5eubJ5JqcsuO8puhIPh/EkOEs3k96RJjY4BbM6SIDrK
Zu4fy+GZZyV0HhZOYMMCp5skcQOOb4XiJvsfyv2eRTJ1wyqX8tquHimZPVLGwDrx2pljjIY0
HR7GvUE3VJHlkQvnDW+XPnTUYqZRadLI0e7DpabbwisZ4Gifb3TmLWfY5z1nCD2YvfO3PVf3
Iktx9AuST1ceQF/SmD9yzWk04ndtZMmv4hexxU3jjlvztd1cwzVAPcbGjgd58QsHS7Zy58dm
ZqTOa/5hTjzEbXs6UT2FKZ2NkIEnB42EQjk6hwxdhUUsF0kSrthZ1XSTr+byWu0Ulr1QNmtV
1UwdwiSL2+L6hrSTCwU553ZqTKUSrHp7x0X1fCHJM4+e1Tq0KKS6Pb31fsevTk/+4yr98QzW
pROjbXqDzt9UU/soNCKMV5qRcyyFojZXZWf6qpKqX4Jmbd3bcqeQK6+Qg/dmssCxqfpOndBv
IZbO/HTeY0yW//H3IZiu9RzY/HjhK8F4lXV5nuj2N6pFTUccsuGYWki1eTEvlYDzQVU0n/Me
adCMl9YRFy5URzcYh5cmol5w6XZkOQD1GL/2RQGAX/ujmT10f1f26BfxR9KFIjZ/bkpq/HQU
lyTQOUuhttE0ep9/My9s0u21WXrf1c4onn317TkLTgQh2yAEJoUuelSairbzBP/YCFr4y7V4
oGMUtIwaUGYXTExZpAa9dZ4uy65GfRLGs74EbL1yVi6PHu4MultWR8Mk5lyOhBF2vV2s5pP4
UUnpVhH+p2U6CDpkQZw/YSiZqdqQp7xfGumRriJUEGTSTZFdj88/GS+DpsaNIArf+RVzZFPg
tYRlW0cKNgm72a1N4JiLLMm2FiN5JQExvz79Xs+MxsipygEwtjwadfe8970tmqSTs8VYUduk
U/3JJi3sUumUeJnIVA9sImXvbQ6wjThSM9uPTSla+6Bi0KkO4nYywYxP+pW2eis7KE1QeHtu
42mqTKo3D47UV9n/9Q0JU8rzTZb+JM/yYGgVHgw6KaB7ncPyZXJg6iBjs88UODVVrGG01j7c
cdu604h1hCcKTHawy9gFsPF4OOBYAmh3logbwm6ItMPJFGtqrSMOwKqfPQovy0ys3Yr4yzVF
iLN6I9Os5352/l6WsLd0Ph6ETYsBQsDYYr7gqYZxA4qxBw0iRDb0fF8m6fU6c3BPoYKpryhQ
xAEMfVtrKGCwk2MKCxCGG/blzOgq3JenvYphQsqzspWgRkK05ue/8wbDACNy2AnGhRRYX4mc
myyEUW2PbYConx3CrGyilU1+xTXX8hw3RzV0AStaTlNvnPssfyxF1yRI1XCgJ/mp+l7mCYOI
AqU8ykLPI2YQvXM+NEsjd5YuTLanhe8qIHJDl7/kG9mhJAbsPR/ktP7SCetRq20OvLTLu4bj
HkVr2WtPDZJY6GEK6694YjSixuetbymquVYo8oi85krovg7ogH2BC7jD4xuUuAZxggpPfcdJ
dhoNAChC3JNJc7PeySLNK3aa1dnu0FWqihwuEfr+VWKZKSqP4TViohyUfGx3svZJm5t5m0vS
/7C55cR8CydUclFrbqkPOUbwRSdKbnw4bXtzl3SSaGx7D/eSD6iLHdeRRxTDaDWOCdkW6l0B
kVQbKusKn+JF65KpXipvy75oebrMwexbXigGKAOs8r0r5cyGfOt6kUxPCEe2IgSRZXvjg+Rl
3Wg4FPut+Sa8l/Gy6g8mWyOzZkY/YbfcVonCwrDrpqUbaOicjAUjSk/Ew1uc5tad+Q0lIeOB
4dx10qKcH+thx+Tzmo5qjIG8cOos91a7lsQIAKRCCnWoDCFBKI1RdZums8pCSQ/LZ11zOk8j
P8rQCjaWj1j1ssegRR8uF9q/F48jB7P3HooTD2gWxPY9q7rekjOm3Tpsad7dp+sc/kRe1aL5
LD0BBv5u+/3AWZ3ETnV3lHTHtV7dDK30K/ZFtUOfO90ef691NOqQEcRX4C1vZWsvbMOY4mgr
iZJTwcpiHCefJ7/xsQU1s4r8JFoM81Ss39ga6axdS5YafWvrFxUQsQyY6SFr6ktHk5X2y34+
OITbc7qIj7qNDsTagVo0MG9a9YcWckUEgmxtSwG7uijbv+M4hpmYu1te9tf9/V1YGr1LEs+S
ce+qoxIH8vCPsrIeMnkv29lmCoTx8ZCd+on5aoNcb//a0tkVRWoxbqhp0NiT+WcajfomcvAh
Ud8QRXBOgbe64ODRTl6ZjgZ3gUWArOXzAa1JFXu3EA0IL97EN2lBahHFALe0G0LE/3GCyyGC
8uUsPmUF6cTcl/lzi5FnXd6JPRdxESeeJie1Xrb1nb0R8dP4IPtHDJVdP0NUmBN6FwqAFGDB
g/PoznDEHDtCqMBikDEJQWWN/MDnZrjAWm96UTBWVquixWI56ly2x6Px18Alc3uYIDhzLzjz
847XYax3WaCFDkwWc0p3FE0WCx8hgDYqD3l74ECCquRY2EHO9j6iDRtITuH3Ik2Ve3T9kHv2
2cGxd1ZoWgB+kH5Y5YHFyUOXQV4g2ZSdxXWYW7gavMSuhnUxqbNwUDO33ruiO8mYzZeLY8lQ
zrtiGSWpSSUK/Fu2+GRCn3nYEmJvg+Wu/HKprXG8SFyN//jDZM8iM5BLrNWjkHgkWUdGpGrx
yVhopqmELVtRrBbkLvUl70k4jood1/h9I/9/oYHTl9x/lKNDR/GPYnx1adQ2+u4Cguc8xuIP
au30DLqNNT6hAPfE4iheDlMQ+0CxPMErqx06kstZeDR5Bf7dIsO1pnKyZG7I/QkT5S8ueM1U
hCAkpRydifneVpagkdKsRhkGwj3vAWbmF3F9jUuAFrtgXBNb3NkiHScfrFyA+WRsWiXuTNwD
VFOTW4xnatbk2/t5u5Pft9yUzXPD9dDVnFC/x/+9leAgBLpkGYKMs7Z4nvg5/dwQ6WrnqF/K
A8iN8+ThDn9bKYIyXk/CKw9Y/bWSgvxQ7+E6EyrJTB/p1OJ5Vo9RUE5+dKLVYqbboXye9VbU
T80lOx5VAB1q7fMlR0+D60/NtkiLWicsUWYozlb278MnnsxLh9EkZKU4hJrpzCebcdO32UsF
ldhIy0yW5ziMAubimX3b7Gi7SKdknYIlurslJWTuPBfmsTy4jHPEn/HVdDGu0e2zZ5wfzeD1
9r0LHloPEkpKpVGmLI4og4BJYKw9OuLJM55ge5VSBSUnQCYrWHG8HPO8FHprGljXtsRUtc3z
ZovpqlrTKcigzgtp2yg8xnFKt47iyVXqFbBkSnysm9ddWWxK1BPD+hnChcWqo+xjm3W1nKn8
6VKB/MlMTsy10fpjPKDvHOCu5DuFvIPk9iMc5rb8ycRUSkM15XRdttHv6ddwPHEWycxckex9
KljEUXwCAsU7PwcdNdzo3do37P2HR11VunX9EqoJQM8t4JH5xSWXXGk+2GLio+N42BkGOSeE
aSQva/az9/Nkr9t465C54ldsfOqsqAia1iyzDGnfOKVhczRkXhx3ZTwzWlYrbsxlYsRFI/eJ
oBNFeUlXLvNqXeVY+L7EG6R6FlGeoP5wRbVd6nSWwaCS9mniRm/+6eHs51kkhQEpxulykpir
ucmfzj7+dh+ZTXf28denqbltzv48+1eAAQBnUO8lDQplbmRzdHJlYW0NZW5kb2JqDTIwIDAg
b2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMzI1Pj5zdHJlYW0NCkiJnFLBTsMw
DP0VK/fRVZOmIbWdYGgCiaFpGweO2eJ2EW1cpdYY/BoHPolfwKEtYhK7cKn9nv0SP6ef7x/J
9FiVcEDfWHKQgoovhgrQ7chYVwTicTMfTBRMs+QWtUE/J2L0a2SWhua3dCLSLJmTY3C6wlRt
bIXNA76sqNJuuR5cU2kWGwWNfZNqPJT+KEtmVJKHbaoCBt/Foo1SX2hfWAdMdVcqMee+2xZ7
yUfDcUBbYqZK4LhVXtU1aq/dDqHZe+ueRaUgt0c0tcBwSGhb6gJX2hUovk2qBrFMyNpzm+IB
nQyrgIwJsRMA5XmDHHyPLoPvQN45g0fIyVeau94o8Flyo1m+C9nN/qQeSeX1VPEkM/8w3wNG
rbrdf5bci38h2zBDx4GM+mQVViK4j72qfbcz6n84Onthf1H01/+SfQkwAHGWxS0NCmVuZHN0
cmVhbQ1lbmRvYmoNMjEgMCBvYmoNPDwvQkJveFswLjAgLTEwLjAgMTUuMCAwLjBdL0ZpbHRl
ci9GbGF0ZURlY29kZS9MYXN0TW9kaWZpZWQoRDoyMDA4MTAyNDA4MjI0Mi0wNicwMCcpL0xl
bmd0aCAxMTIvTWF0cml4WzEuMCAwLjAgMC4wIDEuMCAwLjAgMC4wXS9PQyAxMzAgMCBSL1Bp
ZWNlSW5mbzw8L0FEQkVfQ29tcG91bmRUeXBlPDwvRG9jU2V0dGluZ3MgMjAgMCBSL0xhc3RN
b2RpZmllZChEOjIwMDgxMDI0MDgyMjQyLTA2JzAwJykvUHJpdmF0ZS9IZWFkZXI+Pj4+L1Jl
c291cmNlcyA1NSAwIFIvU3VidHlwZS9Gb3JtPj5zdHJlYW0NCkiJMlBIVzBQcAfiTCD2UoiO
NVBIAbKyFAwVyhUMDRR8gZyQZBAB4gKpKhDbB0QUgYhiLqcQLv2QzNzUYr/U8qD83MQ8Haf8
nBSQ3pA0LgOFdCDWNdezMDFSCEnh0jC2NNVUCMnicg3hAggwAA4SHXANCmVuZHN0cmVhbQ1l
bmRvYmoNMjIgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0ZpcnN0IDExL0xlbmd0aCA2
Mi9OIDIvVHlwZS9PYmpTdG0+PnN0cmVhbQ0KaN4yNVEwUDA1VTA2VLCx0Q/JzE0t9kstD8rP
TczTccrPSVEwBMoYKATZ2QGl3fLzShRMTSB8gAADAMP0D10NCmVuZHN0cmVhbQ1lbmRvYmoN
MjMgMCBvYmoNPDwvQ29udGVudHMgMjQgMCBSL0Nyb3BCb3hbMCAwIDYxMiA3OTJdL01lZGlh
Qm94WzAgMCA2MTIgNzkyXS9QYXJlbnQgNzMgMCBSL1Jlc291cmNlczw8L0NvbG9yU3BhY2U8
PC9DUzAgNjQgMCBSPj4vRXh0R1N0YXRlPDwvR1MwIDExNCAwIFIvR1MxIDExNSAwIFI+Pi9G
b250PDwvVFQwIDEyMiAwIFIvVFQxIDEyMCAwIFIvVFQyIDYyIDAgUi9UVDMgMTI0IDAgUj4+
L1Byb2NTZXRbL1BERi9UZXh0XS9YT2JqZWN0PDwvRm0wIDI2IDAgUj4+Pj4vUm90YXRlIDAv
VHlwZS9QYWdlPj4NZW5kb2JqDTI0IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5n
dGggMzIxNzc+PnN0cmVhbQ0KSImcV01z47gRvftX4LJVVMriEuD30eOZzc5mPDvlUaqylcmB
IiGJsUQqJGWtLvnted0AKMmSdUi5TIHEV+N19+uHD7O7n//6PRDL/u7n2SwQUswWd4EfBFKJ
WSmm1IxTMdsLiaYSAf5MK478XKQq89G7ufunN5tEXjGZKm++RksL6YsnPcm8op+k3q7TlXgY
JrHXbmp0lxPlicm/Zr/d8Q5BSptRSyneS/oxdg3ErMLKz0VVt2KSeL8301m90b1YtJ2YfX/6
ZpZgc5PR3EDSEtPcxxGm0pexWWXX08bNRHpLWqtoYJbIYFGAfzWZSs/HZ4mXmBqR+Abjf8Xw
P/BJ7PGg+cOKJkuas+nFQJ82dMqeDt3SAXtjFNCUFk0+G9uk/FilZFSaZmQVMJj9+y3w2fEk
Ic3KfXIGfSCf0FEetlvazgAZAvXYY0taNBrxZSIDrzjobpJ7fIjisKZPLY2rjHWfZndR5oeJ
SIPMjyNAH2Xm0em7xXmfimJfnfaqPPTl7alJnnK00GdypjKdMsj9PHuv1677Tu+H2RugVERA
IQqzVF4PUJFkqU/DKD4fSmAkpdc2IvhALp3ESe5ltp3JyMtj0z4DKMmTqyDY3iy+dc53emHv
O10qVH7w7kQH0PXeM4A4frJwDL1r4KTxCM7sH8jc0LsIXYI5HeNRcnLCOykhMYaj8pFKUYC8
EJsJcOwntNJUJVnoRdSXJ1f6csozzIve9J2jn0W30E/DW+i/00voX+9y6L/Ta9G/3nuJfpjc
RD8JgT5xFeH/DPyl+j/xDwlH+RZHgz9jnF7zTe4lPC+7iX+qbuGfyFv4v9NL+F/vcvi/02vx
v957iX8QuqJClHrdCbEcneB9rtZafKn7QTeOlm+5QcKaNLrIg0TdxDMJbuGJH0emElAkVzpx
+kSdzHRgX58qcdRonCszhWp9QeTvzL3Se5xq4L6ocNcwDnM/ZIAZVQYwN54BDMzcAdfpCFz0
ETB+1QNq2R4wth0eL+Jv+gBevidc5yixKGUroZsS5a2jji3Vbv6sAXgl9lyn8b+iDmEmUFOL
hgRIpTHzh1KqF7wHDV9Sf00jG2oVXDBPBYoyFke5So8Wx8bg39q6ISN9JFYCHZTQdqGnO10g
IBaD7u5FsV5z79AVi0Vdirke9hqB1sAc7qChTfVW0AS+zOKYdpz9BTttMKiAdGqKpe4EGd6T
kNJ0rvIUDAgwdFSiQPlvzM/O9axOjhW7TdKE3af8PM6c7tI4SUMnGeqyGCDgikEMKy1whqY3
e4XAb8DiJ1Apq+VkRG6G6LGLOhfTymuWJ1PWVXjWw4oggKsYugSe2jX0W/9nx68kK3HKil6m
NGNo+Yc7zGfR676vW55Gfn3RB6Bu+/QrL8NbHiiOjubK2LFEOMIMG0hMKTph5Im6F8WOWgPg
5z4ATq813hkZHrbHMcRg+smCiFofICDF0+dHY0rEpiHA9233YkNmdLgNMZD7laSYAXNy95Zk
XkduNL5Fo2I5eyIJi8G2WhK81Ntwq4RyLjGJX2hMUbsBcx4NMG3eqGPeKJyGJDzN2nWlHr19
mheBitVFXhRV1cEphHfBQYgIJ0qsmxKpATme8/sSRtHyCCZ4/eiYzC0tQxubMVa2sYmkEvsV
B8/aJNDAb1p8/PIFWUXthh6lyXyOJivNg9HmyAUorXxyV8D9YkNaETE/P4iybcjLTTHUzZIz
4JIYsFhiby5plDsrH75/5aPTHMLBHBIgCouNf+QZPrO7B6UyNaaZ5U5zx9FjTPQYey9TPJjy
KuOaxDPuh+NwhpCJQPTEDU25Ag+hc228Lb19T1NGruQFmCMnsSFC4+6S3neNoZXM6yyvmguH
mE9is8kxKqQ9RmaigpOqhTUKqU5EsujMGwPz9PAomBDEigmzMuQpCsPPzfogtkX5ooceOU4x
NNDF5iRQLDVHxgO8mcnFMV0RYYnHKdx1uhkE+6XT50zgyDCyVQlhEeXjJbQoS70daErlm7so
7CLz1wjl4SwpnBelDBMXYLTSqRf5Mrps6LkwSUvZzHlN6UjuciwuCOXFRS2jbvaE4QE0yJlb
jgu3DvuysU7kzMewnXOu28BVkoxI1JnBh/y8GC9Ep8GusiwdoR5WyKuyRXhwScq9XrS7gbMb
pa14GxU4+hpddUW5hC32dVO1+3uGstOlrl/Jx915pjJL2/2qui+LruoFgW4KLa2zpdChKOGE
Y84b6kWtj16J3GKBc68Mx1rXi5H5eLmGgPiTcVyxLliO3ZR1glKIKvHBYeiL01AauStRLgJo
s2MEeDMb+VQbtl076BLxTSA0qA4klM41rIpTKzoj0KE1moqISSXEhv4TDmiKNar0gHS5P4lH
a40K8tBYY1Y5IbxRVzFlFITqWE5A0VxMdj1D2xXM27FXtTzYFw8WjdDrllosgF5XlGMN4vrS
LgRFJqfxG8pLRuOOPtZdxyyEIO04LilZ8VMRD41MNTgaE2vLRb2hDI7aOWu4tnyh70xPbIY9
IGQD5ZghRv42b2mV3he/0ErdGPjGD87KSCaXxdkW/R5JediaJpIWvwsqdzhM2/X34vH5USas
AXg46K0Q6m1u0eIJS238cUPJ1FeJiMLEzxLW0VMs4wIkdHZF1+S3UrGfY6qiCwRfNCnW5qw3
+Vmv6+FAtibMMPKMV92Zw8DSWIp4SU7DpjYltgWrlgP4sK64BvNXZN/B9C9Z6bn6vCy6ObXW
mgcjLvAsuNi88IiBmP91/Lo2i5JfulPr3MkTI9zOlIckgAM4+Sfx7dc/xLdPz/dWmYGr5k7d
cUFowCSdXtcFfzZ4MDIs8Yi/8LKhUOLh66GeWnmIx/as7DmGkWmYXgZJ86ZuGzJn0SX+i56c
/n0Eac6tnwTTzmKstYZ8OBlIBF6Tew2TPAe3MJ/LFTHYcTr4XUanjJ6MpJhfoEhZaGVhRwrQ
lgRLrkAURGCWhUYqGtxpMEiAn4mK+6EDYzhWPN4Qkd/mIojrY2Cvj3b7UrBnjSqzliTGlMQX
T5+w3cP3vwO7ZwKFXj8yOuShb/T6/MvvsO0ZI57w/0CdX9F45OHGkGuXVrMV6BlbXbPN1HO2
LVHXbMOmEjQ4kG83hjPhVLKDI7iqnVQiSz8yh1H1pbsI2f94ILeRP3V/YSVhE103lUqItVad
WJtbl4bm4ij9DCHoVIwJuo0jdgRMbphzYAlwubm7zgVhxEEd+Xk+LidAqLzCBgfYUGjtIGli
jkkoc1Yf94J+GzGwTESNmCRmaE+zuZpUPBI0RIqFbngntT9KMsM+oD9bQS35DLXR6MDyngoE
6fS+7gcSeEXZtebmUenXmi4+5vaBulYJxOeUSd9Mnq51swQ75Kd5EToJF19mslWjtPoPb0YL
z7lgcvjLHxPOEziH1Sq1X4v1zprQjQpjx90sdjmT+G5wvAqxPt7uBk2igNe5qJhKRhc5W+3I
kVzaSnqWHFbClMTXomNSoVIOCxasBEsOCcMfVGtdARSsgJzA5BLJnKPvRdtolowV87OTqZeX
ojgKjpJ8za4RW6jECEMEZCAEKUSPvQ5qI39wALDJoQSaVB1w/RoPrv5HfdU0t40j0bt+BS5b
lUyFGOKTwGEP2dRs1W7tTM2WszWHyUWW6FgbW05Ee5z999vdAEhQJBUlkWxOpWKBBNB47G68
fh3NKuNGirDk4CUrQ2r9CF+gS/hTlqQf/orfa3GFMfD2M/wXCL7cj/iw/gqLRYbJynDnUDpi
BTZtAU73Q1llxkqwsIZb3C64itt/Bx+/vUYuqNnlA/42mxouIOTTRyrFTbOh6gyd7fZuXY80
VqXQqT9EB2S3ImrokG3Mm78FcUzKGEdBXYPzu2h19IbEQj2sqNo7fkfNzRUWX5QNzAKh/CWE
CV9QqPg+yxfRRgtsn1fDcd3JpRsh1pcFFB24oTIMMB/eLHHckMiiC4MYLu7x78MavEhFe4/G
enrBWFPtM+nvL/4Rqn3bMW6w11zdb6jKA4W9vfj513dSyoZd3dSfaUWmF3D1NS19xNobMNjQ
hHbXNmavUG5YaT8vswvWxOuKMqFe4itgMeztSOZix0GL8dJRq9awB2ont9hS9us9wmjC/a3C
LSWi3y1T7/d+QyfyoYopnfLDW/Z3XL8jI0C67BLuLQiq0Att1yhwiBhiNxH6SmxOaAcuuky6
Bd9f12t2RUofjLKkYwgrKnP4pNU1Nh0vc80S74AFmTVwJJQA5NIdaHn1ImY+fP2HpJ3u4XWD
ykVFB6HPINTo6j/oePUCq8Wu/gRPD0Ez4WrcTG3lJcJi2ySM1tGPTXZJWxkYKmboWmvozojT
N1uidHa1wWZt+0AvqYAAM0JFvNlsPxA9X0IjWFPYBJTPegmuIOUFuSDUSD2ohBwtVhQxJDvO
/kX0H+0HyYajT6mtStrlw00qIss1pd76Fa5b14nsU/rAe8yuLcmcl/3+QbZk5e0gUO9ehFbh
3UtoFTdB7d/HjgBOWt7c3OH4cbPtdw/UUNR4HPLlIynxHWjpu7RzVzfUUdxtg7H7O7aivctg
KRkc3EspK5eFq+sT1w3SNXoBU7ZmH5e7lKnoqwf0yXLXSm+4EJTsD+twtdgjCR/Q0KBQru9i
5tfb2L7qkUjqPLNTIJFhDH6xoO8k63h3qEOodzWFwVBkWP35PgU9fEidxJaLapRcRaF7jztf
sfUy3dAwlSLcvMK6NOwKVZlnW4xqaqRMIEZIDopXiESMKNU4+IVsv4+BoelV/L1sIwwqjhZs
0F+UIjFBOmIt8ibGmBG3IXOTIPsP8fJN3TSMqPoePu461BH43sdNE8jyI71aba42NSQ3icT9
xg90GVF8UJDNdVdzcgcJZ4YOek8+/whxum5iAtCHYuTWeN+udncUsMThmHCvf23lbQgr3Nag
2ugKZnbqLZq/7MmyZQYt3kitgqylVCcKD6vdiz/ohqMjQgnKmtaUUB9ehk8Pt2OzTYlCR29X
NXZD7DWauUGILGfgUK1wYcjNPK9MdJvV1TCKID9u0RqkJSQAEYWOefDz6zeUZlB12C8/vWU3
y/9BakH1fthhbU5TosRfMtIgljx/TCIqOQhYajKaG5SqGAbQ7evU1v70dvHjm4uSrRom6B9r
VtuFVho+g1ktQRWCAOTWkaaCqrK4ChveXGC+olDM/rKLN79AnKz37JE59jPY+ydbaFNCB8es
UdALATQyVyR76awwe7u4XlwslFe8xPMrrjQTDh+E5D6cr3GrZBZlLQo0mi7SfNobZqM9kLBQ
1KrScGByZXklWYWaONgrBa8sq4QCCmVFmC7SfNobZoO9TwsRBDJTruKl8d6TAckNW90ucOp2
ATGwqKMLAEY6Usk0pr+rRXzSIOlYWF2gRMc99LtaCHIVPai4ULXbVTRKi0r6t1pc/bD495fw
iZJC81/2rEjRkT2oXnOJULU5kyvTy2xtz0hmPR447tMxoGfy6bdCHji38twLwOzkzJ07BnT2
zpW8qhCzm7tzR4DO0rlQ4DlmADJ2S9iwNBC2ddzoIWGH+bR1nLC1BuUHHvDQG47Eij4i0VXR
MVihsu91ZwzRKL6xED090v2011CeDWJVat5pPwp0lmmvFKggvJuOO8sM10xzUJCU9Z9gVqIe
qhSYF5TuoHqSTvntB7aFNSWrvOSlYlbgnfB0JX6DKaUc4qqk4goxErpgO51KU7cRSo834IoJ
5A1Z0SqBBG1EL95CB+eBVgJN6tNQcO+C7/BJoXALi+H0kvxNv+i70sUH2hPWhmE0Eh7QOC2e
IrlpsCMxfz7YKeKOWz0ecaU1Sc/RkIVtWcgyD2jIL8x3q/4E4ZoGO8dwaYXTXbhsL14ex128
bBawuHEiYNATfeF+EZSiA1f0QBfZ1xTZR+Zf3roj81LPfZ1bo6MnAjYJdiRgzwe7Y1TSChrb
wZMzqg9XNxTaPUo17dwUp0pdlqUxtMwccz3p7/fmeTRyPJsOYB5/MZ8A8B6PpjjbPSIVeaDs
kEnzSO2xUyvH5hulMZhzjFKsaGO3MbHn6HVK+yaCBB3A5FWaYKD0zd/FQNHI8cQ5gHk8ZT4B
4Nh7VZo7LGMC4O4FSbsSI1dJ0Fj7QWr30dyg8aoyEQ4EO0sxMgJyhiIEgjAVHXweDw7tGY+M
k9wieVg/48gMQc4yMob0xGhwfIkvJ6IT900EyIH+GL86s5GFIyBnKAcTR4HYg317MgHJTVHw
jN2XCRkpwuRhcoNa7IDmtZ9ppKbBzjFiSFwT4aIXE/GKHDkWrB6VzD1Y02BnGSwqQG249ujP
5cHqs9/01QJeEfDNpRWT0ZpRlZoEO8NqlVNC2eK2RrQdX+dkyYXFo1XIqkrHIf4BrDS2vLQs
rCwqTqmIP5gz6VW3Ltvd2YynTNDWJMaBb58B7dClHqYBoqrO5NKEEcpSAul0h9LpDua0TydB
ntyn3wJ34FS8X19yagDZ2ivyc4rs/KIFdeJEnQY55tQnhxup2jggXQt9KOxRoHtgVLnE1bCL
WVUBgYExnC3a6bgxTA7Y2la8MlCutIElkivUGVYdlfVOd3nUJVGlw/dWuksjGEfHtElEm49M
+mmMX5H0Z0M7zHnZCutJl04lUUIZji86RD2UtoXpA0qfgTwu5Scxfk3KnwvtvkuNLDnEvury
oHOm4ppumMWkl9zJOIQ/FtHRg4+ANVZaySuqymGAIIxOT7QrLA/DaCY8kHlaPuHXUaADjz4v
5EG+gu5xlgo1KEHJTU+qWRk0j6fgK5nG9JdEjyehgyKRVoNUdPR19IuKpn2Zre0ZyazHA8eT
dgzoiEx7TsiRq4WGEFrhOYYH4Arb6WpIEQiMVYbbtlS083FnmByQden/JJEaAzrLSGWYoQlS
CFmBXFW4HsZVTtslFlRq1xRpdGvTWGD0qF/DJ8mlZGF1uH5l/F0tspe0J6wNw2gkPJD1eOC4
i6fhDhz9vMDHHJ0klpUVB03rvam+39Eu4nWE1+n4cBReN0npB+CeytEnAn4wo6XiFos83onT
Orp9ecqM7sM9j6O/GfjA0SVVfWW5EJgcoidPQuW2dJwitg9jG+VTeBIlsRwtL4SK1BgGWO9p
DT3ZIMRovY3tBlmyUTFQU3HAz2NoRzTKs+Ped7Pypk0KazzXWGHsOHHEwKUhZQNlRYg0atJj
eQ7W9ox0xg9l8wGwB7L56WEPney5SZ3B/J08CXbWTtYl6HqsKfKJMjlwIaENJBnRRvY8zMvT
YM/t5K+CPXCyKjkSnLcecKu8x51Cm8FNVaStDGcvf9Nwv+zmJwU+dDQ0MQ6SQjhmtePugKNT
5IpeRIss1GemjANgv6wynhD2wMkaCmfCbSTshbH2PSeTFjw6KVqdOZEUrX7qCatMcR108zTc
ETc/J/Choz3sReQgWYzgDu+k8jPN5mmwM89mz20iOy3ADOr+E/SAJ+pZR9w8AfdUrcmJgA8c
bVCZxwQB5ClZzlcEv482puGevQh+H22oClbG22e95nbQCX4j3vNk9AG4p3L0mTJaeSjasZpY
o0f4WcQmVHIfiEmmMf0FvOFJU+dKqwsTE8OExMheZmt7RjLr8cCJFmUS7sDRzws8OFpZwSsQ
+tZzz4TnpWSOV2xXL64WUMR5ZZmtHBUPmizibNpHc7dkTDlQsfBKVHiiw1ohJcIJxrzgBi45
6AQ0gkWnnU07aTIas/8nvlpyJblx4L5PUWsDWdBfyit459UcwEBjFq+9mfsDExGUlPmylNXP
hme86S4+iUyKn2CwcPB3Yz7RkbO1hrcMa3Z6Mtd1z+bwhUwGmB/YbtD+YdipTwdDuT42HWx2
Mu7j72YgBfeMuIgoBPz38Kjf7ksKRUcg9BUBYqjG4dCyo2GpPMmSzJL5DoXcPSKTwoul0ubb
5oWhbcf9cQntxVwg1eXBRAYysP5CsDGPwz0zxBtPt3k8NO2wWwMm41vV52dpj4wthe757h2W
Q9RQhRf0TqfbOB6adthfCwVkpVtDsaSzNY/PT2M6nMaG4idjONxPxurZVhCWHMbqyVbX+2QL
99N8JgZ+Lmdr7Ic2rdnxYa/rnu3FVpj0GuqzlQdB4BFH5Su6FSnDyaajLVqVmY6ddL8IGujH
yvZCW6Bp2yi0jL5RqxZWa2RX29lQ2p8XM9XxdUszqJac1nbs6DCkRlc6Xi05nmWG49VUnWcX
W+WZ70w1NsyNKZ1dTO0s5bUtYERYvbDOs8+2WiBI3thKbLsbWzq72MrPW1OCnBtTOuumALHR
Io9RmY21TGMoEIxUhjf2AXAYG4o8u9gq/MydLeH8ja0D58efMB3crS3Ed7+zpbOLLQ0AXScj
vNiygJmxcTw1TxEDw2HhVudYq4lIFXipQ1fi1Kku0DMdbuN0KobpGecV5l3BPIcPydrIlaOl
K66jiJpsyTE77Yr98MD8TJyN/E9PiKw/cwztz5myG9bodBvHU/MMNTtJnFeB7QiaH7GX+7xq
LaQE+O7UPDAbJ8ZCDp7BUjAbsfQ8/YIausevg7XETMhydO/junz4cqxNsBS5NiEoN5Yw6FDX
bmGmAslt4yq1LpeChUNoQbPEPmuc9YEhS889zHGfSiS+sdmUNxz1gT+U7KhnDRWemhqQk5CE
4DRYE8DbWdqsOnM7Tdaha6fXmCdQ8EHHOTEy419vIwWazCZHJb4EK6cT36SjFZZCfWOJkMgJ
sM6fo1sxwitcUfpuK4FwvEgf62lP0BSxQD391CO8LZ7yd1MJAAPHh+LefSWAfixLM0Z03nza
Xwk0qdLhS5m/74o7iagvfUHhh95wFT6vVoRzmPMiyNnV2V4FDO/dPhdYmY7lXrUV+PFT/2LL
MIn9iu90iYxJt7ORUK+NkP9jo8haVSR9fEP57qVLSKMrQ7kLsvv7ty7J+seQ6Izpu4dZXa2A
nx4b0TkEhBq/9tjypdeGv/zU8MV3ljcPjTEYQwTAoOT1RdwOgu5//fL4A3fco+4B7YnFAcf4
rTMdzTh5fK0jSY1oHUFMWsYpEafwzioM1Fjqv/Uv4mQSmG/iQ7qI3m78K7W3zLRoGa32dt8U
HxMRLg31LmKOcXybgS6YcUTZRH3iY0jyyUzgcc1iN2L220uBBEJOzmIqo9NvCiRYgRgBcGn8
TiQNKpBiKa9WIJLEREx5s83NjR+qEq0HEvEAoWsXDdm6gSHQtkrFt/7djyHJI7OgUsll3RMA
tMhnFgIa9of+G0/uD/VWZcZxILk2foenGsGEyK3JLlvRutkqpz+e7p5tnGz3zzl5+/2Xrzr7
kp9/0u2XIAPIUh9lROqdIFTqMsgnZ1P3WM7+zNdQ7n2NL86q7tYxvvf1TYz/716/YnsBNtoo
rWiB/Cm41mZfLIXp000pHH6eCuFL5bvycRHUf8jbtyEN4CEHDf9p/v+G9P+Zmr339E/U7P/Y
52t4Y8OuSAaSAGZ8wGLKfqaUZAAkrwuq7OZ2U7DPvnu/FkLOWg1gML40futfhMAkEM/MKTrE
+qylr5MbPhfNiLMu9ckrZCZ/QEYS5kUP5TRtTEkfoK7J+s7HFOVZt4M32geOOEZAU+BOlTnt
tOsi8bbrfsepbY5JnKTS3Dgcina6WmIDFw0whwqyEPtK1GvePR7/+f2PHkoPF2E+GbHpRBdi
YYKQLgakE/d/f/NcGDfMr2KajE4stqx4QgE1KXz/O5lcxCciayF61NixLqyeQ7rEzzSjTqzh
Ruqkt0S9pegp8APLDXa8wviBYrCHJmfpRHc3MvL9sj2VSSzL3mbPLqOLxMJQKaoJulN6uOAI
M9o3PYS2iEWWzIgdilXhRKhJJakbuj+/XXonzHlX8LQLAbpmvLZHyhYWpBSZhySSOvI9nPL0
BofKd2Q0UNi+v6Y+UNglvQYIztRBQH/iDEgvnp2aVRikpk9UcyY1OpPMGVyCW7jimDE0ZZOk
hEHCvpIKSvDFmz3OpbLUNBtj5c0Wm1HgyI98SOYehG131FDiHpuCPGLt16braBeq73I52YJE
kSWXvOHJZ78SMj58KQ0t0FF06Vdu/MKmLAvOdu1yGe3a3cI4MB/hFnaMZNtFYKi24gzwovlB
bUGlW2Uvsb09/Mpefu30Ma/Le6tWtTkboFOmmI5wnf0CzKHncmGMqWyaplhtO4pWXReXEMHU
3SjNnVe5V5fosoWqKIWt712hp1QwMFBga96WtMhQUDvZCIiEV9N+EyqXJpMvrc2iX5eW7wtl
VmkElMhWiKDyyTNOpTsVbT43tgE1DfyrgRFVncbdyqE4JzAD9Q6atmhV4S0BkGIf+B+8MZ0J
ViyRzfdjft0PZ3g1LoobWWARQbUghvldcaPJjIO40ntuMOePThiElRaaqihqXEE1OS2XgVhg
ql74tS+KyLUDBxCbvcPlcoqw650lJzALHREtYjM2DB3zCBjjvOjBkzPGaVcF45ifGK3nOZj9
DRYBBpFGQIzQhiKYBsS9Y+O5s4CN6HiQAusswCLCglhVxTCpSyG2hUsYzHOawaULP/7k0k6q
kKKlvumZBn0npuAtUWADrQg496nYZ0xl7qbixRtM3tHdhXvbmyRtmJHIEHKu1qQYJLY2JpmV
JuLDRyogqmEiL3LBoFCPpAZQPUfr2R3Qmc486M7bfsKkQ5XilrkDkZyuWFUrVcfgAN8AOoEs
ZWliytA5VcyGECB0UCyrbAGflCCCc5qZWw8N1k8wQIVQ8VvkVFV8NHiZHUZMZnJGJyZNY8PN
ix/5oGQFA/atH7vgq9lQ31AZkkI7DdRRx401vu3iGxvYBy5RGoosqbJsbk6g0Vh7/smQ15Ng
NwozkvlTBhK3MxJHoaJjyVMza3/Ye0uaKvK2GKJuNjfxr7Cky5qBw8BugKGBI3jtpOc6GKqm
bWCQZlw9W/1DVnh1f/UFu9Qo3JJvegnjESUYSWc+JBE/knXI54mZNV8j10TqRUbEgIeKnqUT
85LwlIO6F+i97W10J56DVtgN/JQBEPocXhwiOeDalA36Aqvbms8oWJaYVwwsoZbYTAgMlpDU
f68cMnjr8XH8ta9QT5nUeikVTulsICPQizZSrm7kIy57muRr5QaYG1fRYsAOCfGAZEObTz6G
UxbEaGgX1QjuCf+p1R5+Sd0TtNIpJO3N5khmICKSejtALiYbfDAAE4GRAhGrxBAa+/An/hdt
HSL/WxROmsVSKkrzTYAGWWJrlqNHZ2Vf8IZlzLyOwYkfIUg2eIK2MhosjdfpAG8JNAHBijfk
psgUutPGpO13EAcZFfZOKE5MLBrbCW6Krk3iV7KR/qUvyHEegIMoDjC8Y374wOab1S3lRCSp
1l4XitzT7MUpjMjSSWjXod0oFwOiz37lAFwj+cOXqnNv6QWLYxczMBDKJFUUQ1mkzpBnsxWU
ygIHynmoiyl6TsGVWwOTq9t/4laxDcIPdCy2E3gbIGMnbN2vLEpq+8cPLWO7RONiWVDEhcKt
3RpUuTr/ftEBzpoDHO2GR58TJ+aoreNHHx2pr48qM5X2iwdgqLUPz4qCSG+2P3B8tnTSRgOB
NZQ73bgy5cDYGcWHYlKX2QaDKU/UKEYOr974idCVTfimquksvAkdjVCOTH9Is/GzHIrdoSZ3
g/a8HxSJRqFYVoDIvB1UgSunBt+p3OrezbGgPLNnhNGU+drYN5qBkT1j1lO8bXwjsMQEUtL1
irfB7Mqr0PfPigCPVWfNnJu2XsSoyAv0drIWdgMlz9sFQtsMH1J/U+5i6W/CLotv1gUxq/tR
0Uh1fNdoNgN2I3h9ZO5j0FZ65CxQNnb3zlnJnEgWq5yRq7u148WX5ub3q3+/6jBC5Fa0wqwM
2jUwe5srKU6NA0SmjLFpc3vFWbyb+gV4Nfau/1Jf5TqW41Y0r69Q3IAIcbskY2cGZgBjgg4M
R+1uGAZ6gOnEv++7kBL1KKpUb1UlVeTjosN77nJu8LuGodo5iNWxvYxUFJCxFEsfOM5UiUJC
R3Hk1egphmdWzqFTCdqWJTcDOCKfEyvmKOmfaydOS+CvBTSXXxTQuXZwV4ObOSeXsyC2vMSE
KSE7MSSYK+12iuY45o6BQeGckgEJ90pGZ8Y4N9NukzUjNQ+Xp3MVblBNC1UQ066wd9x0BimL
OEEDgfgl41myo0PWBhJedCiStwQJRLnBb5YKTNRzvGMFKwqyp6ZBaChqOs4x0jCWJDdowUOC
2uWzsByOPUxhLvYoVWkcOiKEshlzIChwmvirMW5IEIkqbdFOdDSzbbOKMoaVQma7LalFxQZq
IfcwAVctK/kYZ1wEct9KSnZpghgAl9OfufUqYU4NKmWOrcpBRs3VIkwdrgLZGa+WTMzaD692
K2E2F3iCiyWXznFM4TnJ6NJTmi2WXMKUjCGVdou7oSIDIhBJZ3ghhpuaIuop8YLkPUuggnyc
zbKpLlyKs4NAirsdFxWUxPaXxII1mUVrljAXIY2bmTnOe6M0SOX5+aZpk48pi+aAvrvrG5z+
tbRQBGqQqnxRKq0IeskrbBSbO9GJwkoU2xqFRSEZKdMBlkhDAgpRWDGKorsN+93KNORwU37v
qIuPxPz321uekcKSzeyVk/z79sbP4LHNqs3lUT4vE76Y94o5vr39+HIYuhjwj7/9Tq9Av/jf
oKfhNzz03+Hlz/jP2x/rd2AhSnNgImNVVj8pBdayxgio6g0qMc5/hnPHr+9vX78Mf+KeaQgJ
Y8AOQOUGx7zGS0defn4G/3HhjWYuOYAKW8q03meR7xyrz4yr748LrnEGC/kBwC/Ij6LgLk9d
maCyTTZXJ5b66A8x8bqXNOEEWAnIk7xGkWTmHHssnAR+hd7U6G3PkcpPBbutwJsa/D4LO9A/
Fg/PfUZDQbIqZBUPIa7ai7NTsAP9M1HgUFEUgQOYh4sK/UhRqbKpqbPpEexmwW5q7OZ9Cvag
X1MVnvWMlgJQBH2yFM32g9LqSB494D7XlYM96NdEwbOe0VCAWtxTWXNY1iKsNPY10urO/vMO
CTvgb1VHj31IS4Ob2z1IAev/R+rBS5uMPei3kvDMJsMZwH5QohhsONZkXIi6/VpWgN69JO9B
P0TBi57RUACgXO52IKDSo941uftEwVUx3DjQDgk74O8aB3d/SEuDnlMp+KA8vcS+UxNO06jt
ob8mGF7YqDmnF6kd3c1E3DmY3+FhB/ytPDz2IQ0N1qpUKlyMasqS46HF+TKYr0xKO9CfUpyv
fEZDgY8KclXD/xhb0v08i4Jb8tEO9GdTcFMyoppWRAa+o2i+zxAFO9A/VRSEpCylUbBD0JjQ
qAN170jUm3ucS3292+Ps9Ak74G8l4bEPuaTBT1pZanKsHoKFJ9Fwbat5QcMe+OfQcO1DWhqs
Yo1t0xAMWpz7Tv05uoU98HdNSQ/vFrwxSlPH6dGhtFOTx3GAgzQcaTgP1LSDDeclCTvQP0bC
c5/RUoD5KsdxmPyx0nxNm3N/dbQH/RAFL3pGm4zcLDGCtkrfMxnV7tPvNG8QSHvoHyaQ7vOS
hgitlebM6tCh4vysx1aFPWnRoO9rpD3wz6kK1z6kkaoos+0c1/gph2PjPkk87KH/ZPFgISif
6xpEdClKsIZdSi9PQU2YYv2Uafj78E/5lf/+axr+Pb/PKx8JrJ6Uxhc4fmCeaKIWX1imXgV+
KZ4YUeegP01l8O3NK3Bltjqwvqz+Dh9ZP9ZZpzS+zhll0RqgAC/AQBp+fX/78eb8pKIbwKPF
CCYvj2W9nJXVn3yjTVZNdF9gXJEm2mBQyH101AwYmsoQRF4ey3o5K6v5PvBqclzeiE9QwQwB
fSffh/6F3FDaNUQvL49lvZyVVbmvIjeGWbQEhOCLh7ITAjshAmMvs6aM+S9SJLPMHu1GmiIT
y//JCyHmic0b7Xzc5kt5UyeONvFthMsLkDZxkpwyBNX5B5my/FjtXV1S3Z4/uG3TLaAPsum1
kBvjhqQSCe1oTm7cLaCnN65RgbI63nVy424APaVxnUVxYyRjzwkbt0rChqi8axO2rJej2wnb
Oax1pO9s2uKKH1HS1bhksNFW740PpGgT3xZFz0faKEwsz56wWntut98Eekq3t5bFZUBNE0lp
ucEp58Tr/8JVQ3ooWLxes7uj6ik65euX4U/cMw0hGTXZATTFROKQ+IpL1kbCFYxVNgvfcnf5
Ki/9zFBWeQNDTGfZSrs0JWivV3xr0ZWklcYJgzYPURpHsR3NLAk32Yxfn9je/J9sN8U84TOy
V4b5EpnQ5by5l+T6YDc4fx3swngkPb3JuHWOpecmZXKsoqyygEP/In8H+wno6oM9I13O0vJC
F6z4SjRe+IKKsHywQxjMbWGPsEkavhncuAI9Vq8Zq0fWL5/NUVlpZb7FrNnQHcK6YDcIex3s
JaOyVnDUDt49oyYJXSm0FynVz2u9nGrcNE3e8zZ/JDz5761+ni85nk0bmMcD8wmAL/Jo4Rku
EqmuiYI2k9ZMXWSnWY6dl6UtmGdkKVe0rWgs2XMznMq5DknYAXRDqZOByptvykD5kuOJs4F5
PGU+AXDuvYJTkcqYRrgXJLk4EXPBoMa6JGk+x2tN4xUqEY4J9pRiZAPkCUUIktBjh+bb5PCZ
bWaiUUDJA9KJmWlBnpIZz3pik5w00Y8ddvK5DkER9cd26JxGFm6APKEcLDkKxR6eu5AJlNws
k+fhUiZUSREX95Mb1uKIad6lkzLVB3tGxihxdejiHzp85Ry5RdYqlZydrD7YU5LFBWim6yL9
xZqsdfbrhxbmFY1vnkB32TpRleqCPWG1qlPCNOMGr+eObzGyURro01a8Krg8pD+IlcegJhhk
5xgUuyL9I58pPy37qtPLnfkrnbTVxdjY9gVoW5MmXEaINjzIpAUjlqUCMroFZXQLzL5NuyDv
btNr4DZGpfh6z6gCcr5vrL8zVt8fZ1B3dtQ+yC2jPh1uTtU+YtIF7EPxjEXdg6MQS67GUwPY
gAkML6PVcV7OB2WxydYQVPBYrpzHLUZZ0hlgD3l9dIsfLU4UnLw3uMWNcJwNMzsRHz7o9H2M
H3D6h6Ftfd7Mwrpr0p4TFZTy+XFBtEIJM8wkKFMF8pjLdzF+xOUfhfbSpN5MCrkPix8sxrTK
cYQBOb1R0eQh/gFCx5OUATuqtEYFrsoyIBDelRmfku0yzNfIhK/n7R27bgJtLPpayI2/ou6J
wIUalaBRfiXVwIjmSUy+NWXMf1n0JBY6JBJ5N0rFyK/j/6Ro5h+rvatLqtvzB7eddgvohkx7
JeScq7VDCkEnRfQgXA2LrkYXQWLAegVzqZjX80lZbJL1lD4JU1tAT8lUhRmbIEuQLcpVS/tx
HOq0PVFB5XbNskYHKGNN7HG/RjOjjBlkt4TflP9/e6t+5DOyV4b5Epnw7fmD2ybuw20M/Vrg
W4YuEgtMUKhpU/LhdkPHjDcy3ujy5BDe2E3pO3DvZeg7Ad/1aGMVUJGnmLivoecf7+nRa7iP
MfTVwBtDT1z1LSityTn0Sp5I5Qb+nOVsL2PI8klmeuIsx9tHbXNqlAHVe97DMxAhxvshtxt8
E2TFwE3Fjp230G5olJfjvjSzTX52CvBJOaowsJ04MnFlyN7AXiFMkyY9mudw7+qS5fI9b94B
u+PNz4fdGjkpXzqD8xu5C/bURnYT6nqqKeZJniy5kNFKksxoc/bcz8t9sI828odgN0a2k6IE
lyAhblv3uD20FdxSRebK8PDy14f7vpmfCrw1NDYxEZ1CxwFcVHHH0IW5ccXoWFH94JSxA/Z9
lfFE2I2RHRbOgtsbPItjl1ZGZi142Clmndlxilk/rYRVpbh2zdyHu2HmVwJvDZ3wLCFHyeK1
ihSTNp3Um/tgT+7NSUFJdk7jNaT779AD3qln3TBzB+69WpM7AW8M7UmZZwdB5MVZHlcEb0sb
fbgPL4K3pQ0bcGeOPkhOQdMJXon3MR69A/dehn6QR9uERTtXE/BuIz/r3IQalSQxmTLmv4hX
Zo47V949+uwYXhyj+rHau7qkuj1/sNOidOE2hn4tcDG0Ba0CCn1IKg06qckMUYXh1/e3H29Y
xFWAAULk4sGLY14t53jtJ19mI6pY/EkH+mKkWmEMwZHLklYegxx1Al1CRWdeLSd5MV8GQIU/
X6YdAalvi/iWcpusVtfls/V1+AVPCtAP2N1g+JtyT/g/8dWSK8mNA/d9ilobyIL+Ul7BO6/m
AAYas3jtzdwfmIigpMyXpax+NjzjTXfxSWRS/ASDTwdDuT42HWx2Mu7j72YgBfeMuIgoBPz3
8Kjf7ksKRUcg9BUBYqjG4dCyo2GpPMmSzJL5DoXcPSKTwoul0ubb5oWhbcf9cQntxVwg1eXB
RAYysP5CsDGPwz0zxBtPt3k8NO2wWwMm41vV52dpj4wthe757h2WQ9RQhRf0TqfbOB6adthf
CwVkpVtDsaSzNY/PT2M6nMaG4idjONxPxurZVhCWHMbqyVbX+2QL99N8JgZ+Lmdr7Ic2rdnx
Ya/rnu3FVpj0GuqzlQdB4BFH5Su6FSnDyaajLVqVmY6ddL8IGujHyvZCW6Bp2yi0jL5RqxZW
a2RX29lQ2p8XM9XxdUszqJac1nbs6DCkRlc6Xi05nmWG49VUnWcXW+WZ70w1NsyNKZ1dTO0s
5bUtYERYvbDOs8+2WiBI3thKbLsbWzq72MrPW1OCnBtTOuumALHRIo9RmY21TGMoEIxUhjf2
AXAYG4o8u9gq/MydLeH8ja0D58efMB3crS3Ed7+zpbOLLQ0AXScjvNiygJmxcTw1TxEDw2Hh
VudYq4lIFXipQ1fi1Kku0DMdbuN0KobpGecV5l3BPIcPydrIlaOlK66jiJpsyTE77Yr98MD8
TJyN/E9PiKw/cwztz5myG9bodBvHU/MMNTtJnFeB7QiaH7GX+7xqLaQE+O7UPDAbJ8ZCDp7B
UjAbsfQ8/YIausevg7XETMhydO/junz4cqxNsBS5NiEoN5Yw6FDXbmGmAslt4yq1LpeChUNo
QbPEPmuc9YEhS889zHGfSiS+sdmUNxz1gT+U7KhnDRWemhqQk5CE4DRYE8DbWdqsOnM7Tdah
a6fXmCdQ8EHHOTEy419vIwWazCZHJb4EK6cT36SjFZZCfWOJkMgJsM6fo1sxwitcUfpuK4Fw
vEgf62lP0BSxQD391CO8LZ7yd1MJAAPHh+LefSWAfixLM0Z03nzaXwk0qdLhS5m/74o7iagv
fUHhh95wFT6vVoRzmPMiyNnV2V4FDO/dPhdYmY7lXrUV+PFT/2LLMIn9iu90iYxJt7ORUK+N
kP9jo8haVSR9fEP57qVLSKMrQ7kLsvv7ty7J+seQ6Izpu4dZXa2Anx4b0TkEhBq/9tjypdeG
v/zU8MV3ljcPjTEYQwTAoOT1RdwOgu5//fL4A3fco+4B7YnFAcf4rTMdzTh5fK0jSY1oHUFM
WsYpEafwzioM1Fjqv/Uv4mQSmG/iQ7qI3m78K7W3zLRoGa32dt8UHxMRLg31LmKOcXybgS6Y
cUTZRH3iY0jyyUzgcc1iN2L220uBBEJOzmIqo9NvCiRYgRgBcGn8TiQNKpBiKa9WIJLEREx5
s83NjR+qEq0HEvEAoWsXDdm6gSHQtkrFt/7djyHJI7OgUsll3RMAtMhnFgIa9of+G0/uD/VW
ZcZxILk2foenGsGEyK3JLlvRutkqpz+e7p5tnGz3zzl5+/2Xrzr7kp9/0u2XIAPIUh9lROqd
IFTqMsgnZ1P3WM7+zNdQ7n2NL86q7tYxvvf1TYz/716/YnsBNtoorWiB/Cm41mZfLIXp000p
HH6eCuFL5bvycRHUf8jbtyEN4CEHDf9p/v+G9P+Zmr339E/U7P/Y52t4Y8OuSAaSAGZ8wGLK
fqaUZAAkrwuq7OZ2U7DPvnu/FkLOWg1gML40futfhMAkEM/MKTrE+qylr5MbPhfNiLMu9ckr
ZCZ/QEYS5kUP5TRtTEkfoK7J+s7HFOVZt4M32geOOEZAU+BOlTnttOsi8bbrfsepbY5JnKTS
3Dgcina6WmIDFw0whwqyEPtK1GvePR7/+f2PHkoPF2E+GbHpRBdiYYKQLgakE/d/f/NcGDfM
r2KajE4stqx4QgE1KXz/O5lcxCciayF61NixLqyeQ7rEzzSjTqzhRuqkt0S9pegp8APLDXa8
wviBYrCHJmfpRHc3MvL9sj2VSSzL3mbPLqOLxMJQKaoJulN6uOAIM9o3PYS2iEWWzIgdilXh
RKhJJakbuj+/XXonzHlX8LQLAbpmvLZHyhYWpBSZhySSOvI9nPL0BofKd2Q0UNi+v6Y+UNgl
vQYIztRBQH/iDEgvnp2aVRikpk9UcyY1OpPMGVyCW7jimDE0ZZOkhEHCvpIKSvDFmz3OpbLU
NBtj5c0Wm1HgyI98SOYehG131FDiHpuCPGLt16braBeq73I52YJEkSWXvOHJZ78SMj58KQ0t
0FF06Vdu/MKmLAvOdu1yGe3a3cI4MB/hFnaMZNtFYKi24gzwovlBbUGlW2Uvsb09/Mpefu30
Ma/Le6tWtTkboFOmmI5wnf0CzKHncmGMqWyaplhtO4pWXReXEMHU3SjNnVe5V5fosoWqKIWt
712hp1QwMFBga96WtMhQUDvZCIiEV9N+EyqXJpMvrc2iX5eW7wtlVmkElMhWiKDyyTNOpTsV
bT43tgE1DfyrgRFVncbdyqE4JzAD9Q6atmhV4S0BkGIf+B+8MZ0JViyRzfdjft0PZ3g1Loob
WWARQbUghvldcaPJjIO40ntuMOePThiElRaaqihqXEE1OS2XgVhgql74tS+KyLUDBxCbvcPl
coqw650lJzALHREtYjM2DB3zCBjjvOjBkzPGaVcF45ifGK3nOZj9DRYBBpFGQIzQhiKYBsS9
Y+O5s4CN6HiQAusswCLCglhVxTCpSyG2hUsYzHOawaULP/7k0k6qkKKlvumZBn0npuAtUWAD
rQg496nYZ0xl7qbixRtM3tHdhXvbmyRtmJHIEHKu1qQYJLY2JpmVJuLDRyogqmEiL3LBoFCP
pAZQPUfr2R3Qmc486M7bfsKkQ5XilrkDkZyuWFUrVcfgAN8AOoEsZWliytA5VcyGECB0UCyr
bAGflCCCc5qZWw8N1k8wQIVQ8VvkVFV8NHiZHUZMZnJGJyZNY8PNix/5oGQFA/atH7vgq9lQ
31AZkkI7DdRRx401vu3iGxvYBy5RGoosqbJsbk6g0Vh7/smQ15NgNwozkvlTBhK3MxJHoaJj
yVMza3/Ye0uaKvK2GKJuNjfxr7Cky5qBw8BugKGBI3jtpOc6GKqmbWCQZlw9W/1DVnh1f/UF
u9Qo3JJvegnjESUYSWc+JBE/knXI54mZNV8j10TqRUbEgIeKnqUT85LwlIO6F+i97W10J56D
VtgN/JQBEPocXhwiOeDalA36Aqvbms8oWJaYVwwsoZbYTAgMlpDUf68cMnjr8XH8ta9QT5nU
eikVTulsICPQizZSrm7kIy57muRr5QaYG1fRYsAOCfGAZEObTz6GUxbEaGgX1QjuCf+p1R5+
Sd0TtNIpJO3N5khmICKSejtALiYbfDAAE4GRAhGrxBAa+/An/hdtHSL/WxROmsVSKkrzTYAG
WWJrlqNHZ2Vf8IZlzLyOwYkfIUg2eIK2MhosjdfpAG8JNAHBijfkpsgUutPGpO13EAcZFfZO
KE5MLBrbCW6Krk3iV7KR/qUvyHEegIMoDjC8Y374wOab1S3lRCSp1l4XitzT7MUpjMjSSWjX
od0oFwOiz37lAFwj+cOXqnNv6QWLYxczMBDKJFUUQ1mkzpBnsxWUygIHynmoiyl6TsGVWwOT
q9t/4laxDcIPdCy2E3gbIGMnbN2vLEpq+8cPLWO7RONiWVDEhcKt3RpUuTr/ftEBzpoDHO2G
R58TJ+aoreNHHx2pr48qM5X2iwdgqLUPz4qCSG+2P3B8tnTSRgOBNZQ73bgy5cDYGcWHYlKX
2QaDKU/UKEYOr974idCVTfimquksvAkdjVCOTH9Is/GzHIrdoSZ3g/a8HxSJRqFYVoDIvB1U
gSunBt+p3OrezbGgPLNnhNGU+drYN5qBkT1j1lO8bXwjsMQEUtL1irfB7Mqr0PfPigCPVWfN
nJu2XsSoyAv0drIWdgMlz9sFQtsMH1J/U+5i6W/CLotv1gUxq/tR0Uh1fNdoNgN2I3h9ZO5j
0FZ65CxQNnb3zlnJnEgWq5yRq7u148WX5ub3q3+/6jBC5Fa0wqwM2jUwe5srKU6NA0SmjLFp
c3vFWbyb+gV4Nfaumt8GhrPzYVHHetk4FJCxvY09cJupMoaEQkmsalRKkBRN77/UV8mO7bYR
3fdXaG1AhDgVyXXWCRB44Q94sBEEeAbiTX7fNZASJZFq9R3Vm27pkiwd1qnhFAaVoN2z5GYA
Z+RzYsUcpfxz78TXkvhrAc3tFwV07h081eBmrsnlLIgvt5iwJOQghgRzp22XaM5jnhgYFL5T
MSDhXsnozBjXZtptsmak4WF7OnfhHappoQpiOhT2jofOIG0RX9BBIHHJeJbq6JC1gYQXHYoU
LUESUSz4ZqvAQj3nO3awoiB7ahqEhqKm45wjO8aS1AYteEhQu3wWlsOxhynMzR6lKj2Hjgih
asYcCAp8TfzVGBsSRLJKW/QTHc1s26yijGGlkNnet9SiYgONkEeYgLuWlXqMb9wE8txKSnYZ
ghgAt9OfefQqaU4DKlWOVucgp+ZuEaYOV4H8jKalErP2Q9NuJczmBk9wseXSOc4pPCcVXWZK
02LJJSzJmFLpsLkbajIgApF0hhdieKgpop4KL0jdswQqyMfZLU114VKcAwRSPJy4qKEk9r8U
FuzJLFqzhNmkNG5m5rjujTIgletnS1OTjymL5oCxexgbXP61jFAEapCuvGmVVgS91BV2is2T
6ERpJYptjcKikIxU6QBbpCEBhSisOEWRbcNxt3INBdyU7zvqEiMx//3xkd9IYclmjspJ/v34
4Gvws82qzeWnfF5e2DDvFXf8+Pjjl9PQxYG//uNfdAuMi/8Pehr+iYf+O7z9Gv/5+HV9D2xE
aU5MZKyq6helwFrWGAFVvUElxvXPcO346/eP334Z/sQ90xAS5oAdgNoNPvMaL525+fUZ/Pcm
Gs3ccgAVtrRpfcwi2xyrz4yr748LrnEGC/kCwDfIl6LkLldduaDyTXZXJ5f66E8x8b6b7NIJ
sBNQJHmNIsnMNfZcOgn8Cr2p0dteIJWfCnZbgTc1+GMWDqB/LR9ee40dBcmqkFU8hLgaL65O
wQH070SBQ0VRBA5gHS4q9CtNpaqmpq6mZ7CbBbupsZvPKTiCfktXeNU19hSAIuiTpWy2X5RW
Z+roifC5rR0cQb8lC151jR0FqMU9tTWHbS3CSmPfIq0eHD+fkHAA/l519NyL7Glw87gHKWD/
/0o/eOuQcQT9XhJeOWQ4AzgPShaDDeeGjI2oO+5lBejDW/IR9FMUvOkaOwoAlMvTDgRUejS7
JveYLLgph3cBdEDCAfiH5sHDL7KnQc+lFHxQnm5iP+kJlxnUjtDfkgxvHNSc04vUju5uIh6c
zJ/wcAD+Xh6ee5EdDdaqVDpcjGrKkuOpzXmbzDcWpQPoL2nON15jR4GPCnJXw/+YWzL9vIqC
e+rRAfRXU3BXMaKeVkQG3qNovu+QBQfQv1UWhKQslVGwQ9BY0GgCdZ9I1LtnnK2+PpxxDuaE
A/D3kvDci2xp8JNWloYcq4dg4UU03Dpqbmg4Av8aGm69yJ4Gq1hj2zQEgx7nuVN/j2nhCPxD
S9LTpwVvjNI0cXoMKO3U5PE5wEkazgycJ3rayYFzS8IB9K+R8Npr7CnAepXzOEz+XGu+Zcx5
vDo6gn6KgjddY1+M3CwxgrZKP7IY1eHTnzTvEEhH6J8mkB5zkx0RWivNldVhQMX5Ws/tCkfS
Yoe+r5GOwL+mK9x6kZ1URZlt57zGTzl8Nu6b5MMR+m+RD846pWEAZ5TFDaAgDhRbw1+/f/zx
4fykohvAoxGEJstjWS9nZfUnW7TJqonsBYoIHelFG4wTsUdHzYDRqgzdiJfHsl7Oymq2B15N
jis+XRFUMENAd2Z76HJsw1SJDN2Yl8eyXs7KqthbqLMxzH08IARfSGNegHlBYOx4a8oz/0Ve
5M0xY7wbHR8jneH/RAzE/GLzRjsft9kob+qEVhNfI4LegHSbwzY5ZQiq809yZfmx2rsyUlnP
H2z7tAX0ST69FfLOuSGpRNozmos7twX08s41KpCSRFsXd24D6CWd6yz2eyMVey7YuFUKNkTl
3b5gy3o52i7Yzk2KJY9NLa74EqVcjUsFG2113/hEipr4WhS9HulOdGF79oTV2muHfRPoJcPe
WtZbATUNql1SYU45J1H/P1w1pIeCRfOawx1VT9Epv/0y/Il7piEkoyY7gKacSJwSv+GStZFw
BWOVzVqw2C5f5aWfGcqqbmCKaaobJvAuTQXa6xXf2onzUCuNEyZtfkS1GMV39GZJuMlm/PrE
/ub/5Lsp5hc+I3vlMRuRFzLOm3tFrg+2wfn7YBfGce5ybcatcyw9m5TJsYqyygMO44viHew3
oKsP9op0OUvLC12w4ivR88IXVITlgx3CcCb6JL8YyriAG1egx+o2Y3XJ+uazOyovrdy3uDU7
ukNYF2yDsPfBXioqawVH4+DDK2qS1JVGuympfl7r1VTjpmnynrf5M+nJf++N82zkfDXdwTyf
mC8AvKmjhWfYFFJdEwX7SloztalOsxy7LkstmFdkKXe0VjaW6tlMp3KuQxJOAN1U6lSgcue7
KlA2cr5w7mCeL5kvAJxnr+BUpDamEe6GJBcnYi4Y1FhbkuZzvLYbvEIlwrHAXlKMNEBeUIQg
CT126L1NDp9pMxONAioekC7MzB7kJZnxrCea5KSJfuywk891CIqoP9qpcxlZ2AB5QTlYahSK
PTy3kQlU3CyT52ErE6qiiIvHxQ17ccQy79JFmeqDvSJjVLg6dPEPHb5yjWyRtSolVyerD/aS
ZHEDmunalL9Yk7Wufv3Uwrqi8c4T6C5bF+pSXbAX7FZ1SZhm3OD1PPEtTjZKA33aSlQFlx/p
D2LlZ1ATDLJzDIpDkf5RzJSfln3V6cVm/kqnbHUx7nz7BrR7lyZcRog2PMmlBSO2pQIyugVl
dAvMvk+7IB/u01vg7pxK+fWZUwXkbG+svzNW3x9nUA8O1D7IllNfDjeXah+x6ALOoXjGou7B
pxBLrcZTA9iABQyN0eo4L+eDsrir1hBU8NiunMctRlnSGWBPRX10SxwtQRSc3De4JYzwOTtm
DiI+fDLo+xi/EPRPQ7uPeTML665Le0FUUMrnxwXRCiXMMJOgTBXIcyHfxfiVkH8W2q1LvZkU
ch+WOFicaZXjDAMKeqOiyY/4Bwgdv6QM2FGnNSpwV5YHAuFdeeNTsl0esxl5YfO8vePXJtCd
R98LeRevqHsicKNGJWiUX0k1MKJ5EpNvTXnmvyx6EgsdEom8G6Vi5Nvxf1I084/V3pWRynr+
YDtoW0AbMu2dkHOt1g4pBJ0U0YNwNSy6GkMEiQHrFcytYl7PJ2VxV6yn9E2YagG9JFMVZhyC
LEG2KFct7cfnUJftiRoqj2uWNTpAedbEHs9r9GaUMYPslvSb8v8fH9WPfEb2ymM2Ii9sPX+w
7eI+3J2j3wu85egiscAEhZo2JR/ud3TMeCPjjS6/nMIbuyX9AO6jHP0g4IcRbawCavKUE491
9PzjIyN6Dfc5jr4Z+M7RE3d9C0prCg69kifSuYE/Z7nayzNk+SRveuIqx9tHbXNplAfq97yH
30CEGO+HPG6wJciKgYeKAz+30DY0yttxb91sk5+DAnxSjjoMtAtHJq48cjRwVAjTpEnP1jnc
uzKyGD+K5gOwB9H8eth7Jyfly2RwfSd3wV7ayW5CXU89xbwokqUWMlopkhltrp7HdbkP9tlO
/hLsnZPtpKjAJUiI29Yzbg9tBbd0kbkzPL399eF+7uaXAt87GoeYiEGh4wAuqnjg6MLcuGJ0
rKh+csk4APu5yngh7J2THTbOgtsbPIvPLq2czFrwdFDMOrMTFLN+WgmrSnEdurkPt+HmdwLf
OzrhWUKOksVrFSknbbpoNPfBXjyak4JS7JxGM6T7HzADPmhmbbi5A/dRo8mDgO8c7UmZ5wBB
5CVYntcE7ysbfbhPb4L3lQ0bcGfOPkhOwW4SvBHvcyL6AO6jHP2kiLYJm3buJuBdoz7rPIQa
laQwmfLMfxGvvDmeXHn36HNgeAmM6sdq78pIZT1/sDOidOHuHP1e4OJoC1oFFPqQVBp0UpMZ
ogrDX79//PGBTVwFGCBEbh68OObVco7XfrIxG1HF4k860Bcj9QpjCI4YS1p5THLUCWSEms68
Wk7yYjYGQI0/G9OOgNTWIt6lWJPVylw+W5vDL3hSgH7A6QbT3xQ7QU1oyIdh5IVRVsp+/F0M
ODMpixvRCwb/DRrjN2NxBngJBX1AB5GrymI5JUvFEihSSWJJsOMBnxGRksIb85E4323eUE7L
cr6cw/QiLpBqGIhIQwos3xDVmMbF5MnFI62O83I5KYvZGtZk/FbQXv3NfrUsSY4iwXt/RZ7H
TDLeoF/Y257mA8ZsTrVjtv9/WY8IkJAEWequykzlti5VkEDIiYeHE9LN45VC8HRGh8chcigC
BaHj1aEsl5OymG+LA4hKtoZkcbU1jc/PxnhxNlYOroxhcaqMxdqWYS5ZjMXKVj63soX9br4m
Gr4PtTWqhzRbk+XFXj5b27MpUNCjiWMKNyKBmy2Zz96NCBlWBl4arGSZnJGVjItIA/UYqbxQ
FijaVBLNo264VANlq6WqlrVyaBo3ZqKi2zXNIFu8a9uRpcUQFzqHY29J0Zond+xNxXltYyuM
vmcqUcF0TPHaxtREqdy2BY4wrRvGeW1tKxkiyY4tR2XXscVrG1t+7JpiyumY4rVsChRrxfNo
lV5Uy2wMCYKWSu61uQEsxspBWtvYCvSZni3m+Y6thefLT+gOqmsL/p16tnhtY4sbAG8nRbix
JQ4TY2V5Pll5DAqHEjcqRbnqiKkMbcrU5ajrRGUIGS8OZXU+aGZk1K/Q7wL6OTA4KSMVlpKO
2I4kSmyLgclqPpgXF873xLOW/vEVLOWfAEP5U0+ZhGt4dSjL88maaiYScZoTbILTdPE9w6et
UkIcAJ1BzQtio1IspME9VAp6Ix49o25IQ3X7V1Et1hNlKYL3sX186LA8m2DJ0rMJTulYQqND
XquGmQgmlxdXiLH5KGgAQgmKJaqzRL3ekMvcOJm53btgid+o2DhuWMoNvxySpRw1ZLhLXIDU
CUkQVI3VgbyVhE2y06eqs5azsrr1uYMEL3KcOoYn/8eupyCTqciRiTtneVfpTQIaYcnEO5aI
EqkDtOOnCJa1QIUtHL5uJhAdN8JH+TQ5nGRhgXz6FBHuZqv4dTIBZKDootjXzwTIj2ZqWovK
m6/2K44mqbRgCfO4l9yOhXoTCxLf5IKLwNx6ItRu9g0nexXn8gpQePfec4YyU1G6R34V6DLk
v3hlyIzqFd/JM1JMvNuLCNX8IqT/eFF4fqrw7OMH0ncKeYYwqlAO5wnb/etHnrH1jzIjMHJe
3cRq6wm4uqxF5RAhRHvssuHQbc0vX9UcvGe4c1FrjShEEAxSnr+I3Yap+88/bv9gj7rFyaA8
8XDAMsa8xkuznzS+lpkkWpQOU4xr+skRT+GekTmQ21Ie81/4SWZQvo4ukqeo7US/0unBU1j4
MRrl7jqxf2QKd3FTz1P0MWrfYiBPxDi8LFP+xEeZMSYxgcsl8V3x2b93CWKIcrxnpVIqvZMg
RhJEBIByZexINHCCBAl5lAThGSsROTzIy02VAWcJPw94igswu+apMFs2UCZkm1NFp/zdjzJj
RGKBU8WHdk2A0CxdMxCh4f2Qx7hyvqiWLBONg5lKZWxGLgSZWHo1yWZJWjWXSvVjtbe2UdnO
n1OM9u8/joLdxeeVsHdOBpG53MqIqScioRCbTq7AuoyYwX6G1YQ+VrsDy3nX9nEf6x0fPx31
ntsDuFFaaUQJ+JVzpcwOpsKMqZMKC84qEQ6lbwtjw6kvQnvXpQY6ZJHhn8b/G8L/MznbR/oT
OftgzFv32oS3IikQBzKjCzS67FpSkgIg8dqQymp+3QS8Z+/dnx+E1Gu5AUPxuTLmv3CBzCA8
PXXRMo1jDPk5OeBzVowoqVLtNLtM5h+YIwjzRo3DbrYxz/gDdFbm/J2PecrIsh3cUT6w+NGC
mgy9qTx1O37rIvDy1v0bq/JydKxJIpkri+WgrOYHGsQghBW99KAw6PWJ2GmIM3mg4RYAESA5
HKUFLw9lvZyVVbFnJ8tPOlyFrp9oos04ZXt0lAIlbyhZHsp6OSur2V7w1M2jIjq+2UA3KrIO
9pQmv0ZtWVvI8lDWy1lZ3T4gbYqL1AOENW2GXCmTK9VgspqfcrFMLusO2U1BTDm7ElcLuYon
Nm+083GbjfKmTmU38TVq+gVId/U8ueU59hBXlh+rvSsjlfX8wbZPW0Af5NNfhbxzbpzGid6m
4IhzO7cF9PTONWOMhDmd3bkNoKd0rrOa2hkz9kzY2CqEHRK9SXeELevlaJuwIc1HFgrocI1Y
8SUKXQ0Lgw22um96YIia+Fohej7Sbdo7tGdPWK09d9o3gZ4y7a2FCqLaTNCgNw897PCYlKz/
L1ZZG0cL85rTHaqn6JQ//7j9gz3qFiczKnsLmmpi4pL4E0vWJsIVjR0tYWR0Lks6+Sov/SdD
WfEGSkwTb5jIuzQRtNereGsnzoNWgtSeylCPUxLfKRb7hIo34+vKyMNAsYzlpwRP+IzslWE2
IhMyzpt7JNcH24j562CXiCcS6s2IW6h3kp7NkMmxKmSVByD2LeV7sG8Qrj7YM4bLWVpewhVW
8ZpovMQrVAHLBzsBw5vok/piKMMCbliBHqrbDNUl65vP7qi8tHLf4tbs6E7AumAbAXsd7IVR
WSvw+/XbGXWS0pVGu6FUP6/1ONU4pZT3vM0fKU/++9U8z0aOs+kO5vHCfALgDY+WOIcNkeo6
UGHPpHWkNuw0y7HzRqkF84xRyh2tVY2FPZvlVM51goQXQLeUOgxU7vwlBspGjhPnDuZxynwC
4EuEXiL0EqHnD9clQt9PhF6M+nsx6hXx3y3iVw99px56heutwnVJnjeTPFfA3ixg0A6eCNGN
xn2/YpmEa0NqSBY/r/U0i3FKKe95mz/Cp/z3q8SUjRxXKzuYx5n0CYA3ja/EOWw6n64DFfat
r47Upp0gvyc7nTpKLZhnjFKWIK1qLOzZLKdyrhOkMMZuKXUYqNz5SwyUjRwnzh3M45T5BMAX
Zf5elHnF+feI89Ua36A1XlF6hyhdAuYNBMwVpPMHyUU3JjjbaMDdBMklRZGLJox6G6T5HK9t
g+RiHD0RibW05QjZ8U2/yh3ZyDGya4A8TnVPgJsDlFQvOjRvB4fPtCOTzBiI4cN04sjsQZ4y
Mp6leTM4k6IfO9HJ5zoBSpDy7dLpkEW58ZfIIhs5xm4NkMe57Qlw19yGdxPObbQckZvl4Pmw
1XIVKWLxPrlBMCXQvJtOGqk+2DNGjIirEy7+oROvzJGtYK2o5OzB6oM9ZbC4Ac3h2tBfqoO1
Zr9+aYFXNO6sgu5G60Rdqgv2jN3qEnqX0Hv5VS+hdwm9xwm9i9vOWkFXgE4eoKv5XJG5InPJ
gv8rWXAF6OQByu1dRzqHGISNLrAcPB84QKGhC3jxvi7Qo01KKTedNFJ9sGeMGHWWTrj4h068
chNrBWvF9WcPVh/sKYPFCmEO14b+Uh2sNfv1Swu8onFnFXQ3WieSEV2wZ5QTFxm+GxleEXu3
iF3t653a1xWsNwrWpTXeSGtc0XqjaNXdVs24g9ejcRh7XznZjDrQp61wQHR5SH+AlcdhVOEm
O4c4MnHQP6rw8tOyrzq92Mxf6SiCLsadb1+Adu/SCcuAaOODXFowQvEVkMktKJNbYPZ92gX5
7T79Fbg7p1J9feZUATnbG+rvDNX3hxnUNydqH2TLqU+Hm6naJ5Bu0GnEGYsnBUYxFa7GqVuw
EQQGY7Q6zMv5oCzu2DrEMXqIC+exxYyWJHywh7IeN53zaEmi6OS+0S1phHF2zJxEfPhg0vcx
/kTSPwztPufRCPJLqOvSXhIVlPL5YUG0QhlmmJOgnCqQx1K+i/FnUv5RaLcu9UaNiH1c8mBx
ph0dV1igpDdjMnmIP4HQ8WTKgB11WjNG7soyIBDelRmfku0yzGZkwuZ5e8evTaA7j74W8i5f
oXtS4EYNJWhGv5JqwYjmmTj41pQx/2XRM7HQIZHIuyEVE9+O/5OimX+s9q6MVNbzB9tJ2wLa
kGmvhJy5WjuEMOhppPAArg6LrkaKIDDB+jHMrWJezydlcUfWanqTSLWAnjJSFWY8gixBtpCr
lvZjHGvaVtRQFdtijR5CGWuK3l8/8syMxtxkt5Sfyv//+lH9yGdkrwyzEZmw9fzBtov7cHeO
fi3wlqOLxAomjtC00+Tj1x2dMt7EeJPLk0N4U5fS78D9Lkd/E/C7GW3sGKjJU018r6PnH78z
o9dwH+PoXwa+c7Tirm/DqDUlh17JE+ncgT9nme1lHLJ8kplWzHK8fdA2U6MMqN/zHp4FEWK8
P+TnBlsKWTHwo+KOn1toGxrl5bi3braTn5Mi+Gl01GFCmzhy4MqQs4GzQiJNmvQoz2Hvyshi
/F423wF7J5ufD3vv5Gn05WVwfid3wZ7ayU5B11NPMU/KZOFCRiskmdFm9rzPy32wj3byT8He
OdmqkQhuChNw2/qN20NbwS1dZO4MD29/fbifu/mpwPeOxiMmISl0ugWXxnTH0SVywyqiQxXq
B1PGHbCfq4wnwt452aFxFtze4CzGblo5mbXg4aSYdWYnKWb9tBJWleK66+Y+3IabXwl87+gJ
Zwk5JMv/mK+WZDluHLjXKXrtiOrgFySvMDuv5gCOUcyi5cXM/SMmEyBZ1dWs1rP8NPZGajwS
KBCfRCL7e2VPxvY3reZrZ//m1dzuMsAueZgh7/+EHfCTdtZFmC/c/azV5JMcfwl0JjPvBQLP
R7H8vCH452Dj2t2fPgT/HGzEgpu9+6Slu7xsgj/o78+p6Dfuflagf1JFx4ah3aeJ5LTAZ9+X
0HBvBkxh/NZ/4a9JSTdXvb3lXhjZCuPwx8PdJyMH6/2DFyvKpbsvgf5rHbdAR/H3AqIv7d5u
vt1duNV7uf3nX1++fsEQvxe5Sak6PPRw66dDT8++qbFYwWLxJ1/4xcpZEQLdMWPN3zOaHDyB
Rjh05unQ1MNuTISDvxvziY4crVW8ZViz04O5rns0hy9kMsB8w3aD9g/DTrk7GMrltunBZifj
Pv5uBlJw94iLiELAfzeP+u2+pCB6BEJfECCGahwOLTsaluROlmSWzHco5O4RmRRerCp1vm1e
GNp23B+X0F7MBVItNyYykIH1F4KNeRy2zBBvPN3m8dC0w24NmIxvFZ/vUm8ZWwrd8907LIeo
oQIv6J2ebuN4aNphfy0UkJVuDcWSjtY8Pj+N6eE0NhSfjOGwHYyVo62gWLIbKwdbXe/JFu6n
+UwM/CxHa+yHOq3Z8W6v6x7txSpMegnlXuVGELjFUfka3YKU4WTToy1alZmOnXS/CBrox8L2
QlugaesotIy+0VYVVmtkV9vZUGr3k5ni+LqlGVRLTms7drQb0kbXdLxacjzLDMerqTLPTrbk
nq9MVTbMhSk9O5lqLOW1LWBEWL2wzLNnWzUQJC9sJbbdhS09O9nK90tTCjkXpvSsmwLERos8
RmU21jKNoUAwUhne2AfAbmwo8uxkS/iZK1uK8xe2dpwff8J0cJe2EN92ZUvPTrZ0AOh1MsKT
LQuYGRvHU/MQMTAcFm5xjrWaiFSBlzp0JU6d4gI908NtnE7FMD3jvMK8E8xz+JCsjZzsLV1w
HUVU1ZY6ZqddsR/umJ+Js5H/6RMi688cQ/tzpjTDGj3dxvHUPEJNI4nzWmANQfMj9uo+r1oL
aQJ8d2oemI0DYyEHz2ApmI1Yeu5+QQ3d7R+DtcRMyHJ073FePrzsaxMsRa5NCMqFJQw61LVb
mClActu4pJTlUrBwCC1olthnlbM+MGTp3sIc90ki8Y3NpnnDUR/4Q8mOetZQ4alqA3ISkhAc
BmsCeDtLm1VnrofJOnTt9BzzBAo+6DgnRmb8y2WkQJPZ5KjEl2DldOCbdLTAUihvLBESOQHW
+XN0K0Z4hSuavstKIBwv0sd6agmaSixQT9/1CG+Lh/xdVALAwPGhuHddCaAfy9KMEZ03n/Yj
gSZV2n2R+fuquJMS9aUvKPzQG67A59WKcAxzXgQ5uzLbS8Dw3u1zgZXpWO5FtwI/fuq/2DJM
Yr/iO10iY9Lb2Uio142Q/2OjyLqqqPT4gvJt0iWk0clQ7oLa/e1Ll9T6Y0h0xvTdzayuVsCn
x0Z0DgGhxI89Vj702vDDTw0ffKe8eWiMwRgiAAYlr1/E7aDQ/c9fbr/jjruVFtCeWBxwjN96
pkczTh5f60hSIlpHISYt45SIU3hnUQzUsdR/67+Ik0lgvokP6SJ6u/Kv1N4y06LLaLG3+6rx
MRHh0qHeRcwxjm8z0AUzjiibqJ94DEl9MhN4XLXYjZj9+lIggZCTszKV0ekXBRKsQIwAuDR+
J5IGLRCxlBcrEJWUiZjyZpubGz+0SnQ9UBEPUHTtoiFbNzAE2tZS8bV/9zEk9cgsaKlkWfcE
AC3ymUJAw/7Qf+PJ/aHeqsw4DiRXx+9w10YwIXJrsstWtG62yuGPh7tHGwfb/XNOvf36y0ed
fcnPX+n2S5ABZKmPMiJ1IwhJWQb54GzqHquz3/M1yLWv8cVZrbt1jK99fRPj/7vXr9guwEYb
pQUtkJ+Ca232wVKYPl2Uwu7noRA+VL4rHxdB/Yu8fRvSAB6y0/Dv5v8T0v9Havba0z9Qsz/Z
53N4Y8WuSAaSAGZ8wGLKPlNKMgCS1wVVdnO7Eeyz796vCyFnrQ5gML40fuu/CIFJIJ6ZU3SI
5V6kr5MbPhfNiLMu9clryEx+QEYS5kUP5TRtTEk/QF2T9TuPKapn3Q7eaB/Y4xgBTYE7Vea0
010Xibdd9ytObXNMykkKzY3DoWinqyU2cNEAcyggC7GvRL3m3e32399+76H0cBHmkxGbTnQh
ChOEdDEgnbj/+4vnwrhhfolpMjpRbFnxhAJqUvj6mUwu4hORtRA9amxfF1bPIV3iZ6pRJ9Zw
JXXSt0R9i+hT4AeWG+x4wviBYrCHJmfpRLcZGfl62p5kEktpdfbsMrpILAyJaE3QHenhgiPM
aN/0EFpRFimZEdsVi4YToSaVpG7o/vx66p0w553gaScCdM54qbeULSxIKTIPSUnqyPdwytMb
HGq+I6OBwvb9NeWGwpb0GiA4UwYB/Y4zIL14dqpWYZCqfqKYM6nSmWTO4BLcwhXHjKEpq0qa
MEjYV5KgBF+8aXEulVLSbIyVN1usRoEjP/JQmXsQtt1RQ4l7bArqEWu/VL2OdqF6U5eTLUgU
WXLJG548+5WQ8eGLVLRAR9GlX7nyC5tmWeGs6S6X0a7dLYwD8xFuYcdItl0EhmoTZ4AXzQ9q
K1S6VfYS29vDr+zVr0Yf87q8t2JVm7MBOmWKaQ/X0S/AHHouC2NMZdM0xWLbUbTqOrmECKbu
hlR3XOVeXaLLFirRFNa+d4WeUoWBgQJb9bakRYaC2slGQCS8mvabULk0mbzUOot+XVq+L5RZ
SyOgRDYhgqpPnnGS7lS0+VzZBtQ08C8GRlR1Ou5WDsU5gRmod9C0RasKbwmAFPvAf/DGdCZY
sUQ237f5dT+c4dW4KG5kgUUEVUEM87viRpMZB3HSe24w50cnDIqVFpqiUdRxBdXkdLkMxAJT
9YpfbVFEru44gNi0DpfLKcKud5acwCx0RLSIzdgwdMwjYIzzogdPnTFOuyoYx/zEaD3Pwewv
sAgwiDQCYhRtKIJpQGwdG4+dBWxEx4MUWGcBFhEWxKpoDJN2KcS6cAmDeU4zuHTix08uNVKF
FC31VZ9p0HdgCt4SBTZQRYGzTcU+YwpzNxVP3mDyju4W7m1vkrRhRiJDyLm2JsWgYq1jkllp
Ij58pAZEa5jIi1wwKNQjqQFUz9F6dAd0pjMPuvO2nzDpUKW4Ze5AJKcTq2pN1T44wDeATiBL
WTUxZeicVsyGECB0UJRVtoBPmiCCc5qZWw8N1k8wQIVQ8FvJqVbx3uAyO4yYzOSMTkw6jQ03
T37knZIJBuxbP5rCV7WhvqEyVAr1MFBHHVfW+NaUb2xgH7hEaSiypGTZ3JxAo7Fa/s6Q1yfB
blTMSOaPDCSuRySOioqOJU/NrPtD6y1pqsjbYoi62dzEP2FJy5qBw0AzwNCBo/DaSc95MBSd
toFBmnH1bPWHWuHV9uoLdqlRuJIvegnjESUYSWceKhE/knXI88TMOl8j10TqRUbEgIeKnqUT
85LwyE7dBXpvexvdieegFZqBn2YAhD6HF4dIDrg2ZYO+wOq25jMKllXMKwaWUEtsJgQGS0jq
v1cOGbz1+Dj+aivU00zqeqkqnNLZQEZBL9pIObuR97i0NMnXyg0wN66iYsAOCfGAZEObT96H
U1aI0aEtWiO4p/hPrXrzS+qeoJUOIalvNkcyAyUiqbcDZDHZ4IMBmAiMFCixSgyhsQ9/4H/R
1iHyv0XhpFksUlCabwI0yBJbU/YenZV9whuWMfM6Bid+hKCywRO0NaPB0nieDvCWQBMQrHhB
bkRNoTttTNp+B3GQUcXeCcWJiUVjO4Ub0WuT+Ek20r/0BTnOA3AQxQGGV8wPH9h8tbqlnIgk
xdrrRJF7mr1yCiOydBLaZWhXymJA9OxXDsA1kj98qTj3ll6wOJoyAwOhTFJFMcgidYY8m62g
VFZwoJyHujJFzym4cmtgcnHtO26JbRB+oKPYTuBtgIydsHa/slJS2z++6TLWVDQulhWKuFC4
tVuDKhfn3y86wFlzgKPd8Og5ccocdev41kdH6uujlpmW9osHYKilD8+Cgkhvtj9wfLZ00o0G
Amsod7rxP+qrprlxG4ne/StwlKZWWOKDAHmcTSqHVO3WZkepHJIcNDJtK2NLKkpe7/z77W4A
FEVKME1RslVlS6BIgK/79cfrplKW6Dsn8WGjpixzEwx0eawaxonDJhpRVWiLSRiJagQLaKSv
RhCOSL/UVeKnBEh5QBnBlTTnPeElViNpHCtQkfFpSRF4CFTQOxanulgfk8Qz5gzVaLxGa5Wf
aEKN9Iy5nMKnnd6QGGJUpGivIH+7MnsIlfTzpwUHh1HnsHLOaOoFHxlCAbmtXQonoUrWpwtw
bebqg/Y2pf7SeJtgloV32gPCzOa7iAaqVSzRXA/IncDzLTMPjdYiosQ5yrXd3GtWVE4oFi2B
Iai5S8cGliyp3m9FfNRBD6G2wlOQlSC7Qs2eVCMp3HUaQCFl6Jusml7hnjrW9Q3UqzB32TTq
GOydzHkdxssMmwIwlmdhDpxUVDmFBIGiMaohUiRdKbcPgsqhbbOkKwBd5HNOijlz5Z96J1yG
xN8X0NR+QUD73kFTDTxMNTnsNc6XTUxQEnwQm9xUnfZwiaY8pomBQME1FgMU7jUZ7Rmj2oxP
S68ZcXho7vZduIUq2VFlsjwq7DUNnda1RbgABxkXl4RnVx01sMZQeOGmDKPFukR0J6QHWwUU
6irfoYMFBXlMTRtHQ1DTWZUjLcZyVxuEw4OCWvu9Zrc5O4bJVs0epCqu7RERgtWMOHAo4DKn
t2bZAQniskoo8BNu9Wwrr6KkJKXg2W631KBiLY6QMUyGupZy9RiuqAn4uRWV7G4IIgDUTp/8
6BXSHAdUrByHOgc61XcLmxzhyqKf4WhXiUn7wdF6T5hVDR7hQsvFfZRTsM9VdDdTykMs6RxK
MqRUHm3uEpuMcQIRdUbqiKGhJoh6LLzG1T2FoKx7ObnloLrQeVYFiMmz6MSFDSUn/7vCAj2Z
RKuXMI2UhoeJOap7EzcgBfP9SclBPhIvmi3EbjQ2qPwLN0IhKOa6cqNVKifoXV0hpyg/iSaY
Vk6x7aNQICQzrHQGWqREAQUolHMKx7Mlxd2eazDgEm/vRIQYyfzn/MZfocJyD1NUJu5rfkNm
0Fp51ab9yu93F3QwPevcMb+5+9QZunPglx/+hVZAXLwwkbB/wqa/2Lub8XDzZd8OaER5lZjA
WK2qf1AKlCKNYUHVS1BiVP8k1Y6yuPntE1vCMwmzOeSAYgbbDazpHt3qYvnHZ/CXRjTKquUY
UNiuTYs4i3TmpPaayd77Jztckwqs8QYYssAbhckdTN1zQc033l1Hcuk4+k5MvJ8lrXQy0Akw
klIBIklWNbZbOjn4NfSyjl4dC6TwU8CuauBlHXychQj0t+XDZc1oUZArbr2KNzbbGy8+OgUR
6NdEgQZFEQSOgTocVOhbmkqtmsp6Ne2CXe6wyzp2+ToFMeh9usKlzGhTYDhCTxRms3qjtOpS
RzuET792EIPeJwsuZUaLAtDiKbY1DW0tM3sau4+0Gjh+XiEhAv5UdXReQ9o06GrcM7mF/v+W
fvCuQ0YM+qkkXHLI0NLAPOiy2CjbbchoiLp4LwtAB2/JMeidKHgnM1oUGMO1n3aMBaWHs2uu
h8mCXjncCqAICRHwg+bB4Ia0aRBVKTWp5Slaol7pCR9mUIuh75MM7zioaS12UjvTJxMxcDK/
wkME/Kk8nNeQFg1K8Tx0uCzjiZccZ23OzWTuWZQi0C/SnHua0aIgzbjxXQ2+Ibfc9HMpCk6p
RxHol6bgpGKEPS2IDLAjaL5ryIII9KvKAptzhWXUKGYFFDScQPUrEvXkGaepr6MzTmROiIA/
lYTzGtKkIU0EVzjkKMGsMheioe+o2aAhBv4yNPQ1pE2D4qSxVc6sBI/T3CmuY1qIgR+0JJ19
Wkil5AInzhQCSmiepLC2piMNXQbODj2t48DZJCEC/W0kXNaMNgVQr3we2yTt1pr7jDnDq6MY
9E4UvJMZ7WKkK4lhheJiyGJUD5/jk+YJAimG/mwCaRhLWkQIwQVVVg0BlVVmnbcrxKRFC/1x
jRQDf5mu0NeQllQFma2qvIZXaVhLfSX5EEN/ZfmgUuApyG6ZcjFkPnSNon7ZEIN+NhYGMKNF
gUqrCLKg+1Bx5Kb/vHABCpSSmPpWZUwKyxU+Ky14mpXFzW+f2BKeSZjNJU8UMwJuw5ru0a0u
ln98Bn9pRCO4RIItFixWHceNPurkeB04QWfF0J9NZw1jSSudjOXGq3aTQQRioRbZNQwcMehv
y4f3HThUrrhFpZ5lzNiMKxdOV0FBBPo1UaBBsmvEbiwzUIfDEPWWplKrppJ1UYc17C11KOv1
NK6uItD7dIVLmdGmwHCEnijMZvVGadWljnYIn37tIAa9TxZcyowWBcLwFNuahraWgU2+xfWV
VgPHzyskRMCfqo7Oa0ibBshoLKopZrSF/v+WfvCuQ0YM+qkkXHLI0NJw47PYKNttyGiIungv
C0AHb8kx6J0oeCczWhQYw7WfdowFpYeza66HyYJeOdwKoAgJEfCD5sHghrRpEFUpNanlKVqi
XukJH2ZQi6HvkwzvOKhpLXZSO9MnEzFwMr/CQwT8qTyc15AWDUrxPHS4LOOJlxxnbc7NZO5Z
lCLQL9Kce5rRoiDNuPFdDb4ht9z0cykKTqlHEeiXpuCkYoQ9LYgMsCNovmvIggj0q8oCm3OF
ZdQoZgUUNJxA9SsS9eQZp6mvozNOZE6IgD+VhPMa0qQhTQRXOOQowawyF6Kh76jZoCEG/jI0
9DWkTYPipLFVzqwEj9PcKa5jWoiBH7QknX1aSKXkAifOFAJKaJ6ksLamIw1dBs4OPa3jwNkk
IQL9bSRc1ow2BVCvfB7bJO3WmvuMOcOroxj0ThS8kxntYqQriWGF4mLIYlQPn+OT5gkCKYb+
bAJpGEtaRAjBBVVWDQGVVWadtyvEpEUL/XGNFAN/ma7Q15CWVAWZraq8hldpWEt9JfkQQ39l
+aCM5anvayaDkMICKymkxM4U0IR5VjclYT+z392v9Plnwm4r+1KeZghWJFyABZoM9BcCqQUL
w2XKLVkKOyagcyCekrCY36Tc6HC1t2H/sPp7aMu+sf+YArD7m79PpwKwT+/gajqH+1OwxzkG
vlKdQzoxA2dZzaZPNyM2nv6FmxK/iQPHOe6c4DLVtB+W/ghaKS15AiBy4INO+X3002KsRvfP
ZQHQximcOjGjz2GxWY7NaLbePMDXaqxH2/FEjNjqjm0finE2Yk/Pj7CbfsVjJrhwz07kaA0L
OmVZbOHAF/hfld/Y+M/pzzeEUVgyFFZKIlr4Mc8oKgSiuwV0WzgpHa3p83FsR7S4/46fDI6/
K1dPiIWVxd1iWZTuBj44w9Xiljkw6WiJiPDKn1jduBvD7zP29XnxeLtY3tfhiQBPGoQHLFI6
iNRhWz/Olpx9Lkt3lB69bPDUsliXxaZYbgnYmMx/QcPvy9n6gT1vilu2XdXeI7PwHq28G1KQ
1bU3lSt04/MW8RbsdoZXW/oMFsGK3lYdmuhwqMjxUMuVVBhUeN7n+byAjZsN+7fDroC+DH0k
Rls88o/RfFHOH4vbP8acTeHgJT7vzKB30MFyF23WOUgKs0ffZj1bAhkbtvpvUWLAIFINgZTQ
P1DyxGsHit2B5PEJ+dtCwaDTDAcQEj8EZz9gOOEJ34qS/QgXBRC5foRzV9/h4wkICFE8CYv/
wGKGezCs73HhXbbLPcdIYF44HAkZpQDGjwBj+uB4QDC40mMxmixxtbqt7iDpGBOrEj+/hYDd
PKzo52X4YeFWPy3un3FBTxeIN2X04AzWG+ae2mxnj8AJbVgsIWi954QWagcTfY8w6bnV81dK
nYLNVwQCzy7xxc8+KyBLtmwGf+zXLy6N3GMQCuV3JN+ZtECbKhCz7WJV7cfTXmabJo+Ay6Aj
A67UwVpDIGDWwflYUUpcPI2FIv5umbvNlsgjElTSvRnyytblbL6FxQL+58WGfUWiAfgcIgvP
Wm7pQOCYHluRnS8Lqlsa6pKvAO5s2FlLdekRa0N1c/oJkL4syuKxgCQp/odMrB01kOCLYonr
eQHZ77jR4BYsOo4ePfobphR7WWwf8Mq9FIMBa82casXyjhgnB4B94M+l26j2cOX/Z7/qety2
sei7fwVfAswUkVaiSEp6bJoGWKAt0iZAH5o+KLZm7I3GdmXPBNNf33PvpSh6rEk8STbZARZB
PKJIkffcj3MPfSLaqQjvfWzGiHGFckyaOU+ukJvtDc9L3lz2bbNv2TPyeRNiWNNDjQ/SuqTH
J0z2zGjdquE8WnWrvXAsh/9mTJXYaOeNNvYo+nJm37YKcc3OxiTan1PnoPwawkRdpt3tJR8v
U/Vzs75VnrLJqeRw74DlZsufIktLn5Ny0Gqnhrwd/CNVBtqYCL+pi3IMf9uPViJOrZJoNush
pnlGT/zD656qRbvjNFnth9UovCWlBX90yXNAuuYn9duLuA1Y77aiqI9j3a6Dw6kUey5u2oke
rs5rvwB1zH8XKIvd4CzyLgqBo801Jf4w1K+xHX29lf3E/8WQLN3mvXedFtJ4K5zij9iIq7vV
+t1RziZR34wT4KrpvSfswH1jGyaOruzi2dATgg6KfXFX+Mih4cwiSjrIWz7U0ZEpAOs7D5Rq
L/sVevWr5cYXOV49b7debJizWxhGzUQ6ibQRrgeuhcn2Edik0sVx+/heGdrXYN9kvVlIknB6
tJTSvmu845OIVmXFtgvWCMXwfCNmNaBGoaG9/Lnk1xfNnI1MY13gxUZemOMke+1TdvhQ0fmN
KuhtctExzXoa659yBVgmLakD/kXFHIbOkd4nBcoPpsQfXAqqMiUvQcZqiuahZXpSu5qyTkt8
qVOnRbqCStfzHl6T5oHUX6gdj9ruDo8OaoiuDiQsINPvaKzdvmc+nu9JC3PjGNl7x1Nv0fu8
l5tOia+IVZobDo2QBROvOZM4tNRCnwvPe26i3GfFKfLBIDmRCKF3+tTRuT1unYvmlnsjEOMg
UBkxmQOTtajgG7aE+uR1MzRJWrGmg9BVV8xkC7zhyBUpzHGKuyst7fg/kp+/g7ggUmA5xd32
cMtk9GwxBM3p43zqmtuWyUZtOU1p//k7emz3zMwRvQycpC55/pw1kosm+es9Jb87Y5ZznoLc
WXercJd4P2zRh11Vx9p4t0enlisEnNSxHDxUsZDcWV0ct6tBNxD0HehWKgIhFm9Q2t1Az6/E
XE1dyX/B9yO+CYiyBvIWNyc6e9uEVQlpl2VDS9ZIWoQoztqQtEXoSkhBZp4V9M9+6et/M583
OygINJpbteg3222AN1RVVmdMjHmBa6QdLgJ0FUGgWWmp7AlfqSCbtmRzv9osdr4RD0LTijxK
/C6x1N+sGTHlKDErYL6WBq35asjOw2ZX+N82axiPlzzb0JNqqGK5ap//9BM+hJPINe/YlXve
AC/f8uN7fsl+ZfN5PCq6qIwsd1XvujXlLjo0kmZgzaYPehL7XlO6U+L3PI/GjWeOC7bmcuMV
C3VxTsk8Fs5TBodP3l7vzz01+xBDfmGTCSoqjNHBtGYbFGa3mgc1mPCL9qbtFM81VDyGi4fV
Sd9Amt0qaQ2sQNVu5bWpCopzEYhqF8uNgRJtWR1X7lUjzXnv/3pBMJeWL6/m+5XoEWqDXhvc
kicavlvsN4M0kcoFrs4X6/w8qXjpvPPyzmu2fnPNj8u4Y+XhJnssJxAjChClU0XuJimtls2C
pEsLf/Tq5Y+/8cUTbHGNJnk5rkRpqj3de6/aXXwLtaF3ITZn6o7cOGgnbFwwyXm1Ea6pRUrn
vtG6QDI85yvP3ziv7fHKUKL8QkmMi6KVjs9rHU385O8oNKVebuhP20+LjeqOShp0xjO5UPar
8JmOEPg2ozn2OrVVKZyA5EqpGAVzfJAevinyXD6irz2RpJC+rCG7zZAGPmW40Rl6zPAy4XBv
Fv5SuV7w8g1rQmpsXv3Q77vhXnIdrgUUvpHZfBBymzGIxKQVAhO19P2yXUkp7yFyc+JkWLC7
Xc+XIL7nm7/h0m2/2W/mx2WR29p5vjS4e3mYbG2n/nD098+Urf53uED5+9hKWp4I8aa73a12
T+N8LobkkcJL/BExmcJyVFHI1E3PRAxbb1YLSlqggYOTHdo6+Ixcs2j2jSLuHtNbch7FOb+d
d9R7KBYhy0uPsy7NUVV5psQFFikYiIz2s7jODKy34Iuf0DDA0o0gx2/Ba8Gzc+l8eN+s99w/
UYdv/ObMjLye/hv+Rrpo1JzL3B5T0wtadsmVVSva60L9gWdHW/xJJXTOc6+X0rPR2GjP6FCm
9UWUSL5ZZGXBjJzrlELjQ94A3A1TCTerS3Zr3+DFYrVRo38lCYJ7nd+zKrzglE2j7EQ8MiYJ
DdOepOr3llN1QXcPkmqk9ZCm0qlyg1FyztSbx2BIDApNoGostCCJYBFOlSy+8Oj7ebs4VD5V
uDRl90ofOmPXsExsqTvT6812IyZesh4l7qcmt25F1yiWp0syX1y/4Bb4hhNAnC+WeNWEyL9g
dXp5TWayg92bc/ymd+4Sub8PaGUtiqaoa5U7k+bMZ1cDV//4evavH15lar6Dg8sCxZtWFM+0
qpXazdczi4qzRuWkYuhPWmn/27ezi9lfs8K6FPSSW5tWFY6o01qrpCxSXvH7d2qNRZkqawS1
UC6nyVrmMJWxkerVD7/AzRo2vlczq21aOFhu6fqTyGlJOHSwSKavZsvZq9mv+PfsNXa7JCYu
Iibm0sUFqsprPgqPDpxscwO45JPckd3kke9feo/8NcvFd8rUdWptXdcl7MlrHIj4u1LNryK3
af/ficfoyyv8spWJpt0d4Un4l3/mswRu8q+R7fC4rJbnjBbIY1LQTZBXJ9EuybANby+jzC/O
+PuL7+CSk4BMhCDP1M/46D/qfwSMhDhCU2JpRqWIpmvqtEAka1cchmUqmyfhQFsOcPAY4NDr
/2psPq9yTvLGw2P71Z0xlO+98S3MdNl9OL5kzOnpSqunIBHUkyFh8XTt3Y/mxPh8SzAfrD0w
idUkLz+19r45L96P5rHzYmZwU8lYujwuXjwBzaPhtWk0VZ06IunafP2y+eKUdgjmq1bNF2I0
40gWg5P/ryY+6I1HU3W/3h9fcHxFHF9+g471ZUrvfjSPvfYef8e6H82jqZ0ITT5W/+fFRn8c
jo7g6BGOPgWOPik296N5WGy+CZgPxgbPpaUGbD8xNh+hga8bm0M0D4/NVwfzwdh81u31RDjD
he8unI9R9AGce/vN/Wgednv9JmCmVHhdAo0tWd1MxUZQjQHJTVriLF2kzqiOhnQYhvjDw5JH
tZ+01cHQyKfg3G6WZGx1luYHo8z5kRqfoc/4p2MjOgDJLfOLBlYyyqaOdsZLPqhICzrXyAYX
x6BzgIbBFMKpu8cE6NyRxwsnODTXhqn8SNPI+bmcBqUWO2odRsChjRKcHqG8GgcBb8UwA1g4
TiVVWhjBSjmQZ6nzZ2QVDws9iTVcGpG6jqC6+sNYNZ+KVCNV7G2iURXMDXPiDn40Ep0Inl8S
EEWRjnYOGHNKqCytHdkAx0XH5ZxGOQV1CqGjFNYlN7Ip6p+OZs2m4RleHQNraEIPyasxyH1e
YxWZO8SQnzMXA5bREFAZHSZtQUGiuuUwAirCpv3JQF9SuhwjzAKqGtZO6PUjgI7qgKiKbXep
dTyqZFQezFU00PFMxjZLRgpOiV7hQogPIFZHdUmppsmQkkpdAwDtX1Kh5NVkUd65Z02pqyOU
OdHKA3OVvzlIV6MP0nWswCiW0/lqqzhf9Wn5GgPV2QkAj4HEGNn6MHUA0Y3h+tSKZIRlFSMU
zsupNoDQTeSrQXkRv1qS/fVpCWvTyihLtNr5yhgGjujNUsGOg8yEZUZKZiJFDzAfBvJuJ8mp
G+c+YUs6u/QHoAVX5hhirAI+FsSRTqs4RYVG2P1hrghsOuL49PQEoeRUyxGd5j54ztyXnnCA
JWQF6Rt8cEpz5OAlhs4YwpLAqfFAaxnRQkuM2w19DHwxBVCbGGARojbRHK3XRFKJJYOzXo5Y
0kH5NE4ziIAHJqmN89LEeXmQvpyxd2H9w36V7MaNA9G7vkLHdoCWuS/HCbIAcxojAnIIcknS
7UnQtgEvmN+fKlKiSImtxe64R8Ac3FY12SIf36tXxbRgzNYmV0GbqlUmZNlQmdyy0NBgwTfo
o2Ki4Hsf7cyzp1iaWEzrcLYrg1MynfQYiscXy5QlLjr0mD7MXF+znkvFCJoVXiq4MiAOkB17
KTdmGo6J4JgOjpkDx4xxw6XCMkOlxIlUWVf+NIdO6X5XfH5T3sIkUmqgjvBSobTh2Y25oRmn
sYzbsxyG5/ZqlN85FmPaTs3GJmBjf7CxdZhFXdqIv5i4SSNxFTQjPZqFBhQ7brDb09yaQpmP
GrhTlXnvn9ky30M4nn6SOuIp/MPOgWK++08Q9f7FKZFReyGZRKiUuTq69attw6LtjvzwTVDj
2xredl1c1jU0KWW9LzQgptYtAI+K0lLChUqDpQIChbutb4rNH39d1L+K9/UI00JhZ65Tr2LN
n+rbFObU/MzE2bnMxIydnZnC5EvICJCZNnNOMP0SIjRMxUsS97fBttdeUEIiOIIFOPAY4ODX
v5WbU5WQkdNYzu2rH0auhCSIuMin3X++RZiBZjUl/ggacBKJNyPx3Nw7uy8eR7N2XyQC6js8
Q7Ffly/OQLMaX8ujMTbc5149bU5uaSmYV82aEzmaUBVFMOr/bmL0NFaTdVfH+cULKXq8PkPF
Ok3qHUez9txbf8U6jmY1uROhoV32v4wbNg2HRXBYB4fNgcNmcXMczTJuzgJmlBt41hILsHwm
NxM28LrcpGiWc/PqYEa5edHtdSac9sLXhzNl0Qmco/XmOJplt9ezgMl14VYDGqldd5PjxqPq
CKGi0rAW45US5QFDXAxC+OdC7SLbDEqThML/FDz3UGyJ2zWpaBIR1URl9wz9mfs4uE0cAAiV
zl8YYMVNyUrhm+FLtxCvOK4r/Av2Q9AUQMOGkcLc3SMDmio8ca48DuZyQ5gmYhipZoxioJnf
h2UhAhxMlB5ng9B/1QUBr3EwA1g4uHJrKi48VtQAJZVq1iDGhZxlsYZLI0hXIVRlx7EytypI
DbviZk8YmbDdMOaPwz0Kz04Er5kSEEVMR28OGCkKilRW4R7g4KLlqJMRRVJzCBVKmGlXyHLW
n2fTuq3BM5xqR6zAAdaKl0FAG13DLNxuy6F7JioG7KOWUB+louVIEuatoxGgAm2sWRnQa5TL
ECEJqCzsNtOvDwAqzAO0Krd3VUnlIuMjnYwZDFg8QtyevSI9Ts8eV4HiBKIZ5CVKjeFGNKY6
AwD4fo2JQk02KXv3rFx3NUBJ0VYWatX9JpGrYIlcuwyMuMzrVZpYr2yeXmOgjMwAOAQSY3S7
D0MJRNXR9dyMdAi1iRF6z6OYG4BQZfQqIL3QXyW2/XaeYGVlRCnRVg9NZrSBQnuTmLBdQESY
JnzKZCSaYE6J7FcSitWYNoLVuLZuFoASbMQQYtwFTJHY2amJJeptxB1/GOPBTTscz5cnGArF
XI7slDbkKXFMnnAAEpFx7G/gB3OKoyNvK3CNlpYtHGocMOYjnCjRcQ9tHQO/yAFkIgbIA2uZ
4iibnshnonbgZNOOSOyDaB6naJuAhSKVsS5FrMtEvk6xfVhpwZitTa6CNlWrTMiyoTK5ZaGh
wYJv0EfFRMH3PtqZZ0+xNLGY1uFsVwanZDrpMRSPL5YpS1x06DF9mLm+Zj2XihE0K7xUcGVA
HCA79lJuzDQcE8ExHRwzB44Z44ZLhWWGSokTqbKu/GkOndL9rvj8pryFSaTUQB3hpUJpw7Mb
c0MzTmMZt2c5DM/t1Si/cyzGtJ2ajU3Axv5gY+swi7q0EX8xcZNG4ipoRno0Cw0odtxgt6e5
NYUyHzVwpyrz3j+zZb6H8G1dXNY1Iqz38Ib6O14/CPOo3ZNkrngZ8CNDYNpNsSkv6l940yEY
f3cbIFD06n/g1aYSXOMSEtK5/lF82Xz4ef10vwNNlhdbtfn09G37eL/blXf78vHv3YXeuK+/
PT1cqM3P3cOjC2/vfuzK/T2M3t20U76or/CKr/Wfxfs6YoZZoK1E0QIVHz/R8vqhuPxwQ8p3
d4DvXwEGAFLiBN0NCmVuZHN0cmVhbQ1lbmRvYmoNMjUgMCBvYmoNPDwvRmlsdGVyL0ZsYXRl
RGVjb2RlL0xlbmd0aCAzMjU+PnN0cmVhbQ0KSImcUsFOwzAM/RUr99FVk6YhtZ1gaAKJoWkb
B47Z4nYRbVyl1hj8Ggc+iV/AoS1iErtwqf2e/RI/p5/vH8n0WJVwQN9YcpCCii+GCtDtyFhX
BOJxMx9MFEyz5Ba1QT8nYvRrZJaG5rd0ItIsmZNjcLrCVG1shc0Dvqyo0m65HlxTaRYbBY19
k2o8lP4oS2ZUkodtqgIG38WijVJfaF9YB0x1Vyox577bFnvJR8NxQFtipkrguFVe1TVqr90O
odl7655FpSC3RzS1wHBIaFvqAlfaFSi+TaoGsUzI2nOb4gGdDKuAjAmxEwDleYMcfI8ug+9A
3jmDR8jJV5q73ijwWXKjWb4L2c3+pB5J5fVU8SQz/zDfA0atut1/ltyLfyHbMEPHgYz6ZBVW
IriPvap9tzPqfzg6e2F/UfTX/5J9CTAAcZbFLQ0KZW5kc3RyZWFtDWVuZG9iag0yNiAwIG9i
ag08PC9CQm94WzAuMCAtMTAuMCAxNS4wIDAuMF0vRmlsdGVyL0ZsYXRlRGVjb2RlL0xhc3RN
b2RpZmllZChEOjIwMDgxMDI0MDgyMjQyLTA2JzAwJykvTGVuZ3RoIDExMi9NYXRyaXhbMS4w
IDAuMCAwLjAgMS4wIDAuMCAwLjBdL09DIDEzMCAwIFIvUGllY2VJbmZvPDwvQURCRV9Db21w
b3VuZFR5cGU8PC9Eb2NTZXR0aW5ncyAyNSAwIFIvTGFzdE1vZGlmaWVkKEQ6MjAwODEwMjQw
ODIyNDItMDYnMDAnKS9Qcml2YXRlL0hlYWRlcj4+Pj4vUmVzb3VyY2VzIDU3IDAgUi9TdWJ0
eXBlL0Zvcm0+PnN0cmVhbQ0KSIkyUEhXMFBwB+JMIPZSiI41UEgBsrIUDBXKFQwNFHyBnJBk
EAHiAqkqENsHRBSBiGIupxAu/ZDM3NRiv9TyoPzcxDwdp/ycFJDekDQuA4V0INY117MwMVII
SeHSMLY001QIyeJyDeECCDAADhsdcQ0KZW5kc3RyZWFtDWVuZG9iag0yNyAwIG9iag08PC9G
aWx0ZXIvRmxhdGVEZWNvZGUvRmlyc3QgMTEvTGVuZ3RoIDYyL04gMi9UeXBlL09ialN0bT4+
c3RyZWFtDQpo3jI1UzBQMDVXMDZUsLHRD8nMTS32Sy0Pys9NzNNxys9JUTAEyhgoBNnZAaXd
8vNKFEzNIHyAAAMAxNwPYw0KZW5kc3RyZWFtDWVuZG9iag0yOCAwIG9iag08PC9Db250ZW50
cyAyOSAwIFIvQ3JvcEJveFswIDAgNjEyIDc5Ml0vTWVkaWFCb3hbMCAwIDYxMiA3OTJdL1Bh
cmVudCA3MyAwIFIvUmVzb3VyY2VzPDwvRXh0R1N0YXRlPDwvR1MwIDExNCAwIFIvR1MxIDEx
NSAwIFI+Pi9Gb250PDwvVFQwIDEyMCAwIFIvVFQxIDEyMiAwIFIvVFQyIDYyIDAgUj4+L1By
b2NTZXRbL1BERi9UZXh0XS9YT2JqZWN0PDwvRm0wIDMxIDAgUj4+Pj4vUm90YXRlIDAvVHlw
ZS9QYWdlPj4NZW5kb2JqDTI5IDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGgg
Njk2Nz4+c3RyZWFtDQpIiXRXXXPbyBF896/YF1UBKZEGFuDXo11XSS5VvrjKTO7Bdw8QsCRh
UQAPAMVTfn26Z3ZBSNSVLXKJ/cDsTE9Pz+fth4//+JaYff/h43abmNRsdx+SeZKkudmWJpnb
JFuZ7cWkeGhNgn86WuRmZdfztTXbpw/fo1/j2Sqq4zwa4jSJDvHMRmbATxk5cyriddTx4yle
RS62ESf53fVm17VPcZpFZls8HPnYWNPiexfP0sh8jxfRkqf8joEpmsoUZvvtC1/zNcZ8/Pv2
X7Q4W6a0MzGzdJ4uzPYnWFW505EL2xccJ+/gKxu++35q3sO5r709PR+bBh80odL5eBkdih4v
1jOKxnRFhWluag1HZy7kVr7JlPwsj06Nm4k/l+rPxKYTO/NcDW3j2YL3xV64fMVfd6Zu+G36
weFlGL3gurN+KAZnLvVwkEmdeeaHg3+6oe51216mYXilc3BlUQ61rMQJ8nRutnKKG52Y0Dia
ma3S1Y07JTjFzjTiGtcjlPemd+KxQTzGsDetPOhgjjw4Cyqw894cimdxJrxXS1z+2nfc0E/s
Wnn3LTZi1/ZvsAenCab2vB1j0eCde6zCKxIMLf7uEFPzW1QqxE5F56pgaxpdl674Ey6XQzjj
0ZHCdevI/NT+z/FCv8VAKy9GGE+im2RqXrpm3ryN7o+2xiE4FxgfahiCUw3wNBzci2kcTMBF
EEp8In5ubr4QYkfsQaSa8sXs2o6LsXCKqI3PUA7eRKoZgz5cBFsd3PAokKh7s+BgCTTNc476
K5yeGBVX9PFszbBwHzCpaAmTisqTAEnewNHBQ7V44KA+1sOLmYB6YvVCrc6zPB0DueGiDCbe
KSRzzbk/ODrjcYHzCgEvZyp+AT/Rbuc61/BXiRx2w8W5htzwVWhiEh3rwbNeLG6jw9gimh09
MxyKwTiJ0Knu6rI4Hl9wIsnty9cRjMkmnJdLtL9HCFamaAd/ZMRVescbtDvD34eRRk5F+ej4
qH8NoJB3qbX5TTT3cm+5qJPsQf7em8sBtweKapkwg/itnuRMMp6ZWqFwnJiscfS2wqHuzwL3
tNEJNAVsKcSNPBL0tT1QsIwmKegjl6abNY+b+fO8oTzzAnNgYMqssndMnIIpWZG5G+WDVH6R
aWVlyjTlCFvpEfdnKYx9rph3FWc04fCnReKamDi8OAptAMOxMkA/lgSNvGfdNF+sbyP/4Mri
3DtTD2CmymTJnVx7bj5VVT3UbcPw3yui+kN7cUqncHYxcUsg9uX0FT5yUlaavVY18YDcy9Cz
HUc/AhVdmYf+OXPUCUc2e3qPG15T0sOZW45apLifazmS9SfUq/FNgfykCIAApwe28iNcxobL
JPnm1l+DRC6Lmt4A2GW8idoGLmlcOTBjat6vMQWX6VIQHt6cR6dBQoTonYAxlA/4EaIAXzyu
M1XxIty2lDMawSJO7+bmc8y69wqG2ShMbv1duaOv44Mvz81eiiAr1oVnEyOcQ+oonuiIo19M
9ARhgktyqhirm0/it0XwXtDrgCC4+1l9fsVfHvypJC1s94SsPbMOoXjBtBpV8Ay6nOwKxS6x
krjreY5c9nlbvkBYSABYuuZJCs5U58gmyUzdEEJXfYBJ2x8UeKkKvNlV4ckwm0iSpVVXLgn0
OcJjwyDXAavYt7oRUjq62S+AtHjq7zWY5D8QXCsiOo+QUb9ZK8eY/7quLzgahKRYHq514So8
xZhA1lk2YULGmlb9zG1agbRkkbRdPxhKvVZV0oxUsRHCBBDvTcrvLOihplVFBDnXjZVGqlSL
6MujUpKsCjtUUA2tCi6TZjMuOrQnXXDl8HXQKCt7mzz6Vncyg26U47yzvFyjwJubn5FClawW
DtK7tsGYwSu2zu2lQB+LzvRnpNWuK7RAC4nIXC+IrSbpPVaExa1Y3pEKkJ2OyXph8erw8Wh2
+DwzdUpO1IHGG0lpCwVYmGWOH7Me2D+Gaa4Vw5jHO6laQgVCChAcniOEz0xujv7o5rEfM2jK
rnaxyscEIolQktPgk9HEtaKFUWucFg29zEFocX8I5p2cTleS1kXsu5ROmFFutBOdhxIgeV80
L2S2iT0hxnazvI3xnrY888qNUQJCAHzfkdFTzYu45Z2qMKaC9T3YmM0osznYQ9I/+uITOblJ
ZGaMVUacrzMb6MLLA0AJqoEtzIPkLZDWjlB/VAFBESSJKzvoCS9hrhC3I/mqzp2lFqGxUw0g
2Zbg/CRAdiN68/MoGW1EDQRbBpjTjQ/R1rQ72bPQpU4jQ4e5sm3etizL6EFQvpNNNPatUsns
JruB+YP0KxdJcbJ1M1UUlCRLBCSRoPXXfmBsV2ehVjSP5lpzx+lYmjGA6ajwYbOBRdfjbTI5
/p32cPFOd6iOK0W/u4Gn7Ed934ytHwSysIQyRo1oKm+5Tpu+IwVu711Wl7XnRwomTy9Nq0+g
w5RLezfR+eH9U7MDV2/ecXQ9pWm5+6uupHuEghWWK30rq11sV+yJ04f2edy3UUjN2M0ppCbd
xyHA7FXzMX+Hl9PlYqSQT8OkfnTa0wjiKa6hrZ0JZLqKin7SCpl8pXD+KFK36LpaDB39vadD
i+F671sxmm3eEaOfvqK1bKX1IE9ISe1RZlFUG/JD3bzT0eAoyUOkYQJC8jlPOV8eCu6ANEFv
154HPhATM7AURdEt9LwMmPnDJjkd7nLUmD6iee3rffPkIdRPvW09G6WrdHmDiZC8urEyoRgr
DTjSwB/i7LrzRXonQDx35iwx7wedKFjhjf7w0XuCjO8VtyQX/4aJNJpb2HTreFeUB3h3kCZQ
/O8qkqW6nZXL/QGtvSYArJp0FmY8n2CNK1RvMGydK1397PpRr86mbVhmp5raO0QYAvjr5YR6
0J7LFzgpnzAKpR1fT27Oh7/GszX5hDVFIMee6ECXVh4oMHXaBfp42PV6cXv53h2h3lEUd20n
xzwc2xLnPtIqj5d+dytN7Vrrn+f/0FN292ymxGGdE4bnfeRuUm4g1BgYZNYUgMHClf2rolJI
21X5StZKgZL0P5pslKd3Rt6xU2VJxaEbgiA1um821JrbRguddnS8u5ZKEKbO624ggSQwqS6B
9JZLexPP0BUYdgMNASMj9JMxxS+O5aDVxtWs8DHP8HGH2uGju/CNhiTvWeuPlQG7ExiVQ0ho
ySId9e05CJhSSVYtuCXpdPUe+qtRi7KI9KEGMIaSeMptTAKfUi/UWUytVwrVB6PTuXqUq74i
peJ1FxgfnPaKHsWtQZvm+a02rYMfxkKrqkrcWsTX55ICkgDjllJTF74req3wc3ws72RFxRVj
SceftIsXUaN5NLZ91wYwtImmKEOL+ayN4TXjRoCkdiw4E42OxSL0twcUH/wvW3l4YioXHbO6
0qxu8dqNz3Xo8kIFmo2QP8mdkfxk90g3N7OrI1djX5e804e81aU20nwliug5lc9BxlPQvBFI
jRdQCzYILAZskYJOMt/xKMWf/Z07ueAcugVZoCtZJlnyRWSzecg5x33mMx59pJPn5m1fO4HE
2452Ivted7GMteXHQvLr3w3vOOPbDsIL7CB+4bNBb/RI9SN9qwL4nzR4fzBblXHwCPec95Kn
q+iEyvqmiZ2CGXV0EoLMG7X99gWHfjVCAn2r3/xrGZcLVBoNeoYUEpYgLAOqh7DKHIpnCcfB
oxA2Trqa7v+cl82O48YVhfd5itoE6A66ZZEiKWmRAG07AYLEyMAzXnlVoiiJaIqUVVS35afP
uedWFSmxxwa8mB5KYhWL9+fc79jQEW4WxxFPtg5mIc8nbfYDvYjstrv6FmCuqOKWVkWMDPNP
g/VqBqOVPeyDocP4CmdBHcvicB5SLz4PVHymSsSQ4gAXVoXcVVpaqYn0JnkRG2sDYXIGvX0l
cZPKwDrs5djUvof1mamv4ws7YBNtzlgGXh0Zh+6x1bbg8o5Hm872+dfAIrCbzBfExKLbGxm5
0E0TNCEShOrCvziKa3eTtzSavGnaql9P4jnP9SP30Ti3PT6BZLGLfDRbueXUSICvzONaZCZ5
iJ7HD49cxhde2LzLdn1IaS3n0xYvsZTicMRtfN6llXtL27No8IQbVs0DMiwynzXIFmi9LcXx
MTKAXyEhQMhR+vqGClbL3JNGkS0jaVCmrIki5hDqO2Fiw39Bk2rO5Z18OBfrPJKGbBqyth1P
cJkDsuhcqePyYo/BfDvb38LuHDLyzT7WGF4PfzOsm/P+uxILl8YyC3ORg1G1ezBP0yQfzxFm
T72mDhQv4xLBsZQkev5tEA3N9b5iPQ8CMZYNiakzOg1kbr5yrOPDlXJ941gXASvmw+lkqmPX
K6pcLi7yp9GBhrd0/FyWlXM7/am5eveVKb9L0+O/YXHPjvBuTXjn5dMTLWEuH799HINZBJ1V
sZ5248lem85uHbydzFH5E4BdDiisaun+jE/acrag1bTla9V/40jIdopVGDvTjuyVomxjLG0L
/zQ1OsTzkmnstTp7Cjp3xKz94RSRq4/wFHF2Qd85W3P560bt0Mz8WDX1yPgqeMUSWsUSWkxD
0r1RNsbzvaQUiyaLBlA4pEWHG4KMiBZeVW8WQW9wznfUyD/W60ceNH9Yy6K/YsXM/Lu9iV6Y
Q0mWTHGv9W4wwVRmEM4oztfAlOJoed1rb+PNnWmqt7io8a0HRKvfFFOvT8ZduW2ps1/W12qg
EGPlVWxjm3d7HfVgGs1buoxVfqo9wOxlL4nChq0vwviqygQF7MlQwhfyd2dOMsyklqSVXr5D
tP4jNgEDbqvSayS0v1KiKacIapDg+yJnCLPlNKWvVXWyDWraoFo3Utm27KDOeIpOcbTbbleX
8q6cy2rVAnPO/hC5RL3v2Ot5sJl6LiY0LWbrrDBFMcvzRKW1mC1m5rvLGc/D+/YGHPSJp/jy
uPL11fG3Hp3S8Jf/1pAFd49Yz+PansM3jhhr5RkrFIbs4vzAlWs1KHhhV7LTnKs8kgRHguum
5kyWR4+akOdFgdc9y+UUC+7c25qF5BQ0uvH48zqpB77PVynRQChKbffFw9GDgORGPpe1FZW0
b7Zu7AbG6WDFjW3fLSP1xwm7Y+QipqkY9d0NLi9mNElGaND+KqNABv0FITv6bGX3JHySX3ty
M2/5rJNtqR3ShEmDMf8RLEe/9Duw/EjwWIEOqT1smU3Y90JgppdTgbjxblbR7V2OIsOd9O84
JKlZDue84AIwJo0qPMt2VmkzgEm+zYi9B331bDNfLlcTFQPp+WFc0Sve8vmJ9jPO1p08u+Mj
McivxvGZe642HstMAPKxIAfq4cvlD0o+t8gf0HGA5p9cNVhaJRU5DaM6ioy3gSlnxADPvJf/
fMAP8s1J1JNzgcg92l/I6yy3kOzB63LDdrzliM2SJPsApQW7nO7ek5JGRxPBGN4Ft0Y8O4SM
nWSNoIQE5nsanJ2yXRtflEmXL3+Rk1ZtSUPBSSJl4ap+wLPnMZLn8/l6kvx3nenN1mxUJjLB
jV/igK+lizErlBRM1Tp+DdhUHbK9CYKEUkBLHaHhumVvw3xMH/QpN1y29IO1yNYx30cgl91H
vXLGq2Cicsj5IxeKLew1XjZNzRuq4Eq+hiuyxPPbUbJkObz76iyT2UEWVx90TTpfFNNcH6SM
35XspVda9schTFM9vw28rXUs970y76oLuTbVqE2AcYFnmUhS5EatJh9FQD5XozWxKG+sXpKP
Ucpnu+neK9crLvYH43qstRsCGZqia6UbOOJEUBC/HgH9XLcllKeiAaLqW0SxtXsxpJN0ztcf
AJxWikYEz69D6JdMiJ9rowGGUaJTS9OjFAQnNuCjeYs/N8xs5Z4ksaXW3F2CX2NFxWINSV4s
pli3GQoQOx5iwUkdllSh3ajIWFz3RQZ+QMz4W6vAd3ZVA7prQO4D312Fb+KkB+b3mKETKk6y
6Eh/hryehL9EXrdMvyqD1FwbvNNYdi+smg2SRbwTYWHlnoKtY1RGZI3NeanThOb033xETXFK
b+4eTXUATv6BJB7FBtrW+IK7q7YDwymjq32KMzf1M1c2S7JZAeM2FzJ7+CygMNBlMctW+GWu
F9kyn4Gq8mwxk3Y9/gVqgmpQtBgDWegQnJeOKJFL7qNX2Wo9y1JslM1W3OhndGF/gNLtQOod
pKJupU3IQdPxlaQ5Z+xzAqSE4vrCErAcjzIt0IWPTfkqE4dhbrxOBN/rBf7vJp1zgfubH2Pf
UPcnMfOAJU9fLCaBSz4I3DqbLU2+SGarTF/3KBWG2E0ZKFBikqp3vY9dPl/NiuV6je2QBm6H
XnjZM7/MNg5yi8WLdarhWs0yNOMoXEdtZrbwMBTOscl9a7LLXDW0dhGkv/e65QdVFy2ul6D6
t0pESGn4rjOfjHd0IkiepIdcxzDkw/AqI/OVKqIpaYWD3Sm8tNWIJuwg6mw1nGnJq9+giF+p
Aimbvdyj9ABmLMkHHC7az9l4GihHywgrlhOdu1MwRkfjJgig4/9cMVIamX5mfnLqIPbR2b5L
hJQOXOVVG7simj5BY8/hi2CYVml0HYNvdd3lXApNAiWRa2wL62nNOv9WJxeaJdrMLK6njieL
Wbr0cgEc6w1gGUDW9dSx/+3ACxcoMY+Bs48yGnCEIZNy1J2ClMl2YgtoRR+p9AmTpdPdgc5X
HPySRMK+UzJoGoLb2ZKtZUXXKq3FUhAhDTSLbwCNJGTSjqdmlDmJ+TEfZzeNznKYD0cfbl/M
bB4t68qzhGa4D8bTaZbYWwJvOiel0EKfbePvTe2HmSmbTlpO874s+N/r5jShPK+1aZYm8Yg7
KblM5zMICU8yrKpMqkqcCAeXllUqU05gvOcaHjvTJn/5xKS+YPERphOJWKOLaznCMaAAVmz8
gq/W3O28sqfTubMly2OrCq/z3lXnt7pEpnF8YhBjtK2F0GV240/bs2jdnzG8y8Hwpr9neNM/
bXiT4tGT0csnF6HxzuMG5F0vsqnHFba2Eo8EOxVSEM+UOqHctq2a4FIJv2omz6FXpC+esHrg
ZSXIYqSbe3VOGxsM6fW23sW/6MxIp2zrrm15wEvKlsyKmCaDV30yFfIpX7+PtsoiBHBaJ+ms
SBdBOGqwigSq7p3p3lvthqa7bA3aNqb4VmojViQLryC65Wig/VPOofvAd8FzqQq1LLPyWjY3
ZZqH/ZiJBOO5SMMB+wNG3P6gb1aKtZU9rCSBzrLQTQNN3kQvyYpED6hbjiXuHW8O7OeWbDhx
VnX7gb3IcqYABLFehlPtjaynhzhzwu12dTn0S4fXPTs27ZcDlMfy6+7S9hLOsa75Ds3ylaKU
PmVMUio8ifxNkyA/nGDOjJzEqRtpYV9bRGev/tU5s7Ht9l2No/cYftsbk3CTjCTRcrljXKvF
HN/UiqDtkc6zZTV2460C1SeaBpTJvChCCB3GG0zXSwNP2lqJZP1G44A5KPNnomLJUqn72e8z
CtLmUjfqdZkWtAYcRoX9tJ7rs/i6C2r8g8OtEoLNz6hLe7I0q1INlTSAq718J9La+La3bdVd
XHONqnKns9Nu1ZMgSJSTIgz2Cg0npxJJWEMRpLLtWxXGtZOSAT5D5GSyQ5b5mYZUwvah5mqW
7kX3ZjzhrMVHoguGZbn+UIPOLkfzo5Vcfn+BgfluaNc7fxHgcJ7PR/MF1oSbfvn8wycxt4J1
qEPlUKQAHGrYccNvtq87nWEy4aQkMeVuByGoVien6jL81fm5707auh3H6VVg5AOZWvyf7rLb
cdSIgvC9n6IvZ6QdL9gGY2lvVvnTKpGiZDcPgKE9a40NXrBjzdunqg402DgX42l+uhua01Vf
xcm0khtsib6GC5hdK3cGhVzr5g2htq7afenpAiSTjPAHym3eWBZJFAlZOnm8zYbJOBt2NQA2
kmDsK2DZ0eqp2hd6bVfu8TL4qE6glJnAeUfT/7Jz7MqJnknv6Zjj0l7XN1kAjrzxbkzN4wBL
N3R5OzonqhOi4SNUwp7eik45TQVHQqkTsYzXr2Jw7C78+3FRf2/hjj7H+we/tRLZ9FiUbaYf
oeeubeAu9xaall+4Af71zbt28qG+uqvh3CEky4johzxhytdBYcfuLBb149FV7VOAxcLmOo/W
tI9qaZJOPqIFlWUXVJYKKnh2LsLOlco4vGzJxVdMlk0eUJgrrHtbITPWF1SZ455Ke/9SFWiL
hht/P1Oprfml0v3D0/besUzTUAA9RqfE6PQJ5Yohd8M3D09w7r70CbC89Ry4wEx1teeCQqx2
XVkAB3kbiSP07RZ+aTXR+NECdrCxSNbp9HN7uCTGKPhj1TV3f1ZeFfPCNcgJWW8Md8yTV66D
L/Hz6ks+JK9iw5y6pNio1xJHkXItj1pf1F04LBVHQ/a58ZJFtowfKDVKGn6JooGbreVmJRXQ
gAXb81McDaK/DOoL087QiqyxWqdz+PoiWs3JR8fZ08uKinxj+IssMU/kBlZfa62yGCzl4s0G
xMLO8KWdqrcJZq3SrrExhriCXV0/8KN4uTTHTObrGz7r7NGyYtWbDvSBomf8Ct3ZXs5KsVr6
NYsDhcGMCeviAlW4cpste6hOHkluq9pU5alw0Nt9HdLgufusJZig2zEq2VykbU3jLUiXNs1W
GzAwNHQZxxHWJ1Hv0gLr3H0zVcXB/4jTIpkUw8NF5kZV8GNpeWew5RuB1juVymQHr6gHxjVs
8imZnRvTvZbprTVxotB1QKdrzIZjpu2lKU42YbObFNrAcLHzJUjbATw8zGLOa9ObLvJn3me+
zzr37oyl79/atZql1uAHnXdGSf0NudoHJdehGlab1WJaA/cP5aTd7jWMVoUWxNPbdGPJhlzT
SQeNd3Xlx4s4hmKmmkEuA6UlU0obCTYG7gqI/skjhbpMUvzBvXl/2tPBsRcOzKcS6mRsCfQr
/j8E21SIwrN9LlmXHD/MU+W8jX/s8+FO43tuW2w2D3BcMll6i5qS55a/1euzOKmXTAkiFbJQ
fqW6ZU8n3lma4RO8BAy9bDrdqNblWaQGKVXK9fnxZsuH8BZNBdU4F4tIZ+NYsBK6C8XEYipp
PbdguLBa/On3Cdyi1u+Zdti92hzpGLnSnmkx3Gru/uErnvmyRzyHqujMT+3+6Kz5yB8Wyos5
3s5l1JEF+8cJWvMVPyYv/41TGqGUTdbtPRZH82UcT1EYJqc9Y0UmE5QU2nRt8Z2ny4v8ji1t
KwMC1d7a7BbMSPscoGJEFMHhddVta50YC0go/8V68qVahkNM3gpCBdy+ExCMD2kJfG4w3uh9
WoWiLfGVDWkbDs6+Q3VLLeAzdOexTnayw+f65dvsxyw293PA2Hni4JjFcfbxt6+xe21nH389
Ru7nevbX7D8BBgD0tQJNDQplbmRzdHJlYW0NZW5kb2JqDTMwIDAgb2JqDTw8L0ZpbHRlci9G
bGF0ZURlY29kZS9MZW5ndGggMzI1Pj5zdHJlYW0NCkiJnFLBTsMwDP0VK/fRVZOmIbWdYGgC
iaFpGweO2eJ2EW1cpdYY/BoHPolfwKEtYhK7cKn9nv0SP6ef7x/J9FiVcEDfWHKQgoovhgrQ
7chYVwTicTMfTBRMs+QWtUE/J2L0a2SWhua3dCLSLJmTY3C6wlRtbIXNA76sqNJuuR5cU2kW
GwWNfZNqPJT+KEtmVJKHbaoCBt/Foo1SX2hfWAdMdVcqMee+2xZ7yUfDcUBbYqZK4LhVXtU1
aq/dDqHZe+ueRaUgt0c0tcBwSGhb6gJX2hUovk2qBrFMyNpzm+IBnQyrgIwJsRMA5XmDHHyP
LoPvQN45g0fIyVeau94o8Flyo1m+C9nN/qQeSeX1VPEkM/8w3wNGrbrdf5bci38h2zBDx4GM
+mQVViK4j72qfbcz6n84Onthf1H01/+SfQkwAHGWxS0NCmVuZHN0cmVhbQ1lbmRvYmoNMzEg
MCBvYmoNPDwvQkJveFswLjAgLTEwLjAgMTUuMCAwLjBdL0ZpbHRlci9GbGF0ZURlY29kZS9M
YXN0TW9kaWZpZWQoRDoyMDA4MTAyNDA4MjI0Mi0wNicwMCcpL0xlbmd0aCAxMTIvTWF0cml4
WzEuMCAwLjAgMC4wIDEuMCAwLjAgMC4wXS9PQyAxMzAgMCBSL1BpZWNlSW5mbzw8L0FEQkVf
Q29tcG91bmRUeXBlPDwvRG9jU2V0dGluZ3MgMzAgMCBSL0xhc3RNb2RpZmllZChEOjIwMDgx
MDI0MDgyMjQyLTA2JzAwJykvUHJpdmF0ZS9IZWFkZXI+Pj4+L1Jlc291cmNlcyA1OSAwIFIv
U3VidHlwZS9Gb3JtPj5zdHJlYW0NCkiJMlBIVzBQcAfiTCD2UoiONVBIAbKyFAwVyhUMDRR8
gZyQZBAB4gKpKhDbB0QUgYhiLqcQLv2QzNzUYr/U8qD83MQ8Haf8nBSQ3pA0LgOFdCDWNdez
MDFSCEnh0jC2NNdUCMnicg3hAggwAA4kHXINCmVuZHN0cmVhbQ1lbmRvYmoNMzIgMCBvYmoN
PDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0ZpcnN0IDExL0xlbmd0aCA2Mi9OIDIvVHlwZS9PYmpT
dG0+PnN0cmVhbQ0KaN4ytVAwUDC1VDA2VLCx0Q/JzE0t9kstD8rPTczTccrPSVEwBMoYKATZ
2QGl3fLzShRMLSB8gAADAMXED2kNCmVuZHN0cmVhbQ1lbmRvYmoNMzMgMCBvYmoNPDwvQ29u
dGVudHMgMzQgMCBSL0Nyb3BCb3hbMCAwIDYxMiA3OTJdL01lZGlhQm94WzAgMCA2MTIgNzky
XS9QYXJlbnQgNzMgMCBSL1Jlc291cmNlczw8L0NvbG9yU3BhY2U8PC9DUzAgNjYgMCBSPj4v
RXh0R1N0YXRlPDwvR1MwIDExNCAwIFIvR1MxIDExNSAwIFI+Pi9Gb250PDwvVFQwIDEyMCAw
IFIvVFQxIDEyMiAwIFIvVFQyIDYyIDAgUj4+L1Byb2NTZXRbL1BERi9UZXh0L0ltYWdlQy9J
bWFnZUldL1hPYmplY3Q8PC9GbTAgMzcgMCBSL0ltMCAzOCAwIFI+Pj4+L1JvdGF0ZSAwL1R5
cGUvUGFnZT4+DWVuZG9iag0zNCAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3Ro
IDY4Nzc+PnN0cmVhbQ0KSIlsV9ty47gRffdX4CVVUkrm8C5q3mzPzmSy49lNRqlUKpUHmoQk
rilSQ0BSnK9Pn27wIkvlsgiCQKPRl9OnH9d3H7788NXW3H1Yr30VqPXm7t73fD8I1bpQvhfG
GY3OKqDJUPn0J6MkVssw8/Bxf/fv2bfqdX4fz7T68uNZtRh282imHtbPqtB1bRbKdnmDebOf
B/6sMqbiZTyn2o06YVDNg1lnjxjmdf2m6EfN/7P+6x1U8ldOpSyDRr66D7wgUetPdH7TdiQ3
pF1qp/NSd6pqNv2crdpmFIMtImYZ880CukVK4tYlCSryRr1olZ/myayt5vGs1PNsVqpNSxMd
XaazNJnPQ+jqk/rJbKJhIKL9dBlB9L2TDUXjWA445MWrtmpTt2fjqc9tp45NVeTGqvl9Oqur
5tVMdM2cwGWQsq6hlyW9qtCIzBfMVK7m6azMRTMy+6amUXum7wsFDVtedcjnqxmrr7B1Q3vk
JHa47xweRFEsuvNZzsY4z+60en54wlmkNf1+/2WNBxl8vpyV8/topjsDqRWZzKi8sEf2YqML
WqDJt8bk3dtCYX1DipYKMic6DPbDmWe1/vNoMJIrDg3IoWyr3lUkzCizo/sOZhvk+JEzGwWP
M1ujnOfuw5n6DBdv6f84R8iSmbRa0tBTj6RfizUw2I4XG95YasMm2Ayuv7BfGCVhbz86dOp6
nRc7tWsPpCyU7uZIGFhg09YUDlWzncpLBnmJu8MqjftLGJtb7WKc4/ujMu2xKzQC/jrWs1U4
KAUpE6/mTcnRow0uCnNwTOX9G6VOjgzAZIkcYCMZow1dgcJLYyFCre3o5xWyvn5aKEM+z8iq
tAFSsOjtIlcCl80CL+zp4XCEJscs/B1NdaHYIX2Npkj+ecRvU9CPVs2RV77ozlMPiP56LrDi
vBfwfkMqTbLVGScI/QmgwFlAlPf44aKtwpmIhqI+lrqcSOvzJ0T0MaxM/FWRFdWp6pARhFBk
OgYpCWr1/PWJxE6c38vKoqDHkXduK/K6IJxMZjXUw6DBz0dV4qHJ1LW2ml/UpuMFe5xhd/xd
HfDIYZjilWesesHzjbJ0WCSYnQCzV7PKWmRdxTPbG1kbZqsbuFxq8RmuWtU1mQy2sOSYDI4h
zMCnThe6OnEGpLzJU2s2ExsNkZTXU/ukcmTkR8m163bQk6oAPzqlGwzMEb8dJa/l76RC0WKw
x+XoI3maFxIYs0VTeVUVgYslzRHSToZcaNBGaiUPo+jKBJWUPS0PDkVbnaRaQpylW3IpVK5C
llRceIIrpZJbdG1nFIXKoa+tvMKSt3hQSMYg7oPpFk/ik60lKCI1PFRh7Hsrlax8V8Np1/qP
u1/Wdz/vCHK8OEZIx7w6TLwkWa1WyxRlP0mWtIW+Uo0r9ncfvu599am9+9vd43pCIiYHZSuS
xttIwHASLQ0mfKNPRo79G3Qj9RKQjtCLU2Ecn6vtsePYWXrquWpQc/YUJKZu7Ue63aOUphvF
xR9qKW7kEhTpiHBjeKGdiL3i2FX2TdnW5rUn/h4vOC3PwSpw9T7ywnAJ7y+jVARThUdJ7CFs
u7MOnRgO++k9CuS9wVxT7ABsnDFcvEu8gkExlCEvGesYLSseUlguZzxyEQWhhFEsFYTAMCHg
0j8aBLHKBon95XUSbSCJdEcK5JIJOaAC6XlmqqI5wbYcbCjmvIaUznyMQkoAPL24nz9w2okM
jezjbKq5sAB8IIbwQOWo5uPpFhOTZFs6mwfLq1QLAU0xfh45DTgnwHSQXfT2+1/+5QiLoGQH
dzNEfvr2DSj84envTwKNyCPGV8Olv0fEWjdbjOxuRH4H1lEYZkMpaze903dCKnD/HO5lT+Ts
4FxqidTVyWLg9ANteKKZXz1s/WdfQ3fC97hapLPgcS4Xe+ClCwlgElZecpPBZmF07ehOM86w
pU5DVajVxHT97Rn6W7LMWZnjQQoNqvSmPvLqicHIkAu3jwCUaCAvOBuVDe6Z+uaK4ydZcOVe
GBC5Q+BHDozBMyMyYOwIcMDVmvB9juSgSNpzHocc/hHCPyJe91miIpyBriiQuCPesAL/93x5
GmBj48ghdu6IP4PSvGK1xoxZQEI+oTS9mZNkpK9BSKvEUYh9ym+Q73MNm+tyy93FSJdgTUwt
ED754VA7fCimfOwwT7gDGcOpdPTkgt8ErkgGy1tFstS97BMHHR/LLE8NPExhzn1muEoYZIx6
hzBw4QgxCyXtwR9HY118tidI6lRAQlb070MmjPFC/we8UKXq2xH/yvHrnbA3yelOH0YeCrms
q+1X5Ooi0dC8WRfgbr8zX8nmxMxLn15UgvHgoMHKnHfKOumZnIwlvSzx8idPjSWWHP6+uDFA
BAM/SNPJ5VK5HdWvp99Iz+9I+W901j9+kFW/kg6/fb+qOkMlFxlRBhly6EVFiqWLuzDjJ33g
sGthHvYkcLthy3HhIL4MPk9Lzrgbt7ykFHWkIPKGm14Kja1a/3imid+dQ3bAo5MGaifSdjYj
muXvqo6rwtEquFF0bCVEFbmhzBvToWLH8SX8KX9hkiMtGI+1tUKkmRnpTli7PxMuVaBJ4v3U
YN0fmCKdsX6kkq4KJsssvaavDuOoCzwzXHVzxO1YFnB7xkxeqYZXfO11JAmaKG8hYKhPIhM8
D1sqLvOIW75vQvcVut60RzrkVkKHyTIe8OV9AybJm6AuBzMuHg/0xk6YlCO47wFDFA6FVEGm
IC4Q+91CvUi3hsYQKXSJQRQBuTLSm3GzNdHRmTMQHnfp3py3tMfGMihsKN1EOIJSWSEz1Ha0
Sv/3MGFufaPmR5lrrdJw1TO3uioqW78hXIqd6yDsTnMkZwhkOrF7XUwblp74LFdp315B4KS9
MscXY/PGVsQoc+4S2MC2+h81MKQ12aWCxiCdFGKGOY7JT/SVAFqTs7lcpAgWupL1JhbKer5w
3S49vPcTgmN0MPLx1Xkrct6KyFuATscdKRN3SpwC1IKUs8tdVXCiNg0jP8dqy/DrIHiInMUI
xUQZkvjakWcGZDlsrBZZj+woecBzYoA0iN/dQiAFpUqwAdro3EjpOHTtieOhpBzvK1Tzyrl0
vmRBE0xxrCG40YFK1lGCbXeO85FjOSururLc8jqeMmEvnf45zFQExp3rejljCX2MkPOeABE4
dK89AIxESsNfcqoQTiW9XnCLm1FU3siYfS4nW/ck1szPppdfcC9JWto374qShn50zaK+dIgC
eH13D4DKjbQbcEt7HFIcgcCwyvPzRHhAJbglJJWDKleSHshcCrBGKnXGzEBthAm89BLLizgb
9A2CkS9BgXarL9hwd1M5YbrqWsG+UGGyeYeHj33nJdtcrF0sUtxwTSBPj3R6Gm1ZvFpde+xl
IODnwVh958am2kiMBLgVDtoeOaG5S+yzJHVZotoD33/C/mDbxWhzlmRu11g/86Mr9xdcA/d7
3RUAN470GJEeS6RLNyDVlqgAVbG80/15PkPZI6/mFSWXYymxW2Kx3YkFFZS8MklYfs2P04m/
t1wDOBzNe9ZQ4BPxWleW+DOYSNeMZNU5v3GNEa0v+7nNhqoueDVXxndOti5AyOYi7KJjCh1I
h2mQ3WiZBlpQcg9b6B4QUscWgFbcLPFS8uPp/4SXW3ebSBaF3/tX1KO9lkSguIm8ObaTdCb2
aEWe9PTq5AFJyGJMIAsha9S/fs7ZpwpKt8yDLSSgKKr22fs7ONeu+0vYERIJ6PcNH7ZkQzjY
IDJA/yUJsMSPdX9G7aTe1+6GR7bgk/hkx2W3frbFUvamMxB1zQHTtflqVS6wwSAodH/MVNg+
6nF6uqXhgwB+Emh6UmQDmLiPJLLkDoCWutuYXoTfbEvekvJGhVej0wIKgiyS/JXxnPw9snpU
RYO+lzfqFTnGP+bPsvTcYLBP1CYmIYcxZWIQyPFijaI2Kskk8dBHNDlyTNqJtzaQMMjzUPem
oqLsTBrS0jLZBFdzgCmtJJdM3XRcXduyddeAT9LX+hRA/ThNzeKGA90s1axCotCWLNUNH1X8
voKZvNSn4FkjbKpiWHEbCH6Yarvi4SHxdDuqWsXgJJKgNVkoQrSbio6ade4x9E9hSCkbEr1p
3jFVG/qmAz5xkkFBGOgTSQ7M0O+xNW7H2paFYwhEVTSR/7qXOjiKnSyEL+cACqIxfMNGV+5l
jbSDi6YyUTU6TGS3hOwWG7oSESmYs5KyjMWCeS4eR94JCfs6Og3hW9NlQsRtz2t7+LhdAG5S
a1L48hgDI3ag4EqoaJ1z6wWwoL03bR0H8/IVoKiHSqGLaBvXxZ4X4AyDBGGU9cZspbXIqwVA
qKJN7wHnJzRZSqtFMdL0vMShweLA3Uv1jB/zVr53RaEWuLaqyk0pjc541RaFy+eBnU4WnukR
xbHoRWguM14HkiWwkZERdUgg4tSXHS0KQlNffpLY+pJpldTMZIb9Vux7ptnjxhF9BS6qhf/q
BvVVbM5YWpzo2BYYP8UpsHyzYRU+10AO4y1jBjA2MwtHOwES6H5kVdYjxRnYOUIqlgkNsJNe
gW9ZF5DXWW42jZWO9GlsSH6vgAut7DOyyCS/hyx6bPAFFKxwEsuHWTPsrnF2wwARaEMQC/yY
40ZeePpNVh7XlOKghh5a+dxQEFbVXoY+0Qm52pmSnZdEtkvFTWCDuZJbskXVJKAKfRy0kpNc
63zYyNiOGWem14yi3o2fyey+aZ1wGWA3UW5bWIwptk4wjXsuVjrJe1XagsXVB+3dsBWJ2Yos
iW1Pyg92BPRqO5mhfdkrCFXWfGnPb2jZ5of1KO0HOTgtwBSLfdC9iNr11UvfAgFMPpKpv/bX
tSPTKDnBYsHDj2DyOvGyKFFJQpKSSRuJamqBjCjw8toQHqAM+Nry0RyIb+BODzwcC8K9wLAP
JOyHfTLb9NSToK/uFo5lYziRGHY0wf5Zdoi9DUmsQMUdO3igRQtjM7izJxSQPCrP+CewYW9F
Ie7eI619YTMjum8hk9DolPiP7yAoNzri0ZTJSYk6nC+E9dc5vH8Odq17+ncVHPjppDdzWWeJ
P3YP3OapGQh4lbe91SyKGgYCvTq5FNtcSodYEno+3KHNkWmpnsaGcU6sOUx0dtqoFJIYcGGu
fsUeDTzl8QI5fO7luXQlLfxN+9G+sE0PdBRcGUHTROb99UVNENvgjlp1jUWq+UGFmpYgSqLI
CUkEoVQkEZfogdMIxWhKknlvzO7c14+ZEFfrM47o9dqiKs1ArIYRw9X4JyYDyBo0b8ImCrMz
vrcjpROHsvvUdbHoSmnJyCvEqqlZ2eTtXq2a1qQlFbxxanMJHIE9K2RHYMiaiOk/Dw48LElf
h0cbuN5i602wodddbvreDEzDR5zaEokIERtlrK5t39y2UhaZlEVRv+IOaLmWcgPkMBV6DrCL
I9Cnzx+xn5K/ZplK4sybaI6PH7/R6zz957eAOU2uw1FI/pVEEy8cLnnz9BQoumUlRC1+Le+b
yAt/uX9//+WeJvnIeHc/k4Wi+3xzH9+S4CmJPEFnnjMJd2/lCTt1dmLBxGO//UHP/Cv4zlKe
efT/Dqb9oaLc41ocqS/eDX16WNeZaE4DH7d80LIJbBDSg8htpPo6MXYa+b2dliNFz5gWm0Vj
RPX3SL1vhQG6smhpJ2tHHtrqNOj7PB7NqpWHnBU12LXl/wyNFBf8Fvy7ASV83ducKLDdlr1o
cbUsrhiKfaKewFD+YkCMybWk+IF0ZKZqJsFIyYCIXHTb/qTt4Oql0z6lvZoOFD7b05RIez82
xzvd+3DoBYmW9eP2T3SkHT3QZCm55ILAnPfdV4r7GpM+youp1syGfKNbaOLfrkfqk8F17fOH
H/N/6TcDP+QvY1wqpz11VCSuKuNJ6qWDKh08kVlkl3RJDSwfii41P+e7WkvvCpd8++bNbrfz
jBXTenfSCvwAA+IGUGWPI8Lbv5pqknlhdKGC4ii+ONN44hGdy0xDU0HqQ84+x1XRlpxoiGGu
IvWPLU1R4weioAf0elRU7yhB2/I133R8p223RuqpxOUc2GMoFxm+GASlLTYJ7CFKpmhMA2pM
yUGoN+VgBsWTWic0VnhVc7NKrk26faTYpVhgM+WOgEF/g0cfVQUWJHa8kF47tuqZoplYeOds
SntBZnV7JFuoILRGkfqSQV4Y9D4xY9kV/M41DvcbRRq8VCJYBogq8vwetUfqM73tDS/zSN2y
QOS4J7SxYzHiLpmn49SlM82+5LP8owPJH0hIp8SsbhZInhkniYMkvaiigPLEqij6zhK6pTl7
QNf79rmoR2oKT/6ak7u1/K/c5/Tj/d3Nw83t7K2aMjix5nfcmrSnYE3sOVDc/Qq9BBhRAk/l
hv9gmneF7UJYdOoGEmGOg9XzFQ+GI8GDW+lHbhaMBGrKmdEA/ppFg5ylG1YNmpfYTf3U7JoW
5MbU4OMTgUD1aJpQfjYk7JDhGdceei7xlpRSIrU6+J03755Hur9XT21ebzxhCDSitNAPOJzz
2lOOXDNP0/efTAIgv/iM8HqPCEW9VBfkeoOrpvTSZKr8Lp+21f46OqXWsa1jUV6WRQe5Bjej
DBcbzuTrOOOPkKBPXJin/wt3i9LY+KnrxHbxk+iSLolQjSuSLmNeje+8EH946k+iyvdYv1lZ
IcJJjZ+k1yuIVod3TOxjoD5qRv0ssetT/OCsSa7wb8Qv8a+qa/Px54Z/2Km7LTq9vbrdL6oD
hE5ta9L3uDysU7FUFWpXCiar2WI90P1WCFsa2VtQC8cIIW6lpkiMqioFs7Hm0t6dumHf1Emc
BokXRaHjiCkAacHyUTO0SZTyvEA+/ZwcaQlvFQ3+mgz2atLe5LalZHlvTVTgTw708o6bx23F
ZbMsqB1L+SWjq3/Sg6FiTVr0eSF8Okj4wONrfimfMPQSfRSOponxM/9iOEZakyMa+SQIx0eb
eOrdlv2gJRKc0qzkNw6+plZfysVL4XQpoX1UYEl2Emq70vU8X7wgW1mZedcV9bpZ0Zuru+bv
on0Lv+odx4heJ2EmwpGxHOEYBZrt27EkImmbyBbzLqdwhycBgYvWoqVtPEjD5GDoIIIhYp22
lgY+519HbMTVedyPUa5TxNKtv0/ppWaPxlh5H9Nz1mTdFXu1U7GXDpUHR7rNQRdzMHy5fC6Y
SCQftRELjfJLxAsz7eljZzEtjRdM0ouRF04CL7baSMVayD+m8GBqPDqGpwKe8rGsKvQLt1uc
rHhzv1KPkHclucJn3MIb1Te3Dqx4UaKDPlweimWZm5zilVzJDv1xPZ5Qb5pdScPLZxBDDEXI
oIwjiDqe9uVCv+Dgg6YtSyaOEcSMRq7tW2bzjQjNHY4IZ8auhHticE90zjJCbceKUgM+NHxP
Pu/yqiuvxylF2eQKptr2I49ggA938F71iLOvnoAy2wR9pVH5w/t/9BzGVEYXDEIHSXhRBBGJ
xIpgAoPg5wkWmy/vtkXXcUHxrn/of/7aG8mfBZvrCMf3nroBxKBvRQkCmiNznlziY04w9W/6
ZXzKIbHDIQ80AECR3fMtKIj4GWlhWYQOYAVEPEUOBJoz7RTq4F4lPH4MQwIzFHFMX3s6HN+a
A46M6n+Ml0t3m0gQhff6Fb0U58iE5s3SkR+RYznJKJmssmAk7HBsgQYkZ2Z+/dSt6gb0SrIQ
EvSDVvetW19ZvNoHJqNpgo3wqIb8inNmG2oKO5xoTFIPbKcHfgqX3pBOor62p5dl2nANNN6J
GoqmmTMkNbqSPA8zWl9yYr1hKDzmJf5Ancys8XiHGmWF2SRf9THcG2KkLSB5adiHynj6YUKV
qhe7IryT8iS8dLN4SObDXKDJis4J1KcK1k9lJEk0Y4neu+qKVx6OvxeNHB/t+sQ4SUL5/l7S
warNgXzcQka2ACuzTuoKpUggSYTJm+gDQy6gmgV133B6YUAXVB+owNir7+u+6PvF6adnTp+S
b8Kcj8csbUVJrqs/T1pdYF8vh6ojN0sPpDGbTqcPyoMxH6amQ9JJqDKJ90hnYKjiccEh6xiX
fIf560pShuSG3UTx0xltLglDyrbksGw7VkgUu9GRQmwKMdn4pEDCyE17gWjvGyKcbOYWZRHO
cE27jk9OZrQi2rnqjMsmnsKBj2SWKLD5SHhvaZKmQDVXtWhGt5J0sxDsLpCeRD/VZIjGJnIT
HWWdOr5UK/F9cp12m8tdSdiSM+iu1Lzcloy7lFN79lXCzwVeOFtvuH25VfWj+uNmoEdbA2nh
M37jjKvKgo6hgd8VDZsF/veyUHVlbTwFvfigGgpHK85Y/PUZsj2jQZtCfY//pA7cJBnkXJbE
kiahoOO673b6AV/zOczid2SZuaghjwC8r9i8+ByBv4eJk+VH/DcmdGzqLqd/v8GlMlzFFA5w
A4D/VJoewXd4IEy74354Fr41kZk1PShTs3fdSQI1RgVzaP7iFc1d2n66/cFImMsy/3TVW+7T
/MvAuODR92wZF2xlhh4n7Igia7acf6DYek+YFgjCIAv7LEtemW/Kqn2m0KCTyjCpHm+a+rWg
BazwGvVpN5gl7GaxeSkywENhU1KtSOpcFM1rSTorKzW7vr7uXcXXdrTg0oUZPzy+FDL36NR8
/HDJB3XEv0IOiQcsqZDcHwMLQ1gpXc+hoeVwWjEbWepmWYdoFCYvUrmALWkPv/OEGwoR9bUU
HEUzhewwxju0D7j2vJA5B9Y4q6TObbdNmXNNCxle8rNtveZH25Li8EQUSH5J3TTqU/VCjELd
NPJjWbbLmnLYpZUz9ky26Wdi1gSKyT4oBhLLJyVMeOiFnYQdPxtrJwjpYPx0/M0JoEgnQAEb
EIS9R3uJ9rUTkvvzw4XjR6b9I7rmTuCPnzH+P/yi25RE5qem+xXmkO5EYx45ODW9YE6+FBjT
oI90v+vfziO5fe0EiVz4lgdK99t+9huM5PYK7a94D9+2aKDu8RD7zHFHqZjOfllI+eAWGT9v
GXolmtn6Pu8aY0ISzu+KHB37VD+3zaV5XONxV9PCiB+xEWO0v1JHfL8MFmbCyU+i9IhHZ8Du
xwalHKhkt+TvXVOARdWXVt4C93gyVLzHMMUpdnUiBpvtD8AXA/gzWk8irNebOZdhCcowmMth
5up85XBnZx8XD8z34tTHfOt1ceil8h62yWmOhM/G2KCqXD0VvMj5pYVBSkKJCZTrz6O/R1qU
T6SaupEKYrVcj97cLrR6akdvbtaeuqpHn0b/CzAAC0b9Vg0KZW5kc3RyZWFtDWVuZG9iag0z
NSAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDEwMT4+c3RyZWFtDQpo3uyN
wQ3AMAgDPZ4H8jjswigZhR5VV+gvliKsYB+SZqYjKY2bU15bqTMjeUeHweILuoiGdzbVZRrY
yPFKxvBblKKcaZNmt1iVM92UCXZijoFeUBYBfcH1Uq+u/tUjwABkzFBpCg0KZW5kc3RyZWFt
DWVuZG9iag0zNiAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDMyNT4+c3Ry
ZWFtDQpIiZxSwU7DMAz9FSv30VWTpiG1nWBoAomhaRsHjtnidhFtXKXWGPwaBz6JX8ChLWIS
u3Cp/Z79Ej+nn+8fyfRYlXBA31hykIKKL4YK0O3IWFcE4nEzH0wUTLPkFrVBPydi9Gtklobm
t3Qi0iyZk2NwusJUbWyFzQO+rKjSbrkeXFNpFhsFjX2TajyU/ihLZlSSh22qAgbfxaKNUl9o
X1gHTHVXKjHnvtsWe8lHw3FAW2KmSuC4VV7VNWqv3Q6h2XvrnkWlILdHNLXAcEhoW+oCV9oV
KL5NqgaxTMjac5viAZ0Mq4CMCbETAOV5gxx8jy6D70DeOYNHyMlXmrveKPBZcqNZvgvZzf6k
Hknl9VTxJDP/MN8DRq263X+W3It/IdswQ8eBjPpkFVYiuI+9qn23M+p/ODp7YX9R9Nf/kn0J
MABxlsUtDQplbmRzdHJlYW0NZW5kb2JqDTM3IDAgb2JqDTw8L0JCb3hbMC4wIC0xMC4wIDE1
LjAgMC4wXS9GaWx0ZXIvRmxhdGVEZWNvZGUvTGFzdE1vZGlmaWVkKEQ6MjAwODEwMjQwODIy
NDItMDYnMDAnKS9MZW5ndGggMTEyL01hdHJpeFsxLjAgMC4wIDAuMCAxLjAgMC4wIDAuMF0v
T0MgMTMwIDAgUi9QaWVjZUluZm88PC9BREJFX0NvbXBvdW5kVHlwZTw8L0RvY1NldHRpbmdz
IDM2IDAgUi9MYXN0TW9kaWZpZWQoRDoyMDA4MTAyNDA4MjI0Mi0wNicwMCcpL1ByaXZhdGUv
SGVhZGVyPj4+Pi9SZXNvdXJjZXMgNjEgMCBSL1N1YnR5cGUvRm9ybT4+c3RyZWFtDQpIiTJQ
SFcwUHAH4kwg9lKIjjVQSAGyshQMFcoVDA0UfIGckGQQAeICqSoQ2wdEFIGIYi6nEC79kMzc
1GK/1PKg/NzEPB2n/JwUkN6QNC4DhXQg1jXXszAxUghJ4dIwtrTQVAjJ4nIN4QIIMAAOLR1z
DQplbmRzdHJlYW0NZW5kb2JqDTM4IDAgb2JqDTw8L0JpdHNQZXJDb21wb25lbnQgOC9Db2xv
clNwYWNlIDY2IDAgUi9GaWx0ZXIvRmxhdGVEZWNvZGUvSGVpZ2h0IDU5L0xlbmd0aCAyMDk5
L1N1YnR5cGUvSW1hZ2UvVHlwZS9YT2JqZWN0L1dpZHRoIDU1Nj4+c3RyZWFtDQpo3uybCZvb
JhCGJa2P2pZkr6Kut22uNk2bpnf6//9bgRnELQHGe2V4nmzW1jLAp1czgIa65qWiUs8XEkgq
tKRURnkeJqNtV/WzGM8VJSJWiBVihVghVogVYoVYIVaIFWKFWCFWiBVihVghVp49K83NKnBl
vdleKMT6mx2xUkojHysN7OjuD+uN+K9u+ceuFz9r8Sl4e/29niz6eAgaO56qICu8a7Ie//12
J7o34MeqO77il8Zvr+JX1HiKSYSGb3f6CMUwGmihweHFm3Q0uvNJFK+R16+I55ndqa4ez516
9o8nuNnjeUgVX1l0S5/nV8azlK4FCPGvWwFYD5jdH67Cij6eUhJBtelx0oYxnvmvx+8OySZt
jXwSxWsUZoU1dLM6njqN9+NJ/NcMyeIri8VYOX5/xoew+UFYkG1AnZZfTAhBGazAeEpJJKR4
jeAZwxAtRKJimrQ18kiUoNEMK+vN/mAKwVDkDnabLr6yWI6VN3fw0Ixv7xQrUxNCgoQQlMOK
aKyURMJ1vNuAFWMYvIVYVCxWLI08EiVoNMPK8WT7FXaBffV+ld5rZZF7bhZFYY7BgjCbaIg7
3UKkx8v4RTXLyo/yGe4VK+P5VntMEkJQDis4njISwYPeyximDYO1EI2KzYqpkUeiBI3CrLC7
2Yk7JwqaZ5Gu7zJ6rVvk/7borLmqYhQ9+8TDqLxct2LCOMsKm84OwoTGilElJQRlsCLGU0wi
bm+Qsx9jGMfTT3HTHw8rpkauRDkrRUuJCmfM1kNTC0eQxYqyOGCX+RPUdhCD+LfMOA96cFk0
vBCDduIJYTcmxEpKCEplRY6nmEQ8UOyYYVHZYuX1uRpyTNoaeVjJWCl6PGztE0J+kRWDpKsV
sUWo8uEArLRCC/mTXRa/LrEi4JKeyeNgU0JQTgwqKpFciYsg5MQg/xIyghVDo8vC9MOzwrCG
TwyH8efaZgUvx7HCZvTSM01xQc2Uk0LQ47MCsxwIQvowMC5HwuKwomvkSJS1UnwwVlqxgbUF
ox8HZAWWce3NSl4Wki2ywh7F/cFgZfKw619WSSHo8VmBxRPeSW0YuGaOhMVhRdfIkShrpWgp
IcdtbDTpXySzIi1yh8HI+HU1OUOY2zIl1ptuuvxpw35h+pjraWMv7u1ObhX0+l5cL6YLfOGQ
FIJSWZn8eCmJ5FKnBybUMHCQMJNOG4atkSNR1krR2cHG7mkb2NoXqUI0av0rFssf4YPYseph
jdzDVHG6zH/Z/2bNEs09ft4lNuEZz5Wxxy8+M5NpISh9j39bl5SIL6c6kAPmxnIYco9fjG/5
xYG1x29odGdLlLdSfIy3WNwHFjZ5xe7Se+bHZCVtPkGsfM2sfF49ISGIlafLSl9Fby8RK185
K09NCGKFWCFWiBVihVghVogVYuVlsmJk1jsvZSCTAEs/xPa69ebaDg8jhN54oM0kVsyzB6Uk
8muUplo+K4td9rBiZta7yfR1v1V/x9/hRPW632LSh/H3M9WXTU7Z6JhNYiStT2nqdo9DbSaw
Yp09KCURq+WRyFPmVKtqr0a2RPMa+Rvw+pV+1q+g0Va+EBlieg2V3Ndq4eqLJvVsdGG4RSXM
NHWnx4E2k/xKP+9XsiSCWlFvHmdUM00apwE0iZY08jaQzgq+D+3l+7Hx99Vyr7GS53V9sPqS
SSMbHQzDK1ozTd3TY3+bBVnJkghrxWU0hFWzznxYpwHkW+xFjXwNpLMiPcQEXtMt9xqp9QnR
JEQhIw7o2ehguK3cNHVfj71tFmQlSyKsFZn9ElTNzASxTgNIvxGhkaeBACufNmYyfXPzB57t
wVDW8BfceMohkF5q3NguyEp/m3WGx8wEBMMNf21gpan7euxtM5EVqVApiWStSFaCqpmu18zE
lBLFaORpwM9KhSeDMJmezXf2f/4FQgB6IksLY1sbyNYwbuxgsAIzLXSD+6yzgWaGsTDcVFvn
grfH3jbTWJEKFZNIamSw0qL76tk09P7Q8MnoCe5lUDXdpJXhPUkUo5GngWAMMpPpVaxvMXcY
8+7r8HlM/cZidSVEMx1vGOPPM8yxMs3xHR3cHnvbTI5BeE61kERSI4OVz38P8LjvhHkWF2TO
T1C1GVbUMihCI08Ds6yoBGkVn3Wr7UWs1M32AlbcGNTiETvbv7o9LshKMYl8rBxfiRzc8R9+
5f7Aj258ONTxrDgxCCWK0ejJsML86SA/ZLJiZKODLZl2ayUaPk9WeCLs+K/I7Z+mDn03nZOO
YsU5DSCdX4RGqayoZHolBNjAhPDZ0Bmerxzf7JpL5ytGNroMBcY5LNNd6z0uMF+RrBSTyJqv
iAz8LyvhfxUrlcXjUjed0wAyp3xZo9T5ynpKpu+1/T70Bh0eFkxZB+EUhQWf6QHJXQcZ2eho
+HgSA9QveHtcYh20ms6plpFIrwUSwQpga/oV2UjUOsg6DaBJtKxR5DqIzbr37zaVlkzfaKnp
uFXCU8FB+Oj9FbnPzCs2i3sPy0KobHSZO9/C5+lCoMcX768ohcpJJGrpErEQxL7474DzlXbg
8xUJS9T+iqaRLdGiRrH7K7NlYlH2JmHfVhUVeHP3bevsHhfYt72CRG43v6yEL4F1ED/q03Ty
yFrkvm3ZLmfkJLSmd4oj3KzEKe/S3UquEFaP/W2WzEnIksjViCNy5j+bCn928teusEQxXc7J
XzFCWWyvAwG2ueA9c2aPA20WzV/Jkih+6tZ0xSWK6HJWrhPlr1xHoueXv1KqUF7cC5OIWCFW
iBVihVghVogVYoVYIVZeHCtUlpSiUlOhQoUKFSqPVf4XYACGNPmxCg0KZW5kc3RyZWFtDWVu
ZG9iag0zOSAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvRmlyc3QgMTEvTGVuZ3RoIDYy
L04gMi9UeXBlL09ialN0bT4+c3RyZWFtDQpo3jIzUDBQMDNUMDZUsLHRD8nMTS32Sy0Pys9N
zNNxys9JUTAEyhgoBNnZAaXd8vNKFMwMIHyAAAMAwpsPVA0KZW5kc3RyZWFtDWVuZG9iag00
MCAwIG9iag08PC9BbHRlcm5hdGUvRGV2aWNlUkdCL0ZpbHRlci9GbGF0ZURlY29kZS9MZW5n
dGggMjU5OC9OIDM+PnN0cmVhbQ0KaN6clndUVNcWh8+9d3qhzTDSGXqTLjCA9C4gHQRRGGYG
GMoAwwxNbIioQEQREQFFkKCAAaOhSKyIYiEoqGAPSBBQYjCKqKhkRtZKfHl57+Xl98e939pn
73P32XuftS4AJE8fLi8FlgIgmSfgB3o401eFR9Cx/QAGeIABpgAwWempvkHuwUAkLzcXerrI
CfyL3gwBSPy+ZejpT6eD/0/SrFS+AADIX8TmbE46S8T5Ik7KFKSK7TMipsYkihlGiZkvSlDE
cmKOW+Sln30W2VHM7GQeW8TinFPZyWwx94h4e4aQI2LER8QFGVxOpohvi1gzSZjMFfFbcWwy
h5kOAIoktgs4rHgRm4iYxA8OdBHxcgBwpLgvOOYLFnCyBOJDuaSkZvO5cfECui5Lj25qbc2g
e3IykzgCgaE/k5XI5LPpLinJqUxeNgCLZ/4sGXFt6aIiW5paW1oamhmZflGo/7r4NyXu7SK9
CvjcM4jW94ftr/xS6gBgzIpqs+sPW8x+ADq2AiB3/w+b5iEAJEV9a7/xxXlo4nmJFwhSbYyN
MzMzjbgclpG4oL/rfzr8DX3xPSPxdr+Xh+7KiWUKkwR0cd1YKUkpQj49PZXJ4tAN/zzE/zjw
r/NYGsiJ5fA5PFFEqGjKuLw4Ubt5bK6Am8Kjc3n/qYn/MOxPWpxrkSj1nwA1yghI3aAC5Oc+
gKIQARJ5UNz13/vmgw8F4psXpjqxOPefBf37rnCJ+JHOjfsc5xIYTGcJ+RmLa+JrCdCAACQB
FcgDFaABdIEhMANWwBY4AjewAviBYBAO1gIWiAfJgA8yQS7YDApAEdgF9oJKUAPqQSNoASdA
BzgNLoDL4Dq4Ce6AB2AEjIPnYAa8AfMQBGEhMkSB5CFVSAsygMwgBmQPuUE+UCAUDkVDcRAP
EkK50BaoCCqFKqFaqBH6FjoFXYCuQgPQPWgUmoJ+hd7DCEyCqbAyrA0bwwzYCfaGg+E1cByc
BufA+fBOuAKug4/B7fAF+Dp8Bx6Bn8OzCECICA1RQwwRBuKC+CERSCzCRzYghUg5Uoe0IF1I
L3ILGUGmkXcoDIqCoqMMUbYoT1QIioVKQ21AFaMqUUdR7age1C3UKGoG9QlNRiuhDdA2aC/0
KnQcOhNdgC5HN6Db0JfQd9Dj6DcYDIaG0cFYYTwx4ZgEzDpMMeYAphVzHjOAGcPMYrFYeawB
1g7rh2ViBdgC7H7sMew57CB2HPsWR8Sp4sxw7rgIHA+XhyvHNeHO4gZxE7h5vBReC2+D98Oz
8dn4Enw9vgt/Az+OnydIE3QIdoRgQgJhM6GC0EK4RHhIeEUkEtWJ1sQAIpe4iVhBPE68Qhwl
viPJkPRJLqRIkpC0k3SEdJ50j/SKTCZrkx3JEWQBeSe5kXyR/Jj8VoIiYSThJcGW2ChRJdEu
MSjxQhIvqSXpJLlWMkeyXPKk5A3JaSm8lLaUixRTaoNUldQpqWGpWWmKtKm0n3SydLF0k/RV
6UkZrIy2jJsMWyZf5rDMRZkxCkLRoLhQWJQtlHrKJco4FUPVoXpRE6hF1G+o/dQZWRnZZbKh
slmyVbJnZEdoCE2b5kVLopXQTtCGaO+XKC9xWsJZsmNJy5LBJXNyinKOchy5QrlWuTty7+Xp
8m7yifK75TvkHymgFPQVAhQyFQ4qXFKYVqQq2iqyFAsVTyjeV4KV9JUCldYpHVbqU5pVVlH2
UE5V3q98UXlahabiqJKgUqZyVmVKlaJqr8pVLVM9p/qMLkt3oifRK+g99Bk1JTVPNaFarVq/
2ry6jnqIep56q/ojDYIGQyNWo0yjW2NGU1XTVzNXs1nzvhZei6EVr7VPq1drTltHO0x7m3aH
9qSOnI6XTo5Os85DXbKug26abp3ubT2MHkMvUe+A3k19WN9CP16/Sv+GAWxgacA1OGAwsBS9
1Hopb2nd0mFDkqGTYYZhs+GoEc3IxyjPqMPohbGmcYTxbuNe408mFiZJJvUmD0xlTFeY5pl2
mf5qpm/GMqsyu21ONnc332jeaf5ymcEyzrKDy+5aUCx8LbZZdFt8tLSy5Fu2WE5ZaVpFW1Vb
DTOoDH9GMeOKNdra2Xqj9WnrdzaWNgKbEza/2BraJto22U4u11nOWV6/fMxO3Y5pV2s3Yk+3
j7Y/ZD/ioObAdKhzeOKo4ch2bHCccNJzSnA65vTC2cSZ79zmPOdi47Le5bwr4urhWuja7ybj
FuJW6fbYXd09zr3ZfcbDwmOdx3lPtKe3527PYS9lL5ZXo9fMCqsV61f0eJO8g7wrvZ/46Pvw
fbp8Yd8Vvnt8H67UWslb2eEH/Lz89vg98tfxT/P/PgAT4B9QFfA00DQwN7A3iBIUFdQU9CbY
Obgk+EGIbogwpDtUMjQytDF0Lsw1rDRsZJXxqvWrrocrhHPDOyOwEaERDRGzq91W7109HmkR
WRA5tEZnTdaaq2sV1iatPRMlGcWMOhmNjg6Lbor+wPRj1jFnY7xiqmNmWC6sfaznbEd2GXuK
Y8cp5UzE2sWWxk7G2cXtiZuKd4gvj5/munAruS8TPBNqEuYS/RKPJC4khSW1JuOSo5NP8WR4
ibyeFJWUrJSBVIPUgtSRNJu0vWkzfG9+QzqUvia9U0AV/Uz1CXWFW4WjGfYZVRlvM0MzT2ZJ
Z/Gy+rL1s3dkT+S453y9DrWOta47Vy13c+7oeqf1tRugDTEbujdqbMzfOL7JY9PRzYTNiZt/
yDPJK817vSVsS1e+cv6m/LGtHlubCyQK+AXD22y31WxHbedu799hvmP/jk+F7MJrRSZF5UUf
ilnF174y/ariq4WdsTv7SyxLDu7C7OLtGtrtsPtoqXRpTunYHt897WX0ssKy13uj9l4tX1Ze
s4+wT7hvpMKnonO/5v5d+z9UxlfeqXKuaq1Wqt5RPXeAfWDwoOPBlhrlmqKa94e4h+7WetS2
12nXlR/GHM44/LQ+tL73a8bXjQ0KDUUNH4/wjowcDTza02jV2Nik1FTSDDcLm6eORR67+Y3r
N50thi21rbTWouPguPD4s2+jvx064X2i+yTjZMt3Wt9Vt1HaCtuh9uz2mY74jpHO8M6BUytO
dXfZdrV9b/T9kdNqp6vOyJ4pOUs4m3924VzOudnzqeenL8RdGOuO6n5wcdXF2z0BPf2XvC9d
uex++WKvU++5K3ZXTl+1uXrqGuNax3XL6+19Fn1tP1j80NZv2d9+w+pG503rm10DywfODjoM
Xrjleuvyba/b1++svDMwFDJ0dzhyeOQu++7kvaR7L+9n3J9/sOkh+mHhI6lH5Y+VHtf9qPdj
64jlyJlR19G+J0FPHoyxxp7/lP7Th/H8p+Sn5ROqE42TZpOnp9ynbj5b/Wz8eerz+emCn6V/
rn6h++K7Xxx/6ZtZNTP+kv9y4dfiV/Kvjrxe9rp71n/28ZvkN/NzhW/l3x59x3jX+z7s/cR8
5gfsh4qPeh+7Pnl/eriQvLDwmwADAPeE8/sKDQplbmRzdHJlYW0NZW5kb2JqDTQxIDAgb2Jq
DTw8L0ZpbHRlci9GbGF0ZURlY29kZS9GaXJzdCAzMy9MZW5ndGggNDA2L04gNS9UeXBlL09i
alN0bT4+c3RyZWFtDQpo3nxSbWvbMBD+K/ex++DqXbahBJK0oYUtjCQsg5APqiMSgS0HW2Xt
v59OcZKG0XE66XTP6U46PZoDBS1ACgk6jlyAVqBLBlpDzkp4eCAT09tZ6wNZucb2c/tn0TbG
/1xmL8HUrvqxIk++anfO78na+bHv3WU/c10fpgfTgeAEczzavurcMbQdVqWwIN/NEME4I8u3
1/BxtGTVvdlVMnBKxdduFw79hisKtyKESBrfkStAHHe48rwARel/9Sx4FnXYMXZSnUPOebJp
suhQC6WI1m3EkFfpC07/kXNlKeVl/XxTtK9ezH17X1GUSc9nMPI0R92ORvHHxn1lfYCiZGRq
js/W7Q8h/qsm2H5EMs40mdVm30NZpP5OJu37JpNlAZmgOTDGKTDKxTahM9O4+uMuEQAiAyBR
4FvC5qaxX1MDI5ahs6E6kHnbNaZOrvXpTpJScgod+31tIWOKLINtfkXu3eeSX///Shzye3hQ
pqQejTbkZTpFiu5iNmTUNnr8zr5Hh8bOLCIXFDDxNSZUwv4KMACsfMvWDQplbmRzdHJlYW0N
ZW5kb2JqDTQyIDAgb2JqDTw8L0ZpbHRlci9GbGF0ZURlY29kZS9GaXJzdCAyMy9MZW5ndGgg
NjQzL04gNC9UeXBlL09ialN0bT4+c3RyZWFtDQpo3nyU227bMAyGX0VPMCZpmwNQBMhWDwsw
NMDaXDRFL2iJtoXKVqpDtuzpJ4uJ66vd2CH5fyRFMZ4vxETMl2Im5iuxuBOLiZje3InXt/t7
+IqevtsuwA8yJwpaIhSdtEp3da+biF/wiC3lMDzFMpyPBM/pMc1P6Nn1epzogMfqIeElBs/s
AR/K/7IPuqrIUSfJv85uoXR0IpDobAdSOxnbytAfUDaglJRKNLGr0cXWYAxga9vRO7hUEoI2
isTNCj6iDeSTy5BYzaF2eCIxnS2hjMZQAIV1Te7yUqUBMkYfvfZArULfAHX5VRmbEkPlUAad
2qmjNjmtoSp8Wk7XTYBWd9HDkVxobPTYKW4jpS/TcAYjo1eDyWx9+kfOnD7jwaGiFt07VDr1
BT+96TvcFfDEo3pROg2xP8OBHWlghrzXYFhqCTxH/uaXmM4nUERn049bkNH1V3BOxjxdgX2n
rkSXrCUMiaU9nrk561RF6cC6S3NdzMDYOu2O6WyAL+mhqAJHtfbpMKSgRZkbotoRwdFEz7MK
v62PaWDaOghNig0WyhgI2iimyxvIPtVffc4mSWljENK9D/rUT4teRpMbWi774EdEl4j+Z4Om
4goXpxfT1Qw2eTFgw9U2o2Xb5FWCzXD0TV6wTQHfruULhguGixFcDNSWNVvWbEea7aApQgOP
XG7H8h3LdyP57iIYqDaaoI/mDDu+3D2je0b3I3Q/MC8cfG6sS6tMrk07WhoPyCxyGEcsclkc
UmAeA6a/53UMxDAxTCOYBkqzRrNGjzR60FAaQ8flLMsty+1Ibi+CgVL6pHsHDyEyGBmMIzAO
xJmDIQ/hfHW/8Sfp+u1br/8JMAAl9u9eDQplbmRzdHJlYW0NZW5kb2JqDTQzIDAgb2JqDTw8
L0ZpbHRlci9GbGF0ZURlY29kZS9GaXJzdCAxMS9MZW5ndGggNDQvTiAyL1R5cGUvT2JqU3Rt
Pj5zdHJlYW0NCmjeMjdUMFAwN1IwtFSwsdH3K80tjgbzDRSCYu3sgELB+i52dgABBgCkBQjO
DQplbmRzdHJlYW0NZW5kb2JqDTQ0IDAgb2JqDTw8L0xlbmd0aCAzNjY3L1N1YnR5cGUvWE1M
L1R5cGUvTWV0YWRhdGE+PnN0cmVhbQ0KPD94cGFja2V0IGJlZ2luPSLvu78iIGlkPSJXNU0w
TXBDZWhpSHpyZVN6TlRjemtjOWQiPz4KPHg6eG1wbWV0YSB4bWxuczp4PSJhZG9iZTpuczpt
ZXRhLyIgeDp4bXB0az0iQWRvYmUgWE1QIENvcmUgNS4yLWMwMDEgNjMuMTM5NDM5LCAyMDEw
LzA5LzI3LTEzOjM3OjI2ICAgICAgICAiPgogICA8cmRmOlJERiB4bWxuczpyZGY9Imh0dHA6
Ly93d3cudzMub3JnLzE5OTkvMDIvMjItcmRmLXN5bnRheC1ucyMiPgogICAgICA8cmRmOkRl
c2NyaXB0aW9uIHJkZjphYm91dD0iIgogICAgICAgICAgICB4bWxuczp4bXA9Imh0dHA6Ly9u
cy5hZG9iZS5jb20veGFwLzEuMC8iPgogICAgICAgICA8eG1wOkNyZWF0b3JUb29sPlBTY3Jp
cHQ1LmRsbCBWZXJzaW9uIDUuMi4yPC94bXA6Q3JlYXRvclRvb2w+CiAgICAgICAgIDx4bXA6
TW9kaWZ5RGF0ZT4yMDE0LTA2LTE1VDE0OjAyOjUxLTA3OjAwPC94bXA6TW9kaWZ5RGF0ZT4K
ICAgICAgICAgPHhtcDpDcmVhdGVEYXRlPjIwMDgtMTAtMTdUMDg6MDQ6MjItMDY6MDA8L3ht
cDpDcmVhdGVEYXRlPgogICAgICAgICA8eG1wOk1ldGFkYXRhRGF0ZT4yMDE0LTA2LTE1VDE0
OjAyOjUxLTA3OjAwPC94bXA6TWV0YWRhdGFEYXRlPgogICAgICA8L3JkZjpEZXNjcmlwdGlv
bj4KICAgICAgPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIKICAgICAgICAgICAgeG1s
bnM6ZGM9Imh0dHA6Ly9wdXJsLm9yZy9kYy9lbGVtZW50cy8xLjEvIj4KICAgICAgICAgPGRj
OmZvcm1hdD5hcHBsaWNhdGlvbi9wZGY8L2RjOmZvcm1hdD4KICAgICAgICAgPGRjOnRpdGxl
PgogICAgICAgICAgICA8cmRmOkFsdD4KICAgICAgICAgICAgICAgPHJkZjpsaSB4bWw6bGFu
Zz0ieC1kZWZhdWx0Ij5NaWNyb3NvZnQgV29yZCAtIDYzNS04MDAuZG9jPC9yZGY6bGk+CiAg
ICAgICAgICAgIDwvcmRmOkFsdD4KICAgICAgICAgPC9kYzp0aXRsZT4KICAgICAgICAgPGRj
OmNyZWF0b3I+CiAgICAgICAgICAgIDxyZGY6U2VxPgogICAgICAgICAgICAgICA8cmRmOmxp
PmRlYmJpZTwvcmRmOmxpPgogICAgICAgICAgICA8L3JkZjpTZXE+CiAgICAgICAgIDwvZGM6
Y3JlYXRvcj4KICAgICAgPC9yZGY6RGVzY3JpcHRpb24+CiAgICAgIDxyZGY6RGVzY3JpcHRp
b24gcmRmOmFib3V0PSIiCiAgICAgICAgICAgIHhtbG5zOnBkZj0iaHR0cDovL25zLmFkb2Jl
LmNvbS9wZGYvMS4zLyI+CiAgICAgICAgIDxwZGY6UHJvZHVjZXI+QWNyb2JhdCBEaXN0aWxs
ZXIgOC4xLjAgKFdpbmRvd3MpPC9wZGY6UHJvZHVjZXI+CiAgICAgIDwvcmRmOkRlc2NyaXB0
aW9uPgogICAgICA8cmRmOkRlc2NyaXB0aW9uIHJkZjphYm91dD0iIgogICAgICAgICAgICB4
bWxuczp4bXBNTT0iaHR0cDovL25zLmFkb2JlLmNvbS94YXAvMS4wL21tLyI+CiAgICAgICAg
IDx4bXBNTTpEb2N1bWVudElEPnV1aWQ6ZTEzZTg5ZTYtZWM2Ny00ZmY0LTg3ZmMtN2ZlMWFm
MGM0ZDVkPC94bXBNTTpEb2N1bWVudElEPgogICAgICAgICA8eG1wTU06SW5zdGFuY2VJRD51
dWlkOmZiZGJlOTkxLWNkMGMtNDE2NS04YjczLTRmYzgzMGQ0OTUwZjwveG1wTU06SW5zdGFu
Y2VJRD4KICAgICAgPC9yZGY6RGVzY3JpcHRpb24+CiAgIDwvcmRmOlJERj4KPC94OnhtcG1l
dGE+CiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
IAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAK
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAK
PD94cGFja2V0IGVuZD0idyI/Pg0KZW5kc3RyZWFtDWVuZG9iag00NSAwIG9iag08PC9GaWx0
ZXIvRmxhdGVEZWNvZGUvRmlyc3QgNS9MZW5ndGggNzAvTiAxL1R5cGUvT2JqU3RtPj5zdHJl
YW0NCmjeMjdWMFCwsdF3zi/NK1Gw0PfOTCmONjcHCgYpGIJJMwgbwjG0AFNGxhAKwjMG82L1
QyoLUvUDEtNTi+3sAAIMAHxrFIYNCmVuZHN0cmVhbQ1lbmRvYmoNNDYgMCBvYmoNPDwvRmls
dGVyL0ZsYXRlRGVjb2RlL0ZpcnN0IDUvTGVuZ3RoIDE3OS9OIDEvVHlwZS9PYmpTdG0+PnN0
cmVhbQ0KaN48jLEKwjAUAH/lbSZD05fYtEVKodhVEBRdXNomYiD0yWvE37eguNx0d1UBCE2T
d6/0IBbOj2PwMt+zH1KguR+SF/3OINYadYU1FsZkWG4QNz9rrY6nicMzWeVihIvnZS3BKqOM
zA/k/hNdYKntSmN1htV3cmRyr8mz6CamcUjQhyWFGD1DrbRCuIlrmB29l5uU+Tmk6MUhrO5C
9wRXYgcZlFub1YjK0STb9iPAAPwqPt0NCmVuZHN0cmVhbQ1lbmRvYmoNNDcgMCBvYmoNPDwv
RGVjb2RlUGFybXM8PC9Db2x1bW5zIDUvUHJlZGljdG9yIDEyPj4vRmlsdGVyL0ZsYXRlRGVj
b2RlL0lEWzwwRkRDRjNDREIzOEM5QzkzMUU3QjYyMkQyN0RBQjY0Nj48QkQ1MDQ3QjBFODgy
NUM0RDk1NjBBQzZEOEI4MTczRjQ+XS9JbmZvIDc0IDAgUi9MZW5ndGggMTc0L1Jvb3QgNzYg
MCBSL1NpemUgNzUvVHlwZS9YUmVmL1dbMSAzIDFdPj5zdHJlYW0NCmjeYmIAASZG5qd8DEwM
DIxyQJLRTgjM7gKRTCvA7NlgUhBEyr5Fl2WYA2a7gkh5sBqGdrBIN1jlKhDJshHMBqtkFAGr
/Almg9UwrUKSVQS5oQ5DFmIL428QKVOHbj5Urx6IlFYBs1ejm8B5DmEOdytY/CuIZH4EFgf7
iH8hWNdimH8Zf9c+BcsyMIJI1v8INvt/7OK42MjqmZDYmCTjHxzif9FNYGQACDAAgcsoxw0K
ZW5kc3RyZWFtDWVuZG9iag1zdGFydHhyZWYNCjExNg0KJSVFT0YNCg==
--------------070502000100060902000502--


From nobody Sun Jun 15 15:16:11 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6924D1A0262 for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 15:16:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s9N348uVjpa7 for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 15:16:08 -0700 (PDT)
Received: from mail-ig0-x22b.google.com (mail-ig0-x22b.google.com [IPv6:2607:f8b0:4001:c05::22b]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6E3C51A00BD for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 15:16:08 -0700 (PDT)
Received: by mail-ig0-f171.google.com with SMTP id h18so2258323igc.4 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 15:16:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=Ew7KQeGH0d0l+SeviMWeWaDAuf/9ZphjHl/wAnXpzlo=; b=Ds3SoUuBujjzNtM9kB99qcRyQTS086zmtoMwdH/6Mya+qWazbxmbE4muiJiHpnwF1B 1ZimLR16uFjOsX/mACDOe/HDHdurybqibv83aZSvCPZIDc+ptjmH+YL8LC0dYd1E2FzI 5K09f9bCW1yV6l7VJgfwaG95/4+dco6Znf+eHaghecxkGcI6iESqPkFdyvvIQrWXPVw6 NO8AA/VHgpZGhMizETdfkMbwnBaCH1rleVjFXwhhnGcD2mkv2N/D7mjIY+Sn0+AM0zS1 s4dC3vFjYbOHdRl++FnDJPEV8HLrEBm+I7vR5CwTE9o28ZJwOBeKCo3hAUv4KeiJi/pq kqUA==
X-Received: by 10.50.50.147 with SMTP id c19mr20737145igo.1.1402870567880; Sun, 15 Jun 2014 15:16:07 -0700 (PDT)
Received: from [192.168.1.102] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id j3sm15401918igx.8.2014.06.15.15.16.07 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 15 Jun 2014 15:16:07 -0700 (PDT)
Message-ID: <539E1B1F.20604@gmail.com>
Date: Sun, 15 Jun 2014 18:15:59 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com> <539CCA1B.9040603@gmail.com> <24746.1402860613@sandelman.ca>
In-Reply-To: <24746.1402860613@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/F_HVMfyyJuMw1Va4-zY37WZ3X3A
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Jun 2014 22:16:10 -0000

Hi Michael:

There is more to security protocols than cryptographic properties - see 
my email of June 10, 2014, 1:50pm EDT (excerpt copied below, for your 
convenience).

BTW - as already said in my message of yesterday, Sat June 14, 2014, 
6:12pm EDT, we also need to "flag" how to set up a temporary channel 
between the joining node and its neighbor, etc. Hence, my item #c was 
about relationship between "join protocol and network":

[excerpt of email RS as of June 10, 2014, 1:50pm EDT]
When designing a security protocol, one has to consider not just 
cryptographic properties, but also implementation cost, such as energy 
cost, RAM/ROM usage, and computational and communication time latency. 
Thus, while one might argue that "security should not care how the MAC 
layer is doing its job", this only seems to hold true if one is not 
interested in non-crypto performance metrics. To implementation-specific 
metrics mentioned above, one should add potential impact of traffic that 
seems to be legitimate, but in hindsight does not turn out to be that 
way (both in terms of denial-of-service attacks, keeping state, etc.). 
Hence, my question.

On 6/15/2014 3:30 PM, Michael Richardson wrote:
> Rene Struik <rstruik.ext@gmail.com> wrote:
>      > I hope this provides some evidence that it is unclear how one could "hit"
>      > an enhanced beacon of a neighboring node. What I described above does not
>      > deal with "negotiating"/"finding" a time slot/channel combo where the
>      > joining device would actually send its first message (and at the same time
>      > have some assurances that the EB-originator is still listening to it).
>
> I understand your analysis.  I assume that the radio people have this under control.
> What is the implication to the security of the various join protocols?
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Sun Jun 15 19:10:49 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D39E1B27D4 for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 19:10:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6XWJS9H1d_0t for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 19:10:44 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AD9711B29D5 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 19:10:44 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id E12BF20028 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 22:14:33 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 1B2AF63B0E; Sun, 15 Jun 2014 22:10:38 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 08E0D63B0A for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 22:10:38 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <27727.1402275319@sandelman.ca>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <bomn1n01Q3zUFux01ompsd> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <4903.1401158997@sandelman.ca> <53840205.2070103@gmail.com> <5384046A.6080706@gmail.com> <E045AECD98228444A58C61C200AE1BD8426B036B@xmb-rcd-x01.cisco.com> <10436.1401198298@sandelman.ca> <53849841.4020401@gmail.com> <25059.1401220730@sandelman.ca> <26563.1401303435@sandelman.ca> <27727.1402275319@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 15 Jun 2014 22:10:38 -0400
Message-ID: <14119.1402884638@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/PvSWb7GEjXmTzh7nz3qJtImdSjc
Subject: Re: [6tisch-security] agenda for 2014-06-09 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 02:10:47 -0000

--=-=-=


We had a very productive call last week.
Rene has started getting some feedback on the issues that are open.

 -- The URL to access the webex, which will we use for audio only:
   https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

 -- we will use with the etherpad at:
   https://etherpad.mozilla.org/ras5RGrQLA

Agenda for tomorrow:
  1. work on trust/cryptographic details of Joining-Node -> PCE message.
     does it need to be signed?

  2. 6top ideas for PCE->joining node protocol. Will this work as stock
     CoAP/DTLS, or do we need a proxy to help us?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU55SHYCLcPvd0N1lAQLiowf9HEF+V2Dy0R+BS3JYT4jeVQEOtE0gBbRb
sLhzABvgYy5pUZcLoeSRs5YU32tIUoDD+ttSMpBAaQRR9GPcKTYUmyXRpnmWfoUH
IDoOm3k7q6tFd45peizrQgmlnNu7vEvEsFY06z08BqaeY7IimFlcSw3sn7V4AYDP
neI72XtUk4F90hyoWb/EMRguzGJyXUOrd6eN8HFRVjgaN3G6LOERaHdJ+vPYSPdE
Ciyemtu1+W5HM5MXbuRDnaPFMscOPB34ccbP7DP+bzO0xzQivQALYqno085SJNyq
ZtNiI95StiTTg2dQUaESjip0WQ0+VioEbc0t8lPVmt4nQ0nMz0jlIw==
=1G8C
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Sun Jun 15 19:11:38 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 673781B29D5 for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 19:11:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EEW4tFXUvu0i for <6tisch-security@ietfa.amsl.com>; Sun, 15 Jun 2014 19:11:31 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC4FD1B27D4 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 19:11:30 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id B565220028 for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 22:15:19 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 3FFCA63B0E; Sun, 15 Jun 2014 22:11:26 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 2B0F063B0A for <6tisch-security@ietf.org>; Sun, 15 Jun 2014 22:11:26 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 15 Jun 2014 22:11:26 -0400
Message-ID: <14319.1402884686@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/v5ntR7J4TOKqKEQF_Cr95ocl3uE
Subject: [6tisch-security] agenda for 2014-06-16 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 02:11:35 -0000

--=-=-=


{resending with a sane subject line}

We had a very productive call last week.
Rene has started getting some feedback on the issues that are open.

 -- The URL to access the webex, which will we use for audio only:
   https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

 -- we will use with the etherpad at:
   https://etherpad.mozilla.org/ras5RGrQLA

Agenda for tomorrow:
  1. work on trust/cryptographic details of Joining-Node -> PCE message.
     does it need to be signed?

  2. 6top ideas for PCE->joining node protocol. Will this work as stock
     CoAP/DTLS, or do we need a proxy to help us?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU55STYCLcPvd0N1lAQL1uQgAmisAmPnMFY8aUDRPpbvcqwbC17K6+MKY
AUEDjVgS5fdZL3ZBsf6wTcJnrE/zwhD7zaeDMUWwvTJ4R+6ZoPa1ggK8G29FbZ+Z
X3zzS5FgbldEXH839zGCRSiaNy3arqR7V3JKtpqzBtxp7fRQqw4bwBAFoxc0fFBE
b66Y+Jb6vC3U4Z1qD/U+YFPTHWJqUu+NKuLOnFNSXrWk2TDN5oNRPrhNce8LXRLf
uP6lkOPV63NYaF9IarzHw5+ZapQ3AQpA+b3u+oVze6KcKCbt6mJdnLVT1AgFH8Ge
fh4HZxPGnKd0snygv/Me3U4TO5hryaN5jEcoyeRkAGFglTIC4kcroQ==
=d5CC
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 16 00:17:42 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7886E1B2C04 for <6tisch-security@ietfa.amsl.com>; Mon, 16 Jun 2014 00:17:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Cxq9gVGPCYd1 for <6tisch-security@ietfa.amsl.com>; Mon, 16 Jun 2014 00:17:23 -0700 (PDT)
Received: from mail-qc0-x22e.google.com (mail-qc0-x22e.google.com [IPv6:2607:f8b0:400d:c01::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B27D41B2B7B for <6tisch-security@ietf.org>; Mon, 16 Jun 2014 00:17:23 -0700 (PDT)
Received: by mail-qc0-f174.google.com with SMTP id x13so7140747qcv.19 for <6tisch-security@ietf.org>; Mon, 16 Jun 2014 00:17:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=Rzd7+8OB1vFdCzYW4gSPApS6mzF3rX8fb+ePHyrX8HM=; b=qNRVrwUHs+h9d6KAImDQvx+SzZJMca2DYn8s9IpCMWLY9f/MzSEeb9DBJdT3quuLf3 Denqa3G60oK9HD5Ivq2KE6htiJ3VSIJLI8APxRRiCM/swc/xiLdyiM0pvIW2D3U7htD8 sBzXLlRMP1291Um04CI3Ha+R/yzEug3HfhdYJ93Rwf/+0KczKXDqR8A7HaWo9fSqyH+V jRgoopXHeqcj36GDoAFGhp/W2s2Da7fa8EA5jdZG1dNDhGAqcaa5x/EHmagoGqq06tVr b9pMNlAQHUTV8dj5mIQtsGQlgtgwQurwDC0Hn8hGjLJ+nD0PVfs+QVr4jYKPbTBa9gTS Ja1A==
X-Received: by 10.140.89.18 with SMTP id u18mr22183219qgd.90.1402903042903; Mon, 16 Jun 2014 00:17:22 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.140.109.182 with HTTP; Mon, 16 Jun 2014 00:17:02 -0700 (PDT)
In-Reply-To: <539E1B1F.20604@gmail.com>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com> <539CCA1B.9040603@gmail.com> <24746.1402860613@sandelman.ca> <539E1B1F.20604@gmail.com>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Mon, 16 Jun 2014 00:17:02 -0700
X-Google-Sender-Auth: zV5xmOiE5xZMP55XjALtbKbv5NM
Message-ID: <CADJ9OA-z=EacUd3_2AVTbctbHJmVYgoF1RtaxcHqH7d_2t4aHQ@mail.gmail.com>
To: Rene Struik <rstruik.ext@gmail.com>
Content-Type: multipart/alternative; boundary=001a11c11e4686d38c04fbeed1f7
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/aauF1aAYCw31yx03i9ez7hCBeRQ
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 07:17:25 -0000

--001a11c11e4686d38c04fbeed1f7
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Rene,

Can you confirm that Kris' response answers your question about the
expected duration for  a node to hear an EB?

Per your question, I don't understand what you mean by " \"flag\" how to
set up a temporary channel". The formation of a TSCH PAN is described in
Section 5.1.2.6 of IEEE802.15.4e-2012, and involved:
- nodes already in the network regularly send EB. EB contain the current
ASN, as well as number of slot frames and timeslot, all encoded in IEs.
- the joining node uses the time of arrival and the ASN IE to synchronizes
to network
- the joining node uses the timeslots indicated in the IE to communicate
with the neighbor, through which is receives further configuration. How the
latter part happens is out of scope of IEEE802.15.4e-2012. 6TiSCH aims at
defining the mechanism of establishing this, securely.

For completeness, below is are the excerpts from IEEE802.15.4e-2012 which
should answer your question.

Although it is important to have a system-level approach, I still don't
clearly see the implication for security. I believe it can safely be
summarized as "one a node synchronizes to the network, it knows how to
speak to the node sending the EB".

Thomas

<excerpt>
A TSCH PAN is formed when a device, usually the PAN coordinator, advertises
the presence of the network by sending Enhanced Beacons.
[...]
Once the listening device has heard a valid Enhanced Beacon [...] the
device is synchronized to the network.
[...]
Typically at this point the device will go through a procedure to allocate
additional communication resources (slotframes and links) to the joining
device. This procedure may include a security handshake to mutually
authenticate the joining device, configure encryption keys, and configure
routing information. The mechanism and rules for setting up these
additional communication links and configure other policies would normally
be defined in a higher layer standard=E2=80=94the content of these messages=
 is
beyond the scope of this document.
</excerpt>



On Sun, Jun 15, 2014 at 3:15 PM, Rene Struik <rstruik.ext@gmail.com> wrote:

> Hi Michael:
>
> There is more to security protocols than cryptographic properties - see m=
y
> email of June 10, 2014, 1:50pm EDT (excerpt copied below, for your
> convenience).
>
> BTW - as already said in my message of yesterday, Sat June 14, 2014,
> 6:12pm EDT, we also need to "flag" how to set up a temporary channel
> between the joining node and its neighbor, etc. Hence, my item #c was abo=
ut
> relationship between "join protocol and network":
>
> [excerpt of email RS as of June 10, 2014, 1:50pm EDT]
> When designing a security protocol, one has to consider not just
> cryptographic properties, but also implementation cost, such as energy
> cost, RAM/ROM usage, and computational and communication time latency.
> Thus, while one might argue that "security should not care how the MAC
> layer is doing its job", this only seems to hold true if one is not
> interested in non-crypto performance metrics. To implementation-specific
> metrics mentioned above, one should add potential impact of traffic that
> seems to be legitimate, but in hindsight does not turn out to be that way
> (both in terms of denial-of-service attacks, keeping state, etc.). Hence,
> my question.
>
>
> On 6/15/2014 3:30 PM, Michael Richardson wrote:
>
>> Rene Struik <rstruik.ext@gmail.com> wrote:
>>      > I hope this provides some evidence that it is unclear how one
>> could "hit"
>>      > an enhanced beacon of a neighboring node. What I described above
>> does not
>>      > deal with "negotiating"/"finding" a time slot/channel combo where
>> the
>>      > joining device would actually send its first message (and at the
>> same time
>>      > have some assurances that the EB-originator is still listening to
>> it).
>>
>> I understand your analysis.  I assume that the radio people have this
>> under control.
>> What is the implication to the security of the various join protocols?
>>
>> --
>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>>   -=3D IPv6 IoT consulting =3D-
>>
>>
>>
>>
>
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security
>

--001a11c11e4686d38c04fbeed1f7
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Rene,<div><br></div><div>Can you confirm that Kris&#39; re=
sponse answers your question about the expected duration for =C2=A0a node t=
o hear an EB?</div><div><br></div><div>Per your question, I don&#39;t under=
stand what you mean by &quot; \&quot;flag\&quot; how to set up a temporary =
channel&quot;. The formation of a TSCH PAN is described in Section 5.1.2.6 =
of IEEE802.15.4e-2012, and involved:</div>

<div>- nodes already in the network regularly send EB. EB contain the curre=
nt ASN, as well as number of slot frames and timeslot, all encoded in IEs.<=
/div><div>- the joining node uses the time of arrival and the ASN IE to syn=
chronizes to network</div>

<div>- the joining node uses the timeslots indicated in the IE to communica=
te with the neighbor, through which is receives further configuration. How =
the latter part happens is out of scope of IEEE802.15.4e-2012. 6TiSCH aims =
at defining the mechanism of establishing this, securely.</div>

<div><br></div><div>For completeness, below is are the excerpts from IEEE80=
2.15.4e-2012 which should answer your question.</div><div><br></div><div>Al=
though it is important to have a system-level approach, I still don&#39;t c=
learly see the implication for security. I believe it can safely be summari=
zed as &quot;one a node synchronizes to the network, it knows how to speak =
to the node sending the EB&quot;.</div>

<div><br></div><div>Thomas</div><div><br></div><div>&lt;excerpt&gt;</div><d=
iv><div>A TSCH PAN is formed when a device, usually the PAN coordinator, ad=
vertises the presence of the network by sending Enhanced Beacons.</div>

<div>[...]</div><div>Once the listening device has heard a valid Enhanced B=
eacon [...] the device is synchronized to the network.</div><div>[...]</div=
><div>Typically at this point the device will go through a procedure to all=
ocate additional communication resources (slotframes and links) to the join=
ing device. This procedure may include a security handshake to mutually aut=
henticate the joining device, configure encryption keys, and configure rout=
ing information. The mechanism and rules for setting up these additional co=
mmunication links and configure other policies would normally be defined in=
 a higher layer standard=E2=80=94the content of these messages is beyond th=
e scope of this document.</div>

</div><div>&lt;/excerpt&gt;</div><div><br></div></div><div class=3D"gmail_e=
xtra"><br><br><div class=3D"gmail_quote">On Sun, Jun 15, 2014 at 3:15 PM, R=
ene Struik <span dir=3D"ltr">&lt;<a href=3D"mailto:rstruik.ext@gmail.com" t=
arget=3D"_blank">rstruik.ext@gmail.com</a>&gt;</span> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">Hi Michael:<br>
<br>
There is more to security protocols than cryptographic properties - see my =
email of June 10, 2014, 1:50pm EDT (excerpt copied below, for your convenie=
nce).<br>
<br>
BTW - as already said in my message of yesterday, Sat June 14, 2014, 6:12pm=
 EDT, we also need to &quot;flag&quot; how to set up a temporary channel be=
tween the joining node and its neighbor, etc. Hence, my item #c was about r=
elationship between &quot;join protocol and network&quot;:<br>


<br>
[excerpt of email RS as of June 10, 2014, 1:50pm EDT]<br>
When designing a security protocol, one has to consider not just cryptograp=
hic properties, but also implementation cost, such as energy cost, RAM/ROM =
usage, and computational and communication time latency. Thus, while one mi=
ght argue that &quot;security should not care how the MAC layer is doing it=
s job&quot;, this only seems to hold true if one is not interested in non-c=
rypto performance metrics. To implementation-specific metrics mentioned abo=
ve, one should add potential impact of traffic that seems to be legitimate,=
 but in hindsight does not turn out to be that way (both in terms of denial=
-of-service attacks, keeping state, etc.). Hence, my question.<div class=3D=
"HOEnZb">

<div class=3D"h5"><br>
<br>
On 6/15/2014 3:30 PM, Michael Richardson wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Rene Struik &lt;<a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">=
rstruik.ext@gmail.com</a>&gt; wrote:<br>
=C2=A0 =C2=A0 =C2=A0&gt; I hope this provides some evidence that it is uncl=
ear how one could &quot;hit&quot;<br>
=C2=A0 =C2=A0 =C2=A0&gt; an enhanced beacon of a neighboring node. What I d=
escribed above does not<br>
=C2=A0 =C2=A0 =C2=A0&gt; deal with &quot;negotiating&quot;/&quot;finding&qu=
ot; a time slot/channel combo where the<br>
=C2=A0 =C2=A0 =C2=A0&gt; joining device would actually send its first messa=
ge (and at the same time<br>
=C2=A0 =C2=A0 =C2=A0&gt; have some assurances that the EB-originator is sti=
ll listening to it).<br>
<br>
I understand your analysis. =C2=A0I assume that the radio people have this =
under control.<br>
What is the implication to the security of the various join protocols?<br>
<br>
--<br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2BIETF@sandelman.ca" target=3D=
"_blank">mcr+IETF@sandelman.ca</a>&gt;, Sandelman Software Works<br>
=C2=A0 -=3D IPv6 IoT consulting =3D-<br>
<br>
<br>
<br>
</blockquote>
<br>
<br></div></div><div class=3D"HOEnZb"><div class=3D"h5">
-- <br>
email: <a href=3D"mailto:rstruik.ext@gmail.com" target=3D"_blank">rstruik.e=
xt@gmail.com</a> | Skype: rstruik<br>
cell: <a href=3D"tel:%2B1%20%28647%29%20867-5658" value=3D"+16478675658" ta=
rget=3D"_blank">+1 (647) 867-5658</a> | US: <a href=3D"tel:%2B1%20%28415%29=
%20690-7363" value=3D"+14156907363" target=3D"_blank">+1 (415) 690-7363</a>=
<br>
<br>
______________________________<u></u>_________________<br>
6tisch-security mailing list<br>
<a href=3D"mailto:6tisch-security@ietf.org" target=3D"_blank">6tisch-securi=
ty@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch-security" target=3D=
"_blank">https://www.ietf.org/mailman/<u></u>listinfo/6tisch-security</a><b=
r>
</div></div></blockquote></div><br></div>

--001a11c11e4686d38c04fbeed1f7--


From nobody Mon Jun 16 06:45:20 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CF221A0029 for <6tisch-security@ietfa.amsl.com>; Mon, 16 Jun 2014 06:45:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yocbIhgoB9rz for <6tisch-security@ietfa.amsl.com>; Mon, 16 Jun 2014 06:45:14 -0700 (PDT)
Received: from mail-ie0-x231.google.com (mail-ie0-x231.google.com [IPv6:2607:f8b0:4001:c03::231]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9E5F11A0002 for <6tisch-security@ietf.org>; Mon, 16 Jun 2014 06:45:14 -0700 (PDT)
Received: by mail-ie0-f177.google.com with SMTP id tp5so4781257ieb.8 for <6tisch-security@ietf.org>; Mon, 16 Jun 2014 06:45:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type; bh=QKv+0cunXZh/hiu/Z3UjC3lq+0FhNGkov758gjQh9IU=; b=JA7LS21G5NnosLk4dPHDHc6dBTkGzmE1faDwyiJGIcEPJdveo78G9vtMByGDZEbvb9 6PWVebX4oNkg2ESF2dBoSfo9Z548NHR1ndFJk+HU31mRAXFxVX2VuKKzv+J+H0d5vUrp R4atoePZPI6Qtj9Jl0I5M/8qkn7vcB0f5zUUpAwMCBojmn6h7Pgl2zrHbZ2HWUKGLuHw yvkc1WwoOHVdIJHaOBexiDV8kWVDVSbsPCUwM9lKPY32LdrKhiwC1KJkIVBKfNuLq+OZ fVdxusvLLECD1bCPdvz/b//ArEvdHTUzeX9Sx2d3RoaqOQoCH6OFqbXwLL6t+Fx6xE4m 0llQ==
X-Received: by 10.43.80.5 with SMTP id zs5mr3094173icb.72.1402926313973; Mon, 16 Jun 2014 06:45:13 -0700 (PDT)
Received: from [192.168.1.102] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id j3sm20808323igx.8.2014.06.16.06.45.12 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 16 Jun 2014 06:45:13 -0700 (PDT)
Message-ID: <539EF4E0.3070209@gmail.com>
Date: Mon, 16 Jun 2014 09:45:04 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Thomas Watteyne <watteyne@eecs.berkeley.edu>
References: <E045AECD98228444A58C61C200AE1BD8416F3AF4@xmb-rcd-x01.cisco.com> <531DD632.2060009@cox.net> <531DDB20.5050600@gmail.com> <10925.1394631496@sandelman.ca> <532069C8.2050005@gmail.com> <23590.1394999032@sandelman.ca> <18106.1395625035@sandelman.ca> <19609.1396839403@sandelman.ca> <11557.1397444260@sandelman.ca> <28192.1398644294@sandelman.ca> <29064.1399255587@sandelman.ca> <19475.1400588783@sandelman.ca> <537B5C77.5020800@gmail.com> <5395D7E4.1010200@gmail.com> <10803.1402774016@sandelman.ca> <539CC8D3.7000605@gmail.com> <539CCA1B.9040603@gmail.com> <24746.1402860613@sandelman.ca> <539E1B1F.20604@gmail.com> <CADJ9OA-z=EacUd3_2AVTbctbHJmVYgoF1RtaxcHqH7d_2t4aHQ@mail.gmail.com>
In-Reply-To: <CADJ9OA-z=EacUd3_2AVTbctbHJmVYgoF1RtaxcHqH7d_2t4aHQ@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------070602020407070009080306"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/UN8jGQMOfN4ERGf_7w-wD7J8fm4
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] tackling outstanding issue #c-1 (corrected subject heading - apologies)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 13:45:17 -0000

This is a multi-part message in MIME format.
--------------070602020407070009080306
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Thomas:

Once again, it is crucial to consider how the joining protocol fits into 
the underlying 802.15.4e/TSCH-based network: protocol details, time 
latencies, interaction of higher-layer security and MAC security do 
matter (a lot).

As already suggested in my email of June 10, 2014, 11:39am EDT (see 
weblink below and snippet), the joining node cannot rely on the ASN 
entry of its neighbor for frame security (item #a below). Hence, the 
newbee node (at least initially) can only hope for synchronization to 
its neighbor (and not the network manager or such). The same is true for 
initial scheduling.

I did not have the chance yet to have a look at the "DSN 2008" paper 
Kris Pister forwarded yesterday evening (Sun June 15, 2014, 5:05pm EDT) 
-- sorry, it was also a Sunday in Toronto. Will try and give this a look 
soon, though.

Please note that I am trying to get an idea of time latencies, which 
seem *huge*. If this is indeed correct, one should aim at ways of 
minimizing these.

http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html
> With 802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13) includes 
> the absolute slot number (ASN) and the Join Priority flag.
a)
> Since a newly joining device has no way to validate whether the ASN 
> entry advertised by the beaconing device corresponds to the one 
> maintained by the PAN coordinator and there is only one macASN entry, 
> joining nodes cannot rely on this ASN entry for frame security. As a 
> result, the first message from a newbee node to the neighbor device 
> should be unsecured. In particular, this should neither attempt to use 
> a "well-known key".
b)
> It is unclear how the join priority flag would help in facilitating 
> resource optimization when a newly joining device tries and join the 
> network. Perhaps, this flag was motivated by centralized solution 
> ideas, where every device joins via the PAN coordinator? Suggestion is 
> to completely ignore this joining priority flag.
>
> Best regards, Rene
>
> [excerpt of 802.15.4e-2012]
> The ASN field contains the 5-octet Absolute Slot Number corresponding 
> to the timeslot in which the
> enhanced beacon is sent. The ASN is used as the Frame Counter for 
> security operations if enabled. The 1-
> octet Join Priority field can be used by a joining device to select 
> among beaconing devices when multiple
> beacons are heard. The PAN coordinator’s join priority is zero. A 
> lower value of join priority indicates that
> the device is the preferred one to connect to. The beaconing device’s 
> join priority is the lowest join priority
> heard when it joined the network plus one.
> The TSCH Synchronization IE is used to construct enhanced beacons that 
> allow new devices to synchronize
> to a TSCH PAN.




On 6/16/2014 3:17 AM, Thomas Watteyne wrote:
> Rene,
>
> Can you confirm that Kris' response answers your question about the 
> expected duration for  a node to hear an EB?
>
> Per your question, I don't understand what you mean by " \"flag\" how 
> to set up a temporary channel". The formation of a TSCH PAN is 
> described in Section 5.1.2.6 of IEEE802.15.4e-2012, and involved:
> - nodes already in the network regularly send EB. EB contain the 
> current ASN, as well as number of slot frames and timeslot, all 
> encoded in IEs.
> - the joining node uses the time of arrival and the ASN IE to 
> synchronizes to network
> - the joining node uses the timeslots indicated in the IE to 
> communicate with the neighbor, through which is receives further 
> configuration. How the latter part happens is out of scope of 
> IEEE802.15.4e-2012. 6TiSCH aims at defining the mechanism of 
> establishing this, securely.
>
> For completeness, below is are the excerpts from IEEE802.15.4e-2012 
> which should answer your question.
>
> Although it is important to have a system-level approach, I still 
> don't clearly see the implication for security. I believe it can 
> safely be summarized as "one a node synchronizes to the network, it 
> knows how to speak to the node sending the EB".
>
> Thomas
>
> <excerpt>
> A TSCH PAN is formed when a device, usually the PAN coordinator, 
> advertises the presence of the network by sending Enhanced Beacons.
> [...]
> Once the listening device has heard a valid Enhanced Beacon [...] the 
> device is synchronized to the network.
> [...]
> Typically at this point the device will go through a procedure to 
> allocate additional communication resources (slotframes and links) to 
> the joining device. This procedure may include a security handshake to 
> mutually authenticate the joining device, configure encryption keys, 
> and configure routing information. The mechanism and rules for setting 
> up these additional communication links and configure other policies 
> would normally be defined in a higher layer standard—the content of 
> these messages is beyond the scope of this document.
> </excerpt>
>
>
>
> On Sun, Jun 15, 2014 at 3:15 PM, Rene Struik <rstruik.ext@gmail.com 
> <mailto:rstruik.ext@gmail.com>> wrote:
>
>     Hi Michael:
>
>     There is more to security protocols than cryptographic properties
>     - see my email of June 10, 2014, 1:50pm EDT (excerpt copied below,
>     for your convenience).
>
>     BTW - as already said in my message of yesterday, Sat June 14,
>     2014, 6:12pm EDT, we also need to "flag" how to set up a temporary
>     channel between the joining node and its neighbor, etc. Hence, my
>     item #c was about relationship between "join protocol and network":
>
>     [excerpt of email RS as of June 10, 2014, 1:50pm EDT]
>     When designing a security protocol, one has to consider not just
>     cryptographic properties, but also implementation cost, such as
>     energy cost, RAM/ROM usage, and computational and communication
>     time latency. Thus, while one might argue that "security should
>     not care how the MAC layer is doing its job", this only seems to
>     hold true if one is not interested in non-crypto performance
>     metrics. To implementation-specific metrics mentioned above, one
>     should add potential impact of traffic that seems to be
>     legitimate, but in hindsight does not turn out to be that way
>     (both in terms of denial-of-service attacks, keeping state, etc.).
>     Hence, my question.
>
>
>     On 6/15/2014 3:30 PM, Michael Richardson wrote:
>
>         Rene Struik <rstruik.ext@gmail.com
>         <mailto:rstruik.ext@gmail.com>> wrote:
>              > I hope this provides some evidence that it is unclear
>         how one could "hit"
>              > an enhanced beacon of a neighboring node. What I
>         described above does not
>              > deal with "negotiating"/"finding" a time slot/channel
>         combo where the
>              > joining device would actually send its first message
>         (and at the same time
>              > have some assurances that the EB-originator is still
>         listening to it).
>
>         I understand your analysis.  I assume that the radio people
>         have this under control.
>         What is the implication to the security of the various join
>         protocols?
>
>         --
>         Michael Richardson <mcr+IETF@sandelman.ca
>         <mailto:mcr%2BIETF@sandelman.ca>>, Sandelman Software Works
>           -= IPv6 IoT consulting =-
>
>
>
>
>
>     -- 
>     email: rstruik.ext@gmail.com <mailto:rstruik.ext@gmail.com> |
>     Skype: rstruik
>     cell: +1 (647) 867-5658 <tel:%2B1%20%28647%29%20867-5658> | US: +1
>     (415) 690-7363 <tel:%2B1%20%28415%29%20690-7363>
>
>     _______________________________________________
>     6tisch-security mailing list
>     6tisch-security@ietf.org <mailto:6tisch-security@ietf.org>
>     https://www.ietf.org/mailman/listinfo/6tisch-security
>
>


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070602020407070009080306
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Hi Thomas:<br>
      <br>
      Once again, it is crucial to consider how the joining protocol
      fits into the underlying 802.15.4e/TSCH-based network: protocol
      details, time latencies, interaction of higher-layer security and
      MAC security do matter (a lot).<br>
      <br>
      As already suggested in my email of June 10, 2014, 11:39am EDT
      (see weblink below and snippet), the joining node cannot rely on
      the ASN entry of its neighbor for frame security (item #a below).
      Hence, the newbee node (at least initially) can only hope for
      synchronization to its neighbor (and not the network manager or
      such). The same is true for initial scheduling.<br>
      <br>
      I did not have the chance yet to have a look at the "DSN 2008"
      paper Kris Pister forwarded yesterday evening (Sun June 15, 2014,
      5:05pm EDT) -- sorry, it was also a Sunday in Toronto. Will try
      and give this a look soon, though. <br>
      <br>
      Please note that I am trying to get an idea of time latencies,
      which seem *huge*. If this is indeed correct, one should aim at
      ways of minimizing these.<br>
      <br>
<a class="moz-txt-link-freetext" href="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html">http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html</a><br>
      <table width="100%">
        <tbody>
          <tr>
            <td style="color: rgb(0, 0, 0); background-color: rgb(255,
              255, 255);" bgcolor="#FFFFFF"><font color="#000000">
                <blockquote
cite="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html"
                  type="cite" style="color: rgb(0, 0, 0); font-family:
                  'Times New Roman'; font-size: medium; font-style:
                  normal; font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; background-color: rgb(255, 255, 255);">With
                  802.15.4e-2012, the TSCH Synchronization IE (5.2.4.13)
                  includes the absolute slot number (ASN) and the Join
                  Priority flag.<span class="Apple-converted-space"> </span><br>
                </blockquote>
                <span style="color: rgb(0, 0, 0); font-family: 'Times
                  New Roman'; font-size: medium; font-style: normal;
                  font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; display: inline !important; float: none;
                  background-color: rgb(255, 255, 255);">a)</span><br
                  style="color: rgb(0, 0, 0); font-family: 'Times New
                  Roman'; font-size: medium; font-style: normal;
                  font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; background-color: rgb(255, 255, 255);">
                <blockquote
cite="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html"
                  type="cite" style="color: rgb(0, 0, 0); font-family:
                  'Times New Roman'; font-size: medium; font-style:
                  normal; font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; background-color: rgb(255, 255, 255);">Since a
                  newly joining device has no way to validate whether
                  the ASN entry advertised by the beaconing device
                  corresponds to the one maintained by the PAN
                  coordinator and there is only one macASN entry,
                  joining nodes cannot rely on this ASN entry for frame
                  security. As a result, the first message from a newbee
                  node to the neighbor device should be unsecured. In
                  particular, this should neither attempt to use a
                  "well-known key".<br>
                </blockquote>
                <span style="color: rgb(0, 0, 0); font-family: 'Times
                  New Roman'; font-size: medium; font-style: normal;
                  font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; display: inline !important; float: none;
                  background-color: rgb(255, 255, 255);">b)</span><br
                  style="color: rgb(0, 0, 0); font-family: 'Times New
                  Roman'; font-size: medium; font-style: normal;
                  font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; background-color: rgb(255, 255, 255);">
                <blockquote
cite="http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00154.html"
                  type="cite" style="color: rgb(0, 0, 0); font-family:
                  'Times New Roman'; font-size: medium; font-style:
                  normal; font-variant: normal; font-weight: normal;
                  letter-spacing: normal; line-height: normal; orphans:
                  auto; text-align: start; text-indent: 0px;
                  text-transform: none; white-space: normal; widows:
                  auto; word-spacing: 0px; -webkit-text-stroke-width:
                  0px; background-color: rgb(255, 255, 255);">It is
                  unclear how the join priority flag would help in
                  facilitating resource optimization when a newly
                  joining device tries and join the network. Perhaps,
                  this flag was motivated by centralized solution ideas,
                  where every device joins via the PAN coordinator?
                  Suggestion is to completely ignore this joining
                  priority flag.<br>
                  <br>
                  Best regards, Rene<br>
                  <br>
                  [excerpt of 802.15.4e-2012]<br>
                  The ASN field contains the 5-octet Absolute Slot
                  Number corresponding to the timeslot in which the<br>
                  enhanced beacon is sent. The ASN is used as the Frame
                  Counter for security operations if enabled. The 1-<br>
                  octet Join Priority field can be used by a joining
                  device to select among beaconing devices when multiple<br>
                  beacons are heard. The PAN coordinator’s join priority
                  is zero. A lower value of join priority indicates that<br>
                  the device is the preferred one to connect to. The
                  beaconing device’s join priority is the lowest join
                  priority<br>
                  heard when it joined the network plus one.<br>
                  The TSCH Synchronization IE is used to construct
                  enhanced beacons that allow new devices to synchronize<br>
                  to a TSCH PAN.<br>
                </blockquote>
              </font></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <br>
      On 6/16/2014 3:17 AM, Thomas Watteyne wrote:<br>
    </div>
    <blockquote
cite="mid:CADJ9OA-z=EacUd3_2AVTbctbHJmVYgoF1RtaxcHqH7d_2t4aHQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">Rene,
        <div><br>
        </div>
        <div>Can you confirm that Kris' response answers your question
          about the expected duration for  a node to hear an EB?</div>
        <div><br>
        </div>
        <div>Per your question, I don't understand what you mean by "
          \"flag\" how to set up a temporary channel". The formation of
          a TSCH PAN is described in Section 5.1.2.6 of
          IEEE802.15.4e-2012, and involved:</div>
        <div>- nodes already in the network regularly send EB. EB
          contain the current ASN, as well as number of slot frames and
          timeslot, all encoded in IEs.</div>
        <div>- the joining node uses the time of arrival and the ASN IE
          to synchronizes to network</div>
        <div>- the joining node uses the timeslots indicated in the IE
          to communicate with the neighbor, through which is receives
          further configuration. How the latter part happens is out of
          scope of IEEE802.15.4e-2012. 6TiSCH aims at defining the
          mechanism of establishing this, securely.</div>
        <div><br>
        </div>
        <div>For completeness, below is are the excerpts from
          IEEE802.15.4e-2012 which should answer your question.</div>
        <div><br>
        </div>
        <div>Although it is important to have a system-level approach, I
          still don't clearly see the implication for security. I
          believe it can safely be summarized as "one a node
          synchronizes to the network, it knows how to speak to the node
          sending the EB".</div>
        <div><br>
        </div>
        <div>Thomas</div>
        <div><br>
        </div>
        <div>&lt;excerpt&gt;</div>
        <div>
          <div>A TSCH PAN is formed when a device, usually the PAN
            coordinator, advertises the presence of the network by
            sending Enhanced Beacons.</div>
          <div>[...]</div>
          <div>Once the listening device has heard a valid Enhanced
            Beacon [...] the device is synchronized to the network.</div>
          <div>[...]</div>
          <div>Typically at this point the device will go through a
            procedure to allocate additional communication resources
            (slotframes and links) to the joining device. This procedure
            may include a security handshake to mutually authenticate
            the joining device, configure encryption keys, and configure
            routing information. The mechanism and rules for setting up
            these additional communication links and configure other
            policies would normally be defined in a higher layer
            standard—the content of these messages is beyond the scope
            of this document.</div>
        </div>
        <div>&lt;/excerpt&gt;</div>
        <div><br>
        </div>
      </div>
      <div class="gmail_extra"><br>
        <br>
        <div class="gmail_quote">On Sun, Jun 15, 2014 at 3:15 PM, Rene
          Struik <span dir="ltr">&lt;<a moz-do-not-send="true"
              href="mailto:rstruik.ext@gmail.com" target="_blank">rstruik.ext@gmail.com</a>&gt;</span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi
            Michael:<br>
            <br>
            There is more to security protocols than cryptographic
            properties - see my email of June 10, 2014, 1:50pm EDT
            (excerpt copied below, for your convenience).<br>
            <br>
            BTW - as already said in my message of yesterday, Sat June
            14, 2014, 6:12pm EDT, we also need to "flag" how to set up a
            temporary channel between the joining node and its neighbor,
            etc. Hence, my item #c was about relationship between "join
            protocol and network":<br>
            <br>
            [excerpt of email RS as of June 10, 2014, 1:50pm EDT]<br>
            When designing a security protocol, one has to consider not
            just cryptographic properties, but also implementation cost,
            such as energy cost, RAM/ROM usage, and computational and
            communication time latency. Thus, while one might argue that
            "security should not care how the MAC layer is doing its
            job", this only seems to hold true if one is not interested
            in non-crypto performance metrics. To
            implementation-specific metrics mentioned above, one should
            add potential impact of traffic that seems to be legitimate,
            but in hindsight does not turn out to be that way (both in
            terms of denial-of-service attacks, keeping state, etc.).
            Hence, my question.
            <div class="HOEnZb">
              <div class="h5"><br>
                <br>
                On 6/15/2014 3:30 PM, Michael Richardson wrote:<br>
                <blockquote class="gmail_quote" style="margin:0 0 0
                  .8ex;border-left:1px #ccc solid;padding-left:1ex">
                  Rene Struik &lt;<a moz-do-not-send="true"
                    href="mailto:rstruik.ext@gmail.com" target="_blank">rstruik.ext@gmail.com</a>&gt;
                  wrote:<br>
                       &gt; I hope this provides some evidence that it
                  is unclear how one could "hit"<br>
                       &gt; an enhanced beacon of a neighboring node.
                  What I described above does not<br>
                       &gt; deal with "negotiating"/"finding" a time
                  slot/channel combo where the<br>
                       &gt; joining device would actually send its first
                  message (and at the same time<br>
                       &gt; have some assurances that the EB-originator
                  is still listening to it).<br>
                  <br>
                  I understand your analysis.  I assume that the radio
                  people have this under control.<br>
                  What is the implication to the security of the various
                  join protocols?<br>
                  <br>
                  --<br>
                  Michael Richardson &lt;<a moz-do-not-send="true"
                    href="mailto:mcr%2BIETF@sandelman.ca"
                    target="_blank">mcr+IETF@sandelman.ca</a>&gt;,
                  Sandelman Software Works<br>
                    -= IPv6 IoT consulting =-<br>
                  <br>
                  <br>
                  <br>
                </blockquote>
                <br>
                <br>
              </div>
            </div>
            <div class="HOEnZb">
              <div class="h5">
                -- <br>
                email: <a moz-do-not-send="true"
                  href="mailto:rstruik.ext@gmail.com" target="_blank">rstruik.ext@gmail.com</a>
                | Skype: rstruik<br>
                cell: <a moz-do-not-send="true"
                  href="tel:%2B1%20%28647%29%20867-5658"
                  value="+16478675658" target="_blank">+1 (647) 867-5658</a>
                | US: <a moz-do-not-send="true"
                  href="tel:%2B1%20%28415%29%20690-7363"
                  value="+14156907363" target="_blank">+1 (415) 690-7363</a><br>
                <br>
                _______________________________________________<br>
                6tisch-security mailing list<br>
                <a moz-do-not-send="true"
                  href="mailto:6tisch-security@ietf.org" target="_blank">6tisch-security@ietf.org</a><br>
                <a moz-do-not-send="true"
                  href="https://www.ietf.org/mailman/listinfo/6tisch-security"
                  target="_blank">https://www.ietf.org/mailman/listinfo/6tisch-security</a><br>
              </div>
            </div>
          </blockquote>
        </div>
        <br>
      </div>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070602020407070009080306--


From nobody Mon Jun 16 13:13:22 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F103B1A01D6; Mon, 16 Jun 2014 13:13:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Jz7xNtI0B6dv; Mon, 16 Jun 2014 13:13:14 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.252.184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8ECBB1A01C7; Mon, 16 Jun 2014 13:13:14 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id B88DC20011; Mon, 16 Jun 2014 16:17:05 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id A69DC63B0E; Mon, 16 Jun 2014 16:13:12 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 96EEA63B0A; Mon, 16 Jun 2014 16:13:12 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: anima@ietf.org
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 16 Jun 2014 16:13:12 -0400
Message-ID: <26717.1402949592@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/YOSVJxUgX3NWy941i1-Wws6iKWQ
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: [6tisch-security] autonomic bootstrap: gap analysis
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: anima@ietf.org
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 20:13:21 -0000

--=-=-=
Content-Transfer-Encoding: quoted-printable


I recognize that bootstrap is only one of the autonomic mechanisms that
are relevant to this group.  I have much reading on the other aspects
which I hope to get done.

The 6tisch security design team has been working on a "zero-touch" mechanism
that would permit constrained devices to join a Lowpower/Loss Network (LLN)
in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
done), or turning the WirelessHART (IEC62591) packet flow into something mo=
re
IPv6-like.  While there are significant bits of design space to explore
while trying to optimize packet count, size and total energy risk of the
join protocol;  the idea that there should be a set of authorization tokens
From=20the device vendor which would permit the network and new nodes to
recognize each other has been central to all discussions.

while draft-pritikin-bootstrapping-keyinfrastructures and
      draft-behringer-autonomic-bootstrap-00

have proposed valid high level concepts, I believe that specification of the
authz token is critical for the IoT space.  A great concern that is that the
LLNs created remain operational for decades at a time, and that the
components can individually and also in aggregate be both (re-)sold,
and/or the service provider operating the network be replaced.

(There are real life examples where a part of a 100 square mile refinery
is actually sold to a competitor; obviously it doesn't get moved.  On the
other side, one has the very real risk that you bought your sensor network
From=20a "Nortel")

I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is about an
API between a (constrained) device and it's cryptographic hardware
module/TPM.   It profiles a number of IETF PKIX specifications in a useful
way, but there is little there in terms of actual protocol.  When it comes =
to
what does an *DevID look like, in it's section 7.2.8, saying that the DN
should contain a "serialNumber" attribute:

   The formatting of this field shall contain a unique X.500
   Distinguished Name (DN). This may include the unique device serial numbe=
r assigned by the manufacturer
   or any other suitable unique DN value that the issuer prefers.

What I have observed is that there needs to be a way to clearly delegate fr=
om
Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
SERVICE-PROVIDER.    It would significantly reduce the number of certificat=
es
in (non-constrained device) databases for some levels of this hierarchy if
the IDevID were aggregateable in some fashion.  RFC3779 came to mind, which
deals with delegation of Autonomous Systems Numbers (ASN) and IP address
ranges from RIRs to LIRs to ISPs and Enterprises.
          RFC3779: X.509 Extensions for IP Addresses and AS Identifiers

I created:
    X509.v3 certificate extension for authorization of device ownership
                 draft-richardson-6tisch-idevid-cert-00

which cribbed together via nroff2xml and a search and replace.

The Pritikin and Behringer documents seem to assume that the ultimate goal =
of
the trusted enrollment process is to create a path in which "EST"=3D Enroll=
ment
over Secure Transport could operate that would permit a new locally
significant certificate to be loaded into the new device.
I agree with that goal.

There is the question of how that trust circuit is created, and in discussi=
on
it seemed that it involve some kind of leap-of-faith TLS setup which would =
be
authenticated by the "authz" tokens later on.  I disagree; I think that with
appropriate evaluation of path constraints that the authentication can occur
within the TLS protocol. (Even easier if done in IKEv2)

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU59P2ICLcPvd0N1lAQLqrggAhrRKqmv7h4vARo3LgeplKsw7ghMCA+ho
KRE6ESV4geNv54RRCQAH1w56wm9Leg1zRk7Dx23BDuU2IZibrYgv6rWnMpVQE6u9
cD785znF4hlLUAYy8hhlFJoz4l0XfK17kMWN9GXkNKFzhZogB2HoHV6IMXpfIbLH
+VUEGxTGC950nloG8dCU4mpK4KgW6dmKDcTjoXR5Ymtp0EVYZZsMtWocWOHSnWLl
+sBsb9nGVF3WGH5n//Gq36a504B/ixqk4oCGm/XAFOC+zxZXc8Fx8jBZHwHkENzi
cu+akpKy5P0CsQmx+5AdqB15h82eq5CyuLoVLeLztVNewQX7JeIn+Q==
=h6ra
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 16 23:57:06 2014
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1BA31A02B3; Mon, 16 Jun 2014 16:00:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gDQKEkLpNuzo; Mon, 16 Jun 2014 16:00:44 -0700 (PDT)
Received: from mail-pd0-x233.google.com (mail-pd0-x233.google.com [IPv6:2607:f8b0:400e:c02::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E45E11A02A8; Mon, 16 Jun 2014 16:00:43 -0700 (PDT)
Received: by mail-pd0-f179.google.com with SMTP id w10so2252825pde.24 for <multiple recipients>; Mon, 16 Jun 2014 16:00:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:organization:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=7hoSwgd8rh5ckrYFcje5ScKq2UK/DXdDO2/0uy6kPe4=; b=0zRYQ69lsHPHgHzmDzSwXTnElSloVBNLrD8LFWJCsZKTo4pKM8kKC/jEts0g4eIhlP UgDZHutRqzvgzlVigFyXZOH1hEfWeBlTx8WBJtS7i5DcRqQREp/uDy92BoTk0W4LBXsF 2ogqxu5h+ibWAZS1xcKYcb6TDfnOfXhBx+8nAdqJm77nD+b4VFjpFuWzei5n4s5bfF0u NDeRmVwz4T5IZDvWa4xTvlazCAaYSToImIpWre/B80R/5C7fEKF8W7PzMg/0YAkf7zgA +eppNH27rah511M/ld3GLisWzebOtrSmfl/eAAAVXf0+CawrZnL3HZ5zNrIO2EuV/p6r 7Fpg==
X-Received: by 10.68.194.202 with SMTP id hy10mr28064686pbc.94.1402959643574;  Mon, 16 Jun 2014 16:00:43 -0700 (PDT)
Received: from [192.168.178.23] (10.192.69.111.dynamic.snap.net.nz. [111.69.192.10]) by mx.google.com with ESMTPSA id ue3sm20664327pbc.49.2014.06.16.16.00.41 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 16 Jun 2014 16:00:42 -0700 (PDT)
Message-ID: <539F771A.3000008@gmail.com>
Date: Tue, 17 Jun 2014 11:00:42 +1200
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
MIME-Version: 1.0
To: anima@ietf.org
References: <26717.1402949592@sandelman.ca>
In-Reply-To: <26717.1402949592@sandelman.ca>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/bqKOsGqYZB4zoFA5YSFK72qSrGs
X-Mailman-Approved-At: Mon, 16 Jun 2014 23:57:03 -0700
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: [6tisch-security] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 23:00:46 -0000

Michael's message is very interesting. For present purposes,
i.e. getting ready for the UCAN BOF, do we need to add some
points to the relevant use case draft
(http://tools.ietf.org/html/draft-behringer-autonomic-bootstrap)?

More generally - I think the AN protagonists have been thinking
of the scope of AN being carrier, enterprise, and home networks.
Should we add IoT to the scope? I think it's an important
question, because it would put new meanings on "simple" and
"available resources". It seems obvious that IoT networks need
to be completely autonomic, but is it the *same* autonomic?

Regards
   Brian

On 17/06/2014 08:13, Michael Richardson wrote:
> I recognize that bootstrap is only one of the autonomic mechanisms that
> are relevant to this group.  I have much reading on the other aspects
> which I hope to get done.
> 
> The 6tisch security design team has been working on a "zero-touch" mechanism
> that would permit constrained devices to join a Lowpower/Loss Network (LLN)
> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
> done), or turning the WirelessHART (IEC62591) packet flow into something more
> IPv6-like.  While there are significant bits of design space to explore
> while trying to optimize packet count, size and total energy risk of the
> join protocol;  the idea that there should be a set of authorization tokens
> From the device vendor which would permit the network and new nodes to
> recognize each other has been central to all discussions.
> 
> while draft-pritikin-bootstrapping-keyinfrastructures and
>       draft-behringer-autonomic-bootstrap-00
> 
> have proposed valid high level concepts, I believe that specification of the
> authz token is critical for the IoT space.  A great concern that is that the
> LLNs created remain operational for decades at a time, and that the
> components can individually and also in aggregate be both (re-)sold,
> and/or the service provider operating the network be replaced.
> 
> (There are real life examples where a part of a 100 square mile refinery
> is actually sold to a competitor; obviously it doesn't get moved.  On the
> other side, one has the very real risk that you bought your sensor network
> From a "Nortel")
> 
> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is about an
> API between a (constrained) device and it's cryptographic hardware
> module/TPM.   It profiles a number of IETF PKIX specifications in a useful
> way, but there is little there in terms of actual protocol.  When it comes to
> what does an *DevID look like, in it's section 7.2.8, saying that the DN
> should contain a "serialNumber" attribute:
> 
>    The formatting of this field shall contain a unique X.500
>    Distinguished Name (DN). This may include the unique device serial number assigned by the manufacturer
>    or any other suitable unique DN value that the issuer prefers.
> 
> What I have observed is that there needs to be a way to clearly delegate from
> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
> SERVICE-PROVIDER.    It would significantly reduce the number of certificates
> in (non-constrained device) databases for some levels of this hierarchy if
> the IDevID were aggregateable in some fashion.  RFC3779 came to mind, which
> deals with delegation of Autonomous Systems Numbers (ASN) and IP address
> ranges from RIRs to LIRs to ISPs and Enterprises.
>           RFC3779: X.509 Extensions for IP Addresses and AS Identifiers
> 
> I created:
>     X509.v3 certificate extension for authorization of device ownership
>                  draft-richardson-6tisch-idevid-cert-00
> 
> which cribbed together via nroff2xml and a search and replace.
> 
> The Pritikin and Behringer documents seem to assume that the ultimate goal of
> the trusted enrollment process is to create a path in which "EST"= Enrollment
> over Secure Transport could operate that would permit a new locally
> significant certificate to be loaded into the new device.
> I agree with that goal.
> 
> There is the question of how that trust circuit is created, and in discussion
> it seemed that it involve some kind of leap-of-faith TLS setup which would be
> authenticated by the "authz" tokens later on.  I disagree; I think that with
> appropriate evaluation of path constraints that the authentication can occur
> within the TLS protocol. (Even easier if done in IKEv2)
> 
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
> 


From nobody Mon Jun 16 23:59:09 2014
Return-Path: <mbehring@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7E0D1A0299; Mon, 16 Jun 2014 23:59:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JIsampmaXL4O; Mon, 16 Jun 2014 23:59:02 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14D601A0286; Mon, 16 Jun 2014 23:59:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6259; q=dns/txt; s=iport; t=1402988342; x=1404197942; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=lpx2Qh+KDOEsZq+O9kCh+wXvbLgCKl+OUojMHFbZc3Q=; b=Wj5nU8VpoyNKungDPulc2qIrPH4C1HDmT2o8FGT4YLFMwpI2X8W4ak2Z L+35PvAnS/eLwNLiZoI2a5o5LxIu1cUGYmKvuGil/R6eMgK9EX7VTvmRO zcV0kHDz4GwF3BgySUbeV670vRhyktK8YH3PpyhwhnP06svSae5sV9flC Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AukGAFTmn1OtJV2T/2dsb2JhbABagw1SWql3AQEBAQEBBQGRaYc9AYEOFnWEAwEBAQMBAQEBNy0HCwUHBAIBCBEEAQEBChQJBycLFAkIAgQBDQUIEQKIHwgNyywXhWOIYjEHBoMngRYEnAaSFYNAgjA
X-IronPort-AV: E=Sophos;i="5.01,492,1400025600"; d="scan'208";a="53642551"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by alln-iport-7.cisco.com with ESMTP; 17 Jun 2014 06:59:01 +0000
Received: from xhc-rcd-x11.cisco.com (xhc-rcd-x11.cisco.com [173.37.183.85]) by rcdn-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id s5H6x1bV004389 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 17 Jun 2014 06:59:01 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.51]) by xhc-rcd-x11.cisco.com ([173.37.183.85]) with mapi id 14.03.0123.003; Tue, 17 Jun 2014 01:59:01 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, "anima@ietf.org" <anima@ietf.org>
Thread-Topic: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
Thread-Index: AQHPibbWdqAxK5GJ0ECGIzHVDHkcBZt03Xfg
Date: Tue, 17 Jun 2014 06:59:00 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com>
In-Reply-To: <539F771A.3000008@gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.238.137]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/ZCZOum2qNQLHTKhMg9gqMpVb-3U
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 06:59:06 -0000

> -----Original Message-----
> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
> Carpenter
> Sent: 17 June 2014 01:01
> To: anima@ietf.org
> Cc: 6tisch-security
> Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
>=20
> Michael's message is very interesting. For present purposes, i.e. getting
> ready for the UCAN BOF, do we need to add some points to the relevant use
> case draft (http://tools.ietf.org/html/draft-behringer-autonomic-
> bootstrap)?
>=20
> More generally - I think the AN protagonists have been thinking of the
> scope of AN being carrier, enterprise, and home networks.
> Should we add IoT to the scope? I think it's an important question, becau=
se
> it would put new meanings on "simple" and "available resources". It seems
> obvious that IoT networks need to be completely autonomic, but is it the
> *same* autonomic?

Brian, we have always positioned AN also in the IoT context, and I agree wi=
th Sheng, AN can be used everywhere. Especially when it comes to devices th=
at will be deployed and managed in the thousands or even millions, autonomi=
c concepts are a requirement, not a nice to have.=20

We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a hig=
h-level solution in 6tisch. It explains how you CAN bootstrap a network, ze=
ro-touch AND secure, and fits perfectly to the 6tisch requirements. The cor=
responding use case is described in draft-behringer-autonomic-bootstrap.=20

To me, the bootstrap problem is one of the real solid examples of autonomic=
 behaviour, because to bootstrap a device into a network I MUST have some f=
unctionality on the devices, ie, distribution is absolutely mandatory here.=
=20

So this is one of the criteria for the use cases: Is distribution a require=
ment? Because if it is, then this points very clearly to an autonomic solut=
ion.=20

Michael

=20
> Regards
>    Brian
>=20
> On 17/06/2014 08:13, Michael Richardson wrote:
> > I recognize that bootstrap is only one of the autonomic mechanisms
> > that are relevant to this group.  I have much reading on the other
> > aspects which I hope to get done.
> >
> > The 6tisch security design team has been working on a "zero-touch"
> > mechanism that would permit constrained devices to join a
> Lowpower/Loss Network (LLN)
> > in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
> > done), or turning the WirelessHART (IEC62591) packet flow into
> > something more IPv6-like.  While there are significant bits of design
> > space to explore while trying to optimize packet count, size and total
> > energy risk of the join protocol;  the idea that there should be a set
> > of authorization tokens From the device vendor which would permit the
> > network and new nodes to recognize each other has been central to all
> discussions.
> >
> > while draft-pritikin-bootstrapping-keyinfrastructures and
> >       draft-behringer-autonomic-bootstrap-00
> >
> > have proposed valid high level concepts, I believe that specification
> > of the authz token is critical for the IoT space.  A great concern
> > that is that the LLNs created remain operational for decades at a
> > time, and that the components can individually and also in aggregate
> > be both (re-)sold, and/or the service provider operating the network be
> replaced.
> >
> > (There are real life examples where a part of a 100 square mile
> > refinery is actually sold to a competitor; obviously it doesn't get
> > moved.  On the other side, one has the very real risk that you bought
> > your sensor network From a "Nortel")
> >
> > I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
> > about an API between a (constrained) device and it's cryptographic
> hardware
> > module/TPM.   It profiles a number of IETF PKIX specifications in a use=
ful
> > way, but there is little there in terms of actual protocol.  When it
> > comes to what does an *DevID look like, in it's section 7.2.8, saying
> > that the DN should contain a "serialNumber" attribute:
> >
> >    The formatting of this field shall contain a unique X.500
> >    Distinguished Name (DN). This may include the unique device serial
> number assigned by the manufacturer
> >    or any other suitable unique DN value that the issuer prefers.
> >
> > What I have observed is that there needs to be a way to clearly
> > delegate from
> > Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
> > SERVICE-PROVIDER.    It would significantly reduce the number of
> certificates
> > in (non-constrained device) databases for some levels of this
> > hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
> > came to mind, which deals with delegation of Autonomous Systems
> > Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
> Enterprises.
> >           RFC3779: X.509 Extensions for IP Addresses and AS
> > Identifiers
> >
> > I created:
> >     X509.v3 certificate extension for authorization of device ownership
> >                  draft-richardson-6tisch-idevid-cert-00
> >
> > which cribbed together via nroff2xml and a search and replace.
> >
> > The Pritikin and Behringer documents seem to assume that the ultimate
> > goal of the trusted enrollment process is to create a path in which
> > "EST"=3D Enrollment over Secure Transport could operate that would
> > permit a new locally significant certificate to be loaded into the new
> device.
> > I agree with that goal.
> >
> > There is the question of how that trust circuit is created, and in
> > discussion it seemed that it involve some kind of leap-of-faith TLS
> > setup which would be authenticated by the "authz" tokens later on.  I
> > disagree; I think that with appropriate evaluation of path constraints
> > that the authentication can occur within the TLS protocol. (Even
> > easier if done in IKEv2)
> >
> > --
> > Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
> Works
> > -=3D IPv6 IoT consulting =3D-
> >
>=20
> _______________________________________________
> Anima mailing list
> Anima@ietf.org
> https://www.ietf.org/mailman/listinfo/anima


From nobody Tue Jun 17 00:21:10 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD0EA1A02BC; Tue, 17 Jun 2014 00:21:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A6QCEBsgBmtx; Tue, 17 Jun 2014 00:21:06 -0700 (PDT)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 07DAE1A02BF; Tue, 17 Jun 2014 00:21:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7311; q=dns/txt; s=iport; t=1402989666; x=1404199266; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=NDRPzcfQ7RQq8/EVAw3NODrk/VsfoqYGb7QendTFadU=; b=iTpYHrD1RB9Un0fsIxR5W80FSJvuJC6o0R6uQg6d4ARsSI86/htqVK5m KMs5OC8W1aF37GutRaozv9RBIRXOHg6HRRi57M6KZXEFk+8gJy7cOs8YH ESZ/SD4kMQw2orTUh1A//B60aM5rVAatWm3Pa1D4MDNrEbr/Ute71GfuH k=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AloGAO/rn1OtJV2Q/2dsb2JhbABagw1STaoEAQEBAQEHkWmGbFEBgQ4WdYQDAQEBBAEBAWQHCwwEAgEIEQQBAQEnBycLFAkIAgQOBRkCiCcNyzIXhWOFdAGCazMHBoMngRYEigWQPoFDkhWBfoFC
X-IronPort-AV: E=Sophos;i="5.01,492,1400025600"; d="scan'208";a="53643757"
Received: from rcdn-core-8.cisco.com ([173.37.93.144]) by alln-iport-2.cisco.com with ESMTP; 17 Jun 2014 07:21:05 +0000
Received: from xhc-aln-x10.cisco.com (xhc-aln-x10.cisco.com [173.36.12.84]) by rcdn-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id s5H7L4So014818 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 17 Jun 2014 07:21:04 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.126]) by xhc-aln-x10.cisco.com ([173.36.12.84]) with mapi id 14.03.0123.003; Tue, 17 Jun 2014 02:21:04 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "Michael Behringer (mbehring)" <mbehring@cisco.com>
Thread-Topic: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
Thread-Index: AQHPibbWdqAxK5GJ0ECGIzHVDHkcBZt03XfggAAIgAY=
Date: Tue, 17 Jun 2014 07:21:03 +0000
Message-ID: <C49BA7DC-96AC-4B63-81D7-9009664F432D@cisco.com>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com>, <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
In-Reply-To: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/pQxxPsqKgyhcaZl4LdIuRikpcT4
Cc: 6tisch-security <6tisch-security@ietf.org>, Brian E Carpenter <brian.e.carpenter@gmail.com>, "anima@ietf.org" <anima@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 07:21:08 -0000

I agree with Michael,

As IT and more specifically IEEE/IETF technology is getting pervasive, we n=
eed to simplify commissioning and deployment in a fundamental manner.

There are no CCIEs in an oil field or a deep mine in Alaska and still growi=
ng amounts of IP and Ethernet devices get deployed in all sorts of places, =
homes, curbs, factory floors, you name it, with a renewed interest in wirel=
ess monitoring.

6TiSCH targets at some of those environments and it clearly requires AN for=
 use cases with huge scalability or ease-of-deployment constraints.

And certainly, the lack of CCIEs is more pervasive than just the WSN/6TiSCH=
...

Pascal

Le 17 juin 2014 =E0 08:59, "Michael Behringer (mbehring)" <mbehring@cisco.c=
om> a =E9crit :

>> -----Original Message-----
>> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
>> Carpenter
>> Sent: 17 June 2014 01:01
>> To: anima@ietf.org
>> Cc: 6tisch-security
>> Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
>>=20
>> Michael's message is very interesting. For present purposes, i.e. gettin=
g
>> ready for the UCAN BOF, do we need to add some points to the relevant us=
e
>> case draft (http://tools.ietf.org/html/draft-behringer-autonomic-
>> bootstrap)?
>>=20
>> More generally - I think the AN protagonists have been thinking of the
>> scope of AN being carrier, enterprise, and home networks.
>> Should we add IoT to the scope? I think it's an important question, beca=
use
>> it would put new meanings on "simple" and "available resources". It seem=
s
>> obvious that IoT networks need to be completely autonomic, but is it the
>> *same* autonomic?
>=20
> Brian, we have always positioned AN also in the IoT context, and I agree =
with Sheng, AN can be used everywhere. Especially when it comes to devices =
that will be deployed and managed in the thousands or even millions, autono=
mic concepts are a requirement, not a nice to have.=20
>=20
> We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a h=
igh-level solution in 6tisch. It explains how you CAN bootstrap a network, =
zero-touch AND secure, and fits perfectly to the 6tisch requirements. The c=
orresponding use case is described in draft-behringer-autonomic-bootstrap.=
=20
>=20
> To me, the bootstrap problem is one of the real solid examples of autonom=
ic behaviour, because to bootstrap a device into a network I MUST have some=
 functionality on the devices, ie, distribution is absolutely mandatory her=
e.=20
>=20
> So this is one of the criteria for the use cases: Is distribution a requi=
rement? Because if it is, then this points very clearly to an autonomic sol=
ution.=20
>=20
> Michael
>=20
>=20
>> Regards
>>   Brian
>>=20
>>> On 17/06/2014 08:13, Michael Richardson wrote:
>>> I recognize that bootstrap is only one of the autonomic mechanisms
>>> that are relevant to this group.  I have much reading on the other
>>> aspects which I hope to get done.
>>>=20
>>> The 6tisch security design team has been working on a "zero-touch"
>>> mechanism that would permit constrained devices to join a
>> Lowpower/Loss Network (LLN)
>>> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
>>> done), or turning the WirelessHART (IEC62591) packet flow into
>>> something more IPv6-like.  While there are significant bits of design
>>> space to explore while trying to optimize packet count, size and total
>>> energy risk of the join protocol;  the idea that there should be a set
>>> of authorization tokens From the device vendor which would permit the
>>> network and new nodes to recognize each other has been central to all
>> discussions.
>>>=20
>>> while draft-pritikin-bootstrapping-keyinfrastructures and
>>>      draft-behringer-autonomic-bootstrap-00
>>>=20
>>> have proposed valid high level concepts, I believe that specification
>>> of the authz token is critical for the IoT space.  A great concern
>>> that is that the LLNs created remain operational for decades at a
>>> time, and that the components can individually and also in aggregate
>>> be both (re-)sold, and/or the service provider operating the network be
>> replaced.
>>>=20
>>> (There are real life examples where a part of a 100 square mile
>>> refinery is actually sold to a competitor; obviously it doesn't get
>>> moved.  On the other side, one has the very real risk that you bought
>>> your sensor network From a "Nortel")
>>>=20
>>> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
>>> about an API between a (constrained) device and it's cryptographic
>> hardware
>>> module/TPM.   It profiles a number of IETF PKIX specifications in a use=
ful
>>> way, but there is little there in terms of actual protocol.  When it
>>> comes to what does an *DevID look like, in it's section 7.2.8, saying
>>> that the DN should contain a "serialNumber" attribute:
>>>=20
>>>   The formatting of this field shall contain a unique X.500
>>>   Distinguished Name (DN). This may include the unique device serial
>> number assigned by the manufacturer
>>>   or any other suitable unique DN value that the issuer prefers.
>>>=20
>>> What I have observed is that there needs to be a way to clearly
>>> delegate from
>>> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
>>> SERVICE-PROVIDER.    It would significantly reduce the number of
>> certificates
>>> in (non-constrained device) databases for some levels of this
>>> hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
>>> came to mind, which deals with delegation of Autonomous Systems
>>> Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
>> Enterprises.
>>>          RFC3779: X.509 Extensions for IP Addresses and AS
>>> Identifiers
>>>=20
>>> I created:
>>>    X509.v3 certificate extension for authorization of device ownership
>>>                 draft-richardson-6tisch-idevid-cert-00
>>>=20
>>> which cribbed together via nroff2xml and a search and replace.
>>>=20
>>> The Pritikin and Behringer documents seem to assume that the ultimate
>>> goal of the trusted enrollment process is to create a path in which
>>> "EST"=3D Enrollment over Secure Transport could operate that would
>>> permit a new locally significant certificate to be loaded into the new
>> device.
>>> I agree with that goal.
>>>=20
>>> There is the question of how that trust circuit is created, and in
>>> discussion it seemed that it involve some kind of leap-of-faith TLS
>>> setup which would be authenticated by the "authz" tokens later on.  I
>>> disagree; I think that with appropriate evaluation of path constraints
>>> that the authentication can occur within the TLS protocol. (Even
>>> easier if done in IKEv2)
>>>=20
>>> --
>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
>> Works
>>> -=3D IPv6 IoT consulting =3D-
>>=20
>> _______________________________________________
>> Anima mailing list
>> Anima@ietf.org
>> https://www.ietf.org/mailman/listinfo/anima
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Tue Jun 17 05:50:00 2014
Return-Path: <mbehring@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46D9D1A0376; Tue, 17 Jun 2014 05:49:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4UdZxiV2vBvp; Tue, 17 Jun 2014 05:49:53 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CE6CE1A0016; Tue, 17 Jun 2014 05:49:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7915; q=dns/txt; s=iport; t=1403009394; x=1404218994; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=dn546IJmcd4GVK8JikpFWHYe2s8FK2vOtooMRQ1C8WE=; b=Qc6fMp0RlcF8Rwx1iNUbiPn08/c5upJbbZumwtJtoSauwFEWSur2J5Z3 ToS7DOmgb3MgLmB4w/zMQ8WkJNigMRyV2zyDxP3TPnjb0yI4nKNU4NzVa t9VCYF9wcLTqjijKpukPZrhegBm2Hp0oet4UzMRncGFh5DtBtCHJs4tYr 4=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AukGAI44oFOtJA2K/2dsb2JhbABagw1SWql+AQEBAQEBBQGRaYc9AYEMFnWEAwEBAQMBAQEBNy0HCwUHBAIBCBEEAQEBChQJBycLFAkIAgQBDQUIEQKIHwgNy3oXhWOIMREBHzEHBoMngRYEnAaSFYNAgXc5
X-IronPort-AV: E=Sophos;i="5.01,493,1400025600"; d="scan'208";a="333641025"
Received: from alln-core-5.cisco.com ([173.36.13.138]) by rcdn-iport-7.cisco.com with ESMTP; 17 Jun 2014 12:49:53 +0000
Received: from xhc-aln-x11.cisco.com (xhc-aln-x11.cisco.com [173.36.12.85]) by alln-core-5.cisco.com (8.14.5/8.14.5) with ESMTP id s5HCnpI0008951 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 17 Jun 2014 12:49:51 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.51]) by xhc-aln-x11.cisco.com ([173.36.12.85]) with mapi id 14.03.0123.003; Tue, 17 Jun 2014 07:49:51 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: Balazs Lengyel <balazs.lengyel@ericsson.com>, Brian E Carpenter <brian.e.carpenter@gmail.com>, "anima@ietf.org" <anima@ietf.org>
Thread-Topic: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
Thread-Index: AQHPibbWdqAxK5GJ0ECGIzHVDHkcBZt03XfggABsLAD//8+9AA==
Date: Tue, 17 Jun 2014 12:49:51 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB5AB4@xmb-rcd-x14.cisco.com>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com> <539FF9AC.5000304@ericsson.com>
In-Reply-To: <539FF9AC.5000304@ericsson.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.18]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/hWcsy-5oDpQPAcv9wcG09pQ2xe4
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 12:49:58 -0000

> -----Original Message-----
> From: Balazs Lengyel [mailto:balazs.lengyel@ericsson.com]
> Sent: 17 June 2014 10:18
> To: Michael Behringer (mbehring); Brian E Carpenter; anima@ietf.org
> Cc: 6tisch-security
> Subject: Re: [Anima] Scope question [was: autonomic bootstrap: gap
> analysis]
>=20
> When speaking about bootstraping, does this have much in common with
> the
> http://tools.ietf.org/html/draft-kwatsen-netconf-zerotouch-01
> draft?
> regards balazs

In a nutshell:=20
draft-kwatsen-netconf-zerotouch-01 expects the config server URIs to be pre=
-provisioned. (If I understand it correctly, from section 4.1 - didn't read=
 the whole doc, so correct me if I'm wrong).=20
draft-pritikin-bootstrapping-keyinfrastructures does not require any pre-pr=
ovisioning. The new device "learns" to which network it belongs, and will f=
ind the servers through discovery.=20

Michael

> On 2014-06-17 08:59, Michael Behringer (mbehring) wrote:
> >> -----Original Message-----
> >> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
> >> Carpenter
> >> Sent: 17 June 2014 01:01
> >> To: anima@ietf.org
> >> Cc: 6tisch-security
> >> Subject: [Anima] Scope question [was: autonomic bootstrap: gap
> >> analysis]
> >>
> >> Michael's message is very interesting. For present purposes, i.e.
> >> getting ready for the UCAN BOF, do we need to add some points to the
> >> relevant use case draft
> >> (http://tools.ietf.org/html/draft-behringer-autonomic-
> >> bootstrap)?
> >>
> >> More generally - I think the AN protagonists have been thinking of
> >> the scope of AN being carrier, enterprise, and home networks.
> >> Should we add IoT to the scope? I think it's an important question,
> >> because it would put new meanings on "simple" and "available
> >> resources". It seems obvious that IoT networks need to be completely
> >> autonomic, but is it the
> >> *same* autonomic?
> > Brian, we have always positioned AN also in the IoT context, and I agre=
e
> with Sheng, AN can be used everywhere. Especially when it comes to
> devices that will be deployed and managed in the thousands or even
> millions, autonomic concepts are a requirement, not a nice to have.
> >
> > We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a
> high-level solution in 6tisch. It explains how you CAN bootstrap a networ=
k,
> zero-touch AND secure, and fits perfectly to the 6tisch requirements. The
> corresponding use case is described in draft-behringer-autonomic-
> bootstrap.
> >
> > To me, the bootstrap problem is one of the real solid examples of
> autonomic behaviour, because to bootstrap a device into a network I MUST
> have some functionality on the devices, ie, distribution is absolutely
> mandatory here.
> >
> > So this is one of the criteria for the use cases: Is distribution a
> requirement? Because if it is, then this points very clearly to an autono=
mic
> solution.
> >
> > Michael
> >
> >
> >> Regards
> >>     Brian
> >>
> >> On 17/06/2014 08:13, Michael Richardson wrote:
> >>> I recognize that bootstrap is only one of the autonomic mechanisms
> >>> that are relevant to this group.  I have much reading on the other
> >>> aspects which I hope to get done.
> >>>
> >>> The 6tisch security design team has been working on a "zero-touch"
> >>> mechanism that would permit constrained devices to join a
> >> Lowpower/Loss Network (LLN)
> >>> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP h=
as
> >>> done), or turning the WirelessHART (IEC62591) packet flow into
> >>> something more IPv6-like.  While there are significant bits of
> >>> design space to explore while trying to optimize packet count, size
> >>> and total energy risk of the join protocol;  the idea that there
> >>> should be a set of authorization tokens From the device vendor which
> >>> would permit the network and new nodes to recognize each other has
> >>> been central to all
> >> discussions.
> >>> while draft-pritikin-bootstrapping-keyinfrastructures and
> >>>        draft-behringer-autonomic-bootstrap-00
> >>>
> >>> have proposed valid high level concepts, I believe that
> >>> specification of the authz token is critical for the IoT space.  A
> >>> great concern that is that the LLNs created remain operational for
> >>> decades at a time, and that the components can individually and also
> >>> in aggregate be both (re-)sold, and/or the service provider
> >>> operating the network be
> >> replaced.
> >>> (There are real life examples where a part of a 100 square mile
> >>> refinery is actually sold to a competitor; obviously it doesn't get
> >>> moved.  On the other side, one has the very real risk that you
> >>> bought your sensor network From a "Nortel")
> >>>
> >>> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
> >>> about an API between a (constrained) device and it's cryptographic
> >> hardware
> >>> module/TPM.   It profiles a number of IETF PKIX specifications in a u=
seful
> >>> way, but there is little there in terms of actual protocol.  When it
> >>> comes to what does an *DevID look like, in it's section 7.2.8,
> >>> saying that the DN should contain a "serialNumber" attribute:
> >>>
> >>>     The formatting of this field shall contain a unique X.500
> >>>     Distinguished Name (DN). This may include the unique device
> >>> serial
> >> number assigned by the manufacturer
> >>>     or any other suitable unique DN value that the issuer prefers.
> >>>
> >>> What I have observed is that there needs to be a way to clearly
> >>> delegate from
> >>> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
> >>> SERVICE-PROVIDER.    It would significantly reduce the number of
> >> certificates
> >>> in (non-constrained device) databases for some levels of this
> >>> hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
> >>> came to mind, which deals with delegation of Autonomous Systems
> >>> Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
> >> Enterprises.
> >>>            RFC3779: X.509 Extensions for IP Addresses and AS
> >>> Identifiers
> >>>
> >>> I created:
> >>>      X509.v3 certificate extension for authorization of device owners=
hip
> >>>                   draft-richardson-6tisch-idevid-cert-00
> >>>
> >>> which cribbed together via nroff2xml and a search and replace.
> >>>
> >>> The Pritikin and Behringer documents seem to assume that the
> >>> ultimate goal of the trusted enrollment process is to create a path
> >>> in which "EST"=3D Enrollment over Secure Transport could operate that
> >>> would permit a new locally significant certificate to be loaded into
> >>> the new
> >> device.
> >>> I agree with that goal.
> >>>
> >>> There is the question of how that trust circuit is created, and in
> >>> discussion it seemed that it involve some kind of leap-of-faith TLS
> >>> setup which would be authenticated by the "authz" tokens later on.
> >>> I disagree; I think that with appropriate evaluation of path
> >>> constraints that the authentication can occur within the TLS
> >>> protocol. (Even easier if done in IKEv2)
> >>>
> >>> --
> >>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
> >> Works
> >>> -=3D IPv6 IoT consulting =3D-
> >>>
> >> _______________________________________________
> >> Anima mailing list
> >> Anima@ietf.org
> >> https://www.ietf.org/mailman/listinfo/anima
> > _______________________________________________
> > Anima mailing list
> > Anima@ietf.org
> > https://www.ietf.org/mailman/listinfo/anima
>=20
> --
> Balazs Lengyel                       Ericsson Hungary Ltd.
> System Manager
> ECN: 831 7320                        Tel: +36-1-437-7320
> Mobile: +36-70-330-7909              email: Balazs.Lengyel@ericsson.com


From nobody Tue Jun 17 07:33:00 2014
Return-Path: <balazs.lengyel@ericsson.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 505D51A030A; Tue, 17 Jun 2014 01:17:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aA_l88SZxUPa; Tue, 17 Jun 2014 01:17:53 -0700 (PDT)
Received: from sessmg22.ericsson.net (sessmg22.ericsson.net [193.180.251.58]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB4551A029F; Tue, 17 Jun 2014 01:17:52 -0700 (PDT)
X-AuditID: c1b4fb3a-f79746d000006fe2-74-539ff9ae3014
Received: from ESESSHC003.ericsson.se (Unknown_Domain [153.88.253.124]) by sessmg22.ericsson.net (Symantec Mail Security) with SMTP id 4B.A5.28642.EA9FF935; Tue, 17 Jun 2014 10:17:50 +0200 (CEST)
Received: from [159.107.197.187] (153.88.183.153) by smtp.internal.ericsson.com (153.88.183.29) with Microsoft SMTP Server id 14.3.174.1; Tue, 17 Jun 2014 10:17:48 +0200
Message-ID: <539FF9AC.5000304@ericsson.com>
Date: Tue, 17 Jun 2014 10:17:48 +0200
From: Balazs Lengyel <balazs.lengyel@ericsson.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Michael Behringer (mbehring)" <mbehring@cisco.com>, Brian E Carpenter <brian.e.carpenter@gmail.com>, "anima@ietf.org" <anima@ietf.org>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
In-Reply-To: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format=flowed
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrCLMWRmVeSWpSXmKPExsUyM+Jvje66n/ODDSbfVLJoXrmI3eLhoutM Fm0X9zFZXJt3kdmBxWPK742sHjtn3WX3WLLkJ1MAcxSXTUpqTmZZapG+XQJXxpMJ/AWzTCvO XepnbmBs0O5i5OSQEDCRODlrLiOELSZx4d56ti5GLg4hgaOMEkv/7IVy1jJK7Jx1Esjh4OAV 0Ja43JUG0sAioCrR/e43WDObgJHE1P7zLCC2qECUxK6+X+wgNq+AoMTJmU9YQOaICPQySrSv u8UGkmAW0JOY8RVis7CAj8TZx5vA4kICnYwS765KgticAr4Sk883s0LU20pcmHOdBcKWl9j+ dg4zRL2GxMMLf1knMArOQrJvFpKWWUhaFjAyr2IULU4tLs5NNzLSSy3KTC4uzs/Ty0st2cQI DOaDW35b7WA8+NzxEKMAB6MSD+8Cg/nBQqyJZcWVuYcYpTlYlMR5F56bFywkkJ5YkpqdmlqQ WhRfVJqTWnyIkYmDU6qBsbTLK+l/Tkjpjq4DG7xeXjicrNPSznx+9gOZbZ//HFJ0bN1S37TZ 72Fv1JW32TlGnIGxmaeXX3n7v3nmp3++9W8PJupGVW2S+y+d8utdSd3bZpkNjV//HX1aUWt0 MKpOxuP7pMedUgL1B3sXBwUF//NdaHauVSrxiJ6vcM3EPxsnLGH8LMU7S4mlOCPRUIu5qDgR AOupTohHAgAA
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/oHn0aWlTde_w-iX9gZV6irFPiFA
X-Mailman-Approved-At: Tue, 17 Jun 2014 07:32:59 -0700
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 08:17:58 -0000

When speaking about bootstraping, does this have much in common with the
http://tools.ietf.org/html/draft-kwatsen-netconf-zerotouch-01
draft?
regards balazs

On 2014-06-17 08:59, Michael Behringer (mbehring) wrote:
>> -----Original Message-----
>> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
>> Carpenter
>> Sent: 17 June 2014 01:01
>> To: anima@ietf.org
>> Cc: 6tisch-security
>> Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
>>
>> Michael's message is very interesting. For present purposes, i.e. getting
>> ready for the UCAN BOF, do we need to add some points to the relevant use
>> case draft (http://tools.ietf.org/html/draft-behringer-autonomic-
>> bootstrap)?
>>
>> More generally - I think the AN protagonists have been thinking of the
>> scope of AN being carrier, enterprise, and home networks.
>> Should we add IoT to the scope? I think it's an important question, because
>> it would put new meanings on "simple" and "available resources". It seems
>> obvious that IoT networks need to be completely autonomic, but is it the
>> *same* autonomic?
> Brian, we have always positioned AN also in the IoT context, and I agree with Sheng, AN can be used everywhere. Especially when it comes to devices that will be deployed and managed in the thousands or even millions, autonomic concepts are a requirement, not a nice to have.
>
> We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a high-level solution in 6tisch. It explains how you CAN bootstrap a network, zero-touch AND secure, and fits perfectly to the 6tisch requirements. The corresponding use case is described in draft-behringer-autonomic-bootstrap.
>
> To me, the bootstrap problem is one of the real solid examples of autonomic behaviour, because to bootstrap a device into a network I MUST have some functionality on the devices, ie, distribution is absolutely mandatory here.
>
> So this is one of the criteria for the use cases: Is distribution a requirement? Because if it is, then this points very clearly to an autonomic solution.
>
> Michael
>
>   
>> Regards
>>     Brian
>>
>> On 17/06/2014 08:13, Michael Richardson wrote:
>>> I recognize that bootstrap is only one of the autonomic mechanisms
>>> that are relevant to this group.  I have much reading on the other
>>> aspects which I hope to get done.
>>>
>>> The 6tisch security design team has been working on a "zero-touch"
>>> mechanism that would permit constrained devices to join a
>> Lowpower/Loss Network (LLN)
>>> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
>>> done), or turning the WirelessHART (IEC62591) packet flow into
>>> something more IPv6-like.  While there are significant bits of design
>>> space to explore while trying to optimize packet count, size and total
>>> energy risk of the join protocol;  the idea that there should be a set
>>> of authorization tokens From the device vendor which would permit the
>>> network and new nodes to recognize each other has been central to all
>> discussions.
>>> while draft-pritikin-bootstrapping-keyinfrastructures and
>>>        draft-behringer-autonomic-bootstrap-00
>>>
>>> have proposed valid high level concepts, I believe that specification
>>> of the authz token is critical for the IoT space.  A great concern
>>> that is that the LLNs created remain operational for decades at a
>>> time, and that the components can individually and also in aggregate
>>> be both (re-)sold, and/or the service provider operating the network be
>> replaced.
>>> (There are real life examples where a part of a 100 square mile
>>> refinery is actually sold to a competitor; obviously it doesn't get
>>> moved.  On the other side, one has the very real risk that you bought
>>> your sensor network From a "Nortel")
>>>
>>> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
>>> about an API between a (constrained) device and it's cryptographic
>> hardware
>>> module/TPM.   It profiles a number of IETF PKIX specifications in a useful
>>> way, but there is little there in terms of actual protocol.  When it
>>> comes to what does an *DevID look like, in it's section 7.2.8, saying
>>> that the DN should contain a "serialNumber" attribute:
>>>
>>>     The formatting of this field shall contain a unique X.500
>>>     Distinguished Name (DN). This may include the unique device serial
>> number assigned by the manufacturer
>>>     or any other suitable unique DN value that the issuer prefers.
>>>
>>> What I have observed is that there needs to be a way to clearly
>>> delegate from
>>> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
>>> SERVICE-PROVIDER.    It would significantly reduce the number of
>> certificates
>>> in (non-constrained device) databases for some levels of this
>>> hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
>>> came to mind, which deals with delegation of Autonomous Systems
>>> Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
>> Enterprises.
>>>            RFC3779: X.509 Extensions for IP Addresses and AS
>>> Identifiers
>>>
>>> I created:
>>>      X509.v3 certificate extension for authorization of device ownership
>>>                   draft-richardson-6tisch-idevid-cert-00
>>>
>>> which cribbed together via nroff2xml and a search and replace.
>>>
>>> The Pritikin and Behringer documents seem to assume that the ultimate
>>> goal of the trusted enrollment process is to create a path in which
>>> "EST"= Enrollment over Secure Transport could operate that would
>>> permit a new locally significant certificate to be loaded into the new
>> device.
>>> I agree with that goal.
>>>
>>> There is the question of how that trust circuit is created, and in
>>> discussion it seemed that it involve some kind of leap-of-faith TLS
>>> setup which would be authenticated by the "authz" tokens later on.  I
>>> disagree; I think that with appropriate evaluation of path constraints
>>> that the authentication can occur within the TLS protocol. (Even
>>> easier if done in IKEv2)
>>>
>>> --
>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
>> Works
>>> -= IPv6 IoT consulting =-
>>>
>> _______________________________________________
>> Anima mailing list
>> Anima@ietf.org
>> https://www.ietf.org/mailman/listinfo/anima
> _______________________________________________
> Anima mailing list
> Anima@ietf.org
> https://www.ietf.org/mailman/listinfo/anima

-- 
Balazs Lengyel                       Ericsson Hungary Ltd.
System Manager
ECN: 831 7320                        Tel: +36-1-437-7320
Mobile: +36-70-330-7909              email: Balazs.Lengyel@ericsson.com


From nobody Tue Jun 17 07:33:30 2014
Return-Path: <jiangsheng@huawei.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 628BF1A0284; Mon, 16 Jun 2014 23:19:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.852
X-Spam-Level: 
X-Spam-Status: No, score=-4.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7GmRpHpVEKSU; Mon, 16 Jun 2014 23:19:23 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 663C31A027F; Mon, 16 Jun 2014 23:19:22 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml406-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BFM87509; Tue, 17 Jun 2014 06:19:21 +0000 (GMT)
Received: from NKGEML403-HUB.china.huawei.com (10.98.56.34) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 17 Jun 2014 07:19:20 +0100
Received: from NKGEML512-MBX.china.huawei.com ([169.254.7.68]) by nkgeml403-hub.china.huawei.com ([10.98.56.34]) with mapi id 14.03.0158.001; Tue, 17 Jun 2014 14:19:15 +0800
From: Sheng Jiang <jiangsheng@huawei.com>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, "anima@ietf.org" <anima@ietf.org>
Thread-Topic: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
Thread-Index: AQHPibbV52AKeSyN3kOxWJK/qa8C6Jt0rREQ
Date: Tue, 17 Jun 2014 06:19:14 +0000
Message-ID: <5D36713D8A4E7348A7E10DF7437A4B923AE8CBDD@nkgeml512-mbx.china.huawei.com>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com>
In-Reply-To: <539F771A.3000008@gmail.com>
Accept-Language: en-GB, zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.111.98.145]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/P4vZy_XfeV7sbqEGahd8np9PvJ8
X-Mailman-Approved-At: Tue, 17 Jun 2014 07:33:21 -0700
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 06:19:26 -0000

Pk1pY2hhZWwncyBtZXNzYWdlIGlzIHZlcnkgaW50ZXJlc3RpbmcuIEZvciBwcmVzZW50IHB1cnBv
c2VzLA0KPmkuZS4gZ2V0dGluZyByZWFkeSBmb3IgdGhlIFVDQU4gQk9GLCBkbyB3ZSBuZWVkIHRv
IGFkZCBzb21lDQo+cG9pbnRzIHRvIHRoZSByZWxldmFudCB1c2UgY2FzZSBkcmFmdA0KPihodHRw
Oi8vdG9vbHMuaWV0Zi5vcmcvaHRtbC9kcmFmdC1iZWhyaW5nZXItYXV0b25vbWljLWJvb3RzdHJh
cCk/DQo+DQo+TW9yZSBnZW5lcmFsbHkgLSBJIHRoaW5rIHRoZSBBTiBwcm90YWdvbmlzdHMgaGF2
ZSBiZWVuIHRoaW5raW5nDQo+b2YgdGhlIHNjb3BlIG9mIEFOIGJlaW5nIGNhcnJpZXIsIGVudGVy
cHJpc2UsIGFuZCBob21lIG5ldHdvcmtzLg0KPlNob3VsZCB3ZSBhZGQgSW9UIHRvIHRoZSBzY29w
ZT8gSSB0aGluayBpdCdzIGFuIGltcG9ydGFudA0KPnF1ZXN0aW9uLCBiZWNhdXNlIGl0IHdvdWxk
IHB1dCBuZXcgbWVhbmluZ3Mgb24gInNpbXBsZSIgYW5kDQo+ImF2YWlsYWJsZSByZXNvdXJjZXMi
LiBJdCBzZWVtcyBvYnZpb3VzIHRoYXQgSW9UIG5ldHdvcmtzIG5lZWQNCj50byBiZSBjb21wbGV0
ZWx5IGF1dG9ub21pYywgYnV0IGlzIGl0IHRoZSAqc2FtZSogYXV0b25vbWljPw0KDQpJbmRlZWQs
IHRoZSBzY29wZSBpcyBhbiBpbXBvcnRhbnQgcXVlc3Rpb24uIEZvciBtZSwgdGhlIGFuc3dlciBy
ZWx5IG9uIHNvbHV0aW9uIHJhdGhlciB0aGFuIGF1dG9ub21pYyBjb25jZXB0LiBFdmVyeSBuZXR3
b3JrLCBubyBtYXR0ZXIgd2hhdCBraW5kIG9mIG5ldHdvcmsgaXQgaXMsIGhhcyB0aGUgcmVxdWly
ZW1lbnRzIHRvIGJlIGF1dG9ub21pYywgb3IgbW9yZSBhbmQgbW9yZSBhdXRvbm9taWMuIEhvd2V2
ZXIsIGdpdmluZyB0aGUgZGlmZmVyZW5jZXMgb2YgdGhlc2UgbmV0d29ya3MsIHdlIG1heSBub3Qg
YmUgYWJsZSB0byBmaW5kIGEgZ2VuZXJpYyBzb2x1dGlvbiB0aGF0IHN1aXRzIGFsbC4gSXQgaXMg
dGltZSBmb3IgdXMgdG8gc3RhcnQgZGlzY3VzcyB0aGUgcG90ZW50aWFsIHNvbHV0aW9uIGFuZCB0
aGVpciBzdWl0YWJsZSBzY2VuYXJpb3MuIEFmdGVyIHRoZW4sIHdlIG1heSBrbm93IHdoZXRoZXIg
d2UgY2FuIHVuaWZ5IGludG8gdGhlIHNhbWUgYXV0b25vbWljIG5ldHdvcmsgb3Igd2UgaGF2ZSB0
byBzZXR0bGUgb24gbW9yZSB0aGFuIG9uZSBhdXRvbm9taWMgbmV0d29yayBhcmNoaXRlY3R1cmUu
DQoNClJlZ2FyZHMsDQoNClNoZW5nDQoNCj5SZWdhcmRzDQo+ICAgQnJpYW4NCj4NCj5PbiAxNy8w
Ni8yMDE0IDA4OjEzLCBNaWNoYWVsIFJpY2hhcmRzb24gd3JvdGU6DQo+PiBJIHJlY29nbml6ZSB0
aGF0IGJvb3RzdHJhcCBpcyBvbmx5IG9uZSBvZiB0aGUgYXV0b25vbWljIG1lY2hhbmlzbXMgdGhh
dA0KPj4gYXJlIHJlbGV2YW50IHRvIHRoaXMgZ3JvdXAuICBJIGhhdmUgbXVjaCByZWFkaW5nIG9u
IHRoZSBvdGhlciBhc3BlY3RzDQo+PiB3aGljaCBJIGhvcGUgdG8gZ2V0IGRvbmUuDQo+Pg0KPj4g
VGhlIDZ0aXNjaCBzZWN1cml0eSBkZXNpZ24gdGVhbSBoYXMgYmVlbiB3b3JraW5nIG9uIGEgInpl
cm8tdG91Y2giDQo+bWVjaGFuaXNtDQo+PiB0aGF0IHdvdWxkIHBlcm1pdCBjb25zdHJhaW5lZCBk
ZXZpY2VzIHRvIGpvaW4gYSBMb3dwb3dlci9Mb3NzIE5ldHdvcmsNCj4oTExOKQ0KPj4gaW4gYSBz
ZWN1cmUgd2F5LiAgIFdlIGhhdmUgY29uc2lkZXJlZCBhZGFwdGluZyBFQVAtVExTIChhcyBaaWdi
ZWVJUCBoYXMNCj4+IGRvbmUpLCBvciB0dXJuaW5nIHRoZSBXaXJlbGVzc0hBUlQgKElFQzYyNTkx
KSBwYWNrZXQgZmxvdyBpbnRvIHNvbWV0aGluZw0KPm1vcmUNCj4+IElQdjYtbGlrZS4gIFdoaWxl
IHRoZXJlIGFyZSBzaWduaWZpY2FudCBiaXRzIG9mIGRlc2lnbiBzcGFjZSB0byBleHBsb3JlDQo+
PiB3aGlsZSB0cnlpbmcgdG8gb3B0aW1pemUgcGFja2V0IGNvdW50LCBzaXplIGFuZCB0b3RhbCBl
bmVyZ3kgcmlzayBvZiB0aGUNCj4+IGpvaW4gcHJvdG9jb2w7ICB0aGUgaWRlYSB0aGF0IHRoZXJl
IHNob3VsZCBiZSBhIHNldCBvZiBhdXRob3JpemF0aW9uIHRva2Vucw0KPj4gRnJvbSB0aGUgZGV2
aWNlIHZlbmRvciB3aGljaCB3b3VsZCBwZXJtaXQgdGhlIG5ldHdvcmsgYW5kIG5ldyBub2RlcyB0
bw0KPj4gcmVjb2duaXplIGVhY2ggb3RoZXIgaGFzIGJlZW4gY2VudHJhbCB0byBhbGwgZGlzY3Vz
c2lvbnMuDQo+Pg0KPj4gd2hpbGUgZHJhZnQtcHJpdGlraW4tYm9vdHN0cmFwcGluZy1rZXlpbmZy
YXN0cnVjdHVyZXMgYW5kDQo+PiAgICAgICBkcmFmdC1iZWhyaW5nZXItYXV0b25vbWljLWJvb3Rz
dHJhcC0wMA0KPj4NCj4+IGhhdmUgcHJvcG9zZWQgdmFsaWQgaGlnaCBsZXZlbCBjb25jZXB0cywg
SSBiZWxpZXZlIHRoYXQgc3BlY2lmaWNhdGlvbiBvZiB0aGUNCj4+IGF1dGh6IHRva2VuIGlzIGNy
aXRpY2FsIGZvciB0aGUgSW9UIHNwYWNlLiAgQSBncmVhdCBjb25jZXJuIHRoYXQgaXMgdGhhdCB0
aGUNCj4+IExMTnMgY3JlYXRlZCByZW1haW4gb3BlcmF0aW9uYWwgZm9yIGRlY2FkZXMgYXQgYSB0
aW1lLCBhbmQgdGhhdCB0aGUNCj4+IGNvbXBvbmVudHMgY2FuIGluZGl2aWR1YWxseSBhbmQgYWxz
byBpbiBhZ2dyZWdhdGUgYmUgYm90aCAocmUtKXNvbGQsDQo+PiBhbmQvb3IgdGhlIHNlcnZpY2Ug
cHJvdmlkZXIgb3BlcmF0aW5nIHRoZSBuZXR3b3JrIGJlIHJlcGxhY2VkLg0KPj4NCj4+IChUaGVy
ZSBhcmUgcmVhbCBsaWZlIGV4YW1wbGVzIHdoZXJlIGEgcGFydCBvZiBhIDEwMCBzcXVhcmUgbWls
ZSByZWZpbmVyeQ0KPj4gaXMgYWN0dWFsbHkgc29sZCB0byBhIGNvbXBldGl0b3I7IG9idmlvdXNs
eSBpdCBkb2Vzbid0IGdldCBtb3ZlZC4gIE9uIHRoZQ0KPj4gb3RoZXIgc2lkZSwgb25lIGhhcyB0
aGUgdmVyeSByZWFsIHJpc2sgdGhhdCB5b3UgYm91Z2h0IHlvdXIgc2Vuc29yIG5ldHdvcmsNCj4+
IEZyb20gYSAiTm9ydGVsIikNCj4+DQo+PiBJIHdhcyBwb2ludGVkIGF0IDgwMi4xQVIncyBkZXZp
Y2UgSUQgbWVjaGFuaXNtLiAgUmVhbGx5LCA4MDIuMUFSIGlzIGFib3V0DQo+YW4NCj4+IEFQSSBi
ZXR3ZWVuIGEgKGNvbnN0cmFpbmVkKSBkZXZpY2UgYW5kIGl0J3MgY3J5cHRvZ3JhcGhpYyBoYXJk
d2FyZQ0KPj4gbW9kdWxlL1RQTS4gICBJdCBwcm9maWxlcyBhIG51bWJlciBvZiBJRVRGIFBLSVgg
c3BlY2lmaWNhdGlvbnMgaW4gYSB1c2VmdWwNCj4+IHdheSwgYnV0IHRoZXJlIGlzIGxpdHRsZSB0
aGVyZSBpbiB0ZXJtcyBvZiBhY3R1YWwgcHJvdG9jb2wuICBXaGVuIGl0IGNvbWVzIHRvDQo+PiB3
aGF0IGRvZXMgYW4gKkRldklEIGxvb2sgbGlrZSwgaW4gaXQncyBzZWN0aW9uIDcuMi44LCBzYXlp
bmcgdGhhdCB0aGUgRE4NCj4+IHNob3VsZCBjb250YWluIGEgInNlcmlhbE51bWJlciIgYXR0cmli
dXRlOg0KPj4NCj4+ICAgIFRoZSBmb3JtYXR0aW5nIG9mIHRoaXMgZmllbGQgc2hhbGwgY29udGFp
biBhIHVuaXF1ZSBYLjUwMA0KPj4gICAgRGlzdGluZ3Vpc2hlZCBOYW1lIChETikuIFRoaXMgbWF5
IGluY2x1ZGUgdGhlIHVuaXF1ZSBkZXZpY2Ugc2VyaWFsDQo+bnVtYmVyIGFzc2lnbmVkIGJ5IHRo
ZSBtYW51ZmFjdHVyZXINCj4+ICAgIG9yIGFueSBvdGhlciBzdWl0YWJsZSB1bmlxdWUgRE4gdmFs
dWUgdGhhdCB0aGUgaXNzdWVyIHByZWZlcnMuDQo+Pg0KPj4gV2hhdCBJIGhhdmUgb2JzZXJ2ZWQg
aXMgdGhhdCB0aGVyZSBuZWVkcyB0byBiZSBhIHdheSB0byBjbGVhcmx5IGRlbGVnYXRlDQo+ZnJv
bQ0KPj4gRmFjdG9yeShWZW5kb3IpIHRvIFZBUiB0byBESVNUUklCVVRPUiB0byBSRVNFTExFUiB0
byBQbGFudC1PV05FUiB0bw0KPj4gU0VSVklDRS1QUk9WSURFUi4gICAgSXQgd291bGQgc2lnbmlm
aWNhbnRseSByZWR1Y2UgdGhlIG51bWJlciBvZg0KPmNlcnRpZmljYXRlcw0KPj4gaW4gKG5vbi1j
b25zdHJhaW5lZCBkZXZpY2UpIGRhdGFiYXNlcyBmb3Igc29tZSBsZXZlbHMgb2YgdGhpcyBoaWVy
YXJjaHkgaWYNCj4+IHRoZSBJRGV2SUQgd2VyZSBhZ2dyZWdhdGVhYmxlIGluIHNvbWUgZmFzaGlv
bi4gIFJGQzM3NzkgY2FtZSB0byBtaW5kLA0KPndoaWNoDQo+PiBkZWFscyB3aXRoIGRlbGVnYXRp
b24gb2YgQXV0b25vbW91cyBTeXN0ZW1zIE51bWJlcnMgKEFTTikgYW5kIElQDQo+YWRkcmVzcw0K
Pj4gcmFuZ2VzIGZyb20gUklScyB0byBMSVJzIHRvIElTUHMgYW5kIEVudGVycHJpc2VzLg0KPj4g
ICAgICAgICAgIFJGQzM3Nzk6IFguNTA5IEV4dGVuc2lvbnMgZm9yIElQIEFkZHJlc3NlcyBhbmQg
QVMgSWRlbnRpZmllcnMNCj4+DQo+PiBJIGNyZWF0ZWQ6DQo+PiAgICAgWDUwOS52MyBjZXJ0aWZp
Y2F0ZSBleHRlbnNpb24gZm9yIGF1dGhvcml6YXRpb24gb2YgZGV2aWNlIG93bmVyc2hpcA0KPj4g
ICAgICAgICAgICAgICAgICBkcmFmdC1yaWNoYXJkc29uLTZ0aXNjaC1pZGV2aWQtY2VydC0wMA0K
Pj4NCj4+IHdoaWNoIGNyaWJiZWQgdG9nZXRoZXIgdmlhIG5yb2ZmMnhtbCBhbmQgYSBzZWFyY2gg
YW5kIHJlcGxhY2UuDQo+Pg0KPj4gVGhlIFByaXRpa2luIGFuZCBCZWhyaW5nZXIgZG9jdW1lbnRz
IHNlZW0gdG8gYXNzdW1lIHRoYXQgdGhlIHVsdGltYXRlDQo+Z29hbCBvZg0KPj4gdGhlIHRydXN0
ZWQgZW5yb2xsbWVudCBwcm9jZXNzIGlzIHRvIGNyZWF0ZSBhIHBhdGggaW4gd2hpY2ggIkVTVCI9
DQo+RW5yb2xsbWVudA0KPj4gb3ZlciBTZWN1cmUgVHJhbnNwb3J0IGNvdWxkIG9wZXJhdGUgdGhh
dCB3b3VsZCBwZXJtaXQgYSBuZXcgbG9jYWxseQ0KPj4gc2lnbmlmaWNhbnQgY2VydGlmaWNhdGUg
dG8gYmUgbG9hZGVkIGludG8gdGhlIG5ldyBkZXZpY2UuDQo+PiBJIGFncmVlIHdpdGggdGhhdCBn
b2FsLg0KPj4NCj4+IFRoZXJlIGlzIHRoZSBxdWVzdGlvbiBvZiBob3cgdGhhdCB0cnVzdCBjaXJj
dWl0IGlzIGNyZWF0ZWQsIGFuZCBpbiBkaXNjdXNzaW9uDQo+PiBpdCBzZWVtZWQgdGhhdCBpdCBp
bnZvbHZlIHNvbWUga2luZCBvZiBsZWFwLW9mLWZhaXRoIFRMUyBzZXR1cCB3aGljaCB3b3VsZA0K
PmJlDQo+PiBhdXRoZW50aWNhdGVkIGJ5IHRoZSAiYXV0aHoiIHRva2VucyBsYXRlciBvbi4gIEkg
ZGlzYWdyZWU7IEkgdGhpbmsgdGhhdCB3aXRoDQo+PiBhcHByb3ByaWF0ZSBldmFsdWF0aW9uIG9m
IHBhdGggY29uc3RyYWludHMgdGhhdCB0aGUgYXV0aGVudGljYXRpb24gY2FuDQo+b2NjdXINCj4+
IHdpdGhpbiB0aGUgVExTIHByb3RvY29sLiAoRXZlbiBlYXNpZXIgaWYgZG9uZSBpbiBJS0V2MikN
Cj4+DQo+PiAtLQ0KPj4gTWljaGFlbCBSaWNoYXJkc29uIDxtY3IrSUVURkBzYW5kZWxtYW4uY2E+
LCBTYW5kZWxtYW4gU29mdHdhcmUNCj5Xb3Jrcw0KPj4gIC09IElQdjYgSW9UIGNvbnN1bHRpbmcg
PS0NCj4+DQo+DQo+X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X18NCj5BbmltYSBtYWlsaW5nIGxpc3QNCj5BbmltYUBpZXRmLm9yZw0KPmh0dHBzOi8vd3d3Lmll
dGYub3JnL21haWxtYW4vbGlzdGluZm8vYW5pbWENCg==


From nobody Tue Jun 17 07:33:45 2014
Return-Path: <laurent.ciavaglia@alcatel-lucent.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A82C1A0304; Tue, 17 Jun 2014 01:04:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XvVtDyemaYht; Tue, 17 Jun 2014 01:04:04 -0700 (PDT)
Received: from ihemail1.lucent.com (ihemail1.lucent.com [135.245.0.33]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E33D1A02F9; Tue, 17 Jun 2014 01:04:04 -0700 (PDT)
Received: from us70tusmtp2.zam.alcatel-lucent.com (h135-5-2-64.lucent.com [135.5.2.64]) by ihemail1.lucent.com (8.13.8/IER-o) with ESMTP id s5H8415Y001101 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Tue, 17 Jun 2014 03:04:01 -0500 (CDT)
Received: from US70TWXCHHUB03.zam.alcatel-lucent.com (us70twxchhub03.zam.alcatel-lucent.com [135.5.2.35]) by us70tusmtp2.zam.alcatel-lucent.com (GMO) with ESMTP id s5H841bZ028010 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 17 Jun 2014 04:04:01 -0400
Received: from [135.244.33.51] (135.5.27.16) by US70TWXCHHUB03.zam.alcatel-lucent.com (135.5.2.35) with Microsoft SMTP Server (TLS) id 14.2.247.3; Tue, 17 Jun 2014 04:03:59 -0400
Message-ID: <539FF669.7020001@alcatel-lucent.com>
Date: Tue, 17 Jun 2014 10:03:53 +0200
From: Laurent Ciavaglia <Laurent.Ciavaglia@alcatel-lucent.com>
Organization: Alcatel-Lucent Bell Labs France
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Michael Behringer (mbehring)" <mbehring@cisco.com>, "anima@ietf.org" <anima@ietf.org>, <6tisch-security@ietf.org>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
In-Reply-To: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
Content-Type: multipart/alternative; boundary="------------070302050706030409050707"
X-Originating-IP: [135.5.27.16]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Bs6lbKTKNgeINbAbBSGJXD9djS4
X-Mailman-Approved-At: Tue, 17 Jun 2014 07:33:36 -0700
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 08:04:09 -0000

--------------070302050706030409050707
Content-Type: text/plain; charset="ISO-8859-1"; format=flowed
Content-Transfer-Encoding: 7bit

Dear Michael, all,

It's nice to see inputs/thoughts from very different domains (IoT) 
coming in!

Connected devices or entities are for sure in the scope of applicability 
for autonomic networking. And if we consider the future 5G networks, the 
number of connected "nodes" will be even more important and will put 
even more pressure on the (operators of the) networking infrastructures 
to cope with e.g. up-to-date/synchronized inventory (just to name one).
In this context, autonomic technologies definitely make sense: to 
address scalability, optimisation/adaptation of the control 
process/functions, coordination/orchestration among autonomic 
nodes/functions, etc).

If we speak IoT/Smart objects, I see a clear and easy first link with 
SmartHome (homenet), and as long as we see a _role_ for the network 
(thus the "_connecte__d_" x), and someone acting as an "operator" (not 
necessarily a classical telco carrier: e.g. who the homenet 
operator(s)?), there is a place for autonomic technologies.

What we can provide (ultimately)  is a (consistent/integrated?) set of 
autonomic/management tools for these very operators applicable in the 
different technological/industrial domains (smart homes, smart cities... 
and of course also "purely" telecommuncations networks). Of course one 
goal would be to not re-specify/develop the core solutions for all the 
different domains. This is very much in line with one of our goals in 
this BoF to identify commonalities that will drive the 
protocol/architecture work.
Autonomic networking will/should develop and provide both the 
procotols/mechanisms and the right (simple, extensible, composable) 
interfaces for operators to use them (in different domains).

As for the point on distribution, I don't know how to phrase it, but it 
is even more than a requirement, it is part of the nature of any 
networked environment: distributed in nature. So we will have to 
"attach" a number of basic/essential (autonomic) functionality to the 
(distributed) "nodes". Secured bootstrap is one. Others well-known ones 
could be (TBD): discovery, information exchange, capability negotiation, 
enforcement, group communications...

Best regards, Laurent.


On 17/06/2014 08:59, Michael Behringer (mbehring) wrote:
>> -----Original Message-----
>> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
>> Carpenter
>> Sent: 17 June 2014 01:01
>> To:anima@ietf.org
>> Cc: 6tisch-security
>> Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
>>
>> Michael's message is very interesting. For present purposes, i.e. getting
>> ready for the UCAN BOF, do we need to add some points to the relevant use
>> case draft (http://tools.ietf.org/html/draft-behringer-autonomic-
>> bootstrap)?
>>
>> More generally - I think the AN protagonists have been thinking of the
>> scope of AN being carrier, enterprise, and home networks.
>> Should we add IoT to the scope? I think it's an important question, because
>> it would put new meanings on "simple" and "available resources". It seems
>> obvious that IoT networks need to be completely autonomic, but is it the
>> *same* autonomic?
> Brian, we have always positioned AN also in the IoT context, and I agree with Sheng, AN can be used everywhere. Especially when it comes to devices that will be deployed and managed in the thousands or even millions, autonomic concepts are a requirement, not a nice to have.
>
> We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a high-level solution in 6tisch. It explains how you CAN bootstrap a network, zero-touch AND secure, and fits perfectly to the 6tisch requirements. The corresponding use case is described in draft-behringer-autonomic-bootstrap.
>
> To me, the bootstrap problem is one of the real solid examples of autonomic behaviour, because to bootstrap a device into a network I MUST have some functionality on the devices, ie, distribution is absolutely mandatory here.
>
> So this is one of the criteria for the use cases: Is distribution a requirement? Because if it is, then this points very clearly to an autonomic solution.
>
> Michael
>
>   
>> Regards
>>     Brian
>>
>> On 17/06/2014 08:13, Michael Richardson wrote:
>>> I recognize that bootstrap is only one of the autonomic mechanisms
>>> that are relevant to this group.  I have much reading on the other
>>> aspects which I hope to get done.
>>>
>>> The 6tisch security design team has been working on a "zero-touch"
>>> mechanism that would permit constrained devices to join a
>> Lowpower/Loss Network (LLN)
>>> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
>>> done), or turning the WirelessHART (IEC62591) packet flow into
>>> something more IPv6-like.  While there are significant bits of design
>>> space to explore while trying to optimize packet count, size and total
>>> energy risk of the join protocol;  the idea that there should be a set
>>> of authorization tokens From the device vendor which would permit the
>>> network and new nodes to recognize each other has been central to all
>> discussions.
>>> while draft-pritikin-bootstrapping-keyinfrastructures and
>>>        draft-behringer-autonomic-bootstrap-00
>>>
>>> have proposed valid high level concepts, I believe that specification
>>> of the authz token is critical for the IoT space.  A great concern
>>> that is that the LLNs created remain operational for decades at a
>>> time, and that the components can individually and also in aggregate
>>> be both (re-)sold, and/or the service provider operating the network be
>> replaced.
>>> (There are real life examples where a part of a 100 square mile
>>> refinery is actually sold to a competitor; obviously it doesn't get
>>> moved.  On the other side, one has the very real risk that you bought
>>> your sensor network From a "Nortel")
>>>
>>> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
>>> about an API between a (constrained) device and it's cryptographic
>> hardware
>>> module/TPM.   It profiles a number of IETF PKIX specifications in a useful
>>> way, but there is little there in terms of actual protocol.  When it
>>> comes to what does an *DevID look like, in it's section 7.2.8, saying
>>> that the DN should contain a "serialNumber" attribute:
>>>
>>>     The formatting of this field shall contain a unique X.500
>>>     Distinguished Name (DN). This may include the unique device serial
>> number assigned by the manufacturer
>>>     or any other suitable unique DN value that the issuer prefers.
>>>
>>> What I have observed is that there needs to be a way to clearly
>>> delegate from
>>> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
>>> SERVICE-PROVIDER.    It would significantly reduce the number of
>> certificates
>>> in (non-constrained device) databases for some levels of this
>>> hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
>>> came to mind, which deals with delegation of Autonomous Systems
>>> Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
>> Enterprises.
>>>            RFC3779: X.509 Extensions for IP Addresses and AS
>>> Identifiers
>>>
>>> I created:
>>>      X509.v3 certificate extension for authorization of device ownership
>>>                   draft-richardson-6tisch-idevid-cert-00
>>>
>>> which cribbed together via nroff2xml and a search and replace.
>>>
>>> The Pritikin and Behringer documents seem to assume that the ultimate
>>> goal of the trusted enrollment process is to create a path in which
>>> "EST"= Enrollment over Secure Transport could operate that would
>>> permit a new locally significant certificate to be loaded into the new
>> device.
>>> I agree with that goal.
>>>
>>> There is the question of how that trust circuit is created, and in
>>> discussion it seemed that it involve some kind of leap-of-faith TLS
>>> setup which would be authenticated by the "authz" tokens later on.  I
>>> disagree; I think that with appropriate evaluation of path constraints
>>> that the authentication can occur within the TLS protocol. (Even
>>> easier if done in IKEv2)
>>>
>>> --
>>> Michael Richardson<mcr+IETF@sandelman.ca>, Sandelman Software
>> Works
>>> -= IPv6 IoT consulting =-
>>>
>> _______________________________________________
>> Anima mailing list
>> Anima@ietf.org
>> https://www.ietf.org/mailman/listinfo/anima
> _______________________________________________
> Anima mailing list
> Anima@ietf.org
> https://www.ietf.org/mailman/listinfo/anima
>

-- 

Bien cordialement, Best regards,

*Laurent Ciavaglia*

Research Manager | Project Manager

Network Algorithms, Protocols and Security Group

Bell Labs | Alcatel Lucent

phone: +33 160 402 636

email: laurent.ciavaglia@alcatel-lucent.com 
<mailto:laurent.ciavaglia@alcatel-lucent.com>

linkedin: laurentciavaglia <http://fr.linkedin.com/in/laurentciavaglia/>

address: Route de Villejust | 91620 NOZAY | France


--------------070302050706030409050707
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#333333">
    <font face="Courier New">Dear Michael, all,<br>
      <br>
      It's nice to see inputs/thoughts from very different domains (IoT)
      coming in!<br>
      <br>
      Connected devices or entities are for sure in the scope of
      applicability for autonomic networking. And if we consider the
      future 5G networks, the number of connected "nodes" will be even
      more important and will put even more pressure on the (operators
      of the) networking infrastructures to cope with e.g.
      up-to-date/synchronized inventory (just to name one). <br>
      In this context, autonomic technologies definitely make sense: to
      address scalability, optimisation/adaptation of the control
      process/functions, coordination/orchestration among autonomic
      nodes/functions, etc).<br>
      <br>
      If we speak IoT/Smart objects, I see a clear and easy first link
      with SmartHome (homenet), and as long as we see a <u>role</u> for
      the network (thus the "<u>connecte</u><u>d</u>" x), and someone
      acting as an "operator" (not necessarily a classical telco
      carrier: e.g. who the homenet operator(s)?), there is a place for
      autonomic technologies.<br>
      <br>
      What we can provide (ultimately)&nbsp; is a (consistent/integrated?)
      set of autonomic/management tools for these very operators
      applicable in the different technological/industrial domains
      (smart homes, smart cities... and of course also "purely"
      telecommuncations networks). Of course one goal would be to not
      re-specify/develop the core solutions for all the different
      domains. This is very much in line with one of our goals in this
      BoF to identify commonalities that will drive the
      protocol/architecture work.<br>
      Autonomic networking will/should develop and provide both the
      procotols/mechanisms and the right (simple, extensible,
      composable) interfaces for operators to use them (in different
      domains). <br>
      <br>
      As for the point on distribution, I don't know how to phrase it,
      but it is even more than a requirement, it is part of the nature
      of any networked environment: distributed in nature. So we will
      have to "attach" a number of basic/essential (autonomic)
      functionality to the (distributed) "nodes". Secured bootstrap is
      one. Others well-known ones could be (TBD): discovery, information
      exchange, capability negotiation, enforcement, group
      communications...<br>
      <br>
      Best regards, Laurent.<br>
      <br>
      <br>
    </font>
    <div class="moz-cite-prefix">On 17/06/2014 08:59, Michael Behringer
      (mbehring) wrote:<br>
    </div>
    <blockquote
cite="mid:3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com"
      type="cite">
      <blockquote type="cite">
        <pre wrap="">-----Original Message-----
From: Anima [<a class="moz-txt-link-freetext" href="mailto:anima-bounces@ietf.org">mailto:anima-bounces@ietf.org</a>] On Behalf Of Brian E
Carpenter
Sent: 17 June 2014 01:01
To: <a class="moz-txt-link-abbreviated" href="mailto:anima@ietf.org">anima@ietf.org</a>
Cc: 6tisch-security
Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]

Michael's message is very interesting. For present purposes, i.e. getting
ready for the UCAN BOF, do we need to add some points to the relevant use
case draft (<a class="moz-txt-link-freetext" href="http://tools.ietf.org/html/draft-behringer-autonomic">http://tools.ietf.org/html/draft-behringer-autonomic</a>-
bootstrap)?

More generally - I think the AN protagonists have been thinking of the
scope of AN being carrier, enterprise, and home networks.
Should we add IoT to the scope? I think it's an important question, because
it would put new meanings on "simple" and "available resources". It seems
obvious that IoT networks need to be completely autonomic, but is it the
*same* autonomic?
</pre>
      </blockquote>
      <pre wrap="">Brian, we have always positioned AN also in the IoT context, and I agree with Sheng, AN can be used everywhere. Especially when it comes to devices that will be deployed and managed in the thousands or even millions, autonomic concepts are a requirement, not a nice to have. 

We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a high-level solution in 6tisch. It explains how you CAN bootstrap a network, zero-touch AND secure, and fits perfectly to the 6tisch requirements. The corresponding use case is described in draft-behringer-autonomic-bootstrap. 

To me, the bootstrap problem is one of the real solid examples of autonomic behaviour, because to bootstrap a device into a network I MUST have some functionality on the devices, ie, distribution is absolutely mandatory here. 

So this is one of the criteria for the use cases: Is distribution a requirement? Because if it is, then this points very clearly to an autonomic solution. 

Michael

 
</pre>
      <blockquote type="cite">
        <pre wrap="">Regards
   Brian

On 17/06/2014 08:13, Michael Richardson wrote:
</pre>
        <blockquote type="cite">
          <pre wrap="">I recognize that bootstrap is only one of the autonomic mechanisms
that are relevant to this group.  I have much reading on the other
aspects which I hope to get done.

The 6tisch security design team has been working on a "zero-touch"
mechanism that would permit constrained devices to join a
</pre>
        </blockquote>
        <pre wrap="">Lowpower/Loss Network (LLN)
</pre>
        <blockquote type="cite">
          <pre wrap="">in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
done), or turning the WirelessHART (IEC62591) packet flow into
something more IPv6-like.  While there are significant bits of design
space to explore while trying to optimize packet count, size and total
energy risk of the join protocol;  the idea that there should be a set
of authorization tokens From the device vendor which would permit the
network and new nodes to recognize each other has been central to all
</pre>
        </blockquote>
        <pre wrap="">discussions.
</pre>
        <blockquote type="cite">
          <pre wrap="">while draft-pritikin-bootstrapping-keyinfrastructures and
      draft-behringer-autonomic-bootstrap-00

have proposed valid high level concepts, I believe that specification
of the authz token is critical for the IoT space.  A great concern
that is that the LLNs created remain operational for decades at a
time, and that the components can individually and also in aggregate
be both (re-)sold, and/or the service provider operating the network be
</pre>
        </blockquote>
        <pre wrap="">replaced.
</pre>
        <blockquote type="cite">
          <pre wrap="">(There are real life examples where a part of a 100 square mile
refinery is actually sold to a competitor; obviously it doesn't get
moved.  On the other side, one has the very real risk that you bought
your sensor network From a "Nortel")

I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
about an API between a (constrained) device and it's cryptographic
</pre>
        </blockquote>
        <pre wrap="">hardware
</pre>
        <blockquote type="cite">
          <pre wrap="">module/TPM.   It profiles a number of IETF PKIX specifications in a useful
way, but there is little there in terms of actual protocol.  When it
comes to what does an *DevID look like, in it's section 7.2.8, saying
that the DN should contain a "serialNumber" attribute:

   The formatting of this field shall contain a unique X.500
   Distinguished Name (DN). This may include the unique device serial
</pre>
        </blockquote>
        <pre wrap="">number assigned by the manufacturer
</pre>
        <blockquote type="cite">
          <pre wrap="">   or any other suitable unique DN value that the issuer prefers.

What I have observed is that there needs to be a way to clearly
delegate from
Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
SERVICE-PROVIDER.    It would significantly reduce the number of
</pre>
        </blockquote>
        <pre wrap="">certificates
</pre>
        <blockquote type="cite">
          <pre wrap="">in (non-constrained device) databases for some levels of this
hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
came to mind, which deals with delegation of Autonomous Systems
Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
</pre>
        </blockquote>
        <pre wrap="">Enterprises.
</pre>
        <blockquote type="cite">
          <pre wrap="">          RFC3779: X.509 Extensions for IP Addresses and AS
Identifiers

I created:
    X509.v3 certificate extension for authorization of device ownership
                 draft-richardson-6tisch-idevid-cert-00

which cribbed together via nroff2xml and a search and replace.

The Pritikin and Behringer documents seem to assume that the ultimate
goal of the trusted enrollment process is to create a path in which
"EST"= Enrollment over Secure Transport could operate that would
permit a new locally significant certificate to be loaded into the new
</pre>
        </blockquote>
        <pre wrap="">device.
</pre>
        <blockquote type="cite">
          <pre wrap="">I agree with that goal.

There is the question of how that trust circuit is created, and in
discussion it seemed that it involve some kind of leap-of-faith TLS
setup which would be authenticated by the "authz" tokens later on.  I
disagree; I think that with appropriate evaluation of path constraints
that the authentication can occur within the TLS protocol. (Even
easier if done in IKEv2)

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software
</pre>
        </blockquote>
        <pre wrap="">Works
</pre>
        <blockquote type="cite">
          <pre wrap="">-= IPv6 IoT consulting =-

</pre>
        </blockquote>
        <pre wrap="">_______________________________________________
Anima mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Anima@ietf.org">Anima@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/anima">https://www.ietf.org/mailman/listinfo/anima</a>
</pre>
      </blockquote>
      <pre wrap="">_______________________________________________
Anima mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Anima@ietf.org">Anima@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/anima">https://www.ietf.org/mailman/listinfo/anima</a>

</pre>
    </blockquote>
    <br>
    <div class="moz-signature">-- <br>
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="ProgId" content="Word.Document">
      <meta name="Generator" content="Microsoft Word 12">
      <meta name="Originator" content="Microsoft Word 12">
      <link rel="File-List"
        href="2014-email-signature_files/filelist.xml">
      <!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Laurent</o:Author>
  <o:LastAuthor>Laurent</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>1</o:TotalTime>
  <o:Created>2014-03-03T14:04:00Z</o:Created>
  <o:LastSaved>2014-03-03T14:04:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>65</o:Words>
  <o:Characters>361</o:Characters>
  <o:Company>Alcatel-Lucent</o:Company>
  <o:Lines>3</o:Lines>
  <o:Paragraphs>1</o:Paragraphs>
  <o:CharactersWithSpaces>425</o:CharactersWithSpaces>
  <o:Version>12.00</o:Version>
 </o:DocumentProperties>
</xml><![endif]-->
      <link rel="themeData"
        href="2014-email-signature_files/themedata.thmx">
      <link rel="colorSchemeMapping"
        href="2014-email-signature_files/colorschememapping.xml">
      <!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:TrackMoves>false</w:TrackMoves>
  <w:TrackFormatting/>
  <w:HyphenationZone>21</w:HyphenationZone>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>FR</w:LidThemeOther>
  <w:LidThemeAsian>X-NONE</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:SplitPgBreakAndParaMark/>
   <w:DontVertAlignCellWithSp/>
   <w:DontBreakConstrainedForcedTables/>
   <w:DontVertAlignInTxbx/>
   <w:Word11KerningPairs/>
   <w:CachedColBalance/>
  </w:Compatibility>
  <m:mathPr>
   <m:mathFont m:val="Cambria Math"/>
   <m:brkBin m:val="before"/>
   <m:brkBinSub m:val="&#45;-"/>
   <m:smallFrac m:val="off"/>
   <m:dispDef/>
   <m:lMargin m:val="0"/>
   <m:rMargin m:val="0"/>
   <m:defJc m:val="centerGroup"/>
   <m:wrapIndent m:val="1440"/>
   <m:intLim m:val="subSup"/>
   <m:naryLim m:val="undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267">
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/>
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]-->
      <style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-536870145 1107305727 0 0 415 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-520092929 1073786111 9 0 415 0;}
@font-face
	{font-family:"Trebuchet MS";
	panose-1:2 11 6 3 2 2 2 2 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:647 0 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:0cm;
	margin-right:0cm;
	margin-bottom:10.0pt;
	margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";
	mso-ansi-language:EN-GB;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	mso-themecolor:followedhyperlink;
	text-decoration:underline;
	text-underline:single;}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	font-size:10.0pt;
	mso-ansi-font-size:10.0pt;
	mso-bidi-font-size:10.0pt;
	mso-ascii-font-family:Calibri;
	mso-fareast-font-family:Calibri;
	mso-hansi-font-family:Calibri;}
@page WordSection1
	{size:595.3pt 841.9pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;
	mso-header-margin:35.4pt;
	mso-footer-margin:35.4pt;
	mso-paper-source:0;}
div.WordSection1
	{page:WordSection1;}
-->
</style><!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";
	mso-bidi-font-family:"Times New Roman";}
</style>
<![endif]--><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="7170"/>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1"/>
 </o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;;
            mso-bidi-font-family:&quot;Courier New&quot;" lang="EN-GB">Bien

            <span class="SpellE">cordialement</span>, Best regards,<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;;
            mso-bidi-font-family:&quot;Courier New&quot;" lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><b style="mso-bidi-font-weight:normal"><span
              style="font-size:10.0pt;font-family:&quot;Trebuchet
              MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">Laurent
              Ciavaglia<o:p></o:p></span></b></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">Research
            Manager | Project Manager<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">Network
            Algorithms, Protocols and Security Group<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">Bell Labs |
            Alcatel Lucent<o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span class="GramE"><span
              style="font-size:10.0pt;font-family: &quot;Trebuchet
              MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">phone</span></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">: +33&nbsp;160
            402&nbsp;636 <o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span class="GramE"><span
              style="font-size:10.0pt;font-family: &quot;Trebuchet
              MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">email</span></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">: </span><span
            lang="EN-GB"><a
              href="mailto:laurent.ciavaglia@alcatel-lucent.com"><span
                style="font-size:10.0pt;font-family:&quot;Trebuchet
                MS&quot;,&quot;sans-serif&quot;;color:#7030A0">laurent.ciavaglia@alcatel-lucent.com</span></a></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;; color:#7030A0" lang="EN-GB"><o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span class="SpellE"><span class="GramE"><span
                style="font-size: 10.0pt;font-family:&quot;Trebuchet
                MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">linkedin</span></span></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">: </span><span
            lang="EN-GB"><a
              href="http://fr.linkedin.com/in/laurentciavaglia/"><span
                class="SpellE"><span
                  style="font-size:10.0pt;font-family:&quot;Trebuchet
                  MS&quot;,&quot;sans-serif&quot;; color:#7030A0">laurentciavaglia</span></span></a></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;;color:#7030A0" lang="EN-GB"><o:p></o:p></span></p>
        <p class="MsoNormal"
          style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:
          normal"><span class="GramE"><span
              style="font-size:10.0pt;font-family: &quot;Trebuchet
              MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">address</span></span><span
            style="font-size:10.0pt;font-family:&quot;Trebuchet
            MS&quot;,&quot;sans-serif&quot;" lang="EN-GB">: Route de <span
              class="SpellE">Villejust</span> | 91620 NOZAY | France<o:p></o:p></span></p>
      </div>
    </div>
  </body>
</html>

--------------070302050706030409050707--


From nobody Tue Jun 17 12:52:25 2014
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 896891A00B7; Tue, 17 Jun 2014 12:52:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b-Xc3WRc3oo8; Tue, 17 Jun 2014 12:52:19 -0700 (PDT)
Received: from mail-pa0-x232.google.com (mail-pa0-x232.google.com [IPv6:2607:f8b0:400e:c03::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E48BE1A0163; Tue, 17 Jun 2014 12:52:18 -0700 (PDT)
Received: by mail-pa0-f50.google.com with SMTP id bj1so4230134pad.23 for <multiple recipients>; Tue, 17 Jun 2014 12:52:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:organization:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=OkLFEFPr64z3Kz8FHY/gBmGv7o1D/2m6FrbtKA2b3No=; b=U6CNw/OaaHovA3G6b2WaI71YOfvafC0vX/NFYKD0bPEdmm99iEGT3oKT0X77pv+y2X jvMav0nKykegY7JOT2inkEapa4npbFKpjFcF5tkqUUiFlIHyDYGKedwOl1/uqDHZX59T /jQfNZ09F6YVFTn7YZpS4uM1CZHRSf97Tc5x5fYdakHW64owBm3JoVVVQSi8fD0cfuo4 sTPn/L8iLqpC6nKUZauZxzat6w55YGKIzjyYP5onFM8v2GGPizGo/AMLWIrK05AON6Xq /beHnErGIAW6++3Xu8mSQAxU5u8gPNJPxtcH/LxSt9JpdgGU3bbFQEqc9zF0V8NsghW6 tgyw==
X-Received: by 10.68.189.68 with SMTP id gg4mr35275232pbc.42.1403034738600; Tue, 17 Jun 2014 12:52:18 -0700 (PDT)
Received: from [192.168.178.23] (171.198.69.111.dynamic.snap.net.nz. [111.69.198.171]) by mx.google.com with ESMTPSA id ao4sm25349736pbc.51.2014.06.17.12.52.16 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 17 Jun 2014 12:52:18 -0700 (PDT)
Message-ID: <53A09C73.2060309@gmail.com>
Date: Wed, 18 Jun 2014 07:52:19 +1200
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
MIME-Version: 1.0
To: "Michael Behringer (mbehring)" <mbehring@cisco.com>
References: <26717.1402949592@sandelman.ca> <539F771A.3000008@gmail.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
In-Reply-To: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB3FF4@xmb-rcd-x14.cisco.com>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/9-KzIGyaxhRo5511Kxf9c_urLXY
Cc: 6tisch-security <6tisch-security@ietf.org>, "anima@ietf.org" <anima@ietf.org>
Subject: Re: [6tisch-security] [Anima] Scope question [was: autonomic bootstrap: gap analysis]
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 19:52:21 -0000

On 17/06/2014 18:59, Michael Behringer (mbehring) wrote:
>> -----Original Message-----
>> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Brian E
>> Carpenter
>> Sent: 17 June 2014 01:01
>> To: anima@ietf.org
>> Cc: 6tisch-security
>> Subject: [Anima] Scope question [was: autonomic bootstrap: gap analysis]
>>
>> Michael's message is very interesting. For present purposes, i.e. getting
>> ready for the UCAN BOF, do we need to add some points to the relevant use
>> case draft (http://tools.ietf.org/html/draft-behringer-autonomic-
>> bootstrap)?
>>
>> More generally - I think the AN protagonists have been thinking of the
>> scope of AN being carrier, enterprise, and home networks.
>> Should we add IoT to the scope? I think it's an important question, because
>> it would put new meanings on "simple" and "available resources". It seems
>> obvious that IoT networks need to be completely autonomic, but is it the
>> *same* autonomic?
> 
> Brian, we have always positioned AN also in the IoT context, and I agree with Sheng, AN can be used everywhere. Especially when it comes to devices that will be deployed and managed in the thousands or even millions, autonomic concepts are a requirement, not a nice to have. 

Fully agree. But when I see people asking whether we will use YANG,
I find myself wondering about low-end devices in an IoT context.

    Brian

> We have positioned draft-pritikin-bootstrapping-keyinfrastructures as a high-level solution in 6tisch. It explains how you CAN bootstrap a network, zero-touch AND secure, and fits perfectly to the 6tisch requirements. The corresponding use case is described in draft-behringer-autonomic-bootstrap. 
> 
> To me, the bootstrap problem is one of the real solid examples of autonomic behaviour, because to bootstrap a device into a network I MUST have some functionality on the devices, ie, distribution is absolutely mandatory here. 
> 
> So this is one of the criteria for the use cases: Is distribution a requirement? Because if it is, then this points very clearly to an autonomic solution. 
> 
> Michael
> 
>  
>> Regards
>>    Brian
>>
>> On 17/06/2014 08:13, Michael Richardson wrote:
>>> I recognize that bootstrap is only one of the autonomic mechanisms
>>> that are relevant to this group.  I have much reading on the other
>>> aspects which I hope to get done.
>>>
>>> The 6tisch security design team has been working on a "zero-touch"
>>> mechanism that would permit constrained devices to join a
>> Lowpower/Loss Network (LLN)
>>> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
>>> done), or turning the WirelessHART (IEC62591) packet flow into
>>> something more IPv6-like.  While there are significant bits of design
>>> space to explore while trying to optimize packet count, size and total
>>> energy risk of the join protocol;  the idea that there should be a set
>>> of authorization tokens From the device vendor which would permit the
>>> network and new nodes to recognize each other has been central to all
>> discussions.
>>> while draft-pritikin-bootstrapping-keyinfrastructures and
>>>       draft-behringer-autonomic-bootstrap-00
>>>
>>> have proposed valid high level concepts, I believe that specification
>>> of the authz token is critical for the IoT space.  A great concern
>>> that is that the LLNs created remain operational for decades at a
>>> time, and that the components can individually and also in aggregate
>>> be both (re-)sold, and/or the service provider operating the network be
>> replaced.
>>> (There are real life examples where a part of a 100 square mile
>>> refinery is actually sold to a competitor; obviously it doesn't get
>>> moved.  On the other side, one has the very real risk that you bought
>>> your sensor network From a "Nortel")
>>>
>>> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is
>>> about an API between a (constrained) device and it's cryptographic
>> hardware
>>> module/TPM.   It profiles a number of IETF PKIX specifications in a useful
>>> way, but there is little there in terms of actual protocol.  When it
>>> comes to what does an *DevID look like, in it's section 7.2.8, saying
>>> that the DN should contain a "serialNumber" attribute:
>>>
>>>    The formatting of this field shall contain a unique X.500
>>>    Distinguished Name (DN). This may include the unique device serial
>> number assigned by the manufacturer
>>>    or any other suitable unique DN value that the issuer prefers.
>>>
>>> What I have observed is that there needs to be a way to clearly
>>> delegate from
>>> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
>>> SERVICE-PROVIDER.    It would significantly reduce the number of
>> certificates
>>> in (non-constrained device) databases for some levels of this
>>> hierarchy if the IDevID were aggregateable in some fashion.  RFC3779
>>> came to mind, which deals with delegation of Autonomous Systems
>>> Numbers (ASN) and IP address ranges from RIRs to LIRs to ISPs and
>> Enterprises.
>>>           RFC3779: X.509 Extensions for IP Addresses and AS
>>> Identifiers
>>>
>>> I created:
>>>     X509.v3 certificate extension for authorization of device ownership
>>>                  draft-richardson-6tisch-idevid-cert-00
>>>
>>> which cribbed together via nroff2xml and a search and replace.
>>>
>>> The Pritikin and Behringer documents seem to assume that the ultimate
>>> goal of the trusted enrollment process is to create a path in which
>>> "EST"= Enrollment over Secure Transport could operate that would
>>> permit a new locally significant certificate to be loaded into the new
>> device.
>>> I agree with that goal.
>>>
>>> There is the question of how that trust circuit is created, and in
>>> discussion it seemed that it involve some kind of leap-of-faith TLS
>>> setup which would be authenticated by the "authz" tokens later on.  I
>>> disagree; I think that with appropriate evaluation of path constraints
>>> that the authentication can occur within the TLS protocol. (Even
>>> easier if done in IKEv2)
>>>
>>> --
>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
>> Works
>>> -= IPv6 IoT consulting =-
>>>
>> _______________________________________________
>> Anima mailing list
>> Anima@ietf.org
>> https://www.ietf.org/mailman/listinfo/anima
> .
> 


From nobody Tue Jun 17 17:22:23 2014
Return-Path: <sarikaya2012@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 947891A0160; Tue, 17 Jun 2014 13:00:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.75
X-Spam-Level: 
X-Spam-Status: No, score=-1.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6HoNdtAWjvE1; Tue, 17 Jun 2014 13:00:11 -0700 (PDT)
Received: from mail-yk0-x232.google.com (mail-yk0-x232.google.com [IPv6:2607:f8b0:4002:c07::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D661E1A0123; Tue, 17 Jun 2014 13:00:10 -0700 (PDT)
Received: by mail-yk0-f178.google.com with SMTP id q9so5636555ykb.37 for <multiple recipients>; Tue, 17 Jun 2014 13:00:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=vwPj4T7GE9QKb47LQpXtDx/E2h2usp75U/ONdcdjGew=; b=jbFvO2WpFa/zK20tPCMB+E6tOnzBr24FJMDhrx1bnlWogOvH3FTEKLmt32annfAPUT NtWJsPbcxFamkr6q4kAGugmGY459OVFOhNOkWlUTZSuuT1RRPuLLJtRg7+dpGLtd5TdV tbtxFvvBrkBwLXmeYEcXQwWP7qEymGean7fciGNiQO/3QA6tITdlrXso9qJMTmLsWSLL Ee+yAfq8X3Kal1gNr/DDDGI0KbyWoBdCikL2lNSJ+d+io54cu/yYySinPD19sokXyYyY Omox/pFc92x2+4xorLVTsj+rpptYcqGn3jp1/3PL7Ueiex/RLAvwQqbJTAhwh2E8tgZA rgvQ==
MIME-Version: 1.0
X-Received: by 10.236.153.9 with SMTP id e9mr46117448yhk.15.1403035210089; Tue, 17 Jun 2014 13:00:10 -0700 (PDT)
Received: by 10.170.156.130 with HTTP; Tue, 17 Jun 2014 13:00:10 -0700 (PDT)
In-Reply-To: <26717.1402949592@sandelman.ca>
References: <26717.1402949592@sandelman.ca>
Date: Tue, 17 Jun 2014 15:00:10 -0500
Message-ID: <CAC8QAcfHz2b0QSjwk0P0ofZBxHbQS64f_7ehM5YGk+WzWUH64Q@mail.gmail.com>
From: Behcet Sarikaya <sarikaya2012@gmail.com>
To: anima@ietf.org
Content-Type: text/plain; charset=UTF-8
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/fK4R1ZDs54p2l2CKGZ-LOse-mSk
X-Mailman-Approved-At: Tue, 17 Jun 2014 17:22:13 -0700
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] autonomic bootstrap: gap analysis
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: sarikaya@ieee.org
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 20:00:12 -0000

Hi Michael,

I had a draft on this for quite longtime, the link is:

http://tools.ietf.org/html/draft-sarikaya-ace-secure-bootstrapping-00

you forgot to mention this one?

Behcet



On Mon, Jun 16, 2014 at 3:13 PM, Michael Richardson
<mcr+ietf@sandelman.ca> wrote:
>
> I recognize that bootstrap is only one of the autonomic mechanisms that
> are relevant to this group.  I have much reading on the other aspects
> which I hope to get done.
>
> The 6tisch security design team has been working on a "zero-touch" mechanism
> that would permit constrained devices to join a Lowpower/Loss Network (LLN)
> in a secure way.   We have considered adapting EAP-TLS (as ZigbeeIP has
> done), or turning the WirelessHART (IEC62591) packet flow into something more
> IPv6-like.  While there are significant bits of design space to explore
> while trying to optimize packet count, size and total energy risk of the
> join protocol;  the idea that there should be a set of authorization tokens
> From the device vendor which would permit the network and new nodes to
> recognize each other has been central to all discussions.
>
> while draft-pritikin-bootstrapping-keyinfrastructures and
>       draft-behringer-autonomic-bootstrap-00
>
> have proposed valid high level concepts, I believe that specification of the
> authz token is critical for the IoT space.  A great concern that is that the
> LLNs created remain operational for decades at a time, and that the
> components can individually and also in aggregate be both (re-)sold,
> and/or the service provider operating the network be replaced.
>
> (There are real life examples where a part of a 100 square mile refinery
> is actually sold to a competitor; obviously it doesn't get moved.  On the
> other side, one has the very real risk that you bought your sensor network
> From a "Nortel")
>
> I was pointed at 802.1AR's device ID mechanism.  Really, 802.1AR is about an
> API between a (constrained) device and it's cryptographic hardware
> module/TPM.   It profiles a number of IETF PKIX specifications in a useful
> way, but there is little there in terms of actual protocol.  When it comes to
> what does an *DevID look like, in it's section 7.2.8, saying that the DN
> should contain a "serialNumber" attribute:
>
>    The formatting of this field shall contain a unique X.500
>    Distinguished Name (DN). This may include the unique device serial number assigned by the manufacturer
>    or any other suitable unique DN value that the issuer prefers.
>
> What I have observed is that there needs to be a way to clearly delegate from
> Factory(Vendor) to VAR to DISTRIBUTOR to RESELLER to Plant-OWNER to
> SERVICE-PROVIDER.    It would significantly reduce the number of certificates
> in (non-constrained device) databases for some levels of this hierarchy if
> the IDevID were aggregateable in some fashion.  RFC3779 came to mind, which
> deals with delegation of Autonomous Systems Numbers (ASN) and IP address
> ranges from RIRs to LIRs to ISPs and Enterprises.
>           RFC3779: X.509 Extensions for IP Addresses and AS Identifiers
>
> I created:
>     X509.v3 certificate extension for authorization of device ownership
>                  draft-richardson-6tisch-idevid-cert-00
>
> which cribbed together via nroff2xml and a search and replace.
>
> The Pritikin and Behringer documents seem to assume that the ultimate goal of
> the trusted enrollment process is to create a path in which "EST"= Enrollment
> over Secure Transport could operate that would permit a new locally
> significant certificate to be loaded into the new device.
> I agree with that goal.
>
> There is the question of how that trust circuit is created, and in discussion
> it seemed that it involve some kind of leap-of-faith TLS setup which would be
> authenticated by the "authz" tokens later on.  I disagree; I think that with
> appropriate evaluation of path constraints that the authentication can occur
> within the TLS protocol. (Even easier if done in IKEv2)
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
>
>
>
>
> _______________________________________________
> Anima mailing list
> Anima@ietf.org
> https://www.ietf.org/mailman/listinfo/anima
>


From nobody Tue Jun 17 17:59:47 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CD7C1A00BD for <6tisch-security@ietfa.amsl.com>; Tue, 17 Jun 2014 17:59:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.532
X-Spam-Level: 
X-Spam-Status: No, score=-2.532 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_MIME_NO_TEXT=0.01, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9-Jlro9WjGOs for <6tisch-security@ietfa.amsl.com>; Tue, 17 Jun 2014 17:59:43 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5996A1A013B for <6tisch-security@ietf.org>; Tue, 17 Jun 2014 17:59:42 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id CE80C20011 for <6tisch-security@ietf.org>; Tue, 17 Jun 2014 21:03:36 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 9412563B0E; Tue, 17 Jun 2014 20:59:06 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 7E86E63B0A for <6tisch-security@ietf.org>; Tue, 17 Jun 2014 20:59:06 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security@ietf.org
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 17 Jun 2014 20:59:06 -0400
Message-ID: <31337.1403053146@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/DT-K0_qd_wd-GmqB4YVqQtbhC6Q
Subject: [6tisch-security] certificate cache discussion recap from 2014-06-16
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jun 2014 00:59:45 -0000

--=-=-=


Monday, on the call I asked the group a couple of questions relating to the
time sequence diagram from Jonathan.

1) given assymetric crypto is there any reason for the JOIN REQUEST from the
   joining node to the PCE (message 4) to be *encrypted* to the PCE?
   (Clearly, it needs to be signed by the joining node)

The conclusion was that there are things in WirelessHART which were decided
were sensitive, and thus the packet was encrypted.  It was concluded that if
there is anything left that is sensitive that it can probably be moved to
step 5/6.
Leaving out the asymmetric encryption likely saves around 300 bits in the
packet as well.

2) having gotten rid of the (assymetric) encryption, the question then
becomes: do we need to do a certificate request/response at all? (steps 2/3).

Some things that were said on the call:

  a) it has been suggested that the address of the PCE would be an attribute
     on the certificate that is returned.

  b) it has been suggested that the certificate (chain) that would permit the
     joining node to be able to validate the PCE's identity, and therefore
     determine if this network is worth joining.

  c) there are some significant concerns if (b) is the only way that the joining
     node can determine if this is the correct network, that this is putting
     far too much policy and intelligence in the joining node.

  d) there is concern that given the complexity; that consumer devices may
     well just join whatever network they see first.

  e) at the same time, there is concern that message 2/3 does not involve any
     opportunity for a trip to an online database for higher value joining
     nodes.

  f) it was suggested that a joining node should record PANIDs to which it
     has attempted to connect to, and failed, and therefore it would not
     continuously failing to connect.

  g) it was suggested (by me) that even a partical certificate chain could
     be useful in selected a network to join.

The question was asked, if the message 2/3 exchange can never provide enough
authorization for a joining node to determine which network to join, then an
alternate question was asked:
  - is there something which can be cached by the proxy, such as part of
    the PCE certificate chain, which would usefully reduce the number of
    messages that need to traverse the entire LLN for each joining node.

A number of people expressed an interest in keeping the message 2/3 exchange
as an optional part of the protocol.  I don't like optional pieces, and I
would want to signal if message 2/3 should occur in the EB, or to always do
the message 2 request, and permit empty replies.

If you go back to my email at:
   https://mailarchive.ietf.org/arch/msg/6tisch-security/2kObJLkLlhuI-HU9s5yqfRm0n00

I had four links in the particular certificate chain that would permit the
joining node to authenticate the PCE.

   *1* Factory:       ACME
   *2* National-VAR:  Cadabra
   *3* Regional-Var:  Sesame
   *4* Plant:         Coyote

The factory certificate (1) would be built into the joining node as a trust
anchor.   If message (3) contained certificate *2*, perhaps also *3*, then that
would significant help the joining node to know that this might be the right
network to join, and it would reduce the number of bytes sent all the way.

Some problems/issues with this include:
    i. certificate *2* of the chain could be very specific to a particular
       device, so might be unsuitable for caching.
   ii. request (2) would have to include the DN of the trust anchor
       certificate *1* in order to indicate which vendor's certificate should
       be returned from the proxy.   Naturally, this opens things up to having
       as many certificates cached as there are factories X VARs.
  iii. at the DTLS stage, if additional parts of the trust path have been
       cached, then this needs to be indicated when the joining nodes issues
       it's CertificateRequest as part of it's ServerHello exchange, so
       that only part of the certificate chain is sent.
   iv. worse case, the entire certificate chain has to be sent at the DTLS
       stage.

If the PCE has a certificate chain which is not per-IDevID, and yet is
anchored at the factory installed trust anchor, then maybe this would have
higher utility.

While I can see the PCE having a certificate anchored in a local CA, and I
can see that as part of the join process, the joining node would have this
new trust anchor installed (along with a certificate of its own), I think it
is important to remember that this occurs *post* join.

In particular I want to make sure that everyone understands that the
(successful) join protocol occurs only once after the device has been turned
on (and/or factory defaulted in some OOB way).  It does not occur every time
the device powers up --- the join protocol would have installed the correct
PANID, L2-Key, etc. into the device.

So my conclusion is that there is little that we can cache on the proxy.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU6DkWoCLcPvd0N1lAQJdXggAswCaWogIKaGXzA6x5EXrtWtl81bmTDrQ
3LVY/ksewROpIxVR1zHoRGTr66DaPxLIewKkm1J6+mCkKe+9dlhLyl4EMM1B0/RY
DPh+JTah83agZXsdhDta2/axth5NBVcjeIx2NNGz4ncydBKVPRH33RwFznVVBLyq
upKJS3BgSAsOUJMLAdE0BMby1LmCZFc+IVzG5e3edLOr1CHDKYuoCardTGG5hab7
A96XgSG+hN88PfOLimKkNptE9EBof14KN8vhKZTgCsNZC23+F1FT9BlZELBBI10/
0jv3gjOM0IGd1Ud9qM8Zon4t64+41QEEs2YYjW91z2fiFrAXE80+pw==
=qIgx
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Jun 17 23:16:37 2014
Return-Path: <mbehring@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 579A21A0253; Tue, 17 Jun 2014 23:16:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qJT9x27weCWT; Tue, 17 Jun 2014 23:15:28 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38F961A0259; Tue, 17 Jun 2014 23:15:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=524; q=dns/txt; s=iport; t=1403072104; x=1404281704; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=ko41FcMAMBzf8TKTwWl6kbkduv+u3iuwIo0KbOL+BkM=; b=UaBPOKWNbszBDGC89zKMi7ZQ64oSglF7Xa+87v77a7GJ0p6ZdrsZ2BS4 /0LYX9EV0hHYRg2sb7VuSDO7eMAVZEIJmtKOoVbiMVEydSRI8u7MAaZoB DDMjh7DHhGHHNgHEvoNK08uIQZinfZuBPMoAjmBTUCQH+G2xUF9Jnb8UK A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Ak8IAPctoVOtJA2I/2dsb2JhbABagw1SWqoBDAEBAQEBAQUBmSgBgRAWdYQDAQEBBDo/DAQCAQgRBAEBCxQJBzIUCQgCBAENBQiIOg3LHBeFYohiMQcGgyeBFgEDnAaSFYNCgjA
X-IronPort-AV: E=Sophos;i="5.01,499,1400025600"; d="scan'208";a="333696070"
Received: from alln-core-3.cisco.com ([173.36.13.136]) by rcdn-iport-1.cisco.com with ESMTP; 18 Jun 2014 06:15:02 +0000
Received: from xhc-aln-x15.cisco.com (xhc-aln-x15.cisco.com [173.36.12.89]) by alln-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id s5I6F2kf029639 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 18 Jun 2014 06:15:02 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.51]) by xhc-aln-x15.cisco.com ([173.36.12.89]) with mapi id 14.03.0123.003; Wed, 18 Jun 2014 01:15:02 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: "sarikaya@ieee.org" <sarikaya@ieee.org>, "anima@ietf.org" <anima@ietf.org>
Thread-Topic: [Anima] autonomic bootstrap: gap analysis
Thread-Index: AQHPimbHvkmm1okankiBjKDA2xpKqJt2ZFjw
Date: Wed, 18 Jun 2014 06:15:01 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF21BB66C4@xmb-rcd-x14.cisco.com>
References: <26717.1402949592@sandelman.ca> <CAC8QAcfHz2b0QSjwk0P0ofZBxHbQS64f_7ehM5YGk+WzWUH64Q@mail.gmail.com>
In-Reply-To: <CAC8QAcfHz2b0QSjwk0P0ofZBxHbQS64f_7ehM5YGk+WzWUH64Q@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.55.238.137]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/aSRWCzR6Kya33P_pwybBCo6TIV0
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] [Anima] autonomic bootstrap: gap analysis
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jun 2014 06:16:27 -0000

> -----Original Message-----
> From: Anima [mailto:anima-bounces@ietf.org] On Behalf Of Behcet
> Sarikaya
> Sent: 17 June 2014 22:00
> To: anima@ietf.org
> Cc: 6tisch-security
> Subject: Re: [Anima] autonomic bootstrap: gap analysis
>=20
> Hi Michael,
>=20
> I had a draft on this for quite longtime, the link is:
>=20
> http://tools.ietf.org/html/draft-sarikaya-ace-secure-bootstrapping-00
>=20
> you forgot to mention this one?

I missed that one. Will have a look now. Thanks for the pointer!

Michael


From nobody Wed Jun 18 09:35:35 2014
Return-Path: <jsimon@linear.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E59971A02CA for <6tisch-security@ietfa.amsl.com>; Wed, 18 Jun 2014 09:35:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.01
X-Spam-Level: 
X-Spam-Status: No, score=-1.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FR_TEST_BASE64_BAD=3.189, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XPDwrEDXEQhO for <6tisch-security@ietfa.amsl.com>; Wed, 18 Jun 2014 09:35:29 -0700 (PDT)
Received: from p01c12o147.mxlogic.net (p01c12o147.mxlogic.net [208.65.145.70]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A69D1A0263 for <6tisch-security@ietf.org>; Wed, 18 Jun 2014 09:35:28 -0700 (PDT)
Received: from unknown [12.218.215.72] (EHLO smtpauth1.linear.com) by p01c12o147.mxlogic.net(mxl_mta-8.0.0-1) with ESMTP id fcfb1a35.0.2528.00-357.6596.p01c12o147.mxlogic.net (envelope-from <jsimon@linear.com>);  Wed, 18 Jun 2014 10:35:28 -0600 (MDT)
X-MXL-Hash: 53a1bfd07755fca5-ef497b6786ab98ead3da0d337c43800698e73251
Received: from jsimonmacmini.engineering.linear.com (unknown [10.70.48.25]) by smtpauth1.linear.com (Postfix) with ESMTPSA id 6626874096; Wed, 18 Jun 2014 09:35:24 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail=_4C69127D-2397-4EDC-BE07-676FF5B7C3C2"
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Jonathan Simon <jsimon@linear.com>
In-Reply-To: <31337.1403053146@sandelman.ca>
Date: Wed, 18 Jun 2014 09:38:42 -0700
Message-Id: <1E9190E0-15F5-48C6-9E4C-3508F95D21A2@linear.com>
References: <31337.1403053146@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1878.2)
X-AnalysisOut: [v=2.1 cv=S+JXwecP c=1 sm=1 tr=0 a=glloKNylpeYNumXQcclYyA==]
X-AnalysisOut: [:117 a=glloKNylpeYNumXQcclYyA==:17 a=kUXG8ynnOQEA:10 a=D2_]
X-AnalysisOut: [GN2MmYMYA:10 a=BLceEmwcHowA:10 a=MqDINYqSAAAA:8 a=YlVTAMxI]
X-AnalysisOut: [AAAA:8 a=SyYMxH9GAAAA:8 a=48vgC7mUAAAA:8 a=aMV7qcG7Xh6nX7N]
X-AnalysisOut: [y09MA:9 a=swpLZQhUTiLASa3_:21 a=Mt3_SwFCgYEIMQMr:21 a=pILN]
X-AnalysisOut: [OxqGKmIA:10 a=19wCD08tTksA:10 a=vsVyj9psLt0A:10 a=qVizmW-Z]
X-AnalysisOut: [YBIA:10 a=p-HxVa_ds0YA:10 a=xLpt9-x9cSEA:10 a=lZB815dzVvQA]
X-AnalysisOut: [:10 a=WEBLvOWhke16hT5DLPEA:9 a=dYTs4voReLHTZ3Zk:21 a=xFlMN]
X-AnalysisOut: [86cr9H9w22j:21 a=lhycY1eOOBq1vkUr:21 a=_W_S_7VecoQA:10]
X-Spam: [F=0.5000000000; CM=0.500; MH=0.500(2014061821); S=0.200(2014051901)]
X-MAIL-FROM: <jsimon@linear.com>
X-SOURCE-IP: [12.218.215.72]
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/e28rHS4x-WCT5PF5ZaZa2cc-0Lo
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] certificate cache discussion recap from 2014-06-16
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jun 2014 16:35:32 -0000

--Apple-Mail=_4C69127D-2397-4EDC-BE07-676FF5B7C3C2
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

> So my conclusion is that there is little that we can cache on the =
proxy.

That may be the case in the many scenarios, but I want to make sure that =
we don=92t prevent people from getting the efficiencies in a system =
where the motes do have a trust anchor and caching is appropriate.=20
--=20
Jonathan Simon, Ph. D
Director of Systems Engineering
Linear Technology, Dust Networks product group
30695 Huntwood Ave
Hayward, CA 94544-7021
(510) 400-2936
(510) 489-3799 FAX
jsimon@linear.com

**LINEAR TECHNOLOGY CORPORATION**=20
*****Internet Email Confidentiality Notice*****=20
 This e-mail transmission, and any documents, files or previous e-mail =
messages attached to it may contain confidential information that is =
legally privileged. If you are not the intended recipient, or a person =
responsible for delivering it to the intended recipient, you are hereby =
notified that any disclosure, copying, distribution or use of any of the =
information contained in or attached to this transmission is STRICTLY =
PROHIBITED. If you have received this transmission in error, please =
immediately notify me by reply e-mail, or by telephone at (510) =
400-2936, and destroy the original transmission and its attachments =
without reading or saving in any manner. Thank you.=20

On Jun 17, 2014, at 5:59 PM, Michael Richardson <mcr+ietf@sandelman.ca> =
wrote:

>=20
> Monday, on the call I asked the group a couple of questions relating =
to the
> time sequence diagram from Jonathan.
>=20
> 1) given assymetric crypto is there any reason for the JOIN REQUEST =
from the
>   joining node to the PCE (message 4) to be *encrypted* to the PCE?
>   (Clearly, it needs to be signed by the joining node)
>=20
> The conclusion was that there are things in WirelessHART which were =
decided
> were sensitive, and thus the packet was encrypted.  It was concluded =
that if
> there is anything left that is sensitive that it can probably be moved =
to
> step 5/6.
> Leaving out the asymmetric encryption likely saves around 300 bits in =
the
> packet as well.
>=20
> 2) having gotten rid of the (assymetric) encryption, the question then
> becomes: do we need to do a certificate request/response at all? =
(steps 2/3).
>=20
> Some things that were said on the call:
>=20
>  a) it has been suggested that the address of the PCE would be an =
attribute
>     on the certificate that is returned.
>=20
>  b) it has been suggested that the certificate (chain) that would =
permit the
>     joining node to be able to validate the PCE's identity, and =
therefore
>     determine if this network is worth joining.
>=20
>  c) there are some significant concerns if (b) is the only way that =
the joining
>     node can determine if this is the correct network, that this is =
putting
>     far too much policy and intelligence in the joining node.
>=20
>  d) there is concern that given the complexity; that consumer devices =
may
>     well just join whatever network they see first.
>=20
>  e) at the same time, there is concern that message 2/3 does not =
involve any
>     opportunity for a trip to an online database for higher value =
joining
>     nodes.
>=20
>  f) it was suggested that a joining node should record PANIDs to which =
it
>     has attempted to connect to, and failed, and therefore it would =
not
>     continuously failing to connect.
>=20
>  g) it was suggested (by me) that even a partical certificate chain =
could
>     be useful in selected a network to join.
>=20
> The question was asked, if the message 2/3 exchange can never provide =
enough
> authorization for a joining node to determine which network to join, =
then an
> alternate question was asked:
>  - is there something which can be cached by the proxy, such as part =
of
>    the PCE certificate chain, which would usefully reduce the number =
of
>    messages that need to traverse the entire LLN for each joining =
node.
>=20
> A number of people expressed an interest in keeping the message 2/3 =
exchange
> as an optional part of the protocol.  I don't like optional pieces, =
and I
> would want to signal if message 2/3 should occur in the EB, or to =
always do
> the message 2 request, and permit empty replies.
>=20
> If you go back to my email at:
>   =
http://cp.mcafee.com/d/5fHCN8q3xEgdEInpK-OyYqejtPqbwVBcSyUepvdEK3zhOyCOqej=
rzPPPz5XCN6ABqM1hYEvIundDOx-NVsSMYNZZpvW_e6zB55x7HTbFIFFYyC-yMYVORQX8FGTuj=
VkffGhBrwqrhdECXYyMCY-ehojd79KVIDeqR4IMjSdyszfZbVKY01PoS9UHgzzAVkIjbQ-Pspj=
boCl31020Gl2FVdIdbxs9CzCzVomt1qJUnKrsDaBypuDSrzapoKgGT2TQ1kLCXM04SztdAsrdb=
rAVkIjbQ-Pspjb6BQQgm-cVeOJI_d45JIjYQg8iFpKB9lwq88_rlzh0X6GFEwjKyMnKUnhsdKf=
6_VCDWZ8T7PQQ
>=20
> I had four links in the particular certificate chain that would permit =
the
> joining node to authenticate the PCE.
>=20
>   *1* Factory:       ACME
>   *2* National-VAR:  Cadabra
>   *3* Regional-Var:  Sesame
>   *4* Plant:         Coyote
>=20
> The factory certificate (1) would be built into the joining node as a =
trust
> anchor.   If message (3) contained certificate *2*, perhaps also *3*, =
then that
> would significant help the joining node to know that this might be the =
right
> network to join, and it would reduce the number of bytes sent all the =
way.
>=20
> Some problems/issues with this include:
>    i. certificate *2* of the chain could be very specific to a =
particular
>       device, so might be unsuitable for caching.
>   ii. request (2) would have to include the DN of the trust anchor
>       certificate *1* in order to indicate which vendor's certificate =
should
>       be returned from the proxy.   Naturally, this opens things up to =
having
>       as many certificates cached as there are factories X VARs.
>  iii. at the DTLS stage, if additional parts of the trust path have =
been
>       cached, then this needs to be indicated when the joining nodes =
issues
>       it's CertificateRequest as part of it's ServerHello exchange, so
>       that only part of the certificate chain is sent.
>   iv. worse case, the entire certificate chain has to be sent at the =
DTLS
>       stage.
>=20
> If the PCE has a certificate chain which is not per-IDevID, and yet is
> anchored at the factory installed trust anchor, then maybe this would =
have
> higher utility.
>=20
> While I can see the PCE having a certificate anchored in a local CA, =
and I
> can see that as part of the join process, the joining node would have =
this
> new trust anchor installed (along with a certificate of its own), I =
think it
> is important to remember that this occurs *post* join.
>=20
> In particular I want to make sure that everyone understands that the
> (successful) join protocol occurs only once after the device has been =
turned
> on (and/or factory defaulted in some OOB way).  It does not occur =
every time
> the device powers up --- the join protocol would have installed the =
correct
> PANID, L2-Key, etc. into the device.
>=20
> So my conclusion is that there is little that we can cache on the =
proxy.
>=20
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> =
http://cp.mcafee.com/d/k-Kr3xAe3zqb5SrLIEL6zATsSyUepjdEK3CnPqbwUQsEFICzASU=
YYYUNuVIhF9mI0kva7X7BPpYEvIundIfcvvmn-LPxEVhhohWZOWraqv8FLEIfesJteOaqJTA-l=
3PWApmU6CQjq9K_8I9LfzAm4PhOrKr9PCJhbcatbVKY01MjlS67OFek7qUVelb4OZfIT6kONJO=
sGm9BWvpKcFByV2Hsbvg5i-rL00jqdQShNIQJKjBiNcLjXdNBcIqnjh1rUPAXaSPYQgmSNfPh0=
xaBCWkBm1EwzZJmd43IqGCy1eWb1uXxt5MSUYrdwQH


--Apple-Mail=_4C69127D-2397-4EDC-BE07-676FF5B7C3C2
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1252

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dwindows-1252"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space;"><blockquote type=3D"cite">So my conclusion is that =
there is little that we can cache on the =
proxy.</blockquote><div><br></div>That may be the case in the many =
scenarios, but I want to make sure that we don=92t prevent people from =
getting the efficiencies in a system where the motes do have a trust =
anchor and caching is appropriate.&nbsp;<br><div =
apple-content-edited=3D"true">
<span class=3D"Apple-style-span" style=3D"border-collapse: separate; =
border-spacing: 0px;"><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px;  "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; ">--&nbsp;<br>Jonathan Simon, Ph. D<br>Director of =
Systems Engineering<br>Linear Technology, Dust Networks product =
group<br>30695 Huntwood Ave<br>Hayward, CA 94544-7021<br>(510) =
400-2936<br>(510) 489-3799 FAX<br><a =
href=3D"mailto:jsimon@linear.com">jsimon@linear.com</a><br><br>**LINEAR =
TECHNOLOGY&nbsp;CORPORATION**&nbsp;<br>*****Internet Email =
Confidentiality&nbsp;Notice*****&nbsp;<br>&nbsp;This e-mail =
transmission, and any&nbsp;documents, files or previous =
e-mail&nbsp;messages attached to it may contain&nbsp;confidential =
information that is&nbsp;legally privileged. If you are not =
the&nbsp;intended recipient, or a person&nbsp;responsible for delivering =
it to the&nbsp;intended recipient, you are hereby&nbsp;notified that any =
disclosure, copying,&nbsp;distribution or use of any of =
the&nbsp;information contained in or attached&nbsp;to this transmission =
is STRICTLY&nbsp;PROHIBITED. If you have received this&nbsp;transmission =
in error, please&nbsp;immediately notify me by reply e-mail, or by =
telephone at (510) 400-2936, and destroy the original&nbsp;transmission =
and its attachments&nbsp;without reading or saving in any&nbsp;manner. =
Thank you.&nbsp;<br></div></span></div></span></span>
</div>
<br><div><div>On Jun 17, 2014, at 5:59 PM, Michael Richardson &lt;<a =
href=3D"mailto:mcr+ietf@sandelman.ca">mcr+ietf@sandelman.ca</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><br>Monday, on the call I asked the group a couple of =
questions relating to the<br>time sequence diagram from =
Jonathan.<br><br>1) given assymetric crypto is there any reason for the =
JOIN REQUEST from the<br> &nbsp;&nbsp;joining node to the PCE (message =
4) to be *encrypted* to the PCE?<br> &nbsp;&nbsp;(Clearly, it needs to =
be signed by the joining node)<br><br>The conclusion was that there are =
things in WirelessHART which were decided<br>were sensitive, and thus =
the packet was encrypted. &nbsp;It was concluded that if<br>there is =
anything left that is sensitive that it can probably be moved to<br>step =
5/6.<br>Leaving out the asymmetric encryption likely saves around 300 =
bits in the<br>packet as well.<br><br>2) having gotten rid of the =
(assymetric) encryption, the question then<br>becomes: do we need to do =
a certificate request/response at all? (steps 2/3).<br><br>Some things =
that were said on the call:<br><br> &nbsp;a) it has been suggested that =
the address of the PCE would be an attribute<br> =
&nbsp;&nbsp;&nbsp;&nbsp;on the certificate that is returned.<br><br> =
&nbsp;b) it has been suggested that the certificate (chain) that would =
permit the<br> &nbsp;&nbsp;&nbsp;&nbsp;joining node to be able to =
validate the PCE's identity, and therefore<br> =
&nbsp;&nbsp;&nbsp;&nbsp;determine if this network is worth =
joining.<br><br> &nbsp;c) there are some significant concerns if (b) is =
the only way that the joining<br> &nbsp;&nbsp;&nbsp;&nbsp;node can =
determine if this is the correct network, that this is putting<br> =
&nbsp;&nbsp;&nbsp;&nbsp;far too much policy and intelligence in the =
joining node.<br><br> &nbsp;d) there is concern that given the =
complexity; that consumer devices may<br> &nbsp;&nbsp;&nbsp;&nbsp;well =
just join whatever network they see first.<br><br> &nbsp;e) at the same =
time, there is concern that message 2/3 does not involve any<br> =
&nbsp;&nbsp;&nbsp;&nbsp;opportunity for a trip to an online database for =
higher value joining<br> &nbsp;&nbsp;&nbsp;&nbsp;nodes.<br><br> &nbsp;f) =
it was suggested that a joining node should record PANIDs to which =
it<br> &nbsp;&nbsp;&nbsp;&nbsp;has attempted to connect to, and failed, =
and therefore it would not<br> &nbsp;&nbsp;&nbsp;&nbsp;continuously =
failing to connect.<br><br> &nbsp;g) it was suggested (by me) that even =
a partical certificate chain could<br> &nbsp;&nbsp;&nbsp;&nbsp;be useful =
in selected a network to join.<br><br>The question was asked, if the =
message 2/3 exchange can never provide enough<br>authorization for a =
joining node to determine which network to join, then an<br>alternate =
question was asked:<br> &nbsp;- is there something which can be cached =
by the proxy, such as part of<br> &nbsp;&nbsp;&nbsp;the PCE certificate =
chain, which would usefully reduce the number of<br> =
&nbsp;&nbsp;&nbsp;messages that need to traverse the entire LLN for each =
joining node.<br><br>A number of people expressed an interest in keeping =
the message 2/3 exchange<br>as an optional part of the protocol. &nbsp;I =
don't like optional pieces, and I<br>would want to signal if message 2/3 =
should occur in the EB, or to always do<br>the message 2 request, and =
permit empty replies.<br><br>If you go back to my email at:<br> =
&nbsp;&nbsp;<a =
href=3D"http://cp.mcafee.com/d/5fHCN8q3xEgdEInpK-OyYqejtPqbwVBcSyUepvdEK3z=
hOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsSMYNZZpvW_e6zB55x7HTbFIFFYyC-yMYVOR=
QX8FGTujVkffGhBrwqrhdECXYyMCY-ehojd79KVIDeqR4IMjSdyszfZbVKY01PoS9UHgzzAVkI=
jbQ-PspjboCl31020Gl2FVdIdbxs9CzCzVomt1qJUnKrsDaBypuDSrzapoKgGT2TQ1kLCXM04S=
ztdAsrdbrAVkIjbQ-Pspjb6BQQgm-cVeOJI_d45JIjYQg8iFpKB9lwq88_rlzh0X6GFEwjKyMn=
KUnhsdKf6_VCDWZ8T7PQQ">http://cp.mcafee.com/d/5fHCN8q3xEgdEInpK-OyYqejtPqb=
wVBcSyUepvdEK3zhOyCOqejrzPPPz5XCN6ABqM1hYEvIundDOx-NVsSMYNZZpvW_e6zB55x7HT=
bFIFFYyC-yMYVORQX8FGTujVkffGhBrwqrhdECXYyMCY-ehojd79KVIDeqR4IMjSdyszfZbVKY=
01PoS9UHgzzAVkIjbQ-PspjboCl31020Gl2FVdIdbxs9CzCzVomt1qJUnKrsDaBypuDSrzapoK=
gGT2TQ1kLCXM04SztdAsrdbrAVkIjbQ-Pspjb6BQQgm-cVeOJI_d45JIjYQg8iFpKB9lwq88_r=
lzh0X6GFEwjKyMnKUnhsdKf6_VCDWZ8T7PQQ</a><br><br>I had four links in the =
particular certificate chain that would permit the<br>joining node to =
authenticate the PCE.<br><br> &nbsp;&nbsp;*1* Factory: =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ACME<br> &nbsp;&nbsp;*2* =
National-VAR: &nbsp;Cadabra<br> &nbsp;&nbsp;*3* Regional-Var: =
&nbsp;Sesame<br> &nbsp;&nbsp;*4* Plant: =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Coyote<br><br>The =
factory certificate (1) would be built into the joining node as a =
trust<br>anchor. &nbsp;&nbsp;If message (3) contained certificate *2*, =
perhaps also *3*, then that<br>would significant help the joining node =
to know that this might be the right<br>network to join, and it would =
reduce the number of bytes sent all the way.<br><br>Some problems/issues =
with this include:<br> &nbsp;&nbsp;&nbsp;i. certificate *2* of the chain =
could be very specific to a particular<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;device, so might be unsuitable for =
caching.<br> &nbsp;&nbsp;ii. request (2) would have to include the DN of =
the trust anchor<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;certificate *1* =
in order to indicate which vendor's certificate should<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;be returned from the proxy. =
&nbsp;&nbsp;Naturally, this opens things up to having<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;as many certificates cached as there =
are factories X VARs.<br> &nbsp;iii. at the DTLS stage, if additional =
parts of the trust path have been<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;cached, then this needs to be =
indicated when the joining nodes issues<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;it's CertificateRequest as part of =
it's ServerHello exchange, so<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;that only part of the certificate =
chain is sent.<br> &nbsp;&nbsp;iv. worse case, the entire certificate =
chain has to be sent at the DTLS<br> =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;stage.<br><br>If the PCE has a =
certificate chain which is not per-IDevID, and yet is<br>anchored at the =
factory installed trust anchor, then maybe this would have<br>higher =
utility.<br><br>While I can see the PCE having a certificate anchored in =
a local CA, and I<br>can see that as part of the join process, the =
joining node would have this<br>new trust anchor installed (along with a =
certificate of its own), I think it<br>is important to remember that =
this occurs *post* join.<br><br>In particular I want to make sure that =
everyone understands that the<br>(successful) join protocol occurs only =
once after the device has been turned<br>on (and/or factory defaulted in =
some OOB way). &nbsp;It does not occur every time<br>the device powers =
up --- the join protocol would have installed the correct<br>PANID, =
L2-Key, etc. into the device.<br><br>So my conclusion is that there is =
little that we can cache on the proxy.<br><br><br>--<br>Michael =
Richardson &lt;<a =
href=3D"mailto:mcr+IETF@sandelman.ca">mcr+IETF@sandelman.ca</a>&gt;, =
Sandelman Software Works<br> -=3D IPv6 IoT consulting =
=3D-<br><br><br><br>_______________________________________________<br>6ti=
sch-security mailing list<br><a =
href=3D"mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a><br>h=
ttp://cp.mcafee.com/d/k-Kr3xAe3zqb5SrLIEL6zATsSyUepjdEK3CnPqbwUQsEFICzASUY=
YYUNuVIhF9mI0kva7X7BPpYEvIundIfcvvmn-LPxEVhhohWZOWraqv8FLEIfesJteOaqJTA-l3=
PWApmU6CQjq9K_8I9LfzAm4PhOrKr9PCJhbcatbVKY01MjlS67OFek7qUVelb4OZfIT6kONJOs=
Gm9BWvpKcFByV2Hsbvg5i-rL00jqdQShNIQJKjBiNcLjXdNBcIqnjh1rUPAXaSPYQgmSNfPh0x=
aBCWkBm1EwzZJmd43IqGCy1eWb1uXxt5MSUYrdwQH<br></blockquote></div><br></body=
></html>=

--Apple-Mail=_4C69127D-2397-4EDC-BE07-676FF5B7C3C2--


From nobody Wed Jun 18 12:28:40 2014
Return-Path: <twatteyne@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34C131A0261; Wed, 18 Jun 2014 12:28:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.677
X-Spam-Level: 
X-Spam-Status: No, score=-0.677 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, J_CHICKENPOX_21=0.6, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bNnnfTJUluxQ; Wed, 18 Jun 2014 12:28:36 -0700 (PDT)
Received: from mail-qc0-x230.google.com (mail-qc0-x230.google.com [IPv6:2607:f8b0:400d:c01::230]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5FDA1A0289; Wed, 18 Jun 2014 12:28:35 -0700 (PDT)
Received: by mail-qc0-f176.google.com with SMTP id w7so1249799qcr.35 for <multiple recipients>; Wed, 18 Jun 2014 12:28:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:from:date:message-id:subject:to:content-type;  bh=2YIjepmHa/hBKkV/5d8xIjX0ixEi+GxK6MzQcgomd1Q=; b=zzmkNgSuD0mSbJjzoOFpaLN4bomS4nKyZvHo3dWH/04dP97CjzJRPohes2CWiRmmav BFyS0DgcMK887aJ/FMdUO3lQUZBucu2REAReQsiVWTYC1ucgJHjnnT9m6XKtfiURorhY PDyE87z2jpqJXHAT5kz0Zjh3aoZxzjplALH9q06cn0cDwoMNcGwVozypCQKYA085xOwJ VN3RuPk07yZOhVTMyj+i2Gp3dqf0oUnt/u9Iu8p7z2EQMLlyaNzChM9vBxIZaVSzLTEK 2oib5nbxJ2XDEtdqdfALET+0AfFC13hP7T6nAyvJLQ9GDU/0UQ0LxgJEQUMZb16pMuG5 MZWw==
X-Received: by 10.224.111.196 with SMTP id t4mr70090qap.63.1403119714808; Wed, 18 Jun 2014 12:28:34 -0700 (PDT)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.140.109.182 with HTTP; Wed, 18 Jun 2014 12:28:14 -0700 (PDT)
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Wed, 18 Jun 2014 12:28:14 -0700
X-Google-Sender-Auth: wgfgkJB-WML6_CxmH4qMbxk93QQ
Message-ID: <CADJ9OA8L6SuucVCUF+qy1Xv+k-f+Z06EXhWX-GWMroZExx685w@mail.gmail.com>
To: "6tisch@ietf.org" <6tisch@ietf.org>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Content-Type: multipart/alternative; boundary=001a11c2d6002dbc8204fc214467
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VlVXxGQWt32xlncc7TbwBoVu1bg
Subject: [6tisch-security] Minutes security discussion 16 June 2014
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jun 2014 19:28:38 -0000

--001a11c2d6002dbc8204fc214467
Content-Type: text/plain; charset=UTF-8

All,

You will find the minutes of the last security discussion at
https://bitbucket.org/6tisch/meetings/wiki/140616_webex_security, also
copy-pasted below.

Please fix anything we might have missed directly in the e-mail and reply
to both 6tisch and 6tisch-security MLs.

Thomas

---

Minutes Webex 16 June 2014, 6TiSCH Security Design Team

Note: timestamps in PDT.
Taking notes *(using Etherpad)*

   1. Pascal Thubert
   2. Michael Richardson
   3. Thomas Watteyne

Present *(alphabetically)*

   1. Giuseppe Piro
   2. Jonathan Simon
   3. Maik Seewald
   4. Michael Richardson
   5. Nancy Cam-Winget
   6. Pascal Thubert
   7. Pat Kinney
   8. Rene Struik
   9. Subir Das
   10. Thomas Watteyne
   11. Tom Phinney
   12. Yoshihiro Ohba

Recording

   - Webex recording (audio+slides,streaming)
   -
   https://cisco.webex.com/ciscosales/lsr.php?RCID=94dcaeeaca494567b83960d2d7cbad62
    *[61min]*

Slides

   - No slides shared through Webex, reusing slides from last call
   -
   https://bitbucket.org/6tisch/meetings/src/master/140609_webex_sec/140609_webex_sec.pdf

Agenda

   1. Announce ANIMA/UCAN BOF.

   http://trac.tools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90

   2. work on trust/cryptographic details of Joining-Node -> PCE message.
      - does it need to be signed?
   3. 6top ideas for PCE->joining node protocol. Will this work as stock
      - CoAP/DTLS, or do we need a proxy to help us?

Minutes

   - *[07.07]* Meeting starts
   - [MCR] continue Mozilla Etherpad

   reco

   - *[Michael]*
      - let's use slides from last week
      - new BoF at IETF90: ANIMA/UCAN


      http://trac.tools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90

      - Core is Michael Behringer's autonomic draft, people should be aware
      of this effort
      - Autonomic Networking Integrated Model and Approach (
      https://www.ietf.org/mailman/listinfo/anima)
      - wanted to talk about messages from slide 3
   - *[Michael]* messages 4 and 5. Need to understand properties of these
   messages. Have to either encrypt or sign by PSK. If we have private key,
   why is message 4 encrypted to PCE? Is it enough to sign by joining node?
   what's the freshness criteria?
   - *[Rene]* what is fresh?
   - *[Michael]* Message 4 could be pre-calculated by joining node long
   before.
   - *[Rene]* First message by joining node, no guarantee will be fresh.
   - *[Michael]* One of the elements of that message is neighbor info. We
   could have a nonce based on ASN.
   - *[Rene]* You cannot have any assurance about first packet. The PCE
   responds.
   - *[Michael]* There could be some freshness in it.
   - *[Michael]* Model trying to see whether possible, is where there is a
   long period of time between messages 4 or 5.
   - *[Michael]* 5 could start a CoAP/DTLS session, there is no strong
   relationship between 4 and 5.
   - *[Michael]* PCE could manage order of joining.
   - *[Michael]* If message 4 does not have to be fresh, it can be
   periodically resent until the node joins the network.
   - *[Rene]* suggesting joining node is sending
   - *[Thomas]* is there any benefits in repeating> that's wasted bandwidth.
   - *[Michael]* if we have an ACK we can avoid it
   - *[Thomas]* The proxy ACKs at L2, it is responsible for the packet
   after that.
   - *[Michael]* what if lost somewhere up?
   - *[Thomas]* can happen. There can be a very long retry timeout.
   - *[Michael]* agreed. if too many nodes are turned on, the PCE can
   manage the order and may go out to vendor and get certificate or a security
   token to complete the join process. Open loops possible, e.g. manual
   authorization by a human.
   - *[Michael]* We do not want to have to hit a button or something like
   that.
   - *[Thomas]* Strictly speaking, the joining node is able to keep sync
   while waiting for reply, keeping in sync with the proxy node and waiting
   for join response.
   - *[Michael]* Question: is there a reason for message 4 to be encrypted
   to PCE?
   - *[Thomas]* In a PSK case, encrypting msg 4 shows that the node has the
   credentials.
   - *[Michael]* Address of PCE could use built into certificate. Is this
   why encrypt to PCE?
   - *[Jonathan]* came from WirelessHART case, where confidential info is
   placed there (e.g. HART-specific configuration info). These device details
   are not publicly broadcast e.g. what kind of device/capabilities.
   - *[Michael]* is there something that would need to be kept private (in
   the future?). If we do not encrypt to PCE we do not need messages 2 and 3
   - *[Thomas]* this is used for the node to know who it is talking to.
   Else it could take a long while to figure this is the wrong network. This
   is really a caching mechanism.
   - *[Michael]* The address of the PCE may well be in the certificate as
   an attribute.
   - *[Michael]* Certificate response in step 3 cannot contain
   authentication token that allows node to know which network it joins. This
   is between messages 5 and 6 when certificate chains or authorization tokens
   arrive. The certificate response could contain much of the certificate
   chain but not all. The joining node could authenticate but figure that
   there is a relationship with vendor.
   - *[Tom]* Example: many networks in a refinery with same owner, since
   the ExxonMobil owns the whole place. This granularity has to be coming from
   a tag. Out of the box the device cannot know which part of the network it
   needs to join.
   - *[Nancy]* we want to endpoint to be provisioned with right
   certificates. In utility sector service provider (SP) may be like a PG&E,
   can be provisioning the smart meters with root certificates that indicate
   which SP network to join. Consumer is very different.
   - *[Tom]* device does not know with the granularity of which block
   inside the network. Need to provision e.g. with a link back to central
   system
   - *[Thomas]* to combine the 2, if the device joins the wrong network,
   PCE can fix that.
   - *[Tom]* can see the joining device probing, trial and error and
   blacklist networks but that places the burden on the device. The right info
   is only available in some central system.
   - *[Jonathan]* in HART it is all initiated by joining device
   - *[Tom]* has to, but must come with some ID. Device provisioning may be
   done by ExxonMobil and then put in the field with a tag name that allows to
   correlate the device with its role (e.g. street address in smart meters).
   Devices have differentiable characteristics so confidentiality of the join
   process is illusional.
   - *[Michael]* concerned about device intercepted on the way to plant.
   Are we adding some defense by having the device figure the place is correct
   or not?
   - *[Tom]* would make that an option. Large system owner would tag device
   for tracking. Need also to look at home owner. No pre-provisioning, single
   step. Enable security system to add a new device, or manually add a serial
   number.
   - *[Michael]* not chartered so mush for that in 6TiSCH, expect a network
   manager. Not to go too heavily towards home.
   - *[Jonathan]* there is an installer that at least can read a do and
   feed back a central office.
   - *[Tom]* there has to be something that binds the role with the device,
   e.g. which pipe a corrosion monitor is placed on.
   - *[Michael]* that can be done out-of-band.
   - *[Tom]* yes, there is a mechanism whereby installer says I'm adding
   that device for that function.
   - *[Thomas]* Big plant case. Out of band provisioning of some data base.
   Device starts with info about this is the network device must join. See a
   number of potential proxies. During the real handshake the networks can
   reject where it is not expected.
   - *[Michael]* could PCEs from different networks communicate to answer
   to the device which proxy it should join?
   - *[Tom]* device needs positive/negative information to rejoin faster
   and not retry the wring networks. PANID can be used.
   - *[Thomas]* How does joining node identify network?
   - *[Tom]* device knows which network sent EB.
   - *[Michael]* can be forged.
   - *[Tom]* in large companies, many businesses side-by-side interfering.
   Lots of rejections in such scenarios.
   - *[Thomas]* PANID is a great filter but not security.
   - *[Michael]* step 2 must indicate what type of certificate chain is
   expected and proxy will answer I'm ExxonMobil and that root says so.
   - *[Tom]* yes, depending on timing when the device validates the chain.
   - *[Michael]* 7/11 could have purchased the same devices so serial
   numbers are needed to validate the right device in the right network.
   - *[Jonathan]* proxy can cache some certs.

--001a11c2d6002dbc8204fc214467
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>All,</div><div><br></div><div>You will find the minut=
es of the last security discussion at <a href=3D"https://bitbucket.org/6tis=
ch/meetings/wiki/140616_webex_security">https://bitbucket.org/6tisch/meetin=
gs/wiki/140616_webex_security</a>, also copy-pasted below.</div>

<div><br></div><div>Please fix anything we might have missed directly in th=
e e-mail and reply to both 6tisch and 6tisch-security MLs.</div><div><br></=
div><div>Thomas</div><div><br></div><div>---</div><div><br></div><div>
<h1 id=3D"markdown-header-minutes-webex-16-june-2014-6tisch-security-design=
-team" style=3D"margin:0px 0px 10px;padding:0px;font-size:24px;font-weight:=
normal;line-height:1.25;color:rgb(51,51,51);font-family:Arial,sans-serif">
Minutes Webex 16 June 2014, 6TiSCH Security Design Team</h1><h1 id=3D"markd=
own-header-minutes-webex-16-june-2014-6tisch-security-design-team" style=3D=
"margin:0px 0px 10px;padding:0px;font-size:24px;line-height:1.25;color:rgb(=
51,51,51);font-family:Arial,sans-serif">

<p style=3D"margin:10px 0px 0px;padding:0px;word-wrap:break-word;font-size:=
14px;font-weight:normal;line-height:20px">Note: timestamps in PDT.</p></h1>=
<h2 id=3D"markdown-header-taking-notes-using-etherpad" style=3D"margin:20px=
 0px 0px;padding:0px;font-size:20px;font-weight:normal;line-height:1.5;colo=
r:rgb(51,51,51);font-family:Arial,sans-serif">

Taking notes=C2=A0<em>(using Etherpad)</em></h2><h1 style=3D"margin:0px 0px=
 10px;padding:0px;font-size:24px;line-height:1.25;color:rgb(51,51,51);font-=
family:Arial,sans-serif"><ol style=3D"margin:10px 0px 0px;font-size:14px;fo=
nt-weight:normal;line-height:20px">

<li style=3D"word-wrap:break-word">Pascal Thubert</li><li style=3D"word-wra=
p:break-word">Michael Richardson</li><li style=3D"word-wrap:break-word">Tho=
mas Watteyne</li></ol></h1><h2 id=3D"markdown-header-present-alphabetically=
" style=3D"margin:20px 0px 0px;padding:0px;font-size:20px;font-weight:norma=
l;line-height:1.5;color:rgb(51,51,51);font-family:Arial,sans-serif">

Present=C2=A0<em>(alphabetically)</em></h2><h1 style=3D"margin:0px 0px 10px=
;padding:0px;font-size:24px;line-height:1.25;color:rgb(51,51,51);font-famil=
y:Arial,sans-serif"><ol style=3D"margin:10px 0px 0px;font-size:14px;font-we=
ight:normal;line-height:20px">

<li style=3D"word-wrap:break-word">Giuseppe Piro</li><li style=3D"word-wrap=
:break-word">Jonathan Simon</li><li style=3D"word-wrap:break-word">Maik See=
wald</li><li style=3D"word-wrap:break-word">Michael Richardson</li><li styl=
e=3D"word-wrap:break-word">

Nancy Cam-Winget</li><li style=3D"word-wrap:break-word">Pascal Thubert</li>=
<li style=3D"word-wrap:break-word">Pat Kinney</li><li style=3D"word-wrap:br=
eak-word">Rene Struik</li><li style=3D"word-wrap:break-word">Subir Das</li>=
<li style=3D"word-wrap:break-word">

Thomas Watteyne</li><li style=3D"word-wrap:break-word">Tom Phinney</li><li =
style=3D"word-wrap:break-word">Yoshihiro Ohba</li></ol></h1><h2 id=3D"markd=
own-header-recording" style=3D"margin:20px 0px 0px;padding:0px;font-size:20=
px;font-weight:normal;line-height:1.5;color:rgb(51,51,51);font-family:Arial=
,sans-serif">

Recording</h2><h1 style=3D"margin:0px 0px 10px;padding:0px;font-size:24px;l=
ine-height:1.25;color:rgb(51,51,51);font-family:Arial,sans-serif"><ul style=
=3D"margin:10px 0px 0px;font-size:14px;font-weight:normal;line-height:20px"=
>

<li style=3D"word-wrap:break-word">Webex recording (audio+slides,streaming)=
</li><li style=3D"word-wrap:break-word"><a href=3D"https://cisco.webex.com/=
ciscosales/lsr.php?RCID=3D94dcaeeaca494567b83960d2d7cbad62" rel=3D"nofollow=
" style=3D"color:rgb(59,115,175);text-decoration:none">https://cisco.webex.=
com/ciscosales/lsr.php?RCID=3D94dcaeeaca494567b83960d2d7cbad62</a>=C2=A0<em=
>[61min]</em></li>

</ul></h1><h2 id=3D"markdown-header-slides" style=3D"margin:20px 0px 0px;pa=
dding:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51=
,51);font-family:Arial,sans-serif">Slides</h2><h1 style=3D"margin:0px 0px 1=
0px;padding:0px;font-size:24px;line-height:1.25;color:rgb(51,51,51);font-fa=
mily:Arial,sans-serif">

<ul style=3D"margin:10px 0px 0px;font-size:14px;font-weight:normal;line-hei=
ght:20px"><li style=3D"word-wrap:break-word">No slides shared through Webex=
, reusing slides from last call</li><li style=3D"word-wrap:break-word"><a h=
ref=3D"https://bitbucket.org/6tisch/meetings/src/master/140609_webex_sec/14=
0609_webex_sec.pdf" rel=3D"nofollow" style=3D"color:rgb(59,115,175);text-de=
coration:none">https://bitbucket.org/6tisch/meetings/src/master/140609_webe=
x_sec/140609_webex_sec.pdf</a></li>

</ul></h1><h2 id=3D"markdown-header-agenda" style=3D"margin:20px 0px 0px;pa=
dding:0px;font-size:20px;font-weight:normal;line-height:1.5;color:rgb(51,51=
,51);font-family:Arial,sans-serif">Agenda</h2><h1 style=3D"margin:0px 0px 1=
0px;padding:0px;font-size:24px;line-height:1.25;color:rgb(51,51,51);font-fa=
mily:Arial,sans-serif">

<ol style=3D"margin:10px 0px 0px;font-size:14px;font-weight:normal;line-hei=
ght:20px"><li style=3D"word-wrap:break-word">Announce ANIMA/UCAN BOF.<block=
quote style=3D"margin:0px 0px 0px 19px;border-left-width:1px;border-left-st=
yle:solid;border-left-color:rgb(204,204,204);color:rgb(112,112,112);padding=
:10px 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word"><a href=3D"http://=
trac.tools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90" rel=3D"n=
ofollow" style=3D"color:rgb(59,115,175);text-decoration:none">http://trac.t=
ools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90</a></p>

</blockquote></li><li style=3D"word-wrap:break-word">work on trust/cryptogr=
aphic details of Joining-Node -&gt; PCE message.<ul style=3D"margin:0px"><l=
i style=3D"word-wrap:break-word">does it need to be signed?</li></ul></li><=
li style=3D"word-wrap:break-word">

6top ideas for PCE-&gt;joining node protocol. Will this work as stock<ul st=
yle=3D"margin:0px"><li style=3D"word-wrap:break-word">CoAP/DTLS, or do we n=
eed a proxy to help us?</li></ul></li></ol></h1><h2 id=3D"markdown-header-m=
inutes" style=3D"margin:20px 0px 0px;padding:0px;font-size:20px;font-weight=
:normal;line-height:1.5;color:rgb(51,51,51);font-family:Arial,sans-serif">

Minutes</h2><h1 style=3D"margin:0px 0px 10px;padding:0px;font-size:24px;lin=
e-height:1.25;color:rgb(51,51,51);font-family:Arial,sans-serif"><ul style=
=3D"margin:10px 0px 0px;font-size:14px;font-weight:normal;line-height:20px"=
>
<li style=3D"word-wrap:break-word">
<em>[07.07]</em>=C2=A0Meeting starts</li><li style=3D"word-wrap:break-word"=
>[MCR] continue Mozilla Etherpad<blockquote style=3D"margin:0px 0px 0px 19p=
x;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,2=
04,204);color:rgb(112,112,112);padding:10px 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word">reco</p></blockquo=
te></li><li style=3D"word-wrap:break-word"><strong>[Michael]</strong><ul st=
yle=3D"margin:10px 0px 0px"><li style=3D"word-wrap:break-word">let&#39;s us=
e slides from last week</li>

<li style=3D"word-wrap:break-word">new BoF at IETF90: ANIMA/UCAN<blockquote=
 style=3D"margin:0px 0px 0px 19px;border-left-width:1px;border-left-style:s=
olid;border-left-color:rgb(204,204,204);color:rgb(112,112,112);padding:10px=
 20px">

<p style=3D"margin:0px;padding:0px;word-wrap:break-word"><a href=3D"http://=
trac.tools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90" rel=3D"n=
ofollow" style=3D"color:rgb(59,115,175);text-decoration:none">http://trac.t=
ools.ietf.org/bof/trac/wiki/WikiStart#UCANApprovedforIETF90</a></p>

</blockquote></li><li style=3D"word-wrap:break-word">Core is Michael Behrin=
ger&#39;s autonomic draft, people should be aware of this effort</li><li st=
yle=3D"word-wrap:break-word">Autonomic Networking Integrated Model and Appr=
oach (<a href=3D"https://www.ietf.org/mailman/listinfo/anima" rel=3D"nofoll=
ow" style=3D"color:rgb(59,115,175);text-decoration:none">https://www.ietf.o=
rg/mailman/listinfo/anima</a>)</li>

<li style=3D"word-wrap:break-word">wanted to talk about messages from slide=
 3</li></ul></li><li style=3D"word-wrap:break-word"><strong>[Michael]</stro=
ng>=C2=A0messages 4 and 5. Need to understand properties of these messages.=
 Have to either encrypt or sign by PSK. If we have private key, why is mess=
age 4 encrypted to PCE? Is it enough to sign by joining node? what&#39;s th=
e freshness criteria?</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0what is fre=
sh?</li><li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0=
Message 4 could be pre-calculated by joining node long before.</li><li styl=
e=3D"word-wrap:break-word">

<strong>[Rene]</strong>=C2=A0First message by joining node, no guarantee wi=
ll be fresh.</li><li style=3D"word-wrap:break-word"><strong>[Michael]</stro=
ng>=C2=A0One of the elements of that message is neighbor info. We could hav=
e a nonce based on ASN.</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0You cannot =
have any assurance about first packet. The PCE responds.</li><li style=3D"w=
ord-wrap:break-word"><strong>[Michael]</strong>=C2=A0There could be some fr=
eshness in it.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0Model tr=
ying to see whether possible, is where there is a long period of time betwe=
en messages 4 or 5.</li><li style=3D"word-wrap:break-word"><strong>[Michael=
]</strong>=C2=A05 could start a CoAP/DTLS session, there is no strong relat=
ionship between 4 and 5.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0PCE coul=
d manage order of joining.</li><li style=3D"word-wrap:break-word"><strong>[=
Michael]</strong>=C2=A0If message 4 does not have to be fresh, it can be pe=
riodically resent until the node joins the network.</li>

<li style=3D"word-wrap:break-word"><strong>[Rene]</strong>=C2=A0suggesting =
joining node is sending</li><li style=3D"word-wrap:break-word"><strong>[Tho=
mas]</strong>=C2=A0is there any benefits in repeating&gt; that&#39;s wasted=
 bandwidth.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0if we ha=
ve an ACK we can avoid it</li><li style=3D"word-wrap:break-word"><strong>[T=
homas]</strong>=C2=A0The proxy ACKs at L2, it is responsible for the packet=
 after that.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0what if =
lost somewhere up?</li><li style=3D"word-wrap:break-word"><strong>[Thomas]<=
/strong>=C2=A0can happen. There can be a very long retry timeout.</li><li s=
tyle=3D"word-wrap:break-word">

<strong>[Michael]</strong>=C2=A0agreed. if too many nodes are turned on, th=
e PCE can manage the order and may go out to vendor and get certificate or =
a security token to complete the join process. Open loops possible, e.g. ma=
nual authorization by a human.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0We do no=
t want to have to hit a button or something like that.</li><li style=3D"wor=
d-wrap:break-word"><strong>[Thomas]</strong>=C2=A0Strictly speaking, the jo=
ining node is able to keep sync while waiting for reply, keeping in sync wi=
th the proxy node and waiting for join response.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0Question=
: is there a reason for message 4 to be encrypted to PCE?</li><li style=3D"=
word-wrap:break-word"><strong>[Thomas]</strong>=C2=A0In a PSK case, encrypt=
ing msg 4 shows that the node has the credentials.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0Address =
of PCE could use built into certificate. Is this why encrypt to PCE?</li><l=
i style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0came from=
 WirelessHART case, where confidential info is placed there (e.g. HART-spec=
ific configuration info). These device details are not publicly broadcast e=
.g. what kind of device/capabilities.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0is there=
 something that would need to be kept private (in the future?). If we do no=
t encrypt to PCE we do not need messages 2 and 3</li><li style=3D"word-wrap=
:break-word">

<strong>[Thomas]</strong>=C2=A0this is used for the node to know who it is =
talking to. Else it could take a long while to figure this is the wrong net=
work. This is really a caching mechanism.</li><li style=3D"word-wrap:break-=
word">

<strong>[Michael]</strong>=C2=A0The address of the PCE may well be in the c=
ertificate as an attribute.</li><li style=3D"word-wrap:break-word"><strong>=
[Michael]</strong>=C2=A0Certificate response in step 3 cannot contain authe=
ntication token that allows node to know which network it joins. This is be=
tween messages 5 and 6 when certificate chains or authorization tokens arri=
ve. The certificate response could contain much of the certificate chain bu=
t not all. The joining node could authenticate but figure that there is a r=
elationship with vendor.</li>

<li style=3D"word-wrap:break-word"><strong>[Tom]</strong>=C2=A0Example: man=
y networks in a refinery with same owner, since the ExxonMobil owns the who=
le place. This granularity has to be coming from a tag. Out of the box the =
device cannot know which part of the network it needs to join.</li>

<li style=3D"word-wrap:break-word"><strong>[Nancy]</strong>=C2=A0we want to=
 endpoint to be provisioned with right certificates. In utility sector serv=
ice provider (SP) may be like a PG&amp;E, can be provisioning the smart met=
ers with root certificates that indicate which SP network to join. Consumer=
 is very different.</li>

<li style=3D"word-wrap:break-word"><strong>[Tom]</strong>=C2=A0device does =
not know with the granularity of which block inside the network. Need to pr=
ovision e.g. with a link back to central system</li><li style=3D"word-wrap:=
break-word">

<strong>[Thomas]</strong>=C2=A0to combine the 2, if the device joins the wr=
ong network, PCE can fix that.</li><li style=3D"word-wrap:break-word"><stro=
ng>[Tom]</strong>=C2=A0can see the joining device probing, trial and error =
and blacklist networks but that places the burden on the device. The right =
info is only available in some central system.</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0in HART=
 it is all initiated by joining device</li><li style=3D"word-wrap:break-wor=
d"><strong>[Tom]</strong>=C2=A0has to, but must come with some ID. Device p=
rovisioning may be done by ExxonMobil and then put in the field with a tag =
name that allows to correlate the device with its role (e.g. street address=
 in smart meters). Devices have differentiable characteristics so confident=
iality of the join process is illusional.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0concerne=
d about device intercepted on the way to plant. Are we adding some defense =
by having the device figure the place is correct or not?</li><li style=3D"w=
ord-wrap:break-word">

<strong>[Tom]</strong>=C2=A0would make that an option. Large system owner w=
ould tag device for tracking. Need also to look at home owner. No pre-provi=
sioning, single step. Enable security system to add a new device, or manual=
ly add a serial number.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0not char=
tered so mush for that in 6TiSCH, expect a network manager. Not to go too h=
eavily towards home.</li><li style=3D"word-wrap:break-word"><strong>[Jonath=
an]</strong>=C2=A0there is an installer that at least can read a do and fee=
d back a central office.</li>

<li style=3D"word-wrap:break-word"><strong>[Tom]</strong>=C2=A0there has to=
 be something that binds the role with the device, e.g. which pipe a corros=
ion monitor is placed on.</li><li style=3D"word-wrap:break-word"><strong>[M=
ichael]</strong>=C2=A0that can be done out-of-band.</li>

<li style=3D"word-wrap:break-word"><strong>[Tom]</strong>=C2=A0yes, there i=
s a mechanism whereby installer says I&#39;m adding that device for that fu=
nction.</li><li style=3D"word-wrap:break-word"><strong>[Thomas]</strong>=C2=
=A0Big plant case. Out of band provisioning of some data base. Device start=
s with info about this is the network device must join. See a number of pot=
ential proxies. During the real handshake the networks can reject where it =
is not expected.</li>

<li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0could PC=
Es from different networks communicate to answer to the device which proxy =
it should join?</li><li style=3D"word-wrap:break-word"><strong>[Tom]</stron=
g>=C2=A0device needs positive/negative information to rejoin faster and not=
 retry the wring networks. PANID can be used.</li>

<li style=3D"word-wrap:break-word"><strong>[Thomas]</strong>=C2=A0How does =
joining node identify network?</li><li style=3D"word-wrap:break-word"><stro=
ng>[Tom]</strong>=C2=A0device knows which network sent EB.</li><li style=3D=
"word-wrap:break-word">

<strong>[Michael]</strong>=C2=A0can be forged.</li><li style=3D"word-wrap:b=
reak-word"><strong>[Tom]</strong>=C2=A0in large companies, many businesses =
side-by-side interfering. Lots of rejections in such scenarios.</li><li sty=
le=3D"word-wrap:break-word">

<strong>[Thomas]</strong>=C2=A0PANID is a great filter but not security.</l=
i><li style=3D"word-wrap:break-word"><strong>[Michael]</strong>=C2=A0step 2=
 must indicate what type of certificate chain is expected and proxy will an=
swer I&#39;m ExxonMobil and that root says so.</li>

<li style=3D"word-wrap:break-word"><strong>[Tom]</strong>=C2=A0yes, dependi=
ng on timing when the device validates the chain.</li><li style=3D"word-wra=
p:break-word"><strong>[Michael]</strong>=C2=A07/11 could have purchased the=
 same devices so serial numbers are needed to validate the right device in =
the right network.</li>

<li style=3D"word-wrap:break-word"><strong>[Jonathan]</strong>=C2=A0proxy c=
an cache some certs.</li></ul></h1></div></div>

--001a11c2d6002dbc8204fc214467--


From nobody Sun Jun 22 20:21:33 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C4011A02C9 for <6tisch-security@ietfa.amsl.com>; Sun, 22 Jun 2014 20:21:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.541
X-Spam-Level: 
X-Spam-Status: No, score=-2.541 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jnKf51jO_FTw for <6tisch-security@ietfa.amsl.com>; Sun, 22 Jun 2014 20:21:29 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C339B1A02A9 for <6tisch-security@ietf.org>; Sun, 22 Jun 2014 20:21:29 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8D31120030 for <6tisch-security@ietf.org>; Sun, 22 Jun 2014 23:25:42 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 1702B63B0E; Sun, 22 Jun 2014 23:21:23 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id E362C63B09 for <6tisch-security@ietf.org>; Sun, 22 Jun 2014 23:21:23 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <14319.1402884686@sandelman.ca>
References: <14319.1402884686@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sun, 22 Jun 2014 23:21:23 -0400
Message-ID: <25450.1403493683@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/_b8Bcvj0TjuTKFxotOUiouA3C-g
Subject: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 03:21:32 -0000

--=-=-=


Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > We had a very productive call last week.

    > -- The URL to access the webex, which will we use for audio only:
    > https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

We will attempt to use the IETF etherpad again:
  http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security

Last time we dealt with the question:
    > Agenda for tomorrow:
    > 1. work on trust/cryptographic details of Joining-Node -> PCE message.
    > does it need to be signed?

which I summarized in the email at:
      https://mailarchive.ietf.org/arch/msg/6tisch-security/DT-K0_qd_wd-GmqB4YVqQtbhC6Q
or:   with the thread at:
      http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00175.html

    > 2. 6top ideas for PCE->joining node protocol. Will this work as stock
    > CoAP/DTLS, or do we need a proxy to help us?

I would like to focus on item #2.
This is about whether or not the joining node can layer-3 address the PCE,
and whether or not the PCE can address the joining node directly, or if it
needs help from the proxy, and if so, what form does the help take?

We have had part of this discussion before.

I propose that we have no call on 2014-06-30, the draft deadline is July 4,
and we need to get some things in.

I will remind that we worked on a table of contents, posted as:
   http://datatracker.ietf.org/doc/draft-richardson-6tisch-table-of-contents/

a very rough version of a document explaining the "Wireless-HART"/6top method
of doing joining is at:
  https://bitbucket.org/6tisch/draft-richardson-6tisch-security-architecture/src/625fefe5574fe3e4ca3de7b3c14c2c1dcf073ebd/draft-richardson-6tisch-security-6top.xml?at=obiwan

we still need someone to fill in a table of contents from the EAP-TLS point
of view.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU6edM4CLcPvd0N1lAQKLNQf9HemZvYfn/7LWmkFSW3NOG1ONvLslPent
5kftIfGnX4DQAo+HFVarBSr8r4MUn8tREhY/s4Z2v2YC+vtZx598FFo1YXHAsvhG
uYNbgAUanLhgSnPo5anoTrxsSTy7l0yr71Et0xV8gzlnY+3fJHHn+6djH5bwt9r5
XbvgW7qn8WZzUcaoaSyuh+nqiI1SXg6XwSbhcm1AqGuF4sRGr1+RVlEeYM++hLhv
DqsvkQH8Gmh0q9IW1G3QBJb/HL20rLVQEyqwmFcTLufBegPQYvDET+GAK4dHYKam
SKVS/URWYXHS3Eb8mikaIF0pb0NBqWYZdtgDuo4TEdB7ehKIZd+URQ==
=kpBY
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 23 06:53:16 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9AB041B2AA3 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 06:53:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gC3ecKpayZas for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 06:53:11 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D68E01B2961 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 06:53:10 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 75C0420030 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 09:57:25 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 5381963B0E; Mon, 23 Jun 2014 09:53:09 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 4723663AED for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 09:53:09 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <25450.1403493683@sandelman.ca>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 23 Jun 2014 09:53:09 -0400
Message-ID: <29190.1403531589@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/oVjOac-rIZC7qCm65Bt1GUBcp7g
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 13:53:12 -0000

--=-=-=


Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    >> We had a very productive call last week.

    >> -- The URL to access the webex, which will we use for audio only:
    >>
    >https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908

This says "meeting cancelled".
I assume it is an administrative oops, stay tuned for another URL, I guess.

I have a bridge that can be used; accessible via SIP: and PSTN, but I will
wait ten minutes before suggesting it.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU6gxRYCLcPvd0N1lAQKL6AgAufnO9OMaw08h1bOG54lqJlRszSrjGmAG
jgnlbRq16zeV9S7ezJJYTpNntbqB1uuubMBShuJakWtmNzYsx8nitj7aNxsDtwbr
Vy2guy+k7XEbyW/VjVHgUnIr8rSMzmsa11N3elTlQaEMeFdTn7ZWmeXgZpIgkQdi
ASQBx51BajV3hDyYj3eLJkasGyF19vwgGAlhc1lB8xuYZAOk1TaEVy2/ZisxZGpm
O4P84D/4ITYw/FSFDBi+XOoOQtajLDkv4jabdbDXWJuQaEK4PGHodog75rysnsgV
HIrOzyCPnyr6Icgk08DkcgW06vYG53IBNqUv+vBW78R6FcRpLhuoeA==
=OKkB
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 23 07:01:47 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F6F71B2B23 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:01:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UsoDpz8SQppR for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:01:34 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F4AB1B2B20 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:01:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1035; q=dns/txt; s=iport; t=1403532086; x=1404741686; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=j1hEZajQ1hOWkBk7OW9PuGR38q2TDYJSdQthf5mNa44=; b=Ofc8PmakDehvMYQDbnxnksMuFGRYBxgTO0xPAd4IIFWtjNlgmdLZEoq4 5JjMeH9pcTzoiOjmnuhu20DnJNY/DGMfGf7D0cmtlpsSxiI9uRT/ZjA3X dDZ86UYR9TN/cZ6LnCHIC33Vkw2jPzzcjVA8A2i4mQiax+gxloKBcK+8G A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AogFAHAyqFOtJV2d/2dsb2JhbAA/GoMNUlqqOwEBAQEBB5F1hm1TAYENFnWEAwEBAQMBAQEBNzQLEAIBCBgeECcLJQIEDgWIOggNNsVqEwSFY4V3AYJuMweDLYEWBJpMk2ODQmyBAgQ+
X-IronPort-AV: E=Sophos;i="5.01,530,1400025600"; d="scan'208";a="334828691"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-1.cisco.com with ESMTP; 23 Jun 2014 14:01:26 +0000
Received: from xhc-aln-x04.cisco.com (xhc-aln-x04.cisco.com [173.36.12.78]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id s5NE1PXG007693 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 23 Jun 2014 14:01:25 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.82]) by xhc-aln-x04.cisco.com ([173.36.12.78]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:01:25 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] agenda for 2014-06-23 6tisch security call
Thread-Index: AQHPjpI/kd8WGZdf10ut/aErZSztHZt/C5uAgAACTgA=
Date: Mon, 23 Jun 2014 14:01:24 +0000
Message-ID: <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca>
In-Reply-To: <29190.1403531589@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.82.217.146]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <F23E6D792F600E42A532062C5EDBD3E8@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/DlVhh_6HvddGs0pjPGeNQhqi5rQ
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:01:41 -0000

If necessary I could create a different webex as well?=20
- max

On Jun 23, 2014, at 3:53 PM, Michael Richardson <mcr+ietf@sandelman.ca> wro=
te:

>=20
> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>> We had a very productive call last week.
>=20
>>> -- The URL to access the webex, which will we use for audio only:
>>>=20
>> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580b=
7908
>=20
> This says "meeting cancelled".
> I assume it is an administrative oops, stay tuned for another URL, I gues=
s.
>=20
> I have a bridge that can be used; accessible via SIP: and PSTN, but I wil=
l
> wait ten minutes before suggesting it.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Mon Jun 23 07:10:07 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 501C81B295D for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:10:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rng94M7gPbJ5 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:10:05 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC0C91B2925 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:10:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1532; q=dns/txt; s=iport; t=1403532605; x=1404742205; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=9Mr5qwV4yDVyz/HSRHbKZw9VXqsQ7YMA8T+9KlJ9FqU=; b=WiN/wwlp4L8os4Wd+SmyJxAA3j8YvV3SJ7vWslGXyKufQbXFYZPnE6E+ FAL0WvbvfB7c/qaKFpS8CkELkNgzQadiaCK/aZrkSRV3JH+bE6e23hxLQ VWALpMPPxOxBD2FFeyh3CrrIl2CDguOJslEMKLeCViiL/ATPPYtdGo2jE 0=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AokFAIg0qFOtJA2G/2dsb2JhbAA/FwODDVJaqjsBAQEBAQeRdYZtUwGBDRZ1hAMBAQEDAQEBATc0CwULAgEIGBgGBgonCyUCBA4FiDoIDTatWZgWEwSFY4V3AYJuIxAHEQeDFYEWBJpMk2ODQmyBAgQ+
X-IronPort-AV: E=Sophos;i="5.01,530,1400025600"; d="scan'208";a="55250801"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by alln-iport-8.cisco.com with ESMTP; 23 Jun 2014 14:10:04 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id s5NEA4pm009385 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 23 Jun 2014 14:10:04 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.82]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:10:03 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] agenda for 2014-06-23 6tisch security call
Thread-Index: AQHPjpI/kd8WGZdf10ut/aErZSztHZt/C5uAgAACTgCAAAJrgA==
Date: Mon, 23 Jun 2014 14:10:03 +0000
Message-ID: <2568FD82-9C40-40D1-86AF-73975FAF3C9B@cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca> <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com>
In-Reply-To: <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.82.217.146]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <5D69CDF0A6FB3E429FE93777BF4BD9E8@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/0eDkHKTJO0OxyuS9quhwFPvXY_c
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:10:06 -0000

https://ciscosales.webex.com/ciscosales/e.php?MTID=3Dmed0fe95ade4c1e13410b8=
7950c11c337

Dialin: (408) 525-6800
Meeting Number: 204 226 648   =09
Meeting Password: letmein=09

- max


On Jun 23, 2014, at 4:01 PM, Max Pritikin (pritikin) <pritikin@cisco.com> w=
rote:

> If necessary I could create a different webex as well?=20
> - max
>=20
> On Jun 23, 2014, at 3:53 PM, Michael Richardson <mcr+ietf@sandelman.ca> w=
rote:
>=20
>>=20
>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>> We had a very productive call last week.
>>=20
>>>> -- The URL to access the webex, which will we use for audio only:
>>>>=20
>>> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580=
b7908
>>=20
>> This says "meeting cancelled".
>> I assume it is an administrative oops, stay tuned for another URL, I gue=
ss.
>>=20
>> I have a bridge that can be used; accessible via SIP: and PSTN, but I wi=
ll
>> wait ten minutes before suggesting it.
>>=20
>> --
>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>> -=3D IPv6 IoT consulting =3D-
>>=20
>>=20
>>=20
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Mon Jun 23 07:13:05 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CBF4E1B2B29 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:13:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5CCTMImX3tg6 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:12:58 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E1D341B2B25 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:12:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1641; q=dns/txt; s=iport; t=1403532778; x=1404742378; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=lPuQf6qUjk+aHE9apjePqkx7paxqQoRzVsbxPQbLXWg=; b=jGStSJVOWr+SC3ej2FSLwZIXcq0CQuz7VLfvl4jijk0loAHUWrFS3+th LoNaj/t4YLZ3jjZ5oUKcFmHjmqqe4rfeJkn2c3siyotoKLQ/KfXmqCRCx efuUhl3NoyToIJFKwRbzIY4KKaZ6nWWUmJa4qtPzsr6d3gsXvFcUEUN6/ M=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AooFAAo1qFOtJV2P/2dsb2JhbAA/GoMNUlqqOwEBAQEBB5F1hm1TAYENFnWEAwEBAQQBAQE3NAsMBAIBCBEEAQEBChQJBycLFAkIAgQBDQUIiDoNNsVxEwSFY4V3AYJwMQcGgyeBFgSuL4NCbIECBD4
X-IronPort-AV: E=Sophos;i="5.01,530,1400025600"; d="scan'208";a="334997530"
Received: from rcdn-core-7.cisco.com ([173.37.93.143]) by rcdn-iport-7.cisco.com with ESMTP; 23 Jun 2014 14:12:57 +0000
Received: from xhc-rcd-x12.cisco.com (xhc-rcd-x12.cisco.com [173.37.183.86]) by rcdn-core-7.cisco.com (8.14.5/8.14.5) with ESMTP id s5NECvC3018541 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 23 Jun 2014 14:12:57 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.12]) by xhc-rcd-x12.cisco.com ([173.37.183.86]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:12:56 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "Max Pritikin (pritikin)" <pritikin@cisco.com>, Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] agenda for 2014-06-23 6tisch security call
Thread-Index: AQHPjpI/kd8WGZdf10ut/aErZSztHZt/C5uAgAACTgD//68LoA==
Date: Mon, 23 Jun 2014 14:12:56 +0000
Deferred-Delivery: Mon, 23 Jun 2014 14:12:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842C4D58A@xmb-rcd-x01.cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca> <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com>
In-Reply-To: <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/N2YhulcVcFdY8Y-qNttZTNURxRQ
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:13:03 -0000

Let me create a webex and come back to you all...

Cheers,

Pascal


> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf=
 Of
> Max Pritikin (pritikin)
> Sent: lundi 23 juin 2014 16:01
> To: Michael Richardson
> Cc: 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
>=20
> If necessary I could create a different webex as well?
> - max
>=20
> On Jun 23, 2014, at 3:53 PM, Michael Richardson <mcr+ietf@sandelman.ca>
> wrote:
>=20
> >
> > Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> >> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> >>> We had a very productive call last week.
> >
> >>> -- The URL to access the webex, which will we use for audio only:
> >>>
> >>
> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd580
> >> b7908
> >
> > This says "meeting cancelled".
> > I assume it is an administrative oops, stay tuned for another URL, I gu=
ess.
> >
> > I have a bridge that can be used; accessible via SIP: and PSTN, but I
> > will wait ten minutes before suggesting it.
> >
> > --
> > Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
> Works
> > -=3D IPv6 IoT consulting =3D-
> >
> >
> >
> > _______________________________________________
> > 6tisch-security mailing list
> > 6tisch-security@ietf.org
> > https://www.ietf.org/mailman/listinfo/6tisch-security
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Mon Jun 23 07:18:13 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1F441B2AF5 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:18:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.85
X-Spam-Level: 
X-Spam-Status: No, score=-4.85 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RMy18mSWRhQ0 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:18:09 -0700 (PDT)
Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5492C1B2964 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:18:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=18227; q=dns/txt; s=iport; t=1403533089; x=1404742689; h=from:to:subject:sender:date:message-id:mime-version; bh=H5V8pMUldwUeAu+wNR5v27lBl3bwNIWxTlMPwWvU7lw=; b=ENabjcjv6Vz2OH9PaJRsA+H7PWLt2RlmJ9ZxvRl+G00AWEjOkoa/RxWJ qvrUyIIye8tD7hEIYwTVc9APAnlAev6CJ+Wq/921JKMqI9DXH+MT+RCSt 878x2NiI2xjnUuNtIN4toVy5QqdsbsXuQ5V8Jt2Rz481pZkvQnvLDkl/3 o=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AncFAHU2qFOtJA2N/2dsb2JhbAA/FwOCRkdSWoJtwQ8BGXQWdYQDAQEBBCMKGw0RJAEBCBEDAQEBCwoBAwwDAwIEMBQHAQEFAgIBAQMTCIg6DTaYb48jhU0RmAUXjjgzDQoLBweCXzaBFgSEY3yLJ4sLkh6CbVVsgQs5eg
X-IronPort-AV: E=Sophos; i="5.01,530,1400025600"; d="scan'208,217"; a="55250473"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-5.cisco.com with ESMTP; 23 Jun 2014 14:18:08 +0000
Received: from xhc-rcd-x13.cisco.com (xhc-rcd-x13.cisco.com [173.37.183.87]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id s5NEI824016826 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 14:18:08 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.12]) by xhc-rcd-x13.cisco.com ([173.37.183.87]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:18:08 -0500
From: webex <messenger@webex.com>
To: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: Meeting scheduled: 6TiSCH security
Thread-Index: Ac+O7a9h4ssVZlIkRoeeznzFC7gKawAACBjA
Sender: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Date: Mon, 23 Jun 2014 14:18:07 +0000
Deferred-Delivery: Mon, 23 Jun 2014 14:18:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842C4D744@xmb-rcd-x01.cisco.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: multipart/alternative; boundary="_000_E045AECD98228444A58C61C200AE1BD842C4D744xmbrcdx01ciscoc_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/vca7SRU6b9dzOarq26wmQ5n3dxY
Subject: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:18:11 -0000

--_000_E045AECD98228444A58C61C200AE1BD842C4D744xmbrcdx01ciscoc_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable



-----Original Appointment-----
From: webex [mailto:messenger@webex.com]
Sent: lundi 23 juin 2014 16:16
To: webex; Pascal Thubert (pthubert)
Subject: Meeting scheduled: 6TiSCH security
When: Occurs every lundi effective 23/06/2014 until 20/06/2016 from 16:00 t=
o 17:00 (UTC+01:00) Amsterdam, Berlin, Berne, Rome, Stockholm, Vienne.
Where: https://cisco.webex.com/cisco


You are the host for this online meeting.
Topic:  6TiSCH security
Date:   Every Monday, from Monday 23 June 2014 to Monday 20 June 2016
Time:   16:00, Europe Summer Time (Paris, GMT+02:00)
Meeting Number: 202 347 993
Meeting Password:       6Sec
Host Key:       809956 (use this to reclaim host privileges)



To start the online meeting

  1.    Go to https://cisco.webex.com/cisco/j.php?MTID=3Dmf0899e407e9726ee6=
daee7032b007578
  2.    Log in to your account.
  3.    Click =93Start Now=94.
  4.    Follow the instructions that appear on your screen.



ALERT =96 PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (4=
08) OR (919) AREA CODES

Please dial the local access number for your area from the list below:
=95       San Jose/Milpitas (408) area:  525-6800
=95       RTP (919) area:  392-3330

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  =93 If you dial the toll-free numbers within=
 the 408 or 919 area codes you will be instructed to hang up and dial the l=
ocal access number.=94 Please use the call-back option whenever possible an=
d otherwise dial local numbers only.  The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.

-------------------------------------------------------

To join the teleconference only
-------------------------------------------------------

1.      Dial into Cisco WebEx (view all Global Access Numbers at

http://cisco.com/en/US/about/doing_business/conferencing/index.html <http:/=
/cisco.com/en/US/about/doing_business/conferencing/index.html%202>
2.      Follow the prompts to enter the Meeting Number (listed above) or Ac=
cess Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666



For assistance

  1.    Go to https://cisco.webex.com/cisco/mc
  2.    On the left navigation bar, click =93Support=94.
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm30763e6b62a4467891f27c5cac79492=
5
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x202347993#



--_000_E045AECD98228444A58C61C200AE1BD842C4D744xmbrcdx01ciscoc_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
 #800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Calibri" size=3D"2"><span style=3D"font-size:11pt;">
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div><font color=3D"#1F497D">&nbsp;</font></div>
<div style=3D"margin-bottom:6pt;">-----Original Appointment-----<br>

<b>From:</b> webex [<a href=3D"mailto:messenger@webex.com"><font face=3D"Ta=
homa" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>mailto:m=
essenger@webex.com</u></span></font></a>]
<br>

<b>Sent:</b> lundi 23 juin 2014 16:16<br>

<b>To:</b> webex; Pascal Thubert (pthubert)<br>

<b>Subject:</b> Meeting scheduled: 6TiSCH security<br>

<b>When:</b> Occurs every lundi effective 23/06/2014 until 20/06/2016 from =
16:00 to 17:00 (UTC&#43;01:00) Amsterdam, Berlin, Berne, Rome, Stockholm, V=
ienne.<br>

<b>Where:</b> <a href=3D"https://cisco.webex.com/cisco"><font face=3D"Tahom=
a" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cis=
co.webex.com/cisco</u></span></font></a></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">You are the host for this online meeting.=
</div>
<div>Topic:&nbsp; 6TiSCH security</div>
<div>Date:&nbsp;&nbsp; Every Monday, from Monday 23 June 2014 to Monday 20 =
June 2016</div>
<div>Time:&nbsp;&nbsp; 16:00, Europe Summer Time (Paris, GMT&#43;02:00)</di=
v>
<div>Meeting Number: 202 347 993</div>
<div>Meeting Password:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6Sec</div>
<div>Host Key:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 809956 (use this to recl=
aim host privileges)</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To start the online meeting</b>=
</span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/j.php?MTID=
=3Dmf0899e407e9726ee6daee7032b007578"><font face=3D"Arial" size=3D"2" color=
=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webex.com/cisco/=
j.php?MTID=3Dmf0899e407e9726ee6daee7032b007578</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Log in to your account.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">3.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Click <font color=3D"#1F497D">=93</font>Start Now<font colo=
r=3D"#1F497D">=94</font>.</div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">4.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Follow the instructions that appear on your screen.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>ALERT =96 PLEASE READ: DO NOT D=
IAL THE TOLL FREE NUMBERS FROM WITHIN THE (408) OR (919) AREA CODES</b></sp=
an></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Please dial the local access number for y=
our area from the list below:</div>
<ul style=3D"margin:0;padding-left:18pt;">
<li>San Jose/Milpitas (408) area:&nbsp; 525-6800</li><li>RTP (919) area:&nb=
sp; 392-3330</li></ul>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-bottom:6pt;">Dialing the WebEx toll free numbers from =
within 408 or 919 area codes is not enabled (non-Cisco phones).&nbsp; =93 I=
f you dial the toll-free numbers within the 408 or 919 area codes you will =
be instructed to hang up and dial the local
access number.=94 Please use the call-back option whenever possible and oth=
erwise dial local numbers only.&nbsp; The affected toll free numbers are: (=
866) 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP=
 area.</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>To join the teleconference only=
 </b></span></font></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">------=
------------------------------------------------- </span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><b>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; </b><b>Dial into Cisco WebEx (view all Global Access Numbers at </b></spa=
n></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Cambria" size=3D"3" color=3D"=
#4F81BD"><span style=3D"font-size:13pt;"><a href=3D"http://cisco.com/en/US/=
about/doing_business/conferencing/index.html 2"><font color=3D"blue"><b><u>=
http://cisco.com/en/US/about/doing_business/conferencing/index.html
</u></b></font></a></span></font></div>
<div style=3D"margin-top:10pt;"><font face=3D"Arial" size=3D"2" color=3D"bl=
ue"><span style=3D"font-size:10pt;"><b><u>2</u></b><font color=3D"#4F81BD">=
<b>.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b></font><font color=3D"#4F81BD"><b>Fo=
llow the prompts to enter the Meeting Number (listed above) or Access Code
followed by the # sign. </b></font></span></font></div>
<div>&nbsp;</div>
<div style=3D"margin-bottom:6pt;">San Jose, CA: &#43;1.408.525.6800&nbsp; R=
TP: &#43;1.919.392.3330 </div>
<div style=3D"margin-bottom:6pt;">US/Canada: &#43;1.866.432.9903&nbsp; Unit=
ed Kingdom: &#43;44.20.8824.0117 </div>
<div style=3D"margin-bottom:6pt;">India: &#43;91.80.4350.1111&nbsp; Germany=
: &#43;49.619.6773.9002 </div>
<div style=3D"margin-bottom:6pt;">Japan: &#43;81.3.5763.9394&nbsp; China: &=
#43;86.10.8515.5666</div>
<div>&nbsp;</div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"margin-top:24pt;"><font face=3D"Cambria" size=3D"4" color=3D"=
#365F91"><span style=3D"font-size:14pt;"><b>For assistance</b></span></font=
></div>
<div><font face=3D"Arial" size=3D"2"><span style=3D"font-size:10pt;">&nbsp;=
</span></font></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">1.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; Go to <a href=3D"https://cisco.webex.com/cisco/mc"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttps://cisco.webex.com/cisco/mc</u></span></font></a></div>
<div style=3D"text-indent:-14.15pt;padding-left:14.15pt;">2.&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; On the left navigation bar, click <font color=3D"#1F497D">=
=93</font>Support<font color=3D"#1F497D">=94</font>.</div>
<div style=3D"margin-bottom:6pt;">To add this meeting to your calendar prog=
ram (for example Microsoft Outlook), click this link:</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"https://cisco.webex.com/cisco/=
j.php?MTID=3Dm30763e6b62a4467891f27c5cac794925"><font face=3D"Arial" size=
=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>https://cisco.webe=
x.com/cisco/j.php?MTID=3Dm30763e6b62a4467891f27c5cac794925</u></span></font=
></a></div>
<div style=3D"margin-bottom:6pt;">To check whether you have the appropriate=
 players installed for UCF (Universal Communications Format) rich media fil=
es, go to <a href=3D"https://cisco.webex.com/cisco/systemdiagnosis.php"><fo=
nt face=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"=
><u>https://cisco.webex.com/cisco/systemdiagnosis.php</u></span></font></a>=
.</div>
<div style=3D"margin-bottom:6pt;"><a href=3D"http://www.webex.com"><font fa=
ce=3D"Arial" size=3D"2" color=3D"blue"><span style=3D"font-size:10pt;"><u>h=
ttp://www.webex.com</u></span></font></a></div>
<div style=3D"margin-bottom:6pt;">CCM:&#43;14085256800x202347993# </div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>

--_000_E045AECD98228444A58C61C200AE1BD842C4D744xmbrcdx01ciscoc_
Content-Type: text/calendar; charset="utf-8"; method=REQUEST
Content-Transfer-Encoding: base64

QkVHSU46VkNBTEVOREFSDQpNRVRIT0Q6UkVRVUVTVA0KUFJPRElEOk1pY3Jvc29mdCBFeGNoYW5n
ZSBTZXJ2ZXIgMjAxMA0KVkVSU0lPTjoyLjANCkJFR0lOOlZUSU1FWk9ORQ0KVFpJRDpFdXJvcGUg
VGltZQ0KQkVHSU46U1RBTkRBUkQNCkRUU1RBUlQ6MTYwMTAxMDFUMDMwMDAwDQpUWk9GRlNFVEZS
T006KzAyMDANClRaT0ZGU0VUVE86KzAxMDANClJSVUxFOkZSRVE9WUVBUkxZO0lOVEVSVkFMPTE7
QllEQVk9LTFTVTtCWU1PTlRIPTEwDQpFTkQ6U1RBTkRBUkQNCkJFR0lOOkRBWUxJR0hUDQpEVFNU
QVJUOjE2MDEwMTAxVDAyMDAwMA0KVFpPRkZTRVRGUk9NOiswMTAwDQpUWk9GRlNFVFRPOiswMjAw
DQpSUlVMRTpGUkVRPVlFQVJMWTtJTlRFUlZBTD0xO0JZREFZPS0xU1U7QllNT05USD0zDQpFTkQ6
REFZTElHSFQNCkVORDpWVElNRVpPTkUNCkJFR0lOOlZFVkVOVA0KT1JHQU5JWkVSO0NOPXdlYmV4
O1NFTlQtQlk9Ik1BSUxUTzpwdGh1YmVydEBjaXNjby5jb20iOk1BSUxUTzptZXNzZW5nZXJAd2Vi
ZXgNCiAuY29tDQpBVFRFTkRFRTtST0xFPVJFUS1QQVJUSUNJUEFOVDtQQVJUU1RBVD1ORUVEUy1B
Q1RJT047UlNWUD1GQUxTRTtDTj02dGlzY2gtc2UNCiBjdXJpdHlAaWV0Zi5vcmc6TUFJTFRPOjZ0
aXNjaC1zZWN1cml0eUBpZXRmLm9yZw0KREVTQ1JJUFRJT047TEFOR1VBR0U9ZW4tVVM6XG5cbi0t
LS0tT3JpZ2luYWwgQXBwb2ludG1lbnQtLS0tLVxuRnJvbTogd2ViZXggDQogW21haWx0bzptZXNz
ZW5nZXJAd2ViZXguY29tXVxuU2VudDogbHVuZGkgMjMganVpbiAyMDE0IDE2OjE2XG5Ubzogd2Vi
ZXhcOyANCiBQYXNjYWwgVGh1YmVydCAocHRodWJlcnQpXG5TdWJqZWN0OiBNZWV0aW5nIHNjaGVk
dWxlZDogNlRpU0NIIHNlY3VyaXR5XG5XaA0KIGVuOiBPY2N1cnMgZXZlcnkgbHVuZGkgZWZmZWN0
aXZlIDIzLzA2LzIwMTQgdW50aWwgMjAvMDYvMjAxNiBmcm9tIDE2OjAwIHRvDQogIDE3OjAwIChV
VEMrMDE6MDApIEFtc3RlcmRhbVwsIEJlcmxpblwsIEJlcm5lXCwgUm9tZVwsIFN0b2NraG9sbVws
IFZpZW5uZS4NCiBcbldoZXJlOiBodHRwczovL2Npc2NvLndlYmV4LmNvbS9jaXNjb1xuXG5cbllv
dSBhcmUgdGhlIGhvc3QgZm9yIHRoaXMgb25saQ0KIG5lIG1lZXRpbmcuXG5Ub3BpYzogIDZUaVND
SCBzZWN1cml0eVxuRGF0ZTogICBFdmVyeSBNb25kYXlcLCBmcm9tIE1vbmRheSAyDQogMyBKdW5l
IDIwMTQgdG8gTW9uZGF5IDIwIEp1bmUgMjAxNlxuVGltZTogICAxNjowMFwsIEV1cm9wZSBTdW1t
ZXIgVGltZSAoUGENCiByaXNcLCBHTVQrMDI6MDApXG5NZWV0aW5nIE51bWJlcjogMjAyIDM0NyA5
OTNcbk1lZXRpbmcgUGFzc3dvcmQ6ICAgICAgIDZTZQ0KIGNcbkhvc3QgS2V5OiAgICAgICA4MDk5
NTYgKHVzZSB0aGlzIHRvIHJlY2xhaW0gaG9zdCBwcml2aWxlZ2VzKVxuXG5cblxuVG8gDQogc3Rh
cnQgdGhlIG9ubGluZSBtZWV0aW5nXG5cbiAgMS4gICAgR28gdG8gaHR0cHM6Ly9jaXNjby53ZWJl
eC5jb20vY2lzY28vai4NCiBwaHA/TVRJRD1tZjA4OTllNDA3ZTk3MjZlZTZkYWVlNzAzMmIwMDc1
NzhcbiAgMi4gICAgTG9nIGluIHRvIHlvdXIgYWNjb3VudA0KIC5cbiAgMy4gICAgQ2xpY2sg4oCc
U3RhcnQgTm934oCdLlxuICA0LiAgICBGb2xsb3cgdGhlIGluc3RydWN0aW9ucyB0aGF0IGFwDQog
cGVhciBvbiB5b3VyIHNjcmVlbi5cblxuXG5cbkFMRVJUIOKAkyBQTEVBU0UgUkVBRDogRE8gTk9U
IERJQUwgVEhFIFRPTEwgRlINCiBFRSBOVU1CRVJTIEZST00gV0lUSElOIFRIRSAoNDA4KSBPUiAo
OTE5KSBBUkVBIENPREVTXG5cblBsZWFzZSBkaWFsIHRoZSBsbw0KIGNhbCBhY2Nlc3MgbnVtYmVy
IGZvciB5b3VyIGFyZWEgZnJvbSB0aGUgbGlzdCBiZWxvdzpcbuKAoiAgICAgICBTYW4gSm9zZS9N
DQogaWxwaXRhcyAoNDA4KSBhcmVhOiAgNTI1LTY4MDBcbuKAoiAgICAgICBSVFAgKDkxOSkgYXJl
YTogIDM5Mi0zMzMwXG5cbkRpYWwNCiBpbmcgdGhlIFdlYkV4IHRvbGwgZnJlZSBudW1iZXJzIGZy
b20gd2l0aGluIDQwOCBvciA5MTkgYXJlYSBjb2RlcyBpcyBub3QgZQ0KIG5hYmxlZCAobm9uLUNp
c2NvIHBob25lcykuICDigJwgSWYgeW91IGRpYWwgdGhlIHRvbGwtZnJlZSBudW1iZXJzIHdpdGhp
biB0DQogaGUgNDA4IG9yIDkxOSBhcmVhIGNvZGVzIHlvdSB3aWxsIGJlIGluc3RydWN0ZWQgdG8g
aGFuZyB1cCBhbmQgZGlhbCB0aGUgbG8NCiBjYWwgYWNjZXNzIG51bWJlci7igJ0gUGxlYXNlIHVz
ZSB0aGUgY2FsbC1iYWNrIG9wdGlvbiB3aGVuZXZlciBwb3NzaWJsZSBhbg0KIGQgb3RoZXJ3aXNl
IGRpYWwgbG9jYWwgbnVtYmVycyBvbmx5LiAgVGhlIGFmZmVjdGVkIHRvbGwgZnJlZSBudW1iZXJz
IGFyZTogDQogKDg2NikgNDMyLTk5MDMgZm9yIHRoZSBTYW4gSm9zZS9NaWxwaXRhcyBhcmVhIGFu
ZCAoODY2KSAzNDktMzUyMCBmb3IgdGhlIFINCiBUUCBhcmVhLlxuXG4tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tXG5cblRvIA0KIGpvaW4gdGhl
IHRlbGVjb25mZXJlbmNlIG9ubHlcbi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tDQogLS0tLS0tLS0tLS1cblxuMS4gICAgICBEaWFsIGludG8gQ2lzY28gV2ViRXgg
KHZpZXcgYWxsIEdsb2JhbCBBY2Nlc3MgTnVtYmUNCiBycyBhdFxuXG5odHRwOi8vY2lzY28uY29t
L2VuL1VTL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2luZy9pbmRleC5odA0KIG1sIDxo
dHRwOi8vY2lzY28uY29tL2VuL1VTL2Fib3V0L2RvaW5nX2J1c2luZXNzL2NvbmZlcmVuY2luZy9p
bmRleC5odG1sJTIwDQogMj5cbjIuICAgICAgRm9sbG93IHRoZSBwcm9tcHRzIHRvIGVudGVyIHRo
ZSBNZWV0aW5nIE51bWJlciAobGlzdGVkIGFib3ZlKSANCiBvciBBY2Nlc3MgQ29kZSBmb2xsb3dl
ZCBieSB0aGUgIyBzaWduLlxuXG5TYW4gSm9zZVwsIENBOiArMS40MDguNTI1LjY4MDAgIA0KIFJU
UDogKzEuOTE5LjM5Mi4zMzMwXG5VUy9DYW5hZGE6ICsxLjg2Ni40MzIuOTkwMyAgVW5pdGVkIEtp
bmdkb206ICs0NC4yMC44DQogODI0LjAxMTdcbkluZGlhOiArOTEuODAuNDM1MC4xMTExICBHZXJt
YW55OiArNDkuNjE5LjY3NzMuOTAwMlxuSmFwYW46ICs4MS4NCiAzLjU3NjMuOTM5NCAgQ2hpbmE6
ICs4Ni4xMC44NTE1LjU2NjZcblxuXG5cbkZvciBhc3Npc3RhbmNlXG5cbiAgMS4gICAgR28gdA0K
IG8gaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28vbWNcbiAgMi4gICAgT24gdGhlIGxlZnQg
bmF2aWdhdGlvbiBiYXJcLCBjDQogbGljayDigJxTdXBwb3J04oCdLlxuVG8gYWRkIHRoaXMgbWVl
dGluZyB0byB5b3VyIGNhbGVuZGFyIHByb2dyYW0gKGZvciBleGENCiBtcGxlIE1pY3Jvc29mdCBP
dXRsb29rKVwsIGNsaWNrIHRoaXMgbGluazpcbmh0dHBzOi8vY2lzY28ud2ViZXguY29tL2Npc2Nv
Lw0KIGoucGhwP01USUQ9bTMwNzYzZTZiNjJhNDQ2Nzg5MWYyN2M1Y2FjNzk0OTI1XG5UbyBjaGVj
ayB3aGV0aGVyIHlvdSBoYXZlIHRoDQogZSBhcHByb3ByaWF0ZSBwbGF5ZXJzIGluc3RhbGxlZCBm
b3IgVUNGIChVbml2ZXJzYWwgQ29tbXVuaWNhdGlvbnMgRm9ybWF0KSANCiByaWNoIG1lZGlhIGZp
bGVzXCwgZ28gdG8gaHR0cHM6Ly9jaXNjby53ZWJleC5jb20vY2lzY28vc3lzdGVtZGlhZ25vc2lz
LnBocA0KIC5cbmh0dHA6Ly93d3cud2ViZXguY29tXG5DQ006KzE0MDg1MjU2ODAweDIwMjM0Nzk5
MyNcblxuXG4NClJSVUxFOkZSRVE9V0VFS0xZO1VOVElMPTIwMTYwNjIwVDE0MDAwMFo7SU5URVJW
QUw9MTtCWURBWT1NTztXS1NUPVNVDQpTVU1NQVJZO0xBTkdVQUdFPWVuLVVTOkZXOiBNZWV0aW5n
IHNjaGVkdWxlZDogNlRpU0NIIHNlY3VyaXR5DQpEVFNUQVJUO1RaSUQ9RXVyb3BlIFRpbWU6MjAx
NDA2MjNUMTYwMDAwDQpEVEVORDtUWklEPUV1cm9wZSBUaW1lOjIwMTQwNjIzVDE3MDAwMA0KVUlE
OldFQkVYLU1FRVRJTkcgQ0VOVEVSLTYuMDMwMzc5MC0yNzMwNTQ1MTItU1U9Y2lzY28tSE49cHRo
dWJlcnQNCkNMQVNTOlBVQkxJQw0KUFJJT1JJVFk6NQ0KRFRTVEFNUDoyMDE0MDYyM1QxNDAwMDBa
DQpUUkFOU1A6T1BBUVVFDQpTVEFUVVM6Q09ORklSTUVEDQpTRVFVRU5DRToxDQpMT0NBVElPTjtM
QU5HVUFHRT1lbi1VUzpodHRwczovL2Npc2NvLndlYmV4LmNvbS9jaXNjbw0KWC1NSUNST1NPRlQt
Q0RPLUFQUFQtU0VRVUVOQ0U6MQ0KWC1NSUNST1NPRlQtQ0RPLU9XTkVSQVBQVElEOi0xDQpYLU1J
Q1JPU09GVC1DRE8tQlVTWVNUQVRVUzpURU5UQVRJVkUNClgtTUlDUk9TT0ZULUNETy1JTlRFTkRF
RFNUQVRVUzpCVVNZDQpYLU1JQ1JPU09GVC1DRE8tQUxMREFZRVZFTlQ6RkFMU0UNClgtTUlDUk9T
T0ZULUNETy1JTVBPUlRBTkNFOjENClgtTUlDUk9TT0ZULUNETy1JTlNUVFlQRToxDQpYLU1JQ1JP
U09GVC1ESVNBTExPVy1DT1VOVEVSOkZBTFNFDQpCRUdJTjpWQUxBUk0NCkFDVElPTjpESVNQTEFZ
DQpERVNDUklQVElPTjpSRU1JTkRFUg0KVFJJR0dFUjtSRUxBVEVEPVNUQVJUOi1QVDE1TQ0KRU5E
OlZBTEFSTQ0KRU5EOlZFVkVOVA0KRU5EOlZDQUxFTkRBUg0K

--_000_E045AECD98228444A58C61C200AE1BD842C4D744xmbrcdx01ciscoc_--


From nobody Mon Jun 23 07:21:37 2014
Return-Path: <pritikin@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7AD751B2961 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:21:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.152
X-Spam-Level: 
X-Spam-Status: No, score=-15.152 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tNep-kYM-tWL for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:21:34 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A56C21B2AF8 for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:21:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1878; q=dns/txt; s=iport; t=1403533295; x=1404742895; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=HlO+pkXHkc3HCmMou7AoYKko9LjNeNyPhrxdfyx+gE8=; b=E5zUahRspbquHTFC6FdSb9/Vz1hXXWeg4695w/p72DPRYxgSMJpZ0c/J yVB1jaOIfN3n/SRARLiWnCG7PspiNnAYOuJbV6lqfsWN0C07x750wPmph MFDCw8QYI7WbSlojeTrBVa26Fm5LGk030+Ln8adn5WN9gML5uUjcGbSCx Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AogFAOI2qFOtJA2J/2dsb2JhbAA/FwODDVJaqjsBAQEBAQeRdYZtUwGBDRZ1hAMBAQEDAQEBAWsLEAIBCBgYDAonCyUCBA4FiDoIDTatYJgWEwSFY4V3AYJuIxAHEQeDFYEWBJpMk2ODQmyBAgQ+
X-IronPort-AV: E=Sophos;i="5.01,530,1400025600"; d="scan'208";a="55253972"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by alln-iport-4.cisco.com with ESMTP; 23 Jun 2014 14:21:34 +0000
Received: from xhc-rcd-x04.cisco.com (xhc-rcd-x04.cisco.com [173.37.183.78]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s5NELXSL018310 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 23 Jun 2014 14:21:33 GMT
Received: from xmb-rcd-x03.cisco.com ([169.254.7.82]) by xhc-rcd-x04.cisco.com ([fe80::200:5efe:173.37.183.34%12]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:21:33 -0500
From: "Max Pritikin (pritikin)" <pritikin@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] agenda for 2014-06-23 6tisch security call
Thread-Index: AQHPjpI/kd8WGZdf10ut/aErZSztHZt/C5uAgAACTgCAAAJrgIAAAzaA
Date: Mon, 23 Jun 2014 14:21:32 +0000
Message-ID: <D1A160F1-0ACE-4E88-8D49-9B09706D803B@cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca> <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com> <2568FD82-9C40-40D1-86AF-73975FAF3C9B@cisco.com>
In-Reply-To: <2568FD82-9C40-40D1-86AF-73975FAF3C9B@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.82.217.146]
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <ADA89946C315864997BCD77C9333A45F@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Oy1Jalzgt4v-g5jBFcHSS3Fk5do
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:21:36 -0000

Thanks to the 4 people that joined this webex. Unfortunately we didn=92t ac=
hieve quorum and everybody dropped. Hopefully a reschedule discussion will =
occur now,=20

- max

On Jun 23, 2014, at 4:10 PM, Max Pritikin (pritikin) <pritikin@cisco.com> w=
rote:

>=20
> https://ciscosales.webex.com/ciscosales/e.php?MTID=3Dmed0fe95ade4c1e13410=
b87950c11c337
>=20
> Dialin: (408) 525-6800
> Meeting Number: 204 226 648   =09
> Meeting Password: letmein=09
>=20
> - max
>=20
>=20
> On Jun 23, 2014, at 4:01 PM, Max Pritikin (pritikin) <pritikin@cisco.com>=
 wrote:
>=20
>> If necessary I could create a different webex as well?=20
>> - max
>>=20
>> On Jun 23, 2014, at 3:53 PM, Michael Richardson <mcr+ietf@sandelman.ca> =
wrote:
>>=20
>>>=20
>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>>> We had a very productive call last week.
>>>=20
>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>=20
>>>> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd58=
0b7908
>>>=20
>>> This says "meeting cancelled".
>>> I assume it is an administrative oops, stay tuned for another URL, I gu=
ess.
>>>=20
>>> I have a bridge that can be used; accessible via SIP: and PSTN, but I w=
ill
>>> wait ten minutes before suggesting it.
>>>=20
>>> --
>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>>> -=3D IPv6 IoT consulting =3D-
>>>=20
>>>=20
>>>=20
>>> _______________________________________________
>>> 6tisch-security mailing list
>>> 6tisch-security@ietf.org
>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>=20
>> _______________________________________________
>> 6tisch-security mailing list
>> 6tisch-security@ietf.org
>> https://www.ietf.org/mailman/listinfo/6tisch-security
>=20


From nobody Mon Jun 23 07:24:42 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C88E1B296B for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:24:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.742
X-Spam-Level: 
X-Spam-Status: No, score=-0.742 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MISSING_SUBJECT=1.799, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01, WEIRD_PORT=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O7lYtGYHRrcK for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:24:39 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4825D1B296A for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:24:39 -0700 (PDT)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 449A92002A for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 10:28:54 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 0DD3F63B0E; Mon, 23 Jun 2014 10:24:37 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id F34D363AED for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 10:24:37 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
subbject: RESCHEDULED agenda for 2014-06-24 6tisch security call
In-Reply-To: <25450.1403493683@sandelman.ca>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 23 Jun 2014 10:24:37 -0400
Message-ID: <4589.1403533477@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/S5_ARCy9OUAhGbIcM3as6WmhU8Y
Subject: [6tisch-security] (no subject)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:24:40 -0000

--=-=-=


The webex was screwed up. Thanks for Max for attempting to rescue.
(And then the Bell guy came to hook up my 50Mb/s VDSL2... it's make before
break, but...)

So can we try again for June 24 10am?
Pascal, can you post a fresh webex URL?

We will attempt to use the IETF etherpad again:
  http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security

Last time we dealt with the question:
    > Agenda for tomorrow:
    > 1. work on trust/cryptographic details of Joining-Node -> PCE message.
    > does it need to be signed?

which I summarized in the email at:
      https://mailarchive.ietf.org/arch/msg/6tisch-security/DT-K0_qd_wd-GmqB4YVqQtbhC6Q
or:   with the thread at:
      http://www.ietf.org/mail-archive/web/6tisch-security/current/msg00175.html

    > 2. 6top ideas for PCE->joining node protocol. Will this work as stock
    > CoAP/DTLS, or do we need a proxy to help us?

I would like to focus on item #2.
This is about whether or not the joining node can layer-3 address the PCE,
and whether or not the PCE can address the joining node directly, or if it
needs help from the proxy, and if so, what form does the help take?

We have had part of this discussion before.

I propose that we have no call on 2014-06-30, the draft deadline is July 4,
and we need to get some things in.

I will remind that we worked on a table of contents, posted as:
   http://datatracker.ietf.org/doc/draft-richardson-6tisch-table-of-contents/

a very rough version of a document explaining the "Wireless-HART"/6top method
of doing joining is at:
  https://bitbucket.org/6tisch/draft-richardson-6tisch-security-architecture/src/625fefe5574fe3e4ca3de7b3c14c2c1dcf073ebd/draft-richardson-6tisch-security-6top.xml?at=obiwan

we still need someone to fill in a table of contents from the EAP-TLS point
of view.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU6g4pYCLcPvd0N1lAQKxnQf/cKO9ARa4AJv4V8Xn65At0RRa3IDFELy2
fCXJJjfWjZIFlAm6DoNUNzdvyYhgVrouR9aw4MjT2FqeQqmgvpqTfP0x3ontsYxa
cMeHZ+fuxI2yVqdDAvmAsgXapwIN2bOsICIV3Q+po9Cux2PpNpbUmyZdei0fjrUS
08PexuQxZAwwONO36WKthKmrNPC8noDVoyIwaUM40Q0AyvK/PA6ZbtZGie0PjVB/
Dk1wH98CdPUMrnbfUmgyhI9V1d4xyKk2QiMb+sGa0BwNFOTBrAkWQwxg6Bg9ExuC
B6+pL78BTG6tQAgiAb3IVQgsA8WHz3thaNc0t9JPrgRrS8IgiAAzSw==
=n6VE
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 23 07:31:29 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB7321B29B6 for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:31:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, WEIRD_PORT=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PuTystmoJTjr for <6tisch-security@ietfa.amsl.com>; Mon, 23 Jun 2014 07:31:17 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6B1261B296A for <6tisch-security@ietf.org>; Mon, 23 Jun 2014 07:31:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=4862; q=dns/txt; s=iport; t=1403533878; x=1404743478; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=mORv7IqCwnAQ6Acd/64nYj/lxwDsUPZYEDmd6ZVrI1o=; b=P3JLItaPoLsOJNBCfyY/Lfov7nwGKlaMAmLc/L+wrYoMe2Edmcu8hwRu t+xcrPMbPa0GZxK6PGRJu39yQaOaitgPrfFLYutINJtfbXAf+n9qkv+Yu A6epBsOI6daaw7XiIu2u6j0kTKRr1HevNO4QcIYqCVGz2lNQE6tzAkkND E=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AogFADo5qFOtJA2J/2dsb2JhbAA/FwODDVJaqjsBAQEBAQeZNQGBDRZ1hAMBAQEEJxMODREfBAIBCBEBAgEBAQsKAQMGBgMHMhQDBgcBAgEDARIIAYg5DTataBGYCBeFY4V3AYI/EAIBCxMhEgUGBAcHgxWBFgSFX5Yykh6CbVVsgQs5eg
X-IronPort-AV: E=Sophos;i="5.01,530,1400025600"; d="scan'208";a="335048185"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by rcdn-iport-8.cisco.com with ESMTP; 23 Jun 2014 14:31:16 +0000
Received: from xhc-rcd-x01.cisco.com (xhc-rcd-x01.cisco.com [173.37.183.75]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id s5NEVFLu024596 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 23 Jun 2014 14:31:15 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.12]) by xhc-rcd-x01.cisco.com ([173.37.183.75]) with mapi id 14.03.0123.003; Mon, 23 Jun 2014 09:31:14 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] (no subject)
Thread-Index: AQHPju7jm7wM2RX080KGKLSWjQ/uV5t+wSsg
Date: Mon, 23 Jun 2014 14:31:15 +0000
Deferred-Delivery: Mon, 23 Jun 2014 14:31:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842C4D8E5@xmb-rcd-x01.cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <4589.1403533477@sandelman.ca>
In-Reply-To: <4589.1403533477@sandelman.ca>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/qqaMREt76SnVpLLAvNXHWM7HhGQ
Subject: Re: [6tisch-security] (no subject)
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jun 2014 14:31:22 -0000

Hello Michael:

I sent an invite. If you did not get it the new webex is as follows:

You are scheduled to host this online meeting.=20

Topic: 6TiSCH security=20
Date: Monday, June 23, 2014=20
Time: 4:00 pm, Europe Summer Time (Paris, GMT+02:00)=20
Meeting Number: 202 347 993=20
Meeting Password: 6Sec=20

-------------------------------------------------------=20
To start the online meeting=20
-------------------------------------------------------=20
1. Go to https://ciscosales.webex.com/ciscosales/j.php?MTID=3Dm51f750a5bb1d=
5806cce3bf7c068e5790=20
2. Log in to your account.=20
3. Click "Start Now".=20
4. Follow the instructions that appear on your screen.=20

----------------------------------------------------------------=20
ALERT - PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (408=
) OR (919) AREA CODES=20
----------------------------------------------------------------=20
Please dial the local access number for your area from the list below:=20
- San Jose/Milpitas (408) area: 525-6800=20
- RTP (919) area: 392-3330=20

Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones). " If you dial the toll-free numbers within th=
e 408 or 919 area codes you will be instructed to hang up and dial the loca=
l access number." Please use the call-back option whenever possible and oth=
erwise dial local numbers only. The affected toll free numbers are: (866) 4=
32-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP area.=
=20

-------------------------------------------------------=20
To join the teleconference only=20
-------------------------------------------------------=20
1. Dial into Cisco WebEx (view all Global Access Numbers at=20
http://cisco.com/en/US/about/doing_business/conferencing/index.html=20
2. Follow the prompts to enter the Meeting Number (listed above) or Access =
Code followed by the # sign.=20

San Jose, CA: +1.408.525.6800 RTP: +1.919.392.3330=20

US/Canada: +1.866.432.9903 United Kingdom: +44.20.8824.0117=20

India: +91.80.4350.1111 Germany: +49.619.6773.9002=20

Japan: +81.3.5763.9394 China: +86.10.8515.5666=20

To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://ciscosales.webex=
.com/ciscosales/systemdiagnosis.php=20

http://www.webex.com=20

CCM:+14085256800x202347993#

Cheers,

Pascal


> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf=
 Of
> Michael Richardson
> Sent: lundi 23 juin 2014 16:25
> To: 6tisch-security@ietf.org
> Subject: [6tisch-security] (no subject)
>=20
>=20
> The webex was screwed up. Thanks for Max for attempting to rescue.
> (And then the Bell guy came to hook up my 50Mb/s VDSL2... it's make befor=
e
> break, but...)
>=20
> So can we try again for June 24 10am?
> Pascal, can you post a fresh webex URL?
>=20
> We will attempt to use the IETF etherpad again:
>   http://etherpad.tools.ietf.org:9000/p/notes-ietf-89-6tisch-security
>=20
> Last time we dealt with the question:
>     > Agenda for tomorrow:
>     > 1. work on trust/cryptographic details of Joining-Node -> PCE messa=
ge.
>     > does it need to be signed?
>=20
> which I summarized in the email at:
>       https://mailarchive.ietf.org/arch/msg/6tisch-security/DT-K0_qd_wd-
> GmqB4YVqQtbhC6Q
> or:   with the thread at:
>       http://www.ietf.org/mail-archive/web/6tisch-
> security/current/msg00175.html
>=20
>     > 2. 6top ideas for PCE->joining node protocol. Will this work as sto=
ck
>     > CoAP/DTLS, or do we need a proxy to help us?
>=20
> I would like to focus on item #2.
> This is about whether or not the joining node can layer-3 address the PCE=
,
> and whether or not the PCE can address the joining node directly, or if i=
t
> needs help from the proxy, and if so, what form does the help take?
>=20
> We have had part of this discussion before.
>=20
> I propose that we have no call on 2014-06-30, the draft deadline is July =
4,
> and we need to get some things in.
>=20
> I will remind that we worked on a table of contents, posted as:
>    http://datatracker.ietf.org/doc/draft-richardson-6tisch-table-of-conte=
nts/
>=20
> a very rough version of a document explaining the "Wireless-HART"/6top
> method of doing joining is at:
>   https://bitbucket.org/6tisch/draft-richardson-6tisch-security-
> architecture/src/625fefe5574fe3e4ca3de7b3c14c2c1dcf073ebd/draft-
> richardson-6tisch-security-6top.xml?at=3Dobiwan
>=20
> we still need someone to fill in a table of contents from the EAP-TLS poi=
nt of
> view.
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20


From nobody Tue Jun 24 07:08:10 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 924E71B29D1 for <6tisch-security@ietfa.amsl.com>; Tue, 24 Jun 2014 07:08:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oE62aNMD5uiZ for <6tisch-security@ietfa.amsl.com>; Tue, 24 Jun 2014 07:08:04 -0700 (PDT)
Received: from mail-ie0-x22e.google.com (mail-ie0-x22e.google.com [IPv6:2607:f8b0:4001:c03::22e]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 327D11B2A39 for <6tisch-security@ietf.org>; Tue, 24 Jun 2014 07:07:49 -0700 (PDT)
Received: by mail-ie0-f174.google.com with SMTP id lx4so289388iec.33 for <6tisch-security@ietf.org>; Tue, 24 Jun 2014 07:07:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=Djf9xduYFiDED3S31yVQsIKc6QyplQv1Kc42bF8fMjs=; b=ZH1hQqAPLDBqUzKQeomqSVvSI2sbi6wRvDY9Jlj6qmuzWGQRP4TvuKSC3ENafaJnJ3 oVi3VIaHwwsROSXytsJd4nn+slWcjd2/JiiV7IIxaIqyCGOk0hR3XkeYsG99V7HOgFIz w45TkhrEu41HbYUzPZoyqiO+XANzykOrQY6uEscEgJr7Tw9pm1CapNHefpCWpqhRb+aW GTANLBwiqNrHXK3w1epDam2TA5CNw0uc2MOGCqHVAdAgkbUvDD6GrmeKixTDCjG7eek5 BDi/k2f5OaYGGmET6SDSTR1JbcluOvNR4D7T4AqIh2g93vmEbv2gCYywv6t3nqgYyCCk LTWA==
X-Received: by 10.42.72.198 with SMTP id p6mr1168873icj.52.1403618868553; Tue, 24 Jun 2014 07:07:48 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id 2sm1896716igs.17.2014.06.24.07.07.47 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 24 Jun 2014 07:07:48 -0700 (PDT)
Message-ID: <53A9862F.6060905@gmail.com>
Date: Tue, 24 Jun 2014 10:07:43 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "Max Pritikin (pritikin)" <pritikin@cisco.com>,  Michael Richardson <mcr+ietf@sandelman.ca>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca> <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com> <2568FD82-9C40-40D1-86AF-73975FAF3C9B@cisco.com> <D1A160F1-0ACE-4E88-8D49-9B09706D803B@cisco.com>
In-Reply-To: <D1A160F1-0ACE-4E88-8D49-9B09706D803B@cisco.com>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VZl3jb_eq5bo2sW5kp1shXjp9dg
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Jun 2014 14:08:06 -0000

Dear colleagues:

I thought we had rescheduled the 6TiSCH security conf call to 10am EDT 
today, June 24, 2014, but did not see anyone online on Webex.

Best regards, Rene

On 6/23/2014 10:21 AM, Max Pritikin (pritikin) wrote:
> Thanks to the 4 people that joined this webex. Unfortunately we didn’t achieve quorum and everybody dropped. Hopefully a reschedule discussion will occur now,
>
> - max
>
> On Jun 23, 2014, at 4:10 PM, Max Pritikin (pritikin) <pritikin@cisco.com> wrote:
>
>> https://ciscosales.webex.com/ciscosales/e.php?MTID=med0fe95ade4c1e13410b87950c11c337
>>
>> Dialin: (408) 525-6800
>> Meeting Number: 204 226 648   	
>> Meeting Password: letmein	
>>
>> - max
>>
>>
>> On Jun 23, 2014, at 4:01 PM, Max Pritikin (pritikin) <pritikin@cisco.com> wrote:
>>
>>> If necessary I could create a different webex as well?
>>> - max
>>>
>>> On Jun 23, 2014, at 3:53 PM, Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>
>>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>>>>>> We had a very productive call last week.
>>>>>> -- The URL to access the webex, which will we use for audio only:
>>>>>>
>>>>> https://cisco.webex.com/cisco/j.php?MTID=m2fe139bf876cea3ec62750cd580b7908
>>>> This says "meeting cancelled".
>>>> I assume it is an administrative oops, stay tuned for another URL, I guess.
>>>>
>>>> I have a bridge that can be used; accessible via SIP: and PSTN, but I will
>>>> wait ten minutes before suggesting it.
>>>>
>>>> --
>>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>>>> -= IPv6 IoT consulting =-
>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> 6tisch-security mailing list
>>>> 6tisch-security@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/6tisch-security
>>> _______________________________________________
>>> 6tisch-security mailing list
>>> 6tisch-security@ietf.org
>>> https://www.ietf.org/mailman/listinfo/6tisch-security
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


From nobody Tue Jun 24 07:13:44 2014
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA30B1B2959 for <6tisch-security@ietfa.amsl.com>; Tue, 24 Jun 2014 07:13:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.151
X-Spam-Level: 
X-Spam-Status: No, score=-15.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, LOTS_OF_MONEY=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uazD6ovfhW6U for <6tisch-security@ietfa.amsl.com>; Tue, 24 Jun 2014 07:13:38 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E00421B2A37 for <6tisch-security@ietf.org>; Tue, 24 Jun 2014 07:13:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5505; q=dns/txt; s=iport; t=1403619210; x=1404828810; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=jSgQj1Vngu4PiZJRIHnaHN5sKBY+t6uLLReNMWVVDhk=; b=gsft3QjLvuXxQ7eELVTR/fhGNxexgilkh5JsEDBWiYn7Nmp+N1xU9CJQ G1C8CsOcTai5K7cY7YJ/CC/UMugRuCLZagFmTGGEmfO2Xs1a7QMfMnOua rTQxmT8P2cPZwu19ChFdcpOS4M4J94q+8m6FZxtHvPQ8S29D6tD4Y0HH0 k=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AkcFAH6GqVOtJA2L/2dsb2JhbAA/FwODDVJaqkaReoZtUwGBBhZ1hAMBAQEEAQEBRQ0RCAsMBAIBCA4DAwEBAQEKCgEDDAMHIQYLFAkHAQIBAwENBQiIJgMRDTarDBGRYg2GKReFY4V3AXyBQxEBDBMhEAIFBgQHB4MVgRYFhGN9hCqCX4trg0OMG4YKgm1VbIECBAUXIno
X-IronPort-AV: E=Sophos;i="5.01,538,1400025600"; d="scan'208";a="335308020"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by rcdn-iport-3.cisco.com with ESMTP; 24 Jun 2014 14:13:29 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by alln-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id s5OEDTga019235 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 24 Jun 2014 14:13:29 GMT
Received: from xmb-rcd-x01.cisco.com ([169.254.1.12]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.03.0123.003; Tue, 24 Jun 2014 09:13:28 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Rene Struik <rstruik.ext@gmail.com>, "Max Pritikin (pritikin)" <pritikin@cisco.com>, Michael Richardson <mcr+ietf@sandelman.ca>
Thread-Topic: [6tisch-security] agenda for 2014-06-23 6tisch security call
Thread-Index: AQHPj7XIgvOagz5pqkms8Wmzog3KuJuATPIw
Date: Tue, 24 Jun 2014 14:13:27 +0000
Deferred-Delivery: Tue, 24 Jun 2014 14:13:00 +0000
Message-ID: <E045AECD98228444A58C61C200AE1BD842C51C1B@xmb-rcd-x01.cisco.com>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <29190.1403531589@sandelman.ca> <9FF7C59D-05B0-46B9-9D42-C7D818DFCB97@cisco.com> <2568FD82-9C40-40D1-86AF-73975FAF3C9B@cisco.com> <D1A160F1-0ACE-4E88-8D49-9B09706D803B@cisco.com> <53A9862F.6060905@gmail.com>
In-Reply-To: <53A9862F.6060905@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.49.80.52]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/VyX68d9NlcBoYLo-KLBFS30Nhuw
Cc: "6tisch-security@ietf.org" <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Jun 2014 14:13:41 -0000

Hello Ren=E9:

I missed that discussion. What I did since the webex was lost is create ano=
ther one on Mondays:

You are the host for this online meeting.
Topic:	6TiSCH security
Date:	Every Monday, from Monday 23 June 2014 to Monday 20 June 2016
Time:	16:00, Europe Summer Time (Paris, GMT+02:00)
Meeting Number:	202 347 993
Meeting Password:	6Sec

To start the online meeting
1.	Go to https://cisco.webex.com/cisco/j.php?MTID=3Dmf0899e407e9726ee6daee7=
032b007578=20
2.	Log in to your account.
3.	Click "Start Now".
4.	Follow the instructions that appear on your screen.

ALERT - PLEASE READ: DO NOT DIAL THE TOLL FREE NUMBERS FROM WITHIN THE (408=
) OR (919) AREA CODES
Please dial the local access number for your area from the list below:
.	San Jose/Milpitas (408) area:  525-6800
.	RTP (919) area:  392-3330
=20
Dialing the WebEx toll free numbers from within 408 or 919 area codes is no=
t enabled (non-Cisco phones).  " If you dial the toll-free numbers within t=
he 408 or 919 area codes you will be instructed to hang up and dial the loc=
al access number." Please use the call-back option whenever possible and ot=
herwise dial local numbers only.  The affected toll free numbers are: (866)=
 432-9903 for the San Jose/Milpitas area and (866) 349-3520 for the RTP are=
a.

-------------------------------------------------------=20
To join the teleconference only=20
-------------------------------------------------------=20
1.	Dial into Cisco WebEx (view all Global Access Numbers at=20
http://cisco.com/en/US/about/doing_business/conferencing/index.html=20
2.	Follow the prompts to enter the Meeting Number (listed above) or Access =
Code followed by the # sign.=20

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330=20
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117=20
India: +91.80.4350.1111  Germany: +49.619.6773.9002=20
Japan: +81.3.5763.9394  China: +86.10.8515.5666

For assistance
1.	Go to https://cisco.webex.com/cisco/mc
2.	On the left navigation bar, click "Support".
To add this meeting to your calendar program (for example Microsoft Outlook=
), click this link:
https://cisco.webex.com/cisco/j.php?MTID=3Dm30763e6b62a4467891f27c5cac79492=
5
To check whether you have the appropriate players installed for UCF (Univer=
sal Communications Format) rich media files, go to https://cisco.webex.com/=
cisco/systemdiagnosis.php.
http://www.webex.com
CCM:+14085256800x202347993#=20


Cheers,

Pascal


> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf=
 Of
> Rene Struik
> Sent: mardi 24 juin 2014 16:08
> To: Max Pritikin (pritikin); Michael Richardson
> Cc: 6tisch-security@ietf.org
> Subject: Re: [6tisch-security] agenda for 2014-06-23 6tisch security call
>=20
> Dear colleagues:
>=20
> I thought we had rescheduled the 6TiSCH security conf call to 10am EDT
> today, June 24, 2014, but did not see anyone online on Webex.
>=20
> Best regards, Rene
>=20
> On 6/23/2014 10:21 AM, Max Pritikin (pritikin) wrote:
> > Thanks to the 4 people that joined this webex. Unfortunately we didn't
> > achieve quorum and everybody dropped. Hopefully a reschedule
> > discussion will occur now,
> >
> > - max
> >
> > On Jun 23, 2014, at 4:10 PM, Max Pritikin (pritikin) <pritikin@cisco.co=
m>
> wrote:
> >
> >>
> https://ciscosales.webex.com/ciscosales/e.php?MTID=3Dmed0fe95ade4c1e134
> >> 10b87950c11c337
> >>
> >> Dialin: (408) 525-6800
> >> Meeting Number: 204 226 648
> >> Meeting Password: letmein
> >>
> >> - max
> >>
> >>
> >> On Jun 23, 2014, at 4:01 PM, Max Pritikin (pritikin) <pritikin@cisco.c=
om>
> wrote:
> >>
> >>> If necessary I could create a different webex as well?
> >>> - max
> >>>
> >>> On Jun 23, 2014, at 3:53 PM, Michael Richardson
> <mcr+ietf@sandelman.ca> wrote:
> >>>
> >>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> >>>>> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> >>>>>> We had a very productive call last week.
> >>>>>> -- The URL to access the webex, which will we use for audio only:
> >>>>>>
> >>>>>
> https://cisco.webex.com/cisco/j.php?MTID=3Dm2fe139bf876cea3ec62750cd
> >>>>> 580b7908
> >>>> This says "meeting cancelled".
> >>>> I assume it is an administrative oops, stay tuned for another URL, I
> guess.
> >>>>
> >>>> I have a bridge that can be used; accessible via SIP: and PSTN, but
> >>>> I will wait ten minutes before suggesting it.
> >>>>
> >>>> --
> >>>> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software
> >>>> Works -=3D IPv6 IoT consulting =3D-
> >>>>
> >>>>
> >>>>
> >>>> _______________________________________________
> >>>> 6tisch-security mailing list
> >>>> 6tisch-security@ietf.org
> >>>> https://www.ietf.org/mailman/listinfo/6tisch-security
> >>> _______________________________________________
> >>> 6tisch-security mailing list
> >>> 6tisch-security@ietf.org
> >>> https://www.ietf.org/mailman/listinfo/6tisch-security
> > _______________________________________________
> > 6tisch-security mailing list
> > 6tisch-security@ietf.org
> > https://www.ietf.org/mailman/listinfo/6tisch-security
>=20
>=20
> --
> email: rstruik.ext@gmail.com | Skype: rstruik
> cell: +1 (647) 867-5658 | US: +1 (415) 690-7363
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Fri Jun 27 10:56:55 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CECD41A0416 for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 10:56:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bqm1EnVShFur for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 10:56:51 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C60CB1A0505 for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 10:56:40 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 2A37E200EF for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 13:56:52 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id B473263B12; Tue, 24 Jun 2014 09:00:28 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id A4DA163AED for <6tisch-security@ietf.org>; Tue, 24 Jun 2014 09:00:28 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <4589.1403533477@sandelman.ca>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <4589.1403533477@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 24 Jun 2014 09:00:28 -0400
Message-ID: <30520.1403614828@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/PlV7H-va8rpNSlve3Ycx6NuVacQ
Subject: [6tisch-security] CANCELLED: agenda for 2014-06-23/24 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Jun 2014 17:56:54 -0000

--=-=-=


Due to concern that we don't have a webex setup for 10am yet, and maybe we
are conflicting with the 6top call, and I don't know if we get quorum...
I'm going to cancel the rescheduled 10am call today, and let's have our
final call before IETF90 on Monday June 30, 10am.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU6l2bICLcPvd0N1lAQLcpwf8CV4RQRIE6usGzjGkjU7rOb6q3f0qBWvP
b/7JgNlOQ//i8Gy1tkrVRQdWnEhPcfZk1mhYK57uvzhBW3T/ITWjFkcLc/o4abW8
9gjiiRR+yfmWaZDRAFlNYgfmuMg3jlvDDeR7PmcVBLCoCtSIhMqUJMTrsqUmQpm0
qm+ukUieW5nG2SGFs1Vq/P0MiLv8mZw0AFSH+XsMSFc2kN3D3GENPvNUOaRQWtRv
T/GUaLbO/cWB48ZzrHG1TqFwBBminJOTg5N/U4Fqh0UOTlDqF1a+2QM30lk111Ic
CcwEizaM7l1SnUEMRA9xxxgDlKO8PmuTj5aJ+PlwoDCEQTMMUzvNfQ==
=vxcF
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Fri Jun 27 11:04:07 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E5D981A041C for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 11:04:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.542
X-Spam-Level: 
X-Spam-Status: No, score=-2.542 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uRsExGfNwcSf for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 11:04:05 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E2E4E1A03B4 for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 11:04:04 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id D1E6B2002A for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 14:04:17 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 40ED063AED; Fri, 27 Jun 2014 14:04:04 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 2D7A2637FE for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 14:04:04 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
to: 6tisch-security@ietf.org
In-Reply-To: <30520.1403614828@sandelman.ca>
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <4589.1403533477@sandelman.ca> <30520.1403614828@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Fri, 27 Jun 2014 14:04:04 -0400
Message-ID: <27994.1403892244@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/1D4HUBF8KxbfAeIFt1c3TU4sdZs
Subject: Re: [6tisch-security] CANCELLED: agenda for 2014-06-23/24 6tisch security call
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Jun 2014 18:04:06 -0000

--=-=-=


Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > Due to concern that we don't have a webex setup for 10am yet, and maybe
    > we

And also my appologies, as this email got stuck, and so is really untimely.

Next call on 2014-06-30, 10am.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU62yEYCLcPvd0N1lAQLo+ggAuttvY7eetiVtBRLuKislqV3xvWvtZF/c
dUWDV3dglgmgKyjsd4IJSKQWshJvHsyI4bYflJMeOjsHTs4RjDfWqTnaeqS+sZnc
S4vl6uBy1hJs8y3qynTB9a4a2gprXDLNkNvkq8QDCL7CcI6XwRqwFwZ+P8nyrX4i
CUTHnDlTGU3UViOuH7I0z4PR8LdExFWXw0Nr3JkdIeGq2QXlfYx1V7psJjIbgcqS
0RdFFhL7e5sKvKIztEFN1LuZo6JnH8ZzEw0sw4+/7YaWQ0WZWueWNxT+0UwCN5u9
6nJ66fbEEdh5gW5iJm45LwPio8xoO9ocUS/PyHDykA7TE63PAGlKJg==
=e5WX
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Fri Jun 27 11:21:47 2014
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D44201B28AC for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 11:21:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pmcvaO7BM9ya for <6tisch-security@ietfa.amsl.com>; Fri, 27 Jun 2014 11:21:37 -0700 (PDT)
Received: from mail-ig0-x233.google.com (mail-ig0-x233.google.com [IPv6:2607:f8b0:4001:c05::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9200D1B28AB for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 11:21:37 -0700 (PDT)
Received: by mail-ig0-f179.google.com with SMTP id uq10so2260329igb.6 for <6tisch-security@ietf.org>; Fri, 27 Jun 2014 11:21:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type; bh=hC1OQed8UUlz17ikKaCLti3cjOTm4F8b9Ip+nuIcEO8=; b=bdCf3T10Jt7cz9BxQQUq4SVbGPxNrcjSlKSqNPMOcLyF3paD2XFuWlk9SLCEoa59hC aWyVhKTKVfB2Bw6Q2dpQtvfcldK6aMWk+8nsB8g9H+VhaTxEU7uuXuvNNmN1Ne2e+K+5 ZeYv/aqkcxnY1c+Za4bYj2aetMNspS7UAKvAy3BfH8qGVQ3SlZEY5iH+D/Us2vElLq4Z hsmty12QUHgF1CchKV+jf1FzOeDM12IQReQ60opN9mw5Of5hx1LEBWvzWxJpkUSdrtpp AWk/Au7ztl6O54cibO/hGopJCl5vNLnA14Sm6MtPPYDLxbx6sD0JjYJHJf4qnKFNOky9 6Nmg==
X-Received: by 10.50.114.197 with SMTP id ji5mr14531797igb.48.1403893296901; Fri, 27 Jun 2014 11:21:36 -0700 (PDT)
Received: from [192.168.1.102] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [99.231.3.110]) by mx.google.com with ESMTPSA id v4sm15613283igk.10.2014.06.27.11.21.36 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 27 Jun 2014 11:21:36 -0700 (PDT)
Message-ID: <53ADB628.7070501@gmail.com>
Date: Fri, 27 Jun 2014 14:21:28 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security@ietf.org
References: <14319.1402884686@sandelman.ca> <25450.1403493683@sandelman.ca> <4589.1403533477@sandelman.ca> <30520.1403614828@sandelman.ca> <27994.1403892244@sandelman.ca>
In-Reply-To: <27994.1403892244@sandelman.ca>
Content-Type: multipart/alternative; boundary="------------070107040301040203000806"
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/GzDazeU_cepcjqzob2P5aCPxe1I
Subject: [6tisch-security] dial-in info 6TiSCH Security Conf Call Monday June 30, 2014, 10am EDT
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Jun 2014 18:21:41 -0000

This is a multi-part message in MIME format.
--------------070107040301040203000806
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear colleagues:

I will be traveling on Monday June 30, 2014 and most likely would not 
have internet connectivity. I can dial-in to the call, though.

I will try and dial-in using the US/Canada  phone # and meeting #, as 
indicated below:

US/Canada: +1.866.432.9903
Meeting Number:    202.347.993
{extracted from Pascal Thubert's webex info}

In case this info is incorrect, I can see any corrections till later 
this afternoon (before 5pm EDT).

Best regards, Rene

On 6/27/2014 2:04 PM, Michael Richardson wrote:
> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>      > Due to concern that we don't have a webex setup for 10am yet, and maybe
>      > we
>
> And also my appologies, as this email got stuck, and so is really untimely.
>
> Next call on 2014-06-30, 10am.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>   -= IPv6 IoT consulting =-
>
>
>
>
>
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


-- 
email: rstruik.ext@gmail.com | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363


--------------070107040301040203000806
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear colleagues:<br>
      <br>
      I will be traveling on Monday June 30, 2014 and most likely would
      not have internet connectivity. I can dial-in to the call, though.<br>
      <br>
      I will try and dial-in using the US/Canada&nbsp; phone # and meeting #,
      as indicated below:<br>
      <br>
      US/Canada: +1.866.432.9903 <br>
      Meeting Number:&nbsp;&nbsp;&nbsp; 202.347.993<br>
      {extracted from Pascal Thubert's webex info}<br>
      <br>
      In case this info is incorrect, I can see any corrections till
      later this afternoon (before 5pm EDT).<br>
      <br>
      Best regards, Rene<br>
      <br>
      On 6/27/2014 2:04 PM, Michael Richardson wrote:<br>
    </div>
    <blockquote cite="mid:27994.1403892244@sandelman.ca" type="cite">
      <pre wrap="">
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+ietf@sandelman.ca">&lt;mcr+ietf@sandelman.ca&gt;</a> wrote:
    &gt; Due to concern that we don't have a webex setup for 10am yet, and maybe
    &gt; we

And also my appologies, as this email got stuck, and so is really untimely.

Next call on 2014-06-30, 10am.

--
Michael Richardson <a class="moz-txt-link-rfc2396E" href="mailto:mcr+IETF@sandelman.ca">&lt;mcr+IETF@sandelman.ca&gt;</a>, Sandelman Software Works
 -= IPv6 IoT consulting =-



</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
6tisch-security mailing list
<a class="moz-txt-link-abbreviated" href="mailto:6tisch-security@ietf.org">6tisch-security@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/6tisch-security">https://www.ietf.org/mailman/listinfo/6tisch-security</a>
</pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
email: <a class="moz-txt-link-abbreviated" href="mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com</a> | Skype: rstruik
cell: +1 (647) 867-5658 | US: +1 (415) 690-7363</pre>
  </body>
</html>

--------------070107040301040203000806--


From nobody Mon Jun 30 06:35:19 2014
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 527321A0327 for <6tisch-security@ietfa.amsl.com>; Mon, 30 Jun 2014 06:35:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.72
X-Spam-Level: ***
X-Spam-Status: No, score=3.72 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FH_RELAY_NODNS=1.451, LOTS_OF_MONEY=0.001, RDNS_NONE=0.793, SPF_SOFTFAIL=0.665, T_TVD_MIME_NO_HEADERS=0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id h1dY5McEQrIO for <6tisch-security@ietfa.amsl.com>; Mon, 30 Jun 2014 06:35:15 -0700 (PDT)
Received: from tuna.sandelman.ca (unknown [209.87.249.16]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E92621A0309 for <6tisch-security@ietf.org>; Mon, 30 Jun 2014 06:35:14 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id AF25E20028 for <6tisch-security@ietf.org>; Mon, 30 Jun 2014 09:35:35 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 77C2563B0E; Mon, 30 Jun 2014 09:35:12 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 6593163B0B for <6tisch-security@ietf.org>; Mon, 30 Jun 2014 09:35:12 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "6tisch-security\@ietf.org" <6tisch-security@ietf.org>
In-Reply-To: <E045AECD98228444A58C61C200AE1BD842C4D744@xmb-rcd-x01.cisco.com>
References: <E045AECD98228444A58C61C200AE1BD842C4D744@xmb-rcd-x01.cisco.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 30 Jun 2014 09:35:12 -0400
Message-ID: <32142.1404135312@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/Gy0jlt_6nerbDUE8kojWsnzNsTU
Subject: Re: [6tisch-security] FW: Meeting scheduled: 6TiSCH security
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Jun 2014 13:35:17 -0000

--=-=-=


Just a reminder that we meet in 20 minutes at:

   Go to https://cisco.webex.com/cisco/j.php?MTID=mf0899e407e9726ee6daee7032b007578

Meeting Number: 202 347 993
Meeting Password:       6Sec

1.      Dial into Cisco WebEx (view all Global Access Numbers at
http://cisco.com/en/US/about/doing_business/conferencing/index.html
2.      Follow the prompts to enter the Meeting Number (listed above) or Access
Code followed by the # sign.

San Jose, CA: +1.408.525.6800  RTP: +1.919.392.3330
US/Canada: +1.866.432.9903  United Kingdom: +44.20.8824.0117
India: +91.80.4350.1111  Germany: +49.619.6773.9002
Japan: +81.3.5763.9394  China: +86.10.8515.5666

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU7FnkICLcPvd0N1lAQKILQgAp+2eYTmyRy5E0m43lRWZ3ON0suug/Osu
ZGW25Z9lMBYueWS/pjRBvdfQislrkku9GA2UdsMaU7g6JFjOORdMh6ycueVG1Xmv
N9mOR7jGnUZEWkdYq631F1XMThq/G8+jKn4LNGzAX0mzi0hUKEEndxopHnsx1F7L
buOwmwdH9QaOrH+sfKtV1vn790rhXRyaMSKQmR1Yhs5HlS5hAVg8MvvJk1Xt7phA
DEJTKI6b9mU+buUr5afkgnMQIpL82WM5w2OtfSfVM6qQy8A61vMleFovEZ4aqY2G
kh9UdPp/saLIi4jQHDwoOHyO0kYjVSdcCbCsO8tSFHOzMBHW16Nicg==
=bqZo
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Mon Jun 30 23:33:55 2014
Return-Path: <peppe@giuseppepiro.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 397E41B27C9 for <6tisch-security@ietfa.amsl.com>; Mon, 30 Jun 2014 23:33:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.602
X-Spam-Level: 
X-Spam-Status: No, score=0.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HELO_EQ_IT=0.635, HOST_EQ_IT=1.245, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 02qMYVUYP7ET for <6tisch-security@ietfa.amsl.com>; Mon, 30 Jun 2014 23:33:52 -0700 (PDT)
Received: from smtpdb8.aruba.it (smtpdb8.aruba.it [62.149.158.250]) by ietfa.amsl.com (Postfix) with ESMTP id E32E11B278C for <6tisch-security@ietf.org>; Mon, 30 Jun 2014 23:33:51 -0700 (PDT)
Received: from mail-pa0-f52.google.com ([209.85.220.52]) by smtpcmd03.ad.aruba.it with bizsmtp id LuZm1o00W18Roeh01uZn8U; Tue, 01 Jul 2014 08:33:49 +0200
Received: by mail-pa0-f52.google.com with SMTP id eu11so10060782pac.39 for <multiple recipients>; Mon, 30 Jun 2014 23:33:45 -0700 (PDT)
X-Received: by 10.68.164.100 with SMTP id yp4mr57645153pbb.136.1404196425255;  Mon, 30 Jun 2014 23:33:45 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.70.89.2 with HTTP; Mon, 30 Jun 2014 23:33:25 -0700 (PDT)
In-Reply-To: <CAH-9zkox0h6O6ezT2jL2T7r+u31NCxx1whaHhhvKmsNP91noeQ@mail.gmail.com>
References: <20140613075557.3685.99730.idtracker@ietfa.amsl.com> <CAH-9zkox0h6O6ezT2jL2T7r+u31NCxx1whaHhhvKmsNP91noeQ@mail.gmail.com>
From: Giuseppe Piro <peppe@giuseppepiro.com>
Date: Tue, 1 Jul 2014 08:33:25 +0200
Message-ID: <CAH-9zkqgt15siUpKG7=+SJpK3+-v9SMzw8zK7OwmjnzWgNZK4g@mail.gmail.com>
To: 6tisch-security@ietf.org
Content-Type: text/plain; charset=UTF-8
Archived-At: http://mailarchive.ietf.org/arch/msg/6tisch-security/WSH5-LDtmMg8tIcmkpvAwDTkzn4
Cc: "6tisch@ietf.org" <6tisch@ietf.org>
Subject: Re: [6tisch-security] New Version Notification for draft-piro-6tisch-security-issues-02.txt
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Jul 2014 06:33:54 -0000

Dear all,

I've just realized that my previous mail wasn't correctly received by
the 6tisch mailing list server (sorry for this issue!)

This is to inform you that a new version of the draft
draft-piro-6tisch-security-issues has been submitted ... some days
ago.

We have reviewed the document by carefully taking into account
comments and suggestions given by the mailing list.

Here a summary of main changes:
- the document describes how configuring MAC security parameters to
offer security services at the layer-2
- the discussion focuses on 802.15.4e specifications
- a better description of secure configurations and layer-2 keys is provided
- the KMP is handled by using only 802.15.4e IEs

We are looking forward to receive you comments on that updated work.

Thanks and regards,
Giuseppe






On Fri, Jun 13, 2014 at 10:59 AM, Giuseppe Piro <peppe@giuseppepiro.com> wrote:
> Dear all,
>
> a new version of the draft draft-piro-6tisch-security-issues has been submitted.
>
> We have reviewed the document by carefully taking into account
> comments and suggestions given by the mailing list.
>
> Here a summary of main changes:
>
> - the document describes how configuring MAC security parameters to
> offer security services at the layer-2
> - the discussion focuses on 802.15.4e specifications
> - a better description of secure configurations and layer-2 keys is provided
> - the KMP is handled by using only 802.15.4e IEs
>
>
> We are looking forward to receive you comments on that updated work.
>
> Thanks and regards,
> Giuseppe
>
>
>
> ---------- Forwarded message ----------
> From:  <internet-drafts@ietf.org>
> Date: Fri, Jun 13, 2014 at 9:55 AM
> Subject: New Version Notification for draft-piro-6tisch-security-issues-02.txt
> To: Giuseppe Piro <giuseppe.piro@poliba.it>, Gennaro Boggia
> <gennaro.boggia@poliba.it>, Luigi Alfredo Grieco
> <alfredo.grieco@poliba.it>
>
>
>
> A new version of I-D, draft-piro-6tisch-security-issues-02.txt
> has been successfully submitted by Giuseppe Piro and posted to the
> IETF repository.
>
> Name:           draft-piro-6tisch-security-issues
> Revision:       02
> Title:          Layer-2 security aspects for the IEEE 802.15.4e MAC
> Document date:  2014-06-13
> Group:          Individual Submission
> Pages:          26
> URL:
> http://www.ietf.org/internet-drafts/draft-piro-6tisch-security-issues-02.txt
> Status:
> https://datatracker.ietf.org/doc/draft-piro-6tisch-security-issues/
> Htmlized:       http://tools.ietf.org/html/draft-piro-6tisch-security-issues-02
> Diff:
> http://www.ietf.org/rfcdiff?url2=draft-piro-6tisch-security-issues-02
>
> Abstract:
>    The aim of this Internet Draft is to define standard compliant
>    procedures for configuring layer-2 security services in IEEE
>    802.15.4e-based Low-power and Lossy Networks. In particular, it
>    provides a review of security aspects presented in both IEEE 802.15.4
>    and IEEE 802.15.4e specifications, the classification of secure
>    network configurations and layer-2 keys, the description of a set of
>    consecutive steps required to establish a layer-2 secure link, and a
>    lightweight Key Management Protocol designed  for negotiating a
>    layer-2 one-hop link key. As the final goal, the document would
>    describe how security MAC attributes can by initialized and updated
>    in order to offer layer-2 security services in real networks.
>
>
>
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> The IETF Secretariat
>
> --
> Giuseppe Piro, PhD
> Post Doc Researcher
> DEI, Politecnico di Bari
> via Orabona 4 - 70125 (Bari), Italy.
> email: peppe@giuseppepiro.com
> phone: +39 080 5963301
> web: giuseppepiro.com

-- 
Giuseppe Piro, PhD
Post Doc Researcher
DEI, Politecnico di Bari
via Orabona 4 - 70125 (Bari), Italy.
email: peppe@giuseppepiro.com
phone: +39 080 5963301
web: giuseppepiro.com

