
From nobody Tue Oct  1 00:55:50 2019
Return-Path: <sean@sn3rd.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB95E1200FE for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 00:55:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NHO9neYhpnlf for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 00:55:47 -0700 (PDT)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1513D1200FB for <mls@ietf.org>; Tue,  1 Oct 2019 00:55:47 -0700 (PDT)
Received: by mail-qk1-x72a.google.com with SMTP id p10so10314609qkg.8 for <mls@ietf.org>; Tue, 01 Oct 2019 00:55:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=0VfDeWq+VKJapCodJ59xWGXjJDN2l5sFZYck4p5O9DA=; b=TCQB/EDt4KfFEI/glP075mOBH8B7TnfJEClhFcHioo/hNJZEMFWGBhxJX2jDbuTjs5 vRkzRUMdAhcPJfYxba2l93W5iKFy3zriXtSYMCSAy9udmtavre+q87H5RlEISA60vEIX w+eZHCgqu+FBSKaiByQgPERR54P81mVrZ+A9U=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=0VfDeWq+VKJapCodJ59xWGXjJDN2l5sFZYck4p5O9DA=; b=HWym+0RXK3zjCFonnDDuKcUceLaNYCvjlh1RJpRIwo6YYiMzMsmARWNX8iAVggkAis NVQeaIgsCzjmu1Xq1grWKdyG17fMcfC63Do/uSSDuwuG2e2ylHwJIgd1hzQXwOftQfU2 Js5+N4S6REWFHIDfniB4k7YE6cj98dvA8QBtw4KkGdas8tjjCKbWFvnwSoEDeBVZ6nal X4VwXKEYI6Uk3RuAGkDy8HIj4Di23dsD97h4SDHcRzutV7Ju2jkH0pUfBZVHrR/mpe04 O+o9PiOZztS+d99lBr4pp36JEuRRNi8tZYuLbAYHwTLFlPnpa3LemI/7tMOUXfV6WcfP zXDA==
X-Gm-Message-State: APjAAAWdjPH8l1bqXfe6vLzyB4Vh6akLBFh6tPXWW4x5ikcip27grk27 NyrmW/mq8nM7oehLKIn2QoOTzMfWYUas6A==
X-Google-Smtp-Source: APXvYqwoMK8B7CEwip29Jsabsi2PhRWEwSvK8/vzccTC7OMBQXmCUoHeusuUO33xryiLzkYEnSxjlw==
X-Received: by 2002:a37:4b02:: with SMTP id y2mr4514163qka.493.1569916545887;  Tue, 01 Oct 2019 00:55:45 -0700 (PDT)
Received: from ?IPv6:2a06:98c0:1000:8800:2c45:f2bd:808b:f893? ([2a06:98c0:1000:8800:2c45:f2bd:808b:f893]) by smtp.gmail.com with ESMTPSA id v26sm11547312qta.88.2019.10.01.00.55.44 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 01 Oct 2019 00:55:45 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Sean Turner <sean@sn3rd.com>
X-Priority: 1
In-Reply-To: <CAFDDyk9aEc-c1cX=mjcBg8LLeBn3=itGB_NqujSziT9MRdPk=Q@mail.gmail.com>
Date: Tue, 1 Oct 2019 08:55:39 +0100
Cc: "Hale, Britta (CIV)" <britta.hale@nps.edu>, Yevgeniy Dodis <dodis@cs.nyu.edu>, Suhas Nandakumar <suhasietf@gmail.com>, gpascual@ist.ac.at
Content-Transfer-Encoding: quoted-printable
Message-Id: <7D15934A-6C2B-4B94-970F-CB56FBF48127@sn3rd.com>
References: <CAFDDyk9aEc-c1cX=mjcBg8LLeBn3=itGB_NqujSziT9MRdPk=Q@mail.gmail.com>
To: mls@ietf.org
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/lNUqxcWcAzVathXDITu0BWDNf_A>
Subject: Re: [MLS] MLS Interim 10/2019 Details
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Oct 2019 07:55:49 -0000

We are switching to a Google Meet because that is what the room is wired =
for.

Location:
https://meet.google.com/rbe-hsde-cci?hs=3D151

spt

> On Sep 27, 2019, at 18:33, Nick Sullivan <nick@cloudflare.com> wrote:
>=20
> Hello MLS Interim (10/2019) Attendees!
>=20
> I'm looking forward to hosting you at Cloudflare London next week for =
what should be a productive meeting.
>=20
> The entrance to County Hall is on the backside of the building (not =
the side with the London Eye) and Cloudflare is located on the 6th =
floor. Let's meet at around 0845 each day in the lobby so that we can =
enter the office together.
>=20
> Once we're in the office there are two options: sign an NDA and have a =
bit of freedom when moving about the office, or decline the NDA and be =
escorted to and from the meeting room by a Cloudflare employee. There is =
no catered lunch, but we have many options nearby.
>=20
> There are many hotels nearby, including the Park Plaza County Hall. =
Prices are on the high side next week, but there are no shortages of =
accommodations in the area.
>=20
> More details here:
> https://github.com/mlswg/wg-materials/tree/master/interim-2019-10
>=20
> See you soon!
> Nick


From nobody Tue Oct  1 00:58:44 2019
Return-Path: <sean@sn3rd.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D54E8120827 for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 00:58:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0RHuejO5kvXZ for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 00:58:29 -0700 (PDT)
Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B97C3120826 for <mls@ietf.org>; Tue,  1 Oct 2019 00:58:29 -0700 (PDT)
Received: by mail-qt1-x830.google.com with SMTP id l3so20467177qtr.4 for <mls@ietf.org>; Tue, 01 Oct 2019 00:58:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=from:content-transfer-encoding:mime-version:subject:date:references :to:in-reply-to:message-id; bh=37G8lK5dh8WwwnZjbTJlxbihktHBfmAieoJntu7Pduk=; b=kCT4b33rQsNHapFZWZFF33D/N3vGuNHU2MaQIvDQRbN9QKbbyG4E9aePd3LyOdWXjD Kbc7BR2wdn+nphP0A54I9zheohtP8+lkU6eo8ZvHPWmKGn3XfXpX4W9028KEGyJjJ67V 0uav+04R2yy89ocGcPWL8Zr2R41+FtV131Xco=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:content-transfer-encoding:mime-version :subject:date:references:to:in-reply-to:message-id; bh=37G8lK5dh8WwwnZjbTJlxbihktHBfmAieoJntu7Pduk=; b=sDDRIOHD+68SMSq1Fnzfk+Rk0EC6nB1WoWu68dgcQjUd9yKXXZCiTqK0Fn0Y2997SX niNc8iq18Lo5oHc2hpvqaN7Md+b3tmP0rVZCxv6yrQAnMf+fLdSM8lg8YQzsR7BX3L9l Hr286XlfdAN/x/3Ud3WzWSZfgMJn5mrq6cw52IiyZL+MKk4Xu5UyMwGf9NVlKxnN2xQe bO3z1QAPhioOocUzdA/hjYZGs83D3NwzWE/9FgVkB7BiFgUyylxR6PSrK7rRA1RYKLax trmZP3mUEzPbcV2LyYyzIIHxBn6tI0aVJfsatjGrMmfLDmuYG7mMOSn2h4apdyG1PtEy DgyA==
X-Gm-Message-State: APjAAAUhXC+UVDTSXQ47kDumV+Dc5RRC+HV2uqauciJ19ykYY1YPLGUr aabX36eqUR/QzwLra3FrghnrbY2qvZvlfA==
X-Google-Smtp-Source: APXvYqzDNfBZbWrS0tznTf1eoIClyzRZw95LxzKzL4sMo8WPHoSE6yEWBy15knGYc80TmlH27KwXSA==
X-Received: by 2002:a0c:e2c9:: with SMTP id t9mr24494047qvl.22.1569916708615;  Tue, 01 Oct 2019 00:58:28 -0700 (PDT)
Received: from ?IPv6:2a06:98c0:1000:8800:2c45:f2bd:808b:f893? ([2a06:98c0:1000:8800:2c45:f2bd:808b:f893]) by smtp.gmail.com with ESMTPSA id s50sm12173228qth.92.2019.10.01.00.58.27 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 01 Oct 2019 00:58:28 -0700 (PDT)
From: Sean Turner <sean@sn3rd.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Tue, 1 Oct 2019 08:58:26 +0100
References: <928256A6-1C12-4C62-BB8E-8E883AA00DA9@sn3rd.com>
To: mls@ietf.org
In-Reply-To: <928256A6-1C12-4C62-BB8E-8E883AA00DA9@sn3rd.com>
Message-Id: <AE7AF70D-DC77-4442-87FF-A7EFE92CD41B@sn3rd.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/NyauAprOHMas28sZoiGRK856qGg>
Subject: Re: [MLS] October 2019 Interim Registration and Issue discussion
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Oct 2019 07:58:43 -0000

See updated meeting info:

=
https://github.com/mlswg/wg-materials/blob/master/interim-2019-10/README.M=
D

spt

> On Aug 29, 2019, at 18:51, Sean Turner <sean@sn3rd.com> wrote:
>=20
> The date and location are set for the October 2019 Interim meeting. It =
will be on October 1st and 2nd at Cloudflare's London Office. More =
details can be found on Github: =
https://github.com/mlswg/wg-materials/tree/master/interim-2019-10.
>=20
> Please register with the following form if you intend on attending =
either remotely or in person.
> Registration Link (https://forms.gle/FAB8jUpLXo6tmaC58)
>=20
> Registration deadline closes on October 13th.
>=20
> We are soliciting proposals for presentations to add to the agenda for =
the meeting. Please send proposals to mls-chairs@ietf.org. Due to time =
limitations, these should be restricted to discussions about current =
active drafts.
>=20
> Here are the active documents:
> Protocol (https://datatracker.ietf.org/doc/draft-ietf-mls-protocol/)
> Issues: https://github.com/mlswg/mls-protocol/issues
>=20
> Architecture =
(https://datatracker.ietf.org/doc/draft-ietf-mls-architecture/)
> Issues: https://github.com/mlswg/mls-architecture
>=20
> Federation =
https://datatracker.ietf.org/doc/draft-omara-mls-federation/)
> Issues: https://github.com/mlswg/mls-federation/issues
>=20
>=20
> We encourage the authors and other participants to read these issues, =
distill the main questions raised by them and propose answers for =
discussion on the list in the coming weeks.
>=20
>=20
> Nick and Sean


From nobody Wed Oct  2 01:19:35 2019
Return-Path: <sean@sn3rd.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D9FA12082A for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 01:19:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ElZvWWGC1Rcg for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 01:19:31 -0700 (PDT)
Received: from mail-qt1-x832.google.com (mail-qt1-x832.google.com [IPv6:2607:f8b0:4864:20::832]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4785612083F for <mls@ietf.org>; Wed,  2 Oct 2019 01:19:31 -0700 (PDT)
Received: by mail-qt1-x832.google.com with SMTP id f7so25248172qtq.7 for <mls@ietf.org>; Wed, 02 Oct 2019 01:19:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=C6pTt3CDb+p8K4l90t1CUXFYqI08kMa6JXRRWTNSlOs=; b=Lp/c6bdwSk/zQA/hKLWhPBSAEdln2uoWgZZ6mOQ789eGvlbdRs2owWUJmsVtipRY7K HPeOfmRz821lkmDbPzSx1cE/JM7lOWLqSjwcoStq9dRxxj9XYWwQZFqepCf9A/tnGFjm ynD4Wm/q7cXkQSiakRCWrRg0hYvAfAtgzkfas=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=C6pTt3CDb+p8K4l90t1CUXFYqI08kMa6JXRRWTNSlOs=; b=PneEn4f0h8eXTx21QoKNOgmINDflxOrOXuyXyM+OPWUoUGASQO9TxCOfcjZhstaLRK eICOLqce789DV8scb9crwx4gZX35XdH7JGCAHZnFyTzP/RxKr6rj25XLR7gc9XdGxODG 0fjfwF3YKSaf6aeNftnbSsECtPluqI7D9NYUC0PB8pbVY3RRsm0UDLm19Sy//mGMyH6b DJLrOTlYbs4EbA9T/0hdA+F78M1IYtAVooplvWFPblCxtOYkTDFRhegO2E7SlZ31XWw4 12JzOm3hjSWLMgKu22+G5ffLBmG/OVXLEoob1VAuSrU3EmEFzrsnEqTCSlJWtO5VR2M9 pDPA==
X-Gm-Message-State: APjAAAW3YubdQwvGOe60olr5Ll6j4x9xIcOJN8J5ijqPij752N49NQ0+ YDW+2D3M20q6TfhZlA836klJmg/4tFnmaw==
X-Google-Smtp-Source: APXvYqwK2wYcTj8QFYjcjeztRQXEwd0kc+myscSLU+JJ3PJ59PH0jmLoikm8gYWrsCwu5WQawiwnEQ==
X-Received: by 2002:ac8:2ac5:: with SMTP id c5mr2808105qta.297.1570004370155;  Wed, 02 Oct 2019 01:19:30 -0700 (PDT)
Received: from ?IPv6:2a06:98c0:1000:8800:38c9:4e75:625e:a073? ([2a06:98c0:1000:8800:38c9:4e75:625e:a073]) by smtp.gmail.com with ESMTPSA id c25sm9304611qtv.71.2019.10.02.01.19.28 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Oct 2019 01:19:29 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Sean Turner <sean@sn3rd.com>
X-Priority: 1
In-Reply-To: <7D15934A-6C2B-4B94-970F-CB56FBF48127@sn3rd.com>
Date: Wed, 2 Oct 2019 09:19:27 +0100
Cc: "Hale, Britta (CIV)" <britta.hale@nps.edu>, Yevgeniy Dodis <dodis@cs.nyu.edu>, Suhas Nandakumar <suhasietf@gmail.com>, gpascual@ist.ac.at
Content-Transfer-Encoding: quoted-printable
Message-Id: <BEA021B4-4275-4123-88F7-3F9916832F03@sn3rd.com>
References: <CAFDDyk9aEc-c1cX=mjcBg8LLeBn3=itGB_NqujSziT9MRdPk=Q@mail.gmail.com> <7D15934A-6C2B-4B94-970F-CB56FBF48127@sn3rd.com>
To: mls@ietf.org
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/N11vUrCkMy6SSpWY5WQCfMEQngw>
Subject: Re: [MLS] MLS Interim 10/2019 Details
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Oct 2019 08:19:33 -0000

We have switch to Meet:
http://meet.google.com/tpr-fozf-gzk

spt

> On Oct 1, 2019, at 08:55, Sean Turner <sean@sn3rd.com> wrote:
>=20
> We are switching to a Google Meet because that is what the room is =
wired for.
>=20
> Location:
> https://meet.google.com/rbe-hsde-cci?hs=3D151
>=20
> spt
>=20
>> On Sep 27, 2019, at 18:33, Nick Sullivan <nick@cloudflare.com> wrote:
>>=20
>> Hello MLS Interim (10/2019) Attendees!
>>=20
>> I'm looking forward to hosting you at Cloudflare London next week for =
what should be a productive meeting.
>>=20
>> The entrance to County Hall is on the backside of the building (not =
the side with the London Eye) and Cloudflare is located on the 6th =
floor. Let's meet at around 0845 each day in the lobby so that we can =
enter the office together.
>>=20
>> Once we're in the office there are two options: sign an NDA and have =
a bit of freedom when moving about the office, or decline the NDA and be =
escorted to and from the meeting room by a Cloudflare employee. There is =
no catered lunch, but we have many options nearby.
>>=20
>> There are many hotels nearby, including the Park Plaza County Hall. =
Prices are on the high side next week, but there are no shortages of =
accommodations in the area.
>>=20
>> More details here:
>> https://github.com/mlswg/wg-materials/tree/master/interim-2019-10
>>=20
>> See you soon!
>> Nick
>=20


From cryptopathe@gmail.com  Tue Oct  1 08:31:20 2019
Return-Path: <cryptopathe@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B14DD1209A2 for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 08:31:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JAwwNouuFpTb for <mls@ietfa.amsl.com>; Tue,  1 Oct 2019 08:31:19 -0700 (PDT)
Received: from mail-oi1-x22a.google.com (mail-oi1-x22a.google.com [IPv6:2607:f8b0:4864:20::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 734461209A0 for <mls@ietf.org>; Tue,  1 Oct 2019 08:31:19 -0700 (PDT)
Received: by mail-oi1-x22a.google.com with SMTP id i185so14752020oif.9 for <mls@ietf.org>; Tue, 01 Oct 2019 08:31:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:from:date:message-id:subject:to; bh=xNEcHY9XAKNgAXr+7J+QW+qiZLefOsjHA+FRqnawl94=; b=FCsJqJ1Ag4nYvjdV7aHhkSvCPOqMrgi53vM6zQAVixmabvXKoNsrM8y3tj03BHgRW0 yT0MOVPssfo95vbjY03QBb1xqReFRUyQuskKI7NyCDmw9f2dZZqrBRlckH9A4Ks3JPF2 +CxUJeNIki6Vl/J0S5eTBy4S+Tbf2HfmJAwmO7nRO/UA8HXSb228o5RrCxdby6awGU2K MqrG4KpakZx7CG/xfHERLFXemGmiLSewCPdDmkP05ShEei3LzFBnqMq5rakDPt/1VyTo JvTLm1EzxuzYdFMxmf18//bZMoiegtYGeX8futM76rzsw2pEtCm6x79qlcojm34NmYP5 yZiQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=xNEcHY9XAKNgAXr+7J+QW+qiZLefOsjHA+FRqnawl94=; b=KPpd0EN8eI7/GYKjUKR+DyBvZwVF5DF7g/l0wG+O5JKQuiFZiFebZwHe/TtUDGNB2p NEJ2FDiUU/NPWY5qoOAX4LVUlLMO4/ikhKTpL/ZOmNthxascRKpg9D6l0xKdUsrBzCsI oF7QfM1atQD53jQOh7QuK9XzUKObnv8AKldt8jrI0xVU5hEErpCo5Usa11GzaQiknX0G +7gViBO3mBt+q/Ls2sMchUqeanH75XmPm84YAndYtqRz6sXmM2FZWX4xJWpqoADWICe+ u8wvmcZAmcTfZEnAaU2735CGw7LERSWFVkyCea4t58SQZSnONEuaLNDBpIDzRHvIqo+D kQKQ==
X-Gm-Message-State: APjAAAWQYKaCWa4xiBDOwfYdnXe5pwY3M/7VuytqwIwnN9WLf/8TyYKJ lJnbPItdjB/MJ0vvDXCqiIUENH8amV1Gkx74QXGkow==
X-Google-Smtp-Source: APXvYqy7jtab8g0T768hNSqPEKJ44LMAnFhIt0+VoxLoxWE90koI/hI/XmEUUZuFjSo7t2dokWhjcuZbyVhW4ozkPvg=
X-Received: by 2002:aca:31c7:: with SMTP id x190mr4318031oix.17.1569943878535;  Tue, 01 Oct 2019 08:31:18 -0700 (PDT)
MIME-Version: 1.0
From: Pascal Junod <cryptopathe@gmail.com>
Date: Tue, 1 Oct 2019 17:30:42 +0200
Message-ID: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com>
To: mls@ietf.org
Content-Type: multipart/alternative; boundary="000000000000328d4e0593db0bb6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/fnaGC2AilosieDn5DcYbh7o5Wn0>
X-Mailman-Approved-At: Wed, 02 Oct 2019 08:17:30 -0700
Subject: [MLS] Question regarding ClientInitKey message format
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Oct 2019 16:09:00 -0000

--000000000000328d4e0593db0bb6
Content-Type: text/plain; charset="UTF-8"

Hello,

I am new to that list, so please accept my apologies in advance for any
wrong doings with respect to the list etiquette !

I am currently reading draft-07 (Aug. 13, 2019) and something is not clear
to me with respect to the ClientInitKey format defined in section 7. The
array of ciphersuites cipher_suites is expected to have a length of 0 to
255 ciphersuites, while the array of public keys init_keys is expected to
have between one and 65535 public keys. At the same time, an above
paragraph says that the init_array MUST have the same length as the
cipher_suites array. Shouldn't both of them having a length <1,255> ? Or
what did I misunderstand?

Best,

Pascal

--000000000000328d4e0593db0bb6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello,=C2=A0<div><br></div><div>I am new to that list, so =
please accept my apologies in advance for any wrong doings with respect to =
the list etiquette !=C2=A0</div><div><br></div><div>I am currently reading =
<font face=3D"monospace">draft-07</font> (Aug. 13, 2019) and something is n=
ot clear to me with respect to the <font face=3D"monospace">ClientInitKey</=
font> format defined in section 7. The array of ciphersuites <font face=3D"=
monospace">cipher_suites</font> is expected to have a length of 0 to 255 ci=
phersuites, while the array of public keys <font face=3D"monospace">init_ke=
ys</font> is expected to have between one and 65535 public keys. At the sam=
e time, an above paragraph says that the <font face=3D"monospace">init_arra=
y</font> MUST have the same length as the <font face=3D"monospace">cipher_s=
uites</font> array. Shouldn&#39;t both of them having a length<font face=3D=
"monospace"> &lt;1,255&gt;</font> ? Or what did I misunderstand?</div><div>=
<br></div><div>Best,=C2=A0</div><div><br>Pascal</div></div>

--000000000000328d4e0593db0bb6--


From nobody Wed Oct  2 08:58:23 2019
Return-Path: <session-request@ietf.org>
X-Original-To: mls@ietf.org
Delivered-To: mls@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FFE012016E; Wed,  2 Oct 2019 08:58:21 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Meeting Session Request Tool <session-request@ietf.org>
To: <session-request@ietf.org>
Cc: mls-chairs@ietf.org, mls@ietf.org, kaduk@mit.edu, sean@sn3rd.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.104.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <157003190144.8977.6563623590714991313.idtracker@ietfa.amsl.com>
Date: Wed, 02 Oct 2019 08:58:21 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/4i44mbnnbVYPJTk-vnQAm5XUulc>
Subject: [MLS] mls - New Meeting Session Request for IETF 106
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Oct 2019 15:58:22 -0000

A new meeting session request has just been submitted by Sean Turner, a Chair of the mls working group.


---------------------------------------------------------
Working Group Name: Messaging Layer Security
Area Name: Security Area
Session Requester: Sean Turner

Number of Sessions: 1
Length of Session(s):  2 Hours
Number of Attendees: 125
Conflicts to Avoid: 
 Chair Conflict: cfrg iasa2 httpbis quic saag secdispatch tls pearg

 Key Participant Conflict: acme artarea dispatch perc 


People who must be present:
  Eric Rescorla
  Sean Turner
  Richard Barnes
  Benjamin Kaduk
  Nick Sullivan

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Wed Oct  2 09:11:38 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F45B120088 for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 09:11:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nJ26Yt-c9NpL for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 09:11:35 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 071E012004F for <mls@ietf.org>; Wed,  2 Oct 2019 09:11:34 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,249,1566856800";  d="scan'208,217";a="404432872"
Received: from 37-164-6-103.coucou-networks.fr (HELO [172.20.10.9]) ([37.164.6.103]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 02 Oct 2019 18:11:26 +0200
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <2B3F98CF-26F7-4CF1-9CA3-002D2B0613F9@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_DBD6F4D2-8FE8-4F26-8862-766F922D9DC9"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Wed, 2 Oct 2019 17:11:24 +0100
In-Reply-To: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Pascal Junod <cryptopathe@gmail.com>
References: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/jzVkkpzAccbLAMp_jI6KeEa2sBY>
Subject: Re: [MLS] Question regarding ClientInitKey message format
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Oct 2019 16:11:37 -0000

--Apple-Mail=_DBD6F4D2-8FE8-4F26-8862-766F922D9DC9
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Pascal,

If you look at the latest version of the draft (master) which is =
available on Github [0]
we moved away from having multiple cipher suites advertized in the =
ClientInitKey
to have only one ciphersuite [1], hence solving that issue at the same =
time=E2=80=A6 :)

Let me/us know if you have any questions=E2=80=A6

Best,
Benjamin

[0] =
https://github.com/mlswg/mls-protocol/blob/master/draft-ietf-mls-protocol.=
md
[1] https://github.com/mlswg/mls-protocol/pull/204/files


> On Oct 1, 2019, at 4:30 PM, Pascal Junod <cryptopathe@gmail.com> =
wrote:
>=20
> Hello,=20
>=20
> I am new to that list, so please accept my apologies in advance for =
any wrong doings with respect to the list etiquette !=20
>=20
> I am currently reading draft-07 (Aug. 13, 2019) and something is not =
clear to me with respect to the ClientInitKey format defined in section =
7. The array of ciphersuites cipher_suites is expected to have a length =
of 0 to 255 ciphersuites, while the array of public keys init_keys is =
expected to have between one and 65535 public keys. At the same time, an =
above paragraph says that the init_array MUST have the same length as =
the cipher_suites array. Shouldn't both of them having a length <1,255> =
? Or what did I misunderstand?
>=20
> Best,=20
>=20
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_DBD6F4D2-8FE8-4F26-8862-766F922D9DC9
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Pascal,<div class=3D""><br class=3D""></div><div class=3D"">If you look =
at the latest version of the draft (master) which is available on Github =
[0]</div><div class=3D"">we moved away from having multiple cipher =
suites advertized in the ClientInitKey</div><div class=3D"">to have only =
one ciphersuite [1], hence solving that issue at the same time=E2=80=A6 =
:)</div><div class=3D""><br class=3D""></div><div class=3D"">Let me/us =
know if you have any questions=E2=80=A6</div><div class=3D""><br =
class=3D""></div><div class=3D"">Best,</div><div =
class=3D"">Benjamin</div><div class=3D""><br class=3D""></div><div =
class=3D"">[0]&nbsp;<a =
href=3D"https://github.com/mlswg/mls-protocol/blob/master/draft-ietf-mls-p=
rotocol.md" =
class=3D"">https://github.com/mlswg/mls-protocol/blob/master/draft-ietf-ml=
s-protocol.md</a></div><div class=3D"">[1] <a =
href=3D"https://github.com/mlswg/mls-protocol/pull/204/files" =
class=3D"">https://github.com/mlswg/mls-protocol/pull/204/files</a></div><=
div class=3D""><br class=3D""></div><div class=3D""><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On Oct =
1, 2019, at 4:30 PM, Pascal Junod &lt;<a =
href=3D"mailto:cryptopathe@gmail.com" =
class=3D"">cryptopathe@gmail.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D"">Hello,&nbsp;<div class=3D""><br class=3D""></div><div =
class=3D"">I am new to that list, so please accept my apologies in =
advance for any wrong doings with respect to the list etiquette =
!&nbsp;</div><div class=3D""><br class=3D""></div><div class=3D"">I am =
currently reading <font face=3D"monospace" class=3D"">draft-07</font> =
(Aug. 13, 2019) and something is not clear to me with respect to the =
<font face=3D"monospace" class=3D"">ClientInitKey</font> format defined =
in section 7. The array of ciphersuites <font face=3D"monospace" =
class=3D"">cipher_suites</font> is expected to have a length of 0 to 255 =
ciphersuites, while the array of public keys <font face=3D"monospace" =
class=3D"">init_keys</font> is expected to have between one and 65535 =
public keys. At the same time, an above paragraph says that the <font =
face=3D"monospace" class=3D"">init_array</font> MUST have the same =
length as the <font face=3D"monospace" class=3D"">cipher_suites</font> =
array. Shouldn't both of them having a length<font face=3D"monospace" =
class=3D""> &lt;1,255&gt;</font> ? Or what did I =
misunderstand?</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,&nbsp;</div><div class=3D""><br =
class=3D"">Pascal</div></div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_DBD6F4D2-8FE8-4F26-8862-766F922D9DC9--


From nobody Wed Oct  2 14:38:26 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EF1812088C for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 14:38:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level: 
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MIRMik2asV9I for <mls@ietfa.amsl.com>; Wed,  2 Oct 2019 14:38:15 -0700 (PDT)
Received: from mail-ot1-x332.google.com (mail-ot1-x332.google.com [IPv6:2607:f8b0:4864:20::332]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0FE4A1208EB for <mls@ietf.org>; Wed,  2 Oct 2019 14:38:15 -0700 (PDT)
Received: by mail-ot1-x332.google.com with SMTP id 89so467637oth.13 for <mls@ietf.org>; Wed, 02 Oct 2019 14:38:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=n2+TN7Az+KSiLt7ar6OjyFLO6k1XEse5N8icNnm25uw=; b=hl9WMPcvWuJRI4fUFvtn4tN7bcUShC8Etq5GnLuiUltwKW3cYiWoAQhBBDn5nlXKck iM+5XuOcExbEq8tm/Cohilv8cjU9ds23AyPTVJYj59InRJUlYo1gsWjm7pcW4PU2lQdW X8Y+0GKrfjszMMgBa8BIxAtAEcrpVOQUtuCKNwmtvHZRcBQBQ+Y/HXC6F0Oa8WrCf/Fa SOhAhAtOSArvMhrICsdGuC4ntyt4PFXEl/vdgdtuG2FiNyQDI3cWEZoAe10mUONxxDJ4 acPool1olHMxfbN8bt53xt3/hS8sE6sNq0vixH1YV2A6rg5NQA48uUPgLzXpg8chgw/r enbQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=n2+TN7Az+KSiLt7ar6OjyFLO6k1XEse5N8icNnm25uw=; b=WyBjX+poJdxUQ5eVvIbMHkAQZxDVa4PH3FTskR8x6+1k0XLM6YjujsJuBxONzxipNd MTBMuLcTksSkYz3IY15q0lnSQQY8zdbT/IvHT41PXXbUj8ndhc1VJHjmvfR1qQbOCu1u EHsESVtt6HIen0vP2+kaLeO+eGHFkPeqxmtSeon0iqV/qSNFASd87xUc6LieMFwSw7kz NiulHb3HEhN8VCUnTtGxu337Bfr1wveUVRAf4+czH8f6dD+WvMSCdeRONA0bOOXc22e1 kjhYG8FIjwpKA7IbYYjMCoiTX0vsDLt9N/Gr7otu4wvCWj0MDTC8o24Krl47I28brNjv wfkA==
X-Gm-Message-State: APjAAAW0Ru+BGNEKW0KwqBRzu0Fj+08hv7f+UCHML6WqSoeBjs8YqzgH +ZweB3dtmFSPGBJwioOhOXN09eY9nnn8gJ/pWrPYMQ==
X-Google-Smtp-Source: APXvYqwKxHzLwyvG+pvGTRStgPuX0+X5LfYlxWX0dScYWQzmDtBwOM1Lux0saLrtPSimnItxlfOe8KVqPVUlz34xlio=
X-Received: by 2002:a9d:4582:: with SMTP id x2mr4148005ote.159.1570052294068;  Wed, 02 Oct 2019 14:38:14 -0700 (PDT)
MIME-Version: 1.0
References: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com>
In-Reply-To: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 2 Oct 2019 22:38:00 +0100
Message-ID: <CAL02cgQ330S8gsUXwbPhhU_i7_cdaEmKKLHcff3SbLc=2tsEAQ@mail.gmail.com>
To: Pascal Junod <cryptopathe@gmail.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000004463e10593f4492e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/ZU7j8OnpPGc32T-xjV1oiB4iRKM>
Subject: Re: [MLS] Question regarding ClientInitKey message format
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Oct 2019 21:38:24 -0000

--0000000000004463e10593f4492e
Content-Type: text/plain; charset="UTF-8"

In addition to what Benjamin said, I think you've misunderstood the meaning
of the length indications.  The lengths indicate the size in *bytes*, not
in *entries*.  So the ciphersuites field can hold 128 2-byte ciphersuites,
and the init_keys can hold however many public keys will fit in 65535 bytes.

But as Benjamin said, this has all been obsoleted by more recent changes.

--Richard

On Wed, Oct 2, 2019 at 4:17 PM Pascal Junod <cryptopathe@gmail.com> wrote:

> Hello,
>
> I am new to that list, so please accept my apologies in advance for any
> wrong doings with respect to the list etiquette !
>
> I am currently reading draft-07 (Aug. 13, 2019) and something is not
> clear to me with respect to the ClientInitKey format defined in section
> 7. The array of ciphersuites cipher_suites is expected to have a length
> of 0 to 255 ciphersuites, while the array of public keys init_keys is
> expected to have between one and 65535 public keys. At the same time, an
> above paragraph says that the init_array MUST have the same length as the
> cipher_suites array. Shouldn't both of them having a length <1,255> ? Or
> what did I misunderstand?
>
> Best,
>
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000004463e10593f4492e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>In addition to what Benjamin said, I think you&#39;ve=
 misunderstood the meaning of the length indications.=C2=A0 The lengths ind=
icate the size in *bytes*, not in *entries*.=C2=A0 So the ciphersuites fiel=
d can hold 128 2-byte ciphersuites, and the init_keys can hold however many=
 public keys will fit in 65535 bytes.</div><div><br></div><div>But as Benja=
min said, this has all been obsoleted by more recent changes.</div><div><br=
></div><div>--Richard<br></div><br><div class=3D"gmail_quote"><div dir=3D"l=
tr" class=3D"gmail_attr">On Wed, Oct 2, 2019 at 4:17 PM Pascal Junod &lt;<a=
 href=3D"mailto:cryptopathe@gmail.com">cryptopathe@gmail.com</a>&gt; wrote:=
<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8=
ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr=
">Hello,=C2=A0<div><br></div><div>I am new to that list, so please accept m=
y apologies in advance for any wrong doings with respect to the list etique=
tte !=C2=A0</div><div><br></div><div>I am currently reading <font face=3D"m=
onospace">draft-07</font> (Aug. 13, 2019) and something is not clear to me =
with respect to the <font face=3D"monospace">ClientInitKey</font> format de=
fined in section 7. The array of ciphersuites <font face=3D"monospace">ciph=
er_suites</font> is expected to have a length of 0 to 255 ciphersuites, whi=
le the array of public keys <font face=3D"monospace">init_keys</font> is ex=
pected to have between one and 65535 public keys. At the same time, an abov=
e paragraph says that the <font face=3D"monospace">init_array</font> MUST h=
ave the same length as the <font face=3D"monospace">cipher_suites</font> ar=
ray. Shouldn&#39;t both of them having a length<font face=3D"monospace"> &l=
t;1,255&gt;</font> ? Or what did I misunderstand?</div><div><br></div><div>=
Best,=C2=A0</div><div><br>Pascal</div></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div></div>

--0000000000004463e10593f4492e--


From pjunod@snapchat.com  Thu Oct  3 01:09:35 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CBFD120825 for <mls@ietfa.amsl.com>; Thu,  3 Oct 2019 01:09:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C5ntNoQJUK6V for <mls@ietfa.amsl.com>; Thu,  3 Oct 2019 01:09:33 -0700 (PDT)
Received: from mail-io1-xd2a.google.com (mail-io1-xd2a.google.com [IPv6:2607:f8b0:4864:20::d2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1DD69120288 for <mls@ietf.org>; Thu,  3 Oct 2019 01:09:33 -0700 (PDT)
Received: by mail-io1-xd2a.google.com with SMTP id v2so3394530iob.10 for <mls@ietf.org>; Thu, 03 Oct 2019 01:09:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=l8cmuPO8e/awMYC6GulsABKYa4vm2Kjk7KGNkCJwmLk=; b=OfCmF/LYGcpZD5QoMrcx+9sj5OjngwfnmZDqz2BCLwoIdfOhfoXB8OJ8umIX9Os4Kt lW68i1HwRF7dFiZot1udcRz4VpqNOxbd48S35U42VwziHEoU40FSUwbzz59P0dYw25xu VQWHYQ+U4842uvB0ypczKdFETl6xh8ssnuIeg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=l8cmuPO8e/awMYC6GulsABKYa4vm2Kjk7KGNkCJwmLk=; b=PGWx/MJ9CPByjXGP604ul7PDAOtCE74nMABy37h5HGFEWoOQPVIjNCnoxN0HhKyctZ jcqOjP8Y1e0bTBwTlRc/yIfLJB5tlG4o5ZixxbzviezKu2/Pzk+yEhPRgB2vYUw9Osfx dnQs7zSnHV7y7oKsBU0SVE1LO37naqG6QbRsPBhYqUmfzJN9z1vJKBhsm8Z3RMsXNCKo Hf1+IMH9Uv/WMj3tcGRSMJb48qLD4pxotUOIK0rYj7d9akrHxICETxrHk5gzgQDScuj6 JSXxVg0+xIhzTt25LoCj2psTOddMB0nc83nw5DGLBdVcdzzZ3LIqP/CXskHaBqp4rLs8 QoHA==
X-Gm-Message-State: APjAAAUungCderB/1hM1yBQkTHx7WrmnLSRFxmvRXaKcd6Aqw77UrYGh qjkbyenaYgDXIrxHuumTmKGdHWG8BoRBegT/DEiJJXO9OLA=
X-Google-Smtp-Source: APXvYqxp9TuOYSPwsgFKXwZ/IP5aTcfI4PPwqhlf2J20Ve+CsLvwq5dHYJy2L/CONfyt/IOzudtlYwtg0nY9EEeCmpU=
X-Received: by 2002:a05:6602:2241:: with SMTP id o1mr6879456ioo.129.1570090171848;  Thu, 03 Oct 2019 01:09:31 -0700 (PDT)
MIME-Version: 1.0
References: <CAPEKH5ZhcAgUP-mNU=E1+C0z4sPRLYDX=woKdCpFd-eb-LkE-g@mail.gmail.com> <CAL02cgQ330S8gsUXwbPhhU_i7_cdaEmKKLHcff3SbLc=2tsEAQ@mail.gmail.com>
In-Reply-To: <CAL02cgQ330S8gsUXwbPhhU_i7_cdaEmKKLHcff3SbLc=2tsEAQ@mail.gmail.com>
From: Pascal Junod <pascalj@snap.com>
Date: Thu, 3 Oct 2019 10:09:20 +0200
Message-ID: <CAPOUjt6FoPN6m3nTk5xq1kyfbtGA8kWsukAJ1AiC1SDCMq+ykA@mail.gmail.com>
To: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000f58d430593fd1a2b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/I9jBMiQIeTHvVIQHL-FQgNjMcvE>
Subject: Re: [MLS] Question regarding ClientInitKey message format
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Oct 2019 08:24:03 -0000

--000000000000f58d430593fd1a2b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thank you Benjamin and Richard for your quick and clear answers ! I had
missed the update in the master version and indeed, =C2=A73.4 of RFC 8446 i=
s
clear about the byte lengths.

On Wed, Oct 2, 2019 at 11:38 PM Richard Barnes <rlb@ipv.sx> wrote:

> In addition to what Benjamin said, I think you've misunderstood the
> meaning of the length indications.  The lengths indicate the size in
> *bytes*, not in *entries*.  So the ciphersuites field can hold 128 2-byte
> ciphersuites, and the init_keys can hold however many public keys will fi=
t
> in 65535 bytes.
>
> But as Benjamin said, this has all been obsoleted by more recent changes.
>
> --Richard
>
> On Wed, Oct 2, 2019 at 4:17 PM Pascal Junod <cryptopathe@gmail.com> wrote=
:
>
>> Hello,
>>
>> I am new to that list, so please accept my apologies in advance for any
>> wrong doings with respect to the list etiquette !
>>
>> I am currently reading draft-07 (Aug. 13, 2019) and something is not
>> clear to me with respect to the ClientInitKey format defined in section
>> 7. The array of ciphersuites cipher_suites is expected to have a length
>> of 0 to 255 ciphersuites, while the array of public keys init_keys is
>> expected to have between one and 65535 public keys. At the same time, an
>> above paragraph says that the init_array MUST have the same length as
>> the cipher_suites array. Shouldn't both of them having a length <1,255>
>> ? Or what did I misunderstand?
>>
>> Best,
>>
>> Pascal
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>> <https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.org_mai=
lman_listinfo_mls&d=3DDwMFaQ&c=3DncDTmphkJTvjIDPh0hpF_w&r=3DIfbwlzxh3jRRAPi=
Bazmj6w&m=3Dmn-PKj1DJNfK2Rh9tm9kieCLTE80UiEIi1WgTqcoI88&s=3D7OSo9t-7f6c0oST=
T_K93tm093Yw4WQb-1_a3uqKEMAc&e=3D>
>>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
>
> https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.org_mailm=
an_listinfo_mls&d=3DDwICAg&c=3DncDTmphkJTvjIDPh0hpF_w&r=3DIfbwlzxh3jRRAPiBa=
zmj6w&m=3Dmn-PKj1DJNfK2Rh9tm9kieCLTE80UiEIi1WgTqcoI88&s=3D7OSo9t-7f6c0oSTT_=
K93tm093Yw4WQb-1_a3uqKEMAc&e=3D
>

--000000000000f58d430593fd1a2b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thank you Benjamin and Richard for your quick and clear an=
swers ! I had missed the update in the master version and indeed, =C2=A73.4=
 of RFC 8446 is clear about the byte lengths.=C2=A0</div><br><div class=3D"=
gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 2, 2019 at 1=
1:38 PM Richard Barnes &lt;rlb@ipv.sx&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>In addition to what =
Benjamin said, I think you&#39;ve misunderstood the meaning of the length i=
ndications.=C2=A0 The lengths indicate the size in *bytes*, not in *entries=
*.=C2=A0 So the ciphersuites field can hold 128 2-byte ciphersuites, and th=
e init_keys can hold however many public keys will fit in 65535 bytes.</div=
><div><br></div><div>But as Benjamin said, this has all been obsoleted by m=
ore recent changes.</div><div><br></div><div>--Richard<br></div><br><div cl=
ass=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 2, 20=
19 at 4:17 PM Pascal Junod &lt;<a href=3D"mailto:cryptopathe@gmail.com" tar=
get=3D"_blank">cryptopathe@gmail.com</a>&gt; wrote:<br></div><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid=
 rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr">Hello,=C2=A0<div><br><=
/div><div>I am new to that list, so please accept my apologies in advance f=
or any wrong doings with respect to the list etiquette !=C2=A0</div><div><b=
r></div><div>I am currently reading <font face=3D"monospace">draft-07</font=
> (Aug. 13, 2019) and something is not clear to me with respect to the <fon=
t face=3D"monospace">ClientInitKey</font> format defined in section 7. The =
array of ciphersuites <font face=3D"monospace">cipher_suites</font> is expe=
cted to have a length of 0 to 255 ciphersuites, while the array of public k=
eys <font face=3D"monospace">init_keys</font> is expected to have between o=
ne and 65535 public keys. At the same time, an above paragraph says that th=
e <font face=3D"monospace">init_array</font> MUST have the same length as t=
he <font face=3D"monospace">cipher_suites</font> array. Shouldn&#39;t both =
of them having a length<font face=3D"monospace"> &lt;1,255&gt;</font> ? Or =
what did I misunderstand?</div><div><br></div><div>Best,=C2=A0</div><div><b=
r>Pascal</div></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.=
org_mailman_listinfo_mls&amp;d=3DDwMFaQ&amp;c=3DncDTmphkJTvjIDPh0hpF_w&amp;=
r=3DIfbwlzxh3jRRAPiBazmj6w&amp;m=3Dmn-PKj1DJNfK2Rh9tm9kieCLTE80UiEIi1WgTqco=
I88&amp;s=3D7OSo9t-7f6c0oSTT_K93tm093Yw4WQb-1_a3uqKEMAc&amp;e=3D" rel=3D"no=
referrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><b=
r>
</blockquote></div></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.=
org_mailman_listinfo_mls&amp;d=3DDwICAg&amp;c=3DncDTmphkJTvjIDPh0hpF_w&amp;=
r=3DIfbwlzxh3jRRAPiBazmj6w&amp;m=3Dmn-PKj1DJNfK2Rh9tm9kieCLTE80UiEIi1WgTqco=
I88&amp;s=3D7OSo9t-7f6c0oSTT_K93tm093Yw4WQb-1_a3uqKEMAc&amp;e=3D" rel=3D"no=
referrer" target=3D"_blank">https://urldefense.proofpoint.com/v2/url?u=3Dht=
tps-3A__www.ietf.org_mailman_listinfo_mls&amp;d=3DDwICAg&amp;c=3DncDTmphkJT=
vjIDPh0hpF_w&amp;r=3DIfbwlzxh3jRRAPiBazmj6w&amp;m=3Dmn-PKj1DJNfK2Rh9tm9kieC=
LTE80UiEIi1WgTqcoI88&amp;s=3D7OSo9t-7f6c0oSTT_K93tm093Yw4WQb-1_a3uqKEMAc&am=
p;e=3D</a> <br>
</blockquote></div>

--000000000000f58d430593fd1a2b--


From nobody Mon Oct  7 04:09:29 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C558120052 for <mls@ietfa.amsl.com>; Mon,  7 Oct 2019 04:09:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 919tT4xbHgJZ for <mls@ietfa.amsl.com>; Mon,  7 Oct 2019 04:09:26 -0700 (PDT)
Received: from mail-io1-xd36.google.com (mail-io1-xd36.google.com [IPv6:2607:f8b0:4864:20::d36]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE73512006E for <mls@ietf.org>; Mon,  7 Oct 2019 04:09:26 -0700 (PDT)
Received: by mail-io1-xd36.google.com with SMTP id q1so27637575ion.1 for <mls@ietf.org>; Mon, 07 Oct 2019 04:09:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:from:date:message-id:subject:to; bh=YvrGd0rOZPCWWNmD10/7KupMuLD3Pt+S9icCGz93e7Q=; b=UnX20iDYuEFcI3OxzuzAYLOYVFVUrnCuUOGHwQ28+KAkEIjg3TzD0J988BumJqOVTH sJRKMzM1Qg2HAmNZwiahrcWaiwxrv9NYNDKuY3jisN4gY8ovAf3sAFk2IayAZQ5FFlof DGjzi9twlc377pQ0RcmocPn7xTxfJQJg79QIs=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=YvrGd0rOZPCWWNmD10/7KupMuLD3Pt+S9icCGz93e7Q=; b=uAs5qaziGUuMCO9GDzGy+X6gLbqYFn/kIWGq8ACp2HzqRaY7FiMhunsxkUOkRrhKTd 3a7Pp9c0oExrOmdbQlS95eFzpTvvmRFB+CoUxhcLmd4aeFvnJP48Dhjix0dJMvDvdW9u Z7huGIllttlCUhH1wlmZ3SbQKqQ/D5pRznnES7U2N6AUsN5ocnrGKdlXq7AyasCdovjU VBpu8g7ybtePqvMfCW49SEiwDCJnr9NehFVIFlbBU5EX52DxPqMqVC1LnAiJyEfhZLBc FQUHky+QZg3f8JmQUJRGxM2X2JD8vqCn4gqACvHKOp891lVZfpB9vCfLekf3KKXWdpWg wUhw==
X-Gm-Message-State: APjAAAVp6SOGZRWfbFvfj5GpOt8ZsI1aM6BmFRxunR4PuWak1qLdnrqq s5SO5ap065YYtFKz+wrWOVXx4qConJEtmLpodkkD0hEYoeY=
X-Google-Smtp-Source: APXvYqzvtCQK0XYsG9ZL83T44Krl0wvTwHb1GhUyWLfmKacVliOIBdrT9XkJ6dpo7dqQ+70MKGSzalsyjgWdPXjpcUI=
X-Received: by 2002:a6b:b213:: with SMTP id b19mr22440483iof.58.1570446565689;  Mon, 07 Oct 2019 04:09:25 -0700 (PDT)
MIME-Version: 1.0
From: Pascal Junod <pascalj@snap.com>
Date: Mon, 7 Oct 2019 13:09:14 +0200
Message-ID: <CAPOUjt5LCmpR1YzgvE6a4-yNY9c+_YktC=m6D3vmVT-RYdD-Mg@mail.gmail.com>
To: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b001910594501541"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/lQ_mOxogf1bvmel-rEsa1hDFJjw>
Subject: [MLS] [ratchet tree update example]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Oct 2019 11:09:27 -0000

--000000000000b001910594501541
Content-Type: text/plain; charset="UTF-8"

Hello,

I have a quick question about the example discussed through the "Ratchet
Tree Updates" and "Synchronizing Views of the Tree" sections.

Currently, an encryption of ps[2] under public keys of nodes C and D is
described. In my opinion, it should be a single ciphertext encrypted with
public key F, whose corresponding private key is known by both C and D. Or
did I misunderstood something?

Best,

Pascal

--000000000000b001910594501541
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello,=C2=A0<div><br></div><div>I have a quick question ab=
out the example discussed through the &quot;Ratchet Tree Updates&quot; and =
&quot;Synchronizing Views of the Tree&quot; sections.=C2=A0</div><div><br><=
/div><div>Currently, an encryption of <font face=3D"monospace">ps[2]</font>=
 under public keys of nodes <font face=3D"monospace">C</font> and <font fac=
e=3D"monospace">D</font> is described. In my opinion, it should be a single=
 ciphertext encrypted with public key <font face=3D"monospace">F</font>, wh=
ose corresponding private key is known by both <font face=3D"monospace">C</=
font> and <font face=3D"monospace">D</font>. Or did I misunderstood somethi=
ng?</div><div><br></div><div>Best,=C2=A0</div><div><br></div><div>Pascal</d=
iv></div>

--000000000000b001910594501541--


From nobody Mon Oct  7 13:17:09 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 769FC12010C for <mls@ietfa.amsl.com>; Mon,  7 Oct 2019 13:17:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zo5etnG4tRyP for <mls@ietfa.amsl.com>; Mon,  7 Oct 2019 13:17:05 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1EDC212008A for <mls@ietf.org>; Mon,  7 Oct 2019 13:17:04 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,269,1566856800";  d="scan'208,217";a="321915665"
Received: from 91-167-205-91.subs.proxad.net (HELO [192.168.1.20]) ([91.167.205.91]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 07 Oct 2019 22:17:03 +0200
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <49C244DE-4B1F-4B0F-91E1-C6AEFBB35EE4@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_7E92E00C-B70D-4171-8429-42C8963CF4D8"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Mon, 7 Oct 2019 22:17:01 +0200
In-Reply-To: <CAPOUjt5LCmpR1YzgvE6a4-yNY9c+_YktC=m6D3vmVT-RYdD-Mg@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>
References: <CAPOUjt5LCmpR1YzgvE6a4-yNY9c+_YktC=m6D3vmVT-RYdD-Mg@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/SHWbJw1gRk-kOTc4IQXWvvAD3G0>
Subject: Re: [MLS] [ratchet tree update example]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Oct 2019 20:17:07 -0000

--Apple-Mail=_7E92E00C-B70D-4171-8429-42C8963CF4D8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Pascal,

I think you are right, it should indeed be a single ciphertext of ps[2] =
under pkF.
It might be that a previous example had a blanked F, which is not the =
case here.

I=E2=80=99ll double check in the morning and fix it. :)
Thanks !

B.

> On Oct 7, 2019, at 1:09 PM, Pascal Junod =
<pascalj=3D40snap.com@dmarc.ietf.org> wrote:
>=20
> Hello,=20
>=20
> I have a quick question about the example discussed through the =
"Ratchet Tree Updates" and "Synchronizing Views of the Tree" sections.=20=

>=20
> Currently, an encryption of ps[2] under public keys of nodes C and D =
is described. In my opinion, it should be a single ciphertext encrypted =
with public key F, whose corresponding private key is known by both C =
and D. Or did I misunderstood something?
>=20
> Best,=20
>=20
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_7E92E00C-B70D-4171-8429-42C8963CF4D8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Pascal,<div class=3D""><br class=3D""></div><div class=3D"">I think you =
are right, it should indeed be a single ciphertext of ps[2] under =
pkF.</div><div class=3D"">It might be that a previous example had a =
blanked F, which is not the case here.</div><div class=3D""><br =
class=3D""></div><div class=3D"">I=E2=80=99ll double check in the =
morning and fix it. :)</div><div class=3D"">Thanks !</div><div =
class=3D""><br class=3D""></div><div class=3D"">B.<br class=3D""><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On Oct =
7, 2019, at 1:09 PM, Pascal Junod &lt;<a =
href=3D"mailto:pascalj=3D40snap.com@dmarc.ietf.org" =
class=3D"">pascalj=3D40snap.com@dmarc.ietf.org</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D"">Hello,&nbsp;<div class=3D""><br class=3D""></div><div =
class=3D"">I have a quick question about the example discussed through =
the "Ratchet Tree Updates" and "Synchronizing Views of the Tree" =
sections.&nbsp;</div><div class=3D""><br class=3D""></div><div =
class=3D"">Currently, an encryption of <font face=3D"monospace" =
class=3D"">ps[2]</font> under public keys of nodes <font =
face=3D"monospace" class=3D"">C</font> and <font face=3D"monospace" =
class=3D"">D</font> is described. In my opinion, it should be a single =
ciphertext encrypted with public key <font face=3D"monospace" =
class=3D"">F</font>, whose corresponding private key is known by both =
<font face=3D"monospace" class=3D"">C</font> and <font face=3D"monospace" =
class=3D"">D</font>. Or did I misunderstood something?</div><div =
class=3D""><br class=3D""></div><div class=3D"">Best,&nbsp;</div><div =
class=3D""><br class=3D""></div><div class=3D"">Pascal</div></div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_7E92E00C-B70D-4171-8429-42C8963CF4D8--


From nobody Tue Oct  8 00:33:28 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 49A1E120106 for <mls@ietfa.amsl.com>; Tue,  8 Oct 2019 00:33:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.748
X-Spam-Level: 
X-Spam-Status: No, score=-1.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QJ6QBH6nsa0C for <mls@ietfa.amsl.com>; Tue,  8 Oct 2019 00:33:24 -0700 (PDT)
Received: from mail-io1-xd29.google.com (mail-io1-xd29.google.com [IPv6:2607:f8b0:4864:20::d29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 46D751200F4 for <mls@ietf.org>; Tue,  8 Oct 2019 00:33:24 -0700 (PDT)
Received: by mail-io1-xd29.google.com with SMTP id u8so34417562iom.5 for <mls@ietf.org>; Tue, 08 Oct 2019 00:33:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=7wZxwDicWjBYDj3N8LQPF2cO6JWZp5jVVnctkzgwDqU=; b=GtWhN92Ve0rdMWFQZJiZs5qMP829aWPEJtEgHMPMv61cY/jvganb/Hf49ZyAaSkdNN b8c28fBtIUvDvRL2eztA6UxP7oEX2ucdONsudtJizxi0/IwI/MJ2xanpPf2oMHQgb5p7 sXyMJz5iBg9jP/ekGJI5UuVbY8dPCR8F/WKYQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=7wZxwDicWjBYDj3N8LQPF2cO6JWZp5jVVnctkzgwDqU=; b=JZR6xZTOdA3wneiyEPdwYBjRdFi1OhZt25/bLfhWhRMshLEFv85s1j1sWgsriGYysf 9WwIfjw3oqTKsE5dQbud8JH1ZI0Q7JChGQwpHNf8gS+/vUSdEcJnnfbAZLNefIpXRe2n zp17KL4mA+U78F/4+miAS2gsnV1mGx3gdFLUSJgx2kFrkesB1JMIaUWEOc5QFRnTlDvD dY/sf9BJxpObo2fbWc8HMBP81epbFg0UcN2uCtWT6zEzt7+Qg1sNxUGkeeh7jQBN6MW+ ZGjtXTccCvg4KOqEsRCw4rfA6Qv9RLSEmQPwUaoAOx8VAWDZ/SycVsqWY5IWOhEK32zJ xjxw==
X-Gm-Message-State: APjAAAXdqfzJCdCbI2ZzGRiTFMZMme7XmMnjGzNv/xrqqKaT0whrvEef qfjk4FXYwVM5nzCYUs/HniSQxl3v7em/dUR9c/swrQ==
X-Google-Smtp-Source: APXvYqzEGPwVbij+KrZMWZCRAKeoMV0dejJrfxgRbk/EB5YqjKVeX1IEYqYe8+8SYyn3zLnuC1Deqh7pdh+F00hRSUI=
X-Received: by 2002:a6b:7802:: with SMTP id j2mr28429582iom.71.1570520003442;  Tue, 08 Oct 2019 00:33:23 -0700 (PDT)
MIME-Version: 1.0
References: <CAPOUjt5LCmpR1YzgvE6a4-yNY9c+_YktC=m6D3vmVT-RYdD-Mg@mail.gmail.com> <49C244DE-4B1F-4B0F-91E1-C6AEFBB35EE4@inria.fr>
In-Reply-To: <49C244DE-4B1F-4B0F-91E1-C6AEFBB35EE4@inria.fr>
From: Pascal Junod <pascalj@snap.com>
Date: Tue, 8 Oct 2019 09:33:12 +0200
Message-ID: <CAPOUjt6y5umCrTG5w+qBBKhcOq-H=48ja4yL0SbLMMYhRz90Vg@mail.gmail.com>
To: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Cc: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>,  ML Messaging Layer Security <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000eb29550594612e6e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/pEDuRDza0Ksid680Uvb-sOH16-U>
Subject: Re: [MLS] [ratchet tree update example]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Oct 2019 07:33:27 -0000

--000000000000eb29550594612e6e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thank you for the quick feedback! I just pushed a PR fixing the spec
document.

On Mon, Oct 7, 2019 at 10:17 PM Benjamin Beurdouche <
benjamin.beurdouche@inria.fr> wrote:

> Hi Pascal,
>
> I think you are right, it should indeed be a single ciphertext of ps[2]
> under pkF.
> It might be that a previous example had a blanked F, which is not the cas=
e
> here.
>
> I=E2=80=99ll double check in the morning and fix it. :)
> Thanks !
>
> B.
>
> On Oct 7, 2019, at 1:09 PM, Pascal Junod <
> pascalj=3D40snap.com@dmarc.ietf.org> wrote:
>
> Hello,
>
> I have a quick question about the example discussed through the "Ratchet
> Tree Updates" and "Synchronizing Views of the Tree" sections.
>
> Currently, an encryption of ps[2] under public keys of nodes C and D is
> described. In my opinion, it should be a single ciphertext encrypted with
> public key F, whose corresponding private key is known by both C and D.
> Or did I misunderstood something?
>
> Best,
>
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
>
> https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.org_mailm=
an_listinfo_mls&d=3DDwICAg&c=3DncDTmphkJTvjIDPh0hpF_w&r=3DIfbwlzxh3jRRAPiBa=
zmj6w&m=3DUrq9OlsiBHujJ-r9Sa8W0KV4HplKu2CZ0WZ88Jy0Y-g&s=3DelJcaMuyOOyES0Trm=
QmvKlDEp7VP9-AFFxw5IWYqqJg&e=3D
>

--000000000000eb29550594612e6e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thank you for the quick feedback! I just pushed a PR fixin=
g the spec document.</div><br><div class=3D"gmail_quote"><div dir=3D"ltr" c=
lass=3D"gmail_attr">On Mon, Oct 7, 2019 at 10:17 PM Benjamin Beurdouche &lt=
;<a href=3D"mailto:benjamin.beurdouche@inria.fr">benjamin.beurdouche@inria.=
fr</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margi=
n:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex=
"><div style=3D"overflow-wrap: break-word;">Hi Pascal,<div><br></div><div>I=
 think you are right, it should indeed be a single ciphertext of ps[2] unde=
r pkF.</div><div>It might be that a previous example had a blanked F, which=
 is not the case here.</div><div><br></div><div>I=E2=80=99ll double check i=
n the morning and fix it. :)</div><div>Thanks !</div><div><br></div><div>B.=
<br><div><br><blockquote type=3D"cite"><div>On Oct 7, 2019, at 1:09 PM, Pas=
cal Junod &lt;<a href=3D"mailto:pascalj=3D40snap.com@dmarc.ietf.org" target=
=3D"_blank">pascalj=3D40snap.com@dmarc.ietf.org</a>&gt; wrote:</div><br><di=
v><div dir=3D"ltr">Hello,=C2=A0<div><br></div><div>I have a quick question =
about the example discussed through the &quot;Ratchet Tree Updates&quot; an=
d &quot;Synchronizing Views of the Tree&quot; sections.=C2=A0</div><div><br=
></div><div>Currently, an encryption of <font face=3D"monospace">ps[2]</fon=
t> under public keys of nodes <font face=3D"monospace">C</font> and <font f=
ace=3D"monospace">D</font> is described. In my opinion, it should be a sing=
le ciphertext encrypted with public key <font face=3D"monospace">F</font>, =
whose corresponding private key is known by both <font face=3D"monospace">C=
</font> and <font face=3D"monospace">D</font>. Or did I misunderstood somet=
hing?</div><div><br></div><div>Best,=C2=A0</div><div><br></div><div>Pascal<=
/div></div>
_______________________________________________<br>MLS mailing list<br><a h=
ref=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><a href=
=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://ww=
w.ietf.org/mailman/listinfo/mls</a><br></div></blockquote></div><br></div><=
/div>_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://urldefense.proofpoint.com/v2/url?u=3Dhttps-3A__www.ietf.=
org_mailman_listinfo_mls&amp;d=3DDwICAg&amp;c=3DncDTmphkJTvjIDPh0hpF_w&amp;=
r=3DIfbwlzxh3jRRAPiBazmj6w&amp;m=3DUrq9OlsiBHujJ-r9Sa8W0KV4HplKu2CZ0WZ88Jy0=
Y-g&amp;s=3DelJcaMuyOOyES0TrmQmvKlDEp7VP9-AFFxw5IWYqqJg&amp;e=3D" rel=3D"no=
referrer" target=3D"_blank">https://urldefense.proofpoint.com/v2/url?u=3Dht=
tps-3A__www.ietf.org_mailman_listinfo_mls&amp;d=3DDwICAg&amp;c=3DncDTmphkJT=
vjIDPh0hpF_w&amp;r=3DIfbwlzxh3jRRAPiBazmj6w&amp;m=3DUrq9OlsiBHujJ-r9Sa8W0KV=
4HplKu2CZ0WZ88Jy0Y-g&amp;s=3DelJcaMuyOOyES0TrmQmvKlDEp7VP9-AFFxw5IWYqqJg&am=
p;e=3D</a> <br>
</blockquote></div>

--000000000000eb29550594612e6e--


From nobody Thu Oct 10 07:02:31 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7898D1200A3 for <mls@ietfa.amsl.com>; Thu, 10 Oct 2019 07:02:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7S9G1MwaXUV4 for <mls@ietfa.amsl.com>; Thu, 10 Oct 2019 07:02:28 -0700 (PDT)
Received: from mail-io1-xd2a.google.com (mail-io1-xd2a.google.com [IPv6:2607:f8b0:4864:20::d2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4ED10120099 for <mls@ietf.org>; Thu, 10 Oct 2019 07:02:28 -0700 (PDT)
Received: by mail-io1-xd2a.google.com with SMTP id v2so13866948iob.10 for <mls@ietf.org>; Thu, 10 Oct 2019 07:02:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:from:date:message-id:subject:to; bh=FvQCJPezF2LCZXKFG0vlX8+Sha+NRmTpxgzYxgeWOlc=; b=IMjiX1rZJfot449IebMsZFe+B40RLSD5BFHZxSgQ8r3Mt56j7WnRTPxeYSVs12B1RP yvku9JvKAy+9u+U7tIgaW1xg8vwkhym7G6Gdu5snVhZYqCodYOOEcOfQvsEJTJMySkxX +gwwEAjwZoD8bljgWFCDyTtEIiXMa8OV/rdQA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=FvQCJPezF2LCZXKFG0vlX8+Sha+NRmTpxgzYxgeWOlc=; b=T88SkzaWisSu/G24kJo1O9z7hDLVTqFf6/tDr6Fbvddw2iT4Cy3ALV/34pvNTnZBm/ o+t1GPDeWbOCy+vMabMy/WYj74y3kcGsMB8hnu9sArkjQ1f20xfe6fC5QaA8dEvcfZwH vWpm7xBNAnkD9LHcZ7K3ho152nDgrxhS11/zRav1off6k4mOq6lZv2A3XbPev4pDnmf6 GzAq3y1dKgzSbz07ywkr/UWc8fHhYg9oqG0XeIlgumuvrjAiHgGLG2R4asc145va/XUz J1b1ZDPse8dR9eOOSoLABThF8l69FBtLT+9b1XSPuoeYQmguX3CmKVkCgq7KT2B2G6SE B7FA==
X-Gm-Message-State: APjAAAWf6niylLu4VT7DvBBwQAYtrVFILkeN5AcCh4mJvPNfjozY5hcz uENLQasczS5YHpMtp/yklZax4gsVqzbqZLumOmcMDMJx2Ys=
X-Google-Smtp-Source: APXvYqyesx3k5nFrfOEeeu69HP2kJ9s7bZ4dOY71ypFJMOguWiUQCNC+wlZrRs9ul9Lt2mx89JDWdc2uftfYGTjJ0qM=
X-Received: by 2002:a02:ba8d:: with SMTP id g13mr10453578jao.93.1570716147171;  Thu, 10 Oct 2019 07:02:27 -0700 (PDT)
MIME-Version: 1.0
From: Pascal Junod <pascalj@snap.com>
Date: Thu, 10 Oct 2019 16:02:16 +0200
Message-ID: <CAPOUjt7K4_sCfnA5zjOBTSDaHZVrvG5mqLB-jZ14yMQMZe7Avw@mail.gmail.com>
To: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fee6aa05948ed99d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/PYT_Cg6Ie5I-bO50l2wQvVWHXj8>
Subject: [MLS] [interim_transcript_hash]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Oct 2019 14:02:30 -0000

--000000000000fee6aa05948ed99d
Content-Type: text/plain; charset="UTF-8"

Hi !

Just wondering whether there is a reason why the interim_transcript_hash
value (necessary to build Welcome messages) value is not contained into the
GroupContext structure.

Best,

Pascal

--000000000000fee6aa05948ed99d
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi !<div><br></div><div>Just wondering whether there is a =
reason why the <font face=3D"monospace">interim_transcript_hash</font> valu=
e (necessary to build <font face=3D"monospace">Welcome</font> messages) val=
ue is not contained into the <font face=3D"monospace">GroupContext</font> s=
tructure.=C2=A0</div><div><br></div><div>Best,=C2=A0</div><div><br></div><d=
iv>Pascal</div></div>

--000000000000fee6aa05948ed99d--


From nobody Fri Oct 11 06:54:14 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04B5E120073 for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 06:54:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level: 
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Jwz_gRLbJvr for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 06:54:11 -0700 (PDT)
Received: from mail-ot1-x32a.google.com (mail-ot1-x32a.google.com [IPv6:2607:f8b0:4864:20::32a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4ECAF12003F for <mls@ietf.org>; Fri, 11 Oct 2019 06:54:11 -0700 (PDT)
Received: by mail-ot1-x32a.google.com with SMTP id 89so7987453oth.13 for <mls@ietf.org>; Fri, 11 Oct 2019 06:54:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=eRfUIB25DmoGshmODLTYj0cqQfok3y6ABH3uDROBzvY=; b=KIs2yuHcPN8V7YNH3pf0NtPvIv2Za8mayIZVun8IIYhV9hyHypPogWVz/IGP1qfo6V ZzvgXuOB6X9Bm9qAH2zSyM5IpDl09R5V9G5lOT+7I+UOqdk6NSQ2I0lC0HawAN2Uo1x0 afbduXvHE2PY6zoMcP+bYOKpPc4x9vmUFl7YhL0C9BWvwD91fe+gmrLq2iz+9Tmf92Z9 7CdH1z2RJqshXx8lsq9MjZ6JEy5BdtbzZZlRSbsF9abYBEQc488WEB8T9IDnkYN13X1O Vdn6IUxx1KRRcN9dCf31iAV/USxByD82toi5lfcyjFlcwwNT8Rr8G0sTId9zx8Qfs5rH E5gA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=eRfUIB25DmoGshmODLTYj0cqQfok3y6ABH3uDROBzvY=; b=QFsl0lfqgb30xf1OkPUttEt8NqxnvTc0NBDaCnTEnA977CYK4d7NwU20fmkYfmSlSh 0+FOpBh/auzLuPwDjzkw7EnclGM0Dylkzi2s2OmCrMrs2Hsm/1QU2I/nPIiErsqdrNTu VoM6UDCs1oX5NzQiBVTiyZFn5Qd+i4Dvs8mdBlaLSh2Pp1tQ+8CzKdFmqB0wcewrFEYS pUxhpc7ETnjFkJ0a+siXlu7cxVwhDH8DAaeG7SGkXriffE0FSmYHYd/LmAANHIex7oCO jl/7RMiE8BCrLguZDZFx3D388q/LwRpahr1D9zHDNPMTIG2YiZeziZ0c1pxLYOvc67Vr IwmQ==
X-Gm-Message-State: APjAAAW0JDCH5p3NwRiJBND2RrnrVcMdEpnojSNvn5WCniNtxlxWYOXf xuijyyjqOg0S9y0o2hjVv5L6d58j/cPwySSKdf/2inuY
X-Google-Smtp-Source: APXvYqzefCuLEswnnz9MlTx9BAOzN3Oosq/huhC8rGsXD+9aFIew/JzkDhWtbyHBvxg6rWyYwOnto1w8zXXaIgeQoqM=
X-Received: by 2002:a9d:4613:: with SMTP id y19mr12109870ote.159.1570802050397;  Fri, 11 Oct 2019 06:54:10 -0700 (PDT)
MIME-Version: 1.0
References: <CAPOUjt7K4_sCfnA5zjOBTSDaHZVrvG5mqLB-jZ14yMQMZe7Avw@mail.gmail.com>
In-Reply-To: <CAPOUjt7K4_sCfnA5zjOBTSDaHZVrvG5mqLB-jZ14yMQMZe7Avw@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Fri, 11 Oct 2019 09:53:59 -0400
Message-ID: <CAL02cgTEdnjbg5c4psAgOCgJ_hBxrYmgCxJ5xoJjSJW7vVgO-Q@mail.gmail.com>
To: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000003a0b550594a2daae"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/GADOzbD8Y6GFy2pRbVBnKDFqZes>
Subject: Re: [MLS] [interim_transcript_hash]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Oct 2019 13:54:13 -0000

--0000000000003a0b550594a2daae
Content-Type: text/plain; charset="UTF-8"

Because if you did that, then you would have a circular dependency:

interim_transcript_hash
<= MLSPlaintext.confirmation
<= confirmation_key
<= GroupContext (via DeriveSecret)
<= interim_transcript_hash

This was a problem in earlier versions!

On Thu, Oct 10, 2019 at 10:02 Pascal Junod <pascalj=
40snap.com@dmarc.ietf.org> wrote:

> Hi !
>
> Just wondering whether there is a reason why the interim_transcript_hash
> value (necessary to build Welcome messages) value is not contained into
> the GroupContext structure.
>
> Best,
>
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000003a0b550594a2daae
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div><div dir=3D"auto">Because if you did that, then you would have a circu=
lar dependency:</div><div dir=3D"auto"><br></div><div dir=3D"auto">interim_=
transcript_hash</div><div dir=3D"auto">&lt;=3D MLSPlaintext.confirmation</d=
iv><div dir=3D"auto">&lt;=3D confirmation_key</div><div dir=3D"auto">&lt;=
=3D GroupContext (via DeriveSecret)</div><div dir=3D"auto">&lt;=3D interim_=
transcript_hash</div><div dir=3D"auto"><br></div><div dir=3D"auto">This was=
 a problem in earlier versions!</div><br><div class=3D"gmail_quote"><div di=
r=3D"ltr" class=3D"gmail_attr">On Thu, Oct 10, 2019 at 10:02 Pascal Junod &=
lt;pascalj=3D<a href=3D"mailto:40snap.com@dmarc.ietf.org">40snap.com@dmarc.=
ietf.org</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D=
"ltr">Hi !<div><br></div><div>Just wondering whether there is a reason why =
the <font face=3D"monospace">interim_transcript_hash</font> value (necessar=
y to build <font face=3D"monospace">Welcome</font> messages) value is not c=
ontained into the <font face=3D"monospace">GroupContext</font> structure.=
=C2=A0</div><div><br></div><div>Best,=C2=A0</div><div><br></div><div>Pascal=
</div></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div></div>

--0000000000003a0b550594a2daae--


From nobody Fri Oct 11 07:06:00 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D9871200B4 for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 07:05:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xAF46BVgKZh4 for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 07:05:53 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8B23712003F for <mls@ietf.org>; Fri, 11 Oct 2019 07:05:52 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,284,1566856800";  d="scan'208,217";a="405787892"
Received: from 82-64-165-115.subs.proxad.net (HELO [192.168.1.20]) ([82.64.165.115]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 11 Oct 2019 16:05:50 +0200
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <2050710D-078C-4DA4-B628-362DE154C30D@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_67A1E59B-C3E4-46A6-A366-20C69276EE27"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
Date: Fri, 11 Oct 2019 16:05:49 +0200
In-Reply-To: <CAL02cgTEdnjbg5c4psAgOCgJ_hBxrYmgCxJ5xoJjSJW7vVgO-Q@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>, Richard Barnes <rlb@ipv.sx>
To: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>
References: <CAPOUjt7K4_sCfnA5zjOBTSDaHZVrvG5mqLB-jZ14yMQMZe7Avw@mail.gmail.com> <CAL02cgTEdnjbg5c4psAgOCgJ_hBxrYmgCxJ5xoJjSJW7vVgO-Q@mail.gmail.com>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/OpAONXmDk4b8Z21vTElyPn88S10>
Subject: Re: [MLS] [interim_transcript_hash]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Oct 2019 14:05:57 -0000

--Apple-Mail=_67A1E59B-C3E4-46A6-A366-20C69276EE27
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Pascal,

Note that it is a technicality due to a set of successive change that =
lead to
the current design, our proofs don=E2=80=99t rely on such complicated =
GroupContext
and interim transcript but only on the hash of the transcript itself.

I promised I would spend the time on fixing this but I haven=E2=80=99t =
find it yet.
I=E2=80=99ll do a PR to fix it within the next few weeks.

B.


> On Oct 11, 2019, at 3:53 PM, Richard Barnes <rlb@ipv.sx> wrote:
>=20
> Because if you did that, then you would have a circular dependency:
>=20
> interim_transcript_hash
> <=3D MLSPlaintext.confirmation
> <=3D confirmation_key
> <=3D GroupContext (via DeriveSecret)
> <=3D interim_transcript_hash
>=20
> This was a problem in earlier versions!
>=20
> On Thu, Oct 10, 2019 at 10:02 Pascal Junod =
<pascalj=3D40snap.com@dmarc.ietf.org <mailto:40snap.com@dmarc.ietf.org>> =
wrote:
> Hi !
>=20
> Just wondering whether there is a reason why the =
interim_transcript_hash value (necessary to build Welcome messages) =
value is not contained into the GroupContext structure.=20
>=20
> Best,=20
>=20
> Pascal
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_67A1E59B-C3E4-46A6-A366-20C69276EE27
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><div =
class=3D"">Hi Pascal,</div><div class=3D""><br class=3D""></div>Note =
that it is a technicality due to a set of successive change that lead =
to<div class=3D"">the current design, our proofs don=E2=80=99t rely on =
such complicated GroupContext</div><div class=3D"">and interim =
transcript but only on the hash of the transcript itself.<div =
class=3D""><div><br class=3D""></div><div>I promised I would spend the =
time on fixing this but I haven=E2=80=99t find it yet.</div><div>I=E2=80=99=
ll do a PR to fix it within the next few weeks.</div><div><br =
class=3D""></div><div>B.</div><div><br class=3D""></div><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On Oct =
11, 2019, at 3:53 PM, Richard Barnes &lt;<a href=3D"mailto:rlb@ipv.sx" =
class=3D"">rlb@ipv.sx</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div class=3D""><div =
dir=3D"auto" class=3D"">Because if you did that, then you would have a =
circular dependency:</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" =
class=3D"">interim_transcript_hash</div><div dir=3D"auto" class=3D"">&lt;=3D=
 MLSPlaintext.confirmation</div><div dir=3D"auto" class=3D"">&lt;=3D =
confirmation_key</div><div dir=3D"auto" class=3D"">&lt;=3D GroupContext =
(via DeriveSecret)</div><div dir=3D"auto" class=3D"">&lt;=3D =
interim_transcript_hash</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">This was a problem in =
earlier versions!</div><br class=3D""><div class=3D"gmail_quote"><div =
dir=3D"ltr" class=3D"gmail_attr">On Thu, Oct 10, 2019 at 10:02 Pascal =
Junod &lt;pascalj=3D<a href=3D"mailto:40snap.com@dmarc.ietf.org" =
class=3D"">40snap.com@dmarc.ietf.org</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" =
class=3D"">Hi !<div class=3D""><br class=3D""></div><div class=3D"">Just =
wondering whether there is a reason why the <font face=3D"monospace" =
class=3D"">interim_transcript_hash</font> value (necessary to build =
<font face=3D"monospace" class=3D"">Welcome</font> messages) value is =
not contained into the <font face=3D"monospace" =
class=3D"">GroupContext</font> structure.&nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">Best,&nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">Pascal</div></div>
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br =
class=3D""></div></div></body></html>=

--Apple-Mail=_67A1E59B-C3E4-46A6-A366-20C69276EE27--


From nobody Fri Oct 11 07:07:51 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C8410120073 for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 07:07:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level: 
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lEmSMB0GcVjO for <mls@ietfa.amsl.com>; Fri, 11 Oct 2019 07:07:49 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9ADE712003F for <mls@ietf.org>; Fri, 11 Oct 2019 07:07:48 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,284,1566856800"; d="scan'208";a="405788068"
Received: from 82-64-165-115.subs.proxad.net (HELO [192.168.1.20]) ([82.64.165.115]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 11 Oct 2019 16:06:46 +0200
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
In-Reply-To: <2050710D-078C-4DA4-B628-362DE154C30D@inria.fr>
Date: Fri, 11 Oct 2019 16:06:45 +0200
Cc: Richard Barnes <rlb@ipv.sx>, ML Messaging Layer Security <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <6DC74783-CCEA-4B54-9602-8DC620C7C6B6@inria.fr>
References: <CAPOUjt7K4_sCfnA5zjOBTSDaHZVrvG5mqLB-jZ14yMQMZe7Avw@mail.gmail.com> <CAL02cgTEdnjbg5c4psAgOCgJ_hBxrYmgCxJ5xoJjSJW7vVgO-Q@mail.gmail.com> <2050710D-078C-4DA4-B628-362DE154C30D@inria.fr>
To: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/WJ4vJC6qGQh5BJLF68YXQ0hld-I>
Subject: Re: [MLS] [interim_transcript_hash]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Oct 2019 14:07:50 -0000

> I promised I would spend the time on fixing this but I haven=E2=80=99t =
find it yet.

*found, sorry : )=


From nobody Tue Oct 15 08:57:12 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74074120879 for <mls@ietfa.amsl.com>; Tue, 15 Oct 2019 08:57:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level: 
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yxul4xpPL8H4 for <mls@ietfa.amsl.com>; Tue, 15 Oct 2019 08:57:04 -0700 (PDT)
Received: from mail-ot1-x32b.google.com (mail-ot1-x32b.google.com [IPv6:2607:f8b0:4864:20::32b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7A0CD120815 for <mls@ietf.org>; Tue, 15 Oct 2019 08:57:04 -0700 (PDT)
Received: by mail-ot1-x32b.google.com with SMTP id o44so17355545ota.10 for <mls@ietf.org>; Tue, 15 Oct 2019 08:57:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:from:date:message-id:subject:to; bh=yt9NnXd986D+I6nQr8JbhlQwPWpWj7Oz7tJSaVKONlw=; b=e3do2pYTV+4GSLNFtIsxL26DPzmEs4Pz1jt76UAdXlLisTPSUvA9gXCqTzuMIIxbIA X78Pud7VMl6V3TkIfeH0+rwtF1v5c4kaADIIKDV01YcV4x3GrkTh0cxa2XhYnHTcFfTr mR+x+BkD7tw/zOq/Y2ADJyzlv5uLTTL6KpzWZIz6b+hMzfp5eFtf/52w3RcnSuCjaGrp Ft0O7eaVe+CCPr3jPFL3CGO0MdSr0hfQ0Y2c1ke4vmOQBwVZyHAwSxfe0zulJwF0Lf2V mhnvXe08Vnt9CJJgrStG+C13kRHyZ3P3iWbDkKvJuorfBy2Ctv4hLP92n93WUWbCu9Kk ilYg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=yt9NnXd986D+I6nQr8JbhlQwPWpWj7Oz7tJSaVKONlw=; b=hyYx+dPcrZQyzRoHmeVzVE4lMQOahEyAE1sCqLxll8/4QCwe4NW9VpYamo/56rl5yj 5UVHBnh5ya0w/RR76LLnpkmps48Kgi9iIy97xhKme48rJYf23cixxGRCZXfBxorjiP2y e+nR/4b5aM1GRkJFHZ1SQdxM+NY4rij8dDpPdzx4tfpL6HSf67g4E1vax574+Paba1kT R0Zb+jICUPkTqiY1BqLZvXnm1CWPvOiYa2BXIH4KuhCf3tWcP39HYQqTYHJY/BAIwApF oEZKVLwJfZEzqHszViNyz3uG7ZL8gKlZIenDYUdz+YIXv8iBp619AsqyZmKs/qVljIfu Hz2g==
X-Gm-Message-State: APjAAAXP+X5IjpP/8MGNaGvc/gFA8gHSvWwVjFx1smTAyojsbBnHVC5x slV+iyuJbfT66bXVvPtx2x1n8jo6Ll7c4oJfzgJwULWa
X-Google-Smtp-Source: APXvYqyC8oz7HOCTc0yFiHSSoKrBRbEL0tKshM5X5ANtiIYlb+OJ0TunQvZ182pQvipZ7e82c1lmM2f7AlNmO/G2hQo=
X-Received: by 2002:a9d:550a:: with SMTP id l10mr432964oth.93.1571155023287; Tue, 15 Oct 2019 08:57:03 -0700 (PDT)
MIME-Version: 1.0
From: Richard Barnes <rlb@ipv.sx>
Date: Tue, 15 Oct 2019 11:56:49 -0400
Message-ID: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
To: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000000ceb7c0594f50955"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/cX2SZVHphamTjvLvqG8ReM2nhJU>
Subject: [MLS] Some data
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Oct 2019 15:57:11 -0000

--0000000000000ceb7c0594f50955
Content-Type: text/plain; charset="UTF-8"

Hey all,

I've managed to extract histories for a collection of Webex Teams groups, a
total of 950 groups (including 1-1 conversations) ranging in size from 2 to
5000 members.

What data would people be interested in understanding from this data set?

I'm currently working on extracting "transcripts" of
init/add/remove/message events, with the idea that they could be fed into a
simulator attached to some library to generate counts of actual crypto
operations.  But it would also be easy to extract summary statistics, such
as the inter-arrival rates for Adds / Removes, Add:Remove ratios, etc.

One caveat is that Webex Teams allows self-add and self-remove, in addition
to adds/removes initiated by someone in the group.  Self-adds account for
~6% of all adds, but self-removes (leaves) are 98% of all removes.  The
latter might be an artifact of "server-initiated" removes being reflected
as self-removes, but of course server-initiated removes have similar issues
w.r.t. MLS.

--Richard

--0000000000000ceb7c0594f50955
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hey all,</div><div><br></div><div>I&#39;ve managed to=
 extract histories for a collection of Webex Teams groups, a total of 950 g=
roups (including 1-1 conversations) ranging in size from 2 to 5000 members.=
</div><div><br></div><div>What data would people be interested in understan=
ding from this data set?=C2=A0 <br></div><div><br></div><div>I&#39;m curren=
tly working on extracting &quot;transcripts&quot; of init/add/remove/messag=
e events, with the idea that they could be fed into a simulator attached to=
 some library to generate counts of actual crypto operations.=C2=A0 But it =
would also be easy to extract summary statistics, such as the inter-arrival=
 rates for Adds / Removes, Add:Remove ratios, etc.</div><div><br></div><div=
>One caveat is that Webex Teams allows self-add and self-remove, in additio=
n to adds/removes initiated by someone in the group.=C2=A0 Self-adds accoun=
t for ~6% of all adds, but self-removes (leaves) are 98% of all removes.=C2=
=A0 The latter might be an artifact of &quot;server-initiated&quot; removes=
 being reflected as self-removes, but of course server-initiated removes ha=
ve similar issues w.r.t. MLS.</div><div><br></div><div>--Richard<br></div><=
/div>

--0000000000000ceb7c0594f50955--


From nobody Wed Oct 16 14:27:34 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 270B2120833 for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:27:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4QC1oQo1gY_G for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:27:28 -0700 (PDT)
Received: from mail-pf1-x434.google.com (mail-pf1-x434.google.com [IPv6:2607:f8b0:4864:20::434]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 48A7D120823 for <mls@ietf.org>; Wed, 16 Oct 2019 14:27:28 -0700 (PDT)
Received: by mail-pf1-x434.google.com with SMTP id x127so188443pfb.7 for <mls@ietf.org>; Wed, 16 Oct 2019 14:27:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=MTy2Vc7vkneEcJaGGPJt/V/LrgQDHN1wtTMwPzvDxQw=; b=SYuin++kWQLBQsg7k/Wj8wD3u1TbVjNYaYqXiBib7610JAsgx8jB0eT5d/3GlR877z EQurJk1eht8P4KtFJSyeqRRB1dOqBKEqP9KvVTJ4cF7q8MmIPUcP+R1ew79DEvECSnhI hTcM6LWf+BcjPnHF0spofdPv6JrUImA/Azn7g=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=MTy2Vc7vkneEcJaGGPJt/V/LrgQDHN1wtTMwPzvDxQw=; b=ep5iNdhmh2Gd8e7sRDsgVyOlYTzED/RkuS2V403t8j5+wJGFxsuAhDhw3kG5dE/BjP b0awqqLf+YZanN2JlMp9utlVWntONNZO0G7n0JGYIQ64aW8LTc9R9ocAqzHX/iH8rtDA 5MpshGtUGdvZCS1LJYG8t/akRJKPGIJ3dy4p5CXNdwhH9AtQ2Sy2q02CIRBJVS9zuv9x sDjsBhebUS2yxtNv2QEtaAIqTCv9zNBbisnA9/PCtUhoynl8/JZSKFEtqs8KHLxMjNbg NR0Fwk4EAmSfiWm+euD9uwwgxwZDbJijHrc5iKgCpBWtJ6s8+IhfMjLJdLZ8b58v5h+E XMhg==
X-Gm-Message-State: APjAAAU3xqzxwYE9mN2g16OdfIhAGbGkhEEi+HhG1Q55Bg+yTdARV6wO iMkFibus7fqngpkhrRy9UPUDTQ==
X-Google-Smtp-Source: APXvYqxs4PRvRfc+GI4CkW6JpVr7GyIpz/jKqScaakb/GijCCa0TmsSm0SRIA6Blpc8q4uBFuau2+g==
X-Received: by 2002:a17:90a:80ca:: with SMTP id k10mr58687pjw.35.1571261247286;  Wed, 16 Oct 2019 14:27:27 -0700 (PDT)
Received: from [10.0.0.176] (c-69-181-121-166.hsd1.ca.comcast.net. [69.181.121.166]) by smtp.gmail.com with ESMTPSA id i190sm31949553pgc.93.2019.10.16.14.27.26 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Oct 2019 14:27:26 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Brendan McMillion <brendan@cloudflare.com>
In-Reply-To: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
Date: Wed, 16 Oct 2019 14:27:25 -0700
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <0C5225D1-FB07-4EB4-BFCD-D36D5F79A76A@cloudflare.com>
References: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/4bbzWtfoNedRstm9cFu8PKyTu38>
Subject: Re: [MLS] Some data
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Oct 2019 21:27:31 -0000

This is great!

I=E2=80=99d love to understand:
- The distribution of message sizes (message =3D what the user actually =
types)
- Does WebEx Teams use a sub-protocol for messaging metadata, like XMPP? =
How much overhead does it add?
- How important do WebEx engineers consider compression? Given that =
human language / XML can have such high compression ratios

> On Oct 15, 2019, at 8:56 AM, Richard Barnes <rlb@ipv.sx> wrote:
>=20
> Hey all,
>=20
> I've managed to extract histories for a collection of Webex Teams =
groups, a total of 950 groups (including 1-1 conversations) ranging in =
size from 2 to 5000 members.
>=20
> What data would people be interested in understanding from this data =
set? =20
>=20
> I'm currently working on extracting "transcripts" of =
init/add/remove/message events, with the idea that they could be fed =
into a simulator attached to some library to generate counts of actual =
crypto operations.  But it would also be easy to extract summary =
statistics, such as the inter-arrival rates for Adds / Removes, =
Add:Remove ratios, etc.
>=20
> One caveat is that Webex Teams allows self-add and self-remove, in =
addition to adds/removes initiated by someone in the group.  Self-adds =
account for ~6% of all adds, but self-removes (leaves) are 98% of all =
removes.  The latter might be an artifact of "server-initiated" removes =
being reflected as self-removes, but of course server-initiated removes =
have similar issues w.r.t. MLS.
>=20
> --Richard
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


From nobody Wed Oct 16 14:38:41 2019
Return-Path: <pag225@cornell.edu>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 805DF1208A1 for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:38:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cornell.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4bHYIaohx4Oc for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:38:38 -0700 (PDT)
Received: from mail-io1-xd2c.google.com (mail-io1-xd2c.google.com [IPv6:2607:f8b0:4864:20::d2c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D1E412089C for <mls@ietf.org>; Wed, 16 Oct 2019 14:38:38 -0700 (PDT)
Received: by mail-io1-xd2c.google.com with SMTP id c25so324229iot.12 for <mls@ietf.org>; Wed, 16 Oct 2019 14:38:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cornell.edu; s=g.20171207; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=gjQHOBcm2mr8xMsvcbCgyYPtqumFK2l99APzVt0935g=; b=aV4+0gYjLlEDGgK7qXLOLGntn1t8PfKAHUPvEj57Jmiijch+XqAmITms4CLpXakNag wwFkRV0JtgJU8ppIjivbv46nrKtPP1JJ7FqkUdRJa9PDS7/z74h1AH8ge4BTzvmyfoXR Y5x/NbYKwTPQZxfVXJE5GN5yuG87fCpKOWMvRlSEMdJcOT0B7eGS68ZnllO4hBlb7yEs rH1sB1GuMHqN4ehhSEIr43lCcanvjkyr9iSO14sBHmTiIEFadKc54pHO0rPC3oiPalXy 0NPaDJ1fdHtRSdOJtjf04KNPQttuQotXDycmtzD0+BedOJc0HfHjJffg1Pq3w+PPL/hr 8WxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=gjQHOBcm2mr8xMsvcbCgyYPtqumFK2l99APzVt0935g=; b=RF5/50gj7NVlulKor8UVSfklIXPhxMNvePlDzu94DpFOfurzQgB6vfv4dN+DohoKcR BdDcrK0PWPZBEFaLfDegVBllypwxJsup6qmFTZBh0XK03kv0Vr1+LFA+E/7YtdcioSrJ go50X/yol3IzeoLJGB5vZ+U2wG+oJxZQH5Gnn4i0gapCzO/FPX6whOt35WvR7v9YL8Fk hQjp194UfkCIUNG777vUm9AbXzLGudlUHAAHLC8b5+FGHlW6XMN6ijZkoW7dqUV8JlMp CMpTxEBN3PHmQVIJtY4OicALFqBxYqo6FAvZqgLVLTcdp0/zpwguwK3MkD+hhSml/hPJ WNjQ==
X-Gm-Message-State: APjAAAUJqc4nF7SE6pJALCrGZJimN9IQHB6wLU+n/f4adDenQ3u5SZwC LvYTPhzjMzxehvIGTEfEqEjs9o6uQ7QhczEjCm0Swelq
X-Google-Smtp-Source: APXvYqyjEqTM+I+jfeqcO2FbntZjb56U0si3i3S/bo1PfV0luB/uR7KWN0fInVwTDa9CUcslRcwg+eyzXunzy+u9Rec=
X-Received: by 2002:a02:2944:: with SMTP id p65mr137514jap.14.1571261917088; Wed, 16 Oct 2019 14:38:37 -0700 (PDT)
MIME-Version: 1.0
References: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com> <0C5225D1-FB07-4EB4-BFCD-D36D5F79A76A@cloudflare.com>
In-Reply-To: <0C5225D1-FB07-4EB4-BFCD-D36D5F79A76A@cloudflare.com>
From: Paul Grubbs <pag225@cornell.edu>
Date: Wed, 16 Oct 2019 17:38:26 -0400
Message-ID: <CAKDPBw8_yNFtxgc4Z+Nqt4G13bv1Sa9_E3pK6CfX4CB7D8XduA@mail.gmail.com>
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>
Cc: Richard Barnes <rlb@ipv.sx>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000006ae6ab05950dec79"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/n0tlVnb41XHQJbfKu2I2ss7HrAk>
Subject: Re: [MLS] Some data
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Oct 2019 21:38:40 -0000

--0000000000006ae6ab05950dec79
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks much Richard - this is very cool! Will any of the data (or maybe
just these transcripts you're generating) be released publicly?

In addition to what Brendan already suggested, just some basic summary
statistics about the distribution of group sizes would be really useful.
Also, understanding the frequency of group changes (adds/removes) vs
"regular" messages would help guide thinking about tradeoffs in designing
protocols, MLS and otherwise.

On Wed, Oct 16, 2019 at 5:27 PM Brendan McMillion <brendan=3D
40cloudflare.com@dmarc.ietf.org> wrote:

> This is great!
>
> I=E2=80=99d love to understand:
> - The distribution of message sizes (message =3D what the user actually
> types)
> - Does WebEx Teams use a sub-protocol for messaging metadata, like XMPP?
> How much overhead does it add?
> - How important do WebEx engineers consider compression? Given that human
> language / XML can have such high compression ratios
>
> > On Oct 15, 2019, at 8:56 AM, Richard Barnes <rlb@ipv.sx> wrote:
> >
> > Hey all,
> >
> > I've managed to extract histories for a collection of Webex Teams
> groups, a total of 950 groups (including 1-1 conversations) ranging in si=
ze
> from 2 to 5000 members.
> >
> > What data would people be interested in understanding from this data
> set?
> >
> > I'm currently working on extracting "transcripts" of
> init/add/remove/message events, with the idea that they could be fed into=
 a
> simulator attached to some library to generate counts of actual crypto
> operations.  But it would also be easy to extract summary statistics, suc=
h
> as the inter-arrival rates for Adds / Removes, Add:Remove ratios, etc.
> >
> > One caveat is that Webex Teams allows self-add and self-remove, in
> addition to adds/removes initiated by someone in the group.  Self-adds
> account for ~6% of all adds, but self-removes (leaves) are 98% of all
> removes.  The latter might be an artifact of "server-initiated" removes
> being reflected as self-removes, but of course server-initiated removes
> have similar issues w.r.t. MLS.
> >
> > --Richard
> > _______________________________________________
> > MLS mailing list
> > MLS@ietf.org
> > https://www.ietf.org/mailman/listinfo/mls
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000006ae6ab05950dec79
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thanks much Richard - this is very cool! Will any of the d=
ata (or maybe just these transcripts you&#39;re generating) be released pub=
licly?<div><br></div><div>In addition to what Brendan already suggested, ju=
st some basic summary statistics about the distribution of group sizes woul=
d be really useful. Also, understanding the frequency of group changes (add=
s/removes) vs &quot;regular&quot; messages would help guide thinking about =
tradeoffs in designing protocols, MLS and otherwise.</div></div><br><div cl=
ass=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 16, 2=
019 at 5:27 PM Brendan McMillion &lt;brendan=3D<a href=3D"mailto:40cloudfla=
re.com@dmarc.ietf.org">40cloudflare.com@dmarc.ietf.org</a>&gt; wrote:<br></=
div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bor=
der-left:1px solid rgb(204,204,204);padding-left:1ex">This is great!<br>
<br>
I=E2=80=99d love to understand:<br>
- The distribution of message sizes (message =3D what the user actually typ=
es)<br>
- Does WebEx Teams use a sub-protocol for messaging metadata, like XMPP? Ho=
w much overhead does it add?<br>
- How important do WebEx engineers consider compression? Given that human l=
anguage / XML can have such high compression ratios<br>
<br>
&gt; On Oct 15, 2019, at 8:56 AM, Richard Barnes &lt;rlb@ipv.sx&gt; wrote:<=
br>
&gt; <br>
&gt; Hey all,<br>
&gt; <br>
&gt; I&#39;ve managed to extract histories for a collection of Webex Teams =
groups, a total of 950 groups (including 1-1 conversations) ranging in size=
 from 2 to 5000 members.<br>
&gt; <br>
&gt; What data would people be interested in understanding from this data s=
et?=C2=A0 <br>
&gt; <br>
&gt; I&#39;m currently working on extracting &quot;transcripts&quot; of ini=
t/add/remove/message events, with the idea that they could be fed into a si=
mulator attached to some library to generate counts of actual crypto operat=
ions.=C2=A0 But it would also be easy to extract summary statistics, such a=
s the inter-arrival rates for Adds / Removes, Add:Remove ratios, etc.<br>
&gt; <br>
&gt; One caveat is that Webex Teams allows self-add and self-remove, in add=
ition to adds/removes initiated by someone in the group.=C2=A0 Self-adds ac=
count for ~6% of all adds, but self-removes (leaves) are 98% of all removes=
.=C2=A0 The latter might be an artifact of &quot;server-initiated&quot; rem=
oves being reflected as self-removes, but of course server-initiated remove=
s have similar issues w.r.t. MLS.<br>
&gt; <br>
&gt; --Richard<br>
&gt; _______________________________________________<br>
&gt; MLS mailing list<br>
&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--0000000000006ae6ab05950dec79--


From nobody Wed Oct 16 14:51:37 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89AE712090C for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:51:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hv0HQ3WNZuTo for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 14:51:31 -0700 (PDT)
Received: from mail-wr1-x431.google.com (mail-wr1-x431.google.com [IPv6:2a00:1450:4864:20::431]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B23F1120046 for <mls@ietf.org>; Wed, 16 Oct 2019 14:51:30 -0700 (PDT)
Received: by mail-wr1-x431.google.com with SMTP id o18so29658363wrv.13 for <mls@ietf.org>; Wed, 16 Oct 2019 14:51:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=to:from:subject:openpgp:autocrypt:message-id:date:user-agent :mime-version:content-language; bh=y35pFvUpTC6UWGJheBGj21Rr3AzeYxspADTAnPZwK8Y=; b=1x5yN4+F/P9vzqb4C2EhvX7fbTLOE+T+aQvBkkmy0lTJRA0fJLHxLYIaxgo9yRtRGr 5dxtrIOXWrM0/FW1K2AvqcQfZepw7VacNasoSrms/VPRUKJodoW6JHXUH4WY5SNCqWjE QDFitPikJZmaBxEACmcnVeYm96QRUmHKEi3wC40rxXxBq2KJV2L3IKdxNpjlFWk9jWVa ZktxUg97eYdZ4H/RIxOdlQjmtH8J1qraeJZT+su9wahhtsa9UIeIOci0jOwGQnHtWNkS 2PAW0XBadwL3MhH15eSRAg8KM9pJmjcbbQX4ub+n7ShcbqS6N+eR7IPhtJTfdLG0Wsrw dKrw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:openpgp:autocrypt:message-id :date:user-agent:mime-version:content-language; bh=y35pFvUpTC6UWGJheBGj21Rr3AzeYxspADTAnPZwK8Y=; b=JoQkFH5LTKCAKv4fTb3QupgrKghP/YB6f2gwe5NG4t+2xKo0dQ3jXbnvBHLV1LyITm q+cwMEIcc5yFhwFknx0BelSDbtYPMxQMNx4/kQDPdjFay9HNhWagAKTcNVQLOOfjtDXW eDbOWSG36H/oht0UeIAdOz5O/gECRnPCo2aFJdCoazl7xXGGisfAA1opAtUVHACi0CZn 7fe6tX7txHMIBhUhVky8j4dMnVkgO5lvQfrahuNAhvEKccfjXelSqbkB64LufQnjNpFC pY+h4eG0eIkUmoHx9OagTz6vb8k3s7NzmQ/a8fEHM5ztzHdeYguR4KqN26voxgT1nlBH ZokA==
X-Gm-Message-State: APjAAAVB9pzjcf5W3c9foHp1EV3mq4oixDm09xrHYMlQkISHmh4syHGy QoKRwsHTFARcUNScjiI2th5dBNnvr1I=
X-Google-Smtp-Source: APXvYqyNMBQqls02u2fed0cfBuL5k1xkY1KNhsAqqQQW0OUhxBeaEtPxnsTYELS1emUbX5Co1ikd9w==
X-Received: by 2002:a5d:540e:: with SMTP id g14mr28348wrv.177.1571262687550; Wed, 16 Oct 2019 14:51:27 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id k24sm8267723wmi.1.2019.10.16.14.51.24 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Oct 2019 14:51:25 -0700 (PDT)
To: mls@ietf.org
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com>
Date: Wed, 16 Oct 2019 23:51:23 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="------------1AA7E09B652DF5246C8D07F6"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/pZ-dWq6A8XyFR64_fB6B9hoVFlo>
Subject: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Oct 2019 21:51:36 -0000

This is a multi-part message in MIME format.
--------------1AA7E09B652DF5246C8D07F6
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit

Hey everyone,

Sandro, Yevgeniy, Yiannis and I wanted to give you a heads up about some
work we've been doing around TreeKEM. I'll summarize the main points
here. You can also check the slides (attached to this email) which go a
bit more in depth about some of the results with lots of pretty
pictures. But for those interested in the full story we invite you to
look at the full paper on eprint [1].

Basically, we're eager to hear what you all think about it all! More
specifically, one thing I think we could discuss on the list is whether
the work group wants to adopt the proposed changes to TreeKEM. While we
are quite convinced this would significantly improve security for MLS,
it does come at a price which we tried to summarize to the best of our
knowledge below.

Besides general feedback, here are some specific options to consider for
moving forward (just to get the ball rolling).

(1) Adopt the changes as part of MLS.
(2) Make it an optional mode for MLS.
(3) Save it for a future version of MLS.
(4) Just forget about it all together.

- Joël




Results
-------
1) We describe the poor Forward Secrecy properties of TreeKEM. Suppose a
path is updated resulting in a new update key k being fed into the MLS
key schedule. We show that an adversary seeing network traffic can
recover k by leaking any of roughly *n/2 different keys* from the
ratchet tree, some of which are known to multiple parties. That means FS
for k only kicks in once about half the nodes in the ratchet tree have
been assigned new key material. (I.e., its *not* enough to refresh the
log(n) keys on the co-path of the update that produces k.)

For MLS this means we have poorer PCS properties than hoped for. When
Alice is compromised and then updates to define new epoch key K there
remain n/2 keys spread across group member's states, any one of which
allows the adversary to recover K.

2) We prove security for TreeKEM but only under a pretty weak security
notion (which is unavoidable given the above issue).

3) We describe a modification of TreeKEM based on the proposal by Konrad
in the mailing list 24/Jan/2019 [2]. (We call it RTreeKEM for
"Re-randmoized TreeKEM" but the eprint version hasn't been updated yet
to reflect this nomenclature.) Essentially, RTreeKEM replaces HPKE with,
so called, "updatetable public key encryption" (UPKE). Its the same as
HPKE except that when encrypting to a PK, the output includes both a
ciphertext c and an updated (re-randomized) public key PK'. Decryption
of c with SK produces the plaintext and updated secret key SK'
corresponding to PK'.

The intuition here is that this gives TreeKEM a second mechanism for
updating ratchet tree key material besides updates. As a result a node's
SK is used to decrypt no more than 1 ciphertext before it's refreshed.
The offshoot is faster replacement of keys in the ratchet tree and so
faster FS. (Ergo, faster PCS for MLS.) In a sense, we are motivated by
treating the event that a group member actually comes online as a
valuable comodity so RTreeKEM tries to take more advantage of them than
TreeKEM does.

Technically, we define and construct UPKE, RTreeKEM, and prove their
security. In particular, we show that, *if* the delivery service ensures
Handshake (i.e. TreeKEM) packets are delivered in an arbitrary but same
order to all group members then RTreeKEM gives us "optimal" FS and PCS.
That is, assuming global handshake ordering, no protocol can give us FS
or PCS with *fewer* message flows exchanged in any type of execution.
Indeed, any such security improvement would necessarily imply curtailing
the functionality MLS wants from TreeKEM. (Put differently, better
security will invariably mean that there will be some situation in which
an honest group member can't produce an update secret they need to
advance to the next epoch and ends up getting left behind.)

Finally, to qualify "optimal": our results don't mean there can't be a
protocol with the same security but *smaller* packet sizes (just not
with *fewer* packets). Also if the global ordering assumption fails we
could still hope for better security with some other protocol.
(Although, personally, I suspect that will only be possible using
cryptographic primitives that are much less efficient and more advanced
-- read not publicly implemented let alone standardized yet).



The Trade-off
-------------
The stronger FS for RTreeKEM comes at a price which we believe can be
summarized as:

1) Currently, we aren't sure how to build UPKE from the X25519 and X448
groups. In particular, UPKE is currently formulated based on abstracting
the underlying ECC group and DH function as modular exponentiation
function (over a generic prime order group). But that's not quite the
case for those X* functions. They first fix some bits of the scaler
(called "clamping") before performing modular exponentiation so modeling
them as simple exponentiations is not accurate. If this doesn't change,
it would mean not supporting the X* functions as a ciphersuite.

Assuming we don't get things to work for X* groups then alternative DH
groups over (essentially) the same curves we could use instead are the
Ristretto variants. E.g. [3] currently under consideration by the CFRG
works in place of X25519. A downside here (relative to, say, X25519) is
that there are fewer public implementations (especially one's audited by
3rd parties if any?). To be clear, we can still use NIST curves and we
are quite confident that having a post-quantum instantiation (e.g. based
on various NIST PQ submissions) is relatively straight-forward.


2) When updating node secrets on a path the corresponding protocol
packet must now include one additional public key per UPKE (formerly
HPKE) ciphertext. Also UPKE ciphertexts are a bit larger (approx. one
extra AES block) than HPKE ones. The public key is needed to inform
group members that *can't* decrypt that ciphertext what the new
(re-randomized) public key at that node is. The extra AES block comes
from including the re-randomizer as part of the plaintext. No more than
$BIT_SECURITY bits are really needed here as they can be expanded
deterministically using a PRG (built from, say, HKDF) to get a
re-randomizer of the desired length. (This little optimization is not in
the eprint version yet. This approach also makes it much harder for an
colluding insider's to use knowledge of SK to choose a re-randomizer
resulting in some targeted SK' as that now requires inverting the PRG.)

In any case, the mitigating observation here is that the increased
packet size means faster FS. So from the point of view of "global
bandwidth required to achieve FS for a given update key" we actually get
a significant *reduction*, (especially if the server delivers things in
a global order). I.e. Basically, RTreeKEM has bigger packets but less of
them are needed.



Differences
-----------
[1] https://ia.cr/2019/1189

[2] https://mailarchive.ietf.org/arch/msg/mls/WRdXVr8iUwibaQu0tH6sDnqU1no

[3] https://datatracker.ietf.org/doc/draft-hdevalence-cfrg-ristretto/

--------------1AA7E09B652DF5246C8D07F6
Content-Type: application/pdf;
 name="FS-TreeKEM.pdf"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="FS-TreeKEM.pdf"

JVBERi0xLjcNCiW1tbW1DQoxIDAgb2JqDQo8PC9UeXBlL0NhdGFsb2cvUGFnZXMgMiAwIFIv
TGFuZyhlbi1BVCkgL1N0cnVjdFRyZWVSb290IDc4IDAgUi9NYXJrSW5mbzw8L01hcmtlZCB0
cnVlPj4vTWV0YWRhdGEgMjE3NSAwIFIvVmlld2VyUHJlZmVyZW5jZXMgMjE3NiAwIFI+Pg0K
ZW5kb2JqDQoyIDAgb2JqDQo8PC9UeXBlL1BhZ2VzL0NvdW50IDI1L0tpZHNbIDMgMCBSIDEx
IDAgUiAyMyAwIFIgMjUgMCBSIDI5IDAgUiAzMSAwIFIgMzMgMCBSIDM1IDAgUiAzNyAwIFIg
MzkgMCBSIDQ2IDAgUiA0OCAwIFIgNTAgMCBSIDUyIDAgUiA1NCAwIFIgNTYgMCBSIDU4IDAg
UiA2MCAwIFIgNjIgMCBSIDY0IDAgUiA2NiAwIFIgNjggMCBSIDcwIDAgUiA3MiAwIFIgNzQg
MCBSXSA+Pg0KZW5kb2JqDQozIDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jl
c291cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjEg
NiAwIFIvRjIgOSAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdl
SV0gPj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVudHMgNCAwIFIvR3JvdXA8PC9U
eXBlL0dyb3VwL1MvVHJhbnNwYXJlbmN5L0NTL0RldmljZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQ
YXJlbnRzIDA+Pg0KZW5kb2JqDQo0IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVu
Z3RoIDU2ND4+DQpzdHJlYW0NCnicrdbdatswFAfwe4Pf4VxKhShH3zaUQvPRru2yMeJSytiF
SZxg2tmbk63kmfsSk90x2BIRs+jGF7awfpL+OtLwstmWq3yxhdFsDN/jCAEZInIh0EJqELRC
aIo4ejiDKo6G13MN600ccVj/aYyGo9R/tV6dxdGnOIKp+ysM59/yCs7Ph7PxzQRw+D6v1kCK
anA/pxcXMJq89dz9iiuJGvBA16PMdX/FwbiGQkG2ahFOABy4NExzEIlkyCH72srWHTbpsAjX
cfSZXFGuSN3QgSQvlEuSN5QbsoQ5laRYNO3XYrGDegX0C2S3cTTNvKPg4UdhMGXS7I3iNz6j
xhJn1KQo7qaz40JxklDAPzqZIrMgpGZK7OFu69dnoJpcPr/Q1PXYYwJlWJ5GZNz4fIPjHhXY
wwVLEp/noVw8NcdNOvASStkuIYpDpHleLV28BKl7LJ4JC1NomUx8snH9tjW3lCdkWx7X2cA6
q3y0HrlKAmMSzqTweSZuplKSt48dHRjipgxJ3Wc7poHjb1RXy/572vhpx8Q+yFqG3ojdfKSK
vLvrwTqt7u9vSdslnxtX+vdUj9QKUvykAsmacu76LHft4dXneApc/ZWxTPick3pZbnqYQpd8
YZkWHlOfiIUu+QqZe3XY8+HRXTLue6BC13xtWJp0NyRhDySMW1LmVVVu+oQqdNmXyFIfLaPW
kk3xXNCBIE9UalL/qHrFLHD518qyVPiYfXIW+AjQ7u5olA/kDdovhR18kQ0KZW5kc3RyZWFt
DQplbmRvYmoNCjUgMCBvYmoNCjw8L1R5cGUvRXh0R1N0YXRlL0JNL05vcm1hbC9jYSAxPj4N
CmVuZG9iag0KNiAwIG9iag0KPDwvVHlwZS9Gb250L1N1YnR5cGUvVHJ1ZVR5cGUvTmFtZS9G
MS9CYXNlRm9udC9CQ0RFRUUrQ2FsaWJyaS1MaWdodC9FbmNvZGluZy9XaW5BbnNpRW5jb2Rp
bmcvRm9udERlc2NyaXB0b3IgNyAwIFIvRmlyc3RDaGFyIDMyL0xhc3RDaGFyIDEyMS9XaWR0
aHMgMjE2MSAwIFI+Pg0KZW5kb2JqDQo3IDAgb2JqDQo8PC9UeXBlL0ZvbnREZXNjcmlwdG9y
L0ZvbnROYW1lL0JDREVFRStDYWxpYnJpLUxpZ2h0L0ZsYWdzIDMyL0l0YWxpY0FuZ2xlIDAv
QXNjZW50IDc1MC9EZXNjZW50IC0yNTAvQ2FwSGVpZ2h0IDc1MC9BdmdXaWR0aCA1MjAvTWF4
V2lkdGggMTgyMC9Gb250V2VpZ2h0IDMwMC9YSGVpZ2h0IDI1MC9TdGVtViA1Mi9Gb250QkJv
eFsgLTUxMSAtMjUwIDEzMDkgNzUwXSAvRm9udEZpbGUyIDIxNjIgMCBSPj4NCmVuZG9iag0K
OCAwIG9iag0KPDwvVHlwZS9FeHRHU3RhdGUvQk0vTm9ybWFsL0NBIDE+Pg0KZW5kb2JqDQo5
IDAgb2JqDQo8PC9UeXBlL0ZvbnQvU3VidHlwZS9UcnVlVHlwZS9OYW1lL0YyL0Jhc2VGb250
L0JDREZFRStDYWxpYnJpL0VuY29kaW5nL1dpbkFuc2lFbmNvZGluZy9Gb250RGVzY3JpcHRv
ciAxMCAwIFIvRmlyc3RDaGFyIDMyL0xhc3RDaGFyIDIzNS9XaWR0aHMgMjE2NiAwIFI+Pg0K
ZW5kb2JqDQoxMCAwIG9iag0KPDwvVHlwZS9Gb250RGVzY3JpcHRvci9Gb250TmFtZS9CQ0RG
RUUrQ2FsaWJyaS9GbGFncyAzMi9JdGFsaWNBbmdsZSAwL0FzY2VudCA3NTAvRGVzY2VudCAt
MjUwL0NhcEhlaWdodCA3NTAvQXZnV2lkdGggNTIxL01heFdpZHRoIDE3NDMvRm9udFdlaWdo
dCA0MDAvWEhlaWdodCAyNTAvU3RlbVYgNTIvRm9udEJCb3hbIC01MDMgLTI1MCAxMjQwIDc1
MF0gL0ZvbnRGaWxlMiAyMTY0IDAgUj4+DQplbmRvYmoNCjExIDAgb2JqDQo8PC9UeXBlL1Bh
Z2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzgg
OCAwIFI+Pi9Gb250PDwvRjIgOSAwIFIvRjMgMTMgMCBSL0Y0IDE4IDAgUj4+L1Byb2NTZXRb
L1BERi9UZXh0L0ltYWdlQi9JbWFnZUMvSW1hZ2VJXSA+Pi9NZWRpYUJveFsgMCAwIDk2MCA1
NDBdIC9Db250ZW50cyAxMiAwIFIvR3JvdXA8PC9UeXBlL0dyb3VwL1MvVHJhbnNwYXJlbmN5
L0NTL0RldmljZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQYXJlbnRzIDE+Pg0KZW5kb2JqDQoxMiAw
IG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA1MDYwPj4NCnN0cmVhbQ0KeJzd
XNuOHMeRfR9g/qEeewywmPeLIQgQSVmwdwVoJRp+MPaBOxrJBmRapijY/vuNE5fsqumqHq6m
l4AGAoaKkxkZEZmRkZGX6uefvXv/1+/e3L6fXnz5cvrH9ZWb3Oyc8yG4OvXippzc9O7u+upP
v5neXl89/+KbPH3/0/WVn74flV3xLuZV7e9+c331X9dX0+fU6vT8q+mTT55/+fL3ryb36afT
i1cvpzj9kxtr3JibQ6nUVkr4W0ufvv7i+uoq+DD3NPlQ5hCmv11fhSRAL7ML0w/XV99siPAq
4ipUZY9zXXHHOe8xB2OOOZNSC9mxCXBWdjT25JVdZQ/uM7KTMZfkIOMou1QBzsrOxl6dsqvs
wX1GdhmK9zrndmTOQehzzNWYc1ZmP7uy4nZzK3vsbQzYanjRa+QAqU+hhzN29zFk6GO/Ys9z
KQ+weze0N2XD7BtrT33h4xRaA7DHP/ytlD73uuAvNBApPMR/dDmfZm/aEnvKxDcl385pPzwu
9w7tA3V1UPYMIHn2oj1+czo399AxBfGHTJje0fxOqcw5SBNskQE0wCFPKbs50z8ho5jlBaNu
qXLh5qy4pCWrUtIyV1bAz5GMVlZXly0LhcoqWItNS2Fd6UyV/yLRiAwsCDpkXUtkY6ROoVaK
l1jzVEzdHGQLDdGVOWJC+Jmn56CpnTpFT73SqZKjUswdKhKCmo6BCqMVhrTkM8pbVaFbmQtx
CGNo4diqEKgqIrVQtVG+pa7HYbz6lduwOT5lTML76yBmYab4EZIEBolLBtTZ5SkTHsgC51GM
mEVlSt0iCAVERQUKaXRkHVQYlQVoFPj8pKyhxUXLSt0iPLJgK1alhHWt82L4nooxm+NYzwXT
ENmlfM9zYssVCFgl8hRiYzdyCcUhRSlj6hbJS2MX1OIclqxCacuobADFDjJZWD355LFlpVBZ
BFuxaSmsK50Xw/hUjNkcxnZ2OsaaZx+4mSpphgDQn6rE2mef2TYqji1JGVOIFq3Pro9iSqsW
rEJpy6hsAEnPk7LCtmPLSqGyCLZi01JYVzovo+kTMWZzHC0zzJRC1SKJGRs5gAodcghzhRUe
xcgCazEKkSFScRzFsSxZjQqjsgAIHBTNhNW3uGhZKVQWwVasSinrSudlAH0ixmzuviwXL5QU
1aVbKqC+VSiDqsMtkXfXpVuWmlDLimtbsgp1dJ4BsG8pq/qdtnx0SxU8it2SdaXzYsSeijGb
I+bPLnlOt9+ye2eqiTW0qSFfgkuRNX78L0K4r7yN0rIQBlMI1hqqgYJfUdcph0+jNW/dZ5K0
DCoo01G35br2a9J4c0DC2cUrFNpii1Kd0+cBtLlTXChl7pktoeJQPZcJBdVqmVsfxc0tWY2K
VlkBUr5TVygrWbVoWShUVsFarEop60rn5WA9EWM2x9E29jFRCMVJUgIfVmgDOnSImSI5rIgo
jrlwmVBYR4uf2VeluOQlq1FpVBbAd6hvrLTdWbQsFCqrYC1WpZR1pfMy3XgixmyOmB2lJMdB
8+iWA2DfSq5z2BW/SzLNj26ZSGoZbplkvhurUeY8BohvGav4nbU83NIEa7EqpawrnRcj9lSM
2RwxOxfJtKlICxuNZj0z7T9SNBtwxJkWFmaaz7GOUpr5R0Yl4qjKtOhofKK/tjqsM5laKuoo
41LXZV7467Zhc3zsXKRErulDnmkNRAalQHSzo619rGjV0/6OiksKUsYU8hyawD2OYprqC1al
pGVUNoCK62SsvixbFgqVVbAWm5bCutJ5mQ4+EWM2R8xOQEp367AxAHar0tMibJTe12GjurQI
G9W1Beug4qjcFnPfWMXrrOXhlCbYit2Cda3zcsSeiDGbI2aHHQkXB8s4r7TEapIURvxIpMjS
wkxq+mP8IBMGoxEjfgitYUD5NIZLq8cIrzKt1B0ZV7ouF6tftw2b49PPXtDwURbuCDA7u8c9
AOVDNEftEpb2iQ0XHTFH8AW9Wj3PeFTkmx/fvD3ebrrn//nm7ffT4e7tsz9+c6OK4dKYb4F9
ii5PbuPW+MXr66vnv8Pec3r9He6OHf3npxzJGuqWzDdXr/+mt8p+Ig3/fPjqJqTDm3fvb+Lh
31T57sa7w79uQjnc3f78/sanw91PN8/iYbp5Vg4//3jzLBy+fXOTDlSUD3c3/z29/sP11eev
t6+h49i2skAf+WTDuznDbZAGpsS0yxwQcXhBCYfDQNeZ9lXe8V3hLSq3OdMcdQWHw8gZwUNe
EeqRCsggubICbtZ9HbF2cqcYpOVGvTfX5KUyC6YteMicmqY8wZ9wyiIa9zg3EnMrJuSAYnJI
XPbB5VoF0LNwt4amWpKYn9OE282qalXyRdIju8J6kLNAx3AkApTQqgyoY4PRU77VqjWLrvHa
NZm3STRfkkQx1KJ+5KQhMkhUs6y6kA04vLVxILrWanXIKMo3kivWBKX0cbSO84roF8ILFq6h
G7lYTUPtQZlVA4DNyqndoQ0fO0vEalciA+qjm6FwtkG4HQbpMP3AvI3k6yhS0xmvLHiAMQko
2ByHPzdytOEdRPH5gXjOoMyxBsB+B9bmzSe55bZwWcjF4ap4NOvUzNtXY3AMrZvhIDwqHMT7
4aAkOCFtnVviYODkiQkFg+mZw4OC17d//sS5np1rrz5dTfD/i9BIUpZiG9/q0BiFcl8uiXsR
0y8XtbaPAn5q2waSIP+5v5ggmpQh7Uqq6XeX6z14XClnui9fyiokn5C0Y1XOn11MEq2Odb/7
wuUE0dSMuy5BucHlJOFI6mO5RKW0NH2MGYXLhrDrEtR/Lz7dygPWUSw+KoqlkyhGuVbD9mpO
FJpPpzkl3Jn+qa+cby9/YUecCG3ksO6M0PbS0VpBUovz/jORXi83M2ljWfKu9Ms6V+Y8qOD+
Y0PWiXNtDnm6bB6rQ04b6nZq/+HN229HnvoVJahfI5H9YtrMUNdq5suur3hPmOOOmhtx7TRr
tvMYnwJf71PCR6kRMubET9eQ7xUOn3j2hnyPMolU+K6fRpJYkBWStwRcgXgprnMFq+PrYKUc
X49oZQao5TwZq+PDD245ERXwQoori2DHzw9ZJ89XZdwyq+xpg1aSVOZneiiOnFxSfyJ9BYCk
k7iZ8lh00HJgSb2bpCYvGpC5kyIeV0QFpzCDatCCKwvgJelXVjKfsn1uGOYfW06wBp1HAwiV
Iverb2yCL0yVqLlZJ6uY30aiozOaVSKzaG/nKQHWNigH8TVo840SQ7xvHMJbo16OphtRGc9e
RG+jhlkDYKuNVXrEWh4dZnKlO6FTbdbVUDkGG4nbYZSO1Q/MXVyyoaTGQ2s2zCQ41qUXtDqn
Yj5ChHPR/GdQ5l4GiPcxZzDP5Ib7wnEhF/c54tfQabj8ehgeSJvro6f17KjjVxlfmLlHAjZK
G7lzJSMvlj3fk42tQuLB8pfO/07sxI55x85Hp9CnwpBwpl1pj13W7kuLkQ8d9vqxXNS0zNN0
z7TH5dKn0qq889rryEcl1KfS8Ny67El7ZFJ9Ko1277vCLu0jwUVeQj7KXEMYzOf6cTu5XqQL
drSMiEkTKWJZ4UWK42RmgBc0PlLDO1peJhuOKaLjFxT8uoIWE6KrlHacWJI5koAoFWc5BhuA
52drzBmot2KWdjs/Fm3ZXm2QWDwAxutDr091tWHWOOBcJ0nlhMssFBfOFhD4sYThY4PK3Fgr
sBMRg/CSEUc3akLjVAQLWmBNkrxqjf5I8UtGrcxA5uxGWPGSGK8HpGV0TpS6ZUZfdVuLSCX0
YxITEhPdbmw8Tlj8YhwAoDmphByo8PNXbcKXgBVWm/fFo0ET7XEwlkwxUMmb0oMymwbAJiur
doe0e+wslap9yRpV62dWONgw3A6TdKB+EG7+ZITHEW37ZmMMuaEsXID338NDfG78kkCcZ1Dm
WwOQloVV3ZJbrgunZcHdfBpKDXdfj8IDuUK/8BYAT74KdzalZx/xkM3jdXzhcUoXX97uBWQv
7rNh4mWP2fBskkPAtqSLbnuRwNYz3VcvZVTAJnHfqAuesoVUJArsdN/ljtlCke+wtiVd8pgt
lMqbu4/iEjV/pCkV8Dp71yc+7JgtPe7u8ESnFDkup9gxBze858WlrE84Dc67ki44I1LJc/f7
Nl3Se1KNOFhJsXDQfzCinH6tevblb6n8aE4/TcMGoGGqA7Ob6Yfq7FxCp8fdOoWtVLfgy1Fq
OSEvuH8P/ccfv31zU/VeeeI757vbdze+He5u8uH9b2/S4QMO89Ljjpk3M/RKaU1pO3o/dg6c
SGuO3wfsSXuVfulp9ra0UJGB79p22Y1Vi3zjjy82NcKtpH3AbLDHnwG+vP+ZKT5YSoEfk8pH
vgYkTr5CLkzlyFQNOMpSil8h0x7GaOSp2RiVkGbxoFVoHHS1SdiQIjdrUwg0KRK1UJVRtpWu
95+orL37cUfVJyfqoWKXUbEBPQmEh7/exMNbmnrfYQ7+nc/V3/zP33/GxHz/ITOxXHYlirli
X7Ct7IWjNh41xzghy0gbsk5OAE79dHyrjx840N8U0KfYAvBpcCRJ/Nl5CLQk8edZ8Ecm+PGt
w3E/k4mU9MYlhLbJ73+ZxuN5WmuYy5PytFXTJpXi99os0IpVO+Fc63reE9tlPREfm/GXhA1q
XdoVL7y9w9fjGKdNZS+dQNCeFqkuRc6wcfJ1kn6e/l7F8YcXSucfPnCI+Hi6zDROFkqeMu0c
sVvms4KMFDQZxY9xODVVoAR+/aOcSmm7qKwAPouiSSSsofCVhLasFL+ogVwrFQ2FcaXuWWfM
/v8hV8FXrPKFe84bDpnIIQscsrNDZnbID3HG/PjnPKcZCrkNPqHYVPbiq3il5RvfSVGYaBu7
r4dX8RxHTktRfcKtU6O/lB3Ix1ONv/zHy018JUL2lpPXlvYjE4HsxcdXeHVZfNDV/2wDe070
+Nvqk3GJ1WGLgeeqxZ/PeH/Cy8qJA92HONHjE4ETZRPeiZY9ZV/fFH+gdLwc7u7+4/MvH3j4
mctDuxb8Ykf0eEzJX2pWvLMEkPgXXAoe2jUGYhEgQisA+sQvNSRPALwCvEEH4PgndArt73ib
x2sbA/IaN/KnlwxwHgogd3n4WPCKEUASlhBEMYezRH5ZyEePBAiVcLOaAu8kGXCsFQFZRFCO
FwMDUWg8UmRatXT8XC2Fpk3gJxMi09kLzcfNAKQrMp41dgbkB2fwmwqtMOC0CS9tVj2tzbgX
jgxUNjTzPTIDcn2dW0VkByAjkPFpv7BErZFnoaW/M2UWQTjkd3MyPkmGXkV/hAihnWuUWTnk
51QCv19lwLHHERBFaO1YBgBId2dKULs0Id0FIET+BZimLJUdg4DqDXDyEzJZFK8sD0BMBrjG
gNdGM64osAnS/qpia1LFaxItEt7DKsC9RWHXaBYRddgZ8AyYZUn2kHhrO2rIt1rF6Cpfaw0G
/iWcqJfzWb4y5hYGkIQj112WIDXSqKEc2leRpwjUTAOoAlQD1JAwaKkQBuBEqCsDkBpOmwji
jUHnIYC8or04Y9B5yUAXoBjgKwM7NP82DOiUDEhhCRR+/A4gtAEIS5AxpMRYmvRx0H4FVD6g
otWv1wGUFVCshjykZqCsgCyDyOmOAnVFJ9HT2xAVGjymYx60F0A5+IEN/wqSH0BfAbIvkJ8L
MyAsgaydwTgDDcwA1F355fMK4Ks4ACUY0FZ0lsjnLKJk3lQtgagcahpovwKcHE44C2wA8hJI
HCwpLW1+0H4FSLzFFaWYmhx3FwHRD0C+g5QHSvg5hiRtqJBTgC+/8JNhrW4DFIsR2bBalB2A
nwYASHsAfxMGQF32BMBNZGTAhwGkFSAhV76DNyAsAUrimwAt7gD8fB+ARlgAZQHgx+xKZKDs
AfrhasWKb0BdAo3fYAFIg05CSxOVP8sCEPsAwJFxc2ssWYAoQqQ45KFUYyAOw7hzMuKomS41
NIx7/ggBQOnWwdw5+CzBxkQOV20Mk/xSmG827AiXfqxw5ClYrvANRzfnYjvL8Fj+ESzYKZ+Y
wIWRU+AbkG5OngTQdTQjeZYhkzayOIEbEy+Lm2hAyLxmA9AYQrM7ZQayxYMmHEWjjhczmyUQ
JZg/65JJcanINHLdIlmTiRayBUMn0yhZ+PTLmVnYawHUYCHaSZNtxOwuMceNMN8kHgRbFzQ+
xLH2ROGwZCDK2u9GuiB6E9DGwhskZruxlleJ0SFadsDLqje/Qf4gcb8cMwyp0Y2OsrhYXqNH
ysHCAQFVV83RRFuuu0VEBBhsDJI/uNFk1lW0jhpJ1tmRCBVpYtCcN8ZVg2EkQVW6CmdLRvvV
wl5nSXqshYo0goHB0VZJkK6g0fyuSpofokYBBtIqQ2nsichp2gBEi6JadEkio01JAJKcqZ2U
ZnpptPf7QDNAEzzNCAngDCShIgOeow+C9KD9kpZ5jQAwkt+yoqPke0lDYtZotQCS1agjw85p
BWRJO5Mt002HONuQAIgroM76g4lhm+6yM8g2YwCEJYDvaSSdDkbHvgK8ydQR6dpXRwAuxDm7
N9r1FZDshx57HoBfAVmmflFnxO+nykYhGZ36AsC+inP6op7EQFkBiSndubloAgzQFiumsgFt
CXgvXVVtT3oKpFmayJtkk70gb34N8EsAczUx0BUosr9susQxUJdA9BKcmuY3DIQVkMXPmm22
o4bVpptBBtoSSGlsUusOoLdW/HhnE8AOXsT2I5BXQLO9shunALxhHICl4F2iItNpQevBAmj2
gr8gK5A1AkeX8oujNcnqZ67CNbBIB40geCmkhxr/C0gODCINCmVuZHN0cmVhbQ0KZW5kb2Jq
DQoxMyAwIG9iag0KPDwvVHlwZS9Gb250L1N1YnR5cGUvVHlwZTAvQmFzZUZvbnQvQkNER0VF
K0NhbWJyaWFNYXRoL0VuY29kaW5nL0lkZW50aXR5LUgvRGVzY2VuZGFudEZvbnRzIDE0IDAg
Ui9Ub1VuaWNvZGUgMjE2NyAwIFI+Pg0KZW5kb2JqDQoxNCAwIG9iag0KWyAxNSAwIFJdIA0K
ZW5kb2JqDQoxNSAwIG9iag0KPDwvQmFzZUZvbnQvQkNER0VFK0NhbWJyaWFNYXRoL1N1YnR5
cGUvQ0lERm9udFR5cGUyL1R5cGUvRm9udC9DSURUb0dJRE1hcC9JZGVudGl0eS9EVyAxMDAw
L0NJRFN5c3RlbUluZm8gMTYgMCBSL0ZvbnREZXNjcmlwdG9yIDE3IDAgUi9XIDIxNjkgMCBS
Pj4NCmVuZG9iag0KMTYgMCBvYmoNCjw8L09yZGVyaW5nKElkZW50aXR5KSAvUmVnaXN0cnko
QWRvYmUpIC9TdXBwbGVtZW50IDA+Pg0KZW5kb2JqDQoxNyAwIG9iag0KPDwvVHlwZS9Gb250
RGVzY3JpcHRvci9Gb250TmFtZS9CQ0RHRUUrQ2FtYnJpYU1hdGgvRmxhZ3MgMzIvSXRhbGlj
QW5nbGUgMC9Bc2NlbnQgNzc5L0Rlc2NlbnQgLTIyMi9DYXBIZWlnaHQgNzc4L0F2Z1dpZHRo
IDYxNS9NYXhXaWR0aCA0MzQyL0ZvbnRXZWlnaHQgNDAwL1hIZWlnaHQgMjUwL1N0ZW1WIDYx
L0ZvbnRCQm94WyAtMTQ3NSAtMjIyIDI4NjggNzc4XSAvRm9udEZpbGUyIDIxNjggMCBSPj4N
CmVuZG9iag0KMTggMCBvYmoNCjw8L1R5cGUvRm9udC9TdWJ0eXBlL1R5cGUwL0Jhc2VGb250
L0JDREhFRStDYWxpYnJpL0VuY29kaW5nL0lkZW50aXR5LUgvRGVzY2VuZGFudEZvbnRzIDE5
IDAgUi9Ub1VuaWNvZGUgMjE2MyAwIFI+Pg0KZW5kb2JqDQoxOSAwIG9iag0KWyAyMCAwIFJd
IA0KZW5kb2JqDQoyMCAwIG9iag0KPDwvQmFzZUZvbnQvQkNESEVFK0NhbGlicmkvU3VidHlw
ZS9DSURGb250VHlwZTIvVHlwZS9Gb250L0NJRFRvR0lETWFwL0lkZW50aXR5L0RXIDEwMDAv
Q0lEU3lzdGVtSW5mbyAyMSAwIFIvRm9udERlc2NyaXB0b3IgMjIgMCBSL1cgMjE2NSAwIFI+
Pg0KZW5kb2JqDQoyMSAwIG9iag0KPDwvT3JkZXJpbmcoSWRlbnRpdHkpIC9SZWdpc3RyeShB
ZG9iZSkgL1N1cHBsZW1lbnQgMD4+DQplbmRvYmoNCjIyIDAgb2JqDQo8PC9UeXBlL0ZvbnRE
ZXNjcmlwdG9yL0ZvbnROYW1lL0JDREhFRStDYWxpYnJpL0ZsYWdzIDMyL0l0YWxpY0FuZ2xl
IDAvQXNjZW50IDc1MC9EZXNjZW50IC0yNTAvQ2FwSGVpZ2h0IDc1MC9BdmdXaWR0aCA1MjEv
TWF4V2lkdGggMTc0My9Gb250V2VpZ2h0IDQwMC9YSGVpZ2h0IDI1MC9TdGVtViA1Mi9Gb250
QkJveFsgLTUwMyAtMjUwIDEyNDAgNzUwXSAvRm9udEZpbGUyIDIxNjQgMCBSPj4NCmVuZG9i
ag0KMjMgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRXh0
R1N0YXRlPDwvR1M1IDUgMCBSL0dTOCA4IDAgUj4+L0ZvbnQ8PC9GMiA5IDAgUi9GMyAxMyAw
IFIvRjQgMTggMCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUld
ID4+L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDI0IDAgUi9Hcm91cDw8L1R5
cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBh
cmVudHMgMj4+DQplbmRvYmoNCjI0IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVu
Z3RoIDEwMjEwPj4NCnN0cmVhbQ0KeJzdXVuPXMdxfifA/3Aedw1o1PdLYAiwLjFyMeBYMvJg
5IGhacsILSuSjMT/PvV9VdXnzO7MkvEOBIggQLK+0/eurq6qru75+Bff/fCnP7x6/cP26a8+
2/775YuwhVMIIaYU+jZb2GoJ23dvXr74959t37x88fEvv6zbH79/+SJuf1yJQ4sh17PUf/jZ
yxf/9vLF9oWUun386+3nP//4V5/90+db+OST7dPPP9vy9j8sbLCwcEqtS1ml4O/e5vabX758
8SLFdJpli6mdUtr+/PJFKgrMdgppe/vyxZcXqohWxYvULXs+9bPc+VSvZU6eOdcqjTrUnYcC
T9adPXuJlt3qXrmfqLt45lYC6tjrbl2BJ+uunr0Hy251r9xP1N1Ww2c/1bFnrknppzJ3z1yr
ZY6n0M5yh9No17KPNWFn04tREwYoc0szPdHvuaYMYxzPstdTa+/IHsNqvTc2neJg62UsYt7S
GACu5V/81to8zX7I32QiSnpX/p3lYjlFb61kL1XybSWOp1q/OK7OidYnGepk2SuAEslF1/I7
04XTTBNLEH9JF7bvZH2X0k41aRHskQMywalupYZTlX9SxWfWl5x6LYkbi/PPrRyzGqUlM7EB
8ZSl05Y19GPJSiGxVWyfvZWa9azNkvhrlUbSwQahI70bRfqYZVCklBZV1nwoXb04yS4acmin
jAURT1yei5Zy+pajjMqUREG+Yu3IJyWk6JzkY/aPqRzzORU9qdKjnZrk0IxppL1UJZBUq7SP
1hrLd2zrPo0vfuJ9uDg/bS3Ch/sgVmEV+ZGKCgaVSw70U6hbFTxJD0LEZ8gs+WbUawihBKlo
QJMW7VkXlVZiBYYIvrhZ1jTyoWSjXkM8smL/bI3SrOdtPkzfh9KZi/PYnxKmKZOl4qynwp4b
kLBL1C3lQTYKBZ9TyfqN1GsoL4MsaJ9rOmZVykpGYgdEdkiXNWsUntxLNgqJtWL/7K3UrGdt
Pkzjh9KZi9M4nlyOuddTTCymq5qhANovSXKfp1jZN/mcR9FvpCAtxjyFuT6LWnXIqpSVjMQO
SO11s6zo216yUUisFftnb6VmPWvzUZp+IJ25OI+uGVZRoXpTxYydXEBHG2pKp45eRHyGFtib
U5AMWT7n9Tm3Y1an0kqsAASHSDPNGkc+lGwUEmvF/tkaZVnP2nwUoB9IZy5aX66LN1GK+pEt
DTDeaqJB9cWW0Lv7kS1bL0jln/s4ZlVqZ54FkLcsq/GdlbyzpVW8Podj1rM2H2bsQ+nMxRmL
T255wcxvtd5JDe2NGDXCS2Ap6U1c/4UIj51mlH1LaWVKyUtDMlDgKxk6yxHLKi368HlN9g1N
sEx724772k+pxRcnJD25eaUmJrY2alJ9XsA4TZELrZ1mZU/kc+qR35RC03o7jbk+j3DM6lT2
xAZI46cMhWWVXh1KVgqJrWL7bI2yrGdtPk7WB9KZi/Pohn0uIkLhSSrIhx3agYk25CqSHL3I
+Jxr4zelsI+2eCKv6udWj1mdKiuxAnGi+Z5VzJ1DyUohsVVsn61RlvWszUd14wPpzMUZc1dK
CRSaO1sugLxVwqTYVb4rusx3tixSa1tsWXS9e1annHkcUN7yrMp3XvJiS6/YPlujLOtZmw8z
9qF05uKMuV+kilFRDn10mu2sYn+U7H2Ai7McelhlPee+vsrK3zMakVdS0tpGz6ftt1JX77xO
+6rNsYzHth71wp92Hy7Oj/tFWmbKmOpJ9kBoUAbkcApi2ueOUqPYd/K5laTfSEHPkQU88/os
S/2Q1SgtGYkdkM9986yxHUtWComtYvvsrdSsZ20+qoMfSGcuzph7QNoM52JjAWSrNstBbLQ5
z8VGD+UgNnoYh6yLyivxOKx9z6pc5yUvpvSK/XM4ZD1v83HGPpDOXJwxd3YUHBwc5bzRKqul
prTkR5GGHHtYpZlxlx/ShZXRiSU/lDYxYPlMhmupu4S3Ov1r2DOetfW4Wf20+3BxfuaTBzR0
ZeGMAKtzRpwDiD4ka9QPYcVOHDjoyDUjX7Kj1acz7g358ttX3+ynm+Hjf331zR+3uzfffPTb
L++tYTg05ilwLDnULVw4Nf70q5cvPv5H2J7bV3/A2XGQP3GrWXojw1J5cvXVn+1UOW7Swt/d
/fo+lbtX3/1wn+/+Jonf3Mdw97/3qd29ef3XH+5juXvz/f1H+W67/6jd/fXb+4/S3e9f3Zc7
+VTv3tz/x/bVP7988cVXl4+h8zJbWWHM9GzEcKpgG6iBpZAOlQIRzgtROAImup/EroqBZ4Wv
kXicqqzR0OAchs6IPMIVqe9UggbJxAaEk9l1knUKO+WkJQ8ZvVMvUROzYjHBU6VqWuoGfoKX
RVs882lINa+1CzXhszAkDvvAcqMDmFVzj4GiRlGZX8uG081uzerCi9KOGhrbIcyCNqadSGiE
JSVgjI2MUfSt0b1YDE20oak0k2S9FJViSCXjSKUhExRquFbdpA9w3vo8CN179zTSKdE3Smhe
hKj0eZUOf0WOh8obNq7VNmGxXlazF+W9WgD6bDltOKzgfbC0WhtKaEBzDTMaXH0SXq8O2TS9
Zd4h9dssStEVURacYCwCETb79NchjLa4Qyj6D5RzFuWMtQDyHbKO6DzJkseBZVEvnKvK0WzT
cG4/m4NdtF4UB+lZ4iA/FAetgAnFdB6FwiBoiIkIg+2jgICCr17/7uchzBrC+PyTswX+/6k0
Sy3HagdPdWSOUntYr1T3aS5/f1Xn/ROBX8blDkpF8Yt4s4pkUaZytaZe/vF2oweOa+2J4au3
6hWUT9R0pVe1/uJmNcnu2K8PX7pdRbI081WWEN3gdjXBJfVjsUQXtbT8GCsKhw3pKkvI+H36
ySU94FyK5WdJsfJIiomuNWBenYqI5sfLXBTuKv/0z0Mcn/2dA/Go0iEMG56odHwWZK+QWluI
8Rdae7/dyhTDstWrtd+WuSr1oIbzjwt1PWKui1NebqvH2pSLQT0e9//u1Te/X3rqr0VB/Q0U
2V9uFzXU82bW2+6viCes+UozL8i1x1qz+2NiSTzeF4VPVCNozIWha9D3GsUnwt6g74kmURrP
+mUmJQu0QuGWhCOQqJ/7qSNr4HGwUYHHI5aYgJRcN88a6PxgyUWohAgpJtaKA8MP2abIozKW
zCZHMdBa0cQM08PnTOVSxhPqKwAonZKbVMSmg5ITa5rTaxoa0QDNXRoScUTU4IVZ1EArmFiB
qEq/ZZXui7bPgtH9veSC3mDwZALRpMxxjYNdiI1Uy6abTekV8/tMTAzG8ETSLbHtoijAVobo
ILEnK36IYoj4xlX5GDLK2dsmVEXYi7bbqdWtBbDXnlVHxEteA+b16nCiTX34UKPJOflMvF6d
srl6y9wtFJ9KKTyN4dMsFed+5ILRT6U5jwgRQnb+WZSzlwPKfcyZnDNZ8DwwLurFeY7yNdq0
WP58Gt6hNvdnL+tTkIE/0/jSiSOSYChd0J27dPJm2vODumEqFE5WvLX+96ifsJiv9PPZKvTj
yqBwlqu1PXdbe1hbznQ6XBvHdtOuVS7Ta117ni79uLaucV7XBvJZCvXj2hBu3a7V9kyl+nFt
Yr1frezWPJJC5hbyo6w1iMH61DheVq4P6oK7liExZSFlbCvcpCgnKwFuaHSpIY6W2+SAmyIH
RlAwukI2E6G7fp3wWEp3VAExKp/UDbaAyLA15kwyWrlquZPBoqN61IZUiwBgRB9GC9W1gtni
BL9O0cQFh1n43KgtQPBjC8Nlg87c2CtgiWiHEMkI1411YVAVwYaW2JKiUa057hQjGS0xgUrt
RrMikhjRA1oyBidr2nbCWE3fi6RJGMeiXSgkpp/YRHhY4mEeAKA4TQQdqDH81YqILWGHteJj
iyjQq45wjBVvGKgSvdGL8j4tgF22rDYcWu4+WFarjSVb1H2c2eDk0/B6dckm6q3m5pURziPK
jsPnGPWmdmAB2t+LQ2IdjCRQ5lmU89YCtGTNamzJkvuBaVnxdJ5Goxa7n8/CO3SFeWMTACFf
jYMt6tmP6GSLiI5vnKdy8+3tgUCOyj4XunhbNxvCJikCLtd0U7MXCmx/Yvj6rTqVYCRe79QN
vWypNJUCV4bvdm621PQe1uWabulmS63TuPtRWKLXH2lJJURnX+WJ93OzleedHT5qU8mUyyVP
rMEL3PPprXpf4A2uV2u64YoorZ5mvN6nW3JP6RmOlZIbhf47Jcrj26pPRv62zqA5u5oGA2Bg
qQPzk+l3pblyCF2ed+qULqm6DTdHpeQCveDhOfRvv/39q/tu58obz5zfvP7uPo67N/f17od/
uC937+HMK89zM1/U0LuoNW1cafdz18Cj2kZgfMC12j4vf683+3JtqUMDv9q32xpWI/PEHzc2
TcKd1fYeq8GDPxN4+fo1U1xYKonBpHrJ14FC5SvVRqpmUj3BlWUUo5DFhnEaemr1jEZosQho
VRqOrrFpNqjIw8tUAkVqjfbRGmPZztp6PUSlrJvnuDRv99QtvFcBehjzlhuvMqckYo5XftBH
EgzoDHAhkywyRdFzKWFlMqaUNAKyRX4xV5RtV9R/K9IoxgCzQv9srdOc5219onfranxtk/ez
AxgTEZakYQC1ulVRcKHU06Sp2CmLU4wZ4A5qQEsMUrCcRlm5SGwAbm/kzbKmRs+plWwUD/5R
r3/VFmrGs+Y+0b/90mKuuCrQxAAMJ1kRemFg8LYropUQGS0rtT2KMPKL1alWXjhApFGLyTj+
yQKuCflxeyGfe8C2ihCtFp+W8t8jmmj7032+++Z9RPvzjLSLjS2IjWrXGvvVfYt3sgW1uzdv
/uWLX727ifX52tfjTRMhqOoruKB+9vQck+RxZaVdr+zWPr1WGUx1pWdhpptW1jKco9cqu6UR
3kTnayp38gX98tPPb+pjbiNC2F3p2I199Q2nNeUqM95Sc26yY8RyfRSfZYs/1vE0vuYq47+H
6VXjjU0v3JKRnTrjLPbGC/+8ItkIr1Z0S7O9ZPW1XunS81b8I2MSBy/Xarrlcre3ROgFv+CM
+PTzmwWA2Ism13p1Q59b6ZFu+mvMd1sTeerxxJXxu53TrYzOo5arnP4+q/zG0ZipazwozvUv
RovczuWICMyrNd3UPTcmY4Wv9OmG6xxHCuX66N10nfN8RuqqYrtecuV8frN4O9gvuGd0pVc3
XOc5MWDjKvfdcp3nnJ8cv9ut81zewenvOlKtfiu4ix1YNERHr2WJ+K0BQSDLvfZ0kiuGV71x
aNzAuUXWOy/lkR3z7V9haP3n2z/d17vX94yRi/nuv+5zpW/tb/ft7vvtvty9kv/88B6WWH1e
xNy11s8u2sHD1uO4LPaC87K71395j7a1G7ctJXDtxbb97u6j92jQ8+KQLjRo4CbUlQZ9y7s5
X2/f/IXRkGJiv4PT90d4HjrS4JYYTe/jlwAb488AEk+exU5MjHs7AkmBzMt0NZ5GfAD0qUDh
BcnaoWM8AIoCVQ/GAw7lz4FgZTQe9456RlmTGjaF2Pgw3wPA08MJHhsPwx8A1iS+qBJld579
IVAdwAF1p1R7AEQHcFGnt1XLDqws0vI+MMhn9FiVQqqIiVfjA6CsFHAeDjoJHMgK5NVwfbup
rUpwlW7wRTbrPJ+UmfDK+miQDmv80uSRr/esIWxSaB9PnpHFScegA53PWc415whDFaOu7HOu
/sbiXMI7cgMT4cAk0Idz2rAnd6YDcz2yQyAy1CTwzpMBRlvHGD/AU97mgIYtdi0Bl3gSgy1t
BgBo9KU1q44VOjsWYMGOOhiVcQ8prOED0BXQWisfrkA4ZOwL6ApYGRq6mlb6oPGitujgVFXP
bd4BDTE1OmuEDIMqHRgKWJVJ42MZmuLA2CwCh0DUkOHqowmgKGBl6INfke8jOpAVUEYpU4OQ
u3MKgKGA1lLoNGbYUFtAV0BHvOhROeyD5oDZC5agMgwphVUJw4hTWK1IHJ2UvCeF3lzQmiHz
clvS1wgNwLQD0GZmM71kJSy6k9Y3R0cO9B+nRSUk787/iTdBU5rOedAUogLahmRPuq2lnYI+
rrYAxBZLo0SPMi6JfHvjAASOEV5gM1Eb9LVSANowWQuYw9ycMQA0BZiiI9xCBis7PxMoZ0Dk
LOeJ9jlQjgAP+pLsGnOnowLsSu+JCTJYzul4BGRV8WyER28OzCOA82KZgTK94Vmf5BI+Dpz2
LpMjI5eE9bPSAWIs1WKCrwuvE6i2uHEtHE/jiYBUkg/lJqk6s+dt8rQs8aqfAglnAIh80L2n
DWXnlmzxt5HBrCLMNPy9ibXLHN6I1jW0TSSmFaHvKSPGQfe6JsY4eE+AbmUEzntb7WrcMQDo
gDdsJKhlNVS3QFibKSqgHhIB7NIn4qUKX9kpBmTycPdnfZt0iimS7SStaWhdz7b34zmrUghY
oVVD5jqDJwgMdDMpz4PCw3bdd+rGxy3w7o8KxiaSD08yCdANYBxo5xMLpAvpebLiM2OFBuW8
AXgsDxumZcD7oXxFNDptL1TqkgEAYTGKsbu97oC3RmM6S9FNPrMMfYA4rzIwY2oHGzATT4nq
ahdjZaLdHwAw9Q3m1lfPcFCPF6Kt51njUHr0sYkaK7nGCrsKrrb64BYNksnRZ4cZ2mkfflZR
13Dre1qzOpdg65qs1LvatSPFdBoAsbOZOTuQlF7NwlhIx8pqN65eTJe+6BkYXsaijAV0Airh
ATAsNNgWQKDrqZvNSeVwt5UeFxkE6DubdM5QLw4oPRZddE4PQCPgbFC4c41mIZAANEdoK0Fh
glAfAHEcc1BqH4usazALuzX24S5cUALklQLiWtg17x3R91bLGhpsRGMf76rPayfbDgFAwmNN
rAng6Ozj3bTasFJwewBQ1yxz6U8k9GmvBBZvIeaz72tiaI6xViLVXqzlsbgPzIbF7cID0yq0
s5ZqZ90NB3B0yvpO2KKT0ovleRrv5goBFSipugyjhKm2rxCghLJlhKBSlVExLqApkF1QglV6
8eFrWcVgcXZFPC3F4uxOYzh7XvJa46G762sEGoGy5LcKY+9ZO6ksdvHddWzSksWdCgaA7JsE
ZrnHJb4HTBcClmJSBRTAJf7kvgIg+1YUdRsx5uoM5SCQfPcCCyPnotuRztSOcWq+A5FA8v1w
crOzdYfJrAro4AkT5s5n52w7BFAU0MEavJ6PLbUuuiitrVZvDTZh2yaG6nuNC5IbO9xX2Lb1
nQfQDA/YgeHxAjYhU+9DLKDD7KjUDUzdCMoWB0B1GsQ4pwWMI4D3uDo1kNAvAylQIFRn+QtA
o5mEYwrVgzL930nFEwA13lN1zuiVblU8Ajy1DOz5qn3pIoBG11WD0xx4tBnaWEQ6ArStofKp
sBu4slb4ZLGqJMMuIuTmlhQueeH94OpKd9KwcjgOVdOH+t2oEmsR8h/IeejeppZXclsaJ1fE
eaoAPd30XbYYin1Z1kUx28CAjk4nqbssGwY3K/E4udlzfBUUBkg2syeqcbW8B7KZQy7F7qaq
bS9iGGmZmAzeFlSqMcRUjLNhye22ZjK1h0amXhg0K5RbXdILBG/VkKWdOpcLJerT0MNtzEaV
O7Tl0MisVKal7m4ZvYhiM9b0rZU5bU7hOcCzKnN1S+NwYfc3y4LbinyB1v00jEGBL6E6XfRd
6TEc6HRXuD9p0hODvagvYKhTZBUpMg9elLiKgLOh5+VbmHSK9OBmPWN0GJ80vJmd/iD3WfHl
cV5qWI4Z+FPrNG3MvSh1OQY0iBRerbSGD0/AFN9IMMB4C1Ejx97q0yuVr37h2EKfZaeSXRlX
ZqpLY6APFCydSFxbuOS4m8tFrT+nEaO9xtSpEIIOthIpYHF/UJU6mGtD3yXJtpgnU+CJF6XX
4zs6oFjtWR/fcQOv8MJFqGbf9qHPnIW6UujF20CmIkApDUB3ig63F7LsRiC3MADWrk6/B55f
UcHeO/UjvsdSXS6xK+6J6l0vf4RgBkIHL5A2kg40sLSqEB2eqornX6bOdG/ZgGSGZiMrYph1
e6d0xGsII5pp2mGX4+pMNYD2N7Ro9U/2SicpQsitIyJTOl+saTZcBfvjdF9iL/Q2Tqz/vICu
gA54oUTBVMYdKARcqtNdhwfKbAYK5Tt+JEa3AXqyoCOr8CSQFNBWZAp5bpZjAZmAjlWmc1zY
JT+itchEC4imU/fNSPh9IAhZ60i0dgdCgbSVkVof4u3UHu54KU/KkGYbQ0cqYFA9Vchz2xQA
D/oaIPy6Cff46AZOYccLQLZZd4w/VA8zheCpLJuwU9V9FQ+7yUpVdqKGwFZQOpmSQRMfAq+Z
osIHheEFNoWr8wHVhs6bGsiIc8jZsYxwEb4Nct9SRD65JFzdd/MKbwfNZb0O0kH5vRWePtGv
qUXqdXxoytqPzNfsoGuriG7YXjfahqrpyOY5+JZRUM9US7zvjy3I7EbZCqWV0PitjoiRBRBM
LYz0UGAbM/UpUOGuze2YAKaDWaejW7E2CoCqW0sdbDB+DUqdXbV3fcJSmJF14EnMiAcuTfev
lUYS/tZduOrTA9VNpSodk/YKPVRk18j3rGD96KRXbLgI55SNXcsMHM3aTcupgQ+fwOZVDblA
LHAw1eFZJv06fMqKlZZBnRrTaClUUjYsXA4Nwh3wjCD60RWgEEX3tGcFKjuPz4NlUfcOfTdR
ATqwwa2qKZXGVdRh9lYFeMu/w2WkDatUa2DAqbRF2ErHumtqrSIUEq8RNJcwpXKbwJMCwXJQ
YcNPVCldKECgDehKLUVPQJbwLapYQuZbmfoOA3Ya61rhPhdjsk2g4C2GyRfPgmVJ2LXxY1e6
bwDA7xJkf1GiFN1qsju7igq6WKYtXgDQIdSHaGVgv59mqqNW7NUyNyqn0C5sPWOaSoyW28ML
o3lnuz4Yrzs3Oqs5VG880KuEElmHjecBmF4p9t3mqs4BmMkBqiHHFAZ4ChE62vWH9OopnzKd
ZvQdgdX1wuEtbU3RJFDjmsTKGWltAYVAXymwLcdutj6BokD3waHWYr5Z0vpcXS4+vHwqbpom
TyCp1pKc/Ziiml5OIKoOYoXSHQ7toMUFFAWas/Tg6a4qxaQzNv+gMrxU3jTgzl0XwMD+mte6
wTsVOITKC9DHN9ZCk9pGN1uKdCatmySWprQPe2Jda1UGYxSf00o/1oCGVx3AWoVndvj6x24l
g5VNQtAkAWC1NnonsCda1xtfC4BnVZXg0vhbPd1t4qLnhB1HIFoEBBCETrASOs0uAaKqIEU1
cEQ02STCnzEIdJN1Ha6FNvhMCQE6LaF/q11dBn/DDt6NtgOkjeNHMfk505Kwk8/aTVt4gyzC
J/YWkDoBk47Y7SGTTT8DjTCYxJdHTM7jhx/0ARUHKNejbxUUl9h4teEECoHoe8ngG4hZFxoB
pW07KvzRDvhgd4C7S9OFhg2rRW7NytAAqu7VlsU2bxgnaQFZgeK7oqSlhTkXUAj0tY8yQVWJ
QaAeAW5NzFEWfSA7ORveZ2VXAGMqEH1zL9xGq6qmBKoC2fUBaC2drz0+AKprELh6MXyzIVDP
AH2GcfjKJNCPQGRUI2Sl+bcA1DOAFk4Fv6j6pNsOzW1V+xLVEOz45gjK+hshsG7mAoYCpmFV
qo544XIH7MlLbVjWMDY/3yWdSJt/qvB4gm9I7kDb7KHLt6oIRnBwNc+90FBP4fQ17yrVI9ib
cweaAuZD55S24sxEIBGoy7+KxSlzE5Y7Fa+woYPLkYnQK/iJlooLrViAsJRg/MCKL6SmnkAC
5lKk/YfDrbQA1YeydQUO4AFdvPoJGS0QAubxo/cGDgBzNgMgbVOgFi2EmTlxAXQCVqZKETTG
HKqD9jJbt3yEIvi6Oz/MRwjadO9JaQcr1ooAEAmY0YanmSbUtGyONn2riR00H2GBBYUfnBnp
IWBZBuTIgKNtLqAoYCYVD+7hUjELNkbbUGo1PyN/NxVGfN6BqoDSaizKZhDMssMR+qi+Lnri
o2A4HTETFr/NwnejkhlhGcy68UxMs2QR2XzgyezTTEECC9bcDkV3YzRCB0O4XqQWpLd1taxr
dXkZ1kFf4FXVr1d6VnCF09wOle7u6eILxjpydHP9dLuph5de80NAB5xPxtJl0MdDwHwI2nBY
0poF+nmkZmytAHBGa3zMimXpGoMTPGiqW5AOAHNLDPQDvhCbgU4HJdwn5hrudJQfAT75AcCG
T2+q8DnbHehnQOUDxKGY34tAOgNw3kilq1ymeZ3dVn/H+ZA+mWusyAOjAz04dPA9WaMHT6iP
ADiPz+wu1xNentN3dwnQKIORYQ4DYduqVkfdAaUtB8+XoVuaG2msx6gdGPpTNGH5twZNih2Y
vO8Iv1ueC1DaEqivKibTaI+A9swfms9mt/DmsT50rvL2azNVCoOaZtVfUO303sewDA3+oApS
aEVXXIjNfwYMvuLJd9lSHxrlR4/M8KCzCo0Lh4HuLuXv8vRh6j69pQNCKwRzn5I3ez0tn26h
KG0WANUZ6MQf9IkOQA6K8mQO2K6OEHiamgPYaUS+WJCahozAh2u+Z5w0DexnbSXgLVD3UhDI
3JjNBQ4DGrv/CP1QJE4ydSRRaVePQVgAdDbY9NkbDpUCv9m2+68HgBCiA/A6RJecGByR3DhE
sGqh/W6YtLRH/RUAHovYsCRkQ29hjb+IrLLcEpihRCDvEZXSBTz94d7/jCXA8xtLwYf8YNV6
LCKjegrCHqzhtABh/ZmrvvIgBDE6KxQu4sUG6ZkdWzReFpbB8HOMCgW2gMHtYIRnTiW6k4FR
Z/htXZE3K8gMlUAK2HkMnWYFskybUXikISrStM4WLhsBTCsZUpwMLX6j0k5sMj20GUExFvBF
pwKOnqadLOlzWI0vnxPg+sp41lwHPdKkztUPkrAopRKMlxahCj8Cw2xWcN4H2t3udBjgJz6C
n5mBauauHTwayIibWKISt7mza18mrfnTCcuZnQh0i7Nq+suNaTk+wamga8y+oxb8DC+fdnyr
/tjCHME3+sSHsGRphhXzxFuap246n8hbVCIKVduBdgQqvVHwv5lrFEBVQFWlwpAHuBTsaD9r
V3Y/ZhoaFCIzpCkSQzVxFrV8jjjgmu684y/PMkWoZkNQviZ4tRUYVCQFyKo6VRlRnAPDcasp
NFYZjyKY6VIcCOq0EYOFUXl4WW0ZgohrwOslZjs6UMxThNgM0Mn8FBohjB95iea9Y2AA3mBw
lwH2pwRFcrlP0DVsY5ogN8bPuQccV/gKE2T16uLnzGfdVkBjibyVndw5WoL+HBv8GqwiT41H
RDgVyKHBQ4gbHApQ/qLRqhnIauTIIHYoKqBRJIgrsxRJT6LNb5Txw+043ZZ8WmbrNlJTBUhu
+mN8sDerAhpZ1Vw/znVqtMCp6cacETHG+ZhG61B1d/Vnf+TBd5JcGYWI0ExdebnoWA3+WsBb
/bU0hNcOV+Rz0cjL6YZ4LvRT4XSjGkAfE34kTVXAnKexvPogch76kJmwiSVokHyyalLUZkC0
cF0Zh+PCDARAcmdJxkLmem9WBA8fISGGJeBlsmwhYznRbwwJpCIoJx5rIhpUFaGcqAajZktA
gQ2pZ8MLhkiUi9FyqBDCob1OYuIhde4u9jJO7TeeJWkrIv2yGA+1mPE4QcL9VpE5WmZs+rtl
spFoMyLdhXgYY1oWrA3sRU3XVI48NeQjv90BEauYOa+WrIPNolkWxpcVd/Hirm/QjXnR/BFV
vqcOAK7Gjf6+4gWICESIYVklTqYwCyZreHUNpsyi2SJMC4Kk6gJI21ihXwONzHsC6SEAm3O8
NohupTydbtzqk3ecntTi0YmkK2ndNrIGX8tQmR5EIBHwMvFaBGNv1wRVPPq0VohMocwxNvYW
F6BvXPuUBzwxJMxUF8Ap9vlKVM4KRmYHuM9XW3R4/4S7eCl9AZGALdxEGykP1xoJcJ83qxXs
i6cZMXp9AZWAiYdkv3Qs/NXXCpgEWlprBHTOToLfQU9fVCgS5tgOcImMaFkmFYHmmywB0NkX
KR7PrGbZkc5cc77IIz+bFAVdlO4uFvDII85UqgOyswgwggGMCcTvcMfhQGOKnJbwgfKS1zrX
B6oIWLUMH2PRzQE8oJDXUGaepkAdKTug+onShQH5EFq6dxLIB3UEF/Ui1ZFglejb29nDRyBn
McPRJV6ho5Z0ccksSwmCsM0FUH9JnoJnDvCLqpuLQFXAUlBD5/nGXABTmHsSv1uZ8fqPxdKQ
Lkon32QYzuv+OQKbMoLtSpUPsvhQAGAC36U647qmKYtH2jbPAJ0fWpE1sulTRvtqaBpph11r
PATW9qobXTFJrBevCDTfkZnAfHGgy1RAO6qWGzZP3/UDt8Z1moFdH/FTMAnrAs5oDfPqfvII
oKvSZa3ow1IUVWMJKK0dwVEIK82WY1ASE9DxR4wCgdB2IB2BqSFYHohEuu500UfVIS/sJPcA
qFYWcTKR3JFOFWseaVUr3NH0iE480EorSuExkJvGGIrqvU4MmcD0/QNtx1catNxcIFKz1F5b
Cmi8nD9z+haNJIZ6pLwN9ZWBvK688xC8qpKsQKIAAl8ZULIpP8lO2qFGczmYnw6KdhmqDdkJ
AMLw4ClX1qxTtYi43Ooa45NhDSoQedkAS98ipRKDf2GpWByoqTuwNhWAUaHmj7nmC51XGUEU
K5R/UKjZuTltGYq9XpbLtqjVZv7XyLiPjOeizNFJ/yCEqwW9wMgyQ1D9OpX34iix02UAhhtt
SfMENfp0cE5gHsXOEcUu4NFT2TS1BUxoDgiANGcpgHoERrWNp7mvrZqN68BEYGWuu4Ua9feC
BVg2rGp/0dySUx+Vbn5QNvQhXyiMoy2gKWCXlIaVMcw6D8PKGHY3LeJ4DpOXFj2GAlpm5HE3
7Hm7kAiAtMUy6m/cZrged0BprRNGIGgL79OAUdAWvJf5kG7G9bW8gELAIi6hAQwAFl5CoCqg
HoPCEypsemPRSVUec23w6K1EP2ElkAmkdTtOHSixDAeg7VEneKvekUjNrPZ1wQ5OmeSRNYxW
HVDmQtyBpoBd9GNABbRt8+cBIG03RvkLgtQHzX0CwBREi091/bxYuypvnAEwn0ylggH30n4J
Eu8cFo99GnqDAEERYQcygOw3K2G5A3AfoF4ygBXglzF5H0Fjep2m28vb1XilocDgSAugp2yW
5QdDln5aZKYCXtYtVPri3NNJ5y1od97RPUtnXV0A6Lpfh+bPZMq8ZQfGJOAtKOQb/FjeDtBD
2D3ulg/pVETArPu2+AVNYeKVYNIQmfsFav7GpgeWwYcoGokoMjXsQAJQ9pBX+QRe8J4w/Lem
dcmXYQrwffr9WzouYQ951/gwIC7g7deqEdWVXUQjRWEK88M1TjFDKPbQ3cTAMB9gXqPFpRaf
0qnv8O09ocGJsC7jm87f7cVh8ipzMsyrh5UA4WgeL0SaZ/cWZmdu3uaGHWn+PJLJVgKFgXrl
LEX0K+p68w73AM2b2nlXBUBY/Zj4+eDTaOXQzLYUffaUAYVm3hCgUzzvodB6mDr3cGqeto49
QBs55hLPjcd0bZmonLMM37xf/iav8wrIumEuthGc6WMHKoHlr64aOOKu5YYJQWSJd4RmGQLf
+g40AnU5sAfPQZtf3aalDCCt8OrJKFCXlepFA+ADynt63NHbAyCsxR+ShqcS+BpWv8oUlet4
XDPw7kDV05G3auUjSGAJu8P5yv8BzaPv1Q0KZW5kc3RyZWFtDQplbmRvYmoNCjI1IDAgb2Jq
DQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8L0dT
NSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjUgMjcgMCBSL0Y0IDE4IDAgUi9GMyAxMyAw
IFIvRjIgOSAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0g
Pj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVudHMgMjYgMCBSL0dyb3VwPDwvVHlw
ZS9Hcm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1MvU3RydWN0UGFy
ZW50cyAzPj4NCmVuZG9iag0KMjYgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5n
dGggMjE4MD4+DQpzdHJlYW0NCnic3Vpbb1y5DX4fYP6DHmcWtSxR9yIwEDvZxRZdoF170Yei
D8bYzi6Q2KmTdtF/X1KkdHTs44kLBwUyCGKbpD6RFCnqdo5f33/+7eZy91md/nSm/rleGWW0
McYCmKRKNCp4o+6v16u/fadu16vjH86DevdpvbLqXW9sojUuzFrffLde/XW9Um+xV3X8F/Xq
1fFPZz++UebkRJ2+OVNO/V47y7UzoyEm7Mt7+pliUT//sF6twIIuXlmIGkB9WK/AM6NEbUC9
X6/OF1RYUbGCJHCn0wztdHgKDA3sQkCjBt0uM2Ovbtfg3gpcdHf0Ht2+gaM3pGPSHRMz9uoO
DZ6MwEV3R+/RHbvhJemQJ3AApveBUwOHIGCrTZyhjc7xKXjuAZuFl0YNE8AXBQX2+F16yGiM
7QwedIxfgFvTrW/Ggra5Wo9jYZ2CnInxFL7nW4xFlzTgIwbCw5fwU8pZr22zFuE+IE55m/dZ
3zMulELWAw41CDwQw9uaRU/hW9IZXbLHn7lk+umKuscJ7n3UAbiP6lJjYIQhKB+MDvgLAomr
QmjUDhtHQ+Fr4uhHqFDcc20sDKsdei1Qk8aemaLGoljEzUqGzmzGxr9yOUIPI1Udg8EgTx2O
CvYSLRebQ3F1McphijIUVfXhMBSoQXYmakfTxOo6aTuNnSflLA5VUQ5zOSqaUShiAvU5QKFr
QvAjrlG2NWU6Rx0RwUDIMPXKBDVllSIUawQ32jrF9lv3YTFosQft4epIUQtYVcBzueBq1RhJ
m6AC8gE9MJbEVMlQJtSOShNQrRRGRIsmaKegN2ZGxnJolUAhu6FnoXZUNKviJhajGDq3eQjf
oTizGMe0b/KBqyllS9C+ei4MoLUjKHC5ppHxJAbvWFapHW1pck1BEQcYoUxJz9S4MbCgoMsM
tZiTU89CUWNW3MTNSobObB7CeCjOLIYx752OLgVtoXaTePPBDLIfm7hUtA3VNxS77FlWKaoW
uWhTuhg3WwOUKemZGjcGag9KoOTb1LNQ1JgVN3GzkqEzm8dqeiDOLMax7RcDbqxS5O1adbIz
EtkQAHQiLyyJaW+YYqOoMjgUuy52cYQ2CnpjZlDhwGrGUJvd0LNQ1JgVN7EYJdCZzWMBPRBn
Fs9kbYcecaeUxrQUhuRWxG1V6mlJu/E0pmVMnlo1ccojlKkpeTqj5pZAJe+k5yktRXEXmxE6
s3mI2KE4sxgxu3fJM3Io5zN9pTJ7g0cdzCVKKfTG9j+phNtUD1ciA+gggNYbNSOK8gqHThDW
995sG76mSWRkgoAm28Z17VuyeDEgsHfxgogHbzaq1O1zZ2RdsC7EqEuonqAYkq0ypsi0FPHY
2MXZjNBGudZYGGh8waEQKHo19MwUNRbFIhajBDqzeQzWgTizGMd23HceSyjdL3nC0QrdGIVs
cAErOXnhSOxCrDKmaB2NVtdcZXEMI7RRvjdmhi1kfoPicWfomSlqLIpFLEYJdGbzuN04EGcW
I9YuWLypRXNKy86oueVNqWWX887zNJ/S0qPW2NPS83xv0Ea15GkMzq0G5bxrPfe0bIpFLEYJ
dGbzELFDcWYxYu2yJOChwg8+NrraGfD84V3zgS4+/eBhwPnsUpfizJ+AQrjetNJsY8Ox/dJr
967pFCmbI8DR1nFf+G37sBifdi8SXW1pIWhcA2kHJQxntMGjvUvUq8XzHYqjB5ZVivY5OIGL
62Kc6gNUKO6ZGjcGipNqUBvHnpmixqJYxM1Khs5sHreDB+LMYsTaDUgsZl42OqOmVSx+KBux
lHnZSMYPZSOZPEA75XrjPMz9BuWsaz33pGyKm9gM0LnNY8QOxJnFiLXLDk/PCWOdF5prNWqC
Xj88GjJ6GNBMO9UPdKEDG9HrB9NSBgQnNZx7nSq86GxSMwFnto6L1bftw2J8yr4DVnB0rqaH
A5qddNxDAE3R9jKLx8RMjx8uOIKBvLfuxU1mnH+8vJ1ePM3xny9v36nN9e3RL+dbMYsekuvL
sPXOBGUWXpJPL9ar4+/poKkubug92eA/rFZWA2aoD/U16+KDvDRbhQb+ffP65vPWxs319sht
7rf/UBd/Wq/eXoxPzXPj7IuM8w+Ns8bRPeKyca+MCekE/CtjDRibz4wtr08ckmcJlTnj3r4x
LpyeROIVMsCdHAH+fRqweeG/7WuCn1AviLaBWG9PvuwpvMhT99BTiJmeYqFk2iCTp4Yf/NFT
dWToefdiRy6XYEx+Mzfwf1HrMN1nijMeovCAi1PE2weKUd+pi88YDPd1B8PiKGS+PfP5/zoY
uOp6W2/icGIuDEZ4xmD4Fw+GNuDnA4KnKIe/nKXqsDAgybivNyQPldNdIi5/kLSDpUHxi4My
fKQxvYa6QNcg0fCbd6jVM6JX3mMrfrpI9UUX0zHEoX5CCPUWhepntMD18wvIpypofFGA4FEF
9YE+GPC4TIVHBfTHDx+pdt7dYx3Nm8vbrd98VjdbW5Clvt9aj7+pwe9bGzaX9/TzSm2P8ub8
endfS+/uP39EhrWby0/bI9ioZ1Th9JUdpBdxj+e5qMsjBz/d3d1Wu8g8t1H/qv5eXZKj5M11
9eZTXUF2W1pF6noScBjwz4T+bfPmbps2/0be9T2NyPVV7ekZjuYXO/poqtH2HJ2lb1vcI2cv
bzk4H2ug7nZkco0K+Qebqz88x+jy9Y1OsX7Dsmz01fX7axxfjsaifcMnUe3qv3aQcHNQaCzq
i6uPtFPC/21WLnnnX7YDWPQu01dJ4QnvfqszanvkNzcclA/q86/Xz4iDf9kK/miWJDzlAd2H
OR3T42myxRlcQ3C5jc+Mhetl8+EHNK1s4rHf83stbbOToRsyuqMJhb4/IoaL9WsV/hiMIIEg
9Yb8fd3t+mTp1cnjGMtnTPSxzPgZE7WIfBOEqwyjbsTe/wKte+EDDQplbmRzdHJlYW0NCmVu
ZG9iag0KMjcgMCBvYmoNCjw8L1R5cGUvRm9udC9TdWJ0eXBlL1RydWVUeXBlL05hbWUvRjUv
QmFzZUZvbnQvQkNESUVFK0NhbGlicmktQm9sZC9FbmNvZGluZy9XaW5BbnNpRW5jb2Rpbmcv
Rm9udERlc2NyaXB0b3IgMjggMCBSL0ZpcnN0Q2hhciA2NS9MYXN0Q2hhciAxMTYvV2lkdGhz
IDIxNzAgMCBSPj4NCmVuZG9iag0KMjggMCBvYmoNCjw8L1R5cGUvRm9udERlc2NyaXB0b3Iv
Rm9udE5hbWUvQkNESUVFK0NhbGlicmktQm9sZC9GbGFncyAzMi9JdGFsaWNBbmdsZSAwL0Fz
Y2VudCA3NTAvRGVzY2VudCAtMjUwL0NhcEhlaWdodCA3NTAvQXZnV2lkdGggNTM2L01heFdp
ZHRoIDE3ODEvRm9udFdlaWdodCA3MDAvWEhlaWdodCAyNTAvU3RlbVYgNTMvRm9udEJCb3hb
IC01MTkgLTI1MCAxMjYzIDc1MF0gL0ZvbnRGaWxlMiAyMTcxIDAgUj4+DQplbmRvYmoNCjI5
IDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0
ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAwIFIvRjQgMTggMCBSPj4v
UHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAw
IDAgOTYwIDU0MF0gL0NvbnRlbnRzIDMwIDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFu
c3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgND4+DQplbmRv
YmoNCjMwIDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDM0Mj4+DQpzdHJl
YW0NCnicrVFNS8NAEL0H9j/McbbQZHazmw8IgSb9QLEHScSDeAg1jYE21iRF/fduUhDEFg96
mF327TDvvXnOrO3rbbHpIVmn8MosArKJSEhJPoQegVYEbcms+wk0zHJWmYaqY5aA6quZPEGu
/ta9nTDrllmwMFPByQ5FA1HkrNOrOZBzUzQVYNlM7zIex5DMT8zjKKFc0kBnqJPc0C8lSN8O
AwX5dhBhFIAAIbUduiA9sv0A8v2grBrFBqNYghWzHnDWAJ8qLLnw8X04iv1hVxrMxXrHNe6O
XGHHhcK+5VJhwT3sa+6ikcunBq67oeFYdsNT4FvdPwN/hPyaWYv8omHxJ8PqnGEtXZu8H4ZP
PiMTiIp1EJEI0lhoc4vFWOSmhtCUUiawJPbI/IUU/2pB/n9mnvLs4IIDXHLh4kvLpxLfuJBY
tAPwZNbuY1Zu2iGjcvNxZvefhtObCQ0KZW5kc3RyZWFtDQplbmRvYmoNCjMxIDAgb2JqDQo8
PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1
IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9J
bWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVu
dHMgMzIgMCBSL0dyb3VwPDwvVHlwZS9Hcm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VS
R0I+Pi9UYWJzL1MvU3RydWN0UGFyZW50cyA1Pj4NCmVuZG9iag0KMzIgMCBvYmoNCjw8L0Zp
bHRlci9GbGF0ZURlY29kZS9MZW5ndGggMTc2Nj4+DQpzdHJlYW0NCnic3VlLbxw3DL4vsP9B
x90AlvV+FEGA5tGgbQK0TYoeih4c13GC2pvUcVvk35cUSY0Gmd2gaC5eBFiHoj7yo0hxpJnT
r29u374+O79VD58/Un+uV0YZbYyxzpmsajIqBqNuLtarX+6p3Xp1+vRFVJcf1iurLvtkk6zx
cTb79b316sf1Sj0Bq+r0B3X//unzR98+VubBA/Xw8SPl1T/NWGnGjHYpg60Q8Denqn56ul6t
nHW6BmVd0s6p6/XKBRqoSRunrtarFwsuLLtYucxwr/MM7XXcB3YC9jECqcG3LzRw0LcXeLAM
Z98dfcB3EHAKBn1MvlOmgYO+o8CzYTj77ugDvlMnXrOOZQJHR/IhcBZwjAy22qQZ2uiS9sFL
T9gsvbhqUAChKlfdgbhrTxmusZ3Bo07pM3BrOnsh67QtjT2shfXKlYID+/C93lKquuYBnyAR
wX0OP5WcDdoKW4CHCDgVbDnEvldcrBXZO1hqx/CIA8G2KtqHl6Jr+zmEpKMjSItABiChLqoQ
jY7wx0VUN/tOpHOYnAxmS9QpjFCWyHKbzANWewiSoSaPlknCyeyY1cKSoDPOMPkNdR+ja8Im
Y2DtA3QVD4sAVpKl3nIsoS4mVVqBN0l73ABWt+3YZbCTlbewKhUmGdDiXgEVCWDaO1B6Ubow
4kSyMpXkknQCBAFdcZNVEnAquWQls2HcyHVK4+qOx7CYH+m2ETqDC7TlqePIQNYmqgjjDrga
i2rsRqBj6Rzbi8N+xwMJfE/QLrk+mQYKtDSrGOqKHyyzdI6NrzkWNZMi6JzzkKhjCWYxY/KI
c77Via1RhxYkDzhs9RHUpdWGCah2wZOuSed4Aimtrlgd3QgliS3jZBmAhgDREdRCoU2WWcLJ
5FjUwpKgM85Dxo4lmMWMyanC56ita4BMpwIaQKZw0PS5ahtbFKD2JZCuSbjZS9WmdjWcggYo
SWwZJ8sAnGGjYihGMVlmCSeTY1ELS4LOOI/N8EiCWcyYHOQinHhyonNUC7IPZOQQndMZo7Co
xkNbTiLhdveg9l3t0wgVyfXJNIDdAFoUQW3xg2WWcDI5FjWTYuiM89gVjySYxcuSHJ0TnGny
WJY8wLWV4ACUe1niMTmPZZlywFmizmWEkjQVTx9otcVQrju2PJUlO+5qM0JnnIeMHUswixmT
y8qnN+4bOP8Da7r50W27SYXCgUsIFBPWFIRj+3+xW9vcrj2sc66DnBNrOA0lLCxYO0bY0K1Z
WT/xxDqkwKCJ2/gIu0uMFzMi1z+X4PJL7ms76PaBoiu0gJR0jY0zqF22TUcSkshJl9rVxYxQ
kbxM5gGgWSFohgL/wTJJOJkds5pJMXTGeUzLkQSzmDG5cvsA3RLf8QTE4cNYBipy8BGaNkbh
Ue1jajqS8JGZrG5VSeoUR6hIoU+mAVuRvkDhYjJYJgkns2NWMymGzjiPJ4sjCWYxY/KSI5jW
H6ey7AOttoKprcNS3QXa0FNZBvCaelkG2tkCFUmKRwaotgRKdSeWe1mKY1YzKYbOOA8ZO5Zg
FjMmbzAi3BTCEKPIjWeES0XwEgO+fAxDhBH2s89dCzt/ArLg+9QmE0fBEX+22qMTn6wlOgwc
uY5HwLsdw2J+5A1G8m2mdVHD0w4PSzzgjTZwNfcZrVq4tIE6BUe6JuGRBjZw9V0NW32AskSW
cbIMgDorgdo0WiYJJ7NjVgtLgs44jye/IwlmMWPyBiNVM28bfaCVVaphaBup1nnbyCYMbSOb
MkC75PvkMux9gVLVieVelOJY1GaAzjmPGTuSYBYzJm8wAr7SH/s8y9SrwZPr/SMAkTHCCDTt
1D8ghA4UofcPkrkNMI57OFmdOjz7FK2ZgDOu48PqbsewmJ/a71I+4i0qmQK/xcd2l4KrXQnw
KHXtiJI9/oEDEWxS+T4KXmJsdzCPaLhqty8Th4ETkxfvz3bTh0dz+uxsd6k2F7uTn19smRl+
z20faG3wBlwtfNB9+HK9Ov0G75nq5Wv8rGvgn1VwySwQDsA0KK75e69VQPDXzZO327i5fHO7
DRt1ebO1fvPur/dqe1I31xfX2xO/eXWBvzdb5zYftr+pl9+tV09eLn8Q9nIjzdG04wG+KgoB
sqdL6Uu12qvdtx7uf6+HNi7M1iTDEzbDkkSdPlmSb3ewJLdbGzcXN7uzK1yZ7Una7N79fvEB
1+IrtbgOc87+y+YwQ+0kPKBBIX+axFdXZ7s/Gsm3W7/Zvb2FX/zf2dXVNm0+fi5tob+sa++P
4EQIxwZIElQq1GvP2371vsTFL7sIqegIlwP44+KnaXt2cba1ZvM3JO8/5Cl9WYr4nR9awB6K
UFknrmXm9nvcUBfA9SNkaGlj/Qs8s3dTDQplbmRzdHJlYW0NCmVuZG9iag0KMzMgMCBvYmoN
Cjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRXh0R1N0YXRlPDwvR1M1
IDUgMCBSL0dTOCA4IDAgUj4+L0ZvbnQ8PC9GMiA5IDAgUi9GMyAxMyAwIFIvRjQgMTggMCBS
Pj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94
WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDM0IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9U
cmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgNj4+DQpl
bmRvYmoNCjM0IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDM1MDU+Pg0K
c3RyZWFtDQp4nN0b2W4cx/F9Af7DPO4a4Kjv7gkEATpsI0EMKJaMPBh5YFaULISmFYpCor9P
nT093JmVoh0IEEGAZHV1XV3V1dXHPHh8c/v29cX+tnvy09Pu32cb05neGGOdM7kbkuliMN3N
5dnm799112ebBz++iN2b92cb272pnU2yxsdJ79ffnW3+drbpvgeu3YPn3cOHD356+udnnXn0
qHvy7Gnnu/8Qs0LMTO9SBl4h4O+chu7nH882G2ddP4TOutQ71/1+tnGBG4bUG9ddnW1ezIiw
ImLjspD7Pk+ofR+XiJ0S+xhBqUa2L9xwVLZX8mCFXGRX6iOygxKnYFDGKDtlbjgqOyp5NkIu
siv1EdmpKj7kPpaRODqGjxFnJY5RiG1v0oTa9CUtkZfqsIl7cdQgAMLQucEdsXuoLsMxthPy
2Kf0CXJrqvaqrOttIe1hLKzvXCnYsERf4y2loR9yQ5/AEcF9in4MORt6q9oCeYhA1wVbjmlf
Iy4OA2rvYKidkEdsCJaiaIleg870gxtwCuIvMKG7gfkdQuqjYxZkkTaAg13sQjR9hD8uIprk
OYX20DkRO0Wn0JIKxJypszTY3oPRQmpyy5kh7CyCBa1aMulEZ+j8G2cjMDBh0gHrSgAbPQwK
cEmWc819MXXWyZoavEm9xwlhe5qeFQY+ufMWRmWATgawOHcAxQCw9g6QXpEutHQKWe3KcEl9
AgomdMWNXBnArixSkKKN0LW6jm7cfOM2zPpHsy8tqhHShQucBzgNaUPuTewitDtQ2FhEY4oC
nEB7zDkOk6A0JFBgJK2Qq525oUCes52QuuIbzgLtMRuSYEWLUkw61bnx1n0xZtZt+VjudJ4i
yA6xD2S5NDhcFGLnfKGoMQHRLnjGEbTHWqVQxAk6upaUIeGMnbUBUgWYzKQWQnDkLBB2ZsGK
Vi2ZdKJz48b7YsysG0s7+3yOvXVElbmI4AZUF+pSn4feRjIF0L4ExhGEuaAMvRkqGoqmhpQh
4YydtQFK3tgJKZoychYIO7NgRauWTDrRuc2V98SYWbdp3RehQMqJyy4ysjZk1CE612e0wiIa
a7ycFMJE4AHtK9qnllQhVztzA+YJSF5MaotvOAuEnVmwokUpIZ3o3ObLe2LM7N5KK+0EJU9u
w1IaJLYS1Ee5hiVW1bkNy5QD9lJ0Li0pQ2Pw1AaKLSGVuBPOY1iK4Io2LelE58Zj98WYWY/Z
oyuckc01780JKmwNbFkgljCkwBpb/8WMbTNtkgTnXCVyTrlhN4QwrmDohMKGys3q8KkkwaEK
QjTq1i5j35LGsw5x1SF3T0zIIwk20KzUQMVxbSj9AHkhpX6IZAmgXbaEYwhVy6kvQ0UX05Iq
5LWzNIDyAwyFkIJVDWeGsLMIFrQoJaQTnVtn3RNjZv2o23YfIIXiOVFAOlyhtWFAHXyETI5W
eET7mAjHEK6jyfYUq4xOsSVVKNTO3GAHVF9JYTPTcGYIO4tgQYtSQjrRuS037okxsx7Tg5Jg
KGmOYVkbKLaCGSjtctwFnuZjWAaQmmpYBp7vSqqQBo82cGwpKcedcq5hqYIFLUoJ6UTnxmP3
xZhZj+mpR4Q9RGhsVJj0jLDdCF5twAPM0FgYYT77XLEw80dCAXztSjDrqHSsv3Ct1qlMwbI6
Qtjq2taF37YNs/7RU4/kqad1sYc1ECsoafCmN7CT9xm5WtjOAToFxziCsM6BCTz4ioap3pAK
xJyxszYAOndKalPLmSHsLIIFrVoy6UTnthy8J8bMekwPPNJgpmmjNlBYpSE0aSMNwzRtZBOa
tJFNaUgr5Gvn0sx9JeWoU841KFWwok1DOtW59dg9MWbWY3q2EfBaoM3zAnOuBkmu5o8AirQW
RlDTjvkDTKiECtT8wbCkAaGTHM5cxwwvMhVrRsKJru1i9W3bMOuf4ej1C51c4Q0Azs7B4ik/
1EMwR/WKFfaJBa8xfPRI5+Ti9DjhqMiLdxfX492lefDXi+s33fby+vyXFztRDK+E6Y7XBm9i
Z2buhJ+8PNs8+AH3nt3L13gzbODHdtGDNTAske6lXv4ud8a2Aw1/3T7fubC9uLnd+e1H6Hy5
s2b7351L28v9h9udDdvL97tzv+1252n74d3u3G1fXezCFlBxe7n7R/fyL2eb71/OXzL7um0l
gdbTyYY1fcSwwTIwBIJNpISIhxdQcBh0dO5hX2UN3QTusXPpI8xRk/AsGGtGpIGocHmEHFaQ
1FkaTC/7OiAdIJy8Y84FRq/PwXJnEgxbcBepNA2xw3jCUxbWePB9ATF7NiE6RENA4lUehlzJ
2DBEpi4FWZXAOT+GDu8us6iVIRZBj2gS6QHBgjq6EXCohHSlBglsJLRQb5WsbHForAxNpG0S
zJfAWQx7wThS0eCpEaCiVXUCG/CsVv0AcM5Z+4BRUG8Ek5QFlPS+csfzCm8b4QkXrqobhFgO
Ve0KqVW1AW0WShkOYTwOFouVocQKaKjDjApHdcK+GiRuuiLaAvLFi8A64hsKcjBOAkg2o/tj
gUCr0QEQnR9w5FRIA6s2UNwhabEak8S5NCGLcvFwlSOadCoa7RMfjKl1Nh24k9KBv5sOUsAg
hK1zCZQMDD8ggWTQnRt8LvBy/+tDY4ZoTHn2aDLB/x+hHqS0Ygtd4oCPXLorF8Q98eHLRU3t
g4QfyryBIMh+b1cTBJPShUVJOfyw3uhhxKV0ZPjiWlZh8YmSFqyK8fFqkmB1zMvD59YTBFPT
L4YE1AbrScIjqa8VEhnK0vA1ZhReNrjFkIDxe/Jorg6YZjF/UhYLB1kMaq2C26s+QGo+nOZQ
cEf4k58ZW55+4UAcCC0QsOaI0PLUwFoBUpOx9jFLz+vNTNhYprgofd3gilQHJbz/mJF1EFyz
Lg/r1rHicthQl0P7txfXr2qd+hwK1J+xkP2xm61Qp2rGdddXfC0Y/YKaM3ntsGqur1CCo9t8
KPigNMKKOdDDNKz3EqVPfNSG9R5UEiHR1T54EkiwKoRocXgFYhmd+4ykhq6DBTJ0PSKdqQE4
x05JDR1+EOcAkMP3T9SZBRt6XEg6WboqI86ksoUNWgrcmR7hIdpTcQnjieUrNmDRCdQEWVx0
kLMjScOgkgo/YMDKHRSxeEWU8BSmQgW1oM7cYLnoF1IwH6p9Yozmj5wDWoODBw5ElTyNqy1k
gk0EJS+12QBWEb16YsDBKNoJzIK9nYUCWHhADWKzE/YFCkN8vViFlwKj7FU3gCK+cmG9Fapm
1QayWkl5RJRzHTCVy8OJOuWiQ40qe6ee2FejxFdXRJ1MUFcCc1eKuhkE+9xGQcl9SBojABjj
NX4qpOGlDRx9ROk0Monx0AQuysX7HI5r1KmG/NQNnyib88nTujcw8JOKz/U0Ig43SjO1cwYj
V6ue78jGrUIgZ9m1678DO3HHvGDnySX0oTAsOMOitFOXtbvSvKdDh6VxTKuaFmmaLpl2Wi19
KC3zs66lgTypoD6Uho+p05K0E4vqQ2mwe18UtnaMOONpCfkqcw3TYDw2jvPFdVMu6NEyZkyY
SB6XFVqkKE9GaqAFjY7U8JUsLZMFjym8oRcU9LoCFhOAM2MHPLEEc7gAEcj3fAxWGyw9WyNK
B6PlI/Md6G1oifpqA8Ti8158bGjlIa4wJo0dnusE7hzwMgvRiaoFTPy4hOGnBJmoca3AnQgb
hA8X8ehGTChUiuCC5kiTwI9YvR0hergonakhUnXDpPhOGF8PMGccHM99U49jNehaBCrhOAY2
IRAw6I2NxRMW2/gBG5Add8IaKNFrV2Fhk8MVVtjbZJGhirZ4MBZUMYSCVaUrpDbVBjJZSGU4
mO84WCJVxpI0yjrOpLBTN+yrSeKoK6amD0LIj8jbFvUxynWpCQHaf9cIsbHQSwIOngppbNUG
5sykEpbEOTdBS4IHjWlUqob71AufqBWGlbcA+OQr0WBDefYVD9ksvn1P5Kew+vJ2JyFbDp8Z
E9c9ZsNnk5QC5iWtuu3FAjYfGb68llEON4nLRq14yuZC4iywMHzrHbO5xF9ZzUta85jNpUyb
u68SEjl+pSnl8HX2Ykx83jFbOO3u8ECn4CkvBz/gHJyJnidrWR/wNDguSlpxRoQU+8Eu27Rm
9ITs8WAl+ERJ/5MZ5fBb1KMvf1OmR3Py4RluAApOdWzTm+lP9Vm4hA6n3Tq5uVI34XehwDlg
XXD3HvqXd68udlnulTu6c77c3+xs2V7u4vb2T7uw/YzDvHDaMfNshZ6hrEllQe9T58CBtGLo
fcCStGfhS0+z56W5jBX4om3rbqyKpxt//B5TMtxE2mfMhjB69JwVgcwQE6mAx3KizRX/23xB
f3WHYIpizR1OEPoydfYreI+3vngt7vWzZm7A+iRa/pqRbjgDl8KQNxmQh81F4St+FR2Sds50
roQHX/iZj0Be90RTbIKCWOkSH5FVIWHA9DAKgZRqqkYB9pmqKwNiyZ6SwNKEOu10/OAQ3zk6
54PthveHh/hvd357DdP9Nc77P25+p4zwFhr+uO5252V78c8/PmBmuP2cVJDWXQrpbXNc0Hzl
ZcMn2kVH3BHOLhvxM0qB0w5AlzwHkVPioecur9Eve/DfDf7z8R0mbcrlei1j/fbDNb0fusSW
G2gK2/eXI5lNnOo/x7dl/dVJ7HMw+2fs+9fOs3ofu4tdAiVvYUH67e377gr+Xl5QzB6q/T81
9Ow1DQplbmRzdHJlYW0NCmVuZG9iag0KMzUgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQg
MiAwIFIvUmVzb3VyY2VzPDwvRXh0R1N0YXRlPDwvR1M1IDUgMCBSL0dTOCA4IDAgUj4+L0Zv
bnQ8PC9GMiA5IDAgUi9GMyAxMyAwIFIvRjQgMTggMCBSPj4vUHJvY1NldFsvUERGL1RleHQv
SW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRl
bnRzIDM2IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNl
UkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgNz4+DQplbmRvYmoNCjM2IDAgb2JqDQo8PC9G
aWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDM1MjU+Pg0Kc3RyZWFtDQp4nN1b3Y8ctw1/X+D+
h3ncDeCxvqUpAgOxnQQtGiCNHfQh6MN1c06CXi7u+dzW/335IynNzO3M2s1uDfhg4LwUxS+R
oqiPefzF7d0vry73d93Tb551/7zYmM70xhjrnMndkEwXg+lury42f/2su7nYPP76Rex+enOx
sd1PrbNJ1vg46/3qs4vNXy423ZfEtXv8bff554+/efbH55158qR7+vxZ57t/M7PCzEzvUiZe
IeBvTkP33dcXm42zrh9CZ13qnet+vdi4IA1D6o3rri82LxZEWBWxcVnJfZ9n1L6Pa8SuEvsY
SamJbF+k4ahsX8mDVXKV3aiPyA6VOAUDGaPslKXhqOxYybNRcpXdqI/ITk3xIfexjMTRCXyM
OFfiGJXY9ibNqE1f0hp5aQ6buRejRgEQhs4N7ojdQ3MZxtjOyGOf0nvIrWnaV2VdbwtrT2Nh
fedKQcMafYu3lIZ+yBP6RI4I7n30Y8jZ0NuqLZGHSHRdsOWY9i3i4jBAe0dD7ZQ8oiFYjqI1
+hp0ph/cgCmIP2RCd0vzO4TURycs2KLaQA52sQvR9JH+cxFolucqtKfOidlVdApTUoWEM3fW
Btt7MlpJTZ5yFgidVbCiq5ZCOtOZOv8s2YgMTEg6ZF0JZKOnQSEuyUqueSimLjq5pgZvUu8x
IWzP07PBxCd33tKoDNTJEBZzh1ACEGvvCOkr0oUpXYVs7SpwSX0iCiF0xY1cBUBXEalI1Ubp
prqObtx84jYs+qdmX15UI6ULFyQPSBqqDbk3sYvU7khhY4FGiiKcQnvkHIckqA2JFBhJG+Ra
Z2kolOdsp6Su+AlnhfbIhiy4olUpIZ3rPPHWQzFm0W35WO50niPIDrEPbLk2OCwKsXO+cNSY
ALQLXnAM7VGrFI44RUc3JRVIOaNzbaBUQSYLqaUQHDkrhM4iuKKrlkI603nixodizKIby3T2
+Rx765gqSxEhDVCX6lKfh95GNoXQvgTBMYRcUIbeDA1NRdOEVCDljM61gUre2CkpTBk5K4TO
Iriiq5ZCOtN5misfiDGLbqt1X6QCKScpu9jI1pChQ3Suz7DCAo0aL6cKIRF4QvuG9mlKWiHX
OksD8gQlLyG1xU84K4TOIriiVSklnek8zZcPxJjFvVWttBOVPHkaltqgsZWoPsotLFFV52lY
phzQq6JzmZIKNAZPa+DYUlKNO+U8hqUKbmgzJZ3pPPHYQzFm0WP26ApndHMte3OGilhDWxaK
JYQUWWPbT2Rsm3mTpDjnGpFzlRu6AUJc0dAphQ2Nm63DVyUpDioo0ajbdBn7lDRedIhrDrl/
YsIeSbSBFqUGLo5bQ+kHygsp9UNkSwjtsmWcQFAtp74MDV3MlLRCvnbWBlJ+oKFQUrJqwlkg
dFbBilallHSm89RZD8SYRT/WbbsPlEJxThRAhxW6NgzQwUfK5LDCA+1jYpxAWEeT7TlWBZ3i
lLRCoXWWBjtA/UpKm5kJZ4HQWQUrWpVS0pnO03LjgRiz6LF6UBIMJ80xLFsDx1YwA6ddibsg
03wMy0BSUwvLIPO9klaoBk9tkNiqpBJ3lXMLyypY0aqUks50nnjsoRiz6LF66hFpDxEmNlaY
9Yy03Qi+2oADzDCxMNJ89rlhaeaPhAr41pVh0bHSif7KtVlXZSpW1FHCqa7TuvDTtmHRP/XU
I3nuaV3saQ1EBaUN3vSGdvI+g6ul7RyhU3CCYwh1Dk3gwTc0TfUJqULCGZ1rA6FzV0ltmnIW
CJ1VsKKrlkI603laDj4QYxY9Vg880mDmaaM1cFilIUzSRhqGedrIJkzSRjZlQtog3zqXydyv
pBJ1lXMLyiq4os2EdK7z1GMPxJhFj9WzjYBrgWmeV1hyNUlyLX8EUmRqYSQ17Zg/yIRGWIGW
PwTWNKB0msOF65jhVWbFmpFwput0sfq0bVj0z3D0+oVPrnADgNk5WJzyUz1Ec7ResdI+seAa
w0cPOqcXp8cJR0VevL68Ge8uzeM/X9781G2vbh59/2KniuFKmO94bfAmdmbhTvjpy4vN46+w
9+xevsLNsKF/touerKFhiXwv9fJXvTO2HWn4w/bbnQvby9u7nd++o85XO2u2/9m5tL3av73b
2bC9erN75Lfd7lHavn29e+S2P17uwpZQcXu1+1v38k8Xmy9fLl8y+7ZtZYHW88mGNX1E2KAM
DIFhEzkh4vCCCg4DR+ee9lXW8E3gHp1LH2mOmoSzYNSMoKGocHmEHCpI7qwNptd9HZEOFE7e
CedCo9fnYKUzC6YtuItcmobYIZ5wyiIaD74vJGYvJkQHNAUkrvIQciWjYYhCXQpYlSA5P4YO
d5dZ1coUi6RHNIn1oGCBjm4EHJTQrtyggQ1CS/VWyZUthsbq0ETeJtF8CZLF0IvGkYsGz40E
lVpVJ7IBZ7XVDwTnnGsfMorqjWBSZUElvW/ccV7h7UR4wsLVdKMQy6Gp3aBqVWuAzUqpw6GM
x8ESsTqUqICGNsxQOFYn7JtB6qZrpi0kX71IrCPeULCDMQko2Yzuj4UCrUUHQXx+IJHToBpY
rYHjDqTF1phkzmUSspCLw1WJaNap1Gif+WBMrYvpwJ2UDvz9dJACgpC2ziVwMjDygISSQffI
4LnAy/0PnxszRGPK8yezCf6/CPUkZSq28CUO+cil+3JJ3FMffr+ouX2U8ENZNpAE2S/t2QTR
pHRhVVIOX51v9BBxKR0Zvnguq1B8QtKKVTF+cTZJtDrm9eFz5xNEU9OvhgTVBueThCOpjxUS
mcrS8DFmFC4b3GpI0Pg9fbJUB8yzmD8pi4WDLEa1VsH2qg+Umg+nORXckf7Lz40tz37nQBwI
LRSw5ojQ8szQWkFSk7H2C5GezzczaWOZ4qr08wZX5Doo4f5jQdZBcC26PJy3jlWX04a6HNq/
vbz5sdWp31KB+h0K2a+7xQp1rmY87/qK14LRr6i5kNcOq+b2CiU4vs2ngo9KI1TMgR+mod5L
nD7xqA31HlUSIfHVPnmSSFAVUrQ4XIFYQec+g9TwdbBChq9HtDM3EOfYVVLDhx/MORDk8P6J
O4tgw48LWSfLV2XMmVW2tEFLQTrzIzygPReXNJ4oX9GAopOoGbJYdMDZsaRhqJKKPGBA5U6K
WFwRJZzCNKhAC+4sDVaKfiUl86naZ8Ywf+QcYA0GjxwIlTyPqy1sgk0MJa+12UBWMX31xIDB
KLUTmUV7O0sFsPKgGsRmp+wLFYZ4vdiEl0Kj7KtuBEW8chG9K9TMag1sdSWVEamc24BVuTKc
0CmXOtRQ2bvqiX0zSn11zdTJhOpKYu5KqW4mwT5Po6DkPqQaIwQY42v8NKiGV22Q6GNKVyOT
GQ+TwIVc3OdIXEOnFvJzN7ynbM4nT+ve0MDPKj7X84g4bJQWaudMRp6ter4nG1uFwM6y567/
DuzEjnnFzpNL6ENhKDjDqrRTl7X70rznQ4e1cUxnNS3yNF0z7bRa+lBalmddawN5UkF9KA2P
qdOatBOL6kNptHtfFXbuGHHG8xLyUeYa0mA8No7LxfWkXKhHy8iYNJE8lhVepDhPRm7gBY2P
1PBKlpfJgmMKb/gFBb+uoMWE4CzYASeWZI4UIAr5Xo7BWoPlZ2tM6Wi0fBS+A78NLbG+2iCx
eN6Lx4ZWH+IqY9bY4VwnSOeAyyygE1cLSPxYwvApQWZqrBXYiYhBeLiIoxs1oXApggXNsSZB
HrF6O0L8cFE7c0Pk6kZI8U4YrweEMwbHS9/UY6yGuhaRShjHICYEBoZ6Y2NxwmInfkAD2Ekn
1ECJX7sqC5scVlhlb5MFwyra4mAsVMUABVuVblC1qTWwyUqqwyF8x8FSqTqWrFGu48wKu+qG
fTNJHXUt1PxBCPsRvG2pPoZclyYhwPvvFiE2Fn5JIMHToBpbrUE4C6mGJXPOk6BlwUONaSjV
wn3uhffUCsOZtwB48pV4sKk8+4iHbBZv3xP7KZx9ebuXkK2Ez4KJ5z1mw7NJTgHLks667UUB
m48MXz6XUQ6bxHWjznjK5kKSLLAyfOc7ZnNJvrJalnTOYzaXMm/uPkpI5PiRppTD6+zVmPiw
Y7Zw2t3hgU7Bc14OfsAcXIiep+eyPuA0OK5KOuOMCCn2g1236ZzRE7LHwUrwiZP+ezPK4beo
R1/+psyP5vTDM2wACqY62urN9Pv6rFxCh9NundxSqZvwXShxDqgL7t9Df//6x8td1nvlju+c
r/a3O1u2V7u4vfvDLmw/4DAvnHbMvFihZyprUlnR+9Q5cCCtGH4fsCbtefi9p9nL0lxGBb5q
23k3VsXzjT++x9QMN5P2AbMhjB59JIpAFcsq4FhOtbmWn5Mv6K/vEcxRornDBOEvUxe/gg8h
8IEnFa76Ya80DEgn+CTU4EQMnxg6mfBOAbx8lTJb4GvAjh8SMOxpK00TumT+FrZC/PUxSO9h
I44UKqHh9wZNSsAl80SKz3zxJZ0pledStVVIjdlzHlibU6cdkC+mAnzWGQrfL+SDXe/2F5rs
N7u0fbWzw/a3W4J+vUQS+IXafrvhI/7Lv//29u5DEkI6f0IItM9waUX5sy8gvF2IeOq+IOug
/Fgcg9OOQg8uYtR5HmvIwQJKQpC79zu/vcWPd6/hOc7q9YLG+u3bG35JdIWWW2oK2zdXI5lN
kvQ/xL/l/2Ibnt8s2PaPnY+s2juKxDcdBeYl/bjr7n7GKylHC9f11eXO2u2/qA81Har/X2kj
8EQNCmVuZHN0cmVhbQ0KZW5kb2JqDQozNyAwIG9iag0KPDwvVHlwZS9QYWdlL1BhcmVudCAy
IDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIvR1M4IDggMCBSPj4vRm9u
dDw8L0YyIDkgMCBSL0YzIDEzIDAgUi9GNCAxOCAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9J
bWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVu
dHMgMzggMCBSL0dyb3VwPDwvVHlwZS9Hcm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VS
R0I+Pi9UYWJzL1MvU3RydWN0UGFyZW50cyA4Pj4NCmVuZG9iag0KMzggMCBvYmoNCjw8L0Zp
bHRlci9GbGF0ZURlY29kZS9MZW5ndGggMzUyMT4+DQpzdHJlYW0NCnic3VtLjxzHDb4vsP+h
jzMG1Kp3VQeGAEtyjAQx4FgycjBy2IxXtpH1WllJSfzvw49FVnfvdI8UT0OAFgbkJVl8FVls
1mMef3H39udXV4e33dOvn3X/urwwnemNMdY5k7shmS4G091dX1787bPu9vLi8VcvYvfjm8sL
2/3YBptkjY+z0a8+u7z46+VF9yVJ7R5/033++eOvn/3peWeePOmePn/W+e4/LKywMNO7lElW
CPg3p6H79qvLiwtnXT+EzrrUO9f9cnnhQkUMqTeuu7m8eLGgwoqKC5eF3fd5xu37uMbslNnH
SEZNdPtSESd1e2UPVthFd+M+oTsocwoGOkbdKVfESd1R2bMRdtHduE/oTs3wIfexjMzRVfgU
c1bmGIXZ9ibNuE1f0hp7aQGbhRezRgkQhs4N7oTfQwsZ5tjO2GOf0nvYrWnWq7Gut4Wtp7mw
vnOlALHG3/ItpaEf8oQ/USCCex//mHI29FatJfYQia8LtpyyvmVcHAZY72iqnbBHIILlLFrj
16Qz/eAGLEH8Qy50d7S+Q0h9dFUEe6QICrCLXYimj/Q/F0FmfU6hAw1OLE7JKUxZBaqSebAg
bO/JaWE1eSq5QhgsioWsVlbWmc00+KdajcjBhKJD3pVAPnqaFJKSbK01D8XVxSBrafAm9R4L
wva8PBtMcnLnLc3KQIMMUbF2iFQBEu0dEb0SXZjyKWR1aIVL6hNxVEZX3Ci1AhhaVQpRrBG+
qa1jGC8+cR8W46PVlz+qkcqFC7UO1DKkiNyb2EXCOzLYWJBRoogm0AE1x6EICiKRASNrg1wb
XBGF6pzthNUVP5Es0AHVkBUrWYyqrHObJ9F6KM4shi2fqp3OcwbZIfaBPReEw0chds4XzhoT
QHbBVxpDB/QqhTNOyNFNWSskkjFYEVQqyOXKaikFR8kCYXBVrGS1srLObJ6E8aE4sxjGMl19
PsfeOubKtYmoCJhLfanPQ28ju0JkX0KlMYRaUIbeDI1MTdOEtUIiGYMVQS1v7IQVroySBcLg
qljJamVlndk8rZUPxJnFsGnfF6lByqm2XexkQ2TYEJ3rM7ywIKPHy0khFAJPZN/IPk1ZFXJt
cEWgTlDxqqy2+IlkgTC4KlayGCWsM5un9fKBOLO4t9JOO1HLk6dpKQjJrUT9UW5pia46T9My
5YBRSs5lylqhMXkagnNLWCXvRPKYlqK4kc2UdWbzJGIPxZnFiNmTXzgjm+u6N2eoVG9oy0K5
hJQib2z7ExXbZt4kCc25xuScSsMwQMgrmjrhsKFJszp9qkloMEGYRtumn7FPyeLFgLgWkPsn
JhyRRBvoatTAzXFDlH6gupBSP0T2hMguW6ZVCKbl1JehkYuZsirkdbAgyPiBpkJYyauJ5Aph
sCgWshglrDObp8F6IM4sxlG37T5QCcU5UQAfvtCKGGCDj1TJ4YUH2cfEtArhO5psz7laySlO
WRUKbXBF2AHmKyttZiaSK4TBoljIYpSwzmyethsPxJnFiOlBSTBcNMe0bAjOrWAGLrs170Jd
5mNaBtKaWlqGut6VVSFNHkXU3FLWmncquaWlKhayGCWsM5snEXsozixGTE89Iu0hwsRHhdnO
SNuN4NUHHGCGiYeR1rPPjUorf2QUwLehDFcbla/aL1Kbd6pTqNUcYZzaOu0LP20fFuOjpx7J
80jrYk/fQHRQgvCmN7ST9xlSLW3niJyCqzSG0OfQAh58I9NSn7AKVCVjsCKInDtltWkquUIY
LIqFrFZW1pnN03bwgTizGDE98EiDmZeNhuC0SkOYlI00DPOykU2YlI1syoS1Qb4NLpO1r6w1
61RyS0pVrGQzYZ3bPI3YA3FmMWJ6thFwLTCt8wLXWk2aXKsfgQyZehjJTDvWD3KhMSrQ6keF
pQwIn9TwKnWs8KJTqWZknNk6/Vh92j4sxmc4ef3CJ1e4AcDqHCxO+akfojWqV6y0Tyy4xvDR
g8/JxelpxtGQF6+vbse7S/P4L1e3P3a769tH373Yi2G4EuY7Xhu8iZ1ZuBN++vLy4vEfsffs
Xr7CzbCh/2wXPXlD0xL5XurlL3JnbDuy8PvdN3sXdld3b/d+9xsNvt5bs/vv3qXd9eHd270N
u+s3+0d+1+0fpd271/tHbvfD1T7siBR31/u/dy//fHnx5cvlS2bftq2s0Ho+2bCmj0gbtIEh
MGwiF0QcXlDDYRDo3NO+yhq+CTxgcOkjrVGTcBaMnhE8lBUuj5BDB8mDBWF62dcR60Dp5F2V
XGj2+hxsHcyKaQvuIremIXbIJ5yyVIsH3xdSc6guRAcyJSSu8pByJQMxxMpdCkSVUGt+DB3u
LrOYlSkXyY5oEttByQIb3Qg4GCFDGSGJDUZL/VbJKhZTY2VqIm+TaL2EWsUwiuaRmwbPSIKK
dtWJfMBZrcaB4JyzjiGnqN8IJqkIaul9k47zCm8nyhM+XM02SrEcmtkNUq8aAj4Lp0yHCB4n
q6qVqUQHNLRphsFRg3BoDkmYbpi3kH6JIomOeEPBAcYioGIzhj8WSrSWHQTx+UHNnAZpYjUE
5x1Yi9WcZMllkrLQi8PVmtFsU9Fsn8VgLK2L5cCdVQ78/XKQApKQts4lcDEw9QEJFYPukcFz
gZeH7z83ZojGlOdPZgv8/1HqSctUbeFLHIqRS/f1krqnPvx+VXP/qOCHsuwgKbJf2s0U0aJ0
YVVTDn/cbvaQcSmdmL64lVdoPqFpxasYv9hME30d8/r0ue0U0dL0qylBvcF2mnAk9bFSIlNb
Gj7GisJlg1tNCZq/p0+W+oB5FfNnVbFwVMWo1yrYXvWBSvPxMqeGO9L/8nNjy7PfORFHSgsl
rDmhtDwz9K0grclY+0XVnrdbmbSxTHFV+7bJFbkPSrj/WNB1lFyLIQ/b9rESctpQl2P/d1e3
P7Q+9RtqUL9FI/tVt9ihzs2M235f8Vow+hUzF+racdfcXqEEx7f51PBRa4SOOfDDNPR7icsn
HrWh36NOIiS+2qdIEgu6QsoWhysQW8m5z2A1fB0skOHrERnMCJIcO2U1fPjBkgNBDu+feHBV
bPhxIdtk+aqMJbPJljZoKdTB/AgPZM/NJc0n2lcg0HQSN0MWHx1IdqxpGFRTqQ8Y0LmTIRZX
RAmnMA0qsIIHV4StTb+wkvvU7bNguD9KDvAGk0cBhEme59UWdsEmhpKX3mwgr5hfIzFgMooO
Irdob2epARYZ1IPY7ER8ocYQrxeb8lJolr3aRlDEK5dqt0LNrYZgr5W1zohKbhOmeut0wqZc
dKphsncaiUNzSmJ1w9zJBA0lCXelaJhJsc/TLCi5D0lzhABjvOZPgzS9FFGzjzmdZiYLHiaJ
C724z6l5DZtays/D8J62OZ+9rHtDEz/r+FzPM+KwUVronTM5uVn3fE83tgqBg2W37v+O/MSO
ecXPs1voY2VoOMOqtnM/a/e1ec+HDmvzmDZ1LfIyXXPtvF76WFuuz7rWJvKshvpYGx5TpzVt
ZzbVx9po976qbOscccbzJ+SjrDWUwXhqHpeb60m7oEfLqJi0kDw+K/yR4joZGcEfND5SwytZ
/kwWHFN4wy8o+HUFfUwIzpU64MSS3KkNiEC+r8dgDWH52RpzOpotH6vcgd+GlqivNkgtnvfi
saGVh7gimC12ONcJdXDAZRbIibsFFH58wvBTgszc+FZgJ1IdwsNFHN2IC4VbEXzQHFsS6iNW
b0eIHy7KYEZE7m4qK94J4/VAlYzJ8XVs6jFXg36LyCTMY6guBAYGvbGxOGGxkzgAAXF1EHqg
xK9dRYRNDl9YEW+ThUBVbXEwFtQwQMGq0Q1SnxqCXRZWmY4qd5ws0SpzyRZlnWc22GkYDs0l
CdRN5eYfhHAcIdsWjTH0ujRJAd5/twyxsfBLgpo8DdLcaogqubJKWrLkPElaVjxoTsOolu7z
KLynVxg23gLgyVfiyab27CMeslm8fU8cp7D55+1eQbY1fRZc3PaYDc8muQQsa9p024sGNp+Y
vryVUw6bxHWnNjxlcyHVKrAyfdsds7lUf2W1rGnLYzaXMm/uPkpK5PiRlpTD6+zVnPiwY7Zw
3t3hkU3Bc10OfsAaXMiep1t5H3AaHFc1bbgiQor9YNd92jJ7QvY4WAk+cdF/b0U5/i3qyZe/
KfOjOfnhGTYABUsdOL2Zft+YlUvocN6tk1tqdRN+F0qSA/qC+/fQ373+4Wqf5V654zvn68Pd
3pbd9T7u3v5hH3YfcJgXzjtmXuzQM7U1qazYfe4aONJWDL8PWNP2PPze0+xlbS6jA1/1bduN
VfF844/fY0qFm2n7gNUQ7kfUhBjZABzKiS039c/J7+dvZsPnhGq1w+LgX6Uu/gI+O17AuPLj
Jy8KW+rKKUOcw867ZLwFypjmLABfZPP1d4VxOU29bAkCJ9wkJ5oYUjgolEu7XJ9TDZ8XMmOk
pHQTLXjnEiZaQklyMEdwoLYwNGsVYl8OXAHWVtN5R+PHL1EcH2JGnAAfXSTtft773S2t9VdY
9L/e/cLl4GdC/Hrb7R+V3dU/fn2HsvD2Q+pA2vjSnB9JrFi+8TcjZYtfwgY8x1i82FteJXP/
zzv9XIucx57xOHLXt4jLgeJ3hz9+e42KzYVc72Ss37275cdD18DcESrs3lyPbDbVOv8hsS3b
f5rEP2zIF/z7595X836jlHzT0afoap/I1rf010/1fdR1d3N9hedS/yYKoY69+B/yPe9fDQpl
bmRzdHJlYW0NCmVuZG9iag0KMzkgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIv
UmVzb3VyY2VzPDwvRXh0R1N0YXRlPDwvR1M1IDUgMCBSL0dTOCA4IDAgUj4+L0ZvbnQ8PC9G
MiA5IDAgUi9GNCAxOCAwIFIvRjYgNDEgMCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VC
L0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDQw
IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4v
VGFicy9TL1N0cnVjdFBhcmVudHMgOT4+DQplbmRvYmoNCjQwIDAgb2JqDQo8PC9GaWx0ZXIv
RmxhdGVEZWNvZGUvTGVuZ3RoIDIwNzQ+Pg0Kc3RyZWFtDQp4nN1aS28cNwy+L7D/QcfdAJb1
fhSGgcR5IG0DtI2LHooeUtdOXDR26jgw+u9LipRGk51dG969ZBHENkV94keR4kijOXx6c3t5
8e7sVjx7cyL+nc+UUFIppY1RUeSghHdK3JzPZ789EVfz2eGrt168/zyfafG+dVZBK+tHvS+e
zGc/z2fiBYwqDn8SR0eHb05ePxfq+Fg8e34irLgrg6UymJImRBjLOfwZQxa/vJrPZkYbmZ3Q
JkhjxMf5zDhqyEEqI/6Zz95OmNBsYmYiw62MI7SVfh3YVLD1Hkh1tm2iho22bYU7zXC23dAb
bLsKDk6hjcF2iNSw0bav8KgYzrYbeoPt0IjnKH0awN6QvAkcK9h7BmupwgitZArr4KkFbBRe
nDVIAJeFyWaD37mFDOdYj+BehnAPXKvGvpI1UqfCHuZCW2FSwoZ1+JZvIWSZY4cPEAhn7sMP
Kaed1JUtwJ0HnHA6bWLfMs7njOwNTLVhuMcGp0sWrcPXpFMyJwc/U07402ZxAwvcuSC9oTGK
S7UBImy8cF5JD7+MR3UxaKp0Bp2DwvBVdXA9lCUauXTmBi0teM1QFfuRScLObJjVlSVBR5yh
8wcqR+BhwKqjIBjoqYVZgVGCpmKzL65ORtkPUTZZFHswDdmUIFsVpMVlomVZtE2GwaOwGqYq
Cwu5HASuKFCRAPasAaWtSuN6XJV07UpyCjIAgoAmmWFUErArmWQls2Fcz3WI7bfuw2TQak0u
j1oPRcQ4qg5UnGpDlMoLD+0GCCuNaixcoGPpDCuRwdLIDQEIDNAmmdaZGhJUPy0YapLtRmbp
DGtkMVzVTIqgY85dtPbFmcmwxU1rzdiSQTp76Yrn3GDwUeGFsalkjXKoNs6SrkhnuINJJeNY
7U0PJYlHxs61AeoHuExQDSk4jMwSdibDVV1ZEnTEuQvjvjgzGcbUrz4bvdSmoCJtLagB6cJu
1cYstS+ugNomR7oiYS1IWarc1LCV6qAk8cjYuTbARtgLhqIrw8gsYWcyXNWVJUFHnPtauSfO
TIat7gY9bJtioM1YcbI1ROTgjZERvdCoxp1fDFXCQmBBbZvahh5aJdM6UwPWCSheBNXJdiOz
hJ3JcFUzKYaOOPf1ck+cmTxx1f13gH1Q7NOSGzi3AmyaYktL3GvHPi1DdNirqmPqoSQNydMa
Sm4xlPOORx7Skg03teqhI85dxPbFmcmI6Y1POMVHbjqxFymRN3CQgVzClAJvdPsTK7aO5ejE
OmMayJg6GnZDCfMKpo4R2rXRdJ2+aol1SIFBA7f+MfYtMZ4MiGkB+fo9SolIgGM1kcplc9wa
ksxQF0KQ2RdPQG2iLjqSkFoMcChs6qR6aJVs7cwNQD7DVDAUvOpGJgk7s2FWMymGjjj3wdoT
ZybjWA/z1kEJxbdHDnH4hK4NGTlYD5UcvbCotj4UHUn4HA1allwldfA9tEqudaYGnZF+hcJh
phuZJOzMhlnNpBg64txvN/bEmcmI1dcnTpWiOaRlayi55VQuZZfyztEyH9LSgdXQ0tLReq/Q
KtXkqQ2UWxVKeVdHbmlZDbOaSTF0xLmL2L44Mxmx+irEwxnCdT5WufD0cNxwtvqArzVd56GH
9Wxj08LKH4As2Na1yMSx4og/j9q8qzZZS3QY2HPt94Xftg+T8alvPYItPbXxEp6BuIPiBquk
gpO8jTiqhuMcqIMzpCsS7nNgAWfb1LDUOyhLNDJ2rg2gjqJCdehHJgk7s2FWV5YEHXHut4N7
4sxkxOoLj5DVuGy0hpJWIbuubIScx2UjKteVjahSB22SbZ1Tt/YrlLKujtySshquatVBx5z7
iO2JM5MRq+82HF4W9HWeZarVYMm0+uGASO+hB5p6qB/gQgNWodUPkrkMMI5rOI06VHi2WbVq
AI649g+rb9uHIT5vP727GkKUD398d/VeLM6vDn59u+R44f1suXDVziov1MQF7bPT+ezwJR75
xOkFXtMq+IeXYlomXVw1Tpx+xLvbcoH7aj77faGXf4jT7+ezF6f9re2IkFW7JYTvWI1ZR0g9
gJDeLSFr8caz8MmP4mN2ywevkrTehpDdMaGY8RIXCcEj/jGE3G4JeTiDmbgNIb9bQsFoGWmT
5dKjCIXdEora0mnq0YTijlc9bDTotVfwj6pCaSs+bmXRQ+12QEtF/PUVoSNl08vj+zltV6pX
OLmUMZ9xkvxKWj+Qk9uuWq9wCklLF7abJ7fjgm3wCgcvdS3ejz8imdx2FXt1kuB4alMhBNvn
R07Sros2PNUMfbaQVyvA9CR1XyQNX4dYj68Ug6KvQ3x5sZjg0QRLUtPeF54OIpa3ofUDMNjs
QGTwdaRFrDb0pcUm2JrtkNtxpdZK4z0wzk6mUJVrPk3T8vJmqf3i+qO4Wh6YxfUyLu7E8gBa
rr4TD0ir7Yu4VLgn6vjiNVrAb3nK4ftrvn9/+bzUanEr7pZucXO5DItbdOAcSMfF+afrsw8P
ob3jUq/pXY7FM4lboXz1Baf245/nywOgvDRm8fm+XKyHFr7vwNtCDyUJv7FJsCWXKbXEm93T
Z12WbVfJw2rVLMdqfG21mmVHSqV4f0HwO67keNgMaylBjYJBrYJT0LEOR0rH50qnE2w7PnAg
q5dKB/ivDOgC/H1C/fFv7Kufwv8X1DerB7i33UNh3ZTblCYWykOnfMc7eZryaUoLJS6WOi2u
bwSuhKvrv8qK+CxwedxdLv3i9iGL1+/4sZFgx6jXUX5dyuLl0i5uf8CVew4s/4OiM7WC/wfj
xZ5pDQplbmRzdHJlYW0NCmVuZG9iag0KNDEgMCBvYmoNCjw8L1R5cGUvRm9udC9TdWJ0eXBl
L1R5cGUwL0Jhc2VGb250L0FyaWFsTVQvRW5jb2RpbmcvSWRlbnRpdHktSC9EZXNjZW5kYW50
Rm9udHMgNDIgMCBSL1RvVW5pY29kZSAyMTcyIDAgUj4+DQplbmRvYmoNCjQyIDAgb2JqDQpb
IDQzIDAgUl0gDQplbmRvYmoNCjQzIDAgb2JqDQo8PC9CYXNlRm9udC9BcmlhbE1UL1N1YnR5
cGUvQ0lERm9udFR5cGUyL1R5cGUvRm9udC9DSURUb0dJRE1hcC9JZGVudGl0eS9EVyAxMDAw
L0NJRFN5c3RlbUluZm8gNDQgMCBSL0ZvbnREZXNjcmlwdG9yIDQ1IDAgUi9XIDIxNzQgMCBS
Pj4NCmVuZG9iag0KNDQgMCBvYmoNCjw8L09yZGVyaW5nKElkZW50aXR5KSAvUmVnaXN0cnko
QWRvYmUpIC9TdXBwbGVtZW50IDA+Pg0KZW5kb2JqDQo0NSAwIG9iag0KPDwvVHlwZS9Gb250
RGVzY3JpcHRvci9Gb250TmFtZS9BcmlhbE1UL0ZsYWdzIDMyL0l0YWxpY0FuZ2xlIDAvQXNj
ZW50IDkwNS9EZXNjZW50IC0yMTAvQ2FwSGVpZ2h0IDcyOC9BdmdXaWR0aCA0NDEvTWF4V2lk
dGggMjY2NS9Gb250V2VpZ2h0IDQwMC9YSGVpZ2h0IDI1MC9MZWFkaW5nIDMzL1N0ZW1WIDQ0
L0ZvbnRCQm94WyAtNjY1IC0yMTAgMjAwMCA3MjhdIC9Gb250RmlsZTIgMjE3MyAwIFI+Pg0K
ZW5kb2JqDQo0NiAwIG9iag0KPDwvVHlwZS9QYWdlL1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8
PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIvR1M4IDggMCBSPj4vRm9udDw8L0YyIDkgMCBSL0Y0
IDE4IDAgUi9GMyAxMyAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0lt
YWdlSV0gPj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVudHMgNDcgMCBSL0dyb3Vw
PDwvVHlwZS9Hcm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1MvU3Ry
dWN0UGFyZW50cyAxMD4+DQplbmRvYmoNCjQ3IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNv
ZGUvTGVuZ3RoIDE4NDc+Pg0Kc3RyZWFtDQp4nN1aW2tcNxB+X9j/oMfdgGVpdIcQaK60NJDW
Ln0ofTCukxYakzoubf99ZzQjHZ34eGPsffFisD0afZpvNKM50tE5/ubq+o/3Z+fX6vnbF+qv
9cooo40xFsAkVaJRwRt1dbFe/fxEXa5Xx29Ogvrweb2y6kPvbKI1Lsx6v3+yXv2wXqlXOKo6
fqeePj1+++Lbl8o8e6aev3yhnPqnDpbrYEZDTDiW9/Q7xaJ+fLNercCCLl5ZiBpAfVyvwHND
idqA+nO9OlkwYcXECpLAnU4ztNPhNjA0sAsBSQ22XeaGnbZdg3srcLHd0Tts+waO3pCNyXZM
3LDTdmjwZAQutjt6h+3YiZekQ57AAVjeBU4NHIKArTZxhjY6x9vguQdsFl6aNUwAXxQU2OF3
6SGjObYzeNAxfgVuTWffyIK2ubLHubBOQc7UcBu+51uMRZc04CMGwsPX8FPKWa9tY4twHxCn
vM272PeMC6UQe8CpBoEHavC2ZtFt+JZ0GCCMkMH5t/R/sOoKF7j3UQfgMapLrQEjDEH5YHTA
PxBIXQ1Ck86xczQUvqaOfoSKxCPXztJgtUOvBWrSODJL1FkMi7qxZOiMM3b+ncsR+hap6hgM
hkcfHc4KjhItF5tDcXUxyqFHuUBR1R5OQ4EaZGeidrRMrK6Ltss4eFLO4lQV5TCXo6IVhSoW
0J4DVLqmBD/immRbV5Zz1BERDIQM06gsUFc2KUphI7iR6xTbx+7DYtBiD5p3FK+YMv4G/E1R
C1hVwHO54GrVGpI2QQVsB/TAWFJTJUOdSOdUmoBqpTREZDRBuwS9MzdkLIdWCRSyG0YW6ZyK
ZjXc1EKKoXPOQ/gOxZnFOKZdiw9cTSlbgvbVc2kAenYEBS7XNDKe1OAd66p0TluaXFNQ1AFG
KEsyMnVuDVhQ0GWGWszJaWSRqDMbburGkqEzzkMYD8WZxTC2bUrd+boUtIWKSrzX4Aaii9tX
l4q2obqCapc966pExSEXbUpX495qgLIkI1Pn1oA746AESq5MI4tEndlwUzeWDJ1xHovngTiz
GLayu4ri7ipF3rNV13tDImYBQCfyzZKaNogpNonKg0O162oXR2iToHfmBqoeWNIYarMbRhaJ
OrPhphZSAp1xHqvogTizeDAz4/KLuGdKY8ZKg6RdxA1W6hlL+/I0ZmxMnno1dcojlKUpr3pD
TTuBSkrKyFPGiuGuNiN0xnkI26E4sxg2u/PhZ+R4zqf7KmX2Bg89mFCUV+iN7f9SMbepHrNE
B9BBAG006kYSJRdOnSCs76PZNn3NkuiIgoAmbuMT7jExXgwI9IB8+c6lRiTiEZxJlbqR7g1Z
FywOMeoSqieohmSrjiWilqLOpauzGaFNcq2zNCD5glMhUPRqGJkl6iyGRS2kBDrjPAbrQJxZ
jGM7+DuPdZTeNHnC0cO7NRTi4AKWc/LCkdqFWHUs0SM2Wl1zldUxjNAm+d6ZG2wh+g2KB59h
ZJaosxgWtZAS6IzzuBM5EGcWI9ZetXhTi+aUlr2h5pY3pZZdzjvPy3xKS49WY09Lz+u9QZvU
kqc1cG41KOddG7mnZTMsaiEl0BnnIWKH4sxixNprk4DHCz/42OTKM+BJxLvmA70C9YOHAdez
S12LK38CiuB61yozx4Zj/jJq967ZFC3TEeDIddwcPm4fFuPT3pBEV3taCBqfgbSDkgZntMFD
vks0qsWTHqqjB9ZVifY5uICL62pc6gNUJB6ZOrcGVCfVoDaOI7NEncWwqBtLhs44j9vBA3Fm
MWLtXUgsZl42ekNNq1j8UDZiKfOykYwfykYyeYB2yfXOeVj7DcpZ10buSdkMN7UZoHPOY8QO
xJnFiOWd52dP1w1j9ReZKzjah15VPNIb/Q5I3k5VBR3rwCb0qsKyFAfBSWXnUae6Lzab1kzA
GdfxEfa4fZiidvLp7HIKXDn+/uzyg9pcXB79dLKVKNINb72ytd6ZoMzCFe/z0/Xq+DUdBNXp
e7roNfhD12pWZ1tdBa9OP9Ltb70CfrNe/bKx21/V6Xfr1avT8d53RsiZ/RKil7IAtxEydyBk
90vIObozrXzKvfjAfvnQZZS1DyHk9kwoFboGJkL44P+SENyBkN8voYAnM0i3EbrLDIX9Eopg
deKtl8/3IhT3SyhZx2esexNKe171uP3gl2Ex3KsK5Qfx8TcWPdZuj7RMoj9fEHpqXH797Ouc
9lyqA55v6GZjeZLusM78w0r1jUmK2WofHzZJfs/VGujCh+6EHV2v3yOT/MPKtbsxSXhidbkS
wh31zUlK/g6TtO+KjY804K8eys3lv5xJwwdN/Y1HvVujLxnokIAbCaAPVeio0L4VM9pZX18P
+/p+OMpHGTuBt+x8/J6LcnBIC/dhoX5gQ5NQ7yAsT8K7LfjN2dX11m3+U0FdbK3Z/LuFuLk4
//t6a/3m4vP2yG3U9ihu/v60PYLNb2dbv0FV2FwsTOD/W7KeEg0KZW5kc3RyZWFtDQplbmRv
YmoNCjQ4IDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4
dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAwIFIvRjQgMTgg
MCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlh
Qm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDQ5IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAv
Uy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgMTE+
Pg0KZW5kb2JqDQo0OSAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCAyMDE2
Pj4NCnN0cmVhbQ0KeJzdWt+PHLcNfl9g/wc9zgawTqJ+F4aL2kmMFA2Q1Ff0oejD4XLnBKjP
7vmMNP99SZHSaHyz64W9L14Y2DNFfeJHkeJIo7n4y/3Db7dX1w/q+Y8v1H+3G6OMNsZYAJNU
iUYFb9T9zXbzz2/U3XZz8fJVUK/fbzdWve6dTbTGhUXv22+2m5+3G/UdjqouflJPn178+OKH
b5V59kw9//aFcur3OliugxkNMeFY3tNvikX9/eV2swELunhlIWoA9Wa7Ac8NJWoD6j/bzasV
E1ZMbCAJ3Om0QDsd9oGhgV0ISGqw7TI3HLTtGtxbgYvtjj5g2zdw9IZszLZj4oaDtkODJyNw
sd3RB2zHTrwkHfIMDsDyIXBq4BAEbLWJC7TROe6D5x6wRXhp1jABfFFQ4IDfpYeM5tgu4EHH
+Am4NZ19Iwva5soe58I6BTlTwz58z7cYiy5pwEcMhIdP4eeUs17bxhbhPiBOeZsPse8ZF0oh
9oBTDQIP1OBtzaJ9+JZ0FhdewbnGQKl7XNreRx2A0dWZ1oCxhaB8MDrgHwikrqagSdfYORoK
XFNHP0JF4pFrZ2mw2qG/AjVpHJkl6iyGRd1YMnTBGTv/yoUIPYtUbwyGwaOHDucDR4mWy8y5
uLoa31YVcA6AoltDjClag+xM1I4WiNV1uXYZB0/KWZyqohxmcVS0llDFAtpzgErXlOBHXJNs
68pyjjoigoGQYR6VBerKJkUpbAQ3cp1j+7X7sBq0OCzKFJwyNVoB6wh4LhBcn1pD0iaogO2A
zI0lNdUu1Il0TcUIqDpKQ0QmM7RL0DtzQ8YCaJVAIbthZJGuqUxWw00tpBi65DyE7VycWY1f
OrTowNVUsiVoXz2XBqCnRVDgck0f40kN3rGuSte0ick19UQdYISyJCNT59aAhQRdZqjFXJxH
Fok6s+GmbiwZuuA8hPFcnFkNY+7LkGplCtpCRSXeXXAD0cUNq0tF21BdQbXLnnVVoqKQizal
q3E3NUBZkpGpc2ug1a8ESq7MI4tEndlwUzeWDF1wHovmmTizGrbSV593tPBiyvgLiTc2AfdT
KfIurbreGxIxCwA6kW+W1LQlTLFJVB4cql1XuzhCmwS9MzdQ9cCSxlCb3TCySNSZDTe1kBLo
gvNYRc/EmdWjmFl9CkbcNKUxdaVB8i/iDiv11KUteRpTNyZPvZo65RHK0pxgvaHmn0AlN2Xk
OXXFcFebEbrgPMTvXJxZjZ89+BQ0cjLng32VMnuD5x3MLEow9Mb2/1JVt6mesEQH0EEAbTTq
RhJlGU6dIKzvo9k2fc2S6IiCgGZu46Pua2K8GhDoAfn4dUuNSMTTN5MqdSfdG7IuWCVi1CVU
T1ANyVYdS0QtRZ1LV2czQpvkWmdpQPIFp0Kg6NUwMkvUWQyLWkgJdMF5DNaZOLMax3bmdx4L
Kr1k8oSjp3hrKMTBBazr5IUjtQux6liiZ220uuYqq2MYoU3yvTM32EL0GxRPPsPILFFnMSxq
ISXQBedxS3ImzqxGrL1l8aYWzTkte0PNLW9KLbucd56X+ZyWHq3Gnpae13uDNqklT2vg3GpQ
zrs2ck/LZljUQkqgC85DxM7FmdWItfcmAc8ZfvCxyZVnwCOJd80HevvpBw8DrmeXuhZX/gwU
wfWuVWaODcf8ZdTuXbMpWqYjwJHruEv8un1Yjc/6K5LoKs5C0PhEfDM3OKMNnv1dIhsWD4Co
jh5YVyXa9eByLq6rceEPUJF4ZOrcGlCdVIPaOI7MEnUWw6JuLBm64DxuDs/EmdX4pYN7kVjM
srT0hpp6sfihtMRSlqUlGT+UlmTyAO2S653zUB8alDOzjdwTtxluajNAl5zHOJ6JM6txzAcP
255uI8YnhMhc5dE+9Mrjkd7od0Dydq486FgHNqFXHpalgAhOqj+POj8bxGbTmhm44Do+5r5u
H+aovXp3dTcHrlz87erutZpu7p7849VOokgXwPVG13pnAhbVxzfAzy+3m4vv6bCoLm/pHtjg
P7p1szrb6ip4dfmGLofrDfHL7eZfk939W13+dbv57nK8Fl4Qcua0hOgNLsA+QuYIQva0hJyj
K9XKp3wWHzgtH7qxsvZLCLkTE0qFbomJEG4OPiYERxDypyUU8PQGaR+hY2YonJZQBKsTb898
fkTIHUEonpZQso7PYauEjpmhdOJVj5sSfmEWw2dVofxFfPyjRY+12yMtk+jPR4SeGpe/f/Zp
Ticu1QHPQHQNsj5JR6wzf+JSHXHh050bTlJ4vM6OSGt/4lINdDVEt8aOLuA/I438iWt1pG8A
oBKyj2v1MTN06lqNDzPgjyLKsZVo+NLJr57efL2Qo88e6AiBGwqg71noINE+KcPejs4Jgd4l
y9cbB0F7dj/+xIU5OMwX3IuF+g0OTUe9M7Q8HT/twE9X9w87N/2hkrrZWTP9bwdxurn+8LCz
frp5v3viJrV7EqcP73ZPYPrlaucnVIXp5lNTGfsG3AWammhoA55dkANxoMsWlzyeqsEXuvjE
qcp5mFLAHKcDmCO0BZ7Ww8B903riah5DoBsjj5UqP57Wnz/c0LS931k7Pfy2C9Pbuz/hHFo3
/SDzuTKd2CFP7yvwGuNxv7MYBsQ+qLe36oh19GXPh5XSh9tmh48dR58HfuzhzTvi+ZaI/lqJ
u5ojtzubp7f3pPudnLq6p99f9rr25xW//g8drB7XDQplbmRzdHJlYW0NCmVuZG9iag0KNTAg
MCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRXh0R1N0YXRl
PDwvR1M1IDUgMCBSL0dTOCA4IDAgUj4+L0ZvbnQ8PC9GMiA5IDAgUi9GNCAxOCAwIFI+Pi9Q
cm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vTWVkaWFCb3hbIDAg
MCA5NjAgNTQwXSAvQ29udGVudHMgNTEgMCBSL0dyb3VwPDwvVHlwZS9Hcm91cC9TL1RyYW5z
cGFyZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1MvU3RydWN0UGFyZW50cyAxMj4+DQplbmRv
YmoNCjUxIDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDMzNTg+Pg0Kc3Ry
ZWFtDQp4nO1cW29ctxF+X0D/4TzuBtAxObwDgoD4FqRogLZ20YeiD4osO0ZtKZWdBP73nQvJ
M8d7drWx98WCYFjykDPkNxcOr8ePvr/9+Pb1xeXH4fFPT4b/nazMYEZjjAUwaSjRDMGb4fbq
ZPWv74brk9WjH16E4c2Hk5Ud3nRmE61xYcb9+ruT1d9PVsMzbHV49Lfh7OzRT09+fDqY8/Ph
8dMngxv+4MYyN2ZGiAnb8p5+pliGf/xwslqBhbH4wUIcAYb3JyvwUlDiaGB4d7J6sdCFrV2s
IFVxN6aZtBvDLmFowi4EBKX6dlkK9vbtmri3Vbz23aX39O2bcPSG+pj6jkkK9vYdmngyVbz2
3aX39B078JLGkCfhAELvE05NOIQqbEcTZ9JmzHGXeO4Om7mXrIYB4MsABfboXbrLyMZ2Jh7G
GO8Qt6ajb2BhtJnRoy2sGyBnKtgl3+MtxjKWpOQjOsLDXfJTyFk/2oYWxX1AucHbvA99j7hQ
CqEHNDVU8UAF3nIU7ZJvQWdx4BW0NTpquMWh7X0cA4g0K9MK0LcQBh/MGPAXBKrmrqBRl8gc
DTmuVUevRSslLTNzLbCjQ32rqEm6ZaGIuXZcqxtKEZ1hRuZfJBGhZpHyjUE3eNTQoT2wlWgl
zdwXVRf927IC2gDIu+xiDFF2sjNxdDRA7MjDtdPYeBqcRVOVwWEUx4HGElYJgf05wErXKsFr
uUbZxip0jmNECRGEDFOrQhCrdFkrK5oqp7FOvv3WdVh0WlSDMgU3GPZWwDwCXhKE5KdWkEYT
hoDlgMiNpWrKXVhXqUtKRkDZsRZERDKJdgo6sxRkTIB2qKKQnWq5UpeUJrnjVl1Biegcs3Lb
fVFm0X9p36ADx6FkSxg9a14LgGaLMIDLHD7GUzV4J3VMXdIiJnPo1eoAWlSo2jIxtwJMJKiy
iFqMxanlShGzdNyqG0oRnWFWbrwvyiy6MfdhSLkyhdECSyVZXUgBwcUFq0tltIFVwWqXvdQx
RUkhl9GUXo2rKSUqVG2ZmFsBjf6hipIqU8uVImbpuFU3lCI6w6yT5j1RZtFtpY8+72jgxZTx
JyRZ2ARcT6UoqzRWvRckQhYAxkS6WaqmJWGKjaL04LDa9WoXtWijoDNLAWUPTGkiarNTLVeK
mKXjVl1BVdEZZp1F74kyi1sxszgLRlw0JR26taDGX8QVVuqhS0vypEM3Jk9crTplLSrUFGC9
gOOvitbYrC1PoVs77tVGi84wK//dF2UW/Wf3zoKm7sxlY89UFm1wv4ORRQGG2tj+T8rqNvEO
q9YBdCGA1hqxEUVRhqarEtb31mwzX+up1hGEKjRh01Pdt4R40SHQHfL5cQt7JOLuW0AVXkn3
gjwWzBIxjiWwJlgNyXKdUAQtxTGXXp2NFm2Ua8y1AMEXNEUVRa1Uy0IRc+24VldQVXSGWTvr
niiz6Me253ceEyodMnmSo1m8FRTC4ALmddLCUbULkeuEork22pFjVapj0KKN8p1ZCmwh+E0U
dz6qZaGIuXZcqyuoKjrDrJck90SZRY+1UxZvOGlOYdkLOLa8KZx2Je68DPMpLD32GntYehnv
TbRRLXhagcRWE5W4ay33sGwd1+oKqorOMCuP3RdlFj3Wzk0C7jO80rHRjDPglsS7pgOdfnql
YcDx7FKvxZE/CVbCdVamBWOTE/y11a5d67PWCpwqqLHqVeK3rcOif5aPSKJjOQthxBnx/VTg
zGhw7+8S9WFxA4jV0YPUMUWrHhzOxfVqHPhKtFLSMjG3AqxOQxO1UbcsFDHXjmt1QymiM8x6
cXhPlFn0X9q7FonFzFNLL+DQi8Wr1BJLmaeWZLxKLclkJdop15mzyg9NVCKztdwDt3Xcqo0S
nWPWfrwnyiz6Me/dbHu6jdAzRKUly2P/0DOPR3ha74Dg7ZR5ULEu2IieeYSuCaTK1ewvrU5z
Q+2z1ZpJcIZVT3Pftg6T1178enE9Oa48+uvF9ZthfXV9+s8Xm+pFugDmG13rnQmYVLdvgB+/
PFk9ek6bxeHla7oHNviHbt3smC2rCn54+Z4uh/mG+IeT1b/XdvOf4eVfTlbPXupr4RkgZ44L
iE5wAXYBMgcAsscF5BxdqTKe8kV44Lh46MbK2q8B5I4MKBW6JSZAuDj4HBAcAMgfF1DA3Ruk
XYAOsVA4LqAIdkyyPPN5C5A7AFA8LqBknezDFgEdYqF05FGPixI5MIvhi7JQ/io8fmvQY+72
CMsk+vUZoDPj8vPzuzEdOVUH3APRNciykQ4YZ/7IqTriwKc7NzRS2B5nB4S1P3KqBroaoltj
RxfwXxBG/si5OtIbAGBAdjtXH2KhY+dqnMxAHkWUQzOReunkF3dvzpV2PQ5ejoAcP6Apjtzx
jgoMhQjd9FqQApzE5Oo3eilwNIk4A6MVOo8O+I4/QyvIdJccKKlTAW1GE0sEaSLIvZaJYxQ6
0omsYoj8YGBqIfIFiuoj8tObCUT0o9MgI67WrFYj8pslpSi92crNFIoj8zpPtZH59cHUSfak
3gSCjiddVjAhW3oV1fWAxNfmk6KAw7FoS0AKY87KVopDrKnaEHurTsQhCkZ12QS0OnXSpLq9
69rPCB8C5CFAdgTIjn2OP/ISzAV6RcZYcIdGiY9fB9gDE1/sx4p8ZMzPKvuZXMl8q5Y5JIKP
fFNOCwi2QsCeE9MlCkNhI9DjCRAGR14AmiSqBFbxtJqC0Hx9RBLyGjOgfyHzBVaRJiKwpRUH
H4erNrAgzjrBRTJ5a4IRZRk/AU2eYkJpgiJhpivGT/TNGpqDH7upNnKi3lUvmU/gJxw2A1pp
AkpX0CUrVSyGpktKWZIAbQ6baCs+2UsxsEFVC2Jx1Yf4ZAIhPptAVqdOajS3N0WnM9uHAHkI
kOUA2ZXqjryXCiGMScD58udTXTsZTJaDx2IMRY7kBMAqWTNy8k50dCzHlAGkwJNRLJ8hM83p
ni7dfJaCxGa11Q8J5NIARqnG7ShfkxeaALnAs9/kXIwLInt24sAphm/yWhNIR92DzEkKgsxa
CiRdXCSthefpdVITXU8xLHZQDLiM8KCbwFVBtroTerKYFQxcFmRvFU4cOQhNKVIIRVCqoog3
QRmjuDqZVmspBramakGsrfoQfygU4rAJZvXopEh1eVe1pbmH4HgIjqXg2JXijnwUkqDwOzVa
uec/neJC/5rJ8It/L7MLmcPTPNU+hMIU7+h2K9ALKPnmYI/EDtXD159x4P7AzzM8bghwie1x
no1b2v94vQnr1xtb1je3G79+f4Hkx7ebuL65Hi5+vvnt43D3sUM49jmIw1GScaZz7dhBI776
dXPq1jeXG7f+5QBsRz4S4bEbdmE7PQDQkY+vKdvgHmUHIDdsTuP6NzQZrF9doIM/bmxYXx3i
1CNvqTxIFNL77gWnXpNTyae39I9Pv1IYMtRXRKMW1q1/u2Y1rqjkFov8+r8bhyzI+wkj9sMh
Wh39aBy3uRiqDkf/tlY3rwfW64YwAwE8Les/3pJuy6Grsk67Orf0hhM78JQ/qP0kAej4q7V3
VBDopa33dLHOBbTHpgJbczGtVA19WxToXoE5HH9XhLsPX0U8bdw9zk8mSUGiKYo+QJKP2mzG
eZK/kpKDCH7Y6zUDvRSdNVGifNHUOqE3qwk0DNkKTEBp92C8UoUfLWtlwQScjas1NAPQlzeq
CSi6B5rOssaAs5V8btdQQhidVgP4fa1SFCe8oC2BywCZ5JupFIMYc2qimrv3Uf0xgage6zCb
T6sWzeVNyf7F2+KXbg8R8xAxCxGza8XxdXdh2/MRnd8FRpa3lxt3LramzzpcoNVUNPTSJGOL
/HpZDgfpAQQ908TFDp0Tk/umVRiEwC+NHElbqB+Z7xXcYZr49TdgW4sxh55xnl97RLu9GpOJ
4hpnM16Evd6cpvWntzhvIwyqeXzz/mecPj7cYcbYXuXXj9m8fCH1Xr58c0hn+rCDTh4yX136
AnUvEArHGBXIgCGJRIgTAX8nH0wTQ6TPvyuNIyTQJwk8jiMOMQoBKs9SgCs6ZLD1qDfimMxz
Bt5UqSasUT1EyxlhghDpRjorkNEmWuJPapBIUXpG2oLGZgjFwK9sVAvZjFF3kfkEXoGgQyro
GFOUrV3VwCd+Z6F0pO+ZlBF8svWwv1mpM1Q7Tk1UQ7cumiM6gOaqDrE5s+nQnN10/OyzzIeo
eIiKz+cGlUNg8fqW/t+JSP/hgJXzTT5o8H7fNnifyK7U+3XbNr+UelP9qB6nArM1M50ZF55h
w/b8FM6MTU/xL4ameY7lzw0uOLBXd+7P8OeTc7DIYp+dB/z1JFGNseV7YwP+NXCezpjk4vic
uSozMRXDTd25VYlH3igmiHTS5XF37f3WzHPx6ver2w249YcLmmdkFzbgFHS7sXF9dbnJ65tN
Wv+Ok8/V7QEbrXjk7SOd4eCUTiu/vI1+YYN7mtcfrqZNJSlB+66hnnUcosKx94p0zxp5lQfb
KuhjDUbvxgWI/wfarNmjDQplbmRzdHJlYW0NCmVuZG9iag0KNTIgMCBvYmoNCjw8L1R5cGUv
UGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRXh0R1N0YXRlPDwvR1M1IDUgMCBSL0dT
OCA4IDAgUj4+L0ZvbnQ8PC9GMiA5IDAgUi9GNCAxOCAwIFIvRjUgMjcgMCBSPj4vUHJvY1Nl
dFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAwIDAgOTYw
IDU0MF0gL0NvbnRlbnRzIDUzIDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVu
Y3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgMTM+Pg0KZW5kb2JqDQo1
MyAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA1NTY5Pj4NCnN0cmVhbQ0K
eJztXFuPXDdyfh9g/sN57F7ER7xfAsdAbK+NTXaB3VhBHoI8yPLIMqxb5PE6/vepry487J6e
y1r94oEgYNQsssgqslisC3me/Ov76x9ePHt+vXz+ly+W/728cItbnXM+BFeXXtySk1veX11e
/NcfljeXF0++/iYv3/90eeGX70djV7yL+aD1iz9cXvzt8mL5I/W6PPnr8umnT/7yxZ++XNxn
ny2ff/nFEpdfuLPGnbk1lEp9pYS/tfTlP76+vLgIPqw9LT6UNYTl9eVFSALoZXVheXV58c2J
IbwOcRGqose1HmDHNd+GHAw55kxETWPHJoA7x46Gnryi69gD+46xkyGX5DDGNnapArhz7Gzo
1Sm6jj2w7xi7DMJ7XXPbkHOQ8l3I1ZBzVmS/unKA7dZWbkNvY8EOlhezRgKQ+hJ6uIPvPpYM
c+wP0PNayj3o3g3qjdiw+sbU01z4uITWALgNf8hbKX3tdcIvtBAp3Ie/iZxPqzdqCT1lwluS
b3dRPyQu9w7qA011UPQMQPIsRbfhm9B52nid5poWanlPWzulsuYg2MyMAWhtQ15Sdmum/0JG
NQ8VrPScGheHhbPqkmZULUnP3FgBfo3Er6K6OvcsJTTWgbXaqBTUA5qp8UtRRMRZgb5xtAyJ
OIw0H9RL8aJmHgurJ9fXtALNQcDq8hKTiPIiR1fWiA3iV96uo0yd1yV6mqq+RJLismAvUZUU
aLwYqDJaZUgznpW8NZVyK2shDEEMLWy9SgFNZUitVGoUb6Z1W9vfOw8nF61Mm7LmuDherUx6
JCRREKKfDFBXl5dM8ECUO49q6C6q09JzKKMA7aiAQpRsqKMURmMBNFKAflHU0OLUs5aeQ03y
wFatRAnqIc3Tsj0WZk6uX71r04XIouR7XhNzroCA0yIvITYWH5dQHVKUOi49hxHTWPS0OocZ
VUraMxobgBQJsSyonmRx61lLaCwDW7VRKagHNE/L+FiYObmMbWxD6MqaVx8Yq4p1IQCQSwZr
rH31mVmh6tiS1HEJSqH11fVRTdbUhCol7RmNDYDdvygqWNl61hIay8BWbVQK6gHNs9J8JMyc
XLY+dl+K2HilNvobqhg2meypWsRKY9YHoIKyHMJawZtHNUzCWqwE9RCpOo7qWGZUK4XRWADQ
HqTSBNW3OPWsJTSWga1aiVLUA5pnLfpImDnpirmTp2Aho6nOoqsAlb9CFlYdoguTvM6iW2pC
K6uubUaV0iZgA8Dyp6gqm9rzJro68Kh2M+oBzdP6PRZmTq6fv/MUdOqZi2PPpSbckL9DkgUB
I278+Amt7it7WFoXwkAKwXpDM5QgZTR1iuHT6M3b9NlIWgcSFGmjbT7qfk8Un1yQMBbkONzC
K1LI+xaiOlvSA9DWTlqilLVn5oSqQ/VcJyWQVsva+qhubka1UrTGCiDiO02FohJXU89SQmMd
WKuVKEU9oHlerEfCzMl1NJ8/JlKoCDIl4OEUN0AHDTGTXgcXEdUxF66TEs7a4leWVakueUa1
UhqNBeA7yDdU8nymnqWExjqwVitRinpA82ySPBJmTq6YRVmSY6W5ieUAsGwl11ntitwl2eab
WCYatQyxTLLfDdVKJjwGENkyVJE763mIpQ2s1UqUoh7QPK3YY2Hm5IpZ3CSTn5EmHq3MdGZy
SVI0HhD9TBOHmfZzrKOWdv6GqIU4mnJZaDQ8oV97HdzZmFor5CjiTOtsJf6+eTi5PqdDJCUy
ng95pRPx9QaIbnXk+8eKMTw5gFRdUpA6LsHqoe3c46imjT+hakl6RmMDUHVdDNWXuWcpobEO
rNVGpaAe0Dwbh4+EmZPrV++0RUp3h6plAFj0Sk+Taim9H6qW6tKkWqprE+ooxdG4TfrBUEUy
rechuDawVbsJ9ZDmeR0fCTMn17Hd6WwnZCPmE0LLouVp/DA0TyLyZr4zEe83zUOMDUQrDM0j
ZVUgiqfaX3rdzgYd02rdhnhA63zM/b552Fbtm3fP3mwL15/8+dmb75fd1ZtP/vObva4iEsCc
0fUpukxK9WYG+POnlxdPvoKzuDx9gTywo3/Iuvm1eWY1pOXpaySHOUP89eXFf+/8/n+Wp/92
efHHp3Na+ICg6M5LECK4IdxGkHsAQf68BMWIlCrT038TPeG89CBj5f2HEBTPTFDtyBKDIDIO
jgkKDyAonZegTN5bqLcR9JAZyuclqAS/VjHPUrtBUHwAQeW8BFUfxQ87SdBDZqieedeTUSIB
s5J/kxZqH0RPurHpSXcnIstV/HdE0Kcutq8+u5+mM6vqTD4Q0iCnJ+kB+yydWVUX2vjIudEk
5Zv77AFinc6sqgNSQ8gaRyTgf4MYpTPr6oI7AIEJ8jd19UNm6Ny6mg6zIJci+kM10XTTKZ30
3mLslh4PSUJAkS/Q9IjleAWAg4gg0+uDAOgQk9RvSQKIOESiC6uXcltj4Bx/CwZoyCVnKHUA
4IxWxsjSRZa8litrkXJBRHZqUPjCwNZD4QTKNEbhqzcbESWtcSaykLXmZzYK31maGMWdrWZT
MbVobOdNfTS+fbAN0hLY24hAeDK2iczQPG5FDT5C5bT5xmig7djnmQg1r61NczW1kNmc+pD5
ngaRBZnI0CXbCNVF3TjRZR+8jhjhRwH5KCC3CMgtfk46swkWM26RMS3koUHx8e0A/0DFN4Wt
7FZP4uAxX7Ac0bneOL/WWDhyKpwzhynB85GJhsrlXqRB5+nANYogDSLWI+C4UAyq4gO2Zilz
IgkYci8z00qHxqmsLl2UwHM+teDA+NQHAcrBIGQuY902MooY9BuhNUE6Jk4IJR/wSpJUks3G
3IKvvU19tIrRp1Eax+I3OnwLNEsboUhG9zax4klIY52YBUaYp8NXOOXbfE0NeEKnHmTGpzFk
TTYiZM02InVRNzZs2Y3RLXr7UUA+CshpAblN6Z3Zq8o5r1WIS/0fV3rtpLVXPYuSJ4kqLNc1
BGbQu5WVekVIWcKXOQggYYo8x5a5zMcAknGpCaDyJHtdlRokmRBWqSY3ldPnHQcjAxKvosTL
GFB4nbcWdPRwhs+6oHKZR5CzaiJBTrOJSCQ06sxF4mN3Y5MEARIt8zA1IPMihbkLshaanwfB
VcY2kUHmQkt+opP2EZE2MdJBRZ5YJZTk8jQZPeohq7M1NeDZnHqQ2Z7GkPWYqJAF28jUFd0Y
0SUfrJrS+ygcH4XjlHDcpvDOHCKpofP9NVj07R9WeNmNpEjMSGsVh6RIi1ku2ogdi1g9bhSQ
tMClgUTYyyk6W3LmpFgENtnk8h7qTsRbpiZ/eGyE/Ip0aAST209LgsRE8Tem58urfdtd7/vu
7Ztn+7K7/oH+EAH7T/ru87evv93n3U/LPu3+hSB19+erZz/+QCBt8O/74HdXVP71vjm2y0x6
KTvJTd/XcoM7UrnhgiLOzcYhuNSDym4mKXWBAeK0AKNSFySbUawO3AqncsEzJi2Tm5NxtY4P
6+LoEM6MUZsA4ooMj1eXpZDv1w4bsBKYuvBuGqGQBkhlIqEgstomIouvEMmNDaD0ic8ClVls
IqYGnC2aemhuLfMQjT3JiQiYWGHQWIuoIuUgVc4XTDziXu40Cal6dVptlkYDncetC51oG8IW
YhBgSzVItMU0Hmyxjcej5wUfpeKjVBwfHJMOsYt0pJ9x/sbCx1uUOwyVr2yaSr64p81t2vfD
U1I3tG8h86Hh3lM+pX2/2vu4e/ueFOxytfdh93/74HbPXr97dfXPpGHj7lvSxr/Sr7J7vvdO
Wr7/+R1U9lDUPu9+/ukKrd8veR93C7Wiv0Aa8EKQf8Io9wef89nTYBXrj5cF/ebpfP3yiiht
OyH0OZH5fu8LHyrXy4/7KD9/fQjdH5YtyzesChIa52+j++X+k7CTyd3TAlw9gL4zu3m1OlxN
uIW+Z69ekXy83dfdLyQsP/FxfU2/3i5C73P8ptq/0+xevWdh4aW4n40Py7ndFA+EFvFeJCCg
eMwGiTrN83fPSHSvme7bheXF3pMRA1bS7uodGrxFi5eMca8RuD1DOX51yt4vme0ZsuBhScHB
yRwzbqw9Yf3mwE8GERaVMtRorJwj43LCr1iTniWVnPTEXKtFnvnhbywdD6UUgDA1oh3ifWSO
N0OlqYeTGzQm4sCGwudIxH9ik+eOy7J8SzYaICEsGtfcDYAHlNmrcgaACCd+RXszRidAWUcZ
j/vgtoxBG67aesyQkUUtYl/VucB9wkaAqgclAOSOxJjBofIKbU1ui/pqmTNV0NutGiACEPRw
xoRWjOInAHfqxpJE+CpRrhXrGoEOXOnRFh5cAuCUF4eZi6HafJFDhxnF2/5s/ltVk1rKVbpI
mEYGFBkkIgaj/hyTETT6XROfhwAE7QNBpRjGBCaOGeHZqrpWkUNiAChZeC9HewauajUPkOQK
ToYyH9mLBMB8xMgTSPZDETJo5pIAvHp0HZZD9EUjgnAKkWvxxdzIwAcontBWAUhv/KZWUDxH
1AAQ86HCHawMUDkn4ykmaSEWDfSXlz7EamqVX4viwMwC4Ogd6HBidtWIp0kASFSxFN6HzAvP
WCEZTIEBVQGOL5fTfOgokb82gClUOwmAOgMCXDpZhjgAeQbgixeRVy7WAUgzwPErcQAUBYA0
AXLnFWJpCANQDgCeuSVAHuU6lWE4CYJYpQxoM4DUUPEM2MppLnNaintsA1BnQGHzD4BoZaie
Uc5dpH6wBb0SDwAJQQsAfDVAkKnxI8QaZHqjlSF+KMtE0MZpvEDBj7KsWFAMfseGRVayE6sL
8b257GCJQyxEJQCABcMrHumTtpoXQUqjXAUgZJMWY4EuRlVkHc8AWQ+oNZFwjYpH2RFi0WdS
chDVNJcLA7J2qNIdIW0KCFIWoqHzgDGcoeglxBDWpFw4EW5vUxVFsXmv6iAHWR/yB0QrMaDx
C3wJdmWEiJD0tMMEAMiya7r78Y6Q711UoyPIVMj1GQbI83xnih4ASKKzT6NkUqRQsG5wH1i5
MEBREj/ecGyNGaAKIBuAr1t4m3AA5AG6zljg/EPoXQ8LBlQByCoEeTzU7eMfDKgM0G0YeHbx
xYFUByDIJwiUMF6G0DnLaoAogGIA/UJKjwbIUh4NvOc8sT8uK+EO50poXQ8PBjQBVANkfgMf
01F51IfCKVFbpA0wMJw8qlcBnAAyn7TlWuC8saJMgGYATTXrrpgAow9wUoeMToDRKa18UCU2
SnpYM92J32HVdgRogzMyygIdBjkfA6rNL95Gky6K/hgwVojOg4BEcjgGRJMDfKIgbUK+AYYs
NQC8qZ0NMOSTJjLgqv7pcuIFwOuAsQfwLDG6sZ/5i0Uh8JcrFEAHTQhJLSgASE6oZz+2Iu2f
wBKoZVzr8n0QKa/xfTNNh84LX9prVsaij5MbAGwi0lRbF3gqR4pJ03+IInsBbIw0QTkq2x5K
WDwM4v0xwMr4aAGMgXQMiEMdeGbEpWPAaOE88577MaDZiuBt9nZaTYA6VAomPNiJR4DQeQXy
DUAwAEaRmTeVQvIZ+iQoRwDPc05HQslDQ3QWlbzt98KylcfOw8ZJZk8BgHs5qev9FrzxbpGF
XmNlWPPC+0R3gTxzxdYq3gCl8stMJczzYYDdqxlRAJJs+GYATBDpiDxaNNYqRhe/VIEisi0/
vudRBl18tcRsNKa8sn7cmIUU96G7VO/0PKTYwVzgyzpDKWAzkqbvaWjpJB+aGfsXxrQLprtw
OHg+pNw4T/DRA5fVWWM5znwU+m7bDzaXa2p/Y2/IF29Ms1exVfzYGh3LgVNdBYp2exRLQQNp
dO5jVHy9bLMU/GSxw7ioYr4o5bGIYWx2cI584rERpVYWx+lgdukRTUYUqUQA9KZAGpabXgxI
4gIGu1HF6fPMTlAa5mCQ7/QIb2Q/OvmKz2Zx+s4AcWCGzZpMiTbch+Kyxne9mKDmUcNwjtJn
GrHNIgD1CkirMCdRVwkWPXtvUciCD8B0q14u4haD9TL8CnEahKiCa1yRAfEWAPkqUSZcPQAA
/AxoeI0zuybNHa5RkcOcrdQ4AGEGdNZX7N2J8wKvqk8A+F3ShebznDN/0ADF/EGNJgBQZoBn
l4RRrOzbXK7yEacxplfTeAAC6/04FC8AcKnGV9MqpMSP4EPg99cM0CQjJ9Cit6tkBJCSZoUd
m4a+G1NRk29d5R+Z0Cot2kgks2XcLdIQ+b4L1tz6SDxTAEhZYhNUtlEzUxmchTOgjMWh71ZO
6uFrgyZ+YlDbhwHioWmaWL51hcOkDICUNQ4hUTMcOnEAvAA0ikA6ioU/RCs32Q06RJLNYBuK
AdKgj+w27zDTx5ya7gJQlIITDeERS28X8UXLFh6JElAJVmY9YO4U4imMUEd0pIlyqRblomOK
Hcc2MuYS1CKARliy4yiP0cTf9WOA1rJTSJKgaX0AigBGGAhiGr1FMQCQskajRPDx9iYaABMR
g2p3AOCKRrs8xYDEAKct+ERCiMsCfpxhj8OmAwBbFkGwgQJOYhrxKnYdRdy0DLkCwMoQRNLx
uoIARAaoGGX5ppoZllxOXLYoGgdZELyzMfjdaJQQlAIgaDgVBkruHADcUMAIyZPNjoQykyli
BAAxoYiVHQPiCHZCwyU7LmdAGCjypQF3CHAjPlol+hlNOjO79QDEwQv2RN7CuIXXMdsFNgCg
FXMbhG0ALS+4eKvaBLPlBZBtgpPkodIGiAIYawRxLBbdYoAEfm2CJWBYtrCuhDrLNjn8ei7S
IRrbAEQBFJNHLHxNY5QNUEzoYfVUte6nch37BpzXPmLaG2C73CJRcTd2NwS0jegfFphQutNV
fCl2Tshi8kf5DCkHUAKdP+ati+tNLQbWi9PZiXLmxy64nogvk9FE3nwRtPvuah8lq/Jmy1D8
dE+qofjTzykcf4cyyU1HXMbhuNB2yYROEWQk8F0euWByB8Yt+c3y4Q9dbuQ34Sk3JN7pULiR
vvnTm33eaWKGJuj1M2RqkLh8+2Z59u3bn68fkHAqZ34MU2D9IQd+Mm82Z44eQNuZ3zDyzbF8
G22fPICgMydvcdeNTupbCIqSZL6Zo7ufzjM/bUxBpDCfzCJevdnyhfTj13cQQyb1O5SRQ4+7
n98wG5owRxbxx33Mer2pIIV6P1fnTvGS+sbHZCPH+I65evtiYb7eguagOd5fcD3r+rToTjpo
XPLFl8VogAT9gf6rCGC0DJivHI9NyWkM0zf2QhMd93ITELemHb54m5GQ4xaRv3ab+CYKA9jo
SWSZybngxaPHZ3ElmuLJo+/87V4J/fHn5tLcAN8vO+iiF/nOrg2CL6nhXspGhlxL3wgN4q5v
rPCn9GZmA3mMwWZjbhA0qmZdyM0XG0Ei5RMNIalNYlTSiRZnNoLTk9sYhdk+z4S3M9Wmamog
k7l1odM9xtD12IjQFRtk2poqF7bkxuT4DvPJ7y9/lJiPEnNCYm6zOM794YrGCQVQ1m6aG6du
efw/Ic+kqQ0KZW5kc3RyZWFtDQplbmRvYmoNCjU0IDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFy
ZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+
Pi9Gb250PDwvRjIgOSAwIFIvRjQgMTggMCBSL0Y1IDI3IDAgUj4+L1Byb2NTZXRbL1BERi9U
ZXh0L0ltYWdlQi9JbWFnZUMvSW1hZ2VJXSA+Pi9NZWRpYUJveFsgMCAwIDk2MCA1NDBdIC9D
b250ZW50cyA1NSAwIFIvR3JvdXA8PC9UeXBlL0dyb3VwL1MvVHJhbnNwYXJlbmN5L0NTL0Rl
dmljZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQYXJlbnRzIDE0Pj4NCmVuZG9iag0KNTUgMCBvYmoN
Cjw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggNjAxNj4+DQpzdHJlYW0NCnic7Vxbb1xH
cn4nwP9wHmcW0VHfL4FjILZ3vZvdBZK1gjwEeZBlyhIikQ4lreF/n/rq0qeHHFJca15MCARI
1te36u7q6uqq7vP0X6/fv375/MX75au/fr383/mZW9zqnPMhuLr04pac3HJ9cX72X79bLs/P
nn77XV5+fHd+5pcfR2ZXvIv5IPfL352f/cf52fJ7qnV5+u/LF188/evXf/pmcV9+uXz1zddL
XH7myhpX5tZQKtWVEn7X0pe/fXt+dhZ8WHtafChrCMvb87OQBOhldWF5c3723ZEmvDZxFqoW
j2s9KB3XfFfhYIVjzsTU1HZsAtzbdrTiyWtxbXuUvqftZIVLcmhja7tUAe5tO1vx6rS4tj1K
39N2GYz3uua2Fc5B6PsKVyucsxb2qysHpd3ayl3F25iwg+nFqJEApL6EHu7pdx9ThjH2B8Xz
WspHins3uDdmw+obc09j4eMSWgNwV/khb6X0tdepfKGJSOFj5TeR82n1xi0VT5nKLcm3+7gf
Epd7B/eBhjpo8QwgeZaiu8qb0Lm1h441nVJZc5Bi3AsDaFJDXlJ2a6Y/ISOZ2whGvaDMxWHG
LLmkuahSUjNnVsCvkTqqRV2daxYKmbVhTTYupegBz5T5lWgg6lSBonE0/om6GGkgqJbiRb88
lq4endh8MLHcHg1DD8s1TXJ0ZY1YGX7ldTpoqrwu0dNQ9SWS+JYFi4iShKD2YqDEaIkhzeWM
8pZV6FbWQiWkYGhhq1UIZJUmNVG50XIzr9vc/tb7cHTSypi0QlshTVQm3RGSKAXRSQbU1eUl
Ex6IaeeRDH1FaUq9gAIK0IgKFGJiKzqoMDIL0Ejp+UWLhhanmpV6AdXIDVuyMiVFD3meZuyx
dObo1NX71luILEW+5zVxzxUI2CHyEmJjyXEJySFFSWPqBQyXxlKnyTnMRYXSmpHZANIh1GUp
6kkMt5qVQmZp2JKNSyl6wPM0jY+lM0en0YwRtm9jzasPXKqKRSEA2CUjNda++sxdoeTYkqQx
BX3Q+ur6SCYLaioqlNaMzAaQ/ZsXLYqubDUrhczSsCUbl1L0gOdZXz6Szhydtn5LcZLZVIsY
Y9zbAVQwk0NYK7rjkQzLrxajoBEiJceRHMtc1KgwMgsAhUFaTIr6FqealUJmadiSlSktesDz
rDgfSWeOnrjcWHGY8rg41piFTKQ6S6sCKnKF7Kk6pBWWd52ltdSEXJZc21xUqE2mBsAip0VV
HLXmTVq14ZHs5qIHPE/z91g6c3T+/L0bn9MDuJzfmWrSGzrWkGRBwKg3fvwLRe4rH6Q0LYRR
KASrDdlAQcpo6LSET6M2b8NnLWkaWNBCG2/z7vZb4vjohIQxITe9KjwjhQ7ZwlRnu3kAbe2k
JUpZe+aeUHKontOEAmu1rK2P5ObmokZFy6wAMd9pKLQo9WqqWShk1oY1WZnSogc8z5P1SDpz
dB7taB8TKVT4khLKYeM2oIOHmEmvoxcRyTEXThMK22vxK8uqJJc8FzUqjcwC+A72rSidc6aa
hUJmbViTlSktesDzbIU8ks4cnTFzpiTHSnMTywGwbCXXWe2K3CVZ5ptYJmq1DLFMst6tqFEm
PAaIbFlRkTureYilNazJypQWPeB5mrHH0pmjM2ZekkxHizT10WjmM9MpJEXrA5ycaephpvUc
60illb8VVCKOrEwLj1ZO+NdaR++sTU0VdrTgzOtsJf62+3B0fspx4zByOR/ySjvi2w2IbnV0
3I8VbXg681FySUHSmILVQ8u5x5FMC38qqpTUjMwGUHJdrKgvc81CIbM2rMnGpRQ94Hk2Dh9J
Z47OX73XFindHaqWAbDolZ4m1VJ6P1Qt1aVJtVTXpqKDiiNzm/SDFRXJtJqH4FrDluymooc8
z/P4SDpzdB7bzfN1Qpxh3hSUFsVOTYahbBJxNHc1E79+UzbUl1HQiKFshFadoeVU4Uut23ag
bVqq2woe8DrvbL/tPmwT9d1Pzy+3uepP//L88sdld3H55D+/2+vEIbTLsVqfosukR2/Hdr96
dn729A84Hy7PXiLC6+gH8TS/Ns9dDWl59hZhX479fnt+9t87v/+f5dm/nZ/9/tkc8D1gKLrT
MgQ/bQh3MeQewJA/LUMxIljK/PRfxU84LT8ISXn/KQzFEzNUO+K/YIjsgZsMpQcwlE7LUKYD
W6h3MfSQEcqnZagEv1axyFK7xVB8AEPltAxVH+XodZShh4xQPfGqJztEfGQl/yot1D6Jn3Rr
0ZPuTsSWq/hzg6EvXGx/+PLjPJ1YVWc69iDYcXyQHrDO0olVdaGFj8gaDVK+vc4eINbpxKo6
IACEsHBEhP1XiFE6sa4uCPIHZsjf1tUPmbJT62razILceui3F/5xhqY7TOnogS3GbvHvkMTr
E/lqTI+YjjcAHEQE8VwfBKBNTAK8JQkQsYlEF1YvdFtj4CB+CwY0RIwzlDoAnD8rl8hSRZbo
lStrEbrACTtlKHwjYKuhcMxkaqPwpZqNiZLWODNZyFrzczcK30aaOorbWM2GYsrR2M6b6mh8
vWBrpCV0b2MCHsnYJjZD87jvNPoRKgfHt44GWo59HolQ89raNFZTDhnNqQ4Z76kRmZCJDZ2y
jVGd1K0nOu2jr8Mt+FlAPgvIHQJyxzknndgEixnXxJgXOqFB8fEdAH/fXjUpvtlT1TkG1lj1
5cReY75AOdxyvXFgrbGI5FQ4Pg6DgkclEyeV6V4kQ+dBwZWJIBkiZiVg09ASlMTbbM1CcwQJ
JeTeZab5Do1jWF2qKIFHfsrBHvGpDgLKQSNkNGP2NjaKmPUbozVBRqaeUJF80FeSp5JsNOYc
fLttqqNVtD610tgJv/HhW6BR2hhFFLq3qSueRDXWqbMoEebh8BVH8228pgw8oFMNMuJTGzIn
GxMyZxuTOqlbN2zaraOb2/azgHwWkOMCcpfqO/HZKue8VmEu9X9c9bWjNl/1LEqeJKqwXNcQ
uIOeFCT6V+FLFr9lDgIkDJFnpzLTvBkgCpeaAJUH2eus1CBRhLBKMh1WOW7esT0ykHgWxWvG
QOF53nLQBsShPauC6DK3IDvWxILsaROTiGTUuReJN9+tmyQIkGgZhykDGRkpzFWQzdD83Aiu
LbaJDTIaWvITn7SOiLWpIx1c5KmrVCS5PA1Gj7rV6mhNGXg0pxpktKc2ZD4mLmTCNjZ1RreO
6JSPrprS+ywcn4XjmHDcpfBO7CipofPFNdj17R9WeNmNaEjMiGcVstfJ3otZbtiINQuPPa4S
kLTgYAOJsJdRtLfkzNGwiNJkmct7p3sL3jE0+dM9JHS6SIemcOAtHeGJ4m8NzzcX+7Z7+eHd
/kncvd6nHTW+fxJ2X129/X6fd++Wf0HC8rd9iLsLAl5e733eXbxDnlevOXPZ/XkfPKf+8rGx
tttMehE7ye3et3JrOxLdcEMR+2djh1zqQWU4k7TSuQmAHGFQoqJbdY1ifeAmONEFz5WUpkNP
xt063rSLo804c4naBIgr4j1eDzCFToLtMAMrg6kK76YWCmmCVCYWCvysbWKy+ArR3LqBIn3q
Z4HqLDYQUwaOHU01NLeWuYnG58qJCZhaYfBYi6gk7UGqHD2Y+oi7uNMgpOr1CGujNDLoOG5V
6EBbEzYRgwGbqsGiTab1wSbb+njjScFnqfgsFTc3kEmH2E060tPYh2Py/EcuMWBPK0M1n30k
z11a+NMDVLe0cEl8jsJT0iNa+I+kea9IEf+876xI/74vu4vrf96T6t0/8XH3PdG/LK+e733Y
/R1q98O7Cyjm6yVLnrK7uqY6lg+smS+ul7J83NucTx33ihlrAA8G+u2N+Cfh+CU2i6vrtwsx
sn/Sdh9+Asc/PCfu3/Pe8k8E087DuV9Q72jHKTwo7znhf/cxy2bzkB5+WiAt3+xhyx3+9Dt6
+IrHnnvJPXkAfyc++zV4Ivtd/F1ePWTIPi20diQYioevkfREvM3RG5rfq8sf6TeJLKT4FQ8f
4J/Y/MCIigC8oOVxta+0NGhkr8VUYdsExW4JEYvWnTJ09fIhA3FqMzUVPIuCZ7LeHomLn8Dr
FZh9xcx/zG4tm9168z0s7NZWK79VtAeVDTeeiaYtxbF6bS0gahYbR4gYSLhTGyljqgLwi+tI
NSnNL6hjTbhHy4Bo18oP8hjo8JzH0tX93ejsBY93VSrgvhkc3JKdxNR5vsybsgGNRqjpoaKR
qiarGv5sefUMoCBHUscWgAYgIkjKAB/X4OAWNzUAn+Uush8ArRE6rLV8ADSoZgMS3xQWfxBX
im2koCprFneJk/rPmTHqCh3n6gAiAB5l7RtfP/aDsYj4Lrzm1jkZjsgvrHS8EvGBu3tFhxND
GenA1waAEY3s8mGAXV2RToB1TEmSWy2l2qQhTEJnQgliYFohl9EPoGCvj9HpMbaJFz3inCV0
xKE60soWi4hlCRnovKg52GkXQ1EHWqtdntwWm4XKPrgoD64ZKLCX8EQ3SauV92kcX5QNkjNM
Pk6aQvN9N9DihWulQQpi8BrQaQXXDPDOVyeFJA/PUIPZII1Er+F9cddTKxQ8hssPESTZQ5gJ
bgIFIL2RDDDlCoKVGfDSd7Ksoi9qyjUSkVIZEFuPDtSSfyzEKONPloG4YhvNFaJOBGTJQQOf
kzxRlhyB/wOgTFGPemdA7LXGFyxAO2HKew6nAZAqXOVuZBsJHO2lAm6zYicRJkQ6KxavVClm
baU5TpJDll6tHP/hnnGjNfOFAQCyBiqtqJpkrNRtU5iqw8ngOo+1NoGPX0SeHrViyZxECC/g
gD6ANgM0xa6xDMjaZaDPgDxDBaBFbgG0JLG6SbCk7wyUGQjMEYA86DjReOLjmbYjQjNZtWMH
f0cCwEb3mY7Sj6ByxkCfgNybAbkZ4A/oCFMaQCoDSDMAXSBVRKPzTEZ+i0G0KCQABzStaujn
MXIM5AOAJRJA3oB0ADiZQa/rh4E+A3h/02UZqz+/sqKcgCgKyinjJcpgGk2CmEWOah1AEUDG
ipY5hpsA8YAB8J4BjRkE3tpoHnMeQBFgxG2qiLPsKwCa0CNI0JnW0Uv8rohXg9DJlkvIBmAP
ASBsk+5okx5gWtekZIhd1mTSTQYA9xwBDqZpTyMy4u210UkAYZK2EgiND3oMY6AJoDkiV+Ht
RA06CyD9op2EaNc1is60AlICb3zw+L+ZDIQuwf6GbYSBJt8LqHbcBNAZkBWYA1sVCN7rlBLQ
IgPaLClJ7J4uIZBtQBNAiyTovOHDZDoJoIxGPtA4bzMCXxrTGr4KQeL9XXUgA5kBbYI36KBh
JMg0CFXCmQQUnzLoReUUdBJaGPC8ngKOrHUAlQE9VkOxVP6kgRhZDDQGxH8BwFf+loxy4VnV
4E6C7EAZmxm1QqaC34AiQDOAv7lQ9RoDA0EAbZb3SfZ6xgFkAaoBWb7UEEeRnBlIo0j0fOdA
vM4MyCUEMRAB4F177VMOA4oBmIBaVeAnejRCygN3IWK+CbQDIK7xJr0BjR8KhlvA4IL4JjvY
pxv0GAvckIEiSzeBwUSL/L6wbeMZBKg2BSTfIZvZykAU4GDmyWKJ/QZgw9e5a9mploNcZDNI
kYrXk2k4zwAEAZoJLO0QgfSQ3PAYQDB5R+Q6tmNUECqpLYC1BYGJziYGMQfiNpgthQUMKcTT
vWpAARBt3INMFXaXbgDG1fdRpPBTXt9UPsRExYVUHdYgHxQhnZqMTqghYiwUwL1MP/bZwCoz
yPetFMDlEypSRw6MrDdTFl3jVvPQBImfkwKIo/OJ+UrtJjCKJH17XG4CyQB88oo6n2/Qxihz
GFgtGd2ZtvmNuGkQwpiBwGyipXQTCAbQfohJU1G/DfBBI0jURmWGjKIAszeZmDFQrRVETyqL
ma1ynEkDwmtjvUFUsAVricyim0cE38uc0OKwJcrHC6ynPAB8FKMU2789P0ylVWuULHFb0nzU
g1bQzRlAFD0ySoCpWm24UYXculLpRJN5umQFABc3SCVWb0BhJWr9EsFpdepoEt1dTU/Ip4mG
oimRL6TlocljlquzZeiEwnfY4qYTGm9htjA51sfX4sYMyr6Zx1JOgTdW1YeBx4b34jStCGzf
cazLGnnHb2ODT/KhJzUaHJtwZFXo+Mcgh4NgqiaKvwJDpkUK2wh+KPLY5OtRRT0aOekxacxI
imIHNhPfpHV0PZbCiAvyrSinpqOeFpyJb8783RScOvV6DmxGtpLVGmVNF8OQNHhEMp9s3bCB
a2XAbtKwjwWAcIGr150PxzIljRcuf89KuIIl7xnYjH8v38NSuRCrA4CINx8oJEfXQIceSZKu
GT60yJG8b8cc+ayWhkKSRDex/CWQkMVlEUyr4/jFlZqDplSxtGFJyanPOeHU22UBnlAMsJg4
iG/jDAEdrhHwKmZvV2nCQTM2ObXHAdQZoBHGAW07WlaufgJoEbKwVNXzDJQZkK+f8NF/HIm9
PwCqGM9VFO5Nmg/Zcv6V/ZeBeABUayNu53RpQ/0HXl0WVa2RcbTfgCKHgFGHLIAJCPwxPW52
0Hmms6wCWyct6CFgA9jg2rrOQJ4BUufaaBt0nukqh5s2+UFCn4GkXLZ1o/NMJ6mxYWoN0Fi7
8AB/A5/7BiUtihy1zF6D2fvDi3oG8BiMJc/IUma6sJgFp+uWgXQANDlCm63NQJ2BwocJAGUA
oR0A0ZwNstMwcECznmXHWByAuALUTVrYJuBVOGi5GiA7USvycQQolEFHpoM620TKghkoDCQB
pA3aCdk9N3yRNYo7bji2ZGuEE1AdW1U+5ReK3qiB1xqOVjKxogJ69rfdCX5D9go283RVcUJz
mOGNeBq5RDMvdeULi1EedL4R5yQOrMMAYcALoO7LwN5ceECzAXDJRWdz0thTHc2LARqHfwJ0
gTREbOFlVUlqfPUSgLp/aU/v4pjVZdv4djYAHfJWpEgaHvrC0wpAnbsi0TGr16LJBUQGNhe9
Z4/xBrD7t5iTmSwHqNtoPjkA2HkJcMUAiGxsUxFMPQB1djtxIXfzJnb+WCoDwQBMQnLDty3x
CABaB5/64B/XicXdyc6AG87uxh51c8J73gRTmPzlUJ60qYdBi1PeJwO4ymQrp/N0MOANAJvD
00p07gIYjXlOZYQsAu/lAIzGYJGuyWUARQCjMe+pqWEzA+kA6Lp5TcAWSEEj2R9QbgQjApsT
eTjGJ2CMDFRKjlM/sT8CGJVy6CWN+IXs7ABGDlSxhR7kk44AvM0Pxg4m95gwLKvcTFzxKWGq
s7gpfIHBAjCEEWJCGk8VQtMPwJjZDYHWD8aormv8oAJAG4sCZkwxTx0DWYBgCwuLAuf3DWgM
2MLKHMWMepuQaQGsEdkaSF/p3jMB3nQIPJ+1207eWJIZ0LXp2ARpY5oANAGG9sMyaknN5hmo
plLRbLcd6NU5u9eqHGGrfgdaXDGuDPucdwrkED8TruQcD4uWEz/ig6mLDz1Wf+Tp5e6Hi33c
vfyA6K5Ec3/4WFg0HH+z5vhrvkkukuOu48FFEcoacfcv462H3N+7p8Qd10bKpz/eu3VtBK6b
hvtMNKu3YsZ/usSNvL3vcvnj7XMEuF/vy+7qcnn+/dWH9w+IcpcTP8aGacJXi47eQJij3A/g
7cT3U/hibr6LtycPYOjE77JxldjXuxiKd11t+DifJ75WkoJIYT56iePicrtmQf/8gpsbwuoP
ekHDx92HS+6G3lraP0nTRR6S2HcP6dWJb6aQxon4JHc8eiHj6uXC/boCz4GvovTdz6/Rt+Oi
O+kg+4CpxxcbqQHW1qi/igDGqo52T9qaNHNKFsnyeF4HwKv/AY9SHL4bbh4gPErBN8OTxcl9
YydSIutAPBT8CqXwx8XFe++xZ/IX0MV5z5/xTHOGzib6VEUv8rVyawRfqMR1v40NefWzMYqH
Qi5NXeFPlM6dDS7jhmC0vWtkCGpUWxVi/loLcAy1mYeQ1Kg0LoMaZ9aN4NS0so4G837pSMAh
GuahmjLIYG5V6HCPNnQ+NiZ0xgabNqfaC5ty6+T4mv3Rr9h/lpjPEnNEYu6wOOqJv/DgG597
wFm7bW4cu5H2/zInpOcNCmVuZHN0cmVhbQ0KZW5kb2JqDQo1NiAwIG9iag0KPDwvVHlwZS9Q
YWdlL1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIvR1M4
IDggMCBSPj4vRm9udDw8L0YyIDkgMCBSL0Y0IDE4IDAgUj4+L1Byb2NTZXRbL1BERi9UZXh0
L0ltYWdlQi9JbWFnZUMvSW1hZ2VJXSA+Pi9NZWRpYUJveFsgMCAwIDk2MCA1NDBdIC9Db250
ZW50cyA1NyAwIFIvR3JvdXA8PC9UeXBlL0dyb3VwL1MvVHJhbnNwYXJlbmN5L0NTL0Rldmlj
ZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQYXJlbnRzIDE1Pj4NCmVuZG9iag0KNTcgMCBvYmoNCjw8
L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggNDA4OT4+DQpzdHJlYW0NCnic7Vxbb1y3EX4X
oP9w+rYKqmNehyRgLOBLEqRogLZ20YeiD4oiJ0FsyZXtBvn3nQvJM+s9u1pbpygsLIpG5mXI
by4cDjk8++jJ7ftfXl1cvh+efv9s+PfpiRnMaIyxzpk0FDBDDGa4vTo9+cdXw/XpyaNvX8Th
p3enJ3b4qXc2YI2PG71ffXV68tfTk+FrHHV49Jfh8eNH3z/77vlg1uvh6fNngx9+48EyD2ZG
BwnHCoH+m6AMf/v29OTEWTeWMFgHo3PDm9MTF6SiwGjc8Pr05MXMFLZOceJSJfdj2qD2Y9xF
7BqxjxFBqbl9loq9c/tGHmwlr3N36j1zh0YMwdAc09yQpGLv3LGRJ1PJ69ydes/c0IGXNMY8
EUcn5X3EqRHHWIntaGCD2owZdpHnrrAN9ZLU0ABCGVxxe/guXWUkY7tBHkeAO8it6egbWDfa
zOhRFtYPLmeq2EXf7Q2gjCUpekBFBHcX/WRyNoy2oUXyEJFuCDbvQ98tLpZC6B2K2lXySBXB
shXtom9GZ3HhFZQ1Kmq4xaUdAozRCTUz0ypQty4OIZox4h8XqZmncq10iZ3BkOJaMwRNWksy
MneuFXb0yG8lNUmPLCXqXCeuzQ2lkG5gxs4/iyNCzoD8jUE1BOTQozxwFLDiZh4Kq7P6bV4B
ZeBIu6xiNFFWsjcwelogduTl2ss4eBq8RVGVwaMVw0BrCZukgPN5h42+Nbqg6VrJtq5SzjAC
Ugihy24aVQrUVaasjRVNpdNYJ91+6TzMKg3UokzRD4a1FdGPuCAOQvxTq0ijiUPEeofIjaVm
8l3YVkuX5IwcecdaAYhkIu0l1ztLRUYHaIdK6rJXI9fSJblJnrg1V1BCuolZqe2hMDOrv7Rv
0TnPpmRLHANzXisc7RZxcD6z+ZhAzS54aePSJQUxmU2vNkenSaVUR6bOrQIdCbIspBZtcRq5
lqizTNyaG0oh3cCs1PhQmJlVY+7LkHxliqN1TJUkupAKgosBq09ltJFZwWafg7RxiZxCLqMp
vRmjKUUqpToydW4VtPqHSkqsTCPXEnWWiVtzQymkG5i103wgzMyqrfTVFzwtPEgZ/+uSBDYR
46kEEqUx670iEbLo3JiIN0vNFBImaCVyDx6bfW/2oElbyfXOUkHeA12akNrs1ci1RJ1l4tZc
QVXSDczaiz4QZmaPYmZ2FwQMmpI23VpR7Q8wwkrddCkkT9p0IQXq1ZpT1qRSmgysV7D9VdJq
m3XkyXTrxL3ZaNINzEp/D4WZWf3ZvbugqSdzOdhzKQs3eN5ByyIDQ25s/yd5dZv4hFXbnOtE
zrXRqBuVyMpQdJXChj6abeJrM9U2glCJJmx6q/uSEM8qxHWFfHzdwhoBPH0LqMKRdK/IY0Ev
ATCWyJxgs0uW26RE0BKMufTmbDRpK/nWuVYg+IKiqKTIlRpZStS5TlybK6hKuoFZK+uBMDOr
x3bm9wEdKl0yBaKjXbxVFMLgI/p14sJTs4/AbVKivRbsyLYqzRA1aSuF3lkqbCH4jRRPPmpk
KVHnOnFtrqAq6QZmHZI8EGZmNdZuWYJhpzmZZa9g2wqmsNsVuwuyzCezDDgrdLMMst4baSs1
42kVYluNVOyujdzNsk1cmyuoSrqBWWnsoTAzq7F2bxLxnBEUj63MOCMeSYJvPNDtZ1AcRlzP
PvVWXPkTYS343pXLgrHRCf46aueuzVlbBU4l1Fh1lPhl8zCrn/krEvBMZ10ccUd8M1V4Mxo8
+/tEc1g8AGIzBCdtXKKoB5dz8b0ZF74irSUZmTq3CmxOQyO1oEeWEnWuE9fmhlJINzDr4PCB
MDOrv7Q3FoFiNl1Lr2DTgxKUa4FSNl1LMkG5lmSyIu0l3ztn5R8aqVhmG7kbbpu4NRtFuolZ
6/GBMDOrx7z3sB0oG6F3iFoWL4/zu+55AsLTfEcEbyfPg4x1wlbonkfK1YFUuur9ZdRpb6hz
tlYzEW5g1dvcl83DpLUXby+uJ8WVR3++uP5pWF1dn//9xVnVIiWAOaNrgzcRnep2Bvjpy9OT
R9/QYXF4+YrywAb/R1k3O2bLrLowvHxDyWHOEH97evLPlT371/DyT6cnX7/UaeENQN4sC4hu
cJ3bBcgcAMguC8h7SqkynvJZeNyyeChjZe19APmFAaVCWWIChMHBx4DcAYDCsoAint5c2gXo
EAnFZQGBs2OS8CzkLUD+AECwLKBkvZzDZgEdIqG08KrHoEQuzCB+lhfK98ITthY9+u6AsEyi
Px8Bemx8/mZ9N6aFXXXEMxClQeaFdMA6Cwu7asCFTzk3FFLcXmcHmHVY2FU7Sg1R1thTAv4z
zCgs7KuB3gA4BmS3ffUhElraV+Nm5uRRRDnUE6mXTmH29OZ9aelxF+QKyPMDmuJJHa+pwpCJ
UKbXOqnATUxSvxCkwtMm4o0brZTz6B3n+LNrFZlyyZGcOlXQYTQxRZQhouS1DIwgZaAbWdUB
+MHANAJwAkXNAfz0ZgIBYfQaJGC0ZjUbwG+WFKP0Zis3UagemeM8NUbm1wfTJDkQexMIup70
WcF02dKrqM6HS5w2nxh1uByLloRLccxZyUr1EGmqMUTeahJRiIJRVTYBrUqdOKlq77z2O8Kj
gRwNZIeB7DjnhIVDMB/pFRljwRMaOT5+HWAPdHzQrxX5ypifVfY7uZI5q5bZJGIAzpRTAMFS
iDhz4nIB6VBYCPR4wkkHT1pwtElUCmzibTVFKXP6iCjkNWZE/brMCawiQ4BjSasefB2uxsAK
2JgEg2TS1gQDJIyfgKZANqE4QZK4wSvaD4QmDd2DH7upMXKi2dUsmW/gJxw2O5TSBJRS0CUr
Viyapk+KWaJwWhw20VF8kpfqwAJVI4jE1RyikwmE6GwCWZU6sdHU3hid7myPBnI0kHkD2eXq
Fj5LxRjHJOBC+XRX124Gk2XjsWhDwJacnGOWrBnZeSe6OpZryuikIpBQLN8hc5ndPSXdQpaK
xGK1VQ/JSdLAjdKMx1FOkxfaALkisN7kXowrgDU79cAthjN5bQgsg55B9iQFQXYtBZISF0lz
EXh7ndhE1ZMNixxUBwwjgtNDYFSQrZ6EnixmBQPDghyswokrB6EpRgqhiIpVJAkmKmEUXzfT
Ki3VgaWpRhBpqzlEHwqFKGyCWTU6MVJV3lltbu5oHEfjmDOOXS5u4auQ5Aq/U6PIPX+yi4tm
/0tD3IHIsAyHrbSFJxQrKRmde920+KmrtS2Ip33OAFekumn5MWXOtclHHDHxG2S+/A+tIsmL
hCgbMO4tXtJzYkoRA2myLccpHa6ob1R6D3oY6/QYuN2YjVlwK44aBuUgnAZaMM73mhWkKJpZ
MKbJQjd7uoSeBqAYIOspsLrABAErg8T8FSM9Q6tBgnCB1RaK4hNJTJW3SKIYJSfVKpJU9CJr
NYNoQ2EQfU0YRaGKiabyxmaP747GcTSOGePY4fjiwjecMfMxljKLYcvvzV8BK783PST0kdL2
YMjvZR/lIaGc0ykXSS+mcJekKxtSR/syFH0kmhIl/T1RW1e/99xLuEsy97/ZHA0JQR/y6fCV
OfEKdks8Tz+8H97/fHV7ZuPqarjAvwH/np2n1ZsbLCQs/HDz5oezsHr3h7sk2S5C66clQb5X
4G8P0QCxnOmZNRskJxJCcX2NBLrvoQq5eiGKhEPgzuvrIksjdQCywlrGNR7pgXCSRYeHisgU
KUuFHylPbevFC+CKzJsdOMRRQ1ijZgB0CQEUBKD8UFYgwSbacCc2iKQoPsHycqmCUB04561G
yGYEPUXm+zAFgo6MrmNMIIFW5SAkznoqHunrAiWEkGy9emtS6h2qHKchqqDbFE0RHUBTVYfY
lNl4aMpuPH70kdTRKo5W8fHuoHxInE+mGP4KNciNR+aNKYJywcmT6470Kl/c7x6KXb73/unk
Ld8bw+gzGSzKacv1fnd9FlevzmxZoacNqzcXWHz/yxmsbq6Hix9u0DHfnQqLC1+TABoG245v
qTCN+Ort2blf3Vye+dXPB2C7X/p5+1UOnSfjLmznBwBa+pmQ5ZdNOwB53EVh9QFF5lY/XqCC
38seezdOWDglHZxYIX1zOKPUa1Iq6fSW/vH7WzJDhvojlZEL61cfrpmNK6q5xaqw+vXMYxfs
+zta7LtDuFo46kPv5elTcm/Ic3/M1c2rgfm6IcyOAJ6X1W+/EG/zpqt+PqJFhJa+K8IJAvkP
Gj+JAXr+JYXXVBEpjg7B1LOBpbwPVdh6P0C3p4a+d4/kL7mH52/dA3twrgiUTAqh0JNTrkh0
WKGP4sUZW3Slhb/cl/MGf2wWdAeK2zeGKCBf2bdJ6Dsq8ucTDLmenoDSjbYJihX+kE4z63AX
cU0auoOjr8HVELJjtBnoiiVrDC7Un4BoKB0GypoNx998KUadpwuNSRJ0eHNaVKqDCHMaooq7
z1H1MYGoGuswm04rF03ljcn+Kwyzv75wtJijxcxYzI6IAxZ+x2LpyBkZWd4ON+66AISw9wKQ
Pj/K7UcfOOXDd69BH4S9DfxpZOBvI6EehPcS7hLNwpluDMToNxdQdds3BBiHBYrDMsZhGIQl
CsIiB2G0cxwYiMHCjxExEEPr8hFVec8wDBYOESkM2wntgCgMlg4L0ejmwbjPj8AWjhQDv9v2
5Bn/fwFYWjispOOj/GLMTLrhHvFXsir+op+4oS/k+nYa3ODxYFf6dhrpJ2xiTaWTcyZ7cFDP
oURCL6S8qc+ZyL/TEyl0Sw5aBT2R8vinb6f0RApJSt9E6ImUbxkwSmCXjR58wFND4EZl9SS0
ldEbqQkGbnZe4aQnBsUqTmizNJpX2k2xb5WG6mFTfZnVxrB+zGoOLLqsQeACzk7DtEZeblU2
TKzvshqfSOA3JIH7tndaVqqH7w/OipZ3n6MqZAJRVdZhNqV2NqrWO593x2BHqzlazYzV7Ag2
0sIPnCkOs5mhwHYcdldCIvm9CQksUXzqgbPaXj5RTPyLDHdkJO6g3CWc+3+HsnUtBi5xSoJ+
0nAmJUF72oBx2OWZNXI3doubeJbLMYSCG2JcfXhX90LAjfOP2Ic3+9f4j6uL22suXL29uTwg
QEr3jzW3OMzJ8BXuPIcHREnpf3AbmRPwz+3NgRrO6WNaXFsvLzlwuhvg/cPKbYDoKPDQNA8Q
x0XHx/je/XoAvvuHmVv4iuHM7Q6tXqB1HnJUSPcLLrc+y6HVhG6Ufptq+xryMSq1GGvQ7edn
a+uxbL82NsGa/lme4ISeivj/59j0hJrX59iG9etzeCz1Lks5Y/lpRDrDfXgoHPY8xMfGx6dr
4EENdw74T/hm3boZxzUur4E784jGpGBsfL6OAsbGJ9PEtUyUoLDCs7UHHpSpnqV18jRgXFfU
dyogL/3JD1iyB59m71dvzyy6okv0Xzfo0/6Dzu3qtrqnTznG5aWvTyHy74nMgz7AQ+WFd82E
54mwU4o7b9PP80p2AjlAkazpkDHOMPBfZ4p53Q0KZW5kc3RyZWFtDQplbmRvYmoNCjU4IDAg
b2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8
L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAwIFIvRjQgMTggMCBSPj4vUHJv
Y1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAwIDAg
OTYwIDU0MF0gL0NvbnRlbnRzIDU5IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3Bh
cmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgMTY+Pg0KZW5kb2Jq
DQo1OSAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA0OTYzPj4NCnN0cmVh
bQ0KeJztXVlvHEeSfifA/1D71hwMS3kfgEDAkg/MYAfYGWuxD4t9oDmUbYxFeSl5DP/7iSsz
o9nVzZZYwMBEQ4DIPCLzi6MiIyOzii++uP/449vrm4/Tq7+8nv7//MxMZjbGWOdMnmoyUwxm
ur89P/ufP0x352cvvvk2Tt9/OD+z0/e9s0nW+LjV++0fzs/+en42fQWjTi/+a3r58sVfXv/p
y8lcXU2vvnw9+elXGqzQYGZ2KcNYIeD/OdXpb9+cn5056+YaJuvS7Nz07vzMBa6oaTZu+un8
7NuFKaxMceaykPs5b1H7Oe4jdo3Yxwig1Ny+cMXBuX0jD1bIZe5OfWDu0IhTMDjHmDtlrjg4
d2zk2Qi5zN2pD8ydOvCa51gGcXRcPkScG3GMQmxnk7aozVzSPvLSFbalXpQaGECok6vuAN+1
qwxlbLfI45zSI+TWdPQNrJttIfQgC+snVwpW7KPv9pZSnWtW9AkUEdxj9MPkbJhtQwvkIQLd
FGw5hL5bXKwV0TsQtRPyiBXBkhXto29GZ+HBqyBrUNR0D492CGmOjqmJmVYBunVxCtHMEX64
iM00lWulG+icDCquNaegSaXEI1NnqbCzB36F1GQ9Mpews0wszQ0lk25hhs4/sCMCzhL6GwNq
CMChB3nAKMmym3kurC7qt3kFkIFD7ZKKwURJyd6k2eMDYmd6XHsZBs+TtyCqOnmw4jThswRN
XID5vING3xpd0HStZFtXLpc0J6BgQlfcGJUL2JWnlEZBI3Qa69Dt752HRaUl9VDm6CdD2org
R1xgB8H+qVXk2cQpQr0D5MZiM/ouaJPSDTojh95RKhIgGaS95HpnrijgAO0kpK54NbKUbtBN
0sStWUAx6TZmpbbnwsyi/vKhh855MiVb4xyIc6lwuFrEyflC5mMCNrvguY1KNxjEFDI9aY5O
k3JJRsbOrQIcCbDMpBZscYwsJezME7fmhpJJtzArNT4XZhbVWPpjiL4yx9k6osocXXAFwoWA
1ec620isQLMvgduohE6h1NnU3gzRlCLlkoyMnVsFPv2TkCIrY2QpYWeeuDU3lEy6hVk7zWfC
zKLaan/6gscHL+UC/7vMgU2EeConjtKI9V6REVl0bs7Im8VmDAlzaiV0Dx6afW/2SZO2kuud
uQK9B7g0JrXFq5GlhJ154tYsoIR0C7P2os+EmcWtmFlcBRMETVmbrlSI/SWIsHI3XQzJszbd
lAP2as25aFIuDQPrFWR/Qiq2KSMP05WJe7PRpFuYlf6eCzOL+rMHV0EjO3Pe2FOpMDew3wHL
QgMDbmz/Fb26zbTDkjbnOpFzbTTshiW0MhCdUNjQR7NNfG0maUMIQjSw6aXu94R4USGuK+Rh
uoU0kmD3zaAqRdK9oswVvERKc43ECTS7bKmNSwgtp7nU3lyMJm0l3zpLBYCvIAohBa7UyFzC
zjKxNAsoId3CrJX1TJhZ1GPb8/sADhWTTAHpcBVvFRUx+Ah+Hbnw2OxjojYu4Vqb7Ey2ys0p
atJWCr0zV9iK8Bsp7HzUyFzCzjKxNAsoId3CrEOSZ8LMosZaliUYcprDLHsF2VYwldwu213g
x3yYZYBZUzfLwM97I22lZjytgm2rkbLdtZG7WbaJpVlACekWZqWx58LMosZa3iTCPiMoHluZ
cEbYkgTfeMDsZ1AcRniefe6t8OQPQin43pXKjLHRMX4ZtXPX5pRWhiOEGquOEn/fPCzqZzlF
kjzRWRdnWBHfjQpvZgN7f59xDgsbQGhOwXEblTDqgce5+t4MD74ilRKPjJ1bBTTnqZHapEfm
EnaWiaW5oWTSLcw6OHwmzCzqLx+MRVI1266lV5DppRqUa0m1bruWbIJyLdkURdpLvncuyj80
UrbMNnI33DZxazaKdBuz1uMzYWZRj+XgZjvgaYReIaTMXh7md93zBICn+Y4A3g7PA4x1wlbo
nofL4kCETrw/jzrWBpmztZpBuIVVL3O/bx6G1r79+fpuKK6++M/ru++nze3d5X9/eyFaxANg
OtG1wZsITnX3BPjVm/OzF1/jZnF68xbPgQ38w1M3OxdLrLowvXmHh8N0QvzN+dn/buzF/01v
/nx+9tUbfSy8BcibdQFhBte5fYDMEYDsuoC8xyNVwlM/C49bFw+eWFn7FEB+ZUC54ikxAoLg
4CEgdwSgsC6gCLs3l/cBOkZCcV1Aydk5c3gWyg4gfwSgtC6gbD3vwxYBHSOhvPJTD0EJJ8xS
/CwvVJ6EJ+w89OC7A8AyGX88APTS+PL11eOYVnbVEfZAeAyyLKQjnrOwsqtO8ODjmRsIKe4+
Z0eYdVjZVTs8GsJTY48H8J9hRmFlX53wDoAjQHbXVx8jobV9NSxmji9F1GM9kbrpFBZ3b97X
djzuAqeAPF2gqR7V8RNWGDQRPOm1jitgEeOj3xS4wuMi4o2bLZfL7B2d8RfXKgqeJUd06liB
m9FMFJGHiHyuZdKcuJwwI6s6JLowMEZIdICi5kh09WaASGH2GmSCaM1qNhLdWVKM4p2t0kSh
ehSK89QYhW4fjElKQPYGCExP+qJgumLxVlTnw2U6Nh+MOngcq5aEy3EuRclK9WBpqjFY3moS
VoiCISobQEWpgxNRe+e15whPBnIykD0GsmefE1YOwXzEW2SEBXZo6PjodoA90vGlnlaklDFd
q+w5uVroVK2QScSQ6KQcAwiSQoSZM5Vr4g6VhICXJxx38KgFh4uEUEATLas5cpmOj5CCb2NG
0K8rdIBVeYjkSNKqB6XD1RhQkbYmgSAZtTVgJA7jB9Ac0CYUJ0ASt3gF+0mhSUP3oMtuaoyS
cXY1S6EM/MBhiwMpDaB4BF2LYsWCafqsmEUKp8VhM27Fh7xUBxKoGoElruZgnQwQrLMBUpQ6
2Ghqb4yOnO3JQE4Gsmwg+1zdynupGOOcGVyon+7qWmYwWzIeCzaUyJKzc8SSNTM574ypY05T
RscVAYViKYdMZXL3eOgWCldkEqsVPWTHhwZu5mbYjtIxecUFkCoC6Y3zYlSRSLOjBywxdJLX
hoBy0jPwmqQg8KqlQOLBRdZcBFpeB5ugerRhloPqAGFEcHoIiAqK1ZPglcWiYEBYUIJVOOHJ
AWiKkYooomIVSIKJShjVy2Iq0lIdSJpqBJa2moP1oVCwwgZM0ehgRFTeWW1u7mQcJ+NYMo59
Lm7lVEh2le6pYeRePtnFRXP4piGsQGhYhsJWXMIziBWVDM5dFi266mptC+JxnTOJKrIsWn7O
hc7a+CWOmOkOMiX/Q6vIfCMh8gIMa4vn4zk2pQiBNNqWoyMdqpA7Kr0HXox1egxYbszWLLAU
Rw0DzyCcBlohzveaFaComtlkTJOFbvaYhB4DYAxQ9BRQXdOAAJWBY37BiNfQJEhgLqDapqr4
BBIj8mZJVKPkpFpZkoqeZa1mYG0oDKyvgZEVqphoKm9s9vjuZBwn41gwjj2OL66c4YyFtrF4
shh2/N5yClj5PXfwZieKKcl9ZNzVswx8ooAXEwGWlgMqFUsWjP5XKgyaEiwFHC9jEgDvE+C1
HS7TpX1cNzkcdqXSKRYm2HkEjJT5KeHFGHMmabtH5qekj1H5+nKbBNMyaL8dBSZuyB4bTEzt
xNi4wP5JM4mZIXiaWAqqAyzY2St6PK0NTs1QqjyFAgHfaIxVYQSjjcEqLoolHQw+MWvirJJE
MfIUiqhUBxamGoKlrSYhdSgUrK8OU7Q5+Gj67pz2C5knqzhZhbaKfY7u6QcVs0GftnUVIGHe
tRpueeDtlo9zlLdrhxWY24zKijEbCqJVCo58S1H0HynRqcwjZlo3hwElssZhYckp+8P0LFZ0
C4VZeFfRbBhzwNqEPa5AVg+RA9l0nwDWrFQ0gkwX8wbEMuBnsgvFXaGz3mG+0mGYL8u42S4N
PUyXpx5GI9iGVQn6YXfM3jBM4b9brghId3CanKWrJmD5KwisoYGR9ad4EA3veLOTKZxMYb8L
e/qRw44L84lCxc91Ye3YIfAt9m63eJO6ZqXZYDMeK4ni8TX2pBfiANsEbbbB0RlNtyo8D6Zl
tpldcJy+7IYZvG17A7ZcPEkOaatHxpukagyoUOtwCG772QnB8ELdUQZGIUwEOpJSPPK78916
W4euWqEfypcZunUIhGE+DHHYl/AwLFC4HAYqcugWLIJSHViUagiWtZqElKFAsLYGStalYkO0
vePOTmZxMovjXNvTjxh2XFtwSVztZ7m2cQEZnDrm4Azm4IqPvBnlM2O8F4tv78D0eH0AtdS+
UgRigJgbL6B7pAbd87eHDhLuE8/T05O7nh8PAgtdAk52Rzyvfvk4ffzh9v7Cxs3tdA0/A/y8
uMybd++hkKHw3ft3312EzYf/eESSqWUz5TMHgd+dp+/guNlDucxsH7HQpbZQXc/XBLx7gBV8
DQApMgwBuxEvCR/Yl0A54T5AyqD0iC+r0tOXDGxLIlHkwhWwcYEOVi4BJHjQy3YHSrerIaxR
MyQb8NEaEBLeVSwKZIIHIVfFBpJUxWeylLoRQagOdP9ajVDMnPQUhe5mKBCZwpOGMSdO+gsH
IdMNXMUjvumuhBCyFZ/UpNQ7iBzHECLoNkVTRAfQVNUhNmU2HpqyG48PPthxsoqTVTxcIpQP
scsX+wx9ESnw6XuhJClsn4YLzh5dd8Q8IrvfAxR7fG96+pXLHd8bw+wLGizIacf1/unuIm7e
Xti6AU8bNu+uofjxx4u0eX83XX/3Hhzz49cy08rXMmGXkMh2fLuWqRHf/nxx6Tfvby785ocj
sK18m57ONuM+bJdHAFr5KhceYNi8D5CHVTRtfgGRuc3fr0HBH3mNPQLnypfsIaokK8Tv3ywo
9Q6Vijq9x19++xnNkKD+HcvAhfWbX+6IjVusuYeqsPnHhYcu0Pc3sNgPx3C18u0S8F4eP2vm
DXruh1y9fzsRX+8Rs0OAl3Xz64/I27LpKh/UP9uD37iACQL6Dxw/swF6+qrfT1gRMcyWMB4r
8A4iVlg5q8abPAa/vRbRX1IPT99dC+TBqSLgxcYQKkb2VJExq4u7CXbGFlxppa/I8dkXffgk
6A54hrQ1RE38xbc2CX7TA/35gMFXpQZQvF1lgmKFPuqimXWwirgmDd3B4ZfJ1BC8YrQZ8Li/
aAwuyOcIG0rckGg2HH1/RDHqPB6uD0ngQaLTolIdWJhjCBF3n0P0MUCIxjrMplPhoqm8Mdm/
CLj4JcCTxZwsZsFi9kUca79CiVvOSMjKbrjx2GWUfPgyCn4Ko7QPENL1Q7oHFPRG2NtAh7mB
TnOTbIQPEu4RTV77uJoSxL5gZmMhDgsYhxWIwyAIyxiERQrCcOU4MhDLa7+w49G6MKv81DAs
rxwiYhi2F9oRUVheOywEo1sG4z47AssrR4qB3iH26Bn/fQFYXv3dTTzDwa+XLlx9e0L8lbOK
v/Bzq/i1lr6cBjd52NjVvpxG/JxqlGvd6JzRHlySfSiS4Ns63sirNejf8XUdcEsutQp8Xcdj
+rKtEfi6DpDUvojg6zq+3cbEy9R1qwdt8NQQnAQek+BShu/rDBiw2HmFE6+7V6s4wcXSaF5x
NYW+Ig3Vw2Z5S6iNYf1c1BxQdEWDgAe4OA3TGn6LSNgwUd4RanwCgd+SBKzb3mlZqR6+v/xU
tbz7HKKQAUJU1mE2pXY2ROudz8djsJPVnKxmwWr2BRtPe2d7MQ6zhaCk3TjssctxuR66HJcD
vdF3OBuWiqPjDDyQsE7+GMIjlHtkU57+qvZOVizDyoEh8pFZsfTJWbGycvSYwdhKXScrVlYO
FAs8+/uxHRGPlZXjw+ItZX6XAdnPjsnKynFjjpWs8N+bFSsrR5q5FPz8/PpZsdKugBRw79mp
JEehK8xq31/wLKSqzEDBvwmiUgel0k3vkVyohl40GemHCquUU/mJiu8LepXBqIYOoUeOo5qK
3/NWPSx/UmmMYWlPpSbBL6UGDYPvrA+g1dEHXAYn1dKSNXitzlHSoic5eo+2/29jcHqgTdGz
Bw1Ezy80mC0B0fjoGYrGac9hNFn0LEeTlupB4lRDsLzbHE0hHYRorKNsKmUmusaPy4qdLOZk
MQsWsy/iWPmcoOL9nbovK/bY9ZBy+HpI9njxg/5MgaMXXfGSExQg0HrkfsgjlPuEs/b7a4Fe
48A/VrX7hu4rWJ5/m2Ahu7mwBsKxe1gnYOX2nCC7+14thB/w99v7C2doUXEb90cg9kcsgHXl
bwHlEHjrht+q2Fn/eJUOCI4CkZ+Am9vr+zvC/GmBXF05yCyp4h2DZeBHxHF17cAS9tG0+dzF
M13imPAw3VBA9zi0tUPMQn/SahEaDAnbPkT24R9HIFs7qAy8eca38x/qkHYy0/Xdze0HfJ4+
XmDCebrbisUgQDsC9NNixrC4JwPXkxx9DmbnkthLY19FY2EJsParq0sP5fL6yuFPqPPxFUzq
jU1fX8WX2MVY466sg99fm6skVdVcXUKVjwV7U7PJgSjil1cBx/oCfv2CWi+JWipwtMxFbHtc
PGvnOUMBbTp4PMOuUlXAn/3mjxee/cr9hU2b2xtU8UXe/BPab++nT/QvK6+DpQRcgvfwcYyD
WTlNUir/EawlQNrDHLWKrL0uYooCHoeQMTf3UFgL29fLsvlwO7aMqH3cVc0L0P8F8M5SIg0K
ZW5kc3RyZWFtDQplbmRvYmoNCjYwIDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBS
L1Jlc291cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwv
RjEgNiAwIFIvRjMgMTMgMCBSL0YyIDkgMCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VC
L0ltYWdlQy9JbWFnZUldID4+L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDYx
IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4v
VGFicy9TL1N0cnVjdFBhcmVudHMgMTc+Pg0KZW5kb2JqDQo2MSAwIG9iag0KPDwvRmlsdGVy
L0ZsYXRlRGVjb2RlL0xlbmd0aCAxMTk3Pj4NCnN0cmVhbQ0KeJztWE1zGkcQvVPFf+jcdl1h
mO8Pl0pVlrDspGJXEpHKIc4BEiRUQZAgZP/9vNlF7PKxAmennIsvsMwO897r7ume6f6r5eru
ZvTHii7eXdI/3Q4nzjjnQkruKFhORnNaTrqdX1/QvNvpv7k2dPvQ7Qi63UzmVnBltmbfvOh2
fup26DVWpf7136M5nZ31311+NyDe/2E0v6VsMu/9cp2fn9PFoEQulhJacUP8APTFEPBXgrRm
3Goa3kQSYECCnGIS45YFRcP7yOu2oOoLqpzedDu/Ze8f78eTJeUqW9zQxeIeD+PcZA/0Ibt6
nM1omNuQLXOhssnkW8Kb9wu6mI3mf+WCZw8f8vx3Gn7f7bweNioTrZQpEn5LlZCWcUnKGMZr
uko5Z9zpV+dblD4HKRpsC0tZpjSwBFNiHwtCzo/Kl63kyz35WjLZJD97SXnPZPPHvCcz+DXv
6Qy+xSecO857cPL9ONfwbpzw6Q7uXE3xDO+u4GMHH8dJNC2+7hALt9MV5tNxL6u0XtbcxbBt
9rI5bnmdOvA8UyQdNtqBWEgcd55JCyzOZDgQd8r8d6wdUQht1yhqoC+TAUELhpqQlFPHHWrS
O9RokkIz776ARz08KgQT5oRM0kKVDsz5RlUpXWrLKG20X7oodfDUc5pOyAY2cfAEy0Qzo8vB
cUauLaO9ICs4iSBYOBhjg3TxLLlkXjZjaZ4QS0imn8Fqkw0PmTAgJ2ikxdT7dN+GEOSbsdRV
ShuKYgc1YiXbq1LKQtWXyKpSQY5+JquesAt92rygHAwsC/khtfxtJKOYds1IA9NiC24jubjx
mpFOqt0h7THYg5JoopS9POFW0u7ChYPg9mXLGB/rAfaXTO12x8x22JvoEAQ/LieJc9SuKG+L
Q1uDqjZniR0k3JWLU0sDknI6of2s1NFXhh+8WyS0n0U24PYZ+9lkSJbHa2Gz/Q5v0R+r/SDW
W4CzgDsHZzp+iCBpiXWsNEi9ItpNExa3wFGhuB9LTzMMKBmfhEGpLn4jO3FMwK5w5W+8sPAF
YrYcwEUA2Us4E8/FccBLZg0KsGSqWNLhiIG9LbyJyT0OiOK8KUL5WilmTP01IFFxagtYwXwN
wfnYI6lxcB4pVFUkPdcMdt2IcAFrq5pKj0KjNnaozUAqqv6PMe9MDcCHWHsrBnH74l8big54
wtU04NYbuKyptIoJeKUyAmJX1q1UTVjbsVpibekKZO2LisXaWRuaa2dWOp7cXcqclo0sBIql
T/EbkIgVZVSMGLD4GUH3NWS+hsxWyFw31OHE/THrArPwGNSCcEyERU9WlAeDt7nKRrMbyns2
tsTyns9W08kJ7S3Rrr91gKaM94zYgvD7NOeLP4veXdmni324+edwbdf4ilwZ360vCEsQFdzF
UNrlG5uHPptMCrrTUS5k9jG32Ulk2zV19g0bCsdjiyMk94iOF/fjh29OYNWuWyB3y3Pswvv1
9cvvHVevF7OP0WaTB1rFtvri8Pm1VqzdplhL62Kx1vHT2VBUa4WkYoGGJCWL3KvwVA3MqgHr
ngaQ4eKADjszcMPaHtD8aWCNshnY1AXhdawHMlYFY0VZD/4/Uk+Z51/Zxg6DDQplbmRzdHJl
YW0NCmVuZG9iag0KNjIgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3Vy
Y2VzPDwvRXh0R1N0YXRlPDwvR1M1IDUgMCBSL0dTOCA4IDAgUj4+L0ZvbnQ8PC9GMSA2IDAg
Ui9GMyAxMyAwIFIvRjIgOSAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VD
L0ltYWdlSV0gPj4vTWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVudHMgNjMgMCBSL0dy
b3VwPDwvVHlwZS9Hcm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1Mv
U3RydWN0UGFyZW50cyAxOD4+DQplbmRvYmoNCjYzIDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVE
ZWNvZGUvTGVuZ3RoIDIwNDA+Pg0Kc3RyZWFtDQp4nL1b3U8cRwx/P+n+h3nci8Qw3x9RhBS4
JGrVVG2h6kPTB4iAIBXSEtr8+7XnIOndrJcN490XYI+7+9ljj3+2x7P/8vbu6uL0/Z04fHsk
/l4ulFBSKaWNUVHkoIR3StyeLxe/PRM3y8X+m2MvLj8tF1pcfnmzClpZv/Xui2fLxc/LhXgF
3yr2j/86vREvXuy/PfpuLdT+D6c3l6I7v9n79Xh1cCAO1xvk8lXaWeWF6oE+PAH411o4J1Vw
4uQChQAJhBbRSgOvB5mtOLlGuS6LqKmIqsSb5eL37sd/rs/Ob8XKdh8vxOHHa/jjbOW7T+Jd
tz6/vfp3pX13utK6u7v6ePNutfpDnHy/XLw6IRXRTYpYodOWEtoEqYyw3kv1PzU20r9Q0b08
2BLpW5BwfbawbJDWAZaWVtdYoMjBo+qbJvVNpb4z0lDqd8/Fas93N/+s9kwHZlztuQ5MCT/B
lmerPbDp9dnKgTHxDZ+vwK53H+Bvbbu725WO3fk5vkl8KL+uwPSXH+7g/eJxK1teKzsV0Utp
K/vHV95xO16SVpgI+6rHF5j9LkkTAEtJk3v8zvqnY+0oBa4dSaXW7ogNCHSBlygkG+3jBvX8
BvVOGO1kijNYNIFFtZbaj4gkDVq5LGMiteI0adh4Kbl+fF4awVJDOo2IBoHZeXKQmpboaP24
RLFVosrJikw6a5l7fWzN589GGZkMjeUUI5Y20g1gtUTDviXMEBMchEXufVqvISiUaCz7mnMN
ddlBJBbbXjXGFK3miKrGgjpuIKqO2IWJNy7YCAtsivqZW/1tJG+lizTS2jdswW2kiBuPRhrF
3Zk3DU4gkqZE6p6PqEra6qva7hYCInpkQPad1u2ts1JDKmotlHh9mzlwWd76IH0mtWJMJmyE
TD+SSPDvXh/76atB9b0NoT5K4jMKYkKEyts5/BlDFr/Ady0MeLMXJiuM8wBjIlQaD88mwZJC
8EpQ95mvT0oGLd7De+9f8E7GKP78+gLkXGAJkzYJEZTeDr4rOxm+PJVPb/37/qM2I5F+eXJS
b0Ep+MwWFBCvx9IApdY5FqmLSvcP8NljwuXbStE6ACmHJrO4GmbaUKchp80kEmOo87asN4Vk
o3s81Om2WriKdd6BTJaQaVSsY66EPbhiaYvM0ILx2eIuGt2CebpWQVnYRZRSa8cWVIPRs3Ww
AmRI39LBasOCqJloLM58NjiPWSaNxZbPBp8l3YhiZMAAIT0mEqnKshqQoJJKtANW5XRD5qjy
bJEiAklMFSkqLAOxeB5Pj5AS2PGO3hv/2xtnELDcDlFCdiMsiGt7SoJX9nCEWO0tmUqsAPWX
JsVq9bddMBexMWHByQN7U69WzafS+Sd0a4tENVoMJUYQaG3RqEaD9BsKeVq3lohUoUVMqnM/
mtiDLzYegtX7Tb7H7TQRu85xGqfpQYMaMVoarTFS7aJBYWqH0MYEq+a26G5GH6QOpUYKPYXl
uEjF3CQKUGVkUiTeBBBKU4gaUArL3NcrYMyfg5LakVqxZkpJBkMisWZKphwRkTrxZUpalRYC
qZNjQzJDdtLGspXt0cTSdJ7eTtHpIY/gtBOUA9TqFe7Qho86tpFjls5Ps5MrrOSw5UVisSa4
2UkzhMVWeCdlpCPjLnj+GCpoa2ST9GQVto+fRk+GuZcdbC6NSkImdn7CGAGhQvWNOvDyk02k
Vsz8lOj1Y+anPKASKz1BqUOrxEpPtJm46Qm759ObCelpwCGY6WnAyTntFDJWT3PYKZaJxTns
hKdApE6cdkpQglKrN20akaD+hOJskoBbYUH1iZajsDjTiAS1px/Cimy283pz1Et5/iEfEhCx
H4/Umxwwz996G6ULkAcpPI58YsLCfBIZnJKGFIk3X/FKejyiC9JOXU9rPCemtGLNV7LM9Pqx
5isWk3xaJ8aEBVYvDejEmLB4OWQmPpWcGTYTW6EUfcDTtTl0iq6MLvQA7dDgS+ZqGqrOmKbZ
xzVWxkSTxGKlQZWxY0VjxRHhmXmY/4EywH9TT1t4HGUwzzDcU4bDyZl5GMPG3skmZsawpFIV
YfQuM/OMfUg4ekWKNGZM2jQfE1YWuec7XabKeyzyitH6KRWbUFicg9IBJ8AGsGwD59V6aRnK
FQDL7dQ1VJDB0ViscyU5SDOExVZF4CGkJXdGU35ST0ZsfNAl2TsY0eDuOzpZXUIdFYAYU6Es
lZtn8aAGUwOLx5knBLyzSUKxNt1jGasjofhSyWQ2Ok1PtDEb3LQk0e4q1Us27afP9XAD0LIx
ePs29R1wjOPl9hPoWi7gZkgVSblGkXPzcUgfOUcBORNeOZiemzUNxU3NA1pxMzNuA6X4880+
asarWRQWNzWrIawWau6fEQrk5mDnZwgQsB1d/8luC0HXmgFJu6FwxDtrBQyTaLTqXkcjWoAS
M5NoIbV0fWq0aPAy8zw+gjee4oCPsJ7+R7xfRGLxnv4HHFCjsUaQtuU+/w62HAwaGWzfdRPG
zmsqV1spJFYPwrNivJUkTR8ULy0A2+ElJQqL1YFULAMUJBZjSznLIa/gA7IB6/hJvGK30atk
onVqi5dVGQUbfBZPx6NpXL85XD3ivcU0k6vjVNYQFl/Vlgc9kPEyVNKb25CkX7CdPSVYtwEk
xqieXJxs/1b9fh9lGvAJvu5yChHvH87hE8ljE260T4jdu8D24S6wwjPAz8vFwgEdOQWJL175
xQeN04YJL9Y+3Jb9D07OenMNCmVuZHN0cmVhbQ0KZW5kb2JqDQo2NCAwIG9iag0KPDwvVHlw
ZS9QYWdlL1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIv
R1M4IDggMCBSPj4vRm9udDw8L0YyIDkgMCBSL0YzIDEzIDAgUi9GNCAxOCAwIFI+Pi9Qcm9j
U2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vTWVkaWFCb3hbIDAgMCA5
NjAgNTQwXSAvQ29udGVudHMgNjUgMCBSL0dyb3VwPDwvVHlwZS9Hcm91cC9TL1RyYW5zcGFy
ZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1MvU3RydWN0UGFyZW50cyAxOT4+DQplbmRvYmoN
CjY1IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDU3MDA+Pg0Kc3RyZWFt
DQp4nN1dW48dt5F+H2D+Qz+eCaAW72QvBAHWJcZu1oBjK8iDsw/a8dgxIiteWU42++u3vrqw
+8zpnhn7tAVYMDQzRbJuZJEsFqvpx5+8e//dN6+v3w/PPns+/M/lhRvc6JzzIbg6TMUNObnh
3c3lxZ9/N7y9vHj86Zd5+PbHyws/fNsbu+JdzEetv/nd5cUfLy+Gl0R1ePz58OTJ48+e//uL
wT19Ojx78XyIwz+ZWGNibgylEq2U8LOWafji08uLi+DDOKXBhzKGMHx/eRGSFExldGF4c3nx
5QoLrywuQlX0ONYj7DjmLeRgyDFnEmrBOzYpuJN3NPTkFV15d+w7eCdDLsmBx8y7VCm4k3c2
9OoUXXl37Dt4ly74VMfcZuQcBL4LuRpyzorsR1eOsN3YyhZ66wN2NLzoNTKANA1hCnfoPfUh
Qx/7I/Q8lnIPunddehM2jL6x9NQXPg6hNRRs4Xd7K2Uap7rALzQQKdyHP5ucT6M3aQk9ZcIb
km93Sd8tLk8TpA/U1UHRMwqSZyvawjejc+MUJkxB/CAVhnc0v1MqYw5CgjWyAhrgkIeU3Zjp
V8ioZn7BoGtqXJicVZe0RFVIKHNjLfBjJKUV1dUlZYHQWBlrtUkpqEcyU+O/ympEChYsOqRd
S6RjpE4hKsXLWvOxqLo6yLY0RFfGiAnhR56eHSY6dYieemWiRo5qMXeoSgAiHQNVRqsMaYln
kLemArcyFsIQxNDCTFUANBWWWqnSKN5S1nkYL37jOqyOT+mT8PY+iFmYaf0ISRYGWZesoI4u
D5nKA2ngPKqxZlGdQtdYhAJWRS0oJNGM2qHQG0tBo4XPD4oaWlxQVugayyMztmoVSlCPZV4M
38eizOo41rsW0xDZpPyUx8Saa0HALpGHEBubkUuoDilKHUPXcF4am6BW57BEFUgpo7EV0NpB
KguqJ5ucKSuExsLYqk1KQT2SeTGMH4syq8PY7pyOsebRByZTxc2QAshPTWKdRp9ZN6qOLUkd
Q1gt2jS6qVeTW7VAFUgpo7EVEPc8KCp0mykrhMbC2KpNSkE9knm5mn4kyqyOo3mGmVyoWsQx
YyV7QYUMOYSxQguPaniBtRiElSFSdezVsSxRDQq9sRRg4aDVTFB9iwvKCqGxMLZqFUpRj2Re
LqAfiTKrpy/zxQs5RXVpllqgtlXIg6rdLOF316VZlprQyqprW6IKNBtPL2DbUlS1O6U8m6Uy
7tVuiXok82LEPhZlVkfM37nlOT1+y+mdoSba0KGGbAkmRdr4/ieWcF/5GKV1IXSkEIwamgGC
XVHXKYZPnZq37jNOWgcRFGmWbbmv/ZYkXh2QcOfmFQodsUWoid3nXtDGidaFUsYpsyZUHarn
OoEgWi1jm3p1c0tUg6I11gISfqKuUFTSakFZIDRWxlqtQinqkczLwfpIlFkdRzvYx0RLKCJJ
CXjYoa1gggwx00oOLSKqYy5cJxD20eJHtlWpLnmJalDqjaXATxDfUOm4s6AsEBorY61WoRT1
SOalu/GRKLM6YhZKSY4XzdksewHbVnITL7tid0mm+WyWibiWbpZJ5ruhGmTGYwViW4YqdmeU
u1kaY61WoRT1SObFiH0syqyOmMVFMh0q0kJHg1nOTOePFE0HhDjTQsNM8znWXkszf0ZUIPam
DIuMhifyK9WunfHUWhFHEZeyLv3C37YOq+NjcZESuaUPeaQ9EB6UFkQ3Ojraxwqqns53VF1S
kDqG4OfQBJ5ir6apvkBVSCijsRVQdR0M1ZclZYHQWBlrtUkpqEcyL93Bj0SZ1RGzCEiZ3PGy
0QvYrMqUFstGmabjZaO6tFg2qmsL1A7F3rgt5r6hitUZ5W6Uxtiq3QL1WObliH0kyqyOmAU7
Ei4Oluu8wrJWE6fQ149Egiw1zCSmn9cPUqEjGtDXD4F1GVA8XcOF6rzCK0+rdTPikazLzeq3
rcPq+Ex3XtBwKAt3BJidk8c9APlDNEftEpbOiQ0XHTFH4AW9Wr0bcRbkyx9ev51vN93j/3z9
9tvhcPP20Z++vFLBcGnMt8A+RZcHt3Jr/OzV5cXj3+PsObz6BnfHjv7zQ46kDXVL5purV9/r
rbIfSMKvDp9fhXR4/e79VTz8ixrfXHl3+N+rUA431z+9v/LpcPPj1aN4GK4elcNPP1w9Coev
X1+lA1Xlw83Vfw2v/uPy4uWr9Wvo2I+tzNBHjmx4N2aYDdzAlBh2mRdEBC/I4XAY6DrSuco7
viu8RuM2ZpqjriA4DJ8ROGQVoc5QgAfJjbXAjXquI9SJzCkGodyo98aavDRmxnQED5ld05QH
2BOiLCLxFMdGbK5FhRxQTQaJyz6YXKsomLJgtwZSLcman9OA282qYlWyRZIju8JykLFAxjAD
AUJoUy5QwwaiJ3+rVSOLrvHaNZmPSTRfkqxiaEX9yE5D5EKCmnnVhXRA8NbGgeBaq7Uhpcjf
SK4YCXLpY6eOeEX0C+YFG1eXjUyspi52h0yrXgCdFVO7QwnPnSVstSvhAU29myFwtkG47grp
ML1h3Eb8dRSJdEaWBQ8wJgEtNvPw50aG1q2DII4fiOV0yAyrF7DdAbV5s0mm3BYmC74IropF
s0zNrP1oDOaldXU5CGctB/H2clASjJCOzi3xYuAkxYQWg+GRQ0LBq+uvnjg3Zefai6dHE/zn
MI3EZcm28a0OjVEot/kSu2cx/XJWx/rRgp/auoLEyL/0uzGiSRnSJqeafr9f78HiSrmj+/Je
WsH5BKcNrXL+ZDdOtDvW7e4L+zGiqRk3TYJ8g/04IST1oUyikluaPsSMwmVD2DQJ6r9nT9f8
gONVLJ61iqWTVYx8rYbj1ZhoaT6d5uRwZ/pVXzjfnv/Cjjhh2shg3R1M23NHewVxLc77T4R7
3W9m0sGy5E3u+xpXZj+o4P5jhdeJca0OedrXj9UhpwN1O9X/8Prt191P/Zwc1C/gyH46rHqo
x2LmffdX5BPmuCHmyrp26jVbPManwNf75PCRawSPOXHqGvy9wssn0t7g75EnkQrf9dNIEgq8
QrKWgCsQL9V1rEB1fB2skOPrEW3MBUQ5D4bqOPjBlBNBARlS3FgYO04/ZJk8X5UxZRbZ0wGt
JGnMaXqojuxcUn/CfUUBnE7CZshj0wHlwJymyTg1yWiA506CeFwRFURhOtQgBTeWAi9Ov6KS
+uTtM2GoP1NO0AadRwMIkSL3q2+sgi8Mlai+2URaMb6NxITOaNaI1KKznScHWGmQD+JrUPKN
HEPkN3bmrVEvR5ONoIy0F5HboK5WL2CtDVV6xCj3DjO+0p2QqTbraogcg43EdVdKx+oNYxeX
bCiJeGjNhpkYx7q0glbHVMxGCHAumv10yMzLCsT6GDOYZTLhaWG44Iv7HLFryNRN/ngY7nGb
69nTenTU8UceXxi5RwIOSiu+cyUld/Oeb/HGUSHxYPm9/b8TPXFi3tDzbBf6lBkczrTJ7dxt
7Ta3GDnosNWPZVfVMk/TLdXO86VPuVXJ89rqyLMc6lNuSLcuW9zOdKpPudHpfZPZ3jYSXOQt
5IPMNSyD+a5+XHeuF+6ChZaxYtJEithWeJPidTJzAW9oHFJDHi1vkw1hiug4g4KzK2gzIbhK
7YSIJakjDohCcZQwWC/wnLbGmIF6K2ahO3GyaMuWtUFskQCM7EOvqbpKmCUOiOskaZxwmYXq
wt4CFn5sYfjYoDI29gqcREQhZDIidKMqNHZFsKEFliRJVmv0M8SZjNqYCzJ7N4KKTGJkDwhl
dE6UtmVEX022F5FI6MckKiQGJrux8Yiw+MU4oADkpBF8oMLpr0rCl4AdVsn74kHQWHsExpIJ
Bih5E7pDplMvYJUVVbtD6M6dpVy1L1miav3MAgcbhuuukg7UG8HmT0Z4HEHbNxtj8A1lYQJ8
/u4W4nPjTAIxng6ZbfUCoSyoapZMuS6MlhlPZtMQqpv78Sjc4ytMOx8BkPJVuLPJPfuAQTaP
7PjC45R2395uLchezGdFxX3DbEib5CVgndOux144sPWO7qt7KRVwSNxWascoW0hFVoGN7tsv
zBaKfIe1zmnPMFsolQ93H8Qkav5AUyogO3vTJh4WZkvn3R2eyJQir8spTpiDK9bzbC/tE6LB
eZPTjjMilTxOflunPa0n1YjASoqFF/17V5TTr1XtCjXg7nj7wzp8opECp8/JZ41WkHi7Cbkw
lCNDNeDwrhDnXZLXZjB25myICghZpPAJjKN9GwQNTkEzmgKApHDUShVG0Y5k3b6UT0efCeuX
uZrQKAUcU4lDLPzxZqCT5MQfOUBHBjiFzSFoxmCiAfKGJYDS5Cw6hpGCSiPGWJ4WGnJ4lKRC
nPXIDK1apRPMY1nv0G7+prRM/EWqgzOMnDKG4fKVPGTa0uHGsBOXsTYkg/iWlNcMLSiBr2UV
UyGli8ZagHz1OChqKBwrUsoK8VUn+FqtSCiIR+Leod/8zWvMSI4u5PK6sZE7xynSjb/vQ34G
ckHJ/y4nORX2KWnImVOskVtRfFCLv5PARm5FOi/YG9ZOcHDc68RJKcXfyq+At5doASV37/DF
errEsXzlV5Av8IfRq/J9dXj0AKHOC6WtCxXx5fuGTO+uQkRA/+/ff/d/VyEfbr5+QBw/tf2l
TIGvXTfEfHVVPMnqy+Hm5g8vP3uAiOedM9ZFnOK4YXxfHf5yuF+ofH660YpQdGzbEopvZn52
32W/v5iZFjS3OTP+cvUAqc5PzjiRqsQkK5pbCz/VcMtl4NrqOEAeQ8Rn1t+joMoH1/ydGPId
G20MIWCRr8j04a+tC5/Pq+ckRmwidCKv3suWUhFj6FBGRg831oKIgElH9WMUurIeNm9plnyW
bwiDVsmMwVme9gCT2PE3HteiQpGjfuYsHmrPqE7kd54h2mEBaSQrJEGd+ItzhNIqi1EKSxjK
DGW9M+gFVUVmzIaN3AgHpwlLVdjHwDE6Foi6MCWWvgSGRHrkVWXOS5rHAAVTs0bIS8oBhqY0
kDZcjHbJHByaWaMgNJOsJPlIgoXugKnUC1jjjsm9YYR7Zylb6UqWyHqZ5S02AtezRjJGqoCL
NoQgjcGX4YUQbTH4Jcngs2kASNGspkNmVL2Aba5jsj0yXb8wV2MrxswiJTP04zGYoz5nzsjM
nzRvzEg3hT0DwvheMG5O/13DRfhyMQd5P2HlJPTsxa63IYU8ypi2FNv5Vqngw+fNIdv1jFfI
09eVbLUXz4oanShWPcc+NhR7kX5psss6s1i2h2zvO56a4MlsjVg8Y8RWeOUgm8CHsMUq+Wdr
zCQa7Pu1cThvgq/wrg33ShuK5nDG0nV7HtQWx/yhFpM6YVvZNMwHhMryeRlpp2ElX/gETVsP
7eD3+20JmQ9DwMf/0b6iQBAj8jNDCfqhmvf4NHEKdaBDk2yu8PpxpxeDVEe+8Yr8AIdBoWlG
RS8oHMtTVDrapNIp02YquRrMGGp4/nRBhQpCWUQOTsNGgPEwReCLpjcomPhKLvC1DJCT0Hai
EW7nqH+SN061siCEDUEkLp5iB5o+IaIw6cciCx7p7r2QDdw1RpZb4RkS8hJYosT9WFh+3HJJ
NE68gwRve1qOQ2SvRBtBKfR6MRLEtaVOPUp208w8ek4lUtkICl1sAWadFBaFFU/7QsnOXaVc
tSch0NzLkZOmZAyuZ4VklFR+fHeiYxj5YzUbX4Lc0fCTsD526wgTUpTMcgzqhqUFaneKqjap
lGeTBePaLVqFUms/GoRf6LbdClzzs2xbs/E8n+0kcI0L/C1OezpseLcMF4u4cV+5+Hj2Yrdk
06RXmBta7Xi/lypb4ua6uW84fmKr2+q//S74snMy6da1Os9PO+YEh/COgdotDTwHPi18CE5Y
Gre30hNOq9v7ednHp7dz1SFzoiABczWt95bpRCQAR3z2gqRlfoOBU10brYKIOCRJlaTDeSan
F5e0lZwazoy8lgcbykTeG63VeBuhcWSGHAxuLBAyL+U2QgvwPoY8qwBUWoxpm1fKJHaRuEKU
xNiCNzfJs5c82IKHGiAUy1xokfEqRuB7Bbh0/LRmhI9eUdDw/l/i2x2iVUWjQufxSfdWcEaA
hR8KTPxQX8X25TuUSARvTVFAUvgwKCIRRQBLqFZQrdKWeVLHxQr1WJ6GJyALy08dRFDtL8gF
cgCoH+ZxQEHsjd7I5Rf5OEoDj9Eh0Vbo44VBBKs6e9w6yMBAOr2DUMEN6npZgahtqPqOIRPu
vaVspStZIm+9zAJXG4TrrpIO0xtBRkBJRhGkEQqREQ7yXOtsALhmjmYeeIivJTMdg7plWYEY
nmKKTSrd2WSZbTSLZpGyWfvxIOyxv4Mi9dTWdNxxf+f8qe2Jv+v+ztGzCSPr49p18YvdllgE
18getrTacX+PuHmt2wvnnvs73yrV7f7bb3+POeHSb0urHff3WNmf3h6p/WwCy9z2nNqTU+Nk
jwdzWt3gd/5uB9cuvH1yBHllg78Vv0DYD+m2uWId5OcqGucqZv6eHM9IIMKUOVsUj4Xj7oOs
JuhtB/IoYubX/AAg8I5QfesQouDV2k66ledBMVOSGwuhi4wKCY6DLbZNL49VNA5cJyePVYjE
BGW5Cpj48InGpALi+5Jrh4Ii2HWSXTWzQshiJVayDYE3cmbl2xpAyKclIacF1PqLG1IgtxGG
SuqT9EY5R71MMcZ4HH4wmTJ/Zc0iM5DtoIjoPG08i4HQcL000muLaeok8FxLM+oEINo+8yYJ
edxEtCxvGYvYBnWtekGRyxRBlQ4xyr2/jK92J2SauxoiJxuJ61kpGSvVAbm9OpREy019mLPj
O7nZCtLEibJiJHyf4s1+OmTmZQVifYYqlmmUu92CsTerZplCt/ijcdhjkwdFJD9vTEk37Xbc
LUU02eK0760LO9UYSbd6iN8to7A0tp4trXbc5Au5e6FsL55nRe+PA7+ujXmT0Y77bg1VZuAq
pz3TWSvtPHzU2ei8PT2kmvgxsU3j289DqrR04Bb31zc+Oonxtfqvv0xU8izDtk7n3d3curdJ
8GS3OO17cVN1Z//VF6Ta+Mvi7Tl138dOudyZVFgDf5iEr3sRLvf8Mr2P/K68pRXe22gjdTCf
nwV3y5YCh/zxq5wkH/3ph/mZpdf//eZmuHrU+Lv2P7z8N/o7HW5eX//1AVlx+fysuFtzjYMY
IXF25m2pb97iG/zrq3h4hz/+9cNVPrz/jn78/e1j/jz/5vodnpBaVjxEifPy5k7ecaipwpdC
GDieKIF3HCZ+NcInfUECbzk8y/SbePmXzk/u6aNI093Fp4/KE33v4eVTKvLPvRRnJVOeu5if
oSqW5/cfasrOb3+1xvn7q5ri/ypFPg9SU3/82/2DUM5LwDt9TAMvP20MwvIjKeo+7tL7BTwv
F++k7yZXR/5qfc1KDj+OSF58Pz6g4867aD6dguSv46myiZ+GP5mCNKn+Qf9kKg7ffvePq2LA
A2Td+c2OFh0/hrkm68+1v/PO+6f2h/ci6kY3stk9nSp+56cy1/ktl0fhydEaQL/x5ouUZ/c0
PTlZIu7X7Pyk71v+JH/k6Ss/v/ygNZpf87MHVHw8/PSWX/q7Qck73m9++Nvwjlt9/xqF3xH+
Q5busvOu2fB2dOQv63M6nZQ3s25ILWbVTmX8f4fdSFwNCmVuZHN0cmVhbQ0KZW5kb2JqDQo2
NiAwIG9iag0KPDwvVHlwZS9QYWdlL1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3Rh
dGU8PC9HUzUgNSAwIFIvR1M4IDggMCBSPj4vRm9udDw8L0YyIDkgMCBSL0Y2IDQxIDAgUi9G
NCAxOCAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4v
TWVkaWFCb3hbIDAgMCA5NjAgNTQwXSAvQ29udGVudHMgNjcgMCBSL0dyb3VwPDwvVHlwZS9H
cm91cC9TL1RyYW5zcGFyZW5jeS9DUy9EZXZpY2VSR0I+Pi9UYWJzL1MvU3RydWN0UGFyZW50
cyAyMD4+DQplbmRvYmoNCjY3IDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3Ro
IDIzNDg+Pg0Kc3RyZWFtDQp4nN1aS28cNxK+DzD/gcfuAKL4fgSGAFuWgzwMbGIFe1jvYSKP
bGGtkSMp8WZ//VaRRTbb0zNSNHPxwLCkYvEjv2JVF4vNPn5+e391ubi4Zy9en7Lf5zPBBBdC
SKWEZ9EJZo1gt8v57J/fsNV8dvzdG8ve381nkr2vnYWTQttR78tv5rOf5zN2BqOy43+wZ8+O
X59+/5KJkxP24uUp0+xzGiykwQRXzsNYxuBP7yL75bv5bKak4tEwqRxXil3PZ8rkhui4UOzj
fPZmYgpJU8yUJ7jmfoTW3G4CqwLW1gKpZm4dcsPWuXWBG0lwmruit8xtCtgZgXMMczufG7bO
bQvcC4LT3BW9ZW5XiUfPbRjAVmV5G9gXsLUElly4EVrw4DbBQ3XYyL24ahAAJjIV1Ra7Y3UZ
rrEcwS137gG4FJV9Iau4DIk9rIXUTIWADZvwNd6cizz6Bu/AEUY9hB9CThouC1uAGws4ZmTY
xr5GnI0R2StYakVwiw1GpijahC9Bl55nYxy3KkOSBaUBHKosM1ZwC7+URXUaXxXpAjo7gd4q
amdaKEl55NSZGiTXYCRBhW9HzhJ2polJXVhm6IgzdP6Qs4/g0WGSEbD2BrKKhkWAUZzMueVQ
TJ10akkFWjiu8QGQPD2OVYZxPNMSViVCJwFafFZAlQUYWitQ6qJUpsUVSZauWQ6OO0BkoApq
GDUL2DVPSUpiQ7iW6+DG2Vduw6R/Sra1kBmUyY98zjilwXNhmYV2BVyFRDVmI9CRdIHpRWG+
owYHcw/QKqnaOTcESGmSEVQF3YxM0gUmvjRxUROpDB1zbhx1KMZMeqxscUqnOJHRcpOMpAaF
qd6COqTYEAbVyuisS9IFViAhxRWprWqhWaKRsXNpgIQA1mWohEAbRiYJO+eJi7qwzNAR58Zj
h2LMpMdKVaG95VIlgM9VQW5AplBoah+5tMkKUOtgsi5J+LCHyEWsaqiCGmiWaGTsXBqghrWM
oGjFMDJJ2DlPXNSFZYaOOLfJ8ECMmfRYKeQsVDze5ToqGVkbPHKwSnGPVkhUY9HmXZHwcdeg
1lWtXQstkqqdcwNmA0hRGSqDbkYmCTvniYuaSBF0xLnNigdizORhqZTODmoa34YlNVBsOSiA
fA1LLJN9G5bOG+xV1D600CwNwVMbUmwRlOKORh7CkiauatFCR5wbjx2KMZMeK4eV9RP3LdT/
wDqf/PJpO0khmwOHEAgmjCkwR9Y/MVtLn449pFOqgpQqo2E3lDCwYO0IIU0dTZb1KzORDikQ
aODWbmFfE+NJj5Tjn3Jw+M3Tx1To1obAI6QA53i0iTOolZdJlyUk4R0PsaqDaKFF0qUzNQDN
CEYTFPg3I2cJO9PEpCZSBB1xbt1yIMZMeqwcubWBbInveAzicDMuDRE5aAtJG63QqNbWJV2W
cMt0kqeozGpnW2iRTO2cG2RE+gUKB5Nm5CxhZ5qY1ESKoCPObWVxIMZMeqy85DAi5cchLGtD
ii0jYsqwOe5MfqCHsDQwq6thafKTXaBFKsFTGnJsFWiOuzJyDcsyMamJFEFHnBuPHYoxkx4r
bzAsnBRMY2ORE08Lhwqjiw348tE0Flp4nrWvWnjyByAJunZNcuZYcJk/jVqtK3OSNtMhYMu1
LQG/bhsm/VPeYDidekplOex2WCxRgxZcwNFcexxVwqEN1M6orEsSljTwAEdd1fCoN1CS8sjY
uTSA2rMCla4dOUvYmSYmdWGZoSPObeV3IMZMeqy8wXBRjNNGbUhh5aJp0oaLcZw2vDBN2vAi
NNAq6do5NM9+geaoKyPXoCwTF7VooGPOrccOxJhJj5U3GAZf6bd5nuScq2EmVfOHASKthRZo
yiF/gAkVWISaP7JMaYBwlMPzqEOGpzmLVgzAEdd2s/q6bZj0T6xnKW3xFOVEgJ9B23SWsvnI
Dlsl5FMroDvWKuVuFGawNp2/NCKhZ7qV2AwaGLz5tFgNF47i+KfF6j3rlqujX9/0xAjvcdPF
rDRawDQTF7kvzuez41d4vmTnl3idK+AfJKrALdRS8EtZx86v6aJXMmD3r+6n5aKXovuzt93y
rj/S3bes/zc7/2E+Oztv73vHFOV+KeK1KKzaBorfr/oj1V31urv/sVeqWwLXv3rX3U0SbW5u
yznMYP0a83tJw7ViECh2cNxsi36Tj/R+F8BDwMCMEDrcqbUFeP7uHXomrcAVGH+zWnz82Jvu
L9YfSd19vr2C1bjvJbgQWkJ25m2vRHd3dbN6jD/Nfs2BmNcaS9B07/mlOas/0J/Xvy37I9Pd
Mvx5c8n+02udXcvegmvBrmTR4va+z6av3uMikMm4DPcfQHAdF4+x0O7ZQs+DxFI4XQd/aeFi
9Y64ukz94raXvlteJ5NXyB0NqBa5bgEevLxHq5e3qQFXgvx4hGvyCBPdnh9KvLcxTPvAw7qJ
YJCjICNrb66v/tfLkEyhMH3bP/SI1kuYkG7kME/jmRCyNt654fz1Kd3eZdODGnZeFAhhM1oY
PNBCWOP24+Tawpz9F3PU4vrTxyX7nELXpEh92H9x/1TxewO3keovmPnPeyfJm8sfz14/zNPs
eX+S3uLXDFgMIPtr/AYpfYiUOMKgj6C05/0ILxZ3paT2S0njdwm57lXxiZT2vGnhpxJS7kZp
zxuPgW2cVgnqiadR2vtOIfGueidKe87sTupKKTyRkt9zAQSU0uvHv0Wp+dCunKzo/gXK93wR
IPG7Gp9uBepO8kCfDVuJ2T0/f1GXp7M/vluLfn0b+XRzAbvHh1TQjSsm3F/uoD12b7vFHftt
eYm78E3O4W/7bx/2nt0thbsNpugQ8BXVF6Y8EyL4k4c57ZbDzXpJjQXCJko6vIJBtYBT54l0
z4T0L4UMp9h2cmRAFq+EdPBfKNA5+Ps098e/sa98Dv/Pct8oHmHebvvBxiV3jnvz1CXf+ykm
LfkkpU6wS6wOb3LBv7p5l4IZ41gN5fzDlPe8YQRIOHIT5b938Bzz3G0XWYtmpUT6FFTAyXRt
F0nh/Ah377aNrHHSUFUaoCY8/noip932kTVOJkTcZndbp93ODGucXJDcuB3XabfNZz2eoufO
Mi30RFXySE5ut11kfZ1gJ9QhcRL+qZz2vIsY7fGzNix1g3ssp/8D75W6LQ0KZW5kc3RyZWFt
DQplbmRvYmoNCjY4IDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291cmNl
czw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAwIFIv
RjQgMTggMCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUldID4+
L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDY5IDAgUi9Hcm91cDw8L1R5cGUv
R3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVu
dHMgMjE+Pg0KZW5kb2JqDQo2OSAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0
aCAxOTQwPj4NCnN0cmVhbQ0KeJzdWktvHDcMvi+w/0HH3QKR9X4AQYAmTYM+AqSJix6KHgzX
SQo0Qeq6aPvvS4qkRhPPblzvXrIIsA5FfeJHkUNJozn78vrmt9cXlzfq8fMn6o/1yiijjTHW
OZNVTUbFYNT11Xr10xfq/Xp19uxVVG/+XK+setM7m2SNj7Per79Yr35Yr9RTGFWdvVAPH549
f/LNV8o8eqQef/VEefV3G6y0wYx2KcNYIeBvTlW9fLZerZx1ugZlXdLOqXfrlQvUUJM2Tv2+
Xr1aMGHZxMplhnudZ2iv4y6wE7CPEUgNtn2hhr22vcCDZTjb7ug9toOAUzBoY7KdMjXstR0F
ng3D2XZH77GdOvGadSwTODqS94GzgGNksNUmzdBGl7QLXnrAZuHFWYMECFW56vb4XXvIcI7t
DB51Sp+AW9PZC1mnbWnsYS6sV64UbNiF7/mWUtU1D/gEgQjuU/gp5WzQVtgCPETAqWDLPvY9
42KtyN7BVDuGR2wItmXRLrwkndG1BPgtteCvr+oaHvAQko6OxmguSQNE2EUVotER/riI6mbQ
iXQJnZPB8Ik6hRHKEo3cOnOD1R68ZqjJ48gkYWc2zGphSdAZZ+j8lsoReJiw6hgIBnrqYVZg
lGSp2JyKq4tRjlOUXVXNHkxDdS3I3iTt8TGxuj20XYbBs/IWpqoqD7mcFD5RoCIB7HkHSi9K
F0acSFa6klySToAgoCtuGpUE7EomWclsGDdynWL7ufuwGDSpyW2pjVBEXKDqQMVJGrI2UUVo
d0DYWFRj4QIdS5dYiRyWRm5IQGCCdsn1ztRQoPpZxVBX/DAyS5dYI5thUTMpgs45D9E6FWcW
w5b3PWvOtwyyNerQPOcGh0tFVM6XljUmoNoFT7omXeIOprSMY3V0I5QkHhk7SwPUD3CZoBZS
cBqZJexMhkUtLAk64zyE8VScWQxjGZ8+n6O2rqEybS2oAenCbtXnqm1sroDal0C6JmEtKFWb
2tWwlRqgJPHI2FkaYCMcFUPRlWlklrAzGRa1sCTojPNYK0/EmcWwyW4wwrYpJ9qMNSd7Q0YO
0Tmd0QuLatz55SQSFgIPat/VPo1QkVzvTA1YJ6B4EdQWP4zMEnYmw6JmUgydcR7r5Yk4s3ji
kv13gn1QHtOSGzi3Emyack9L3GvnMS1TDthL1LmMUJKm5OkNLbcYynnHI09pyYa72ozQGech
YqfizGLE7N4VzvCRm07sTSrkDRxkIJcwpcAb2/+LFdvmdnRinXMd5JyMht1QwryCqWOEDX00
K9MnlliHFBg0cRuXsc+J8WJAXA/Ix+9RWkQSHKuJVG2b495QdIW6kJKusXkCapdt05GE1HKC
Q2FXFzNCRfLSmRuAfIWpYCh4NYxMEnZmw6xmUgydcR6DdSLOLMZRDvM+QAnFt0cBcbhCS0NF
Dj5CJUcvPKp9TE1HEq6jyeqWq6ROcYSKFHpnarAV6QsUDjPDyCRhZzbMaibF0BnncbtxIs4s
RkxenwTTiuaUlr2h5VYwtZVdyrtAj/mUlgGspp6WgZ53gYokySMNlFsCpbyTkXtaimFWMymG
zjgPETsVZxYjJq9CIpwhwuCjyI1nhONG8OIDvtYMg4cRnmefuxae/AnIgu9dm0wcBUf8edTu
ndhkLdFh4Mh13Bd+3j4sxkfeeiTfeloXNayBuIPiBm+0gZO8zziqheMcqFNwpGsS7nPgAa6+
q+FRH6As0cjYWRpAnZVAbRpHJgk7s2FWC0uCzjiP28ETcWYxYvLCI1UzLxu9oaVVqmEoG6nW
ednIJgxlI5syQLvke+cyPPsCpayTkXtSimFRmwE65zxG7EScWYyYvNsIeFkw1nmWqVaDJdfr
RwAio4cRaNqpfoALHShCrx8kcxlgHNdwGnWq8GxTtGYCzriOi9Xn7cMUn1cfLt5PIapn31+8
f6M2V+8f/Phqy/HC+9l24WqDN1GZhQvax+fr1dnXeORT56/xmtbAPwvniIi3QHiiTFGdv8O7
23aB+2y9+nljtdn+os6/Xa+eno/3tjNK3hxEKXxMycO8BWSW8c9HlB4aX75+9GlO9ricQqm4
fuE0RX9fTu64nFKxOqQD58kfOZ2Kx3TyxuPd1P3SKRx5mmBz6EujBIvXPacpHnea5AIQltBa
7jxNw+cEqR/sfcQjfTJ0OxvpYF/anRNWFTzBQI3BWyVcreUTDCg3EB98IeARbR1/WLEXuKMk
+Xzw5GjjwrwGxHZXjyU0UW631+2WJujpP1vnNhfvPvx+pf7e+s1v27C5eavukFvl+FTxNj7t
pPpya83mfJvs5npr0+bq6runz+/A88hV3uZW5XFBQ/b3eSzDYVV+V6XYQcloewdKhxX5W5Q8
XtLT3s3Ve1I6rMYvFIqId4wHUTpyiQ+pyiyFW0vhHSkdVuJvUYrZ4vXsQZSOXOGT9Z3S7Qp/
N0rpuJQyUGqv0P4XpeEztL0X2CFp79rezeGXWrA1ubXkpOLagoVLjnX8Ld9e3I4VJxxexuf5
EyBv6NuaUm6V8BdbFzYX1zew0PwLna+wosMCBMX88q+brQ2bqz+3D/xGbR+kzV8ftg/c5tcL
XJC2Nm6uFub0P8Fr/GYNCmVuZHN0cmVhbQ0KZW5kb2JqDQo3MCAwIG9iag0KPDwvVHlwZS9Q
YWdlL1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIvR1M4
IDggMCBSPj4vRm9udDw8L0YyIDkgMCBSL0Y0IDE4IDAgUj4+L1Byb2NTZXRbL1BERi9UZXh0
L0ltYWdlQi9JbWFnZUMvSW1hZ2VJXSA+Pi9NZWRpYUJveFsgMCAwIDk2MCA1NDBdIC9Db250
ZW50cyA3MSAwIFIvR3JvdXA8PC9UeXBlL0dyb3VwL1MvVHJhbnNwYXJlbmN5L0NTL0Rldmlj
ZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQYXJlbnRzIDIyPj4NCmVuZG9iag0KNzEgMCBvYmoNCjw8
L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMTk0Nz4+DQpzdHJlYW0NCnic3VpJb1w3DL4P
4P+g40yAyCK1A0GAZiu6BEhjFz0UPRjuZAGSIHVStP33JSVKTy9+Hrv29JC5jE1RH/VRpPj4
luNvLj6/fXV2/lk9ev5Y/XG0MspoYwwgmqhyMMo7oy62R6tf7qkPR6vjb0+8ev3paAXqdZ9s
AhjrZ7Nf3Tta/XS0Uk/Jqjp+oR48OH7++Lsnyjx8qB49eUw4ZzP9hpjoF+n3guw5r11Szhud
g4IMGpPCrI3rNovmr8IjFR5GW3BsLvMvkPblt0erayyddGYnH88+dHJw/OPZh9dqvf1w/+eT
jTDlPSlOgrPGK7OwKY9OidAzVJDU6SveGtoXBcpbYhWIRNaeNO9l00ARwV/XLzbo1mcXnzd2
/Y/yarsBs/57g2G9Pf/z8wbcevtpc9+u1eZ+WP/5cXMf17+fbdyaVH693fymTr8/Wj09Xd5l
FO6Wt4q2N0TeIce/MeS6Qwioac8Ag0ZURA5dHchBG1Tvxl2aLFuxvMIocKvjDG21vwrsGth6
T6SGtW2qAzvX9g3uQOCydkfvWDs0cHCG15jWDrEO7Fw7Nng0Ape1O3rH2qkTz5FToYM9VnkX
ODew9wIGbcIMbXQKV8HB9IjN4svbRhngMh0L3OE4QA8a7zLM8F6HcB0eO/9GFzUdFOZPuwFW
YUo8cBW+Z1wIWec44AOFwuF1+CnpwGlobN9zsSGccpB2se8553M5xUibjQL3POCg5NFV+NDr
XaIYUTVywP97qPXOBe2x2igutQGKMfpSvjz9Qc/qsiA26ZwmBy57XR3cCBWpWi6TZQCoYKoG
NXG0XCWeLAuLurGs0BlnmvxmXpmpCCcuxZZ2hawEkIJ8IK4uRjn2KGfM5WJUrkVYgmxN0JaP
CehybLtMxqOyQFuVlaVcDopPFKmqQOtZJKVtSnQjrknQplY5BR0IUYGYcLJaBZ5alxSlsBHc
yHWK7dfuw2LQ0s5WxFNVQVfLRa1WbSBqagM8jSN5YIDVXMlIJ9I5lybkWikDgRhN0C5hn1wH
EpVDUALFZAfLIp1z0SwLN7WQqtA55yF8h+LMYhzzrsOHtqQU5NIPvu8DyNcOr9CmkkbGsRqd
rboinXNTk0oKitrjCK2SWObJbYAKCrlcoUA5OVkWiSfXhZu6sazQGechjIfizFIYsfUppUe2
0WvAgoq116gDTJcaWBuzBl9cIbVNruqKxMUhUaefu5q6qwFaJbHMk9sA9cZeCZRdmSyLxJPr
wk3dWFbojPNYPA/EmcWwwe4qSt1VDLVnK673gcjMPKKO7BuwmhvEGJrE5cGS2na1DSO0Sdgn
1wGuHlTSKhSSHSyLxJPrwk0tpAQ64zxW0QNxZjGOOB6/QD1THDNWBiTtAjVYsWcs9+VxzNgQ
Hc9q6phGaJWmvOoDJe0EKikplqeMlYW72ozQGechbIfizGLY7M6Ln5Eb9Hp/X6RUvaGbHkoo
zivyBvq/XMwhltss0SF2EGKzxtNY4uSirRMEuG4N2va1lUTHFAQ0cRuvcF8T48WAuB6QL5+6
lIgEugevpHJppPtA0pmKQwg6++IJqTFC0VWJqcWgU+7qZEZok2ybLANEPtNWCJS8GixXiSfL
wqIWUgKdcR6DdSDOLMax3fhbR3WUnzU5xvHFuw1k5mA9lXP2wrLa+lB0VeJLbABdcrWqgx+h
TXJ9ch2AzPQblG58BstV4smysKiFlEBnnMdO5ECcWYxYe9TiTCmaU1r2gZJbzuRSdmveuXrM
p7R0tGroaenqeW/QJrXkaQM1txq05l2z3NOyLSxqISXQGechYofizGLE2mMTT7cXbvCxyYWn
pzsRZ5sP/BDUDR56Os82di2d/Akogu1Ti1w5NlzlL1a7d21N0VY6Ahy5js3h1+3DYnzaE5Jg
y0xAzy9QuIOSAWu0oZt8G9kq0J0eqYPDqisS9zl0gLPtajrqA1SkapkntwFSR9WgEEbLVeLJ
srCoG8sKnXEe28EDcWYxYu1ZSMhmXjb6QEmrkN1QNkLO87IRjRvKRjRpgHbJ9slpOPsNWrOu
We5J2RZuajNA55zHiB2IM0sRs9e8EOXXDWP1F7lWcFofe1VxRG/02xN5mKoKOdaBTehVpcpS
HAQnlb1aneq+rNm0ZgLOuI6XsK/bh5Pld8V2zy+LkS6aWG88gy8vi019w15eFoM2i69855Tw
TpTcl5Qs7ZtjZpH/fEHpgbHp2cPrOdn9bpPLUB+rLG4T3mib3H63KSTQLtxxm/yesylZziZr
LL/cupxNcINtCvulFPgNW6VErf7tIhf3nEzyApEuqzndklLaLyWIpQxwxUN3yzKQ/5dcuoKS
uUkuObNfSpbfA9dLPl7OpZtR2nP95iQCuBulu9Xvy5RCbrtENwK3Sm+35/LtI/ALvyso0bX3
BpTuVr4v1yWwndLlInAzSnuu3pEolScv/4nS8J3V9NWJ9fz4MRhuKpP19SFkKu/Sudfhpy3U
+YRLX9khXTb44aVlNKB8MrYTeEWj5O5etLXhwjOef1++QeLGLsClL+ue/r1BXJ+9//huq/7a
2PVb/mzujbpBHO9ezC9R5a+MwpVUX/JXf6ebAOuLDYT1dvvD0+cLPP8FWUMKmA0KZW5kc3Ry
ZWFtDQplbmRvYmoNCjcyIDAgb2JqDQo8PC9UeXBlL1BhZ2UvUGFyZW50IDIgMCBSL1Jlc291
cmNlczw8L0V4dEdTdGF0ZTw8L0dTNSA1IDAgUi9HUzggOCAwIFI+Pi9Gb250PDwvRjIgOSAw
IFIvRjQgMTggMCBSPj4vUHJvY1NldFsvUERGL1RleHQvSW1hZ2VCL0ltYWdlQy9JbWFnZUld
ID4+L01lZGlhQm94WyAwIDAgOTYwIDU0MF0gL0NvbnRlbnRzIDczIDAgUi9Hcm91cDw8L1R5
cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBh
cmVudHMgMjM+Pg0KZW5kb2JqDQo3MyAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xl
bmd0aCAyMDk2Pj4NCnN0cmVhbQ0KeJzdWk1vHDcSvQ+g/8BjdwBRZPE7MLyIHSfIbgwkloIc
gj0I8sg2EMmOLMPZf79VZJHNlnpGA2ty8FxGKhYf6xWrWCS7++S7m9t3l+cXt+LZy+fir6OV
EkoqpTSACiJ5JZxV4mZ9tPr9G3F9tDr58dSJNx+PVlq8aZ2V18q4We/Lb45Wvx6txAscVZz8
Ip48OXn5/KfvhXr6VDz7/rnQiAzOCOyN41gnbRTWKZm80ElLiAKSVLaNlTWfs/2Y7SPcBBzE
2YSDvPrxaPXAKKeNzemH8+tGSJ/8fH79Rgzr6+PfTkdmR/OQHdPWKIfj35+IZ2dI5gcQOoqz
S5oOnAv0yhlp0bp1STrUXPFEaYEE/xh+GcEO5ze3oxn+J4JYj1oNf4/gh/XFp9tR22H9cTw2
gxiP/fDpw3gMw+vz0Q6ocsN6/K84+/fR6sXZ8swCczc0TUqCp9mxln6DT2WGQINMVmjwEkAg
ObClIXmpQPzZz9I0suGRVxAYbmSYoY10m8C2go1zSKqzbWJp2GrbVbjVDGfbDb3Ftq9gbxXZ
mGz7UBq22g4VHhTD2XZDb7EdG/EUKBUa2EGRt4FTBTvHYC2Vn6GVjH4TXKsWsVl8adowA3DF
QIItjmvdgkazrGd4J71/CA+Nf6ULEhcK8cfZ0EZAjNSwCd8yzvskU+jwHkNh4SH8lHTaSl3Z
XlGhQZywOm5j33LOpbyKAScbGO6oweqcR5vwvqtxicqTjKXKWS8dFHR2pjZgdMHlwuXwDzhS
Z1NQpQvs7BVFrqq97aEslZFzZ27Q0qC/DFWhH7lI1JkNs7qyLNAZZ+z8dl6PFYbBoocG5wNH
8ZpL8YG4uhjfWhdwDoCim0OMKZqDbJSXhhaIlnnBNhkHD8JonKokDGaxF7SWUFUEtGcAlaYq
wfa4KunatcjRS4+IAoQI06hFoK7FJCuZDeN6rlNsv3YfFoMWFw8eDusI2FIgSn2qDUHixu+w
HZC50qSm2oU6li6oGAFVR27wyGSCNgla59IQsQBqwVCIphuZpQsqk9lwVTOpAp1z7sJ2KM4s
xi9tW3RgcirplE+AV60BaLdwAkzM6aMsqcGaosvSBR1jYk49VjvooUXikalzbcBCgi4XqMZc
nEZmiToXw1VdWRbojHMXxkNxZimMMJ3/qVYGJzVkVCini9JAdPHIakKS2mVXUG2iLbosUVGI
eLZPTY3nqQ5aJB6ZOtcGWv2CoeTKNDJL1LkYrurKskBnnPuieSDOLIZNt9VnDS08HyL+QigH
G4fnqeDLKS273hoCMXMAMpBvmtR0JAy+SlQeDKpNUxvfQ6sErXNpoOqBJa1AdTTdyCxR52K4
qpkUQ2ec+yp6IM4sxhEWd0GPh6bQpy43cP55PGGFlrp0JA996vpgqVdVh9hDizQlWGvI+cdQ
zk0eeUpdNtzUqofOOHfxOxRnFuNntu6Ciu/m5WqfpVi8wfsOZhYlGHqj279U1XXINyzWATQQ
QB2NupFEWYZTxwht22i6Tl+1xDqiwKCJW7/VfU2MFwNiW0DuPnDJEfF4/S6kUj5Jt4YoE1YJ
72Vy2RNUQ9BZVySiFryMqamj6qFVMrUzNyD5hFPBUPSqG7lI1JkNs5pJMXTGuQ/WgTizGMd6
5zcWCyo9ZrKEo128NiTiYBzWdfLCkNo4n3VFor3Wa5lztai966FVsq1zadCJ6Fco3ny6kYtE
ndkwq5kUQ2ec+yPJgTizGLH6lMWqXDSntGwNObesSrnslryzZZlPaWnRqm9pact6r9Aq1eSp
DSW3KrTkXR25pWU1zGomxdAZ5y5ih+LMYsTqcxOH9wzb+VjlzNPhlcSa6gM9/7Sdhw7XswlN
iyt/ArJgWtcsF44VV/jzqM27apO1hQ4De679KfHr9mExPsuPSLzJOA2O3qRcTQ1GSYV3fxPI
hsYLIKq9haLLEp16cDkn09S48DsoS2Vk6lwbUB1EhWrfj1wk6syGWV1ZFuiMc384PBBnFuOX
tp5FfFLz0tIacur5ZLvS4lOal5agbFdagoodtEmmdY5dfajQkpl15Ja41XBVqw4659zH8UCc
WYqjUVsv25beRvQ7BMulyqN9aJXHIr3eb4fk9VR50LEGrEKrPEXmAsI4rv5l1GlvYJtVqybg
jGu/zX3dPpwuv0o2e36XDLixQrmcepffJavy0j2/S9ZSLb4RnlOCR1GydykZnDdLzAL9uUPp
iTLxh6cPczL7nSabdHkGszhNIPUO02T3S8mHlJ944zThPnqXktkpcm7PyRQNJZNRhl6A3U8m
2IGS3/Ms0Vu4QglvA182S2HPucQvGXGvTfELKcX9UtIhVwEqeGC/sAqkfySXNlBSu6w4q/ZL
ydC74rLjw/1c2o3Snss3JZHWj6P0uPJ9n5JPdZbs/boEu+SS3XP1dkFTqdxASe1Sl+y+q7c2
jdIXFgG75+odkFJ+OLNISUnzwMdh1rczpXF0K/CKzpTROL7jOdpCTbB4UQSb6F2eQ3Xsvr8D
3DboTmEIraF857EduOGcZPdctL1z9BLE4gEg3v/m7tdPa/qm7uOo9XD7bnTD++tvxXiszfAT
f2y38K0ddojDxwy8GM1wM2o/rBF7K95fih3Cv+c9wOMiiQa3FkPfvN31cP2BeL4nom8zcZM/
ILwcdRze35DuMzl1fkO/rze69q+HcqjeLyHmrzPoYEyP7/CY7O98rbna3mVDXrjH7wlS0YbU
7wsuf7lG532v783ci79HgOH86sOfa/EZJ+MdJcDbHQLsHr9X3KNK36b5jVRf0beiZ6PXHLH1
f168XOD5f1Jdf98NCmVuZHN0cmVhbQ0KZW5kb2JqDQo3NCAwIG9iag0KPDwvVHlwZS9QYWdl
L1BhcmVudCAyIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzUgNSAwIFIvR1M4IDgg
MCBSPj4vRm9udDw8L0YyIDkgMCBSL0Y0IDE4IDAgUj4+L1hPYmplY3Q8PC9JbWFnZTc2IDc2
IDAgUj4+L1Byb2NTZXRbL1BERi9UZXh0L0ltYWdlQi9JbWFnZUMvSW1hZ2VJXSA+Pi9NZWRp
YUJveFsgMCAwIDk2MCA1NDBdIC9Db250ZW50cyA3NSAwIFIvR3JvdXA8PC9UeXBlL0dyb3Vw
L1MvVHJhbnNwYXJlbmN5L0NTL0RldmljZVJHQj4+L1RhYnMvUy9TdHJ1Y3RQYXJlbnRzIDI0
Pj4NCmVuZG9iag0KNzUgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMjM0
Mj4+DQpzdHJlYW0NCnic3VtLbxy5Eb4L0H/g3roXK4osvgHDQPzYxSYxsFkpCYJsDsrsyBZi
zSiSjF3/+1Tx1WxNzwNW5+C5jFwsfuRXrGIV2d0+/8P948311eKRvXr3mv339EQwwYUQEkA4
FqxgRgt2vzw9+fu3bHV6cv7DhWHvH05PJHtfOwsrhTKj3tffnp785fSEvcVR2flP7MWL83ev
f3zDxMuX7NWb10wi0hnFsDeOow3XnmkjeLBMBsnBMwhc6DpW1PwW5/dxfoQrh4MYHXCQn384
PdkzykVlc3F3taqE5Pmfr1bvWbdcnf31os/saB2iYVIrYXD8zYV4dYlkvgcmPbu8puXAtUCr
jOIaZ9cmcIOa27xQkiHBf3Y/9aC7q/vHXnWfmWPLXoru9x5st1x8euyl7pYP/ZnqWH9mu093
/Rl0v171ukOV6Zb9v9jlH09P3l5Oryxk7oqWSXCwtDpa06+zIa0QSOBBMwmWAzAkBzo1BMsF
sI/tKg0jqzzyCbgMV9yN0IqbbWBdwMoYJNXMrXxq2Dm3KXAtMzzPXdE75rYFbLWgOYa5rUsN
O+d2Be5Ehue5K3rH3L4SD45CoYINJHkXOBSwMRksubAjtODeboNLUT028i8tG0YA7hgIsMNw
KavTaJXlCG+4tfvwUPkXusBxoxB/XA2pGHhPDdvwNeKsDTy4Bm/RFRr24Yegk5rLwvaWEg3i
mJZ+F/sacybEXQy42JDhhhq0jHG0DW+bHBcoPXGfspy23EBCR2NKA3oXTExcBv+AIXWcCoq0
wM5WkOeK2uoWmqU0cuycGyRXaG+GCteOnCTqnCfO6sIyQUecsfOHcT4W6AaNFipcDxzFypyK
j8TUSf+WvIBrAOTd6GIM0ehkJSxXtEEkjxu2yji4Y0riUgWmMIoto72EqiTgfApQqYoSdIsr
kixdk+wtt4hIQPAwjJoE6pqmzMrMJuNaroNvv3YbJp3mJw8eBvMI6JQgUn4qDY5j4TfYDshc
SFJT7kJdlhaUjICyY26wyGSAVglq59TgMQFKlqHgVTNylhaUJuPERZ1JJeiYc+O2YzFm0n9h
16YDFUNJhngCvK0NQNXCMFA+ho/QpAatki5KCzrG+Bh6WW2ghSYpj0ydSwMmEjQ5QSXG4jBy
lqhzmrioC8sEHXFu3Hgsxky5EYbzP+VKZ7iEiHLpdJEaiC4eWZULXJpoCqqV10kXJUoKHs/2
oarxPNVAk5RHps6lgXY/y1AyZRg5S9Q5TVzUhWWCjji3SfNIjJl0m6y7TyvaeNZ5/AWXDjYG
z1POplNaNL02OGJmALgj2ySp6UjobJEoPShUq6pWtoUWCWrn1EDZA1NagkqvmpGzRJ3TxEWd
SWXoiHObRY/EmEk/wmQVtHhocm3o5oYcfxZPWK6GLh3JXRu61mnqVdTOt9AkDQFWG2L8ZWiO
zTzyELp54qoWLXTEufHfsRgz6T+1swqKfDdPV/so+WQN3ncwsijA0BpZ/0lZXbp4w8o6gAoC
KKNRN5IoynDpMkLqOposy1dmyjqikEEDt7bUfU2MJx2iq0OePnCJHrF4/U6kQjxJ1wbPA2YJ
a3kw0RJUg5NRlySi5iz3oaq9aKFFUqVzbkDyAZciQ9GqZuQkUec8cVZnUhk64tw660iMmfRj
ufMrjQmVHjNpwlEVLw2BOCiDeZ2sUKRWxkZdkqjWWsljrCa1NS20SLp2Tg0yEP0CxZtPM3KS
qHOeOKszqQwdcW6PJEdizKTHylMWLWLSHMKyNsTY0iLEtJviTqdtPoSlxlltDUud9nuBFqkE
T2lIsVWgKe7KyDUsy8RZnUll6Ihz47FjMWbSY+W5icF7hm5sLHLkafBKolWxgZ5/6sZCg/tZ
uarFnT8As6Bq1ygnjgWX+OdRq3VlzqxNdDKw5dqeEr9uGyb9M/2IxKqIk2DoTcrt0KAEF3j3
V47mkHgBRLXVkHRRolMPbuegqho3fgPNUhqZOpcGVDtWoNK2IyeJOueJs7qwTNAR5/ZweCTG
TPov7DyL2CDGqaU2xNCzQTepxYYwTi1O6Ca1OOEbaJVU7eyb/FCgKTLLyDVwy8RFLRromHPr
xyMxZsqPSuy8bGt6G9FWiCynLI/zQ808Gum1dhskL4fMg4ZVYBFq5klyTiAZl7N/GnWoDXnO
ohUDcMS1LXNftw0X06+S1czvkgELK6TLqTXxXbJIL93ju2TJxeQb4TEleBYl/ZSSwnXTxMzR
nyeUXgjlv3+5n5Oad5l0kOkZzOQyAZcHLJOel5J1IT7xxmXCOvqUkjrIc2bmYPKKgkkJRS/A
NoMJDqBkZ14leguXKOFt4MtWyc0cS/klI9ba4L+Qkp+XknQxC1DCA/2FWSD8X2JpCyVxyI7T
Yl5Kit4Vp4oPm7F0GKWZ0zcFkZTPo/S89L1JyYaySnozL8EhsaRnzt7GSUqVWyiJQ/KSnjt7
S1UpfWES0DNnb4eU4sOZSUqCqz0fh2lbz5TK0K3ACjpTemXS3SB9OkcPaqiS6hBf5qUPIYYv
8AALB90qFOElpC899kG3nJX0zInbGk9fA2i8BVu98d3dP3pXvq37hv2t17Zb3vcguoeb9eqB
0Xd2v3SiVx2H73ATfNeb9Ane1erX+jme5PKXnh3g+ZnTv3UqnkKVpNvfU8PW1+w/vVLdEil/
7m2HxuhuvULGvlvQ14XrAxjPXB2cxQvTNsJn+/mYmUuDc5qq1RZCd/EDyw/pk8sYIcvk9Mfe
d+sDHG6eXza4oDL6xOkqxMd9epPycrW4/3yH4fqIrHV3gwas0PfXvQzd+h6l2ysUH2/wJ4YC
BvK/158eD7Fl5npjraXTpvKOe9i0444Wer1ASz4cwG3mwuOk3MHtkDiduew46ehxzxZCavqj
4LjTV+v45yMu5Hr1Hn+X97H3Df5zdYjb565WVAWwJtj4meRTSx56KRP7GKbRjG/21C9T6hf4
+GUYXcrp1QHuHfvkS/GT3V221CPz/Hq0sYupJgqIzxqs3FiGt7/3AN3V7d3HJfsNHXWT89B+
bz2/wmxQpe9i7VaqP1Mlueyt7O57ibVz+ae37/Y5LAy8zhIxY6yH/L8LvMKT8SZDaQQdJiIn
Y7j3mLzTwYdeAXq2QGLnP95evV/iWePNmpWZ/wcbwYj4DQplbmRzdHJlYW0NCmVuZG9iag0K
NzYgMCBvYmoNCjw8L1R5cGUvWE9iamVjdC9TdWJ0eXBlL0ltYWdlL1dpZHRoIDMwMS9IZWln
aHQgMzEyL0NvbG9yU3BhY2UvRGV2aWNlUkdCL0JpdHNQZXJDb21wb25lbnQgOC9GaWx0ZXIv
RENURGVjb2RlL0ludGVycG9sYXRlIHRydWUvTGVuZ3RoIDE4MDMwPj4NCnN0cmVhbQ0K/9j/
4AAQSkZJRgABAQEAwADAAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0a
HBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwhMjIy
MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjL/wAARCAE4
AS0DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgED
AwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcY
GRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJ
ipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo
6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgEC
BAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl
8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaH
iImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn
6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwDCkjJGDuY+nalVJEXAQAGsYabfDj+1ZvxXFSLp
s4+/qMxz6GvPsjouzU2EEksD6hjUUlxFEMmZB6jcKpf2XA/35ZnI9WpBptmp/wBUfxBaiyBN
kp1mzQ4ecZ7BeaY+twn/AFUMsv4YxUiW9sn3IEz7pipNmewAH91aNB6lE6xO33LCQ/U4qNtU
vVORp7Ed/nrU8tcdWP1Sk8vg8H/vmi6BpmXFr941zGsWnsW3Y617lpUTxaVaqwwTECR6GvH1
QrIro2HVgRiOvZ7J91jBlt3yDJ245710UGmVFMlANPWJ3ztGcDNS26xSPtkJAPSro8nTEknk
ceUQADXRJpK7KZmvC8aqWGA3Q1ZtHtYzl13MKspLbagiFDuiXnjvWfdJidiECg/dpRkmroWp
elaCdDLIAFPCjFRyzS2Eiqjh4yvAPas5ixXaTlRU1xcef5YAxtGKbUVsNIiJ3SFhwD2qZ7mR
kjj3YVSMCoBShsdufegbiaV1esJsI2UKYx71njqOfzopc8Him2K1ixb+Wz7WiLD1x0q1fS/Y
bBPKj3szgKOw9zRYTCNSWC7McmnTXMclrJK+FRFZhuqJbETPmv4h6hLqXjm/lYllUhF9sVhw
j5cnireqE3Wt30oJIaZiDVVB0AOSOornl5HmVdXoXIY8qTQxI4XipYctGAO1QSTRrP5O7Mnd
R2rPVsxsxoXcfm5NaUEEUcLMVUsemaqQx5kBI4qad+NoPAqJXAbuCt8vSrMZHl8kZ7VSTFLu
y3XpU8tx3LDtirGnxJJcorttVmHJqiCWcDtVyEHcoA6HNROGgJ6ndSaTYS2bBJVGxclsVwN7
OlvcNHHIsgHQgV0SzmDSJixwzjAJNcYIf3zBm3e4rlwtN8zuzetKNlYWeZ5wByAKWCJFwzdq
kfai4HWq5mycdMV6FrHPcnuJmfCrwtRpEuPmpynK5ppyx6Hj0o3EjrNmP7n4ZpcBjw6DFWfJ
Yj5Zl/KjypB/y0j/AO+aGe0QYQDmRf1qFwo6SR/iDV4LIOkqfTbTWSU/8s4zU2AoKATxLD+R
qX7OzDIeI/nVoLIBzbRfWoGY7sNav9RRYZH9nkB4KH/dYipPKlUcwt/31Tv9GI5QqfrTli3f
6qdvpnNIZNYK015BDudCzgYP1r1gAhQMYA4A/CvM9EW4fWrWIxhwGyWxyBXqLKO33c8GurDr
Qa3GxcNnGcdqvT2Iv7Py9nlE+pqirbWB7VZivWa4QyOQo6iuiUVJWYDNM03+zC0bzfO33R60
l47mTbIfu9KL258273oenQ+lV3dnOWOTUU6fJGw0MNJSmheTgVoUJijvTxRigBRzR3xRxirM
EMMq4aTY3vQ0JuyuROsiRBjwjHis/wATTf2Z4aubh3ILRkAV0kiQ29kiXLqF3YDH1rzv4v3g
TRreBJRiZskD0GKzk1YwqVE0eNyMpJc8Z5Ppya63wf8ACvUtf8MJrMV4iefuaKJh6EjHseK5
PCt19cdOnpXs/wAFdZWbQrjRHYNLaMZEB7qx6/h/Ws0cKV2eW6hp9zoUlxp1/CY7xB8vo/oR
XpGpfDLSD4Eluo4sapbW/nyODk7tu4g1ofFfwn/bl1ok1mDHdyXS22/H8HXn1+6akfSrrw3q
F5p0t1cXa67Eqo7nAjdcAjHYYNJRLVJHiMckltOlvcW8kMrR78OuM/SlcbpGr1f406XaW9lo
t9CgWVLj7OCB95SD/hXkpb7vuM1Dic9SNmPwEFNzk8Urfd9aj3Bcc0chnZlqMD8auK4iUHvW
d5y44NJ527q2fpUOkxpO5futRedPK/gFZ3IztxQxA79aZ8/YGiFJRKsKffvUZQE0rbh1BpAC
exrTlFykmVAC889ak8xFAAqAAk9DSGM59KXILlO9/df882/KkMiDjy2/Kmbov+e7n6Zo2oRk
Tt+dZ3PYHGSPHKkfWmEwMfv/AK0mADxOD/vc08LnvG30ouACEEZSVvzo2TKOJCaQwE8tCPYh
qjOFPBdCPUUmCJtk23lFYdx3qHZHu4RlPcipVllKnYyvjuCajsTqmoapPaQaZJLFCAWdBwMj
PNCTHdHU+AN7eJ1SQiSMxMB6g16ZcaePJUJwEGTXl3gzzo/ETwwoY7uOMkxMOeelem21zqAD
R3Sxll4wDjJrai2nZibMxgRx6UwdannOJ3R08tgNxU9qgAIJrrKi2xe9BNFITQWL6VdhgRHR
mxhgagtpkQ7WTO4gCk1UzfYcQg5bBFTKXKrg3oOW2aaRgOFBOTSShBJtRsgCvMdb+MU2lXza
XZ2UVwU/dsc/eb0q9rvxJj0LRbcy2y/2rNGHNuD/AKr60RndGbmjvMc8cntVfVNdsPD2nm9n
RpZN21EUZLeuK8i8PeM/GfiXXI5LaNTZxtvmwuEVR1ya2dV1FvEOpm624tYcxQIDgY7n+VO7
Ic00ej2ur2/iryFtwTZoRJK5GAD/AHfrSa34BsPEqq13NIuz7m08AVwnw41I6fqV1pVxLI8U
TiSGJRncWPOf0r2O6vYLCJTO4TPUY71m0mZT2OHT4O6EAA0k7DGD81SReC9P8G6rZ6zp5lVN
32a5BbOY24B/A4rsrLUmuUZxbtGmfl3Dk1V8QutzoN4jAj92SMD05z+lS42RklqSXdvPcavp
8oQGC1LuSe742g/lmsjUtQgbxfpMUil47fJduySOAqZ9iFb8a29Luvtuk2k4bfvhRuPXHNcx
rcLzeLkt4Y2KzLCZSi8DZID/ACLVm20aIZ4g8Mp461H7NPcGKz02TonBaQr/AEGPzqoPgzoH
8clwx/38V0mlTeV4l1yMMCpeJ+OmSnP8hW79oz3zWsVdGcopu5wH/CmfDnIY3BH/AF0q5D8J
fC0aBTayPju0hrsmmOARTPtDdMH8qNCeRHKN8KfCmP8Ajyb/AL7NRf8ACpvCu7K2bj1+frXX
iaTPIP5VJ9oIH3frmjQOVHEH4Q+GjKziKQbscb+lH/Co/Dv9yX/vqu0N6g+8yikTUImOFcE+
1OwciOM/4VH4d/55yH6vU6fCbwwvWCQ/8DrsfOJ7H8qUTfX8qLIORHJN8LvC2zb9jYe++o4v
hd4ZiLYtWYH+82cV2DXIUcg/lUP9pQg43oPxFIOVHz8ZyRgKR9DSZyMsM/XmhmTHLD8BiomK
t0fp7iuOzO4k3x/884z+FNZlPREH0OKqPNGnV0HuXxUPnKxyJIiP+ulPlYuZF4GNTnc4/wCB
U7zSRgSkZ6Z5rP8APjxw0H4vVe81GG2hDvLGq7gP3ZyTTUXcTkjp/C/h1/FPi0xtePHZwQCS
REGMnoK9N0HRofBmq3Fi0rvb37CSGSTqrDgqT+IxXDeB9P13w/rNrrEumyjTLiLy5yWy2COD
j2OO9emfu/Ed4TuEmm2zqQV/5aSgc8+g4rZLQzctSh4m0v7DJ/wktkFjvbRSZMcCRO4P5CrM
ejtcWIvNSmkFzLHvJVsCLjOB9KsatfWOqJPowmMk90jJhR045/AU3xTctZ+GLlx/rHCxD6uQ
n9TVJahe5wHg7StZOoX2r6tqE1xHIzR2qO5YFATg/wAq7HOabDAttaw26DCRRqgGfQU/jb1O
Qc4Het0dMNhMUhrkLbx/Zvd3cEsE6NBMUJC5yPXr04rVi8W6LMR/pipnu4xRdFNo1p7n7FbS
3QAzChkGfYV5b4b+I2qavd6xqOp3KpZ2dm7JGOhY8LXYa/4h06Xw/fx2t7HJK0LBVU5zXhFz
4b1G1tIdpZUnjHmYJx16fXmm1dGE5taE2laJqeqXK6gpVUeUy7mH8Wc/4Vv6h4QmvhPd3N60
15KCSxHGfT6VNazyeHNChW52qQu7azcn8Pyrai1FTZtcXAaFEAZlcAEAjI/PP6Ur6WMb3OP0
ufxVpsUekxkrauNzxpwWX3NddZXkUo8jb5MiAfIQOB7c1xPifXJ/tcdxaSOkc0O3OR0/D61J
4b0zW1mXUp7S8eFVG1thO5c80hHUXHiA+GtSe6t8LcyRFYzjHOR1/KqDePddubz7Xd3TO4yV
jY8DNZeq2l3eyLfgiclmVIf4owMnkVlxPbFg0hLSdwe1ZyTsZ1GzsV+I3iCV9sdzKSOpzgUy
88beJHtpA964TY24bs5GK5/7Uip8kOcepA/rVWbUJJIpIVhKsV7+h71mlIzjJ3PUdB1nU9Mt
LSaC5kZREu6It8p4r1Lw94hstat3ugqxTxrumU9QBXkFgJBYQrIBkIMYPsKnfUZtIinvYDt2
wNvUfxcYx+tbOKaN76Fe48fahDrusS2bIYZrjCN6qqgAj9aov488Q/w3zD2xXM2uBZQ5HJXJ
+uSf60qjJNYuVjknUd9Dp1+IHiJR/wAfrH8Ka3j7xE/H21h7jiucKHIp+wAc1lKo7i9ozXbx
Rr0j731W5+iviqlz4j1onP8Aa13g/wDTU1QdwFOKrxq80hHak5tD52Xf+Eg1j/oJXJ+rk05P
Emsocpf3APqHNSW9hGyZPeiW2iiNR7foPmaJF8Z+I4jxq9zj0JzTz468TOMf2pOPoao/ZBO+
1Tj3p76U0YGWz9Kftw52Pk8Xa+/Emr3hz234qs2uaixy13cMT38w0j6cy5JUkCp7bRprlNyI
cCj2y7hzsvy6DK64bVWJPbGKrDwqu7LX8jf8CrpGdc4aONj25xRt4/1HHsapM9LlOfPhO1b7
0kj/AFaoJfB1uRlWkX6NmulwnONyn3WmYY9JFP0p8wnE5GTwiq9Ltx9VqFfCEm9Sl0rEMDhu
BXZtHcAcMCKrOzjh44sf7QzmmpMnlPWfC/jvTdWs7e0v2W3vQPLkRhhWIHbt1rbvIV0nw+tn
agB7mbyht6AyHk14QyRugAWRDnAdWyFJ7gfhXpHhDVT4j0RNHuLtodU0+VZIHc48zGcf/X/C
qUtQcdDp7WKO18WQWS7dy6a7Lx8xO4KTn1rP+IuoC30ZLSMAzSSpJGpP8KMpJ/nWnNpJtHt9
XmvP9LgYvLIx4KkHKfnXnmt6qdd1aa7dcIP3cY/up/8AXNarUlaM67TdSh1WyS5hPXlweqn0
NPubtLYqGDMxIwF61wuj6mNF1mOSQ7bK5bFwB0Q9j9OTmvRNWhjCrcWaLJIV/dOOnPQitdkb
wqJHk72M91fXiw27wXkEpKAsBvUkkZHrTI7yEhkugsM6cSI+Aa2PFGnz6Tf22prK73lwdk+B
navHzAe2azr3StKuwFZnu7pvuyLyfqfTP9KyctbmkqfPG6KH9oaduAX94Qf4UJ5/KqmtaqkV
lHJ5UhRZBuBQ4NWLNNRkCW0FrGJC+0ZBOMd6v3elFLD7PqWpWnnytt+z7fWtFK60OOSezPMD
Fqfi3X/Ltonlkmk2xofuqK9Z1z4X+JbjwbbRiZZb+2jWJok/5aKCSM+4ziu+8C+DbTQNGSKS
G1kfIkjmSM7hnrk/lXaDbuBAAPrtNS5CsfJ1h8M/Eza5ptnqFhLBBPOsfnMcqvPSvqm2sILa
yt7WNAEiiVMAYzxg5H0Jqj4mYRaR56AB4Z4pFxx0cf40zVPE2l6Skf2u8i86Rtnkq2SxJxx+
lJzKSbKeqeDNDvDMDEsDXTqrtH1OM4x9RXFaT4N0O5sZYZ7BD5FxJCHB5IVsZrc/4SS6mu9b
1C6tXji0tESCID+JwGz9QMVb0u0NlpsELcyY3O394k5J/WhO5LV9DAk8AeG4EMrWn7tFJbJz
mvN9f07zPHtrZQxJEkqpiFRjavUZ+vevc2G6MjAPB6/Q147eW88PxPvLuVzNJDEGcdskDAH0
A/WqUdSeRG5qFn/ZtwJIyTbvwc/wf/WrH8QyiPw9dE9WG0e+TXZpLb6rp5wMxyfw+n/168+8
VSNbWkdg/LmYfig//XTb0B6RMGNSsYT+7xxUiDB5701Me57GpCwUZrlnucL3JCBgmqzy845p
rXAyQM1A7bjWbWoIJHwRzV/TcvOERCzMOgFZjjcMZxWvo+pG1j8mJFSU9ZepFZVr20KSu7F/
DxqVCnNZdw8kjBWB612OlSWOquIbgBZAMtJ61la7/ZdtOY7N9+OrCuGnUbly2Np07K6MZfMj
YbM083kmcHqPWnxyNIQI1yxqQWbsctE249eK2bS3M+VjhcPMNpGM1etJ54IykZx61VjtpO64
9M1oooRcZAPeldMW25bKoTw4z7igROD2I9mxTjJIekIb6VEzL/HC612nrEjZXgh8fXioyYv7
yZ9MYpVkXotxj2Ip7eYV4EbD3FNAVyuCCqdf7rZzUby/wM23/fWpGjYAkIUx1K1GJWzjeG9n
WmAgUkD5VZev7s4pn7yK4S4t7mSC4jyVk70rmMN88TRE9GB4NPHnKMo6yjHAP4UBY6SXxB4g
1Dw8rajcpJZ+Z5bNCmD7E1SbgDHToK6nwpaQXfhd4Z4sRyuxK/pXL3NnJpF89hOSQSWhY/xL
6fUV100ZyiVrjaYJBIMpt+bPSun8Ka/Po+n2+n6md8M4/wBHlf8Agz0U1zhiFzcRWn/PRhvH
+z3/AKV089olxbNBKBsPA4+76EVpLYhbmhJoNxrmu/aZ5fIskTyyCfmfPXHtxXO6xYWfhOcp
pKtNDM4jZFO5o3PTJ/E/lV3TtQuGlXR7u8W1ULlLhyclO+Pfp+YrXhgtbyeNoIsWVu2UYrzM
394/571k4p6HTGpyo5uDw3d6f4cvZ7q6dZhGXIi+uev411l1pWiaHYWt1HpP264lwVYDczEL
nPPbrVuQLLG6SKGVzlge/tVLSdQl0KS307UWaWzEmLec9YycYDe2M0neK0Oe/vXMRfjNpyKy
zaZcoU4MYYZX2xmtjVvHdzp/h0aymmGS0crtIl656V598V/Cx0fVl1i1jJtrs5YBeFfPf2Of
0rAXxXP/AMIVJ4bePeiyAxyE8qAc4rnlNo9KGFVVJxNLxT8SNW8SW5tEUWlmzfMidTj3+orj
JJ5fNW5Z3eaM7wXYnkcj9aTsO57n1pG6e+DWXtG2epHC04Q2PZNEvZdZ+Hut6rcnE95dbWwe
PlCp/Suvz2yTjgc1yPh2E23wesBtwbi6UnP+1LXWkgk8f/XrtpbHzdZL2jsODKDljhcHcfQY
ryuFvtWo6hqbZL3U5IP+yvArtvE91ImnfYbZwt1eHyo/oerfTB/lXIQL5UYhIx5XyY+nH9K2
RkybSp/smpCDOIbjgD+61c549kSfxJaxqPmhiJbHvj/CtyYbP3gxmP5wfTFcHfak2p6veX56
SPtTP90VEjKctLEYmMa7R3JphkZu9RO2TSZwMk1i4nK9x5z7U3OOtN3cU0sQM0nECTOR0NCk
q2ckVGrtT8k9azcR6mhaXrxlgjlCVxmnWpR5GDrnI4PvWep2nOKnScqu0cZ64rndNRd0O72O
38MaHAZBcTvg9VX+ddr5Fn5Z2xJyOuK8q07W5rNX28uy7QSelblnrb6bppnnkMkknRc9P85r
x8Vha05Xizuo1oRVma2pWsSN8xC7c9K5K8nVblgJOPrVe81u6u5WYtgHtmsuQiaQszMK78Lh
ZJe+ctecZPQ7bvmObkdiKfuuf9hvocVWEhP34V+oNBaDIDeYme4ruW56Viw0idJoce9QmOAn
KORn0NPD8YSYMPRhUTZLcwo3+4aqwPQkCSryJN4HZhUbS4J822JHqvOKNq9maNvQ5oWS4U4w
kg9FfmiwJoaBC/8AqpChPVXHWmMhiYEnZkgAg5HXvVgyQSjZLHg91PUUxoCoHlPuj/uHmgZ6
P4TBHh+At/EWOR9an17R4tbsvLI2zIcxSd1P+FN8Np5fh2zTB4Uk59zWptzXbSTS1B6o4HQb
WaO6u2vI9tzEfL2nr35H1rWlLCMsvzMoOAa0dc0yS4UX1pxdxdf9sen1rOtZ1ukJACufvKeq
n3qnuZSjbU4RdM1PW9cM9tuM9r8vlSvwP/rcfpXp+iQ31vp6pqM0ck+MnYMBfauCnR5NRubu
GUwzh8K6npV228Y6vZ3qW9/HC8JXHnkEY+v1qOpDZ6F7dutQXVsl5bSW0pJWUbR7Hsadb3C3
NukyMrAqPunIqUjrnhscUWuIqpbL4s8EXWl3gP2qFTEdxz8wztYfWvnu5tpLO7ltJkKzQMY3
U9cjvX0LBcLpWvw3BOIb0eRNjoG/hP8AOuE+KnhxdP8AEC65Gn7u7+WXjgMOh/HNc9WGh6WX
1+WXKzy3zV9/f2pxKsufxq1cWoaUME+9kMKoxlRvUnG0kc+n+TXKl2PanJqOp75Dj/hWnh6I
D5Wlg6f9dM1tblRGdyFWPLFj2Fc1ot4tz8MfDzjPyXUSHd7PTPF+ryLCuk2rbbi5GJG/uJ6f
U16FL4T5ir8bIrd21LUp9UkGYxmG29lB5P41m6rD5WsFuiTn8MirehztJYeQx+aA+Xj2HQ/z
pNfjMumiUY3QOHz7VqZHL+Ir37Ho0xU4eUeWv49a4SMeXEqjsMVseK7v7Tq6Wyk+XAuXH+0f
/wBVY5PAFZyaOWo0GTmrVjYy39ysEYJJGeBVXpWx4d1tdC1D7WYvMIXAFZ1L8r5SY2b1Lv8A
wh0pAIdwT/s1JF4Gv2f/AFqqMH764FdRpXja31QtE8HlyEZGcYzVmW8uLgYLYyP071408VVh
L3kenHDQnHQ8qmtpbe4eCRMOjEYx196YGHQ5Feu3FjZTyeY1tH5ioqs2OvFctq/hFQWns3AB
P3T6mumnj4zsmYVMHJao47HB5FMXO41dvtJvtPk2XEJH+0ASDVEZrthKEldHHKlKLuy1Efm5
PAqWWdpSA/IHaqauQT7CnFjwQRyM1EoJsknZxgDH5U1VDZyajUd81LtwOapK2hNuppjxJGw+
WzuP++aeNebHy2M7Z9sVveTAh5DNn2p6IqHMcA/E1HMj1FGRzz602M/2fcA/TNQtr6L/AK2C
RPT5TmuqzM2f3ca/U5qGSBZP9bJHj0wKpNDszDj8SWBUB5ZEH+2M5qQ63prn5JoWx7bTVx9L
09id+CD2qEaNpRyPsO/3Ip6MVmiIatbA/fAU9PmBqaO9t5WARh16hqhfw7pkgIWzcZ7qcVWf
woiruiaVAORg0rId2e26AMaFZgnP7vIrRqhoUJg0CwhP8ECgk9Sav4ruj8Jotg/wxXP6zpbw
THU7CIswGJoR0dfX610GeaeqE7W/hoB6o8oglimjkkTlDK3HdfapJ9v2eQOMqUPBGa6bxR4b
a2mbVNKiyhG6a3QfmRXKySJLaOyEYKnJ9DjvUqzMJKxp6PFeeH7SOSxzPaMA8kDtyCfSupsN
d0+9ARZhHKf+WMnDCsmy/wCPGD2jXnHtVPVrOCSylkMQ81VJDjqKdkSdhc20V3bNC7YRv4h2
9CKbFEvivw3daBqI230abWyOSOdrj8q8sN1rkD27adeyEFeYn59OBXR6ReXl3dwX3nyxXkOV
GB8p9VPf07VlNXRUZOLujF0/4a+Irq/8i5g+zQo3M7nII9fxrrIPhv4P0pWOo3RuJ8gtl+n0
ArrbXXLTVrdoJrgWc+cOjN0+mfWnyyeHdLtGbdbsR/DgO5Pse1YxpnRPGTkrHN+ITBY+F9O0
/QoFC+eJI0cfwodxP06fnXB2dtfRb59TYtd3J88n+6D0A9uK9D8mXVJ7i9vQUV0CQwn+BM8/
nx+Vcx4hZf7clRMBY40QKOgxn/61dEFbQ55Pm1K+kSGHUTGT/r1P5j/9da2ovHFpFw85xGIS
ST/n1Fc2zmKeCcceXICfoTineOruZtMh063GXun+Yd9g/wD11U5KKuyL9jzJZHnZriY/vZSX
bPr/APqxT4ozM2Bkk9AK020W8lIKwFS36Vu6RoC2Eck1x88nlnb7Vx1MTFK6M4UHOWpzMWk3
kxYRQu+AT0p8GlXrylTbuCDgjFehaYht7JXACs454q1FdCFrjCKX39SK4pZjZ6I6Vgkcfpeg
XEV0krKV2cgV10SquVA5Kkk+5qZcyr5jHBPUCkRFS0lkPX/69cNar7TU7KVLkHMxGV/vNg/g
BSTIXihT+9Ko/I5qXZ+857HNOfgR+okBFcbdmbl4RxSqTPEr7iRhhngZrmL3w5ptzfXP7oJg
gDb+v8xXSSShcDsODj1rMjbzLic/9Nf6ClTr1IvcUqMGtTlbnwVCJIPJuTmRtuCKpah4Q1Cy
jMm0SRgnle1d4Y8XFqT0DmrF65MKwj+Lk811wx8k9Tlng4y2PMLLRry4kCRwtz146V0Nr4Ll
mMiyzBWQgEV19nGNw2qq4wBxU1m+Z7qTHDSY6elXVzBvYUcFFbnKO4XqyrUTNn/loxHsKaLW
UtkBQPRual8hlXmXZnstesIYEU/cR29cmmvCcf6uMf7xp3kRD70jH6tTXW1GPkYn2JpoTIx5
idFtx75oJfPzXir7KKdmLotsfxFAQnJFsn5UyRmT2vyPwpNkjj5b4k46EU25mFtD5klsoGcc
CobLUYrqYIsYUg8e9axhJ6pE8yuexaWHXS7UOckRDmrRNQ2mfsVuMceUtSE9ODj1rqSdjVNW
HAFjgCplWaOFlIG0/nVcMVORVq0zNI29ySB0ptOwGfZXs4vTEVJjPTI71ynjHQfsZm1DTYeG
Vmntx3PdhXockSRw+cFUbT1qC6g+0Q+cgVgR0rKEJK9zJq5wumyLJpVs6nKmNf5dP0p94m6y
nU9TG2PypdR0uXSpHvLJS0DHMsI/hPqB/npSJJHdWm6JwyMOp/UVZDVjk4gXt48EhgoKkdiK
63QJrW/linkYxX0Yw4B2h8dDj1rlbcAxlc42MVI+hqYBlcSIxSRT1FG5DZ6Lc2NpejNxbqxJ
zkjBpkGl2VrJ5kNqiOOjdcfnXMWPim4j2pdxq6j+JeuK2l8SadIv+u/4CR0oURGpJIkaNISA
FG45PavN55zd311cn7skhKn/AGe1a2s66b8Nb22UhP3m6E+30rHHy4A+7jpVWsUV5ZBI0luh
zJt79Mf5FVvPk1TWUvypMa4hjB9h8x/Om6u72US6jEozECJMd1PB/pWrpVp9n0yx3gFhHvbb
6nn+tefmNTkppGtCCbFjDHamDuxjPtTpIS0EhGchauRJ++DY4Cc0qgupwMgnFeF7RtncopIJ
IvLgiTnhBVNVDTzkZ+/WxcjO4kcAYH6VnW8ebmccffpRVxolGRCB+VST4Wzz2JGaVUy3PQVD
fnFuUXqSAKfKO5cUAgn/AGj/AEouFHnW6+5J/SpETKZ9hTJXBmAbgohP8qwmrFIZcOFtWXPz
MT/TFQW6hN3c7jkj14psmJLpQThVXn6063STypG45csv0rDoWWnwrwj0yTUDuDKOeoAFOJMh
QnsKXykMqv6DFSBZjYJsjwdzZ5FOtAfI47sTRCBklgSdpIqzCgWCP/dFIDjGSY43ScelIRGB
8zbjT8p3RjRgfwRAV9ajz2QeZAp6/pT/AD4uwP4ChhcA9YwPpTDHITzOPfApkjmuD/DG7f0p
hkmYcQH8afsx0mHvQwYjicj6UXSEYetSTu0ashSMnBqgEIs/Ni+VopMkiujntYp4ik824da5
u+ja0eSBGJVsHjvXp4eUZRsjgrRknzHc6b451rWbq20vT7aGOTYAZDzhRXd6fFfw3LpPMJ4d
g2uFx83evn2O5ktnDxyvG46Mpwa7Pw/8RrvTYFhvUN0gPDZ5xXTUo6e6VQxFtJHr3XHXgUqS
GMkqcHpXAr8VdOJ5s5k/L/GpB8UdHxkwy5+n/wBesPYyOv6xCx3RlkMZiDEqTnBo3PGNqsQP
SuCHxS03JxazYHfA/wAauL8RNDlRTvk8xuNuM0vZSQKtBnVM248YyeDXJ69bHw/v1e3Qvagj
z4F7DI5A/OuktZVkijlCsu8buRU9zbJd2stvIAUlQxn8a55bkyaex5hZSxz/AGiSBg0RmYqR
78/1qwc1mxWMuk6xcWgIRY2xICeo52kfrWirhhnp7HtVxMnuGMf/AK6TAzwP1oMi+tJ5i+op
gHIAGSace1RtMoIAPJ6cVJHDdTMAkJIPc9qpDGTxJPbSQycpIhVgfQ//AF8Vp6VMLrQ7csFE
sf7mQDsQSP5YpkWhySSAXU4EZHKL3/ycUkECWOvXVpECsMqLOq+/Rv1xXl5lByp37HRh2lLU
vJHstZGxyTgfhUcIZAAM8nJqdpDkxcYU/nUijnJxXgxWt2dzaHFMwsWPX1rMtf8AXXDZ6vxW
hdyboQoPfmqkEQVnHuDWunQm5ZjQhMkVVmG5lyONwq8WKxYxUARmyxGAOn1reMVa7I5tSfcI
Ydzds4FUvMMzyyPw7KFFSyu00YP8IxxSbV86Rv4Yhg/WvOrSTlZHREryLun8tf4vvH2q3Axe
1XHBRioz3WqkQblv4pAR7gVas+YvLP3l+6fUVjLYsdEn78r0UdM1IqfJnGcGnAfMp/vHBxUr
bVBGeB6VFxERcxxyE9QuB+NS7mWKNVYY255qrdLiEZPVhTt42qeeRkUAjl/Mf++f++ab5khP
zF8ey1zf/CZ2/wDzwm98CnDxnZ9Wjnx719aqbR5fOb7bSefNP1FKQpHyp+ZxWIvjHSmAysg+
pqT/AISrRH65OPWr5Gyec09jH/lnH/33RsP/ADzjP/A6yz4n0PI5xn/ZzUg8R6J/z2UfhR7N
gqiL5UZw0UeD/t1h6wm25aRowIiuOGzmr417RJOPOj+rDpVfVbm0vLJPsbI+5sfKK6MLdTsZ
4hqUdDrG+GSXejx3en3DGRoFcRsOK4m58OavYlhcWEvXqFyK+iPDUItvC+mQz4W4Fqu9e/er
Utul2oCQgKOrHvXesRrZGP1fmR8yw6ZdTsVitJi3f5DQ+j3kcm17WYN2G019DSQRwSlRGoK9
wKjaKNm3FVJ9xTeIGsI+54QnhnWpUVo9OuCD04q9oHhq6l12GK5geMRMHcMOwr21WIG1QRjv
6VWlg3M0gUbiMFgOTUSr3RSw/LqIjAkHnHRR6CrK56g9OR9aqqoUhR2FT56Yri1buaW0MHxJ
p8cd7a6kEVkJFvPkfwEjDH6c1VfTrRuWgAyT04z2rrJLNdSsbqyk+7LCy59Djg/nXJ2MrzWE
TSZ81MxyA9mXg/rVxJZF/ZFmT/qv1pDpNkvWHP41dJPpRx3qxEEdpAgwiAAe2anChR/9ajgU
1nGQCQPqaEMdkZGR3rK1BfK1bTbnkZZoGJ9GGf6VdkvLaHO+ZcjoM1h63q8c1l+7jZvJdZQx
7EEf0zWGIjzQaLg7SudEbJdy/wB7Az+VR3DpEAMg9annmYRM6Hlhxmsu/wBouY4gSWEYYivm
Vr7p6LWlxDJ5jgY96mQf6QwHoDUCKfMUAZOKs2kbPesD6AYraEdSWaCW4Kru6EVVu3UKkcfT
zBmrNzdFNsUeDkc/hWe5P2dW4y0n+NY1a3K+VFRjd3HugSNVAPOQKrkj7OV5zK25voKlllIi
Rz2JP5iq8H72TJ6KtcLfU3SJWXylV8c4OPp0p9uFKNEThweMfTmluGwn0AxVeNttxI2eS39B
UXugL8ZU5lbIdBt2j3olOAij1yaavOcEc81CXZmJPfpmkAydvMmjj7FialbOyMn+7jimsqiR
D1Kgk1IVbykHGRkGhjOSMVq3WOH/AL4pr2NiwG6KIg/7NTnzz0iiP40YYD54lP0NfXczPKUT
DvPCemXZ3RsI29jgVnN4FiP3bzH1rqzs/wCfZvrTPLt8HKOKtTYnBHMReBIlP7y8JHtVxfBW
nIQTmQ+5rYEcGTtkkH0NHlRk/wCvcfU0c7FyIpjw5piL81kpAHUmqWl6fHeeILWysoQkZlG4
D0Bq1qdwIIdqTkluK3/hfaBdaku3XLJGSM120I2jzMxlrNRR6hqGmXNxNG8cxRxGFODxxV64
eWGzQo+BGnz4/nT4pzNeKWOBsOcetYuqXsjxR2AGGvLhYQ3tnJ/QVHJyyudNrIrnVjNvMNpc
z4YqWjjyDj8aiXVkSZI7uGe13nahmjwCfTNdvDbwwQrFDGsaKMDA/wA8025sra7t3huIlkjc
bWBHXP8AKhy6kc5mQWbo6M21o2HJU5qSS0xbyJEATnrWVBLP4Z1GPTbiXzNNnJW1dhzG+OFJ
/lVjT49Q+1zJM5WFhvBOe+elKU22kh81yhIGjkww5zipBxjNS6jAkM67X3Z6+oqGVgNlMlmn
p6EyE+i8/T/OK8+1+S50zxbqlrG6iFpBMgI/vDn+Veh6WxEp91wfoa4bx4hTxbHLjiS0HT/Z
OP601uZsy/7VusclD/wGom1S8PAZB9BVME96ceelWIcbu9Y/NOcUws7cl2J+tJRQA0xqeSOf
eiWNHtZI2+6V5x+dOxR3/T8+KUldDTs7m5pc63mkWcgfcxRcnPcdajurXztY+1q/IXYADXne
k6xNp6GGFmEkUrKWzx1rb069mnvQ0k7KGJLE14EsE1NyRusWrWO5trX503cGomkFpd3JHMmz
Cj0NZFzr32eGRlnG1BnJ6muGTxFdnVzes5ZWPIJ4wKJYeXKVHExbPS7PL3ILnkJz9aS6/dRx
A9DIf5GsvSfEVjcQvPJIsbkgY/OrupahA8dsIZEYmT19jXjzhNTtJHdTqRa0C4kX7LJz90L/
AIVY0+NVjyRyXCmq3kx3Vow3hS4GefQipFmii3F5F2o+45Pap5W1ZFuSsTXo/fFf9rFQiHcZ
XBAUS7T7cD/Cq1tq8eo3siABYQeGNVzftcX8tlDKEg8wNI3qP85qlSdrWJ50bMSEJN1ygxTk
KuiYHbnNJHcwiPDSLk/L15IHSoIbiFYgfNX5jjr0FZODvYakmMkbzLyXacKqgDHrVpCSCOvO
f8/lWbHeWm64VJOVkTOfqc1I1/Bn5XB5PSrlTb2E5xXUyCidQxH403bH/wA9SKkMBxkOePUU
wRN1+X8q+oRwDgqleJelRlJP4ZgfYipivHAqFmCnDRn61QDGSf1jP9ajPmAjdbr16g9alHlN
nDkGkMLE5SUkjtQJ7HNao4kvSirt5xgDOTXonw9Ci7uFRCpEGDkd681eRxquWyT5navWPBsb
efdueyBc5r0pppJHLQ96bZ1xbB4JB6GsvUsw6hpF0x/dxXqZP+9kfzxWkfvfrWdr0L3Gi3CR
jMqASx/7ykEfrUT1R2SWh3Gc8jvSDdniue/4S/TV0i1vp58GaIOI1GWBPJB9wTWNcfEQKdtv
a5XsW4rPlZyvc6nXtLTVdFuLVmYMQGjYdUcEEEfiPyzVHR9Y/tKxhmlXbIU2uM5ww4I/PP51
zEvxBu2D7LaMZQgZPc1W8Iaj9pu9WtmAR1l+0Rr6qw5H5g/mKaiaw1djp7pzPOzYA7VXlydt
SkH0JqKXqAO1D3LasbGlf64/7tcb8RCI9c0493tZB+TKf612Wjjczt6Af1rnfGlvFNrmlGVA
w+yzcfilNbmMjgt4PVh+dG9R3H51uPpFjIx/c457Gm/2LYj/AJZn86tEGI00f98fnTfPTorZ
PsM10CaVZJyIFP15qZLaGM/LEg+gxTA5wJcykCOFz74q3DpF3K672Ea5B6810G7AwKUHPTse
c0PYDyaGy2XV0mc7bhx79f8A69bcFqyLu6ADmoERF1bU+gxctwTRf33m25gt1eQnqUH6V582
7uxytO5RvrlrpxFHygPp1pP7J8xAd2w+mKWyljR/Llj8qXsrjFaDOAc7uR1HpXDVqSi7GkdD
nJ4HtZQgLYPtV+x+0NMjO7YQgitFnilK5QMRViONAOBWUqsWtUaRlJO6GTanKNsYJBxiqsj3
EvyAsc9eetXBaI77yASOlTR24Fx5hJA9K51KKNfazZArPZ2/lovzHripYYGBLDgtgk1dMasc
sAadlVFJzT2DmkQSERhJppCoTOfen28gmiUhT0yPesbU77z7pI1/1aHc4PcCqj6jOkmI5Pnl
PyqP4V7VosPzK5LqzR0YRBuZUGWPIqjJNdSSFbZAqJxn1NEVwYSlvvDyH5mIrUhikZSSijJ4
ANYy9wfNKQy28/BE2ODxipmxUQkb+4RQZHH8BNe4dBJ3601ifWo/OY/8sjR5zAf6o0wFIQ/e
QGoJClsfMDH3XvTjNITlVH40gdS2ZCmSPWhbiOT1AGG+mUA4I3hsdM16t8OBKdIuJJiSWYAE
/jXFX1rBczRvJKBgfMAOvSvQvBO3+zJ9i4XzcCvR9qppIwo0nCdzo8cD6UjA9M8NwfT/ADkC
n7Tt3YOM4zSFcxE9AflFI62eX3NsLHWdSssny1lMkQz/AAsSaYFyMgn8TWz4ythDrGn3qDHm
h4XPuACP61k/dyp7elBzTVmRlc8HpV/w7OLbxdbdAbmJ4/qRjH9ap4PXFRxO0euaPIp2lb2M
A/Xj+tAouzuewWkDAHcmVfoTWddW/k3roOR1rV3N9mkihcjGcH/P1qhHZytEskkjNJzkHrUM
2vdFzSGAEuPb+tc74uk3+J9PjHO2zlJHpytbUF2tqGBQn12muE8X639l1y5uGiLBIUiRSeSx
5oMWTXN/aWYAuJ0Rm6Ank0yDU7K6bbBcxu390HmuYS386Rp7vEsznPzfwjsBSS2MTkeWxhkH
3XQYIqkSdmBxTe9c3Ya89sws74FpOiSKCd//ANetCTW4gh2QOSDg5+WhuwkavB6GkZlQgsyg
e5rJS91TUVkNhpkjqhwzKCeaymluHDy3Ed1thkKyZjOI2HODUXuNlCSytdSupnt5WbzLl3nI
6KOAB9eDWokMUMeyNdkWeFWqHh/b/Y6ugwJnaQ475JxWhNIEUvtyTwB70Rgt2Tyrcr6hp8Wp
WrxsuJFGUYdc9ua6Dw94COs6FBerc4JyrKR0YHBqlbaVPJGJbm4FvnkKSOPrXb/DrFjY6nYN
MDHDceajMf4WH+IrGtRjLYTWhz4+GOoCXKyxlK0YvhvOF+aWMGvRwykckY7e9LlB0x+FYfU4
saPPW+HcgXiVCfpUA+H9zk/vEH4V6QWX2pdw9vwpfUYDTPOB8P7kg/vkH4Uz/hX90CM3KYz0
216Vlf8AJpPloWBgO55DP8J55RIVu/md9xwvb0pR8JZGmM2V8zAAwcAV67x60uR7Gr+rW0Rm
9zy6z+GEts4kJUuO5atD/hBLr+J1/DmvQQw9BS7x7UngYPVlp6Hz3tP91qRgQOj/AEBpfMQ/
3vzxS71znn/vqkdQwLxnbKPqajk5GNsv/fWKWRhnIDP/ANtOlRtJu48oL/vODQhXQzMSA7om
Y+703fGo3fZwP+BUjYXo8AP+0c0zMf8AFNGSf7oFMLoV7k7TthQZ/GvS/AUDXGiMNwDPJkCv
Myq5+WXr2AFes+BbTOhxNu2YY85remncLnS/ZSlnJE+MjkHtSNYCS3hUEALyTRq0NzLp5jtX
Pmbhk+op0NrKLRVlmO7HNaqUuawczOH8eQJ/ZaOuSILqN+OuM4NcssE8oBWJjn+IdOtdv4wt
lTQrwMclQrAj2YGs5sdUAVTyAPStCanc58aXduvJQfrVW806e0ksbmQqVjvYSQvX74FdP1PT
9az9cJXSZJO0Txyn6K6n+VBmtzu/tL7DGgC+pqa7vSoiaP723DVQXPloSRkqM4pvU471Juk7
DvvKxwef615j4jn+3eOLi2AJS2CuwPQttGP616ML+NZNrg5BHGPevN5isnizWZwuN8iDPtsF
BlNEp4GevHFBUsQi/eY4FD8L7CrejxebqEjkZEQx+NWtjIlPh+GW12y4M+cq+T8p9qk0DRYZ
tAvNd1uOSW1gUlIoif3gHerGqXP2fTLh0OJAmE/3iRiu2uBp+l+HE0idwsb2zRICDycHrgVj
N2Gc/wCFtZig8I6rPo6MbeKH7XAjfeAYMef++Kpaf4utV0K68R3dsTBdWMMs9ug6yM7ITycZ
pngK0v8AS/Cs3n2UrRXMPkQrjJ2KW6/XdWHq2g6r4c+GMlrdWhlDyRs21hiOMMTj9TUJ6gyB
LdbG9v7SE5gguGEQ4yEKq2Pw3GrenxSSXCTKnmTO+y3TGdx7t9OlYGkXk17pj3Em0TTSlWK/
3iePwwa9K8F2Cxz3WpyoGisl+zwfVc7yPxxj6VtfQRt2HhHTrWy8/VVFxMTmR5WwFODn8Kp6
X4bsoNd1i2V5jGRFKoDn5Awb5f0H5is34laiuq+GdPs7G8CNf3KI7B9pCYbdn36VV8R6zqGk
afbtpxxe6xdjYrdRCmACf+AismFjRivNa0nU9SsEVryyswJg2SXCtn5f/Ha2bTUhf2cdzBKx
jfPUYwQcEfWsUeJrbR9TinvQzXOtT7Yx2WKMdT7Hcf0qXw2caFCzgoZXllCk9A0jEfpikpO4
+U2/OlP/AC0NO8+YfxmoQ6/3hR5i/wB4VdxqBN9on/vml8+f++ag85F/iFBuoxj5xTuhuBY8
+4/56Gjz7j/noarC8iH8Yoa+hXq4ouhchZ86f++fzo86f+/+tVDqMP8AezTDqUJ7E0nJAoHh
7aLqJA3aq/t8tQvoOpHprDfTbXSbpR/AGz6EUxyf4ojXNojXlZzD+GtUYZ+3sw9RUR8MXvVt
QmH4V1IeNuCXUjpmnMHONsucdjT5l2D2Zx7eGJmP/IQfj1FH/CLScZ1Bx/u11zvKF/1aMO+O
tV/MtHOJItjDuaakLksYVp4dWG4R5NRmODwM9a9t8LAxeHrYBjg5YHPUV5j9ljdcwy+4r07w
4v8AxT1mD2Stab1NEjovt3zoqDC9DU814sEoj27kxyc81kdOR2pXdnIZq6LLcfKUfEiifQ9S
2A820hGf904rCtZRLZwSA/eiQ8+6iundRLDJC+NkiMjZ9CMVwMV8thp6WrDddQM8JX02tgfp
SJqLQ2WYIMsRg1S1Ca3n0+6gMqkvC4Az32kViSyzztulkb/dHQUwBAfunOD/AIf1oMVueh6T
P9p0axmJyZIEYn3Iyf1qz3xWT4Gkhm8KNHLIPPtJXjZfYHIx+BH5GtZ+M+3AoOqOxyup+JLP
T9Va2nVlIAIbHBrkkvra717UTbOWRtjjP+7j+lX/AIi2aJfW1wDjzAynnqeK53wyvmazNatx
9ogzGxP8S9APzrncnz2MZnQtxncelaOggm2uGHBMp/KsoOZHeKQYkB2sP61Z8LyiH7XYM7NI
shkUnurf4Yrpi9DIl1BvtmvWNrn9yLuJWx/Fzk/yr2aaCOX78SsVGRkZ5rwu2LHXrXBIxqI6
9cV7swbdjJBOev41jMDJv9YaxuzbW9mbhYAHmKDAReccevWuf8fzx6l8M9SuoW+WSAMjY5HP
T69RW5oTmS+1qc4ybwoM91VV4P8A30awNbgWPwj4o04qGjt3Zox7OA/5Ak1mnZiPLdJtv7K1
VtPnX5MC4B7ldv8AiBXufhG0+y+F9MUp+8liWeUHuzgs36tXj/itTbXFrfBQPMtpIGb0+TI/
lXt+mHfpNo6nH7lNvthB/StHsBmXmg6Ek0d3dwRYTLLu5AzxwKpSeBNK1C+hv57qedI4dkCm
XhAcg4Ppg1f02GHVru5vpgJYAzQwKf7itg8epNU7W6OneFNaQkA2Uk8Yx/CCMjB/EVm2VFXZ
wcWi3Gu6pFqd/eFrWzDW1pEFAPlqcc/XArrN6Iqom1EXgKD0HpXmVlrF7Dp1vHDdAZTdzzye
tDalqT8m8XPsKnmSNOU9JaRP+en60glT+/8ArXmf2zUOv27b+Apn228zhtS+mBilzAkz1DzY
/wC9+tL5kZ/iH4mvL/tl1/0EWH40Ne3CjLakx+hp8w2enma3A+eRB6c1A11ajrPGPqa8ye8Z
8Zu5T9VzSCZf4rmQ/wDAaXMJJnpbX9mg5uo/zqu2sWSni6X8q86aVOouHP8AwE00S7v+W7n/
AIBSuyi85MfzPE6f7S05LteAt1j/AHhT0khLYWQxuezCgwFgS0KSZ7r1NQMlEkzKeEkHtVdn
hB/fROh9aZ5EKnCySQt6GhheQruQiWM9+tCAkzblf3VwQfftRuuQn3I5l7etQG8iLbJoFBPd
RShELZt7naR0UiqAdvhk45hk9K9W0JTH4fsVPaPJNeViV2bZc25Po6816/oMAk0y0jd8YiUG
taW4bFu3thc7sH7oqKeFoZAhyc9K1IbT7NPuD/uyMZpZFgeUAsC6dq6G0tw5nbQx5I2j27hg
E151rltHa+Jb5RkmZVuAT3JGGx+Ir1S7ikuGHyYROea4LxtZbEtNTUcwN5cp9Ebqf0FMTu0c
433jznFNPUU9gc8jGBim49aDne5c8NarDoeuyNdEiyvV2SH+7J2P05rv2YOzEHIPT6V5rDYn
UW2gYjzksRW7Z3GpaZEIYJEuLYdI5eo+hoNoTsR/EG2jm0u1aRgrLLwTXmzGfS5Yb6JwXt3D
p83X2rvvEmp3t9p8cJsUQGUffbI/CuYg0ELcJc3bb2HSNR8tYuOtxSlc6ILba7Al1bv5c7Dt
3/zzWXdw3WnXMNyUYSQtnI6OvcVW06V9NuzbIxGxiYgejD0+tdNFrNvcjZcR7X/2hxWqMmc7
eXhD3N3aDlZUuEb0OQSPwwfzr3XStTj1jSre/hbKyruOexxzXh+qQQ2V8ZoJFa0uV2Og/hY9
/pW/8O/EY0oNpt5Ji2LlVYnhT2/A5qJBY9B0MhL3VoWByuoMzD2KrisjXT/oXisk/wDLCInH
rs/+tV+6uf7K1ya7KPLaXyKTJGu7Y64wfoR/KsjXZv8Ailtav5g0f9ozLFErDBwFAHH51g9x
nJeNbc3HhWbYP3ibXB9sc/pmvSdH1Af8IFb3eTui0/P/AAJV2/0rz/xPdQWnhe9aYj/V7VB7
kiug8CXaah4TvdNJG5UbYCezqdv61u02hM6/QLYQaJYqDgi3XO3pkgMT+JNch4qu/s3gHxRO
BxNdOFPqTtX+YNdNpuppb+FbW6l+UxQBHXvuXgr9eK4Tx7P5XgPTtLc4u7+bz3Ue7bmP0yaw
e5pA83hCRqE+z/dAHU+lS5X/AJ9WH403ZcNyZHHXHy+9O8iQcm7J+o6Vm9zUXeqjJhH03VIk
sJ5Nuo/Go/mXpMjfhmlZblh8jQ49+KQCtMpJAt049aRZgp/1MY/CovKnB+Z1J9qlVJD94OPo
BSuwJRdyZwiIB/u07fK3JkC/8AqIxN2Mv4DFIA6n/WSL/vDNF2BIzSY/1x/4CtHUcyyn/gNG
6QjH2kf980bpVA/0hfyouwNbZxvjKSj/AGjUbxqHyjNBIffg1n6nq1jZAm3O+fsqHpWBPeah
qbK8k7KF6Be1MDsCZhxcQiRe7CkS2UnzLaRlz/ATwa5ZLy9j/wBZePjGMU0a3PbMfLu1OeoI
zQgOnk2N8l1EFY/xp0qvNZyIoKASRjoVPzCsJvFV+V2qEkz1ygpkfiLV4gwjijVT6imxnT2h
uSUAYyxsQo45WvY7CB/ssEYyCsYycGvnqHxPq8BUrHbjnOCua6H/AIWbr4RAPsykDH3Dz+tb
QkluM9/jQRxbS5bjpWdpmmzWV1NNM+8SHK5bpXjEHxZ1+AkMtq4I5+UipYfjDrUZbzbWB1Pp
2olJSlcjU9p1GWUAFTgdOO9Y15bpfWsttKoKSIQQehrzEfF+b/lrp4Yd8PT0+MNrjEmnMDns
a2c1YpCvDLp12dNuN3mx8IWH319fr/8AWoIMjpCnJdgtQal8QdG1uHbd2cnmAfJIvDA1h2Pj
C3h1SGS7RvLjPDn0pKabMZR1PRIYltoVhT7qjr61IAOmOB6VQtdYsb2NGt7lHBHAzzV4Efn7
VZNmZet5LWi5+Uydz0rPI6dQK2dUtWurFwgzInzLx0IrAa7iVSZpFj553HGKV7A0yK7tFuo+
CRIp3Iw65qK3ukkZoLjCTr13d/pWfe+J7OA7If3z+3Subu9Xubu8W4lIBXOxR2oc0hKLO7kg
jkhdCvy9zmsq0i+w6i8UzEwyAbWPT/PNc7Hr+oow/eI0eeQR2rUHiPT5ott5FIWAO3Yc81Pt
YlcrPR9H8YXmk2ptZkNzEB8pZsFRVLXtfl8Q6lp9vMRHbRyiVlJ7L6/nXBWviY+U4aIsF+6W
PJHas64126ub1pmiBjK7CgOOP8gVLnEFF3Op168/4SOcpG4+xxblA6b5ORWz4N1l9KjguIlG
6FPIuU7nBGD/ADrhhq1xJGNtoiH1Bxg+tNt9T1C0vHuY9o3gBkzw2O/61PtC3B2PbxrvhtpR
dEzMrSGUwY43e9ed67q1x4m8ST6hECtvBH9nt1boB3rnZvEF9cxNFHDDHnq3JqvBLd26YjuI
0BOSMd6iTXQcYtHQYu4xjarjtzSb5OklocHuMGuel1DUSwVLlWz/AHV6UzzdXY/8fNQXZnSC
W33BSgQd8rUqxW0mSiqfpXIT/wBq7fnuhg+1Vov7UD/up2X3osgszt/skWc7KX7Gp7uPoa5V
ZNWx899ila61GNcnUM0NIEmdULOTtcOMdqDbzAf6wN9a5GPVtWLkJMGx1JFWP7a1NeGZSf8A
dqbDsdGYrlf4IyKaxVP9ZbAk+lYA8Q6gOCyYH+zSnxNdjujfhQTZmcqEIWSItIerNTkiuCOH
2jvUjX0jjCqFX1xVYyM5ILH8KLj0HvAg5eVm9s1EWtx92PJpRA552n6k0otscs1AEXnheiY9
KDdSY6GrHlRr7/Wo5LhI+MDNNAVxNJnnIzSpMwf5gT7mhppZeFXb74pohbHzuT9KYiV7pd2F
XJqMm4k4xgVIiheFjP1pWJ9SKLjuQCD1Y04Io6CpOW7ZpCuBkkfSi4DSxA7/AIGmbeeSfzzT
854FLsUDJNCbERK8iMfLd0I/iDYq7HrGpxqANQueOmXqmWBPFKvNVdhYunWdWOc6lcAHqA9V
HmkkOWZ5D3LuTRkemaNx74H0o5mKyGckAdPoKcISRnH40eZ6Cnb3bvgUr3KsIAq9c0vf5UI9
cUmF65JNL5hxgZFIBQpCc8fjT1l8s8Lk1Dk5604OPrQPQn8525LfhTfM57n8ai5J5Io4XpzU
juiQys3AUj1pMkHJLUzczUfU0BdEvnMp+UU9bqX1x+NV92O9AbNOwXRa+0HuzN9aU3j4AAqo
T6UnJ70guic3EhPt9aQsp65JqEAjvml570Bcf5zJ90dfSkMshPfnrSZpwfAoC4uAR8xpwZFG
FH6VDu60CbGfkNOwF1bUAfO5PsKkwq4VUooqBjGEwPoPWoHkAOM7m9qKKaigI/Kml5JwB71K
lsi8kbj70UVVgH4A4xx9ajfaDRRSsJjC7t92hVJzn9aKKLE3GM+Dhck+1MCknJzRRVJDuK3o
KaATwTRRRYVxwi44o2Fe1FFFh3E2uenFAiJoop2BMdt2dAeaT5z2ooosUGzvSbuccUUUrCY4
Rg85pcKtFFFhJgBuNP8AKwOe9FFHKhsCqgcEZqIoSeeKKKVhXF8kmlEW371FFOwJi7QOhox6
c0UVNihdjUm0iiinYBCr9hS+S5GTj86KKEhXFEIHORSEr03KPxoop2C7P//ZDQplbmRzdHJl
YW0NCmVuZG9iag0KNzcgMCBvYmoNCjw8L1RpdGxlKEZvcndhcmQgU2VjcmVjeSBvZiBUcmVl
S0VNKSAvQXV0aG9yKFNhbmRybyBDb3JldHRpKSAvQ3JlYXRpb25EYXRlKEQ6MjAxOTEwMTYy
MzQ4MjArMDInMDAnKSAvTW9kRGF0ZShEOjIwMTkxMDE2MjM0ODIwKzAyJzAwJykgL1Byb2R1
Y2VyKP7/AE0AaQBjAHIAbwBzAG8AZgB0AK4AIABQAG8AdwBlAHIAUABvAGkAbgB0AK4AIAAy
ADAAMQA5KSAvQ3JlYXRvcij+/wBNAGkAYwByAG8AcwBvAGYAdACuACAAUABvAHcAZQByAFAA
bwBpAG4AdACuACAAMgAwADEAOSkgPj4NCmVuZG9iag0KODcgMCBvYmoNCjw8L1R5cGUvT2Jq
U3RtL04gNTAwL0ZpcnN0IDQ4MTcvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA2NTE3Pj4N
CnN0cmVhbQ0KeJytXW1vJLlx1ucA+QH51h8TIME2q4pvhmHgEJ/jy8bJwndGYAT5oJPmdoXT
SovR6O72N+c/2KmHU63tkaY5rRrD8DZvZqpYLD71QhbZKnEYh1KGkociQ0g0FB6I0lDDQPp5
pYHLOFQeROpQxyESDTUOUb+oaUgpDzUPWfS/lEkIQ63KLg9hVKKobJTpSBX/DCFQ0AYPgfTb
MOpXlKM29P8sSRv6tQT8WBnE9puijaz/jPppivpP0E8z4yslKMqs6IdFZS/aQU34BQ00svIM
og2VPIQ4UIjKPCQdG1iFjEFqL6EMxIQfV22UJttAIvpjFZZEhxN0xBSj/phUNUmZBVLOKUN+
5ZwZVMo5q050RKo39EXKuUJaHT01wVRqHvXjwEEbUBKrdgNGriyY9nrQRlLOOgBm7TBw0gYG
x3ngJhiXgZt2uGoDShHlnHQoqj1tZOUsyjArKbhz1nkLogyhpyDaRdXvg06ajNCwFG0U/CYP
gn5U+YMQpizqb0jnMURFAEOrOjZhKF3xINK+ioNEzHEUbRR8onwSlKBfS26TqD/OWTuN2ldR
JYWkfAo0pqOVCiUkhdXI+IS1AT4Kx4ieQwLwMMCUtIHhqEIjqwgh61eiGg2paKOohDqvMarg
IYchJp3qoFMVU1aGCreYVQSF0BBLwG+0i5LBRzlX1U3Q/0gjUKoaSSMYKgATlB1Us4ka8Egb
yj7o16nhR8VNAtyqilMTQ8GUmhglqJ1ADJ3ylKA6tROFj4qh/5HbANXcMunHQTWSCWhR4GaG
otSEMoOhml0WTJwaXo4wFpheA4AaX25dKF5z0lHCwjKQSfq7DGRiOjOQqcYxZCCT1AIzkAnk
FSATYytAJulICrBDOnkF38NsCpBJSlmATIhbgExSPRYgk4KaI5BJanoFgqnZDQXIJDW9AmSS
SlmATEynKj7CItVlKHaIYM3aIcHHjCovqQ3WMYGzOp9mZKrriuGS2mBVs9SGuiCG1SoEK+tU
kxpalQg/pg4sjnnv0GL7Cm5LYU6KmJpHfKJ8MpSgyqoFXahwtcD/KdyrMoJjgEODymB/4wg1
qPWow4r4DN6IGq/m6DJI4QIZw8SEjYJRAVyjKDpJmtdDX4LfRZ1dis2nKQeC4Yx5737Q0jkl
gEVNAhRwlFXFJ+AmAKkElCmbDD8FdDWPJWgpqgmuK0DyZsjqj9AbUMhqVpRAK/CVqblKTB8c
kBox3B34JeggwX9myKxU6jdHSFrQgl4TOMOKm1dV9IGioAVeBa3mPjMcIqyCMpxlgk5z85/6
a2outfWBuEBZbYlgtlQEFOBcIR8igg4DFM2vwq/Df/EIWQp8JHwrNbcZWiiDJ4WOCS6QGdLD
pnSKlAt8DUtz3fDKUlILfuqEMXJYrKpKOcPxcFI9qWeHQ4aea3PN2ich1HBRNBCinvpIOH70
0SStcMYjAk+Ffx4xM7W5bIUZIc4ITJ1bEMTcMgKk6JC0FdEq+Ax+W1Q2hncW9XPagudWvzTg
t9pCzIaTkgznj3AniMy8d/U6owxHIxXxCAFKqupEFQa3r4jjAA+OOM3wKBEugOF7I+gY8Tmy
jgE2py4/I2LB1Ue1NibEjNR+h1iRVJ8a4RARMDY4XAW79oHIFhuK4etiVc02Z5fwDSOYJNF/
GZFeIwkoEA8wC83dauKBz5CyZAS0FjbKiKCJz4rOUYtWqgyVBYEwVVDALvOIUAqbzmMFBTw7
vDDDkpsbZth588MMO2+OmGHJzRNzCxOCfmHJ6otB28KLWhPDpnNCv7DarGIN+0iVW8BGH7ki
hqOPotbJLVhV1TvDpnNV9DPsV/MbQYhHS9HFsN+CmMyw6dIkhQ0W2BXDpgt0B7vWFlACq1Xf
rH3AutU5ax+w1RITcoYWuCJa6E3VoS1ErIxZhf1qxoAEAlxgeQyrLRWzCkuuo9out2i1z0EQ
gRAt4Ia1lfE7fMZIeWC1VQK4JLTUrji3uBbRRwtsbbZCy+S4ZZ7qSkbkoAhgI2QuLaYpHhne
YYSHw5xoeIOuYLkjtaw1tzQQFAhs8MBIW7Sl4+cKzpGQCiEiRuXPLUgmpFAVfWSMt6KPDMTC
a44F/dYWFjG2mluGCX7oowJNsHr1xYLcCjFS7UrNHq2MfKuFSx2hwG/DnWkLQRUIEXjNAEll
RIBErEBOoVFU0d9iCMxHW+gjKf4kgLMCemgeXAHYMjgEV+RpSIUDQj20ri3Vtuxz4JbpIXgi
DRcEaEJKJS2OIhAL4g/ByyAj1xZSuZY2S/sW0VVUEwIfqB4dn4Efgr0gPyakIc2nqltHOol+
4QVg1xqZkRHCR6srbaklWhWfIXqOLd0cEaYJtMjSkWsJtxiOUTKCOHyVOkZE8RHfIowLOMML
c5OKW0SHBPCzCmBkxvhdVlwI4oogN4Y169CgSfh8QbwTafE7gB+iNrCszheRnGNbEGkLS6OW
BURoHPmVJJ0fQYwTrI9aJiKZkCWjD0Q1QeIiRUCLPir0jPitKgWXgnwAI0cOpRmM8kOsjsj9
BflQRO6nTh+xHzODmBThcwW5SYT9aQaOLEA1C8RrS/Hdso/YJEXci4i/guQnJsx+Rh9ZtS3I
YXThpX0gC4jwAtJyCXgByS2DwFy22N9mS9GtOsPsq51rC8hGvpeQ4wgsOcH/Cyw5wQcJLDlB
24LombDWEsxMiu1bZBDIh6S0/AJYg01rHo+VAzINWCO8iLaUF6KiemzFhcCmM/yGwH7zCA3B
fnNb88C6M5JoaATphtLWlodg5LDuDNuFPNrSGWg5UdbFxYCsWzMS5RxhyblJBdvPTVfwB9pQ
WmRbuTJWNMhI4JHgezUPUay0lLTAniNsumB+4j4jUcuJsNUCjxRh3QXYjbDkkrSnCOsuGmi0
Bc6apWONhBaWMi0TQlyNsNWCuBph3RWRHXEUa1LlAjuvbaUEO69IkOM+m1G9R1h3RZSDPJrN
qFVEWHcF4lreWkEXYd2a3GBx1jIcna1oy13tA/Zb4ZEibLoWlS3C4jV8aB+w+KqdaKvlPzor
ESvbEb4pIkKPWM5GeNcRy5kI/z4iI42INSNieUREHeGloyDrabOFuDxCT8jetAXdYz2svl0l
gH8fc/sWfeSCz9AHrDEi/xmxBsFsawu9RWQzo44mxpYxKR7hWTQbgk4RuwL8BrYItFXwGXIs
5AsxIuuB90XOqy2MPCKfQu9qfsi2FBctb1AHrN+mlneBcwJtkwpxLzRdtdwJWWTLOTQM6dgQ
zwi+T9MttCo443eQIyIzUHNULmrT2sKiWJGiGY3OFHJ8BmSH2PK4Im2BjAwMI0JsJXikiGin
EwKKgpb+G1s+he0CIEBbagu6pkYuhn4RURm5X0TeytxW3MjU4PURxbSldor9As3UYBXIKhi+
MyJzYawIYmk5m+IsIkPkNlsVfTRJEec1lGsfyBY0MPPw61+/eYetrHH445tv33z76fLuzXef
P23efLvbPl7tvr7dfHzz1dXu8fL2u80vu3/83f3258vt9fDt5mq7ufo83P8w/NPw5u3/DOP/
Dm/evR8YfH7zm7//u9ex/W672bz9+g97VuEoKzZWvw8vGClNwbbcH7Exp4+j9GT06O/7+1+O
MpElatXluoH85a8X/35xf/F/F7cXw8VX+u/PF5uLuwtTEp3F+1/2TPgsJv99c/Xjds9Ijuqp
GqN3xzSkSIKaK+0fvKivtRP/7eXd9fbe1BPPYvWv99vNbnezZ5XOYmWazmcx+e328vPu/s7G
Vv4WAtWzmHzzX79/axZ23Fr7U7+3MPVZ7ZH3j7J/NMq2h70ACGxVr5Pyz5uf3m/ubj6b3sJR
b7Ce3W/vr28ejNVR81vPyiYhHDXA9Wz+889/MkYOA0RZYK9qtqfYMy6rPq1V/c3l3d3Nw6T5
o+a4ntt3D5vbzY/3j3dP+j9qlOsZTvo/apbr2XzR/1GbPKX/bPou9jToh0Xor4k8e/dtpjxh
aRrTMaa5TKPdXO2OxrI9PvajOaqwMAH2dzfvH7ebY0zMTex/+SrK4KYkNyW7KcVNGd2UyU2Z
3ZTFTVn9SDgDRH4UBT+Mgh9HwQ+k4EdS8EMp+LEU/GAKfjSRH010hk/yo4n8aCI/msiPJvKj
ifxoogU0yRQ8j0b1J4I3bweqM6q4Mhd4d7ndfR7CsPllc/W42zwMj5+uL3cbW2gtYE2mhPt4
hiCzoL04nE4uYNKf4YQsNRTpCJJ7Y0Dx4RTkuyMonZ67+RUvmEtcm13renJ498d/sxyWF0yo
z24OK45rRUeZqek98or566kvjsYoLDOKXRBiD/CUMXYl6EAwpm7PqPec03Pu9Fx6Pcup0NDt
ti53m7p7K3OwSJhR8UrE/qm5nOEBO2q7XxlwZcH8+lwPZOEZFXWBm2zZkTqz/qSEnhbTGuT3
Ehlb9+zl9afzC1afysopubn74X64/P7+cTdNx0I87XM8mI40o+o6X5QVmxbyuEIL3enouOE1
alzwIHktsl+qcSHK9zkeqHEW5XMf1dlQndeE054a83mojgt+KbvRGBcy2T7HuRojzaj6aMyG
xnIuGnMHjWV1PI4zt7a6vLB3sQ/DzbQbGxc8hK9gERe8w1PN4rhmrWaBk5CnFdPTbOkkeqtW
cpa4lDOBfnzlcHKrCgeQW//BLDaYYkKyp+25BdtzCwZJsjyJLGyQ8SFLgMn4kfEj40fGj4wf
GT82fmz82Pix8WPjx8aPjR8bPzZ+bPzE+InxE+Mn9nux30XjG41fND7J6JN9nowuG79s/LJ9
n+37Yt+XTi5Vplk5uftH/GrK4KYkNyW7KcVNGd2UyU2Z3ZTFTVn9SDgDRH4UBT+Mgh9HwQ+k
4EdS8EMp+LEU/GAKfjSRH010hk/yo4n8aCI/msiPJvKjifxoouNoojBtuCylhXuCw90/ou6e
4Wt3/57LRFMidDSpI5rlUIvD6SRzJv0ZYN0nDSbnwhj6m0dfdv8WBeiOIHZ67m8eHTcXorVL
peO7f69jN4fVbPfvhOhkSSTxuGL+uurLNoFlWY3cBeFs988lAS9DkLi7ppnt/vl6lk7Psdez
nAoN3W5Tp9u8Fiyz3T+Steexurt/z2Xpcz2QhWcj6G5bk61OSHqznldoUdYgvxcri1lQPYuP
+AOn+AOnHA+cJN1jKQdTlmdU3cDX29mQhVC6muPBzoYcN2aS7k48WQGDYicGPSmmC6nzoEC2
0ibp+NLY3UaM5/iVeSXoRbfdGBxPpavdbjsBuF+9iefE/Xnp5kW3q0PubIOP0tqq36fH729v
roYfN58fhsvds02+57Ks5np1f7i/52ZkJ9figo9YP8zL3Yfh7v56Yyfq4vEoT0/FmuPmuS+v
tPur+6fYs4ebNQhIy/a+bt1iOVQ6L5JE/+I0+hen6binOL39WWwb0A5XBztdHaptO06nAu0E
brAjuMHO4AY7hBvsFC6ufuyfFtjtyCjZkVGyI6O0PzLa7rDvn+Ys7Wgj2dFGCsYvGD/brsXl
9f3T+Nm2Ldm2Ldm2Ldm2rS1/ptXHlFBPyeyUWk6J3pR0tAvh+6fRiX0vRm91d/Ook4ubINuu
Wu+fxi91gkGawuTpbdH4asrgpiQ3JbspxU0Z3ZTJTZndlMVNWf1IOANEfhQFP4yCH0fBD6Tg
R1LwQyn4sRT8YAp+NJEfTXSGT/KjifxoIj+ayI8m8qOJ/Gii42ji8eQ2wH6r5GBblMe1xza+
+mG32T7bBH0uwVpef/nrxbuLy4vtxe7i88VwEYZ/uHjQ5+PFp4tr/Xx3Me22Hschj93FGVsq
w/PbL4va6mSuNiB/lLVcy+RdEKS/93nKnLri50633bU6nzLFbrd1udvQXYPwKTPudRtCp9tT
B4afbGO2t8th7YHhbz5+ut/uLu92ww/32+HZbdhfDZfT5Sk+7jDWd/Rwf38Hdo/z/cFBe7n/
abPdXE/dHHcu67vBhvmn7f3V5uFhc/3PE9cFv7Oa6/XmdvNURzke104wm0+UjA4RbnSGtvcf
h92HzbQztuBi1k/J7qk4JMeNlcOJwsp+JcK2MmJbGbGtjNhqN2wHWpg63iSsOEpuY/O7NVvi
2bj8S4njTubk0piyLT3tpAtlWwra2T7KthS0EzBkJ2Ao29LPDq9RMT52MobsxBPZLTkqxs+O
ZFExfsX4FeNnS3Wy+3pkS3ayJTvZkp1syU62ZCdbspMt2cmW7GRLdotRU4iYfPbkRKfJbm+B
WgQErb0A+dXdsPnl8uOn281wc3v7+LDbXu5u7t4PNw8Pj5uH4eeb3YfDS/370pajJ43+32ns
3+j/3l58ffEHRP+DO/5uzs8878H1+hdMu4UjtnobWwGPDwp4z1lN9t0zOkqLDE4ing+Kp896
59Nn8KaL3eHVlMFNSW5KdlOKmzK6KZObMrspi5uy+pFwBoj8KAp+GAU/joIfSMGPpOCHUvBj
KfjBFPxoIj+a6Ayf5EcT+dFEfjSRH03kRxP50UQLaEqnFmA8HeWfb06ktUn41zfvP+yG99v7
x0/Dx83H7zfbh8OtihfynLgoN3/FwtJQetF+XjTzhEArwpmcC4KcOoPypFP+cgaF89ozKN/c
7Tbbu8vbfWlxOoTCCya0mu33t5d3Pw43dze7m8vbW8vReMG6nlYRx6fJjrxzphVa6k3X/FKV
a7osM091mc/J60xfpktmVGtz3//YXP40m6YFx7Ga3Tc6QW83nx8ONy5esOsn0bbw4vkln0W1
dOenY49r5sdWhpyXzfJ0Es623LILH2wVSbYLH2yVSbYTS2wXPtgufLAdqWK78MFWwWSrYLJV
MNkqmGzHVFiMn10MYTtHw9H4WaWTo/GziidH42eVT47GzyqgbHV1tgslbPcszcFNljPN0MLs
ra6MMr+aMrgpyU3JbkpxU0Y3ZXJTZjdlcVNWPxLOAJEfRcEPo+DHUfADKfiRFPxQCn4sBT+Y
gh9N5EcTneGT/GgiP5rIjybyo4n8aCI/mug4miScqozykQsjEtZWM1ddGHkhU7eEKfOt9cXh
dDImk94fzOxYl8m5IEg/+/tyYWRRgO4IUqfn/otqjpuL9C8Onbww8jp2c1jNioonRBcr9sj8
oo5PfcUmsC6rkfp19C8XRlwS0DIE5cRdoy8XRnw9x07P3Xq7nAoN3W5zp9tTR52fwDK7MCJP
a5uzLow8l6XP9UAWnlF1S/diqyPh3qyvOC5s0vk9l1VsZF6x8fBZsHpeu4LGCzq2Hy93NyjZ
H3lrzOsYH8xKcoizubvafv6021wPj3fXm+10dsBkOm7n67n/uPmMI/a7DzcPw+3m8ofDaycv
2PYvbdlCWmwhLbaQFlkzo11oLYeU08t/qxazVYnZqsRsVWK2KjFblZitSsxWJWarErNVidmq
xGxVYrYqMVuVmK1KzFYlZqsSs1WJ2arE+BsL+6dFbDvYLXawW+w0lNjBbrFqstjBbrGqstjB
bksvpug+BawpWEyue3Kkk1G3vymyf3acr6yvVcZXUwY3Jbkp2U0pbsropkxuyuymLG7K6kfC
GSDyoyj4YRT8OAp+IAU/koIfSsGPpeAHU/CjifxoojN8kh9N5EcT+dFEfjSRH03kRxMtoCmf
rFUeOUgtT6WQv812wXOZuuslOaiPLA2nlxkdFEYcwcyO4JmcC4KsfbvsogDdEZROz6veLvuc
qv/6udPbBa9iN4fVfLugL7pYMirzl7S51GfZrUm5MIK1b5f1SdCBYFn7dllfz7nT86q3y/q6
rcvd9v9yzxws8+2CunbLsr9d8FyWk4XrJ1lm2wW1v8FpqxypnVmvazY66xrkdzyXLcNMXj+f
Bauvr3mfZ3e74FWMD2YlOcRZt13gHex0JX/3YfOwwYbBT9PldVkIyrW/bWqLYfyJwf0z2HPN
rHbhtRxWTm4ZiFX6xSr8YhV+sQq/WIVfrMIvVuEXq/CLVfjFKvxiFX6xCr9YhV+swi9W4Rer
8ItV+MUq/GIVfrEKv9gpI7Gr/pKMn92NFjsBIHa8RewdxGIH8MXO31iKMUX4KWhNAWNy35Mz
nQy7/ZHI/XPZAcenS2WntwzyqymDm5LclOymFDdldFMmN2V2UxY3ZfUj4QwQ+VEU/DAKfhwF
P5CCH0nBD6Xgx1Lwgyn40UR+NNEZPsmPJvKjifxoIj+ayI8m8qOJFtDE3TeEPxEcbhnE/kvk
Xr1l8Fym/judeJ7YLA2nkxmZ9P6QZMcn40FR5rkg/YX7bMtgSYDeCA7qSc8YPCWH/S2D51Rr
F2ALWwavYjeH1WzL4ITo0ZLROP+DQj71kTHijhr7C/fZloFLgg4E+y+jm28ZuHquyz3HfqH8
VGjodTt/dd6Lbk9uW05gmW0ZxLh227K/ZfBcllPXuL/IwjOq/svvbJUTY2fW44rNzhjXIL/j
uWwZZvL60/kFq+//ZaHXbBm8ivHBrCSHOOu2DLyDXbFl8BwL3eARbTEcbTEcbTEc05pZ7cEr
LYeVk1sG0ar10ar00ar00ar00ar00ar00c7pRbsLHu1ufrTXr0Wr4kd7yUC0an6042HRXjIQ
7dxZtJcMRKv2R/urGdGq/tH+aka06n+0e9LRTgFEO30T7a9mRHuNW7TjQdFe52YpxhThp6A1
BYzJfU/OdDJsfU6fdxzw07Wx01sG9dWUwU1Jbkp2U4qbMropk5syuymLm7L6kXAGiPwoCn4Y
BT+Ogh9IwY+k4IdS8GMp+MEU/GgiP5roDJ/kRxP50UR+NJEfTfQCTf8P9sUbmQ0KZW5kc3Ry
ZWFtDQplbmRvYmoNCjU5NSAwIG9iag0KPDwvVHlwZS9PYmpTdG0vTiA1MDAvRmlyc3QgNDkz
NS9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDY1NjQ+Pg0Kc3RyZWFtDQp4nKVdXY8duXGd
5wD5BwnQyFMCxFHzm2XYDmIkBha7D5vYb0EeRtJdr7LSjDAaZVd/3s45vOTVnTuXNWw2sNqu
mekqsoqnisUiuzuIX9YlSMQ//CeLMRnXvBjhr9NivSxxtYszHlezuBxxXRfvA65hCWbF1S8h
W1zdEr3BNS9p5X1pSSnjGpfs0hKNWQSyIngkUR7aWx2YINysaDUahx4kiDR2MdaibZNAoJfR
xMW4CKkmLMZbNG9XEMKbISdECkbHo0UPLOREdtVCTgqQjN+aDGERnCaztxaNiuM9UHNdyRVB
BEqWxRqIjzaDYFedXax16I8zi3VQJLoVBLvqPKzkwAVNrM+8BwJDIBcEUmrEn23MvAeSUwCX
h8AMw0UPrpzRQw85kmIxoVvJ7lfYnUZwGQSN4OPiLI0QMCSOPQwOhEByAFegdSHdhQSrBtzM
TsWQFvQUTcAQLgnZA0Yykcsv4KbkvPiVg+wTCIGCGGEPsy4hgrCwRIwY90hAwNY+YXRjdCDw
9xj94jOsHnlzzmBHL73QYhECRXgzoFXMG4E1g6GOMF8wCTfjXyjDnSwIWgMKBIe+RFg/eKIJ
3Q2ebcFGIWD0YkogMuVAMi0aEyQnDmWG5IT+RnQlZAAkYshDJhrBEIRwzJ6Qh+RcsIz/ETGG
RshEK23IrlgMfuS4WppFLIcTkouNgK9ICHqqXIYBQxQ5VARjFFoE3YwEd2IPaYjMJkrDaKJ0
VxxdZuUPlCz0H/7PL8kAXwmelSyMkDDAycIItH5ybi2Oljx/DW9MPhpw4LfB8maIoDNz7BNR
AGHwSPQ5wb9SEooHQwaIEvwrCfqc4F9JoFNCL4FQyMBvM82S4D8ZfoUumAWjXToF12bLMHF2
QEECCLLHULKZ7DPvgfsHT66wZHptwuBljlUCqnLy5ILkxK7Cv3IGrBJ0ywK/SZCVhV1Fe7Ii
TiW4lRA/CX8WWyzhQQBxCUMlDjIi7hNPs8Gykk0xEgigKcG/RHAjx0OKpvBBs67somckMsWm
gRQ1woia1dJqwCOoTI5cQhc5ShDDaNKtzeqBowRfNGugxeCnoDjMgW0wjqTANgifFNgG+VJg
G7kMGNvINHJgGwLLYBBLfEQbgLRhI6DQBklQlhRtFhk+S0/Rb1AAJb0TtoLyCfYBRXDBJTGe
kJ8S5cEH8TsG/5D5V7RrGBBSKuH4CBpScJSU2G7mmCXKE/Y5sQ1ha7AvAidbw/AaawgNOB2o
xMmAwdxi+FJmfHcrwWdI0UKwq0EktQQkKbhKypQX6AtAkrEMyClTHl0rZcqjhgm2gbrAFTBM
inoI5Qk9Aj8ZtxJ5wBEo6gF+4wydAh5tnC345xxTrAZXNs654goLzUfeTAqWSOiZcYFQXcnL
+TNDF85PADTuNa4geqUUymekN5g76VFsV+glK+VJJgfkIcYB8UCe8YbOBMcEBf2zWcuExzbQ
F49O43eOFCxGaBvvHe/jxBjoUpxPMbz0VvTPc7bInBt98TxOhZ6jkjk7evgdqDKXYhRymUw5
gpwtAQ2OoCsURo8WNoExJcOrMTuwV5Z/LdECbYOChbKllOxKdCBFLWEvE8QzGUC7yCLA4ThR
r0BwhgYmmhJPAin2D0jBfI7WmT6Aop0d53gHz8mYXABTtovegmLv4dsGcyJDD9sIQEOmd0dO
i0StiQyLmd4difRM747UIdO7EfAjwxYowT2Z3p1KT+ndCLZog96NAIo26N2IjmiD3g3jog16
MmIW2qB3w3T8K9pFkOFfKc8DXZneDbdHu/T4xDQh05MTI0Omdyf6c6bHJ45UpicD/OCgdwOi
aIMeD+hBD3otIEWOxFSHFqLHY7jRe3otlAQHPR4mZhvoCwy2MgSTghdzQjLoLqMx+pJL6kav
zZyiMz0+M1oyd0AWBfRnem1mm8SRyZzyOc2CIkro51KsRj9H1MZ99G7MNORlCmZhnUzvFmd4
H5NPx9Gnd2MQVk4IoALHjd4tAf3N9G5hQkRfN8LpL9O7hTEt07uFGMj0bgR59J5ei/keHMJE
bwWSMkYCFP6C7oICxkqKalfGA3KBQo8EPm1X5iMZWiHAGd7nSUEHWZlBBs40KyWXBHelZKY6
Ao/HJMUpamUb9HExbINjC5OA4nQkhm2IMElm2rkG3oc2GMhBJVKZ9/GvFuMhhnkqe4VZEJTH
zwLvBiWk0IahBwh0gT4YM0GMYChGX2Bra+hDYtkG+8G5BlTkrAoOKEzJgRQsxphlIYb3oV3L
+V9KXmwxUsLEGK4KXmbG1pcpOZNiX5gb28A+MxW2zJ6Z84Ci/ZgVW0ZQTNmkMLbiKU8SedEr
5BiwAfNprEQoBX12zIiYdIICXoSZtOMcTc+1jtGX0QYU8CeeUmgdgXeDomR4N3yWWgJloIAG
gWdY5L3ggHdbb2mXwMzecixDSfYtOQIpIFMwTtZzQQRggkLwBJVJsd3ANrgOkcg2mJByTrK+
JCSRbXCOkVhWD9Qysg2ON0eC0yDaAGptWJnvRC4uViBd4PE2lJ6iZzZYYhLYB0U7458NzBAF
ngwKXiIYHXgb9OfyC0sUy786UrRGojwuQ+BCCwcL7Sa2y/mds7sNuSRRbENKa2yXLcHVsMBZ
mZjBky0cgFmXJYX+Iu3iOogYz1wROVooc0nkaCGMtkUmTQ7IQ6BmG5kUkzihPC7WRCiPeTN9
xEZmT0zfASHqIWWJJUzp2BeOo9CnkVKTI5OiJ3NRi8mKWRbdO9FsIFeSsfwW7Mg1S0qIthMX
HyAtyeMNlBCON6D5FI83BJLlBjpySscb2IN8vIFdyMcbKFfKDaasA8sNjAS4tdwAuZjjyw2Q
m+3xBk/yeAOE5WMn6fCYFZksMgpkrgFwAxrG/ETdGDkyMzvcwMUmV20g2QRTe5BsoiROK2NB
LvPayvCRGWKY8pJkTF3p5rIe01+0BhgUNiGZCxtaE+vr0t4iQhS2SDIVNrQGH2SyTC+GS1EC
A4mwcmDojyCLMAYGSeUGLpilZGgrHV0YwEBi/bpy9EpSDDKVG7DyXVlHAMnF9NFmXE6vXKMY
hn6A0BW5iattZmorV86IurwB/XdrLGsAz3tTGQCuuteSC3O5iDySqQ/jtFvpr8z0SXIaYrxy
5jiagLFDvk3dYlnSF4W49Ea2WeQ6FlhckWtIMulkVsQEtawb0Jph8guSbFw0cjVBkkkDphyQ
zLrEk4tzTmncIaodlxsky8DDLM4ekQHPBcmZeYVS6AsTKUxVJEsXECYQ7MpCBDGAqTH1SaxC
lGQAxgDJmA4ykyy6Iy64UsLgmgakKQUetAMyFbKUL1whWcCwhQ1BhDl3IdGa80e2SPLIhtaQ
dxcykzyysbVY2IStpWM5ia2V9QjWUCBLgomJlmRhE18qJ4VEa6X6YTjRgTyyQa43rtamnOdK
0zBXAFnWSKyLeS4SfvObV9+XOsm6/NerP776w7s/f344vPrTl4+HV398fPj85vE/3h8+vPr2
v+H1/7O8+v7PC3CNW3/3u7/9m3HWfJ0VXTuy/vHj7d0zxn978/j59v2fDr88/qP5p6XIkY6c
VOV8f6111gbx5xd6z3Ze3/9yXUDuCmBhcUyH9aiDWztyVk0H1jF36VD72Wnbb9TBdOQ4XYew
Vwev6JA26mA7cqKuQx8Kgzqkvg5m3aiD6+ggqg6mD4UxHY797OjgNurgO3KsrkMfCoM6OEWH
uFGH0JETdB36UBjUISo6yEYdYkdOVnWwfSgM6tAPzlx5bJof3PUpihsoqg59KIzpYPvBmdm/
0rbrzIxjzfbjKUsyWrOdiXSsWSWCWRUt/vrcN9isAhQ3OglXoPjOBOb0SdjtnYSdMgk7dfL0
16erwWaVedONxrpmus6c4/RY5/bGOqfEOqfmkSeGV98u3n/l8qOg+cPD/Yfl7v7n5f7u10u1
QifiD8v838+fHpefH949HpbDx/s3Pza5nSg8LPfu84fXh4dPVVonHnod5r7AvGzvHq8afPLA
2PmRhKO/fIhHntbvjk5hGAP5K1cYtetf/rr8QzXq9di5SdRys9z8cHN/84Dr65v3N7c3dzc/
gb7D797eHG7q+IXOWiG08fvu9/dvv1w1WahjGJQ0x7ex++6b6zKUaBVUc181XOgE3WFR6/LD
/QMc8e3h0/Lzu8fmM6GTyQ/L/ebu3eO3hy/N6J0AF/zLRo/V6KlelXXji8ZXJnff1jrfvfq3
haca+NNVIWvtiOLBfiT6+pFlj+LBvlrG96eBdArihzePV5fh8SgkxFyvx7AQ0lqvpl5tvbp6
9fUa6rXKSaleq7xU5eUqL1d5ucrLVV6u8nKVl6u8XOXlKi9XeVLlSZUnVZ5UeVLlSZUjFT5r
Hb21xuG1GnGt4dBUHz8uM1qq3tLdlnq2XLAlZy3LaRlHm7pbLG+I6HhBW1b0B7sGreOQb+I0
05x2mtNNc/ppzjDNGac50zRnnuaUeSTsANE8isw8jMw8jsw8kMw8ksw8lMw8lsw8mMw8muw8
muyOmDSPJjuPJjuPJjuPJjuPJjuPJttBk2wsB9gOtERfJ8lZOaDbey2rEtMXIFtr8h2Mi16T
l7BXB6/osLUm33E20Wvy59szczqkroC0bq3Jd7xe1Jp8WhUojOhQ+9nRYbQmb5/uKzyTo9bk
06pAYUwHp+iwtSZ/PQ6mVa1TpbUPhUEdoqLD1pr89YCcVrXKmkwfCoM6SF8HM1qTv9hXeCZH
rckn04fCmA6mH5yTGa0MXOwrPJOj1vaT6UNhUId+cE5G3fN2L+VZarP9eJrsaDhsoeT61JqM
Hg7t3nBolXBo1TDmX0oW1WaVCGY3os5fnw2TvqOU7F7UWQV1VkWdfynjVZtVUOc2os53JjCr
o87tRZ1TUOfUwHlieLpJkdwoaL6/fXj8soTl8MvhzefHw6fl88e3t4+Hp9sVz/qkQ8kpc9lJ
HdUeI9mlUrOoFark+pnFi2VDPvpFIXzy63itZa9Yy2Oxlr9qeZHnII/XWg6rZcZYy4yxlhlj
LTPGWmaMtcwYa5kx1jJjrGXGWMuMsZYZYy0zxlpmjLXMGGuZMdYyY6xlxljLjLGWGWMtM8Za
ZqyrlZbxt6y5ZZ4te2sZUMsi2kzcZrM2s7QQ3cJlizstBjRnakjooKTFi5fLhXkzp5nmtNOc
bprTT3OGac44zZmmOfM0p8wjYQeI5lFk5mFk5nFk5oFk5pFk5qFk5rFk5sFk5tFk59Fkd8Sk
eTTZeTTZeTTZeTTZeTTZeTTZDpri6LL8slx4KUdflqfz5LDXey2bitIXkLYuyzsYT/qyPLmd
OiSr6DB8EOCiXHgpR89qU9yrQ1B0GD3SflkuvJSjLrRSUqAwpkPuC8ij5fPLcuGlHLV8nrIC
hSEdslF02Fo+78TBrJbPU1agMKaDV3QYLZ+7i3LhpRy1fJ6yAoUxHVJfgGwtn3dmhqyv3EWB
wpAOogRnGS2fX5YLL+Xo5XNRoDCmgxKcRS17u5fyLLVZJZ4OP+FzWS68lKOHQ9kbDqXvA3n4
CZ/qhv761Mp3Kyg65HVnOMxr3wfy8BM+l7XHSzlqOMzrznCY174P5OEnfNo4XJ9as/6ET153
hsO89sNhHn7Cx10UMi91UMNhNjvDYTb9cJj1HaATw9NCZh7eczkWMtMLhczLPqkpXzb9EPVV
HdUeI8BWaiLH7azWz05HVHw/sWv8yjW8IfOfnw+fHt/xCPs3zabLp8Obh8Pjcv9DO35+feYa
b+R4lt3xoO7Ptw9vawP/WqVfn2WyvheU63HGbPsB8qvttEG0IwswbRBzHURltnmpGp3qIct0
PMte3uh0vNYqaz10n3yttvpara0naJOv1Vff5NQqbD3qm0KVVw+Ap1DlhSovVHn1rHKqZ5VT
qPJClVer5nxX0/Fa5dXqearV81Sr56lWz1OtntfFcFtQtkVZW9i0xUFLsFuS2hK9liy1xKVl
AG0WbTNRi+YtIjZ3bojowLnNYi9WpY9W3cRppjntNKeb5vTTnGGaM05zpmnOPM0p80jYAaJ5
FJl5GJl5HJl5IJl5JJl5KJl5LJl5MJl5NNl5NNkdMWkeTXYeTXYeTXYeTXYeTXYeTbaDpuHH
ly6q0s/k6KlxOEuNu73XsqrzB5Wetb21GtrBeFCX/znIXh1yX0Dc+oKPjrNFffkf7U4dolF0
2FoN7Xh91Jf/UYHCmA5e0WF0+X9RlX4mR1/+RwUKYzqkvoC0tRraiYNRXzElBQpDOpxvVT3T
YbQaelGVfiZHrYbmpEBhTAen6LD1MHFnZkhqVTUnBQpjOijBOW3ctXSdKeq0ZL2uQ1agMKaD
EpyzutvoXsqztGazEk+HN4cuqtLP5OjhMO8Nh1nxga2bQ74zteqbQznvDYdZ8YHhzaGLqvQz
HfRwKHvDoSg+MLw5dFGVfiZHD4eyNxyKEg5lNBxeVKWfydHDoewNh6KEQ32n6cTwtCotm/d2
rk9mfMeuormsSjA6dVzRXNYRCCvVj3oGtPazo4OK5CcWjGdcW7FzfRoS/bkcWfvY+dpx1YIj
6xylCnTcmWr97HRkHINf30EiZisGr89GYnQMmj4Gv3Zcs6DZh0GpFVoxCgb1t8edWzCsZ1yj
GPzm7of7hw+33AZZbl/ff35srxC5PrGMCy77Hk9fRzIt61dP30MyLce1XZ4q7/paYoOOd28e
vnx8PLxdPt+9PTwsPx2+fGqyO2FxWPb9D2fvdakyr+fcor9UT+rpdambNVJPsctx86e8Y/x4
VdzBjAQUszOg1OP2YpSAYsfdIZ1xbQzJ4XqeLVa3tFVC8sh0LnanBesDCWI1Cw6H5CBfuYbf
J/fN28Pd47sfvry7+/Py+/sPr+s7hOL1ZFv098uJUzBpR0K02xmi6yMd4vohemiDpxNOnbru
Oh+MaM+4Rlc6f/nr8nc3v7+5v/lw83r5+5vf3iw3394cbr7g+njz480t/r/cvMdvHm8+3dTI
FTtRdrjR27f/d3j4dPvwZXk4vLkH3QR3wu2w4Kdb9HzzVRXcibXDguse/b9UcZ0w69R1odRt
bKmvZpO6nS2+j8Cvw69CeGSRoEC4vsxIXD+4vLhJn2tkyfXNSbk+8pTrG5Ry9ZNc36SUXT2i
4Ormc31uLbsqp3YquyrPVXnVirlaMVcr5nooINdDAbkeCsj1UECuhwJyPRSQ66GAXA8F5Hoo
INdDAbkeCsj1UECuhwLq3kCrr7cadavztlppqze2ml2re7XaUavjtIJIKyq0hXlb3LYFYlvz
tMy95Z9t4m3TRwt65RMcx2t/FSy+LaBf3tS3mznNNKed5nTTnH6aM0xzxmnONM2ZpzllHgk7
QDSPIjMPIzOPIzMPJDOPJDMPJTOPJTMPJjOPJjuPJrsjJs2jyc6jyc6jyc6jyc6jyc6jyXbQ
lDaew7YdaCV150HOn1Dq9l7Lwp7svl22vfWtTh2MJz3DPH9CaU6H1BdwejRp66b+pQ7qzoOc
P6E0pcOT3bdLHbZ+aaHj9VndeZCsQGFMB6foMFqquNzUv5SjlyqyAoUxHaKiw9a3OnXiYFY3
YkUUKIzpIH0Bp92nrZv6l3LUDV0RBQpDOpy/cu9Z21sfH+3MDKIemBJRoDCmgxKct34RyXWm
KP15KREFCmM69INz+SCd0rh7KdFS2i3fvVMa3vqeu+uza/linqJB+c7eLvu1rvaa37qndn2G
LR/20/XYGRdbV3vNbzyi4q/PsuX7g6oeZmdsbF3tND/8zrvLPf5ngtTwWD6uuFMP0w+Q5XuM
2/S4PtuWrznqeuyMka2rveZfelLqyPF0r798YnKb+tcnufKBSlV9qwWpkUeVWl93VCnq/lfr
bKcz+heWnlgynrNtBdL1aap8s1O3pBZe7BCS7MhaSLNkLUa2zvY6M47JfMY2/Ga7y83/Z+2/
gEmnYdIOYdLtxaRtmLQaJt0wJs/OAJRvs45Z8t8Pj/d3t4+nLbvlt8t3h9uf+PO3hy8XBwKe
de4FwDoNsG4IsG4vYF0DrBtJU5RicG8ae/F7S19HyJ2xjX9w6f5hOfxy++Hj+8Ovl9dfljf3
Dw+fP5YR+/zp8LCEBTcUKv7z5emGy74ON/r442mz7afDl8uDDdNifzw8HC4ONEzLun3//v7n
T8vj/WmvkZ2u0nshdlj68w3HulN4cUrgWQNqul++fnyEo2+4rNtY5bvHlVDdZmDru+m5x22k
dWZfnAu9EO1H0+G3xwh1uDxN8EzgC2lx2J0Wey1Q61+8Og8D0ZyzjdZAe6e1Yi8uDUs+O64V
eznusLBfXWz4Twu6OLAVe7FnXM3+ia3YC0bDwq8c2Yq9GBTUcnX5IvnR9epT6eVr5JVoOUNo
7hn7qD7DpArrsG9iLF9Tr73S1vH6o2NPHOQ8Jxx+WqtG5tgLOPrjWuXT7AOdVy0Z91oyNkvG
viVfPLAhdWqROqFIPRgh9WCE1IMRUg9GSD0YIfVghNTxlHowQurBCKnAlIpLqbCUikqpoJR6
cELq2xKkaiX1IIXUtyVIfVuC1IMVUt+WIPVtCVIPWkh917DUtydIPXhR933a3knbf2g1/FYH
b7XkVo9tNc1WFzzV6E6lrlOt6FRsOVUrTsv909r1tPQ6rRxOuS2J02+aHN9+40++3CRHbVVy
elLv5RMdfjurmWe186xuntXPs4Z51jjPmuZZ8zyr7IDEHjjtwJPZASizA1FmB6TMDkyZHaAy
O1BldsDK7MCV3YEruydO7cCV3YEruwNXdgeu7A5c2R24sj1cbd3Osz2Q6ft5+Pv5Oq2rgZrJ
PdnSuxBhhp+TuzzzcRL0/7u+k9gNCmVuZHN0cmVhbQ0KZW5kb2JqDQo2NDkgMCBvYmoNCjw8
L08vTGlzdC9MaXN0TnVtYmVyaW5nL05vbmU+Pg0KZW5kb2JqDQoxMTAzIDAgb2JqDQo8PC9U
eXBlL09ialN0bS9OIDUwMC9GaXJzdCA1MzQxL0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGgg
Njk0OT4+DQpzdHJlYW0NCnicpV1NjyTHcZ2zAf8A3co3CaC0lRmRX4IswIQs0BAgCKIAHywf
hrtN7oLLmcXMLKX9kf5LkuNFdTRrpjejsrsOHMbWVEZmRL54GflVE8IcpnkKYZ6nHPD/PIVY
IaQpzvqEp5gjhDZRbBDqxLM+KRNnEiHEKRHUhDDlWZ+IvswQ0lQIegJPddYnNNWcINSpEfSE
MkkD9JFUP2f5ESLKEFRFURzRrhCk9pgLnokiImiL8grP+kxUcUbbo7ycCPqi/EgNLUPLc9L3
5JWirY3yz9K0IilbE8qirU0bjFdaQ/sIvkgwXaqM+jKaFuVFSHWKMUMflSmStpmySA3t4zBF
VtfyPMWkbaYmUkP7WLRk9S5LiQJHBJbairaZpbaatGycYgtoH0ttTeuVX9DMeJbmiRaHsfRR
qKqvSG8x2pxoIoLDQsoiFX2WJuKE9xJPlILqiyJV1CuOoJzQPmk4lYBnYiDV5T2poxbVJ3U0
Rr1iAs/ovCCdLt2hkqBD3RmkU1jcAalNTFqizBOz2luCSOrnIlqy4kAgIF2JOgQpvHhDkMZV
e7CItCBHKuKlj0qa0lxUM09p6aNSRWqot4YpxQR9FVBllWhKrF6TihJrb1XRkgpaUPOUsqJJ
XCKPYLm4LlXFQSlTaoBZqFUQr4HSgP2EZw3BpKFSm0ja+lqmHNF6wDuTtk+6MVdts4AhN8Vk
k9+2irKtTGXp31anEhTjYkyBcyQg5qlEwBtRWiJ8FSUoCwmkRKKpaIxGCbmi+BMETyXFsART
SVUlqSOzSlJHmVWSOoqWkI4vVUtIXJeqJSTUi/Z5RByr5VFDeymRphqWElmkpUSZalxK1KnS
UqKJpCUkuqv2QpQflbWERHJNWkIMrFlLCIBrBuqiRHwtiO4okVyrWimRXGvRZ1JvI3hIoNdm
kFEUxzbFZJROaQhTecZTg3NEIpGKPotCSBLOIpWpMZAYRVXjos/S1BJQHCWSW1amlH+2jIiK
UqyJy/Fb0VfRW1GittWqz6Qti9cYDDfPUCiBLqJaDEDOiPKgMTujE0SsEKs+BXKWvgUhzIyg
jBL4IoJMFdxzAqwisDprHEWEuAAOTVXsFVINaENVAxDlcwWnKoXNDQQVFeOz2qCkOCMQ4kL1
6nmlrKhWKLfFrNSclRihVwme1QodBrigvRpPSf2vsE8I3Vg0utWKrMEVs/F8AdPFQhqQqE2Z
pUV9mjQg8K7iYk6qNypI8UB7TeM/LrCCj6L2B0V9d+k41av9BW/Eqi5CMMaqLqr6VJsHbyyx
VnQw0r4p+pqqqYrptvzAU8S+QB4qEdQ0a1OFDIQZFQ/wAMXlXQxqamFseIFIXxC9tEQITCHW
BzP0JjhRA0roGnoQC1SAqwi/UFUrMNLQEhNNR0sEBQH7wtSqTGpjHWwJoGAdbQkAYu0GQgHW
8ZbQpawdK0MORHQvwUDxnorQm9F0CtBQZn0KvQVOJJA+V61YaEWGLOCKgOc0Z/WR/CphCJWn
8u8E9hHHRIiAGMEZiRCKhOQgsXoDw2NibS+6X1qjri0Q1Z8Y+FNRH4GcUwGCCC5KFVGn/k4K
LuXn1NTV8EvGmLhkHBkBLqKUzWoWAa6Z1UwQclaAE9TkrBkP+jgrTRB+VUBXQdtfFGIE3hDm
RnMAirIoQ/uLJlga+ELeaDqoYmFvLSD0DeNBKyUvAEEVRdsLAikVDicYWCpgTmANCSwVUVtT
7wBAVWOIQCBVszJCl9awFJPaalyKZYhLMflRaSkmtVVeijWIWgy0UheXIDjq0hcgkKr5GMHA
qqkPAUvSRhVRW12Koba6FIPethST2tqM3iP0eZsRdYTwb0tnIThaVCCCYdoSaujzpu0jhGJj
0qcEEdFBAGZLaDWhIYJOfZohaoTC9U0HSAKXtKpxgd6VcRtdCH4QXooagJI5zqRPI8QlLAty
a+1Y6X4ZthXrFVnm4lRhDRnCNbKENWSYUj8Iw4iomGzQm7IGNvRm0qcBooKgQVnRaJFGC1Mj
ZqhBQ636LtrQ1Appkwz1mj4Ll4gIpkJMRU3s5AVpg467AcCMC6vxjAxYew+ZhiQBcWEUiOgL
nqE3ZX0qzRFd4IMAvblpbdBbYAVLzEt6gEjiAGVVmSqgWAOKWWhFcgVYIUwFEdTLwgwR1UGU
imPUNggpiFT0qVQRFdsckKezMpWErYjoPRazZWBIynUJiXzQp6gtYySQxFXEwqoXtVUlrYja
KoKXCbXp4M5CK5JsKAMK2YhYFg4VUQd3gE3GHmVATCpIhyvGrII0mhnTCmJlYUGuiEWpFxOL
pH7ALILyQsioLRd9F7UVUr2oTWdajFmDgE0ZG7Xp4M6YVbAO7ozpB+vgzjpP0cGdhUAkdVE/
CFWIqD0kThbmy8r5Uhuz4gHTFvmVvgsNiklO0Lt0d8ILWV2doLcUFaGhgqk4QW8Dj0vuL/Mi
TSmRsYqIeMOgLDmPWiFsJClNVb0RsyntWIGgDO3gVBbAi6jQyCi2dGxGsaxDUEaxpWPFbEmK
QBVcUJvObrjghab+LdDbtOkFk+A56VPRm4N6UlwvmZBWLFZJfqQjonCU5DwYjTAYiajtFVoR
P4JWkOPKOKaDY0WxXLUNKFYUygXFqrYXBJKrhhOoQhhIn8oLZSYVK+aN2nRQRQmKSRBI0bEb
oSgJ1FIxZpasOBOOkgQqqV6xWOgMbQCtyChCOiqLWBRy4JJlHoBJkojqX/COzATQXtCK5OEY
dEEgkvxieAUpVMzLRBS9VRPBBAKpOgwmkEJFCGPgh1j13YJJL1g4gRSqDtgJVCFIhggCqbqC
kBD+whRamzxts0IOdNWCxgVYrh0HbKmiLUkCaKU1rVhiVXIpzS3EhyKCvGXSKCIm2JJxyLx3
xtwJeYiItBSrEJc2FEzDwQ8pQkPSF0QjLQQtOYuIWROKiHczekhQLGLJ+lQm47N2d4pojo4i
iVCbjiLI6iU/0hcIU/0ZgEkRc30d6rCqQDpZQloEEaBNYjEt6QCmLaQ0jWQJorZBYl5yNIyT
yJUImQvelZYFXbPBqC0e0yRMmEHEpRhEHTqSmE0YniBKxRGrRUjCIKpeiQjJ3FQZVini4jMs
U0QEawCpEWJaEzaIajzWJwQvqBiLFoAqRFRRZ30KvTqSJaxWSI6rL0h7pQ/xAlYuSCd9SXwo
qZ3meVnXQmZ9OkNEXCSsaJDmYzLlF5GXF6CM9QVptCR82oUCYoGSejKjWM5arGJlRSOgzLrI
AosLatMFnFRQrKneguY0DRFxkVSmZkpLJffTPi5YnFncJ2EgaSBp4logIjaxSCMZobZM1EhG
CC5JEpUiIjaRHcpwokEmeIYRaJlwiYhIfVJFbTrPwuxGRCQ1qaK2iphPFbUpDWL5TMSiabLU
luZlUQ2rRbMGpNgqiaTirGE1CesBIhJE9Y5EoXgPdCV0ClG906BMF+ySkI2kl1Frk+Yk9S9+
iAgNGO8kx4R/YQqWqQJEVFyRjGYJf0nqNCkXJ4tvpPBvfvPqT8vS5jz9+dXXr/706i+fPhxe
ff308PH103++P/zw6g//g99H/P5/p1d/+m4SCIr829/+678shbFYsxT+y+HvT9/c/72jIvRV
YCV1UfH1h9u7s/L/8frp4+17aP/5/IsJ6ij0FPGGIXm/IckzpF5oSOwpKhuGtP2GVMeQEAYN
4aMh1FO0Aa2wH1rBg1bgC3uEe4powxAHF6OGsGdIGTSEjoaknqK8YYiDi1FDimNInC/skdwz
pPmGRAcXg4Ysbe0ZQoOGhKMhpacobhji4GLUEPIMSV79VPfV7FAuNpouo5nWU7TBl3E/X0aP
L2mUL4/RyXNP0QZf0n6+JI8vaZQvj6Dm3lBMG3xJ+/mSPL6kUb48Qot7QzFt8CXt50vy+JJH
+dIM6Q3FtMGXvJ8v2eNLjp4hpxKv/jAxr4uNJocWWr2BjzeSQ/aY6tR43/4hUP/+3XcfHw4d
DRo2p9b2WuOC+5kr86pYGoWSubI3YvEGlJJHMafGu65MDpQGXVnNlQ75Y09/1JV1XexSVPZG
rrSByuShMg2hMu1GZTJUJg+VaRiVaV4Vy6Oo/N3h24+P7+6+m768/+Gbx+nfpz8fvn04PL7F
oz8cPi2OTr0BKW1gNnuYTUOYzbsxmwyzaShh6atKveEsu1nrs06idbE82Elf3f/t8OPh4dfT
N5+mt7c/om8+Ph4epjTdPyxSno491ZtqDdf14fDw7f3DD9Pt3fTxw5vbp8MX0+Ph9cPhafr+
8Mlq6Q0Hw7W8PTwcjrp6U5FhXXf31qwetQ6ren9/95148+3h/YfH6eHw+l68rt5WT5gj7r+1
Cjtp/HiFhw/3r99ORz5LPT7L7mRCzzwtCM8G9dyOQplNCCY42e5PSPZjcmjJx4vJzNbQnTya
e0l/GR1M3oABD2+WLsg9pisbQ0rZvwpWvFWwMjwO5LgqVkfHgf+6Q9TfPr27v5tuv7n/+HSE
eO5lvsOaFeJHZT12Glb2y6OiHgENKyKL6aPCHguNm3n3+uHTh6fDm+nj3RvhEGHLR1Pe46Vh
5cI4d/dvDo/T3949mS973FM2xuRqRFCjCZaJVIvKmkzwMqUyNIDX3QN4MVYrXtJZxyOkrYq1
C/P30iOcuuH35uVCdciVbbcrq7my9l1ZTgtIh9dPn1Uz24Az2zgz2zgz2zgzl2gCmcAmJBOy
CabQ+nouprmaZgPubMCdDbizAXc24M7VNFfTbKbP1TQ309xMczPNzTQ309xMczPNzUbd2cbY
2eJntl8F+1WwGAvZBBuio8VhtKiLVpysOFlxsuJkxdmKs5VK9iSd8gJ7kk1POQnWZuuCIxY7
QG02O+qjzAIkX140XF80Xl+Uri/K1xdN1xfN1xct1xet1xdtOyCxB0478BR2ACrsQFTYAamw
A1NhB6jCDlSFHbAKO3AVd+Aq7uGpHbiKO3AVd+Aq7sBV3IGruANXsYOrGC/cjYkdkMXo78bE
uJ7PdS3wEr74bJfyrP7R3Rjb9O0gPkZ/NyY+26W70pDiGEKX7l53wi9GPwWPz3bprjOEZs+Q
0d3rl0dVzhT5u9eRHFyMGkKeIaPrV/HFUZUzRf7KVSQHF6OGZM+QdmGPdFgyUvUNYQcXo4Y0
xxB/o885qnKmKGwY4uBi0BCOniGXnkvrjB9xY+sxsoOLUUMcBo88es7i5VGVM0X+OYvIDi5G
DXEYPCb3eARt5mduzcmh3JhG+TK+OKpypmiDL9N+vkweX6ZRvnx5VOVM0QZfpv18mTy+TKN8
+fKoypmiDb7M+/kyeXyZL+RL7g3FeYMv836+zB5f5ks3xXtDcd7gy7yfL7PHl3lzfXYJoudH
VWK59HxFb+DLG8lh8Zgqj6zPHtu6Z83BNvCOre20pmyerzi5Mq+LXQql3oi1sRkWi0cxZQhK
ZWjy5LnSVjiPre21ZhyVq6MqcXyf6cVRlbP6N1BZPVQObcDEuhuVtigfi4fKOozK9VGVWEdR
GV8cRjmrfwOV1UNlHUJl3Y1K27I4trbXmmFUptVubxzey/ry49P0hDMY063898O9/PgG53/+
7eji3hiysccVm4fWoT2u2Haj1TZ6Yh1KnJ0V+t5ksG2e9zl1T1oXG80Se5vxqTcXGta82oxP
PXYfVvbLF6dgrlb0YjM+9chy3ExnM76Xeg8r/9xmfI+T2kY+b3uI+N7GUTju6+FbG0chmODl
iW3k5M7RyD3RZRuiR9M+rwqf7hiMkPVxFZovnEflDlHR7PudZmce9VPjPVfSvNeVZNvFNLuu
dNcZnrlylTfT8G2z7smfTiI9rnl98qfDXOPKfvniLM3ViuKLkz8d9rrATIdsOkw2rvwzZFM6
DEYb9wIpHE8BkB1GoGAIDMmEbIIbIXUkQsLQcrsbIUaGwckKKAxHSAmrYnEYMUe/d5YIKG74
PTq8/VPjXVfG3a604yYUPVf69++euZLWxUZ5+8tP0+v7h4ePH55Oh5jzF9P7w+3D3bSii9LJ
vMYrOtJF6ZHYsKJ4DOXSY7BhTY/fHzX1KGxY061xdOmR17Cqf/zz5sPN7c3DzeHm7ubpZpKf
9zdv5F+T/P9b+fnx5lH+9TD9TP4/3bwX+Vae/0rk/755JyXeioSft1r6e/n9p5svbqx9Pf4b
bt/xEPYaHLXHf5eCo3aytnFF9Pxk+K+OertEsZGV2LkvitUEi1o7CUZk2SAZm9vZMCJjc/Ly
iTiU3Ty7YnoV4URrjbMPvn3UMNhJvGAH8IIdwAunA3iWPAdLnqMlz9GS5zhHE2wGbulXnJMJ
2QRLy2dLy20kinaiLwbTbMNqtGE12rAabViNNqzGYJqDaTZijtE0R9NsJwOPRw0m26qfbKv7
tFV82mo9bVWetvpOW2WnrabTns9p5+S083BauT+tfJ9Wjk+roKc1vNMK1Gn95DTLn/QTg0fB
8DmfBIN3OOHcWUWn02709pnDennRcH3ReH1Rur4oX180XV80X1+0XF+0Xl+07YDEHjjtwFPY
AaiwA1FhB6TCDkyFHaAKO1AVdsAq7MBV3IGruIenduAq7sBV3IGruANXcQeu4g5cxR6u8oVn
RWIPZNk/K0LPtg27FriZX66OijI6Z3555vBM0cac+dktxesMebahe1b/pd8w6oVf8U+B0rON
zCsNYc+QS0+B9rig5A1DPFwMGlIcFcNbqi/PHJ4Z4m9SUfVwMWbIsy3VM0MuPQXaY8nTnmTP
EA8Xg4aQZ8iFq/HUo+y6Me+tHi4GDcmeIZeeAu2NH9U/1UTNw8WgIR6DN3eL3TlzeKbIP9VE
zcPFmCHNY/Dm7tXTZn7m1+xRbhvly5dnDs8UbfBl28+XzYkLfCn7oujk3lDcfL7keTdfHtva
M+TCb75xZyjm2edLnnfz5bGtvfov5EvuDMW8sXvJ826+5NnhS55H+fLlmcMzRT5fctjNlzw7
fMn+NtupxIszhzz8gcuXZw7P6veTQw4OU/3UeNf+MARqb+5v65fH1vZa44L7mSvzutilUOqM
WBw2oBQ9iglDUApDkyfXlcVc6ZA/+xuPz1xZ18UuRWVn5OKNi2scPVTGIVTG3ai0tW+OHir9
nZq1K9dnDjmOovLlmcOz+jdQSR4q4xAq425U2rYSRw+V/uc2n7kyrotdeJ0y9caKjY9bMnmo
pCFU0m5U2m4Lk4dK//rcM1euh53hy2rmyt6ws3FZjdlD5diwS7tRSYZK8lDJ46hcDzt8KSp7
ww5voJI9VPIQKnk3Ku0TIMweKnkclethh0dRuXWouDcc8QZak4dWHkIr70ar7ZwyO2gd2kfr
TMN4+6OZ1j05rIuNHp/vnvPrzUKGNa/P+fXYfViZnfPrLIqNK3r5ha8eWY6b6Zzz6ywYjSv/
3KHiHidtfN6U0/GQANv3f9j29Dkdjw1wnk1wZvc89C1UTkNL3F502bdQOTlcyP6dvmcRsiaw
S2/Q5R5Rbdyg4+zNqfOQK/NuV9oXno6t7bVm84KJubKs8+bhy3g9sim9RHpY8/qUYI+5hpXZ
KcEeaw0renGouPTYa9zMPtmUHpMNK//coeIeg21cm2T73hvbmSC2i3dsnxZj+94bFzdCRu4H
cRlaMnIjxMjQ2yzl7YuBpwgpq2KX7mKVzlI3b+xisbeLxUMXA9ndxRpypV0M5OK5cvti4MmV
bV1sb2ZTe6nWsOb1qdMecw0rs1OnPdYaVhSek03tsde4mX2yqT0mG1b+GbKpPQbbuMLJ9lVH
tlOGbJf92L7qyPZVR25ehAzd9+S6ezi2+57sbdayv6+3jpC6nuW2YcQc/d7LKP3tOP2zjAON
d13pbsoNudLOkR5b22vNMG/XVZKIP+Q45srzGwyPU/yCLFw6ueO4/vuHiT9zI6J1uGxc8ZF+
WofHxhWFo62tQ2TjmuxGROsw2Lim26fp9u714fFJ3Lewzekj7a3DYOPK//FPuwVx8zj97HQL
4kf5+di7CXGsu0N043ULFX8xfeYSROvka5fjocMJ44oM+62Tyoxr+txlitabjW1sWyc7+Z/s
5H+y8+fJTv4nO/mf7OR/spP/yc6oJzv5n+zkfwrewNJGUq+jS3axoQ18rZ96bV+vIFuFJfue
MLHdNLHrA2TLi2R/SIfsQgGx3RtkuzdoC2VkfyqG2DTbpQNKptluH5AtAFAyzXYfgWw1g2w1
g2w1g2w1g2w1g+zOAtkXj8nmw2S3GCib5mya7V4D2VesyeYwZF+oJvseNdlNB7JvTZPlIGTf
kSa7JE12V4XsZgobGtmwx4Y0thslbLdF2G6CsN37YLv+w/YhaLZuYj4t+9gTcy/nk2B5Uzkl
UPardhKc0wVpeGv8jx9/+EYoS2h4+csyf/357z++fz/95eFw+GL64/305fvbu+8f//qLJcqP
o9vSj+vqbPn9q/j5QFrvoJ+XHslM0noH/VxF9ew9lZB0IgyXWnnp19PdyU+6WK5Z8vQkXpre
Ht5999bmMnF3+2hdyj9GnOxOUrI7SWl9AfVaP1dHhf/3GnlXxesd5POK3Rx67cA0XOpZ7vDX
h/87rivubkFZl/JT9mSMkWz3N0XP/4Oe9KLN/4zr2o46XGodKsd8oOfFjXTAiDNR3O2G9a7+
uRv8HcMu043V7HEVDQMprMmKRsnqq9v334Kont7a0kPo0dKwziVZf3e3Vkp7lS70efvjSWOP
P4Y1rjcy7cbTubYNVrUUK1mKlWzsTuyB8tSvPjSGwtu7yGUpRVp/lfdM1fDW+tf373+Uvn26
P0Zu6BHgxh574v1jPLtj/PgX7l+U3U6wk10KTuHEwzYfsRvSyS7zJrvKnewyb7KUO60/Z3vu
wdE9+vOs7HeHh3c/6trpy1wsvqzEjO3lYuuN+vPSQ/Oi9Ub9mQr/c7GnEi9yseGPzF6ci13f
vnUutvHt2mQzomQzorT+guuVfl5/zfbcDpfHeF/F1anY/6uVawem4VJ+LnZ9C9a52MafwUw2
K002D0vZ8/+YJ7MXbf6e99qOOlyqn4ud1b6Rm9rEO+Wy3w3Jc4N/tKjLdGM1e1x1UrF9U/ys
7ObnXX/iuThc7Lz3TnnWWf3+5aBkiyNpfTHxSieu73meN2TjHsS+mj0WLRup3L6aPQ7c2Pft
EddYzdXjjOp3e9lXs9fP1U8A676aPZBu3EzsEdxgzR7CqouwuI+aqocw/yOuscdKYzU3D2H+
rcPYy6sGa/YQ1lyExR4TDtbsIcz/rOiazCMPF/t8UhN7tHRBG/K6mB8cyb6/lGwvIrWhIdF3
phM0ed46Df6TIWW4WMeZHda5pA1tXcz/4EG2fYFsu1R53j265vXVzXND3O6lMwb6f4Ojet8N
CmVuZHN0cmVhbQ0KZW5kb2JqDQoxNjA3IDAgb2JqDQo8PC9UeXBlL09ialN0bS9OIDUwMC9G
aXJzdCA1MzQzL0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggNjYzMT4+DQpzdHJlYW0NCnic
pV1bjx3Hcd7nAPkBeRvkyQYScfreJRgOHEAJDCmAIjtPcR5W5JFMiFwSu0tL9I+3U1/N1OzZ
Pds1vdMPooqHU1Vd3V9dunouLs9pmieX5zrlMrkU+Q/P/2U3T6FUEH6KQX4JU6QMIk4pJRBp
wl+YyMwdQJSpBA+iToUcCJpqggY/TzQTCDdRhmTPF85eKOadq1AszkWhWIOfhWKlfuHgcYSF
g/8ICwfLjMIRWE0SjsCak3DIYIQjYHzCEVhHWThYR104WEddOFgHLRz8By0cNPlZOKKbvBOO
GJnKEBrD5H2S3/zkg4ORcWaqYrZinnzMmIqYJp+Wf61Myb/y1HgIZYolFy/XsbZShLdMvka5
jnUQJiwn1kEVM8prEGYsWE5xCm7GkqTCVJHr8hS8LCUPLXjCOiWaQkigMi9vlLXLnqkiFMtL
mM6cmTfPsI1BEbKMhScnlCT/ylIqJicXlkIO2opjikDlOMU5CwcDxlVYxOZHL/PHKIkBy52L
4Ep+S1OMEaPnYcQ0w7ZSmAIioTwKVHIhpipGwGw8ZIyZxcfqoKMybxW9leWRrAdPcZoTeGuZ
EqN8gUDyQXhpSkFGTzNTstKMWfYByGNjUpJRUZgSFpkpRn6R1ar8W5W1rHwdFZE8TzxpGDPj
PLtFMntGktUn9jA4AVP8rzDGFTaVZ6SCckxRAeUntiCDChOPJ4GKTGGNCi8y/x5AZaYw42Vm
p3MMH6bY67wTipiCHYUduYQglGOKhPJTicLBTl2ScDAYSlo4WEdeOFhHXjhYR1k4WEddOFhH
FQ42q5BwMIALCQcvWZ2Fg5ebGYSKTC0caap+4ShMCQf7bw1Ae+F/qBFuX7yED6EqU0WoPFVZ
D7ZrqhgQU/xbKfIby6vwAExspYI5Zf+luch1aSKX5bc4kUcYQ8CiAIRhaSnIKjC4KCb5jTlS
kN8CBy4nlEcIE4qjWklrQKEK7ynskkSz/JaZytCBiZhnRKOCaDi7WbgJJMKOyJh9kGsRDdmf
QSJEBpkx9mw3RwEL0MFTC2thwJwEGkD3LLFE3HTG6jFZQcosZImyUa6FXAJ+C8A5S0Ap8B4n
EaVg0IxgjDcjJLsKbez5/GOSa1kux2KMF9PpJNgVjNRFGFAwpiUcy7pIimESEhBBXIFKmV7+
FcLqwgZhhLhVoJIDsFwbkQxkJivygpMpZ9fjIUo4R5hhPIGt4IIg/gUYcPDFeOGhPiHMFyyc
zwLIKqkly6+EzCeuhUjg5U/JYb4KTAgSSJaFIwKTMqnwwLAsLCWQBMWItmEZJEnOQmAvyJ7B
C4ZxVQgCYkIqCyTRBxJilqzEDIEw1RWBOM7InRWo4uhaQfJVUXJ1hX9wpEUKA6w41GpeiwEc
FbwxYP0rxh8jFlacmDOnA8l/jylCG2DFUyYktCFVMAlt8HMmoU1Wr2K+Y13YoI0WNmgjYfOS
koUNM8BwEJK1JSdsSAXJCxtSf/ILG2tLYWHLIBc2KVAWNtaW0sJGIIVNCgCJsRXrmLKwYW2S
OEqVukAMqPC0VAGxCgAlgmfVJXrPci1SybzIJamDMNWS9hyAxwFK6hUsi6SEAANkMrhygARJ
UBJEqmSPhMWpS8Iucq1kyUWCpD8sTo2S4QCuuqQuGCDOwaFYfpV0QkLOkglEbpVwDrmSPbwA
RpDrq/waJephZEnClBO5VWKXCCsShzAPWRwfi14RHwoyJJPiSFBfF1d0cq34H1yiZsEzFNUF
o16uFYySVFhZsIQfECoYCbi2LOuI8SIy8NTjh2WKZNYRQNhWjLfIoAXKMkVS9VX4VC2ybkX+
EEWIAVWgUGXFKly6CuBJVh744EgtY0CxJ1mqAla0uBPWkVB8McnCqMgSVikM4aEVE0cyXRWT
zCUQdPJsMabF9TiAMCnj5VDhZ4mpmC0ml5FwHTl7QTW7P5MyDzxbfg5YHE5hKD5l5TlIMCnG
EkpSiWdwOiZJSGhD6ccktEkOoBnapKJEWuKiemGDtrqwQRstbAUF7sJWQS5srI1jPEjGKJPC
5lAMe2FjLHmOeEIGkMLmUCPHhS2BXNhYG1wWJLTlhQ3apNQkD7lF2Dy0SaRCtvLL+pOHCoJb
oiZmEvGWOFR4th7XcgDhkLtIiCBpreq991muZcVLqY66xS+1OjGW/FKsYx25qMdiUYhS38u1
KPWzSGCv5PIakYoChEkmoIAxCOIpYAyykyDsBnhd5VqWG2YgHhGHh4CYRNhC8GjkWuwhPBBP
2GyEAJcm7CJCnOXaBFImCnuQIMUJYdPAfiPXQq4UmIQNRECR4gj7hiD5gbDVCOISSDA+QD2T
LJc1yLURpIAfGw/eKEAbo9FH7+TaAlL8IGF/ExC0uDhiMspqsgcziexJHGw4ISGUUQ6yF5Jr
ZVsEH6cMYVKzoFbifYIsbMYYZMdI7F5MCuzZbbn+QAhCzc31G0IQSmMmBRoFF0hGJ/67T6gv
WQKBFJSUJHsv8WYeQ1pWiGMJk+LNHAk4C4nFPIdcKCCsoEBiUlae3dbzjgTzwHPIpMwkRsZb
S4yMIwGjTBaL55BJQRQjzPPuTcgCsrplfwlACQltRdgQQLKUZiimefMrbAggWeIXIYBkEjYE
EN5JCJlALmysjet8IQvIha1ik7mwYZcZJGAggLC7CYldaPRCepBVSNbGmWEJZUzmhQ3a4LEe
oY63rPCDGVGjVIkziCUFyYZjHeSKhwJhvs6LBAKZJS4yA5chci1r48ohSrQECVTMCBUcy+Xa
jG0xpM8IK5xHERcRKjhNyrWQixYGgizIAm2IGhW7AiYhF6WOR4piskgUhlzxuhkBhETRjADC
YbFIbGbSRbm2YkMORTNiCaMI2jA8jhe4FmGFUGgxOYMEQGYMjz1NroVctDk8NnRMVon5kIst
gMdWknf6UDQjrBBSEDLBhFCCa9mvwyyKZnYZJiXD8PB4WWXW2a/DjAKZSQ9SMgwPjytWmXVG
OVeIsm5RuglLhoGwJLOewIaSCsmGySIGsf+FGdUfkxgD0qA0SLj8ReyY0ZpwMl0zug/YdkiO
YtJl+RV9ChRPTPIYXJCZlD7GEorRbnBRMIkOxRJk0VcIi0tgM8AVIvyLNz1MIkZJ9EexjelD
68IjRnkUzMEvy4LmBcc2XIvuhY9iJtoXHO0xSI4aTMpicSwJXpo6c4GKIqAtUIzdlkduDICq
pFeQAoKy9FuERMNF/AuVL5PCxj7FO3Jh49DBpLCxyoChgWRt4JvEQCYXNtYW4sJWQC5sVXo6
QkJbFjaCtixsBG1F2AjairARtFVhI2hbqgiCNlrYWG6cF7YCUrDDYYVjHNDH21kmEQY99jxM
FqkXWG5ElckkOksyXi4oQFZpnkECqkyPwMq7HUnm7O1MAiW8GUVDKq2NNrbSizaMQXCGxgrn
G+AM9VpIgjOHhmWC3UyikYUq8ze/efXt0tScp+9e/eHVH0+/3H//4ZdXf/z88fTqD/e3n17f
f/Xu9P7V1/8rtT6u+r/p1bc/Tgw5pn/723/8h6ci/uPtj59uT89JCO5ZXp6VhfMPp9f3z2rG
ZPAl2MZ4JYoStBKM8ZXQixm+K+GUSEooe1H2qtcwylZCL656cdWLSS8mvZjWiwGuldh+qe1p
QyNsb9rmlTW+nNUdZ/XHWcNx1nicNR1nzcdZy3HWepyVBiAxAqcBPLkBQLkBRLkBSLkBTLkB
ULkBVLkBWLkBXPkBXPmRODWAKz+AKz+AKz+AKz+AKz+AK9/CVZw1fX+8vrng3Dhefc1V+Tlb
sNh+9/r+0/U7VCO/+vb69v7z5KbTL6fXn+5Pd9Onj2+u70+/niTVtFAX/Sr+2+edM8azpNw0
ySyHFgtGIkRcy4h1tK3RJMuUgMJ8bxC2HdlSXkzlLQeK1Lm61zdvpm+/+89pXc6WU9nyzkEW
Uvfo5XB5WYDketbSnsaqi0mGrGTiknexYddHzVEkC5Qpmsp5L7GbAGzlyVKeLeVxN33YmsuY
L8aBDBQHMlBsOVB2vYCP8ZwtWmxnfvfdGkBjKxV1S/rXVVArL3ULuuVY8OH927+e3qzRILZc
oVvkH29Pp6+/+q9VXCuDdYv7069WSS036Z/+RyNLLfD3j+zXq6QWjnOwvE9ubVmiV85KFCU0
sOV1+5t1Y52LFTY3CJuem61E3JVFs9fxWbGvmIE3jaXQYmo2o27arUFtzVbILWbITbsVrK3Z
CrlbT+d5zbv1r63ZSrC1uxxN+Zyttxz9H1Sf19+/O03ffv3Vl9Pp+vWf13CVWuGqW/bp5vXt
54/3bz/cvHpzUlKlt6JXt/S//f3q49Xt1YerN1efrl5fna7urqarG/7/z/z/j1c/Tf909WrV
1Ypv3bruflok5VZke8GoeVzrHORWdOsf1xf3X6yyWh7fv1p/Od1MP77Fn6vIliu/fNparvmy
afsXXtj3stB3V9dXPy5LvmpoueBLwcrZ+tPNm9Pt9PGn6fb0/vrtNhutgqB/NtgHTvertKZz
7Wz06toWztrOxSnSSmiGq5rhtMGLuzlWQrdopFlGW76417EjDJmRrA5vIbVtvc7Ds6L2G+w4
CVzEODXTqZlOJ9DpBDqdQKcT6HQCnU6gV4FeB+hVslfJXiV7lexVslfJXiV7lRxUclDJQSUH
lRxUclDJQSUHlRxUclDJUSVH5Yp6sZ47rFuobTszyc3DK6FyssrJOsKi7EXZi7KXDXuzgQXS
HsD+MUF+Oas7zuqPs4bjrPE4azrOmo+zluOs9TgrDUBiBE4DeHIDgHIDiHIDkHIDmHIDoHID
qHIDsHIDuPIDuPIjcWoAV34AV34AV34AV34AV34AV76Bq+J1L9rcly0XPD4mKL63kfzN6fov
p7svpyfnAhfD6JX3+5u391+fPt+t8hrQK97c6MojG5LeSzhvlTQnx6oW17GPxAstq9ZhN0YT
fO9SBX/Oljqn9ndv3rzFzvb63bvP08+3b+9P019Ot3cPe93QcLh+FTef3n/Pe5IPP0w/nT5P
f/rV3f317f3bmx+nn9/e/3n6Yn563nBYEc4v3vJO6PT+dCMKrn+4Z8W8N7z9rEoabtyv5Pak
vdFrzJs2+0LDx0swO05y4/AKSsWDFsMlGBh7AIYJ05BGYap1/GpIYzT7B48bTMs5W+/286tf
rt9/fHdaILPOeCu6dQt93PgNjUxado4vS1z3ESUak126zjHLo3PMQ+ul55jl0TnmxWhK5xzN
X8xrn70VxaPZ2JRHzTpMsmelGKYkE3rPmtJKINvJZsOUZOSNTlPSbJnSi9wHUxqlVLHPNuUJ
vmFTDKyW7YSx35RWoknmmbs8azhsSrZM6S1THkxppbK0U6FkAx29plhJI5vVxLOmtBLmdqLU
MqUrkpmmZCuC5d6E/WBKK0XnnRSdDXT0mmKlhlxfbEpjV1CyfZNFyV1lq22KVa6W7jog1nO2
7jrg44fXf56WivKOa8nru+n70w8fbk9/+vWXT86DL4a2ExGLVd+U3iX629+nf35ykDwia7qa
rn64+nB1y////urd1fXVzdVPclSEo6PT1d2To+YLXYqHb/79w5vPDcPXXmmpVm4qCo5vft8Q
Y+Gi9gaes/lrpbZuWfPEyJhuPrw53Z0XjqmVaLoFP96Ppla0r25/8vUO96JnI6VaoWJ3FaoV
MzcX+ObV7/DXxRefX03djVRrr1y6itqiNpbh3Yg+PbCa0pp4+6x9t5VjWlOtYrTaZ+27jSBb
s5XaaTY177aRTM1kgYDsuzl2m5u2ZqvIJPtujt3WqK3Z8kMyEZZ3G6u2ZgthZCIs77Zlbc1t
hHUcXJKeo5Geo5Gmlllbb7M68OyV0OgwawTUp3XKrL2RWaPRrL2RWSXraSleGLMSKlmPTYse
mxY9Ni16bFr02LTosWnRY9Oix6ZFj02LHpsWPTYtemxa9Ni06LFp0ZPQokeZ605522duu7Rt
j7PtELb6eqtOt9pui7pbnNvCzhYFNqfcfGSD7Iag53FSZw0j+4eb9eWs7jirP84ajrPG46zp
OGs+zlqOs9bjrDQAiRE4DeDJDQDKDSDKDUDKDWDKDYDKDaDKDcDKDeDKD+DKj8SpAVz5AVz5
AVz5AVz5AVz5AVz5Fq7sE7OzXZzTbopvwSzYPa4azovTpg1WxbWOtqXffkZkF+G25mRpNuvb
sOsftuZiaTbr27DrXbZmMjRH8zGP54ATWv66HfY0gBOtVe8zJTrLFPMJg7AbKmzN0dLc2/d/
mMRW8LGftZN3kw1PYrZMMft0GwfONM/uXq+pF0bPnWm2AmK30Cdnmq0gmXYAqhuTmqwQt82Q
OcnJQmpXBaH7pfro9OzCpt4TgQfotQK//XCevLNuFHrJCr/JhN6jEwH35Hj2QpR9IlCTFRI7
TamGCPvhuWdNaWWXvAPaPB5Vs4XV7ifAHkxppaudR8BqttDRaYoVpnP/+b97cjx7Ico+/6/Z
QkenKVakt4+cnjWllf+yff5fS1ckM00pVgTrPgZ7MKWVPHdOu2qx0NFpipUaSm8d8GBKayNR
duqAMl4HFCue2+d153VAPLu3qdbewGe+VCG2MnjdCYbVCoabSeas1OHErUeLtbZhv99Yrto0
rtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtorrtor
rtorrtorrtorrtorrtorrtorrnovaNVHbKo+YlP1ptWqj9hUfaCm6q2DVe8YrNpqXjcAWxG9
1WpbbbNVBlte3bLSFtO3iLjFk80bNwy10GmmSuZYo/bX03zO1Vv2LC6TnneZtXxYNJxL36mE
zo/XLpnVINtjqiVCo7vlMfpkXD0/Zjwiyh9nDcdZ43HWdJw1H2ctx1nrcVYagMg8wNt0jQ7e
AUC5AUS5AUi5AUy5AVC5AVS5AVi5AVz5AVz5AVz5AVz5AVz5AVz5AVz5AVz5AVz5AVz5AVyF
Bq7I9+7bHto1DZiRs/dt5M8K2bYNVmZfR9syxX6R1C7Cbc3B0tzb8/JPe9aXouyeF/k8PonJ
MsV+u9muu9qajcKMQj8S3eOe9aURO0gM40gMFhJDbwfhAQ+NeETB7iDQ+fNAR02xoB16OwgP
pjTCIwW7g0Chq9a2TTG8g0LvEwQPoa4Rrck+HpOPNwybYuyDKPY/QeAeN9kvRdmnqxQNdHSa
cn7Odqm//wmCJ032S1E7sTOOx85oxU77qMpqsl+KsnfJFM1dcp8pVjDuPunyT5+BuhRlt8go
GejoNCUZ8ZxS/3mBf9xkvxRlnxdQMtDRa4oRzyn1nxf4x032S1H2eQGlrh6KbYoRz2k7Reo3
pZXt0062z+PZPhvxnOzHuc67bDGfs/UGvmdOqGMrx3YL/e7ZF0FeytsJqdqipGwuds9T0pS7
vMfad2vnlHLbizoa3foQSNX7eKu+86rqDb1V33lVabtYe4Z6i28lbe3qndhV78TGlzNWwinh
lVAjtLtO2l0n7a6TdtdJu+uk3XXS7jppd520u07aXSftrpN210m766TdddLuOml3nbSXTtpC
J22Yk/bJSW+3Jn3NFGlXnPSRaNIntUnfJUX60uE1wG7haXPuDUMtgO29DHk9iHvU6Kbug76l
0V3sRveT71jQztkfnZ/9XTBvBpkec372dylCgW55jN7ETudP8hwR5Y+zhuOs8ThrOs6aj7OW
46z1OCsNQGQe4G25Rg/vAKDcAKLcAKTcAKbcAKjcAKrcAKzcAK78AK78AK78AK78AK78AK78
AK78AK78AK78AK78AK7C87iSLw/2JfvLRveFKLMolu8dduRSI7PraFv67R7tLsJtzdXQ7Hp3
bX7rOz3vM/IdR3MSnRueRDdbpvQWf2HDw/MuLF+ctE0xK70+U9qVnnzbshfa/knn/EKU2aOV
L2oOm9L2DvkK50tX5fkAJ1/xNE3xbXR0m0KGKdtxVL8pz8db+d6obUrXPsA0xbfrf/my6Utj
5/PhX76MapsyHju9FTu3txO+vHN+IcoMw/Ll12FTrGAcXn5Pdys5BrNHK9+oHTUltOO5fNf2
paa0knMwe7TyNd1hU9rxXL7A25sin3bOL0SZPVr57u+wKe14Lt8K7l2Vp53zC1N2sn0cz/bR
yvbdbyMMT98edilqJ9vH8WwfrWzf/WzX/EV40jm/ELWT7eN4to9Wtt99tmtr2511zuVT0n0z
8N+fTnd4PeiX0++1Zzctn1DAe1CftNKfDq5by0nehhXwmqOfr2/frBr+7Uln/UL8Tshdn/2S
b2h3zKC5CKnLu6zN+vrslw67ZdPu/cbbetI5W2/IfOYkJLVSWrfQxychqZVX7AMz+Wb5OkNW
UZg6bmDWsY+s1/omEx32s6L2T0JIbzwnvd+c9CsNpK+mIv1cA+ljBlS1qayf4qCqxwL6oi3S
MxbSW61JX6NC+hES0vepkH6EhPRAhvRAhvRAhvRAhvRAhvRAhvRAhvRAhvRAhkhxPc9KOCXU
AdcDGd33bxvwbRO7bQG3DdS2/diK96303QrHrezaipYt5W8Jc0s3W7DefH4DUwNpu5/LK/rV
p/mcq7fS7zoSiU/HtFP8n7/i8ZK54+NpakBLxP7TMnyRTvijQ8Qjoo6zhuOs8ThrOs6aj7OW
46z1OCsdZ92ORI7wNl2jg3cAUG4AUW4AUm4AU24AVG4AVW4AVm4AV34AV34AV34AV34AV34A
V34AV34AV34AV34AV34AV6GFK+otkS+PRC5E7VTH52+7a9tgZvbz9zFe6jf7C2EX4ZZmN89t
zW7ubfNeHolciLLbvG4Oo5O4jralv7f4uzwSuRBlV3puNiu9PlOMSs/NvW3eyyORC1F2m9fN
NG6K4R3O9fYhLo9ELkTZPQfnDHR0mvLo2O5Cf2+b9/JIZBP1/2/ufU8NCmVuZHN0cmVhbQ0K
ZW5kb2JqDQoxNzc2IDAgb2JqDQo8PC9PL0xpc3QvTGlzdE51bWJlcmluZy9Ob25lPj4NCmVu
ZG9iag0KMjExNiAwIG9iag0KPDwvVHlwZS9PYmpTdG0vTiA3Ni9GaXJzdCA3MjkvRmlsdGVy
L0ZsYXRlRGVjb2RlL0xlbmd0aCA0NTMzPj4NCnN0cmVhbQ0KeJztm12PHMd5he8N+D+072LA
0fbp+gYMA0YsI4EgQSCFBIGcixU5ogiRO8RyiUj/3tXd56kZyZ7hCMplbrbf3el+u6vPqbdq
nqpdpDjN0yKFKWs9tklLXYP+Yw5rUKYlxx4syxTCes6iKc55DeYp5rIGaUphOydOeW5r0POV
NXFPVsJ2TpmqljXIUy1r5p6sxfWcME+aldbP+u3nsubu6fqzbaeF/kjr4ygsPSpr+p6xn7Gd
lyfFZX2skHpU1zv0pEpxO6/ny8v6ZKH2qK73iD1LSdt5/Yo6rw/XU6lpPS/2zK2t18b1DZTt
vPXXtJ6X+uMuac2S+i1DWD9dU8V5+1t/3Lhf21OlsmXufytaWxn7FWX725qgbk+Q+j3a9gSp
X9bast8o7PdNeQrr4/YoTmHZXmyee1R7+nmNQr9RqVOo/cX1FxNXAWpXJfQPa5cp90evuR/z
+jrDFKvU2zdPaVnvUDSlktOascu/Cbz6oLct9Ktz7M8YewNy7WlSb2JZ+otKXfKS1z93x9S5
367011xjb33tRqi1v6TWn6uF1u815zq1VvvbV4vrr6uIYVWjS9L/kNRf/bLULlTq9+0N6K1W
Xh9zKXGVr61ah5xXrdZr22qSWlfdQ+kKtt6KVXit76R7JS39Rn/8492Xu63n6dnd87sv7776
8d3h7vnT44cXT5++Oby9++zr9fO0fv4/092Xr6ay9oRnf/rTb3+zX7y+4P3irw4/PH1z/OFC
ing5xdqL9hTP390//MP1f37x9OH+zZr9X/TJ/PtpTRjqpVTlI01pv74p9UpT+vu9rSnzJ3JT
2qVU8/WmdCP+2qbsT3vp/vGXNiXOl1J9xGDLrzfYcs1gS/nFTdGlVPkjTbnijlubUq40Jcw3
NmWhr8TlUlPa9aaEK+64sSn7015qSrhZlcVNCZdSLR9pyhV33NqUcK0p+camhKFKvJQqfaQp
V9xxa1Pytaa0m1UJbkq6lKpeb0q84o5bm3Klnq9ziStNGVfcfdaH/vPLbi18/314/7vpPw+P
718fH95Pf1t9+ofe7f4w3T+8nPSJ/vb7yW+oXHrCW291/Hb6/vDj++n4ML04OumlMfDmpP/q
RJdGoJsTvbt/+m768P7wcno6usnp0lhwc9LDw4vHH989Ta8fvj0+vr1/6i95uv/m+OGJO1wq
0bff4d3xxXdOdqlI/tKXmS6VqJsThenDu5f3T4fp4Ti9OT68Ojz2V0CbL1WNm7O/f+qpf+ds
lzpu/Mh4HbcatX8jcFAIKkFzkGYCESwE12rq6L1XC0C8qbL/9fWrD4+HCxl4mnjtadLVF3xe
S9J5LUm3zjw+/eH+7bs3h+l/X/euZHkuVY2bkz776vFw+OzTz53vUsFIH5nTJDRN16rteENX
9Uo3DV/X9EqYL10Zxm5Jlf553Svj28jhxdM/fYQ528lzLgSVwLafy0zAyWUhCASRIBFkAjIX
MhcyVzJXMlcyVzJXMlcyVzJXMlcyVzI3MjcyNzI3MjcyNzI3Mje6/ExPnyMB9UFUAwUCPlr4
aOGjhfKykDnQWQMuCKPgjPLCTfOl+cWZqGsPeXY8Pt09O745fH7/btpf892X94+Hh+3TaX/f
q/J+z9J+K/EGLXrYv4RsAGg7WrLoR0vz3rCU94fPe3/a0M96rG54c0nSnLNvaB3Wr/h7kOS/
JJderUhpD6yM6jzznHtitZNPx7sZDf2i99vPDj9OS/Jr+mt/Lw/Hp8PdF+uPTx9enn6hj299
5N8P9y8Pj3u8XkP8Hw9vXj8cnn93v77t9Q9/fugZtpHcvz8+vf72vgfbb/91fPz+m+Px+7u/
HF98eNsfavvL++8Oh6f1KZ/uPr9/8Xg8+/3fvus/z37/y+v7N8dXZ394/ub1y8PZuft9+mmv
Hu/fujK4rV98ePv+6/5K3E00DYNuJGiTc0NBm6AbC9qk3GDQJuZGgzY5Nxy0CbrxoE3SDQjt
om5IaJd1g0JbuGxYaNd4A0NbGHc0tAu9w6Fd4p0ObXHZ8dAu9M6Hdq13QLTLvROivVvsiGiL
l50RbXHYIdEWx50SbQ7hBd2/Pbz/ev+194T9Wd0BXC5sUpcKu9DVwXdvvsCtxqAzhrdPXTfk
t0f50Ow2Y3XZxesjiR4hXyxfzMtxoTHAmcyCJuqOachksDJRhowWJqGPq5K/p0/+yj9RpPyl
d/L354ma5W+Qk7+MTpQw0aVdBahowhrR+VxFPE+ZmHwx5RpHT7iYZnmWNTFwno7lZ0fqh++T
MZvPpxi52skjnGwaeTSTBzN5LJOroCrVyM9VKVOYt5yJ6TFJDTf7okYl882odbaZ7DPZaGJM
mhna6BEMbIxrDGuMamMg9pHCOcY4Hxl1xsDkI4MQ4xRDGb3Q+Rj0GPNsstPR5zMC2lyLTXU6
xp8d6dW+D6Mjs12baHGlWZjSM5Fn1s6k3SZamH0lzvNzZefNPs/mWWyexeZZmDHlehJ7Ya7E
DIkJEvMjpkfMjpgcMTdiasTMiIkR8yKmRcyKmBRR+pgSMZ4zIWI+xHSI2RCTIeZCTIWYCVFq
bcLFJgw2X7DZgs0WbLJgcwWbKthMweYJNk+weYKYd3iAcgULrmBhCaeXHOykYCeFcFY7g20U
AjMYP5ltFFybGHSCa1NwbQq2V7C9gu0VbK9gewXXrGCbBdes4G+LwbYLtl1wDQu2X/DcLtiG
ITmf7Rj8VSXYliE7n2tasD2D7Rg8uIbCjM33s/OCnRbKmV2DbRZsr2B7Bdsr2F7B9gq2V7C9
gu0VmFfYXsH2CrZXsL2C7RVsr2B7Bdsr2F5xnn30LMU1LrrGRdsu2nbRNS7aftE1LtqG0TaM
rmXRNjwdfb7tF22/6Fp2OqafHX0/OzHafNEDZLQJo00XbboYmE6fOTfacdFOi3ZatNOinRbt
tGinRTst2mnRTot2WrTTop0W7bRop0U7Ldpp0U6Ldlp0QYx2XHRBjC6I0Q6MLojRToweXaNr
YmTK6ZoYXQOja9842pTRpow2ZbQZT8fys6PvZxNGmy7adNGmizZZssnSzHea5SRGssOSnZXs
rGRnJTsrefRMdhhfZpILXrLjkkdP5rfJBTDZeckFMNmByQ5MLoDJDkyewiU7MHkKl+zExGze
jkweZZOncMkOTXZocnlMdmZyGTwdfb5NmWxKvqudju2nR5sx2YTJpks2XbLpkk2WbLKU+WIZ
z8Sww1LmIt/Ezkp2VnLNS3ZYcu1LHnWTHZdcC5MdlzzqJjsvedRNdmCyA5PLYrIDk8tisgOT
y2KyE5PLYrIjk8ticllMdmiyM5OdmV3usstbtun4EpRtqmwTZZsm2yTZ5sgLnzuvxc8uS9ll
KbscZYudPeZli55dgbIrS7aoOfF350lnY0t2GclWNlvZ7PKRQQcWN7t8ZIucLXK2yNkiZ4uc
LXK2yNkiZ4ucLXK2yNkiZ4ucLXK2yNkiZ4ucLXK2yNkiZ4ucLXK2qLCK7LGsuKwUV5LiClJc
MYorRHFFKK4ExT2/WMziHl7cs4t7cnEPLqyBrS+9uBsXd9/i2UyxssXKFitb3J2LFS7uziWS
x1zHY0xxty52QrETiseY4jGm2BnFziju7gVOZHMUd/9ikxSbpNgkxSYpNkmxSYpNUWyCYtGL
RS4WtVjEYtGKe2JxzyvuecU9D5xQ3fOqe151z6sWrVq0atGqRavL2RhSXaurFawLcIyLfFPX
6Gplq7tptcLV3bW6VldPZSuwzaJXd+Nq8avFrxa/wnIsfrX41eJXi18tfrX41eJXi18tfrX4
1WJXi1stZrV41T26ugdX99jqHlrdI6tFqwPJ+DqLVi1a9ayxWrRm0Zp7WnNPax6jm8fk5rLZ
XDabYD4+z2W0LUAgX2cdm/Vr1q0FKJExkfVp1qNZj2Y9WtTJHC1CSH2RRWgWoVmEZhGaRWgW
oVmElmBUfkj3wGZRmntgcw9sFqm5Bzb3wGbRmntgcw9sGfjlfO6B8NfmMt3cIwFvzWW6uSw3
l+HmsttcZpvLavNY2WBu0LYTYBMBSG2wNAHfBHWDlM0gshkmNgPDZujXDPaa4VwzgGuGaM0g
rRmWNQ+0DcWaYZ1zBPYBtmbQ9gzSmmFaMxBrTpycxsk8GEDLsHsNBlhPJ1NpHmgWtMXqjVi9
Eas3YvVGrN6I1RuxeiNWb8TqjVi9Eas3YvVGrN6I1RuxeiNWb8TqjVi9Eas3YvVGrN6I1Rux
eiNWb8TqjVi9Eas3YvVGA8ZqBpwO3DoQ62CrA6bilIFLBycdYHSQ0IE+B+sccHPQzYE3B9dk
AVmDaArxWaLUgJdC6oExhcrK42QeDLkHyxRyC7kHzhSaCgUH0RQKCgUH5ByUk0UjGW0Cr5Fo
EM2BNAfTHFATqimwpuCaAmwKsinQpmCbAm4KuinwpuCbAnAKwikQp2CcAnIKyikwp+CcAnT2
gMyDt5+AO5kHYh9MneIC2OwBmeHisEwtWGaJ3AvLLGlAfC6nKIAsBaPUgkFY7xFEUiBIwR4F
bBSUUWBFwRMFQBQEUaBDwQoFLBS0UAFx4YY9YCkBTUGHgh0qIBP0sAecjEwARUEUBUoU7FAs
ZgpwKNa8FMZKx1jqGGsddPEwVjvGckc4r7lhrHYwNMASBUwUNFHgRMETBVAURFEgRcEUBVQU
VFFgRcEVBVgUZFGgRcEWBVwUdFHgRcEXBWDsAZmxVaAABRZSoI89IA/lJjCWBPzFqqLAi4In
CoAoiKFAhYINChgo6J/Afb3kjoWlhSARcA6dNeILKJ7AeL1icw7iR+o7CE9xLGKhKaBOEDqB
5ASTEzBO0DeB3wR/EwBOEDiB4AR7E7BNUDaB1XrA89DFI+N6RAuYm4BtfUjicjp9pNMD1now
TuYJ0QvY1gMup9hHhAOwKdHp2T4gMJtYXRbATRA3gdwEcxPQTaZu7ogwNgHTBE0TOE1wNAHO
BDkT6EywMgHLlOj5aWxaoK8DynrAVfgCVtaDfP6YY1WTjppO65mkxxPwMQHIBCETVExjPR4u
JsCYIGEChQkGJuCXoF4CdwnOJQCXIFsCaQmWJSBWD8bq6ziZdViEzwifET6jtyGXX1JG4kyP
zgwC0K8esJzLIAAQ60El4BGwQsYKmToANtv+c8gBmXEJKK0HZGboyBSNjG/gbD0gMwbK1JOM
k4BwPSAz3spYChAnSNx5wFXYKlNzwHTnQfqHgLunkYe7U4UgeMqn9XPujvWgdgLbCW4nwJ0g
dgLVCUYn4JygcgLDCQ4nQJwgcQLFCRbXp8HclLoEnusBd29naLn/NvYCkAzXlpltARSwgo8L
Pobu9YC9Ahga4NcD9rdQwGCAPSAzNgcL9oDM2BxS2AMyY/OCzQs2ByP2gMzYvGDzgs0L7i54
GcooMKMKhmWPl8rYt4NhwY2CLwrAKIiiQIiCGQpIKKigwICC+/WAW4w9GmOTBt4pFLLCUFYw
ERywB9wLy4AEe8BVTD0KFc14kA0d2KHigooL4IY9YCsILgAl9oBdJLigjl14uADO2AMy44I6
dkjhAiBkD8iMC+CSqriAnXmCTmrs1oJTClApSKVAlYJVCjgpqKTAkYJDCvAoiKNAjIItCpgo
aKLAiYInCqAoiKJAioIpCqgoqGIPuLyeQVnVsVkHB1SKBqCxB9wQT8Aee8DlFA5wZA94KCpI
o4I0LAOr7AHbf/BOwzsN7wAye8AeILzT8E7DO1DOHpAZ7zS80/AOCFQwUAE9e8Dl2KHhgkZR
aAxnDc1hnIJrCqApCKZAloJRCigpKKTAj4I3ysDR6oEZe8AjMJg0ZjYNB8Ace8AjUCLAkD3g
ocbOUopGwymNkQdYqcbI08buLkzUxj6vsdFr7PQaW73GXq+x2Wvs9jpt9xr7vdjwNXZ8jS1f
Y8/X2OQ1dneNDZPs35rZsDWzUwsUuoBCe8BNw9hVxjYy9l/NbMCCdy7QzR5wOf8YMbPbCsy5
ADWXOZ0V1QWgubBT+P+3pO+B87DBdGFn6QLUXDR28o2te2Ovnvho4SO247HZk/+OHP9bOP4z
b/xf20/+tYTL/0/+YeYn/wTB5WzEG7vef/ubvwMUZXIHDQplbmRzdHJlYW0NCmVuZG9iag0K
MjE2MSAwIG9iag0KWyAyMjYgMCAwIDAgMCAwIDAgMCAyOTkgMjk5IDAgMCAyNDUgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgNTM1IDAgNjA3IDQ4OSA0NjAg
MCAwIDAgMCA1MDQgMCA4NDUgNjM4IDAgMCAwIDAgNDUzIDQ4MyAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCA0NzEgNTIwIDQyNSA1MjAgNDk0IDI5OSAwIDAgMjIxIDAgNDQxIDIyMSA3OTEg
NTIwIDUyMSAwIDAgMzQ1IDM4NyAzMjkgNTIwIDQ0MCA2OTkgMCA0NDFdIA0KZW5kb2JqDQoy
MTYyIDAgb2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDI2ODkwL0xlbmd0aDEg
OTE1MDg+Pg0Kc3RyZWFtDQp4nOx9CXhcxZVu1d1633e1pNutllpLS62lW6u1tLVvli1LbUuW
ZS2WZBlbSF5ljDeMsY3ZzIPEQAI4ICBfHEjLJDyjxBMiPEGQWIZ5PHiTBA8hJPP4Jn4zTEKS
sa3WO3W7W4sXMMmbl8z39S/drqpT26lzTp06deXPjTBCSAkfDPItb8nMebIr93mE8CBQu9cP
9Ywo+YRfITRkhgZ563dut5X9bsVhhPbYEKIeGxjZMDTy2aG9CG1ZgRD3+obNdwzcT+1ehtC+
M9C9bbC/p4/7/hNxMNZv4ckbBIIyJe5fYPxEKCcODm3fdWZt1jehPIXQphWbh9f3xD/kvRuh
f1IjlJ8y1LNrJP4dsRLqa6G9bah/e88TB0/uRLimGMqHbu8Z6q/sqjAjbCxAKOujkeFt24NB
NAj1saT9yNb+kQ8P1mUjtEsP/EsRWStX9MuXAmf/o0tV/BmyihHBm794coSk79eNrrryyczP
pLtET0FRgigUAvTjUBDhc9LzVz65IpbuEkZagBgDoVgfQd9AYrQL0dBTjTLRAEhpgnsdShgx
TCpORywSs4+zHhgyPpTSb6PDFHSiVDRFUQxNMR8j9+xrKPFOgQPAshabjUx3hQnxIHqKctoQ
niV19GlWSVaK9IwSuSPc4AvozwJTi87etO7ni+voT27edlG7l764Hf79rY21iB9JqA+95sZ9
uUl0lrV++XG/LOinUeMN6ReR5j977puB/jHSfek+/4wC9E/Q6I3qmGUosKjtrsXlm47Z+MXt
8D9+fhuoV1w37jdDfah3btyX/QgFmO03rmOOo+Ev4ulmoC9cI4eSm+i+BsUumnMPeumW57iI
kjg9Kr1h3Zov1it9Dg3e6lwRMCnoBXoD6rtZPff3qI+9HKqHtpsWzff7W5uP6kMu7hByic8g
F3MCuebmts/nPw9c6621Wwj2VzCfCea7Zg4yFvPePE0k/fJjE+Bz6NFbaPPCjej0kXn6zdoA
ny8Q3dxsbCb95jr7IlCTi8elzch/o3bs44vp1DdQ8iIeLqBkxr+YdiOQNsxllCxKQcnci1/c
nrSBtT/7Re0ioO9BqewJVHbDuiMo9VbHIYA1NlK/QDuoFlQP6QoqgJrwq/Nj4FXoNqHdAbQD
N6MdTD20Je0vzvsD/CmU01A1fh8lUx9Cfhty0O+jHKHfDpT4Zfj5rwqwa+GJIoooovhbAPU1
HH/Tug64YC0A/gx5//M5+ssAcdWj8By5jp6DHobn8Be1uxXQsi+Oc6L42wF+Bd0GT8//775R
RBHF3y6YH/2/2dfUH9FBktKr0EHqRXiOhMoEeGsoT70P9BZ0kPkKOkjvm6+fG+MI8lHfXvye
JIoooogiiiiiiCKKKKKIIooooogiiiiiiCKKKKKIIooooogiiiii+C+Om/4r9yiiiCKKKKKI
IooooogiiiiiiCKKKKKIIooooogiiiiiiCKKKKKIIooooogiiiiiiCKKKKKIIooooogiiiii
iGIxZif+2hxEEcVfGXT4iQ192xd2QwlydCJisBYIbmRDDCLfv6VACSgVpaNyVI3qUBNqRQNo
IxpGo+gOdBJn2yS2/bYHk356hZkVvrUL2ttQitC+Eto3oBbUA+03oa1z7ffaHoD2CNrj2c/I
/7RLp85egH35mzBvvxc4appdj3IvJSP0q3v+qQSh8LeSpYXbpAj5LOE7R4pgrggq5z5pup4+
gcywQicqRqVAq0LrUB+msAqrcQyOxyl4Mx7GO/BOvBffj4/jJ/D38Gv4RwzNMPhD7MJuXIML
cAPi8B+EUf9w7TejQZkKf48ahT4foZ4hnuaVsI/eL6Q3/Haam4B881ZoVQSZ8ERWF8G6m39z
zsLVC+VOeOakIFAWSAJKb3wJzv46oG+tGdHmrQ+KB6L74Lp9gHy+/jZ/a8vK5hXLm5Y1NtTX
1dZUV1VWlC/1lZWWFC8pKizIz8vNdGekpziTEh0JvFmvUasUMqlELOJYhqYwSq9yVHfbAs7u
AON01NZmkLKjBwg9CwjdARuQqhe3Cdi6hWa2xS190HLgmpa+UEvfXEusthWj4ox0W5XDFjhf
6bCdwWua2yD/QKWj3Ra4JOSXCXnGKRQUULDboYetyjxYaQvgbltVoHrn4LGq7koYb1wmrXBU
9Esz0tG4VAZZGeQCKY6RcZxSioUMlVJVNE4hsYJMG6CTqnr6Aiua26oqrXZ7u0BDFcJYAa4i
IBLGsm0kPKP7bOPprx27/4wa9Xa75H2Ovp61bQG6Bzodo6uOHTsS0LgCqY7KQOruj82w5P5A
uqOyKuBywGANK+cmwAE2Se2wHfsMAfOOS79dTOkJU7gk9WeIZMkS58QE9ZE8At6AQ1if3U54
ue+MD/VCIXCguS1UtqFe62nky3S1B6huUvNapMbgJzUHIjVz3bsddqKqqu7w785Bc+BAry0j
HaQv/CbBL9TbArSzu3f9IEl7+o85KitDcmttC/gqIePrCa+1ajwrE9r3dMMiNhIxNLcFMh0j
Ab2jPNQACDaig40tbUKXcLeAviKAuteHewUyqyoJX7aqY92VIQbJWI7mtleRZ/bDca/N+rIH
eVE74SNgrAClOKuOtfUNBPhuax/Y54CtzWoP+NpBfO2Otv52oiWHOpD6IUxnF2YUesHarmkd
aUxWLkoS29ooK91OtAUEWzV8OMqLoUIN6hKKRKPlxbY2bEWRZjBLuAXJLRoHCnRSRS2poknX
ilqrvd0ewuewZA3zxCYFxAvGUgNhjqfQPDdlLdSaMJRqq+qvXMDgokHZMIPh0W7MJ0VkEZ4Y
eoiJOmsjVXQS7FygUTCMQCJaNNsCaIWtzdHvaHeADflWtJG1EVkL+m1ocTQ0r2kTtB22ktZF
pVB9wVxdOBegKsAAq13WiE6Fco1QnivWXlNdF6m2HRM7GlqOkZEd4QGRDbYPrJhz1vXcV6D1
wr6sBtfmqO5x2NS26mM9Z2YP9B4b9/mOjVR1DxaRMRx1fcccLW3FVoG1lW17rbvJVFrUgBta
yzPSwfGUjzvw0eZxHz7asqbtVTVCtqOtbacpTFV0l7ePJ0Jd26s2cOkClSJUQiQFGymQkVZC
QSy0t77qQ+iAUMsIBKG8/gxGAk0coWG0/gwVoqkjNApoTIjmE2gEoCHzIMgXfG2VrY/oZk/7
4LHudrKzkBH0CL84gB2lKEA5SscxxckDUkd/eUDmKCf0MkIvC9E5QheBVWAjBmlWDToisnJU
Dfb0n0YYG3SOgnGMNHkZaFySuVSJi1EZPBQuxHmoAPFwvIXSfJx3uoB/e2kplDGuRQUQNPhx
NaRVkFZCWgFpOaRLIfVBWgZpJqRuSDMgTUd+dAAOSwyf9TBGXagOLYeRMPo3aA8HOC5BWfBQ
Qm4EngPwfAgPM/saLnlZqalGwKQXGnmhyovehoeBxh5kg+cA9pym5ZlL5TgbBlPBJw/PMDz7
4XkIZ59mVegMdvu+hvUfjc3yvxyf5X/+6Bb+H9938z97byP/v959kn//vXT+f76Xz789HcNf
mB7kz0+/xP90+gCvmsZD/DSGZMlbUwf5N6fu59+YyuN/PNnE//1kG39usot/fXKA/9HkEP/a
5AEeTaonbZP0kG0ya5IiWYpQqCW2SfzDCSf/dxNF/NmJlfwPJob4709s41+duJs/M3EHv2IC
n5l97eWJ3QerhXTw9lDqXxNKy6tJ6pudyMyp/t54A//d8U7+5fH1/Onx2/jA+Cj/nfGD/Evj
HfzzY1v458Z288+O3c8//WQc/9SThfzXn3yEf/wxP//Y/Vn8MXyv/x7axR+ia/iDHQf8d506
4N/fsde/79Ref+ZenLm3bO/w3qf3Xtg7u5e7o2PUv+vUqJ8ffWj06VF6FO/27+nY7b/z1G7/
yG58tOOw/8ipw37+8EOHnz5MH6a3+lfs7N5J7YTM7QND/sAQ7hoaHto/RA8BZXvHVv+2U1v9
vq3dW0e2HtjKbKWG/Vs6hv0jp4b9wxzmbwOmNtZs8A+e2uAfqOnz95/q86+v6fX31HT7fd14
bc0af8epNb56/2pouKqm1e8/1epvqWn2rzzV7G/mqvnlNU3+JjqJX1bT4G881eCvr6n1152q
9ddSLr6mptpfjV18YoKUdySYeURjMX0WE8NjwSKPo1ZXwxnR7MqGgHhFRwAfDSS1kE9f85oA
dzSA/Gs62sYxfrD9dAx4i1bBCwrlex54AMWVNwTiWtpO0ydPxpW3NwQOkLzPJ+RnSR5Bk/Z1
21zXY9s1+W3bSLotXIDf7XPVGB4UTl3hvMsVqcc71m3bviMyh9AOCKEymuuMXWjdNoEOk2wn
HxEGSLrdvA4h0VPsEH0m+AgJlVnlzM9u/X6wADUQTe9Ez6KVaNuf1T8MdieS0eOII9+CO3t5
9lLweXjOsMoFFIFPJg4o4W9fnpXM/h9ooRNoKqHVp6RV8Axdjjihr2zmDaDC7WI2iZZAWTGb
B+XfUUdIPtRD9FTwO8EXhFoZk4+/BnJogbvEUtQId5x14Lq64NayD8r1kO9FuyHtQJvRDnQQ
VcC9ZhXUD6AhkMF+9HWQw2voH6CnH3puQCNwO9qHjqDj6AQ6hd5EnXAzHULb0Z3oGPoGOosG
0RYY7250P3oM6jvD47wI6Qjckg6ge9HD6AmoqYU6MuNyaL8LxjiGboPZjkO/UfI95H9rYNcg
Azo5+6fZ8uAzMz+gk2g5/ims+QisaAes5TLqZfVoE5s++wecMPspK539LbN/9lOcPfvvSErv
oeHuSb7vnD4PGqSRCBWiZajel5ghoopOVypfNFXCD4VtL4kZTPFiTDtyObrZoqkrYzDK/ODi
BxfPl8Gj0RYW4swPPrh4ieQyM9WX4OeD6axsrLFrhEevpEQiPedIcFO5yd48jyenlMr1Oh0J
SkqgefPyS2lPTjxF6yOUUkoon7/aQ7dc/QN1V+LSNi9rNEiVUpaJMeizl6Zo2nqTy7JsIlrE
0qxYlJJfYa8aqEj4kFOaNFqziuNUZq3GpATrvPzvrPJKAXPwyj7aWLzO58DfEosohmWmTAar
25e4Yq3GoKElKrlcJxbptApn+ZqZPZERwim5/Z+Fj49BUvHIBUd4gS/O6ZmU8a/HyAwGGXo9
XRaTPJGdLUqcUDd7J0StqOxS2SVtYeYlkM0vLmkKM7WFIJcckIpeyTjsCc5cDUjCDos0EPHE
07TXTTkcGiIbXShrhyz9sTWntuO26uC41unUYuOW+zsyDGllLu/aqpT3Ykt6V751sW5NUWxr
6vLtqz7BMaVddS58W2HvilKX0ZrIHE+0uv131Ltba4v00vzWYUrvaVliC2Yll6+eueDrLU8I
iviSDggPYG3MdlibFvEo1qfUvY5iJiXmCWWzdYINLQVnXnr3ksA9sLaAe9E828z2lSf/5dlZ
gVH1c796vOnuwtFXHnhj6tB/311CPfHsf3xzVYilNc/986NbfnT/8is/XXr0AnnPQCS7DWZP
R26fKSZ5UqKz6WxIEjPhdHKWCUVz8gQ3L0+ceT5kZSDLJMLNtbJ02DXXZOltjEQumnmGcEb5
RXIxw4ihfAm/JQ7lxcE8KlYklzB5Cr1SFOJSpDQoFXqFKFgoUkBOJ+dmrkJO4Hf2Mt0I/Caj
ZJ9OpJtUxKH4ONGETmfhJhKaLX5UFmE185ymMKz0a/iKWHqEc7qR8BiU4Z8TPoR8EpiyVmNW
csB1vkB9T2DIyMr1KpKb+TEn5RiGfHxfYDjEG86HXW9A6lfQpFS9kiXsgPbC0grNGdpeBpwf
mUKkMqm1sFv0cyP+JpKLrPgdGNWDcnwxWefs0klDwrn0dIPkHDIkr7RL1daVar8wUxn4AJju
XUEA6pmcuXmdzmSsuY4DDQ7tfIOeE2FsNNLvMEqzTpukF818FuGNU5o1hDcMFC1sSaOCkSmC
qfiPSs4okooYRiGhHpsZvJ7zme9SjSIpRzMiCSfTK2d+PXOvVhm2t2pYTQwy+qSGSSRRrTSE
TQys69Iiu4rwKeiomtjKzAWtc46lfyUWVKDUq4jVfD8y8ZUd85bCsWApxajBl6LIyjJlZkrd
ZnPMZGK2XC6dRIl5zTKzSZFpznZzfEoz79eGpVimNRVqPIIgczQeNfnQFJZkejwaz0JFOrCS
Jrlk7FhkUYRnE/YQ4QrscyynMmnVIEwqSFNipU6h1CvEOBiLga4DN8k6teUWZ5xejE+x+KzU
ZInT1En0atm8PTx05TYGXC3NgsC/emXLQsuTGeJ1V64yyGzXi4nTDK+cWceqUQny+KzJKpV+
Ml7qdudMoviClVK3KpmxkJ3ChUzGVLhgpZmRFYYWBnbjMOoNN1hePG3yOL3zOmLWyTQGiUVv
53ldsCChisd4fgflmG0xFhXutC8pyLeGKkAcoiXEwUstaXY6ZcneJXWP112dWLgysc5hnflK
0aYNfZ7WV1qpTzmpiKZFoT3ROPuv4AV4VIdW+lxLJxNzEnPk1teRvN5hLXZ/P186obHl43xN
vsZYPFFnXLrUyqa2GCfYVcTMYJPAYQnHAniyTnJgQgmrL5JdA5SIn01wM5GTMHRkurlwmTOE
xUHOUIM+nqMbS0ee6Ci9fdUSo5QRyTilp3lLQ8lAfarXv3nLZr83r/felamtDUt0LEPRHGyH
jMp1xUvaiuK8q4a2DK3y4nWrjnblmGx2E2/SGJWsI9VhL+0oKl61NDe3tGVkWcNoS7rawusk
Sp1SYVCJ4xLjbPn1qcWrynNzS1qGiTw04CNIJJGAYnxyxE2aNZx2Iq5ZLrjDHJx5bub8nCOc
U6Y9ctoL++s88cvBfWR3Ea0F94llxD/LxPQ+wWsL/u/KtjkNPSACAvhpEfF9FNIBBy8zDpSI
UlC5z2Y2JcudigsmJ5RlTukF5EyKS0ueksu1cf3aQXYw5K0yBdlbMs3vEnVoC9UfhFIwQqOe
E4KWZNpOk33mdHrzQ/6KMYkcQHyJlVuNJqtKRPUFXZ20WBWjN8TIWbyLlmpjdCqjWi7hKD/1
Q3xfqkonpWngGYuClwWfJNWr6F+IZRyNaYaTsJtnfg0xRgA80y6IskMxhtdndXqmZfw0RBjp
FxBEGFMQYSRNqfs8U6INCyOMsLv9cvEFydK7TOkljWtKgz9V2e0qrOnY3pSscXgdaQ0F9h8a
s5dVvDpVWpNhXAphQt07f8ivL7TjtKzmihyHxsLTL/KWxKreUmdlkVstTq9cg08l+zLMwSfi
PRXB0uwGjzV4hzmrmtjG6Ozv6P1MGspFST6dGSVfkBun4hLe1AxQU9npb4o2orKZdy+Rh4QZ
54T9zywIBJlrzF3YDkKAuF9k8dZ3FWz49p1VlXd+ezBrTWOxRSQYeHJ5b2XD3vacnM67Vizt
9KUqWPBeDxtiLI54Q+2xN/bve/OBBm1coiXGrNApOJvTVjT8zIaBk7cX2pLtnFJP/tJGtPEz
0EYkKrqAYqYl5illn3WK3XDTqMizOCqif1Z5aPK+XxPxXj46sc+3L73z4a0vPHf78e4sKu7w
W0erQoKsPXx2V9uJ4bKr3/FuHgOJwdxUEOYOx0TTEgiJdBATTZGYaErRlzzFbfhLYiIYnJyQ
VwW1X434teAyvHsufxgLB5oX9hgXYpKDLImEgic5uV4pB7kFd3ByHdFwYPYy9RHw60Aun4HV
TMfKZFYUa2WnNBoTM2XrMw0ujooyw8bKfV5YZKQ+UiqD6/GROZ7uIOE98Q3A9W+USvqTGHPw
KGFGYKsIFA+eQcLR/8BbYkJc4VTwCEI0NC1V9wu7/mbRUGpkcBFJ4XjXzY33JzaUY8lf0RQw
agm7lXKil+ASxlFORVgCdC/MVUBiJM/bCbJpo+PtjAyj9G1kTOlPkGli+zVzXufGMRI57z4v
RoKNjOHYo3tZhVmrt2plbLA1wrPgNElI8lVOoSFXIAVHwb0oeBB/jZzbwkFOHBDFz/zy+mVB
OPU+IQhuVSwFL9w+M8tKJBIUtsW3YGVmEi/pppFI0a+fYjYsjJe4G4RL1FugvByVfY6ze0Qy
Ee2NiQFj+h+Ria92glGFpMfmgP0UoKU+e7ohI9k8naDIlGZkJHil0yghty/DKKPjnH1xg+qw
EOfDBi1ERiBSMwmTCgsXx0dhD/558ZHRwOaAFNUaE4gs2MeYYpU6uYgKjlKcAsIHOA3tmlqT
PUYnxn4Gd0uNVruhTGubN44nr3aKZSQwop+9un6hCcoMvO7qr2mj2Q5xCR+2kXMgySUoxae3
a8/HMlnnUWxevyzNRLYIvWGhdeSE9zNHXEsoENIT2V6/EKPR5HHT8+Knz8Vrqyw2VfCN9NXp
GMAqDOrQQpo0Zo1SjGPcXW5KqFEaNBqjnC3gLbGxVFbT082JjY2NiTOPL1wHuQsFuZXfWp3W
1tbmorScDIJAiDLARw7PfsrYmXSkg9sQ+Ej9BRR/QWqZUg04ptiN1/nIBXd7wUUucOeMvfSO
7+4Y/c72gtLd39255cWdxQcSm+/u6jq00ulovru7+1BLIhW7//zDTbVH39i/5yfHm2qOnDu6
9qkdFdW7nmrrOrmzvHb3SeKzQcLbwI48yEfOT+n5bLVL473gXAIuyaWZWrLEVCh4o5ANRc7P
SzlC6PXewp2Y7KYd11tN+DQ1meCussDJb+OUMTqtSSWmO9TJeQ0lO+f91OV1+/xp8XkN7lh3
kl3VIRX9nTm3pfr5k5Wr8q2CDdFihfRyel1ufDB3odBTqtcXefwV2Sq5I2dpyu8sJuqT5PIs
a/C+OG91KP78FDxuOmpAeb7Y8mmn1+lVxk0jZdabhaVvxlWwrgHpWzrzm2z4cIXlCefrdTEm
d6sxJvVRQe+Rppy1DR4lx1IUJxVL06u7i3P8pY70us7uzrr0rFXbKlOWl2eF6sWcJKWkxeuq
zrZm1HX2dNZl4Nia4cZUnTVWKZVr5CAhCcSR5swKl7vCk5LmqewpW7K+JkVtsiilSq1caVSJ
rbzVnFZoz6rypKVmV6wl644FDbtAwzYhzmSmjSpGPWXtkw4ujjO5m4eZLoUieIHsbZ0RgswL
kcOF+rmQ+yQm5uq6OUU8I5x5cAISNwWzvzT7KT0NO9hFrN02jYzTUme/ut8atvaya6193iWG
7XzBLp0u3viVNase2VRAjEUH3sfZsLGsdLA+iVUaNSajgsUntn9lQ55n/SP7qG0Rhznz1cHh
BmdSw/A6asfcoYRREkhlAvhKgPNXj0zgPU1Sk2FaZorrN7Lhc08LfkUIdIUoVwhxI9dHpzMv
b4FTzDEaORG1hBarY3R6q1pKB+9hKWmMyWiBGyRupnAVLVJZ9AazlGaNJIilOQjSL4aCXAl3
dZQ+EglygbdS8O3vA2/FqMnnzJTKUXFWljxnulhuMiuSHA55wrRZnt+f1p/lkNELY3Pw73MM
WzJJUG5Wh/JayC9gn3bQcwvxLl6IkNNFlsR8i5YbYmFJGgkdZC7RUo1VD5dXWN8brMJqNJAL
MlZTGIHrN+u14BcprKGuUiKlxWAwSSlmfrHVVyeuXbhUdHUPfYgsXBDC7lBeEAJIgdxOaoXb
idOnM00r5DHTiWY0Lef7zZy2n4soKHOm8INLoB7y/nTOiG6oH/xbOFnV5KAPnhLTMqvJYAX/
g80U1hLtGIwxMogXngzujBgzPkatVmmlDOEuKMF/FMxHplWSWHcQbrN2elLwmz3fO1HwQgGV
fWb233y5UkVtiq5AR0l1MTpKrDJDWWLyjqPkZHKgFZ3WLE17PsERN+bOfdZodNeXjMmXMY1k
K5YJwc3vL8G99tK5TiHgA5W51nV2ujqThJuV05mbGzqfhb3pyQ0fCWEKI+wSUcj9GD05efm0
XWGA+7yi5JHlNVua0kq3nuw9bs5bVVrcXZspJZuXs/haurM6DyxPGH2udnOtY/2amjur9FIZ
y8qk/eW1SVW9JQ3D9UlNRe3F8eB6GJlGbrBYEuK0Ga13Nr0ak1Od0dRZ10jk8QLI4yy7FaWh
ErTc57ljyb1LqDvc97opNsWQQg1KMEsbaEosteeNG1ynkUGal2tn2KwxZ721Wt1YOMYuE9wB
nDAm4X4WWj0sHhBxDsmG671EyGYjh6NIYzQK58vZnPUPr0urqayBGFWvUhkULEvec4PPcDXV
1yX33rc6Za+5qLvWUVW7zNVwXwNcy2Lxx9tfPVitcRal7gjZpFTEVkac3cxPMkqS1I0HX9rR
+ODtFXp3XV5wZ0dPxeajoNQ+WDsPtpCL+n2VA2k70w6n0QNJO5MOJ9EytVVNPSb7poyC+F5G
xYJhi1HyaWUePZZtGeOzsn3ZVBm/nKey+Ww+PXFMV5/+nEQQRfhlh/C2QzCJdZ0Q3QjygCOX
WxAawMHDhc4dbtFdj6cYUUxJY1vmuod7PWW3P9KasbIqzyJhKY1UmerrKDv4gLNmwFe8tjJD
Rjz3E3KdUhaTEq8ru/PlHYd+sKtQE5toUah1ijhToitx6mzXQ12ZTrdTpBLe1MGauRPsLjSK
1vvyVzX52sd5p8+4/cN++bhx4HsjRvhpkn4XZZ9u6pexm+pixtbVpDrcY/aW+iWJec/VLdM0
ssTqy2Y+LvPAI5y3wlkQ+ZvITM7H6ovvvkveNtw43Hc6wwctc+P1GxZJyWiC3ROSF33dW1Tu
BHgGnT6G3IlWw0EnGIo8WVPeVRrn9AgSkztL2koOPLRIYtfK15xlMmjd6x7sthe542V4n0hj
sGi0FrVYoQqewP9NIRFevxK7oqiZ4NxbmcsUlVDc7C7r9ShUenmcyZ5sXyht5bV6EYvjql3l
W1uzGJFELrv6E3yXBO4JFCcRSXWq4LeCNpU6rCH2ZXYI7UNdPi8a3bicHq/NX640j3tKPMvh
Z1TvXHN6dKVj9Vj9nvq+xK7nti7zmMeUJXWxYxnLKsbE1YIVlnku5YSVJLxrENQjvHdU/xh2
KdxMwfHOiZYyGMJyJaGgcYEqmPAFI8G52Hfdsv6o1QZtesuOurotjSmXRTIxo1ZeLl5mTo43
ismbCk5uSXRbKtcVW+9SqhmxTHRXbE6Ny1WTY03In1fgNSZ/vQLp00S2t6/ISPfvb93AKXQK
i2Xm0zs3S+VScH4Kk0Uul4oS60a6Kd5iIS9CVlf0lMTx+U3uso6iW1QfeMtN4DHuAt04USEa
9cnzU/RG1Lgz53AOlQGHyMtGtAzSP/mKDWjZzvTD6VSK2gANNsRgicFioCRqi5oSy6yF40pv
mplBmad1RfZqWWGylVGmjZnrvWPKZWzoTLkkXPrAfbxrKpzzqK5OF/zO3foWnimwT+bjrbkd
JugkHzhW6FVqg0JU+0RH77HVKTm9x7tWHi2PeNbRhvsaiR8lfjWxsnZZuj7iRg82tTce/E7v
NnCvdTWUfe7vDU0d3eWbj1Y3PDgseNTIuXov+FIX8oJnWboz+3A2tcuNT6S+kEp9NeX5FEri
sDgoCW/hKfGAaKeI0uns6aeRC7u8zGl7bvqzDBObCacKWHKCZCwWXCkcqeEXKSCGnA86SR4c
aeho6RQC35taHZST8wQpiOh7ndqZE/bG3e1lfXXk9ATzgbV5W4d9G5+5vXDJ7V/rGjje6bqT
PnaockONk6ZEidbWoz1eo9UIobBKpJBJpRaLvuzOV3Zte2V/ReW2x1plx5/xtA4Xw151zV6m
9oA3LUZlvmSPTSyvNarVELFnIRpZx7NUaTitLAknScfyamKcY1l1tkZ1nXAfyyH3xc5znZ4Z
eM5BuIAXXkIWbsa5K/78Dgy9K6T2wFWcFRvtGfFpRYmqiyIp7C3FRQjoyFsI9qhSBVdX0dGE
qsGqBJ8dPA3LKzVSBnaEdUln+abQHrn6RkSpdGFoY2zoOtzqVKhkavKm2QWnhQXW1492obU+
b1qaITFzvFC6dmS82WAoHDiNKksLpVtG1jLsprGe+lXV8WP1Ne6isco6b2Ninbpx+1x4IKw4
EiWc8wivhMBDFQqvMjLn7xELQgWO+3LyMH1BbMFZcnpJbFFVnSpSGITYghGx0iKv11TT4dWd
D/mm81zondic/NLaDq+Nyc1KMSoZ4TUJbJh0IRSBjbRnbstAKFJ941CE+d8UVoiZuOLOspvK
fNO6Qy1OhhNxYrFULv6CuEXQingZaEWLTqK7ffWPPjp8cmR8T1dXffv68WHdcJlLNl5vqx+G
nz3odO7hA3tO1n197P7qkfV7xg7X7Wzc2NheV9VYJpO6mCzlWNEydiyrPqm6ZcxSI+gq7HxC
SssJvfvyhM934QApDP2hToh0Q8q7RtL4ZioxfGkt22+qcKMJAoL5A8ggevvauPCKx7X68For
0d0NwsjrAs0FxqCfDm2m6UhMEawM6X7eLBxVA+XpPi05wSUysdmREdtSjt+5RleU8/M02/sl
beV6u+kmo6vFDGxWhckIO3vHge6QV2ICYB89qNGXWlOT0JI47pYbx1sTtAlaVOhxi8fW1LTU
LR8rq3YYM8cK61IbYxvlgl8Ka5w4p3Oec0TjHuH1XHiPzkv7L1KVfZ7MBKQysYlIr+JiaANe
XCDza7biDWX+g0SgupZqxXLi4cJS+LOlt2mehoSddpm+HySpQ360xGerQt+T8uP+Ztv4/2Xv
S6DbuK4sf1WhsO9LgVhIAAQIEARIcAVXiaBEkQQ3UZslxaIkSiQlSpREiVoiO3Zsx5LsxIkT
x4mZjCl3d2DH9ngiQ5GcrXMm00dnOnG8JLGdafeJHWfp7iQn6pzOyZmTpE1o3v+/Cgu30E73
9Jlp+B1CvwqFX+/d9/777/3/qhyvjW5JDqU6er3RVNzwDB9PBgcdJDAmKZA4amDaWnj95itL
FwW5NaBWkB/YfPWCjXtIYSqz28vMCoUZ/2tSmFcx0O6DnUKV34HDJUDLXFrlGU6weqtJ9rLd
Y1EqLR673WNVKq2ef61dDSVqwQqVSq0zawVBoVICvHaziA7/LYLOhyCDah4Zqf6gNx0djU4D
TFGgVk/6Q3uq0xvXtX4waeD5jadTB3v3JHelkj3V3tbUxmTDoARa1u5gWnhZgk5KKV4h/sac
P02siuMqkMqWMcOlOPPfovhKOJsJzgTdzMZ8xEuWMU/XIuvcCGqIlIMaZFgNFjeooQvUYF6z
GlYyXO0Su11OS8Qb8NdBSyfQWKKpuzu2vi+93XZNHkjHjsYU100xoO3+a469u7a3pMZ7+7an
9iaHB9cnqwblAW0Z9gs90mJ9NnDJzgfGm6CbhfqbWRexXK2LbZkk8P1M7lwnnnxxemZ1mkwO
E07PPst8WqsWk0DQyS5JO6xcro23NhTO7Iv0RWf2+iCd2flT2Dm/+61lsjLlsunfe5/XRW0o
fgna+Cy6J9F74frD+/a1H+1I90UiQkUs3T7d/ulr92vSwnmhHagPEvGtg333a/iPJu/u8aRO
9R5NHkrt6umI9aW2JjcMNg1WJKV8PG8MddKcPH/SBhUVTtqxFfbi3vd0vPzQyosAFhmF4peF
WiOjK09ry07BaxhvdMqXlEp+ydylpBZjVGqxxTyiUy+f0L+v2XeZYVgw3S9rUaIlcHeAJYyg
lkSZx+PvUadHHP50a0NsoMeS6uz106nZkeQlF5mdVV4Xh1vFnx8sc3esPmQKJ5XCIUOCYeuf
MSBIiRH1UF8ia1K3J+q3bauNeTwaQGJ/LNZxTJM+t6823ZPoOAWgTPbuS96eGuyp9XekepLx
wTx0ctafhYimGACUyfyewHr/Rs5/SQKMo2AKf6YlA9ahvOB1jVi/X1OlVvkvsk+SjG9zoirR
n57w+1HjxIS2Z1cDSgtG7XBq31Ai2ZBsaxOqU+7efqRNCUk5WbTACgCkOzvpFAE6uIFVYJZq
IFaFNT/79WWT+D+xKsX0LpftBja6Acm85NhvZL4umau0BNU+nF2CUhjcwSorXoLihlbIhw06
DF1++vy2tMD8trjY9NYhabHJ5jToVHwgOTPINlBE5TcA0U+is4nE+vXOYVc6tGePblqfdm52
nv9IWndM5wQKfRjVRULnk9PJ2dm6ydSO3uFkX6q55yMufShVl/QNWgcvpRTSYnt9LlzqpPlZ
3gLf4vQsW2S09iBpOW28NyXJbygMpQDrRoA1s2ll08cKC25wFSosYGD+2k/WLbxa/IUSvvCS
L4zMN6TBUKBJG1zCc/350K8+IvZgtdIRkafW/UTbev3atY3j4Edv/ZGp5T3IhnzIldAJ1922
tNrzjMNIndPbUmnA0lIcC3YngH4csiGmTHIekoTm8uqoD/9lxz33oMQIU1db7quFP7CwL8L9
y7iv0OqftFq87UrVP0tus0zviPbK7eZPoUbUmwgLdUzdO+XatOC/7qxmcLXPNQdcI9jLGbuG
KdfwlUl3TzYWAVscHWVir5M1u1GyJ1Bbh0bXVvwjFkjvXiY+kDhe64ye2wZacRYm2IGUEnY9
7xO73K3EXvk09zcwt59LjPQOMcGh+BCLhoxDLL/JtokNdTd3s/JuoZtV9nYy8WBPkO0xMz2W
dFlZvTrtGdk8wqIRZmR9KF1vTA30B1Jd/et7qluS1ZAu5SAWi05aXx8dxQ9e3Gwl20zi+mge
82S6UphWOSENZHHvVdQEn6bDVs/b6wYaOu8dwodY+BJyOJjDgpbWDD+0qXV3d60htm2gp3zH
mV5PFhy2OjE1ED6wb+HcymdyxnfPzmFXXXe4sTdi6Zh8YFCyxQuAZz3qSoS5WkstqxRiwVg8
xsXNPWa2CpDTpPGToGXGVHV/lSOQlIAyt2KQwBKNFJ+9qyJTCISNuyA5Lmfjlvimjy4V+bP9
u+8YyI1P1rF9NbFAnP3gL/C+47dBGlxLtCeRmKo4X8FO+s762EnXWRc7ZT9vZy+ZmcdMjNx0
0cQqdcwDSkaleFDBKjhGab2KHwsuu6qudKQM/f4n6QorWSQHKaWt19GCDdiVapG4b7eceOr4
kSeONjWfeOrEkSeOxO8u6zm7a8vZgYD0L/PT6RcuDmy86+rM9AsX+jfcdfWOoYeOdrYdemjL
8MePrG+bfIhqh50ne+oVCUvQkN4H55zqJyP9QYPNm7QNItFcmdiNUayF/LXu5dAn9idn51le
IVeVeIN2V2NrZ3Ax9qENHa1luvKQRyvjGO6EwaZTqNQqe8P2dQuPL0X/4daekJ5TalQKDanj
3HHrN+w3gOckmkysv9T3WB/rDDKaIGNjGRnLdD0fCNTXa11pfKm2vybVrH7StL95ppkdMYm1
7ilc6N4viCvcIN+ijV/q/OqxI8nXxZor3dlv1O7+0EBse3dMUGNRNFWdO1trBls8lV3bdm7r
qgwMnBkp39hcaVNwpNJd6W3si8V6a+yVG7bv3L6hkuG7DvUFDXantcyBn/Zx+9zWys6qqraI
z1/Vsb09dntfVGO2GTVak1Zr0SsEpyBUxr3Rjmh5ebhti4gRv40/hh5BH0p0tzw/sSfdNZMO
hC13XkgbHIZjXRMTXRaDwdLFDd2Lhu5MelJnelr2HOkZeHJrDdDOhi8Ej/TvTPUMXTCkHMkH
U+L+eD3ZnDSJywfUj8EIvWG2wxkAzEzXl/FTAhhK4oflK+9CsouBs60KdN5+8gqRC7+Nkck1
pRU0JLxAdyUvuBt6I5G+BndlmWI5tFfXVXjwaJe71moVqrefSyZnhiqXi100Rr1arZeil0W7
lP073DbHMmpqXV3JTXu6QwqFsz+08cSWgq3RvPiFQaFb/8LeLnsWtaEdiRa1UWfsi6jb1QNq
TqcuVbP+6rQd6Yw6VqczhcPIYPKYOk2bTTKlqTrlT5bqUvZknRiZ3nwZD/K9ozewFmOjDTdJ
5UOkYrlt5NVUwN6eCx4vUQVcKgj7TLoVwz4K3CoBG5FX9k88fu51WyK6taurfrwhPewOputR
fTmQbtfweHLvXnlDcDi1K9mc6huKDrqTQkreK0bfOP7GkTcTo2vk1F7pugp4t8J4WdyMXSHR
XH2rXcKIa/dvOrTJ21UuhcmxRhIM5y2Z09VJZR4qK0PIXc1t8pEw16pdYUtwhaxmMca3bmFM
uW/xHjbIPA0mpWAr2E8ihHRfQ8ytW9f6Nhi4kUijaGvcl8DWunDVaqzLmI6UlUUMaa4p0pU0
RlLtTUlrqmJIRXfBXwZnwcTISjDOZsgCo2B7PwBeshuzOYh2jSDZre9+/D1DIcoo+7LsNcih
tydqYl36dGR4V1q3QecGQk2R7Wg42ZVsb/f21faxfbv0kVRT0gxC75FGEbYvXEmG49AbOIHO
s7HF+ZywZAN8Ofl9uTh7ufEm+7LcSHPgdlemLA8ehpMbXBXLA8T8lCe1v3hIkgWOP7bnyjpg
SOp1ahGjPOg0Or1Oq10JPEYh4Z35w/LjVpGAcfsJdDLReeD0xvTee0PpDWc2GJ3p4H3BLRua
goIQbNqwhUeH9955/M7jh9WpB3rvTZ5Obgw596YOJ3tTu4YiqY6h7C48hbqeFkgDyHhAk1ko
P5MWDe9P7c8vb4trttA8DWUTbkUiL/X1Gxfv8MNoz6ujMZYFllGgwuAJrKY+0vo9TsIr1nm1
f7pGYIVRsMbBka/fXKZNvYfcQbzHNeo9ZL/MeY+TR4c35LyHXAEj6wj6QKLBs35z+kj9Ef2R
0dEjes41nN5Qh9IVrm2p8aG+wfXJumQk4m2pbWFbNiNXqiIpS9nEAEQcXGSdim40EaXTpzLJ
QtV719ka/BKzcU2OJ6cYtlswZV27tkDZ0mjlht4H9GtybID2F3C1E/cVyLo6EyG1yWliw8ZW
I0tqI5WaEEm4PGlLdTKk4R3JQK56iT7ZgfMRsXJpSc3SonLxeHOueuleXi8YcUny8GdIciWh
QVKwB4d4/aJ1Z5xXHXpgP+vPlnz+YvsRnISxueUMBoUhg9wDskTRzkTca9Sa+qq8zING5g4j
U2lkLsqZM3ImJGeMPs9Vj+2EjbX55D7/VbTZx/gqkz6NM6kZzFaWj5a8RUrLR0ltuZhrkQoe
RfY55VzSZWfs4tOULLeHYVgm81VOa3aYTE6zloM2x8h1glFwGiC7c7EsI7BKg8NqtGl57glO
IVdw7z6shMwSr21wJ3FLoebJ0bu/4nlOwLUDrJw8v9R564/8LpBxE3okcXurUWvsc7ZWtbIR
HNFVRhhHhOlzM3E3EzQzfXomrGdaZYy71FwTjRqr0qXGFj3TArbItbUZO56fAd8fM+4zsi4j
Y+zCC75RI2evSNoHVYP5ReujoyUk0xFr1UelynX6aKmUiEYwPPIsOlxIkStkz4bjdou92SLW
sueaIBGb+QWrMZfiCnYN+wOWvcFqoWl1W9Rs5lccJwd7sTlhuPyGZd9kFfRZJjn7K5b5Z1zQ
bjVaIUN8gtcpc0CyLyqVC/EcrAo9n0NVoaCoFh6JGIczn+b2AsYBtDVRO+U472CZq14Vo1Lp
kdOVDjjVzpKrMf2H9aze4NznZJVOT9KhtiTVA7LNaEBcucG47RVxIw8okFUyQMvH0eHRbMFv
ESgo8cepi2BVsIq7ea/fXKJj+XuUWjbzFV6DC+CJ7cgYgTe5rRaHls/8N40BF30zXZxewc2C
Txel4QS9ipOpTTq8bjnIvshGeQeqhsh/XcKrsLXNI7zcP2+wPFZTU8lVzHm9atdc5cnmOfVp
bpYWJprok8T4+cabN6Rqd4auY65Q5Z5LuPKL3Nmoze6yhva1RpONpZV9k+vHDeUt4UB7Talc
Y9A272/fsKvJfvhAJFFlba6r7wuzP1dr1Jp4sEqIrAtVd1fbQ56Y12C2gcgmc6nD09xfdYfO
ESiJRiujWLozIN1DcjsKomZUkyhRe2rnLaF5ZPGo9dG58pOOY/rZhjn+tFS+3ppXvp5XjbbY
XVGVKMSlIxsteGIf8iZG17lrq2scgktr0sjwmyuw2cVvb0h8oAVu5W+tCo80VW+pqWwNmLjf
b5rZXKUW/CVdag2e4jm/TC5jWfjIfK0+VLN5qjs82O6v6fh+Q4O/rR+srh9ksfN2VEufK66Y
V9vmSsvnDCe5uWjlnOL04ueKycPRWdzz1hbkFHwiBGuHO/r2tH/kYlVyvM0WCYfsOL+QK3m5
KtobGN6xY0usN6iGCZflGlQGjcrpf/Tjm08m/XKt2azWGrQqo17JVTiOTE1NeCsUegtGfQQ4
PSy3wfhoQtGEXeVomkfV8ybPMYeKq5wTTtbPabOmJE0TORNaa1UrWM9hq0Nn1vK1Bzq6PtDi
9Cb2dTbsqMK4G6xa/nD1lupwW8CkL2+JhLc2YdPBOPfV1tcMH27vObm5KlzJtMsUMo6Dj8zu
hoZAW38wPNQeiLVjKYZBir0wMipQDX4DTo1s3mUyuYLzyCWTcXM1NSXhOe9Jy5xeNVciYk8q
VeshgpSSFfHZrGyJqmAr0EmuQJXd69Bn7rdU9zUF1tf71EqFIVRdU1vy8CeDvZNdG/evc0/J
hocq2ysFVsaX2Kp76hwwUxttDkGvVco+/cimE0Phyk2jjbrhbc5om4/4KPZV5pq8FMWxBsxm
pBfmq4Llyrna4+VzwlzVCfes/gSJf2/SnbqF+hu54ppsuiost4ccz+0SMdeAIY6vdboqBOVH
NDqt+oJMYzWC2fPb1fDfdntNb0yotSh5ln9bo1eyRoOnzrfOahOsmTA2eqwR5n9Z4T5tLVsa
S1RKpcYI2B9hX0W/5n+b3U15wo3m1Z7PO4wz/Gz+boplycJhc95uyo+BFxM2BWwSJqtGpnMH
K1zuiqCL/bl0c9YFwRTLwscLAYcjAH8YvTPsq2wP+I1G7DXqLpdr5gX/5Wr1E0jA2xwz7mOm
WcKIWGbxOjBDn23Oeg1ume2N5tz2hsIiCGwPjXL0KtlNmdZqlDjFTuNFmdpgMxhterlS+9V3
YLLKMsw0Z74jtfN8Rsk7+BjLoTDovpn5qV4ryoHeAjnIzsa82niMcE12NpZC99ZiJnI3zd1I
7JV7A0ZGD2pOlMX98zUdpnl3z7xaP9d10jvXerIjHq6fCc/a8zAS9yliN+keRd4jg8FFy++L
j7Ei6WK8IG1KwM3FMd7eERis5jUWAw6VWjuCAzWSDFa329ywp2Zgu720MVZjbx2qteZhuH5k
pLEx89GVjlmXWqNR9zXWtNWVVTo1gXVbWiSrOAxyR1EoYQ2AzJp55NbPhU4G7N4ZSVpxs4Hu
NawiZ04ukAi6FSVa31m5pVo6sLqd1oZ9dW1b6oR85rdsaWrIPLCEWcImndEfAS4t4LnwU8rz
qGxe7YB5wi/OdGt7SjnOPhIaPN4zON3jq+g/OdB7pNd/zFS1qTHWUy3gf3ft537fdWJLdWhg
etOG4yPR8MDRvshQW7m3ZbimeqjVe1hEjHmRRBf+hKnciQzzTvXnQifLDbayGdtsbk9g4YZ5
lT0BChV9GQnzIkRoMqXWaLcYPeWhknx9OyKhgMVQblfKGNmPtGatHEaD1lXtyzxeiNVmXxiu
Uco1pDauh32ReQd47MTPFrfOe73RqNYxj7RVj9XFH3O08hUn1Y+ZBILd4meL6dL+0lX9OMQ9
ssIlQOkRGRnzTnnHjoay1hqPBpyiXKZ2wyTQ0BtJDCQiZfGhWGldRYlGhp+wl1t9NZC8km+4
05WdUbvGYATvqjZqeKPFWFntCTjsoc6mQGtYUGl1aqsRJmheZ9TFSv0hpy3QQbJlkO4L/F9B
/hZO2JDfE5q3GDSeE6E5h2bOciJC4ga8aEtqZm4s3HgrL3JY7O4LpgQcQuBzzBfkSpurTL9n
mHp8yXbn8NGcv8ZVpeB4CKtVZotaIed272E6sLu/T5p47yOTwWstrSYO4mdiMy+yR3krzLow
ylT+eVQ6b/KruPCMfcabCxyyz5wtEzbkJZZCQV7JHrW69Wa1rG6irm2kTuDxIwAWrayzK7i1
RuJbihN6GqrxgGIGJNvJ/M3I1qYG5oPSMebVDx5hM/Aawk8im32eeYtP6fPPK3w+nXNGN4tm
qEfAD/a+lXsSGVdIwhwgpT8Q1RRmP6wTGIG05G85pbHEYnEaVeyLYBDALUwWPPtFlv0cpDgC
bwV3r9YoFzIKlZzs/7BwWo1DNcxul0bD/He5gsf/D4p68NhPAp8b8VPJXl+dEItZq+d9VnO7
ValYt87aOa+wxmdi66ycq3LGNStxTl87kX0qmWR3hcndYlFCK0uV1+ROGKw6SK6eYxUGp8Xq
NCmZuxh2llWaHBarA8R9DkJQnZWK+yDL3sfItTiqgBHzcZa9h1HoqfAqjSonPPMxjSZzJgeF
SqsqgCKrx+wR1mCA+SM7Asj4UEPCgS4rlWr7vE9QCdbLasE9Y1MZZlSz3FnUufSJcjL0xVyt
mcsmapZm8Qlsq4KJsl6vUdAysuF3eI3dYhEgEfsi+znyRi6LHSZYnVrFKbTK66xXa1CRwoRM
P8tclysBHJVBi19mzF0ldSUapEWmF9B1uYrDZfpvv8xQ15NXO8LUSrUime/JXhFLQzLXyP9H
Q1YKvZwq6GV8pV780Ug5/st8j/fF/OUx+Mu8DL0wZbf+wHyb3wXRRBg5EhrhBa/tyxq+wjVo
RLHOt15ZPK1wuQqXwomGeYYXH77R8Qanzeo0yM0Kq8/h9FkgMPI5HT7Abre0cMO9RrIpjVH7
r9XuCkGlEirc7qBNpbIFQbLMrd8wc7KdhCdXQiv8wGt7VWOsAq6mEPBkvLF2ru7GgQR2ATpe
77RaSvRyncJUmqsBLzUpGKecWpGcs6sNKhmv0qvftZZ4MTfeEkc5LuIuB6tqzPyY2Ym+iVzI
/IIRXTdr7G5kfB2j/T9pTYlCQYdJsyV7+53YA31MpjFYDRqjgpF9TGmGRN5tVp13RSsrhTfI
Q49gIYx5RnDhLXAXtt9HM/+V+RH/APLjN0Q4ryDjFTl31ebRXECdkIgs/PDmD4mZwqRutguC
+IaYGg7fVQxHmTcn9h/cL2NUVpPWYlBz8W2tpd72bQ0w5mwmg0XD8Ideymx/7Y3Mba+qdCoZ
K1Pw49/7u7dPnnz7zR9MgmsHNMg7gS4BJ68CJz6IOnToqtnGXzF4rticasoKMGL8oagIBX3D
WLw5bm5qZENB0U8IZubV0tatcU4NXtlsVbGysQNj4xxD4jsdz07ewZacfPvvvjcOkyMrA2Ze
Zp574zXmuZcUOtAKcPLdzBDm5FO3dMxzsqcBE7BS40ty50uIewUwQbG1QvLMlqHNQxyjspm0
Zr2ajW6osTtiG6sYHkcbFg0ne/CpzJPPXck8/UWlTinD0/jWZ69c27Pn+vPPboMgGSDRAB8X
gY8nCB9gmZ6XbAb0ipl/yeBUE0bWAEgZxzxhr94YYVV6s9ZsU7Hc8ODAFo7VWPG8JWfCG2MO
5s091648u1Um51kZMPMUs/vKc8ztTyk0AAmwsu3Z56/j9zg9eksJdvIPrJy7G43C8SU4fpUc
fxiN4vo17hB7FmIcPI7AkmzXNL5rYd4V7DHi0v+X6wm/yw2jRWcEG7uf15p1erOGt6tMLrPF
ZVJkPlNwKuTh7pVWbpk3s++7ChWe0+kw30fYLcw2+SlWIYNgjXsCzozBmUFyxoLPAM5HMleZ
bexror4flzsfR9w80feNPH3jZQ979jV3hfre0rmus4NTmo3gZZSsvylgtlQ0+Ri52qzXmVUs
+43zC/fcl7kTD0GG42Udd917f3f3hfvuXs/KSOUFtrox4GKQcIG1/Thoe97MP060fYNqW6r/
U0gv2ItDoBjM1/agJdDkZ5Xg8IxmJbe+o70T5jHgARwg44sHrf+j+/577+qQkU05lfxD737k
noXzxC9wMnb93fddQEiJxtAO2X7ZNmiZkBO4iaImtB5yteOJtk7Xde9Gb9x83d5uD6DrfJj3
2nne7uXqVdf11dfrI5ueDnV11a57urWWK3taUV7eaHvaYWx8WluLYg0L9dITm0apQR/6z22c
5D7ESaWpsaHeIjWyZ/glZyqWOUP/5X5SHhwe7vsw+cwMBEIDAwOZ75J/2KOeMJxcEMg/zDXx
O/gY4D6KDzIfxp/MkUDlYP93AqGekYWRskhy6KfeCHzH4rNtyeQQft/xfewb7HP8W6gE8CKr
PabLVrwcUBaeV6HLAZXVMxcK8e45/cWqOZhGC95GSDf9za1L342HQ2XyNsKg32+jLyMMii9R
Yp+LDh1e9zOD02n47j33trSUd1Q7n+7deufFini5qWHvno8/422NOrhrzdtb3BY7e81umdzb
cptd7q3bwDS2dv2rLVCT+dqmZOafTb46GL3AP6cC/s2oFOd86LLFOa8qAXZdErt/8u19cU7V
Mv34+NcxS985+Nhk09nyvhNDd57/zKdlExOfHa+jXDSOPbQnMb25euELj2Gbx7jdBvctxW/u
s7jm5YJcr0dyy5zTyZnn1HB77lTBm/sAJ9E68t7bR1IKn81XbxNfkcfeZs9MY0aYhzVarSbz
VcYpQHD3j8yQnUMRyonVbrf8LmI3ZX5F+Pg+2wF8OFFFwqxCWtk8svJzWq2Rmyu5aJzNvY7v
Zays3Lv44M741Uny3FueBbZDq868xPjVWiHzVonXWwJc3KnW8mm7NfN7SDEz31RpNCr2FeCA
IvB99Fv+J0iHjC9o5+WqS2x2hcWc7RZvDP4W9+XweEvYH+Hf/1KlVqsW7CLvT0EPQYyh/+8h
/jQ7Lns8yieQuUSlc1svcRCOdzZ0NohLTQ0xsZhWTHtwJW3BnRiyWCIV0bJP2QLmEohVMt/F
HOA/Jqx0e72CQpf5B6YOQuV/VGtYvLDwYOacKstb5q+YvRqlWqXUGzIvZR7WayR9x4FXI347
nn4eKdSX9KKKmdiNmwV6xayAKuP2zEMGJ7lttZ1jq0F7rxLZ91PZZVbQWxXkeraqed40X1Jx
0Ss3cFb3ReusZpadzXv7HTFgREWlL7sLknfdyfNGnN3SYInTsWeSWQWvx85m3pA5nK4SLvMT
xu7xCqXmjVURze+4jCHo7bW6qDZSC7tVSpWS/eLCHoLAiw5bmW/hFbauwmVzLMRFLb3L/xi8
QzBhqZmXBV36eaHqkrrc7LhoFvkU17LrX6+njGZfZSfgjWF5/rCzWwR7QzAHFPuuy+4rC5oy
f3DWlTAMK3jK7D5jxOq2C/obm7oY0KSntIT9jdtZylyr2lETP9Oc2auB/9hveez4idDMX8/c
2fdkH1OPB8xCF3CcgDy6h/8l6kAdCU/8sifqiepKLiNdeK6mhm+YK4nzgQfUnzMabXRZqD4m
VTDGlntzGgQlNENYvL4BYRseRbkFDrYHu7aqZEtIoYT0VOVrTNb1f6Blx4EdLaHu0WZ3a31I
zfMmZVl1R7BnY+uOgztauSvNO9rL9DBTKCEbgBTQ2r0u0lIVah7prBtsdKkMFhVvskdNNlMi
GmmOhJo343ejgUY+BbYjIG/CABnOvNZo1Mq0c5aLylnx9Wj1UsUQXbKQ5y9q4KH+KY3mJrbM
XxMkkxoNHuUL+4gJ/KXVXmK1IubW1xW3sUHFZZgllGlwtfiVzRw4qx52euFRxeU+hNBn/hQx
XAFtEOnzy9AvFhNrWZHuALqSIy7Kzb9XklXk0eSfRX+7EvEN/Cfy6CVK8sAydGIJfX4RPSmR
wgzUnUdfUXrz6PCq9BYl1e48mhPp58uRul59PUca2RJ6aCXSqrX355Nuh94P9DwlQ2QZ+i/G
SdNZs4vQs0vJctdKZO22JW2vUBIeta/DVFKzCh1fQp/LkUNLqDmPfuzsKaAvrUYupUifz5H7
E5RK5SI9X3pjMZXFy37qedXzs8Xk/bwPLUunygN59NEV6A/+ff5rAXvgbOANTBU2oPMVqaA3
OBv8GqaQJnRH6LXKcOVdYTXQB/4D6K7wXxSpSP8G9Kt8qmoS6ci/OV2p+p1EkZbI3YQuRj6x
Cv39/6f0s8ivV6ZoLDpbpP8sVK1bAx0Deqb6Zk0VoQGgv6z5Tqwsdi5L/1TrKlKRilSkIhWp
SEUqUpGKVKQiFalIRSpSkYpUpCIVqUhFKlKRilSkIhWpSEUqUpGKVKQiFalIRSrSfxhFi1Sk
/7yEEKpn9yL8tDX8xxrxJ2kzyMkGxTaL9GxCbHOollyF27K8a3hUwg6LbTmcnxTbCnSWvUds
K1EVJxPbKuTllWJbzf4FXym2Neg2xbfFthZVKcvEtk4vV/aJbT3qh2sYwitilMKw2GaQzj4m
tlmksB8X2xwqsd8mtmV51/BIaz8jtuVw/l6xrUDt9k+IbSWyCTvEtgoZ7d8R22pmxP6m2Nag
iCMstrXI5tgutnUKzjEltvWoInuNEXiTfmtCvF26xkx44xAjU4EAZvZ/i22qC9qmuqBtqgva
luVdQ3VB21QXtE11QdtUF7RNdUHbVBe0TXVB21QXtK3Tl3inxTbVBW0bkT77WxP0FEfPIC+q
R7WoDrVAawhNoYPoFDqBZuFvEp2GcxuhdQrNkM8xODMFreOoBr7pQtNAXrQVzh1Ch+G7WXI0
Af9OwNVn4XMcrtShPmgdgDMT6BxcsRl6m4A+tqPzpOVFg9Dzeej3DLnjNLQOEU688HcCrjkP
v5Xu4c3yXIsaoBXMHjWjKLn/GPQwA9d64b5jcB/cx0F0VLy2H44Ow1n87RngbzYrz3Y4P0Vk
mF6Rn0mCgxdtgOMD8A0+O0ZQKJSR9nNClNRL7nIGvj1I5JXQPQe/PUXOnIGrxglqXjh/mJwb
QkngCaMzRX53nODaTn4/Qa6YQMfgnhjlcfLpFTmSrvWS87NEp1PAi6S9nBz4+9PAxRT8chZQ
WGoBbcQGxkjPB0g/lCOqDaztQ8D9NJHkNiLBbPYuceixHrRU+PvqvN8v7pniNkZQwPY2TmTE
fR8leE4W4LPUWg+R4zMgq3Q11v4xOMaWMEXQqPm/ZPXqot3/P2P3g8DJQVQJZ2ZRWPzei3qJ
VZxY1U6PwfdUAirvGOHBK1rDFLHBSTh7jNzrPBydg9ZpoqdZuOsBaE+Tu1HLxXhMwechEUna
62kiM73ncSLxQSLJcXHEYT0midYm4Qy22DME4VnS74SoqykiM8VqlljNLBld1KKxRmfE89Jd
jpGxfZqgSLk8DmeOkbvSPmcJkjkO8B1niCx09EjYU96niVVhSzksWjbmio7Pg4T/KSLx6azd
U8zoXaiej4ty0fF9gFyZ4zhfIozaB8nvqNRH4bhmiT8Lkd6OkR7OExzOiOM4H2/JOo+Lln6K
2MppUcuzWRueILr2ij6ISkN5PCReg/3jHWLvp0EKqqGzWS2NERvBI+RYgVySbzoInIyR+x8U
719DkDpNtNeGYkDjZOxjrRxb4t1qRJ8Yg/Z5oqVDpDfsO87D2THgl/oAqVfa5zQZI1jqSaJR
qnXa13I+dJZgMEOQpqNU+h3WwW5yD4r7eYIXHbmns95IulpC6aBoyVjmKBmj+LoZ0WvlW+0M
0clxES3ay4R4PCZa6ATBd4pISLk7QPiQ9LzYo5wWf0Et79SSM5NZGaJrmqnoGBknmJ4WxyKd
P+h9o9n7LJaA2tQ5gtNBMoKWw+ycKOkUmQmmic+nM9NS7PFv6DirhOvDBR52+d4pD+8X23z/
TX2dV/RWp4nmDhZ4jcUS5HzEYr7a82wAS0Jlob5TmstPZf3wOPFEx4lHGltRUmp7YwVWRcfx
CfGTSkXbZ8h4ofPnOBnVU+LcR/vBV04Tz7CyjdIo47iomVzv0giZyvOxh4kXmxJxxlGHjszn
E6IMkr+VUC606ijRzBhpj2dnm8Xz8OKRULnIL0yQOOIc8a9TRPtYq2NwDiN0CK6QvouJfe5b
NLeHxdGb8xY53yhx816ipzVGK173oj4GpT68pVlrPgLnqJ4kq6G+elqMcnLWvVoEJlnlylEY
1txIduTM5kXRVN/UCibEe1GPfVzUe5TIfEqMjqS4l84Sh0Q9S3ZM7WpGjBvoHU6QKGSMyClZ
yhjKRaGL/dm/gy6yCI0R2TFuU6KvHxfH6kEx8jhOeM2P6aZIbDJLbFPkcWXdQntbYRwK2g7n
YTSeFy/lj4c194dyMZ509fLeLbrIu0nYL/71NImRphbJLfGVyxFyoyY3E0k6jCIpVsUxqXQ8
kWchMyQanSb2djhvhqVcHyC8TIgz1ZmsLvN9CdVhTNT4LBkl01kepHFdaEtrRzV/hqdS5s80
hTadQ+IcwfHY+9SjNBucIbE2RWYij4Nx8onvmcPlCFxxMG/uOL2KP6aef5xIIM14bQVenEZj
Z0l7uazwOJkjpFkmP1qV5onlfErhr2aJr6C6OiDKvfycO7aCRk9lpZ8lVnqc9E5H0dI84P1a
gDS/9aFN5NvNqAeOdsJsuZWcScI5L3jRrfDNbXDUDWe74UwIrtgmfh8imtpJ5qE+uG4HmeNo
H1vhcxiOdxMf14O85BgfDcD1w9AX/u0mtIvcYxP0to1cuZX0/X/a++6wJrK2bxKKFCkaVESQ
oSOEMAkgxUUMEEg0JBhCUVEMSYBImkmoNgiKsBZQkWIFGyoqArq6YseC2BC7rr1gAUGwi/Ke
mdB03X32+WOv5/uuS2Iyc9rd7989MydgMOilgyOlex6ywh/0hIE2ch6EoqCKHwOsUt3j0rpr
okpSNuiHejX8VioayrFHsmDQYgH61O5RMqBNQ+kh8iP8A9FzRq+cgd2SklEbIZQRmv5AIjra
QnrDwDEEzAtF+ZNRnVXSMlAdAsG4ShcKKgHCmdCtq2oeYp/w7hHER4h8dPDq04qM2oCKStNn
P39wDAGSI/SDwCgbrRBMsDIA1TQUtR6l22aItnS01aeVylP+qDaIVREbBIDzYPAO6rUdC/1U
ycLqR+1b20Wg432zVPqRuz/9Ucsx0ZbKG/5oi436ChnFd/uSherxPdcINBIp6CwyqnFob4QE
otGrkr4nOlU8mP0kUfFDfNtflp6ohv4mR1RUesbDuj39Z7sgViejNkHkCu3l/FeUQW5ug0gw
0RMKFnBlErkkVgH5S2RSiYyjEEjEBIgsFEIsQVy8Qg6x+HK+LInPI+hT+TEyfjLElPLF7FQp
H6JzUiWJCkgoiRNwIa5EmipDVkAIZdgVskMOHniIxRFK4yEqR8yVcBNA73hJvBiiJvLkCB92
vEAOCfvTiZXIID9BjFDA5Qihbo5gjgQwheSSRBmXDyHiJnNkfChRzOPLIEU8HwqmsSG6gMsX
y/ljIDmfD/FFMXwej8+DhKpeiMeXc2UCKaIeyoPHV3AEQjmh1wDekD9HKIiRCQAhoAaLH5co
5MjC+TI5smQ0geTaPe6MjvdMBrJxIIWMw+OLOLIESBKrkqfXrHEySaIU6eZKRFKOWMCXE+iJ
XAeOfBQQAQqSSSTfkhJJgE5AVY5YDhSRCWKhWI5IIEyFkgWKeEieGKMQ8iFAU8wTiOOAXcBU
BV8EVop5gIVMDOQlQDQFFMvnKBJlfDkk4wNDChSAB1eOh+QiDnAtlyMF58gSUaJQIZACkuJE
EV8GZsr5CpSAHJLKJCAgEIMB6kKhJBmKB4pDAqAGVwEJxJACsQOQDCwBZhYDXkDNGEEcSljF
SMFPUYDFggQ+oce89nJIxBGnQtxEEFUquRGLiYGfZRygi0wgR5zK54ggYDjABlCMAz1yQRqY
rpAAhZIQlTgQiAGRihdiaG48RwYE48sI8QqFVO7t4sKTcOUEUY8nCMABLopUqSROxpHGp7pw
YkDQIVPBTGEilyOPlYiB6mBWn/PkiVKpUACiCBkjQJMkiUD2VCgRxJMCiVykGxGJC4ys4OMh
nkAuBdGsMq1UJgCjXDCFD44cYFC+TCRQKAC5mFRU557YBEIDD0pkPSexCAf8n2MJeISXyFXg
kcBIAmvxyJoeBsBSyfECbnw/yZIBU4GYK0wEidAnvUQMfOYgGKXKkX7TAYW/k1aVUiDqgAfk
CpmAqwqNHgZoRPTQGoNawEEAuIDoRHBFhsQwT5IsFko4vG+tx1GZCvgYqCMBrMBnokIKIIHH
R9RE5sTzhdJvLQpACkSRajriEAEasfGCGIECASt9NhA5VoLELSJyt6nxUAxHDmSViHtho8cJ
Dt2xwBcTkgUJAimfJ+AQJLI4F6TlAmZGdwPMKOBeNCzQaETI/BgRf4Rkjd0z6MiMy4iZZ0iA
TohpQFQLAcqh5v4WMxFTfoOa+vohiHPkKDIBvYEJ+GAVCGxgGR4eipUBBEQgB6REHNAZsTGw
FfAoWA5JYgDyiRGjcFDU7omzf64FIhBHLpdwBRwkPkCeAfAQKzgqcBUIgWUcEIrfaAuFdsP2
5VGoRDwUl1R++OE8FPGQ7n7hhu8ON0T6nmGhAMSpijdCS6YqW4ADmkSIhngEVQWxyJGPGkSa
CBSSx6MJC0jHJCLJK0c6u6MEaOgCFJfzEbCUSAUqbPtLUVUJD1iqkqbb0qgQyfES0d/oiKRB
okwMhOGjBHgSgGaoLDP4XEVPgPXFMQh+ngBNPG9ViAMYS+L3q75iiQJJGRWsCrrTWBUp3UPy
eASZY/jfZC6nn6IyhL1cAYJJAFzUWwP+zgBIvlEpUCgzkB1BZlEgWigUwmKG0wIoAZA9ORS0
7fFQBI1NZYaxITCDRWawJ0HMQIjMmARNoDEC8BAlMoRFCQ2FmCyIFhxCp1FAH43hTw8LoDGC
ID+wjsEERZ4GMhEQZTMhhGE3KRolFCEWTGH5U0GT7Eej09iT8FAgjc1AaAYComQohMxi0/zD
6GQWFBLGCmGGUgD7AECWQWMEsgAXSjCFwQbFjwH6IEo4aEChVDKdjrIihwHpWah8/syQSSxa
EJUNUZn0AAro9KMAych+dIqKFVDKn06mBeOhAHIwOYiCrmICKix0Wrd0EVQK2gX4kcE/fzaN
yUDU8Gcy2CzQxAMtWezepRG0UAoeIrNooYhBAllMQB4xJ1jBRImAdQyKigpiaugbj4ApSDss
lNInSwCFTAe0QpHF/ScT9H/uEfzcI/gvbPtzj+Df2yPQRd8/9wn+/9wnUHnv517Bz72Cn3sF
P/cKvkfzn/sF3+4X9Fjn557Bzz2Dn3sG/8/tGYDc7P7dBjW1r59Bhv/4B9N9RH4LAcsTiuO6
zwly1Xk4ck6WcWLA3axMJMZD/qkyIR4K4ksS0E8Z+JTxwTnyuAkP0TkK8X83G5UBg8oB3ubr
wdFYJZJ5Iaw0X6Gl45hFzXqvjxmALVGazwdd6VgMhqgH62hpOhmoY0011WCOlq6TFkYDo/TA
YjRKQuGJML5fj9mGkelmyH87BV5MFBgl6KUKUkjHIi/Ysh8xDeNOjs2Usj3P3LwqaXStz4pj
Xw9WmZQoTcJgpUYtrFQvL1HHYrBYnCsQsX4OaejsuV80VXauh/V7pcVoArmSUTHVwzS0cNiw
UCIOHoQ0tHG6ERx5vEAcp5CIiUawAdI5ADeAxeeJJGIecSRshvTo4ob8cMOHaAlbIOPqOJO+
cbZAxHcOVXBEUijEnwyPHKZPHA17wR5ED3dPd/fJoOnZrwlnVP8rkunDesi4Hk4jmBnCItrD
tqrmSLG/QIo8+w0IpUCUUIa3B8kzwNnfzT3QOdCL4ke0ha1VGpn9UKNQ1RN0WImx6m9hjKaa
uhJjqAb6dbFKDEYtV7rOYOrmwj3732/dedZ154PfDa0niuXazxkfbW2XX4iJPFmXsaOz6uGz
2Qs/4O+/Tp5X4mYyzCsnOHaNetCT4bcfv87+6FmtYbE41zjSqDLPa9LHjk4Hr0nzk5QJmhRy
AB6vFL6abdB5gayXuOKzkL4uuDrvXrrdx1lzYt+v2WC91OX2zLBN2y5zG/Jtq5zafQ6OSXqI
NW3dGUVtqixe72XseizXP/hZwyUlN0xj86srS5b8FnUov/x8WgW1yfGSk/RWtlInwurFmWFX
NO1q2g50jAj0WKEJ73y6JMkw63PCAc1ijLrScFOJllfwvGLpXl7lDUMPrYdJq+4P6mhflpKF
ccvLD5kfjVUHebRRidEBFtGEzYFJzQ00hmoYx75vNJuMqyc+x9oLC+JW3S0bUVWPxpC5tYYJ
PDTd2Nrtw01WoFS3ZdznpM/VTrtr3asNYTYywUIjGJ4A00qCSihZ/t0P3bky4Xc7NdIEAdLr
0r3nIXfpdSPiRdSJICoJYAocqaUNElNTcwAGo0GHx8PUnjaMzfqlm0FycvKPGPBlf0NZAeMQ
eW01BsK6PSTVtb9LSHUkSoQlXVENqTXXm3Zp3a8xjyEmvFsdt/WVbryP7dr0AG3quW0N9If3
ykfjkttLSwaZmn2a5TWOXL7ruvaUOeYHz7YML8urNRAOOeqwdtzSavnCIEYItHTZ1KzXe9RJ
62yu+GqtsXNQ0u67vWi8f3Xf6qoqk6aKWAqm0Vu3Ov5VEo7E974+Ycf0x9535qW1atx2ndM1
bGesKO1oVZj2ihF/HN9aOZE7ZN2F/FEU+kfvHcIl7zxuO5Q0G1xOWNJmxeNzTlU6kuxscufv
H+N05tYz6ZftsxIPONPtb9ZELW3ak99e6fZs18YO94zHR8QGCdNlm+/fOaN16GZB2PSEmfH2
qzbSYzQ/XlJUz3kDK7UwAMae94OxE89zPqRlhDzvQmHsRH+r6QEYm/uvgIUDbKdKeov+4zw+
FCqIQ3c8gGORfW8iimYesCeRSILBy02FZn1NWPGvyNc9rv4X4/8RjbJ/3W9TOyB3VXrqkE67
6Z2ybPynNxsLswsC9208G53j4u1KGLks5dPsbRZKzN60s6YH1esDX54sfv9Zw7x9gW6Xlbi0
Pc7npL3JEweLtxr5ZG7zowNDFrfgVrnf9ZSyJWOad1J0YNqxw7lw8cCzSWfey1cOTb60qCb/
tPYCqGXkVvfXM4/fV6hN+LXxj2Uvr6V8XfJp5/Rsn0O/W+yKKTxycn5l3q5rFU6X2Z/db52f
ufzpyK7mmQln52knKe4bTaReea1WR6VvHOD+ZJL+l9lr6p5OfrTg7bVVhhZLtzyeP+zYtfr1
5pjTX6hluOWuhZZU0ofjNhvUqg6H1meKR03JaPUUp3fUNOP0XvagUTqwyGwV3NgicNNbmena
mN5MVe8HV2evxcy/ON3rRVfc8ajGupryfbW4IpiFDA/SAFi0KQimfF9p3GAS0tTEOZFcYZhI
cuJ6wm4x7nyOs5tXjJuzG8nV09nTdTTJmefpTozlkEjubrHcbyCQKuY9CdG8rNw+zMPDaq9o
a30iduVfQ+APEUoilaMoCMIFxDGIYhDASPxGIx/OsIcz7IlCIKcfBIbB4GqlHwRS/iODHhT8
GxYKeCAiOA6D6dLAwmrfpbO6EotR0xpqcTvieEidNXPDxJTrLR++nD909ejrjyPCW0LrBEGa
V0+cbX7YWTxlZfQgT4ejmhTc/VWp2Qdjy2/XvMSGWe/zsU4hi3Z9eK02Ob/4V7NzOisbVpkF
wNs2Dz19IGjKWye3RetzIz1qGWYVVvVG528ojba5t+2yqsu12ZKx6J692eNY85yxhK4I9eBj
4swS0ss91S4h4VO1KocsrjPn7pMPfHQtzc7QsYBSRsocWzA2gpZsnfO10uj0r0+0h0w86TSZ
OMVrRsHWTdkJBQ6S1yd2vThEGXYuhpGxl20atLRos+io2P7UB3uLuhZom17l6wt6q/Ifzlgr
yCwdfV0EfV1wtat2f+Fona8+xseKjLcdzTrXqjxWHmbjb7KXuiAlq+Fj41rf4TeNc5qWrI+3
yY4fs+10OsOuSduSzv2yZsWQYNe94dOZ18f/7rm0i3CnMnqTf8KZlIuVNQm5mcKFsu0vNn9e
f8f0mlcn74xorPaT2ZmVOw9uPDDrYkH4prTIs4ODYhotWzt/OUHUe+8ylrfZQzI9xHdfQB6z
RG/R4bmR707HLeTcXld0om7xWUnQg6OE/JbKd7thUfMM2tbnBUl1h7RPfB3zdpfcQ6sq/OLw
KzVv8+sXmrWnz8AwfxuRIa++PMXK1zvS5F72q7gTtDKXP2wX+UxraHYLWGZ+cNnAJOXY1hM3
nEs1sEupH1vvYC+qbwBFYAAoAq2qIqDLGRrvhmK/2feXsNEonOrqLLfLWdGO52GGD1UH0Ugc
Dg/7plOnN1hBGDqpcNOmDzdZEgkATxC6glgBl6PgQ+RERbxEJlCkIuAOe8BusCuR5O4KewFw
JxHRpiuMNP9319D/Cd/Xlwor792mLnecnUAY/uDQw0cniydah+y8cMeEYWP46lLZJfpOBQwN
ejngKnvlEFr+CL/lu4qiYLtbagnPZh1qzhlg+N5Ao6gt55zFWVebhWvb38SZ4TtnNWWbv2hi
bCw9Zh1av+QT5aJOw7SKht1+Ghs+bhGuiLvu8Edg6O6shicOgQT7HVnMMNbAx+r4zzPy8mDx
wo5J8NpPc68VVj+zLJz7oRHXob0vVMTaQ8lbT1UbHxQ7yH5U7NbCx5e1MsZv+Di/bFCQsY5y
/fyWsJSvmFXmIdoL1IzgwJZ9d60Da044s9dXjEwhE5PPrb43JnNFKQe711y/svP96irMBasJ
7K6PmrXHIb0efC8HFimDDXsRRxNWB4d+eP7Dq0sEvs0NNTRA/GXBRlo63TVhCAbpUYMzilTY
nJEHZyxJNzbYoZw+Lty+8IktrtPxgW7oykmPN5VyN3H+9fBUGqXuHFo6vmTzTro88s0AHIEP
h6iKAg0GdajEv4Sc5fvPr4t7h5GvkiFQjhYEdr+CQIUD4YB+BcHzv7kmRvTwV1H9h9fDwNZG
hb/WRqkHjL7zfM/O5NsXUicGYyoJiplTRANx5RcOz8rdT7gyeMNiUcz+COxZBoQLKb6TNu5h
RE1F5CqzB+aYrB01Ke2LGprHYF49PJyrq1m3hPqwLXTIHWb58sdNS2ZcTT/2NL9dy2WB+vNl
jjZW0s/vOh+nFBP03w94KD1owli7NEFXtnJ/qdeaOOeTEw1exET5Di1aBPk+HGBK+niOOD6J
6OMk06t7IfXpWqCLu3dcl7O07fr+YS8Zi+addHeatvHIy4Nz9PxmXQmVWb6C62tS+FFTMMN0
jQ0abxkXvf3l99jIameXpo8Lss5NDH+2Vpov3OFFv/Iu9ch2k7SYUa0bVo9y00o2jTnjM1Jk
oWzTO42vuehf/eRj85y9jzZtVbjvZ5ycaT3YLknvF9bimZMD/Y0PVlfvDo6rW+/XlZ5qmb5u
CBz7zG/wNNO6dVaWDf7PnZ7XvKGew1+5QUqn2zlSbaInvwhv3XK3eG29t+RQhr1Ca9CrJMsj
q5XH7Nm/Vc7wySlN4uwRl+K2HNke1DZY8uVXkrDq672JdYutz8QeWmu+cDAP6+NcMSl3/2PL
J3t313P3pLA1r5AJITvyd29OKa8uKUg0vbl8IS7RyoW0VVtcMmWx7ZGS1vn1ltdejmSeWfWK
dv89hi/J0ZtTJ6h7Kn5RVniBOKrL4OSUqBvBI0pvfHJZ50sIG5pwBrfxC6wckAYrNWN6SoFB
XqPqb0d8fxuQkf2vQDEJhlUJOeqfJGTfHQERlA1PEuzupSoao9EmEUaa//M7FiX2z7UDi9QO
LKgdIOfK2z7JjMwIO2+ItyuNgt0OtP8Wabneb4RjwvPJIdv3a3maatAOzKsdOPKOR8KpwTf0
2jyPF2vtrvO6ijEm+l3O0U/lLZybP91GWLGOtuZ5/LTGe6tDq3TxtRU3tzntStOpuF4wqX66
qebz2KRnJJbdYJemcu2Qi9UB+6beOEFQTyyP7zgr6vCOKh36JvDAfU/eDjHPPWVLCdfQ+fK4
FR8e3R2gfzUqdTNtVJP+4RJc8uF8n9bPj5wmG1kEhztsSJPdH+y9jzbtRkuL/7LMm7OqZmWN
uDm2cvHUZznM+abtpS6THueNcd7lGnly39ivpMvV6j6VVRXLPec2rk3Hv2WEL7N0t631EvPm
hR5YY7hzuPX8s28OqGcteR/d1sA6sjh/4cGjlgrbaBOH387ZO3jaFnmNH31xduXyXWbWZdti
mzkWMx440NZGZz+0nXrZcsJY1om9Eb426m2X0qa4XLV+JJ1qODEwufqD2oODO7DK6NtHh1Qf
GnElbEKTV6nhc2vaQZP9AbMpj4/VytLuy5ps7h0JLD7Zetws4nbmkuZgGlxWvvRe85T1FZ13
dsc+PFaYMavlWsuEJtqoMpzDlrI5celPf41Jia5ymX89Yk3UkWQHh9ctolqHXHzuOA/msQcL
AnJO6NBPXtns76JY+V78IQWKxOOmTl+5aizTdf6t3dnD7q5jvCnYfTCwRFjUeP9a9uLe2tkC
aufzH5S/vuL5w/uS4b0LjLEaA0fqqoWiOz7+auRv6+qfinL/Ox6ZszeWmOf/u7Em48GLstPE
S9Y5bvBkVXFDHqEyS4JLJmTR/quHPiBvQdaCZO29KYmGXaNJJLTMTetX5lhwCMzoV+b8/lmZ
+xv6CjhjPSI8pJFRCGfkwxnLeo1EUIczMmHfHnZYzFDX/3SbhXwdGWgmEHFkqVypnBCvEMHj
eglgYbeRJMhcja6G/JEOZHMtGt1cU23GpoKWvHubmN+7WU6AzH90IxbXnrW56D471ZRw+YYi
zmq1XsGgB9zlxX4FcxpTB+Yd40cT8GM/1MouiTK/HvZ9pls/5kjQto0dgtvcI1bumwun8ufn
zVkUGBJ2Y+Dy2Y2mE8w6fvFbxGrY/SXh0dgBhFGrn/qM2Hxlr3lyvtfD57wzAT4padYduDlb
8hSZS96ctcMGOh7/1ahm0zbNgatb4j/FE1aWOPo6JkTSuBY6AvHkooLHmW+O5nYEOt3tHNNw
yL1VbLvrSYV9S8OdDoOKYofComADH7127ZxrFrUkk4dtJ50vTFm3h+ale0r3+Kmdu55U3bw9
JHsiJdKTNNPedF7lG/sPd/HekKCoalJOvFhStk9RO05TawvG0WGs0hcXHKt3tDr47YPceWaS
IXMoZUlPxjnyN9ZOZcVk1ZpzRxdm3bvV8aF9aOkq+wfnNxc2vJrKJT+aMmDNwrFayVqXtCoT
LYwPczh72/44NULj8D3yaQOHV3f5Ls2F70qjCm6oXSsNPDSpo3CzzgSqUXG6RYPaqJOVqzf7
UpJHup9q3LBhfVqa1SfqSovyz0HW6W/XfTiSsG9C4cOXiSmmzS88ilNNJnRdq7aOT3xa8alz
0Uu99BeCMRWdcIsGfem9e4ki7jKfS2vDGcwj6RFWpSmDSJZprWTdSt/PW89tmnqsNHt1xMxw
BpVy1O/M6qQpuunUhC+p648dEolmnGHJcfppIeeJSo3dsFJjBxaDgTNW/q8L148fB/ZtjpRk
nEDApzuIddSJA/vvvAAp+lp6RAO4/+gQ2LpvoQYRQFvuqReNH15r18KuNSfi9q7KGljW2gbz
+i0ZSAyH2SWO6Q4//A4f+89/Y6HULt3mLzOb3fvrBNB3tVlDiVHLnM5bO5GSSzi+sbi6wmy3
vVSqZTj3nHBRgST1oIU19a3w9RXO3ejW/GBHO0FsRt7R4K+fNT8d9+Q4bLS/EzPrrlWmpeO7
2QevW8dGMbhZTz78UnhtO6XcJu5CZyq5dt3LdW6O5vlVjRUk32Wj8pr3bH/GNSm9blWSkHHH
ujF/np3v6+AjHQmXlFMv7nV3Voe2TaAPpehqz+B+ERB2xZxvan6hucaQfv5u2Yb9Y7Zf8nva
dEy8wXTu8KKtFvWUsV1lekHPpq5+A2nXZRL+wP7WYTr+NS6SX+gQcqL5ZWaz/HnrQAOH1gde
phtWvFxdYUuOXcZvXLgvY8mhlMFTM0S2aaPfXFowaXlOqRLrAC5PbPp8pEVUYoeArkFoaC79
n92I/3inrV9MToVN+oekXt+OIQYw7x3RJBqiD45HE91JRORn8p8i0nXvyCfejYPF04o07ry7
lX8zv1P76ne3TEisxEbfSfvjyyfP3J0rZ+gdTD7nR4OtqZG3q6Oi3s+8LAyod3jZ7hK7XTCt
efDTx/VGkncb7w8+M9Vk3xr9z5OGk9tcvC+2Xrkds+UNzXXGDqjiWdSM6CXBDWcIfOdxp/yZ
HvPK96yc1nVe7HriZluZknBN/Y9nJ/e/yEoa6GA6sZ7s3fTenRsS56vegcuFpuyNtzJf0Jpk
uDzN5e4vY+YsyzRZVXDqeOCn8Az9Xw48abIJefluxu4ldjPdJxhiwzs85t2STde1NzL/ciue
mT3XaGxbYNS7out7STqcaY+DjJaunV62PkMrTF1vZMfWcyZ7XubNSxG535p3J7k9D7vH0lTW
RGKd5s1rZZ5S+z/SY43MDQplbmRzdHJlYW0NCmVuZG9iag0KMjE2MyAwIG9iag0KPDwvRmls
dGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCA0NDY+Pg0Kc3RyZWFtDQp4nH2Ty46jMBBF93yFlz2L
Fn5gTKQIqQNBymIemvR8AAEnjdQB5JBF/n7suu6eniyCBNJR3XLdKlNptat347Cw9Jebur1d
2HEYe2cv09V1lh3saRgTUbB+6JZI9O3O7ZykPnl/uyz2vBuPU7Jes/S3D14Wd2NPL/10sN+S
9KfrrRvGE3v6U+0976/z/G7PdlwYT8qS9fboD/rezj/as2UppT3veh8fltuzz/mneL3Nlkli
ATPd1NvL3HbWtePJJmvun5KtG/+UiR37u/gKWYdj99Y6Uiuv5lzyMpAQRJkEVSBNpCJtiLIM
VBNpQ6RxSo6YzohMJBNIcEmUC3IXfYgPVx9NCN4EmRAcahnViBd3TQjxAhkVFGILIttCFqCc
SMcDYUbHvAJUg1ZEOdrNN6AGVD22bTTZNjnU9X+283vbJhZsqESxIjIchPKGbkKsYNsoEGwb
tLvRIP3YWkVHiAo37B1+tZbdW6twoYZmoTRKyAqEicotaONJelMPyytNl6J0A3X1sLyKw5c0
GVUgCf+o2mJqSgTKMvSj6q/lw38f1vNzqbqrc36faIdpkcIKDaP9XPN5mkNWeP8CnwkZVQ0K
ZW5kc3RyZWFtDQplbmRvYmoNCjIxNjQgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9M
ZW5ndGggNjI1NjIvTGVuZ3RoMSAxNTcwMzI+Pg0Kc3RyZWFtDQp4nOx9B2BUxdr2O+fsppdN
JWRJdsOSUDYQOqFIljQIoQWyuAktIQWQUEMAacZCMYrl2jv2EtTNghKs6LUX7P2qKOrVKygW
vF4U8j1z3h0ITfH/7n/9v//bN3nO88w777xnzpwzc2YRXBJEZMHBRBUFufml6b2b55GW6SVK
Xl2QOybvrg1fuUhz7CAK2Td+UlbfG54cuJdIbECriqp5lQuvu+nWy4jmXk5k/rRq6RL79oXv
DiC69RKUH6ldOGvemo/0QUSLlhNFOmfVnVlb+OTg/UR3jyERt2F2TWX1z2PPxLlEBPINnA1H
5L2dZP58lLvMnrdkefYtVZ+j/CXRnM11C6oq657r8jKJR95E+OR5lcsX9orOGIj62Yi3z6tZ
UnntOZuWkjayN8rnza+cV3Pjgf0zSPyQSdS7fuGC+iVtVlqH69kk4xcurlkYN6tzR6I1t+F0
X5Mci6Ahn3wdv2/JjOhh+6ljCEl7+OtVL0l+p2jZ+F8OHGwM3ROCc1IoacSGdkF0iMRTYZt+
OXBgU+geI1M767hZeqw96Gay0HIyo6WFsmg9UexAnFdDrW5yiktQE2K+xtwPKVOZ9VdpnUYh
pEWbNU0z6ZrpM+rVtoO6rDR6ABs7yW4nF9EvJu5D8I1ahp1Em6zTt5mj5JVSvCnqSG/EK7jd
N5OD/qCZymmzKZ8qT1i3hza3L+tfHl0+men30mZzBE05Lt+vR9prplPLZcRupGCjfTduo087
cdugd3DeHieuM4+hqlM9n3GuzpzHPJOqTJ5jxuFeGnmiNvoXFH3UOTvTPad8vibqHJxKp50k
b+rvtdd/xNP3B81kopv1F2neCetq8Fy3z994dNnvyzzON4FuNp1DdcflW36kvdhzfK72hvoY
pbXh/rzPcxtt14nbBgXhvJeeuM50D9X+1vmONf1pzmNqoVp97zHjMJ6KTtimjDoddc6NdNMp
n+8gpQUNp0HH+V+igfq5x99XfQ7lH1V+i6ae6rkO968/XaPPpPIT1QUvoPKgDwHB9YitOOp8
v9C04/p0Ap+2iNKDrqX0kLco3dQMfZ1fD6P0U+lj0NJTi1P5ZHxQKM6Rd/w5ZJ1p7xFfcDdK
15+iAcflOuZa/b5rlBZv09rf6w9ijHhTKm0Q/2h7S0KW9VuPynPNidoGVdM17c93XF+yT3zP
ThrfLpf2wtF59TQqOVEb831H+7X7KO2onF9QmqnhaN8Jz40YcxylBRfj+X7v9+NlDPp7+e/F
KdNvoM7m1uPvob6Muus3Uefj/N2p7GS5tM2Ur31Oddo4g0dprTRSPEFdtKuoh/YV1YkqqhTz
2t5FuU5MpzrTZMR+YaBAtpM5xE8o96ZcsZscso22lmz6t5SpraFu2jqyaYMo91Sv7b9rehc/
F/6nzsiG55rEzv/sOQMWsIAF7GSmXSfClNYfOPr9rVXQXsNfTSsk4zNWD8PfhR7WzHSVilN+
ydjrbQCcik+1H3oHEtrHZDuuf/V4hwCnfD3zaC2w4ji/i84DVvxenNGXX2nZb/Z1AF1wqv35
v22my2mG9iI59D00Eygxuamz/g54IK3RfUfe//g8PAq4D1gMzALsQA0wFzj8+c+UR7PwmbKj
fjZN1eupTN9MGfpsqtS30Xy9CJ/h/YY9xARgI1ADzASGALOASmD6SfvX7ZT71/tE/cO+bJT4
GXsILxVr99II7QNK1+7AM/IxTdEupb7Hjo/2Kp0uHqEKwPPfaavdQNliP/XRJtIwrYh6aqMp
XiukvloJ9dayj+ynTjmupa34/+yOn7rhOZ7++1EBC9j/TjM98cf+7ONEpu2nTtrf6SI9iMr1
YrpIuwu4EOV8lKfQReIO4EUya7vgR9k0D3UNWDcbqFx719Dl2nV0utZIhdrpZNLjoXdTsqmA
1wrtgqP/7CRgAQtYwAIWsIAFLGABC1jAAvb/r8nPmAbjc6Zk9TnT0L/zOdOIaeD/Lio/bxqf
Nf2fM9VnzIAFLGABC1jAAhawgAUsYAELWMACFrCA/edNnPRvuQcsYAELWMACFrCABSxgAQtY
wAIWsIAFLGB/jmkLKRYYBKQDGUAq0A3oCFj/LeeopeHAdGC8H72AEiAfOOH/e+aItd317+hD
wAIWsIAFLGABC1jAAhawgAUsYAELWMACFrCABSxgAQtYwAIWsIAFLGDHW9tDf3YPAhawP9l0
PzrxN0lpJpSg9ANkkt+FRePIRWaS3+kUSZ2pOw2iIXQa5dDpVEYLaQVtorvoXtpC2+lr0Ucb
lJKZ0iulT8qQlGEpufZQu8Xe0Z5it9vz7Qvty+zr7Relv/SLqc34xijks1M3yvTnG4F8lbTY
n893VL7eKf2Qb7g/Xyd/viX2VfYLkY+QT7TtR58nAykmky57a3yvR1uVmKE9rRfqwymbBrT1
+3r9kZ+9XXfP3J2LnwW7P9u9bvc6ot1rP5bfdMTfqDUaGOMfI/k9Nuvotj80rhuM47VydPXR
+lW6W1+se/Q6fY++V/9G/1bfp3+nf6//QCaKoVhKwvhnUFeMRhbGYxgNp3wqoGJjlMtpOlXT
bKqnJUIT0cIikkWq6CYmiHIxTcwRdWKBaBBLxWpxvrhQXCKuFQ+IHeIJ8Yx4Vrxk0ky6ySR2
mcymIFOwKcQUagozhZsihFP0EiNFtiimIPGT0defjv0uMZQ1/zePafTbxi2NKz3i1NfoZxl8
smuXdafLo2kE1Fgp/shoIP6Y/4v8740PIo4boT9yU8VvfpOZfvGJ/VrwHznHsUmPKU7XZ+B4
+FvMTN38PcPdPPWkojYwu/+XzG5yla9bu6R+8aKFC+bPq5t7xpzZs2prqmfOmD5t6pTyMo+7
dNLEkgnjx40dUzy6aNTIwoL8vNwRrpzhpw0bOmRw9qCBA7J69czslpHexdHZlhQfY4mODA8L
DQkOMpt0TVBmgaOwwu7NqPCaMhyjRvWUZUclHJXtHBVeO1yFR8d47RVGmP3oSBcia4+JdHGk
63CksNiH0bCemfYCh937cr7D3irKSzzQG/MdZXbvXkOPNbQpwyhEopCWhhb2gqTZ+XavqLAX
eAuXzm4qqMhHvpbwsDxHXk1Yz0xqCQuHDIfydnMsbBHdhgtDaN0KhrRoFBIpT+vV0wsqq70T
SjwF+da0tDLDR3lGLm9QnjfYyGWfI/tMF9hbMnc0XdhqoZkVzohqR3XlVI9Xr0SjJr2gqWm9
N8bp7e7I93Zf8VkSLrnGm+nIL/A6HUhWPPHwCYTXnG5x2Jv2Ezrv2LvnaE+l3xOUbtlPUspL
PDxMqFea0Df0ENeXlib7ckGri2ai4G0s8XDZTjOtPnJlOcu8WoWs2aFqEtyyplHVHG5e4UiT
t6qgwv+7dHaSt3GmvWcmRt/4Tccv6u1ePaNiZtVsyZU1TY78fB63Uo/XlQ/hqvRfa0FL7yzE
V1bgIubIYSjxeLMcC73xjlwOgMMu78GcSR6jib+ZNz7PSxVV/lberIJ82S97QVNFPndQ5nKU
eLZTv7ZdLf3t1i39qD+VyX54E/NwUzIKmjzVtV5bhbUaz2et3WNN87rKMHxlDk9NmbxLDou3
+y6cLs04o9EK13ZMtAqWVx6cHmL3aFa9TN4tOOyFODhyh6HCgttlFOUdzR1m9wgrqTCcxR8h
1VF5UNDT80bJKl02zRtlTStLY/uNLln9fTKne0Pa5bLAcbhPfJ6Tdo2jZYe62wtq8tt18Kik
Zn8H/dlO3E9NjoX/xGgRIm/nKFWlp2PmwqchjeGSdzHJ7qUJdo+jxlHmwDPkmuCR1ybH2ri/
xZMcxSXlHuNu+5+S0qNKXJ/NJS+loVoVtDw8g4VOq7qtRnmkUT5cHHVMdZGqdsh+NTVVt5Ce
Lh9la4swhDnvgjLveGeZwzvT6UiT/eyZ2RJCEWmlFXmYq4VY7hyFlQ689AqbKlvbGmc2tbhc
TQsLKmYPwbxochRVNzkmeYZZjc5P9Ky2rpDnjqViUVyai1Qa5bY4xIaSFpfYMKncs91CZN9Q
6vFpQsuryC1r6YI6z3Y7XgCGV5Ne6ZQFuyzITBNRCDHirdtdRI1GrclwGOWqVkGGL0T5BFW1
auyz8IkyjBO5sEesajVxjUtFm+ALYV8jR3fzR4egxiJrHiK8SMioZGshOcCuMLMrxBXqitAi
NQypdPngeQixoYK2RIhIYW1BzomGu1U0toS6rNuNTBP9kY2IlL7Gwz70XIa1S4Tz8YW7j1yB
u9yzJYKQ3zgiIlcansKk2XiG8D4psFfL529V2eymijK5elAinlX8Cq9wDCev5hiOHgdFeMMc
NbnecEeu9OdIfw77g6Q/GE++SBS42XLRbapwYCHGjPGQVfBc02VKe2tbW6kn7WXr3rI0zKWp
QLnHG+rEy82cPhpxIyUq4B7pbayqlP0gt0e2DU4vqirDvFQJEVLkDUWGUH8GRBQabeR8Q6Mq
PGuVDkPCjaWjscxb5pQn9cwpM+arxUujHEO8QRmc05whT5RV1hTr6GssPpjrYenrJYWibzTJ
wx4rijhZGQ9ScAR6XuVAVVWFnZ+RSZjL/LIIs7KnBmu+KaPGQJjVX0nysvT08Mgwb2gvJMSv
1OG95JpjTg8uK+POG6X1/gCc2+INR48y2g2lvwFGB1VFsi/4XY+uytAnZJqSVproWI6lU3ba
yBSMam9kelEl3m7cPhweR7ZqHCIXwXB/jqfYGyyvPALjjiWhte1Ox5lp7Qxrh3z7yeePrNsx
Uams6ViHd4qzZ2bIsd5Iw93UFBJ54gY8XiGRh9lwaulV8q0Alg+c8bzZC+Sr0jG6RRvnNFgY
3DTagTeIli6BjY6O6ZNmry6TUejyBGMtO2mQaBckX9NG8ibLUFUS/hLfzCbvrKOLsw8XCyWw
GUzvxXsIXIpca/GsnGH11uHJVCHyjtib7BbHEIc8GI1HSlTgJh2eFnj88dTJSdNYZffMxMOO
hIUVTYVNcotaVekfNv+ZvPOdR6XEvBB4eJBIXo63cYK9osxega2pKPGkpVkxG8H2WuxTHZXy
VTCBr2dCubFVqWySjzhhp1Jm9QbjxVRbWeNIwxvEK1cgHn3ZR5N/2pC1qcnR5DXmbSGCkT4D
065IEn4XOh2VNXILXSt30DVG20J01xgdmc1a4MBcroHbGEsMHJa+mfJQ1SQ36NMqnBiJmKbY
JvvgJizB0/D2MGVUTa7Aq0q+kezGra60ooRBKJKlMiTiwNB0GchTQPZmnrNlWnD6EY/xu8DJ
wSFGVvRsosc7QYUY80mKRU6v1iEblfLixcRyj1qndFldhOF14amyytZ2r1bq8d8eo32RbGpV
N4ybwWO8Q/zz6/DbRr2Hploxpif14+Wgj5ikPac9gw+UNu1ZP39I2dr75NbeA78DftfPb4Pf
Ar8JfgP8Ovg18OPgx8CPgh8hN5m0D6g/UAroh1U1cBvwJmCmucgkKBztBcVrT1I+UA0sAS4H
zIh9DHW3IaMgu3be1tAkMRo39FwlzlHibCUalThLiTVKrFZilRIrlVihxJlKLFdimRJLlWhQ
YokS9UosUmKhEguUmK/EPCXqlJirxBlKzFFithKzlKhVokaJaiWqlJipRKUSFUrMUGK6EtOU
mKrEFCXKlShTwqPE6UpMVsKtRKkSk5SYqESJEhOUGK/EOCXGKjFGiWIlRitRpMQoJUYqUahE
gRL5SuQpkavECCVcSuQoMVyJ05QYpsRQJYYoMViJbCUGKTFQiQFK9FeinxJ9leijRG8lspTo
pURPJTKVcCrRQ4nuSnRToqsSGUqkK9FFCYcSnZVIU8KuhE2JVCVSlOikhFWJZCU6KpGkRAcl
EpVIUCJeiTglYpWIUcKiRLQSUUpEKhGhRLgSYUqEKhGiRLASQUqYlTApoSuhKSGUIL8QbUoc
UuKgEr8q8YsSB5T4lxI/K/FPJX5SYr8SPyrxgxLfK/GdEvuU+FaJb5TYq8QeJb5W4h9KfKXE
l0r8XYkvlPhcic+U2K3Ep0p8osQuJT5W4iMlPlTib0p8oMT7SrynxLtKvKPE20q8pcSbSryh
xOtKvKbEq0q8osROJV5W4iUlXlTiBSWeV+I5JZ5V4hklnlbiKSX+qsSTSjyhxA4lHlfiMSUe
VeIRJR5W4iEltivRqsQ2JR5U4gEltiqxRQmfEi1KeJW4X4n7lLhXic1KNCtxjxJ3K3GXEncq
cYcStytxmxK3KnGLEjcrsUmJm5S4UYkblLheieuUuFaJa5S4WomrlLhSiSuUuFyJy5T4ixKX
KnGJEhcrcZESG5W4UIkLlGhS4nwlNiixXol1SqxVQm17hNr2CLXtEWrbI9S2R6htj1DbHqG2
PUJte4Ta9gi17RFq2yPUtkeobY9Q2x6htj1CbXuE2vaIxUqo/Y9Q+x+h9j9C7X+E2v8Itf8R
av8j1P5HqP2PUPsfofY/Qu1/hNr/CLX/EWr/I9T+R6j9j1D7H6H2P0Ltf4Ta/wi1/xFq/yPU
/keo/Y9Q+x+h9j9C7X+E2v8Itf8Rav8j1P5HqG2PUNseobY9Qu12hNrtCLXbEWq3I9RuR6jd
jlC7HaF2O0LtdkTeFilatfN8qcNt2DP7UhNA53DpbF/qEFAjl85iWuNLjQCt5tIqppVMK5jO
9KWMAC33peSBljEtZWrguiVcqmdazM5FvpRc0EKmBUzzOWQeUx3TXF+nAtAZTHOYZjPNYqr1
dcoH1XCpmqmKaSZTJVMF0wym6dxuGpemMk1hKmcqY/Iwnc40mcnNVMo0iWkiUwnTBKbxTOOY
xjKNYSpmGu2zFoGKmEb5rKNBI5kKfdZiUIHPOgaUz5THlMt1I7idiymH2w1nOo1pGEcOZRrC
zQczZTMNYhrINICT9Wfqx1n6MvVh6s3Jsph6cbueTJlMTqYeTN2ZujF15dQZTOmcswuTg6kz
p05jsnM7G1MqUwpTJyYrU7IveRyoI1OSL3k8qANTIjsTmOLZGccUyxTDdRamaHZGMUUyRXBd
OFMYUyjXhTAFMwX5Ok4AmX0dS0AmJp2dGpcEExkk2pgOGSHiIJd+ZfqF6QDX/YtLPzP9k+kn
pv2+pFLQj76kSaAfuPQ903dM+7juWy59w7SXaQ/Xfc30D3Z+xfQl09+ZvuCQz7n0GZd2c+lT
pk+YdnHdx0wfsfNDpr8xfcD0Poe8x6V3md7xdTgd9Lavw2TQW0xvsvMNpteZXmN6lUNeYdrJ
zpeZXmJ6kekFDnme6Tl2Psv0DNPTTE8x/ZUjn+TSE0w7mB7nuseYHmXnI0wPMz3EtJ2plSO3
celBpgeYtjJt8SXmgHy+xCmgFiYv0/1M9zHdy7SZqZnpHl8i1mtxN2e5i+lOrruD6Xam25hu
ZbqF6WamTUw3cbIbOcsNTNdz3XVM1zJdw3Q1N7iKS1cyXcF0Odddxln+wnQp113CdDHTRUwb
mS7kyAu41MR0PtMGpvVM63wJlaC1voSZoPOYzvUl1ILOYTrbl+AGNfoSsBiLs3wJA0FrmFZz
81XcbiXTCl9CNehMbr6caRnTUqYGpiVM9Zx6MTdfxLTQl1AFWsDJ5nPkPKY6prlMZzDN4Xaz
mWZxz2q5eQ1TNUdWMc1kqmSqYJrBNJ0vehr3bCrTFL7ock5dxifyMJ3O3Z3MJ3JzllKmSUwT
mUp88S7QBF+8PMN4X7x8vMf54s8FjfXF9wSN4ZBiptG+eOwLRBGXRjGNZGehL34NqMAXvx6U
74s/C5Tni28E5fpiC0EjmFxMOUzDfbF4v4vTuDTMF1MGGso0xBcjH43BTNm+mJGgQb4YD2ig
L6YcNIDr+jP188VkgvpyZB9fjLyw3r4YOTezmHpx8558hkwmJyfrwdSdk3Vj6sqUwZTui5Gj
1IXJwTk7c840TmbnLDamVG6XwtSJycqUzNTRZ5kGSvJZpoM6+CwzQIlMCUzxTHFMsdwghhtY
2BnNFMUUyRTBkeEcGcbOUKYQpmCmII40c6SJnTqTxiSYyNUWPdMmcSi6ynYwutr2K/QvwAHg
X/D9DN8/gZ+A/cCP8P8AfI+671DeB3wLfAPshX8P8DXq/oHyV8CXwN+BL6Jm2T6Pmm37DNgN
fAp8At8u8MfAR8CHKP8N/AHwPvAe8G7kXNs7kX1sb4PfiqyzvRmZYXsDeB36tUin7VXgFWAn
6l+G76XIebYXoV+Afh76ucgzbM9GzrE9Eznb9nTkLNtTaPtX5HsSeAJwte3A8XHgMeDRiEW2
RyIW2x6OqLc9FLHEth1oBbbB/yDwAOq2om4LfD6gBfAC94efabsvfIXt3vBVts3hq23N4Wts
9wB3A3cBdwJ3ALeH97TdBr4VuAVtbgZvCp9ruwn6RugbgOuhr0Oua5HrGuS6Gr6rgCuBK4DL
gcuAv6Ddpch3Sdg428Vh420Xhc2ybQy73XZh2J22tXq67Tw923auyLad4250n93c6D7Lvdq9
pnm1O3y1CF9tXV28euXq5tUfrHbFBoWtcq9wr2xe4T7Tvcy9vHmZ+yFtHdVqa13D3EubG9ym
hviGJQ36jw2iuUHkN4jeDUKjBkuDvUGPWOJe7K5vXuymxRMWNy72LjYN9S7etVijxSKstW3H
lsXW1EKwa9XiSEvhIvcC98LmBe75tfPcZ6CDc7JnuWc3z3LXZle7a5qr3VXZM92V2RXuGdnT
3NObp7mnZpe7pzSXu8uyPe7TET85u9Ttbi51T8oucU9sLnGPzx7nHgf/2Oxi95jmYvfo7FHu
ouZR7pHZhe4CXDx1snSyd9ItsgPjOqEnZBW5va0u6y7rPquJrF7rDqseG51sS9a6R3cUeeM7
igUdz+p4cUc9OumVJM2V1D2zMLrDKx0+7vBtB1Ocq0P3XoWUaEm0J+oJ8toSx5YWGpyTz9xn
gHGttkRHRmF0gohOsCVoBd8miHWkC7sQJCwgPQQxW0WCrVB/VMi/GGgmIS6hUmdxawhNLPaG
TJjiFRu86ZPk0VVS7g3a4CV3+RRPixAXlRl/J8EbL/9SiVFeu3EjpeQWe1MmeXz6pk0puWXF
3kapXS5Dt0lNCClzTq9vqHd6XKdRzK6YfTF6wuOWVyxadLSIjm6L1lzR6Hx0lC1Kk4e2KN0V
1WdQYXSkLVKTh7ZIPdEVCY+8vq4RE0oLo8Nt4Zo7J3x8uOYKz8krdIX37F143HVukdfJZ3Yu
mY7D9PolTuMXpTLRIItO6ZW/9UtQlj8NRpmcv2kcBppRD1uinEt+u9X/6yb+7A78zzf+mzwj
2rTzqFo7FzgHOBtoBM4C1gCrgVXASmAFcCawHFgGLAUagCVAPbAIWAgsAOYD84A6YC5wBjAH
mA3MAmqBGqAaqAJmApVABTADmA5MA6YCU4ByoAzwAKcDkwE3UApMAiYCJcAEYDwwDhgLjAGK
gdFAETAKGAkUAgVAPpAH5AIjABeQAwwHTgOGAUOBIcBgIBsYBAwEBgD9gX5AX6AP0BvIAnoB
PYFMwAn0ALoD3YCuQAaQDnQBHEBnIA2wAzYgFUgBOgFWIBnoCCQBHYBEIAGIB+KAWCAGsADR
QBQQCUQA4UAYEAqEAMFAEGAGTCPacNQBDRAAUbWATxwCDgK/Ar8AB4B/AT8D/wR+AvYDPwI/
AN8D3wH7gG+Bb4C9wB7ga+AfwFfAl8DfgS+Az4HPgN3Ap8AnwC7gY+Aj4EPgb8AHwPvAe8C7
wDvA28BbwJvAG8DrwGvAq8ArwE7gZeAl4EXgBeB54DngWeAZ4GngKeCvwJPAE8AO4HHgMeBR
4BHgYeAhYDvQCmwDHgQeALYCWwAf0AJ4gfuB+4B7gc1AM3APcDdwF3AncAdwO3AbcCtwC3Az
sAm4CbgRuAG4HrgOuBa4BrgauAq4ErgCuBy4DPgLcClwCXAxcBGwEbgQuABoAs4HNgDrgXXA
Wqoe0Sgw/wXmv8D8F5j/AvNfYP4LzH+B+S8w/wXmv8D8F5j/AvNfYP4LzH+B+S8w/wXmv1gM
YA0QWAME1gCBNUBgDRBYAwTWAIE1QGANEFgDBNYAgTVAYA0QWAME1gCBNUBgDRBYAwTWAIE1
QGANEFgDBNYAgTVAYA0QWAME1gCBNUBgDRBYAwTWAIE1QGD+C8x/gfkvMPcF5r7A3BeY+wJz
X2DuC8x9gbkvMPcF5v6fvQ7/D7eyP7sD/8ON6uvbbcykJc2YTkTBNxIduuyof9cygc6gemrE
zzraSJfR4/QBzaRzoa6hTXQH3U1eeoKep3f+0L+W+R07dKZ5HkXo2yiI4ojaDrTtPXQH0GqO
aue5DKU4k/2Ip83S9s0xvm8OXdZmOdQaFEthRttI7XV4fxAH2w7glYty20BZ1tZDRxstvgu+
8dD9h+48ZgxKqJym0FSaRhVUieuX/z5nDkZmLtXRPJpvlOajbhaOtSjNQBSWF0MfiVpAC4HF
tIQaaCl+FkLX+0uybpFRbqBl+FlOZ9IKWkmraLX/uMzwrELNCqO8HFhDZ+HOnE3nGEoxe86l
82gt7tp62kDn/2bp/MOqiS6gC3GfL6KLT6o3HlW6BD+X0l/wPFxOV9CVdDWei+vo+mO8Vxn+
a+lGugnPjKy7Ap6bDCVrH6Fn6AG6j+6nB42xrMKo8Yiocak1xnAhxmAVrvDcdj3m8Vt2eLTW
4NrltTX5r3Q5/Oe0a7HUP44y8lxEcha+DzLL6mNG4hJcA+sjV8SlK4zrP+JtPyq/5VXjcX27
kbnOKEl1rPdk+kq6ATPwZhzlqEp1CzSrmwzd3n/j4dhNRvlWuo1ux72401CK2XMH9J10F+b2
PdRMm/FzRLdXzPfRvcad81IL+WgLbcWdfJC2Uavh/626E/m3+P2+w57t9BA9jCfkMdqBleZJ
/CjPo/A97vc+Zfi4/CT9FWUZxaVn6FmsUC/Qi/QSvUJPo7TTOD6H0qv0Or1B74hIqNfoKxwP
0qvmzyiKRuDj/0MY5+tpOk3/d65ux5o5mRJoU9vPbcvaftZHUa0oxQZyM+7SVroQn9jnH4kU
NgozfUrxtLXtJ30quNvB982zD93S9i2ZsWrW669jldMpmAbTWBpHV3nXOj2PUCR2KYk0RDzw
QEJ+fkjP4MewA9HIjj1MCAmR54o2aZHbkpNzHNsGBG3UY4paRc+tOcEbsTvPOfjRwZ1ZBz/a
Gzs4a6/I+vCTjz6xfLczZnBWv0/e/KRPb6srPjlyWx2aDnBsqxugB22s02NyZHtXaF2OSwve
WIckSTnO5J3OnVnOnU6kcfbuUyZi0mIMxEdpwcHxQY7OvbQBXTMG9uvXd7g2oH+Go3OUZvj6
Dxw0XO/XN1XT45VnuCbLQn/913J9/MEgbY0jZ3I/c2pydHxkkFnrlBTbc1i6ZdKU9GG9UoL1
4CDdHBLcbVBu5+K6gs7vB8ekJCSmxIaExKYkJqTEBB/8wBx14Htz1C95prpfLteDhk7N6aJf
HRaimYKCWlOTOvYYmlY0OTrOYgqPs8QkhgTHxkR0y596cF1CJ5mjU0IC5zo4FsPpaDtgWmOO
p86UQX+T476durR9uTXCIsY4Wv0io7Vt39ZwiHAlwiBcyVKlW+Qx0jhGGEdXN5EuqzPDxdgu
joz0HyPCI5I6pzjCIkWiKYIiLBHa/Y7HHa84dEeEIyI2ZWKs2+ymnJyc2MGDs7KmTYvpMDgG
MqafZW/fmH59egvnNP/b3+m0ulKRMiL9x7r2OdvnSVKJDqdxIgtuXnpiYpBxx7rqaXqU7uic
kTFwkODb1CHYoaeZGkKEJd1mS48LNS04+MUZelico1NKerQIET5TZMeuqfYeyVGmleJj8eRp
idYokx4cESqGHno+NDLUZI6yJpp84VEhuh4SHb7x4Eo8zZuJTALPdSo5KZv+KcfWlWxLsoix
Nku0PETikBSBgx0jJf/Lu6tbcoIL9Qku1CckhGfK4EwZnCmDM2VwpgzOfAgfoqltxwPQlNEP
92kLIsH7tkT7OdLgn7ZEGPzllnDJmsUVuSl8R7gWntz1xz59grsYf9Zf0r9VhLcEl1LO3hxj
xgwWWdM+MYa875tOFnIGOAezlhMoLLlP1x/rkMIic2yts5QEyyy+OqTBxMkxGgyWcyY+yuRI
65wxIKb/wH5pGOsEOXlSddG/l+ZwxMiZE3dEmoQte3zVoqJD93Xo3r2DyFhyeVXfROeIHgOm
FnQ7dDA5u3y076m8iQM7jksfObdk54GhnrwMUX/arInDeyTYuprO6WrLLF0xtlfpyOzYsAET
52sia8yAToemOYaOP/jhEM8w26HsToMmyn85Xdm2zxRhTsV6Y6w1WzrRUKd/FJ3+UQTvkaMI
/kaOotM/is7HtH5YZZNEFqVRhsj0xU0yPSx60ADqLXq1hE7G4vPmXgmRxcNlefspjFhLWlKr
yNpSlxaX0Soyt9bFTRpgahU9ttQNCO0t/6NTHVpi4J5ySsjHNT4qqN3KEZTgX0nkGpMQn6rJ
0ZKPrilCM4fEu2asLFrz4sVjJ1352lnZZ5QXWkPMuikkPCSq7/hF4ydvrB40oOqSKWPrS/pH
B4cF6dssSbFR8d27Wktv++6Gm3+9f2qCvYc1Ki45Nr5TXGjXrK4F655YtfLRs0ZkZGUExaTK
/2eCfJYvxrMcSza62niSU3LSRJx8PuPk8xkXj5GKi8UwxSVhjOIels8nJfOIJvtHNNn/XCb7
n8tk/4gmP6zFUChGNML3X6R9C3wU5dnv3HZmdmd2d2ZnL7P3a/aSTbLJbkjYXDchEMgFSIAE
kYBAAqKrgGgRpYhCsfVStV5arb2dtra1PbZAAlFbtedgrW39jud89Otpq/6kF+XYxmr72YKQ
5bzPzOwlEVs9x/x+uy+z887O83+e93n+z/O8s5qG3NN49IhOtcUigqeKdjfmPmJCMPKTedOQ
Ds48mtdp9qaaGjHH1JgKw7pn5JvvPFZ4WzGrqm+f+dLQVOOOxw9//8i+x6/LEo98+/w3h1UD
Gv36mYe3Tx3quyB2HPgxshQkObkPSV6DPQFyH3HFNDuJaVLFNKlimlQxTarYNCHm9HopIAWQ
cK5pnM0ZD0Tx56L4y1E8GqWd0HwzDsXQ2xG6tPbGdl2HxE4pHkzQ1iBYT1S5AJdHFmcn0Wyj
U4HBOETDBY7m6fKy27hhTDMg4gMLLxwU5w3JfZTByM7eD8AQW1kjq9OhlwKNH2WRX6P0aLyc
wFmjgeq1uC2sChJrcVstbpEtXKUXPJLFJTCFBlZ0w8r63sX3ydUIrxh2UMGLkTS8JA0vScNL
0vCSNLwkhNeU0Yv5vAyS6JgkOelpPH4sNOSE4KBF8tRJMVuBigSnTuXRuSE4eTKvnI1CQCli
f0DmYkAuokKuRvIzBaQYBsmojHOsNeCSQ1YWIbJEOXpS8iBhlzKC2ya5Rf3sHxkjo9OhF+oJ
AMOL5L784tvUjboA1om9qq4Pj8csw/qQYX3I4L9lAw8jJKsMtmHEno3hgVgudkWMjJk1lMwa
SmbN+5g172PWUDLDcwWpRrwRLQPDZCiUTXU8jRsQizLgiaPZVVbkW46kRsCakAcSVdA0X35q
bOxkyZkDeiG4xvE8XETXgYbH8rqsYRpPTOazq1JwpaP51IhqVieTYiWic/xQU7MIZgZ+SsFZ
BI9f9lwUdSPF8gy/cMPBdVc//onOxTd9Z6Lt5gWFU6JI6VEE/SJntxgsLes3jzc89Oevj4x9
Z+bevtsmFrsM1AbJK7HRuujyO57Zse+5Qz1eL743FEEKYFnBYylIrqg3JPNj33vngUfe/8Em
VzjhCmkWSK1EjCaFvQGamOxswMO8Bi+vwctrRshrRshr8PKgGI8jwoHmONAcB5rjQHMceDYO
YqgDy9lQ4M1J8CKI+ACWQ59jDmhOoQ/g/Tj6zFE9jIJjTc78HI+/zOP8XK6DlvpMJ46i6ilQ
iWbU5SU/5j5WPcyr8/MYj1Y9P4/jKAu9s7jSFZuuNG81PNjQseKQWslag7IrYGVnj6GRE0yc
tYZkZ9DKEoOK0aORCykL2TbPEh2z/604pn5THM2+T9DFsYY2vhahbcM2AdonOh0rHN93kJgG
OKYBjmmAYxrgmAY49hTy/YaLz51AuBmEYQUcBErZ4R9TDiKJ5whaFAlfWxREbws6nJW3X75l
dJfMxbfxP6C7jGM3qxwX+xi350W3J+KDXlN4WP80nsYkFKrqjui0SI+cUul23cfCw5J+Gk8f
y0s6WQnrumJYL68dupgNKGlDWZY/eHp2DHua60IcoyNIFL1ZZ7jOH6oPCKqQkh5fMnhgXYPe
LPK86LTYUSpgtpjFuqEu8ssgMayzog8+i6TNYAcUXyQ2gNOpB/tNwSho0LRj0MQ3aOIbNPEN
mvgGWA68LTYcNAjuYaHM0zuLoRlZahJoOVd5jsbByyqLRmP4JUxTY982K83guN1OnmWsIXe4
xs4UIvPtE/8ZLTiCLldAYoyWwir830TGA8GKFgzE7bN7S/64bKc/Jjr1PEPp0AGjyzF7cfYR
l6TF836EjUu11ycxmwqFTYPCpkFh06CwaVDY4DklTG8etk3jSS1g46mXypo3D9PwUSkUzw3B
pdUIIacfhVX97ElHoiTdy5BE9Fvdkh4F2CeKMpz/ml70qPqkkyimtmH/oehTuKJjZwdhrK93
pFKGOll2TX9EogXq9EUaeN4A/s0A/s0A/s0A/s0A9mEAg0eZRc4J1h9pGuJkhzElN9TR/viQ
f03RfXVaUHaVQQAU8wOUYwmlkZhtT2UykLuNoVT7kteQyxeZs7DDOKRmKEnDw3NCtZKl4Rmw
GAVIOsla/U5HUGKJQobkbF6rzWfliEIvjvyYU0ZmUuO+MlAfkfX4Hh1+mHP5o85rzG6JL/uH
becfYAwMSSFGjNLoh0vHH6uO8K64+8Io+Ziv2snpJa9Niyr7dSLWjj2mZAwxs9mqwa68m7V3
o/L+DsBu1WC3KrD7DHV1aYA9LZvhBZ2YFngYoVPScIqA+RYOG+rMMcoJPAZsTMEIYP4AyqkM
pGGmeRNkbUYRUxVKtPzCdrvtEoD6SEcmWmGf1H6jzWVsdsXCYVvhykCXhyAIVvLLst/C1riG
vTG/V8RbvE3pBhlHrFDyO+0BC9tr9VhYzpuOEa9nP9m69KG+C38rLcjH4yGDI+Gf/WnjlivG
Uiu+u4J4BuXNiFgiV0VgWy7OUGd0QeRSY9iX1AzZChhZwTStkFRYIamwyiqMmZw+gNVjB1B2
7dPA92k279MIk08jTD4NfN/TKF0zYE5Ej8yrwrB2dSNzk4ux0ho+YnYq9Me8ShdWlrJuZG5y
UVHJUXKLilyMOtN3/2sPfO6Xd/b0PfDaA/ecunvxVOzyL+zc+YWNiei6z1+365ENceKhL104
snH0sb9/9eH3v79x5Jt/+861P7pz+eq7nt523XN3Dq6+54dKpoV89wtorXuwBPYVhUFHaE1U
WhOV1pY3rS1vWhOVBiNyiF4A0AsAegXeiA94oWLghU3/mFgFNI+meSQed8w2xFdQa9XEKnMO
Gs6eyqPTbXD+ZF6ZMJ9dh+dTaqoi7SJfyO35rzfer5eCTvBz1S7cVj24/ZqBxFTr6FjNV764
fNuSCHn/pkevbSvUlRYgMhnG0bl+7+iKqxpNs+fivVsUS+nS3Y4sJYa1Ys+oDNsQtMRB1jjI
GgdjiYOxxMFY4kjenAELeOo9BzykJ61BmNYgTGvWktasJa1BmIbndy1Bg7EWDMGxqopqBpMx
gsmcegmgypbtpsSmswitSTTJAbNy+jyal6OMxmbFhoyKDQmnXC8BblAS0WmAxejKDF8rjOjw
eYaFpDbwtPWy6w91NDy0pWhgd/77PUulREf1smuXxq1s4Xvzbe06h1+kg53r2nw1I4/946uP
nAOD++uXhh44tLO2bVHILIWJ16/94Z3LV9391JXXPXsXsr4fadZHccj6mrAe7EcKyj6hTmxm
ETTNgHKzYlHNgHozwNyM8DqRgJpVolMEbNFI1DAWNTMVNTMVNYxFeDDDUyeghPb4zhyeyzna
kXVNBYccWnBR8uCZEtAVNSgA+mhdDqZO5dHEIMw8ntemgvMr1Z2KISVG1pEfsFG7w0dqdSiH
ZLfjjdFYNFqsFHC0NeJzBa0ctcdW27G6dXfRehMOXGrocvXvXh4Ld6/PBhpr49brTWxhtmel
szNz37d7tnT7UXhBPEyPHHtD42hnePbXJatGmaKONC4c2bGoa9uKFqsp2ba8ofD7iJf81MB2
B0MXBoKtK1Gc6b04Q25Bdr4Mj6v8pOvimUmzgA90aXB2aTB3aVGmS4O1a5qoySXTOcmKD6Rz
iK9G0pE075ZhrhuCvFsQ4AVNcYPq3E8RDRDpj7kVuvvcMaf2blXfj5shseHrnsZjWDNKL6M5
Tgw04805jscHRNizZ4BRs9gs2tsgDe9y6xKr7GgFaB4WqWtGhDpGMjkmzAjgYsqZjkX9oOx6
m+tgJ3VeRAlo9EReuWoCLnsir1xXBxcuOWQ0O6lduuyaqTm0urFEs+eXzmhyy6I9Xxvr2jHa
6uAQZWZNmZW7+haOLYqkh7dfe+VwpnX7fauTo4NtEk0RJM0xXKpnrKVpZaMrveqqa69alcGv
vvyzW9L2QEiu8tu9FiYUD/uaV2aal7c2ZDpW71oxdMtIrdnplzhRliweSe8Je7313VVNy9vS
mfZVu4Chm5GX/xVaZyGVoZ+Qc1AfEAH3SUhDPrLLB7omXnxuCtYZbYGCiVfz6mmURr2rwPt8
UjgJGB+lvRalSuIt+vF0uURSziGLLkmhqr9SKkAPFOk4GmkVIvKQUh9SKiPnv1yy8s2s6JEk
tb+A5Hwcxfe9iG0nsSnVZ19RiwfAewTAmwTALAPAPQNgkfALADmxMrdGVozZNSjsGhR2DQq7
BoVdg8L+FCFAJgkZOGwTzunRJQzRYWHYXbZJJeHW/HcyWZFmTsGJUFIsG1lnZdQvM3jr/LyN
2rv4wPQNV/9gf49aN5LYmlU3LOu/YSipoBZEadtrn3jyQHfH3uN7yHARqQt/XXf4stqatbeN
ko7KfDqEPPCVCLEIdlhFLALONx7BXfAedeFxBx414jVOvEbGndOac1AG4Jrl4hEY5CxwyCk7
5WiVf1jWWdT82pLtFC24unxAemxsDB8bG0uOJd0nSqfJynngSBVCTgGLbGqqoOFpu51miBOU
yRnz2oOyyDNk4TIWt8RDnqBFT+G7cXw7ySJX6o8YSdYHvREcZWMcSx1Vuies0XD+WaoTjkP3
BGRvR3nO60j2NuwOhWNH23AUmM/mFoGjqUIGzcIgnsKrBOVIFR6SYZAI4XIABrUNeG09XhvB
a8N483D1cLieIyuLLogZdyJto/+gqaT9uXPm+ecWaXRZfkhIyOJoPhJzMdEdpARPwudPekxU
4V3ifdLkSgSCNR4zWXicxsVowB+RGAIP47iV1FurfJ6gVU/iCQL3krQU9vrCAq6LmkTgyKKJ
/J8XUsUx9V2HC4AzcedPUi2cGRJ+M3f+J1SrAY11JpcDYehT+KMVq8Z2ffxKB4+Wj0Ophj2X
46E8VjXspi3DtGY1eKXHPlH6rGQqFTl+GSMUXx2ZpqZmqWQzy9S018YWPsfpzLGgr8rO6Y45
0y7C0eCcJDkp5IokBB2H/6NQWi74q8RvQHqKMRoKdy24vjW7qxn/hMHEgNx2xFwEJPcfqCha
N3FV8inZEeOjxmkCz+kd0QA6zkUN00QrSrOiVd7q2Fmop01YrtRdqdXjoFyKO1PyqdMotFiy
LuFVdQB5loBm8LGz+fIcrQYHddE5zcVYkJnbXKSU5iL5G4YUosFglZUlRwu5YcogRTzesIlg
8e0UL8d8zrBs4Vjyk8T38W1tdtAzzetn/qTnYXl4bOTznIkhcVKH4tWBggF+Tflr6OXrVEDr
L25VcoVo5mmCxDjMT9iPQQNxmmhH8nKu2O8aGpiqN4TxzHvMtso+36nTaHBaOJ1Wu+INsd8p
Tb2qN/LCOJN5L4/O/kjtPPKS7Tzy657M4jVbugr/3RqJWPH4xv0jNVKkKZwczIb+Yqtd3Pad
qWxX3Nbqbl7V88xrC3oyXjzTOLI4HRK8QfIbQW+oZ0tXrKel1sRWL1qLPxJuidsLz7pr2wr9
ye46ufANe7ID/MY1F98hD1L12ALsakDhqIzFpomOnIG3n095O72ENzSNWxB92UqcDTTUNxAN
NdP4giPMdijgjc0oL4hsnoI23XGv/XzeKyoTDHlxawNxNt/AwPlH82jCvA7dnDr3h3XoyIOs
q3HZWHP+6C1Leg8cy6dG+1pdeooxMFy0cyy3ZPdQTWpkz7L20fa4kWZ15Be8QVfQI/V+5sXb
bv3FZ/sET9AVDlpcIuuP+Jq3PTS2+aHxjC/so0UPMHawggvICqAz16Hum5CILDTfCGtOr5fP
mcbd53Tbiimvuv2BN8nn8qZxnftcXrdtboobvnT/jLyw7I6f3n1eUaN4x48P9vwgvub2/H33
bj18WQ3hv+sXh7tUjS0+9Oz+4bu2tVx4u2Hi86AbuD8Tur8abG2xf4ZuzKoPSAEJ07v+AZ2w
s8bx2Fm6bJd46iW1/6VYpRR1/SOvtLzO5o3jNFqFdIVRfoxOl4liOHr2TZCBsDAcg5wJxxSu
wLcxHPTt0fhh/FuI71E9CG1GlYcR3BaL08wWfsEILkl0Ckzhm4zghN/yrgHJdAeJKPZFBDdN
6GsUeS++T7yD5A1jKxV5dSLIa/FwnBvzuHXnRNFBnQ+MO66c29QqCmsWdefy6JwAdT6vnDUn
3ab/WS/LTrxjNhf24jtpHkTj6cK9rAQExMoipZ0zm8nfRgKFSVZwShYXkmg1q0LAkj8LeoNw
7/mLb5NvU2ksh+1U4q/PZ5bhmXosbp4mFuYMC8LvOXXor94ADxW2bLWiVXKkfrumN9CYuo6Q
34QGU45zht/LKxNaYMZkvmVrPcw5mq/fXtQgsJAPayuFy1QUqlc0owbg4oIj39YxesrcMHDN
wMgdmxqbt3xmqG5T7M9FzeIb7QFBDK5cPZK45cW7lq2498WbF123ptlqIO+S3ALrrfK2XfXg
ZZsf2rbAbsN9SKmgaMbrL2yxehmLS+IG7vrJTbf8270rbH6/5Nd0iwhxFEth6xTdhnn44QFH
hIOft8Ic1RMRcBv6DwQWpYCXVjV8rHqCj6je5YPB5ON0c8hfsTak3YCVKfiUmmcQquVB2Rmw
svjvGGtACbGOEho/KbQUx+RfS9a/Bf9ScaxJiPcjCW1YRGMPSDKDMKHIgnQLAij/+tCGTH/x
XvRwB+heSndA/o1WRzSsHhF903rdp9DqeUJZPVFR+UX7i+/gX0HfH8cay9/vNYUnZPDYuu1q
1V29j/AEtFiQX9ZtLxbc/0WD5SuuhRt7XfUJL7oZlNnpGdbqjrh8cYcBwQW9BRavG7l2eQ3D
mThecJjtPpHhzUYx0pojfl26edUO7kZ3uRDboN5lmLhisrbWvjDzDNGOcjqOsGJ2zEBsyRkx
e3wixImeCbFkD2o9V3g3fToFsVdZKJUnfaB7ApTzn3VPUADGcRSC72alsNMTcRh1hf0fsIgd
tNkekF0hSY9SWn3hW/gemqVJmUG+goRmnzj7F/YDiioswH+GjpJwlOZMIlfYXdCzJqNB8+zE
rxEKclFXEqwCxjiBlrjpCLWt2CEBXRknKDh6NE9tKzdH6Ev0RohfC+aC3xop3zdklYsjyEOR
vyje1oVbGdGt6kE3gXztQuwqpdNbY6uNIZO4mNOHjClDbW2o0QD/ErHQgvFaO0d6o+PeKwVN
EaXKetqSbYcNF2h9ikqFKWeef3qxWzG/V6Fxvn/Wq7DbdBOMFHA4AxaGKNxJheM2j0VPFh4m
GEvA6fRbmKic99cEZT2eoPA07wwmPFudkfKq2XPhEM8jY6XJfRc+Uzr6QigATYrZRuKnvmoX
FwgV/dM7SCOt2IDin4IW+IEMD1U/jf8cmaKnaYKrdkBUIbdVmqLmmXJc5edzrJAGWqD2Eaxq
h3+etArJryPLyiTfCbl2+6NC4Ux8RQzHCZwRPXbZC9LuE91WkS0k16CUB/1HWzwO2SvS3aGA
P0hw/Y8MhPr6+0Kzz1TKypploRAZ+tpwfM2akTj+Hqt2O1lgQFsvvk31UGmlh7AU5H4WsxKt
yKn40CtU/s1HzVvD07hZ8x8lGqSU+82TefNWKPebS47kI5X7e7pu+eFNN524ua37wA9vumFq
X+5osO/GtWv39ocD/ej9poEg4bvtf9y3vOf2nx3e/9K9y3sO/+Setffn23I77h+6/KFrWrt3
PgjsDWnsKmTBXsThl6sMnn4aeQ8R3XwbUpkYe0+n46v+bhvnr6ws1RfZgi6GAqyOt1X9Pa+c
8q+K81D4ZCqrneRVjVvumXig6C6iMm4M9wRaLs+FjnV32FL2z325dVmDk/jjqtsuTxXuq1QJ
zfCZ5RN9SzeLOl3hGn9zv6qL9dSzSBdVWBa7QuEQ+oAYhd8rwtz18BubYkDPJwFs+9YF8Ebx
SCcnZ4qVdcQdtHI6Os+eVNRj38rDqcfycK7ceTJZrqNr6+8SdXRkj1DXnae0Z2kTJ+7dsiKU
ODB404m9Jd1ZqppCC27sMpkK/17S4jL0fvNAaL3NZ6tr7ww7Ij2f/vnh/T9Hmrz9hUOLbr56
XaSuy0ZXEf1rH7gGafVzK9d/Pt/WvfN+TauPIq1mEJMaV32jgbBNNghJsRF+winaqpBCsycp
vtHa6sj+Hdac6pWKednpNGRm2f9QwoMl2Sq+kUdnBrJ/z2vnXrrYHbtEsbuUozkQJBV5Gvko
a6vyuIM2AzlijtR3NW4rWgGii64rPnV5vXfBQIO7tiooXGZg/myr7889+NmO5WmnxCBnROpN
3F+re1KuwoqSVfw86I0u2dYFGZzABetz8f/jchKvhduSzsITzhT84v6yi28TF5B99GOHVFy6
CctUtDHaaPLCL1ZhJuSqjDl9tuOcd5EuuRW5b/F4QKqXCAn5daOygJWUDUGj7LBUQFL5wJGs
MteYzyY7zuWV6RLM17ZiGIvL+6RaPj6Z/DC+8E8qx8SF1q2fXZXZOLBAYHQEgbgzV7tkU1vt
QLM/uWTd2Lre6sb1+5ZWDy9qMCmf6xl9on04E8vVyDW96zas663BY33Xr6ixuD0CJ9gEq9eq
94a99kRrNNGeqqrOLN7UldvelxDsTjMnyoKEsj6X12WryniTHXWxeLpnA/h5D7KvDmRfAaxF
8RkYhczpmN1MCSjGHnOPG67UCsAn330e6r6UGz6YzCuflOu+9IeXfTvMpsJpvSXodPmtbOF0
MUEizoCuyd9WBS/cVtL6flZEOZJbZBh1B+BXlCwiijxaTs1HA4SEvLGdsE4ZohPChLvsijuL
rngKPoDya9kLf9TyK/l2+7Vf3rzx0R0tyHxlV1Biw4s3ZrMbeoKsFJC9fonBH7n+89sXZiYe
vIXYWaQQs49umugJhXq2rCV2VDC7IEL2FXTvIaxfqSRgDmQ6f5kKOQIGhw2lQjkD5/BO2HUa
I4aamFIxUstFSq3oROnzeSXUSxQOlXLYtZTBEfWHqmWeKnyRpsyRgD9sZUg8TSBGoLeGvN6g
kWJ86uZyE08+b3cblc3nF75GrjcYtfIpjjVffJ9m0L23YXuVyrE+ZeCxtvp6Pj2Nv5MztPEO
2VgVDvOhacKeE2W+eaJ6oj4MRc9ysgI1z6JEzhRUv2RBHVuyFo0czZ93qWIpeYliqZSRtGKp
NgLpqTcooyvuCyVljnydPEXxctwfSLoQFP+bwS3RgC8oMeR/En8mWUvQ6wlZGPIs/nuSlQAV
E0FrqAg88f6sjjfPQ8hw4XFyFWeEo0b9he+qY8rkhjppE9L0/QitDHaDaqURYiHmwuIEljOk
nZm0C/1hJvgpOZlXyoYixgeiUb52IspL/gmpks47U5mUS0YGoNhANqWySUGl9pUTKklV+XGE
GFN+HqECLke5ZIqTt5pJS8Lvj9oNuj9y3B8pzhp2+eMW0oTXFH7P6yzxsDdkM+h+beZPUQYJ
seWomeYKv+9wyUYdiYgS/kmHo3CQhWqiUZbxV/GfKzVGRK4LX3W58A1QZ6RNLmshi7CBWupu
pZbaq3ppByEdNfIu+IW7iIxB7NLz/gmZtkzQxWWQejf7S5AfVkDpo39RGS6bAeHUSyGHEy3e
wiTPmKMhX5VNT10g/hMtgLAnVGXScfiDhZLPwfcTK9QaKUpl6vGXWY6mKLMTVkEPhpFVyDcm
1Bz9SUwgNh0PWNEfFoUfmTQEFCfpHDdEFT8EaUpacZantaITeMyAE86ayqPTdFHVKymJS1r1
naWKE3jMZnzO9lc1H0NUC90GutXZ3bKfYgUj/rtCUBCAsxJ5XuJpkjXzhSCBmcyLLW6B9fuC
ZrvDLREvBWGHK8OYrcaE2WZzSrMNIWBW6y/OkJ3kzxRO8XdlfQfM3f7uVDfJ6R2NPI8PNkI3
rREaaY0CdIAap/F/5ExYLGbGcB6DfhvWovWMW7SdSi1a8b+l2DVqmSbYnFV0PI81Co1E63ON
ONaINzbWdVVP42jpvxzCQyHK+1ZdX/sr/CCFpYq71pWtxmO7NowVt9WcTG4Yy2o72NPIb2wY
c+eMnANvdDyfh+uFlAva81gIt1PomnXet/J1fXz7K3m4rpyq2Muu7DweU/MQGpbJggUVhC+z
QCN52hFKCQqMGrHtUEYiOwWP2+U3td431Lt7qLbj+m9v32dvWJ5t37SsgWd5PcW4u0e2Nm76
9OroN+7uGe/2X7aya0e7zPM0zfPrOpdULdnaNbCzr2pJ48oFbhStWcFpdnpdYa9Us2b/6pOO
2s7EklXdPUhHDyMd/VK3C6vG2rHjSg8CeVNDsElrtTRprZcmDXX4t4J60zR+Nue2JWH3SjIA
z5yAFpPQJ00KyqMohCGnx2yGpgVBSodoju54tM+9RBjIouER3aASSpEiHNnSTrEy8mPuE+q8
KEzM6fPqVB3MRWY9qAZbhLYjWxFxY7YPhl7VexczIUa02xUa+cvMlnvHksuWLImxFrfN6rHQ
KN9FybuFjfcvXRrffOdo/Alb40gu0JFbHOvZt6hjbbMTf/OGpw8tEaMtiWtZtVrJ6hYWk7rZ
PyYWhoXlB39ww+Lbxtst1d3pwsOrRtu23AzsYh3COEC+iC3AfqpwH4+yZ0FtcL2uNbbOTEJD
6xIParw99wGNi2+pD24QXM6YMuEm55v+nMG41B+ZxolJqY/8UwP04/XGpdAwoI/oB4F9JmeU
l9K2+pPadqkc73e+mVcvIMEVTuSlvgbyT3m4yBRcRA9XOZrXD6o0VOkjXPpRH1olnfScNkKA
0DHOtv61qU0PTSzo2vXwZcmhngWyniYsRnOsbU3LnluCubG27Ehnkod9jf9FdIpGZ5XXkrv5
2A2fevamVsEVkk2SbIn5g/HgiSdGD65NRpJhVvKqqNK/1d2I3YCdUrK2bRuHroJfqa9vHsI8
0/i5Y7HYRuvT+DmMRYydy7k2Jmd29Ha2rGgh6gdyA0TLQMtAb+eZ9PjSXiRizrBuEPOQoQHT
gBNwI/sUA4XAN9OZUfeEjI1peTiUwNKvnTp1WlQ7bYEdyZn8jl5zi7+FwAaEAYInlauPd57J
o+uvU76Az5e+gXQqoKLvUOwYviTZmVF3hyDvMaZm82rEqSxcKPgy5QPRqEbyqUvDb5ujJLsj
GtXURdqoG3vv6V93c39Ib0H5k9/KOOp7GzpuXswqZR+J5cLm9tGF7kitoitjVXYoq+lqTWe1
oivQbGv/qKLZXP6zy201ksPasPWR7YnFTSEj2dS/rH3rZzbNvgLdc3isizAPbuiJrF0ze2fx
CPW/CMLftDTROVhvEl1izO+L+FUdhxUd2wSnhXdWeRRrOPSjG7MM41lU033d6gYdw5mM2sqi
p5AN7MF+o9jAyPLcZWAD/mjOfv0zRAybwHhkAXZsK5E/vtOO/pYbniaGELVvQCbhXz7B6a5e
5prZ0NuZWJEg6ltzrUSiNdHaVHcmuGopcnH01LJBcUA3oKS5lXbQqeX+p7WnnoR3068LFSZR
pVx5g2smv6HXnPAnCKxVaEV2oVx9Vd2ZPLr+MviC43ntG5TkeK4VdKo1g0tVVP8/VD9/Czs9
xViDbndYNtGFQ/P0H0qV9X/DrR9D//gaxuIMyU5E8EzmwlP4Dt6gbDMjGaMe/2vBON8GFq5J
/b/YwIVX8U8YjHqSZDg9LwuFpwpVok21C92zuh3YfvX54Elsz/YVJBjG0uYV8DTeuRyXac+s
QH97rNF14EztezqHVwwT9eO5cWJ4fHh84+ibffuWboSVq79uMCPPmNqXIq9CTdUOLpphlyhF
OWQQ6UqzUIpB6oO8GeF0WvjJqdPCSVGxB5d52D9MYOPCODIC5fr7Rt/Mo2+4TvkKYx59R7s8
k0ffUgtfg2Je7SC7aCaPvkqp7yHLSM+1D/ARJbUiDqfpFGop9gozoLTCr8b3StzjI9sO0Wy3
1l1+26pVnxxOvgHcQxTeaF7iiHhsrI6lScbkiaXdvVtyvj1mC6U3Mnuctd2JeHed01ev1xEW
3li1sOQ8io6+Miwg41lhS5KT7p5k947hurqRW9dsYESXFAkUfLs26g16nUm2+EJGI8dU9e/e
jL8fiEgukelrG212e9JLqhcOpU0WZ6XpqCHCWhlMkOkspIGTXoFi8aO6a7AolsV+qHBSf2cr
zrmzwESzsK8rC3sOs8BhskBpshBCMCylRuqUFqBTWoBOaew0pQXoFNAelMws4bIxN2WqBsIi
9yFaSx0zDSp+ZEYhPZ3znhNVWU/OUJwow8zJvNxngrmTeWUylEEU0jOnpl/JLNFKLxcZSj5C
0Wwz+SgjeqzwPH3vw5dvuWs0nt5838YVB3OM1Q/MR//Yok/2dCKeg3hPV7A9tyTmLNKcPYMj
gwePbL7+6UO9ixcRXHGf/OxixHA278v13DaBGM+iBoTuGEL3YcT4k1gj9paCbnWqqbNpRxMp
AUeUAvAwpRSsgR2dNYCu+pC4wv0R0zg31ZP8RpKAx5mngEM2UhpBojQepPybU95V8k8B3sFg
zQsHqHsp4jkKf5nCKcqTeiXaJ791hWmniTDp3/IMaiW48tOqKtV8NakSIuVJcUUBIarmhfwn
lGtEU68g3mmS38pjJsFEmEmTR/9W3qMyIeU5Npg3Vupyf+gKQv+ONSm6YMiHY87Zo74lO4dy
48tSPMPRJIF8V9PIrtyOb13X0rbrq1uuevCK2sfIvXva13eECIKIBftvHKmzuWyMyWkxSmae
c8pSx03TN13/5K2Le3Z/ca102wN1AxPN0J9U0Nf5iCjuU/qTzG6IkVUX3ycOoxjZhn1aqQ/Z
BaCdCt10a+zeXWT1bo32uzVzdsMPvddXV01ffDlngacGqwwzTb2u6Ez90sCAsFQJi2lgRcmT
mXdVZpmBLSk5sckwk0dn1kdn8tq5SoBLd36gc17puEptqrK3UvvmxGEKORvG5ku4qxoDphdZ
Tq+zmF+EcpmMwtUtapp6S3jpNX3h7giUDMySw6TTc3o5M9SyWfUnF/5UDDukTXUiYxtuH0kY
zbzkBt9QhdhEC0JqArtR3fs5WV1ti6SAS2YN63fC/x1pyGbLboV4wWE9HVnDrp3rKd3VkKNY
N/WNLPHN9PXWtcz0LG0ciCwVBq6vTHUUoIoZz8mMwiIzp9NqCw+2HpxQr7ZJuZwrD9fr883k
0RV7WmbyxWvqrp+bAymQ/rNUiKY/HtIOjR18SOpEtyC3AanT4jhrAXciMpSe1mfqGxwdK+vE
J9UA8eR8xVSPHh5zLcwkHCYSZ8SACz5L9C1dFtt8x2j8e3ZItdq7FscW/V/WvgQ6jupMt5au
3velet939d5aW5LVrcXd1VJLsiQby2DJNrbBscu2hG1IsF8SdsgkIQYbwoTMkHPykrzzZgZs
vAWSN3nnOLwwGXNIhpCQbeDMvISEUyfh5b2BLJbfvbequltSyxtjWWp1q+pW1b/d/7//f7//
2MjAbE+rUEvyXZIEzLN3THevyc3tcw9viktkMplSrlQrrxWXIX7Lj1CfwIzYc9jvEb9PnDj4
HOTz2WPbto1u2Ql/O2g6WEyooMugGPWNHgRfx7ALhKvk7Xz408eeY57lPlte2HmMe5i5u/ax
2hZmfa2oUiYkWS1kU+84BV7OZ0EgPsPZK0gQBPvPS0Sezze3C34kchsK6CdfXiMUpfieYz77
LMfCKz18jGNXXqtXiyaL3vEsvFxJxcIL2mc4FlwSSYkwa/DikhfqDlYwFq8LwIrg2XLDMuVf
U7z4TQx1p8Mi+57I+sgwirIdf+6CouIEokJrJSjdDCQlhiQFBOXtSPbWV6IyEwzbkewpgezR
QPaMLwGjIDHoXhJlb4ldKYUhZl8lOWRRAvug1MgtvphjtB9/Y4VkEIEdcw/dwsuRYpUc3V6X
TAW/sKeQvMJLZudU987VkrlaSjfB0XUKCTA6Jp8bWKg7FjYLdlryHSCNO/gq6jOVSmAmBO1v
Wk1D8fNuDBgDRqzQnpZzt1ZmmEmuWA7SGa7AxGuumhoZY0GkoEW+2H4RilQ7SpULcuS6Vc6x
8NziJMfCswsZjq2fb2vIR1Gc1URGfSQu+xsfS74DCe8FhF/3Km8qXr1Bdp0Ig08TwxbgaZKU
3ueSQwLeNOF3ND4TeCCVghlgP/Ys4kF7ezcsDfnjmVs9nmFoBE7vT3WDl3PjleHdJrjgKi1Z
9oxuK0e5mUr3MDfOrKulGLsQMTZsPgwWL7XzCVLIEh7N4AwYYg8aw8HCQWaiHAuGAQEG2zSQ
rdhs5pdFhC3WBG7a3AvLDVIpzwWzjK6vCCCm3KyVrzw+tuVozW+/yjrAzZp2folB4Ju8BHTn
JL8WdObRR3ee2AWt98LMzMD4ZjiD7zy5swNZ8QH1wE7wtZCAK5hu772HF04wX+A+Xd61eYG7
l9lbm6uNM1ZHoRauZQFrzjtGDeUKR4nGGyYH1jLdqw235wTz6S9wLBz83gWOXT68A44PrDW8
AlXhWKpurYWLNNnqlab52otD/2k22k8stTDJlcdHtxwb88uN/LKpLV3NDhwdAQIBNzgjlyDV
/ZHM8gmJrZUZvo5lJWCPlYqPao+hd/An8hyQKRO2ia8tPbUee5k4gCkxL7ADm6Z8UJosXdnk
FDPO9Vd8Sa5LR3UxkZodKf8bl/ScKCPv5H/x/hvvvAYlgp5i+sc5FhzfleRYXUk8A2r5G45L
ifyyqsB6BEFeB+OWrcJaYP0peU5BRz3uqFWptEbdniitMF6FC5WPjdDJkFMplRCAFQZH2LW+
l5A57JJ/dkXgCBGXK2xXKOzhP+euRk9+9pQrlCq9zeBzyeQyYJ+dNp6i1PuIosew00hPN2xI
fRzS8UxyLskCt+rgOWUSfBW80NQe25pC897wusLHGR1FDR/mdla2MrNctZzyFbhhpr0mErs+
7wHDekkkubg29xrSS97kloJgqBIYa+dhjoWjVWc5Fo43XODY+ojLZkJwouPSdfPkKuyRtJgT
V/OMel9hbeaZFfEMadXSvmvpkFdUobgdTZVlwNJUELCUIpQamdEeca7vAyx1XDdL11IXzapJ
tDXHl54UdOhO7CmkQ5sFHcoB43xnIHDnzjzksY0ZGsiaP7YTspnZxk1U8gMcw/TUgI2WnLJP
8rY3L7DX0N7Oc/gSMLVAr16BfHXypwPWMhPbOBaMwAxwLBzDDgc5zYJReOuaF1kKxlmbq0I9
De8bf2Stsw/smTTHQy4VRRISqVKqsMe97pRb91G08E9/2Xp4Jg1OUqj0er3RqZcplKZUtUr2
35BOLj0p6OTj2HeRTt5///znt0H92xcAvDoIeDUF3uTT05BRvsfnB+cH80cO7tvQfvzzzGe4
o+Vt0/u4IzrqCLO7NlsbA7Q+3zOZZtoa8Y5gC6GCCqy7JHqmkHtN7ika8+hnOBaOemQfso/8
uD1wYDBXwqHtbc2RjWA2oa62Zii1BpsMLQuvb0aVV6vsZQ1UPVsyZEd81MgMdsBHpHpQFOgY
LwqkDIiCzup3uFMe3Q1otzBBrpSI11tz+S81RhQUnVEHBUUqkwJJ6SQ33LCq874W9Q7wkQ/y
qCJnRkYyA8z/wP+IbcQsRASTYiHgbWX2ZWQXCPacIQO+NgYvENMll31+dmMPt6vCbOTmmYna
ANNWk4bUnpq6ipXFupT6glLdsUJu1fv5d5rEZFcPx4Jh5jdy7OqBbI2RxNWmVsA99agW/0i+
MzkF2QSzHbaA3RagYbbjm/iCWik3oZyKTrr0kMhMQi5TZTuz9LU96M6o4EFTi/DTv/ywRZZD
0TKdcuOutOA9u4ANeAp7i68/eYhgzz6+bVvfvn7oQzOJBB1Gq2B9bN+TLwMeP4ipoCdNf4Lu
A1+MErI3jE3XmAdV1Geqnyx7ubsq+5g7udlyf4bhppmhWmctzBjqYVF9ui4WhdCo4UUDVi/3
o/ntBlFh6Lu8HAsHn72TY+Hw0wzHLrsAHy7VZ+/iVZJoN+0it57Km9zzFcImd8lNAUdDHNBs
DsRBneHF4bp95BUWgPfLO6O0jhT9cnwjTLwBUbQotVogigfVqtaJt5tatVhmC4AgrfTPW0oq
L2HkV4HN2IDtQTbD6w2WlXCO2WAPwmnFXGjPjJVNXLES5Bc07AwlOnZ1H/qNugWwjJWLJo4F
R4sLGOh4Wz1QXhYj32xITH71I2guin3tH0Ev0VYB3tr+K9DNe3hknZJiZiab8XpViG5nt2cy
/fvRusQ927KQkO5yqf8uQMg7KtuY27haORvs58pMV62Jog3lq5OVX5QAxDUIXrLvrvIdgMBw
lNptHAvHKfdzbNNItuVadiMEv3m9ov5VVB6SVx7LR1QewLBYU1Br/0/UjhaLiPxKxe8kf4dy
DE8if7g0Cpch1LuDQaxj9251ebYdg5aW1qsnoMdj2TZeYtqZ3l46xbkqo5iaoxkpSiPmeXe4
WORnS8DHi5CNRnFb5qltaAAHWx/BleJYOAat5lg0ik1gID9MYnnNYwvWNCdtROZcM/GM712V
pKnsHw2XPWoZSUrllNwMczrtPh3+lBzWoviM8l9BwA6j7tddDB12WWTgIIlC74ln6MqukptM
r5HG4cnfnPV5U0TtelPIJyvnxHyyO6DXKqThsUMThJbnivTXQMu+gP0zsk8DA44JmPs6G926
VcNqYYTqmHR84gGoYm2a/RoH+Ip+Csslop9gWObQodwd3KbKBMNw3eUHnNool2P8NXPtERi9
yMRSt3wjRC3yK0dNtQKrl45Cwsib7uBYOHY3mOjQ6Lkox/Ljyx5BkY2sXg+Xb4Ss4l5HyQ1G
qK14fGOsl/5aofcCZpV3lTxX82lhri464gFKuSy1h58IVWASL6iB8qGQysxu9AcgH3CDKBwB
ViFQRv2vkHyYgXxIJbc1M/TqujrdUlg2z889sjmu1QofgxPQxzvXliGIZ9AJ4tvHyO9hA9gE
tg2nkYW2GFMVWD1QkavBD5/ehNcq7cULVz6EidWiUDcAXt8+B/9UlE2CX0sanRGvTToluizZ
LpPBLLceZWG/U9KAX1LtMqdT1p6SwMxtqQOmbmfhJWZ9enDabFu4pAKvYV1WRvaM/lQ9867F
sr2H/E0/0+Ybeqtn9La3fJPChuciD7D7Jp+GTLRfgilbK5BCCKxiAB/qLyXA/4T4A7leaFz1
6E9ZtcUy8y4LB+8nf8PC4XuG3mJ7Rn23vcX6JsXt0UW+/FX/Sj0pCQRE9LgjUSmIxGirgGYl
BmrdsJKlq1usZ6GtIELDOyL1klgI0RCJRrWk8I58zKS7L+jKz316onun02gd7HpveGE63bHv
a4v7n7k9qffnfLlMPuwNdWy9rxaveHG9wbC0tHsuW8lYd9+WYzLWmW1Tv/HFbYoH7x7bPeAk
Dwe9oc2ZiY/PJN20Me0Jpgkl4V+3pW9gYVMuXNrS4R/oabfba8l12yPhuaHxezemFHL/0vtb
7/T1VGNb7vB2M5fne4uE3J6KxyyDw+7sAKo2AfLxLPlP2Drg+TyCsu95zwZoTTCtFivD2gVN
zI1N91TzAxs8kuAg7E6bGgWxLnk2WLO9R/Fs4zOGKHZ+5yKyEaimSNN0ZgqeeoZNjQbhySUF
G6xRtvdYSmAKn//j4+Nwq7i3c9k2dcJaV/HVVSTd7FfY3M6ZLrMcrmXAhd7qx0ZKO4Z88dFK
JSoWlsQr6ytxMUO8qrQkvP+Z7UmV0aLR6c1qmMcz2U2Odbtru+OFkG78gedvP/TSAxVDuC++
X8Fv41EsfYCKTYrr79/Vb4wP5+Bc+gzwKp+jFrE8j8N4ptiBtzWguYWShibMbgHDG8y3Vg8P
j4yAkhFGMipBUcG/KXlkZE8bSu+cT42GyvWEDtCgOnYuX65c4GGP7SmUx1Gw9cN5Z9R4jXTN
ygV98rllK+rHRvg50SQT65MrX6jeevV0SnNRspghIbCHrvwJn6IymAXzY1/nUY+Dk8GDQZIW
6uqXYVOZ0OvbKzCseMyql4lFzIVZ1oKcFchuAaQ8p/TCrhCwIfYZu76KaPgmlxCqb4TKJx4i
3w4POsvyRwHSvZLIttqqb4LuIbQUwETgAytpY0r29Sbgd5065IMixjCe7W2LF8A3LzcgQPtW
E2IA/uEZpXCDImKAcCOtEQNWXbrpikBYSRKILZwfHgX6/zSgehXbhO3gpfSb2CixcHpDbOsF
8HKLZwDQCVkDlJxSAWuwc8ATHKlum4FU2zKerhZWWoM38yAoQm1CGgbhjXf0PEyKqj7AOBzh
HAuHCBZaGoVX8glxoGvZhVWb2bobxGjiCdX0O/lXHXv+Zk9ufjJnlRGEhFJKFfH1u0aKW9d5
AuvLo5Et91Q84oxuTgxlnIV1I1HRBbz8PcDHtkRfXxsxAn/Cd7zRMJgNOq1Za3ACo2FFRuP2
cFfI0HfHo+NEu0j7y//Wu204ZIgXs8Rh8bO6BIjfGHHlR0tP4rsAf0JYFnseVRBP5mEnGFRk
D17/D5TtsFhsBlvEQCEPQ9Yl1JhwXBMsFS/7dXwqyFKl3Y7l01AP0oAfL8a8VTN0C3lmAm3g
uYhqp3iNgPpwBpwTSyOVACdQZuTnCXx7JcHzi1oGIUgv32G4TFGmPKVdFV/KppDgpEwhkwat
/oxHK/pjJpHSul1HNybkSo3BqIHtEShziqmS/321AmE4otsU0KAQv1/ylBo+6jnwpJFljydI
KMQoQn9a/iDX8RjXuPWr37EwQxwDM0QH9iLyzdTFLjyew3MlIz6eu3DldcSunFBkmIP8VKNX
VGSYe5mIYgFMLXB1bfx9MGk46FQKg0zmJw86oKJiVVe5vuSFlrkugukio0d1cvm3Rds3B3S2
+WibcPh1Q2kIQOTHGktMD660TvhGuVCNrdDAauwDmtaLQo2po/VCjmg7AUUt2FQdO/8gws5v
DdHW0AlkY8uijW1g5ZdvztA27pW/K+p14GdtwD2Iz04jxIxHfV0iCHcvikD3Fqbx8uoeHjw2
aVOvj9/W/QSPh4b4zJ48jzaOcMcR5DhyF+AK1vkNEPFxw8DqVir8sKtarryMfwgcFj0uPT02
GkK134OjA+VUTzVVszdJSzPcc0FAkwWRoYBlB70O1BfceWoMOh5n2LHRQTSall0+nChOAkbE
1VyRtXwTi7D3URA46nXeRQFWOzmSLhxCFSJwTYZODqcLh+seCwTJoN16We3xas+Wkaw+NTVW
CW2+u+pt+C7BwgrfZfUnjfn0nk2TjsxgLDfSZgJOTU30/wDX89gFxHUdz3X4Q3AFV3J2jS4u
cCubR6XXix4haqLR1D8D//C84BQiL0+ZGm2zh6oiu2BU1eiooF/GIecp3jFUsU3n8CmKa/Jj
OfnXdg3rhH56/Bqu4TJiAiJuh54h3J32S0BFiEXyKqKjqxjHY0Y8boConRE1HpHjERnehgAf
W2CYv90SwxwGN56MElc2gaP7loOjv0QoIZrveR02vgDYab+A46d1o8ELOCFUzcIdawJZM3XI
8znxHw+Ggp9hdaMQDIWoV8VeDxgK+cveQ39/18H/eqCrcOjvDoHX7n9wDuydBKGM31ncO8ns
HfHh//vANx8eG/rkmbvA6yh4PVa9//ZCx7b7x0fv31HomL8fUu+ZpRPkjwD14P7JU+L+SX9X
i+4UvB1stKmAYYiF3zqJNlEi1GN+F2XLvZNV/eSaeyevvnUSnHmtrZMtxG7trZNPzMdGBkuh
JvkzW5xGWbw2PpWC9bz/YGlHWyfL0ZF7hwe2dDvw39z9rQcq+kBHcGlAtNqS34ih3SfaBuKW
2oPPH1l/365+E4jtlv56ZrZ/1zFew4mvox3EfE3kQice0QkkbbQXEkirE2iug6Q1NsHxQhpj
DkDxcEmRGI3oLL6qpYYJZhZNy4lGLHcqgQ5Uso0jbYIFXVG53kpXEdGkxNcJqUIut7pDFnu2
sze4UlPDg70Ft8YfcqslJE7eTnsMCoVCbk7Xui+/sFpXH+gaiepIuVKp0EIEqakrHPEaoEkV
1/M+TWasODY59qmx58eoJsDt/xCAtpGWDsINp6YVQNwIgBv/ecnLo24jvG1o9ATQbVj+D7XW
+RL+H6i9hhK6N+qSSgBbjYDxiurn1YQ6/Ytu5XuGDYbthgUDyYNr/wwiYI/S7/LCWofVFkC1
5yCUcROodlMkWAp3p3/BGpTvsZhBb/AZSC0pAGv/DKFqj1L0u6IY1yG14W6Mm0HVJl5rn79/
Irt5fZZWSiBqdqJ4S0/bSN4ZLW3YNFWKxqePToeY3rhFRpIoVx/oqmbaSnFLrDS9aaYUxbXr
WSAlVrs55DUBB9TpcxqDXeFIR8wbSAzc0t+5o5pUGy16tY7WQxxG2k6bgllXtDPmC7T1b8R4
blL7qYPYE9gfeByoHvzn2G5sK6D5ILaAv30mFDcdfQgGEr06u27/4O5Bk05nGtwtGb8PGz/K
eLkj5Z6te8tj701vmN4+vTBNpqfT05vbX43sHd38bnn8IR1nZx6DHrmCt6jNG9b0cDGwgBJB
b1w08quARr78XP9LCNjEw0F0HGWOeDmWv9D0GODMtH7aNw04g661t/1VFlytvPldFlzPruNY
O6N4DDn6CsEeL9+5ljDw/kjzNuKW+9OIlfyyXJW/Tbsc11iapvYTEpnaG0OZBM9RnRGigt9r
Tw/FY8NZR9AthzGGItA52szkq4tIasO+AXvCSFuzWx/YOH1sY9uvIMa4mLwQFqcNtEGl0onL
083713LleGnU5fO0kI7eq8tW7471EanUxkSGDk4t2zTXWKCG2DC/I/ZL/h7rxR5D9jOOGYIp
wSakBFuREmxFSpjZU4JdTaHElFWT4oKMW8NZmVwjncFdgoazXdi7duki2kwOhuZYcKy1ZNVw
rJWR5ZrTEwmH/lJxGQbtqvTDGlwj9sv1vnjaWt5Vcn+S59l/EcOBX8NsLKB2d8UacpnllIJa
ngrgaX2VRXxEI8mfqY9ju7ATaP6eHhzM72qHD2+fcEXyWD4AvjSzE7uY+Xlpe2SCm2W6YWZN
yYwnay6G5qQVYUKGOR6YegGUuShkdi4J1fcopaMThpid4NhZhh9Fw/LDSGmOlVbE2RmmcuBI
0KYtT8IIy7Fr5FWvvvFTJDLZG2T2VwPDcJ8USsElsijD8iqfd/sncbpaSjSRdW0ekOcb26hQ
SsWoWmPTVXMCzm9Yk0lwLxvgCvk7KkNE8G9gGCYjwsTfwKbM6POfA4ke5CsJTmcG9TCyTHg8
CR20kmqyMzHI6BNcXycDVxteDI8r+G2Xl4DtwzOoLBSumCGOaMChnQmO7St1MmEz2mmJjkc7
LVE1Lqofau5DdP1U/oaHFrdTL2Wuk5JOx1+evnF6CVL8A8lPwNTxNYEuWkCX04mJWVRDqxnS
uMAX1pnYiE0wg0xfn4/JMgQzq01wnYwRKmp4fGuTgkNZvjjHpyovwrRyfVezQDo7PwzG6BlC
RTKds1pISEBGo0BG2dZl6g9FWg/3TbbKTdKrdk62omgDSNbQyk5IfiA38FniomdpsIngBCnT
eWKtSY7/o7iYhPY2G7W/7qrUs863uf16rVKgehMzDGaDRqNZix04LiLAL11pbW9k24G9+Tz2
GuLU7YeHIafm74vCxNDQkSG9A7IsErk/MjXUGaHpSOfQFIXtmT964OiBPUru0cp9zGFmOOqY
5/ZA7ArJ6dlxWOJ6tn+8vieT51+ez1gAzkGLxM/vTelmkZMONPCjSo6tD71nnmP3MLMVxMrZ
8X44/jlWuACPVJDg081FARD5enZ1tlad61aoJvbXM9Oy7RJKIZVZUI7Yq6vvCzX6+axzsomb
MoM/2kI65Hr/NWUDfwNmq8ODAc21d5auobTXqcvNwoPMKkpJCxZROoMs4hneIlKEaBGlg0Dz
9/JrnKe9A5PIEO7N79XunZvbqyWdE7BCaCgH1+BOh50zcN6x7hpnagNMjkkkfD3ZHqJnEnNy
YUYCTYBFcBUFA1Dk53poOZEMIeFB3Vh3oaE8bGMsrEffA8xBT3gSCzs5NsxYJMgKWERPsGED
6hUnN8796zDI+O5mFhu8a1jcBouJYbcVVRdBdOpMk9g0jAqZXqOC5GpMXNuiN5egAD6egMgE
5Lfqq1neYgeuisKoLAqjsijspRJF645RPVpgxP94jo9vvYIn5xU8OfD6IYqI4S8vokbtQojs
FeI+L9oJZUpVoyrKXg1dwKkGPEFzq8x6mMbDEyiEE7QhtOG0AUqwAvu5jkmwIm3U1cgakc/K
jG6L1W2Qjj+Flq3EVJA1w2QHjq6Xmb0wEaSor2bds2mi/87HbicC9RzP/53cNhye3UQcaWTc
UC8a8iigYhLXCDjXVz4sWeHirxd1Ygl7cQ//iwenBWpYhFdzY0kYvRrr3b+u/L7UDVuHGfCI
AY/q8RiFB2Lgg3UBPBTA/fDXoh8P+XEf+tSHh3x4VIff7cf9cOu8wmBh/D4QL/thhxsFcLL9
EAkBvoP88sPx1bDJaazqVzmqqlqjdwn4hyXm0KpXgv8P+97M8dyBvWASzrOYH9dT6EIqcKH6
GDySXQKom2CcZfVGlU2ZfhGzz0OQR3GCJJYuIXRDT8yulSy9JqFgx0SrO2hSSJYk5J8Jpcnv
tHoMMvJvJQqlWvaX/wbRDCVyrZLcrDYqSCD3BPihuOxQq4lfQYQ+Qq6CfOm88ifqQcCX9XiO
50vlyndK6wARemCZTLwH74av4TQe8eMRHx7x4hEPHnHjURcek+BxEu/tw/t68b4U3p/E9T4L
Pq4XEtTwtaQE4q/3gRH0OuFj+Ioawujgx7rBKjoOkr2on9Qf1H9KL9GXjDSjb6+Gq71fSOJJ
+LckXNnQm2jmzuQ9SWI9+NRaQ/7jjyDN5y4Wi5cAzXnONFoR8c2I+H+IJSX3YFWn9+rhpSRq
/joldKENSZxEFzGCi0SSXUmCAKIq4S8DOPYjCO2S2AavBPzP+Tl+45G0zjoReZGHqWzBxaZf
qQcl1NIHpMYa83jb7Gry2wTxPKlxxD3eKHi39Edg24B/6goAx/MtgvhfhMIIdM5rlBM/JvA3
CYXJ77C5IadlZl2Dz8TnFIrLhxpc15llChVgukwDmK5QAKbDwi3YzdYmviPkSiABcaCZY0AC
MthXeQnIASoYIGYKtGxpaNP60rgN6MI5iAdow62C9aLFj2hcATWlDeaV4Dn9GN4TxLtUuMoH
l+4hn1WqXDZeDaoM7qqhvjzP947K1PtGQcXhdQd2AW4+fBnYpQjVTLaEumwCuhyWm6JeT9Ci
kvzkxxKVJeByhw24ArctfSDHTVGfO2hWSi69LlEavE532Egolv6Y1JrUFAlRIXcvfQkC0lJq
kxY/j39da9JISKlStnQKn5TCTq8qs25pHtq1pRPkMZRxFXokOQElOqFNcuJxJ25DqS4bHtF2
aYmoAnfAZbpeB27vgWS1496qXWmqKsckk9iYkGKCXaUSvDmBZgWCwTUfJCSOICn8JE+JbhNs
ihzpqAPCmvgtUmYZ0f5xaS7v8BkI6TGFnlz6R7k+5PEEzAoKx8kPpYaAzxUySJfO6g2U2qzF
CxKjktxqsWkpUq7TXE4Tb5pUFJwToaXYgmHEj8nzWIJH4/4mpgdPSsOuYBHUyTEDjulQjCgI
RdhwASdetDO6KEoZjNVhMecuzcEez87TYTs85CwLjqGifIpg7AYxMT0E8WOpXCu//KbFCSUe
/9zSp/Qm2A2ZkKgMahn8bOkI/jU5iAfKEAbT5Q9oadquJ/b6wxBiWKqlDT6tzerQX35Kpndi
BDZCfJcoUU4shfVin0U+m8zSewG/5QwGq4Av4FtKbl34pM/ntBz3pfFsupQm0mml82RssftJ
5WHykIAihNqxGxC6enNZWNgXPsmCk9OW4yyW1qd/nybVJDg/5jzJxhaV3U+yaAwBTEjAq2x0
awmsiVXZWFxrhqokSk6P3xGe602OdXljY+zwRo23PRLuT3nkGqO2b9e6kbmC4+HpWF/EmE8m
iyHi39RqlSYbjtPJYlt6fYoOOttcGqPFEHSZzB6bu2s882k17aOj0VAU0IoFtPqy1IRFsG5s
K6KV0pt9Gd8M01X4Z0oGzORVapMvBBbt+7WH2k9Rh8XkSKEggM4josCjAskXWP44qv0UC44U
UyGFFdApK30XXt5lQobOwidCiC9DRCtXPp2yOQN6WktJ9Q6z2aGn8lvaS7f2OD6v8eZD4XIm
VokH8149+UF5cUNCSQdt/WoNLJsjXRTE2wY/ll5NhTMb9o6ERzp98a5vp1PejmGICgue3EbZ
sSw2LXSICl8AT6xTWp52B76oWySfScaelR3mO7ojZHG+HVSJdlueZt26wBdZ3WKSfIZNymLP
srLDyxpBoZ5YdY42LYxLebaiJyZshEQWuLXv4c8kxvYMmBOxiFUlJaF5kiljRX+lNjaaGIyo
ZDIQYXdojBqlzf/U5yYPjYWkKoNBqTVqVWajUuK3bt+x/TZ3UGGA+w0Z8FT3Sg3AjnXyaLen
FfbOl/FZEMqk8MdKeoN3v11Bxl6gF/NfUjfJeoHH3Ra5CQ+iYy+w9KI6/yVW3SzQhWIDu+L6
wLGAEN9r9xtonTSzo3/otoLDN7itmJuOyXSIo9JHY5VYCESXak8+EqqmiX/nOTiYyWUmP9Zf
PjSZiETwNCWXkGBOpJZm0mlfx3AwVO70JzphjrACnvkA0PcwlsaOoXqZNIiKHjnjNBickQv4
5pIVc5pOaLWK9HEfhJ6yxZ/wLSpO2g6L3aUWhSYK4toVpIFXazrBgnMkaaDmEtxJgvN88SdY
36JNcZK1Ha63m4L63dyNqY5TRVuWCUEDpYo44DAtHTfGh3KRYt6vVMq1gUSu23fyZHR030gZ
BEKPSNaPBDtCJkKCOezRdW20Sqc2OVx2rVpBPXGyvDjRFivPdxnKY9ZYhwfa9BDxffwlqQvr
wm5B69BGI6alL+CzJUNbJCB/Knsg8DT9dNtB1yHtQbR+wfGbGt7PX+SL4c1Z+VNs9kBb4Gm2
jQbf/JFoIaI53VtfG6Vb7fHpatS54y8REikpTVhhtHdErdWo7pFqnWYLYPaECtinCWtuNG/N
WRQUQf2L1qgkNGpnm7vH5nLbloqA9RLIf/x/2twuW1f3dKdDrpBrzBiJteEfELuBzvZjNew2
7Fd8RmcKH8FimBGfBlPaenzmfC4BvsLOdRfwmdMybBwaMye2Eb+lFAtLThQOxqZOlCwbLISF
Oa5Ly8gu4Nao1b7S8a5F32Z88/GSD/dBiFe5ivHdjRUTc9wiLyMgOOfenOMKAkjpGz+HWJQ8
OOU7COO6lCtITrDgApapEyxm0YNLqNXMcRZd5W10la7ScRZeB4iUD9eQTReyoUBCwDwDl0ro
X5lLFOo4MVev7+5aVd4NvmWry7ulUuEdsVujGDNq/QO3dHp7jEpNxPdkutbhClYPjjF3DHqS
UZcv6KDtgYHN7a6M5ZxK9e3ebmfcqentcCWcmnRn5pGgbWwk0RvUSX5mp00JW5rJOzRqpVVv
tBFSwhLpCcSGO9x0pNMXG/RoMo5gn5UuJDJMu1NK2f42221wR83ZDr07tLTX4yEkzigd9Ols
PtRxjPg+8UkwIwl2+VTMCDnowlRAnHWYyxCzak8lFgP7rYeoQ2LRcKG5AQo4IqE9xdaPESuF
m2chMPtErl4pTHwSOBNmE5hwunuCTJziZx+pOAulb832TuVp4t/r0trDVDKppZPi++b5py0W
GpgpAEu1A+gpQf0ZVQmXeOml8Z+Ch8PAI0LgC8cZu34BPdcvGz1pYPGu4xxrL6E/gcdxvAbl
wrTq3rubqhL/H6VzWMQ7tjh0lCaQTfsD6ay/cc+ETSqXEgT4cb7N44m3eT0YceUn+Ae4Gtxj
AFjTMSHGx396Oq7G4DRiBZG/41zEvWB+hrob2k90nxf5G40kL0DPmI2U3AuU+RmWQnIt3G4j
edzF5xa7Wt84jhlTTBedpsH9qeRShc5iCIdkOqcJPow6kMn4g+mMn3g1O9HlkcpkapPeZSUp
MlUgOlY9DS9NO4A0dWBb4LMMqrAc/lewHxcgOA0e7CzwEpX4BdiVC1YJLrj2G0S5EsSK78uF
an+bj2iqI6y7NmQLcepu1BHKTDRN7JAZXTTtMiioH66UqTMSpdGBSj0U2q9+XyVvEq7U0r+0
EKzAW1KllIRPLDcbX1h6z6jjnxj7A3jipurrzWeU+v3oqcTq6/38E7SUoj+svK/GfTSuLWgq
+Vsw75axA0hTu4Jgsj2d7jdAQXFhZTDzmpXaU4OLvlOFxf6ueH4hfsjaRF2hBi/zTgH8hwS2
DgK9HVws+E6xy09YUWV3FS1e+R5KFF/iRdf3nf4WPBiSpo5O33BMqnOYLE6dLN8ZGKqruT0Y
tObnc9VNNmd7JmPrnciZ11b1le8Jmxr8G2pPd2dcEbsqtG66R5DEo4BaSaGrU8jQsGtazKV9
IboYsvoWRALxVW/QqiHSaKPaF9imI5pq3K5CjcbTQ4t2FDLUBB61qydYiYlEsAf99vz29r7p
3DJrVoWPdGLVI6GHAZZsPfC5vgKexgS8LqHHqBl/DHbYAl6mQml/SrcY/CIfLTT1GNXZnwJO
MxX8ohgeXLuUrIv4SnzyLmZyoRqI1o5MjB6ohj+nC69Lt62LmeHrxCbyg+GF6VS0tr8yfHAq
GR/bX41VOj2ujkqyrdzhnod3y+IfEl8GdwujnNv5VfysEpLfgqIcM2aBIY4ym/FKKOeC/kg9
0IHberjmQIfmo5zGoc2xDjy6+YlWln3VebE61inOr3Mk22JWUQApLa0PONp39DdiHSYVK8dC
7TDWqSxOJhQmt3npMgX7LkmBH8VB9QQsymUzk/tQrJPo+HYqzcc6QPbwH6CIuIyq8AMOTAcd
Y7VDeTG6GNBZPAuWQ42Krfcv8ijbmqjyItv4+3XUafECxzc5xn8AwhtKrgIGXAf8CbpZt2xt
kaBJ66dlwB//ocGmlVFSSmWLuZe+sVziKt6YVS6RS7WwP8sQ8V2cA09R5JFWv4kV8I1nfUlf
Um2/gG8quTF12/G3c7/PEbmuJ+wFKryoPP4dw+sGwkA/QR1u7hI1t7xNVCmcazvO8m2Aw11P
sOhcg/I4KpEC9sJA0U8IPOaBaVGzqLnWFVFdIKCXLK8pEOI+QBEuVNzS6etLe9VSkpJJlO5Y
Vzg10DZQLcZ9ham8pz3qUFHgL5SUDmW8eeB8jxbbyHsSQymbSqdTWy0ak5rSG3WBqMtvtcZK
ndH+BK1Qa5TgLwY1pdFr4g5P0EaHUQ/kIKDX89RXsDwfFbyIBb1RyHW9SafyHow+bVc9bTqY
eEbGa+kltGH94vvf/RGKcv8/cV8CHkd1pVu3tu7q6u5aeqveu9VSL2qpte+W1JZ3WbYl75bl
Fe9uvBswi4EEGLNkYAhLQiYvJDAQSMDYku1+ECbkewQmgHkhA4TkgyQMA+QlcTKZhDiA3Xrn
3qpuLchgZvK+h41KtdzyrXPvPec/yz3HFd7tSNyb8zqyDvHenGO3Kf1VQ8kloSbFLFpEwZmM
/yfoCFjdxdfQUd7iDkWl9UsXiqJoXcAb2t+tcCbeGqn0xXmW52hGdmsg9tmhtSiO8f81nJlj
WfhxDdEOfl9XL7GiSub0D+nDnBNQil5VV4jpam4Q81MlJjCpPZ49kSdKSm4ppbxessh4wBp5
Ypx6WxLoE7XbcW4W9wQvC33YG1M9Nq52c0PHQJ2bB8To9Mp8S1t0bqrIbEvqbD1hnqiP15cs
X/iXOfNqqlGueA7fFKZfAv3GSSWMWlNqFKDfkRFH1BwF2TqYFU2RaNTm22PbT+3RhQTy1vg0
rLeWak2V7usiwkjQAvCjaNcG3XyiWZsOO/2SmWGfZCzOskAg5rIwT3GcIAec7oDKM3fSzBHa
LPs5JyANq2Qr2M14b7lZNKP/tCpWM0eTr1nncKBvmsw8A99RRb/E/C/4jhnUFWQXQyRa566p
cVbDx2TFqFPtcJpNnZ3ObmyLU0zO5j01nU7Gn9zj31/8Mr0UZ6nsFCk1Vaw7VazALk1uN74m
5+SPTlz4+8f9yhyGKWli2AcZsyPq80ddAr0L0ZsZwYnPnBbmWyxjUnxOT0Ax0Ydo+jJkkr0u
l9fOM9fR9D5kVnQyiZJ9HJk2W62Fr40RzS6LJaJZreib+gQw84U1onGGV28S8MIyoGENtV+X
r2VohNKocpBXQkaDP5RHtObRbSNusUa05NEp0I4iMTG1JyZywT1KCUYQMv5w3CQpaa0E045/
fpx5HrkNEZYwatc3tjgScYNsHgPUmkx0P4fkiE8LOcz0FdcwAmBbX0TmH3uAR1LE5w0qZubA
fsYs+V2+sETz36B/K1hNLA3L+cUXgc2R+GRkLZhtcJE3cU//M4utPCab8DFeDaDtbwEKRIt1
myh0cthstnjy6OYTUXdEcDvz6Nas1eIO7HEJ0h5hH3OZAZ0mlmDTubxl3FNayfhuFGxtaWHG
fA/jqmwtZNKVnqCE2AVvmpA95NMAubN30TfRvBLUtJCEOFqyiazZZjlGuyWnlaVNVrFwkEZf
MllgSYkOmSKS6xX0Z84O67rfsLmjN06GnPCHKsujn2VFIap81btbit3H7QNB9Qz8nVB8KmuP
epWv5uAJLnZfDp4BNvwM/C1KoJKN3REr2dhBDuP5T1jvn3Fl48ItEkxNi+nMO6KdYLx1smKR
fvMhKd1olpw2k9ulWSRJFlGfz2+Hc9XjdQSchRHO5sS7LSnmFH0/F6JE0AI1qkeflVa6j1Ip
nu47TrmEPOoclhhtLtX9i3pSP4sUqzzuYvCdEzmJyWo4vsX3cn2p3uBUWxsR6ko2N8cTzS1x
tLH42/n17A9akomm1mSyyTgWfoB7xUboH3BfnNyrDaRXG/ReTce92jRVr6brvdp0Ub3qSbW0
JJItLUl0baqlOZlqbk2c7+YqWlLJ5tZkosU4Fp4FxAm0IvuBRcpKJYt1q/eO8AKDMwn/4rSu
iI0ITJZkBvb94vSkfxmhgeJ228JR9rSxObBwDL+bjaD53I0T3305efemSe/edIF3z69qa61M
t7WmCyeg/+lUSyu8G/qNLKN/QW9yawEYp6gKEq/JVfgXyDiB2Fs4weZJriJLzrEZ4q2Xx8N3
Jl7aHDkR0KOnQed1uQKqSUFmVyzgj7nMdsGbDIdTmiBoqXA46RXQweLOBeZJq2rleBAtH7dF
035R9Kej0WqvKHqr9Z3Wf2FWQA8bqbm6tRd/vXrC55NSKS6Pfnxckpry9Oas1F1eHhacwxxX
K8xsxyEZ6FgtKSzy1svYq4OTKKCaMw34rwI/SVVV3IRzDudIo2z7glrc7HiuVq8S4iMtSfqF
osvfZEAF8vFGvDQ9ufbYJ3IgrqgfPLzAFEu4QqqZR8A1Vff0oTZfJLuhp31FNmUxiWaWd7YN
bGjced+m2sKzQKRQJImT0CUjISAa88uVR9Y3c3+UJOwJRi5P0GFKzRyqb1s3K+4NacCb3JrX
EfapndtuO9cxmYg0dWb0DDrKriOj3KqvGDe9iYpQLrrtpChXwphvp4BO8rNF3e0kvpj14zqc
Pnx9gtmj8UIDf7cJOL/bL/NI4R3lAX+ZwyQI7vJgIO4RBE88ECx3C6gJVyxh4Ac9apUtHCdK
1nORYEITRS0RDCa9Fos3CX2+cvQMQ7ObqFaqT0cV36Pa6M0AMTj045PKDPiTDuRpNeug0vG4
GH230f0AvKtxgTi3y/gWPOoy9uiV0H9RCrqgRWP03RznfiBnNMp2lb4Vjzl24ZXG3Ni0nbjA
mPNTjjldvXBnlgO84He4QwrPw28e2dy+uMHta+xvblw8LW4GGrA0w8kN81bUrj6yurrwseCu
CAbjbiBaPBiscAtMxZy9/TX8CcKzOcH8qjMgm2Kt85LVvU1BLaiZAHSKslWQQj61bvnBc7+b
TEdEVRZ+gfZTv6L8VJBgTNEToORXcSaSYTELvwPK8p02nLfFT21xlIZ0P+hiys2czeF1KB4L
Ym8UtXKft9wj3h5uzFR7X8Zij0xKx3X+CLYhRWDsnho9i77E3E32wNXr9WmdefqqU5ZQzNvH
ScART3efJkFweKrha1mJsEW4PIWFQJk8z76EuUkkiblJMhLWF8qEcyYSqcKLoCpSVo2P1eeT
Uf0CrAqf1eqrBsrcC73cBZQRqZTeRz4/+sxJK1oAnLWPwh1M/wCTScgyfaRzegHCMba6q6Zr
Wgb/f+mcmsws+B/L/krmINrPXQH09hv0ngPvMsg9p/ge9DmpzcXDDTXV2ssmK4kGEZDjWl9E
5Xk1gmMZK5mfwL/5Gs0zq6k1QP8jzOVMhvShhYoRDxFf5q6HfjScxhQ/wZdl8anW3eA7TUTg
hNwxRbQ3xVUSnPCQ6IlpWplb5G0e+e84q+pVZbcFcQXPFDdcIsvOOWz01RdqgDlz2gzzntQd
PXOBG5jvp5nL6VcmfIOY8DSMfYOYyOLTsW8oUZSA11K60ikJTb+Cu3iEtaka7iJzg8UT83pi
brFw37gb8FEsuYO/iUuEoY/aaTMuf2yGEVBgBGBdKxHfhW7AyBxhXoWRwCOzlloD52nmVfgq
fL4ORgpRqPA+Y+H+GTizh8xBmaPI5gb8i0bCgD1G340N6qZvszZn0OWNqixPr2FtjpDLG1FZ
7o82ycyabA4bf5VNEoCITlLRLTzaSA+zr32O9z/DiPB+LaKwDPoPALQB+LcUhnsUlxnmsdVh
ESk4DDIbv38WGqEzdCcFuoheGcwknmEp7FzFU36EFc/kcC3PkrdUXzskDCSjKoW1KvyHvmW2
CRz6MBEKx+MhXvEBnWbRM+G9p2kTsw90/DvgX7qx8DD6E3crFdM5StbF4BAnBm+pY0ggC+MK
izdS3Tg4mwSS+Y/jc62b8HGedjlVT6ngboYhc1r/ZPSHdWvWreaQPehVfQ4r07y4NRBuW9yA
QCV2ewIyzW38UWHV6z8tDL5oVUQO1D1uyytvvLV375s/+8lWlucZ3kJQ/5XQw/ehh1Fqho5T
VD0OUjV2COHjCdxTFResxCFYlM+i9zhdb3QZXzC6jCduMVKqWW1qpEv6mFtF7wdaB5oZq8On
+oI2xA2tXbuWpeWAxxVQzPTWg7R371tvvLKFM/M0JyrWF9DDP30dPfwjQbZAb3n2dGER9PeG
UQk9x44ARWt135SM7qd4ygc/Ac/SzHEgKIWD3f/4ug6hj8G5PmmK9HROSc8f9PX2zWNtIU31
OkSmqqfarWV6KmlQpAG5SCz79w8Uvn30WOE7/2RRLBzWA5d+9+jw0JqRJ76zlIM1xFlwDrkr
oXdPkt7V69QMo2uOuyTqKVoFqM/BieSzkO5B52S9f3BBq/kM4oUY9KSnqqeKFoE9+UI2xPbO
m9vHMlLQ4/TJZrqyJ6Oht4eGj34XOgPkgz4+iJYfO4pWPiDYLRzDQne/88QIzNEbR1mYkb+G
tXyYrO0r4fx9cn4tWduXU88wR7jLqW6qhcxYCx94vz2RUOrnKFRNN84ueEavGsonAu/ninc0
/Va6vqTsefDHFMEXULplrFB7hknolmb4WBMp236EFYCxvhbhrZKFtzolyQEzVrCLfFnhtWIU
NUqDesjTZleZr7ESu3dAOUzj7RrMe4pXNr/fvu/A1TNNVmyYtZpmXX1gb/v7Ztmr4E11qXlz
5qYwHZxqcu7ceSmT5AVefSuzhb6POzhei/DH58jArLsJsz7J+bPkHGsRJW6tA+miF2DSFbeL
/iIve1RVk3iPxRn1aFGngAp/N+FabZy5qahGoP9d/K1QN/GaLGN5sm70DNvENhBMMlef7056
NvZgwE8L5UXu49JQLI/cx7h1E9wYZFu8eyQnDeFt8e7jObh/sdvi2aZpVz11+AunLmvBx+vz
l7UcL++7YsmC/YuS5X2XL1lwYFGSdlz6/FcGF3/5+YM5fLzz+WtX3LsnO23nnStW3LMXjl/G
lt3Rj2ieTQJnmUa4uEfM075hSrGKedQzHFgN6lF39/nTGOdicg9bswF8ZyRHbmFTZwni6QZO
E8/rwQMtFYaXjOYtrojHHXGJH+H9GLisNqpkrQqs4bBq8goEd4gWZtVdIl7Zilex8t+nORph
JI+530bgGTcDfbuoA/p6ddPbTzZUwB+qLU/fMCJGIm3+PGrLCq2Km+EzQ3JbHrUf49eQMEMc
bUGQ+jgryAi0yJAmYq7YhseNjuegFQk7xJETOlI3Yg8NsAJfNRVIJ0GI+jq5mbNIwvk2m9tu
ZgXJhlxzBhscWt38hq5NvbUiDwoZw5mVjhX7epbdsLrGN3P/yt/SdWbJws1V/apgUkKaK+J1
CL+Ztr5/VjSRzfgiiQgP8sLulm1yeZmW6Ns9u3Hj9stmf1/Qa+EMFArMIaDPIHW7Tp8Gel7W
1r8s2d+T7O9P9jD2YJ7efoqyOzodnVprHmlZy/xlmdGyMm7+kJZH3mPcBn3zd82ZNlnfckwU
G30TidpGaHaStJ5Pmttyy8oyoznyAg6/AabuBmOnd03a2Ot9oUxVmHpjUYsXUHoIPV0hhjnU
se/R3bP2r2gFDsNgY5PYuHj3rJ5LZpZVLTnUd6VVEljOLIl7erbPS/ia+ps6NvbWW4AJsTRr
dnUsu7R78MhgdaRrdXv3riU1hwdu3TbNHQ6LNlfI7fBKfDQeKeta3tC8srsMFB6Xwyvzse5V
zal5zeFYKsbJfrfkVuzOipgns/Tg7M7ti1utNFe/eBes+rJRC1vPxqlKKqPHvx7PROU8zY8k
WJaqztPcKXdajq7O+BN55Dkhr7GsZ9dQRlJfnJwOpiNWU/CqOqU/KOMnT+aMRzUja6+RmI6P
xUqguak0G4u5hRSsNMRQlK13qC+Z8QaNqMN0Pi+qNh6nk0d/5ZzR6nCsLmR/SXIXttGFavTa
nLKK13FpbA6Y9+swwTzOcCAgM9MFDMLMknDuthhTca6g732nmB1sBFZgTp9hLeinJ5L1yXqr
P0/POU5ZI3lEDbe3c8151HG8atA9NqmMgLhxTrJj7fjpEzl4vAo/P5KrGuTc4ydRMQquYupd
5KUoV8UAfNg/FDXCbZgds655bGvbloEmp4XD28Arejb3du9cVF02/4rl4ZpEuSOghYN0CAQX
53QUpkXnlu/+1vaGEzsf2N0quTRnIip7ZUELeCIzt8/rXtMVYjjWV0HLkYjZEXCUJwt3s0zz
hiOY7x8ePcP8nItQ9dRsaivhnqnOPD1zxOrzWRvy9KxTlDUz2trKlcPnHnes6skjV1ECjBGl
GCUotMKCgodxdW9qJOdYxeHnx0RCKTCwRBK2YVLCV9OkRCDFBCo/b9r18N7FV6/pjiuOmkWH
HtqV6Jteo5gRbxUs8baFDWtvWp5mfD0LV9buuHN14gmtdbCnom9Oty+aXZedvr4rhO5f9vUr
5iV7c7c8uHbJo//j1q3TBLuqBAEgyma7bF9w3beHpJAmtW2+dX3nup6YzRNWr3t8R3Vd/2Z9
P4mFOQxzJ0zNNCzW9LZhnvcoebp3mPJwSh5NG/YNiutJrmQjdJKYVTkfvjeSIzdJCuQJ22NI
nL++EvRpwBxmOIEv1PF2LeaPxmXEo1+fv1uQBIAU9B/sLpFnXleDPp/949OYbZhwCH+vxRFQ
ExW8GsAjOhdG9PnJknwWkeSziCT36JLcM6Uk9xQluedzSXLm+brcY4evf2RTqvbSxw5f98jm
1BNa5/aB3m3Tg9o0cgzRas6Q5Jc+hyX5vxxeee/u7vYdX15pHIHOj4OU/AabAm40oNM5Rfuy
khJSRPhDaQ41tjoF9HQW5eJbINSLm9/xJ5xyqFl4hMfPjIlB31unJ4vAhugUQp7s82W+wVts
pvNDJqvI88BGkH2CxAfFVwOl/Ddmu8DNxJkSgOU6VJ8i0L8lot+jaIrIP1MU/eeuFhQfnkGg
pzH/CKPSrkdcYPm/82RNDP5QTXn60IjoruGB/G3DlUNy0zjJr4fzjRf78GAlfvJEDh7lmyYI
/PEV2yZK+/hkK+w4Yf+PHMyv8012l2RiLJIVab2DdfKGSzovmV9v40SBs7i7B/d3r7pxVZV3
5oHBM3QjyKrJgr57Q//s8gWDkWTUrAQcvqi7POZNzs/1tGzeYQh5RG0FGX8n0GBlUcbX0b1Z
28Il8YXZ+MKF8SxjB068A2R8h9KhuJuJjJ+3pGo0EuHmDbkvWsaT1vOadRm/JFI1miMvmMie
LyTjm/+LIv7OrgOP7py+d2W7ZOYZu01oWrJ7Zs+mmWXpJYcWXAX0MvGiXdhLBHzjQFP7hr56
C96Jw3Ame/vS/TMGj6wGAT/YMWN3f/UNK+/Y2uIKhSS7M+gq94fj4bKuZQ3Nq8bEe1l2VUtq
bnO4DMS75HcrHtVqLy/3j4l3U+PATswLIsC3/s2Q72vH5LvHkO/oA5DvlujqhD+DVz6LpTZw
sIYpxTt5TsYPnsjpTwI7a/jc0p35N6d6p9kRJVWgz78E6jeP86CgM6wzUh2O1oalO2V34X5U
mIZ+OEm6hzzOkE+zMX0mK9kPZj53c0m6bwbpfg+R7ldOlO4YN849AbjRoTU/hTqoKqodBDeg
vqrBSbBxojGcrDVoRMT78VxZO4i0UznS7pNocTzKngoqlvEXFPX3zL7uWG5abmmTjMM9zKLJ
Ujln+9wZewYyiYGrl3eujBNR34mxtVMtBGPzanc/tLvt+LZv7m5XvZrNpvgU1a+YvSFvuGdb
b9e67rB1oqjn6KYNt8Bc2Aly4WmQ9NhT9JyRG3b0maxHohes70Xpg91oSzea0Y0au1F5N+rO
0zOyTmsgYL2yCe1oQvObUHsTSjch4FYzTu6hUASIjjc/Snr6xVPwGqrWiqz50Y+yFjixto/W
1nJxHTbM/ARsSK95NZ1es+ZtsouRIAjyWz3eJgZAorZ9NAfNHfEikJh5EUCCvxgg8XRj7qG9
A1cPdVbIambR5Q/tqujLVtkBaiOTKIjx5gUNuDIG45u+YHnd9jtWxR/3NAOU6J0FUKJ7bXd2
bVcQPbDsG4cmQglJFW2Sw07AhGLvu+4RA0zcvL59XU85BhPXP769unZgMxDtEliTR2GmBidi
CRdgia3DlItTMZbQpsQSmkqwhPapWKJkQmSOEiiR4SRPua8srtA8+s35LzscACT+8wJAIlke
JzCCprbCbHlzMopoISiihaAI+3FpC8AE+zFu+ydRhB1QxBaMIuwwZtsvHkW82QaK0qUP5Jra
9zy6Bx8fT87Z2D5z84yyxJyNHfhIa9e/fEff9BtevO36l2/vy97w0l0Hvr4+2b7jniE4pjp2
3INT+41+hN5kE1SUai/ZAxzDUWIPmD4c2Mxtw/aA5zBpMWs7bsXmgOkjOXIH0/W5C1gDitHL
6E0LqCeesMv877LLCiqdxfyh6PD4VS2smDSz7oQwM+uvt9C2oEfxKFb2ayZBD3KB/g0BFkiz
9dQ0ancRC2wYswV8oWgLaDzZ4OYzW7AhoOkYv1U3BLRd2BDQmBVyegtsBmgCVLDVMAO0TW0G
aPl0M4AbOmm2mc8fsbtsPGdRbT+ZubLB6amekWlY2p0W8IZR0E+V5oUbmpZfszjlm35g9cPo
TVWZrfhUgQe55Ap5PbZXZu4e7IuWdVRp/jKfSQk4bU7FJoeCrqr5m9oaN+2/ecW3EngfJsy3
CoINvljEBq2fwAbZrLsIDj4EYPAOlutb3B/qM/DTUUHWa8CCDzEkeIdAgi2c+8Pi9JyIB9B/
Gw9UtOfu29Cydl6dBKzFKoqVPWs621dNC4FGNnsfBo+sxWbONa7oLnNU9tQ0rJxVjZN3YYLK
LUDQhZcPpEJNfdXT1veUo8q5ly2ulj0+nPLIGfECq/fV9CQrZ2W8vN3rVL12zlc7KxVpSWm+
Mh9n9zokl2yTQgFnbMbGrvplM6otDFfZswpWdXz0HHMjWw5CsNbQ92ujUh6NjiQ4jqrJo0ey
kjvhrz3LVkdl2RLdbNlGwmBr1DaMCSYAgqwMaKD2bG7co1rxWQAFxZ06n44IQjSBBDeq0tdN
zrAb58goVAEE5TB2RjfzznA6VJYJ2b4Oy4kvfIMufAXtQB3RsreLTvK3OTmoqQHNY6cHRLtF
3wp+uUn20v3nf4VxwYbRPzAacNsevaoqjpJ9qIQL2nVc0JpHctZa1fUuTIqqTdq4+XQBSEAa
yLlI17s50oTTJsyjcd7xT6KB+CcVf7wmjfLnjDZr/33La5fPqLbxLOEXlkRbf0PP+mz4tpt8
yVhY9jh9PvQ7nPaNFaxCYa/N4wuqQ3dc0oSWr7hxqEZUnBZR8Tlkj92kuJVI66Lq9YMMx2hh
9D8DfjNRVhxC4XeIQSi9aA/MiV2jv2e2ATeqp2bqlpFjqY487SxaAJxZB2Vtfi+TcXDhcLb8
rGNL9i8GyzdKOE0yAngyze/ljMcd5Wdzji1c9i8lKWC0uWgzQHyC8N5Wf8ntQ/P2LmmPyUp6
9vbb14Wmt6dlM81bzJZoXU/lwt1zYrSrZUZvYuW1ixOPbtga7OxodIVaBhobF9ZraGnfDeta
ot2De27qnfP3X9izpNYkSrJXw0GqFqulfcPhmVa3YqlZfKB/aKuguO2X3DhQVtaxEM+jmtGP
GPtEqT3dkNqdWGqDxtk0rG0St00htfE9kNr45lRSu3Gi1LbjJGmFg6zdHfNGEwqH/un8WUVR
ZfoO7F5jfq4GvB7rucdE4maURWZ7vLwcW/kw3u+HsVwEY4k9DV3FSJZmkNoR2pUVrP6zypaK
v04S2Fmr4j+bU7ZwFX+dQlazF5TViyqH7toxa9fSzriSWn3Xzm3/MJh6zNc80NzdX6P6mwZa
ugcyCq1e9cIdiwA4Hfry8qt/dMei3ltfuGX//ZdkunJ3r4BjdWfubqDtl0AeVoG8zlCLilq/
eiqkgMIvOgDxZE/GNqeUDwwJiO34zxI2hE35jmwMP5G15OAZXvmgJPPGmfRLOn/DBXX+Kk4Q
+fNPciIu/iRyv3xHcVlZPKuQmQNUp2ohlf++Ce5OV72SySR5VdUrm+i/fEFAUtijuEEffoBh
GbzdynRuP7Cf0VFqM3xVI4wFz/xYwFEIG0HCZUDC8cwrAh6rdphRuU/aXlFRN3uQ8OLMWTZ9
cbw4A7w4/d/gxbp2lnNI1wuOqEcLO0yFblHGe1IFHl3Nq6GqMM6Gf73NVcjThYfRalQZjb4C
SizLwo9XOCmgOYOa20pvFBWdOZ3fHqHnn38Na/7AhavHc+EO4MKVjZWNmAu36ly4nXDhTNc7
oGNlNmkffBYXzrTrXLis650cacJpH1w0F57K/krYsKGVVXdcet+GaetmV4o4BokFNlw2bfX0
9jU95aGeLXPDdakYZsQajTPWk/T/hSHfzOTaO9bVoqXLb1xdY3c6Bavic0pum8kJDKZxoLVm
dq2XZRl3BOWBEQOLVvyqUPg9Taf79+D5sMFYu5gPk9wDx9LAh5kRrIMBH6ayEmVtfTeT4eIf
AA9+z1jFn+S/jkzru8B/QXf6gPDe90qr+mK0pok7ckprvXrt7et79yxujUpyYsa2OzZUzGqJ
W3kOweQwmSJNc6oW7poTYSpvWr76qr7Ig87q3uZZ+yv9zQNNLQvr3GgpTmEd616994vzZtzy
xX3LGsxWSbTYHFaHT+JFm9i28bq53sqaZQf6M/MaAwnvxpsWl1dMW4D57lpYJdMnWl6zhuW1
y7C8Ng37puS7Pp3v+j6V746zvE6Hj+EK+zkbMN6yhMyjB8//EUaWVez0vTbFUmK93xGtJoP1
Whx+VWe+hgeVi1JOKkn16rzXRdcA7w3TNccpiy+PLMelJeVwOMYtNzjws2/r3gQJ3wWdaQm2
s1tAZ1p+QZ3J9Uknavfhp6+5+sRlrZ2Hv3ftNXA8XrnoQO/KK3qjqf7981dcMT9KX3/3n7+7
bvkjZ7/5lbNH1y1/9Oz91jteuL5jwc1P7zWORS8q5wGtqUGndJRWsoJHEa1iYDG3DIe8nia1
/7CNzSpmyUUS9/o3cZ5aBXb2XSJjDXlU4jwFzIJwCtyi7xQo20VdVdSXVo/pS9edEpXWNl1l
yhCVaQlWmZLH+KXjVabJdtRTeiOsOGUMxWkJUZySoDgtnaA4TWVUdVyECxVbVVuLLtSPVm5v
UQKARNrXz62xwDdzNC8o7ct3da390pqMe84Nl56ma7BhtVcNOASTHHI7Qx6PDVmG7rxiYzq9
oL2sLBE1K0GX3aPY5YpyX9PQlbO6rr7j8b2vC6qRqZs5BFQaZ11t/IQGNTjOuioS6+qfsCa0
xA2nxrS8WOuqqFtX/0RUqSXYuiqWJu7fWps61Lb3O3un71nRppg5xmYXG/t3zS66Tw8Vrau7
S+7TDb0NNkObcjSt2D199c1j7lO0Y+CWrR3OUMRuc4bcMX94svdUMpVlV7Zg72lZKoq3Zdk8
qqRGy/01Sw/M6dw+0CbSXP1S3Xv6EctyTiLBt4xJcFtRgn887CaWVSC0IZkXW5ZdUIgP69ZV
MSvmxj09lRwfl43wgj5U1qm+YHYSK6v5/HslH+oLnDOaCcXqwvYXHA7sQ12NHkbXJ8OFX2JO
x+LolygvBz2OcMCv0B+AmqG7UX8WpV8/P9+YZTs4O0jyy4r61LMlSV5f0qeqskKm609YLA9o
E6fWBYQ5aWMFYf4nIswHsI114nz63PKcH9OqiD+1e8eiGjsOoAKuYknO2DznUzyqSjhSoWGf
Knpg5wO722SPR7Q6Ak7ZK5s9Aa1sxo7errWdYZa4VaVoRFCJrfUemkaoaeMRQHuGX5XmmWco
IyMdcxjoNk6OLTPkWBOWY4Biq4d9A+KyKeQYvgdyDN/8m3gQ2WfVoN9r//hlq4yDFrHhT3AE
HPH4eA8icBIHlUYiic3yTirQUVEs0FGNk8tVYBNyNRpXegPXsXHiPJLOCM50qOHfnqKrsSKi
p/2OGEF/EaP+TcRIJgnHX+MY43Kcd4SuzgqWCFVLZSkGl7TICtCixrLIQlMkz6FESuPQ2P78
DLE5UxbKUl3l1yVtxThJizOyteGikzgRm/z2mvG1U9IkM9lYlQ9/URRXfJYoBknMjpPELPN8
zaVPXH/lw1vStbknrrsKjk/Y/elpC2qX7eh0h6Zvntu6rDOpCfQtd//l2IYVj5y9/66z5Pjd
DfddtqzF23/b93L/8OJ17eUz1u67kSp6Q0EiZ5CVjEJ5eQiVB1F5AMX8qNyHyr0IJ2HzoBQZ
HRXnpaslVTzxgNQiChOfShmZ1lMGyVNG/s6UQfKUkfgulQd5bw9puJEm4p+iYhj44fjqMLxT
wYUdZHJevP4MfgVJWSlAi/sVpGCVrXs4tjgl55GpKISx1makkTydfjbdQMpSpX9IaE+lx/IZ
rimqdN0ncvAKHr9jTB5PpdT9zR25zBt3W3RHroxhCMsi0G/4j2/HjlzDj0uwyAtkTGypZpQO
oVQQZ5DM5osOlSxy49XgJqG37gjJK0hXl0CLPiJtT9LXUqJOQhHnixRxJaCLBjO4joiBZ4xZ
TJHMkP/voc0kh/HHK7a3qYGm/sbODfPqrFgjpDmz1rFqZ4cObW7afZpu+HRokywzqyGX5Jbt
rvKYRqDNVbcf3UegDdEfzzB3YmyD5ujccxAIHcCEHkR1ZiBlHWY7dYTadZjadcBWsxYMfhZq
DrQgizOhxuGROE67WcJDZrlYdYS09OOWfmM5AFiqPkESP1KkIh9wF7sx7e3GSrLj4XbA4Nk7
cDG2jixJGNiByLIwlkfWgi9+DshF0kWSjJ+vpotVSwgCwyW5MAgrsiycQKIDicznBWRjGVr/
v3i8ad7saF+2Ozve4432rbp9S4srGLYTl3cgUgGYbFl9y8rsOEy2qiWJI9qSxOUtAQh2wEzJ
LD1oYDJTU/9OkF21IGf/VcdkiMTaZttxmtdqlKhC5QlUHkcVART3oxhhnxUaqvCguBvFXSju
RCAsYZKUc6icRWk/IrxU1XlptVuDX9wR2ahVqtco/dUpXMM0kMnI+dFz2SA8IeNlL+M5JeNk
yjIWgjIOxZefohUqQbE6J2VBgOFlz5J0snCbZWtrPh0sGllF00YdjHS9guspw3Fs5U/6728L
KZl/xY57p16s4fxvrLKNw/tn0U84R6gqFK0LyXcqrsI3dUi5Jxov/EcxmTKSeTmkObA3iFHx
lkYOcOW552L0/znfrvvuzzD3ADbqos7pPDXRghLNpBAYQ3jqSZ2lthh8swUnmBZhWbU8CTRN
wiAl4WoSr8GkfVH97vpr65n6IB6IIB6IIFncQby4g0/SDRQFbzFQwwlSQ9GRx2XBcPVeh9ZM
cGhV+58jZQg7+yfB1zU6fk0j+XVjdT675lV9oerDgMehFDdQlVVyZe1/zlFlsE7J2z4Ba0kx
oc9Ctp8dPdAsfZ7oAXT/tm/tble8mt2q+FQFhw8EfZGZW0vhA2OQ1ggfAERrxA8Aon2BINpL
YKUdJYj2P3WerACPtShR1KfIOkb4tcEECdxQjPTTcPwrmfEHSHprOV9sJct6emXSSjZakdsi
zqB9UMbLkzeSZ0eLsyKKoxAIKIHjGyOYXbsMVDKuSjB5Jxx/dQLaEGP9BLCtwxIygmkj23Ux
6bVhR/pM/D2Wy/VCbnfOYhd0x/sY/pYEA38nQQFxCBh/A6Xn0s/SP+fep00sB2jja3AlRr+I
DnL/Dld448p8+hV6K3nGZFyZDq1WkStm40oF/SJ9gvslXBGMK7PgmaXcz+GKxbiyGq7cR1qJ
xpV6aLWePGM1rqxgDtOH2Df+L3vfHedGda49VTPSjKapjUZ1VbdpJa20vXv7rstiL25rY+N1
wxbu2HgxNqYZQgipXAhpN5cbDAQ7bmAgVIt2iROKAySECyk/wk3iUMINCWHl75yZkVa7Ni3f
/eP7fnf9gHTmzJnVmfec857ntPcFMaIesxwbQEcNm0CMpMcsBDFL1BgLjFFHEWXYL7GZ6g6C
gk2kI6pNpMPQJtIJfmfwBLnrLJtIJzL8TjJ4IgNu5Yl3+GziPWkKDPtldO7l88+/bChSeh78
nhP9mhLvqqzuLre4El0V1V0V0o+XfH1dQ82abyxb/I11jbVrvrFq3sZOT7RvbQf4dkf61qoW
Ys4k0Euw/vw5gvuREvTAUXUC7DhqOeK+lLxMP0egTYLp5wgsRzPqrcI5AvKTdg5cQksuaOiF
+gYnmeDcOvUAzgDeY3WaieOUkQT9o5HCtg1RmAlu2jabyI0ogaHwXA3I4eCZWmwNkGmtNsN4
P5Do+8diJbESJHUcm9FuMjpeKd3Jpk/gY9rmwfyMlypbc6njlQy4jadPZEACjVGr+TVM2RPw
sZsF7dgalsuVM3Ahijabbq1uCZjam8JNMT9NGA24QSpv6ittW9bqM1ct6F+Hzmb5mzxegrWL
gt0iMjcnZrfXyvFmq91q4B2C3SU5bZy/fnYs2H3+2q5Vqu3ODlBrFoE3nJ3fBxBDX2g39/SH
eupDPT2hepxzHkf/0q4g3EB5u13pKz/4nPcNL+b1konHOnbaH9crlKqqKxrOsQ/ANeAtP5hB
vIIXs+PgsY7EY5mOnaT98UKF07VykU9cQ5GVvikkqbZoRbfAkAyQIGGLKuZs7YnPrPPDmSgT
a/BXd5bNnCsn+xJ98CQnQZmo7nkLm1tCbckSMCjBcJKtbOqLtC5t8cyeVdqddtvqFzb7WVGk
GN4h2d2SVWyu88T9goEDPNnKGmY0VdVaHBbZY5bMRtZh5dzp3oq+lQKGe5LtoAWGzySwY1jX
lBUm9O78/NSVcIVJrnpM5waXmi77pBUmWah6LFOUdAqN+Gz7//AUdow1b6cFtREYcvfAs40Y
SRlQDyjZkNNd6mS3M1zuTezDjxyK+9a8NaBbCfB+vNNmNaH3GSgQRwEVW+pHb8upI+VuUGuG
sTbAIJbkd//tza/yo8+38wgXeBju7H85tkN+bKKKTDF8ZWkMPAx39MdqX87EdpDyY8VVoiLx
+fb36bbNsOHYvK09wY6aCEsQOLQVSDnL2uLRjirZWtGbiqQVibfY0a2ASRGcOfeqpUruWdsd
SLav6AzSnGgygUEW6CEoXuL4QG2pP+HjaMmOznJYac7BefxHMdTXdD6ctRkBMvgmaDlVSLs2
G3koWncc/dFRkyyb4sfRg+0OxISkhTT2ThpNHygvJwOPijubHymSxtLNU1aSytMHMiChGHg0
I+4kmx/5GHnk1QTx6StJ2DdDA5m+4Q3tLtabnrNp0BEv97M01Hm0M5Tw1M9Jyah/cVPPsmbl
Js6fjsRmeS2hunC0JsBX1S3rLa0bvW4oserC8zvCJM2ydptoM5M0TYU7FiStnlD7opZATdAi
W7sX1zrsYKSNItWgDSwHNcOnWRiFtmbe09bt0feh11NcelnZwVw2ddat3Ygr0ssZ9dYnrdnr
fT62HMdpIvcGDg8cu/08jlblbjSzuMFkQN8G/T6JEZxNkpjxf6GNBqD0zTS2zecGap8mzQ5Q
dgvO/BbbibYgZsSFpLXTkAhH2UwHCOkeGYmffgn6xFHPCrYzhOlAhpBl6Z6MDI8OC0+edXrY
Lk66wnaCimVheLMZPW3misMo5VEUj9PjyX0IA4oLriMszx1ER7Gf50+WwnOvu9Vzr1fAc6/o
3UdsPuZqpC07cfD1MIyQ27Ka/SBojzdvLmnywdflTY3N9QTKyDbexhuxYE1QlELpEpQ2O0TJ
yeLYfds/vPKqf+yE4waMIInW3Xuv6uq6eu+eNgz0i4DdgtwtBLlbouYunT/3uls994reo557
veIIr5i07MGDryqrOAxjtPyFJ06+putqofIuPvm6RArWBHAjb+fsMhhYNzQ0YRgrW0Q7Z0AD
NSHL411X7d3dCnKGwWHN2N+vvvLD7dDRDlDdWNuevVeDkqw/8y62Crt5gvW0S1bEaxKcqPMg
v8cXRIMHyStBi9sM/kPjj516TGc9BzP8HjJ4MANuftbdktiqQM/6vv61M3wlXev756xvV74o
lNSGg+kSwQLeozTlM6O9s3Yvqq5acPlQ/67F6dqRsf76BY0ed/28+q6RGpu3aR6QaPLMh+hV
2FcB66nPs56D7SaV9nzk3kPuncR52k2Q9HyUUW984snJAuO5ihZdNuiqADIeAgXK/EHCaLYJ
NidPitC0IQatL/1tNoUbrSKINxEbUAxFQQWAjKcZqDYFyLMWGc4znlP3QsYTg5SHaBeMggN1
HCzdY/YBtXYQvwLKtloVbrHFKMB9DmZAIjx9MAPSFLhP+PNwH8Vsyo2yPDyUzTDXhKu95tqq
QE1UAYybxEkuWtMRBJJ1iWX9dctQD2eucTsB97HwNok3jgXTVZXOaLVggd23aLUKVol1VXeV
lbR1zooNqdwnBuqOAN71POQree5zpN3cNyvU1xjq6ws14tCy48/b/QhbU1MmJNDEXZ2+MrRs
v4/nrT4f2bnHZ0Wtd+vVS+2b48LpzeC//IrLlB2R4K90Ju7K+Mr2Z/J/gbTena+C2h+YsrWd
+IT5otrJwpuYLQJcSCjtW90aaEuHeYPRSLvLm8uDSR8vRVsrZ1AmzcRlR+9AusGTLvMYCECY
UJw0hWo7I/Vz61yWYMpb2lJmvz82kPYYOVFwKi6JFznBWSKCMZYZevngLQyRigXjgoUnWAvH
8CxtsohmZ0VL2FNd5qEJpVS1jm898yHWgt2ocqKVE5zo2jwn2tMu2aMuXxVadZfOdXab9k7Q
os3n3HlzV6Yo7WfkRZYiXoRDXtTCMoO6kW0q9xu4HIcSlOFPOOcIyu6o0zRoMv8Je+qZ44p7
M1zbhCbyNhNAOwl2STCh6whKM32a2+ZAu3MvIGrf9y5mwfYh9Zr3yvuRJLrnWKgyVMm6joOa
JSMsbDN3ABIsgPpxoOxynx2131VQT5ASbJ7CkLzpOzIgfVn8QKbsctJ+V0FffeJpx8gkgmSf
xI8sZYMXtZd3VLmBEiANBqMj0hjzpSP2vv6qBofIW6zoMGNm2dzfLXGheWlH4Pn0vEaf0Ww2
OWRozoPlWbOr3FOdpnkrqlhE2eNx3YCizkQfos4GvovFQIuqBHpElcGhcAoSYJPdbgKFfTeQ
gQk2pB+UlpKCH/XfAVR0PVp/57lkUGBFpYkfZEB63n8H1Nn1d36MDPJ6+9ysKFJMimKBGcua
u5a3eLz9YyPWioiHhUvXcBRRpiQ7yy2ob3asZW7KcUO82dfh5r0xt6fCxf08Nq8tXDG0rX/W
NSsaSIphREGwsgRFGbzp7ohk9dUMJGsaLHz1QNwh+St0f2UYD2rExC5G9EWdDb3UziI2UpBQ
6YB8OQOrPKjskxgRKUsHMuq9SYwIz1tIKbZewmMYTX6AMxZ4FkzACJTMPcWYzQx6THXRNM9s
FSVTjoXqH1pkQM8oHq+MM7YzZ5B67FJsFenBKMIKinAfiElie9GrSCeIsekxzdg+TFHT2PWY
GHhKUGMceowV24u1kFYQI+sx1SCNhQRZJpx6TALExNSnFD0mAJ7i1TRwQ+U+BD0zeOZX+Aay
BrHl+0fLmUdV93Zw2hBOOFloOJMooLNo1XwMGq9QnT8VGZEp2NpA85YUAyRndVvtLgan8atJ
zuay2VwsTtNGIwUG1haWNNKMAac4KwNq8QVoPf5tvF9lh62aHRlADpkfoyaEQETwOZkiHiIY
dQkTkEQRroF+Vp6If9vBj7O83Spi70vW4jCOl/p8paFAILcA+moLBwKIgKxGFhMjxGyEQnjE
Afh1FIkjdUgb0ovMQRYgy5A1yEZkB7IHnamyoA1DazPDmfpLdzXvKt20rXKbf/nK0Eq6byY7
E2nvIrqERNqazuzatnJmVzrdNXPltl0Zyr1wiewe2LJ99vYZY7t7dlev21C7QVl8gfcCae58
+3yssdXQaiqv4qq2795wwfzWqqrW+Rds2L2diqxeEYgg8ZPxk6LuhFT3jfzJHyh8Qvo8T8BG
Uf/P5a89AopE+bxZVMsvGKhJp6qj+rdF/3bo3/n71JTrqd9T71P2ydfhKX8//3v4qUQ6nfg6
/PgglUwlQzCUq6sG/+5JJZMpbC78HFdgBHZVIe34gUS6ujqEJtPpJPoUvJlbAj8/gKm/DkP4
zdWwu0ymci+nUsnXwQX6LyAwH/61y8AH+lB1vGa8D4S+kUikMb+eKEeBwFvwsV+kE+kqEABt
2I2dxE6R/4UZ6CMInE/9EvYc9l3yd+D6mDpzvRh7AruXfAdJ6V6dETkCfR0J5jnJZcnXk7gr
6UqWlWSl49i1R8qy9DZ9szt0Yo/GT2tujyx80pf8bhI3a6mlkmwGpj9Gl2Uz9Lb8Xvei5TZD
3k6e7pPErnaDATD+KHZMUqfa5sfuBd1/edtQ5ewrRlLppVfO7thWLhg5xqgwynBzfKixZNMq
T108zAo2I8Piw34PSzkcYmrl15atuC3TEAhyAavfK1CCP9y3rvuGa41mgTKxdk0Wz2PvqrK4
D8lfL1Svj6uy+RKQXQf5O6BpNDvSpBlaJWatRsRKZs1mkcjKx7FrDomqFWl9CiUrjKsyYc1k
NgPSyEQ2k08lt7VN8gdUZAq7mBJgHSYx9+4ZwWwWznijEa+ioCtFE7nf43vDXuIJ5F7hLBYO
O+GzekCeF2NZ7DXyHZDnB/R3OImdVMv7wfw1KqvXP1avSew/0Bb1+iH9/k+w4+QfwPXDBRl0
qNeP6Nc/w1+HloroR9XrG8Hff0u9fky9Xow9jbvIP4PrE3r6Z7HdqgyfQCDrWIytwC8l3wZj
wBSyTNXXle6AFQxRvwBopwm94d5ApdtHZqOgvhx18FkfrGA/0U96nz51OgsCcIMiSBQFAoXJ
2o0OX7uPz2Z8atVShJ8UXLhMGRRaNAucUYOh4GsJyJuy28H4FvuiNTHU1DxUbbMk5jQ3n1dt
+5ONY2q6Z4f859UfvrNq5LrFd96zpK7bYhaNOLGkefVgeWzWqrqWNfB7dW4sJFtCNSWC4z+y
S29Z1/jThx/aUBGmDTRnhWsEQAY7VRk8qdajHtDGGoEMujVvGPcjzejCY6FkKGlWjqP72s2I
mU/xKUfDoWaFLIMNzaE7GdB2OGh7DzV30qotUi15WcOhjP7AMdJRcDWgbWYo3mwYUaceYDvz
4vqsrT4ZoZkIAzLJtz1oix6O/rHG8v5VTc1L3ZxkxB2MwjK+aMLT1OeIpFyhvqZQeMbiWldN
VYgx0XbWwVhbY7U1jmi1OzTQGMaPNCxq8bmgKQm72ClSlMCbmtJK1KuwYqRmsDY9VOumeYvJ
ZLd2cSTjqYkoEZ8T3KsdALIjgOzmqrJ7Sq1PC4DsDqj19WlVlgq4/zT5e9DHNmreGowKaF2H
rTgHGxm+Ne+/FTbC+0Hq4lvyFMvOUfxcTiWfoErKHF6JwT+gDWzAb5V5I/7MCZziFYfLw5AU
9gcLCyf8sUesMovD0PhRbNDE0TjOyjZE5U3PEnHy9yDPz6h5hjp4I8hziebf44iNLkFAwR8G
gz+Qs2MIbcMJNY+Emn1o3jx+cvykasr8fvD0lCTyhCXzvOIovIivYH0RvMkXfJGI/wUTxfi9
NkUwEmviiVHCyMsWfwCMCAks91veaORRD7rfJpuhzSb6Py/Z8hptpgnwJpBM5nsPJICENZZ8
Xygb9LCs5AF5OSIVLImDId5pbUYklM1MSSDnU6h6r2BXL1oymQmCQqDAyO+nJMp4ZdktGIgZ
uTebMVp0y7KPQUnUhBlFl83uFU3Y8OqfYn/lBCOGkpThyCFouw6nRTP2GmUkMIwwGb6Z+xmC
5/s6xItUgHGfahn2iIJEUg+jCxAG8aHXAx5bCTo7DmGUSPa5arS6mg5neZjzVJbeMrF4AtdO
gDICql1UzctLSnUkm0GqUTsOHuHD2Qx86BidAv3dlrMWTlRfCHn9XjQRgKtzBjbNB1chiH3X
Eqxu7q18gXcq3PG+pS1+Til1+utL5R+bXZXBBcv8pYq5SgrVlq7d7a0IWPBDodbqiGK2yNjD
ssWVGoy7UxVBBq6woA22gMz+RPKV5x5yV3j4X3OeMliqer+HSKAV6VaxLUAfI4iCLjpidGbN
UAJK1rBFX48Erw63ppqdoEeD72lQshnDlslzc8Xvp07OBUX1bd5Nr/7aqv2cy8UdXX3T8uSX
XI0Lu0ZGOhY0eYk1q29dVQ2y/ZBsqVl545K60b7S8V8HuteqPa/aE4OxqjZ7r0RhzysY/RbE
qGSfi6CRiEHPZzSfT7WkwCCt0AWLEZBPJAIKCaSeyHx0IvN6IRXM5511BMaWLy5QOOpYbqE6
rbCDB++DXkMaSWi0gsz94kPVYj34+BCtJOHkA8PbOUp7N4p3CLydp56kWZkTZM7wJiU4VOal
9txglKCeNDzidvPycXTxYaSUhwyMTZOkSc4GAnFTtgF2CtZsvOCW8LRmofpUFm7AUB0egMQB
OZsByRtM2Qx84Fjcms3EJ7wRVkjFOyuKOsrauppg0fw9dPBOFI/ZsdegRxI60DBU17ikPRDu
GKn1Nis/NJlw0PBQxsBzBnOovqnFC09eNqz5ysLYnNZywUAOMxJLONyO8oE1TZ1r+kIcdzwQ
4K2Men4694woS3aebrjoqyMX3LK+WbA7Q2GdcwH+AsZP2vnLIAtl4giBYRwgp45yUITtxmD2
Oeg07ywttBQ6Kjk1rleA+5FykNjMBkEtYEEtOJdWUp22FM8vQ6f2+eCE2/sJtx4nNdeUPJV7
0SC4LJIXGjL2ShZoyTqWv4e9AY1TwnVqdGbuaD6M/TUfyr2IxvJh7Z0hRwPaqFxrjQi6GDEh
AlD3umuu0+rr6BGady70rGyi8tQcTeRj4rfB7+kcEInoFpch5V90jCnJCltJICDIZtG4KsJ7
BcDl9VjIXsHvWiY8nugLGxHdyLFDc1lUc9QgeNSfl8o6k/bSEgdBU2YzI9Imt5WzmSnypXxe
xn+aPK/BR5tY0mRVIi6aJFnaEfVp3FvlpYA1ztTPZpseRBdBr0ygBEtMgguWpFDsyiJ+Wp2F
vP/sFMXOKzRGFImi5yjm/DQkdI4AOirw+2ZFcYUkMvcPUlukpWjeZQWvRn5gYK1uh0NhCZoZ
R6Ft0l+TNDR+YEBHc9/OawPsg0KJ34f2wwi1JQnm3JO5fTyL6JoO8G1E0dZwDlEofE0BsYPM
o1mzqtrAq51U3wxEHjOjQJFp+ktlABPKStVeunVoB2oj85OgX+Jd+WyTL49vBdpH1LXTq3r2
1HyoPB9p0lbHD8WcsMEFEya13QVroOqscjC4txSGvFsnfOGpdOXU6WrhtCb+mnOlnOR/pSD5
gt+VYJGvOa0PcVhSsDjU8sBfh65ULC6O+i/UCFSpYOeM6K9QlBJkG/Sj47X0OPxOwfAM/iIl
2ZzSgMnCGrHfgpcD/4DQ28d/jMMtYYSBAOEThfiXFBv4E+L4e5hZUngDyYpmeAJXG+EgLdoq
yyEmdRydf7il1Pogej6gEvWgYPgqZwDWLueU+ndKF8FZaabWwDz7jELvneLZ7+7FHalIeqJq
Ym8ZAROPSC5Z5p8XQhaUwCgO6BqZo7xivdVlszL/yrsVpwgIEa/YBKiDPoJHpCnRJ6PXeboq
0+eV5kbyjnKxV2SbgXNacs+7QcONpTp96A/zdVYds6ljOoRHgnl+IOj84IYjtA32u9ce8WUL
Ptzy/MCmdrFgNOLLnu3FLT8AO+vstCu2eN/iw3fAzwN33zR1VEaMLgPjq5OPL70ZfD4xZRim
chl1vIm4kTK9vEIG2IJExAM6URMihrIGA+gCbJA8s8Uj9dP5kboBcFaQxgb6iXyqSSN1WF5T
y4go5ji7w70ruodpDnrV5ClFvMuV6OiNO7/kqYjZZ8+MpAISMd462h3NvV2oeq84rQQXqR+o
CadkKveRLZyGK9/auBGpRbo0P2ZHqtqQOkAGjpS520TIgGR3VVsWEVHofswvviG+I5Ki6GjN
+mFNy/sH1P2TN0AdLoAhtMZZPVViG+gIJz1rxMHT/tZsZuJ5WfOICjvGzRWTXFiCMeNZcrDr
zmYBm3UA9Y+n1WGkTmR3EqxdEjwus2HA5PCUu+th92gDEnLxd3vL+HhfUhbD9UGrzy2be4zk
k4Eo63X2zi1J+nnsda06mugH3ImgJfdwQXCvyhKO0oGarrJoWyLE0q5QwnuPXQJlkWRw/JQI
GS6aH0WCcUtj3l4/6OFk0SBlPRMVoRoME8dPqlbuPVI24ykq/OpzlHyBE6lMcC407n2SFKFi
FcmfwWVPwIcILKxa0v4B7+Cp8UsK2b4BsEBelIEGFmSQP31UC90Sw/x1mBA/qLMViB18MkgE
9Lagrz/i0ptYW76JPZi/dYx0FZqYqlT0+bQid2T6etOECjmAlc/e3NuRmVlpENw2CfQGjoqm
SLSpzEGKisXqBgPYv/RtmhMND2zsQ/+QVwe55vSstKJUz6xGnymoCLh6oo1xkWZkFnyDB5E6
kDPAt44lggw+hZgBtd+m5v5j0sj5RBNvArqEIqdc+UF6quCSK1UYr+OLccbisdu8Fgb7MnYl
ZpI8DocPXDxHoLzX6fQAYvZN/CbMwAEtKfMG7Fv4zTjJex3QGjqOvWk0wVV3kxHN5bB8GHsF
Di4xwkiNP4XVQ2tFcHPi+BNYM/SniNMCtDo+8U89kaS6cHAtWpSAIywJjWJLiU3qzgfVChT2
7JEMTwYfxJ5FMoB/vYC0VUDt8qnbGpb6ezefN7Sh2+fr2Tx3aGO37zJbZUdlqiPC2ytngO8w
h51cdtvGlvrMt0aX37axuX79t9Yv2TMUTM7f3jOyZyiUnL8DllYdWovVExnQfTmOmh0unNEy
gqsZqY6nYE4Kyx/QNITqNFqbgFVXZbF6M5PrMfEcc+A+u2Bin6UVZ4n9ZsaMjjqtVqdiw5av
Za0+h43aDUYipvFGG/jVMNqADRI7AJf3HRHwgEWVQgCPFf84HJYU//qkjQfwOs/JtI0H2KCZ
yzlFC2e9vaanTBwYDLYkg0YbxRlLG3tLO5a3+aypxT03ope70Izssvm8Qenfa+b3NrkaBm1O
GxhtspTNxgcaZlZEZy9e33k9yGUELcH6iS1IP9J8ONlcqWayK6CA73ZLhg/4AvHAssDGABkI
kM08ac0X4fOq5KCqrWiA6gItpsOFDZKRYN4B4pSjmfqb2fNHSLD+2LztA2W99WHKREp0INUT
u2DFukvmMaLADJV3p9xCoCYSmZEK0YwRvG1ZY1/ZpWPOyrZwck6tB5PrR9pDZouVoq3umEW2
DHX0zrYossUerQsosYDV7rRLisNuou1Wbs2F0c6aEI0RJaluWFe9aAybR1wEelA/EjqiSIwf
vroxg3vsDEPZqeOwnOJFy/ioFS7iqxNPNXqhoYWaAtptCTbPOeT1eJTcowxPG1EzHSmPlQ05
X8VyKILZY7fDxc/bpRJfSERfFc0CN/4R+miuXfVsh/qxXmIpYP1lh+KAwD97LBOPk+EKtVDC
pK1Y+HG9h0anjEMKki9eZ7dZJ1bZe2PDOwaq+lI+A01RJqO7qjN+wYZV28LNPkmwSeg1Tmfu
uNzo6d/QH8ZSM1b3hBmOJ0jZLdp5kT9vZOYco+REZ1ttyeSvMSzQsgDI0Ana+3zQ3isAayw7
FE2qOY9GSdGn5lwkGya3/Mk513bXFJZBPnHP4Pxg78WDwxvanaw3NbRxoHkWY6aMjMEergm1
LaxX8NDFM7qXNTi3ipGmioYlQTvQFrG2UglraBgdrGhce9P5qfWrFs6ISBQtQgcQJjpx3vom
ezjcvrA13FRu9zrmZGa4vYk2WBoutBwbJlYgDsR2GLcCavfs4YxVrw9alTdQ6lTqZGt7dmzY
aMo9S/lDDoXBCLQ/t4JnOTP6oUUk4krAOr5WZNUDAHe7ZdkFF7aRVuQgUPTrVH3pB/qyw6SK
i8deQUi44V8V3UuIRig/VWlGXU3LOmeMNCpK09KuGUsblTVSqDZcXuszS6G6cEWtj8HMc/Yu
qY4v2jtvzpXw+8pFM9fN8Jb2jTbOvAh+r4DWNpAHMApfBXSm6xDrOI69fLhIb/4ctv42oDfD
n6I3KYbOfcXIssYv3yKZKWa/wWH1SLto5g2bKFlBbfv7fEaSrZJhLUHQ9PhhCcp9DvIQ5sAv
RqqQ6FEec5RI2q+WYK8cNmKV2gWmZ6EiBfVn2PoZ1afDnlvP8Yx4fWVDgGtp9aZKPbRoYKhA
oqmkdqjGKVQMNG5HW+y/LxcUxc1fH+ttTtrjLaJNLBOtRoMksq5Ee6ikvX9hwxY1p3djdnw9
0omkDrcrYLzz7L0ZRSHjjeUPq7lsVAvQCisOTx6HJZiqULMcr2j4DCqz9twaU/WOjNnD3Sta
A01xL+BhPOWuaAzPPm/hhV1G3mzq6Flodlf6fXUV4CYNXi+YaC5ZuXpW29yl6I6qwVoPw4tg
aOQICxZhRm1TB2+3Cp0N9ohbkGwSb5cstMEiMgvmzFjIYfRCUD+rkGNYHT6q6sgI1JGwXd+X
V5EPYC8jFCyPtk/WkpZiLZnC6uzDDsVly73KcBT9N9ofLS0Ztj+L/vltdHvketpkoq/n3U4v
h36BY0DnOw/dlbtatd2O3IVZ8SVIAokfqlJUTVNVRYbKNImHQF7Olvg5NOUnKspqWHWt4Z7R
lmhTuUJSBo6SI/XR2SPzLvSlZJ6TeLTTZsu9Y03IO8fQm+rOb/IazSxOWhx+lmM7Z7Z1ULwN
BVW8rPwB7CLYwrtACy8BLbwMaUCqDoVjar7DYZL3TGrrNZPa+llqEvt4NTlpE1GJp2mktWek
1iZ3bFua6KRNFG0kLd4Kb81AlQP1jtQ1zE7Yljf1xWd6pHBtKFxTwqNfjc9rCSXmb+9tv/bi
bsFg4EVA4Y1UadeipOTz1vanWvoUacaiOlkuS8Ny6EUOYz78AsSKyIdxkXlIzblYqAqTFSRU
j3nt6KPo3BmD4o1yNCrm9oMqhN4ucHja7hbHf8GZRA6rr7DaRfgbyJkdxHuIE2ER8RCLPYg9
CX6CxR5FoBq01cDSUpfSCbiQE1mwfFX6+u87RQXn/S4RQc/sJ28kBPI9MKLgDhkYIPFDGQOi
SlTfdwa3MeDvc+DfP55zu8n3bG6PI5kGTz5A3YQlqP9GcISGbiUhQcRLbCU92PbxL1D/vRpw
3kc0oJmPA9aIvTABfI6O358NYpQsLeB1CEP1OXGn4U6qDuArE6Dn0bkJGPedGyYLwJPMPg3s
WBH+rMG871zgSO6OCfDBs/Ctj4NQIny3CG9rEJcUsKaAJ6TzC3hSxT8mw2JQsQjgV5ZfWT1F
+Hebvwi7PwZv2t60X2T/qwbHrUV4S4Pcc07c7mwq4BklWsDXNLhWfRzcDvfjE/Bkvc/5XvO9
5v+ihpLBAuYX8MfAb0PloT+Fn468F73tbJR+/WyUrSpbVb67Yk3lLbEaDVWeqrcgEkTSWsCJ
PKoXqXh9KlJWgN+lr0ifSp+quVzF0xOoPVG3uhj15MfgKERDq4bG8ASahnW8qaH5UPNDU9HS
3+pta2zrmYr28vaT50LHrTO+mUdnQ+eBPLp8k3Csu7r72z2Onlt62d5cX6bv4f5w/3f6XxxY
N/D8YOng/sH9M5mZ/zZLmrVr1huzrwTNc+2cZ/8ZDNkBLvwncdPQQ9OYxv89zuNU/EjDXBPA
AYC35r41r2neahXfA9g/bBq+ePiS4cvPiXuGX8vjfOP50jkxev6Decw3zR9RMTp/fRHemIwF
1f8j+PKC3yzcsii26N8WVy1+bMSh4pKR3yxZudSz9KsXBC/4/bJGFbcse2v5lgvDF35nRXzF
46M2FZtGXx397egfV1648i+rdq96EWJ1avUVayxrfrK2Z+0v1/7monoVH617cv3ezM0Xb9rQ
uWFww98gNqIbTRstG90bwxurNtZtbC+gf+PcjSMbj24iN23f7N78lS2WLd/Z8m4eW+u2Xrv1
pW3xbbu3vX/JD7a7t397R3iH9u+KHdfv+OqO23bcvuOeHffueATiUuRzY3Aa/y9h5y2fiu/t
3D8WGasaqx27buzLY7eMfW9s/9iPxo6PPTr29NhzY69cNveyxZe9c9nfdiG75u5aDHDfNKYx
jWlMYxr/G3G5HeD7AH/ZDUjb7nf2rNvz/T3vX7H2ih/uTe49vPfwlTTAhqssV41elb26exrT
mMY0pjGNaUzj/2vMm8Y0pjGNaUxjGtOYxv8Qbrv6pWvKrrnzmrevHbz23mv/+OnYV7Nvy76n
rmu6bu91v7q++/odBdys4sg0pjGNaUxjGtOYxjSmMY1pTGMa0/gcyE5jGv97odpSiGEB6FoD
BjFBjcFVG4qceoWrNkU54kd6GEdCxMN6mChKQyIy8Rs9bCiKp5DtxId6mEbKyd162Ij4qSv1
sAn7XiE9g8ynvq+HWaSc+pseNnMGOp9PDhkAaXR7EChtL9XDKEI5EnoYQyj5Cj2MI7K8Tw8T
RWlIhJW/q4cNRfEU0iTfrYdpxGaP62EjIshv6mETOlRIzyAV8l/1MIvYnCV62Ezhzlo9zCFh
kAZHUOgNDZPITXpYk7MW1uSshTU5a2GiKI0mZy1sKIrX5KyFNTlrYU3OWliTsxbW5KyFNTlr
YTMn+xv0sCbnOxE/Uo0kkCRSD0KzkIuQUWQLshHZCv5fjWwDcZ0gtAXZpH5eCGIu+j/sfQl8
U2Xa79myp1AEpSDLURCKlJKWQisgk9CFFrvZhVWlaZK2gTQJSUpbRQi1YkEcqqKi19EiLjCO
CsO4jYrB1oLSUdRRGTeqjjgjMBT9RopWev/ve85J0goMM/fz3vv9fpzTJufdnuX/PM//PYc0
iis3k4gRC+PCKTJF6KtkqjDmpy0H3h2YvQKvdsyMYbJxVY4eB1OLGQWQ5oCMEqaeXolMLiTX
Q24N1ejCVSW1RMSvB3PqsVbRIYZtNjFTyPeHw61UJoHqt0KCF3NF6LVCD5FhY5bJc+eiVYVe
MloD+/xhf0rQ76Q+uM5qTwXFQWRmo12OEdJrpSj09VGS45E9FamWGozaqL8KurVY66M9NZhl
p6iJ6K+ifXlMDmwi6DjpOjfFdQZd76AzHEw1dBKU7fRVlC1S5oq0309j6oQtSvQifpDxAKxw
YqUfKKRTb5zUE2fYDyt+q7FCslDyx0p1iHKsnZBIpFoxj8iqR6sWVwEaBz/8K8e1i9rko1gQ
f514rZSRkqQGqE+STjf1yEYtdVMtfhqnHBqVCvSQfKyhCPqpXIccCyf1ScLCT7PCD6lWOV9J
xLxyv6KlGnJcFB+vbKUbPdVUqyTTT5GKWEA0eqkvUm0o2Eq2u2jWkEyokjOXWFWNuVboD9CW
m8ZayWsJM0mLFEe37JeHYltOZ0YsjvaIoFZH10leL0M7kdZudDTHU2nVVEI9xaFGrtJovJXs
c8uZTPyX4uKj2aDkqIPGmmSuN+yNZGOlPMeP1o2y9AC8kCK0IhwlK80RUgHVffxSmMcGS6xU
v03Wn0jZpZLGioz8nK+m/8zreXLmKJk/DVKSwRxnz/QA1WmnmUi0LAvHIFKZP+fJSjmvveHZ
JHOliLsx30Fz5/8O3+ovMO7/GMbNhSU2Jp5W2QR5XGTm0KzwUMsCOAlfTWcm47RTbMnK6p9l
T6Kcc5NxXU9zqJJmEYlNPXqtsF3CWJEqyXRRG4gFFdRaieckWWfKUT/Ncy/1XUJBWUeiupDq
kJimniItIRMIR1uZrfCCTeZuUuUJFAMyzytnRTRPeymubpkfJCkOuW2VOdlBGcVJPZSsK6d2
KFHuH7GAvELKH9/PeirCPiScFxNIu4KdYhqQdx+pPiW9CWE9/T2QWLSW4mSj9XQmzGplT520
0ly0pqTK/zn2ZI20s8Rj/oQ+GXxm6ZIN/ym20fUh7e6ivD8HaORsffbJ/h5EdsX+ds2IygHi
ieSLdLegcKUvfOdhp3uvm/KI9ayeSrln7ZNVEh945FfJK+m6htaLxE92uo85ZW6R5JCZLsr+
Z89RicXdcmQi0pUKcUbdVVRRvnPKOBNWj6F86ZB9UO4wFJT7ZnUCjYyVXtsZ5f6qP8/1r4T4
frzgoDxdS+8onDT6JKpW9BGEKjFDGZssy1zSjzsnyNUbYYvI3YBizb+zO53nbiCO6CcjV5Eh
jgxn81L0SXFSska6O3HJu0gku8+1wylZefZdjkSuMFw5/qh7ESneUhY4ZF0SY7vluCdQn33y
7qPcV0j3RZVynJU8lvLKK9/vSBo89L7bSv1UMsXKRHb5/nz2C8QijJCV+k5wc8pcb5dr1Sbf
a7uprdF7ppPejftpbso2nj22uC7uu88j2hOiMLJHPSFE18N5y2MiTzXK7DOzW0I/dlOw77/a
RZ8KnP38VuyK3INFqiayEykxTGCUpzPyFKa0HVEZ4qXPXy6ab1VRO6xkdTm1xSHvVDXhWEZz
iRTDyXLE/bRKXGEblLrum0vnj2r0Di95Gb3T9M3pCBK1FMfq/zCOym5QQ58uJWQcURbY6SvR
GcFlKWbYovaOwDn4WGJ+O/VA2fGm92Fx6W5sBb0+0123m+4Ryi4T/Xym7BNn4pS+q/yUK6RY
lct+n3nPtZ4lor6w936apW4qXaqinz/5/qcZoOxv2UwmHS1gstCaj92yiPbkoE8EixZhZB5a
GejNQM94zCiWx8fTSM2n+1A25pXSPU6SUYTXfLQXUo7LYkTaJq1rMD8fssjaTGYB1ZEJacV0
ZhGVnYfeXLxnyvPIinT0lKJNrudQFpT05WOV9AyRI++JkqUl6BfDHva1KodqVCzLQ6sI8rPl
UQtk51B5xH6iP4te54ftzJIttVCMiGQiMx0W5dIW6S3FeyHmFVP9FuqzZG0+9SEL45IvmdQC
ojlR9lWaR/CZJ4+QGBH7cnFGvLJQDLKpNRH80vFeCMuJ/DkYLaE7RAFWZlBPiyl6mTJmxNtc
2op4JUUqnXpDUCUYZOA6D79zwtgV0VfJlqIoaX2xm0/HI7Mk/yzyazpFroC2pGik01YJjRUZ
TZBjWUT96K91Ps3ETDrLQj0uDmdIFs1eyXolOyUdBVGWSPpIbKNtUbJaPEeNSFKU8VI50j/H
haBuoZgQu4rDms8mGbW5XUw2JaWJeU6bz+P3VATEdI/P6/FZA06PO1G0uFxikbOyKuAXixx+
h2+Fw54Yk+0o9zlqxQKvw11S73WIudZ6T01AdHkqnTbR5vHW+8gKkUg2TRHHkbfUBLHI6vJW
idlWt81jW4beuZ4qt5hdY/cTPSVVTr/oipZT4fGJs53lLqfN6hJljZjjgVLR76nx2RwiMbfW
6nOINW67wycGqhxiXk6JmOu0Odx+xwzR73CIjupyh93usIsuqVe0O/w2n9NL3KM67I6A1eny
J6ZbXc5yn5PosIrVHgiEHqvbDyk+Z4VYYa12uurFWmegSvTXlAdcDtHngV6nuxJGYWrAUY2V
bjsA8LkdPn+imBMQKxzWQI3P4Rd9DnjhDECHzZ8g+qutwNVm9eKaLKmucQWcXoh011Q7fJjp
dwSoAL/o9XkQDWItpLtcnlqxCuCKzmqv1RYQnW4xQLCGZVgCH93Q5akQy52VVLCkKOCoC2Cx
c5kjUZTdHO8Xq63uetFWg5BKdhP43ADZZ4UvPqefIOqwVos1XqIGEivR43feiOkBDxxaQVyy
ighAtaSLJI+tyuqDYQ5fYpGjssZl9YXzarqiejrJh6nzABEJwbTE5Cl9oA/4rHZHtdW3jPhB
QxrOzEog7iXdNg/cdzsd/sTcGlu81T8BURTn+DyeQFUg4PVPnzzZ7rH5E6uVlYlYMDlQ7/VU
+qzeqvrJ1nLkGZmKma4am9Vf4XEDcMyKKPPXeL0uJxKHjCWKCz01QKxerEEKBUiykm4ChA2h
DTgSRLvT70UCSwH1+pwYtWGKA+9WhNHhq3YGAhBXXk+9UtIRUCFvPD7looJoSPi578gDe40t
kEDScQXWJpA1igLEp7bKaauKsqwWSp1um6sGuR+x3uNGpsQ7J0hlETUdEs5lrVRFyHXE3R/w
OW1SQioKaB4qsmZQBOKd0IKaIFTiI5Vj99S6XR6rvS96VgkqZBbcQfjIRU3ACxawO4ibZE6V
w+Xtiyh4CbkrTScBcdI6qXKWOwOEn2JKYHKFh1QLMVmGOkEst/phq8cdZgolCPFyLjjcibXO
ZU6vw+60Jnp8lZNJazJmLpE5ZQLCS9OC1gARc2YSPBN5vSvPyCUz3iMwL/XAJwINaskFYqNw
96VJAmUfooyJKSTB8dPigd+AwIFVSGwgY08QK3wgPVIiKMRK+EwwBlaIKJaLnnKQnZuAYqVE
reTZ+XtBDLL6/R6b00ryA3UGynIHrBKfOl1AJp5I7OOtWCwz9XsTqEV2yoZSHM44j/Is6Y5K
twQ53Yj1yrDLiTyVdBNZPmmnggZaRMTDBMLlzgry7qCAeGvgkL+KFixEl9eQ4vWTTjlL4OFk
OO53EIr2eJ0So57VVKngoVIqGhlpakRtlaf6HD6SMqjxuWGMgwqwe8Ch1JalDltASbBIHiP5
7U5aeNOlFAeNrXBEbbhuT4CUjETmTrmMpUyRh/xVZD8od/SpXGuUoz6i3h9AMjkRovDOcy4A
SL1lZ4rFBVkl8y1FmWJOsVhYVDAvJyMzQxxvKUZ7fII4P6cku6C0RMSMIkt+yUKxIEu05C8U
r8nJz0gQMxcUFmUWF4sFRWJOXmFuTib6cvLTc0szcvLniLOxLr8A+3oOKhFCSwpEolAWlZNZ
TITlZRalZ6NpmZ2Tm1OyMEHMyinJJzKzINQiFlqKSnLSS3MtRWJhaVFhQXEm1GdAbH5OflYR
tGTmZeaXYMvNR5+YOQ8NsTjbkptLVVlKYX0RtS+9oHBhUc6c7BIxuyA3IxOdszNhmWV2bqak
Ck6l51py8hLEDEueZU4mXVUAKUV0mmzd/OxM2gV9Fvykl+QU5BM30gvyS4rQTICXRSXhpfNz
ijMTREtRTjEBJKuoAOIJnFhRQIVgXX6mJIVALfaJCKaQdmlxZsSWjExLLmQVk8XRkxNjLnws
cOFjgX8D2wsfC/xyHwvo6e+Fjwb+Z340IEXvwscDFz4euPDxwIWPB/qz+YWPCPp+RKCgc+Fj
ggsfE1z4mOD/u48JUJvSdw0YpjeOWcuc6eDkv8hn2Hj85tK/7D/XIQgWo5HFHC5wvvNjYsh8
PnS+8wcOJPNVxvOdHxtL5qsXnO/8QYPIfM2j5zt/8GDMxztDvqEg0PkCfvPo6yDAfBEznIkD
kY1gUphxgH88ApPALMYGXIVNpIaZyTQws5iNCOGDCMx2kNdzCFMrUvsAs4j5jLmBOQJa72aq
WBXjZy9iAuxo5kY2heVYCzuQzWVj2YXscNbOjmKXs2PYlWw8u44tZO9lF7Fb2evZHayTfYV1
sR2sh/0LW8MeZlewJ9ib2R52HadhN3BD2GZuNPsAdyX7LDeNDXEWdg+Xy7Zz17N7uSq2g6vh
NFyQn8ut5fO4u/lSroWfz23jF3C7+MXci/wN3B5+CfcG7+Le4X3c5/wq7mt+Nfc9v5FX8ffx
g/ij/DD+GD+O/wc/hT/Om/kuPo8/wS/iv+Ur+e/4AH+SX8N38+v5U/zdgoV/EHnwaF8s+W3/
B1juBJa7geV+YHkQWB4Glt8xdoitYmOA5XBgOR5YzgSWOcCyBFiWA8tqYHkTsFwLLO8GlluA
5dPA8mVg+QawPAgsDwPL/wKWvezNnB5YXgwsLweWk4BlGrDMBJaFwHIxsHQBy1pg2QgsNwLL
e4DlVmC5E1i+CCzbgOWbwPJdYPkRsPwCWH4LLLv51bwWWMYByyuA5SRgOR1YzgGWJcDSCizd
wPImYNkELO8Blg8Dy+3Achewe7kvlhp7FJZDgeUVwHIKsLQAywJgeT2wXAYs64HlbcDyHmC5
FVjuBJb7gOUHwPKvwPJbZhFrYG5ghwHL8cByKrBMB5aLgOVyYLkaWN4OLB8Alo8Dy2eB5R5g
+Taw/AxYHgOWPawTuLm4S1kPcq+Gu4pdgby7mVsALO3A0g8sVwPL24Hl/cDyMWC5E1i2AcsD
wPIQsDwCLE8goxi+lB/IzwdOC/ix/GJ+In8Dn8Iv4a/mXXwW70PvKvSs5r3AsgFYNgPL+4Hl
E8DyWWDZCizfAZaHgOUxYPkjf1LQ8d3CYP6UMFKwCONR0qa+WBo2RWE5DFjGA8tUYJkFLEuB
JXnc8wPLBmB5J7BsIf+fR2C5G1h+CCwPA8teZiE7AFhOAJZpwHIOsJwHLB3AchWwvA9YPg4s
fw8sXwOWbwHLz4DlN8DyFFvI6dhFXBx7PRcPLKcByznAcj6wrASWNwLLtcDyLmC5BVg+BSxf
BJZ7geV7wPIQsPwWWJ5mO/gYToM6ncuLwNIELM3AMgeolQLL64CcA1i6gWUtsFwHLDcCy0fw
+iywbAWWHUDtY2D5DbA8xXcJWv6EMJT/VhjHfydMBZYZwLIQWF4HLKuA5fK+WMaqorC8FFhO
BJYzgOU1wHIxsFwGLNcCyy3Aciew3AMs3wGWnwPLHuYadigzn00GlrOB5RJgiccndjWw3Ags
fwssXweWncCyC1j+xMZyA9jhyLtRXAI7BnkXz+UAy0XAcimwvAlYrgeWDwLLp4DlbmD5HrDs
BJbHgOVPbDOvZx/gh7LP8uPYED+F3cOb2Xa+lN3LlwNLH7BcDSzBl0CnlN8GLHcCy93A8nVg
+Raw/BBYdgLL74DlKX61EMNvFC7j7xNM/FHhKv6YkMP/Q1jIHxecwLIeWK4DlvcDy+3A8kVg
+TqwfAdYfgosD/fFcsiRKCxHAstEYHkNsKwClvXAcj2wfAJYtgHL94HlYWB5kslgtUwmewWw
nA0slwBLL7C8E1g+DSxfBZYHgOUxJsDpmRu58SzHZbADuSJgaQeWPmDZCCzvApaPAsvngOVe
YPkXYHmEdfEM6+EvYmv4sewKfgZ7M5/DruPnsxv4KmC5Alg2AstNwPIRYPkisDwALD8Dlj9y
GtThXCGWzxMu50uFFH6+MItfIOTyi4Vi/gbhen6JUMm7hOW8T7iNXyXcASyRl8LzwHIvsHwH
WH4BLL/jj6sEvkt1MX9Clcx/q0rnv1OV8CdVDr5btZw/pbpZsKjW4Z7iLnK/o9XgJzY2Pj5j
ZUODVsVqNZ3NzV1NTU1dpKH2NgVxNHm1alar7WpqxIERASNdwSB+gn0aQTotLSMYfLAxI402
sKCHrNKyrFYIyoeWZ7SCKB0hqqepuSXU0tzcRKSp5FldWi2r1be2Pobj/vuptLa2Rx/dtGnD
Btqoa6RHHRVATcYinSZqRE0dokPNTVS2uqw5aBZjm8u0Kkar7pZtUCyVxBFEGhoyMuLjY2O1
BkZraBQbxbnmueZrcYpBMUjXNjUVFpK1ahWr1nRp65qaqCEa2N1EFKoFVq3yEj+8tF9LpmAS
ne9t6g4GpfmFjNwQgInJ3GUmB0bU6rrm5rKgVwoExO7YR9ZLODISQnq+V8uLTBhJ4mAwSKBs
ae4DuFrLqvXPvbEOB9UvyZJNwUFMVGskwzGbZ9VCp7QQXqi9wZAptlMjMBpBss9EV5LZm6vU
KkatksBQ6xi1rinYFCzFnnA5TmkMI4VN2sg0s5koUHXiItjJ8gh4S5SxTJC60RkbW2Y2M2ae
Y1geE9Usq+aD5CY0yOLggxjQkgGeZExhSwsP/FSFhS0GFaNTabWxsSLRFAyyPCijU89BAWmS
w2ymTXJBjmBQQwIqijQdeGpQSwsNMgWHwoNGWQuFuVsegQ7RHG54tVp5mslUWNjcjdShGUbT
WB5JM9PckBrd1ESzWaB+hHBBigKgdEoXZjHEqxiVupvpPkeNInE1pN6CQbnefrka1Zy5RnWs
1rAnuCf4CM5NOEn8+9YqKlKXltGAA/rCBUlqVRsZmcn/t9Sq8XxrVadidZpgdLGqpWKlA9pw
tZKBsuYuUsXEpEJGaugERodqPVO5KpLPUq9CpF51AqtDvcoFq2NZXRj9f7diCdnsCPWrWEop
5jOXrPocJauOlKz6rCUbbS4TpK6UNZ9H0erkotXJRas7e9EaOKhQihbFSttK1aIbBuqUsiV1
q5PqFmkUqVs0InVLR5S6lRpy3aIRqVs0InVLCixct2RErlsVx+hp3ZpVPKMXQujrlK9wCgS7
bobp1ukYnU7LDMFJ4LUwq2ku6NSsTkuEdiONu7Fp6bQzZ1M3Z88kLV13IymLBoyRdOoOSsUb
aXUHpc1OpyPrft3QIK8ji06Tl77pRPJVFSsfnVR7o1TPTY1EplqZ2K3TszpjCMcW8xbzXfTc
gBO1qtPv2bLlznXrbr31FtqaOXsNOaCYiKOO0CTXkTFmNrMmfM7GXRcbjExrAklRT8jtBY2A
TsPoNKcVA8OeUM6gEBLJFsBHQCRgahmdgdXFkHJfLxd8UpAUPJUkM0JsrEbFakiY65D2ejWr
10LMC22woe0FMiTd3zR56ZAgCIENGNoQ0KhZDbmJ6AkGV1Kr4xm5pRcYvSpc92as02hWktwI
YkJdHw1wkYZArv2gke/VRYof5a9XsXpCFHIc9CyrjwQsqNGxGuMupoMSqnRSs2TZiomNklq5
v+0FslJgNTIZ0GtCbGUk6iQHFNNNVABdD38JSqTSUeoaPaMxZJgzzFcGyTkIN9bSMAYLC5v0
UVNRBVR+Vywp2i7wgk7domc5vbI7wHXqJCk6k0h8x27HCaR4NSyrgbeEGoIcy3K4FjgAQMYE
rFFnNzc3o4pwkZ3dHKNmDGpB6MMQrKDqjOFZvUqMogiR9pAL6cCQjligsIQoCJAN0c1y/slE
QVsyUYjd8hhVZ460pExFPmji4uOzs5t6tFqlHkEWWlkK2EKiCzqzhxoNq8EXBkHiC4ExqDoh
uUu+KovtFDSMWnOaYU7rdYwefBFhjNVIelpWGlavo9VDmKFHr0VzlkXy2zKLNPU9DbQg12CU
JGKPQhM9NAhh1gjSyXTtxjVr5LVkXS9d3S8PacbHhqmDSm5UbgUaSVMTntujN7D6mFBZqAxE
3HKneCdqc71IapTqIPQh8Qc4Qm+YJXumHBawBBVPvJS4xKA/47xfMUwojAfopLGxQc4zkukk
EnoNo9eG+SQ27KJEWBTknzOKliH2D2gUlZuICKtQeWFWiZWrT1iJ4jGoWQMp+mhe0ci8QseE
MxMLdTU+zCwGkgtgljC1aDB1FSnvIO76VvbV8i+5xaBiDTQuMrkYWNYQFdT/LnYhrtZRCu/6
pdmFQ2GrW1oMLGdQ6IW4Tx0lxXl+BGNQCMagkQiGXJyDYAbwrCGKYAix0K4Iw8gUY9BGU4yB
UgyNsPwsSoBUcXqtGCYZeZQqFc094WYd0kXeSuLCPEObK2F71OhMs5wNUjPMNGYNzxgFWQ+e
2oygGNLdpVyTzQCEo9ESwjHoGYPeyFxEz8twmoOrg5BsDpoNGtYglxjlHIMW7VFWCQyzdRRp
67vXSqzTsLab5ihhHZl2Im36EjToWINhNFMWNDMIHbNRkhMsC45m6FAkPXujUrV/6tJCiY0w
ErWyIXw300C0RigJVsSwhoGhuFBcS3xLfHN2czYh/Fu1t2obtFRrKNiCsxlnU7ARZwPONZKt
IxhbH+6xoD2CkWGhd2e0+PRnmToSNBWeLNEUtQ5hht8mLYmkQcMYoogqth8QEXGzGBopEhf8
BC+jsSIxM+KkPpL/RWBmrHTGE2dbYs2xZqqAPiJJCuR/OgF1oTSNGtaok1iF3Gu1vdDngZKO
cjimZ5HRrOnyoyPhq4w06gn4S2kbVciutAiBkfTRRhisYWU/ZQ0N0k4TBi2G79VHk5gYMqpZ
IyU9JbhGljVG50JQa2C1A14MtYuNUSd94lSU9Hn8NERGKJnRZzqZzILyIwHZQbCBkHsQs7lb
ciWNSpEEAgY8dWrP+NSpcJr0vExYDKRmiJ6OQlQeI1CSwW6O5wyalhYjyxnD9+AEEuq6twnV
3p/YtCxHHr+ZfsxmVJjNqDCbkTLbAA1j1HCcwm0ytalUnQN51kiozSwrxZVI++iVwm1msvUZ
CbHISQp2M2oIu9HMloBVsDXoTIXNciKfpu26RqSPQAgu0gbDcRwyn7CJcciQsRkZjb3wk45L
FMfRcdKWOC4i/7TsCDwBy8VEWI6NUYdZTrruw3JGA2M0DGAGMJfSMymYFCwLrcadCrlZMWpZ
o76nvb29rae9tbW1vceoQ8doxhssY0JRZxl6RjMod6PxNNMa3BMMRR17gq3B0wzN8dOk3UN7
T0c6Tkvz6PLRQa9Zkr1XXl4W8oZGB+lgRGZvtIKQkUOO9OlAxanjwsdmL3Wktb2j42DXwYMd
7e2tRLs2asVp4wDWGNs5onNE18wDCQddB137cjs62jbs3dBqbDVS7Z2hrtCB0EGcHTjbcb4W
ag3tCRkNrDFmNLNcxkw5y0LLQ8BEQpCCRxUNMJ59dpDpZEwU4h6mnWmlZztDrqXWniAFbWZF
KNRZN2KAWt1RZ9QyRl1vxNW4fkBFDmvwVwwNtqSOnCTYUthJAhgHssZBe9R71K1rbRtsGyo6
KjqmHUxZMLMuzhRnMup7jTpr0BqcwpBzFE5j+KRPpSvb1epV7e1vrYjRsjF6ovGTw63kOPyJ
9BRfQc2omEnHeRwzKul45Qzy0Ayv2tuRCeV0XFdRwTCRHjUSd2ZZWVl3mXwYyYrVSMz2laFV
kLGqv9LW1hiOjRFCIew0yhEr9MaoTCaGMUWOzhgNtJHRduRG18GOjnZ5YdShM7K6gZ90fm1q
73PSZ/2wPunJv4JeV8w0Ro0d/oTIIE9ABzsVieTZua6NhNG4oY7cqqkj3qVRUbJYoEOe8sk/
JNoYck7DOQKnbgB+SHLa4io32zen7JjZFVcWV4ZHJJ22taJiZtzMiopW45nXxuE0MdSIHmNc
nAn50MMBZE1HRwzHxUTVEtCjCNVtUKvVxjQgBvRUPMupYGgoiE1QpyIgMwRnsiOiheEYaViF
pdrLKzo6OlQaJkZbUVHR0TRIwwzQQJYRiuNICMjMECuwKtzQEoaSOuTiLysz0U56JR9k3KBl
YnQQoKS+CtZrO8hBK06OgxIKoz6t7qBSIb20Y2U7MhBmwPlIh3qmGr3tK2kNDkCOXwLAxjEV
TBYqsDeoZshJZ68igVopzyYdoyiI7RGNvTxBTHIS95cDVN4d1Hqw8AB1J3Ej1KVcwzUwMqvR
EUaW/qJE+XuTePxydpe7Ur5O9EvX88i1xWctTxAtvmp3gphe73MliHMcnmX01YdXnwPX5Ntd
CWKuNeD+92ZTG1hqB35HPoz3IZJJI+8zNYy8W627cm322pMxrIZraRjZiC6y5yYZTDq1auIA
nhuuYkxWtX6iGqFtSOVYoaXYdK0pIapnxCOjgiOYmfQsoH+H6KF/GUz+bnUWOU2XRQkThmzl
b37y/ZI/zPtx9Kv3znjmCdu188be3NIQV2pqEFpNDfyTLTzHctzgKTCxvS44ja0Z7vRRg9tN
MWFrscEzplpqJl8qqAdzpcVJg02DSEM7WD/f6q9yuisDHndSrGkA6dQM1hQ57NUetz1plGkE
6dEPvviMX6lOusw0mozzg+Mi4yXOasek4oC12isWpltMo4bGJE0zXWVKTUqdmjZ1yiI006Ka
pjW7fhHLYkwGMm4YLOQVFBYljTddITVHudOdXvJVy4ziTDGzOH961tTktElTUlNTJ6VZUqcl
XWEaI3k04oweFUtfWDU1sJdHI8yqGL6BHcigX881sCzzlGHMpdvebIofMu3L1qrr1Y3xNZbb
Ltr24PYUrmzLU1nP6WN+99h7MVmZf3vmoRHf+W/o9fQ8t3nSPd9fOqbp+2t3ff2/5s/7KW//
I1Nf/Mq6v3IINzSje93Fc1om6Tcyz+y/LTTX/kba7s83TPymde2U5yaGhu84Nf4Btcmbdujl
wW3Bt+eWbV7+5eetnuebp8/5ItbwpK/pulVj0wd88NsnLktp+uh3tc1ffT5w5d1D1465Y9h7
e5e3P/b9jsKEhxd1LNrB7t3U0Mb+eDHnOOrePZSZdJvqzvU33JG6Qffw7opOd/X7nS1zP/5s
00M33vyXSypC7JWTC8b/sOir7hMjjwwQvl+WOWrIzSH7vR8feLE3662lr/pH4wmdYbc2sDog
ojKNBKQjBwiXCEP+/Or3yTuakgYeHrbpxKxXk35YzA3U0RwaOUaIM10SHDImpfsvRVle/THz
jyt+3DVxR+vUXQNNJWTCaCHPdI0pp2VOS+badPk7rjafq98Xo73LnKR3svwVY//kcBhJFGkQ
kZWJmGJaoNaiMFVgbFbINc01ZSttE7d2pqygtrb2TAocvnNIDpgGE3uvEIwmvSKS1/YrSJ5k
yebFzCfHt2bf/tfCqyo3jQ15Nu42H7rq8YS8dQnbFs5K1i/t6LluqLDZVPBur/GRWz+74jVh
uvZk/l/ZXZ+50x35nVcnZnon1Lxb4Cy4pG7XWzfNOj7sd3k7n65JLhqruq/5YPZHf8v4sdl6
ycIb/rRzYuk9DxddtydkGq/5xwe54+t3tZ6cOzVmWN7WpNc/eW/45XeM16WYU996KHvE+pr1
6b85OKHkD9tSXUMe2lfnen7Yb2+r25pq383edfRT8+olg2JLNqkWfbR6V/w1Fz2U0nD75Piy
1NgTlcP/3OD/+FDyj4embP3SPPWyl1MXJ1d59h+c+DfWarvzvqbD33Tt4J45dfK6nkNrWlNW
/eHaTy8dfbTo6A+mBjULGvt7FI21/X1d941rCv/eS2msLRo1A2hs1S9CFvGmcVLRj44etzvE
Ymcl/YIxAkv+yxJJlM1STWlJSckmnCkSm0WapsAvYp88zp9l/F+yUdP6F8a2ajY+EKy/uGdc
WY+vKeGH/9p6X9O9Wc9v3b9k3eTpUxJH3Vn3w8rtoxvYZ2/cP/xl/s2sI6/ff/JHYeS3t+p7
L3dv+bby6tfHx30VP/qfwiaL7eiXf7x4w7HBD0z9LM1b4plx9KlMnSlnz+6NpvuN+1e8cdJ/
zyW179z+0qa92lvFY6O2TT2x/LXOAHPN+nc/ufPIB3Wn7/jhqbKmq195cfTT5fe9+nrjzuan
P3hm4nslP0796E/L7zo8qvfo8mX7V2tXBDpjr83+8wlmX3buVs3UrxbG/LTywX2HF3156z8/
eGDg6F8//tfGoXs+ePPhkezen7KfGHzXlPsuy07ufm3sI8zvdxe/eYt7wuI1x9Pcwe9eOjrY
cERhoyAQWSnRzRWEbsI7c66WDVcqH0VX+z8ob3y77Kpveitfu+7dfS89+Xzr4M2mIjI8SAAX
PTrHlNl/p0kxJZOmavDE5CkmU1LyRFuaKaV8qsM6KeWq8pRJKclT0ialTZmWPMmeNjWpwpqc
PDWlwtaHArPd9q8KVe81/HZoaurlz1Zve7OGu+fsFHhGhvJ4/ZQFkS7IY2QxEpjk7xLyMsmU
OsmURinQGkWBpSbcrURRYOa/VKCw4DlUBExGYvhglu0VONxI9y1nvoFjGfUloz+e/1rhvjEF
j1xb9+Gx7p/+9Mr7oROnLp13rHifc47q/bb9R7/ouX/xPUsGpcWHVJmDOx+ob3q54smPXzrC
lY55/uoxdZbqp7tPMIs23b9+RIfungMPjMgwbX/skr1/nLP4nxNTbn9444LU1vwRz1z+Zuyf
DjbEbp/a9fTl+zaOfXzN7YfGj/hrxch1sxJ75/N5e9y3tCQf+cOuyYXzrlfvvHjDvpG25/3G
Lz+4cdzAK+/NfCL5lln3zpqfUztm3emdsXvXf6W9+NrXJy5KWnzV0nu3Pdq07N54z4m2p795
JXNoR3n+mmdLhs/59ebHqkPu8e3d40fvOyZuN+w88ZbhgU1fLP2N85Yt0z6sFk/f+n5v6wv3
TdOdvnrIns1DtofWdhxv2PNk6dj0uGezb61be+DUu7/51bC/DFn39R0PV41tqpqxfW8wf9zX
2stybT89ePfFeVOenVdW8OHcF9N+3Zv46c4lj6Yve6Pu7Z0vLdt4i+s232+/eezHhz8d/sFV
PfY3qmdpv1p5y86nXt76x5vevnfeozcu2H/RnPJ3LzveM7MtyXBy8iz7Y6messJfPZ/RXNBi
uH33qgXf7628zfrxQ5vb9m3Y75nzeShx07Gd3+8wVR9dmrPt7/eu2PeKtu30jH8+7U9V/37e
28P+/NI/N71524hvg0vZgucuXePf9d7iy381fUHcoaZ/VLblPDH5kytuv/qGA0dTMu4c+fKd
xhUNs463HZy0ReB+nX3q+Kfc2/wj2AQ02ASOS5uA3npJVQrl/hH9b2GXUDrV6+4at+7ubxPs
7LBLeGRj0jDT0D6dunCyIg0nSrw5NsKbRR4PyBOp66xw2qwBh2ipCVR5fM5APSF3U6opxTQl
KXnqFNNVIPfkJNqcYiLN/3f30P+K3x/e4tp56OPsu65cuSxx2OevfPHl6/dfO6bwqbc+jcsf
O/Af7zzxTu5TAZM46Ijm/ZJ7Ls7ZdOnsu57efJ1p3EfMsr/d9MrRdZqBJwcIm7vWdYzeP2Xs
bb/59r8qRyT03PR108hvvs7fumXPmOI37/gh823dgRueObBjtvDIqcddd1d+GP9JVvGOtQe+
iv/fxZ15PFRrH8DNYGTGlkGubGOdEePMFJGQJfu+75Ilu5JlRokZIkJyaUiYKUtFWaaiyJpI
KkkSL7Jla3BRKal3RvfKe+t93+4f93PPP+fznOfzPOec5/x+v+/v9zyf53f00LJlCea2Vhzj
zPKr/unpQHDikiOQ9/FEL4k6hSCdWOmGL22ptg6yurE/vcCAyUjfZ6ssyucyafwZhGB08UN8
yVZ9PnZiQTzNFvcZdF7EYstJJh5Aj1Y9JKlXe0/BpqBcFKeFiezMHVaL+5XiAb4pwln56X1u
FeixhLHNlw+sLc3isD/seyl9REoA7g2Lwwow00+b7PkPvUuG+RbhZmGhy18CwANh/50J/CDG
FSaAkP3VNhPSAUJqLB9XGfHAPjtZ0oQ0/JPcCNQ6y3G8kOJZ6PG3iyeRB39NgGJELrpmctRh
mQ2O9gYsvkLBEKBziKxD1krQ/Hm/eKOakWmIYcrXgWCzCQgGgB6guwkIKn/FJ2a8h87XXn/S
H6aPNQ8pucWFWVd5cPrGtciBx3hLU1AlOuyIcxAHvPRx/bEzNege3ospQQdr7MEPzcThFjmD
UftG7WvLHc4Lj4iAEspqcYunu96ogeZG689AWdtTDUYXrPkHzUszxidT/Z/HNr3OXIQonmSe
PisnJXF49d2ncVwOmvM92+jhOkGzvLQAaGhWDUX1wiGFVkuumYMumgLZp8U1R9mEsB86MUYR
GPUdobD2mcPqX05C4cPNUI+0hRc122bNTse0Ku1wu9QwWxcN0z7WYx2KmAM6anHeLs6gbVA+
ru5+vuy3e2/7OFAVFCc/nEzotLSbyjucGVimatLzDt9wVTDqIGr+Yi5qFyRS6OADddEgMeIC
rE2+9okOdeLDm+ibY4WXw5RqzFqPSPLKRMD2WqUccdLT4aujUitMD7UXaH+JxSNi8/kBnylt
Xjeh9nwJRJfO9I7p2mWDTvmePmysiYycgZS704zdfPFQTl7HnpC7BNkwyNa5CERDLrFJ1uZW
pb96EiXC40YwBV7ccFV/gTdkLRkbWPV52LI9RfKBz908kUReL7C6QrnjmZpxxMTNig7PGzgb
1h4ttEVZZkURrpRKPhcu9DIjER4uoYi9vCWY7Jwi3UCej+9A9M6Kmj84P2f46j3IOyQJFt3u
1/46eKaE9BiD+sLV6uzSZ7qd0vdRMV8TbSsQ8AB+aQ0gskUBRNaDf6CAK717HQXMfw4DCKf+
FlOMBYCvCon6GYX8FhFg6NhQwQJKql+hobxexACM4j8esRDB37MDzGAHmM4Ous6VLnwM5RFG
X+sLvkrkMd11Z/GWA6JAe7tcwLSTxdUaiIoQi+GdmBYO0cHdAfd5+2ALKs05kIp21ecgPoz2
syROvFfiicwDUoHl+YYXpn3duodzraug8i3lL6/suB7FXv7inGPHASHWaZ+IKayVDK/iZOkW
iydU3WrXvnto5vBS36WHQUt7XCgCy3p3Xql4lQV7KeGKyZ7cCs/2/boyNsTG+dwFX2SImuSs
J8Mj6zPV51fHdjjxiJnaIS9Ghb7i3VNt6NZHo+mcjXt5rOpYwvaXGpUprlNJ5vFCixRFx/F0
NYXrOx1aqzU+Y59RmdUrq8ozVE5058XKvzWzO4tQkm5RDfaKsb5zgfvaL5LxD5fvMCekvndf
6LJqSMlMrGtEhEm7CyJvdcoiVaSzVY2UnxyvzLguLFlyxeeNh5j/CNIwz/3UqLTrM4SxhtW9
m/aaUswLT6OcFZ9Ljh125bbUi6SuMI3UlYGJ7gON/NS723tsjSdVKdzTkoZ1gjW6x/ePN7WE
Rr0KnZQabtDLaZ1vFrYfiEt9Y2oIlJSmDb9xLij/NFjhM9pEIhyj9dKMJw1RJXBkcUn0odjX
yQdx7lWK8S/sL7g0RCKRv9GCWpBn5M/s223eNHJSN+keu0lrT5GOYljW++AVnLiDPNz1QNZ5
DfOd8f0Vp7YN5Zstn6uo0yMHZne/6j2VssFOGp2d0z/A3zd4/jAu+WWjAR+YhUMUymS9vsFa
h0nrP7n6HZQ3RzyhCnvAmHSd23ysZiMzJW2Yp5JJuwCnr3BjTKGak03JxgmGf2nSh663dK2l
K+tGUOIO7HTHYtcx57YJc1aABWC2CXPaP4e5/9F/GEAoYDy8OAuBBBAyAcLZjUFCMwOEOEDz
j9uBQQI7/1+Yxcj+R38zvyCPULzn4aNo37AgYN9GB2BglyhWXITJhInxwxHGXnb39b3sX3Mf
4Omlo79nZfDeyE2BFhf5USB2aDGhKPuVDV4I/awv7JBELuzc1hHPjBztc9HdeI70Jm93tLzG
Skvo06C4z/WaU9AOtQb9K5eW/AY8GySUikiu3vHp0af1LGz7ODKOdwsZCy/t1T5t1VWxFjCm
wYZG5b5W317Uc1MkMlN1dNrrga46LkpyCR5dnB4Wl7r8UAasJ9eczFNbeIWVI5fm+9EXnUWW
05QLcDD0FGP3C3bKPjcet9x4Zklvx9Anta67SvPB0tcnymVpXYNLXOU5SFK2KZc6bHFLUq9Y
C1ZwdKFV4bFz/g1DVeh9aPP9a9cnql4O8J+y3O+ggj0iKxRTuSy7MiS/R9wvu8oxyTc4pKQ6
rGUfK6QYJIfUIGrCTX1gjVTTtyNnYoRD+KP3l0RM7JPzvtTianUwoUXEU5mUMNy/tLIoQDkv
O/KoiNQ15+qpNebMdiFRAxIJeQqpDBfjq/fwuLnwr/vbWeqHtdq4kHND3opvSO8oLuf6mHop
encdl0hF7MYGPDmxYl1MqNbK3CLN/ZGiSve7L14siIqS+GiQJVa6qi8Z+zZ/pSGg2pg0OhuO
E3ozszsHL2j8pZcq6Rv+uvzjp9OzsNgZP7XyTwCNxSRteDg8yPOs+tM8OzPzhlh7CQpuKxYR
Na8FrdRcvdxZ6NpEOZVrf8TOzGB/o/aD3AhnaKxBwBq+oOluUJD/A6ujcM4oi0cYIksFQGQp
A4NAACHrnwbXj6cDvy2OkAn3GMbndyFmZ8ZwbF55oT/FtxIMwwVsruUHJL81ZMHQTdtapm5J
2uJvvQTeYdTdoPT4W7NCQ4DXpiYcGDvAhiwXi/xhyiyb7/9iQpGJlfqvmm2zkb1T/E9sZiGC
mKz104rjbuWHOMlCBjBuVoq1VEs2TQyXSNT1SH0bl4bdu7h38zyz9pGyhfRbneWfyj4v4Bfq
LH+dOo5G8Uhz6UFX/RIz9APvZ3gZDzQnswz7zmMSXgzd6Lh2lpZabBkTgrsCYqlbq6u+3T5N
W2tNZOqfrM3zutSt1hbY5r46vXqHv4ukEkjbAVmc10/ciusS+WKv9mjUQdRuqu3UFt7m4sCc
CxOrjSjvlb17mcsMbkhoRSFK6l7zdabrrDpvp5lHCGpdXbtiwJ2sZlvj31xXjB305KlXdkhj
RWsKp7teTJ2cEkqaysx+hH+nMSscQOTyB3XU2cn4FnKKDcvY9BnLOyOSKUQwku6eSH37RhAM
EcxPv7R1XTTT/rFA/McrbZtk0hUQ3CySsG8rhiD6zTdqWDHc6xPHyhglLIZxOH0nkTrT8Wr5
Fsi2WZkU/uCeRl+R3Fv4P4VMDFnBmMFjwEn2zMKORqSwWWicEWqnEKrNdal/bHHueGlmruQU
9hDvLMdo//NUM2l/mUvD52PdchS6ld28+a68HCs/IRA0o7WtK2zwS8g8O0U7f9HoSIyclVO+
2ByYqmCYqYvomfsAY/OYtcWf2II/QToMdyd7OyNZxXzaqtp98nrmPIa0IvSr14b6J9aInyc8
HZ/cGasicfrd6z6S9dvbCN3br+7hn35+XFgDK8CwWk+Y1NTeFrN1pSzFT2cMpdZVwAiz8DwN
Zf+AC52uWk+nC58PXKJO9Q9wRMMd+rTle4JrX6DU4me1ORvj2CxH9iyVOppUJUeA5subUYvh
RckY1X+l6jL9G+afDgMNCmVuZHN0cmVhbQ0KZW5kb2JqDQoyMTY1IDAgb2JqDQpbIDBbIDUw
N10gIDNbIDIyNiA1NzldICAxN1sgNTQ0IDUzM10gIDI0WyA2MTVdICAyOFsgNDg4XSAgMzhb
IDQ1OSA2MzFdICA0NFsgNjIzXSAgNDdbIDI1Ml0gIDU4WyAzMTldICA2MFsgNTIwXSAgNjJb
IDQyMF0gIDY4WyA4NTUgNjQ2XSAgNzVbIDY2Ml0gIDg3WyA1MTddICA4OVsgNjczIDU0M10g
IDk0WyA0NTldICAxMDBbIDQ4N10gIDEwNFsgNjQyXSAgMTE1WyA1NjcgODkwXSAgMTIyWyA0
ODddICAyNThbIDQ3OV0gIDI3MVsgNTI1IDQyM10gIDI4MlsgNTI1XSAgMjg2WyA0OThdICAy
OTFbIDQ5OF0gIDI5NlsgMzA1XSAgMzM2WyA0NzFdICAzNDZbIDUyNV0gIDM0OVsgMjMwXSAg
MzYxWyAyMzldICAzNjRbIDQ1NV0gIDM2N1sgMjMwXSAgMzczWyA3OTkgNTI1XSAgMzgxWyA1
MjddICAzOTNbIDUyNV0gIDM5NlsgMzQ5XSAgNDAwWyAzOTFdICA0MTBbIDMzNV0gIDQzN1sg
NTI1XSAgNDQ4WyA0NTIgNzE1XSAgNDU0WyA0MzMgNDUzXSAgNDYwWyAzOTVdICA4NDJbIDMy
Nl0gIDg0NVsgNDYzXSAgODUzWyAyNTBdICA4NTVbIDI2OCAyNTJdICA4NTlbIDI1MF0gIDg2
MlsgNDE4IDQxOF0gIDg3NlsgMzg2XSAgODgyWyAzMDZdICA4OTRbIDMwMyAzMDNdICA5MTFb
IDQ5OF0gIDEwMDRbIDUwNyA1MDcgNTA3IDUwNyA1MDcgNTA3IDUwNyA1MDddICAxMDg5WyA0
OThdIF0gDQplbmRvYmoNCjIxNjYgMCBvYmoNClsgMjI2IDMyNiAwIDAgMCAwIDAgMCAzMDMg
MzAzIDAgMCAyNTAgMzA2IDI1MiAzODYgNTA3IDUwNyA1MDcgNTA3IDUwNyA1MDcgNTA3IDUw
NyAwIDAgMjY4IDAgMCA0OTggMCA0NjMgMCA1NzkgNTQ0IDUzMyA2MTUgNDg4IDQ1OSA2MzEg
NjIzIDI1MiAzMTkgNTIwIDQyMCA4NTUgNjQ2IDY2MiA1MTcgNjczIDU0MyA0NTkgNDg3IDY0
MiA1NjcgODkwIDAgNDg3IDAgMCAwIDAgMCAwIDAgNDc5IDUyNSA0MjMgNTI1IDQ5OCAzMDUg
NDcxIDUyNSAyMzAgMjM5IDQ1NSAyMzAgNzk5IDUyNSA1MjcgNTI1IDAgMzQ5IDM5MSAzMzUg
NTI1IDQ1MiA3MTUgNDMzIDQ1MyAzOTUgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCA0OThdIA0KZW5kb2JqDQoyMTY3IDAg
b2JqDQo8PC9GaWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDQ1ND4+DQpzdHJlYW0NCnicfVNN
b6MwEL3zK3zsHir8gTGVIiSMiZTD7lZNe6p6IOBkkTaAHHLIv9/xOAldDkGC0fObmfewPXG5
MZu+m0j86oZmayey7/rW2dNwdo0lO3vo+ogp0nbNdEX4bY71GMVQvL2cJnvc9PshWq1I/Abk
aXIX8lS0w87+iOLfrrWu6w/k6aPcAt6ex/GvPdp+IjTKc9LaPTT6WY+/6qMlMZY9b1rgu+ny
DDVzxvtltIQjZsFMM7T2NNaNdXV/sNGKwpOT1RqePLJ9u+BlqNrtmz+189mZgWxKU5179MIR
KRqQDEh4xCqGiJcBJQFVqHLtx27db2YE1BIfUswW7Jod+GRhRqgipGVeQnJvhlPBEUnPcfaC
1tLMy3Neyu/yfCmvOOoqriCYTEhTCpUjUQRCz4R+6E2J9T1VogeVyHklDSvFvKLDylyV0u9e
5dKrFrijWqiwB6ihUZXqBM70E/6XhfMRJv/yrAklJr2LJBWWmTIQ1cKhQc8QUt8Pjk/jNkLb
r0c/b5LypuuRpAGhlinxBvkAqBLYUa2LR/eCceF3CoIOtyj7b+/9tfXTdZ+J5uwcjAOOIM6B
n4Cut/cpHYfRV/n3H9t6DYwNCmVuZHN0cmVhbQ0KZW5kb2JqDQoyMTY4IDAgb2JqDQo8PC9G
aWx0ZXIvRmxhdGVEZWNvZGUvTGVuZ3RoIDM4Mjc5L0xlbmd0aDEgMTE0OTQ0Pj4NCnN0cmVh
bQ0KeJzsfQtgVNW19trnzOQ5SSYhk5nk8JjJyYuckMlkkpCBIZk8BSKQhGATHpKQCQZEntH6
JqhBHBDxQX1WaS+W1tv+nARag7U1WvWqF3zUXtvavxWqWH+FgtbWYjW5394zEwKi7V/bets7
K/Ottfbaa7/Wfp0TRkOMiJLBDNReV13b8mbdx3cQm/9Hopiyuurza1K7un5FrNFGJB+eU9Uy
c17jzVuJLb6ByH/lvPnO4i2ZX6sgYnehlvbOSzrW5v9A20XU0wP/xs7LeuyybEHe3bDF3L98
7UWXfHefLYXoy08SmfddtOqK5Quua+4i+rqPaPH67q4O/4frnn8W9Y1HfWXdMKQ8Wfgw0i1I
Z3Vf0nN5xxXTM5BG/9ZfuWpNZ8e6Bxc5iIb3E02/9pKOy9fmseQ3kX85/O2XdPV0FH6nZDH6
W4R0y+qOS7pkNjON2LQSIsuP1q7Z0DOymXqIzfsj91+7vmvt8rkv9BFtQfnkPOKxifp43YtZ
LU8sTfL+npQY4nTgzbtmcPlK0W/feL/k2Oy0d20nkIwliYKEclHThz2sw7rw/ZKPd6e9K2oa
Q8pGbpnwQzofcfeRjJJmctJmVLJbtMtINhxjO8hIMcZ7jG4UuS8o2Qe0nA1LSZLBKBsNUbJk
OExRI9WUNRJufM58u52G0LvdUR7eB9uJcd+1E3uA58mPGhfwkZJsrKUfiq7+iP4qitpMl/51
JSP0P5kMa2nFp+YVU+UnbBtoFpfyPJovr6UL/559i9A/lgwP0cpPzbuMurk0fp+6Rm3uoM2w
krrl3ZG18M9M8lxa8ql56bizzrY10nlcSjfQXOleuuDv2LV/GWK7yTZGv2RsnjSL3+ERilCE
IhShv5TkbLr1i2pbeow0+f+QS9bJbSgj79g8pFeP0fuBNcCmz/KTjlKBfJgmy69TpcFPM8/w
W01rxugDwCZgBzDn0/zkaroW6AQ2ANPG+nH7Z43tiyr7RdDfq7+GvZ/+TBWhCEUoQv/bSEqm
VV90H/6eFLWfNnzRfYhQhCIUoc8iqZq+80X3IUIRMgbIYxghz2j6ZfLIMafTfwvCO/o5/41L
uom2nW0z3Hn6d7Sj5Qeo+G/ZnwhFKEIRilCEIhShCEUoQhGKUIT+Gehc783/aDJ8jXYADwNb
gK8CTWflb+LS+GP6Vhift81oF235vHUYGV33aXmG/bTgE/4ydXApP00Xy/+PLv+87f8rkfEo
3fCZ+Y9QtXECVYfTUTJVy/bT6c9DhhHqNTxHPYY46j1XvvQ8fUN+nNINP6We0f4U0+Sz/eTX
yPW36M+/CvG4hXXDEzQI7AC+CZyxN7idS+OH2NshfN62o/fS3Z+3DuOqT6/DaPnk7yGNa4Lr
w+DAeqqnmz9v+/9K9Of2d9QSajA+QA2j6W9Tg3zZ6fTfggwNdMe57DKjH5xtM+755O+t5T9E
9vdYOlfcvijCmbGT49PyzkgPn9svQv+6FHcvZXzRfYjQ/z/Frol8BydCEYpQhCIUoQhFKEIR
ilCEIvTPS9KrtFNeQQNfdD/+J5PcTPuBnC+6HxGKUIQiFKEIRShCEYpQhCIUoQhFKEIRilCE
IhShCEUoQhGKUIQiFKEIRShCEYpQhCL0eSjuXtr3RfchQhGK0P96MgAykAUYiZgZKSbSMsUh
fR88jiFdQnZoqdASKJMmUwEVwlZOFTSH/HQxraUNONMO2IvtPfbL7TfYtzh2ZKZkPpX74ciI
aCeBHJRHGkq5UGrGaKn1NDBaatMZpdjI74lSUtCH78nVcjXRyI/QsviRDkpPvnHydRN+4vHz
3Dslrz/2ZlXob3sWhcCp4M8HgL0llyXUsSMJ5yc0UiIM/P+gw2g4nG8BrJQ5WSmmzHzFTZnd
SgllrlBKKXO9UkaZG5SplBlQyilzq+KhzNuVaZR5hzKdMncqXsq8U5lBmfcpFZT5qlJJmb9Q
fJTvVaoof4ZSTflfVWoo/36llvK/rdRR/neUesr/T+U8yj+ozCST6N3+UDfUsV0W8QyC/7FR
RxDsLcjMIOQyyDxgMmLI/26KFkRCXSgqADsCWRgEewPSJeaZZP7f6JYHIV8JOSOIhPMhK4JA
rEj8fRsOM+APYTNwcQj8/5mxNoTbgPUAr5v/fxv4d6VxB8rXQh4IQr6GyF4chBFjsPcEIfdC
Xh6EfAPkJgBSxkzZtwQh344Q7AjCuBAhSAkioR7yqSCiUCb3wyASpxP7yVQAY4zOgeRpL/R8
yEYBiq6EvECAousgFwlQ9GzIdgGKnkfsld0CFD/Ot66vZ8P6dWvXrL5k1cUrV3RftLzL37ls
6YVLFi9a2Na6oGV+U+O8uc1zzm+YPWvmefW1NdVVvsqKGd7p0zzlU8tKS9zFriJn4ZQCLX9y
Xm5Odpaa6bBPmjhhvJKRbrOmWVLHpSSbkxITTPFxsTHRUUaDLDEqYDbdVtNat1JPr2nXTWqt
arbrprkn5zh1SlEcarLd7WybEvLSjZpO4xr01MbWfvKVt+lR2tkuc3U52/yeA4XnKPY63ZCN
jzq7w6/nNbc6VPMrymh+G8roGTWtDoeiS9n4zEIWPrM77H7d3Ai7QwlaZunU2MoxOPLrchip
3NEG3tyqTwwn29rO1UksipGhs7o5lwXM/ab0mlqdUvvJ9GudLNztZDnp5NXzNHTEDE3URk6d
pb6ns3E6s8xBl89sghc7XH6OGNT5V6p1/hWIqL/9dExPBiPqsAfsgebWZDdU0ekG/Zmm1v74
uBq1pisOBhIG6o+LhyWeG1DF2n5mqmBCkUx10/oliklA+FJ4d+s4Vuq+re1Q1FrEDTnjTucM
jgxtG5tFKBbWxgW1YCf0qBo9OtgJ+wrd16HTVnt/wVBg26CZlrVrJr/q71jcqssdcOgnObuu
u0Uf39C4ECY0BbR32/l01wrGJ89e120PIM1928HVWj7pZ9j93V3tfJmwdrUWeaym9UbHkKKn
QNbpyZqeALeEK99Q5ECdbYWdJwOBG+36LnR3TK6DcywCG7oeqFPRGiqrW1nNp8Q5Om1iNc7y
i8nxbe2w673LVgbXXse28Pp3BMy66Q8OzA7mByVFwVAo/e0reZdXdvBh1q20B7Z2iaFuE0PD
erXXrazl4AWx+mkBSi9sretW6043iIFDkbPPLutw6OkaLxgI1PEudvjR+2CXkXG6/3xPKBpD
f2p0X4sQ1CLmAC36OmrbQqaQw0JejOe017a1OYLzDlc9OvtGY6FqD/Aao7P1VM3seBJ5Q1MK
Gppb62oVMXpdqmmdcdymHIfe0DhqZjb4BJzHlWCMGuarDU3BVdAdZu0twQ0sjc48XEP+otZD
NuVQUF/cWq/WtwcC9aq9PtAe6Bgc6V2m2s1qoN9kCqyta7eL7c9gf2Srotdva9PN7d1smpgh
Xp2dr7365gZ9XNMiPlX19u6O4MFRqTrKFUfyqE/jp2WH9hxWP/YA33MB8zH0LRGnk2Kv50fN
IE4IRTeX8y2LDi1oxZ7oFOtXMOyV+ahc4btGbsuuWzE/FCyszNDi4WdgU8iKShwOvp+2Dvpo
GRJ6b1NrMG2nZcoA+Zwa5rGd5wyFcywLeE5vOGe0eLuKebM1zP8z63vs2g4kqyl2j1PEXxy9
fn2oBWP8Y7keUx6a+nE1rbIihTRJkbkWp+Eo8+pWTRTkMcGJGTCr9hdV3azphprWIcXbZjcn
46hj8Jmp8R2EE/VF9VnGz1FKNevMq7M0biecq+J4l63lyBxdSPa6QHtopY0dVugy8Hefe2zw
MasYnhL0T05R+QgPiuMtdGpn1/N9pTiCHrPb9ER+NuuJxwRDf5WaVjtOIuzcJqHY6+zdfLJ1
e3utOBLalLHmwZHD7bX8CESXuYsSWuLgwdCeudamFPylC70XC33TtrbuaajFl48R2EvRrNgt
La2hKJUroR3F25rFh3Jm/mgUwz6YfGw8h16U8awNCzXDdrztXCFvaDkjNaYxkVc+ejK0tOr1
WrjyYPo8TRmbnHlW9qxwNo6Pa5Qroah8zIGAn18ncPAp/Uwoxpqtbfo8rU3Vl2mqQ23t4ldO
DJkcLe01mE8eR7W+A8FDJEUcA/0+H48hDxlO2Fn+gDq/1RuchxRqYA0tOE1xbVb3q2xLU7+P
bZm/sPWAmT/9tbQOSEyqaa9u689CXusBO5FPWCVu5UaesPMEr6kZiRjhrxzwEfWKXIMwiHTn
ICNhiwnbGHUOSkGbOdhQjmjIh8fvzkFDMMcX9jbAFhO09Qa980LeMcgx85xHCI9uJDKD1E88
wL44oy/GF+szSQkSIslNA7A8At9YRvtMLIEp/aizWZgHWW9/rE85IGpqDnn2wpPbekdt6Dl3
G1MR2gsOfMHpESxY2LrPRKhfcHhUc8IdbOvGAmpVsWX8uq+x9eq27kB7G1+qlBbcvjgX1ArS
JbUCPY4y6XFqV7Uer1ZzeyW3VwbtUdwerVbj8MDRYucHZaBdxeGJ66uVFNbGDwC+2aRs++DI
CO6fQ7i3HHpU9mIA11Os1mbHGTAbfudxtMN8nt7b2cH7wTe5zG/CWZ1tesxohXCZpceihthQ
DfCoF2X4HYpCnVhiHapQYcbR0tumt2m80dYVvAK7HU+TM9VpelROsE5jDm/I2RZIUYvFZRyV
rcdl38hFLPrGrxFhUZBEY23BIEWb0PNOFVmd7fbgGpmPrWzI4Z84JWjpwjORIadLIE4JZVLw
/IlPiNNjC/lNHy30+EJUiE90W1uw8yJ1Y8gBbZv1ePQoZ0woQwUQHWTN4n3B50Z0lbs+zqtp
GqRm9XKcYLzToqZoZOsJ2bM6cFwHy8fDopaHC6OuGGHidTwZtEbzkZvE60DL4Mge9QrHGMKR
gWcbvhmIFDyB+6gtcLZBX4RrJ+Zsa4IwBwIxCecuEIxXTMKoXBS85Tpxsi/nt52dX7VYb2TH
/YygRuXM6thanlLCny5WYEWrs/uluZqQTMjAbFw3KMmB21/GhnLY/W3cS+VHPT/UPtWJjXHi
j4ui8oB5ejjFQqng9Ab0i85Mdo8m6zn4I3Zh6PnRkCMuGoe+UtFXYa2GXfgc4eXErE7jl9I0
Ufg8jnZM2+hGwYbAOuTbqLfT3roMyx8V4larD6ARe2dHKJChlvTV2hlVYqcwLCdUxIej9zba
29vs7bj5WBN/EcT+hLQv79B9age/ExqD48E7Bh91R4AveuLXq6JH455a3tGliidnfiYFo8/7
aAhtJFICATWgi51cD2dUn8OnjQt81mpqRxdml7dn7+gK3diBYHR4bUqdit3dxR9gpotx2XEY
LuOsUzzEL2nXEInkQErA7gngUF6C+8SQ03lBO+4sfjXZxVR3KCp/6TPP4qk2VBR0jM3mjsFN
wXtzida/JDr7tEV81mhB5xhRq1289DaGXcQO48o6vOzhEYqa+eBZs3jkFyeXzLNnIbw+rCrx
ymzXpZbwi4QoP4sXVcITFiwGi7hVQjuuP5ttaRx7Wy3W0xqaFykI7BQ6QHY2vD/WxmbbB9mH
YeVUWPljWPkgrPwhrJwMKyfCym/DyvGwciysvBNW3gwrR8PKG2Hl9bDy67ByJKwcDisvh5Uf
h5WXwsoLYeX5sHIorBwMK7vCyi1hZXtYCYSVLWHlxrCyOawsCisLw0pbWGkNKy1hpTGsnB9W
GsLK7LBSFlaKwoozrEwJKwVhJTasRIcVo29EaO8L/p7g7wp+UvATgh8X/Jjgbwt+VPA3BH9d
8COC/0rwVwX/meAvC35I8IOCPyf4s4I/I/jTgj8p+BOCDwn+mOA/EHyf4P2C7xX8QcF3C75L
8O2C3yz4NsG3Ch4Q/CbB+wS/QfDrwX0Vs+29IrVR8GsFv0bwZYI3Cd4o+EzBqwVP5DypqtNQ
RZMAJ1AJzAOWAmuAjcAtwAPAXuAx4AUggZbKb+OpsFd+n3YAuwAdGAJeBA4DJ4EY1OpGrW7U
6katbtTqRq1u1OpGrW7U6katbopDH0rgXQLvEniXwLsE3iXwLqFotKrSa8AJQKYk8ElAJbAU
eMCg+lTjyV8z/eOhj6Whj1/8+PDHJz82BIU8NPLiyOGRkyOGtVVxhmx0ewj8ReAwcNKQ7TMZ
Dv/w5A8lwZKqkg0OVOzAYWGWWuGdBH4YkNBsHE8bYvazpByWVKUYokU6CnyjZBW+99EkwAlU
AvOApUAUvQZ+AhiR7vPNl187nGYd/5P/Arvq6jTlqqvTX/ox9Mu+DHbJWrBVa8AuXp2mXLx6
4/qMnktTLeMvWgm2fAVYV3eq0tXdty4jfUPalTXpjiuA9CqXdBvdDUg0HryAa9Ld0j3SvWSS
bpa2S7dABqSt0jYykSLdTVsBDAn8AeD7wC8Ag/QgfPZQgvQAyn4N8j6UvZ8SRt6Stg+kqp4D
UO7hSlWGdJ10DaZYkzZJV5MR8lrpSjzGadI1IXml9CVh/7J0kZAXSV8aMGq4ftYOKHbPD6T1
yOd+q2E3cPuX9rncntiqKmkdpQMPIX9Q+KxA6lVobwGydIN0BSKq4e3iClF+IyTvx1UheYV0
gci/XFrOf+svXQbJ7ZeG5IaQXB7y64EkYQ/KNdIFA9Ha5KpGpBlt5lxaIl0oLUUIm6RmaT7k
XGme1IhQxktzgSaKk5bQdOht0C8DLkX6XqS/C/lzyDhpBUpcjIB2oqYuyHbUtAxyBXmlTqAd
WAI0AXOBWskrolYjJWOiNLxfBdMVSPNRz5CSEbX6KgvsjOrBnwYkaTryo5HvgeSjmxryd8A/
mkfZPTAuzVOVJjlDGYUhOQWSN1AQSmshmY+CRu28qmqkGRnBHxRdmi65qQHwI9XDfaVqySya
roLkNVVC8q5PC9nLQ7IsJEtD0h6SJaFyrpAsCtknh2SeZMYQAlWrkWaUAX5AKsaQrZJNSsek
xEt4c4SMkWKlODE5MUA8gm9Fb2MwOfGYnHhMjhWTE4PJsWJyYpCvokQ2JmMCapoEmYGaxkOq
mIgJQAZgBeKBGPKy+WwOHxmbG5IXsMU8VmxBSH4JkttfZT/B2aaxn4XkUXaYj4wdCcnD7B0h
T0By/2PsHcTah+eFgdg4bLYhZhhwuUIKNs3gyND+/5hk98BDHigo8DzCZIZQDEzKVA9wdd/Q
xIlq2DhhQtg4fvyoUVHCxtSMkNYbPy6k+WLjoEmM7fM1boXGuA1aVRzjL+zzaBI3cYkO0UDj
AtEz2qeqvEf08ISJHt9biiK6+ZusbM8FgyzGN4798mdGbforDa9IPj0+wfP4kFGDg2/qA+PG
eXz3OYs8993DtHvvMWr33GrQvnW3Qbv7NlnzPVXg8tx2q6xtufWuW6XYTlvnf3TK9s6EJFR+
cv95k7I9/znI4nzj2V07mTb1fvaVnZJmuzMn32O9k5l3Vvo8P9/JHmVlrAD3hcaKBg4ZNDxc
DBzkYsrAIRmigBsfZeez2cJn9sBGo3aALWIt2FdJVemsBcNtIYltZlvE5NwIySf3ppDcwm4R
BbdD8vQt+/qMWmWVie0ixp5nB0XmjyGxDdlL7OBAFJ/Z6IHiYg8Xe2Uehn2/miim1Zf8f20Z
nmefk7XnnjFovmccmdy67xmLVcinEU0h0zKEt/rYFJensQlxakK8j2JYb7yOxOv5+Z5DB7GC
DlbXCv+DublcPnzQmuF54m2GUccOvCoa9rnfzs72vPY28z2pTPDs6zdq/ZgY39CMGZ6hvQbt
5b1Gbe81OK5fTUnzPPUDZt/OzNsZr3JrWbmoemuuJrpSvBV1b7vZqN0cMGg3BYxaAHF8/4Ss
vXfCqL3bK2kndxm0EwiN71hxicd3DK3x4ruamoOy7rygLPeK6uJ3YeJf28V2oSS334H1z+0/
6UV8Nm1k2rXo1TVo4jjws41sY1/2pC19TLsRuAGtXA9M7vP0zeqTl/ex+j5W1sdy+pgy1WIr
s1hKLSklliS3xVRsiXVZooosstNChZZTHybZTxWdknJyE/Nyk/K1xAItKVNNzFKTJk5KtE9K
IqPZKHlnJMZ7e7x3e+Ukc7IpNi7eFBUdY5INRhMuCFOU7J+0Np8l5bP4pIYknBTTqVbukf+d
fpEUFU/xcnzSdJoe2yYvir1Mvpfujb076edkOsDimcmXn6SwCQm26IwEi9makGJITXCeWnPq
gVO7Tr1w6sVTUZWnfKf2ntJPHT5lpEEWP+A85XyExVMli/cVGf7kPeX9wPt7b4E335vnzfFm
eTO9du9Er+K1eS3eFG+SN9Yb5ZW95JUbG90tTE9poIaWan0cg5xfrbu1hkHZ3qwXaw16bOOi
1n7GtrfBqktbsKNbdMMWvC626Ck1Cxe1DrJ0nt2nHMACJ72hve/mNk2bUK37G+a3Dsi9vROq
2/Rioe/YAZ0a9OImXVGrtXPRhp5Lw3JDT8iEH0H9eTl1en5dh15Q116rha2C2AZQ0D9UalSO
IdQ52s45Wx+bxQUTGvXwynq4pafnDMdztMH9PyUlatxwZhkKDzjk0vOXlflEn3vCfrpNr8QU
nu3Qz/hcNjZX83+batD9zQ36xMZF7XqGWt2gP4NUWeMiPVGtRt0bgtTDP5du4BMRsonfx/ZL
nEWBLVrUWtXJhsnPPgROAX8EPgD+AJwETgC/BY4Dx4B3gDeBo8AbwOvAr4EjwGHgZeDHwEvA
C8DzwCHgILALuAXYDgSALcCNwGZgEbAQaANagRagETgfaABmA2VAEeAEpgAFQCwQDRh9K/zv
+9/zv+s/6T/hP+4/5n/bf9T/hv91/xH/r/yv+n/mf9l/yH/Q/5z/Wf8z/qf9T/qf8A/5H/P/
wL/P3+/f63/Qv9u/y7/df7N/m3+rP+C/yd/nv8F/vb/Xv9F/rf8a/zJ/k7/RP9Nf7U/0n3PF
/M2p7R/TjPFm/n0o4wIyi+/SgAxW8c0XQfKjQR2vWV/lPGwfbj6to3Q/JcgzKIHXIllGTkqH
yTyya6zHJ0k+HG4lJgT+lS2qpmtCDp2jcq2QF3xWbfTEZ+aem56nZ+n7dL3QH6V99O2Q/dv0
XepDjY+G/vpVGx6MbqBd4C2wLKRZtIAuFH9ZZx3tpgdDpZZRO7nEd40qENFAyPocvUXfYx/B
795PtH87WllPg2jpXpqN+iroVoz2Dvp34n9jZjNSp+kVwQ9LHbSSNtAe0lHWT93COoc20Uxa
jL7VI0rraDVaX0h7aT91UT/dDfuj1Ez3R/2QYqQePlMjv5OmjfyOtqLsV/CWtEnaLvdSD11N
99OvCK/+dMvwE589e38B7aC7MIobaDvmdKE8Q26U20fn9s/Rw4jX44jN5ZiVb2A+7qcdLJvu
oRvpGmair9KjrPiM6Pw19DBtO/2Xn0L0IzqAuD2I+d2OiG3AvHwTvW88uyjLY3FYNytpIUuk
D2np5+zJuWkt1sLlWHHXoZ31GHkrLcfquhSyG7h0tC9lrIK2YNb/DWfiG7BX07W0mjlwUj5N
W5iNroT/V2G9gx5hRfDdQPtZHp1C/Yswyk8QzgNz6Dwgvi9ZGvYJ9qb8IU/Lb4fPgzBnWfTM
2POAqSwB6+1hegjtf53uZQqT6fd0hIaZk43HzE2ml4CnEbdH6HHE7xg8bPRTxv58X1Biq7HL
EMr9ZF+w2m8+42zahJ1yH/bXNVhD+7HXH6fb6HuQ25DahR10J30Ha+AbWEu96OvpdheSG/wi
zkUMErEyaLTdIW4feWnkkGj3ULjU8PZR/b+wm3+B/dyIsyJCEfoHkhT90evG16RZxiQjG3nH
8FC0YXgR+z0yHsSOvx38KvxcdO6y8sfyW8a9I781PjJcbUw2Zg2vG74ad9lP6ef0Aj1Fr9PL
WNnP0W/kIvkp+Yj8nqHdEGU8ZPw6fddQSF+mr5xdn2G1odvQZNhtWGgoNOYiPR53VTN9CXdV
O+7Li/k3Z407ol2G24wXGP3ye/KHxrtQbBXOvc04m24n/i1aA/0QbLOxhfKogIqohBp82RZn
Sd7kAiqYEO8qLCmILyyMLygxlJbRZK3InTJuXKLNVuiSqfJQsROfyl++cqg4OYVZPU6Q+ZD5
ULLbfKjY/MunXUWstKRCmlohl5bkqJmJUrRaWlbmLp4oWVKRSJQtFqtFLWXJjmQOaWpUWn6W
NUdJqqqwF2Wlx7Z7b6qp76wYn5TlLbDnWKJTdrCPPo6SOz4qZ79JS8vOL81Nd7o9akNzalbx
xOsmFk5w10/OqZhRP8VRkJs3Pmr11742/Ibhnj8tN3zw4bcxQGL8XI/iz1FldK/ep7X6ppek
+2JTZqanu7PjE3PlrOysb9QmZJPL7fpGbalVkd1yuq3ElsTmlJRMijqeZi2VU1LKMxS3PKlX
cx6xFqd4nFb3EXDN7aZKq1tLJrfNyYXVnZziscHuKlJ86Wc1w5sIVk82lEp2O93JogD8i1xt
DJFJTp0oWS2O0gqpNLkkZaqKg19NSznTXCjlljoYc0QlFORa42MtkwuHl3oKzLFRycM9G4Z3
JBtjhe32ivyEOGtOIetiS9l1rNmYFZ/mqK776IGaiiybyeVKzKpvYhvvZKWejxzyiRnDQ98a
vi2UZc6dOVvuqKtULQmuj9zyIf7N8RUjJw2a8U7KRBR3iigWJj9kNiftqTVb3KlOm1N23umz
pWVOnjRpsjx5p2+SOTpqT200xbC4vpTUTFnlv5aIRUxVtbzgesUpwocoUmWlhnBkHNeSU8gT
VMjttnGr+SgPoxXtoAmb885VqH/S5J2rUDfqRSmU9VRqxcWVR3n8Sgrl3NKp7mCwotWpuYmS
mplTWsIXX5oVgZPVzChLapq7uMJQKhvkBGuu+73pUala2TGvKalyyQrv7oGep66qXuVJdJTX
OHs3r15bMK18mpJoqGw/v3RiSmxJ3J+unFuTlx5fErfbUFOTd+qd3UfXWmzD/XMv9BWkHhoa
eibJMa2owsXXXCX2lxfx8tFLPFoHKGXkrX0Y/rjBoEwdHDnpmwElv3CG3aoYLVnyZJ9EKSSZ
cCcmpY93yYXOwj21itOSlLinNimpYsae2gryscRkS3qWkfL7yvgvfMxsTplTO1JsLQ4FkiO4
EvlCXHrhkoxDfKnxZeYqwquJ4sv6jBZ5a0m8FRHcSr4+MU9n1MIj7S6eWlYmPtjiWI2WqKjo
aJaWxtdoGbfl5OYWSqqKYAsbjoLk0OywVXaHJd07tdAZG5Odz/YWdk99k9mLm4qGezPS4zOn
fDlzgl0pN09xD28ozk2OFpP0rleaEh2ruTVvusUyMTPK5Yr1lbw6vKW6Ms7lkpNTkyYUV+ya
Mt508oIaNcHlShifW1Mm14XnjK/eWcPNhnj5IE67ctorVm9+bJRYoArlFOYUyoU7fTlpZRnu
SW7ZfScWr/WhtDTLntq0pMzrXYMjh/mMufgKTkDAXa5pZMuQy/uSxJqGJcmM/CSnpgUPB0gK
rt/Ty3l0gfO0WNboAG985yre8CT3natEq0mI/FGxprG0k/m5kG0J7/7TUYy2VshY1JbUqCgs
cRkO7uKyUjM/bS1sbaxVKxruzppiizGYrLlT3pmRkFQxc855eQ/2+x+7YfblxbYZ82uvuPJo
eVOjY+LLVb5sG8IYZ5lcP01eOHNGXkZKbGnsvxkqPTnmD3774JF16Wxpe3eV/dkn2RZ17qx8
rO35uNWm4FjIpa+JWE5MS7el76m1WbKz9tTmPJSdlIQXihhzjJQqxxh7TXylp5jTZhpNsslo
jo2JmZzLUvomDo68yMM6kS/f4mSP8xCuFo20DJv5EBYcFlvlUbGgQ/GyoBHLWZWLur+Hqk0+
o5mfIoe0jNHCwegxawVigwsnR9xFOErHLklJLMk1iVMvvKRumnOdrcyZdV51eprbPXxJjsNm
MthcU96eIafJNXPyo94sc+U31hcNf31RnT3W5TKl2Kvr2X7fXKc1poT/W+eFIyflOETFxeJF
VNKcGZUZ8zLkxzIYZZgz7BlyRkbOBP5bYd/MlLSZTgYy5pguM202SdmmUpMkk8ls8pkaTe0m
Y6zRNKHQMkGesBMDLzTKxp2F5owH09PzixnejWPMfZmZ7pi+fHGMHknm4ApVHh9zmCIQS5cg
FvwgWKJxhyVL1vNQfkbPXH9Jz9Cxnat4t3auKuRh1zBJY1o73RiPv4qDQBy7adbgEwAWbG6p
O40fw5I4Kgql8BktjbSnec+f2rg0p7Fr+ZrKsmU3Nrbc37BMWbkkq67MnteyctHqyrZvrqu+
aol0xFs3vqGq0FuiFcxeVjtvVe3E9NSXFs9PUr1T3L7SKTkzl9U0X+FLGMd3/0qcxdUGK1kp
iyp8Dut4efzvrD4r21NrjVdl9Xfxvvi4PbXxscnHJ03KST9hDEaVb2EsRh5RZ0hzFbmDd3AO
P/XEE000BiQnY8UUi3NPzVxZkm8255ewwFcP3tE0OfuWF/XFEyZbf/LS8kc21bsSsqumSYum
+3JMrqlXPR7Y0t2xuUZ+4qPb5V8c+cpTi/m90Y2+rkdffbTBV0V5cp4vRc6UaXoh7UwtsmYU
yVMKp+ypTZ+QKhfGJ3pk73TvnlpTjFmeHpticDgmJMckJtomjKu22aop70SJ8wjfWfzg9jg5
Sx59YLHiiSWk8AFa3dg7eHITd+Pomc5Y8OQRZzqOdIOqju6f0TBY+Jlz03iXZ/rGckvuFPat
rOa6/2buS8DbqM6158yZkUarte+7rMWSZW2WZMmyPbblPXYcJ7az2bHjJGRxSEJCEqBZWAIl
CSEpDTROCyVAQgJlSVgMFMpfcEJ6Y7iUpe2lcEuhLrSE/fYSwPJ/zkh2HAL03ufp/zw/RLGl
M5r5vu+83/u935kzkP0TKHX5Sv3ZxVar3HtUolSrzLoieXE0u6bUL5f54mBfokhGZuT+bc1l
JruTDod5kbrsW9k1Ib9VFA6TOo3GH/tPuUbG0Nl3uXhNxq7KjSneXZ3E0VqKtO4sFK0wsZCN
6glWLGskCJ1I4vJCIZ5Tj8ik0WmOZAAKnE4QJhBPGSAvaP+ouDhK8j6R5+LzdlShnRaai7Wc
C6kwjfpi15EKU0/nFDyARBt5bfYlEUVid+/NuzsPmEEapOJFBbLiSPbyUr+ML8r+8hFyuGxp
OMte5OD4IvLOsMTDJsfvSbMuPOZmU+DNTP/4HITn5XilD3ltI0qIZtajxxhm9foAQdoI25EM
IQ7AwGcoX0UIGgL5p15vyGH8iId8vQjWyFnOSQPGtn26axENri589C+qMB4ufaE8l7I4oUkm
25d37bUDwx0lbost8pO+RWlFOL1tzdyVjTZvQ1+yd7pLlVf0Nwy6LSqbBf6yvdkjgnuzDYby
OWl2dkSZ84laiXwKEiliNVum0/rCYR/0fcaGw4TYRgaJ4JGM2UGIkzA55ZrLqNXKfTaHIy3/
NBZLh31TTqIXdoyb0/PuRrnZnfIYc2Ty29yWQr4W+avF4HdOlzI4Avk0nxaAsR+faNP5q1pY
UNJUNNvsD3knistnFsbL0wtwOPb+cAd72ZzOXCwW4liEEIEFGtIRj1agrGOvC0bNTDi1andV
QvNsPjJta9chEiTyVaWc8iCE97OlBoPFRRAikYtwyVykmHZR6gAFqc/YgEZtgZbP1EL9PQaD
z75DJgv7dvD5UeKecI7MJl8XVQg5YgVdEPN1OKTMyQiOkyHu4TAnq6cTOESY4Pj7GW1VX8vA
pbZ51y9eWmWsHNw7q2Xf3H5b5czKBSudnRsa1s30nTrZfe8sQDfPdnfNLqlhU76a5uZA65pG
u1Qx1thin9MYrUuHLeX1c9MHfqKTf4Aw0IN6YCHvGYTrKLHiMZo6kqGP8YcBZKUSm9oslwXU
CNh/ZdXDgHzcbPZAzxhrHgaAVRcck0jERzKSc8wZW4EcRqMx36iec5jrMDgp9rkBey77PK/I
MAhkn/8Fcx4387hvwFk81TdMNQ7q6Y0DjJEhnin5UJA2xY6G+fxITa2rdU15x80LQrWowSoM
2Lt6WmcZS6I2Mf3XxrCVKRGMe4MeoyDIXwZDPnXzvmWDtzVLCl4LxAtN4ms3bb1S6nA51Him
WVjBeR8lNrNGwgrRBwqrVeySijDa5Yw4HDqSCR+LPAlQOUaHW1webSFWXCq96xylMBj0UhnD
aNV6fYywnfFz1IYSICmfIv48/nWyd5Hj+Lep/I9+K/3zcxkAL5Dyk6mCdJNFond4Us4CownE
XXWFB59WW4stT70iVSpVGrHRm33LaxTzTGUPhKgHhbqox14g05KBAFVs2/V3g1nLCwC5ooD3
02ChUhAICBSFIVLaEMERw0+ZN5Ap2E4/QzhRPEqJnaycoXn0kUw7DxA8GY8UQB4GhknpJrwO
VCXHHGxYU2JEQv6vRlYhP5JRHlM8DfAjyg5AEkYEEkXpOcuo3x8Xa1Q1heCMWByPYdR/EvlT
JK+dPn8XAyLHFjg6U7+ggKFMWZdTouBbInGBHPeosLaJ5xc/1KhGSCz+7O9wLIyxYxEBzx+N
B40brmn/YVdfnb0pNntOS7s1ldKRQdi6GQWDwcFwhshgoNgkCDIrySKXXnjv0Ppba8+1tNi3
X7nlKmXIq8tyaqENVpBzUZRcxCxWIiBAASwQgxhEchjlxeM6p+NIpvCYcxihRaHLi/RzzLsC
4KpRnDEHP/lT5HWcHrjkca7j9HgTuaqN4FWcbyjnb0OAjReqbvB7Pd0il0tZnJDKHIXZ/3Dp
JTxD7FiYbobRgJa5w+nQRF2mcxG3nIddcxeDUNhjQBmBtVkXDJEHkQcBVMvWsxKbSKSnFHqo
H2M1CpTnrMjnQww3thc568O5bi05p9Cr9SaNj6AoPngHda78My6XuuCMyRTSvKM+T3WcKk7i
KsD9QfM72pOjgOfz9CfH08m5d16f4gnMqdNvEqGSLJuhqKmMVxoTtfXtwRu2r97YpmiqKq8z
ljW462I2X1N/rHhBZoDWhksDRTqX3WgK1wZ7+q23pOKRgNFtt8icgbgznClWCqTjtyKHdNkP
QC3xHiEh0lzHoOAdf1bCCiSNEh5fQj4sEhVIOWiePBkhgn7DB1i7C6aOwfXb8AFuEDng8T24
NntATBpasTAeLVHx36vP1G9YX1cRal3cPKMZXW81gkwCXQ8SRdz1hPCh7SR4kCRpKpcCqCqi
a5zAHxO4RHLdpzMGEr9577338Gw9i85wC92JzsAnarlzGEj+QywPQkiQwJsiXoE19IM8RsB7
0BvyA9nbn76Ny03QMP4iOvFj+WPzn+DuADqhEl/hlur+8OkX6M6vW+CjX92CLkYS++Dz5GH6
Nu5aXlbNI4AM77Zi8D7SByH1IJ8vYDizX0UYxlW/B08nOqEdvcAcdoWBVFet1NO3ZQPgFfxC
3/MjJw6haqonUqxRplapNHya4TNHM3yNUGVT88U8YqdYbDRwzPC87NXXDfpRbO15okSCAUxf
jcPgQbF3RXlq8I7E1tAy/vKcFpvBqHanI0Xg+gQNmJpqn56uqOA7mueCj70usd3R+H7/UWRN
GBFdK7LGTQyyyQK+lR/kQznk801urVYlKJRIhCqTCupVQ6xJKHQL3NB9h4DHt94kl3t1boHA
o92j03k98mmCJ/jJ66NEkGMtXOQjeZhzpstzKzlIzaIylohCLOsTXAuGXMiv0Wq4JVoen+wu
8pvUSqZL+vWn9hPr+xan+ucv2mjctP5k+5H7fHOubDrSeJAn1bht2f8KNbxySeeqtemuBYP9
TyUjV/ygbPHApZV7+tC8RbPH4UP0UuRnBLH4LazTZHJbw+ESqQSJKuTNEOuhtJ4hb0hrhdYh
LUtpoXYYiNkiCvH4EEsJo5GaqDJCSQRuNyG4ye93hPcQhFF5k8MRM+0xGmOl8unaJv/CqT65
psgtiHE87ifOaz7FecUztTKNJlHNyRve+f6U43BnbCpGQF5z6bPz6q8eKK/f1JlaNTvSf3JP
x9MzL3MO9l215d47u7Y/3LV2ZdelZvK/IXgiEbc3rGntvL7fKxDF5lzesv7R5R7bq4M9N990
y0/nMHN3da29cskKcsmXu4iJCSKd/TUVpxeSPLiYwO8vRarvBXopeo935QLiYYSUIwgpRiKN
ah4Sp3qGJ2AEBzKMXqixaVFOMMTOggKziQvI87LnZd+FXMghl8ojl+8BCLjkz0WW5LwZ4zXz
uoMGicFoXTOzGDyVpAFdVu7WCGFTEyXR2hIV4COvqyLWDKQcetcgm3b9/4ne/efRW/jQ96O3
5cXl34Heq7PH0ZxMoncXa/1e9LL/euQa/lWo3fs/Qi0M/q9QiyKURy1hIgqRAlnHOgR8CyGX
yW1yKIRyudjCR03JQVbF5wtNBnTU4YxpGIhYnUMocLtqXFCuEKtuFFocCDSFDONxY++iWLN/
EnltlMgtZVedB/DkWirGAbecDRCOY/YYiOK2LI5kmDO/VArs8tI4asQB+MDtVEp442+T5XtL
Q0V6Qav4Y77SG8huzH4IruZRwuw2uDD7mVChcaZSd7XA9V/fJfeWvHBXusprEIdBFvVf75eP
76b2IG/zOUmYiWKiAmkVFhUkOZV0OFBLeoB16BjHAW9Ih3rWIVZHMWEYHmKUgDBa5DKVcSdq
Jyw7VaoqMbUzFqsKoCJTVTkFgWlYwEoleb5JOz//WuyvVjO55Mt1JwnPVJeCPgY53ZnvT3nw
grdSkvwbufKylS/s2Pr08vjCGeTyZSuf3/yb3y4ffyO8qrNpebx8Vf36K0TRdV3tq2LpNc2Z
3pSefFniu3/j5cf75923Yc4PulDfevu6ZXctPH7X2p8CYfe1Myq3zp2/rfL6rz+Yv3tW4/Vd
fbtbAu0rMVsVoyp7D4qUnqhhrXJkm4rRUJivjmYYDSFRqQU8QqAldkokuUr7duSk7KTsdf0I
lmm5VQldFcYCnmTXJGeRU5zFFdv3xGpnZfn4y30ZvclomV3qB7sSvC9jKYe2gK6sFHibamDa
6/IXNr7fdwzZVIQAuw7Z5CXms0GbWaEQ6HQaxqyBBs1B1kwJaFambKS9DOol7mBoPs+2W6Hw
6b0CgW4P6iSjk/wU4QgKiciT/ugURaG8THKARNxETnJTnp2QxdPYCWJ2WhZOF6plnfKvT/t/
dP2GaFlCFxpoear6iitemfPkM+rAjIXrnpn3c7EpEMz+MbTij/u31zSu6Am2rK/592eT0bsO
xuZ1L7lk82msH6sQIq9APoWIrWymwADkUCJ2ud0u6Bpi3ZTGjbjJQBgIS0BjgXrLEKtRUgEI
AgcpSsy43b4QoiQDs9vnMyh22+0R4x7DtzIScpI4T8fI2eB0VuI4OUdIOXD+c0Jq2/Cb3nXH
5meuWlyxbm5s6b/v7zo1e7Nz/cA1Ox46Nv+GJ+ZvXNe70USlnknE669d0Hl1X0mOijY8gqlo
ee+eXT8amsvM3dm1ZvOyFUgnNuJ74IiFDISDWPAEUTDxLBsQiBsLChih0ESboOkgq6BpxqBD
RxzOGGwMLJAJFTeabHaGoulCIx/jbIp0osFvEk5uFRBNLnLgO9gmlmObiWSxbPxVsulmdSpi
l84Qf8zdiF2JqOYGTDVXcPdc786xjD/84t25261g4hwmmVtw3V+DZnSCq/tXcnX/OELti2iG
DcSi3J0WhUat1k7Wfi2lJaQaDc4mYqdUajLmugXZSXk0yHU8F1Z/Iyua+rqWwuKAq61oDCvx
yTSDF0qDxyX2yt7WcfOaRRGtyWjb2F0MXk3wAJ0qd6lFZFMTLXdU1kO/11WTagValGrI6quR
1ae5XDvAWR39Z/mm1ysE35dz+Of35Z2RNeYvwRjMmoODU+dnvHcMMphS8Nf83Fp4MncP83+W
qs/8a1IVxWQvmtnfcLn6FBeTzEWpyiXw/5N8RTk6PWVxvKwSsds1NOieumhAr7EMDWqUgAoc
HKQwOvwRLmJJ7vtBfxJH7X+X6Hf8KxMdZXorynR7PtOHcnfVcbYH89nOp/8l+c6tFnAZb8yd
Xzd5fiFtOjg4eW50XqxPJnPIH0lyOzkwtP4ZUZBUpU/yvUSBd2B8N1HASZ5AWiRAVBE3coiK
c3qk3Oksh+VDrFPLOBGomCiMDrGMUuuH/iEtZbzJ40mILTcplWJqdyJRXbJb/J23EC/UHkZW
w53fWT406GSiQ4P4nEODHI/4q/xBv5ZjkYsVSl6g5BQKt8B8XqFMfysloY5ct2Hta3t2nF6T
7m8mf7fu5W17nx8YHH/IVDnQOHtdovqy5q07RJbqZU0dl1fUbJ7ZvLTKiDRK8dFNOY3SvX22
Q9Lz50sOLZx1YNWldwBe+fIZgeotHfO3pG/8+tPqdR2h2uvm9+1qKmlbgbl2K6wg3+DdAPjw
IOKrnxH84wT/HFEVw2MDaOwp3k1o7KeTY8zk2HoYIp/gxn42Oab8Mj+WQt/7gncNGrudGxOc
AIQefzF/Vj/5FvfNQ9yo6BESEAz+bm58a/b35BukI2fRRBkhZ4UEwQfb+DfzST4R7FmXOws6
6inSm7PtO49an/038gnuqJ+dPwqCbfBmSMKpo1LoXF+Q5py96CglKwIEwYBtzM0MyXCH5a95
knyLO9sh7jg1K8bPuOnANt3NOlKXOzCGeW7rxM+RD39DuXdvLkPlE39iEyJpI24MSAEtV2nV
KqgaYwvUVjUpgGo1o/XjNZixDL8Yi0Obms8j+MSoRJKvZ5PdLCcOq6bEId6UMnUXI5es+FIW
dCmeXCMn5eg6Y4PfuEoxOoM8mv+6X57s4fJ1+v6KKYWJah9dYJ/ZPf7C7LZCuVKp7q4rBL0B
ADv8LrUYsCwpUrv84KReE/DXPVawpgx7P4C8f4r8GPXED+S8t018zMYQf9hkRplASdNGt0aj
ZIxKqHzO6BfY0IjA/R5TTL+Dqp/mXa1WYBuVyVB3nGuMo3lml70ewYmZ9FednSx86OPcumbO
dXwdxzeugy7z3ODkVRj3e4MMdt+f5G7XTz/DVDnkf1tXne8zUSP5pdOlKSiok44/5tjQ1tPm
bm2s7NYumndrauYllXrvgg0/KJPzpRrX/3E37WmZt2BWUaathr2h0OpINHvCnQMr1nWgCK2f
uAXh8mPEW2McawUDNQThc6LKrrPpoATqdEaxyOF0OqBjjHVCpXPMG4KoqRpjoV9phJphNMcO
QUGjxjimDIj4TifBH/V4LIF3CUJbMGqxBHUoisGS72qvUVX8ltZanpxsKoPcljMHEagZvNgs
p2Ns0IlMGYR+zg4htkNpHBtUBrh6yfEgPtvkyfy5knm+Yk6x43dUzC13Xle/qTHcWTuwuWn/
qsw1iQXqmTXd8zZenu7dmmyur+jSkoU7a9wdlfGZKZNQtmZm/aWsTv0jNtU+c87cBhidVVpR
X1ONa2UKIfEL8i+oB7MTq3J1LCmRoTqGqqSBNkDDGKvAD+r9nH6IpgSQpgkr49Oiw49k9MW4
YJ4xWhn0sQGb+83GnMvB/M6wqaoZ5Wom/S3Fj7tvAHPFD4JlxRZJdgvYv0HscWoFVYL7pQ5P
9sxRQFCUYCLKqIpirXHSOP6VxGYfao37lPwAYDcV3xzO3oPXHAYm9iAm+piwoC4zRdzGYaiC
q0xlDkcZLBvjOnEEGiYEQ2MsE8Ad+ZjOT5iscpUJQSVmHVWpxNRoLJYOjIrF6fLzbfgUVDjx
/P110FE2NuhgQmOD+Apjgzr/P6uD0wuhSzW5+yXXqJ9/Q1aQM9vbfjzQs7vVWxsHrU2de+es
3plqyV7WOTtUWSid19I+R7igM1LtlvXM7OoG88XmVXWNa9JlKxujLTG92NpfW7s0luxN1/b+
pL3DWBw3zZjVmi3u6LEEy80dPV24ypBq8g16Ua7KkJfj+qWhJuseGnuKXpqrLbkx4+TYepIh
n+DGfjY5BifHUuh7X9Dzc3UEjeG6h/TRZN0jIfkW981D3ChX93RUru4hTuiBFVQHbwsRIa5g
xSEtcVgdDgcO60tKhkGUtYrshYedToH4sFYvOoeoQSQLaRxas1CjRRUtTA+DYlai9cpkpd6g
MxAw3+0Nvo9aB+6mniL5djQSjAZHOaZLKvBeZQKx/9lINHg2Ins3OHoWDZ4N4hsHF+7jyAk1
J8T7Pi668WVXgijVUWSWiM2+7G99JjGPFmQ/7MoyNE9s8mX/4TNK0E8g+TugzvHaBQpnePyL
oFPF3eV0hv/Uc8Q7Pkx2pJ9ueD3oVAoDAaG8MEQy3O/jL5BlKCKD8C5wnIf/K9oxDuESSJJg
hKI+BYBHwuAoavDeRw1RBFtufBwNUmBkkMKNDvoI408NPUpw/JPOXTxbcvyXenIJjvN64n5e
NRxD3aKVFfN5PJp5hiAhmsRh+B5RFUFflZ2NcOcEdiUfxIAW2nnVX8n/Up7dBG4s/wv1EcnP
/jEBtrBgSyL7JjrjL8BLYD/5HCEixCcIHhQER4ngKPo6tyCV23wL7NHq6ih6kc9l4vEMfmF+
ShIETdKdSCd4CB0r9rj26Q8boNG8T6LALF119mwEn4fbMkY57YlKmFByu5ASSm5ZS8HlC598
8rZf3tVRueHQT365JbtQ5HYbNJpjmmBUZDJ3HPrz3W3PPVscpTtLNp/64Q3/eOlAR1GYZwzV
DUBySUXQBcNf8eG6T4Doxy+/AnF8kE3U75BNxUQTWyxjUdmUyTTqfTcLgECgKWZNYJFkjWSb
BJokJomGJJl9/sPFULPPii3GBge5bqmHo/51ZxGd+LkbUiXQaYfIZtRuOrHUdUJ7vvmc5hX1
u7o+SmP1e7NPXvarhhb3gvmdKk/0he3AW15XUeHrn/v1jdO8ozuzo91z7aLxz2tbs9vbkwXj
v9LF+2dnD1/oX84negj5VEX4WHWqyJ047JHtCwbLPNAg4GkPM3pkfBTNeqQKEfxZ2QfoN2Q0
D98Q1fJzBtrhBW9zm8ESdj5qkaH9grdUh4QJxETZtTlTO8b/Olsk9KamPjgmkCDjwV6R224w
qTOkPnPBB8BZXmcKuKhwzguwPnt9pLrI76bDk24V9RixX2FG5e3sy74Iohd8kJ9D8iXkrwlp
VKFWdVgNBbzDTB5TF7k2zXZwwwW2c2H+DsMmw3v+qismPoK74BnUj5lZaYGUkBIiar9BJrpN
oeGwwQED5xW3l4bk9pLEE1peLkcUuDBo+eQnpDroX3rnsvb2BTuaK3p/dem+W9uHXrx8x9ow
eWZGxnFn9g8/XDZQ11yxvO/+u1cB4td9lj+jTNo98TFZS2dQbbQQNhYBVi1Q3K7XQFIsExwR
FuDrvz6KTeAM4DsTMOc1AiDvG4YkyFjJwyX7tP4q0eflezUGkyVTmVx85YzqNhOd+fWvx3uX
RAI2MiYY37o44i0M15Vd0ryoecZGHAHdxMfUNjiKarKP1aTUhU6n7XaPRhG9TY13/Mrp28Uy
PAeIXXIzgX4ia+J53ePJr7rwtZO/XGxbIj65p4IPnUCOrLPWpZMLr2ytatKJFz/c27PEXG3M
mdy1vaO6zV6sKygp9fWvrlEv+gV5ZV+ptzBaW9Y3a3ZtrJrauWPVoqoN2S9XBzg/Fnb2NFZv
/UXvfFNdRe0N23qyM7FPETSra9GslhAuVqHV+hxCoZEgjHC/T2bcr5yc2SDeZybH92XAtK0E
U0sjiembCaZ2uvLJT0WLls1crJ/RXjWjWLXoruWzf7441EYtWb1olSXT3NZd3Hn7ip4DMwLk
6XkLZ9UUJmpC7qrKuvC8bZV6y3/0Le5sC1SnA8EZ81IzN7Ea42+RtRwO4AjhJByIuiCBgKD4
g3GYEpxgBBgGryEQRORREIwihubStoTMoWAq1FLodHA2Jj4Ti4T6IguGgUhkMDka48lgS22t
1xkrVEql5KFYo15rkfM5LISaDd7CVLosnPEpjCUVzsL+Cszweyf+TinoAqIAWaQ+bj3FDMMP
jqtPoWLzIRc5pBUdpJzbXIFYXkbmVgcmNxhKSbL+rd/XXnF4YNPRVZEPsklzxUI2Pb/cYk8v
KK/vTWjVoAY03PflPbPm3fPhrdkT2fvIO/f/YXdN5bWnbxx66+ZM003/hmLyOGJ0Ps0QRYTh
EYvdbnQNw7OPSIRzxBaOEKJRbgsI7v8mVz8T57tANGFYwUqxXqIEBUKxt7K74uu/lneknBKp
Ssy3mKxX9ks04h98tqWCxDsTrAGrhhFLBDTo7iZpgYgRqG0lDnLUY2OrtCW6zA21ie4OL0YW
/r8Q/A3FJkrYHrWazYZTDhwcJMKH4X8/LOSMC+JXZPKeAmoeJq3jwsP7xkNVNJ98PVjmMsh7
aAH99cM6tn1ZZe/GjN4cnx3v2eq8dvvvupbfsrBIZCy269sXLV/cYbiLrwv7G/Y2lMZXDK6v
7N2xfG4k2pV2LO17LhYKtq+t9tRW17hsc/qWL+vzIot/hnIBWxxH+S2U+vx+ymJyntKjyXwU
2XEKUMgBrpJgu/FujNHk9BuVyEZuuXBy+7cFnm9+YJ4E7t/4cl/7rmXJwpbVDbUbuiPpzQ9t
7Hm262pZcXlr+OodD94/d8WBZZHLBhdcZYd/GYlEHXWXZNjF7dUWsTg2ayXbfuOSMpfl95GG
gOqqLTtu7KPDbcvL+9YsGUBYnIVwUEsDwoFy2ccq9IVqtVDgkxY4CgulthGHRYpwQVRVneU0
oyI5Go0GZaN4yZ/GzUycSES5va/cPExfzUMfOXkknxRZfCYJH4yP7gfu/XcoiqJWtbgTlcd/
0PpwcbY9ew5sJyFFivp+1Z9mJHKtM+a5duZL4MBLX7/D6AOFicGya1NsoUKcBu+ediy5pMe2
K/vhTnwPeuJ9yoqi7iISRAuRYJW8mhpnqEwmc+sJdYPfL4qdsmDkVJwSTaYVF/okCI5i2Tsa
xW4AlYbrPHHwcXojq2OoH3HnUw/3I9NTL78wdz4TYSnYuKHmBw+sXnZkU7U93R1fu4Ksv+re
nsuPro6tHX/cXNnL1vUkDa7qBYnNW2W22oGaukUVpsLavlRmgDWTh6AQ+g6tmH3jQCy0cMfs
dE9zyigJ7b+kZcvccKhzY+OyvR+kemod7prucHphtfWq8WDl0kZPUX1vtPqSOrerdhHOmKMT
H9FF1N1IadpYCSFApCWWkAQU8GkieDL6Jr5HAFCFG8UlXu6U22N2RMp2NUwdysrBR4fAR2B8
/FNSeoCUjn96AJ8PjNNF5K0oxszDEHCqVRmzq49S28H4gQOYv44CJ10E13D7j8QnSIJHEcE3
X88fB3LHfrWd2k6+fuBAthV/h8tr3lGkPuqJJGvmqVRms8VSlCAqRsw1ejsVrq90B6WiyIgk
bJtSXQotakfQdCFqRqoez9b05wAxGeVB5nSTHqeFvnCMexhQo9DGFQk772ig1MDnGUpLsqFQ
qY4mKR4lW/3qyuuWPLdETlIUhIDWR4PZ5aGYjqJ1pSFwa+9w7/Izy8FVtLJAZmWrvj5azjpV
EpaVKpxsGqxvHNp5qemzrPnzc+C9L3TN85deMuDP3l5ehWoAyxYonVXlsDtdaVfIaj7Kej/8
EPz+IxS3ayY+pO6mHyRCRDUx42G5eJhSPaJniHBymNKyAre+OgTt8VP+YYr3mPwztTr9jB3V
qOPMiOBJSoZkE0NU/ReCMWpFEJa1CMioPYtGOelWirfjeWKu/CN+OBcRQbsdHiTf8sDGgMaP
+pFTO3bJGJyL+iOBMRoAklqgLSuruZptwtHgw3hna3t4/k390eZrHr7EVZUsM5uSc8tv3Lt5
S3qg3kOh0qzVOI0o6aRfLalsKFKJ6yAFfR0+kkzUugtg7TW/uurqkesztFghzt47d12N/pXn
To8U13X5MRY6Eefcj+JQT7Q/Fiwq1KlFBArFicrakQz2tI5iWE3ZSMIWG4nbgmorRUnNI1ab
TDIiHab4Ob3K0dEozmoUExSJCPcPt083nkDcVMo9fgH5nOBAmCiNczsW8R/nBU+NcW2rKwru
1anMMmEwVRm1d4I/xi6/YnOy9bYZen8gYsseBiSPp/AmWxNqo9aoKaF1IX+2IRjVQl15ORA2
kS0QkqZAojyprRSzLNO0/PJo79P9toBdzbAyvVolMle0LavTmyQQ/HeadSoQRqSqwqoUnNXe
nzQJaqQ4q/qzc6jtcJzwE2mi7QmikNIcL/WnUWAek/r19vCpIgyGxDjCBO+4ckyFI6VGvzIj
/GH4yXF6hId+EPmI5OgOQyQSxHLim4mBV3H5mgi3OVeRoz+PXDW5yT23O/d+Wh8PZ1P+sJ6P
sBEHsBkyENIk299e73n0udor7lt+YNBcuaj62ms3bYn0zyh5oLzKoZDW1EgUDrYcXpVsDhkF
GZF/NgJFZZNLmP3iqx+OXF0ZBAvnb6jVnzl9+qSnqs2D8bAK1fw9yPMAUXNCJBZrMRhcvjGU
CLLjhLkYOcwWWEcsNtOI2UaIgVgsZ9Bn3PPWPZzDimQOBByloynHbuHt+TD/YNtF3oNjCK6h
WbPnJSrLtot01iKTuYn1iyylvmyFJ4gdTsQBrwFWk4AsbS5Ri78wFRklLnZOMHt1Va2jAM2y
VGZnK8ADdXMTZuQl8mLzxIdwBfIiRTSdMBmNApzdIQIAJfqFFRcWSaUxHQC8U6kYMv5Rk8l6
yqBDU5qXBvgv7rkM5AcqTcGzOcZz5nfYczosP1HnHxFDzpTQU8kNF60vKIo3lHQtkYZ629sv
a3Yklt/ae+K+dZbLlvqb4lah2q6Nr17SXe2qvPTWuc7aps4Yec5X4VE21pqKAxG7LZ2Zk2hb
11IYfndRp8Kd8upcNrPUGg6GKtpKmwbrnVAgFeH5um7ibbqfepLgoZ5OTFNvIPTziDcAIAl9
MKqTYS0tw7SkjQEQA+rrKMtXf6betD4AngDPPzD+n3ipi6hB3XcxLUfdaAipchExYrI53jTa
Am+iHBcfF49I0I8cmjlBfEF/Hcl1ESSPctpdEQ61iZxqx2Kp1eqxGuR3C4UlFQVgd//NpQ0b
u0KXvpr9zelsN4hRJodTdPc7s2bNiA7s63HGNBW0xN81k/xDcUZX7AJVCoVqxrrbek9kf//a
ppUAgKWr1ny2Z+HegShJIs+R1dRXyOoQ0ckGiJGQLRDwvhkssFltpM3melNLmGVm0mwu0Fq1
VdqZWkqrlQRtMpn6Iq/QjP9f9r4Evq3qyvvet2iXLMuL5E1+3pfIe2LHu5zYiePEeMHOBiGW
bdkWkSVFku04hGBCQl0aaOhACV1pWigU0oaE0NDOBIMJ0EIKM2xhaEooDJAJoTC0mRBiec69
70mWkwD5pp1v+E2tE/mdd99995zzP+fcTU8KfS63YB0gJf65yMzQ/gjdEiEnM/sjzcnZyXGS
keyTSzbwqoTCnMC9jiOZJdkp0b1rurDcmJ3y8jAuKV9aWWEZXHu+t5qPmLeyOWRo4NmKlsKY
QKHGXJIduHF+ZSI/dc4wv+uKwL2infwTYOdS1LZ/0ZE6onztESs5FB4pgINVG3MyojS5lCkt
Tc47kk9K9ClHBMEM/bT6iEqAMUsIeY/21utCriSjuLjPQD5R4ctSQucX76HQGXBwC+VGTs4x
BZW6wGp1cqZKGWOKj4vXTJ3Qpppj8mv0gavUouOVauL4+9SpOUkmQy0jaJPiI0nJvaQkNhIb
TVkpCbrcNK66WqbXKsta+9z+ssrt24bnZWdAmYRSdlMsQalKocvtaAmcXDDi702hBaqIee3N
SMSIeRMwSkap+01HjAScmCOxcPil8ohCkB2RC2Hxiz9no4iX4x+olEWVM+qLcXuf2pQSFxlp
0GBjUXUCVXa2+6pkSn1iwZISkktjMK94nfafi1H2ASHhcDb0K48iAz//magIMlzUHOZpT3Ma
uhkYFuh2TwZZ0mZC58GRVXeZMbjYhfiCHlS6KKkK3SgnrYRLS5lASdc1XfNHtuUsH9iyc3nL
aLGt7S6tKjnJkJZTlKxP1Re3NzdlN7bqSnT65W2VfR11ecbq+tTatNVbzi7trTM/+GPbge/f
eHVJhtAQM7Vx4bLEzFSduSAlMkVfsqwgZl1bXg6ur+nNa22Yv3Z4+zesTocpvuFpsNIPVjbB
DDINVlpZ+4V3YSDU/zI1E8lyn4nWkbGx+LCMDguilTAK0m9qsNLTr2R1JaNL19AKP6Nkxmhp
2MOv6krWrVldMDy2ZvdvPI2bK+LmGw3Zho/Uao25ODMCRzW+pIhe1tZ+S8/C6sV5TscaNl5e
taY88aF7d01PuJNSdakRvFLGFRZbTVGJkQpcrzm/pnQgr22x42cvOzdcW+l/kPzgNYwUp8Ff
2SjlICTaM1npZEQwRkdH/DFe9BP0oHREIPtibFYQfdE10q6P6Dc5W4u1SQWppT2dS4oTOjoK
Wle0FUWlRTmPbfnuvbktrvEfrFp2/eKFzHvzG7IjcWGnd/s3l17rjsyuK4zOivYMHrz/ml98
Z+tVxfrIvwDC901/yNzB3wzz+lyUsz/r3exfwxwjB7q8yP0MA9MP2YEI1eEYScPakoLTeoox
2TibCZ7QVkkNV1Y6H1ZTBGfGVfR0QY5OnZxsSM8pMtfP71yxLCez2mLSx5mTjDzDlNRpcGoR
f/Nrr332UuUSKSQWLViWH51YVJ+T0u3busVXoIiQZaUzMNiCrnGBjewo1TUVoiH5XYHomiLp
SudI+pMwBOtoOIRrSiM7q0wcQstKDVIXA7EwWvSbor64Fu/u7vjCqDhNdnxRc3VRTJo1x6Rm
FiyOwJoGot+5u70/HijieQfPxtePrNuDEye8NfGKtBSGzgJIlN5Nd5XLHklNyD28gGwzJcUf
SYCpq1VZ26HXa7H6XZj66w9oM7EZltZ/OU12xU9L01q6Lx4eocEvnpWlGIPz2XCcYUabhve4
Jv5Do9KaizNIhO5LzFy9qrU6XcjV4IG4Wr/bXWEqjtPEmBKjdeaMAnN9Qduy+rTa5tI8s1wb
bTbiMwEVV7ygOhSxZ4QSa11FtMnMW2tKr+5st6z4fnNOZYZBFZ+XWle4JC+mdui+PlNSBEee
Hp3+kNdCLC9HeQettbUVhxsA+1+WmGNjYvSHyR7b/nmHWSktaVjTv2SDU3qajLsocEpDP5DD
ySUs6N5mVvCrZHKGt/2T/VqHIVFINCQmR2VkF5obitqbV8xLh5CCXjMZht355oYlixfOU3me
+rZWU2nIyIE6xVcub8ppapMrmT/v2O7tT3Zt+7q/XSUFW3FjgTGxaHF29gZr3Yi9Jb6mIrls
eee6/ICK2Tm/PX5ZhDk/uQ66qFhbS7QlmowARZDHPwbbFyCLVZ2l1RYZYSL7zPyi0PzOeIn5
nbQZCvPS8Eld2G4o9Wnwq1VyNl5t68tZUpyoy1lebe0sjq4YuLXj6v0981fxGzy9Pl3O0vLK
zrL4Bd23rLT9uLmQ+WDtytisUiGpML9YSLMuWp6/dOMVuaakd9atW9mcVpJfJKRYFzXm1G64
wmIy/hFsoDnPfoIyUdKBtHfTM4nuGrVadjhypid6JTSAfX6G4+u/NLvxmsvIbIwOQRLP446i
eJTzGLCmR7Uwg4+WA5ZFv1Sckgv8KZk0stKvMWOywMEXP6iC6YMqn8QW+reen9y8cUFcUoJ5
rHcBnl7EcJirLU2OZNatY/XJpbXMXelCXa0dK2P2kOcwdpFfpuJeBUQWPoYEzmDVyfT6bGNs
bNRxTbrCBDFdFNyPVAjifmQJDKpwxLAmLSg/Pftp5897ZoR5u6RUiI21x5y/v/hnG8e9ZR7H
VTekfGPbG52+u9amV2z/2cH2e1UxQmng3bINL7i2bR+p6vF2XXNkQV5xq7O88brbv/OTTQSt
+6dPs5+CtnloxT8iOWdAWSgCdI42ZwEVIHXKcZg1RplMCcdjYSGihPEm9ziGhCyaHZcFp8uJ
9uUFBfrT+tN0f/Lyn8149NSTfXsdS7d03/7za//1u72HW3eY/V03bNv7s9Vff+xKZ/+a61PZ
vb/pKtu0tsXfmaMz7vH33XNNmvnVazr8/uvG+vnlwyvW9HWtJ7062RlYyT1Nn82wPhylIkun
eC4xMU0WEaFSGfiT8uT4eCU6EicYj5gEJTVDmmCWgyVkn4g6ge6KXOppw/AHLjCjqrNETT3H
tDxgKC9J1azTfRZTXB6oPoOHZbw2sHOR2lx5haeFjZrSRhUUvuVpqUlQLcIv/dz6z0sDMvLE
xa7pf+MKAXvxiYv2xxAHa/YFCxIPcbGPZGVVRecBs1+jSYYDrPeRvnAhXng8NVWRe9xEgqjw
uCJsa/L0Rrpeh5UTdUcJDev/7sMSbAPjH/K+vmv8+Y2V3S2MZ8OWlzb/8LedrqlfbxldctX8
mG2DQ9dF7NiybP1C47hv6w3MDkPO9+2OPavbv+tYPnhFuiHvtu7uf2i+8pZV3V//w9BIlrUl
xz3smerY9LV5DSvnjYxfL+47vsG3cYeQGkUdVMplDOLoh+UlTx8/WnLBVuPqRwNy/Omj+FP8
ydT7jGkvY5p6fy9tA3/CtzH3AJbqhxnxw/bQduP9+JO9e+HKAziCv5a9ie42KkCWnFcwCJA7
hWpfPaoP33aMgps+W83dH8e8undvoHzvXlwBMu5GSG6EEbkYLbFmxxYaWS4xh4s0RReyajRZ
nJk3mZ+ZPplmTplMNcfGaibVZuUk/ZyhFnwQWsCQ7bajBUcN9MsmF/6wRfjPkV3ihzDkxvqC
2OjChoC+IT9aqYwI1Nwa6NIpldH5DYEV9Xkx0fn1sDK+ET+I7+bVEUkVrecfbK4QIpqaCI/d
d2PDovN17Avdgd8OBX7UXJGsb2rSJ1a2sJ2UP381+xPInLunT3Hn+Qn6CwFLH9YrDnGG/Sgl
9xAX92hciT4m62TSIc68P286BkJuv6YjgozM3HM82UWScSok7RkFd40ggUqC3//PkL7/z1/0
/f/I2d//Z+9S5V+DU5oV+asCp1rV6vbBweobHu26+dSdLa5KQ3plU+ltu7fusKzomB/NrR9u
LdGuiPiss9lqiWhW/5RvaUgd/fCnD5/dHGsK7GlaU5kf9drkC88aF1YvTCWfIkO/QKwrQQ20
Tz5gKXyuiOhezKmsxqzJTCF9MkMwP2OIQ0hjnIwT1LpJmGMlh20Wnp7ZLLz46/zir7mQz6Av
/hkXGNteic0ps66viMvLx1PVGysDuDS1pLEo8LvAvcbk5JT0aMuiQPoiS7Qq/2qc1MKs12df
aS0zxWeyTU2yxgXvBG6YV5ihasITSXGqadRcmUxdCw5c728nIJC1TWAVd4xLpN/p73wMmbm4
A/NiECwLDDD6oYTsk6nEbfnTCcSJkc8ZiOlRnNmq4SdlMsWkIC+UM3K6/7eO9ByzdwDpFmDG
Rc/qZEhfzjeIPQx7wZfz/zWmeEkgjliVtwob23XKpR2rm/MOv3LTm7f+YGPpplXjt1x3U8n6
9dnxR8AiLQ3WK9g7mxrzI5q1e7n6qpzIwAdT/3jGhXdfd13pvzx79LfJLYvobt8YdJ3E1gxU
/jAygIkHzKnPpRGL0sEiXdykSUB87KRRUCo1sGw1030+Ykxorzf0DfzIi367Ksxpx1QtG/xL
66y3GaqrkxvXGuMXVgaSqnNilPPAnlZ2Hd/RlKkLnC9fmN5RnR8YaK9JVBErapbh/2iz5kY0
a0DXW6dPsQ+Drnmo0hoFU1p5BkYoIlEt5Bow5k5CepkfiY2NO2kQO3Lxo8lIivvRYn3oU6bL
/iY9+5Prkwbta/ry1rp8NzUf/5cDT46ZRwZsG/OuGqrZuGpBw6Yfrmq808OqWjuX1WdVl1ry
21zNu39Y8vH6Ne1NlpqyovjypjXlbe5GIcJI9+n28TbuT0iGEqwqnqPbdKFdOvKxiv5o2C4d
e/a8gjve+jh+A793eGrfA2Q8Xk73gcizSNko9RE0GS+YD7Fn98cJmXA4qM1UT2oyZ+3SMeKT
I3SXzsyF9uhmhib51fPzU+IeiIoqLY7EEzsOf2OgvWDs48CTHwdycZ+8O+KRMz9vefOZ7uQm
RXqbkzm/xpKcFo2b4itXDH9/zZHAC++4trK9vw9869evciSWiH43g37zkHV/dnY6KHVgXlIS
JMtZq9YYH280atHkPCEiIvoCdcWAKigpIBtverrQnqX7pR9NIpMINoUa8LPo6NIiPVfZsoWJ
SMq3BEY3/KF5ae7wOl90bv7HQ7izfWV7+U3dn30824zAzwvXLTQE5pWuCnQvLY+d+jjH4Qx8
TbRD1gV2VKJFVmXZu6WZ8ycXZEYQMxIsFmPWu5kwRGVkktSgiTGpEGST8vAdNnEKcdFeEzP7
GaUwC+XkYZGUWae8VqUqbdAHkiKJhcun9raEn0suO6EvyU811jIdi8LPcWZeldmSjZuovXhV
4HvzqpND5yH7GxUZnf2Bd3BW+LnkRzYX7E9ASVa98d3YzOjJmMyLzLzQtHDl8Wufq+xs5WYr
A7LvgJGzBHI8ke7GsCcT4g5xpQd1Wq1qKlJK65ndGPFR1AsewKF9EcuO1jRs+MXQqpXr7hxq
8X6w4ye/WHLfx7f89PZK5jPblfcEXvu6e2iZe+3w8OEH+j9762sp0yS//mn6FPMivx/mNsko
a3/ic0lkX8DMYjNRQavRKKf1MyrAbGfWfsusZ4CCe4oZJczu4jdKTBGaRTkdlcsd3+ts709u
1ipqFkXg+A5+/zvvfPbLhkVJS621yxxdGzvbduHOiipjuplt1pJnxKZP8cOARRkqPliQnz9v
uhgUsaoQm2E2REbqxNlD8jSsH0pDC3rSMc9a0ssv1q4suIYn63nChj3YxCxe/6TD70lsiFEt
yrmycgVReSCzKK2nxuex6hyvfy++DiyB4pWta+Ssadu2IVf5dYF31pTGBI24esdj25o3Nt+4
ZVlAwXzHU7bUWtPosA2sSk8UV+mn2CfApmyySjerVBmRxMtZGQTimBjTySjRy5dcpYt9dnAS
HvbEUmgiDiv0IlVvf7srpb15vLv/kH/iyZL1vMftGF7mu85jOzB8+DvFrGxNe6c1p9KavWTs
6vXfvmL+B6uvXtW0pL160TdaOm5tz38ftKSRwEVBBiTuN8UlEOWUCgU/rZnx/ytHpQT4HMfj
+y7tdOz4PIeD3Dunn+Ht3PMwi49+VCFTHWaxNA0vmaI/dRM+ja+/bepNJuU2JoWRT00w1h2M
dWpiB2kD+g47sxOiWLOfOSzef1qclt/JvcjId+wgq6U7cRn/TfYqaR6fZ9XLD+/i8Qv8m/yf
eHYfj/lD7JkDCrj/V+wZpCDT+zOn9WfWrdt4OmyGD+19Vsi9mMu8umNHwLZjBzZQG37PO7hH
YZwrIWuwjAMw0qFDXIY1CuM3ZKdkn8lY2cv8O/yfeZano986IFPB6Ui6yJLGvzu5ms+e5F5O
/zZ+Db/27anXdxJ04s/dp3xf+QGKRmnWiMhIbTSDsUalU8vlMGcmP/ZcTBbNkSVHi2nvgGMw
jBJRZOUPbabQ6Ql+iXvg3FnZM77NljtKztj50XP7lO7txp23KR2fPjT6qWUPjptK65FvkMet
n9r3ylnSK/hQreI814YiUAx5pkPLMOhwjOGwglepFKig5HoyfE+9erp4C31uMasMxJLtQfpc
spw1ppRlpci999ThkwFj3Y/Off1HdQEjPll3z+sbZfVe36ePs1c9XhYwWgPGsieeKMMnrfhk
2eOB0zt33kbjAR1kVnHpiEMRBzBimUNcKuQGfXgEpEQxqwIHhia49CvOv5nGrqDfwz3IHOVe
+tz6RwPeW9/lXlp/vi6H/QvUfyRQxVr4e5EWRR5EcrWK5cCighJMP+3UG4zydBSpRxlGGYNt
b71nCrwReBaX4/SEf38LnwvsCVQ0NzfjKXwtduBpYAN1ROfMQBXzA6lNObqwTSarjCNt8lml
BvzxiVMJOB2XB54NvGF6D9rE7fhx0hAO3BX4doAlzT9N2jxw7j7VjdTzcVaVVh+l4NVyFvGo
4PjTJcTn9Ne8ya4OJAb4HeYKhtiSFPAA84Pbdhq3K93n9vGjZ+wld1g2+2TPnDvLPaB0nH2F
aV1/9r2zd/YwxwPv7ZG9PCrrEH+6fPiLCZv+jmhfODEjQWLNQA9ww38n9Hw48T1AfyAkawR6
Wd70f5x+E06K1hC9rXhbWa988itI5wipEiRqm6M5+orSdX8VPakuVj+jfkGi1whpUjS3a1O1
d4uky6e0SffHCHvEcxK9REifrz8UuTbyTZEMN1L6puH7hgcNv5LotxfQccNHUWyUUSLLBfRg
dFX0RzFXSzT1t6JYdWxcbFZsqURLvpBemKM5+krQuf+/ZEybozn6G5N1jv5qusX4Z0Imp+mn
l0n/NkNx2SH6VohOztEczdEczdEczdH/FsUX/dXki388wZQwkvCSSImrgcYSb0988MsoKe9L
6eFwMleF6DHzY8mJybd/RejAbBJ0wjZCKdEpay6Dnk8tSr0+jF5KS067i1B6TIhGviI0QSgD
ZazKOJwZI9EdQI9mPpv5/pdR1lVfSr8Np+yKEO3L3pcjy7F/RejmC+jV3ApKv8o9e3k0rzSM
tobo/SBZKr8iNPI3obstD4XR6yLlyf5uqe7/MN0wR3M0R3M0R3M0R/+jdFfeL75i9Ho+O0dz
NEdzNEdzNEdzNEdzNEdzNEdzNEdzNEdz9D9M5XM0R3M0R/9bRL9/W8BUiF/ERVp2HAVfOuSk
Zyw962X/LPHkv+hySTyDdNzNEs+ifG61xHNhdXjg75B4GYrlHpJ4ORrmnpR4BcrlGIlXoiX8
Qokn/7fqVolXo5WaoD4alK35g8QHdWZDOmPJgmKtTOIx0mgXSzyD5NoWiWeRUbtQ4rmwOjzw
KyVehtTabomXo0rtoMQrUIxWK/FKlKa9X+JV7A7tcxKvRvMiWyVeg6Ijr5N4LX4q8psSr0Ol
UVeCJphTSjiLvIizyIs4i7yIs8hzYXVEnEVexFnkRZxFXsRZ5EWcRV7EWeRFnEVexFnktVI0
EF7EuRk5UA/yIjfywbsP+ZEA3BDyADnhmh31QkkfXHPBtXzg1wA/BMdBZEOjcByC+nY4+tEA
1PeF1SZlbvhL2rdDbT/8tcB5L61H2ictkBIb1CdyPFDTId3bI7Vil85ttG0PnHtBtgPK/JJ2
3VQPIp/o4aQWkbuCeol3kLvdwF1Y0heywRI6D7Z1KXQ89LwX7umBcwvFi7Q3LMm1hORcaAGx
TEAjFKce+HtpzEYkS0ntHrBmCGQROy+FPbnHSblsqJ8DRztc65ZwuVTrog7/XWxnWu+lLfVD
GfGtD2p4qVV++Oum2F9sQVD6xXpVhsUAsUS0xU/leSiaNtq+aGsvlIxQy91Q/nmWirFnmxVV
duoXt/RXtErkh+DMQ/8KVNugN4PtkJpOqPFFMUo8VAfc6AWtBzPEIaFM4ofo202RFn07QDH3
oApUADRCKZ/6Ynb85VOZg1DHD3IINv0UHQ+0MAqlQft9wBM7+uDaEGhO7rTRrNuEHgAtilEh
KkJlnxPjiylGQeSDPhXtcwIJFIN+qrUvFANiFoj2XNxqBW3XRiOI3G2jsm0Up3a4q5/qSfy8
krbkk6QKqBTaKweafXfw3gvbFFG2Uc95aXzYab540YbLyu9+ej5EfS3WFhH30Ah1UEuJfUQ3
t+QF0tYyKqU/lBfBeO6AEi+NoQ6p7gjFdQO0c6HuA1ImkhyzU9t7qTyCtSusL/ZKuZ8H18Te
Vawt9rO9F+kgxjDJFzdFoZ9yvVJvJN4bniW99F5xLCBWiT4nemyW7Cf2+sM0HqY+G6V9xLDU
oo9i1nORNmIGiNE101+QNuspDv20xEZlBu8R2/dTf4lXiGSCrJO2b5e8LtYWY9EBWImlXuoh
L81hMZ6HKT9K6/qpPkRHS6h/dtI7BqiOxGoxq2wSDpdqPRypoB6OUO8w4wWxTxNxE/Gc0WGD
1Mu6Qj4Us8sW1pv46b0u6a6gJLfUd4n1BqmOTmqliGxHqIcM+pn4xSPZKV4ZpHlAWhEjW+wB
bRCNwVouNJM7DgkPUssXiiRvaC5glyJuhJb2UHvtNJsGKGY2OlqImR6O4hDII6Nr+Ijho3nm
DOuPuylvC7PZQdHplkaj4Jhmp3cNSj30zIgv5mAvZJBDytsgUqtCGXHpnkXszcMzsYf2v+Ej
XzB3gvlCpA5L/iM9r0CjX4wOSxheMxHjBc0uRurinPLRGCU9Z28IFR/1itg7izHupRoPUX+G
az6DltiDiyPFTMTYL+iBRAxcKIvecy3Fwo9mx/mFEobo3WKG+pA4evdA6YxPKsKkeWeNBAKN
nqAtl+of7TCezZY8QiNzQBoDxHb6JVzstBUxAgalrArvNXpo/+6SRn4fYEf874ZWZmOyVOpz
N4TdvRhqi3MUMScurzcfkjQX48hJMzCYB57QvHJmLBR1t0m+CMaKK2yUFvsoP83cwdAdBCeP
1If6Qv2cOENyUF/M9FBBnMQRyUF97Jbmd2LrLjqKhfdANppNwXwdlCLJERqhHDRDhLDxMhyL
v938h2TKzBzo0q3OXJdae0AoLiwqE5odPV63z93nFxa7vR631+Z3uF35Qp3TKXgd/QN+n+C1
++zeYXtvfqhqhbDYNtjtddiEZpt/oN3eP+S0eVfavT64VSjNLy+XLpOrwZoOn2AT/F5br33Q
5t0guPsE/4A9THq/1z3kIcU97kGPzeWw+/Kb3S63f9RjF5YN2vodrn7B5uoVOhxet9ABpSNu
7wZfsPUBm0/otttdQq/d5+h32XuFPrdXcLvyfD1eUuy123qDLfjdgtPt3iD0u929wsgAXPV4
HS4/3GPzC75BG1juc2wG+cIyP2142O4dFezDUNHnsfUEm/F43QAXQQtq1jts/W6XzUmvQH2/
owdOBmwOr9PhsvtoMaDo6APWawd1nIDzsN05Kvj8Xrer3wKKOJx2YcDtdWx2u/xwc1h1USnS
BtFTNME+6AHdQE/awga7AOWgGrgLQLd7AV0b6OsnN7mH/ATsQZ/dOUzM6hgAZxCbexwekAkn
g26fXwCwHT12WzcpclHvOEAPR4+PgARakBKne8Tu7bH57ELPgM1r6/GD00UVh7p7h+xEQRA6
Ck2Ait12gijc5vACDxIAS7vTPmh3QVSBp8GDvXkO8C1RahVxRFiwDPkkJ/bYPBRk6h3iF8EN
AEPwCh43wGGhelFgvHkhpUKe8g24h5y9RBWfk4QzIO619w71SI1TtSDAh5x+CoxdCiDQwJXl
F64dgssi5sEbhnzEoT6h190zRC2poLd5xSQQRuxEykw82jdJN484/AOQAVCnH3Sx+wkAgzZS
RkKjx2F39UD56GC32ylpshQidwO9vHjU63CCJy4R5kPQOGDkdPuIDzyQqA6ahdA6+J+i4qIp
DRHlt9sGyQX7Jqjn95GYcws2x6CdBhTRCRLJ4fNDDJLoddlHxACyealfBwEkB0kohwe8SvJS
1CJ/wO/3VBQUjIyM5A8G8zkf0rgAKrn7vTbPwGhBj78PwtoXVpWek2ozfQAY4HE6KNIuf76w
xj0EEI2SUAAnQ0yQYqIq5LTNb7cIvQ6fx2kbtUj5CNZC70G8RUMNjBx0+Eled4+KwQvh7SJt
wQWIIm+Q6SMSLBd3SZDhECkQYaT/g3st5J6gAAAEUrZnIEyzERAKSeUcAn/PaO92QcxlO3Ig
Y7sJ0qHq0MIXaUur004L4tMPLhGzIChAzFGprUqKQLYDpPihY4BeHAJmFGJ0xOV023pno2eT
+jsvMcdNOwvoITzQSfTaiZmkzoDd6ZmNKAwJrlGpOnEI7ULcA45uB+h8WSFAHV7Qa++zQSDl
23yeTcE9WjR9E4xMl3ox0k4mwtlw9NMd0S966Q2VGg2GOvh7l1tfqyX1Gf3l1o+IoPW3X259
vZ7WP3u59SMjSX3Webn1o6KgPhwR2dnlaH0O3kZELLoZxaBbURr6FipCd6BadCdqwm+hTvwO
WoffR71sKdrIwoyP9aOb2SH0D+wwuofdjPay16NfsVvRU+wN6HfaBnRMuwK9o21Fpw0V6FND
JVaCWnGzZeKkMJlGkJkBMktAZh3IXAEyV4HM9SCzD2T6QeYWkHkLyNwNMu8DmY+AzCdB5lGQ
eQxkvg0yz2lbMWuowBEgUwAZRbNlMleEyYwDmdkgswxkLgGZ7SDzGpDZDzJdIPN6kLkDZN4B
Mn8MMveDzCdA5osg8w2Q+S7I/Fi7AitAZgzItIDMWpDZPlsme88FMnNAZjnIbASZHSCzC2Q6
QKYHZN4AMsdB5l0g8z6QeRBkPgUyXwKZb4LMUyDzP0GmDmQmgMxikLkEZK6dLZM7FyYzAWRa
QGY1yLwCZF4FMgdA5kaQuQlkjoPM20Hmj0DmwyDzCZD5zyDzLZB5GmR+qm3APMgUQGYeyKwH
mWtApmu2TNlAmMxkkFkDMteBzC0g8xaQuRtk7gGZD4DMX4PMp0DmqyDzfZB5jt2M49jr8UJ2
K25gb8DtIHM9yNwMMr8GMveAzEMg83ckvxVKpFC9PdaDOoGWAdWht8eUMqSUmxSKTePj47ud
5Ew2YbU2tna1Nn4AZzL5sd76+vpNVusJGYdk/Isea5D17LIKu06wDGIYq3WMwXAcG1NgrGDH
yAuNjbEsVvL33HOPgscKuXBCIK+z9MQzrtAL1vHQiUehGPcoZEghV5iyG8fPKxKlK+Pwb9zD
k4asoNcJyk0I1rEQJ0zI5Viu1Ov1AXhzcswrAwgFaOGYR8NoPGNqDiv4QlCSvKzWQjWHFHCr
oCcvQZhQKrFS/QQAcyE0OBwaOQAFKqxo9LQ2fngBNDzgcWxAhAbLZDPQsBQazAAmSoyV3NiF
2Ch5ECJhI5ylZ4CHiE7ojMJDFSDw3BJQKBKlaxJAMharKUCgAGHBOIBIYq3URPC9Aok0PRbk
OAWWqaZhWJArsFw15tFhnWdMw4FqQbgIXhoOKUN4EcBUKqzSvDVhG2untIKSdeytCZUcqxQa
jtuyHV47h1VypFJQzFo9jfUfwqlc8fvuRfDaAprKeSSXUdSA57AcYBvr0u86wYm4hYBTYayS
gJOQU8kAORXPqBRC1z0SdCoZiN60neMIdtvPh043cRy3fRNVDMCT0JOubt9O3ts3yXiskdGW
zoL/gN2lF1o/ouwJfZdef4JGyCXgU2KZenqMjA/TY7TOGOpCiWSwHWPh2IXGkI7DahmoFIJT
0NOiMesMoNYxlRqrtCdOdE20WdusTUD1QIDLCbUcq5WAKFdVD5quKCXnBFLrFfWNIqYQ58d6
AVIaiXIey+VBTAm/aXzMoxj/6GJMGRU/gylHNNoFLwKqcjaoSgnUehFUcqooVHDcuIeAqgwD
lZwurN9WD2/4A+K1crGls5SnSd8Y4j0kpgEzzSVwVWG5ZnqC4jqhVEGdMVhmaxA7hqzsmAb4
MRTBY7XcFMKVAGuK4JFaPgGwKsQXYDuhVmO1LojsbGw1cqyZwRbA1SigIAQuoAs1FCK6FF7r
CdotifhKJwBwl/4SCKsxow4hLEKskROI1TyjnoFYOKuWgYcLG0Mgh84JytvHPTQCFKYQzPRc
hDiIsy4MZ10YzrogzmoSXhwK0vSJGZ5grQ1hrcZKLcFah/AEEvCEjmKth/wIx5qCreeRJhxs
irZWh7X6E1WehZ6Fq+G1YveK3UtNS02LgKymE1VaJdaq5ZAfhGqhv50MUT+qHCOXVScgbQj1
053aAbQJOVEfVP2EXFaqP0Q+ZBsLUg/aKlX/CHpHrFR86O2ir49I763Y8vxTJzYl7nz+LM8i
hoNicA+DGW5iQstgLT8hvoiDJiY4EpfHjh3bpZUzWrVp025T8LVVqwC1tzx9E8vKZBpToe2J
6bCSKhnL3vT0FmqaDIDToViUCbQE3Tw2PQbjBFAEopdrwIwnxgj1oNm8gmf0wc6MjIp6hTgK
NIZO6BhAg/lz/KjBct30R9SPH6k1UC+UM10wu+gK5k2kDGsVnKmwq0uyvqur0MTR0jHgTBrx
ZYIatGMLzYvJuoDpdbr6JT7WJ/I1hK/zDrosZPnstJDl9AaLsMLmd126lLaoYmQdfTDQVqkP
KZ/CFmh6GcxqXoQ52B/RGbwHBcg8Hluh/EMsY/qxDv0Jzp+HtwXHMlPQQie8d+BU/Gd6zOWO
wZzxIZhP6eAIsx1+LdTdhYuZO6AM2uHIOmUHrVvF7cMrSD1OJtaDsg7M0WMvvLcRnhXE+mTO
BmXfCuP30Xbuw7+Tzv8gtovQFEGsDqnQIMIdra1WK0Q5OXDRbFtbXR1uQ7itjjzzoYf0KgTn
RIKJrXDUUFODRxlKQriVIB+JlEiLcKc1dJTBOkO8JoMYIxzchHh6l5yeX1zeGzpHVbNXNdz/
c+0vumpAxVR/FGOV7Pii2gpZtPaMrpR7By+E+6ACn0sq4R9++RtFw7sM3mulhomQVr5YPOcr
wAdijNbwi1Au30TbD735DnpPlVQnTzrW0Taunl1Xul4nvfOk+9Kkd510rArj06R6cUjMDcLn
Sm3N53tBPyetXxNWP2hPFe+nfKtUv4rfQo911JbtVM+gXlXBNqlNOykflDef1r9DLOO/R9uu
ofxP6LGM2vqQaLPUVtCusrAjxZZ/hLZpkWwqlq5ZpHoWSX9zmOwgVsH7gnyrpEedhElrmPzW
MJxbw47h5XUXlP9Xbd8DHmV15X3fmXln8u99MxlC/hFC/pGEEJJJCCH/MxMQ2Zba0UWkiCx1
WUuty0alfCxLXdamu3wsdVnr17JKKbUpUpd1U5YqpVEDokVEREVExX7UUqQWLVqefjx92Mz3
u/eee+d9J5NAu0+H5+bOPXPOueece865573vO0PdGDRhhw276X0twcMOeVRT8892yB5zwLqp
ZZCuNUTj9MMmwp9HYycvZfMmml/1ineNOSR6uW6HtF+qJmxuHtW6dpsn9Do105y8dZqnRT/K
D82z2uZOumYll3mBzTAvJfyQdGsmHk7Zm0l/pw7aD+mzbuqbHTw6k2yp/ZB0WkIw7YfmFZcf
LmEJfxKxh6vQZD/k/TX4oTGAfeW3SEI3Iund7B7/Kd7j6jvTnGFiZrMXGckw55pzmce8AIt7
AxWBRSikng1cZpG0d9Iz2LrMCZm57PHMSZnFbHfm/qxq9oQ1aL1kFCO/hnhZhr8TmHGRoarI
FnlW9TYrkvkXa5cr3imKiXzXGE6Ms3k/ZzSHZLrkPsh3rIu8D4nNOEfsYInPc7hkjjGvhuTO
hn4uP+fIF/AC/JP4Lnr/GeOpEezXcey/I2eonXW8pxZfjP4dmHUbL0nQ+tA2oGEKzxDaDtj/
s+g3o23BXs5xwMezXH7m2Us0K6jdJfd73e+T/Ea2ogF35DTJsdnx/jjaYbRDJNcJ2bjscciF
q2o2corgp4gOc8X7HGNnO0/9Gfqcjy8SbCu1i/Lz/95NcCzByLCDx1kHb44/iPnS0F8hORX/
0ySX4n8hhTyXHbinSdejjvcX6PPzZItLNL7ioDuekMtYCNuiEPAiLr2QyQNe3iCtxUa8h908
a+lzjgcb+pppPRD/ngVo0M0zIM94xToOyiZoeb24Gq1PwgzOC2PPaaLjuMep52u+Cw36e2AX
Xx3x2yVl8KyU8nJ/8vajn0+tRsJFW8D/823yQfijZ6uk8xSjQWbu3kJm7lObiX49WoEcCx2X
S1t4c6ktZbxeh76BQU9rYJ+X00fkPIJmaeAFiRc45q0jn4bM3lapmw/5WNBgbm8N1ylwks/P
5xV25P18aWMO52eDXB7xHnbwDpMdtpDN+uX8HvA3zlOMcXtXkr67Kb6UPoB7+0iXLKmLkCco
e+9Why5ZpO9qh+7FtAaYy7uWaFZIO4k1R/NGyF8KKE7Pkyxn5Pp7DpMOh0jeIdJnt/Q5zwVa
//myF/bg8++jeU5LHsK+8GnvFulzXHZzh5zXGyMa7p8D0v6+1dIPuM6+LMnXhD6+faTvVlpv
bme+TvAhXxr1sLUvQnTnCW9AxoYXcerl63aB7IJ15NdJZlDi+5ZKO/mKaV0ukk05v0Epm/ew
1NsAvsFrbL4XQk8GPgw82SmKHcxlgAe7InGMNOkjxhWKi6NkU25rzGfABkarvE4zoCOunuTl
Io/FsORlcN8akveJDPirl/xV6MT7Nuo3ku/zdT0h78twv+N24fcChF+1kl+0Uszvk2Oum/D9
1fK9+JznmD1oV+RacH/2fkn6GYdznbgPipi+QLmmhuZeTv6/l/QtljqL+Nko85aYH7rwbU00
HivNpCfPHZvQH5RjtW+hDijn/2sXoHuNvcww9sG6HmMI9vEaB4wDzGc8bzzPTONF40XmN142
XmYB41XjVZZmvGG8wdKNt4y3cOVc7ClhmZ5Sz0xme5/1PsvKfY/5zrIK3znfh+zzvksmY180
q8xqtsZsMBvYWnOmOZP9rdlizmbrzDZcHa03P23ewO4z/9y8hd3v/00gyP4pMAFVyA9EFfIh
r0KM6syszDrjlsz9mR8aa7NqsqYbu62w1WgMWs1Wi7En1BKabfwI9TD29VeGcXVajbrgufhw
Vg/2elVtqD6dX89+5rpgMCsCC2SIuodZt1jfYunWv1nb2Kesx6zH2Q3Wbut1dpM92Q6zdfYB
+zX2QM6pnNNsR6g0NJ19PxQJ3c1+aO01nrRDKCwQBXYVEy+7mfqbqF9O/Srq+6l/mPpd1D9J
PSLSfg/tPI1/J/tsH/Uh6jFndgsaVjsbc2Uj2rPvQLuLPl+HhijP3kljeE/2a2hY+ewRFE3w
tiAq8CA8NXgD2lKmX0HQBjfQ+2+ylK/gburhVcFTKT7/GfXw5hxPah78lZNGfakDhojJ6ab3
C6m/E22tA+c+6h+i/lE0RGDOMzQ+Qf0HaMgAOSNyHILeoXK0MI1pntAC6u+knuYK/SP1mCeE
SA1hjtALaEcJ/jb1tF4hWq8JtF4TsF4TEMkTWmiM9ZpwO1of2gNo2wj+OBoy44RjaGcTek74
hPrLss/NQ0M2zG1Hm5+7KHcFwe+hfgv126nHOuVijXKP0/gc9ZdkP5HWZmIQrR6tk8afon4x
9XdQj6w28X40mmci5pmIOSbupzF0mIg5JhL/PPDPK82rzwPfvCV5K/PWoIct87BeecN5x/JO
M9cr7/eyzye/yC+hvpJ6+Gx+BA0+m7+CjXrlkx3yN6CN4bvi8wHqh5LgJ9Hgs/kkRwHsUlCS
+LwAti/oLYgVLEN/V8G6go0F2wt2F+wvGC44WYB1K6D1KkwrLClsLmwvRLYvhA0LIU8h5CmE
rQphq0LEYiF8phB+WYSMXgT7FMEvioBXBNsUwc+K4FtFFxmbFJpUMwn+MwmxMAn+OQn2mwSc
ScNoiL1J8Lli+FsxfK0YvlaMq+5i5IFiZP3iHWiIiWLEQ/GlyRmTsaNNRnxNhvyTsZaTsVNO
Bq/J4DUZuk/GTlQSKqkpwXwliIkSyFSytuSBEvhpCXy0BHKVAK8E6zslAw38piD3TYFdpvSi
xdDumNI/5UH0O6Y8OQX5bAp0nXIGDXKWQs7SotJIKdavFOtXivUqhc6liIVSrEkpYqz0OBry
RynmKINOZeGyRWXIT2XQvQxxWQbcMvAte688rRxrUw7blSMHli9HQ54th07l0KkcOpXDF8sv
VWRUQM6Kqoq5FcCr6Ku4r2JzxaMVgxVPVoBPBeSrQHxVIrYqKysRWZXzKxfhL+SrRC6s3FK5
sxL5sxJ6V8I3KuEbU+EXU5vQsL5TERtT10/dNHXr1O1Tsb5Tj6BB36lY2ypUJVW1VZEq6FsF
HaqgbxV27SrETRV8rwq5vgprXO1HK6muq8bs1UvQoGc1/KUa/KoRv9XwleqRmtwa+H8N/L8G
61LTV3NfDXStebxmuAZ5owaxVAN+NRen+adh3mmQbxrkmwa7TINdpsFu07CO06DLtCPST6eB
by3mrkV81WLuWuDXQvdayFp7T+2GWtDUDtTuqUVc18KWtfCP6UVo8LPpyJ3Tad+YDjtN3zL9
yemw53T47XTKh3U2GnyjDrLUQe468K6D39XBN+t21T1ZB/w6+GYd8vQM+NOMMBpsNYP2sRnA
m4E9cobI6zNOzwBePXJDPcVkPfy0HnFRv6n+0frB+mfqwaseNqiHTeth/wbk+wbI21Aj8Rsg
c8PChjsbYN+Ghxt2NWDfbTja8HYD5G34XdgXDoVLw/XhzjDyX3h5eFV4ffjB8I7wzjBsFj4S
PhWGDcJXGjMa4U+N8PtG7PeNvY2LG+EDjdCrEbmxcWvjzkbgN8LGjYjPxo8arzRlyPmbStEg
QxPs1gSbNWGPbnqiaagJuE3AbQL/pkszPTODEn8m9JzZPPOmmctpvIZ6rPvMR2fum/mCGJ2e
+QHvm1kz7N1c2dzUHBHjZc3Cjs33N28R/c5myNV8sPl4M+KrGfE1C/l5VnBW1SxRt8zqnYX4
nXXHrPWzNonxjllP4O+hWW/Pgn1m/a4lq6WIw1tqWmD3lgUtS1pWivGalv6WB1t2tOxs2Svl
a4HPtkCflnMtl2Z7ZqfNzpPw2ZTHZ/dSH6N+GfWQdzbmnr1l9vbZu2fvmT1M8GPU034x+wPq
aV9shQ+3Io+21tK4lXrkwlbYuhW5o3UDGvy5FTHQilzWCp9uBd9W5O1Wytv8K8ZtkLUNcrbV
tpGUbbG2RW3IBm33tIm6oI2qj7b+tk1tW5l+te1sE3VR2562fQQ5xlyvthNt77Vdbhtph1+2
h9pL27HntiN/tcPf2mPty9qhf/u69o3tiP32gfY97dC/HTzaoXf7B+2XO6BnR25HeUe4o7tj
QceSDti/Y01HfwfybceOjp0dsH/H/o7DHchVHac7PuiAfTqo9unM6izqRBx0Ys5OzNnZ2xnr
XNZ5V+e6zo2d3+wc6ETu7cR8ncc6T3fCvp2g7cJ8XcglXeVd4a7urgVdyE1dmLMLftjV3/Wg
U7euHV1PdCGndcGXu7D2XfCxLti26xN+mNrt787tLu9u7e7uXtDNz09Z98ruVd3rJW33pu6t
3Tu793YfFKPj3aJ+7NaVUPcniXm6ac17IFsPZOsp6qnpgT/2oLbqQX7vWd6zqkfw7dnUQ6vT
g3zbg7Xpwd7bg3XvOSmgZ3vAN8IidgS+E6mNtEbmRZBNInequSJY7whWO7I58nBkV+SJCNUL
ESFn5LDGO0k9+WfkPerPR7DrRX3REEv5ihZQT/ksWkc98mUUPhydF4U80dujfdE1UVw7RGHx
6A60J6J7o5AhejwKS0UvRLEn9SIv9ub1QpNeEQW9rb3zEjP1Luy9vbdPvBM1be9Dbkl6H+0d
TII8M1re3qO9yO69yAa90GuOqHLnkG5zSqmvd1LM6ZzzqTmiipxzR2obJL/mrJ5zv+i3uKDb
R+Ht1u9E9TlHrMackxoqvGfOJ3PZXHtuMQE9LJv5GH9u8atsGyvC9etM1izOwxeI8/DPiPPw
G3Aluoh9VlyDPiVOwj/O+E7GPqMsMzcz1+jIbM7sMjr5ebgxL2s6rkf3hjpCHbgGNTy0b8V/
JDq560T5t/L5qfbNEWZ45ZWFDWiehqqev/yOkZsSVo/za60YqDP5/dkYLt75GZi4H1HigLop
xxsZnn0kT0zII+kTfPgfw6Crqfito/RJHkn5gxjFwFtV6FHwtzgOP5zgpzf8xFa/EhTyLkmy
FWJ6Vs2Dn4TCFkrqTHHso23Cz1ziAMSvpLD/thSU6m63wU+04nQtqC1+TbhXsWOn5ndiXH53
juIXdfFTNqkROHvJG/hL3c8wPHSmkOQngMZ5Vvo9oHpOz7YUuMrifBWy+MrEImNwJf/g55SQ
yCaJJ2GNgt6LY8LJGvwOSGo5tc84fcA/albEe/zCKHqVk5cInIdSzKGs158ynu5KKZWKa3md
myKu+Zm35pZY00FAS/WaDrq4pI7D1Os9dpT9EfHsGXDJ0TlKmqvHuPCLFNnkWiLeHY/XHsmG
9/QfEPU1QsoczBK8tugkHCl7lpCPQ3G1Fl+qucp1XEHc5oNbBn8aJsLvx4Piupj0lfihZE/w
YKI4r0oKmNOffkQr4E/MyO/W6jz4J949vHuldqTXIPvT7iX+hD3+qD0lyJL2AX4irnOmEzM2
yhrO2a/NB3PIRv2OPH9tu4mVaofg6/rH7S1uyj/EymPsOHbKHSftmvcftfMo3NR7Q+KV2H3c
3oerzvigxulLycW9bnxN1Z38sfckhwXG3JsOOeCZHB7zBdnw2PvSalekXNsu5ZQj9W7VL+/Q
E1fklfjreqQsI3eyDTpfk4wOzFS7nOGLseQ8onKMhI+xA/K7eJpOzrtLj8bfHU+pjCfsuJKg
q8VeYOkV5B69g/RSL7+4V4O1wXuPsUveF4PP58V3slKBkS6f5/A5okR4FbdSifAJ5RWAxDfS
yqodQM0RJP/td+GgcopGopx2N+VuJjShDCBkeZCw1fMpBr+bGx8S0Dz8zRZPo4jYWsB16JP3
eUf6oEMpaWkB04hEgtI6dvwYxhWQXllH2S6D94LLAFliI7gc0lwsh/7vCQmKYJ9C0BzomzlM
Wi+MkeRKT0voExmHzuLSa42vnW6s+XJBp36l7KL2oV3C5202w7GHZfGnbsQce0ScSQ4TuL34
uhiXYK1DrCC+nJVLK0YRraAu5JYwFoJ+giNDBPnoZqp0SOI8qccbEZmfR2mZI3kxqqsFVbeg
Aq831jtyH6dalOS7fO93rhcWL75Ta7yCYoNLIXzwxojuOU2eeMIHHhOvZPIkQD3VlC3q72Qe
FodGmZ5XyvQs+W0iLlPRiP5GRfOuXqsQ+dRGoomiUkkX0cNTWwanum4hUe3UkUPx5KpZZBS9
SHuHissMHmWoj/rIShfE8zp5WmOL8BJxfIhisULEorSWjLqv6vnFM2LDTuywqt5u5OuxVt4d
HyllefwJI/EtyYRN3TQyquR6HAfNfPFUkpQuk0v1WUe1mUQLH4ndmGQdZXFpnZjLOoNaLxU5
l8QzUkovta6pcfeIaJAv/rt3ibpRzSL9Unj83EjSyDCGyFNyVVTAsvpT8iXpNeqpuERWV6cu
Fa4qmdMcc82d2Guk1nTNkVRd79H51rm7RF1rOCCfKOKZdGSYMHQOFCPnnUCq+mNB4r5f7/2A
vqoooi4K4f1zY8l28p4ijBqxg+U46lFltQROp1oh1J6JHYzn7f3kQzn8ScOYF3pxrw2OyosX
x5lN1ruO0ULXGqtrr/gp0tW53xJOVOFcoLVVviz2LAc/Lh3wPepkO1drFoRmG0mzQeEleaTZ
BFmPj+1ZN/NMt17T5oFWxb2UVMnoPANK7Nd7tG5OX5rtkmwX4hbSjexmJfEprJ4ksWlHnQEd
h73CJF7asSIxqgM53mwhcUisn9iNbl5I2vaLmM6DfyuJg8J788RunrhiU7ErrSmr2wu6glZX
Fc5d5L2ksxultXs9VL7eTBSdDkkTtl0hnw+Kb6Q6U/tU/HxSJlbRJzMdl+M+UclI7RLP14bI
g5pGrcQFHVPZMhumuGZNzLKNZuF74kHCULPIGIhpeXcR36jIPSHyz1RZJnnPuVoNylx0MZZ4
UcZYGKS4HRLnCLzylBbhvz7qujpLub8l1p37YOJqTcn1orCWqh2dcqXaPRM5MXXt+cfuC+PV
fpTRUtZ+8hs3WbSjjVXn/E/qytEVYXC8itBh1/HWOWFVdyXIa7oFVHUuZMmVYA5Z+ep14Gga
5xVEIjfvcVQttlpFIWGN42zp6pWkmzvVFy5JbC3J1avO/qtUnQ6Zxll1JZMpfDGP8/cpqVS1
oFdDnuSNEUH5PIICjHaKRIXIyF/UucpGqlBKhGaWuPJKVKi8kup3VlJRlVmayEJqBTz8OlRk
zTrMc9xZiV5M9Mm1XtARJ6lrvRUa6rxSUycOAvc6dZ27VT4PH99Me2mIP784nB2Pyy9Qim9s
qqjnM55xWXSesqh3SGQEGzPQmeSNzLHaWGkvNugR2DU+18lB76rqxJTvKz6WeDl8ktdZ/Pne
eKvcM9wrS97wENmYr6ySXJ2NSo356nWKHUfR7KI9q0bYdyLfmYOjq0PuS7wWaRKrnkX7aS6P
MI192sVzP8mSKb6Nwn/jQmJt1uujzhF3OeoicfU9l/Pmtog6dqUakQdkLlNVAPehPIpAFldn
yGLlh1WeWkT0sjKNkV1FdlgYIcs7a1BuVTrTEX4u4lLXf7YYjb7q+oJjJnflb/PcdWNQ1762
uA7K5DIuVJRKP7VmiVp2QD6BzmPZUYNJj5aVXuJbo9mOPJ9Y39SVZH+KSlJk2chcmXuFTPPU
6UqM/HlhZBTHINVAG8atLylCyQZKtr30bp7iJPjvo72kWOD0kWdEwTMovjHLHDKpewzjSaxe
Taq+m0v5lEflaMsyVUOLtRZ5W90d2EFxLnXLIXlTRV1ip1LnfGGm9F+rdx0pEY8iTEM5YTT/
xGlpAf4W8FOBLEfNAyqbW50xcZola25F7cqC2s/ENfOrc7SnXi2OVPR3Clpp80Rl6OQsdsDr
EraXWT6Zs9tmgibqPNHgHGMad9Alubw60Hl5jDXZoteRQyfSSUpqP1FVvtyXN4osXRIfZvy5
8nqZG4bDmrfyQW1Z8U1kHqPvg2OGrtwN71GpQDwouhKRC4IU9fxZk69QLhCcr5N+6k/a405o
742pzyLDo675m9TucV0ufXZcW2+Y3nUy5+nUR1TD6ivnSJBqjA3YqbhN1bm2zHQRzU/dm1gM
TxQ7wFz+IHviXeJ6ke/4ydcYHzmkyXJVpsv1fDskhaMyU1fdqtpSmE4/ScbMIus/yxTdjpR0
KWTSM63WFKqO9zGqZ9m9jH+H1HasqaqKB0UXTkE39kyto2ZKJZvcwQTFyF0pKaQVbNdesM/1
mbKQrAf65TcE4+GUmioK21GRJjLKbj2v7TgXCTvvEiVpoyqEJkERkicxQsbEfZiPaIWdninu
vY40jGGjXdLa8csuGw3R/t2kTkNiEV1hJa6+/Wj0pKEj3/1PaN0rFpRnP/wbTSm8Sb4KnXeg
xR2UHfqzqLpCjoTB5YpzZ0+yAq8j1lLkJd8HVxX3gKgA87gkmo/KZwZbS5AYc3hz0plhHVP7
t+24shxy4aoTflwVxbeOOUvUJfVOtXbXBUdJAtuJX+arVF7Dn29ip104+5j6JQebuU7G46rG
EE9C6Ptehvi9kLWQ8D2s8SR+D3LYca2cJIFbSrJFkgRXx+Ev9VxEjKTTO6LA1KvJz77Et9iZ
4iaMnjvq6Q9XPSNO4B51RnPS/LlOT2PM8VliDTtZ8hnxd5OvqDTXVGvI12fuKOu4/dGSX891
XdN+N6XMTspro+APvDr2gaQoGRIayuh2n9Nqv03i5jxPG+vca78YraCRvBcknnMa73mSpKeW
1HMBg2ysp5ZSzXBtz4Rc63NNygZ/2LMl0gsGXJIqy1ybLa7+DIq6gkiWbKXm5vTataOeclQn
WsnPkKx0rQHVlElPPrlxslLgJHmJONV4Vq/h+NarceBc7fkn5/Odux0UiaqHn5qtYM6XeLZD
nPDxVyY/57l5YXg46Q4I4Rr/Reu2gFaPnqkYZo7TAPdL7ngRqkfFU02CduMY2IeZ8y5/0Plk
gsgkNWoPM84Qp1TPMFBUO54/SqoNVT4TGAb/praoy6Iac0eSXBy2YQzqxWz0qXBqzG2ua+89
8ncRUmKqp3JS8PSqSmHG1ebj307Gdcc1SObGdNh2FJ2qjkVNavDvncf/3TWDrmOSZljhGKXC
uLqUfxhGombkcTLlmvGdsFMpqZxVnNNag5pOn8Dqs9WvM2VlfirOzz8M/l118Vqh6EZ+pudT
MyTW+FujZHlQcBmm2OrUXIYV5rV/pnU4pudLXEepaPr6GDz1SbK+bkzhmdoSO5nKgQk6pdE2
MdpE8CbNJem7OkSlViyqOX7XjaG1WsRoDxrZQp95BIJj93fdn1B0G0dJYKhfgXJcNyXJ71tI
8JrRI83ZrzkPas6HpS4iuzrvOSfPkGpWBXOfyzpHTpjOLPwEfySRkVQ1XKIxW8f5TD/zlnQH
AZKLM+Oo/oy55Eg8P1ejeQ2P89nrmrPrs6RqS32WkE9nAPF3NGYi27vvXMb0fOre1dg7ToIi
saOJ2m1kQI9Sc3Hgax7Je2hCRx9L9RpbwmT7uKh0zVIzit9ymSvFCVHCUjLWw8R9cAzJkjKa
t9OZb9y8vA/J3x1ySXXCxZ/vgPqUSVdAJS5JjrHRa7bDhclPL5a759FW2q+plR0M/tsl8WaN
OeDyDUUnrMt/2UVUCVx/eeWh4hHy899vYvIkfjHhiCpDfC6yBP9lk4S24r6Zsoc4lRO6y3Mh
8mNa40s02siS1zgh4YP6M0Z1i7TnBs2TX+MPaJvRVZQcJWU/dYXFXDxlpj7jqop2OTHF35iW
E5aKb1afKT+hHfO4k0uSRruY87Qy7NRPnIUMKI2SMusWV2Zlkqfe8xPP7Rxmh4wVrJVN9QQ9
N3ju8Oz0POM56c31tngXe9d5t3n3ek96L/uaffN9S319vn7fVt9u37DvhO+s75LpM3PNm8wt
5jF/lj/sX+i/y9/vf8g/4N/rP+Q/4T/rvxzICqwMHAqcClwIXEnLSitOq0tbnTaUXpC+On0o
w5dRnNGcsSBjRcb6jIcydmccyvgkszTzhsz1mdszj2T+Lqs864asdVk7s17LGrFqrUXWg9Yx
66Idspvt5fZm+3C2L3th9kD2UPZ57GVFHsNj8F8D8g7Aus94n2Ee70Hvc8xrlpllzDRvNW9l
fvM28zYWMB8xH2Fp5rfNb7N0803zTZZhnjXPskzznHmOZYlfXbH8f++/n+X5n/UfZEXQ40NW
Yt1sLWI11jesb7Baa6u1lU23K+wKVmdX29Vshv2S/RKrt4/Zx1iDfdw+zsLZ38v+HmsMtYd6
sIt7WLGxz/gxFmLIeBqxcsA4yHzGy8Yx5vc95nuMpfle9B1h6b6TvpOQo8qsghxLzCXMMpea
S5ltLjOXsWxzlbmKBc0+s4/lmPeaq1nIfNh8mOWa28xtbKK53dwOic/4f87y+S/QsEKrxWph
k6weq4cVW3OsOWyydcW6wkpswzbYFBsvVmpPsCewMrvALmDl9vX2fFbBKlmaxwjMs6en/3to
iVVm12X/OrQit9Gekf+T0KrJi0N95TI7eEJ9Zc1lzRgZ+h1/md6BwDzrlvSAtTj7eutz+fnW
krItrJj5vc8E9lrfT79oPZbzlrWr6D+sH1T8wHq87vuCyuv/BWPphzKeYsya6bsP/34Cvmn8
l6LwTvI9CL7HwfdV8H0NfF8v+xcBfw7wo+lp1suAHwP8lbIHuBZmGbSohxa3QosGaPFX0CIM
Lf4GWtyttbhba3G31iKNGfAY+fspnpzf+Abx7yccxr+zIOAc4zbzLYkBr2Le83yUwBUYj5hH
iMdFzeMRweMI8fi2woA3ch4YJXC5duabgXmh0vRAqCz7+lB5fn6oAlpzyrP+EqI8a542T/OR
fidnP6cxzim4fsfvlZnmhbTHrcGMV60f5rRYewqfsv6r8pLvY7Ea/Lv7hzPXIFG87VvgW5D+
PDP8z/P6LFNmEJ/5IWj3gvZHoH2y8CkB+wiwpwDbB9iPCfYbwPYD9hPAhgh2EbCnAXsGsGcJ
9jFgw4AdAOwgwT4B7DnADgH2PMF+C9gLgP0UsMMEuwTYi4AdAewlAfMigs1QJew2Nft6Md6A
cRXG1TT+B39eqCZ9Smha9ioxvh/jWoynYwzv8T8Lr/oqvOcmq8zqh/cszW20vgbvuWPyLdY/
ls+UlvUfSz+Ef9w6L6cvhwc/wZigHgb1P4H6z0G9EdS3gfp/g/oLoN6kqV/V1Mdd1AdA/c+g
XgjqzaBeBuqvg3olqB/Q1K+AYjmnSUghqHmc/Auobwb1FlD/Baj/FdRfBPWDmvo1Ta2l4D7p
Pwvqe0G9GNSrQX07qL8M6rtAvUZQp/l/CZz/BZzPAWctcP4SOH8LnL8GzjqBY/rPBWLW36V/
w1qfvcb6Sn63dV/ZbgF/H/C/T3/I2gD4PwB+v4B7/ef9ZfaB9Bb7YPaXxfhXGD+H8SEaf4Dx
8xi/QONf+0vtF9Pz7CO0fhf8ufbL6YGct2h9PzQb7dfSO3JOZ3+a+4h1cyBmT05fYJdkr7Gn
5HcL2CLASgErA6wcMFjP+kZgtfUQdFsE3f4PdFsO3b4J3e6Ebt8i65nWDvY19jVuPes74h2s
Z21PAfu2ggneW8H738D7FvB+GLw/D96PgPeXwHub5j2g+XxP83k0Bey7mjd0sSsCf2ZXpj9u
T80+bFflHxCwasBqAJsGWK2Aee2XYKejsNMpaSf7GLLkKxi/TePjGL+K8TtynP092Pmn6fXY
b0VchNoDd1pfgg4Ra6Z1V/YroXm5X7D+Ov/7oQWTn7ZWlf+Qsjmu8Y260FfgXYe1j//UqGOM
wwSfDvD5G/CJgk8f+FwPPneDz2fA5x7N56jm85Lmc8TFpxM2vTX9O6G51mRrafZvQ5/K7bFu
yz8Uik3+O2tZ+eelTf1v8Oya/gn4nNR8TnjPe8+HYi7Y6zw7czzBuwu8/wK8rwPv5eD9afD+
PHjfCN63a95vpeB9KgXvN128u8H7L6F/L3xhBXxhfm6T9VfwhRsmL7buIF/w8hhPu+KOcf/L
aVcSuSLUAz5fAJ854LMSfP4MfL4IPp8Fnzs1n9c0H0fO0XyghbHP022d9kasd32brJ8Ftlj/
116t4WcA/7nvHuu9wCbrF+L34kxjyNNlnQD8DeCfBP6bhP+051brlLfcegv4bwP/HcI/4PmW
dRbwX/r+2ToH+Pt2n4AfBPw84L8Cnw8A/zXBX/bcZl0A/EPf3dZHgX+1fmN/WcCPee62LgL+
MeCfAP5bwHOZz/eY55xV6b3Hmgo+VYEtMssBUop/9yBa1DsmsF8Edi2wpwO7TmPXauxaF/YR
YM8Adj2wGzT2DI09w4V9EtjVwK4B9jSNXa2xqzU236Wr+K8fc4xQnWcu/n2OwwxQCTjHWOKX
Jw/eEP9l5Fx/L1bxHe5fvlmoWpq4V/meINylGreRe6XvP1249Sau2fxRwl0WWDYOXzfuKv/v
x8HN5Ndk3tmE26dxsxC9l/idgDH53uv/5jh807kdvGWEu1rjZoDvFm/5OHwfRs0ucRtgnfv8
8M2QpXGbXTbbpnFnKps5cMO++8D3XsLdnjZ/HL4JXFRX/jO+j2x/4JIdyPyxnWa9bafnyHsM
3pwLotZ7F7Xeh+Za/HuXGTkfibrwXaL9OWgzQJsJ2izQWpr2nKZ9X9Oe17SQ0Qorj7LC3E58
lPAtgdE42uesRqfPWS2aR8sYPHp8/09K5MQwLhmXRnuwNcf30bVqbl3xfWz9d+CyNZL5tBW3
fmaznBDR/or/cqx/D6flFbKg/TW/QuAwTmsbvo9tT+Cy7c182vaB1tS0v9C072vaX7pobdBm
w+JBWDwHFg+RxU0x75Ccl1fPgvYDzybPJh4/Dtiv+fmH5jcB/HLBbyL45YFfvubnkEXTnvUs
9iwW/BKwhHygsgvgEYXgV5S5z54EfsXgB9va14/r6dnOyLTna1xbRWZK72X/HyCnDEMNCmVu
ZHN0cmVhbQ0KZW5kb2JqDQoyMTY5IDAgb2JqDQpbIDBbIDY1OF0gIDE0MVsgNTI0XSAgMTQ2
WyA1NTZdICAxNDlbIDQzMF0gIDQ4MVsgMjA1XSAgNDg0WyAyMDVdICA4ODNbIDU1NCA1NTQg
NTU0IDU1NF0gIDg5MFsgNTU0XSAgMTMxNFsgMjU4XSAgMTM3MFsgODM4XSAgMTY2OFsgMjgy
XSAgMTgzMFsgNjkyIDYyNV0gIDE4MzRbIDcyOCAzNzldICAxODU1WyA0NjBdICAxODYxWyAz
MTddICAxODY2WyA1NzRdICAxODcxWyA0NjJdICAyODY4WyA1NzkgNTc5IDU3OSA1NzldICAy
ODc5WyA3MjggNzI4XSAgMzAyOFsgNjI1IDU5OSA1MDVdICAzMDM2WyAzNTEgNDY5IDYwNV0g
IDMzOTdbIDc0NyA3NDddICAzNDA0WyA3NDddICAzNDA4WyA3NDldICAzNTMzWyAxMzI2XSAg
MzY0M1sgMTE3OV0gIDQ2NjZbIDQxNSA0MTVdIF0gDQplbmRvYmoNCjIxNzAgMCBvYmoNClsg
NjA2IDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAgMCAwIDAg
MCAwIDAgMCAwIDAgMCAwIDAgMCA1MDMgMzE2IDAgNTM3IDAgMCAwIDAgMCAwIDAgMCAwIDM1
NSAwIDM0N10gDQplbmRvYmoNCjIxNzEgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9M
ZW5ndGggMjEzNjIvTGVuZ3RoMSA3NDg5Nj4+DQpzdHJlYW0NCnic7J0HfFRV9vjvfe9N7ykz
SSaTTPIykzLpE0IKkCGkTBoQwmhCTUiCsSARiBRFsIKxgL2timXXVXSZDKBBUBGzuquirmLv
yq66khVddBVM5n/uO5MQUPyr/1397f83Nznzvffc8u4957YX8gmEEkKM8CGQ1sryipmtXUs3
Esr5CeHvqSyvn/LgW3OaCSVKQrjfT2vKyb/9YLGDELoearW2L2rrPmVy+weE1OyG8tr2s5fZ
yx5uPkDIGQOEyNcv7D5l0R1/L7+fkPpnCVFFnnLGyoX33zwAdZfWE+Lo7+ps6/h6zsoLoD0t
tFfYBQrdTs0nkK6AdErXomUrNrk1CZD+mJDq185Y3N5Wf2MFdPYmAYqftKhtRXfaLZaXIb8L
ytsXdS5ru/mCTWcTKm+G9EVnti3qfLf8pVxCnp9DSO5l3YuXLgtaySWEBD9m5buXdHZ/43l6
KSG+9wgxv0+YLeQl729+dJVnvmHClyQWhg1h56fnPsv4as3yGUfeGBqnjlNOh7IqwhEMUE9O
hgkdUG868sbhS9RxUktjgnIP01gzyPVERjKhHkeMJIe0EqL9WnouJbxQy+2CXKXsJpkbmkxA
8i+QhzkwP2dQcLwg8Jywn2QHd5OUc6BZFWu7ocluJ3ZCjoT6oLiNc9oJDbI8frdMz0ZKogT9
sT0SXicW8r84yIfJFb92H36tIFQT9b+1vavYmjoa+A3Hpk8U+ObvLyf85sfV/7lB7v3PtC84
fuS4zyHW/8Tz/ycEoY7UHZNWkNofU49bT2JH6zxHYuV7SKxKdVT3SweZ+eizFfN+fD9g/Of9
Z3r0ywbutZ83Du7JY88VmfHHnzMyD7Eoev+7ziXuS1LCPUVK6AskXkofIbN+VD2C5ehhrBcO
4RAO4RAOv27gbiF/O2HeqeT5X7Iv/y2Bv4Cs/LX7EA7hEA7hEA6/buAjScxPKS/cTFb8p/oS
DuEQDuEQDuEQDuEQDuEQDuEQDv/d4ae+Y7IQfs8Mh3AIh3AIh3AIh3AIh3AIh3AIh3AIh3AI
h3AIh3AIh3AIh3AIh3AIh3AIh3AIh3AIh3AIh/+BgQ9JfOivDt0GKYhxvUQgF0A6jhhBw/7i
i44kk8mkgSwkXWQJWWbLtBUfIUHpLwVBXpKU13FcHg1+SUjwieC/oMwXNI46P1336Tq5K/Qs
s/QZdVyHavkboGQCTSNyekBSfX78X0SCNBf6+0kc+eFAj7b6k20zNggn0Ff8lEZC4yL0e/7K
A70c5Oaf0bP/P8KvPts8VfPnzZ0ze1ZLs29m04zG6dOmNtTX1dZ4q6sqK6aUT/aUTZo4obSk
uGh84bic7KzMNKcjRUxOjIkyGQ06jVqlVMhlAs9RklkpVrXa/c5Wv+AUvd4slhbbQNE2RtHq
t4Oq6tgyfnurVMx+bEkPlFx4XEkPlvSMlqRG+wQyISvTXina/XsrRHs/ndXYDPErKsQWu39Q
ijdIccEpJXSQSEqCGvbKmK4Ku5+22iv9VWd39Va2VkB7fRr1FHFKpzork/SpNRDVQMyfJnb3
0bRJVIpwaZUlfRxR6thj/byjsq3DP72xubLCmpTUIunIFKktv3yKXyG1ZT+V9ZlcZu/L3N17
eb+RLGh1aTvEjrY5zX6+DSr18pW9vev8Jpc/Xazwp6/aHwND7vRnihWVfpcIjdXNGH0A9csc
RtHe+yWBzouDB47VtIU0cofxS8KibIijZoL8kTiBvkEPYXxJSawvl/V7yAJI+Nc2NmPaThZY
A8ST42rxc60sZ/dITrSP5awdyRmt3iomMVdVtoa+z+6K8a9dYM/KBOtL3w74hny7n3e2Lmjv
Ymzr7BUrKtBuM5v9ngqIeNpCY63sy82B8m2tMIhTmRkam/05Yrc/SizHAqCwMx+c2tQsVQlV
80dN8ZPW9lAtf05lBeuXvbK3tQI7yNoSG5t3EHfwvb4Cu3WrmxSQFtYPv3kKOMVZ2dvcsdCf
2GrtgPm50N5sTfJ7WsB8LWJzZwvzkmj0p78Hj0uSnijVgrEdV3qkMBu5wqG0N3NWvoV5CxT2
KvgQyydAhhHcJSWZR8sn2JuplYwUg6eESrDYMe1AgndM8bIsnlWd4rUmtSRh+IEuWUN9kjn8
yjFtGUEx2id8zgm7hqVZh9LtlZ0VYzp4TKOyUAdDrX1/Pzlmi9CDoYaSudM7ksU7YOWCjoNm
JBXzYozdT6bbm8VOsUWEOeSZ3szGxmwt+beuSaxrnNUseTs0S2Yek8L8Ikz5SRJkjyS4KTAH
q1zWEbdK6WopPZr0HpddM5Jt71WKdU29rHEx1CCxwwqCQcudNW2XFUUUwNKsgt1NrGoT7UZ7
VW9bf3Dtgt4+j6e3u7K1q4S1IdZ09IpNzROsUl9nNK+2rmKPiiB1tG5meVYm7D3lfSJd39jn
oeubZjXvMBJiXz+zOcBRbkpreUtfCuQ177AT4pG0HNMyJUvYWYK1NAMSSqm8dYeHkLVSriAp
pHR7PyWSTjmio6S9n0OdcUTHgU5AnUfSsQBOiukCE8N2W2nvYO45t6Wrt7WFLS5iBlfCN/VT
cRLxc+KkPsrJtX612Fnu14jlTF/G9GWolzO9AiYGNVMwDtuTeltF2KdgQjUTK8WpyLMm7f3B
4MzmpL3WwZYkmGpzQGY1+1Uu2PtljlooV82kFdTV/rXtbawfxNfM6iocNe0tMG1HGoQiNX4V
tKAKtQAlqqQ6bDpCpXbwDThQqr8WEv61Lf4WF3to86kt0nQ2+olXLAG3Y5syJ3tQTktvhJgv
rU1YCmrHOgYV9I00NaPGCkl4WAsaSaGFnreLkNXeagdrC6S9CaY67qVqK2o6YUsUnJ2SqK2h
TMKGxTs0OrVflQ0NwjeLa7LZkpQ5FC0t2HkptS5UAJ5t9GugR84xpgxVAOtAVg3rC3yvg66y
oo+zZhr7yQxxBewsrNNSSwrI9uscNW2w+WN9DWjEopHKSrZHaEJtDKBWwUauBbvzjpn9wXvE
lUljQlamyA4HNjGJdQdMbNLSe7zCP9uVlak8XquT1L29St33V0B7KXWjBCUJqPhPJ9v4KTDl
S/nJ8HkZn0tuAeGIwOeQDpBlIPtABD6LzyBFJJHPDNHFZwSKElMeg+TdINtA+OBuUIqpVTuk
SLy9anI7P4EU8aXEx5cAi4FFwPHAQuA4YAHQDRSBycAkoJ34iItnS/F09slPxDxIlYIuhc8j
M0E4KVYQSh0CEUgUn0oqQPaD8NDrVCiDmmUgF4FcC7IP5BCIErqeDC0WwBMp1LVDaTuUtkOL
dqhhhxp2Iue+CSTYEvu5rwMJLsC/AgmZgK8QXyIOYd4/MfUF4nPEQcRniH9gyUHEAVR+ivg7
4hPEx4iPEH9D/BWxP5CgAnyIqQ8Q7wdsEYD3ArZYwLsBWw7gHcTbiLcQb2KRNzD1OuI1xKuI
VxAvI/YhXkK8iPgL4gXE84jnsBN7Ec8inkE8jY/9M5b8E+IpxJOIPyIGEE8g9iAeR+xGPIZt
Pop4BJW7EDsRDyN2IPoRDyEeRGxHbENsRQQQfYH4fIAfsSUQ7wb8AfEA4n7EZsR9gfg8wL2I
32O9exC/Q/wWcTfiLsSdWP0OxCbE7YjbELcifoNN34K4GavfhLgRcQPiesR1WO9axDWIqxFX
ITYiNiCuxKavwOqXIy5D9CIuRazHCusQlyAuRlyEuBBxQcBaADgfsRaxBnEeYjXiXMQ5iFWI
lYgViOWIsxE9iGWIpYgliLMQ3YjFgbhxgDMRixBnIE5HnIY4FdGFOAWxENGJ6EC0IxYg2hCt
iPmIeYi5iDmI2YhZiJZA7HhAM+JkxEkIH2ImogkxA9GImI6YhpiKaEDUI+oQtYgahBdRjahC
VCIqEFMQ5YjJCA+iDDEJMRExAVGKKEEUB2KKAUWI8YhCxDhEAcKNyEfkIXIl8DQQkw2pHFRm
I7IQmQgXIgORjkhDpCKcCEfAUgpIQYgBC5vQyQFLCSAJlXZEIiIBYUPEI6yIOEQsIgZhQZgR
0fiEKHxCJCojECaEEWFA6BE6hBahQagRKmxTiVCgUo6QIQQEj+AQFEEk0CBiGDGE+BZxBHEY
8Q3ia8S/pMfSr6QR0S9ReQjxT8QXiM8RBxGfIf6BGEQcQHyK+DviE8THiI/weX8LmEXAXxH7
A2aYYPRDxAcBcxHgfcR7AfMUwLsBcwXgHcTbiLcC5krAmwFzFeANxOuI17DpVxGvYGMvY2P7
EC8hXsTG/oL1XkA8j3gOsRfxLOIZrPc0Nv1nxJ+w808hnsTn/TFgLgcMYIUn8EF7sNePY2O7
EY8hHkU8gtiF2Il4GJvegU33Y9MPYdMPIrYjtuGDtiICiD58rB+xBfEHbPoBxP2IzYj7EPcG
omHfpb8PRE8G3IP4XSC6AfDbQPRUwN2B6GmAuwLRMwB3BqI9gDuwyCYscjsWuQ2L3Ip5v8GS
t2DqZix5E+JGrHAD4vpA9HTAdVj9WsQ1iKuxS1dhyY1YcgPiykB0I+AKLHk54jJEbyCqGXBp
IKoFsD4QNQewLhA1F3BJIKoWcHEgajbgIsy7EEtegEXO92wBHjRUJn6m9ya+p52auAfkcZDd
II9pTkoMgPSB+EG2gPwB5AGQ+0E2g9wHci/I70HuAfkdyG9B7ga5C+ROkDtANoHcDnKbuivx
ZpCbQG4EuQHkepDrQK4FuQbkapCrQDaquhI3gFwJcgXI5SCTVdy33GFyEknkjgC7SCJdE4hk
y/G8QASbWssQSwMmNrWWIM5CdCMWI85ELEKcgTgdcRpiAqI0YGQoQRQjihDjEYWIcYgChBuR
HzCweZqHyEVEIEwII8KA0CN0AXBKP9UiNAg1QoVQIhQBHXO13DMb+A+QQZADIJ+C/B3kE3Dn
uyDvgLwN8hbImyBvgLwObnkN5FWQR0EeAdkFshPkYZBbwRW/Aemna9HSqwImNuVXonFWIJYj
zkb0IKYgytEOkxEeRBliEmIiDjkaEYWIZNjB8zwX8CTe/SjPwcsdRwZAeJ5gX85BNKHXZ2DP
GhHTEdMQUxENiHpEHaIWUYPwIqoRVYhKRAUiGZGEnbcjEhEJCBsiHmFFxCFiETE4TAvC7LkF
OATyLcgRkMMg34CDvwb5F8hXIF+CHAL5J3j1C5DPQT4C+RvIX0H2g3wI8gHI++DdvSDPgjwD
8jTIn0H+BPIUyJMgfwQZAHkCpB/kIfD4gyDbQbaBbAW5hXmfG0Ibr0acizg1YIKrEO1CnIJm
WYjoRHQg2hELEG2IVsR8xDzEXMQcxGzELEQLohlxMuIkhA8xE5GDyEZTZyEyES5EBiIdkYZI
RTgRDvRNCkJEyBACgkdwCIorknjuBAZBhkE+BsO+AvIyyD6Ql0BeBPkLyAsgz4M8B4beAXIx
70i8iM9OvJBmJ17gXes7f/Na3xrvat95m1f7NKtLV9et5jWrrYBzVm9e/eZq+bneVb5zNq/y
CauiVnHqld7lvhWbl/s0y6n2bG+Pb2bP/p5DPXxUz8yejp5lPdf27AOF4u6ebT0DPXx/cLcn
oqeotGptz8YeLgryOdJDDUyd1KPRVy3zLvEt3bzEJywpWMKVHlpC31tCudwldPqS1iUclNq6
JCWtipUet8QcV2VckrvEs4Q/y7vY1715sW/a4sWL1yy+ffFji2VrFm9YzG2BGOdZrNJVneld
5Ht3ESW7uCAxguzmggFevXgnN0wo+Ywb9gTp6WCA08AQp2af4uvafIpvYXaHr3Nzh689e4Gv
LbvVNz97rm/e5rm+OdmzfLM3z/K1ZDf7TobyJ2XP9Pk2z/Q1ZTf6Zmxu9E3LnuqbCvqG7Dpf
/eY6X22211ez2eub7qXV2VW+Sr4wEU4QkgDf3QlrEw4mCJpWW7eN67a9Zzto47vjD8Zza6zU
ELcmbkMcb4APDj9iE2M3xN4euyVWZpAivLY7Ym0E121aa+JyTR7TC6b3TAIxbTJxhg2G2w1b
DPw0w3zDZ4agQdhioFv0j+mf1/PT9PP1i/W8Qc/SvNGjz86rMugSdZ7qHB0/IUdXppum4zfo
qEeXnV/l0aWkVpVpp2nna/nbtdSjdaZXfaYOqjmPGjI+UwVVXFBFCU/tlBJqBPBK8M02Gp1Y
xT/C/vMeIiOUbiQzXXX9iuCMOr9y+mw/Xe93NLFPT+Msv3y9n/hmzW7uo/TKlj7KTZnpj2I/
W5fSF19xBbGV1/ltTc0BftMmW3lLnX8ti3s8UjzI4gSKtLjmLe1ZunSZa6kLPkDmLQXNsh74
lkDhE9izjOUsW0qgiOsEgZVYytAjFVraM78H2oAMUC+V1Cw1TypyojZ+0XDCkfwSgf6aD//f
HQhMZDarl46diGwywDxdGjN/nvQ7AIrbCBm+ZswvBZwPX78hm8l28jB5nDxNXiL/pGrSSi4m
j5EPyd/JF+QIrFsFjabxNP3f9QsQ0IcLZYuIjt9N5Ox/MQkeDn4yfG/wE9ge9GM010DKIjiP
aoIRwcHjdcPXDPcPPyfXEKNU18g9A9qDdDB4mCtj6WAhS3PrWFyqcVBx2/CW4duP6U43WUJ6
yAqykqwi55DV5DyyhlxILiHryHpyKdhiDcQvI5eTK8iVZAPZSK4iV5NryLXkOnI9uYHcSG4i
N5NbwI63ktvI7aE8lr4Nvq6XclnOneR35F5yP/Aucjf5LbmH/B7S94H17yd/AB1qMP0AaDaR
O0D7O9CyUky3Bb78pI8EyFayDXyG6ZFUP9lNHiQPAXeAN3eSXeQR8ij4cTd4do+kY5qR9IlL
4ucTZID8kTxJniJ/In+GmfEMeZbsJc+R539Wzh9HNSz1AvkLeRHm2j7yMnmFvEpeJ2+Sd8i7
5D3yAcy6A9/Jfw1KvAFl3g6Veh9K/ZV8AiUHoSSWwzJvSbkfSy3sg7rvkf1USb6kHDlCghBj
3rte8tBNkh+Z95h37pbszPyxBdLMQ/eM+uYBsPED4E+WYvGbQ974A5TtAwuO2O/7rfZcyDto
711QhtmC5ewN2eKpkCdYO4+O1n1GygtI9faMtnrUojjCl8dY560xNvwr+ZtkGbQe5h61Hiux
H8owK7M2jrXtB1AXrc/qMv3YOizvDUh/ArvDAbA046eSJz4lH43GPwrlD5J/kM/Il9LnQfI5
7Cf/JIcg/RVoDkLqu9rjNf+Cr6/JN+QwePBbMjQmNXRczhAZBh/DBYNylCfDR2NHtZIIVEbl
sKcpqYqqqZbqqJ4a4LqiOC5HM5pj+k6O9nvyVJImgkbSKNgvLTSGxlEr7Js2mkATaRJNHpMX
O5pjhxyRplBHKM8s1YwdrZsIJSxjyqbTXLocPl00m+ZAPI8W0HF0PC0GTRak8yFdAnm5EsvJ
dLKAnEEOyz7mnoX2o2BX6fu5u7bsPhJNNgW/DpYP3zm0i3+QzqTPgkX0JAieOpN6yCbZPHK6
rDv4FU0Ofi6rDh4QDgcP0LzgIaLmN/ELYR28L9STc+EWSIaX8m/Cjs0TBSkmDWQqmbmL6Oit
sK2X0Ge2VVQosxSPQpIjdvoMUYL7bvVECpzOai0Tx8kv5xtNNWWKy7mZpGzonbefhI+9EcU5
e2nO24OvDBqHnjQV5wzuG8zNo6YkkyRRek6hkMvF5GxuXKqz0O3On8SNK3CKyXpO0hUUjp/E
u/MTOD5qRDOJY2nKv/ntNL5yKIVbmVTalCejLoclMVKp5BMTdA633VDXIBamxckEpZyXKRWp
heWib3lt8nPqmNR4W2qMGmiLBw7tkekPfyHTHzlZqDiyi/u4uHlSinylTsPJVMpb0xKiU/Li
J9bpDDqZ3mqJi1coTXp1hrdt6KY4h0Wttjji4h2sLcdQKVjEEjwsPCGLIsnESd5md2Rf8w6S
Evx4m8ZA68X+4MceG4s5tDoxRkfMVG92atRispoIIjWJTge8dXoSPBqipRG8VptqSxHFBLXO
TMTkGEWEbUaET+YjMWVlZRGW4iKT2wSGnT9vrjtuMJ/G5sybG7M337163cAAjRmYNxejuXlw
g7Ye24ftLPL/8KzcPJerxWE2o89S+SSFnheTnc7C8RQdZVGIfJLQp5Wbi/LcxQla4eThuBmC
zjbOlV0QJdfSDXKjOMldWpVqku+hD9HFC1IyomW8yqijwpA+UiPILRmicK4pWsPzGnPkk0Nv
wOvJFcHD8rNgVk4gr6JdPRpdbq4lJ0edHRMT1891bEvJ02rVEHmIpBQ2xmo1MTtpFvGQ7ODB
bUaRq8/rDx702FnMYmSfOvy05OTmZcsT0xoTfaMjZkNmVzQYa35+Gc3ZN5hvchvZh6l4Yo7b
bXLn5lm3/1sfkpvX4hiZ3iaRMoOCaaloGlUWsJUBtqVuZmUWjZafpbHlOlJy47Xc8KVCRGJu
cnJuYgQ/fD2nScgBvU1TmHV/dnmuXUtjBJqsS0wvcvRZU2N1KWqjWi6HD8F2ZL/OpOZlGqNG
iD/y4aj+fHehQSzO+HaIpxklKQY91GK/5ayG+T1JyCQpJI3UbY+xpGqdun6u8SGLEzQaJ5j/
zu3E6bBlpPZTo0el1UbYOiO6ZF2EjRcWPswimKkx+wZNxcURxca3kbl5R2dT6vGzScDZ5NIo
zaXj84riNcLk4YUTZWw2ZeVFKjR0qtyUMsmdXpoeZ1ILT3JXUcd8MQ3mk8Kge7RfD4OTmzOS
+ZuMkWqBCgqtSfvb4Xo2lksIEUrgvhpBEknqYySSuwv20ThuDVGRGJob0HdY+2len+wUUjZY
NkhDmxZzR1KyU3JHEvhAVpDNiaKJ7VlCSeN1L28cfichPT2Blly598ra4a+SvMtaTz+9eUmD
k0u+7oULSlOc/NXOFM/5ey6tWtGSP9SWefJamNvQEz4LepJJJvbFpfZzax5S2SPtkUQV10/1
Dxqd1OmUx7KfBus6wK6mPjn2CQx6FnRsb3FxTo6RLUvH8b2LlhTRR6MmFuWzZEqdcmgP6yhX
AlFBgI/h82mlUq8SBJVeObyTXggqWZsV9jjss8rsjLemWNT7IWKNc5hVw8MqC/tvlMklwcO8
GnovEnefzNTP3fpQvEZjJfFWWT+N2GoyWYR+Om6rvcPCZgHrNPQ5ZwCOAanPNEp+bA/HTvik
fDOvNpqG76AV0DWZjHVtlzYh3+nMT9BC5+NNRv7xcdnDsA1bWVeHL1BjMTW/y5mSFeqdYIYZ
m0MK+kQt+0d9S4oGOrmNWDI6tf10kUeVknLcLMUlf9SkUnfG9gzPn2jQjUQFszbB7WDdGl4O
HZRirKMOIL1UirkTtIlqNLCa3jjcNRLnP4IPmQySw5fQVSPxUN9lT4Bli4h3W2Z0VmpMP9fi
USXrctRZWckFsNi6PCaSPK4jy6zhbc4OW5cxNAi2t+AgImDDiigujmG7V3Hx2PGINLTivm+T
iXRHSpuMOVr2hMaa63Dmxqu54ZeEojJ7VryBH36VA63TmWNVZzu3ZHmyE7WvC+/qEl0lqQ+k
Zo6Oks/79mmTQVBqlXzht8+PagPpmcbk4rShAa44o0Q0ZKZLqxFm0UcwVjfspuU7iJq7b1ue
0WUqYL+e4iw1McfFu0z9VLG1tNRS3E9129mMwuFKk6oYlmj+PogWvzJ4dJypqdm8KB43qXCu
KRJ4i8VspkdXMP+R1l6S5Sqw6/kGvc2R46iVXOm2wVyjMzs3dJXEjZtaEJvhSDb61Mrhx03O
CYVnn+kuy4iOVKhlvKA2aj9MK3ZGDK8ZHesjzpRk7+K6wlnV44zqhKyJqa/H27hn4nPFqOF/
RDkKmJetMPJWGLmdJPYRAabmVrNBMPbT8VutHWppzeTTnIGhvbhWxoxl9C4kLepWkzGos+U7
U/NsuqBSx56vU/KcUqsS+MeLsr59YrRPE/EGxG4vqWD5uuAn/LPwzu+E2941eLYGNNbinRz7
uUQOt8Sjjkyq0hSnWgV9Rn/oGpHRT2s8qpjaghiWKoDUNo++QVbPTra4QVfZoAtnIGya+TDr
rB7Vz2xi7Lk4LnRJlNac2TK69nindFmMjkrgmBfH88+qY9IT7Gmxmsob5iy8oiXNveDq+XWr
JrDD0gGH5eHC9sK8ald0RHpFQVyeu9CerDGoBUFt0LTXzph2ydb25Y9e4p1YSuE01MjlGqN6
qKDCmzejc1zRaU35huTxaWy+1oLVHuRfJS5SQHm02tbIyKRM9rsorgJwI9gtic+MzOSsmU8I
7MfgFh1tIIJR4OqnC60Ct0nwC5wgxOeAQbYaaAOjxw5lcvY7a2O+InqjnjPxelWMljaoYqCA
6htPfANYJ27I5doHVzE4AVwumPlzz5o31zU4by6b/2+zpSDZ+xd9NHhJ2sdDHnDjCpOPvaxH
pxZKXlLwD6anDL1vLZ07ubyjJteggs2Bg/OnZNay8uVbV5ROOvve07pvX5h7iJ89P7c6J5aj
h7Mzi+dOTo60RCoikmLNiWaDPsZimrDq4dXLH7u4qrxn0zz7aStTJjblwFqKDR7mbpStgFvi
WSGfmI3E2s/N35qb4VD3U9vWwuo458gUdPbTxAc9uV57vdEr3clg3uWzs37APTTghrszXJzV
P66OZAGcp9JcjEYbHLdenZI13CGbCNyNglItV5hiky3W1DjtXSqDWhYVeZc2Pj8lJc+m6Y6M
lIFqcUrD8sbUqjS2fL+wiZEKhVJhcpS6ZqgtabbxOUPZagM7Mgxq7sWc8bY0i7pu9qWzs+GF
JTYVLSK8K1tF2sjsbdXVyU0p7Be+srVmgEc9MzkiOYIUu7OVYJpts6qbvNNYpKxKNOfAOB8q
9qbXx9drvdKZAvdUuHWgeQbYncMtnZEmNuGY96Why7935EknNILZksBHj6mcdFQNB4oBbGOP
LnGDZTSy6Ii7tfF5KY68eO3wdq0t7xgbORp6pmdWxWrBSFArIiYpqiSf1jkbehpd1bEaA1xx
DuWmyZVyb5Pvu2b7rgnLZ62fnW2AtmJTbXlQT1HTVD1t9vrZWdC+PiYN7SqvgZm2iHRsc7vH
d0aBQbfNSkiYomEGXpQ1HvBgQ/WUzshY2MsbtnXVzq9KZROwqXr8FLCtR93gnVif5Y2thy2v
DO0rmRcOMLjTufEsYzaWVvTRc7tAspTiqEXl8p826yz4khZtKizEt4gayay5CZoIR5Ezr238
iJUFrULtSHdZsiaI+mvV0ty8DvIcY+2edvLF86yTilwxep6qYvPS4WVZW76uZs65DcnJI0al
Q5Nrx9mqpgxtGdEIl8jBpnyEY0L6CWdxw6xLZ2cJCpVKq1LptQq2Dw9HesomdF3WTtD+yo0w
r68jG7etX99+bQfYe3t3U9OkhpPZcm+/rh2uDq0e1STtpHb46nYxfySuWtZ9rXcjm+NrqzpO
7mZ+MKzynlY/t77Ba4krrnfU5zJnxdWaqqqhVJ+smkhOYffCo2uA+Ue6aeTksPdCfDeU7rO4
GE5gaNPP9uFPWD/cl+mSS8ZnxugEqrTmpTlybdrJ62pmr25I1tpyJc9GOIqduQvGaaUD0cYc
rRIzM83gaMN1aj1batePWWrHbUffv9QEA1se4C+lTnO8v4be/oGpcKkc9jPe5CxN/9krE+fD
AdjnVpBOMr/PU8t2N22nKJKCzk5tVbObsDlhNmqn9tNqj3p+g8fr9paUmLPYTIivriXwIpC4
1eyV15OQj2HRlUl7nbQSB9hKjBh5Y/mBtRV9zBmQNHr4jXWqecwRKWA79L7v7Pn1Zzem1ol6
Jc+OCLkpNsnCXtzpDFyrNu0eXJBPZE2IssdEKORqhUwTmZxTGF9/pjeZO3SCU0GvZ3Ybe4g8
BZccGbz+q59C6w/PralRqBSK6JT4zNwIg0bunLZiBv0zWljhhBW3kVy2bdKkuKnsWN2eOmeO
7gw92/vipsWtvJDZPVq3SBcHX6lrSJ4rdaX3DO/SpXkLmaV91VO9XohsH191oVWfyk7SPG9S
fVT9OnBLn6JBWmtl0s9DcCcEH0hrbWB0reUfv9gco0ZM+jHr5UQu+mmeUziZrcfH14Gth7ec
eKmwkzvdm8JO7rEHPa1z1J89w1mVytyrgDumKSbJHM8yZmhs2NZY98aawL1KYdVYf/zwIvEw
Xxt0x/m6umH2pXOydHo4wGzxYiRswXKjY0KG78RTALx+HrydvCjrJvnk9JGfZ2rggMvPgAOv
dWtCBpxuoZsRO+Y8Kk9WbUqVdKhJP+SC21FE6M0MrlOBH1X8mJ+FfWerHH35Du2q/Isj9o9M
OWZXG2Fo7/uB40gmjtz0x54wMHJuJ9zw3eRMHHmf08COFC2JM6gT1TlqXser2Q1aQxvgatnk
UXtctU5DtL0mWhoNzFk2nvnsZj4wWIy3yf9r8eMukt8z8GjpWJFzO+HWrFZGxSZERGdkwfBD
w1XHpSfaMyxqcVJRUbwuwR6jkQkcX5eSHadm8yBlQubQvpGB8+eOxBbnT3YaeIVKrY3OgLFb
gge4K4U+UkKuwrE/ZDLpStOJmMVuNxZd1ogXs9jGKXptuhGFjv2mm8Wbx35DzqOQXhrY28Je
EJrjHsofyDfhK8oOkvUz2vg/7HwJfBPV9vBM9rX7vk63dE+nLV3YhHRNsRtdWH1ImqRtIE1C
ktIWEUoVBEXcUBZFCorggrIKCmiRfRMfKvJcUVEEQdCnD1Rov3PvTNK0FMT3/fy/9/++5NDk
3jvnnHv2c6cTysQGb+Dcvkm2chZJfWLYbJ3q64fUndI/z5RDmTyTCvgzUtJ8nXnG5NMtMwRs
xaeg8+iISVurVKoMXSauguVhigwiIxpAPq5cp540SZCpKEeKjVPngGKvq8tSSsPUAeiUIShm
Kx+qfajqgaX2shXvGHvGRueKvrWKveu9yXlhgC4zgLm4OXFlUImK49EJWSQWCGMSA8ISguUu
B2583OtucjHQza3J7eq998CVRy6+yZ2Ka5u5hbkJ1r4i3pfQ2f+2KU2Fes2m5PJxyMYB8jx5
GACRlVxDlKtVarV66DiPZGTkLLUPip64srt6Wws277EM3FT2on7u6Cnwr38nCbjhPnYg8/1B
m+CLpL4xypxQ1JK757hYkMsXekUrB7YhObs3NvFRzLXFz0hR+nnIWGO52DAsKsBT7nEzK15x
/Fr/yg3hy9hXuBzidxHxwKY6ez6y76Q58ail5zXneYUgQwcqOhSj87IUAQGKrLzRfKJxkuke
0z2N6IZ6pGR+8Ry1XZ0fHzIJGb5RXYwMP64M3FC8dVgZvk9mYpvp7MwtTloaivFA+ExzbeyM
J/7wTnrg+L7tqI+6ccgTLkedGLXogFAmAdh7cba3N7l4QeIbO5BXJT5xf+hT8gmUcHHqeE8x
94/u5l1zJCXAmSOuy6n+N02dXqf3nvwIDjGEs5PztEBKxBJZRMYmcXDWDnIDQRCp5JaRXt6R
TcFibsIrAdMy1svsXBsxgnnM4PKbPPZG//Z+F5edw3k6Oi0o0k+YqhlW8LfBIVEjJ49Qlsah
RwjhigDxOxHZkaEJQVJxYHxYaG4M52sPL55IKsxOpdNHG4epbVXJUVGkv1Ai4HLB7N2jYhUh
SdmhETlJodHJBKvLg/wIIo5QEqqNSt52csOWUG/vUMV28pWRgUSoBxy8Ht6g6FJwFIqgxCeo
aeJlQfbeRydQVdFTaR/XJxHO32AFMBGkuOH3V5wHQ0O713nG5CYmqjKjJHKxJFSRXZTauTKp
0jZq1NQCaic3c1BoQogHh3slMiI8JcJTLJMExsSGe8gkoseWqZsrkxOKNYMDc4f7RCaFQP6F
cfaR+wUhRDaRtsXHh/CAlrBxpHeSIlq0mjZFrwlYk2QOs3mYcRJdZG5JoI0OduaJsw0EDHTn
n9178iX3c/hCviDKxzvQUzDRw9ND/jdxQFx4eFygOM8DpqrgQaNzgjNCJAIOv8svWM6XiHzC
A9MikhKjuhuEUtQhpEJyWVRiUoQyuzo3XCiSeIeiCjKBs4/TKZARNJG2McEHBVQYIQUlPIkw
74RAj43J06KbAm18G/NrJPwLjg8usjZ3nm4Utz7mcTohasLDQNaE5JCsSBEIHqYIkEgCFGHh
cQGipNq0oVWZAZyvnXKm5WbHRne/6JhzvQRMHAm6z0ZHx95RO5iVnPwcIiiVUGyODiE8IYJG
ykIku+OnRXv6R1j8kcgo/sHq1/f6DO5bmoR9HiuA+ZmTGY/8nMOXCIUSubdcHhQS4e2QNSaN
jg6Ij4v28Qj3E3JJ3tshUfDJ54l8IgO6dzkE5fh7wGsoEIh5QpEPhSNkJ7mfvxLO4CmbiZjI
eCSlFzTNSHP8mmDpGl9z8ktCJq6P4V9O7L2+97O9WFYcwVn9AsElWPxRxcQGJveL5EHRCt+G
ySM94BZhBERGGIqMaVA4PKwhUcGRfL4QDBgeHi0XC/ka7TUUB3ahVMiDwim0oyg5HRcr43sG
Q2Z+2/Mjh+A3Ev5EIhG5kwjgbCcowp+z6HUpPy60zKsIzPrZu45nquzDbq5DOt/+3/P4kpQE
J8OhNlhChsgisxISBkXK+fKo7MTEHEoup3ISE7Oj5OQ6xyGeu1DuJxcI5b7y3ysSc6M9PaNz
E5MGx3h6xgxGVeN4zznyFM+EZaOQbKuxbKtfl3olgXQGAkTz2uv6wBfJ4pTOu790b0kCE6mo
pEBxiDgsKzk5M1wsi8iMV2RGyuWRmYr4zAgZWS+Wo6IuF3M+8PAF0WS+HtcGxWVQHh5URpxi
EPocBJK1cXWcj/ktDqv5cwSElIjiCF5P5Icqir3glDjiWAYIdnJAwRwr8VwFU8A4e8T+0SGh
MX7iIFloCkWlhEq6jWK/mJDQaH8RGUiiRVU6d5GjUZBvO5pHt6rvmr9/Tw8RxDnK+Z3/HUcg
2kygv3PVyjnKi+afgXkXgezKXofOEk+MHBkYB1EUoJBJpdzYkPg4xU55fKRMJohE3+P3JQSc
HmJEJnrY6jM482IGib5VEXQMzr6D8RuoFxDA/lrL+Y0A9EUgX/YLJtzMeM6PfH58VnRCoIhL
d3encsV+ish0hYB/iScNTIhRKEOk/A9eqOL6ygIF/mIuZNeiB9EDMakfP1DO2SjzEHI4Ig95
d9l1VAdYXYhkkFwcTVAeoqioAMEO8hPQzIv8ZFtAlNCTK42Hw1D3Jl+udDsWP3NEpk/gYBwo
Pvh7IYN9HB1SkeXNRR1SEc/1ZufOR6uOJ6u86NjcLMVuYXxmRhL/DUV2dlw8NS0iOSJAvPxZ
sX9obLA9IZpzwdPb25Mju/6Tj8zTk+N5/Z94vjk6RhoQG9RdRa4PjgmUxkSjr4A9ywB5538W
OB7/UbDfJrzBADdoAGhwgX1/DnhD/wRsHwCu/k8C/wkGBJMGgLMIhE+IqsUT/29AIkMgFQ4I
9//1IOPcApYyIFcPCFc9Lv014Fnrud0rGGD6AHDI65B3tBvc8P8AWPrArv8e8JG5wQ3/34Pf
TSDMDW5wgxvc4AY3uMCMm8KnbnCDG9zgBje4wQ1ucIMb3OAGN7jBDW5wgxvc4AY3uMENbnCD
G9zgBje4wQ1ucIMb3PDfA/hPi6dy0H8v46IhxwuvoDFJeOAZF//fPxHvJDvmEkreBnbMI4J4
+9kxH8afs2MBjP/FjoXEdL4HOxYRSfzH2bGYoIRPsWMJp9O5l5QYI3ydHcuIJJGMHcs9BKJs
duxBjAIckvnL6KQoYBg7JglhYAE75hC8oLXsmEsEBi1mxzxCFrSSHfNh/DI7FsB4GzsWEkOD
9rBjEeEfkM+OxYRXUDc7lpCVzr2kRHKwBzuWEf7Bg9mxXMgNLmfHHkRcMPqb6yRPDML58O9n
x4ydmTFjZ2bM2JkZM3ZmxoydmTFjZ2bM2JkZM3ZmxoydmTFjZ2bM2JkZM3ZmxnKPIGo0O2bs
/CJBERkETaQTuTAqIwyElrASZsIGP/WEHdbyYWQlLPhdAysGGJkIJVxREUYAiqiCtQaiEa7Z
8EwPn3rAng7vOsCUE2oY1cGKnmgBjArgpgceNUQbHlFEKXBuA77NeEcjjBqwJBT8mAGnDWgd
e1BOmWkiE0YK5yyHSMH7a4CDBXAp2FcD+yAeWmIqizsKZo2wiq42g3w2pz41sG7AOhhvKk89
tgNF5MEc/f1/tKrBVuirI8PHzGpK4V2a4aoW6+uwbgvQWvFKM2DpsNUoWG/Ea2VECciErGPA
dCZs16GYXo8x9EQT7ImsrMPvFCuRA5fC6zbsUwPI4vBerx7ouh2kMAClDayQj7UxYE0MTj00
8NMEFIyEjD4avAfF+toAHBFXDeAhXm0wa4GRHfvBBvrVwdiIZbJiWyB9DfDewFqK4WrHOjF7
mrBGWiypCe9iw34qwV6phxUUj83YgjbMV8/6woB1Ymxhw1FhA64aNl6RxyzsumOXJuBjxPax
sFKaYKUJ78rwtGFL9UqAdrRgXZjccNiWkd2IowZFQiMbuUiqJsDVwP52PDNhXzvimrEZswvj
RxOrlxnbtg5j9krsqhGyWiumY7SeCnMlzl1Xb8Zjbk2YQxu2QzObpa72dkSfiY1kpD/jFyuO
BkeM6rGvUeRanNowMjawODaYzWC520ELxkPTnV7S4BhBGdDURy9H5dGCJBq8v5bdXzlAhRpy
g54oO80w1xFj2KhxRH02cMiAqtEXP9WJf/Pot2M5dDg6kUxTnX7pzdYba2cDG+sWJzaKZiYK
TICvx/H0P1ODJe4q/L+mCpeCJFoiAWdeInudIopxVJixZHYAVMOGEGkAOmxbRNl0Q/Qo2ZhL
g3EbjqEGHEXIN22wqgHZGRs7uDI8jVgGJEE9lpapfQyvgWLUhuPcgnVnrOCgQ14dj/dgqk8b
tjRjGbvT2w5sR63QsvUcZX4KtgHCs7BR4Vq7LdiuJrZmMFz07FzD1mk9rjIGrCEjXR2Ww+Hl
/h6zsxRM/FhvWKl36pByW5WA6RQ6bFM725GY/GT2TXHu018DprK2YDtpcT4NZLMWVlMDzjQj
zikm82+0PaJhuk0C4Cf2ieCBuTMy/Lu2dc0PpuNTbM+2Y89p+/TO/hr0dsr+cg11iQGkCaML
c4Jw1Eqr8zSiw/3YhOuI5qaaMrGn6RNVTD0ws++MVsy4GecLU590uLcZ2NrC8EGYRlz9bx6j
TBU3sZ7p5e7IEIPLSaMR1zsDa2dU1eW4XupZHRynDoeV+0Z1CvaMBo91hOPM1b/O9c+EhH51
QY/rdAs+ZRiw95FXNbCGLNQAGI5raSzPu/vVzkQ2e3urRe8JwSHNn+lOt9kNqLB+PEodPKhw
ZzRPgTXGT46oYU4sRraL9Eb3rTqcIypv3uWQ5yqdmWNzOaMw/maiQM/uxVRsE+v3FKyzle0+
jnMFc1ZqYP3siGMmrizsOYjZwYzP4hqspyNSNERvl+9fz/4CXzgtpMG6I7sZ2FqvY3NVy56/
TVhW155pwCd0G45NVsab+xbG1X37PHg70cVGOpe7Btd8uG1+RO+djgN74OqW0q+6OWzfn9qI
7xQM/fR2yNV7BuvNmt5O5PBhCuG4Y0N3Zo653iVCLPiezIjjrdGlwzJS12FZ9Gynanb60rWW
MD5MYz1uw1lidMrgyOu+sXT7VnXt8IyWrp2mb0z3WqIF27Hp3/Sjoxs04ztOxjJ6Fwl0+B3t
2WuXKYChdekd9lvUY6by67AGjo43pE8VZ05j0/F4oFO3CfcIR5dxvWdz9ImBakpfKhuuFYyv
6li9B+65mpt41OrU3oaj1IS5M1l0493wvxsBjv6mJgrx1QqiCGZjoVtW4ZUSWKOgilbBlTEw
K4DVAliJB4xq9no89tRY3IfUgFeLexzDowrey2E+Hte4IoLCczS7E/DLgReiLSTG4T0KgVs1
xqzCvMtgtRQ+C1k8RJEPK7UwR+NiXAWZ/cqBirmHKGF7IiNpDaxTTg37SlWCd3RIVgazKuCv
Zq+qgHcJ5ofkR/sX4XG5U84iVlIVthHijHjmg0SleIZWa+GzEvCq8f4qrDMjbTnWoQiuM7oU
YgnQzkpWVwYP2WcMewX5CMlXCtCrlQrbQI2l6bVfPnxWguSIfzFcrcEdogIoC7Cm1dh6hazN
kLaleNarFeOpfKwNsiqyQQGMy+Cn2Gm7KvzOyFLlwq2v7cbi671YjH4q9j0fW64Czxhv5ONZ
DfYVuprC+rIK69F/17E4EgsxlgprXO2MkCIcvYz0juhk9qhwkYTZD/nWVRZHVFO3yBGGi+N6
LevpG+2CrK7CNkFyVTt3vhlnyM0XqQw6PZcqM2itZpu53k7lm60Ws1VjN5hNSkplNFJVhoZG
u42q0tv01ul6nVKu1tdZ9S1UhUVvqmmz6KlSTZu52U4ZzQ0GLaU1W9qsiIJCnOlMSoE+clKo
Ko3R0kipNSatWTsVVkeZG02UullnQ/vUNBpslNGVT73ZSuUZ6owGrcZIsTsCjhk2pWzmZqtW
TyFxWzRWPdVs0umtlL1RT5WV1FClBq3eZNMPpWx6PaVvqtPrdHodZWRWKZ3eprUaLEg9vIdO
b9cYjDZlvsZoqLMa0B4aqskMDGEfjckGXKyGeqpe02QwtlEtBnsjZWuusxv1lNUM+xpMDSAU
oNr1TUBp0oEBrCa91aakSuxUvV5jb7bqbZRVD1oY7LCH1pZC2Zo0YFetxgJjRNLUbLQbLMDS
1NyktwKmTW/HDGyUxWoGbyBpgbvRaG6hGsG4lKHJotHaKYOJsiNbg2RAAjqaYC9zPVVnaMCM
mY3s+lY7EBum6pUUq2a8jWrSmNoobTO4lJEbmc8ERrZqQBerwYYsqtc0Uc0WtA1wbIAVm2EG
oNvNoNB0pJKGAgc0MXuh4NE2aqwgmN6qdAbUEMeeVJ7ZqBsDpkGmz1ZmZLLrqWi9j/ntVo1O
36SxTkW6YLc6o7MBrG5By1ozmMBk0NuUpc3aBI0tETxJFVvNZnuj3W6xDUlL05m1NmWTg1IJ
BGn2Nou5waqxNLalaeog1hAqYBqbtRpbvdkERges3s1szRaL0QDBg64pqfHmZrBaG9UMYWRH
AYuWkTG04F67PoXSGWwWCGLGqRarAa5qAUUPnxpwpd7aZLDbgV1dG9bKEZJgLogds9UxqEc7
pNyoO8SCrllrT0EhOR1oUxCNYwPwUUujQdvoIlkLbGowaY3NEP+90ptNEC0JhkQmNVzQgcOt
pGUyCeIdfG+zWw1aJigdG+BYdPAaii2QYIBdIC9QObGi7NGZW0xGs0bX13oaxlQQXaAOuA8N
mu0WqAQ6PVIT4TTqjZa+FoXaBPHLoCOHGHCuNBrqDHZUo+Q1IHK9GWUMEpk1dQpVp7GBrGaT
s1o4nJDAxoLepGwxTDVY9DqDRmm2NqShWRpg3s3WlURwLw4LnAeIzcCFcKACdoLFKEUY7yMz
TzGDTsg0kE9GKG7Y3H1LJTJln2Ipl1ci59hwIoHeYAI9UEFgg2V0KVS9FQofShFIxgbQGdkY
bAUeBXLKXAcFz4SMosHF2hFnt68FEkhjs5m1Bg2KD8gzKFsmu4apqQYjWCYBceyjLVXNVuv3
E7FEOlwRGT8MiIdrLVp2CbcUNtyQ9I7LRgPEKbM34mVluhXsgJMIaZiC6rmhHn3qsUEszaCQ
rREnLLCua0bJa0OLbJSAhmmguE2PyrTZYmCq6k1FZRIetmSShrU0FqKl0dx0Cx1RGjRbTSCM
HjPQmaGOYlmm6LV2R4D1xjEEv86AE28IE+JQxqbrXZquyWxHKcMUdAObxkyksJdsjagn1On7
ZK7GRVEr2t5mh2AygIuc3edWBkD5pi6kqiuKasaqqgqpkmqqsqpiTElBYQEVr6qGeXwKNbak
Rl1RW0MBRpWqvGY8VVFEqcrHU3eWlBekUIXjKqsKq6upiiqqpKyytKQQ1krK80trC0rKi6k8
oCuvgN5eApkITGsqKLQhy6qksBoxKyusylfDVJVXUlpSMz6FKiqpKUc8i4CpiqpUVdWU5NeW
qqqoytqqyorqQti+ANiWl5QXVcEuhWWF5TXQdsthjSocAxOqWq0qLcVbqWpB+iosX35F5fiq
kmJ1DaWuKC0ohMW8QpBMlVdayGwFSuWXqkrKUqgCVZmquBBTVQCXKozGSjdWXYiXYD8V/Muv
KakoR2rkV5TXVME0BbSsqnGSji2pLkyhVFUl1cggRVUVwB6ZEygqMBOgKy9kuCBTU308Aiho
Xltd2CtLQaGqFHhVI2JXZKXc/WjA/WjgT9jW/Wjgr3s0IME/7scD/zsfDzDecz8icD8icD8i
cD8i6F/N3Y8J+j4mcFjH/ajA/ajA/ajgv+5RAeQm838QCKIniJhHDPTisN/UJ8gE+ByJv/F/
qxePu0QmIwGHbLxdfLkc46+7XXxPT4z/3e3ie3khfM5ty+/tjfFvW35fX8CHTwL9zwUexufB
jwS/FxByMoSIJiOINLDgEHICUUwuJGrI5cTd3FHEVKBqBaz2fvT3D0BPA/1QoC8B+rFAXwf0
ZqC6F7Dm9qUnxS70gUCvBPrhQF8C9OOAvgHobUA/B6geBaxl/ehXu9AHA30G0OcBfTnQTwJ6
E9DPAPr5QLUUsFb1pefku9CHAn020BcDfQ3Q64F+OtDfB/SPA9VzgPVKP/pLLvThQD8E6EuB
fgLQG4F+FtAvBPpngOpVwNqO4lQk7BEJg4KGxdbPqq8XiQmRZHf71wBX2j9s/6z9EICIT4gE
QUGtp+DVKuATAoHl1NWurlYRr0fEoydfnoxeGKmr6zJCOiXgEgLe6S70EvJ6hDwGhxZxSBEP
rxJdXVwuKeJ3dnaKhIRIlJtrNBq79+8XiUmRtP/+YgEhFspksplH4TVTICAEwtaj17q6Zor5
PWJe7mRWAowGvK8itKMCHiHgX8abiXiEiM9i0WIOKWZkwELwCbEABBaLCbE4jAgjsgG0ALOJ
3e2728VSUiw/Da8fT/998icAhye/CyARkBKRQ6CjM4UCUihqPQoi7W2V8AkJ3ykSg+mU6aiQ
RwpZobrEsDVIdRXj5Uo4pITf5ZSLxyclQmRJiYSQSGREBEAmgKZ9NgBCkshIicdpy2V4/WMD
guP0cXo/gFRISsUCeE0He+7vns5Idw2kuzZTyiek/NxW2JXZFuMibp8i3P37hXxSKEC+ZeUT
sJituVIOKXXIxwooxQJKxYRU4rBcNrYcY7vd7VI5KfU8nXs693LrZRw8x5YeW3p86YGgA0Ey
ISnrFRKkFAlJkXhm9/7urne6Z8r4hMxVzMkYnZHzWyyoiE+KQFAmxJDNHZKCqDIORybo6iur
DMsqkxIymQfhQYRiSG9Pb5/dNbtrchf8myzzIGXep8NOh10ednnYKeMpI3LYgYUHFu6R7ZHJ
RaRcwoXX0Nln9+zZc3b2ULGIFEuGzTq7p6fry9l3yPmkXOAq8WRMgQT4vOfrPfgl5pNioUPm
LikyoBO/NVfO4ch7pUZi84GnCKcT4VJPUT3m6IymBnastDHjMWissmrqUiiVtcmUQuW3WY0p
VLHePBW/W+HdqocxenqRQpVq7KY/h41lILEc8BO+Ej79GJHCl9Ad4U8IxEnz1POuyEkhp7Mj
/H5YaueQZLqUFgv4yR5cTgifoDUCSbKA5JEdORyS11lNj6ZTXFbCVke0hxHDMFTgc7YZ3/mi
+7I7ENBRLsx4fq3dC61/a3hj4vOaU3NPTLrrxx+kcTs6O4Jq6Q7eHrqD+3Inl0NyOL6ZqNIF
DVv3EfeeezuwwNtpuVNakg9ytWAxubU8gS+ntjrdl/ZGE5GvZKzG1mgwNdjNpnQv2gMtCn2F
VXpdk9mkS4+gw9CKxNd/wK8NpEfRkeg61zeo93qNoUmfWm3XNFmoynwVHREoT8+mB9M56TlZ
uYOyJsA012VKz9n8l0gmp6XoutSXV1ZRWZUeT8cx0whTvsGCHiUWVBdShdXlQ3IKMgpTM3Ny
M1Lz6KKc9Dg6htEobECNqpkHsnQHGe1qYZJPcDtITwLWJZwO6PorVu9/r+L9He9ueI5X9p1o
zdYZny5be2LZNv2lPfeNfyzxmV+mr7+7+ena9L2FDRd2Td52ZWNM7FMJQRnvZwjvmrt7xfhF
Q3cMO3tccF2yZfabdx4d/4X/NNVRWj+GX7w0ouuJnx/9fnXKN+lJLQU/BX70Rcj1davGfjz+
4uNf+p9Y+4ZGdfmezlkRH+e89uZrbWphWdD4zCE+U54OXR7w5PD1lkPrnvtRNeS1tw+vXLF6
Gf/n5HuORK5ZNTH2/IR6mf1YAyftvge3BT3WmFrV9evvw0f5nluz5+SY907JJ0xqGj1jTP5d
3341a0KN+o0TurxXvthk9tmZ2dmReZLOlo/wm1lIzry0ZdCWxo6Onn9uve9C6K/3criQR891
kGKwCJ8OB5OGe/ACeH6PvT1j7uni5Y8dO+8zeXj8w9IH08s7cAyFx/CC6IB2v5hBV/9RVWSR
XBz5+/TfNydv2JO12ZOuQQiRvDL6Trqks7izcF4++wxXazX2e/BvmWpAq2nsI3RbmtONyIvY
iRCVSkChxwlEkJh8vpAkeaX0KFrtmNOcecPYDVpaWgbaQG+9BWc77YvkjePJaImDJVfULyG5
KEpitKuUS2JXHdK/qVj8xYk6YvE6+7hHphR8Wr/idOmWtGWNHz9Mr9kUmPTLQ9YzltOt+0ee
ffXsCc8H6hMUR781xQS11g2dKVh75cmMXavf+TBjZtM/tEeW7dtKvLqv+ufCq2Wvrsyf/El2
0wvkhaqInwflzMq+MuQ8b/IDMX7imbGFPUselY/fu3XlBw8nriOa066/oHj6/g+V2+Ja971V
/AZ/94Lp45fOPJX60dqXzzwfvuDOj/6lPDVzhmf4imvUqs5NX9ArdzXlrtXtvPN83u9nPvn5
8sw5TyU2vEAcHXpvwuXjP9gPfBo9gtw8JIVemTtt2B2qiN0d1MTjdWeeaFbOOjq5JIGyJRhi
Z8uWiBKUc+gOAQll7JxLGdt7bsHVGXMqz/XgMrbX1WrQ2ulZf0mxSKAVTNJHul7X6alqQwN+
gA6ORd+eSsfVLIfOTU/PoAEGMdWsd0rb/xL52Ovcm1z/w2o0/8HtsXuEjyxvb/O/pph8zTo/
5befn1sy/6mibc8duXtB2pBMZcRjrb/NfDGyg9w640jITu7hou/3LbvyOy/8p7mSnmjTqp8a
hu+LD/omIfIX3mKV9sLXb/ovvOi7POvzXEuNeeiF9YViumT3W4/Qy2RHph+6YnsyoOXvD+1Y
fEA0l7oYsS7rx2nvnLYTdz544tPHvj/Z2v3wb+snzx++643IV+uWvL3v/o2PvnryteT3a37P
+vjYtMe/jei5MG3qkdmi6fbTXqPVH/xIHFSXPifM+ma8/PrMZw5+O+Hrub+cXO4ZueiFM/cH
7j55eGU4eeC6eq3v45lLotQZV9+JXU1seqv68H2mxIlzLuWa2v+544Kv9HtHNWoHi8xkyk0c
KjfOzlwqIp2ZynUpV0dO1t1/fPLg8z0N79x14uCOl7ft8V1KV6HL3jyoRc8X04X9O80gOgNN
+b7JGZk0nZ6RrM2lB9Vl6TWpgwbXDUodlJGZm5qbmZ2RqsvNSq/XZGRkDarX9imBapPum0r+
+x0vBebkRG9tWne4mfPkzUvggBXKbLHhKgjhAnEMUQwBjOL3bvSWSuek0rm4BGpcSmAtDacV
lxJY+IcbOKrgLbaw0zIkONwI9/A4NNEvnbkdHJIQBER+MvadyoMxFatHt3508er1Y7s+7Prx
19AxF6sPGor5H+49cuGra8smPnm3d25CF7/Q9/Tytvk761/+ZMf3nNqYbcNjWlVNr179kZiw
eNmDYUfFT763PKyAfnFNwIE3iyf+kjzooZWPjMvZUx72WvRhr2OnOrxezLr8avTBR2JfmPPQ
F/FhZ+rDF9yh7BnLLdttuq8z4/stm9Mqx/xNsNF/4cFw7Tab7OuTMxSeSU8Vrs24746n7hhb
0hKzoHuj14EHvxH5j96XPCF94uApT617fv7UpxLMP+599fyuwsCjdeVzttaEFC9auqapyxS/
/2p85MGL1IvSjT++K12++KspKwz3rcr+qInqnvthz57tS7LF3cP9di/1e7Fr3tFLHbtfro3N
D9qqnts6771fT6wYEfwPvwVnH17ZGDu/ceiLB9rLFWdFUaXa68884V+WuXXM5IqPRr2Ru6hH
+dnGu5/Pn3qo9fjGHVMfuc/4gPWl82t+X/lZyMnB13SHmu4QfTPzvo3rdz735j3Hnxrz/Ixx
R3yK605EXbo2bG+69EraHbo1OebJlSO2FTxa0Sl96K1Z4/51oOEBzSfPLt17cOERc/GXXcrF
Fzf+awPddGFKybpzT00/uEu0t3voL6/acgSbxhwP/mDHL4sPPxD2U/sUsuL10Dm2ze9PjB4x
ZFzQF/N/aNhbsjbt07iHhk9678KggsfCdz4mm95xx6W9p1JX8TiL1L9e+oxznLsamoAQmsAl
pglINAGNg3DtD+t/hL0bl1OJ+HHFgid+StGRwQFciMb0YDqwz6LYGawQhslM3YztrZtVZjMU
TwhdQ71Bq7HrKVWzvdFsNdjbUHGnc+hBdGZ6RlYmPRiKe0Y6nmbSaPqfO0P/UX1fucq48YtP
1I8nzZyqDP5y11df71s2OqZy/bufBZXHev7w97V/L11vpynv74Uf1jzpX7I4NO/xV5feRSs+
JqZ+d8+uCwuEnlc8eEsvLzgaeSQz9oEVP/3cEJZy7Z6z88PPny1/btXumOrDD/9WeFz83qTX
3tuQx1v96wvGJxo+Svi0qHrDvPe+SShSxr8yr6K2SnaGm/L7lEcfpU0P/HM8veK3WSeXbP4u
asmsqyd8/ynaVt1UtaXw0ZVqYlRxvXd8Yv26JWfeF8wZtfrX+9d6F/uJO1bef7G2tZtcHl4p
mkt40UUXt30eU7Rjb2rNytciWlXpLUef/mLofU+s0nC2hss3Xrvy9Cby3eg7a3p+5e95h5I6
6vvLYJG1tKez4vBpLny41PMBT5eofId78ngQf/NoL4GY7Qn+JFoh6DlLmdo851F6zsPtfh6v
dEweOSZ+yTdxvteSvpRUPzn+zPOrtM9r/vLw7PBqWx+walTnmvWltnE/C32VerqSaQolNPSh
zvxO1bwRt38udl5G36RFpRw3hBqXhqCmi+gCl4aQ+2fOxEiPfIbrbZ6HwdZeSx7ccxe3IPuz
c1vWt3zybtvoMnKj0j5tYpPM9+V337rnke3KD3xWL2yq2z6Wc6Sc8q1c9tmMkV+N3fHauOVh
X4aT817Z0frTQ+9dGEr+8NVbj0j4Bx9Wf3W52v+zipcfP3P24Skftu/+dvFPgrS53HOPJcVG
W37/17UzrcuU8ivCryw7g8pXLJoqsT65fdXgZxpS9432OF9314iApQ9RI74ShmT8ejR91PT0
4clW6cHzluE9cyW+X7wj0Sy6/NH2wO/LH5q9Lyt50nNvf7/zXmnePR9UW6N+oA/vaNXfNZEM
lPh5nPjYb+kvw96oH7c5Ne3sr3PnHR095rsVlsXGVwaXfvCvtrdfCppRl3hp9dOJgwQtIXWH
hkc0RXZclh5I2XE8f/M3v164d+vXz6+zZ20v3zctxkcxXTqsauG0CUX5fjs3b95Q1nBwZV5P
e1tU+7P+dP13eT6TQg4+Gx31Xv655HM7flYfTfngVEZ7qSJJHXv3hPNjLr3w+bIVh4eYd82J
twu8f5ge9fbTHbvja17fOGX4glXTNVtMq3xfePul4ss+5usPZhg3dX8x+uDCmEP1u1aEP+Cj
4wxPfW38I9vPRH2zdcNh7ZbWGv4HKmXlK4s3rGl9eXPnU80h/3j8Ad/m6LSMdSJT58SFcW93
Xrr/cNTJ7yMqDi3/oeT0FVJvXiC996Dh4Lem82uXvJue2OOxb+Jdp8pCV536Le3ZEcragKmH
fJ+7TncIZ9Ad/DpHK/B49ARuBdz+twFz5v8lpTiDppmETLydhOy9I0iHtpGbQWcNZppGNp6m
02j6H79j6eDc2Ds4qHdwoHdAzr18+TerV5hy/SnTSx1eZYPe/On1cVEr80KTpp6bUPnSdkFu
CK/kzdl7ZBGf5Uzd73NKejn3nWWCDQcHf0j6pee9v0Depntg1uLJscbXni155lzjpBP/Z/dn
B2/i0jm8/uZK7XVVnOuvT4s8lSDF+jKt7IVRkJqQ/vPVHAHnN7tsj71xRI+5dHXG59O5n61i
Fop9cdv1wCJlTV6KacWyBcn8upcdJv94fI+d92pM5VJPzee8+xYIl++bYvv+92PtKAF53zCN
RVVFD4SstnvG3Xj71nli883qTdVt0jftNvbEvuj0b5H6tFA/8skEa911xhFHt9v9M7q8mdl2
46b1kyzqLs1t0PnqFzZR0VT1sGVeSn3wrjn8ayWVW05/2cXc1vs9/sOFoP09U9r3HFAsUY2X
0Nh2Rl3DQnWGpZfZ+ZqNk9bJKC9fmfYmUT7roYbn3PiOR6qxlxW97YKObA23V2H+cLEqWv+q
8uOCWP5At/LNPxge7lnD1BR/+4Do5r3SV0K9n1su5H+p7LlHYodLjeuTg4eLqh4UPVe5v99t
5tH3h2TCbzf3vvH1NFi+uu/+m+j56//c3ZD26OD0xuq31956P/fUXC6ssWx5bXrDs66kivhN
+i3Xw+fE7C/X0Pj4NvewRr9Ov4O5/8GHrS6dRzh9jl5Z6qxfMvV73o8KhQgd4diEqbPs/I1b
bm3oEL83z+/LtA173BbkzLj04FpHD7zufAusO19iqf4QlSfWfokkXIMIEwuPHBdDMHgBgTOD
I2q9ilEpI/d4inStmAwnOO8UYfV7+Gr5ccOLyp0mBlGQyg00hOq/wHeBd5snSYM+wHwLzLXA
zArvlMQbGMcbGYGruTikai7IIMDAD6macyKumsNjfolB43yQ4xVYGqcbNE4xaJwIDyQ9ZoPG
ZgN7mHVMjGLGhLpZoN0tQJ9l5iYWVSYXFOtllOQaOMANYDIwkTNSkGXwYUhlSAev1YgHr9WA
rO2pBPKKoauOUuFrr/QUZLF1xNI/tS2d8SCkUkrv8o2SdKXZ3NMEHyZPmuk0rfZSJc+Eg6nx
ejp2Pw4XXcxt/rfP/gXXKev97isXf868nbxfyXTp9NjUlgm13W4BoTd4JtVckvKW+Wzj1B10
YcPf7Md27Hqas5/ZSi+9slW2fIrlo5cpJ11sK6qUPwvXLptQ0tz75bQak5vWoS6B3UtWsvLM
fpvxK0Nv6gIte63sCM9kec7MvKgZ0540fznQ/9lN+94f6wt7Td/nqa57ul797YW7n/nWz9SY
PsOXz5b7E0fnNfnDRhKPPhzVPRc9b4unJdcxrkPH1q57uunmbdGOQNcIC6NCdan6jV/Uf9zT
sVLInLEpsjMjL3/59pLDDqxsyxi1NOya7IV907gPbPb9+rC/XiZftNZ1edlTB63UxYdjg5La
Dssmm01vu3/r849PYgtnqT88u3T6hXexyY6Po9nntNuxlbNdZNtYKi+yLzFx64c7x6RZ9t13
PM6n8e5eqv6b6d8Wxky7wXBtodveyM/Tl3J6ewjMbJC/wKB5dOPspfau5XKmxy4tWjS/qkrp
l8dU+dW/3ZUbvs77sT97u/f0R69LK6TevDKfWSnh/f/aZuWM0mfrf/3pfs3d8CrTev0fg7cs
Pn3375fmJk+0vTg3zM9/f0O40sIKQSPFqveOXBvtf684syT24MKO2eGFYX4ergecTs4ui+Zq
8Mj+Wzn/4N7c3KyTQcXCvFUBZw2bWDYYNLGsYWJkNGicOtAVF/bhQMTkyILGI6DCB5qIOZkN
eZBnXoCuQPC4DfkMkGVFDZQRGlkMgUXbjDNpmTOyXX9/V5v/bp1tl7cL0xFhgxQkLTyGYQYh
C7QaNLAuCQ/BPKlnoVqDCs6cHQLfnaaAVjezNDEyiC3dOL+Esb5ywePj5Unza5cK/BPpO75b
88T+JWuOPze+kv5mtxGP1uGda09xmMsoH7Lrm7LzgM6OWI/ViwTdj1q4LtXP7pb6vG+Tjcwq
0VA7w94rKw3ZjhhP6E6sqFbmUFjZYmLIvFIpfEfb0a39ye2TXkffvdXq8pk7ZOrEch3jnZcD
7BcGTm76vE/7zj6jO/7vi7adfB+vXhytE7fyjevMT+/FbHwc5Usrik2/HZ0cWn3sRbZrckiT
+atAH6sP+mEy0W9Msp6n5Pys0yyZqBZVZF+yeOWT40ZNj+LMWs2/TvqRWL9m45J9z9PLr+4K
PfqjP2Vdwc0zXNIdBgudL2+x1pR+MvPD6YTvKzP/Lmxi0gA2T1QQccRm2MQkChQSBCfNvgHr
iGOfaUNKk7EGEshJkhsxY8gItBwuw2rIDx44NjM0NTIEgSiMFGkbqlDtN4V3hqBa9VuH1XWZ
LncsWNG6TKC0Inop5dim7btNZsxbUX4p/ZRB7AO38roL52p376lZcWKvgRFjbr1/7uveVeW8
RivSL13L/2zokHy6yF2rb+UpxaMW8r3rhfImOrQ8C5/jbDA5/MGO4P6vnlt1vp3x+umzUWeW
u09lx133TUtObvv05Win2n1D7rwwSxexgyXPf7huMAtyeLLsV57U86Lz4eFMJy8ES4StWcLq
0mvFOD2i0KGY+8yttrZk0fU9QnObq4JCDktPe2T/tLLgn4vx79mL3rO4XDg9N+ZO8m6ex8Xq
2jLeDkXRbwIVncJOB+XvzV14g+2qxqsrv8/Y7UvjWKD1/pFWY4Tn/NmPNWZ5mhxqbeLNq3tj
4NW/kul7wuO5DADNVMXzDQplbmRzdHJlYW0NCmVuZG9iag0KMjE3MiAwIG9iag0KPDwvRmls
dGVyL0ZsYXRlRGVjb2RlL0xlbmd0aCAyMjY+Pg0Kc3RyZWFtDQp4nF2QwWrDMAyG734KHdtD
cZrLdgiB0TLIYd1YtgdwbCUzLLJRnEPefrIXOpjABvn/P/Fb+tJdO/IJ9BsH22OC0ZNjXMLK
FmHAyZM6V+C8TXtXbjubqLTA/bYknDsag2oa0O8iLok3ODy5MOBR6Vd2yJ4mOHxeeun7NcZv
nJESVKptweEog15MvJkZQRfs1DnRfdpOwvw5PraIUJf+/BvGBodLNBbZ0ISqqaRaaJ6lWoXk
/uk7NYz2y3B2Pz6Iu67qurj398zl791D2ZVZ8pQdlCA5gie8rymGmKl8fgAH/G8nDQplbmRz
dHJlYW0NCmVuZG9iag0KMjE3MyAwIG9iag0KPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0xlbmd0
aCAxNzkxOS9MZW5ndGgxIDU3OTc2Pj4NCnN0cmVhbQ0KeJzsfQt8VMX18Jm59+7efd9d8thk
N9m72ezyWEJCHuTZ5OaJEHlDyCKBhBAICPIIKPhcq4iub/+KaP2LaFXUqjcP6RJsoZXa+kD4
V6utbRUVq7aN0P6sT8j+z9zdBGjtp9/36/fr99hzc2bOzJyZOXPmzJlzryQCAQArJjyEZ83L
L0yZfsXjAKQba9s713as//H63eUASgHW/bLz4k3ykwfevgUgdBxAd9GK9SvXlj2cFgSo4wFM
6so1W1fsvGb7Huw6H8CxpburY/mfmltexrH+jDilGyscRWldOFYulnO7127askyny8PyLwCq
V6xZ19nx/Q/3tAFsxD6+grUdW9anTzU/gu3nIb+8tmtTB/eA0AFwaDmT76KOtV0Hq5fvArjr
FMCkpvXrejbFJsAObG9g/Os3dq3f3ffhHwFmDACY84GtVQ+gvvHkxqW2qr+JLhEYPPje2Aks
f/3a43/+8unTKyUQ52DRoPEzwFxfPTwT6iX48ukvL5VgtCUBlvtYjf1uKAGqVVCQQIHrAIR0
nJcBx11PbgMBROFeoQgHcMVz7r9gBXWIAjXpeMqAPwaTYgdhywWaBAjzZ9TLOJZXzhFeHZ5D
ivTVpE8BEovFcNMCwn62UkjVJUSi5TCSq/QNWAL/B4Dwc7j/m3h0j8POr+m3+18xP98DTf8r
/ejjsO1fMf+/G+hhWPvvliEJSUhCEpKQhCQkIQnnAtkTG/x3y/BtQXD93yNrEpKQhCT8O4FA
bFBElCDpN5OQhCQkIQlJSEISkpCEJCQhCUlIQhKSkIQkJCEJSUhCEpKQhCQkIQlJSEISkpCE
/x/BMB0e+VeOx3/wj79v9fcg/PwfefjffnO/JCQhCUlIQhKS8P8ccAl0J37lfBOWkCKXAg+t
WHaAhDUUcqABZsBcWA4bdYqcw35fHbx/Xxd778xzSj3W9fe/WR8HojvzK/eEUkj8lv1ZDIi8
8I2ijx0hClhS8g/tU88pLfjG8f4Btv/Pd/nW8L9Nu8oF2zb1bNywft1Fa9dcuHpV98oVXcva
Whe2LJg/a2atUlP9narKivKy0pLiosLJBfmT8iYGJ4wfNzbgz/XleGVPdpbblZnhTE9LTRnj
sEs2q8VsMhpEvU7gOUpgYqOvqV1WA+0qH/Cdd14eK/s6sKLjrIp2VcaqpnN5VLldY5PP5VSQ
c8XfcSpxTmWUk0hyFVTlTZQbfbJ6uMEnR8miOa1I39zgC8nqkEbP0OjbNNqCtNeLHeRGZ3eD
rJJ2uVFturg70tjegMP1moz1vvouY95E6DWakDQhpab71veS9GqiETS9saKXgmhBodRMX0Oj
muFrYBKonL+xY7k6e05rY4PL6w3lTVRJfadvmQq+OtUW1FigXptG1dWrem0aeRVbDdwo9048
GLkpKsGy9qB5uW95x+JWlesIsTnsQZy3QU2/9LjzTBEHd9S3bj+71cVFGp2rZFaMRLbL6gNz
Ws9u9bI0FMIxsC/1N7VHmnDqm1CJzfNknI1uC7WqZBtOKbOVsFXF19fla2Q17atl1eCr83VH
Vrfj1mRGVJi71duXmansix2DzEY5Mr/V51VrXL5QR4O7NwUic7f2ZyhyxrkteRN7JXtcsb1W
W4IwW84mukbbNEpjZ1Tz3FHNEiaRbxoahCp3yihJqw/XVMaSrjKIdJYhG0KIYC91Oe7IKtVQ
3x6RKlg9668KfsknR/4GaAG+oT+fW9ORqNH5pb8BI5mdjJoato/QajCoTpjATERfj3uKMlZr
5ZK8iRdHqc+3XpIxQ/XBbNRtR6giH9Xv9bINvjGqwDIsqOE5rfGyDMtcfaDkB0MqbWctB0da
UhewlvBIy2j3dh9a8oB22FNVMTD6Y5PSxjR2V6gk7X/Q3BVvb57na56zqFVujLQndNs8/5xS
vL1stC1BqWPqWzkXTVDUxWmtaJSLR5lZodWs8n780WlGvTyqF9EqtRoiN6lS+3nxNGT0er9l
p2jsJOulZWe6JcRUK4LnlivPKZ8jnjnCocB8gDbPXxSJGM9pQ1OLTzgtkaHFw/xWr1yvwgI8
mX78icYOljEMuVQFVVbPGND+4lWJ4jmMrgQdQmDWmTexCR1dJNLkk5si7ZGOaCy8zCdLvsg+
+lP608j6xvYRw4nGBm90qU03hVBX3aQib6KPtUQiy3uB8+M0iquXaERp/Y0hdVYw5FOXBX1e
X2sXrqW3Asze+e31SFGo6/WR6+f0KuT6eYta90kA8vXzW/soofXtdaHeXGxr3SfjVaHVUlbL
KllBZgVoJqiaPipq/K59CkBYa+W1Cq3cGSWg1YkjdQQ6ozReJ8UnCmgTKXi/dUb5eIsyws1j
nRivC8e5xyW4RWyRWMsg4I0DWmMcerEwv1UxlioVSqVSTWsoaoRV9WHNIPJWEuivJjXE1Ytj
ztWqoyTcW6m49mkjzU1whpGT1YVH61ByxnbWQDhffOELzqxgwaLW/mrA8bUUOeoYME+LQpx9
hjTHxOx8YbDVTCPN89ACWaOxzGU8q1lmHVXiU5f6tnjZ6tQW31YvVvpUGb01MvXCVHcoEpHx
8aFWOlta4ylrIhPdOFJIDS8b4XW50SbOFM3YVbOrfjfzIaOzXTYy20acjRGRkenUzq+dDaVX
yQUs1X408XungC8+P97S8UkjiyOL0B69ahabOCEHFq3ukDYCSrJTk4Rol1MnxgQr2FmSmZND
N+mb3ktnBrWcaHlkuq9xOXIwxEu3BDfLKy8PMS4fOzTM8P8pEzmLiV0k2uARqXKkRBKl+PGN
qCvPLXaPFpsYYozinxR3E7gW7ch61dUudU0oOMrSwdYcwbNdwQ54hdZ5KsN2vHamquHODhQR
75tpnT6smI4VcuuyuAbZRR1hkVNnB3ZjWk7MpF4UPGdI9AkEXRQOxJajhmfL7SG5HX0ImYPK
dsmqgLm8AsMnXwfzG7Pj65mNzh+zjsg87Ats21yqHv3Zio4uH3OuKrP3uPaZjDxKB/NaVXBF
Ij60IRTR34TMOHxA1QWmsQx/1gd9HV0sslvBAruueMiB4mraYaO5Gn3eELJQv6ZLVBwetGUs
6YywuLGtPYiasEccEbk8gge+TWJ/BquzpR39mizJTbK21R0uLKESprFSCAeKMxr8jBH7az8B
dW2wt03vP1Oj/awLxplFbVQtiFBnj7DotR8kNgRVml6GjWzxZO4i7V7AjWLKE/zTUL0KWpWL
9cZTND9xbcT7T2NdXSMbFu+GNaGRCwDtvddPrp99tidcrDqa517gQsXm9c7fVmviJrKH5kAW
eLggNwGqMJ/Qp8vyRLlx/QGn5+iz3Hg4hki58X3BLM8+biyX1VfpUaKcr9+RWmirzeNkdMH5
Wipjug7xacQDiDws5bKxXsL0KsQw4tOIBxCPIuILGaasVUZch7gL8Rhr4bI4d5/skWrHchnY
NwOXYOPS4QRiDJFDOdNx1nSYhbgU8VbEXYg6jY/VrEO8CvEA4kmtReHS++4oQtnT+27Usv7V
awq1Yke8uLhNK/YvDMXzGXPiecO0OFtFnG1ycbx6Ul08Hzsxnjv8hWGWGy2FB2vTuDRcZBoK
vh5TQg+BjRDwwANcKqiIlNMlahTO0Z8bKNx1gOOBcJQj+O7liR3kSJ/FXlhrpDF6At/YPPRj
OhRvoUP9Vnvhrtrp9F14GvEAIkffxecd+g5cRY8xnWNag7gL8QDiEcQTiDp6DJ+38XmLvgU2
+nvIR6xBXIq4C/EA4glEPf09phL9HQvytJTRNYiU/g5Tif4Wl/VbTG30TaTepG+iaK/2lZYX
7tOIYH6C8PgTRLorQTjSCqP0l31fjEeLCuBOo0Xt53KgGoq4nD7/ZDQ/Z1/VKk+UvtcvBz0P
1BbQ10BFZG/tr+HMr4GMOBuxHXE9og6p15F6HcKItyE+gKgiopVhKiHK9EXElxFfhwJEBXE2
okiP9uE0UXqkL1DnqU2jr9CfQzpq/DD9hZa/TJ/X8pfoz7T8BcyzMX+RPt+X7YFaE7YD9pEw
lzDPx3aB/qQ/1+GJ1drpAdSdB9N8xBrEWYhLEW9F1NEDNKdvuceBg+yHF0VAzj74SMsfgQdF
UFZ7lEA9GqDMkkDFd5DCZJe8K0CVwI57sMiSwC13IMWSwLU3IcWSwKVXI8WSwJqLkWJJYPlq
pFgSWLQUKZYEZs1HCpMovf+HuWM9pbMuJHKtjV6CWroEtXQJaukS4Okl7IEveCbb9/omTECN
3asEx0/whDG2eZaE55LwgyTcRcJXkvDVJFxFwktIOEjCbhLOJmGFhPeTMlRFmCgD5xTLFScJ
v0jCT5JwDwkHSNhPwrkkLJNSJUq9fdOKtKxRy/pr2aHD/DvV6H1s1Isa9aLNe9EnHMD0CGJM
KynIJOfEmTOyWZ7TP6EmXp5UUbgOj89z2PE53Ibn4G1EHjfoOTSj53CQ53AAG6Y1iEsRDyKe
QIwh6pA7BwW/VUttmOYj1iAuRbwK8QSiThPnBCKFdQkRn9YEY0LnJwSfhcjT5/DJwcdLvUqW
5JaC0nncrW5iyyazsmPZtBTS0thXG7tojxLL3s8sn39mAUOtgd5Cb2Wum96WyG/t+wJdN9nZ
F9jvqU0ld0M2j5ZHyiFA/JiXQY9WLgG3yPJicNMnMC/sc7dgN1tfYKJnkFhZr72eL9zHPR+5
oxTJD937PW/IUZ70eX6FNU/s9bzmvsHzQn5UxJpnA1GC2aCsse5zl3mefFFjvRob7u3zXMmy
vZ4r3FM9F7q1hq54w5IeLCk2z9zAIs95OF6De5lH6cEx93pq3Es8VXGuEtZnr6cARQjGyQko
7Hi3NqkvG2sGPCULFpRGSbcyUb9D36qfpZ+iL9RP1Hv1Hn2W3qVPER2iJFpFs2gURVEn8iIV
QUyJxo4pQfbRL0UnsUzHs5TXaImylH0fZK6PiBSmgzqGa6bN8+pIs3qwE5qXyeqn83xRYsQX
P8FXR/Bmheb5dWpZsDmqj81VS4PNqn72Ba29hNwSwlqVXo+vLvNboyTGqra52CeWfUCIfdvN
LpaP23ZzKATOtItrnDWOant5U8PXJO2JNHgGnOfQWXXqjuZ5rX0ljz+eVRdSCzU6FkO6Wf0P
9ilmH/krOdnYsI/8hWWh1n1cNflr41xWz1U3hELNUdKi8YFM/oJ8aDp/0fhEvKUZH8hidpzv
3jifH/sjXy7LkM9gAL/G5zcYND6eML7entzGht7cXI0nXYYejacnXT6b50U/8vj9Gk9aGF7U
eF5MCzMetVpjcbuRJdutsZBMcGssbpKpsbScYclPsNwwynKDNhNHzvC44zyWYyM8lmPIE/y2
0FUXDJL+ylDnYvYZq93X2IXYrt54cbeTReRyb2co8X0r0L6ss5vlGJOGfF0NaqevQe6tXPw1
zYtZc6WvoRcWN85v7V2sdDX0VSqVjb6OhlD/1NnFpefMdcPoXMWzv2aw2WywYjbX1NKvaS5l
zVPZXKVsrlI211RlqjYXaKY+u7VXhLpQ/eJ43k9NRjTbdozj69Kk9dWaDVd6nVe6BjF02QOm
YEg1++pUCyJryqvNq2VN7C/7YpOVfatMNDmvrPS6BsmeRJOE1XZfHQQ3be7ZDM7GVQ3xnx4E
rNq0mSk8ngZ7/hlgW6OqdDT0bAJoVifMa1Zr8OW3V6/H2na2JLVipM5kaozGDsYrJ2FlBavk
uFFGVlfF6gyGBOM/7v/mRF7PTkGY7u8nSjbZBD0hTs1unk/RI8xPfBQaxMCK3RU9IVxgDwmS
npExEmIHgxAvA1vzCG7anKASutiUyOM9sUvPiEpGgSkrOKqxTdqwmjqDi1trrdwULh9qMXYu
wDwP8zzMCzEv5PIVR8DD0VKPQSz1mIwNHr2uwTMyaigIwiBkIGYKj0IGHwAnQOwDxA9ZPrwq
9iFrZzn9I3rNaAIB9sCTZBU8CQfgp+Qk9noa9sEAsKiqAe6Dy+FO2I435SKsuQHm4iNg/Z0k
IzYA+bAb78rdcBh5F8KVMAhpxBn7CK6Cbdyr2GsbWCAHFzMb1sHN5PzYZlgMb/PXQCmcDxfB
ehKOtcZuid0R+z48DPu4X8ROgwkyoROfw7GPhV/HfocKWAx3wT3wNrnD8AwoOEsYOf8TNsK9
XBtPYitjX6IEXrgEZeBhBhwmB2kQR++CD4iTXM7V4ygPxdTYIeRyQxt0w70wSErIVOoVFsdm
xA5DGs6xBUe9B/pgLz5R+BG8SczCydj3YychAybCNFzPALxCDnLDp68erkGNCail8VCOLevg
x/BzOEp85Cd0nWAWCgVFuDT2GqTAZFiA0j6KPf9APqNX4nMV9zzfFKsDK+rldqZt+Bm8QzJJ
PplFWuh4uo7ez20EEWecjM9yWIX63omjv4XGuJea6RHuIf4J/itd1vCxmBV3JADfg/+EnxAL
rlQmPeS75HXyHq2nS+n36Lvcnfxj/C/1HbjqJbAWboYn4DPiIGVkDrmAdJPLyXZyO7mHHCZH
yYe0ls6nF9ITXDe3gfsRX4fPPL6Hv0a4TrhR9+Fw6/Ch4f8a/ixWGLsO5qA9XI3S3wX348r2
wRH4DT5vw7tEICZixUcmXrKAXIbPleRm8iDZQx4jAzjLUfIu+Qgvtr+Rryhe21RHXRhLsYjK
Rzdi0HonvY8eweco/TP9gkvncvBlt4Sr4kLcOpRqO3cbPs9w7/CZ/BE+hnouFHYIu4Q9whPC
T4WTOrP+uxgwvHzqodMTTr81DMPXD+8Y7hseiL0DqbiHeAfhO1wVSt+Bz2rc7x1ocU/Dq8SM
usskE0g1OR81s5SsJhvIFtTkteRe8rAm+1PkWdTSG+QEymyhbk3mSbSE1tFZ+CyhXXQDxnZ3
0AH6Ov2S03MmzsalchO4qVwb18Vt4rZyOziVe5n7Pfcu9yl3Cp8Yb+Q9fA4f4IP8VH4pv5m/
n/+A/0BYLLwkvK8z6tbqrtNFdX/BEKlaP1s/R9+mv1W/V/+a2I7W+Rw8Az88+7/pkWPc1Vwj
9wzcQov4DHwregXteSks52ZQtFS6h1xPryADNFfYoquklWQmnOQDqOvn6S76Ka3kZpBmMg9W
08nx0XQp/OOYVfHPwRD/LK7tFRx5i85MrqQndGboI9rfHSc/4wr4IPcSvMm9TfT8bvgtbyTp
ZIg+ys1GK/gRXy20gpe7D57iNpAr4BnaCGD8SrwJ7XgmeRz9wnxSSD7nYvhCPBOtqJR7D66B
C+mvYQjP8fVwN1nOr4RboIhcDh/AI3gqxgsX6SboUskLdBUfoWPIAFD+Mfa3z0ku4YQUuJa0
cffqTtDfwGY4whvhLe4HKP0R+hQ3gz8pzCXdeAKugOtgQ+xq2Cq08r8kK4EjLeDnj6F3u5wr
5L2YX4VeZTH6tL14ugfRD9RyM7DGiZZzPtrFAvQQ9+KzE/0Ejxa0Cs/4QvRir8CAbj6NwkrB
StDrAPAvDc+FRbFH4J7YSrgodgfkoT/YHrscR9wD78OtsIdsG74M1uPb6W/wbJ8vNNEjQlMs
j0bob+g8uuPc/UVt+4kT/ojPU1ioFvZDhH8D5kFN7KbYr9C6x6GHvQeWYfR7HFf5Mc5wHncQ
ioZn0t5YE7ce1/s2zIk9GvMQI3TH1sAseBYe1gvQoQ/iHqvkl7jey6CLzo1t4rqGV6EebkUt
sL9pvxn9zw38Bv4a/gu4Cc/8DvQ3D+C5eRxPDjv7oH2ER2cosH8noIe6AUqO6/RReo8yBgT+
OAdGPX+cQIaoE45T7lk0MgO6nEngDEqfVp2umil9UjXjdBXUIC2dwmRygdfutfsxwSAfTsnc
wVOKAF+BzB9k/xJARV3cineYAAbYoW4LtvbqtC/8FIQofVoxiVU6o6GCr9JVEJJ//PRxqDn9
hxpXr1trDWArBZ3R9BJnqBDK+CooQz6uilKZEPKS0Wi62rt7JwbqKFVb1QxpSDqOQxyXPoaa
mhnS6T9gkN4vYABFpCqpKhSaXODCbdIrOnzvAGdNTebhwvyCyaExnL3IznElRakflL5d/NAR
soYzkMbh/ac+G77z8GFcwxKun16ircEE/8HWgGqMfd6f4y8WorHPlZzA+GKTzojbgy+BgqAz
fWwQRY6joBerjDZD2EANGOkoqRZbseEtwvFVlCgWezHJMG941MlEDzKNSqeDbVWaYpmwp6sw
IXZHeTnDyQUkGHQpZsLrjSDo8DUrvgDpUHq5tgCUnSvS0tsKD+f9fvLhAq6fpJ88OfxRPGU7
cT/u+iJchQ2yyEy2CsUhe0i96M7KpoTapWwbiOm1UmwYzGAmCrRAeuyvuGJTgv4U6y1EUTwt
6QHZQDyKxUIXGGRJwtRos2Hq1GqisU8Us9msW2DI9GRJVpMpSpSBFsloscQJbENCsbZIMtE+
brIRIBr7dIANohFsHCS+HDCbNeKzATYeMGXjMEi1ZVcuZgYZj6JQb5hWJYptQyw0Y/ZZo5ln
/VZlCufS4wuqgK+ovC7DmemkOpPRbLQYOV1qWkramDRO5+LSvcRhxcQpur0kzWj3YoiHap+A
cDVpc/WCFOWKBtaASLKQ6FtDKG5BsCaIG1Bk9xamp6WnOVJTqJX6/N7CKaVTppQUB8YGfN77
yRdPLLoytKln5qW3H9423EvKb394cuOMu9fMfHL4ZWEwNev8ZcNHDj06PPxYR+GTUyY3fvTI
Hz6bkM3ekHeib7fhjkncbLZf/eIEU1yHFIl9bFt6KTtM+0CMfaqYmLJEq8VOF9Bo7OMBRqB9
fqyMY5TZwZoFm5kzAKGiwWQF0UCNJh3TvkliGjehxvcyLpOEqv7DQGJfPh/Zl1PxfclH9R7W
EjxlBw9KR48etDvSy4NBzUqD4IqfcMWjl00m3QKdlnJaymupoKViNPZXxccoatY4dGyPqVWz
HM1+jFqqZxKwTRfZ9nsYFRCIWTY6im1aIpg5IFYTiCKhRrZwNppGaIPspy3sn+XQFsUC2kSg
GzEmbVggbC2f5H+iGU1NVVV8MW3x1Zz1CuFSrgJqE1OoS+QvNl9n/gWq0jzNPM3Gjef9lonW
Vu4C/mLLFut2i2iiglhumWKdRZu5Br0izrDUWY076T3cDv0OcQ/3qF7noDartUCgKYJARbPF
UiCISIrmuba5RCGUiqLBaDJZLFarxPap3RF2UMcg3YMncHKfIItRMvkZswEdYPx0GY3xQ2Vo
McqK+SoTMQ3isq3EhLw0ipmNQK0Rj/DIcQbtOOMx/2ELyLb1EpGitOWHstAuhAUOfe+efntl
yBnMQL+KntV5mh2vocwMaQhLmWcVj7cxP1Sl+ayRJ1MaGtouTApuv+LQ9klOlk0uwDc/E775
ZeOb34/AHPsKLfZ1oLHXy8rKQqRZNWPbuDmLVFqvKrMXoUFbYp/3Wo2sUXsJtMRe2+stt070
lluiSJaWWwtLNfKZPKzNK0+8TW3c0AYb2khbCF8Hcb8sJgwvBfaBitq001qkPTXxE0vS0qeU
Eq/dZ8cXAftOjEouKEjLKMF4Utg/3PL0cKsw+NVfbz9v9ve4U1828S99VcIf+0pGP7ob/eiT
eCqdkEOv0vyo12GyEscU9yLPCnGthzdImrlqqV5Lc9H/a74MRf5EI8wjhGmEcERj7/Y7Mosx
P9mfM7bYzspZY4ulRG5L5Nj+6/6sQLwd+aVEztqVaUj4rdPd0+V5psXute6Nhi3WrbZtxutt
d1ses0VtH1o/sEl4xGS7LcVut9ltZoMDI/rMNKPOYZcsZsFpMKSlZ2Zkp/84dvAs34+3Fzs6
6engzWG3BTidNptVzD7nusg+67rIHrkunmnJDljv00VjH2puRDfi3nXsM2EGW7hOx1Ska5Nz
1+eGc7ncHCfVjHmgxTlyeTiNZkv8znB+450R94Og0476110dvso98Vt35PKYEb892rTrI+O4
M3F/MFNmN4ijHB0E3s9V5fnoGYg9vXy7dVJQuEJCsyZt53wkYI6iDQ1WMYqKrdwmVdgdFcwu
yQbNiq2xt5TMjHJ7Tka5A9GquMulnBRED2Jq+cg3AVefISM9yhUqpjUZGUBsaMQkB8ujV06N
nclUnrh40tJSU3R6vH3Sx/i4SRSvHJ8dq7X7x+fdTSOHXr70xVdnjFtwfuyTny64aGGet/kd
snvbjpl3PzRcIAzO+sXW+17P8ufO3Dy8gUy+9qYyk/70Zq6odOvU7uvQ2ptiH3Jvo7XbIYuO
0az9ciPlLX5LsaXBIpSklLgX0vnGuSnz3CvpcqHL0JnS7j7oeU341ZjfZ7w/5v2UE+l/yng/
65gn5knzeIKZVWlVmc2Z6z23efSTaK5lUloFLbE000ZLU8o090Jji2Wl5X3dB2lfkk+sEknl
rCbJBi63SW8HY6qbMznRiX0OFmZYaGROpDXjQwspIrB/xP4G8CXBbkPbPMNqi30yaqe2ET4l
t8Xml6SjdiLZFXu7PWznPYrJRBfEYxu7g1mZncUzdmZmdp3ViqkW5djZ7WViNma3SpKOleP3
jX3kXrHvH5Fub4t9k0NMhD8Oc8K4HXHj3tviyNVLiTrmLZidV7Yc0B/Rv62P6XmPvkY/S8/p
s5lceiezbX02k0CvXWZ6s+ZlMrWbMiO7ePZZpt22IRicwYz59Fkm2rYBPTfmGG5WHWd2PoSX
HqKdBZrop9sI86GuXi41yuUrxjWciVitYDS5sDiwxqS3aYFnsKbIUa6FPt4SnS8nECgpdkwp
KkxLx0iapKQVFWrGl6PjyroOXfWrzatfu6Z9R37/afkHmy9+eM9lW3Zfd/9NXz20i3CRObXU
+mUTdbz84k+ef/PlQyzq2YbB6vN8NdiJXrO3yvwxROKJjy/m6/l5/Ap+E68z2EWDaLCMsRss
wInE5NbpiQ6MhnG3iUTMkceQMTTHPuI97CO6t4/o3u4nwEJyqWhK8Un2nyJkOArH8PWFbd5I
2KPY2XYDP+JOEjEQ221gNpFms40GE6LmWmY6ph46E5VqG6BFpseltk824ptNTc2QHQP68nIt
sAfphe1W7W5s24jx5Q/BSHQGTmeKclP61uj07KQXFiYuq6LUKajedD3TqV6Xat/2YPWqmguW
VNfVVS5JyeYDuzecV/Ho2Kk17RtPv8Z0uJYcpd34rm+Cgvj7CkfmKVaD7mUZCvBQbzYvfJQJ
2jYE+UP4VtTHKQZw5mceZi8TxWwj0aXgtq69q3vVXXet6r6LvrLqzjtXIQ0kNojvtnvIq/j2
6PwRUHoCw8k/4Zad7BVIvoSrxAGJt8RL9gw7yMfEjy/AWh/B9c19BNeXu4SOM30I/LM+75+Z
B4YHSdOZPuK36CPCZ4PiWX2kb9FHghODUqIP+20/8SnhVSiG1UrDtsnkkslk3MSyiXSBjzT5
yNRM0pTRkkEbnWSbgVxiIOP4Mp66imQIyOPAZpItMCnb7fXaddlpnJWOM4MINYcOoXkUFeUX
DZH83w0VSr8bkoYKJxe0nQGvvXgS9eVYaSrGLEWpRdVcUWE2TU/krHK0nZ8ebPnuws07F/kO
7hXdoQ3bzptxw8ZQlji2a+uNMy6KXjv9ILa3bt4Z8nHTt+/rKVx4+4GVp9DNv1G0sNbvaVw3
u37N+eOUO/82cOrxsxnQdPCdhL+B34ASp0KFklNmJg06Uk8JnyvZZBu12dJT/SDKIhWNQdGY
GoQoN4E5GVxV2xBeW21D2prGeGWwS+D1lhYVVtMSJrhvJ3mK5BDv8AfDHw4rg5+svnNJsHD5
XZ1D/IbhPw4fH35v+K37i7p3rblo55LxibcjIR8lSYXdyuKdKWRrCmlNIdNSSIrD4ee5FJ5z
8NtNd5voxSay0kRaTKQR42KLxS/oUgSdRYgIZKtAymzn2ehmfhtPeckm8Hou1U9puk7vB4OM
L+5cCjuQEwYEnohGtkmHaooOFbK1FOJihoowImBbI8FPtgtBDAlI22jROVqeXOD12X0YZWLK
4s609KIpGHoWCflP6YZ/cOPwU/xTREccKS6RmrLTScYQd+Opzdx9p5bzG06nFS+TPSur6FsJ
3b+AK05Hf9Wq5KWkMd+XK2n/d8NccEtu2c253cYcp+gHo2ykxtSUFGdQrzfIQbaIPmJgS2BO
CCW3F+EqTh+ya3tSiGgv1740eDGI4HyapMyqMLRITUsn3rhH9/IvHP+V/zs10yc/OEjdyx9Y
X/XkY5ddeHoJqbzhtstuGFZJ6ZSpQfuwxP93e98B19TVNn4z2EOU4QK5iApICDcgAipogABR
IJgw3BiSAJEskyDiqIB7L0TBBW7rABzVuhGpuPeqtRZHrYO669b/OecmISi1fd//r9/7jfSU
5DnnPOfZ4w5KR+Lc3AGF5S50ViklIUXME8CHYt11Ywn27v9/UC5+Pmgr9cPM5a+HOe8r4+k/
PyzcTcM0TMM0/teM0H9kCEzDNP4bDrnFVIty0zAN0zAN0zAN0zAN0zAN0zAN0zAN0zAN0/i/
Oyw7/M0h+mL8pB9WvUzDNEzDNEzDNEzj/87AMKwH9QBG/jVXjNoO/WdlNPSXE6zRDMJUzJ66
DNP/1dco6jc6mG6EY4a1oR7WweYA/0cdbIGJDTiWGEH9QwdbYTPMzHWwnT3dbJ7+75JS7ByL
dDAFM3Mq18FUzMKpXgfTsI5O53Uw3QjHDLN1eqGDzTELZ/0fjLXAWAYcS6yN41IdbIVxnC10
sJ0F1TkO/hVbOvzLqrauCQg2A7CD6zAEm6N1BYIt0PoYBFsieAaCrYCgHai/6WDShiRM2pCE
SRuSMN0Ih7QhCZM2JGELLN21VAeTNiRh0oYkbGfv5PoewdZG8ttA2XwdEGxrtG4PYV8cwQ5Q
Nl8CwY4AbuUbjmAnI3xnpCMJuxitt0VnExHcHvEiaboZ4bgbwZ0QPmnPrgiWIdgPwcielkby
WxrxsjVat9XrshHDsQCMwFhYMICSsCxMAr7jMSWmAD9aLA9ToZVIMFMDGH4KwboUYTDBDhuT
gYFjfLCWCc5rMQ2aScC3BGCPAp9ihGkHRiyYpYNVCZYLVniIugLw1fOJA9TzAO0cQAcHdJWA
phQTAVgEYBXYUxv44AbpCSwQQF0Ms2CMgWQQAgoqgIsDvkLAB9IQYdk63L5glgVW4W4OkFFj
0AnaQYr0kP2pPBnIFjgWAebpYAeuCpElmupI0lHqNMURlxywK0L6wlkGoJ0LzqrRSg7AEiPL
4WBd7w8ukAlaR4rOKZBte6LzEoQhweSAJ7S0GH3iOon0uDha14AVaD+VwYONesB9LZBCCk5q
gBXYCJPUSK+FEMkEI0CMOEKZs5F2Gf9W9HyO2aMJVxhDmcAeMsQHx7wBvhRpoDTYzQdLQbbS
GPQJBnRhDDRSigeS/dfGuTX6McX6/5RY/zIOGr0UhSIhF+AqgD2gHzPAkOp08kO2VwJ5pIhD
AtrJAivQmhrkm0QUSWq0I0U5JACfjbpDm7GwUCwEePTLCId65wBZVEhLUt8MJK8W+W8gsjGO
sjEP2ZS0gdbgVz02XFOi6ILWhzJJkHxihKfS+Z+B8lyB+KiQ1ORZkY6KRDcXItoqpIEcYGnR
HjyVjuTQ+/Nz32h1J8hIUX+xkmHQgWGYN8bGl9ZRobkYnBGBOUMXJzAfSb4MA5/PNSA9lovs
JEKZ05zNcnWaSlFOyVD26DP9c9vDMzIEeQN8nyax2jx1UoZ/17bGmaCPTzWKfX286WO/OQ30
3L+Uq6dRDEBNSF20iJ++NqpR9uSh+FECKylQxRD+qaZk7AmbRBWZ+UrdJ6kVCcMapNJVIiit
3pt6OhAT1ruvxShZtRU6zzRS12eIVGdlNaqNUpTDWp1v4bWKvktkoGyWIS31Vm4a1QzkGSGC
xbo4+LKifZ4J3qiyQz17YP5gSFBFhjyyUd2SIK8KwRq0UCbA0O/562imfVYlfXTZ21gtNAaL
6aX5V/rQ36z7uOtnNOL0NHA3QzSPAGukn/RRI0E9U6brF43R/bVepo/KP+9n0HOJhszRGF0Z
kP4mo0Ci45WJYlmh8zsD6azW9Rmy9sDKIET2J/2sj2MyrlS6Ck5ygH2A7CsKQ6QIscZ+/nk9
+wd8YbCQEOmu1PUcff0Qo5UcYBsyRxqvcXDU1WS6mPHWy/jnvsVgH2vS0YG3fYxsJEZdRtak
znyp41fooeorRef02M1XN8Zn1U1v+89PQ6uR9dRYb71cjVdbjVnT2In0PmSgeq9EXDIMc4lR
hMC6RXpIA6g1dlhS6nQki0TXqXIMvjSuJaQP/XUe16AskRlk0Od101j6+1Y17vCklsadpmlM
N1oiF9lR/m/6Ud8N4NWgQmcZiZEEYvQJeTbaZQTAEBn1Du1X6jFZ+cVIA33H69GkigsBRSWq
OM1fX5PXf/ou02gffSdrtJFxTWl6SoNqBemrdJ3ezfdc4Z94VG3QXoOiVIGok1lEdl7jjv7v
RoC+v8ViHLTLw6LBLBV0Sz5a4YI1eN3KBzspYBYFVqPAihfAEOj2vZCnUlEfigV4yajHkTT4
4DMBzAeiGheN4WgOZ/0AfgKgBc9ysAGIBwdQEyBMPqIdD1bjwDdHhwdPRIKVZDCHcAyqgiS/
BHCKvFvg6noiKWkSWMcNGjaVios46iWLBzM+oB+r22UD2lxED8oP+UcjOMEgZ7ROUjayEaQM
aUYCieLQDK4mg+9EgCdA/NlIZ1LaBKRDNNgndeEgCSBnpk5XEg/aJ0W3A30E5YsDo1ErNrJB
LJKm0X6R4DsRSA7px4DdJNQheOBkFNJUgKzH0dkMahuHZo1akZ6KRNpAq0IbRAE4HvzEGGzH
R5+kLHwjak1tl4r2G7FI/di6z0hkOR6akd6IRLMk5Cu4y9D5ko/0+JxrKopEDsJiI40FhgiJ
RtFLSq+PTpIHz0gSkh/0rbEs+qjGv5IjJBX9frLO01/aBVqdjWwC5RIYOP8ZZeZGPIBgBeNJ
WRI8XqlQavNUEjxSqVYp1UKtVKlg4myZDOdLM7O0Gpwv0UjUoyRiJm5nFytJV0tycZ5KokiC
Z+KEecocLS5TZkpFuEipylPDMzgkTwTiXeBXMAPnC2WqLDxWqBApRdlgta8yS4HH5og1kFNS
llSDy4zpZCjVeIQ0XSYVCWW4jiPAUQKmuEaZoxZJwFeGNleoluA5CrFEjWuhHtwkPE4qkig0
kp64RiLBJfJ0iVgsEeMychUXSzQitVQFFUQ8xBKtUCrTMNlqKWAEOAhxrVoolsiF6mxcmfHn
1tEv9iBP8iWZOTKhGveOl4rUSiiaT4pErYFsgpkEgZDikwyUkOGi1MJcqSIT52VkAOlwP5yv
TJcq8ASpKEspE2oYeKJQq5aKpEJcIEQ6anBWaEiAgQOuyVGpZFKgXYZSoWXiA5U5uFyYh+cA
PbXQonAZ1ypxkVoi1EoYuFiqUQErM3ChQoyr1FKwKwIoEvAt1OAqiVou1WoBufQ8ZE29zbRg
A5herQcyIAcG/EY2N4ijUivFOSItA4exAs4y4Bk9A6BYbhbQzEiyXMBUqhDJcsQwsPTSKxWy
PNxb6kP6zggdUPiatKSroT3VEg20G3RTIwN43ECrJ7KAtxRw0Urk0KdqKeAqVuYqZEqhuKn1
hKSpQIgBdZSAFfjM0apAqIolUE2IkyWRqZpaFKSPIk+HDh0CCAL7ZEnTpUBmpp0dDKwMpUym
RCGgMzUDTxdqgKxKhSGc9U7wztJqVT38/SUKZq40W6qSiKVCplKd6Q9n/gAzTRf4PsC9KCw0
UDBIpvlMbS7Dzusw4iDGBWjmEUqgEzSNZJREBrIPmbtpLkNTNslmO7tE6BwNin6gNzCBBJzK
VAuBZcQMPEMNMhNEjyhLqM4EOkMbA1sBj4LjuDIdZKQCGkWIqok+zv6+FlAgoUajBJkD40Os
FOXIgUeEZNJLZcAy3pBiE21xga6cXPBBEoklsB6QfmgWD8+VarPgslG4MXThBqXXb8ukIE5J
3pCWmiyogANKIqghA5crxdIM+C1BBlHlAIU0WShhAen0HJi8GrioixKgoT9QXCMBFRpQgL7W
WalZUcmEByzJpNFZGgmRm6WUf0VHmAY5agUQRoIIiJWg7CJZRkhEWn2ANcYxCH6xFCVeDzLE
henKURKjrgDqH0wZJA9MMlVjpOi2NFlCoFW6pEnmCo0UVUP2Gi0IJlh4QfKSif41A8B8i+Xg
Al50Uiqbz8G5AjyRz0vhRnGicC+2AMy9GHgqNymWl5yEAww+OyFpIM6LxtkJA/F+3IQoBs4Z
kMjnCAQ4j49z4xPjuBywxk2IjEuO4ibE4BHgXAIPNB8uyERANImHQ4Y6UlyOABKL5/AjY8GU
HcGN4yYNZODR3KQESDMaEGXjiWx+EjcyOY7NxxOT+Yk8AQewjwJkE7gJ0XzAhRPPSUhiAq5g
DeekgAkuiGXHxSFW7GQgPR/JF8lLHMjnxsQm4bG8uCgOWIzgAMnYEXEckhVQKjKOzY1n4FHs
eHYMB53iASp8hKaTLjWWg5YAPzb4NzKJy0uAakTyEpL4YMoAWvKTDEdTuQIOA2fzuQJokGg+
D5CH5gQneIgIOJfAIalAU+NNPAJQ4DxZwGmUJYrDjgO0BPCwMTITXNco0T0SvF9RoHuRdCyP
YgfuOEaA+X10t6TfF+jub8TonkRMK6VV0fbTDoKf72l7aJubvAn6p94+mZ61m561m561/+ef
tZPvS03P2/9nPm8nvWd65m565m565m565v55NTc9d2/63F1vHdOzd9Ozd9Oz9/9mz96N7mCF
qEfo5/XojlbS5A5X0uQeFt3F0jvQWfR+9Bh6GPgMBdhCUPngdTpZr7IolZRyGobqJ7y/VaPf
AoM0dL8/jmGfvLBirPl/KLpvb/jb3GKZIlMHu2hIOBz8dGSr5QoGHpmnljHwGLUkm4HHCbUK
tlqYzsC/3INP5kgMRJ+CeIAft+Xg24lk57aIKHSbb27VdUrslFd2FAtqWaFbIVj6hkqhsGwI
K3MzX3satZ0ZRgjNrX3NKXRKYTCVQi8TEP0JhtGK66oO+a5YLzR4qNAqkRFhYw6Hg/AwIkZ3
ujLPsY1DqzaZhy9QNtVWXtsxZGnxxrLCNgKikF5NFNI2ltGoFCrVMRCIeLjMqjZ41P0/TiGB
DxN2BmkpZkCuXCQmLZlu7khNFrAciZZwYulonSrUZEkVmVqlguVA2MNFC0cLvkQsVyrErA6E
K1yxdnRufJRu9KaB5UG4w32aY5vG/SSpXOIn0ArlKjwxkk10aG3H6k6EEsGs4KCQINYgMA0x
mhIFVf+IZLaENdy3caSxeZGsLkQncuaWlCWED1mTBAKcI0joERkYQfgR0d3Zft1Y4J/OhCep
j2uz+gjIlwdEIaWjsX0pZhitkNICA+vW1EIKBVt2Myx8OK/YJn/YH09mKD9GtlrK7r+zZBZL
42bb7nLgrdOhe05hk6ppcUHPl4VsPOrYM6iusFrS0/dxXWbdrAm7T+5a882C94LK30eenJh8
cRfT/sXk/AiHEsk5Bjb5bUxM4usg8xUebetXJCm4cQGP9sw54tHD45NWOz48dK3kh45Ta3bk
RVvMucfdeadl3btNH/ozX3istHJZIx63R3wvo55x5d6qEy6vPR5jgkuR/RZOqikti1rf5djS
EeMdsuIG7n83csudh2fEDiOH9Kyfvd9qyjVOVN2JWXXrbveeWUph9s6o/hSxCtuxxXJpdeaR
fe9Xudwu+ZhLS1vQy6f/j/Wz+5UldRVKeztw4f+/mLK6kGIFLGJGuAGTutnTXehOtzvkXX1f
N5zRsu2SVvLySsXs08s3owhy86S3IVzynTy7vb7Gj1ZZN/R5N+rddt/KmqDtLYgkiOBOjyf6
EdyymDLOlEjd+waRWsaU6/3EFCnl/qpsKVz1173u0fgb3Ai9iJwIYpIJUIgB5pYgLc3MLCgU
ehzRl4jVzwnqlF46Brm5uc0xkKi/QllLOEJ5O9NhBOpI0iw/S0cajBLvbknZlS0+yq/vw5ce
X93a90S/ut52XU/vDMjeu/zF8WMfS8c7NASFDLqysSpt98sdK7qW7No9YOvp62foa0sqY3f4
WJZ+MLfccfDG0RcpaT+d/Slp3QRHfg/vt5u9eg19ECUJ1FjXfcq5+yLmN/vUXrMzR02YP2Jr
8LxRUrdQ7pZan0u7BrYfXJ85Z8jayxXtBpW0HkbLpoftn651ftS287Z3Gi6/+qbEMaOMtvT9
9g1PDqyqnX2t/kgL6Y8Th3S7l/Lg3e88jTT/Q/SxMZs+el0SRtoubFcw1JoVdtziRkNZq/CT
6dQj7MqLkuP942bfPrQsRe0Z+WLzmcLBvMSHs/kOq6zl4Quv2IY/cZ1OFJpTQBG7b1TEjtyf
/npMQeL9T6iIHTG2mg0oYt/8I6XCm+hCJr278b5YggukmehlD3AsfB/NQrUsmAhhsQIIMLqR
taxxSmj/Efl0+7Q/2f/LajRtxu5ONRZzS/PznN93Gf5ePY3x9sXqxdOKo3etPpE23b9HILPD
/NFvx210L6TsHHOi3T7a8eiHtSWv3tHdnk22/tRRUf4sM6zWq81db/eX9CK26NHtPc6zGhxL
g34OUSUpez7awrEiuNUH5hIltidGHXulWeSSe27m3qKjlpPxhg4bgp6OPPyLFus34/xP8x9e
Hv1x9tstw6eF7f/efWv64oO1k6rmbb1c4Xsh6V3Qj6dGLvi1w6dHI7NPTLAcpf3FoX/sxadY
XWzcaouguwPtPoxbVvfroNuTX14ubeE+Z92dSa2rLx9f6UY5+iF2veOCwMUesQGvD3dahW07
IDg+UeEzuOBxiCL/+d5HjjYP9dUoH1hkHFluOsNyY+jLcZYUQ6bSjMrVicvpk84MD33wKfPw
kPN1ezftqnFcQvDhdks6qEVrYggOy46wITsLPZ6XyGd1IwLg1MzRNyCQIFgBvqIQolt6kETo
1y00vZtft4DAEL+QwO4BfmLQ/DKEAQFB3TJETUpgrEJ8N9HsQuG3rYODO+6UbzieQ1305yWw
2QqlVGlQFQThAuIYRDEIYBi/afDDjwj2I0JQCRQalcBkAlyrGJVAzl8y0FfBr7DQErZQcEcK
5ROdSmCfpTOtkErBzF3cr6ceTqzz5K3qP/pKw+sPp/ZfOvT0TfuUBkGdNMbs0pETj269Lxm8
KK1liPchM47jL6V50/ZlbLq+9yE12XNXmOdotnzr66fYoKKSGa4nrRadLXWNIjaudTm6J2bw
S99uM1fOHRBck+Ba0fG4w6mrhQ4bg55s7Vg3t9O6gpk3vVzvZLhND2d+SqXFVysmlgU83LHd
PzFlqHmV86w6N9Euje3ty2O6tOhazFkfMDG8ODyVm+s5/WOVw9EZdy2d+9f6DmINDh1RvGHN
tOxib+XTI1sf7Oe0PpmeULAzqV3MnCVr5YcUXj+89nKva8A32lQ9PW1TWnRrxHLpxPLuV+T4
x8mXPtXsXtzd6mOYU/USp42Hppx8XFi9KblTZJudsZNHTzn75vzy3m2vOU2/N3tlVqdpWT03
Hs1P6HLP0iNO9GHZQuf4wJ0pw3lX+n4fMucT80ZV2prI7GOjz1TtzZ47UTZV/e2Dte9W3mh3
OfS9+Jg83PLuuIlVW/at3jP2THHKmjEDTrSKST/v8fh9ryMsm1f+4eK1wcrhib13Rc3jldnM
PPDNgD+OZk4VXl+x5EjdrBPKmPpDzKKGqj8qCfmjEdwN94tH1e23PPKx58utmmDzbSln2l7c
+7Lo+FTXZ/kjKLzv2hdotl8Y3LF3jwFtbk77PfMId73/T51nhg07+6hb1Hy3ffNtRxWGPz5y
1a+cTp0T++bxDeoZ2irQBCxAE3hMNgFroUtWN1T7XT+/gE1D5dTaakGX6QufMcSUti40EI2s
tkTrJotWhmAFYehL1s1OjXWTr1SC4glCV5ohFQm1Epydo81SqqXaPFjciWCiGxHICggKJEJB
cQ9goWkgAaf/uSvov6rvK8tlVTevxy7oOi6b2bZ+/63btSX9PRO3nL7RJqFTi9/PrT8Xt0VL
4C0fWlxKWuTMLWofsWDrkiFElx+x7N/G7n803aLFK3v6kifTT7qfCOw0dfmzF5mujPdj701z
e3AvYXV5tafg+Oy3nDNWZ4dVnK2MoK96s062MPOK90/RgsopZ+96RzO9Nk/hJfNt79AY70bM
m0copj4fSCx/+83lxdt/81j8zevzjs8tdwnk/B2ceStjsb4xGS29fDI2LL5zwbyg76o3k9a3
jHGyKlw5qSF59EdKqVui5WTMgYhu2PWzZ/TeI35JKys6jGazck8uvdlz4sJyIXWnm13V+1dL
t1FOd+yX9OmNWc1h3EZf3zcBi6wnWhgqjhlBA19G9bzZq0tYvt1a0Okg/qYQDuZWup7gTIEr
GFGwhKzNBfOIgtn5TvabC4f3SfFafLez4/uu9daCRQPvrCkXrRH+4+FZ6JC3xaW8b9naLXGa
AS8sHJkSIpFsClwC9KGyyDL2lN5//7rYsK0GHGEpRw0hyaghxBLRRJRRQwj5V66JoR6RJNW/
eT0MbO2weEbNEFpU9xv3d2zJvX46r388pYqpHTlYbuu46fSBsXN3My+2WjVLnr47lXoiAXdM
LLkxps+t1L0VA0pd690oUzbvHf1s5tlHPSm/3zow19qsbnbsrScC5xu8TQvu3Js94lJ+9a9F
z8z9J9Puz+/aqaPq3R/v74wuYdq9sril2tcmYfmcbGv1ot3locsy/Wr72z9IH9LbZclMvPct
i3YBb06y+o5ihfmqbeoeqMI+TbZ2vHnYWjjnyZXdrR8mzJxQG+Q7bPXBh/vG20SMvShQe/xO
HN87WjJkMKW1tZP9+R+dlrzs9X3GgO1+/vfeTJ5ysn/Kb8tVRbLNoXEX/8g7+G2bMek+j1ct
9elmntsu/VhYB7l74RObo4y9ZyK3333zaPzO22s2aIN2J9SO9GzVZZRNL/6skYOiI532bd9e
GZ9ZtzLiU36eR/4KZyLjt4hWw9rVrejocTbyvu/9vS9iTzIuXg3Ij+vSNbZT2qAHKY/X/Vyy
/HgP5f4CL615y99HeRxcWljtlfRd1Yiw6eWjhDsU5Y7rDn4b86SV8sOMANm2jzf7183yPJax
f7nb1FZiaphfxcC5u+943N1ZeVy0Y3SS2UU2M3FzUeXa0Zu2lxXntLu2YKpjTkf/gA2WirLB
szofLHs86bjH5YcdeMdKf+f+8ooiUU63GV8nrftV8WD94tMsn0/2tYOHXI1vX371rf+K3sxk
l+xjjqs/EIUWY4hCs3R9K7Cfd578L/U/vw0omPaPlOIAgiAT0ufvJGTjHQELtI2QACIolGwa
3dGURcDpf/yOpZD6Ze+gwt5BBb0D5NymJ2/VDq7MLVcV3xY6xHfb8+y7AR4rI9p3zb4/KPHb
3eYh7ejcPRNqbDvcCM7+odVVmychh0vMK+tCL1GcWBEXptvliad+UzS8k6xiBXfZ/axh528u
FWyzZtRUXNvou3WMVcWV4oHHh7czu58x6rcAfpdW/vc2WSae2R61a+jVI0xazqas5yfkz3sM
KXd5Eb3nlxDxZoU4aPS6MlELvwt9Fr6+/bOF3aUheWu5PvfsDpQ55h4oCnv87rbvIAf3+BTv
VWPUv7TqsYs77GpDQ+T8idfGbhs7pf218KpZQ3+bzpvU7lm5/8A783r6bQ0cULsr/GPAhe20
sKptFQtCvjm/PJ/xMiFlvkdQ55pQhXiCYM+yFlvaek468WIPbcrsV2lPzvIPziqauu+Qh7Zz
Whvv7056eYd0XhLat/uZcVULtrp6rt+Y8UjoPqLem7s8bdqtzkMvePQL5x/Zmdq7E+3JuTGD
/S953lYNbdE/Onf7a6x+32ZqYdr1Q87b97e/mNzvXmh5i/ue3H1tdkeN49yprlGP+UV9r9PN
g9EltY8Pu6Zenzj7UTyXWL9pzs1Hg1dWvL9RmXGrenHB2IbLDf3ucX3WO3qvWz8+M//XGemj
07b5T7qSumzIwVxv76cN8hrvuYy5fYJ51fWTo6YfsYqrvbg20l+76JXi9Wh8AMNx6PBFpeG8
wEk/Vk5r/fOKhBfFlfuiy2RLzv9yedosQ+9sAL3zfjPtr7F5Nntf0tZwwIlKt+1gjQnQ+6NI
jN20r37RlI3veNR+PaiseZHfO5kl1D9Yf5R1znN6N2IQ2dzgA1ReWXxZvyncf+mhD8hbkLUg
WQ03JWlEYFpAAGpzw4zaHJ9IJBKM2lzE32tzX6GvJQpWQuFxesFioqCIKJhvMBKTRhRMJHrr
2VEpLoF/dZslVoo0QDOpXKjOE6k0zCytnOhjIEAlunUIwN2wOAz+mQD4QD4NvaojX+3mgZlG
99JZYnj1zsTdmrsRy3w2Ze2SX5Ly2jEvXNVmdlxqU9yyXrSgJKJ4/Pk823nVkjQmI/x1jfqc
fOLHA71/sz7e82DMxtXPpddFBzsGrV08VDJp3viZ0YnJV20XjDvfrp/r814RM/lnKz9k3w63
YPos/TWs/dqLO91yi0Jv3RcfiwobPcbzueP4dfO0E2e/ONGFGt318AyHvWs2mtkubch6m8Vc
VNa1d9fsAVyRu5VUMWhJ8Z2JLw7NfR7t+/P7nmf3Bz1WdN56t8Kr4eyN5/YVJd6Ll8Tbh9k8
s5x+2b0moM2tJ7V+pwev2MENtf7B+vAPW7be3XbtuvO0/pwBIQEjvdpNqHrh9fpnRg9cumTb
wOlZCuX6XdqaPmbm6yhdvcMLezvGZ9gc2h7/sn7uBFel83jO+lF3+3SVrK4Zyk+fUuMm6r54
ys0fn79+5lJe6lV/au3is78PFbFvD7ZYNjXcPNf8nHlVjrvTAaFw55OffmhPP3CTfdTe+/ef
Jf6PFv9RPqT4Kna5PHr/wOeL11r1i3UoyXc/i/nUVi1d25uT2yHoh/OrVq0cM6bj29hF7pve
xXjmv1zx+mD2rn6Lbz3MGd3u0YPgkrw2/T5d3u6ZlfNrxdv3Mx/a5D+Q9qx4TzTQ4+bcvJkj
F80PO7c8JYF3MD+1Y/nolgEeYx6zrat6v9twcs3Q6vJpS1NHpiTEcg5FHFs6arB1fmz2h7yV
1fvl8hHH+BpHuzGJp1iF9EqikL6ZSqEQBYv+042r+ceBja9GygqOwOKjC2IrGsvW+L0LkKJx
ZsOyJ4x3nQnPxoN0FihtM35y797Jpcebb78X55QGhp5irGbcJcRGR2xZKURSWdf85v76hv7v
JCh1v9MDf4cor7xLfqc/zeykPJUyUy1UZeXhn/VmeiEF87e7c9Y5cdymqvIjL5n9LWZ+smPf
nFm8bvDTh+m2c3/13G7Vag1F/vggzdU/0/bELrcTZufGiGz7u+6UqtfWf5cyem7DshutQ0XV
x4q3HfiUb8M+s7ThBGWyZ8GFJ52vF31z6IPHwV5OZhdPxS7+rs3TsUODvk29NWDjjIYnt347
U/39grmt+62vjZrjlDhjhxvzFjHvWCxlbvq112Gn+O+eWzhHFHUpf9L7wCZv+2NpvrRv+86h
Oe/ryOZPPFOqzWVKh5ZKJ7J2Ou2xvs5wpeRclY4YP+++xfX1Ybv9xj1g1A/lmwXYlZl3H1q2
osKqiyv13KQbDZabhsWft95w7uPsVr1sAh1+Xdj9WfCK78oLqd7g8qRTo4/MWYVUZ7DUEoXm
nP/YjXjz79mMYnIo0cY4JG0a3xdSAHPDjhmrBXpwzGIFs0ID0UuwzyMyo5vjjJG3B4Vs3NF2
g2jlccc+Pzpv++yWCcaKqP2vFaL2YRt+dj9pdvqp5/TaCq+gkTe7vzjwR3DuXa1/yti57Xdc
2fDwaOpN25oc5UR5ZH2I97J1m2ntvHrUsXvTX/Hra0q9bNZsp8QmxI6aOKlYfihqVtH+CRP6
mDHih5oVnQqNp5+aNZ23cPu6wYeWF7+7tO6YT3r34nl+Py3sYxZ7nhtAj0l8+67yQm3WtF/U
ZVFzunCzdjx4c3HKg9Qrz4pLKuhrDnZ+uUJ17uT9U3eX+j+aMd+9avbZsJ0filuPOHBc88BM
cs/+Tf0BTn+7o5rzr+z3HZs4puJIlPPwPZL9khkndwRc2LzBrW/RxX3Xz+Rf7+OacG/S3LGX
Hnef8bTFE0X4EJk88LvUkcAB/w+9DvwUDQplbmRzdHJlYW0NCmVuZG9iag0KMjE3NCAwIG9i
ag0KWyAwWyA3NTBdICAxMzVbIDM1MF0gXSANCmVuZG9iag0KMjE3NSAwIG9iag0KPDwvVHlw
ZS9NZXRhZGF0YS9TdWJ0eXBlL1hNTC9MZW5ndGggMzE4ND4+DQpzdHJlYW0NCjw/eHBhY2tl
dCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+PHg6eG1wbWV0
YSB4bWxuczp4PSJhZG9iZTpuczptZXRhLyIgeDp4bXB0az0iMy4xLTcwMSI+CjxyZGY6UkRG
IHhtbG5zOnJkZj0iaHR0cDovL3d3dy53My5vcmcvMTk5OS8wMi8yMi1yZGYtc3ludGF4LW5z
IyI+CjxyZGY6RGVzY3JpcHRpb24gcmRmOmFib3V0PSIiICB4bWxuczpwZGY9Imh0dHA6Ly9u
cy5hZG9iZS5jb20vcGRmLzEuMy8iPgo8cGRmOlByb2R1Y2VyPk1pY3Jvc29mdMKuIFBvd2Vy
UG9pbnTCriAyMDE5PC9wZGY6UHJvZHVjZXI+PC9yZGY6RGVzY3JpcHRpb24+CjxyZGY6RGVz
Y3JpcHRpb24gcmRmOmFib3V0PSIiICB4bWxuczpkYz0iaHR0cDovL3B1cmwub3JnL2RjL2Vs
ZW1lbnRzLzEuMS8iPgo8ZGM6dGl0bGU+PHJkZjpBbHQ+PHJkZjpsaSB4bWw6bGFuZz0ieC1k
ZWZhdWx0Ij5Gb3J3YXJkIFNlY3JlY3kgb2YgVHJlZUtFTTwvcmRmOmxpPjwvcmRmOkFsdD48
L2RjOnRpdGxlPjxkYzpjcmVhdG9yPjxyZGY6U2VxPjxyZGY6bGk+U2FuZHJvIENvcmV0dGk8
L3JkZjpsaT48L3JkZjpTZXE+PC9kYzpjcmVhdG9yPjwvcmRmOkRlc2NyaXB0aW9uPgo8cmRm
OkRlc2NyaXB0aW9uIHJkZjphYm91dD0iIiAgeG1sbnM6eG1wPSJodHRwOi8vbnMuYWRvYmUu
Y29tL3hhcC8xLjAvIj4KPHhtcDpDcmVhdG9yVG9vbD5NaWNyb3NvZnTCriBQb3dlclBvaW50
wq4gMjAxOTwveG1wOkNyZWF0b3JUb29sPjx4bXA6Q3JlYXRlRGF0ZT4yMDE5LTEwLTE2VDIz
OjQ4OjIwKzAyOjAwPC94bXA6Q3JlYXRlRGF0ZT48eG1wOk1vZGlmeURhdGU+MjAxOS0xMC0x
NlQyMzo0ODoyMCswMjowMDwveG1wOk1vZGlmeURhdGU+PC9yZGY6RGVzY3JpcHRpb24+Cjxy
ZGY6RGVzY3JpcHRpb24gcmRmOmFib3V0PSIiICB4bWxuczp4bXBNTT0iaHR0cDovL25zLmFk
b2JlLmNvbS94YXAvMS4wL21tLyI+Cjx4bXBNTTpEb2N1bWVudElEPnV1aWQ6QTJCRkQwMUQt
MzA2Mi00MzM0LThDMjAtQ0VGRDVGQTVFMDA5PC94bXBNTTpEb2N1bWVudElEPjx4bXBNTTpJ
bnN0YW5jZUlEPnV1aWQ6QTJCRkQwMUQtMzA2Mi00MzM0LThDMjAtQ0VGRDVGQTVFMDA5PC94
bXBNTTpJbnN0YW5jZUlEPjwvcmRmOkRlc2NyaXB0aW9uPgogICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAK
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAKICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgIAogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAKPC9yZGY6UkRGPjwveDp4bXBtZXRhPjw/eHBhY2tldCBlbmQ9InciPz4NCmVuZHN0cmVh
bQ0KZW5kb2JqDQoyMTc2IDAgb2JqDQo8PC9EaXNwbGF5RG9jVGl0bGUgdHJ1ZT4+DQplbmRv
YmoNCjIxNzcgMCBvYmoNCjw8L1R5cGUvWFJlZi9TaXplIDIxNzcvV1sgMSA0IDJdIC9Sb290
IDEgMCBSL0luZm8gNzcgMCBSL0lEWzwxREQwQkZBMjYyMzAzNDQzOEMyMENFRkQ1RkE1RTAw
OT48MUREMEJGQTI2MjMwMzQ0MzhDMjBDRUZENUZBNUUwMDk+XSAvRmlsdGVyL0ZsYXRlRGVj
b2RlL0xlbmd0aCA0MTU4Pj4NCnN0cmVhbQ0KeJw123ccb3P9wPH7uq699957Ew2UhlVmmdkj
mU0iRWWGZCV7R0RGyKgopBKKbCUts4xfSBr4fe95frt/3OfjfB93fL/nfM7ndd73cb8TJox+
vPVWo59nnTBhMpcPdNzAxHMGppwPm+GtgaleG5h6eTw8MM2dA9M+PbCgX7LQoThvYOF1ccLA
IkcNLDo9lsXdA4vNObD41ANLLDmw8ZYDmxwysPXGeGNgm1cHtp1mYLvLBra/bmC3pwZ2n2Jg
vwkD+y80cNjKA4dvMnDSdgMnHzRw5hMDZ+2IgwfOngu7DJyz9cC5Bwxc/PrAJTMOXLXGwNWb
Dtx808Atjww88OTAQ97S8/cOvODFN52Jt9aeTLO9MDDHcJaad9LAfIsNLLbHwOLDiWzN4Zy1
1uoD614xsN5tA5tcOLDpDQNbnzuwzbUDu6w0sOtOA/vcN3DNy6MlMLqo605YGatgVbxtxIRt
JsyHKTAR49+32uhPuW7O4Wj0YpgXU2MSpsRUmAnTYFpMh+kxA2bE7JgZs2BWzIZ5MAfmxFyY
G3tgfm9+dUcLYEEshIWxCBbFYlgcS2BJLIWlsQyWxXJYHitgRayElbEKVsX4AqyG8dt9O96B
d+LdeBfWwppYA2vjPVgH78UH8D68H+thXWyA9fEhfBCbYUNsik2wETbGh7EltsBHsDm2wrb4
KLbGNtgOO2FHbI8dsDt2xsewG3bBrvg4bsCelsb4JO+FvbEP9sUn8El8Cp/GZ/BZ7If98Tkc
gAPxeRyEL+CLOBiH4Ev4Mr6CQ3EYDscROAZH4mh8FUfhazgWJ+I4nICv43icjJNwCr6BU/FN
nI3TcBbOxOk4A+fgXJyHi3E+LsK3cAEuxCX4Nr6DS3E5LsO1+C6uwfdwBa7EVbga1+H7uB7P
40bLZnxT3oQf4If4EW7GLfgxfoJbcRtux09xB36Gn+MXuBO/xF24G/fgV/g17sV9+A3uxwN4
DA/iUTyCh/Awfoff4vd4HH/AE/gr/ojn8Cz+hD/jL3gST+FpPIO/4WX8Hf+HF1yO8eb4Il4a
aLyXv+KXjHfMV/EPvIZ/4nX8C//Gf/BfvIE38Za/SBQTxXQzFU0UE8VEMcFMFBPFRDFRTBQT
xVQ0UUz40sYEM21MKZPytDGdTjdTypQy4Wt+qGHamGAmmNmFW8z5FJskMolMIpPIJDKJTCKT
yCQyiUwik8gkMolMIpPIJDKJzO6duzGrIFe68RvUxpQy+UwbU8okMolMItPGlDKJTCLTvyQy
iUw3U8pkMFFMKVPKtDExTfHSxkQx3Uwpk89EMRlM/9LNVDTBTCKzJ7ezKzY+E6KYKKaU6WZi
mlLmIao9IZFJZBKZRCaRSWQSmUQmkUlkEplEJpFJZBKZRCaRSWQSmUQmgyll2phSpptpY0qZ
GqaUiWJKmTYmiqloophgpoZpYzKYYKaGKWWammCmjalhaphuppRpY9qY7bdzXLHxolXKlDKJ
TBQTxZQy3UxMk8gEM4lMMJPIBDOJTBQTxUQxUUw3U9GkNaVMKVPKPGB1IyQyGUwp08aUMt1M
G1PKZDClTBsTzAQzbUwp08aUMm1MKdO/lDJRTCLTzXQziUz/Er4EM8FMKZvcxolbjB+se8wV
G+8vEplgJpEJZhKZYCaRiWKimCgmioliopgoJqZJa3qbUuZRpRcgio2jqJupaJraKz7K5Enx
nleGGW90FCZhCkzE1JgKU2I6TItpMCNmwPSYBTNjJsyO2TAr5sKcmAPzYh7MjQUwP+bDQlgQ
i2BhLIZFsSSWwOJYGkthOSyLZbAqlscqWBkrYEWshLXxNrwH7x6d+Wf635l/B96O1bA61sKa
eCfehTXwdbzPihz/De/HB7AO1sV6WB8b4IP4EDbERtgYm2BTbIYP4yPYHFtgS2yFrbENPopt
sR22xw7YGTthR+yGXbELPo7d8THshT2xB/bFPtgbn8In8Ql8Fp/Bp/E57I/98HkciAPwBRyE
Q3Awvogv40s4DIfiKzgCh+OrOApH4jgcja/hWByDP+F4K2S8Ik/AiTgJJ+MbOAXfxKk4Dafj
DJyJs3A2zsG5OA/n4wJciG/hIlyMb+MSXIrv4DJcge/iclyNq3AlrsU1+B6ux/dxHW7CjbgB
P8IP8QP8GLfgZtyGW/ET3IGf4nb8HD/DL3EnfoF7cDfuwr34NX6F+/Eb3Idxsh7EA/gtHsZj
eBSP4I/4Hf6AJ/A4fj/Q+Gb+s5X1Xkd/wZN4Ck/jGTyL5/BX/A3P4wW8iJfwf/g7XsY4Z6/i
H3gN/8Tr+Bf+jf/gv3gDb/pgath4h37LkTamjWlj2pg2po1pY9qYNqaNaWPamDamjWlj2pg2
po1pY9qYNqaNaWPamCgmioliophuJoNJZBKZGqaGCWaimCimm2lj2pg2JoNpY/qXGqaNqVq6
mdSljUlrqpYaJnUJX0qZnCWKaVyKl2AOg98INcyWl/U5zHgjFC9RTAYTxSQyxUsUk8FEMYlM
DRO3RDHFS/+SyCQyiUwic98OU93oBhq/M1FMFBPFRDEZTBSTyGQwUUwik8FEMYlMBhPFJDIZ
TBSTyGQwUUwik8FEMYlMBhPFJDJRTBQTxYQvbUwb078kMolMBpPBlDI1TA0TzEQxUUwU07/0
L23Mg1KCmVKmf6nhMPiNkMFEMf1LDdPG9C81TBvTv9QwbUz/UsO0Mf1LDdPGFC9RTAYTxSQy
jUsUk8FEMYlM/xLFZDAZTDBTvGQw4Usik8i0MY1LBpO6pC6JTDATxSQywUz/Ury0MW1M3BLF
NC6NSzDTxpQyUUwiE8wULxlM+JLIYeKbtNn44XIY50b32HifEMXxVJcapn+pYdqYYKaG6V/j
/oliEplu5nFrGO5GqGFqmBqmhqlhapgapoapYWqYGqaGqWH6lxoOo97o0wbl6pXJk8bqw9Ho
xUmYAhMxNabClJgO02IazIgZMD1mwcyYCbNjNsyKuTAn5sA8mBvzYz7Mi4WwIBbAolgEC2MJ
LI7FsDSWwpJYActgeSyHZbEqVsQqWBkr4R14G96O1bEa1sI7sSbWwLvwbqyP92A9rIu18V68
D+/HB7AONsCG+BA+iC2xEbbA5tgYm2BTbIYP4yPYFlvho9gGW+M5bO+OG7/BHbAjdsLO2AW7
Yjd8DLvj49gDe2Iv7I19sC8+gU/iU/g0PoPPYj/sj8/hAByIz+OL+AIOwpdwCA7GofgKvowj
cDgOw1dxFI7EsTgGR+PrOA5fw4k4AcfjGzgZJ+GbOAWn4zScirNwJs7AuTgHZ+MCnI/zcBG+
hQvxHVyMS3EJvo0rcRmuwHdxOa7FVbgG38PVuBHX4QZcj+/jZtyEH+GH+AFuwS/wY/wcP8NP
cCtuw+34Ke7APbgTd+Mu/BIP41d4CA9iHLB7cR9+g/vxAH6HR/BbPIZH8SwexzN4Gr/HE/gD
/og/4c/4C57EUwONF8rkco3u9/FO9Dc8jxfwIl7COFl/x8t4Ba/iH3gN/8Tr+Bf+jf/gv3gD
b+It71MGk8j0LzVMG9O/1DD9S/9SyvQv/Usp07/0L6VM/9K/lDL9S/9SymQwGUwpU8PUMDVM
DVPD1DA1TA1Tw2QwGUz/0r+UMqlLBlPKtDFRTBQTvoQvUUz4UsokMqlL/5LItDFtTPHSvyQy
bUwbE7fUMMVL/1LDBDN5STATzKzBpC5RTBQTxUQxcUv/Urz0LzVM6tK/VDT5TD6HWW2E/iWR
aWPaOMxxI3QsNUzckrq0MW1MG9PGtDFtTOpSw/QvNUwb07HUMHFL6tLGtDFtTBvTxrQxqUsN
U7zUMG1M1dLGxC1xSw3TxpQyNUwbU8qkLv1L8dLGtDHJShtTrpQrNUwbU8rUMG1MKVPDtDGl
TBSTyBQhqUsUh6lutLuNF5j+pX9pY0qZGiaDyWDCl/CllIliMpjipXjpZqKYRKaNqVpqmLgl
fKlh2phSJp8JX0qZRA6T21QbjMeB9C+lHOa40Yce31wal+KljalhapjwJYNpXPqXfCamKWzC
l1KmjSllwjee49K/tDHhSw1Tw8Q0FU34EsVEMVFMBtPNhC8ZTPiSwYQvGUz4ksHks3EGFTZp
TfHSvzwSD8PdCG1M8dK/tDFtHMa50VUZJ2s0x02ceMdwNHoxbIMpXKP1HU3ClJgKU2MaTIvp
MD1mwIyYCTNjFsyK2TA75sCcmAtzYx7Mi/kwPxbAglgIC2MJLILFsRgWxVJYEstjaSyHZbAs
VsQKWBkrYVWsgrdhNayO9+LtWBvvwTvwTrwLa2BNrIV34/14H9bBB7Ae1sUGGF/brfFBbIUt
8SFsiI2wMTbBptgMH8ZHsDm2wI8x/mfJ8ZvYFtthe+yAHbETdsYu2BW74WPYHR/HHtgTe2Fv
7IN98Ql8Ep/Cp/EZfBb7YX98Dl/EAfgCDsKB+DwOx8E4DIfiEHwJX8ZXcAyOwNH4Ko7EUTgO
X8OxOAHH4+s4GSfhRHwTp+AbOB2n4VSchTNxBs7FOTgbF+B8nIercSGuwkX4Fq4cbU8LzvW/
7elSXIKL8W1cge/iO7gMl+MafA/X4Vpcj+/jRtyAccduwo/wQ9yCmwca72c/sbzHt9OtuA23
46e4Az/Dz/EL3Ilf4i7cjXvwK/wa9+I+/Ab34wE8iIfwMB7Bo3gMv8Xv8AR+j8fxR/wBf8af
8CT+gmfwNJ7Cc3gWz+Nv+Ctexgv4O8YBexEv4R94Fa/gdfwTr+E/+Df+hTfxBv7raqph48X3
liMZHIa7ERMhg4liEpkMJopJZMKXNqaGaWNKmR0s4RtmvNFasgsniklkgpk2po1pY9qYNqaN
aWPamDamjYliMpgoJpHpZqKYRCaKqWFqmESmm4liEpkoJpGJYhKZNiaDaWNKmf6lhglfMpgo
pn+pYZqamCamyWASmUQmioligpn7NnVKIhO+ZLDx5RC+ZDBRTPiSwUQxMU0GE8U8Z6W+yW4y
mCgOo94IGUwUk8gUL21MBhPFlDKlHB6lRwjfMCmOltT4o4hiEplgpo1pY9qYNqaNaWPamDam
jWlj2pgoJoPJYNqYUiafiWIymAwmg8lgSpluJqaJYjKYDKaN6V/ymW4mkUlk2pg2po1pY9qY
NqaNaWPamDamjWlj2pg2po1pY9qYNqaNaWPamAwmg0lkwpfipX9pXIqXRKaGqWH6l94mtMPg
N0L/0sa0MalLIlPD1DCJTDDzQDce9VLDxjWUyP+NeuO7X/GGqW704viuUsO0MaVMFBPFRDFR
TBQTxUQxUUwUE8VEMVFMFBPFRDFRTBQTxUQxUUwUE8VEMRlMFJPI1DBtTA1Tw9QwpUwNU8PU
MDVMMBPFRDFRTPHSv7QxpUwihxlvdHaDgA2j3oIbDkejFydhPONNxNSYClNiOkyLaTAjZsD0
mAUzYybMjtkwztlcmBNzYF7Mg7mxFObDklgC46/lLYAFsRAWxiJYFOPvHCyOFbA0lsdyWAbL
YsXRqVt5r8n/sXXiKsOXOiee+fjA2c9MZoqTLh04ZfOBU48fOP2CyUxacfge5qSV58JFA0fs
N3Dk8AXMSXcN31addPdyA4+8NGHC/wOeeuRYDQplbmRzdHJlYW0NCmVuZG9iag0KeHJlZg0K
MCAyMTc4DQowMDAwMDAwMDc4IDY1NTM1IGYNCjAwMDAwMDAwMTcgMDAwMDAgbg0KMDAwMDAw
MDE3MCAwMDAwMCBuDQowMDAwMDAwMzk1IDAwMDAwIG4NCjAwMDAwMDA2NjggMDAwMDAgbg0K
MDAwMDAwMTMwNiAwMDAwMCBuDQowMDAwMDAxMzU5IDAwMDAwIG4NCjAwMDAwMDE1MzUgMDAw
MDAgbg0KMDAwMDAwMTc4MiAwMDAwMCBuDQowMDAwMDAxODM1IDAwMDAwIG4NCjAwMDAwMDIw
MDYgMDAwMDAgbg0KMDAwMDAwMjI0OCAwMDAwMCBuDQowMDAwMDAyNTM0IDAwMDAwIG4NCjAw
MDAwMDc2NzAgMDAwMDAgbg0KMDAwMDAwNzgwOCAwMDAwMCBuDQowMDAwMDA3ODM4IDAwMDAw
IG4NCjAwMDAwMDgwMDQgMDAwMDAgbg0KMDAwMDAwODA3OCAwMDAwMCBuDQowMDAwMDA4MzI1
IDAwMDAwIG4NCjAwMDAwMDg0NTkgMDAwMDAgbg0KMDAwMDAwODQ4OSAwMDAwMCBuDQowMDAw
MDA4NjUxIDAwMDAwIG4NCjAwMDAwMDg3MjUgMDAwMDAgbg0KMDAwMDAwODk2NyAwMDAwMCBu
DQowMDAwMDA5MjUzIDAwMDAwIG4NCjAwMDAwMTk1NDAgMDAwMDAgbg0KMDAwMDAxOTgzNiAw
MDAwMCBuDQowMDAwMDIyMDkyIDAwMDAwIG4NCjAwMDAwMjIyNjkgMDAwMDAgbg0KMDAwMDAy
MjUxNiAwMDAwMCBuDQowMDAwMDIyNzkyIDAwMDAwIG4NCjAwMDAwMjMyMDkgMDAwMDAgbg0K
MDAwMDAyMzQ3NSAwMDAwMCBuDQowMDAwMDI1MzE3IDAwMDAwIG4NCjAwMDAwMjU2MDMgMDAw
MDAgbg0KMDAwMDAyOTE4NCAwMDAwMCBuDQowMDAwMDI5NDcwIDAwMDAwIG4NCjAwMDAwMzMw
NzEgMDAwMDAgbg0KMDAwMDAzMzM1NyAwMDAwMCBuDQowMDAwMDM2OTU0IDAwMDAwIG4NCjAw
MDAwMzcyNDAgMDAwMDAgbg0KMDAwMDAzOTM5MCAwMDAwMCBuDQowMDAwMDM5NTE3IDAwMDAw
IG4NCjAwMDAwMzk1NDcgMDAwMDAgbg0KMDAwMDAzOTcwMiAwMDAwMCBuDQowMDAwMDM5Nzc2
IDAwMDAwIG4NCjAwMDAwNDAwMjIgMDAwMDAgbg0KMDAwMDA0MDMwOSAwMDAwMCBuDQowMDAw
MDQyMjMyIDAwMDAwIG4NCjAwMDAwNDI1MDkgMDAwMDAgbg0KMDAwMDA0NDYwMSAwMDAwMCBu
DQowMDAwMDQ0ODc4IDAwMDAwIG4NCjAwMDAwNDgzMTIgMDAwMDAgbg0KMDAwMDA0ODU5OSAw
MDAwMCBuDQowMDAwMDU0MjQ0IDAwMDAwIG4NCjAwMDAwNTQ1MzEgMDAwMDAgbg0KMDAwMDA2
MDYyMyAwMDAwMCBuDQowMDAwMDYwOTAwIDAwMDAwIG4NCjAwMDAwNjUwNjUgMDAwMDAgbg0K
MDAwMDA2NTM0MiAwMDAwMCBuDQowMDAwMDcwMzgxIDAwMDAwIG4NCjAwMDAwNzA2NjcgMDAw
MDAgbg0KMDAwMDA3MTk0MCAwMDAwMCBuDQowMDAwMDcyMjI2IDAwMDAwIG4NCjAwMDAwNzQz
NDIgMDAwMDAgbg0KMDAwMDA3NDYyOSAwMDAwMCBuDQowMDAwMDgwNDA1IDAwMDAwIG4NCjAw
MDAwODA2OTIgMDAwMDAgbg0KMDAwMDA4MzExNiAwMDAwMCBuDQowMDAwMDgzMzkzIDAwMDAw
IG4NCjAwMDAwODU0MDkgMDAwMDAgbg0KMDAwMDA4NTY4NiAwMDAwMCBuDQowMDAwMDg3NzA5
IDAwMDAwIG4NCjAwMDAwODc5ODYgMDAwMDAgbg0KMDAwMDA5MDE1OCAwMDAwMCBuDQowMDAw
MDkwNDYyIDAwMDAwIG4NCjAwMDAwOTI4ODAgMDAwMDAgbg0KMDAwMDExMTA5MCAwMDAwMCBu
DQowMDAwMDAwMDc5IDY1NTM1IGYNCjAwMDAwMDAwODAgNjU1MzUgZg0KMDAwMDAwMDA4MSA2
NTUzNSBmDQowMDAwMDAwMDgyIDY1NTM1IGYNCjAwMDAwMDAwODMgNjU1MzUgZg0KMDAwMDAw
MDA4NCA2NTUzNSBmDQowMDAwMDAwMDg1IDY1NTM1IGYNCjAwMDAwMDAwODYgNjU1MzUgZg0K
MDAwMDAwMDA4NyA2NTUzNSBmDQowMDAwMDAwMDg4IDY1NTM1IGYNCjAwMDAwMDAwODkgNjU1
MzUgZg0KMDAwMDAwMDA5MCA2NTUzNSBmDQowMDAwMDAwMDkxIDY1NTM1IGYNCjAwMDAwMDAw
OTIgNjU1MzUgZg0KMDAwMDAwMDA5MyA2NTUzNSBmDQowMDAwMDAwMDk0IDY1NTM1IGYNCjAw
MDAwMDAwOTUgNjU1MzUgZg0KMDAwMDAwMDA5NiA2NTUzNSBmDQowMDAwMDAwMDk3IDY1NTM1
IGYNCjAwMDAwMDAwOTggNjU1MzUgZg0KMDAwMDAwMDA5OSA2NTUzNSBmDQowMDAwMDAwMTAw
IDY1NTM1IGYNCjAwMDAwMDAxMDEgNjU1MzUgZg0KMDAwMDAwMDEwMiA2NTUzNSBmDQowMDAw
MDAwMTAzIDY1NTM1IGYNCjAwMDAwMDAxMDQgNjU1MzUgZg0KMDAwMDAwMDEwNSA2NTUzNSBm
DQowMDAwMDAwMTA2IDY1NTM1IGYNCjAwMDAwMDAxMDcgNjU1MzUgZg0KMDAwMDAwMDEwOCA2
NTUzNSBmDQowMDAwMDAwMTA5IDY1NTM1IGYNCjAwMDAwMDAxMTAgNjU1MzUgZg0KMDAwMDAw
MDExMSA2NTUzNSBmDQowMDAwMDAwMTEyIDY1NTM1IGYNCjAwMDAwMDAxMTMgNjU1MzUgZg0K
MDAwMDAwMDExNCA2NTUzNSBmDQowMDAwMDAwMTE1IDY1NTM1IGYNCjAwMDAwMDAxMTYgNjU1
MzUgZg0KMDAwMDAwMDExNyA2NTUzNSBmDQowMDAwMDAwMTE4IDY1NTM1IGYNCjAwMDAwMDAx
MTkgNjU1MzUgZg0KMDAwMDAwMDEyMCA2NTUzNSBmDQowMDAwMDAwMTIxIDY1NTM1IGYNCjAw
MDAwMDAxMjIgNjU1MzUgZg0KMDAwMDAwMDEyMyA2NTUzNSBmDQowMDAwMDAwMTI0IDY1NTM1
IGYNCjAwMDAwMDAxMjUgNjU1MzUgZg0KMDAwMDAwMDEyNiA2NTUzNSBmDQowMDAwMDAwMTI3
IDY1NTM1IGYNCjAwMDAwMDAxMjggNjU1MzUgZg0KMDAwMDAwMDEyOSA2NTUzNSBmDQowMDAw
MDAwMTMwIDY1NTM1IGYNCjAwMDAwMDAxMzEgNjU1MzUgZg0KMDAwMDAwMDEzMiA2NTUzNSBm
DQowMDAwMDAwMTMzIDY1NTM1IGYNCjAwMDAwMDAxMzQgNjU1MzUgZg0KMDAwMDAwMDEzNSA2
NTUzNSBmDQowMDAwMDAwMTM2IDY1NTM1IGYNCjAwMDAwMDAxMzcgNjU1MzUgZg0KMDAwMDAw
MDEzOCA2NTUzNSBmDQowMDAwMDAwMTM5IDY1NTM1IGYNCjAwMDAwMDAxNDAgNjU1MzUgZg0K
MDAwMDAwMDE0MSA2NTUzNSBmDQowMDAwMDAwMTQyIDY1NTM1IGYNCjAwMDAwMDAxNDMgNjU1
MzUgZg0KMDAwMDAwMDE0NCA2NTUzNSBmDQowMDAwMDAwMTQ1IDY1NTM1IGYNCjAwMDAwMDAx
NDYgNjU1MzUgZg0KMDAwMDAwMDE0NyA2NTUzNSBmDQowMDAwMDAwMTQ4IDY1NTM1IGYNCjAw
MDAwMDAxNDkgNjU1MzUgZg0KMDAwMDAwMDE1MCA2NTUzNSBmDQowMDAwMDAwMTUxIDY1NTM1
IGYNCjAwMDAwMDAxNTIgNjU1MzUgZg0KMDAwMDAwMDE1MyA2NTUzNSBmDQowMDAwMDAwMTU0
IDY1NTM1IGYNCjAwMDAwMDAxNTUgNjU1MzUgZg0KMDAwMDAwMDE1NiA2NTUzNSBmDQowMDAw
MDAwMTU3IDY1NTM1IGYNCjAwMDAwMDAxNTggNjU1MzUgZg0KMDAwMDAwMDE1OSA2NTUzNSBm
DQowMDAwMDAwMTYwIDY1NTM1IGYNCjAwMDAwMDAxNjEgNjU1MzUgZg0KMDAwMDAwMDE2MiA2
NTUzNSBmDQowMDAwMDAwMTYzIDY1NTM1IGYNCjAwMDAwMDAxNjQgNjU1MzUgZg0KMDAwMDAw
MDE2NSA2NTUzNSBmDQowMDAwMDAwMTY2IDY1NTM1IGYNCjAwMDAwMDAxNjcgNjU1MzUgZg0K
MDAwMDAwMDE2OCA2NTUzNSBmDQowMDAwMDAwMTY5IDY1NTM1IGYNCjAwMDAwMDAxNzAgNjU1
MzUgZg0KMDAwMDAwMDE3MSA2NTUzNSBmDQowMDAwMDAwMTcyIDY1NTM1IGYNCjAwMDAwMDAx
NzMgNjU1MzUgZg0KMDAwMDAwMDE3NCA2NTUzNSBmDQowMDAwMDAwMTc1IDY1NTM1IGYNCjAw
MDAwMDAxNzYgNjU1MzUgZg0KMDAwMDAwMDE3NyA2NTUzNSBmDQowMDAwMDAwMTc4IDY1NTM1
IGYNCjAwMDAwMDAxNzkgNjU1MzUgZg0KMDAwMDAwMDE4MCA2NTUzNSBmDQowMDAwMDAwMTgx
IDY1NTM1IGYNCjAwMDAwMDAxODIgNjU1MzUgZg0KMDAwMDAwMDE4MyA2NTUzNSBmDQowMDAw
MDAwMTg0IDY1NTM1IGYNCjAwMDAwMDAxODUgNjU1MzUgZg0KMDAwMDAwMDE4NiA2NTUzNSBm
DQowMDAwMDAwMTg3IDY1NTM1IGYNCjAwMDAwMDAxODggNjU1MzUgZg0KMDAwMDAwMDE4OSA2
NTUzNSBmDQowMDAwMDAwMTkwIDY1NTM1IGYNCjAwMDAwMDAxOTEgNjU1MzUgZg0KMDAwMDAw
MDE5MiA2NTUzNSBmDQowMDAwMDAwMTkzIDY1NTM1IGYNCjAwMDAwMDAxOTQgNjU1MzUgZg0K
MDAwMDAwMDE5NSA2NTUzNSBmDQowMDAwMDAwMTk2IDY1NTM1IGYNCjAwMDAwMDAxOTcgNjU1
MzUgZg0KMDAwMDAwMDE5OCA2NTUzNSBmDQowMDAwMDAwMTk5IDY1NTM1IGYNCjAwMDAwMDAy
MDAgNjU1MzUgZg0KMDAwMDAwMDIwMSA2NTUzNSBmDQowMDAwMDAwMjAyIDY1NTM1IGYNCjAw
MDAwMDAyMDMgNjU1MzUgZg0KMDAwMDAwMDIwNCA2NTUzNSBmDQowMDAwMDAwMjA1IDY1NTM1
IGYNCjAwMDAwMDAyMDYgNjU1MzUgZg0KMDAwMDAwMDIwNyA2NTUzNSBmDQowMDAwMDAwMjA4
IDY1NTM1IGYNCjAwMDAwMDAyMDkgNjU1MzUgZg0KMDAwMDAwMDIxMCA2NTUzNSBmDQowMDAw
MDAwMjExIDY1NTM1IGYNCjAwMDAwMDAyMTIgNjU1MzUgZg0KMDAwMDAwMDIxMyA2NTUzNSBm
DQowMDAwMDAwMjE0IDY1NTM1IGYNCjAwMDAwMDAyMTUgNjU1MzUgZg0KMDAwMDAwMDIxNiA2
NTUzNSBmDQowMDAwMDAwMjE3IDY1NTM1IGYNCjAwMDAwMDAyMTggNjU1MzUgZg0KMDAwMDAw
MDIxOSA2NTUzNSBmDQowMDAwMDAwMjIwIDY1NTM1IGYNCjAwMDAwMDAyMjEgNjU1MzUgZg0K
MDAwMDAwMDIyMiA2NTUzNSBmDQowMDAwMDAwMjIzIDY1NTM1IGYNCjAwMDAwMDAyMjQgNjU1
MzUgZg0KMDAwMDAwMDIyNSA2NTUzNSBmDQowMDAwMDAwMjI2IDY1NTM1IGYNCjAwMDAwMDAy
MjcgNjU1MzUgZg0KMDAwMDAwMDIyOCA2NTUzNSBmDQowMDAwMDAwMjI5IDY1NTM1IGYNCjAw
MDAwMDAyMzAgNjU1MzUgZg0KMDAwMDAwMDIzMSA2NTUzNSBmDQowMDAwMDAwMjMyIDY1NTM1
IGYNCjAwMDAwMDAyMzMgNjU1MzUgZg0KMDAwMDAwMDIzNCA2NTUzNSBmDQowMDAwMDAwMjM1
IDY1NTM1IGYNCjAwMDAwMDAyMzYgNjU1MzUgZg0KMDAwMDAwMDIzNyA2NTUzNSBmDQowMDAw
MDAwMjM4IDY1NTM1IGYNCjAwMDAwMDAyMzkgNjU1MzUgZg0KMDAwMDAwMDI0MCA2NTUzNSBm
DQowMDAwMDAwMjQxIDY1NTM1IGYNCjAwMDAwMDAyNDIgNjU1MzUgZg0KMDAwMDAwMDI0MyA2
NTUzNSBmDQowMDAwMDAwMjQ0IDY1NTM1IGYNCjAwMDAwMDAyNDUgNjU1MzUgZg0KMDAwMDAw
MDI0NiA2NTUzNSBmDQowMDAwMDAwMjQ3IDY1NTM1IGYNCjAwMDAwMDAyNDggNjU1MzUgZg0K
MDAwMDAwMDI0OSA2NTUzNSBmDQowMDAwMDAwMjUwIDY1NTM1IGYNCjAwMDAwMDAyNTEgNjU1
MzUgZg0KMDAwMDAwMDI1MiA2NTUzNSBmDQowMDAwMDAwMjUzIDY1NTM1IGYNCjAwMDAwMDAy
NTQgNjU1MzUgZg0KMDAwMDAwMDI1NSA2NTUzNSBmDQowMDAwMDAwMjU2IDY1NTM1IGYNCjAw
MDAwMDAyNTcgNjU1MzUgZg0KMDAwMDAwMDI1OCA2NTUzNSBmDQowMDAwMDAwMjU5IDY1NTM1
IGYNCjAwMDAwMDAyNjAgNjU1MzUgZg0KMDAwMDAwMDI2MSA2NTUzNSBmDQowMDAwMDAwMjYy
IDY1NTM1IGYNCjAwMDAwMDAyNjMgNjU1MzUgZg0KMDAwMDAwMDI2NCA2NTUzNSBmDQowMDAw
MDAwMjY1IDY1NTM1IGYNCjAwMDAwMDAyNjYgNjU1MzUgZg0KMDAwMDAwMDI2NyA2NTUzNSBm
DQowMDAwMDAwMjY4IDY1NTM1IGYNCjAwMDAwMDAyNjkgNjU1MzUgZg0KMDAwMDAwMDI3MCA2
NTUzNSBmDQowMDAwMDAwMjcxIDY1NTM1IGYNCjAwMDAwMDAyNzIgNjU1MzUgZg0KMDAwMDAw
MDI3MyA2NTUzNSBmDQowMDAwMDAwMjc0IDY1NTM1IGYNCjAwMDAwMDAyNzUgNjU1MzUgZg0K
MDAwMDAwMDI3NiA2NTUzNSBmDQowMDAwMDAwMjc3IDY1NTM1IGYNCjAwMDAwMDAyNzggNjU1
MzUgZg0KMDAwMDAwMDI3OSA2NTUzNSBmDQowMDAwMDAwMjgwIDY1NTM1IGYNCjAwMDAwMDAy
ODEgNjU1MzUgZg0KMDAwMDAwMDI4MiA2NTUzNSBmDQowMDAwMDAwMjgzIDY1NTM1IGYNCjAw
MDAwMDAyODQgNjU1MzUgZg0KMDAwMDAwMDI4NSA2NTUzNSBmDQowMDAwMDAwMjg2IDY1NTM1
IGYNCjAwMDAwMDAyODcgNjU1MzUgZg0KMDAwMDAwMDI4OCA2NTUzNSBmDQowMDAwMDAwMjg5
IDY1NTM1IGYNCjAwMDAwMDAyOTAgNjU1MzUgZg0KMDAwMDAwMDI5MSA2NTUzNSBmDQowMDAw
MDAwMjkyIDY1NTM1IGYNCjAwMDAwMDAyOTMgNjU1MzUgZg0KMDAwMDAwMDI5NCA2NTUzNSBm
DQowMDAwMDAwMjk1IDY1NTM1IGYNCjAwMDAwMDAyOTYgNjU1MzUgZg0KMDAwMDAwMDI5NyA2
NTUzNSBmDQowMDAwMDAwMjk4IDY1NTM1IGYNCjAwMDAwMDAyOTkgNjU1MzUgZg0KMDAwMDAw
MDMwMCA2NTUzNSBmDQowMDAwMDAwMzAxIDY1NTM1IGYNCjAwMDAwMDAzMDIgNjU1MzUgZg0K
MDAwMDAwMDMwMyA2NTUzNSBmDQowMDAwMDAwMzA0IDY1NTM1IGYNCjAwMDAwMDAzMDUgNjU1
MzUgZg0KMDAwMDAwMDMwNiA2NTUzNSBmDQowMDAwMDAwMzA3IDY1NTM1IGYNCjAwMDAwMDAz
MDggNjU1MzUgZg0KMDAwMDAwMDMwOSA2NTUzNSBmDQowMDAwMDAwMzEwIDY1NTM1IGYNCjAw
MDAwMDAzMTEgNjU1MzUgZg0KMDAwMDAwMDMxMiA2NTUzNSBmDQowMDAwMDAwMzEzIDY1NTM1
IGYNCjAwMDAwMDAzMTQgNjU1MzUgZg0KMDAwMDAwMDMxNSA2NTUzNSBmDQowMDAwMDAwMzE2
IDY1NTM1IGYNCjAwMDAwMDAzMTcgNjU1MzUgZg0KMDAwMDAwMDMxOCA2NTUzNSBmDQowMDAw
MDAwMzE5IDY1NTM1IGYNCjAwMDAwMDAzMjAgNjU1MzUgZg0KMDAwMDAwMDMyMSA2NTUzNSBm
DQowMDAwMDAwMzIyIDY1NTM1IGYNCjAwMDAwMDAzMjMgNjU1MzUgZg0KMDAwMDAwMDMyNCA2
NTUzNSBmDQowMDAwMDAwMzI1IDY1NTM1IGYNCjAwMDAwMDAzMjYgNjU1MzUgZg0KMDAwMDAw
MDMyNyA2NTUzNSBmDQowMDAwMDAwMzI4IDY1NTM1IGYNCjAwMDAwMDAzMjkgNjU1MzUgZg0K
MDAwMDAwMDMzMCA2NTUzNSBmDQowMDAwMDAwMzMxIDY1NTM1IGYNCjAwMDAwMDAzMzIgNjU1
MzUgZg0KMDAwMDAwMDMzMyA2NTUzNSBmDQowMDAwMDAwMzM0IDY1NTM1IGYNCjAwMDAwMDAz
MzUgNjU1MzUgZg0KMDAwMDAwMDMzNiA2NTUzNSBmDQowMDAwMDAwMzM3IDY1NTM1IGYNCjAw
MDAwMDAzMzggNjU1MzUgZg0KMDAwMDAwMDMzOSA2NTUzNSBmDQowMDAwMDAwMzQwIDY1NTM1
IGYNCjAwMDAwMDAzNDEgNjU1MzUgZg0KMDAwMDAwMDM0MiA2NTUzNSBmDQowMDAwMDAwMzQz
IDY1NTM1IGYNCjAwMDAwMDAzNDQgNjU1MzUgZg0KMDAwMDAwMDM0NSA2NTUzNSBmDQowMDAw
MDAwMzQ2IDY1NTM1IGYNCjAwMDAwMDAzNDcgNjU1MzUgZg0KMDAwMDAwMDM0OCA2NTUzNSBm
DQowMDAwMDAwMzQ5IDY1NTM1IGYNCjAwMDAwMDAzNTAgNjU1MzUgZg0KMDAwMDAwMDM1MSA2
NTUzNSBmDQowMDAwMDAwMzUyIDY1NTM1IGYNCjAwMDAwMDAzNTMgNjU1MzUgZg0KMDAwMDAw
MDM1NCA2NTUzNSBmDQowMDAwMDAwMzU1IDY1NTM1IGYNCjAwMDAwMDAzNTYgNjU1MzUgZg0K
MDAwMDAwMDM1NyA2NTUzNSBmDQowMDAwMDAwMzU4IDY1NTM1IGYNCjAwMDAwMDAzNTkgNjU1
MzUgZg0KMDAwMDAwMDM2MCA2NTUzNSBmDQowMDAwMDAwMzYxIDY1NTM1IGYNCjAwMDAwMDAz
NjIgNjU1MzUgZg0KMDAwMDAwMDM2MyA2NTUzNSBmDQowMDAwMDAwMzY0IDY1NTM1IGYNCjAw
MDAwMDAzNjUgNjU1MzUgZg0KMDAwMDAwMDM2NiA2NTUzNSBmDQowMDAwMDAwMzY3IDY1NTM1
IGYNCjAwMDAwMDAzNjggNjU1MzUgZg0KMDAwMDAwMDM2OSA2NTUzNSBmDQowMDAwMDAwMzcw
IDY1NTM1IGYNCjAwMDAwMDAzNzEgNjU1MzUgZg0KMDAwMDAwMDM3MiA2NTUzNSBmDQowMDAw
MDAwMzczIDY1NTM1IGYNCjAwMDAwMDAzNzQgNjU1MzUgZg0KMDAwMDAwMDM3NSA2NTUzNSBm
DQowMDAwMDAwMzc2IDY1NTM1IGYNCjAwMDAwMDAzNzcgNjU1MzUgZg0KMDAwMDAwMDM3OCA2
NTUzNSBmDQowMDAwMDAwMzc5IDY1NTM1IGYNCjAwMDAwMDAzODAgNjU1MzUgZg0KMDAwMDAw
MDM4MSA2NTUzNSBmDQowMDAwMDAwMzgyIDY1NTM1IGYNCjAwMDAwMDAzODMgNjU1MzUgZg0K
MDAwMDAwMDM4NCA2NTUzNSBmDQowMDAwMDAwMzg1IDY1NTM1IGYNCjAwMDAwMDAzODYgNjU1
MzUgZg0KMDAwMDAwMDM4NyA2NTUzNSBmDQowMDAwMDAwMzg4IDY1NTM1IGYNCjAwMDAwMDAz
ODkgNjU1MzUgZg0KMDAwMDAwMDM5MCA2NTUzNSBmDQowMDAwMDAwMzkxIDY1NTM1IGYNCjAw
MDAwMDAzOTIgNjU1MzUgZg0KMDAwMDAwMDM5MyA2NTUzNSBmDQowMDAwMDAwMzk0IDY1NTM1
IGYNCjAwMDAwMDAzOTUgNjU1MzUgZg0KMDAwMDAwMDM5NiA2NTUzNSBmDQowMDAwMDAwMzk3
IDY1NTM1IGYNCjAwMDAwMDAzOTggNjU1MzUgZg0KMDAwMDAwMDM5OSA2NTUzNSBmDQowMDAw
MDAwNDAwIDY1NTM1IGYNCjAwMDAwMDA0MDEgNjU1MzUgZg0KMDAwMDAwMDQwMiA2NTUzNSBm
DQowMDAwMDAwNDAzIDY1NTM1IGYNCjAwMDAwMDA0MDQgNjU1MzUgZg0KMDAwMDAwMDQwNSA2
NTUzNSBmDQowMDAwMDAwNDA2IDY1NTM1IGYNCjAwMDAwMDA0MDcgNjU1MzUgZg0KMDAwMDAw
MDQwOCA2NTUzNSBmDQowMDAwMDAwNDA5IDY1NTM1IGYNCjAwMDAwMDA0MTAgNjU1MzUgZg0K
MDAwMDAwMDQxMSA2NTUzNSBmDQowMDAwMDAwNDEyIDY1NTM1IGYNCjAwMDAwMDA0MTMgNjU1
MzUgZg0KMDAwMDAwMDQxNCA2NTUzNSBmDQowMDAwMDAwNDE1IDY1NTM1IGYNCjAwMDAwMDA0
MTYgNjU1MzUgZg0KMDAwMDAwMDQxNyA2NTUzNSBmDQowMDAwMDAwNDE4IDY1NTM1IGYNCjAw
MDAwMDA0MTkgNjU1MzUgZg0KMDAwMDAwMDQyMCA2NTUzNSBmDQowMDAwMDAwNDIxIDY1NTM1
IGYNCjAwMDAwMDA0MjIgNjU1MzUgZg0KMDAwMDAwMDQyMyA2NTUzNSBmDQowMDAwMDAwNDI0
IDY1NTM1IGYNCjAwMDAwMDA0MjUgNjU1MzUgZg0KMDAwMDAwMDQyNiA2NTUzNSBmDQowMDAw
MDAwNDI3IDY1NTM1IGYNCjAwMDAwMDA0MjggNjU1MzUgZg0KMDAwMDAwMDQyOSA2NTUzNSBm
DQowMDAwMDAwNDMwIDY1NTM1IGYNCjAwMDAwMDA0MzEgNjU1MzUgZg0KMDAwMDAwMDQzMiA2
NTUzNSBmDQowMDAwMDAwNDMzIDY1NTM1IGYNCjAwMDAwMDA0MzQgNjU1MzUgZg0KMDAwMDAw
MDQzNSA2NTUzNSBmDQowMDAwMDAwNDM2IDY1NTM1IGYNCjAwMDAwMDA0MzcgNjU1MzUgZg0K
MDAwMDAwMDQzOCA2NTUzNSBmDQowMDAwMDAwNDM5IDY1NTM1IGYNCjAwMDAwMDA0NDAgNjU1
MzUgZg0KMDAwMDAwMDQ0MSA2NTUzNSBmDQowMDAwMDAwNDQyIDY1NTM1IGYNCjAwMDAwMDA0
NDMgNjU1MzUgZg0KMDAwMDAwMDQ0NCA2NTUzNSBmDQowMDAwMDAwNDQ1IDY1NTM1IGYNCjAw
MDAwMDA0NDYgNjU1MzUgZg0KMDAwMDAwMDQ0NyA2NTUzNSBmDQowMDAwMDAwNDQ4IDY1NTM1
IGYNCjAwMDAwMDA0NDkgNjU1MzUgZg0KMDAwMDAwMDQ1MCA2NTUzNSBmDQowMDAwMDAwNDUx
IDY1NTM1IGYNCjAwMDAwMDA0NTIgNjU1MzUgZg0KMDAwMDAwMDQ1MyA2NTUzNSBmDQowMDAw
MDAwNDU0IDY1NTM1IGYNCjAwMDAwMDA0NTUgNjU1MzUgZg0KMDAwMDAwMDQ1NiA2NTUzNSBm
DQowMDAwMDAwNDU3IDY1NTM1IGYNCjAwMDAwMDA0NTggNjU1MzUgZg0KMDAwMDAwMDQ1OSA2
NTUzNSBmDQowMDAwMDAwNDYwIDY1NTM1IGYNCjAwMDAwMDA0NjEgNjU1MzUgZg0KMDAwMDAw
MDQ2MiA2NTUzNSBmDQowMDAwMDAwNDYzIDY1NTM1IGYNCjAwMDAwMDA0NjQgNjU1MzUgZg0K
MDAwMDAwMDQ2NSA2NTUzNSBmDQowMDAwMDAwNDY2IDY1NTM1IGYNCjAwMDAwMDA0NjcgNjU1
MzUgZg0KMDAwMDAwMDQ2OCA2NTUzNSBmDQowMDAwMDAwNDY5IDY1NTM1IGYNCjAwMDAwMDA0
NzAgNjU1MzUgZg0KMDAwMDAwMDQ3MSA2NTUzNSBmDQowMDAwMDAwNDcyIDY1NTM1IGYNCjAw
MDAwMDA0NzMgNjU1MzUgZg0KMDAwMDAwMDQ3NCA2NTUzNSBmDQowMDAwMDAwNDc1IDY1NTM1
IGYNCjAwMDAwMDA0NzYgNjU1MzUgZg0KMDAwMDAwMDQ3NyA2NTUzNSBmDQowMDAwMDAwNDc4
IDY1NTM1IGYNCjAwMDAwMDA0NzkgNjU1MzUgZg0KMDAwMDAwMDQ4MCA2NTUzNSBmDQowMDAw
MDAwNDgxIDY1NTM1IGYNCjAwMDAwMDA0ODIgNjU1MzUgZg0KMDAwMDAwMDQ4MyA2NTUzNSBm
DQowMDAwMDAwNDg0IDY1NTM1IGYNCjAwMDAwMDA0ODUgNjU1MzUgZg0KMDAwMDAwMDQ4NiA2
NTUzNSBmDQowMDAwMDAwNDg3IDY1NTM1IGYNCjAwMDAwMDA0ODggNjU1MzUgZg0KMDAwMDAw
MDQ4OSA2NTUzNSBmDQowMDAwMDAwNDkwIDY1NTM1IGYNCjAwMDAwMDA0OTEgNjU1MzUgZg0K
MDAwMDAwMDQ5MiA2NTUzNSBmDQowMDAwMDAwNDkzIDY1NTM1IGYNCjAwMDAwMDA0OTQgNjU1
MzUgZg0KMDAwMDAwMDQ5NSA2NTUzNSBmDQowMDAwMDAwNDk2IDY1NTM1IGYNCjAwMDAwMDA0
OTcgNjU1MzUgZg0KMDAwMDAwMDQ5OCA2NTUzNSBmDQowMDAwMDAwNDk5IDY1NTM1IGYNCjAw
MDAwMDA1MDAgNjU1MzUgZg0KMDAwMDAwMDUwMSA2NTUzNSBmDQowMDAwMDAwNTAyIDY1NTM1
IGYNCjAwMDAwMDA1MDMgNjU1MzUgZg0KMDAwMDAwMDUwNCA2NTUzNSBmDQowMDAwMDAwNTA1
IDY1NTM1IGYNCjAwMDAwMDA1MDYgNjU1MzUgZg0KMDAwMDAwMDUwNyA2NTUzNSBmDQowMDAw
MDAwNTA4IDY1NTM1IGYNCjAwMDAwMDA1MDkgNjU1MzUgZg0KMDAwMDAwMDUxMCA2NTUzNSBm
DQowMDAwMDAwNTExIDY1NTM1IGYNCjAwMDAwMDA1MTIgNjU1MzUgZg0KMDAwMDAwMDUxMyA2
NTUzNSBmDQowMDAwMDAwNTE0IDY1NTM1IGYNCjAwMDAwMDA1MTUgNjU1MzUgZg0KMDAwMDAw
MDUxNiA2NTUzNSBmDQowMDAwMDAwNTE3IDY1NTM1IGYNCjAwMDAwMDA1MTggNjU1MzUgZg0K
MDAwMDAwMDUxOSA2NTUzNSBmDQowMDAwMDAwNTIwIDY1NTM1IGYNCjAwMDAwMDA1MjEgNjU1
MzUgZg0KMDAwMDAwMDUyMiA2NTUzNSBmDQowMDAwMDAwNTIzIDY1NTM1IGYNCjAwMDAwMDA1
MjQgNjU1MzUgZg0KMDAwMDAwMDUyNSA2NTUzNSBmDQowMDAwMDAwNTI2IDY1NTM1IGYNCjAw
MDAwMDA1MjcgNjU1MzUgZg0KMDAwMDAwMDUyOCA2NTUzNSBmDQowMDAwMDAwNTI5IDY1NTM1
IGYNCjAwMDAwMDA1MzAgNjU1MzUgZg0KMDAwMDAwMDUzMSA2NTUzNSBmDQowMDAwMDAwNTMy
IDY1NTM1IGYNCjAwMDAwMDA1MzMgNjU1MzUgZg0KMDAwMDAwMDUzNCA2NTUzNSBmDQowMDAw
MDAwNTM1IDY1NTM1IGYNCjAwMDAwMDA1MzYgNjU1MzUgZg0KMDAwMDAwMDUzNyA2NTUzNSBm
DQowMDAwMDAwNTM4IDY1NTM1IGYNCjAwMDAwMDA1MzkgNjU1MzUgZg0KMDAwMDAwMDU0MCA2
NTUzNSBmDQowMDAwMDAwNTQxIDY1NTM1IGYNCjAwMDAwMDA1NDIgNjU1MzUgZg0KMDAwMDAw
MDU0MyA2NTUzNSBmDQowMDAwMDAwNTQ0IDY1NTM1IGYNCjAwMDAwMDA1NDUgNjU1MzUgZg0K
MDAwMDAwMDU0NiA2NTUzNSBmDQowMDAwMDAwNTQ3IDY1NTM1IGYNCjAwMDAwMDA1NDggNjU1
MzUgZg0KMDAwMDAwMDU0OSA2NTUzNSBmDQowMDAwMDAwNTUwIDY1NTM1IGYNCjAwMDAwMDA1
NTEgNjU1MzUgZg0KMDAwMDAwMDU1MiA2NTUzNSBmDQowMDAwMDAwNTUzIDY1NTM1IGYNCjAw
MDAwMDA1NTQgNjU1MzUgZg0KMDAwMDAwMDU1NSA2NTUzNSBmDQowMDAwMDAwNTU2IDY1NTM1
IGYNCjAwMDAwMDA1NTcgNjU1MzUgZg0KMDAwMDAwMDU1OCA2NTUzNSBmDQowMDAwMDAwNTU5
IDY1NTM1IGYNCjAwMDAwMDA1NjAgNjU1MzUgZg0KMDAwMDAwMDU2MSA2NTUzNSBmDQowMDAw
MDAwNTYyIDY1NTM1IGYNCjAwMDAwMDA1NjMgNjU1MzUgZg0KMDAwMDAwMDU2NCA2NTUzNSBm
DQowMDAwMDAwNTY1IDY1NTM1IGYNCjAwMDAwMDA1NjYgNjU1MzUgZg0KMDAwMDAwMDU2NyA2
NTUzNSBmDQowMDAwMDAwNTY4IDY1NTM1IGYNCjAwMDAwMDA1NjkgNjU1MzUgZg0KMDAwMDAw
MDU3MCA2NTUzNSBmDQowMDAwMDAwNTcxIDY1NTM1IGYNCjAwMDAwMDA1NzIgNjU1MzUgZg0K
MDAwMDAwMDU3MyA2NTUzNSBmDQowMDAwMDAwNTc0IDY1NTM1IGYNCjAwMDAwMDA1NzUgNjU1
MzUgZg0KMDAwMDAwMDU3NiA2NTUzNSBmDQowMDAwMDAwNTc3IDY1NTM1IGYNCjAwMDAwMDA1
NzggNjU1MzUgZg0KMDAwMDAwMDU3OSA2NTUzNSBmDQowMDAwMDAwNTgwIDY1NTM1IGYNCjAw
MDAwMDA1ODEgNjU1MzUgZg0KMDAwMDAwMDU4MiA2NTUzNSBmDQowMDAwMDAwNTgzIDY1NTM1
IGYNCjAwMDAwMDA1ODQgNjU1MzUgZg0KMDAwMDAwMDU4NSA2NTUzNSBmDQowMDAwMDAwNTg2
IDY1NTM1IGYNCjAwMDAwMDA1ODcgNjU1MzUgZg0KMDAwMDAwMDU4OCA2NTUzNSBmDQowMDAw
MDAwNTg5IDY1NTM1IGYNCjAwMDAwMDA1OTAgNjU1MzUgZg0KMDAwMDAwMDU5MSA2NTUzNSBm
DQowMDAwMDAwNTkyIDY1NTM1IGYNCjAwMDAwMDA1OTMgNjU1MzUgZg0KMDAwMDAwMDU5NCA2
NTUzNSBmDQowMDAwMDAwNTk1IDY1NTM1IGYNCjAwMDAwMDA1OTYgNjU1MzUgZg0KMDAwMDAw
MDU5NyA2NTUzNSBmDQowMDAwMDAwNTk4IDY1NTM1IGYNCjAwMDAwMDA1OTkgNjU1MzUgZg0K
MDAwMDAwMDYwMCA2NTUzNSBmDQowMDAwMDAwNjAxIDY1NTM1IGYNCjAwMDAwMDA2MDIgNjU1
MzUgZg0KMDAwMDAwMDYwMyA2NTUzNSBmDQowMDAwMDAwNjA0IDY1NTM1IGYNCjAwMDAwMDA2
MDUgNjU1MzUgZg0KMDAwMDAwMDYwNiA2NTUzNSBmDQowMDAwMDAwNjA3IDY1NTM1IGYNCjAw
MDAwMDA2MDggNjU1MzUgZg0KMDAwMDAwMDYwOSA2NTUzNSBmDQowMDAwMDAwNjEwIDY1NTM1
IGYNCjAwMDAwMDA2MTEgNjU1MzUgZg0KMDAwMDAwMDYxMiA2NTUzNSBmDQowMDAwMDAwNjEz
IDY1NTM1IGYNCjAwMDAwMDA2MTQgNjU1MzUgZg0KMDAwMDAwMDYxNSA2NTUzNSBmDQowMDAw
MDAwNjE2IDY1NTM1IGYNCjAwMDAwMDA2MTcgNjU1MzUgZg0KMDAwMDAwMDYxOCA2NTUzNSBm
DQowMDAwMDAwNjE5IDY1NTM1IGYNCjAwMDAwMDA2MjAgNjU1MzUgZg0KMDAwMDAwMDYyMSA2
NTUzNSBmDQowMDAwMDAwNjIyIDY1NTM1IGYNCjAwMDAwMDA2MjMgNjU1MzUgZg0KMDAwMDAw
MDYyNCA2NTUzNSBmDQowMDAwMDAwNjI1IDY1NTM1IGYNCjAwMDAwMDA2MjYgNjU1MzUgZg0K
MDAwMDAwMDYyNyA2NTUzNSBmDQowMDAwMDAwNjI4IDY1NTM1IGYNCjAwMDAwMDA2MjkgNjU1
MzUgZg0KMDAwMDAwMDYzMCA2NTUzNSBmDQowMDAwMDAwNjMxIDY1NTM1IGYNCjAwMDAwMDA2
MzIgNjU1MzUgZg0KMDAwMDAwMDYzMyA2NTUzNSBmDQowMDAwMDAwNjM0IDY1NTM1IGYNCjAw
MDAwMDA2MzUgNjU1MzUgZg0KMDAwMDAwMDYzNiA2NTUzNSBmDQowMDAwMDAwNjM3IDY1NTM1
IGYNCjAwMDAwMDA2MzggNjU1MzUgZg0KMDAwMDAwMDYzOSA2NTUzNSBmDQowMDAwMDAwNjQw
IDY1NTM1IGYNCjAwMDAwMDA2NDEgNjU1MzUgZg0KMDAwMDAwMDY0MiA2NTUzNSBmDQowMDAw
MDAwNjQzIDY1NTM1IGYNCjAwMDAwMDA2NDQgNjU1MzUgZg0KMDAwMDAwMDY0NSA2NTUzNSBm
DQowMDAwMDAwNjQ2IDY1NTM1IGYNCjAwMDAwMDA2NDcgNjU1MzUgZg0KMDAwMDAwMDY0OCA2
NTUzNSBmDQowMDAwMDAwNjUwIDY1NTM1IGYNCjAwMDAxMjQ2NzMgMDAwMDAgbg0KMDAwMDAw
MDY1MSA2NTUzNSBmDQowMDAwMDAwNjUyIDY1NTM1IGYNCjAwMDAwMDA2NTMgNjU1MzUgZg0K
MDAwMDAwMDY1NCA2NTUzNSBmDQowMDAwMDAwNjU1IDY1NTM1IGYNCjAwMDAwMDA2NTYgNjU1
MzUgZg0KMDAwMDAwMDY1NyA2NTUzNSBmDQowMDAwMDAwNjU4IDY1NTM1IGYNCjAwMDAwMDA2
NTkgNjU1MzUgZg0KMDAwMDAwMDY2MCA2NTUzNSBmDQowMDAwMDAwNjYxIDY1NTM1IGYNCjAw
MDAwMDA2NjIgNjU1MzUgZg0KMDAwMDAwMDY2MyA2NTUzNSBmDQowMDAwMDAwNjY0IDY1NTM1
IGYNCjAwMDAwMDA2NjUgNjU1MzUgZg0KMDAwMDAwMDY2NiA2NTUzNSBmDQowMDAwMDAwNjY3
IDY1NTM1IGYNCjAwMDAwMDA2NjggNjU1MzUgZg0KMDAwMDAwMDY2OSA2NTUzNSBmDQowMDAw
MDAwNjcwIDY1NTM1IGYNCjAwMDAwMDA2NzEgNjU1MzUgZg0KMDAwMDAwMDY3MiA2NTUzNSBm
DQowMDAwMDAwNjczIDY1NTM1IGYNCjAwMDAwMDA2NzQgNjU1MzUgZg0KMDAwMDAwMDY3NSA2
NTUzNSBmDQowMDAwMDAwNjc2IDY1NTM1IGYNCjAwMDAwMDA2NzcgNjU1MzUgZg0KMDAwMDAw
MDY3OCA2NTUzNSBmDQowMDAwMDAwNjc5IDY1NTM1IGYNCjAwMDAwMDA2ODAgNjU1MzUgZg0K
MDAwMDAwMDY4MSA2NTUzNSBmDQowMDAwMDAwNjgyIDY1NTM1IGYNCjAwMDAwMDA2ODMgNjU1
MzUgZg0KMDAwMDAwMDY4NCA2NTUzNSBmDQowMDAwMDAwNjg1IDY1NTM1IGYNCjAwMDAwMDA2
ODYgNjU1MzUgZg0KMDAwMDAwMDY4NyA2NTUzNSBmDQowMDAwMDAwNjg4IDY1NTM1IGYNCjAw
MDAwMDA2ODkgNjU1MzUgZg0KMDAwMDAwMDY5MCA2NTUzNSBmDQowMDAwMDAwNjkxIDY1NTM1
IGYNCjAwMDAwMDA2OTIgNjU1MzUgZg0KMDAwMDAwMDY5MyA2NTUzNSBmDQowMDAwMDAwNjk0
IDY1NTM1IGYNCjAwMDAwMDA2OTUgNjU1MzUgZg0KMDAwMDAwMDY5NiA2NTUzNSBmDQowMDAw
MDAwNjk3IDY1NTM1IGYNCjAwMDAwMDA2OTggNjU1MzUgZg0KMDAwMDAwMDY5OSA2NTUzNSBm
DQowMDAwMDAwNzAwIDY1NTM1IGYNCjAwMDAwMDA3MDEgNjU1MzUgZg0KMDAwMDAwMDcwMiA2
NTUzNSBmDQowMDAwMDAwNzAzIDY1NTM1IGYNCjAwMDAwMDA3MDQgNjU1MzUgZg0KMDAwMDAw
MDcwNSA2NTUzNSBmDQowMDAwMDAwNzA2IDY1NTM1IGYNCjAwMDAwMDA3MDcgNjU1MzUgZg0K
MDAwMDAwMDcwOCA2NTUzNSBmDQowMDAwMDAwNzA5IDY1NTM1IGYNCjAwMDAwMDA3MTAgNjU1
MzUgZg0KMDAwMDAwMDcxMSA2NTUzNSBmDQowMDAwMDAwNzEyIDY1NTM1IGYNCjAwMDAwMDA3
MTMgNjU1MzUgZg0KMDAwMDAwMDcxNCA2NTUzNSBmDQowMDAwMDAwNzE1IDY1NTM1IGYNCjAw
MDAwMDA3MTYgNjU1MzUgZg0KMDAwMDAwMDcxNyA2NTUzNSBmDQowMDAwMDAwNzE4IDY1NTM1
IGYNCjAwMDAwMDA3MTkgNjU1MzUgZg0KMDAwMDAwMDcyMCA2NTUzNSBmDQowMDAwMDAwNzIx
IDY1NTM1IGYNCjAwMDAwMDA3MjIgNjU1MzUgZg0KMDAwMDAwMDcyMyA2NTUzNSBmDQowMDAw
MDAwNzI0IDY1NTM1IGYNCjAwMDAwMDA3MjUgNjU1MzUgZg0KMDAwMDAwMDcyNiA2NTUzNSBm
DQowMDAwMDAwNzI3IDY1NTM1IGYNCjAwMDAwMDA3MjggNjU1MzUgZg0KMDAwMDAwMDcyOSA2
NTUzNSBmDQowMDAwMDAwNzMwIDY1NTM1IGYNCjAwMDAwMDA3MzEgNjU1MzUgZg0KMDAwMDAw
MDczMiA2NTUzNSBmDQowMDAwMDAwNzMzIDY1NTM1IGYNCjAwMDAwMDA3MzQgNjU1MzUgZg0K
MDAwMDAwMDczNSA2NTUzNSBmDQowMDAwMDAwNzM2IDY1NTM1IGYNCjAwMDAwMDA3MzcgNjU1
MzUgZg0KMDAwMDAwMDczOCA2NTUzNSBmDQowMDAwMDAwNzM5IDY1NTM1IGYNCjAwMDAwMDA3
NDAgNjU1MzUgZg0KMDAwMDAwMDc0MSA2NTUzNSBmDQowMDAwMDAwNzQyIDY1NTM1IGYNCjAw
MDAwMDA3NDMgNjU1MzUgZg0KMDAwMDAwMDc0NCA2NTUzNSBmDQowMDAwMDAwNzQ1IDY1NTM1
IGYNCjAwMDAwMDA3NDYgNjU1MzUgZg0KMDAwMDAwMDc0NyA2NTUzNSBmDQowMDAwMDAwNzQ4
IDY1NTM1IGYNCjAwMDAwMDA3NDkgNjU1MzUgZg0KMDAwMDAwMDc1MCA2NTUzNSBmDQowMDAw
MDAwNzUxIDY1NTM1IGYNCjAwMDAwMDA3NTIgNjU1MzUgZg0KMDAwMDAwMDc1MyA2NTUzNSBm
DQowMDAwMDAwNzU0IDY1NTM1IGYNCjAwMDAwMDA3NTUgNjU1MzUgZg0KMDAwMDAwMDc1NiA2
NTUzNSBmDQowMDAwMDAwNzU3IDY1NTM1IGYNCjAwMDAwMDA3NTggNjU1MzUgZg0KMDAwMDAw
MDc1OSA2NTUzNSBmDQowMDAwMDAwNzYwIDY1NTM1IGYNCjAwMDAwMDA3NjEgNjU1MzUgZg0K
MDAwMDAwMDc2MiA2NTUzNSBmDQowMDAwMDAwNzYzIDY1NTM1IGYNCjAwMDAwMDA3NjQgNjU1
MzUgZg0KMDAwMDAwMDc2NSA2NTUzNSBmDQowMDAwMDAwNzY2IDY1NTM1IGYNCjAwMDAwMDA3
NjcgNjU1MzUgZg0KMDAwMDAwMDc2OCA2NTUzNSBmDQowMDAwMDAwNzY5IDY1NTM1IGYNCjAw
MDAwMDA3NzAgNjU1MzUgZg0KMDAwMDAwMDc3MSA2NTUzNSBmDQowMDAwMDAwNzcyIDY1NTM1
IGYNCjAwMDAwMDA3NzMgNjU1MzUgZg0KMDAwMDAwMDc3NCA2NTUzNSBmDQowMDAwMDAwNzc1
IDY1NTM1IGYNCjAwMDAwMDA3NzYgNjU1MzUgZg0KMDAwMDAwMDc3NyA2NTUzNSBmDQowMDAw
MDAwNzc4IDY1NTM1IGYNCjAwMDAwMDA3NzkgNjU1MzUgZg0KMDAwMDAwMDc4MCA2NTUzNSBm
DQowMDAwMDAwNzgxIDY1NTM1IGYNCjAwMDAwMDA3ODIgNjU1MzUgZg0KMDAwMDAwMDc4MyA2
NTUzNSBmDQowMDAwMDAwNzg0IDY1NTM1IGYNCjAwMDAwMDA3ODUgNjU1MzUgZg0KMDAwMDAw
MDc4NiA2NTUzNSBmDQowMDAwMDAwNzg3IDY1NTM1IGYNCjAwMDAwMDA3ODggNjU1MzUgZg0K
MDAwMDAwMDc4OSA2NTUzNSBmDQowMDAwMDAwNzkwIDY1NTM1IGYNCjAwMDAwMDA3OTEgNjU1
MzUgZg0KMDAwMDAwMDc5MiA2NTUzNSBmDQowMDAwMDAwNzkzIDY1NTM1IGYNCjAwMDAwMDA3
OTQgNjU1MzUgZg0KMDAwMDAwMDc5NSA2NTUzNSBmDQowMDAwMDAwNzk2IDY1NTM1IGYNCjAw
MDAwMDA3OTcgNjU1MzUgZg0KMDAwMDAwMDc5OCA2NTUzNSBmDQowMDAwMDAwNzk5IDY1NTM1
IGYNCjAwMDAwMDA4MDAgNjU1MzUgZg0KMDAwMDAwMDgwMSA2NTUzNSBmDQowMDAwMDAwODAy
IDY1NTM1IGYNCjAwMDAwMDA4MDMgNjU1MzUgZg0KMDAwMDAwMDgwNCA2NTUzNSBmDQowMDAw
MDAwODA1IDY1NTM1IGYNCjAwMDAwMDA4MDYgNjU1MzUgZg0KMDAwMDAwMDgwNyA2NTUzNSBm
DQowMDAwMDAwODA4IDY1NTM1IGYNCjAwMDAwMDA4MDkgNjU1MzUgZg0KMDAwMDAwMDgxMCA2
NTUzNSBmDQowMDAwMDAwODExIDY1NTM1IGYNCjAwMDAwMDA4MTIgNjU1MzUgZg0KMDAwMDAw
MDgxMyA2NTUzNSBmDQowMDAwMDAwODE0IDY1NTM1IGYNCjAwMDAwMDA4MTUgNjU1MzUgZg0K
MDAwMDAwMDgxNiA2NTUzNSBmDQowMDAwMDAwODE3IDY1NTM1IGYNCjAwMDAwMDA4MTggNjU1
MzUgZg0KMDAwMDAwMDgxOSA2NTUzNSBmDQowMDAwMDAwODIwIDY1NTM1IGYNCjAwMDAwMDA4
MjEgNjU1MzUgZg0KMDAwMDAwMDgyMiA2NTUzNSBmDQowMDAwMDAwODIzIDY1NTM1IGYNCjAw
MDAwMDA4MjQgNjU1MzUgZg0KMDAwMDAwMDgyNSA2NTUzNSBmDQowMDAwMDAwODI2IDY1NTM1
IGYNCjAwMDAwMDA4MjcgNjU1MzUgZg0KMDAwMDAwMDgyOCA2NTUzNSBmDQowMDAwMDAwODI5
IDY1NTM1IGYNCjAwMDAwMDA4MzAgNjU1MzUgZg0KMDAwMDAwMDgzMSA2NTUzNSBmDQowMDAw
MDAwODMyIDY1NTM1IGYNCjAwMDAwMDA4MzMgNjU1MzUgZg0KMDAwMDAwMDgzNCA2NTUzNSBm
DQowMDAwMDAwODM1IDY1NTM1IGYNCjAwMDAwMDA4MzYgNjU1MzUgZg0KMDAwMDAwMDgzNyA2
NTUzNSBmDQowMDAwMDAwODM4IDY1NTM1IGYNCjAwMDAwMDA4MzkgNjU1MzUgZg0KMDAwMDAw
MDg0MCA2NTUzNSBmDQowMDAwMDAwODQxIDY1NTM1IGYNCjAwMDAwMDA4NDIgNjU1MzUgZg0K
MDAwMDAwMDg0MyA2NTUzNSBmDQowMDAwMDAwODQ0IDY1NTM1IGYNCjAwMDAwMDA4NDUgNjU1
MzUgZg0KMDAwMDAwMDg0NiA2NTUzNSBmDQowMDAwMDAwODQ3IDY1NTM1IGYNCjAwMDAwMDA4
NDggNjU1MzUgZg0KMDAwMDAwMDg0OSA2NTUzNSBmDQowMDAwMDAwODUwIDY1NTM1IGYNCjAw
MDAwMDA4NTEgNjU1MzUgZg0KMDAwMDAwMDg1MiA2NTUzNSBmDQowMDAwMDAwODUzIDY1NTM1
IGYNCjAwMDAwMDA4NTQgNjU1MzUgZg0KMDAwMDAwMDg1NSA2NTUzNSBmDQowMDAwMDAwODU2
IDY1NTM1IGYNCjAwMDAwMDA4NTcgNjU1MzUgZg0KMDAwMDAwMDg1OCA2NTUzNSBmDQowMDAw
MDAwODU5IDY1NTM1IGYNCjAwMDAwMDA4NjAgNjU1MzUgZg0KMDAwMDAwMDg2MSA2NTUzNSBm
DQowMDAwMDAwODYyIDY1NTM1IGYNCjAwMDAwMDA4NjMgNjU1MzUgZg0KMDAwMDAwMDg2NCA2
NTUzNSBmDQowMDAwMDAwODY1IDY1NTM1IGYNCjAwMDAwMDA4NjYgNjU1MzUgZg0KMDAwMDAw
MDg2NyA2NTUzNSBmDQowMDAwMDAwODY4IDY1NTM1IGYNCjAwMDAwMDA4NjkgNjU1MzUgZg0K
MDAwMDAwMDg3MCA2NTUzNSBmDQowMDAwMDAwODcxIDY1NTM1IGYNCjAwMDAwMDA4NzIgNjU1
MzUgZg0KMDAwMDAwMDg3MyA2NTUzNSBmDQowMDAwMDAwODc0IDY1NTM1IGYNCjAwMDAwMDA4
NzUgNjU1MzUgZg0KMDAwMDAwMDg3NiA2NTUzNSBmDQowMDAwMDAwODc3IDY1NTM1IGYNCjAw
MDAwMDA4NzggNjU1MzUgZg0KMDAwMDAwMDg3OSA2NTUzNSBmDQowMDAwMDAwODgwIDY1NTM1
IGYNCjAwMDAwMDA4ODEgNjU1MzUgZg0KMDAwMDAwMDg4MiA2NTUzNSBmDQowMDAwMDAwODgz
IDY1NTM1IGYNCjAwMDAwMDA4ODQgNjU1MzUgZg0KMDAwMDAwMDg4NSA2NTUzNSBmDQowMDAw
MDAwODg2IDY1NTM1IGYNCjAwMDAwMDA4ODcgNjU1MzUgZg0KMDAwMDAwMDg4OCA2NTUzNSBm
DQowMDAwMDAwODg5IDY1NTM1IGYNCjAwMDAwMDA4OTAgNjU1MzUgZg0KMDAwMDAwMDg5MSA2
NTUzNSBmDQowMDAwMDAwODkyIDY1NTM1IGYNCjAwMDAwMDA4OTMgNjU1MzUgZg0KMDAwMDAw
MDg5NCA2NTUzNSBmDQowMDAwMDAwODk1IDY1NTM1IGYNCjAwMDAwMDA4OTYgNjU1MzUgZg0K
MDAwMDAwMDg5NyA2NTUzNSBmDQowMDAwMDAwODk4IDY1NTM1IGYNCjAwMDAwMDA4OTkgNjU1
MzUgZg0KMDAwMDAwMDkwMCA2NTUzNSBmDQowMDAwMDAwOTAxIDY1NTM1IGYNCjAwMDAwMDA5
MDIgNjU1MzUgZg0KMDAwMDAwMDkwMyA2NTUzNSBmDQowMDAwMDAwOTA0IDY1NTM1IGYNCjAw
MDAwMDA5MDUgNjU1MzUgZg0KMDAwMDAwMDkwNiA2NTUzNSBmDQowMDAwMDAwOTA3IDY1NTM1
IGYNCjAwMDAwMDA5MDggNjU1MzUgZg0KMDAwMDAwMDkwOSA2NTUzNSBmDQowMDAwMDAwOTEw
IDY1NTM1IGYNCjAwMDAwMDA5MTEgNjU1MzUgZg0KMDAwMDAwMDkxMiA2NTUzNSBmDQowMDAw
MDAwOTEzIDY1NTM1IGYNCjAwMDAwMDA5MTQgNjU1MzUgZg0KMDAwMDAwMDkxNSA2NTUzNSBm
DQowMDAwMDAwOTE2IDY1NTM1IGYNCjAwMDAwMDA5MTcgNjU1MzUgZg0KMDAwMDAwMDkxOCA2
NTUzNSBmDQowMDAwMDAwOTE5IDY1NTM1IGYNCjAwMDAwMDA5MjAgNjU1MzUgZg0KMDAwMDAw
MDkyMSA2NTUzNSBmDQowMDAwMDAwOTIyIDY1NTM1IGYNCjAwMDAwMDA5MjMgNjU1MzUgZg0K
MDAwMDAwMDkyNCA2NTUzNSBmDQowMDAwMDAwOTI1IDY1NTM1IGYNCjAwMDAwMDA5MjYgNjU1
MzUgZg0KMDAwMDAwMDkyNyA2NTUzNSBmDQowMDAwMDAwOTI4IDY1NTM1IGYNCjAwMDAwMDA5
MjkgNjU1MzUgZg0KMDAwMDAwMDkzMCA2NTUzNSBmDQowMDAwMDAwOTMxIDY1NTM1IGYNCjAw
MDAwMDA5MzIgNjU1MzUgZg0KMDAwMDAwMDkzMyA2NTUzNSBmDQowMDAwMDAwOTM0IDY1NTM1
IGYNCjAwMDAwMDA5MzUgNjU1MzUgZg0KMDAwMDAwMDkzNiA2NTUzNSBmDQowMDAwMDAwOTM3
IDY1NTM1IGYNCjAwMDAwMDA5MzggNjU1MzUgZg0KMDAwMDAwMDkzOSA2NTUzNSBmDQowMDAw
MDAwOTQwIDY1NTM1IGYNCjAwMDAwMDA5NDEgNjU1MzUgZg0KMDAwMDAwMDk0MiA2NTUzNSBm
DQowMDAwMDAwOTQzIDY1NTM1IGYNCjAwMDAwMDA5NDQgNjU1MzUgZg0KMDAwMDAwMDk0NSA2
NTUzNSBmDQowMDAwMDAwOTQ2IDY1NTM1IGYNCjAwMDAwMDA5NDcgNjU1MzUgZg0KMDAwMDAw
MDk0OCA2NTUzNSBmDQowMDAwMDAwOTQ5IDY1NTM1IGYNCjAwMDAwMDA5NTAgNjU1MzUgZg0K
MDAwMDAwMDk1MSA2NTUzNSBmDQowMDAwMDAwOTUyIDY1NTM1IGYNCjAwMDAwMDA5NTMgNjU1
MzUgZg0KMDAwMDAwMDk1NCA2NTUzNSBmDQowMDAwMDAwOTU1IDY1NTM1IGYNCjAwMDAwMDA5
NTYgNjU1MzUgZg0KMDAwMDAwMDk1NyA2NTUzNSBmDQowMDAwMDAwOTU4IDY1NTM1IGYNCjAw
MDAwMDA5NTkgNjU1MzUgZg0KMDAwMDAwMDk2MCA2NTUzNSBmDQowMDAwMDAwOTYxIDY1NTM1
IGYNCjAwMDAwMDA5NjIgNjU1MzUgZg0KMDAwMDAwMDk2MyA2NTUzNSBmDQowMDAwMDAwOTY0
IDY1NTM1IGYNCjAwMDAwMDA5NjUgNjU1MzUgZg0KMDAwMDAwMDk2NiA2NTUzNSBmDQowMDAw
MDAwOTY3IDY1NTM1IGYNCjAwMDAwMDA5NjggNjU1MzUgZg0KMDAwMDAwMDk2OSA2NTUzNSBm
DQowMDAwMDAwOTcwIDY1NTM1IGYNCjAwMDAwMDA5NzEgNjU1MzUgZg0KMDAwMDAwMDk3MiA2
NTUzNSBmDQowMDAwMDAwOTczIDY1NTM1IGYNCjAwMDAwMDA5NzQgNjU1MzUgZg0KMDAwMDAw
MDk3NSA2NTUzNSBmDQowMDAwMDAwOTc2IDY1NTM1IGYNCjAwMDAwMDA5NzcgNjU1MzUgZg0K
MDAwMDAwMDk3OCA2NTUzNSBmDQowMDAwMDAwOTc5IDY1NTM1IGYNCjAwMDAwMDA5ODAgNjU1
MzUgZg0KMDAwMDAwMDk4MSA2NTUzNSBmDQowMDAwMDAwOTgyIDY1NTM1IGYNCjAwMDAwMDA5
ODMgNjU1MzUgZg0KMDAwMDAwMDk4NCA2NTUzNSBmDQowMDAwMDAwOTg1IDY1NTM1IGYNCjAw
MDAwMDA5ODYgNjU1MzUgZg0KMDAwMDAwMDk4NyA2NTUzNSBmDQowMDAwMDAwOTg4IDY1NTM1
IGYNCjAwMDAwMDA5ODkgNjU1MzUgZg0KMDAwMDAwMDk5MCA2NTUzNSBmDQowMDAwMDAwOTkx
IDY1NTM1IGYNCjAwMDAwMDA5OTIgNjU1MzUgZg0KMDAwMDAwMDk5MyA2NTUzNSBmDQowMDAw
MDAwOTk0IDY1NTM1IGYNCjAwMDAwMDA5OTUgNjU1MzUgZg0KMDAwMDAwMDk5NiA2NTUzNSBm
DQowMDAwMDAwOTk3IDY1NTM1IGYNCjAwMDAwMDA5OTggNjU1MzUgZg0KMDAwMDAwMDk5OSA2
NTUzNSBmDQowMDAwMDAxMDAwIDY1NTM1IGYNCjAwMDAwMDEwMDEgNjU1MzUgZg0KMDAwMDAw
MTAwMiA2NTUzNSBmDQowMDAwMDAxMDAzIDY1NTM1IGYNCjAwMDAwMDEwMDQgNjU1MzUgZg0K
MDAwMDAwMTAwNSA2NTUzNSBmDQowMDAwMDAxMDA2IDY1NTM1IGYNCjAwMDAwMDEwMDcgNjU1
MzUgZg0KMDAwMDAwMTAwOCA2NTUzNSBmDQowMDAwMDAxMDA5IDY1NTM1IGYNCjAwMDAwMDEw
MTAgNjU1MzUgZg0KMDAwMDAwMTAxMSA2NTUzNSBmDQowMDAwMDAxMDEyIDY1NTM1IGYNCjAw
MDAwMDEwMTMgNjU1MzUgZg0KMDAwMDAwMTAxNCA2NTUzNSBmDQowMDAwMDAxMDE1IDY1NTM1
IGYNCjAwMDAwMDEwMTYgNjU1MzUgZg0KMDAwMDAwMTAxNyA2NTUzNSBmDQowMDAwMDAxMDE4
IDY1NTM1IGYNCjAwMDAwMDEwMTkgNjU1MzUgZg0KMDAwMDAwMTAyMCA2NTUzNSBmDQowMDAw
MDAxMDIxIDY1NTM1IGYNCjAwMDAwMDEwMjIgNjU1MzUgZg0KMDAwMDAwMTAyMyA2NTUzNSBm
DQowMDAwMDAxMDI0IDY1NTM1IGYNCjAwMDAwMDEwMjUgNjU1MzUgZg0KMDAwMDAwMTAyNiA2
NTUzNSBmDQowMDAwMDAxMDI3IDY1NTM1IGYNCjAwMDAwMDEwMjggNjU1MzUgZg0KMDAwMDAw
MTAyOSA2NTUzNSBmDQowMDAwMDAxMDMwIDY1NTM1IGYNCjAwMDAwMDEwMzEgNjU1MzUgZg0K
MDAwMDAwMTAzMiA2NTUzNSBmDQowMDAwMDAxMDMzIDY1NTM1IGYNCjAwMDAwMDEwMzQgNjU1
MzUgZg0KMDAwMDAwMTAzNSA2NTUzNSBmDQowMDAwMDAxMDM2IDY1NTM1IGYNCjAwMDAwMDEw
MzcgNjU1MzUgZg0KMDAwMDAwMTAzOCA2NTUzNSBmDQowMDAwMDAxMDM5IDY1NTM1IGYNCjAw
MDAwMDEwNDAgNjU1MzUgZg0KMDAwMDAwMTA0MSA2NTUzNSBmDQowMDAwMDAxMDQyIDY1NTM1
IGYNCjAwMDAwMDEwNDMgNjU1MzUgZg0KMDAwMDAwMTA0NCA2NTUzNSBmDQowMDAwMDAxMDQ1
IDY1NTM1IGYNCjAwMDAwMDEwNDYgNjU1MzUgZg0KMDAwMDAwMTA0NyA2NTUzNSBmDQowMDAw
MDAxMDQ4IDY1NTM1IGYNCjAwMDAwMDEwNDkgNjU1MzUgZg0KMDAwMDAwMTA1MCA2NTUzNSBm
DQowMDAwMDAxMDUxIDY1NTM1IGYNCjAwMDAwMDEwNTIgNjU1MzUgZg0KMDAwMDAwMTA1MyA2
NTUzNSBmDQowMDAwMDAxMDU0IDY1NTM1IGYNCjAwMDAwMDEwNTUgNjU1MzUgZg0KMDAwMDAw
MTA1NiA2NTUzNSBmDQowMDAwMDAxMDU3IDY1NTM1IGYNCjAwMDAwMDEwNTggNjU1MzUgZg0K
MDAwMDAwMTA1OSA2NTUzNSBmDQowMDAwMDAxMDYwIDY1NTM1IGYNCjAwMDAwMDEwNjEgNjU1
MzUgZg0KMDAwMDAwMTA2MiA2NTUzNSBmDQowMDAwMDAxMDYzIDY1NTM1IGYNCjAwMDAwMDEw
NjQgNjU1MzUgZg0KMDAwMDAwMTA2NSA2NTUzNSBmDQowMDAwMDAxMDY2IDY1NTM1IGYNCjAw
MDAwMDEwNjcgNjU1MzUgZg0KMDAwMDAwMTA2OCA2NTUzNSBmDQowMDAwMDAxMDY5IDY1NTM1
IGYNCjAwMDAwMDEwNzAgNjU1MzUgZg0KMDAwMDAwMTA3MSA2NTUzNSBmDQowMDAwMDAxMDcy
IDY1NTM1IGYNCjAwMDAwMDEwNzMgNjU1MzUgZg0KMDAwMDAwMTA3NCA2NTUzNSBmDQowMDAw
MDAxMDc1IDY1NTM1IGYNCjAwMDAwMDEwNzYgNjU1MzUgZg0KMDAwMDAwMTA3NyA2NTUzNSBm
DQowMDAwMDAxMDc4IDY1NTM1IGYNCjAwMDAwMDEwNzkgNjU1MzUgZg0KMDAwMDAwMTA4MCA2
NTUzNSBmDQowMDAwMDAxMDgxIDY1NTM1IGYNCjAwMDAwMDEwODIgNjU1MzUgZg0KMDAwMDAw
MTA4MyA2NTUzNSBmDQowMDAwMDAxMDg0IDY1NTM1IGYNCjAwMDAwMDEwODUgNjU1MzUgZg0K
MDAwMDAwMTA4NiA2NTUzNSBmDQowMDAwMDAxMDg3IDY1NTM1IGYNCjAwMDAwMDEwODggNjU1
MzUgZg0KMDAwMDAwMTA4OSA2NTUzNSBmDQowMDAwMDAxMDkwIDY1NTM1IGYNCjAwMDAwMDEw
OTEgNjU1MzUgZg0KMDAwMDAwMTA5MiA2NTUzNSBmDQowMDAwMDAxMDkzIDY1NTM1IGYNCjAw
MDAwMDEwOTQgNjU1MzUgZg0KMDAwMDAwMTA5NSA2NTUzNSBmDQowMDAwMDAxMDk2IDY1NTM1
IGYNCjAwMDAwMDEwOTcgNjU1MzUgZg0KMDAwMDAwMTA5OCA2NTUzNSBmDQowMDAwMDAxMDk5
IDY1NTM1IGYNCjAwMDAwMDExMDAgNjU1MzUgZg0KMDAwMDAwMTEwMSA2NTUzNSBmDQowMDAw
MDAxMTAyIDY1NTM1IGYNCjAwMDAwMDExMDMgNjU1MzUgZg0KMDAwMDAwMTEwNCA2NTUzNSBm
DQowMDAwMDAxMTA1IDY1NTM1IGYNCjAwMDAwMDExMDYgNjU1MzUgZg0KMDAwMDAwMTEwNyA2
NTUzNSBmDQowMDAwMDAxMTA4IDY1NTM1IGYNCjAwMDAwMDExMDkgNjU1MzUgZg0KMDAwMDAw
MTExMCA2NTUzNSBmDQowMDAwMDAxMTExIDY1NTM1IGYNCjAwMDAwMDExMTIgNjU1MzUgZg0K
MDAwMDAwMTExMyA2NTUzNSBmDQowMDAwMDAxMTE0IDY1NTM1IGYNCjAwMDAwMDExMTUgNjU1
MzUgZg0KMDAwMDAwMTExNiA2NTUzNSBmDQowMDAwMDAxMTE3IDY1NTM1IGYNCjAwMDAwMDEx
MTggNjU1MzUgZg0KMDAwMDAwMTExOSA2NTUzNSBmDQowMDAwMDAxMTIwIDY1NTM1IGYNCjAw
MDAwMDExMjEgNjU1MzUgZg0KMDAwMDAwMTEyMiA2NTUzNSBmDQowMDAwMDAxMTIzIDY1NTM1
IGYNCjAwMDAwMDExMjQgNjU1MzUgZg0KMDAwMDAwMTEyNSA2NTUzNSBmDQowMDAwMDAxMTI2
IDY1NTM1IGYNCjAwMDAwMDExMjcgNjU1MzUgZg0KMDAwMDAwMTEyOCA2NTUzNSBmDQowMDAw
MDAxMTI5IDY1NTM1IGYNCjAwMDAwMDExMzAgNjU1MzUgZg0KMDAwMDAwMTEzMSA2NTUzNSBm
DQowMDAwMDAxMTMyIDY1NTM1IGYNCjAwMDAwMDExMzMgNjU1MzUgZg0KMDAwMDAwMTEzNCA2
NTUzNSBmDQowMDAwMDAxMTM1IDY1NTM1IGYNCjAwMDAwMDExMzYgNjU1MzUgZg0KMDAwMDAw
MTEzNyA2NTUzNSBmDQowMDAwMDAxMTM4IDY1NTM1IGYNCjAwMDAwMDExMzkgNjU1MzUgZg0K
MDAwMDAwMTE0MCA2NTUzNSBmDQowMDAwMDAxMTQxIDY1NTM1IGYNCjAwMDAwMDExNDIgNjU1
MzUgZg0KMDAwMDAwMTE0MyA2NTUzNSBmDQowMDAwMDAxMTQ0IDY1NTM1IGYNCjAwMDAwMDEx
NDUgNjU1MzUgZg0KMDAwMDAwMTE0NiA2NTUzNSBmDQowMDAwMDAxMTQ3IDY1NTM1IGYNCjAw
MDAwMDExNDggNjU1MzUgZg0KMDAwMDAwMTE0OSA2NTUzNSBmDQowMDAwMDAxMTUwIDY1NTM1
IGYNCjAwMDAwMDExNTEgNjU1MzUgZg0KMDAwMDAwMTE1MiA2NTUzNSBmDQowMDAwMDAxMTUz
IDY1NTM1IGYNCjAwMDAwMDExNTQgNjU1MzUgZg0KMDAwMDAwMTE1NSA2NTUzNSBmDQowMDAw
MDAxMTU2IDY1NTM1IGYNCjAwMDAwMDExNTcgNjU1MzUgZg0KMDAwMDAwMTE1OCA2NTUzNSBm
DQowMDAwMDAxMTU5IDY1NTM1IGYNCjAwMDAwMDExNjAgNjU1MzUgZg0KMDAwMDAwMTE2MSA2
NTUzNSBmDQowMDAwMDAxMTYyIDY1NTM1IGYNCjAwMDAwMDExNjMgNjU1MzUgZg0KMDAwMDAw
MTE2NCA2NTUzNSBmDQowMDAwMDAxMTY1IDY1NTM1IGYNCjAwMDAwMDExNjYgNjU1MzUgZg0K
MDAwMDAwMTE2NyA2NTUzNSBmDQowMDAwMDAxMTY4IDY1NTM1IGYNCjAwMDAwMDExNjkgNjU1
MzUgZg0KMDAwMDAwMTE3MCA2NTUzNSBmDQowMDAwMDAxMTcxIDY1NTM1IGYNCjAwMDAwMDEx
NzIgNjU1MzUgZg0KMDAwMDAwMTE3MyA2NTUzNSBmDQowMDAwMDAxMTc0IDY1NTM1IGYNCjAw
MDAwMDExNzUgNjU1MzUgZg0KMDAwMDAwMTE3NiA2NTUzNSBmDQowMDAwMDAxMTc3IDY1NTM1
IGYNCjAwMDAwMDExNzggNjU1MzUgZg0KMDAwMDAwMTE3OSA2NTUzNSBmDQowMDAwMDAxMTgw
IDY1NTM1IGYNCjAwMDAwMDExODEgNjU1MzUgZg0KMDAwMDAwMTE4MiA2NTUzNSBmDQowMDAw
MDAxMTgzIDY1NTM1IGYNCjAwMDAwMDExODQgNjU1MzUgZg0KMDAwMDAwMTE4NSA2NTUzNSBm
DQowMDAwMDAxMTg2IDY1NTM1IGYNCjAwMDAwMDExODcgNjU1MzUgZg0KMDAwMDAwMTE4OCA2
NTUzNSBmDQowMDAwMDAxMTg5IDY1NTM1IGYNCjAwMDAwMDExOTAgNjU1MzUgZg0KMDAwMDAw
MTE5MSA2NTUzNSBmDQowMDAwMDAxMTkyIDY1NTM1IGYNCjAwMDAwMDExOTMgNjU1MzUgZg0K
MDAwMDAwMTE5NCA2NTUzNSBmDQowMDAwMDAxMTk1IDY1NTM1IGYNCjAwMDAwMDExOTYgNjU1
MzUgZg0KMDAwMDAwMTE5NyA2NTUzNSBmDQowMDAwMDAxMTk4IDY1NTM1IGYNCjAwMDAwMDEx
OTkgNjU1MzUgZg0KMDAwMDAwMTIwMCA2NTUzNSBmDQowMDAwMDAxMjAxIDY1NTM1IGYNCjAw
MDAwMDEyMDIgNjU1MzUgZg0KMDAwMDAwMTIwMyA2NTUzNSBmDQowMDAwMDAxMjA0IDY1NTM1
IGYNCjAwMDAwMDEyMDUgNjU1MzUgZg0KMDAwMDAwMTIwNiA2NTUzNSBmDQowMDAwMDAxMjA3
IDY1NTM1IGYNCjAwMDAwMDEyMDggNjU1MzUgZg0KMDAwMDAwMTIwOSA2NTUzNSBmDQowMDAw
MDAxMjEwIDY1NTM1IGYNCjAwMDAwMDEyMTEgNjU1MzUgZg0KMDAwMDAwMTIxMiA2NTUzNSBm
DQowMDAwMDAxMjEzIDY1NTM1IGYNCjAwMDAwMDEyMTQgNjU1MzUgZg0KMDAwMDAwMTIxNSA2
NTUzNSBmDQowMDAwMDAxMjE2IDY1NTM1IGYNCjAwMDAwMDEyMTcgNjU1MzUgZg0KMDAwMDAw
MTIxOCA2NTUzNSBmDQowMDAwMDAxMjE5IDY1NTM1IGYNCjAwMDAwMDEyMjAgNjU1MzUgZg0K
MDAwMDAwMTIyMSA2NTUzNSBmDQowMDAwMDAxMjIyIDY1NTM1IGYNCjAwMDAwMDEyMjMgNjU1
MzUgZg0KMDAwMDAwMTIyNCA2NTUzNSBmDQowMDAwMDAxMjI1IDY1NTM1IGYNCjAwMDAwMDEy
MjYgNjU1MzUgZg0KMDAwMDAwMTIyNyA2NTUzNSBmDQowMDAwMDAxMjI4IDY1NTM1IGYNCjAw
MDAwMDEyMjkgNjU1MzUgZg0KMDAwMDAwMTIzMCA2NTUzNSBmDQowMDAwMDAxMjMxIDY1NTM1
IGYNCjAwMDAwMDEyMzIgNjU1MzUgZg0KMDAwMDAwMTIzMyA2NTUzNSBmDQowMDAwMDAxMjM0
IDY1NTM1IGYNCjAwMDAwMDEyMzUgNjU1MzUgZg0KMDAwMDAwMTIzNiA2NTUzNSBmDQowMDAw
MDAxMjM3IDY1NTM1IGYNCjAwMDAwMDEyMzggNjU1MzUgZg0KMDAwMDAwMTIzOSA2NTUzNSBm
DQowMDAwMDAxMjQwIDY1NTM1IGYNCjAwMDAwMDEyNDEgNjU1MzUgZg0KMDAwMDAwMTI0MiA2
NTUzNSBmDQowMDAwMDAxMjQzIDY1NTM1IGYNCjAwMDAwMDEyNDQgNjU1MzUgZg0KMDAwMDAw
MTI0NSA2NTUzNSBmDQowMDAwMDAxMjQ2IDY1NTM1IGYNCjAwMDAwMDEyNDcgNjU1MzUgZg0K
MDAwMDAwMTI0OCA2NTUzNSBmDQowMDAwMDAxMjQ5IDY1NTM1IGYNCjAwMDAwMDEyNTAgNjU1
MzUgZg0KMDAwMDAwMTI1MSA2NTUzNSBmDQowMDAwMDAxMjUyIDY1NTM1IGYNCjAwMDAwMDEy
NTMgNjU1MzUgZg0KMDAwMDAwMTI1NCA2NTUzNSBmDQowMDAwMDAxMjU1IDY1NTM1IGYNCjAw
MDAwMDEyNTYgNjU1MzUgZg0KMDAwMDAwMTI1NyA2NTUzNSBmDQowMDAwMDAxMjU4IDY1NTM1
IGYNCjAwMDAwMDEyNTkgNjU1MzUgZg0KMDAwMDAwMTI2MCA2NTUzNSBmDQowMDAwMDAxMjYx
IDY1NTM1IGYNCjAwMDAwMDEyNjIgNjU1MzUgZg0KMDAwMDAwMTI2MyA2NTUzNSBmDQowMDAw
MDAxMjY0IDY1NTM1IGYNCjAwMDAwMDEyNjUgNjU1MzUgZg0KMDAwMDAwMTI2NiA2NTUzNSBm
DQowMDAwMDAxMjY3IDY1NTM1IGYNCjAwMDAwMDEyNjggNjU1MzUgZg0KMDAwMDAwMTI2OSA2
NTUzNSBmDQowMDAwMDAxMjcwIDY1NTM1IGYNCjAwMDAwMDEyNzEgNjU1MzUgZg0KMDAwMDAw
MTI3MiA2NTUzNSBmDQowMDAwMDAxMjczIDY1NTM1IGYNCjAwMDAwMDEyNzQgNjU1MzUgZg0K
MDAwMDAwMTI3NSA2NTUzNSBmDQowMDAwMDAxMjc2IDY1NTM1IGYNCjAwMDAwMDEyNzcgNjU1
MzUgZg0KMDAwMDAwMTI3OCA2NTUzNSBmDQowMDAwMDAxMjc5IDY1NTM1IGYNCjAwMDAwMDEy
ODAgNjU1MzUgZg0KMDAwMDAwMTI4MSA2NTUzNSBmDQowMDAwMDAxMjgyIDY1NTM1IGYNCjAw
MDAwMDEyODMgNjU1MzUgZg0KMDAwMDAwMTI4NCA2NTUzNSBmDQowMDAwMDAxMjg1IDY1NTM1
IGYNCjAwMDAwMDEyODYgNjU1MzUgZg0KMDAwMDAwMTI4NyA2NTUzNSBmDQowMDAwMDAxMjg4
IDY1NTM1IGYNCjAwMDAwMDEyODkgNjU1MzUgZg0KMDAwMDAwMTI5MCA2NTUzNSBmDQowMDAw
MDAxMjkxIDY1NTM1IGYNCjAwMDAwMDEyOTIgNjU1MzUgZg0KMDAwMDAwMTI5MyA2NTUzNSBm
DQowMDAwMDAxMjk0IDY1NTM1IGYNCjAwMDAwMDEyOTUgNjU1MzUgZg0KMDAwMDAwMTI5NiA2
NTUzNSBmDQowMDAwMDAxMjk3IDY1NTM1IGYNCjAwMDAwMDEyOTggNjU1MzUgZg0KMDAwMDAw
MTI5OSA2NTUzNSBmDQowMDAwMDAxMzAwIDY1NTM1IGYNCjAwMDAwMDEzMDEgNjU1MzUgZg0K
MDAwMDAwMTMwMiA2NTUzNSBmDQowMDAwMDAxMzAzIDY1NTM1IGYNCjAwMDAwMDEzMDQgNjU1
MzUgZg0KMDAwMDAwMTMwNSA2NTUzNSBmDQowMDAwMDAxMzA2IDY1NTM1IGYNCjAwMDAwMDEz
MDcgNjU1MzUgZg0KMDAwMDAwMTMwOCA2NTUzNSBmDQowMDAwMDAxMzA5IDY1NTM1IGYNCjAw
MDAwMDEzMTAgNjU1MzUgZg0KMDAwMDAwMTMxMSA2NTUzNSBmDQowMDAwMDAxMzEyIDY1NTM1
IGYNCjAwMDAwMDEzMTMgNjU1MzUgZg0KMDAwMDAwMTMxNCA2NTUzNSBmDQowMDAwMDAxMzE1
IDY1NTM1IGYNCjAwMDAwMDEzMTYgNjU1MzUgZg0KMDAwMDAwMTMxNyA2NTUzNSBmDQowMDAw
MDAxMzE4IDY1NTM1IGYNCjAwMDAwMDEzMTkgNjU1MzUgZg0KMDAwMDAwMTMyMCA2NTUzNSBm
DQowMDAwMDAxMzIxIDY1NTM1IGYNCjAwMDAwMDEzMjIgNjU1MzUgZg0KMDAwMDAwMTMyMyA2
NTUzNSBmDQowMDAwMDAxMzI0IDY1NTM1IGYNCjAwMDAwMDEzMjUgNjU1MzUgZg0KMDAwMDAw
MTMyNiA2NTUzNSBmDQowMDAwMDAxMzI3IDY1NTM1IGYNCjAwMDAwMDEzMjggNjU1MzUgZg0K
MDAwMDAwMTMyOSA2NTUzNSBmDQowMDAwMDAxMzMwIDY1NTM1IGYNCjAwMDAwMDEzMzEgNjU1
MzUgZg0KMDAwMDAwMTMzMiA2NTUzNSBmDQowMDAwMDAxMzMzIDY1NTM1IGYNCjAwMDAwMDEz
MzQgNjU1MzUgZg0KMDAwMDAwMTMzNSA2NTUzNSBmDQowMDAwMDAxMzM2IDY1NTM1IGYNCjAw
MDAwMDEzMzcgNjU1MzUgZg0KMDAwMDAwMTMzOCA2NTUzNSBmDQowMDAwMDAxMzM5IDY1NTM1
IGYNCjAwMDAwMDEzNDAgNjU1MzUgZg0KMDAwMDAwMTM0MSA2NTUzNSBmDQowMDAwMDAxMzQy
IDY1NTM1IGYNCjAwMDAwMDEzNDMgNjU1MzUgZg0KMDAwMDAwMTM0NCA2NTUzNSBmDQowMDAw
MDAxMzQ1IDY1NTM1IGYNCjAwMDAwMDEzNDYgNjU1MzUgZg0KMDAwMDAwMTM0NyA2NTUzNSBm
DQowMDAwMDAxMzQ4IDY1NTM1IGYNCjAwMDAwMDEzNDkgNjU1MzUgZg0KMDAwMDAwMTM1MCA2
NTUzNSBmDQowMDAwMDAxMzUxIDY1NTM1IGYNCjAwMDAwMDEzNTIgNjU1MzUgZg0KMDAwMDAw
MTM1MyA2NTUzNSBmDQowMDAwMDAxMzU0IDY1NTM1IGYNCjAwMDAwMDEzNTUgNjU1MzUgZg0K
MDAwMDAwMTM1NiA2NTUzNSBmDQowMDAwMDAxMzU3IDY1NTM1IGYNCjAwMDAwMDEzNTggNjU1
MzUgZg0KMDAwMDAwMTM1OSA2NTUzNSBmDQowMDAwMDAxMzYwIDY1NTM1IGYNCjAwMDAwMDEz
NjEgNjU1MzUgZg0KMDAwMDAwMTM2MiA2NTUzNSBmDQowMDAwMDAxMzYzIDY1NTM1IGYNCjAw
MDAwMDEzNjQgNjU1MzUgZg0KMDAwMDAwMTM2NSA2NTUzNSBmDQowMDAwMDAxMzY2IDY1NTM1
IGYNCjAwMDAwMDEzNjcgNjU1MzUgZg0KMDAwMDAwMTM2OCA2NTUzNSBmDQowMDAwMDAxMzY5
IDY1NTM1IGYNCjAwMDAwMDEzNzAgNjU1MzUgZg0KMDAwMDAwMTM3MSA2NTUzNSBmDQowMDAw
MDAxMzcyIDY1NTM1IGYNCjAwMDAwMDEzNzMgNjU1MzUgZg0KMDAwMDAwMTM3NCA2NTUzNSBm
DQowMDAwMDAxMzc1IDY1NTM1IGYNCjAwMDAwMDEzNzYgNjU1MzUgZg0KMDAwMDAwMTM3NyA2
NTUzNSBmDQowMDAwMDAxMzc4IDY1NTM1IGYNCjAwMDAwMDEzNzkgNjU1MzUgZg0KMDAwMDAw
MTM4MCA2NTUzNSBmDQowMDAwMDAxMzgxIDY1NTM1IGYNCjAwMDAwMDEzODIgNjU1MzUgZg0K
MDAwMDAwMTM4MyA2NTUzNSBmDQowMDAwMDAxMzg0IDY1NTM1IGYNCjAwMDAwMDEzODUgNjU1
MzUgZg0KMDAwMDAwMTM4NiA2NTUzNSBmDQowMDAwMDAxMzg3IDY1NTM1IGYNCjAwMDAwMDEz
ODggNjU1MzUgZg0KMDAwMDAwMTM4OSA2NTUzNSBmDQowMDAwMDAxMzkwIDY1NTM1IGYNCjAw
MDAwMDEzOTEgNjU1MzUgZg0KMDAwMDAwMTM5MiA2NTUzNSBmDQowMDAwMDAxMzkzIDY1NTM1
IGYNCjAwMDAwMDEzOTQgNjU1MzUgZg0KMDAwMDAwMTM5NSA2NTUzNSBmDQowMDAwMDAxMzk2
IDY1NTM1IGYNCjAwMDAwMDEzOTcgNjU1MzUgZg0KMDAwMDAwMTM5OCA2NTUzNSBmDQowMDAw
MDAxMzk5IDY1NTM1IGYNCjAwMDAwMDE0MDAgNjU1MzUgZg0KMDAwMDAwMTQwMSA2NTUzNSBm
DQowMDAwMDAxNDAyIDY1NTM1IGYNCjAwMDAwMDE0MDMgNjU1MzUgZg0KMDAwMDAwMTQwNCA2
NTUzNSBmDQowMDAwMDAxNDA1IDY1NTM1IGYNCjAwMDAwMDE0MDYgNjU1MzUgZg0KMDAwMDAw
MTQwNyA2NTUzNSBmDQowMDAwMDAxNDA4IDY1NTM1IGYNCjAwMDAwMDE0MDkgNjU1MzUgZg0K
MDAwMDAwMTQxMCA2NTUzNSBmDQowMDAwMDAxNDExIDY1NTM1IGYNCjAwMDAwMDE0MTIgNjU1
MzUgZg0KMDAwMDAwMTQxMyA2NTUzNSBmDQowMDAwMDAxNDE0IDY1NTM1IGYNCjAwMDAwMDE0
MTUgNjU1MzUgZg0KMDAwMDAwMTQxNiA2NTUzNSBmDQowMDAwMDAxNDE3IDY1NTM1IGYNCjAw
MDAwMDE0MTggNjU1MzUgZg0KMDAwMDAwMTQxOSA2NTUzNSBmDQowMDAwMDAxNDIwIDY1NTM1
IGYNCjAwMDAwMDE0MjEgNjU1MzUgZg0KMDAwMDAwMTQyMiA2NTUzNSBmDQowMDAwMDAxNDIz
IDY1NTM1IGYNCjAwMDAwMDE0MjQgNjU1MzUgZg0KMDAwMDAwMTQyNSA2NTUzNSBmDQowMDAw
MDAxNDI2IDY1NTM1IGYNCjAwMDAwMDE0MjcgNjU1MzUgZg0KMDAwMDAwMTQyOCA2NTUzNSBm
DQowMDAwMDAxNDI5IDY1NTM1IGYNCjAwMDAwMDE0MzAgNjU1MzUgZg0KMDAwMDAwMTQzMSA2
NTUzNSBmDQowMDAwMDAxNDMyIDY1NTM1IGYNCjAwMDAwMDE0MzMgNjU1MzUgZg0KMDAwMDAw
MTQzNCA2NTUzNSBmDQowMDAwMDAxNDM1IDY1NTM1IGYNCjAwMDAwMDE0MzYgNjU1MzUgZg0K
MDAwMDAwMTQzNyA2NTUzNSBmDQowMDAwMDAxNDM4IDY1NTM1IGYNCjAwMDAwMDE0MzkgNjU1
MzUgZg0KMDAwMDAwMTQ0MCA2NTUzNSBmDQowMDAwMDAxNDQxIDY1NTM1IGYNCjAwMDAwMDE0
NDIgNjU1MzUgZg0KMDAwMDAwMTQ0MyA2NTUzNSBmDQowMDAwMDAxNDQ0IDY1NTM1IGYNCjAw
MDAwMDE0NDUgNjU1MzUgZg0KMDAwMDAwMTQ0NiA2NTUzNSBmDQowMDAwMDAxNDQ3IDY1NTM1
IGYNCjAwMDAwMDE0NDggNjU1MzUgZg0KMDAwMDAwMTQ0OSA2NTUzNSBmDQowMDAwMDAxNDUw
IDY1NTM1IGYNCjAwMDAwMDE0NTEgNjU1MzUgZg0KMDAwMDAwMTQ1MiA2NTUzNSBmDQowMDAw
MDAxNDUzIDY1NTM1IGYNCjAwMDAwMDE0NTQgNjU1MzUgZg0KMDAwMDAwMTQ1NSA2NTUzNSBm
DQowMDAwMDAxNDU2IDY1NTM1IGYNCjAwMDAwMDE0NTcgNjU1MzUgZg0KMDAwMDAwMTQ1OCA2
NTUzNSBmDQowMDAwMDAxNDU5IDY1NTM1IGYNCjAwMDAwMDE0NjAgNjU1MzUgZg0KMDAwMDAw
MTQ2MSA2NTUzNSBmDQowMDAwMDAxNDYyIDY1NTM1IGYNCjAwMDAwMDE0NjMgNjU1MzUgZg0K
MDAwMDAwMTQ2NCA2NTUzNSBmDQowMDAwMDAxNDY1IDY1NTM1IGYNCjAwMDAwMDE0NjYgNjU1
MzUgZg0KMDAwMDAwMTQ2NyA2NTUzNSBmDQowMDAwMDAxNDY4IDY1NTM1IGYNCjAwMDAwMDE0
NjkgNjU1MzUgZg0KMDAwMDAwMTQ3MCA2NTUzNSBmDQowMDAwMDAxNDcxIDY1NTM1IGYNCjAw
MDAwMDE0NzIgNjU1MzUgZg0KMDAwMDAwMTQ3MyA2NTUzNSBmDQowMDAwMDAxNDc0IDY1NTM1
IGYNCjAwMDAwMDE0NzUgNjU1MzUgZg0KMDAwMDAwMTQ3NiA2NTUzNSBmDQowMDAwMDAxNDc3
IDY1NTM1IGYNCjAwMDAwMDE0NzggNjU1MzUgZg0KMDAwMDAwMTQ3OSA2NTUzNSBmDQowMDAw
MDAxNDgwIDY1NTM1IGYNCjAwMDAwMDE0ODEgNjU1MzUgZg0KMDAwMDAwMTQ4MiA2NTUzNSBm
DQowMDAwMDAxNDgzIDY1NTM1IGYNCjAwMDAwMDE0ODQgNjU1MzUgZg0KMDAwMDAwMTQ4NSA2
NTUzNSBmDQowMDAwMDAxNDg2IDY1NTM1IGYNCjAwMDAwMDE0ODcgNjU1MzUgZg0KMDAwMDAw
MTQ4OCA2NTUzNSBmDQowMDAwMDAxNDg5IDY1NTM1IGYNCjAwMDAwMDE0OTAgNjU1MzUgZg0K
MDAwMDAwMTQ5MSA2NTUzNSBmDQowMDAwMDAxNDkyIDY1NTM1IGYNCjAwMDAwMDE0OTMgNjU1
MzUgZg0KMDAwMDAwMTQ5NCA2NTUzNSBmDQowMDAwMDAxNDk1IDY1NTM1IGYNCjAwMDAwMDE0
OTYgNjU1MzUgZg0KMDAwMDAwMTQ5NyA2NTUzNSBmDQowMDAwMDAxNDk4IDY1NTM1IGYNCjAw
MDAwMDE0OTkgNjU1MzUgZg0KMDAwMDAwMTUwMCA2NTUzNSBmDQowMDAwMDAxNTAxIDY1NTM1
IGYNCjAwMDAwMDE1MDIgNjU1MzUgZg0KMDAwMDAwMTUwMyA2NTUzNSBmDQowMDAwMDAxNTA0
IDY1NTM1IGYNCjAwMDAwMDE1MDUgNjU1MzUgZg0KMDAwMDAwMTUwNiA2NTUzNSBmDQowMDAw
MDAxNTA3IDY1NTM1IGYNCjAwMDAwMDE1MDggNjU1MzUgZg0KMDAwMDAwMTUwOSA2NTUzNSBm
DQowMDAwMDAxNTEwIDY1NTM1IGYNCjAwMDAwMDE1MTEgNjU1MzUgZg0KMDAwMDAwMTUxMiA2
NTUzNSBmDQowMDAwMDAxNTEzIDY1NTM1IGYNCjAwMDAwMDE1MTQgNjU1MzUgZg0KMDAwMDAw
MTUxNSA2NTUzNSBmDQowMDAwMDAxNTE2IDY1NTM1IGYNCjAwMDAwMDE1MTcgNjU1MzUgZg0K
MDAwMDAwMTUxOCA2NTUzNSBmDQowMDAwMDAxNTE5IDY1NTM1IGYNCjAwMDAwMDE1MjAgNjU1
MzUgZg0KMDAwMDAwMTUyMSA2NTUzNSBmDQowMDAwMDAxNTIyIDY1NTM1IGYNCjAwMDAwMDE1
MjMgNjU1MzUgZg0KMDAwMDAwMTUyNCA2NTUzNSBmDQowMDAwMDAxNTI1IDY1NTM1IGYNCjAw
MDAwMDE1MjYgNjU1MzUgZg0KMDAwMDAwMTUyNyA2NTUzNSBmDQowMDAwMDAxNTI4IDY1NTM1
IGYNCjAwMDAwMDE1MjkgNjU1MzUgZg0KMDAwMDAwMTUzMCA2NTUzNSBmDQowMDAwMDAxNTMx
IDY1NTM1IGYNCjAwMDAwMDE1MzIgNjU1MzUgZg0KMDAwMDAwMTUzMyA2NTUzNSBmDQowMDAw
MDAxNTM0IDY1NTM1IGYNCjAwMDAwMDE1MzUgNjU1MzUgZg0KMDAwMDAwMTUzNiA2NTUzNSBm
DQowMDAwMDAxNTM3IDY1NTM1IGYNCjAwMDAwMDE1MzggNjU1MzUgZg0KMDAwMDAwMTUzOSA2
NTUzNSBmDQowMDAwMDAxNTQwIDY1NTM1IGYNCjAwMDAwMDE1NDEgNjU1MzUgZg0KMDAwMDAw
MTU0MiA2NTUzNSBmDQowMDAwMDAxNTQzIDY1NTM1IGYNCjAwMDAwMDE1NDQgNjU1MzUgZg0K
MDAwMDAwMTU0NSA2NTUzNSBmDQowMDAwMDAxNTQ2IDY1NTM1IGYNCjAwMDAwMDE1NDcgNjU1
MzUgZg0KMDAwMDAwMTU0OCA2NTUzNSBmDQowMDAwMDAxNTQ5IDY1NTM1IGYNCjAwMDAwMDE1
NTAgNjU1MzUgZg0KMDAwMDAwMTU1MSA2NTUzNSBmDQowMDAwMDAxNTUyIDY1NTM1IGYNCjAw
MDAwMDE1NTMgNjU1MzUgZg0KMDAwMDAwMTU1NCA2NTUzNSBmDQowMDAwMDAxNTU1IDY1NTM1
IGYNCjAwMDAwMDE1NTYgNjU1MzUgZg0KMDAwMDAwMTU1NyA2NTUzNSBmDQowMDAwMDAxNTU4
IDY1NTM1IGYNCjAwMDAwMDE1NTkgNjU1MzUgZg0KMDAwMDAwMTU2MCA2NTUzNSBmDQowMDAw
MDAxNTYxIDY1NTM1IGYNCjAwMDAwMDE1NjIgNjU1MzUgZg0KMDAwMDAwMTU2MyA2NTUzNSBm
DQowMDAwMDAxNTY0IDY1NTM1IGYNCjAwMDAwMDE1NjUgNjU1MzUgZg0KMDAwMDAwMTU2NiA2
NTUzNSBmDQowMDAwMDAxNTY3IDY1NTM1IGYNCjAwMDAwMDE1NjggNjU1MzUgZg0KMDAwMDAw
MTU2OSA2NTUzNSBmDQowMDAwMDAxNTcwIDY1NTM1IGYNCjAwMDAwMDE1NzEgNjU1MzUgZg0K
MDAwMDAwMTU3MiA2NTUzNSBmDQowMDAwMDAxNTczIDY1NTM1IGYNCjAwMDAwMDE1NzQgNjU1
MzUgZg0KMDAwMDAwMTU3NSA2NTUzNSBmDQowMDAwMDAxNTc2IDY1NTM1IGYNCjAwMDAwMDE1
NzcgNjU1MzUgZg0KMDAwMDAwMTU3OCA2NTUzNSBmDQowMDAwMDAxNTc5IDY1NTM1IGYNCjAw
MDAwMDE1ODAgNjU1MzUgZg0KMDAwMDAwMTU4MSA2NTUzNSBmDQowMDAwMDAxNTgyIDY1NTM1
IGYNCjAwMDAwMDE1ODMgNjU1MzUgZg0KMDAwMDAwMTU4NCA2NTUzNSBmDQowMDAwMDAxNTg1
IDY1NTM1IGYNCjAwMDAwMDE1ODYgNjU1MzUgZg0KMDAwMDAwMTU4NyA2NTUzNSBmDQowMDAw
MDAxNTg4IDY1NTM1IGYNCjAwMDAwMDE1ODkgNjU1MzUgZg0KMDAwMDAwMTU5MCA2NTUzNSBm
DQowMDAwMDAxNTkxIDY1NTM1IGYNCjAwMDAwMDE1OTIgNjU1MzUgZg0KMDAwMDAwMTU5MyA2
NTUzNSBmDQowMDAwMDAxNTk0IDY1NTM1IGYNCjAwMDAwMDE1OTUgNjU1MzUgZg0KMDAwMDAw
MTU5NiA2NTUzNSBmDQowMDAwMDAxNTk3IDY1NTM1IGYNCjAwMDAwMDE1OTggNjU1MzUgZg0K
MDAwMDAwMTU5OSA2NTUzNSBmDQowMDAwMDAxNjAwIDY1NTM1IGYNCjAwMDAwMDE2MDEgNjU1
MzUgZg0KMDAwMDAwMTYwMiA2NTUzNSBmDQowMDAwMDAxNjAzIDY1NTM1IGYNCjAwMDAwMDE2
MDQgNjU1MzUgZg0KMDAwMDAwMTYwNSA2NTUzNSBmDQowMDAwMDAxNjA2IDY1NTM1IGYNCjAw
MDAwMDE2MDcgNjU1MzUgZg0KMDAwMDAwMTYwOCA2NTUzNSBmDQowMDAwMDAxNjA5IDY1NTM1
IGYNCjAwMDAwMDE2MTAgNjU1MzUgZg0KMDAwMDAwMTYxMSA2NTUzNSBmDQowMDAwMDAxNjEy
IDY1NTM1IGYNCjAwMDAwMDE2MTMgNjU1MzUgZg0KMDAwMDAwMTYxNCA2NTUzNSBmDQowMDAw
MDAxNjE1IDY1NTM1IGYNCjAwMDAwMDE2MTYgNjU1MzUgZg0KMDAwMDAwMTYxNyA2NTUzNSBm
DQowMDAwMDAxNjE4IDY1NTM1IGYNCjAwMDAwMDE2MTkgNjU1MzUgZg0KMDAwMDAwMTYyMCA2
NTUzNSBmDQowMDAwMDAxNjIxIDY1NTM1IGYNCjAwMDAwMDE2MjIgNjU1MzUgZg0KMDAwMDAw
MTYyMyA2NTUzNSBmDQowMDAwMDAxNjI0IDY1NTM1IGYNCjAwMDAwMDE2MjUgNjU1MzUgZg0K
MDAwMDAwMTYyNiA2NTUzNSBmDQowMDAwMDAxNjI3IDY1NTM1IGYNCjAwMDAwMDE2MjggNjU1
MzUgZg0KMDAwMDAwMTYyOSA2NTUzNSBmDQowMDAwMDAxNjMwIDY1NTM1IGYNCjAwMDAwMDE2
MzEgNjU1MzUgZg0KMDAwMDAwMTYzMiA2NTUzNSBmDQowMDAwMDAxNjMzIDY1NTM1IGYNCjAw
MDAwMDE2MzQgNjU1MzUgZg0KMDAwMDAwMTYzNSA2NTUzNSBmDQowMDAwMDAxNjM2IDY1NTM1
IGYNCjAwMDAwMDE2MzcgNjU1MzUgZg0KMDAwMDAwMTYzOCA2NTUzNSBmDQowMDAwMDAxNjM5
IDY1NTM1IGYNCjAwMDAwMDE2NDAgNjU1MzUgZg0KMDAwMDAwMTY0MSA2NTUzNSBmDQowMDAw
MDAxNjQyIDY1NTM1IGYNCjAwMDAwMDE2NDMgNjU1MzUgZg0KMDAwMDAwMTY0NCA2NTUzNSBm
DQowMDAwMDAxNjQ1IDY1NTM1IGYNCjAwMDAwMDE2NDYgNjU1MzUgZg0KMDAwMDAwMTY0NyA2
NTUzNSBmDQowMDAwMDAxNjQ4IDY1NTM1IGYNCjAwMDAwMDE2NDkgNjU1MzUgZg0KMDAwMDAw
MTY1MCA2NTUzNSBmDQowMDAwMDAxNjUxIDY1NTM1IGYNCjAwMDAwMDE2NTIgNjU1MzUgZg0K
MDAwMDAwMTY1MyA2NTUzNSBmDQowMDAwMDAxNjU0IDY1NTM1IGYNCjAwMDAwMDE2NTUgNjU1
MzUgZg0KMDAwMDAwMTY1NiA2NTUzNSBmDQowMDAwMDAxNjU3IDY1NTM1IGYNCjAwMDAwMDE2
NTggNjU1MzUgZg0KMDAwMDAwMTY1OSA2NTUzNSBmDQowMDAwMDAxNjYwIDY1NTM1IGYNCjAw
MDAwMDE2NjEgNjU1MzUgZg0KMDAwMDAwMTY2MiA2NTUzNSBmDQowMDAwMDAxNjYzIDY1NTM1
IGYNCjAwMDAwMDE2NjQgNjU1MzUgZg0KMDAwMDAwMTY2NSA2NTUzNSBmDQowMDAwMDAxNjY2
IDY1NTM1IGYNCjAwMDAwMDE2NjcgNjU1MzUgZg0KMDAwMDAwMTY2OCA2NTUzNSBmDQowMDAw
MDAxNjY5IDY1NTM1IGYNCjAwMDAwMDE2NzAgNjU1MzUgZg0KMDAwMDAwMTY3MSA2NTUzNSBm
DQowMDAwMDAxNjcyIDY1NTM1IGYNCjAwMDAwMDE2NzMgNjU1MzUgZg0KMDAwMDAwMTY3NCA2
NTUzNSBmDQowMDAwMDAxNjc1IDY1NTM1IGYNCjAwMDAwMDE2NzYgNjU1MzUgZg0KMDAwMDAw
MTY3NyA2NTUzNSBmDQowMDAwMDAxNjc4IDY1NTM1IGYNCjAwMDAwMDE2NzkgNjU1MzUgZg0K
MDAwMDAwMTY4MCA2NTUzNSBmDQowMDAwMDAxNjgxIDY1NTM1IGYNCjAwMDAwMDE2ODIgNjU1
MzUgZg0KMDAwMDAwMTY4MyA2NTUzNSBmDQowMDAwMDAxNjg0IDY1NTM1IGYNCjAwMDAwMDE2
ODUgNjU1MzUgZg0KMDAwMDAwMTY4NiA2NTUzNSBmDQowMDAwMDAxNjg3IDY1NTM1IGYNCjAw
MDAwMDE2ODggNjU1MzUgZg0KMDAwMDAwMTY4OSA2NTUzNSBmDQowMDAwMDAxNjkwIDY1NTM1
IGYNCjAwMDAwMDE2OTEgNjU1MzUgZg0KMDAwMDAwMTY5MiA2NTUzNSBmDQowMDAwMDAxNjkz
IDY1NTM1IGYNCjAwMDAwMDE2OTQgNjU1MzUgZg0KMDAwMDAwMTY5NSA2NTUzNSBmDQowMDAw
MDAxNjk2IDY1NTM1IGYNCjAwMDAwMDE2OTcgNjU1MzUgZg0KMDAwMDAwMTY5OCA2NTUzNSBm
DQowMDAwMDAxNjk5IDY1NTM1IGYNCjAwMDAwMDE3MDAgNjU1MzUgZg0KMDAwMDAwMTcwMSA2
NTUzNSBmDQowMDAwMDAxNzAyIDY1NTM1IGYNCjAwMDAwMDE3MDMgNjU1MzUgZg0KMDAwMDAw
MTcwNCA2NTUzNSBmDQowMDAwMDAxNzA1IDY1NTM1IGYNCjAwMDAwMDE3MDYgNjU1MzUgZg0K
MDAwMDAwMTcwNyA2NTUzNSBmDQowMDAwMDAxNzA4IDY1NTM1IGYNCjAwMDAwMDE3MDkgNjU1
MzUgZg0KMDAwMDAwMTcxMCA2NTUzNSBmDQowMDAwMDAxNzExIDY1NTM1IGYNCjAwMDAwMDE3
MTIgNjU1MzUgZg0KMDAwMDAwMTcxMyA2NTUzNSBmDQowMDAwMDAxNzE0IDY1NTM1IGYNCjAw
MDAwMDE3MTUgNjU1MzUgZg0KMDAwMDAwMTcxNiA2NTUzNSBmDQowMDAwMDAxNzE3IDY1NTM1
IGYNCjAwMDAwMDE3MTggNjU1MzUgZg0KMDAwMDAwMTcxOSA2NTUzNSBmDQowMDAwMDAxNzIw
IDY1NTM1IGYNCjAwMDAwMDE3MjEgNjU1MzUgZg0KMDAwMDAwMTcyMiA2NTUzNSBmDQowMDAw
MDAxNzIzIDY1NTM1IGYNCjAwMDAwMDE3MjQgNjU1MzUgZg0KMDAwMDAwMTcyNSA2NTUzNSBm
DQowMDAwMDAxNzI2IDY1NTM1IGYNCjAwMDAwMDE3MjcgNjU1MzUgZg0KMDAwMDAwMTcyOCA2
NTUzNSBmDQowMDAwMDAxNzI5IDY1NTM1IGYNCjAwMDAwMDE3MzAgNjU1MzUgZg0KMDAwMDAw
MTczMSA2NTUzNSBmDQowMDAwMDAxNzMyIDY1NTM1IGYNCjAwMDAwMDE3MzMgNjU1MzUgZg0K
MDAwMDAwMTczNCA2NTUzNSBmDQowMDAwMDAxNzM1IDY1NTM1IGYNCjAwMDAwMDE3MzYgNjU1
MzUgZg0KMDAwMDAwMTczNyA2NTUzNSBmDQowMDAwMDAxNzM4IDY1NTM1IGYNCjAwMDAwMDE3
MzkgNjU1MzUgZg0KMDAwMDAwMTc0MCA2NTUzNSBmDQowMDAwMDAxNzQxIDY1NTM1IGYNCjAw
MDAwMDE3NDIgNjU1MzUgZg0KMDAwMDAwMTc0MyA2NTUzNSBmDQowMDAwMDAxNzQ0IDY1NTM1
IGYNCjAwMDAwMDE3NDUgNjU1MzUgZg0KMDAwMDAwMTc0NiA2NTUzNSBmDQowMDAwMDAxNzQ3
IDY1NTM1IGYNCjAwMDAwMDE3NDggNjU1MzUgZg0KMDAwMDAwMTc0OSA2NTUzNSBmDQowMDAw
MDAxNzUwIDY1NTM1IGYNCjAwMDAwMDE3NTEgNjU1MzUgZg0KMDAwMDAwMTc1MiA2NTUzNSBm
DQowMDAwMDAxNzUzIDY1NTM1IGYNCjAwMDAwMDE3NTQgNjU1MzUgZg0KMDAwMDAwMTc1NSA2
NTUzNSBmDQowMDAwMDAxNzU2IDY1NTM1IGYNCjAwMDAwMDE3NTcgNjU1MzUgZg0KMDAwMDAw
MTc1OCA2NTUzNSBmDQowMDAwMDAxNzU5IDY1NTM1IGYNCjAwMDAwMDE3NjAgNjU1MzUgZg0K
MDAwMDAwMTc2MSA2NTUzNSBmDQowMDAwMDAxNzYyIDY1NTM1IGYNCjAwMDAwMDE3NjMgNjU1
MzUgZg0KMDAwMDAwMTc2NCA2NTUzNSBmDQowMDAwMDAxNzY1IDY1NTM1IGYNCjAwMDAwMDE3
NjYgNjU1MzUgZg0KMDAwMDAwMTc2NyA2NTUzNSBmDQowMDAwMDAxNzY4IDY1NTM1IGYNCjAw
MDAwMDE3NjkgNjU1MzUgZg0KMDAwMDAwMTc3MCA2NTUzNSBmDQowMDAwMDAxNzcxIDY1NTM1
IGYNCjAwMDAwMDE3NzIgNjU1MzUgZg0KMDAwMDAwMTc3MyA2NTUzNSBmDQowMDAwMDAxNzc0
IDY1NTM1IGYNCjAwMDAwMDE3NzUgNjU1MzUgZg0KMDAwMDAwMTc3NyA2NTUzNSBmDQowMDAw
MTM4NTE4IDAwMDAwIG4NCjAwMDAwMDE3NzggNjU1MzUgZg0KMDAwMDAwMTc3OSA2NTUzNSBm
DQowMDAwMDAxNzgwIDY1NTM1IGYNCjAwMDAwMDE3ODEgNjU1MzUgZg0KMDAwMDAwMTc4MiA2
NTUzNSBmDQowMDAwMDAxNzgzIDY1NTM1IGYNCjAwMDAwMDE3ODQgNjU1MzUgZg0KMDAwMDAw
MTc4NSA2NTUzNSBmDQowMDAwMDAxNzg2IDY1NTM1IGYNCjAwMDAwMDE3ODcgNjU1MzUgZg0K
MDAwMDAwMTc4OCA2NTUzNSBmDQowMDAwMDAxNzg5IDY1NTM1IGYNCjAwMDAwMDE3OTAgNjU1
MzUgZg0KMDAwMDAwMTc5MSA2NTUzNSBmDQowMDAwMDAxNzkyIDY1NTM1IGYNCjAwMDAwMDE3
OTMgNjU1MzUgZg0KMDAwMDAwMTc5NCA2NTUzNSBmDQowMDAwMDAxNzk1IDY1NTM1IGYNCjAw
MDAwMDE3OTYgNjU1MzUgZg0KMDAwMDAwMTc5NyA2NTUzNSBmDQowMDAwMDAxNzk4IDY1NTM1
IGYNCjAwMDAwMDE3OTkgNjU1MzUgZg0KMDAwMDAwMTgwMCA2NTUzNSBmDQowMDAwMDAxODAx
IDY1NTM1IGYNCjAwMDAwMDE4MDIgNjU1MzUgZg0KMDAwMDAwMTgwMyA2NTUzNSBmDQowMDAw
MDAxODA0IDY1NTM1IGYNCjAwMDAwMDE4MDUgNjU1MzUgZg0KMDAwMDAwMTgwNiA2NTUzNSBm
DQowMDAwMDAxODA3IDY1NTM1IGYNCjAwMDAwMDE4MDggNjU1MzUgZg0KMDAwMDAwMTgwOSA2
NTUzNSBmDQowMDAwMDAxODEwIDY1NTM1IGYNCjAwMDAwMDE4MTEgNjU1MzUgZg0KMDAwMDAw
MTgxMiA2NTUzNSBmDQowMDAwMDAxODEzIDY1NTM1IGYNCjAwMDAwMDE4MTQgNjU1MzUgZg0K
MDAwMDAwMTgxNSA2NTUzNSBmDQowMDAwMDAxODE2IDY1NTM1IGYNCjAwMDAwMDE4MTcgNjU1
MzUgZg0KMDAwMDAwMTgxOCA2NTUzNSBmDQowMDAwMDAxODE5IDY1NTM1IGYNCjAwMDAwMDE4
MjAgNjU1MzUgZg0KMDAwMDAwMTgyMSA2NTUzNSBmDQowMDAwMDAxODIyIDY1NTM1IGYNCjAw
MDAwMDE4MjMgNjU1MzUgZg0KMDAwMDAwMTgyNCA2NTUzNSBmDQowMDAwMDAxODI1IDY1NTM1
IGYNCjAwMDAwMDE4MjYgNjU1MzUgZg0KMDAwMDAwMTgyNyA2NTUzNSBmDQowMDAwMDAxODI4
IDY1NTM1IGYNCjAwMDAwMDE4MjkgNjU1MzUgZg0KMDAwMDAwMTgzMCA2NTUzNSBmDQowMDAw
MDAxODMxIDY1NTM1IGYNCjAwMDAwMDE4MzIgNjU1MzUgZg0KMDAwMDAwMTgzMyA2NTUzNSBm
DQowMDAwMDAxODM0IDY1NTM1IGYNCjAwMDAwMDE4MzUgNjU1MzUgZg0KMDAwMDAwMTgzNiA2
NTUzNSBmDQowMDAwMDAxODM3IDY1NTM1IGYNCjAwMDAwMDE4MzggNjU1MzUgZg0KMDAwMDAw
MTgzOSA2NTUzNSBmDQowMDAwMDAxODQwIDY1NTM1IGYNCjAwMDAwMDE4NDEgNjU1MzUgZg0K
MDAwMDAwMTg0MiA2NTUzNSBmDQowMDAwMDAxODQzIDY1NTM1IGYNCjAwMDAwMDE4NDQgNjU1
MzUgZg0KMDAwMDAwMTg0NSA2NTUzNSBmDQowMDAwMDAxODQ2IDY1NTM1IGYNCjAwMDAwMDE4
NDcgNjU1MzUgZg0KMDAwMDAwMTg0OCA2NTUzNSBmDQowMDAwMDAxODQ5IDY1NTM1IGYNCjAw
MDAwMDE4NTAgNjU1MzUgZg0KMDAwMDAwMTg1MSA2NTUzNSBmDQowMDAwMDAxODUyIDY1NTM1
IGYNCjAwMDAwMDE4NTMgNjU1MzUgZg0KMDAwMDAwMTg1NCA2NTUzNSBmDQowMDAwMDAxODU1
IDY1NTM1IGYNCjAwMDAwMDE4NTYgNjU1MzUgZg0KMDAwMDAwMTg1NyA2NTUzNSBmDQowMDAw
MDAxODU4IDY1NTM1IGYNCjAwMDAwMDE4NTkgNjU1MzUgZg0KMDAwMDAwMTg2MCA2NTUzNSBm
DQowMDAwMDAxODYxIDY1NTM1IGYNCjAwMDAwMDE4NjIgNjU1MzUgZg0KMDAwMDAwMTg2MyA2
NTUzNSBmDQowMDAwMDAxODY0IDY1NTM1IGYNCjAwMDAwMDE4NjUgNjU1MzUgZg0KMDAwMDAw
MTg2NiA2NTUzNSBmDQowMDAwMDAxODY3IDY1NTM1IGYNCjAwMDAwMDE4NjggNjU1MzUgZg0K
MDAwMDAwMTg2OSA2NTUzNSBmDQowMDAwMDAxODcwIDY1NTM1IGYNCjAwMDAwMDE4NzEgNjU1
MzUgZg0KMDAwMDAwMTg3MiA2NTUzNSBmDQowMDAwMDAxODczIDY1NTM1IGYNCjAwMDAwMDE4
NzQgNjU1MzUgZg0KMDAwMDAwMTg3NSA2NTUzNSBmDQowMDAwMDAxODc2IDY1NTM1IGYNCjAw
MDAwMDE4NzcgNjU1MzUgZg0KMDAwMDAwMTg3OCA2NTUzNSBmDQowMDAwMDAxODc5IDY1NTM1
IGYNCjAwMDAwMDE4ODAgNjU1MzUgZg0KMDAwMDAwMTg4MSA2NTUzNSBmDQowMDAwMDAxODgy
IDY1NTM1IGYNCjAwMDAwMDE4ODMgNjU1MzUgZg0KMDAwMDAwMTg4NCA2NTUzNSBmDQowMDAw
MDAxODg1IDY1NTM1IGYNCjAwMDAwMDE4ODYgNjU1MzUgZg0KMDAwMDAwMTg4NyA2NTUzNSBm
DQowMDAwMDAxODg4IDY1NTM1IGYNCjAwMDAwMDE4ODkgNjU1MzUgZg0KMDAwMDAwMTg5MCA2
NTUzNSBmDQowMDAwMDAxODkxIDY1NTM1IGYNCjAwMDAwMDE4OTIgNjU1MzUgZg0KMDAwMDAw
MTg5MyA2NTUzNSBmDQowMDAwMDAxODk0IDY1NTM1IGYNCjAwMDAwMDE4OTUgNjU1MzUgZg0K
MDAwMDAwMTg5NiA2NTUzNSBmDQowMDAwMDAxODk3IDY1NTM1IGYNCjAwMDAwMDE4OTggNjU1
MzUgZg0KMDAwMDAwMTg5OSA2NTUzNSBmDQowMDAwMDAxOTAwIDY1NTM1IGYNCjAwMDAwMDE5
MDEgNjU1MzUgZg0KMDAwMDAwMTkwMiA2NTUzNSBmDQowMDAwMDAxOTAzIDY1NTM1IGYNCjAw
MDAwMDE5MDQgNjU1MzUgZg0KMDAwMDAwMTkwNSA2NTUzNSBmDQowMDAwMDAxOTA2IDY1NTM1
IGYNCjAwMDAwMDE5MDcgNjU1MzUgZg0KMDAwMDAwMTkwOCA2NTUzNSBmDQowMDAwMDAxOTA5
IDY1NTM1IGYNCjAwMDAwMDE5MTAgNjU1MzUgZg0KMDAwMDAwMTkxMSA2NTUzNSBmDQowMDAw
MDAxOTEyIDY1NTM1IGYNCjAwMDAwMDE5MTMgNjU1MzUgZg0KMDAwMDAwMTkxNCA2NTUzNSBm
DQowMDAwMDAxOTE1IDY1NTM1IGYNCjAwMDAwMDE5MTYgNjU1MzUgZg0KMDAwMDAwMTkxNyA2
NTUzNSBmDQowMDAwMDAxOTE4IDY1NTM1IGYNCjAwMDAwMDE5MTkgNjU1MzUgZg0KMDAwMDAw
MTkyMCA2NTUzNSBmDQowMDAwMDAxOTIxIDY1NTM1IGYNCjAwMDAwMDE5MjIgNjU1MzUgZg0K
MDAwMDAwMTkyMyA2NTUzNSBmDQowMDAwMDAxOTI0IDY1NTM1IGYNCjAwMDAwMDE5MjUgNjU1
MzUgZg0KMDAwMDAwMTkyNiA2NTUzNSBmDQowMDAwMDAxOTI3IDY1NTM1IGYNCjAwMDAwMDE5
MjggNjU1MzUgZg0KMDAwMDAwMTkyOSA2NTUzNSBmDQowMDAwMDAxOTMwIDY1NTM1IGYNCjAw
MDAwMDE5MzEgNjU1MzUgZg0KMDAwMDAwMTkzMiA2NTUzNSBmDQowMDAwMDAxOTMzIDY1NTM1
IGYNCjAwMDAwMDE5MzQgNjU1MzUgZg0KMDAwMDAwMTkzNSA2NTUzNSBmDQowMDAwMDAxOTM2
IDY1NTM1IGYNCjAwMDAwMDE5MzcgNjU1MzUgZg0KMDAwMDAwMTkzOCA2NTUzNSBmDQowMDAw
MDAxOTM5IDY1NTM1IGYNCjAwMDAwMDE5NDAgNjU1MzUgZg0KMDAwMDAwMTk0MSA2NTUzNSBm
DQowMDAwMDAxOTQyIDY1NTM1IGYNCjAwMDAwMDE5NDMgNjU1MzUgZg0KMDAwMDAwMTk0NCA2
NTUzNSBmDQowMDAwMDAxOTQ1IDY1NTM1IGYNCjAwMDAwMDE5NDYgNjU1MzUgZg0KMDAwMDAw
MTk0NyA2NTUzNSBmDQowMDAwMDAxOTQ4IDY1NTM1IGYNCjAwMDAwMDE5NDkgNjU1MzUgZg0K
MDAwMDAwMTk1MCA2NTUzNSBmDQowMDAwMDAxOTUxIDY1NTM1IGYNCjAwMDAwMDE5NTIgNjU1
MzUgZg0KMDAwMDAwMTk1MyA2NTUzNSBmDQowMDAwMDAxOTU0IDY1NTM1IGYNCjAwMDAwMDE5
NTUgNjU1MzUgZg0KMDAwMDAwMTk1NiA2NTUzNSBmDQowMDAwMDAxOTU3IDY1NTM1IGYNCjAw
MDAwMDE5NTggNjU1MzUgZg0KMDAwMDAwMTk1OSA2NTUzNSBmDQowMDAwMDAxOTYwIDY1NTM1
IGYNCjAwMDAwMDE5NjEgNjU1MzUgZg0KMDAwMDAwMTk2MiA2NTUzNSBmDQowMDAwMDAxOTYz
IDY1NTM1IGYNCjAwMDAwMDE5NjQgNjU1MzUgZg0KMDAwMDAwMTk2NSA2NTUzNSBmDQowMDAw
MDAxOTY2IDY1NTM1IGYNCjAwMDAwMDE5NjcgNjU1MzUgZg0KMDAwMDAwMTk2OCA2NTUzNSBm
DQowMDAwMDAxOTY5IDY1NTM1IGYNCjAwMDAwMDE5NzAgNjU1MzUgZg0KMDAwMDAwMTk3MSA2
NTUzNSBmDQowMDAwMDAxOTcyIDY1NTM1IGYNCjAwMDAwMDE5NzMgNjU1MzUgZg0KMDAwMDAw
MTk3NCA2NTUzNSBmDQowMDAwMDAxOTc1IDY1NTM1IGYNCjAwMDAwMDE5NzYgNjU1MzUgZg0K
MDAwMDAwMTk3NyA2NTUzNSBmDQowMDAwMDAxOTc4IDY1NTM1IGYNCjAwMDAwMDE5NzkgNjU1
MzUgZg0KMDAwMDAwMTk4MCA2NTUzNSBmDQowMDAwMDAxOTgxIDY1NTM1IGYNCjAwMDAwMDE5
ODIgNjU1MzUgZg0KMDAwMDAwMTk4MyA2NTUzNSBmDQowMDAwMDAxOTg0IDY1NTM1IGYNCjAw
MDAwMDE5ODUgNjU1MzUgZg0KMDAwMDAwMTk4NiA2NTUzNSBmDQowMDAwMDAxOTg3IDY1NTM1
IGYNCjAwMDAwMDE5ODggNjU1MzUgZg0KMDAwMDAwMTk4OSA2NTUzNSBmDQowMDAwMDAxOTkw
IDY1NTM1IGYNCjAwMDAwMDE5OTEgNjU1MzUgZg0KMDAwMDAwMTk5MiA2NTUzNSBmDQowMDAw
MDAxOTkzIDY1NTM1IGYNCjAwMDAwMDE5OTQgNjU1MzUgZg0KMDAwMDAwMTk5NSA2NTUzNSBm
DQowMDAwMDAxOTk2IDY1NTM1IGYNCjAwMDAwMDE5OTcgNjU1MzUgZg0KMDAwMDAwMTk5OCA2
NTUzNSBmDQowMDAwMDAxOTk5IDY1NTM1IGYNCjAwMDAwMDIwMDAgNjU1MzUgZg0KMDAwMDAw
MjAwMSA2NTUzNSBmDQowMDAwMDAyMDAyIDY1NTM1IGYNCjAwMDAwMDIwMDMgNjU1MzUgZg0K
MDAwMDAwMjAwNCA2NTUzNSBmDQowMDAwMDAyMDA1IDY1NTM1IGYNCjAwMDAwMDIwMDYgNjU1
MzUgZg0KMDAwMDAwMjAwNyA2NTUzNSBmDQowMDAwMDAyMDA4IDY1NTM1IGYNCjAwMDAwMDIw
MDkgNjU1MzUgZg0KMDAwMDAwMjAxMCA2NTUzNSBmDQowMDAwMDAyMDExIDY1NTM1IGYNCjAw
MDAwMDIwMTIgNjU1MzUgZg0KMDAwMDAwMjAxMyA2NTUzNSBmDQowMDAwMDAyMDE0IDY1NTM1
IGYNCjAwMDAwMDIwMTUgNjU1MzUgZg0KMDAwMDAwMjAxNiA2NTUzNSBmDQowMDAwMDAyMDE3
IDY1NTM1IGYNCjAwMDAwMDIwMTggNjU1MzUgZg0KMDAwMDAwMjAxOSA2NTUzNSBmDQowMDAw
MDAyMDIwIDY1NTM1IGYNCjAwMDAwMDIwMjEgNjU1MzUgZg0KMDAwMDAwMjAyMiA2NTUzNSBm
DQowMDAwMDAyMDIzIDY1NTM1IGYNCjAwMDAwMDIwMjQgNjU1MzUgZg0KMDAwMDAwMjAyNSA2
NTUzNSBmDQowMDAwMDAyMDI2IDY1NTM1IGYNCjAwMDAwMDIwMjcgNjU1MzUgZg0KMDAwMDAw
MjAyOCA2NTUzNSBmDQowMDAwMDAyMDI5IDY1NTM1IGYNCjAwMDAwMDIwMzAgNjU1MzUgZg0K
MDAwMDAwMjAzMSA2NTUzNSBmDQowMDAwMDAyMDMyIDY1NTM1IGYNCjAwMDAwMDIwMzMgNjU1
MzUgZg0KMDAwMDAwMjAzNCA2NTUzNSBmDQowMDAwMDAyMDM1IDY1NTM1IGYNCjAwMDAwMDIw
MzYgNjU1MzUgZg0KMDAwMDAwMjAzNyA2NTUzNSBmDQowMDAwMDAyMDM4IDY1NTM1IGYNCjAw
MDAwMDIwMzkgNjU1MzUgZg0KMDAwMDAwMjA0MCA2NTUzNSBmDQowMDAwMDAyMDQxIDY1NTM1
IGYNCjAwMDAwMDIwNDIgNjU1MzUgZg0KMDAwMDAwMjA0MyA2NTUzNSBmDQowMDAwMDAyMDQ0
IDY1NTM1IGYNCjAwMDAwMDIwNDUgNjU1MzUgZg0KMDAwMDAwMjA0NiA2NTUzNSBmDQowMDAw
MDAyMDQ3IDY1NTM1IGYNCjAwMDAwMDIwNDggNjU1MzUgZg0KMDAwMDAwMjA0OSA2NTUzNSBm
DQowMDAwMDAyMDUwIDY1NTM1IGYNCjAwMDAwMDIwNTEgNjU1MzUgZg0KMDAwMDAwMjA1MiA2
NTUzNSBmDQowMDAwMDAyMDUzIDY1NTM1IGYNCjAwMDAwMDIwNTQgNjU1MzUgZg0KMDAwMDAw
MjA1NSA2NTUzNSBmDQowMDAwMDAyMDU2IDY1NTM1IGYNCjAwMDAwMDIwNTcgNjU1MzUgZg0K
MDAwMDAwMjA1OCA2NTUzNSBmDQowMDAwMDAyMDU5IDY1NTM1IGYNCjAwMDAwMDIwNjAgNjU1
MzUgZg0KMDAwMDAwMjA2MSA2NTUzNSBmDQowMDAwMDAyMDYyIDY1NTM1IGYNCjAwMDAwMDIw
NjMgNjU1MzUgZg0KMDAwMDAwMjA2NCA2NTUzNSBmDQowMDAwMDAyMDY1IDY1NTM1IGYNCjAw
MDAwMDIwNjYgNjU1MzUgZg0KMDAwMDAwMjA2NyA2NTUzNSBmDQowMDAwMDAyMDY4IDY1NTM1
IGYNCjAwMDAwMDIwNjkgNjU1MzUgZg0KMDAwMDAwMjA3MCA2NTUzNSBmDQowMDAwMDAyMDcx
IDY1NTM1IGYNCjAwMDAwMDIwNzIgNjU1MzUgZg0KMDAwMDAwMjA3MyA2NTUzNSBmDQowMDAw
MDAyMDc0IDY1NTM1IGYNCjAwMDAwMDIwNzUgNjU1MzUgZg0KMDAwMDAwMjA3NiA2NTUzNSBm
DQowMDAwMDAyMDc3IDY1NTM1IGYNCjAwMDAwMDIwNzggNjU1MzUgZg0KMDAwMDAwMjA3OSA2
NTUzNSBmDQowMDAwMDAyMDgwIDY1NTM1IGYNCjAwMDAwMDIwODEgNjU1MzUgZg0KMDAwMDAw
MjA4MiA2NTUzNSBmDQowMDAwMDAyMDgzIDY1NTM1IGYNCjAwMDAwMDIwODQgNjU1MzUgZg0K
MDAwMDAwMjA4NSA2NTUzNSBmDQowMDAwMDAyMDg2IDY1NTM1IGYNCjAwMDAwMDIwODcgNjU1
MzUgZg0KMDAwMDAwMjA4OCA2NTUzNSBmDQowMDAwMDAyMDg5IDY1NTM1IGYNCjAwMDAwMDIw
OTAgNjU1MzUgZg0KMDAwMDAwMjA5MSA2NTUzNSBmDQowMDAwMDAyMDkyIDY1NTM1IGYNCjAw
MDAwMDIwOTMgNjU1MzUgZg0KMDAwMDAwMjA5NCA2NTUzNSBmDQowMDAwMDAyMDk1IDY1NTM1
IGYNCjAwMDAwMDIwOTYgNjU1MzUgZg0KMDAwMDAwMjA5NyA2NTUzNSBmDQowMDAwMDAyMDk4
IDY1NTM1IGYNCjAwMDAwMDIwOTkgNjU1MzUgZg0KMDAwMDAwMjEwMCA2NTUzNSBmDQowMDAw
MDAyMTAxIDY1NTM1IGYNCjAwMDAwMDIxMDIgNjU1MzUgZg0KMDAwMDAwMjEwMyA2NTUzNSBm
DQowMDAwMDAyMTA0IDY1NTM1IGYNCjAwMDAwMDIxMDUgNjU1MzUgZg0KMDAwMDAwMjEwNiA2
NTUzNSBmDQowMDAwMDAyMTA3IDY1NTM1IGYNCjAwMDAwMDIxMDggNjU1MzUgZg0KMDAwMDAw
MjEwOSA2NTUzNSBmDQowMDAwMDAyMTEwIDY1NTM1IGYNCjAwMDAwMDIxMTEgNjU1MzUgZg0K
MDAwMDAwMjExMiA2NTUzNSBmDQowMDAwMDAyMTEzIDY1NTM1IGYNCjAwMDAwMDIxMTQgNjU1
MzUgZg0KMDAwMDAwMjExNSA2NTUzNSBmDQowMDAwMDAyMTE2IDY1NTM1IGYNCjAwMDAwMDIx
MTcgNjU1MzUgZg0KMDAwMDAwMjExOCA2NTUzNSBmDQowMDAwMDAyMTE5IDY1NTM1IGYNCjAw
MDAwMDIxMjAgNjU1MzUgZg0KMDAwMDAwMjEyMSA2NTUzNSBmDQowMDAwMDAyMTIyIDY1NTM1
IGYNCjAwMDAwMDIxMjMgNjU1MzUgZg0KMDAwMDAwMjEyNCA2NTUzNSBmDQowMDAwMDAyMTI1
IDY1NTM1IGYNCjAwMDAwMDIxMjYgNjU1MzUgZg0KMDAwMDAwMjEyNyA2NTUzNSBmDQowMDAw
MDAyMTI4IDY1NTM1IGYNCjAwMDAwMDIxMjkgNjU1MzUgZg0KMDAwMDAwMjEzMCA2NTUzNSBm
DQowMDAwMDAyMTMxIDY1NTM1IGYNCjAwMDAwMDIxMzIgNjU1MzUgZg0KMDAwMDAwMjEzMyA2
NTUzNSBmDQowMDAwMDAyMTM0IDY1NTM1IGYNCjAwMDAwMDIxMzUgNjU1MzUgZg0KMDAwMDAw
MjEzNiA2NTUzNSBmDQowMDAwMDAyMTM3IDY1NTM1IGYNCjAwMDAwMDIxMzggNjU1MzUgZg0K
MDAwMDAwMjEzOSA2NTUzNSBmDQowMDAwMDAyMTQwIDY1NTM1IGYNCjAwMDAwMDIxNDEgNjU1
MzUgZg0KMDAwMDAwMjE0MiA2NTUzNSBmDQowMDAwMDAyMTQzIDY1NTM1IGYNCjAwMDAwMDIx
NDQgNjU1MzUgZg0KMDAwMDAwMjE0NSA2NTUzNSBmDQowMDAwMDAyMTQ2IDY1NTM1IGYNCjAw
MDAwMDIxNDcgNjU1MzUgZg0KMDAwMDAwMjE0OCA2NTUzNSBmDQowMDAwMDAyMTQ5IDY1NTM1
IGYNCjAwMDAwMDIxNTAgNjU1MzUgZg0KMDAwMDAwMjE1MSA2NTUzNSBmDQowMDAwMDAyMTUy
IDY1NTM1IGYNCjAwMDAwMDIxNTMgNjU1MzUgZg0KMDAwMDAwMjE1NCA2NTUzNSBmDQowMDAw
MDAyMTU1IDY1NTM1IGYNCjAwMDAwMDIxNTYgNjU1MzUgZg0KMDAwMDAwMjE1NyA2NTUzNSBm
DQowMDAwMDAyMTU4IDY1NTM1IGYNCjAwMDAwMDIxNTkgNjU1MzUgZg0KMDAwMDAwMjE2MCA2
NTUzNSBmDQowMDAwMDAwMDAwIDY1NTM1IGYNCjAwMDAxNDMyMDggMDAwMDAgbg0KMDAwMDE0
MzQ3NyAwMDAwMCBuDQowMDAwMTcwNDYwIDAwMDAwIG4NCjAwMDAxNzA5ODMgMDAwMDAgbg0K
MDAwMDIzMzYzOSAwMDAwMCBuDQowMDAwMjM0MzIyIDAwMDAwIG4NCjAwMDAyMzQ4OTMgMDAw
MDAgbg0KMDAwMDIzNTQyNCAwMDAwMCBuDQowMDAwMjczNzk3IDAwMDAwIG4NCjAwMDAyNzQx
OTggMDAwMDAgbg0KMDAwMDI3NDMzOSAwMDAwMCBuDQowMDAwMjk1Nzk0IDAwMDAwIG4NCjAw
MDAyOTYwOTcgMDAwMDAgbg0KMDAwMDMxNDEwOSAwMDAwMCBuDQowMDAwMzE0MTU0IDAwMDAw
IG4NCjAwMDAzMTc0MjMgMDAwMDAgbg0KMDAwMDMxNzQ3MCAwMDAwMCBuDQp0cmFpbGVyDQo8
PC9TaXplIDIxNzgvUm9vdCAxIDAgUi9JbmZvIDc3IDAgUi9JRFs8MUREMEJGQTI2MjMwMzQ0
MzhDMjBDRUZENUZBNUUwMDk+PDFERDBCRkEyNjIzMDM0NDM4QzIwQ0VGRDVGQTVFMDA5Pl0g
Pj4NCnN0YXJ0eHJlZg0KMzIxODM0DQolJUVPRg0KeHJlZg0KMCAwDQp0cmFpbGVyDQo8PC9T
aXplIDIxNzgvUm9vdCAxIDAgUi9JbmZvIDc3IDAgUi9JRFs8MUREMEJGQTI2MjMwMzQ0MzhD
MjBDRUZENUZBNUUwMDk+PDFERDBCRkEyNjIzMDM0NDM4QzIwQ0VGRDVGQTVFMDA5Pl0gL1By
ZXYgMzIxODM0L1hSZWZTdG0gMzE3NDcwPj4NCnN0YXJ0eHJlZg0KMzY1NTU2DQolJUVPRg==
--------------1AA7E09B652DF5246C8D07F6--


From nobody Wed Oct 16 18:53:18 2019
Return-Path: <nalini.elkins@e-dco.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80887120047 for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 18:53:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level: 
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=e-dco-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Sgn5XkW3Qq0M for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 18:53:13 -0700 (PDT)
Received: from mail-lf1-x132.google.com (mail-lf1-x132.google.com [IPv6:2a00:1450:4864:20::132]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 93944120019 for <mls@ietf.org>; Wed, 16 Oct 2019 18:53:13 -0700 (PDT)
Received: by mail-lf1-x132.google.com with SMTP id a19so462043lfg.12 for <mls@ietf.org>; Wed, 16 Oct 2019 18:53:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=e-dco-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=lygFjB+S49B0qE/AmQV4kq8aoXS4VqNfeIblYXuSYB4=; b=p6gIzE28pq0TTW1Nal5mOJkYu3eGLrjjrdOOA3z4X2kzntY3PfIgo0tNXcI4N+Pzqf uYp4s8FAB5qI8beSiobXApuznIsYFfWIlk/z3Hka4RqfRr0CNffI+e2Oion8Tc1P+7IS XtGpsOd23izg3cPiwrfzBRR6p7UwIi2IuvvGxyZmBKMJXivuAjtTLWLXnFpvC7F9Bcoe D7D+FtArlMqZO2IE9/CpwC6zHsASeHhcVx+RLYKUz6pEUcXE++zKVIz5H3JiFf55QttL C2cI6/eH0rw2pcdZKScg46h0wYu9ovffvoW3fEKfwCHViATrg2DJL2LamET+EHKAUu7j Wgdw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=lygFjB+S49B0qE/AmQV4kq8aoXS4VqNfeIblYXuSYB4=; b=IfZs/DQG+UHJbrRuJYqz9MdIQw2WYuIRZjOL6MZ40sHPeklmwZ7Bxx3Vv/PadG2Ue7 +RoxGXNdL3RLPmeaBGFbkHH90vn3O9Dys7QWc3Cp1n6mtad0QOQO1Eoz3PpisvinpLOU 8l8dxs9fmxqy23VLOZh9sJ+9PQmmPxwyBMP83W3kcGiLdBNhypMtjZTDRbZTTTmdqZDr TDs1XYhd5fGZnxVok0t8NyqykeaeK3ZiSeQxfnH1/nTZIm5v2jfrH0rkRV/BNdHyU0GV cV8jcLMRqh2M+5zQlrULZfyyMy/hQIQafx4bqz4w3fN2rp0DE6o43OmYWTMBSAAoZ17H aUCg==
X-Gm-Message-State: APjAAAV8nc/8ymEAiIM73AXncmXxX+PRZfKmUUTbt9pg78+yGLOoxN9n rJj3+Lf0GJDZznmzWm0UKOpmuRgZC8gIwdH98RyF2xwxlyg=
X-Google-Smtp-Source: APXvYqwi3JqHUWdapfR+mT3hVzM/C68ukXR2/VvHohODSHqrBtU5wfaDSGEJvOagm6ix2C6wmrGHIz3ByNAjDd8dIXo=
X-Received: by 2002:a19:ad0c:: with SMTP id t12mr445597lfc.149.1571277191479;  Wed, 16 Oct 2019 18:53:11 -0700 (PDT)
MIME-Version: 1.0
References: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
In-Reply-To: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
From: nalini elkins <nalini.elkins@e-dco.com>
Date: Wed, 16 Oct 2019 18:53:01 -0700
Message-ID: <CAPsNn2WcfCxKE3o4PDMpjGEKyitxnScySZW=9d4ikKcGWfZ9Mg@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d795640595117a73"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/LNMDNc5yVoxL7xHw6TZOBq4wgik>
Subject: Re: [MLS] Some data
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 01:53:17 -0000

--000000000000d795640595117a73
Content-Type: text/plain; charset="UTF-8"

Richard,

>I'm currently working on extracting "transcripts" of
init/add/remove/message events, with the idea that they could be fed into a
simulator attached to
> some library to generate counts of actual crypto operations.  But it
would also be easy to extract summary statistics, such as the inter-arrival
rates
> for Adds / Removes, Add:Remove ratios, etc.

I don't know if this is appropriate but if you have per packet payload (or
payloads which can be distinguished that way),  it is possible to use the
TXT2PCAP program of Wireshark to create a PCAP or packet trace.

Once you have a packet trace, then it is quite easy to do summaries, flows,
etc.  I remember doing this with the early TLS1.3 code.

It this seems useful, I am happy to help.

Nalini


On Tue, Oct 15, 2019 at 8:57 AM Richard Barnes <rlb@ipv.sx> wrote:

> Hey all,
>
> I've managed to extract histories for a collection of Webex Teams groups,
> a total of 950 groups (including 1-1 conversations) ranging in size from 2
> to 5000 members.
>
> What data would people be interested in understanding from this data set?
>
> I'm currently working on extracting "transcripts" of
> init/add/remove/message events, with the idea that they could be fed into a
> simulator attached to some library to generate counts of actual crypto
> operations.  But it would also be easy to extract summary statistics, such
> as the inter-arrival rates for Adds / Removes, Add:Remove ratios, etc.
>
> One caveat is that Webex Teams allows self-add and self-remove, in
> addition to adds/removes initiated by someone in the group.  Self-adds
> account for ~6% of all adds, but self-removes (leaves) are 98% of all
> removes.  The latter might be an artifact of "server-initiated" removes
> being reflected as self-removes, but of course server-initiated removes
> have similar issues w.r.t. MLS.
>
> --Richard
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>


-- 
Thanks,
Nalini Elkins
President
Enterprise Data Center Operators
www.e-dco.com

--000000000000d795640595117a73
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Richard,</div><div><br></div>&gt;I&#39;m currently wo=
rking on extracting &quot;transcripts&quot; of init/add/remove/message even=
ts, with the idea that they could be fed into a simulator attached to<div>&=
gt; some library to generate counts of actual crypto operations.=C2=A0 But =
it would also be easy to extract summary statistics, such as the inter-arri=
val rates</div><div>&gt; for Adds / Removes, Add:Remove ratios, etc.=C2=A0=
=C2=A0<br></div><div><br></div><div>I don&#39;t know if this is appropriate=
 but if you have per packet payload (or payloads which can be distinguished=
 that way),=C2=A0 it is possible to use the TXT2PCAP program of Wireshark t=
o create a PCAP or packet trace.</div><div><br></div><div>Once you have a p=
acket trace, then it is quite easy to do summaries, flows, etc.=C2=A0 I rem=
ember doing this with the early TLS1.3 code.</div><div><br></div><div>It th=
is seems useful, I am happy to help.</div><div><br></div><div>Nalini</div><=
div><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Tue, Oct 15, 2019 at 8:57 AM Richard Barnes &lt;rlb@ipv.=
sx&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0p=
x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><d=
iv dir=3D"ltr"><div>Hey all,</div><div><br></div><div>I&#39;ve managed to e=
xtract histories for a collection of Webex Teams groups, a total of 950 gro=
ups (including 1-1 conversations) ranging in size from 2 to 5000 members.</=
div><div><br></div><div>What data would people be interested in understandi=
ng from this data set?=C2=A0 <br></div><div><br></div><div>I&#39;m currentl=
y working on extracting &quot;transcripts&quot; of init/add/remove/message =
events, with the idea that they could be fed into a simulator attached to s=
ome library to generate counts of actual crypto operations.=C2=A0 But it wo=
uld also be easy to extract summary statistics, such as the inter-arrival r=
ates for Adds / Removes, Add:Remove ratios, etc.</div><div><br></div><div>O=
ne caveat is that Webex Teams allows self-add and self-remove, in addition =
to adds/removes initiated by someone in the group.=C2=A0 Self-adds account =
for ~6% of all adds, but self-removes (leaves) are 98% of all removes.=C2=
=A0 The latter might be an artifact of &quot;server-initiated&quot; removes=
 being reflected as self-removes, but of course server-initiated removes ha=
ve similar issues w.r.t. MLS.</div><div><br></div><div>--Richard<br></div><=
/div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div><br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"=
 class=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div styl=
e=3D"font-size:12.8px">Thanks,</div><div style=3D"font-size:12.8px">Nalini =
Elkins</div><div style=3D"font-size:12.8px">President</div><div style=3D"fo=
nt-size:12.8px">Enterprise Data Center Operators</div><div style=3D"font-si=
ze:12.8px"><a href=3D"http://www.e-dco.com" target=3D"_blank">www.e-dco.com=
</a></div><div><br></div></div></div></div></div>

--000000000000d795640595117a73--


From nobody Wed Oct 16 22:43:07 2019
Return-Path: <karthikeyan.bhargavan@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 103E5120821 for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 22:43:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IZISady4tDon for <mls@ietfa.amsl.com>; Wed, 16 Oct 2019 22:43:03 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0AF2E120236 for <mls@ietf.org>; Wed, 16 Oct 2019 22:43:02 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,306,1566856800"; d="scan'208";a="406531636"
Received: from 89-156-101-160.rev.numericable.fr (HELO [192.168.0.62]) ([89.156.101.160]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 17 Oct 2019 07:42:56 +0200
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Karthik Bhargavan <karthikeyan.bhargavan@inria.fr>
In-Reply-To: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com>
Date: Thu, 17 Oct 2019 07:42:54 +0200
Cc: mls@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com>
To: Joel Alwen <jalwen@wickr.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/TtC7GXzrJioeHSFtUHGAan1yTRA>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 05:43:05 -0000

Hi Joel,

This looks very interesting. It is new to me since I was not at the =
interim.
After reading the paper and the slides, I am still a bit fuzzy about =
what the recipient of an update needs to do.

For example, for the running example in your slide deck, it would help =
if I could see:
- what secret keys does each leaf need to keep
- how do these secrets change when an update from some other node is =
received.
Just working this out for one update is enough.

I know that this is made precise in the eprint, but it would be faster =
if you could help us understand it :)

Best,
Karthik

> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com> wrote:
>=20
> <FS-TreeKEM.pdf>


From nobody Thu Oct 17 01:46:45 2019
Return-Path: <cas.cremers@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 523DE12004E for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 01:46:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r7sfjVpm47-m for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 01:46:41 -0700 (PDT)
Received: from mail-wm1-x336.google.com (mail-wm1-x336.google.com [IPv6:2a00:1450:4864:20::336]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6DACA120844 for <mls@ietf.org>; Thu, 17 Oct 2019 01:46:41 -0700 (PDT)
Received: by mail-wm1-x336.google.com with SMTP id r19so1643406wmh.2 for <mls@ietf.org>; Thu, 17 Oct 2019 01:46:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=ij09xLYLA8smd2EgWDHaz++JYlDPUJrMpw+y9e8mrRg=; b=OOyL32jBoMYvSNuGImh8zb/Lpc1CUWfNG4kVP6m+khe6IFPVOlGgUn9uBa5PzqqLA+ 6Et0ZsVZxkrfe5J9SIci4bw8luwfLRAbuQE1ybF3R87X795M5LXlebTK1C5IVLKUaZx8 aPUW0JKvdAMPGvfDILubCY1owAL45+nfoxFe5TgMSSFyNV45MHlId2RBjr0x8gbwi7md lRDwhc83e08cdaDZTNEV0C7y09wTn8mfCIiGVj7bSnyU5uEd7vBkEFZgrYe0BUa7b3QH IfE5I8dZN3kpc3/wmIPnj0KpWU7NrjF8L6rqN59ErXaMhCatEtEsFXSV5e9nSjjQAfJ5 Wy/g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=ij09xLYLA8smd2EgWDHaz++JYlDPUJrMpw+y9e8mrRg=; b=U99OFqBzIoZuKNrkZbREuNGWqjwj48qrBEpQtVMhuudIlMOKnbyaYcVH3rSU7m8qhw WwERtJv6GVFaFbn4RIV2YWej2z2erzTjDxvNfowN6EDGTi/AJpRu5Uif4LuGcm/ogtkw q7iNE8zIt6l0CfPL6ul2tCpoP22Cf7CQRXxs8+Ws1RuW1pSP+VFHPHhEWA93+Pa7Jyay c0CRVOQKI+RZetBkfkZntmXcT2ayrEbJq/m4TqGwRymVsjyDUjX5vS6V8ZVSGDX4umjp A7EU0JMOMHEW16kmfSGw+80HYVMZjGTEeAT/9Vy3X2MSbEEirLtoYr6r0QwE8g45Yt76 d4JA==
X-Gm-Message-State: APjAAAWh1LnfNZp7UPHdDsHiZIfFdntr01K8nwY4AVk5OQdmBE0hvu9x VvMcUppfIHkcASoHDdx24spBby5lsNdUIAu5YrJpOQ==
X-Google-Smtp-Source: APXvYqx/nuVzRYRPgms+cS4xZiK060BrnuiD2xp9UjfjrCQql0jxUGrzET0vGg5jPh50Gc/F/eUpGL0NlzaFLJwIFvA=
X-Received: by 2002:a7b:cd19:: with SMTP id f25mr1932597wmj.154.1571301999783;  Thu, 17 Oct 2019 01:46:39 -0700 (PDT)
MIME-Version: 1.0
References: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
In-Reply-To: <CAL02cgTe3SgDQgW3--4A3nUm=+mZrd_NyMfkfhi0Qs6KHayH+w@mail.gmail.com>
From: Cas Cremers <cas.cremers@gmail.com>
Date: Thu, 17 Oct 2019 10:46:23 +0200
Message-ID: <CABdrxL5Rbu8+uipeqEPMRTB5akd2h=CtzYtqH=fGc4OMnxGVKQ@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/IAOZiLTXU3I4Tf8Ws4KH6YyVdfY>
Subject: Re: [MLS] Some data
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 08:46:43 -0000

Hi Richard,

That's really helpful, thanks!

Some of these have been mentioned already, but to ground some of our
design choices it would be useful to have:

 - Distribution of group sizes: one might expect many 1-1 and few of
5000, but how is the distribution in between?
 - (Main classes of) typical group dynamics over time, especially for
the larger groups. E.g., frequency of group size changes, typical size
curve over time, lifetime of groups, ...

I would it be convenient if we could also look into the data a bit
more (in how many groups are typical users / subgroup relations) but I
would assume that's not possible or desired.

Best,

Cas




On Tue, Oct 15, 2019 at 5:57 PM Richard Barnes <rlb@ipv.sx> wrote:
>
> Hey all,
>
> I've managed to extract histories for a collection of Webex Teams groups,=
 a total of 950 groups (including 1-1 conversations) ranging in size from 2=
 to 5000 members.
>
> What data would people be interested in understanding from this data set?
>
> I'm currently working on extracting "transcripts" of init/add/remove/mess=
age events, with the idea that they could be fed into a simulator attached =
to some library to generate counts of actual crypto operations.  But it wou=
ld also be easy to extract summary statistics, such as the inter-arrival ra=
tes for Adds / Removes, Add:Remove ratios, etc.
>
> One caveat is that Webex Teams allows self-add and self-remove, in additi=
on to adds/removes initiated by someone in the group.  Self-adds account fo=
r ~6% of all adds, but self-removes (leaves) are 98% of all removes.  The l=
atter might be an artifact of "server-initiated" removes being reflected as=
 self-removes, but of course server-initiated removes have similar issues w=
.r.t. MLS.
>
> --Richard
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


From nobody Thu Oct 17 04:47:22 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DE7BF120271 for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 04:47:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 71i9evJfpDCe for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 04:47:18 -0700 (PDT)
Received: from mail-il1-x12b.google.com (mail-il1-x12b.google.com [IPv6:2607:f8b0:4864:20::12b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D48A1200C5 for <mls@ietf.org>; Thu, 17 Oct 2019 04:47:18 -0700 (PDT)
Received: by mail-il1-x12b.google.com with SMTP id f13so1686427ils.11 for <mls@ietf.org>; Thu, 17 Oct 2019 04:47:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=WuQjGzqUHroahUNV021g+6Mg7m8RxsTNIdZZ07NidQI=; b=JOLLy7XUzr/lueS4dYJsiaRo+u9s4SUb8/APHmGR61kU7yDzdU7gtgTY2OesVWGhUM nyUYEVnC8YP1UqIL0+7tchlSX0ne59RkwezWjhlxwbuL7QVnU1t/HyOggf2JC+ljjVfa pLKYZs9nYX/fB9xcUbKYsfrlVPB074UAXdTbkgvvC969L/WD47NkcxLuQCIYfXohK8Ah uYtJOgo+xbshJSZJJ6p2pMNtSG/x8gSSahGpnfpBoNG51gkL2vGyDzS3ywx/CeLMJeV9 xMCDlA1r+HE442DFuBxAaJpErL58jSmlf/4QtGt/B/4+XK+SnmQKaXmlgGeX1V5NXwYj pf1g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=WuQjGzqUHroahUNV021g+6Mg7m8RxsTNIdZZ07NidQI=; b=NVM+U73w4AXjs+fnMrXBy+7TaMVNOkxZUbvBsMWxNyMDTBJxJEYphOkdeh5eMNeheQ cLehs4NoO2xwlmgOAeBm9cxMkZIg+QjhETq3cEAFL4mSG+7t7CJCsvwbe3pbmTanIiiE LzKAA7mamuG3a2t7ADVio9cPvF0+uPcvYc+BtiA9Idp7nnGA5Pb8KQKbkbJyGi3cCKqF f3avHacu7GfhK7F92rm3RP4RvdHQFwo+tV3X2CKRIczNKTTyCSzUj0Vi+tSqnVK1BdP+ f4mR7VM6yfN5lGIOS27qStqXMLSXDSsTACPFLR6hFxX1ieJ+p0FfXNDwYF0T8LpD1qm7 jb4w==
X-Gm-Message-State: APjAAAWPDs3hint6odo9nbUsx1zxcXZ8si2Ekr03tmTF14oZw9QzSQNT hl7lp8VWCZtEx7wRWzd8zBjxW5ZKs2m4r9ZaD/I=
X-Google-Smtp-Source: APXvYqxTCM7p8pz6biKRKOL6fXwosIgf+1MgW0hM+keBSARyAn93YUU/VRA8Qtdtr2xRxhEYOTy/hLYVbDDd/kZgvvM=
X-Received: by 2002:a92:8941:: with SMTP id n62mr3073079ild.20.1571312836938;  Thu, 17 Oct 2019 04:47:16 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr>
In-Reply-To: <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr>
From: Yevgeniy Dodis <zaumka@gmail.com>
Date: Thu, 17 Oct 2019 07:47:05 -0400
Message-ID: <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com>
To: Karthik Bhargavan <karthikeyan.bhargavan@inria.fr>
Cc: mls@ietf.org
Content-Type: multipart/alternative; boundary="0000000000007a1254059519c7c8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/clNoEbV4CyQLgpfxivTqH8zZ7ec>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 11:47:21 -0000

--0000000000007a1254059519c7c8
Content-Type: text/plain; charset="UTF-8"

Hi Karthik.

Sorry for the short answer, about to drive for 4 hours ;).

Each user still stores at most log n secret keys on the path to the root
(and all public keys, unless retrieving them as needed). During each
operation where this user is not initiator, there will be precisely one
ciphertext this user needs to decrypt using one of these log n keys,  just
like before. In the original TreeKEM, after decrypting this ciphertext, the
public and secret
key for this encryption stays the same. In RTreeKEM, --- and this is the
main (and effectively only) difference, --- the public and secret keys for
this encryption change. In a way that the new secret key will be able to
decrypt ciphertexts encrypted under NEW public key, not not OLD public key.
In particular, new secret key will not be able to decrypt the ciphertext
that the user just decrypted. Given our global ordering assumption, this
does not get users out of sync, even if some and offline for long periods
of time.

So think of this as public key analog of a steam cipher. Where after each
decryption the steam cipher state changes to ensure forward secrecy. Here
the cute part is that the public key will be effectively changed by the
sender (who does not know neither new or old secret key), but in a way that
the recipient (and only the recipient!) can recover the matching secret
key. Intuitively, the sender will not only encrypt the message, but also a
random Delta value. It will change public key using homomorthism by
multiplying with g^Delta (in specific DH based scheme), while the recipient
will decrypt Delta (using old secret key), and add it to the old secret key
to get there new one. So now corrupting (old sk plus Delta) will not help
decrypting the ciphertext just decepted, emailing forward secrecy. So very
small cost compared to the original TreeKEM (see our earlier email for more
details). And really the same scheme, modulo PKE  being stateful ala a
steam cipher.

This is the high level, hope it makes sense.
Thanks for your question,
Yevgeniy

On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan <
karthikeyan.bhargavan@inria.fr> wrote:

> Hi Joel,
>
> This looks very interesting. It is new to me since I was not at the
> interim.
> After reading the paper and the slides, I am still a bit fuzzy about what
> the recipient of an update needs to do.
>
> For example, for the running example in your slide deck, it would help if
> I could see:
> - what secret keys does each leaf need to keep
> - how do these secrets change when an update from some other node is
> received.
> Just working this out for one update is enough.
>
> I know that this is made precise in the eprint, but it would be faster if
> you could help us understand it :)
>
> Best,
> Karthik
>
> > On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com> wrote:
> >
> > <FS-TreeKEM.pdf>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000007a1254059519c7c8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Hi Karthik.<div dir=3D"auto"><br></div><div dir=3D"auto">=
Sorry for the short answer, about to drive for 4 hours ;).</div><div dir=3D=
"auto"><br></div><div dir=3D"auto">Each user still stores at most log n sec=
ret keys on the path to the root (and all public keys, unless retrieving th=
em as needed). During each operation where this user is not initiator, ther=
e will be precisely one ciphertext this user needs to decrypt using one of =
these log n keys,=C2=A0 just like before. In the original TreeKEM, after de=
crypting this ciphertext, the public and secret</div><div dir=3D"auto">key =
for this encryption stays the same. In RTreeKEM, --- and this is the main (=
and effectively only) difference, --- the public and secret keys for this e=
ncryption change. In a way that the new secret key will be able to decrypt =
ciphertexts encrypted under NEW public key, not not OLD public key. In part=
icular, new secret key will not be able to decrypt the ciphertext that the =
user just decrypted. Given our global ordering assumption, this does not ge=
t users out of sync, even if some and offline for long periods of time.</di=
v><div dir=3D"auto"><br></div><div dir=3D"auto">So think of this as public =
key analog of a steam cipher. Where after each decryption the steam cipher =
state changes to ensure forward secrecy. Here the cute part is that the pub=
lic key will be effectively changed by the sender (who does not know neithe=
r new or old secret key), but in a way that the recipient (and only the rec=
ipient!) can recover the matching secret key. Intuitively, the sender will =
not only encrypt the message, but also a random Delta value. It will change=
 public key using homomorthism by multiplying with g^Delta (in specific DH =
based scheme), while the recipient will decrypt Delta (using old secret key=
), and add it to the old secret key to get there new one. So now corrupting=
 (old sk plus Delta) will not help decrypting the ciphertext just decepted,=
 emailing forward secrecy. So very small cost compared to the original Tree=
KEM (see our earlier email for more details). And really the same scheme, m=
odulo PKE=C2=A0 being stateful ala a steam cipher.=C2=A0</div><div dir=3D"a=
uto"><br></div><div dir=3D"auto">This is the high level, hope it makes sens=
e.</div><div dir=3D"auto">Thanks for your question,</div><div dir=3D"auto">=
Yevgeniy</div><br><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr" =
class=3D"gmail_attr">On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan &lt;<a=
 href=3D"mailto:karthikeyan.bhargavan@inria.fr">karthikeyan.bhargavan@inria=
.fr</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Joel,<br>
<br>
This looks very interesting. It is new to me since I was not at the interim=
.<br>
After reading the paper and the slides, I am still a bit fuzzy about what t=
he recipient of an update needs to do.<br>
<br>
For example, for the running example in your slide deck, it would help if I=
 could see:<br>
- what secret keys does each leaf need to keep<br>
- how do these secrets change when an update from some other node is receiv=
ed.<br>
Just working this out for one update is enough.<br>
<br>
I know that this is made precise in the eprint, but it would be faster if y=
ou could help us understand it :)<br>
<br>
Best,<br>
Karthik<br>
<br>
&gt; On 16 Oct 2019, at 23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wick=
r.com" target=3D"_blank" rel=3D"noreferrer">jalwen@wickr.com</a>&gt; wrote:=
<br>
&gt; <br>
&gt; &lt;FS-TreeKEM.pdf&gt;<br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" rel=3D"noreferrer">MLS@ie=
tf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br=
>
</blockquote></div></div>

--0000000000007a1254059519c7c8--


From nobody Thu Oct 17 07:37:37 2019
Return-Path: <karthikeyan.bhargavan@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 79DEC12006B for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 07:37:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.898
X-Spam-Level: 
X-Spam-Status: No, score=-6.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UJAOPsIrtSa0 for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 07:37:32 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56B2412000F for <mls@ietf.org>; Thu, 17 Oct 2019 07:37:32 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,308,1566856800";  d="scan'208,217";a="406651919"
Received: from 89-156-101-160.rev.numericable.fr (HELO [192.168.0.62]) ([89.156.101.160]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 17 Oct 2019 16:37:30 +0200
From: Karthik Bhargavan <karthikeyan.bhargavan@inria.fr>
Message-Id: <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_A6134B80-EA56-4FF2-9AFA-76C097731D2E"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Thu, 17 Oct 2019 16:37:29 +0200
In-Reply-To: <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com>
Cc: mls@ietf.org
To: Yevgeniy Dodis <zaumka@gmail.com>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/15H0eEcIy3iPxHx1gat1G3sF8z4>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 14:37:36 -0000

--Apple-Mail=_A6134B80-EA56-4FF2-9AFA-76C097731D2E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Thanks Yevgeniy,

This helps a lot.

To further my understanding, another question:

>  Intuitively, the sender will not only encrypt the message, but also a =
random Delta value. It will change public key using homomorthism by =
multiplying with g^Delta (in specific DH based scheme), while the =
recipient will decrypt Delta (using old secret key), and add it to the =
old secret key to get there new one. So now corrupting (old sk plus =
Delta) will not help decrypting the ciphertext just decepted, emailing =
forward secrecy.=20

I see that in the DH-based scheme, this Delta needs to be private, =
otherwise the adversary can compute sk once it knows sk+Delta.
But, in general, is it possible to conceive of a UPKE scheme where the =
recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric =
key,
where this one way hash-forward function does not have to rely on an =
externally chosen secret value?

Best,
Karthik

> This is the high level, hope it makes sense.
> Thanks for your question,
> Yevgeniy
>=20
> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan =
<karthikeyan.bhargavan@inria.fr <mailto:karthikeyan.bhargavan@inria.fr>> =
wrote:
> Hi Joel,
>=20
> This looks very interesting. It is new to me since I was not at the =
interim.
> After reading the paper and the slides, I am still a bit fuzzy about =
what the recipient of an update needs to do.
>=20
> For example, for the running example in your slide deck, it would help =
if I could see:
> - what secret keys does each leaf need to keep
> - how do these secrets change when an update from some other node is =
received.
> Just working this out for one update is enough.
>=20
> I know that this is made precise in the eprint, but it would be faster =
if you could help us understand it :)
>=20
> Best,
> Karthik
>=20
> > On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
> >=20
> > <FS-TreeKEM.pdf>
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>


--Apple-Mail=_A6134B80-EA56-4FF2-9AFA-76C097731D2E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Thanks Yevgeniy,<div class=3D""><br class=3D""></div><div =
class=3D"">This helps a lot.</div><div class=3D""><br =
class=3D""></div><div class=3D"">To further my understanding, another =
question:</div><div class=3D""><br class=3D""></div><div =
class=3D""><blockquote type=3D"cite" class=3D"">&nbsp;Intuitively, the =
sender will not only encrypt the message, but also a random Delta value. =
It will change public key using homomorthism by multiplying with g^Delta =
(in specific DH based scheme), while the recipient will decrypt Delta =
(using old secret key), and add it to the old secret key to get there =
new one. So now corrupting (old sk plus Delta) will not help decrypting =
the ciphertext just decepted, emailing forward =
secrecy.&nbsp;</blockquote><div class=3D""><br class=3D""></div><div =
class=3D"">I see that in the DH-based scheme, this Delta needs to be =
private, otherwise the adversary can compute sk once it knows =
sk+Delta.</div><div class=3D"">But, in general, is it possible to =
conceive of a UPKE scheme where the recipient effectively =E2=80=9Chashes =
forward=E2=80=9D its symmetric key,</div><div class=3D"">where this one =
way hash-forward function does not have to rely on an externally chosen =
secret value?</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><br =
class=3D""><div><blockquote type=3D"cite" class=3D""><div dir=3D"auto" =
class=3D""><div dir=3D"auto" class=3D"">This is the high level, hope it =
makes sense.</div><div dir=3D"auto" class=3D"">Thanks for your =
question,</div><div dir=3D"auto" class=3D"">Yevgeniy</div><br =
class=3D""><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr" =
class=3D"gmail_attr">On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan =
&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">karthikeyan.bhargavan@inria.fr</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Joel,<br class=3D"">
<br class=3D"">
This looks very interesting. It is new to me since I was not at the =
interim.<br class=3D"">
After reading the paper and the slides, I am still a bit fuzzy about =
what the recipient of an update needs to do.<br class=3D"">
<br class=3D"">
For example, for the running example in your slide deck, it would help =
if I could see:<br class=3D"">
- what secret keys does each leaf need to keep<br class=3D"">
- how do these secrets change when an update from some other node is =
received.<br class=3D"">
Just working this out for one update is enough.<br class=3D"">
<br class=3D"">
I know that this is made precise in the eprint, but it would be faster =
if you could help us understand it :)<br class=3D"">
<br class=3D"">
Best,<br class=3D"">
Karthik<br class=3D"">
<br class=3D"">
&gt; On 16 Oct 2019, at 23:51, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" rel=3D"noreferrer" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:<br class=3D"">
&gt; <br class=3D"">
&gt; &lt;FS-TreeKEM.pdf&gt;<br class=3D"">
<br class=3D"">
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" rel=3D"noreferrer" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer =
noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div>
</blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_A6134B80-EA56-4FF2-9AFA-76C097731D2E--


From nobody Thu Oct 17 07:40:07 2019
Return-Path: <karthikeyan.bhargavan@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 262FA120091 for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 07:40:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.898
X-Spam-Level: 
X-Spam-Status: No, score=-6.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kLpdxLziT-fh for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 07:40:03 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 23A4112006B for <mls@ietf.org>; Thu, 17 Oct 2019 07:40:02 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,308,1566856800";  d="scan'208,217";a="406652396"
Received: from 89-156-101-160.rev.numericable.fr (HELO [192.168.0.62]) ([89.156.101.160]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 17 Oct 2019 16:39:36 +0200
From: Karthik Bhargavan <karthikeyan.bhargavan@inria.fr>
Message-Id: <94ADA5D6-C8FE-4F1F-A5D3-BA4365E31ED9@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_8D5C84EE-D202-4B84-BFC5-75025A55C44C"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Thu, 17 Oct 2019 16:39:34 +0200
In-Reply-To: <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
Cc: mls@ietf.org
To: Yevgeniy Dodis <zaumka@gmail.com>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/ogleJIJh3tmmYZEsc73nC7pg83U>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 14:40:05 -0000

--Apple-Mail=_8D5C84EE-D202-4B84-BFC5-75025A55C44C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Sorry: typo (symmetric key =E2=80=94> private key)

I see that in the DH-based scheme, this Delta needs to be private, =
otherwise the adversary can compute sk once it knows sk+Delta.
But, in general, is it possible to conceive of a UPKE scheme where the =
recipient effectively =E2=80=9Chashes forward=E2=80=9D its *private* =
key,
where this one way hash-forward function does not have to rely on an =
externally chosen secret value?

>=20
> Best,
> Karthik
>=20
>> This is the high level, hope it makes sense.
>> Thanks for your question,
>> Yevgeniy
>>=20
>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan =
<karthikeyan.bhargavan@inria.fr <mailto:karthikeyan.bhargavan@inria.fr>> =
wrote:
>> Hi Joel,
>>=20
>> This looks very interesting. It is new to me since I was not at the =
interim.
>> After reading the paper and the slides, I am still a bit fuzzy about =
what the recipient of an update needs to do.
>>=20
>> For example, for the running example in your slide deck, it would =
help if I could see:
>> - what secret keys does each leaf need to keep
>> - how do these secrets change when an update from some other node is =
received.
>> Just working this out for one update is enough.
>>=20
>> I know that this is made precise in the eprint, but it would be =
faster if you could help us understand it :)
>>=20
>> Best,
>> Karthik
>>=20
>> > On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
>> >=20
>> > <FS-TreeKEM.pdf>
>>=20
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org <mailto:MLS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_8D5C84EE-D202-4B84-BFC5-75025A55C44C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Sorry: typo (symmetric key =E2=80=94&gt; private key)<div =
class=3D""><div><br class=3D""><div class=3D"">I see that in the =
DH-based scheme, this Delta needs to be private, otherwise the adversary =
can compute sk once it knows sk+Delta.</div><div class=3D""><div =
style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break: =
after-white-space;" class=3D""><div class=3D""><div class=3D"">But, in =
general, is it possible to conceive of a UPKE scheme where the recipient =
effectively =E2=80=9Chashes forward=E2=80=9D its *private* =
key,</div><div class=3D"">where this one way hash-forward function does =
not have to rely on an externally chosen secret value?</div><div =
class=3D""><br class=3D""></div></div></div></div><blockquote =
type=3D"cite" class=3D""><div class=3D""><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D""><div class=3D""><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><br class=3D""><div =
class=3D""><blockquote type=3D"cite" class=3D""><div dir=3D"auto" =
class=3D""><div dir=3D"auto" class=3D"">This is the high level, hope it =
makes sense.</div><div dir=3D"auto" class=3D"">Thanks for your =
question,</div><div dir=3D"auto" class=3D"">Yevgeniy</div><br =
class=3D""><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr" =
class=3D"gmail_attr">On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan =
&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">karthikeyan.bhargavan@inria.fr</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
..8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Joel,<br class=3D"">=

<br class=3D"">
This looks very interesting. It is new to me since I was not at the =
interim.<br class=3D"">
After reading the paper and the slides, I am still a bit fuzzy about =
what the recipient of an update needs to do.<br class=3D"">
<br class=3D"">
For example, for the running example in your slide deck, it would help =
if I could see:<br class=3D"">
- what secret keys does each leaf need to keep<br class=3D"">
- how do these secrets change when an update from some other node is =
received.<br class=3D"">
Just working this out for one update is enough.<br class=3D"">
<br class=3D"">
I know that this is made precise in the eprint, but it would be faster =
if you could help us understand it :)<br class=3D"">
<br class=3D"">
Best,<br class=3D"">
Karthik<br class=3D"">
<br class=3D"">
&gt; On 16 Oct 2019, at 23:51, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" rel=3D"noreferrer" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:<br class=3D"">
&gt; <br class=3D"">
&gt; &lt;FS-TreeKEM.pdf&gt;<br class=3D"">
<br class=3D"">
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" rel=3D"noreferrer" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer =
noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div>
</blockquote></div><br =
class=3D""></div></div>_______________________________________________<br =
class=3D"">MLS mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_8D5C84EE-D202-4B84-BFC5-75025A55C44C--


From nobody Thu Oct 17 08:19:03 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74C0C1208BA for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 08:18:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qXdes44hFqN8 for <mls@ietfa.amsl.com>; Thu, 17 Oct 2019 08:18:47 -0700 (PDT)
Received: from mail-wr1-x42c.google.com (mail-wr1-x42c.google.com [IPv6:2a00:1450:4864:20::42c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F9891208E9 for <mls@ietf.org>; Thu, 17 Oct 2019 08:18:43 -0700 (PDT)
Received: by mail-wr1-x42c.google.com with SMTP id j11so2838071wrp.1 for <mls@ietf.org>; Thu, 17 Oct 2019 08:18:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=0vPDHW8Ulsz/tw9wzWoHXCBN4NIwIBa3WM0pTTnapQY=; b=dtC/tJ5m7dXnva/SceEbOt5+4Iilmmj1EBBDzdbu8Ia+EC8uR40MoDDX9F90oGz9pd 7JiOMgk1UiIHrTdMKQnuSE8le3c8GuwpzP1/iXLuhLRBgnw3NRbRzq1I95PGDYYIxOJ+ sqYgW/lqnlkIGxR5LpwOaC9kNzt3Sc3e7mZTUg4lojfvi1kB72VqqYJECH1WOnm89sZ7 0szcGQ0bRbkYdBjDp9Vfc4ebsQxV7TY+azBoYZgOfCWLj9JY/RVEIOQWYglh0L/v1hlC q2KVfxv2iJ/DRgmHZjGVfQTKI4wLZKu6c2Y4KcjHcxPX8jtzOsJc+ZiPgwXWjbmg6uia xpbg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=0vPDHW8Ulsz/tw9wzWoHXCBN4NIwIBa3WM0pTTnapQY=; b=TJF+hrBVC0e4y8FobRdUOx1weK4Qnei3RI20jhLvgq0gsHOFurJL6mpUZuE3xnBh2p rXo4KGKw+YohfNtID3bjtUFuoVeubrZxp6LMKlbQ8oyi2ZOsiS4slLKGdeO5prjbvBGX ntN5i6Ot8/NkRO7zRKQAKkZQLR4GYBnp76xNPnCmKSIk5KE5N0bRdixasxxWcQ9DDt32 NjEMIY45C46+3jAdANOO2DZ+y2ROTyP74snxS3rPOZcfzu0BSfJCccVCbl/E4vbJTzE8 IXHrldLCnue9xJlsvnU31YUqA3zYp8eLSWA9Ux5RD1dTXyVfvpau/EjpNWFEsKwmFa6P cF0Q==
X-Gm-Message-State: APjAAAVTXehM2nQmYlAmIrHqr07g1HrCB+ew18d9Wmb1Q508b54lJZp4 zUAewZjyK/IhjCpCyeYT/DUyoEayv/8=
X-Google-Smtp-Source: APXvYqxdDUtlazqOrSTnXIxYGMXmUIETog63Gtb2iNfOmyqHMMg9t7vEqELFwfN5N8CPPTMA43O0mw==
X-Received: by 2002:adf:f40a:: with SMTP id g10mr2825301wro.228.1571325521345;  Thu, 17 Oct 2019 08:18:41 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id t11sm2399202wmi.25.2019.10.17.08.18.39 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 17 Oct 2019 08:18:40 -0700 (PDT)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
Date: Thu, 17 Oct 2019 17:18:40 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/pvRkCB2E10J7Tsp76qfr3RlqD3I>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Oct 2019 15:19:01 -0000

I think the challenge with the hash-forward approach is how to do that
homomorphically. I.e. what we need are two algorithms; one to refresh
the PK without knowing the SK (but possibly knowing a secret
rerandomizer delta if needed) and one to update SK (again possibly using
delta). So to use a hash-forward approach their must be:

 1) a way to evolve PK forward to PK' and
 2) a *one-way* method to evolve SK forward to SK' compatible PK'.

One-wayness is what gives us Forward Secrecy and "compatibility" between
the two key evolution methods is what allows for asynchronous (i.e. 1
packet) updates.

Currently we use a secret re-randomizer delta to ensure the SK update
method is one-way. That is, without the delta you cant "undo" the
update. But that would break if we (at least naively) used some public
delta, say hash(ciphertext). So I think this is the challenge that we'd
have to overcome. Basically, make sure we SK evolution is one-way but
also compatible the public evolution of PK.



Now one way sweet way to get all this (and more) would be to use a HIBE.

Initial, PK for a ratchet tree node (i.e. its "identity" since this is a
HIBE now) is simply the empty vector PK := () while the secret key is
the master public key for a fresh HIBE instance SK := MSK. We also
include, as a second component of the nodes PK, the master public key
PK_0 = MPK. To "hash forward" / "re-randomize" when sending a ciphertext
C to that node we can do:

 PK' := (PK, hash(C)).
 SK' := DeriveHIBEKey(PK, SK).

So simply append hash(C) to the identity for that node and derive the
corresponding HIBE key.

Ignoring the problems with using HIBE for a second, this is a very cool
solution. We don't need to send out the updated PK since everyone in the
group (and even the adversary) can compute it for themselves. We also
dont need a re-randomize delta as part of the plaintext because we're
using delta := hash(ciphertext) so the plaintext is shorter again.
Moreover, HIBE security means that learning SK' doesn't tell you
anything interesting about SK. In particular, we have forward security.
(In fact, FS will hold even if hash(C) were chosen *completely*
adversarially, say, as part of a malicious update in an insider attack!)

Of course, the problem with this solution is that we're using HIBE.
Worse, with unbounded depth because each new ciphertext sent to a node
results in going one depth further into the hierarchy. AFAIK all HIBE
constructions have pretty horrible (read exponential) efficiency as a
function of their depth. (And I won't mention the state of
standardization and open implementations for HIBE.)

Now there could be a totally different approach that entirly avoids
HIBE. But even with this approach there's at least some glimer of hope
to improve on it because, if we don't wory about insider attacks we can
assume C is honestly generated which means hash(C) really has a ton of
entropy. So we dont seem to need the full expresivity HIBE identities
allow us. Rather we only need HIBE for "random" identities. Still, that
seems like a pretty slim hope for major efficiency improvement. It also
doesn't do anything to address the lack of implementations and standards.

- Joël

On 17/10/2019 16:37, Karthik Bhargavan wrote:
> Thanks Yevgeniy,
> 
> This helps a lot.
> 
> To further my understanding, another question:
> 
>>  Intuitively, the sender will not only encrypt the message, but also a
>> random Delta value. It will change public key using homomorthism by
>> multiplying with g^Delta (in specific DH based scheme), while the
>> recipient will decrypt Delta (using old secret key), and add it to the
>> old secret key to get there new one. So now corrupting (old sk plus
>> Delta) will not help decrypting the ciphertext just decepted, emailing
>> forward secrecy. 
> 
> I see that in the DH-based scheme, this Delta needs to be private,
> otherwise the adversary can compute sk once it knows sk+Delta.
> But, in general, is it possible to conceive of a UPKE scheme where the
> recipient effectively “hashes forward” its symmetric key,
> where this one way hash-forward function does not have to rely on an
> externally chosen secret value?
> 
> Best,
> Karthik
> 
>> This is the high level, hope it makes sense.
>> Thanks for your question,
>> Yevgeniy
>>
>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>> <karthikeyan.bhargavan@inria.fr
>> <mailto:karthikeyan.bhargavan@inria.fr>> wrote:
>>
>>     Hi Joel,
>>
>>     This looks very interesting. It is new to me since I was not at
>>     the interim.
>>     After reading the paper and the slides, I am still a bit fuzzy
>>     about what the recipient of an update needs to do.
>>
>>     For example, for the running example in your slide deck, it would
>>     help if I could see:
>>     - what secret keys does each leaf need to keep
>>     - how do these secrets change when an update from some other node
>>     is received.
>>     Just working this out for one update is enough.
>>
>>     I know that this is made precise in the eprint, but it would be
>>     faster if you could help us understand it :)
>>
>>     Best,
>>     Karthik
>>
>>     > On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>>     <mailto:jalwen@wickr.com>> wrote:
>>     >
>>     > <FS-TreeKEM.pdf>
>>
>>     _______________________________________________
>>     MLS mailing list
>>     MLS@ietf.org <mailto:MLS@ietf.org>
>>     https://www.ietf.org/mailman/listinfo/mls
>>
> 
> 
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Fri Oct 18 10:49:06 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DF0E12011F for <mls@ietfa.amsl.com>; Fri, 18 Oct 2019 10:49:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NatiYwaZrrx5 for <mls@ietfa.amsl.com>; Fri, 18 Oct 2019 10:49:00 -0700 (PDT)
Received: from mail-pf1-x432.google.com (mail-pf1-x432.google.com [IPv6:2607:f8b0:4864:20::432]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 756981200F8 for <mls@ietf.org>; Fri, 18 Oct 2019 10:49:00 -0700 (PDT)
Received: by mail-pf1-x432.google.com with SMTP id 205so4330437pfw.2 for <mls@ietf.org>; Fri, 18 Oct 2019 10:49:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=SENqneeVArgojE7c0mezLqd0SVJk59mkwLmWygZXbFA=; b=SuPj/SWbHdQTZc/8BxIGmEJ4tov96zOlJCINQZNB+AN90rZBkSzL6SpKL25oroSc5B 0bQXsK6aqNkdFPXzhooiQGj6madn1xFBjg2kWet/LQ/qMLBgyqy9YzL3JvbHlHiAehgw j6L8GKfASKIssNThnTCAefccwVBjm1fCjUNRA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=SENqneeVArgojE7c0mezLqd0SVJk59mkwLmWygZXbFA=; b=XoEumGqfM3Tes/YWnxmp+UmNvHit+eaySnsCiZtzsUvjDwHU06amufDemsZO1z/Y3f 55ljyPSa52H3AJC4qWh56DOnaGDYXRhqApy4Wh32ht+6DgIw5nG83DX00+d5qPQxhsyc qO/28W9sjzNfrOtZ8jPEFi037Q9FgyIRzrJ5Aqnkoz6dMRTkVg3aLqSQgCexgNTZihMP kPK8wry6v2rpV0NgsmQ+rNjq0S6Ww1/Plyg2n+og03si51VIJEek1WKhbuL6TB5VSRv2 W7jolhAvrYIWjfIaVbIay59a0ZpHOFTSMVOnO5zwZAOgyeS0J193Ll42ZdOb77yctuZh xqCg==
X-Gm-Message-State: APjAAAUGIw+xBGlGUGJNfWzK+lpEQKxnT4lCxDyZSSv94Jeax08G7WGW ZZ3Gerevox0v9qHZCL+f1CD/Vw==
X-Google-Smtp-Source: APXvYqzxdOscjz4fLkEQ9EuJucyyVz3VSPuKYfamrB4K3XrbU81uJg9yG9DD2fFVT+gVFEV+8WzDUQ==
X-Received: by 2002:a63:4b0f:: with SMTP id y15mr11783834pga.161.1571420939614;  Fri, 18 Oct 2019 10:48:59 -0700 (PDT)
Received: from [172.16.16.58] ([198.41.129.1]) by smtp.gmail.com with ESMTPSA id x139sm8926609pgx.92.2019.10.18.10.48.56 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 18 Oct 2019 10:48:57 -0700 (PDT)
From: Brendan McMillion <brendan@cloudflare.com>
Message-Id: <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_E0250104-3F91-4CB3-B7B7-049CDF0DAF11"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Fri, 18 Oct 2019 10:48:55 -0700
In-Reply-To: <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
To: Joel Alwen <jalwen@wickr.com>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/NRqbpU_XNXriF63CjncdfHjt1ts>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Oct 2019 17:49:05 -0000

--Apple-Mail=_E0250104-3F91-4CB3-B7B7-049CDF0DAF11
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hey Joel

This is a pretty subtle topic so I want to state the assumption that my =
conclusion is based on upfront: RTreeKEM achieves FS and PCS after a =
single Update (and all users come online and process the update), while =
normal TreeKEM requires everyone in the group to Update before achieving =
the same security guarantee.

This actually makes TreeKEM more attractive to me because it encourages =
implementors to keep the Update frequency high, and it provides an =
explicit signal to the group that everyone has processed every update. =
With TreeKEM, the policy would be =E2=80=9Ceverybody Updates at least =
once per day=E2=80=9D. But with RTreeKEM, the equivalent policy is =E2=80=9C=
at least one person Updates every day=E2=80=9D which isn=E2=80=99t as =
strong, because you don=E2=80=99t know whether or not everybody came =
online that day and processed the one Update.

And if you have a high Update frequency, I don=E2=80=99t think the =
security properties of TreeKEM and RTreeKEM are materially different. =
But RTreeKEM has costs like being harder to implement, and restricting =
what algorithms we can use.

It=E2=80=99s on this basis that I=E2=80=99m opposed to including =
RTreeKEM in the spec.

> On Oct 17, 2019, at 8:18 AM, Joel Alwen <jalwen@wickr.com> wrote:
>=20
> I think the challenge with the hash-forward approach is how to do that
> homomorphically. I.e. what we need are two algorithms; one to refresh
> the PK without knowing the SK (but possibly knowing a secret
> rerandomizer delta if needed) and one to update SK (again possibly =
using
> delta). So to use a hash-forward approach their must be:
>=20
> 1) a way to evolve PK forward to PK' and
> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>=20
> One-wayness is what gives us Forward Secrecy and "compatibility" =
between
> the two key evolution methods is what allows for asynchronous (i.e. 1
> packet) updates.
>=20
> Currently we use a secret re-randomizer delta to ensure the SK update
> method is one-way. That is, without the delta you cant "undo" the
> update. But that would break if we (at least naively) used some public
> delta, say hash(ciphertext). So I think this is the challenge that =
we'd
> have to overcome. Basically, make sure we SK evolution is one-way but
> also compatible the public evolution of PK.
>=20
>=20
>=20
> Now one way sweet way to get all this (and more) would be to use a =
HIBE.
>=20
> Initial, PK for a ratchet tree node (i.e. its "identity" since this is =
a
> HIBE now) is simply the empty vector PK :=3D () while the secret key =
is
> the master public key for a fresh HIBE instance SK :=3D MSK. We also
> include, as a second component of the nodes PK, the master public key
> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a =
ciphertext
> C to that node we can do:
>=20
> PK' :=3D (PK, hash(C)).
> SK' :=3D DeriveHIBEKey(PK, SK).
>=20
> So simply append hash(C) to the identity for that node and derive the
> corresponding HIBE key.
>=20
> Ignoring the problems with using HIBE for a second, this is a very =
cool
> solution. We don't need to send out the updated PK since everyone in =
the
> group (and even the adversary) can compute it for themselves. We also
> dont need a re-randomize delta as part of the plaintext because we're
> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
> Moreover, HIBE security means that learning SK' doesn't tell you
> anything interesting about SK. In particular, we have forward =
security.
> (In fact, FS will hold even if hash(C) were chosen *completely*
> adversarially, say, as part of a malicious update in an insider =
attack!)
>=20
> Of course, the problem with this solution is that we're using HIBE.
> Worse, with unbounded depth because each new ciphertext sent to a node
> results in going one depth further into the hierarchy. AFAIK all HIBE
> constructions have pretty horrible (read exponential) efficiency as a
> function of their depth. (And I won't mention the state of
> standardization and open implementations for HIBE.)
>=20
> Now there could be a totally different approach that entirly avoids
> HIBE. But even with this approach there's at least some glimer of hope
> to improve on it because, if we don't wory about insider attacks we =
can
> assume C is honestly generated which means hash(C) really has a ton of
> entropy. So we dont seem to need the full expresivity HIBE identities
> allow us. Rather we only need HIBE for "random" identities. Still, =
that
> seems like a pretty slim hope for major efficiency improvement. It =
also
> doesn't do anything to address the lack of implementations and =
standards.
>=20
> - Jo=C3=ABl
>=20
> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>> Thanks Yevgeniy,
>>=20
>> This helps a lot.
>>=20
>> To further my understanding, another question:
>>=20
>>>  Intuitively, the sender will not only encrypt the message, but also =
a
>>> random Delta value. It will change public key using homomorthism by
>>> multiplying with g^Delta (in specific DH based scheme), while the
>>> recipient will decrypt Delta (using old secret key), and add it to =
the
>>> old secret key to get there new one. So now corrupting (old sk plus
>>> Delta) will not help decrypting the ciphertext just decepted, =
emailing
>>> forward secrecy.=20
>>=20
>> I see that in the DH-based scheme, this Delta needs to be private,
>> otherwise the adversary can compute sk once it knows sk+Delta.
>> But, in general, is it possible to conceive of a UPKE scheme where =
the
>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric =
key,
>> where this one way hash-forward function does not have to rely on an
>> externally chosen secret value?
>>=20
>> Best,
>> Karthik
>>=20
>>> This is the high level, hope it makes sense.
>>> Thanks for your question,
>>> Yevgeniy
>>>=20
>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>> <karthikeyan.bhargavan@inria.fr
>>> <mailto:karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>>> wrote:
>>>=20
>>>    Hi Joel,
>>>=20
>>>    This looks very interesting. It is new to me since I was not at
>>>    the interim.
>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>    about what the recipient of an update needs to do.
>>>=20
>>>    For example, for the running example in your slide deck, it would
>>>    help if I could see:
>>>    - what secret keys does each leaf need to keep
>>>    - how do these secrets change when an update from some other node
>>>    is received.
>>>    Just working this out for one update is enough.
>>>=20
>>>    I know that this is made precise in the eprint, but it would be
>>>    faster if you could help us understand it :)
>>>=20
>>>    Best,
>>>    Karthik
>>>=20
>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>
>>>    <mailto:jalwen@wickr.com <mailto:jalwen@wickr.com>>> wrote:
>>>>=20
>>>> <FS-TreeKEM.pdf>
>>>=20
>>>    _______________________________________________
>>>    MLS mailing list
>>>    MLS@ietf.org <mailto:MLS@ietf.org> <mailto:MLS@ietf.org =
<mailto:MLS@ietf.org>>
>>>    https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>>=20
>>=20
>>=20
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org <mailto:MLS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>=20
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>

--Apple-Mail=_E0250104-3F91-4CB3-B7B7-049CDF0DAF11
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hey =
Joel<div class=3D""><br class=3D""></div><div class=3D"">This is a =
pretty subtle topic so I want to state the assumption that my conclusion =
is based on upfront: RTreeKEM achieves FS and PCS after a single Update =
(and all users come online and process the update), while normal TreeKEM =
requires everyone in the group to Update before achieving the same =
security guarantee.</div><div class=3D""><br class=3D""></div><div =
class=3D"">This actually makes TreeKEM more attractive to me because it =
encourages implementors to keep the Update frequency high, and it =
provides an explicit signal to the group that everyone has processed =
every update. With TreeKEM, the policy would be =E2=80=9Ceverybody =
Updates at least once per day=E2=80=9D. But with RTreeKEM, the =
equivalent policy is =E2=80=9Cat least one person Updates every day=E2=80=9D=
 which isn=E2=80=99t as strong, because you don=E2=80=99t know whether =
or not everybody came online that day and processed the one =
Update.</div><div class=3D""><br class=3D""></div><div class=3D"">And if =
you have a high Update frequency, I don=E2=80=99t think the security =
properties of TreeKEM and RTreeKEM are materially different. But =
RTreeKEM has costs like being harder to implement, and restricting what =
algorithms we can use.</div><div class=3D""><br class=3D""></div><div =
class=3D"">It=E2=80=99s on this basis that I=E2=80=99m opposed to =
including RTreeKEM in the spec.<br class=3D""><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On Oct =
17, 2019, at 8:18 AM, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">I think the challenge with the =
hash-forward approach is how to do that</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">homomorphically. I.e. what we need are two algorithms; one to =
refresh</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">the PK =
without knowing the SK (but possibly knowing a secret</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">rerandomizer delta if needed) =
and one to update SK (again possibly using</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">delta). So to use a hash-forward approach their must =
be:</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">1) a way to =
evolve PK forward to PK' and</span><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">2) a *one-way* method to evolve SK forward to SK' compatible =
PK'.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">One-wayness =
is what gives us Forward Secrecy and "compatibility" between</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">the two key evolution methods is =
what allows for asynchronous (i.e. 1</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">packet) updates.</span><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Currently we use a secret re-randomizer delta to ensure the =
SK update</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">method is =
one-way. That is, without the delta you cant "undo" the</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">update. But that would break if =
we (at least naively) used some public</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">delta, say hash(ciphertext). So I think this is the challenge =
that we'd</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">have to =
overcome. Basically, make sure we SK evolution is one-way but</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">also compatible the public =
evolution of PK.</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Now one way sweet way to get all this (and more) would be to =
use a HIBE.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Initial, PK =
for a ratchet tree node (i.e. its "identity" since this is a</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">HIBE now) is simply the empty =
vector PK :=3D () while the secret key is</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">the master public key for a fresh HIBE instance SK :=3D MSK. =
We also</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">include, as a =
second component of the nodes PK, the master public key</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">PK_0 =3D MPK. To "hash forward" =
/ "re-randomize" when sending a ciphertext</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">C to that node we can do:</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">PK' :=3D (PK, hash(C)).</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">SK' :=3D DeriveHIBEKey(PK, SK).</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">So simply append hash(C) to the identity for that node and =
derive the</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">corresponding =
HIBE key.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Ignoring the =
problems with using HIBE for a second, this is a very cool</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">solution. We don't need to send =
out the updated PK since everyone in the</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">group (and even the adversary) can compute it for themselves. =
We also</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">dont need a =
re-randomize delta as part of the plaintext because we're</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">using delta :=3D =
hash(ciphertext) so the plaintext is shorter again.</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Moreover, HIBE security means =
that learning SK' doesn't tell you</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">anything interesting about SK. In particular, we have forward =
security.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">(In fact, FS =
will hold even if hash(C) were chosen *completely*</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">adversarially, say, as part of a =
malicious update in an insider attack!)</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Of course, the problem with this solution is that we're using =
HIBE.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Worse, with =
unbounded depth because each new ciphertext sent to a node</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">results in going one depth =
further into the hierarchy. AFAIK all HIBE</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">constructions have pretty horrible (read exponential) =
efficiency as a</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">function of their depth. (And I won't mention the state =
of</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">standardization=
 and open implementations for HIBE.)</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Now there could be a totally different approach that entirly =
avoids</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">HIBE. But =
even with this approach there's at least some glimer of hope</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">to improve on it because, if we =
don't wory about insider attacks we can</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">assume C is honestly generated which means hash(C) really has =
a ton of</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">entropy. So =
we dont seem to need the full expresivity HIBE identities</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">allow us. Rather we only need =
HIBE for "random" identities. Still, that</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">seems like a pretty slim hope for major efficiency =
improvement. It also</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">doesn't do anything to address the lack of implementations =
and standards.</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">- Jo=C3=ABl</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">On 17/10/2019 16:37, Karthik Bhargavan wrote:</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" =
class=3D""><blockquote type=3D"cite" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D"">Thanks =
Yevgeniy,<br class=3D""><br class=3D"">This helps a lot.<br class=3D""><br=
 class=3D"">To further my understanding, another question:<br =
class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D"">&nbsp;Intuitively, the sender will not only encrypt the =
message, but also a<br class=3D"">random Delta value. It will change =
public key using homomorthism by<br class=3D"">multiplying with g^Delta =
(in specific DH based scheme), while the<br class=3D"">recipient will =
decrypt Delta (using old secret key), and add it to the<br class=3D"">old =
secret key to get there new one. So now corrupting (old sk plus<br =
class=3D"">Delta) will not help decrypting the ciphertext just decepted, =
emailing<br class=3D"">forward secrecy.&nbsp;<br =
class=3D""></blockquote><br class=3D"">I see that in the DH-based =
scheme, this Delta needs to be private,<br class=3D"">otherwise the =
adversary can compute sk once it knows sk+Delta.<br class=3D"">But, in =
general, is it possible to conceive of a UPKE scheme where the<br =
class=3D"">recipient effectively =E2=80=9Chashes forward=E2=80=9D its =
symmetric key,<br class=3D"">where this one way hash-forward function =
does not have to rely on an<br class=3D"">externally chosen secret =
value?<br class=3D""><br class=3D"">Best,<br class=3D"">Karthik<br =
class=3D""><br class=3D""><blockquote type=3D"cite" class=3D"">This is =
the high level, hope it makes sense.<br class=3D"">Thanks for your =
question,<br class=3D"">Yevgeniy<br class=3D""><br class=3D"">On Thu, =
Oct 17, 2019, 1:43 AM Karthik Bhargavan<br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">karthikeyan.bhargavan@inria.fr</a><br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br =
class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Hi Joel,<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;This looks very interesting. It is new to =
me since I was not at<br class=3D"">&nbsp;&nbsp;&nbsp;the interim.<br =
class=3D"">&nbsp;&nbsp;&nbsp;After reading the paper and the slides, I =
am still a bit fuzzy<br class=3D"">&nbsp;&nbsp;&nbsp;about what the =
recipient of an update needs to do.<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;For example, for the running example in =
your slide deck, it would<br class=3D"">&nbsp;&nbsp;&nbsp;help if I =
could see:<br class=3D"">&nbsp;&nbsp;&nbsp;- what secret keys does each =
leaf need to keep<br class=3D"">&nbsp;&nbsp;&nbsp;- how do these secrets =
change when an update from some other node<br =
class=3D"">&nbsp;&nbsp;&nbsp;is received.<br =
class=3D"">&nbsp;&nbsp;&nbsp;Just working this out for one update is =
enough.<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;I know that this =
is made precise in the eprint, but it would be<br =
class=3D"">&nbsp;&nbsp;&nbsp;faster if you could help us understand it =
:)<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Best,<br =
class=3D"">&nbsp;&nbsp;&nbsp;Karthik<br class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D"">On 16 Oct 2019, at =
23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
class=3D"">jalwen@wickr.com</a><br =
class=3D""></blockquote>&nbsp;&nbsp;&nbsp;&lt;<a =
href=3D"mailto:jalwen@wickr.com" =
class=3D"">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br =
class=3D""><blockquote type=3D"cite" class=3D""><br =
class=3D"">&lt;FS-TreeKEM.pdf&gt;<br class=3D""></blockquote><br =
class=3D"">&nbsp;&nbsp;&nbsp;_____________________________________________=
__<br class=3D"">&nbsp;&nbsp;&nbsp;MLS mailing list<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><span =
class=3D"Apple-converted-space">&nbsp;</span>&lt;<a =
href=3D"mailto:MLS@ietf.org" class=3D"">mailto:MLS@ietf.org</a>&gt;<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">MLS mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">_______________________________________________</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">MLS mailing list</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><a =
href=3D"mailto:MLS@ietf.org" style=3D"font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">MLS@ietf.org</a><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a></div></blockquote=
></div><br class=3D""></div></body></html>=

--Apple-Mail=_E0250104-3F91-4CB3-B7B7-049CDF0DAF11--


From nobody Mon Oct 21 05:03:42 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB4EA120110 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:03:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 71nntsyY0YhZ for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:03:36 -0700 (PDT)
Received: from mail-wr1-x431.google.com (mail-wr1-x431.google.com [IPv6:2a00:1450:4864:20::431]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 497061200EB for <mls@ietf.org>; Mon, 21 Oct 2019 05:03:36 -0700 (PDT)
Received: by mail-wr1-x431.google.com with SMTP id s1so4905546wro.0 for <mls@ietf.org>; Mon, 21 Oct 2019 05:03:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=FJ48iA7qywFaJ23IqHs13Sqe9jpRvk2ATuWREZDdXLw=; b=flPbInKc9g9wgy0lmmPyn7sV7/bLf8NogsQ+03aWCWzHPaSnScE5GVddxRcrtGRJUG wk+t6zNOdTwZSo0xUB0DUzL2BTQhJYiA2Gu4jImxYaeCFgeA7gv7+AiSnN/N4jqPYHbv Arzi0/Ai2UetV6yqol5MbRuCIGf8EZ92Ar2Zb9+gTP4t2maeRsjk16oPq++JnxSaOF0S zylsB2CFG3KIzqnadRCAlBSObBTvGJsr0SY9JoNwaZnJMre+syhcQjmvH2uv2rOr3Xi2 GpKw+fMW0pPwskxL1wJzpqHAWZfSEx2mM9T+UC9x/1/RThit1AnnoeueOXs1iREpVvDE fUkA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=FJ48iA7qywFaJ23IqHs13Sqe9jpRvk2ATuWREZDdXLw=; b=sS/ESd3SEDiuwudcDfx3/H2MPbikMPFOzD6U5IHJfuA7UjMx5W6kyiBkr6xe2hP45t 9qub9PU7SRAJVIq8dF+o1RGayIMNdZaQuVZC1rsvIvrWnJ8bAL94Gp8zRa4ktRj4ALcn I2BaFrT3l/0+ZGdpgYpCHAzVuejUUEJLY4LDlGkv7f6dEutz4kTHOQxKeCEy1AQvUeeM Ag2EeUWRKZ9tp1CE7jfItlyNB1I8ug5xpawHfoxDy76pkeL0zerM0Xae0BwOVwzhLI7Y xC/Etj/hFQ5pJaNFCzSSW+b3moNAJPYo9uz47aRQSLCARcF2yPVwbA6QV4fW6BGRCBwY PA3w==
X-Gm-Message-State: APjAAAW0LMz0hZ8LQP+pQfJ/UK2xRuXfRA5cc96LBH1TYz4J2PCaOGrV gnH0JfvkZ+skcZv2YaZ4o6OlPE7Hou8=
X-Google-Smtp-Source: APXvYqzElO2Lc8nxSyHZp7nJDDXeGPAiMWPc9F1M8haVTH+PCyHIp4LqKkoTEHdEiaxZTHHvvjQI4g==
X-Received: by 2002:a5d:5392:: with SMTP id d18mr13291537wrv.382.1571659414550;  Mon, 21 Oct 2019 05:03:34 -0700 (PDT)
Received: from wifi-pro-82-027.paris.inria.fr (wifi-pro-82-027.paris.inria.fr. [128.93.82.27]) by smtp.gmail.com with ESMTPSA id 200sm4217271wme.32.2019.10.21.05.03.33 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Oct 2019 05:03:33 -0700 (PDT)
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Message-Id: <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_0DECCE8C-96BB-426F-BEFF-F7D328A92AD8"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Mon, 21 Oct 2019 14:03:32 +0200
In-Reply-To: <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
Cc: mls@ietf.org
To: Joel Alwen <jalwen@wickr.com>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/dXcn4Z22oGM10rVxqMS9_bLzyb8>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 12:03:40 -0000

--Apple-Mail=_0DECCE8C-96BB-426F-BEFF-F7D328A92AD8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

I see. So, here=E2=80=99s how I read the improvements proposed in =
RTreeKEM.

Currently, in TreeKEM (like in ART before it) we rely on each member to =
regularly *send* updates in order to get both PCS and FS for the group =
secrets.
The informal secrecy guarantees we get are that:
- (FS) if member A sends an update in epoch N (moving the epoch to N+1), =
and if A gets compromised in epoch N+1, the messages sent in epoch N =
remain secret
- (PCS) if member A sends an update in epoch N (moving the epoch to =
N+1), and if A was (passively) compromised in epoch N, the messages sent =
in epoch N+1 remain secret
In other words, each member who sends an update gets local protection =
against compromise, encouraging vulnerable members to keep sending =
updates.

However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we =
could do better, at least for FS, if we use one-time decryption keys.
If each recipient deletes the old decryption key after processing an =
update, then even just by *processing* an update, we get an additional  =
guarantee:
- (FS=E2=80=99) if member A processes an update in epoch N (moving the =
epoch to N+1), and if A gets compromised in epoch N+1, the messages sent =
in epoch N remain secret

It is also worth remembering that Signal also has a notion of one-time =
prekeys that work similarly for new messaging sessions.
Although the following would be a bit ridiculous to use in large dynamic =
groups, here  is a sketch to achieve the receiver FS guarantee without =
the need for new crypto.
- Every time a member A sends an update, it generates fresh node secrets =
for nodes on the path from A to the root
- =46rom each node secret, A generates a large number K (=3D 100) =
private-public encryption keypairs and sends the public keys with the =
update.
- On receiving the update, each member B stores all K public keys for =
each node in its co-path
- Each of these public keys can be used only once for sending an update, =
after which the private key is deleted from all recipients.
- The last public key at each node is not deleted; it can only be =
replaced when one of the members under that node sends a new update =
(with a fresh batch of public keys).

As far as I understand, the above scheme can be seen as an (inefficient) =
implementation of UPKE, right?
Of course, it increases the size of each update by K, and only provides =
FS for K updates, after which some member has to send an update.
Conversely, it does not require any new crypto algorithm. Is this a good =
baseline to compare UPKE schemes against?

If I am mis-reading something, do let me know!

-Karthik






> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com> wrote:
>=20
> I think the challenge with the hash-forward approach is how to do that
> homomorphically. I.e. what we need are two algorithms; one to refresh
> the PK without knowing the SK (but possibly knowing a secret
> rerandomizer delta if needed) and one to update SK (again possibly =
using
> delta). So to use a hash-forward approach their must be:
>=20
> 1) a way to evolve PK forward to PK' and
> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>=20
> One-wayness is what gives us Forward Secrecy and "compatibility" =
between
> the two key evolution methods is what allows for asynchronous (i.e. 1
> packet) updates.
>=20
> Currently we use a secret re-randomizer delta to ensure the SK update
> method is one-way. That is, without the delta you cant "undo" the
> update. But that would break if we (at least naively) used some public
> delta, say hash(ciphertext). So I think this is the challenge that =
we'd
> have to overcome. Basically, make sure we SK evolution is one-way but
> also compatible the public evolution of PK.
>=20
>=20
>=20
> Now one way sweet way to get all this (and more) would be to use a =
HIBE.
>=20
> Initial, PK for a ratchet tree node (i.e. its "identity" since this is =
a
> HIBE now) is simply the empty vector PK :=3D () while the secret key =
is
> the master public key for a fresh HIBE instance SK :=3D MSK. We also
> include, as a second component of the nodes PK, the master public key
> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a =
ciphertext
> C to that node we can do:
>=20
> PK' :=3D (PK, hash(C)).
> SK' :=3D DeriveHIBEKey(PK, SK).
>=20
> So simply append hash(C) to the identity for that node and derive the
> corresponding HIBE key.
>=20
> Ignoring the problems with using HIBE for a second, this is a very =
cool
> solution. We don't need to send out the updated PK since everyone in =
the
> group (and even the adversary) can compute it for themselves. We also
> dont need a re-randomize delta as part of the plaintext because we're
> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
> Moreover, HIBE security means that learning SK' doesn't tell you
> anything interesting about SK. In particular, we have forward =
security.
> (In fact, FS will hold even if hash(C) were chosen *completely*
> adversarially, say, as part of a malicious update in an insider =
attack!)
>=20
> Of course, the problem with this solution is that we're using HIBE.
> Worse, with unbounded depth because each new ciphertext sent to a node
> results in going one depth further into the hierarchy. AFAIK all HIBE
> constructions have pretty horrible (read exponential) efficiency as a
> function of their depth. (And I won't mention the state of
> standardization and open implementations for HIBE.)
>=20
> Now there could be a totally different approach that entirly avoids
> HIBE. But even with this approach there's at least some glimer of hope
> to improve on it because, if we don't wory about insider attacks we =
can
> assume C is honestly generated which means hash(C) really has a ton of
> entropy. So we dont seem to need the full expresivity HIBE identities
> allow us. Rather we only need HIBE for "random" identities. Still, =
that
> seems like a pretty slim hope for major efficiency improvement. It =
also
> doesn't do anything to address the lack of implementations and =
standards.
>=20
> - Jo=C3=ABl
>=20
> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>> Thanks Yevgeniy,
>>=20
>> This helps a lot.
>>=20
>> To further my understanding, another question:
>>=20
>>>  Intuitively, the sender will not only encrypt the message, but also =
a
>>> random Delta value. It will change public key using homomorthism by
>>> multiplying with g^Delta (in specific DH based scheme), while the
>>> recipient will decrypt Delta (using old secret key), and add it to =
the
>>> old secret key to get there new one. So now corrupting (old sk plus
>>> Delta) will not help decrypting the ciphertext just decepted, =
emailing
>>> forward secrecy.=20
>>=20
>> I see that in the DH-based scheme, this Delta needs to be private,
>> otherwise the adversary can compute sk once it knows sk+Delta.
>> But, in general, is it possible to conceive of a UPKE scheme where =
the
>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric =
key,
>> where this one way hash-forward function does not have to rely on an
>> externally chosen secret value?
>>=20
>> Best,
>> Karthik
>>=20
>>> This is the high level, hope it makes sense.
>>> Thanks for your question,
>>> Yevgeniy
>>>=20
>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>> <karthikeyan.bhargavan@inria.fr
>>> <mailto:karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>>> wrote:
>>>=20
>>>    Hi Joel,
>>>=20
>>>    This looks very interesting. It is new to me since I was not at
>>>    the interim.
>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>    about what the recipient of an update needs to do.
>>>=20
>>>    For example, for the running example in your slide deck, it would
>>>    help if I could see:
>>>    - what secret keys does each leaf need to keep
>>>    - how do these secrets change when an update from some other node
>>>    is received.
>>>    Just working this out for one update is enough.
>>>=20
>>>    I know that this is made precise in the eprint, but it would be
>>>    faster if you could help us understand it :)
>>>=20
>>>    Best,
>>>    Karthik
>>>=20
>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>
>>>    <mailto:jalwen@wickr.com <mailto:jalwen@wickr.com>>> wrote:
>>>>=20
>>>> <FS-TreeKEM.pdf>
>>>=20
>>>    _______________________________________________
>>>    MLS mailing list
>>>    MLS@ietf.org <mailto:MLS@ietf.org> <mailto:MLS@ietf.org =
<mailto:MLS@ietf.org>>
>>>    https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>>=20
>>=20
>>=20
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org <mailto:MLS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>=20
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>

--Apple-Mail=_0DECCE8C-96BB-426F-BEFF-F7D328A92AD8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">I =
see. So, here=E2=80=99s how I read the improvements proposed in =
RTreeKEM.<div class=3D""><br class=3D""></div><div class=3D"">Currently, =
in TreeKEM (like in ART before it) we rely on each member to regularly =
*send* updates in order to get both PCS and FS for the group =
secrets.</div><div class=3D"">The informal secrecy guarantees we get are =
that:</div><div class=3D"">- (FS) if member A sends an update in epoch N =
(moving the epoch to N+1), and if A gets compromised in epoch N+1, the =
messages sent in epoch N remain secret</div><div class=3D"">- (PCS) if =
member A sends an update in epoch N (moving the epoch to N+1), and if A =
was (passively) compromised in epoch N, the messages sent in epoch N+1 =
remain secret</div><div class=3D"">In other words, each member who sends =
an update gets local protection against compromise, encouraging =
vulnerable members to keep sending updates.</div><div class=3D""><br =
class=3D""></div><div class=3D"">However, as Joel, Sandro, Yevgeniy, and =
Yiannis note in their paper, we could do better, at least for FS, if we =
use one-time decryption keys.</div><div class=3D"">If each recipient =
deletes the old decryption key after processing an update, then even =
just by *processing* an update, we get an additional =
&nbsp;guarantee:</div><div class=3D"">- (FS=E2=80=99) if member A =
processes an update in epoch N (moving the epoch to N+1), and if A gets =
compromised in epoch N+1, the messages sent in epoch N remain =
secret</div><div class=3D""><br class=3D""></div><div class=3D"">It is =
also worth remembering that Signal also has a notion of one-time prekeys =
that work similarly for new messaging sessions.</div><div =
class=3D"">Although the following would be a bit ridiculous to use in =
large dynamic groups, here &nbsp;is a sketch to achieve the receiver FS =
guarantee without the need for new crypto.</div><div class=3D"">- Every =
time a member A sends an update, it generates fresh node secrets for =
nodes on the path from A to the root</div><div class=3D"">- =46rom each =
node secret, A generates a large number K (=3D 100) private-public =
encryption keypairs and sends the public keys with the update.</div><div =
class=3D"">- On receiving the update, each member B stores all K public =
keys for each node in its co-path</div><div class=3D"">- Each of these =
public keys can be used only once for sending an update, after which the =
private key is deleted from all recipients.</div><div class=3D"">- The =
last public key at each node is not deleted; it can only be replaced =
when one of the members under that node sends a new update (with a fresh =
batch of public keys).</div><div class=3D""><br class=3D""></div><div =
class=3D"">As far as I understand, the above scheme can be seen as an =
(inefficient) implementation of UPKE, right?</div><div class=3D"">Of =
course, it increases the size of each update by K, and only provides FS =
for K updates, after which some member has to send an update.</div><div =
class=3D"">Conversely, it does not require any new crypto algorithm. Is =
this a good baseline to compare UPKE schemes against?</div><div =
class=3D""><br class=3D""></div><div class=3D"">If I am mis-reading =
something, do let me know!</div><div class=3D""><br class=3D""></div><div =
class=3D"">-Karthik</div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On 17 Oct 2019, at 17:18, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" class=3D"">jalwen@wickr.com</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">I think the challenge with the =
hash-forward approach is how to do that</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">homomorphically. I.e. what we need are two algorithms; one to =
refresh</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">the PK =
without knowing the SK (but possibly knowing a secret</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">rerandomizer delta if needed) =
and one to update SK (again possibly using</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">delta). So to use a hash-forward approach their must =
be:</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">1) a way to =
evolve PK forward to PK' and</span><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">2) a *one-way* method to evolve SK forward to SK' compatible =
PK'.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">One-wayness =
is what gives us Forward Secrecy and "compatibility" between</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">the two key evolution methods is =
what allows for asynchronous (i.e. 1</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">packet) updates.</span><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Currently we use a secret re-randomizer delta to ensure the =
SK update</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">method is =
one-way. That is, without the delta you cant "undo" the</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">update. But that would break if =
we (at least naively) used some public</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">delta, say hash(ciphertext). So I think this is the challenge =
that we'd</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">have to =
overcome. Basically, make sure we SK evolution is one-way but</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">also compatible the public =
evolution of PK.</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Now one way sweet way to get all this (and more) would be to =
use a HIBE.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Initial, PK =
for a ratchet tree node (i.e. its "identity" since this is a</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">HIBE now) is simply the empty =
vector PK :=3D () while the secret key is</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">the master public key for a fresh HIBE instance SK :=3D MSK. =
We also</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">include, as a =
second component of the nodes PK, the master public key</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">PK_0 =3D MPK. To "hash forward" =
/ "re-randomize" when sending a ciphertext</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">C to that node we can do:</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">PK' :=3D (PK, hash(C)).</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">SK' :=3D DeriveHIBEKey(PK, SK).</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">So simply append hash(C) to the identity for that node and =
derive the</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">corresponding =
HIBE key.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Ignoring the =
problems with using HIBE for a second, this is a very cool</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">solution. We don't need to send =
out the updated PK since everyone in the</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">group (and even the adversary) can compute it for themselves. =
We also</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">dont need a =
re-randomize delta as part of the plaintext because we're</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">using delta :=3D =
hash(ciphertext) so the plaintext is shorter again.</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Moreover, HIBE security means =
that learning SK' doesn't tell you</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">anything interesting about SK. In particular, we have forward =
security.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">(In fact, FS =
will hold even if hash(C) were chosen *completely*</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">adversarially, say, as part of a =
malicious update in an insider attack!)</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Of course, the problem with this solution is that we're using =
HIBE.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Worse, with =
unbounded depth because each new ciphertext sent to a node</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">results in going one depth =
further into the hierarchy. AFAIK all HIBE</span><br style=3D"caret-color:=
 rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">constructions have pretty horrible (read exponential) =
efficiency as a</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">function of their depth. (And I won't mention the state =
of</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">standardization=
 and open implementations for HIBE.)</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Now there could be a totally different approach that entirly =
avoids</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">HIBE. But =
even with this approach there's at least some glimer of hope</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">to improve on it because, if we =
don't wory about insider attacks we can</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">assume C is honestly generated which means hash(C) really has =
a ton of</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">entropy. So =
we dont seem to need the full expresivity HIBE identities</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">allow us. Rather we only need =
HIBE for "random" identities. Still, that</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">seems like a pretty slim hope for major efficiency =
improvement. It also</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">doesn't do anything to address the lack of implementations =
and standards.</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">- Jo=C3=ABl</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">On 17/10/2019 16:37, Karthik Bhargavan wrote:</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" =
class=3D""><blockquote type=3D"cite" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D"">Thanks =
Yevgeniy,<br class=3D""><br class=3D"">This helps a lot.<br class=3D""><br=
 class=3D"">To further my understanding, another question:<br =
class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D"">&nbsp;Intuitively, the sender will not only encrypt the =
message, but also a<br class=3D"">random Delta value. It will change =
public key using homomorthism by<br class=3D"">multiplying with g^Delta =
(in specific DH based scheme), while the<br class=3D"">recipient will =
decrypt Delta (using old secret key), and add it to the<br class=3D"">old =
secret key to get there new one. So now corrupting (old sk plus<br =
class=3D"">Delta) will not help decrypting the ciphertext just decepted, =
emailing<br class=3D"">forward secrecy.&nbsp;<br =
class=3D""></blockquote><br class=3D"">I see that in the DH-based =
scheme, this Delta needs to be private,<br class=3D"">otherwise the =
adversary can compute sk once it knows sk+Delta.<br class=3D"">But, in =
general, is it possible to conceive of a UPKE scheme where the<br =
class=3D"">recipient effectively =E2=80=9Chashes forward=E2=80=9D its =
symmetric key,<br class=3D"">where this one way hash-forward function =
does not have to rely on an<br class=3D"">externally chosen secret =
value?<br class=3D""><br class=3D"">Best,<br class=3D"">Karthik<br =
class=3D""><br class=3D""><blockquote type=3D"cite" class=3D"">This is =
the high level, hope it makes sense.<br class=3D"">Thanks for your =
question,<br class=3D"">Yevgeniy<br class=3D""><br class=3D"">On Thu, =
Oct 17, 2019, 1:43 AM Karthik Bhargavan<br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">karthikeyan.bhargavan@inria.fr</a><br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" =
class=3D"">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br =
class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Hi Joel,<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;This looks very interesting. It is new to =
me since I was not at<br class=3D"">&nbsp;&nbsp;&nbsp;the interim.<br =
class=3D"">&nbsp;&nbsp;&nbsp;After reading the paper and the slides, I =
am still a bit fuzzy<br class=3D"">&nbsp;&nbsp;&nbsp;about what the =
recipient of an update needs to do.<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;For example, for the running example in =
your slide deck, it would<br class=3D"">&nbsp;&nbsp;&nbsp;help if I =
could see:<br class=3D"">&nbsp;&nbsp;&nbsp;- what secret keys does each =
leaf need to keep<br class=3D"">&nbsp;&nbsp;&nbsp;- how do these secrets =
change when an update from some other node<br =
class=3D"">&nbsp;&nbsp;&nbsp;is received.<br =
class=3D"">&nbsp;&nbsp;&nbsp;Just working this out for one update is =
enough.<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;I know that this =
is made precise in the eprint, but it would be<br =
class=3D"">&nbsp;&nbsp;&nbsp;faster if you could help us understand it =
:)<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Best,<br =
class=3D"">&nbsp;&nbsp;&nbsp;Karthik<br class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D"">On 16 Oct 2019, at =
23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
class=3D"">jalwen@wickr.com</a><br =
class=3D""></blockquote>&nbsp;&nbsp;&nbsp;&lt;<a =
href=3D"mailto:jalwen@wickr.com" =
class=3D"">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br =
class=3D""><blockquote type=3D"cite" class=3D""><br =
class=3D"">&lt;FS-TreeKEM.pdf&gt;<br class=3D""></blockquote><br =
class=3D"">&nbsp;&nbsp;&nbsp;_____________________________________________=
__<br class=3D"">&nbsp;&nbsp;&nbsp;MLS mailing list<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><span =
class=3D"Apple-converted-space">&nbsp;</span>&lt;<a =
href=3D"mailto:MLS@ietf.org" class=3D"">mailto:MLS@ietf.org</a>&gt;<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">MLS mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">_______________________________________________</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">MLS mailing list</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><a =
href=3D"mailto:MLS@ietf.org" style=3D"font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">MLS@ietf.org</a><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a></div></blockquote=
></div><br class=3D""></div></body></html>=

--Apple-Mail=_0DECCE8C-96BB-426F-BEFF-F7D328A92AD8--


From nobody Mon Oct 21 05:20:44 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6A6712022A for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:20:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iODMzQkubH85 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:20:38 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [80.241.60.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6A10C120289 for <mls@ietf.org>; Mon, 21 Oct 2019 05:20:38 -0700 (PDT)
Received: from smtp2.mailbox.org (smtp2.mailbox.org [80.241.60.241]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id 57ECCA33C1 for <mls@ietf.org>; Mon, 21 Oct 2019 14:20:36 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp2.mailbox.org ([80.241.60.241]) by gerste.heinlein-support.de (gerste.heinlein-support.de [91.198.250.173]) (amavisd-new, port 10030) with ESMTP id xCpHZx1S79aV for <mls@ietf.org>; Mon, 21 Oct 2019 14:20:31 +0200 (CEST)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <dbe0eb1a-7a6a-4973-0951-7b6dd6f74a56@datashrine.de>
Date: Mon, 21 Oct 2019 14:20:30 +0200
MIME-Version: 1.0
In-Reply-To: <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: de-DE
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/y1EULsayK2htwIQS60DPnt2ue18>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 12:20:43 -0000

Hi Karthik,

I think you got it right with regard to the additional guarantees gained by
RTreeKEM.

Regarding your UPKE proposal: Wouldn't A then also have to send the private keys
of each key pair to all leaves of the sub-tree blonging to the node that the key
pair is generated for? Otherwise, only A could decrypt updates sent to those
keys. These private keys would have to be encrypted under some previous one-time
key that is subsequently deleted.

Cheers,
Konrad


On 21.10.19 15:03, Karthikeyan Bhargavan wrote:
> I see. So, here’s how I read the improvements proposed in RTreeKEM.
> 
> Currently, in TreeKEM (like in ART before it) we rely on each member to
> regularly *send* updates in order to get both PCS and FS for the group secrets.
> The informal secrecy guarantees we get are that:
> - (FS) if member A sends an update in epoch N (moving the epoch to N+1), and if
> A gets compromised in epoch N+1, the messages sent in epoch N remain secret
> - (PCS) if member A sends an update in epoch N (moving the epoch to N+1), and if
> A was (passively) compromised in epoch N, the messages sent in epoch N+1 remain
> secret
> In other words, each member who sends an update gets local protection against
> compromise, encouraging vulnerable members to keep sending updates.
> 
> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we could do
> better, at least for FS, if we use one-time decryption keys.
> If each recipient deletes the old decryption key after processing an update,
> then even just by *processing* an update, we get an additional  guarantee:
> - (FS’) if member A processes an update in epoch N (moving the epoch to N+1),
> and if A gets compromised in epoch N+1, the messages sent in epoch N remain secret
> 
> It is also worth remembering that Signal also has a notion of one-time prekeys
> that work similarly for new messaging sessions.
> Although the following would be a bit ridiculous to use in large dynamic groups,
> here  is a sketch to achieve the receiver FS guarantee without the need for new
> crypto.
> - Every time a member A sends an update, it generates fresh node secrets for
> nodes on the path from A to the root
> - From each node secret, A generates a large number K (= 100) private-public
> encryption keypairs and sends the public keys with the update.
> - On receiving the update, each member B stores all K public keys for each node
> in its co-path
> - Each of these public keys can be used only once for sending an update, after
> which the private key is deleted from all recipients.
> - The last public key at each node is not deleted; it can only be replaced when
> one of the members under that node sends a new update (with a fresh batch of
> public keys).
> 
> As far as I understand, the above scheme can be seen as an (inefficient)
> implementation of UPKE, right?
> Of course, it increases the size of each update by K, and only provides FS for K
> updates, after which some member has to send an update.
> Conversely, it does not require any new crypto algorithm. Is this a good
> baseline to compare UPKE schemes against?
> 
> If I am mis-reading something, do let me know!
> 
> -Karthik
> 
> 
> 
> 
> 
> 
>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com
>> <mailto:jalwen@wickr.com>> wrote:
>>
>> I think the challenge with the hash-forward approach is how to do that
>> homomorphically. I.e. what we need are two algorithms; one to refresh
>> the PK without knowing the SK (but possibly knowing a secret
>> rerandomizer delta if needed) and one to update SK (again possibly using
>> delta). So to use a hash-forward approach their must be:
>>
>> 1) a way to evolve PK forward to PK' and
>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>
>> One-wayness is what gives us Forward Secrecy and "compatibility" between
>> the two key evolution methods is what allows for asynchronous (i.e. 1
>> packet) updates.
>>
>> Currently we use a secret re-randomizer delta to ensure the SK update
>> method is one-way. That is, without the delta you cant "undo" the
>> update. But that would break if we (at least naively) used some public
>> delta, say hash(ciphertext). So I think this is the challenge that we'd
>> have to overcome. Basically, make sure we SK evolution is one-way but
>> also compatible the public evolution of PK.
>>
>>
>>
>> Now one way sweet way to get all this (and more) would be to use a HIBE.
>>
>> Initial, PK for a ratchet tree node (i.e. its "identity" since this is a
>> HIBE now) is simply the empty vector PK := () while the secret key is
>> the master public key for a fresh HIBE instance SK := MSK. We also
>> include, as a second component of the nodes PK, the master public key
>> PK_0 = MPK. To "hash forward" / "re-randomize" when sending a ciphertext
>> C to that node we can do:
>>
>> PK' := (PK, hash(C)).
>> SK' := DeriveHIBEKey(PK, SK).
>>
>> So simply append hash(C) to the identity for that node and derive the
>> corresponding HIBE key.
>>
>> Ignoring the problems with using HIBE for a second, this is a very cool
>> solution. We don't need to send out the updated PK since everyone in the
>> group (and even the adversary) can compute it for themselves. We also
>> dont need a re-randomize delta as part of the plaintext because we're
>> using delta := hash(ciphertext) so the plaintext is shorter again.
>> Moreover, HIBE security means that learning SK' doesn't tell you
>> anything interesting about SK. In particular, we have forward security.
>> (In fact, FS will hold even if hash(C) were chosen *completely*
>> adversarially, say, as part of a malicious update in an insider attack!)
>>
>> Of course, the problem with this solution is that we're using HIBE.
>> Worse, with unbounded depth because each new ciphertext sent to a node
>> results in going one depth further into the hierarchy. AFAIK all HIBE
>> constructions have pretty horrible (read exponential) efficiency as a
>> function of their depth. (And I won't mention the state of
>> standardization and open implementations for HIBE.)
>>
>> Now there could be a totally different approach that entirly avoids
>> HIBE. But even with this approach there's at least some glimer of hope
>> to improve on it because, if we don't wory about insider attacks we can
>> assume C is honestly generated which means hash(C) really has a ton of
>> entropy. So we dont seem to need the full expresivity HIBE identities
>> allow us. Rather we only need HIBE for "random" identities. Still, that
>> seems like a pretty slim hope for major efficiency improvement. It also
>> doesn't do anything to address the lack of implementations and standards.
>>
>> - Joël
>>
>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>> Thanks Yevgeniy,
>>>
>>> This helps a lot.
>>>
>>> To further my understanding, another question:
>>>
>>>>  Intuitively, the sender will not only encrypt the message, but also a
>>>> random Delta value. It will change public key using homomorthism by
>>>> multiplying with g^Delta (in specific DH based scheme), while the
>>>> recipient will decrypt Delta (using old secret key), and add it to the
>>>> old secret key to get there new one. So now corrupting (old sk plus
>>>> Delta) will not help decrypting the ciphertext just decepted, emailing
>>>> forward secrecy. 
>>>
>>> I see that in the DH-based scheme, this Delta needs to be private,
>>> otherwise the adversary can compute sk once it knows sk+Delta.
>>> But, in general, is it possible to conceive of a UPKE scheme where the
>>> recipient effectively “hashes forward” its symmetric key,
>>> where this one way hash-forward function does not have to rely on an
>>> externally chosen secret value?
>>>
>>> Best,
>>> Karthik
>>>
>>>> This is the high level, hope it makes sense.
>>>> Thanks for your question,
>>>> Yevgeniy
>>>>
>>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>>> <karthikeyan.bhargavan@inria.fr <mailto:karthikeyan.bhargavan@inria.fr>
>>>> <mailto:karthikeyan.bhargavan@inria.fr>> wrote:
>>>>
>>>>    Hi Joel,
>>>>
>>>>    This looks very interesting. It is new to me since I was not at
>>>>    the interim.
>>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>>    about what the recipient of an update needs to do.
>>>>
>>>>    For example, for the running example in your slide deck, it would
>>>>    help if I could see:
>>>>    - what secret keys does each leaf need to keep
>>>>    - how do these secrets change when an update from some other node
>>>>    is received.
>>>>    Just working this out for one update is enough.
>>>>
>>>>    I know that this is made precise in the eprint, but it would be
>>>>    faster if you could help us understand it :)
>>>>
>>>>    Best,
>>>>    Karthik
>>>>
>>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>>>>> <mailto:jalwen@wickr.com>
>>>>    <mailto:jalwen@wickr.com>> wrote:
>>>>>
>>>>> <FS-TreeKEM.pdf>
>>>>
>>>>    _______________________________________________
>>>>    MLS mailing list
>>>>    MLS@ietf.org <mailto:MLS@ietf.org> <mailto:MLS@ietf.org>
>>>>    https://www.ietf.org/mailman/listinfo/mls
>>>>
>>>
>>>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/mls
>>>
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org <mailto:MLS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/mls
> 
> 
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Mon Oct 21 05:28:07 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92590120099 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:28:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id inEnQwpXoOQF for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:28:04 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6436112004D for <mls@ietf.org>; Mon, 21 Oct 2019 05:28:04 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,323,1566856800";  d="scan'208,217";a="407220125"
Received: from unknown (HELO [172.20.10.9]) ([37.170.227.202]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 21 Oct 2019 14:28:02 +0200
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <53173BBC-7339-47C0-98A8-FCE6A30E3D78@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_1B97420D-3A11-4D00-AD6D-7CBFEFE31E0A"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
Date: Mon, 21 Oct 2019 14:28:01 +0200
In-Reply-To: <dbe0eb1a-7a6a-4973-0951-7b6dd6f74a56@datashrine.de>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com> <dbe0eb1a-7a6a-4973-0951-7b6dd6f74a56@datashrine.de>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/D8T_dKwijwTcAXXSTsnJIFpe1KU>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 12:28:07 -0000

--Apple-Mail=_1B97420D-3A11-4D00-AD6D-7CBFEFE31E0A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8



> On Oct 21, 2019, at 2:20 PM, Konrad Kohbrok =
<konrad.kohbrok@datashrine.de> wrote:
>=20
> Hi Karthik,
>=20
> I think you got it right with regard to the additional guarantees =
gained by
> RTreeKEM.
>=20
> Regarding your UPKE proposal: Wouldn't A then also have to send the =
private keys
> of each key pair to all leaves of the sub-tree blonging to the node =
that the key
> pair is generated for? Otherwise, only A could decrypt updates sent to =
those
> keys. These private keys would have to be encrypted under some =
previous one-time
> key that is subsequently deleted.

No, I think Karthik suggested to KDF (K=3D100) keypairs from the new =
secret (instead of K=3D1 today)
and immediately kill the received node secret for FS=E2=80=A6

B.=

--Apple-Mail=_1B97420D-3A11-4D00-AD6D-7CBFEFE31E0A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><br =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Oct 21, 2019, at 2:20 PM, Konrad Kohbrok &lt;<a =
href=3D"mailto:konrad.kohbrok@datashrine.de" =
class=3D"">konrad.kohbrok@datashrine.de</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Hi Karthik,</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">I think you got it right with =
regard to the additional guarantees gained by</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">RTreeKEM.</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Regarding your UPKE proposal: =
Wouldn't A then also have to send the private keys</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">of each key pair to all leaves =
of the sub-tree blonging to the node that the key</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">pair is generated for? =
Otherwise, only A could decrypt updates sent to those</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">keys. These private keys would =
have to be encrypted under some previous one-time</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">key that is subsequently =
deleted.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""></div></blockquote><div><br class=3D""></div><div>No, =
I think Karthik suggested to KDF (K=3D100) keypairs from the new secret =
(instead of K=3D1 today)</div><div>and immediately kill the received =
node secret for FS=E2=80=A6</div><div><br =
class=3D""></div><div>B.</div></div></body></html>=

--Apple-Mail=_1B97420D-3A11-4D00-AD6D-7CBFEFE31E0A--


From nobody Mon Oct 21 05:31:14 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E1C9120099 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:31:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LXWB35YqyZ3f for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 05:31:11 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [IPv6:2001:67c:2050:104:0:2:25:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 607CE12004D for <mls@ietf.org>; Mon, 21 Oct 2019 05:31:11 -0700 (PDT)
Received: from smtp2.mailbox.org (smtp2.mailbox.org [80.241.60.241]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id 4682AA0190 for <mls@ietf.org>; Mon, 21 Oct 2019 14:31:09 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp2.mailbox.org ([80.241.60.241]) by spamfilter01.heinlein-hosting.de (spamfilter01.heinlein-hosting.de [80.241.56.115]) (amavisd-new, port 10030) with ESMTP id 3Ycii6M5Y68F for <mls@ietf.org>; Mon, 21 Oct 2019 14:31:05 +0200 (CEST)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com> <dbe0eb1a-7a6a-4973-0951-7b6dd6f74a56@datashrine.de> <53173BBC-7339-47C0-98A8-FCE6A30E3D78@inria.fr>
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <a0af9af2-9133-6300-9bc2-217862ab7ca9@datashrine.de>
Date: Mon, 21 Oct 2019 14:31:04 +0200
MIME-Version: 1.0
In-Reply-To: <53173BBC-7339-47C0-98A8-FCE6A30E3D78@inria.fr>
Content-Type: text/plain; charset=utf-8
Content-Language: de-DE
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/4qT0AOpi6rRlr0YxAktm0aW-P8A>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 12:31:13 -0000

Ah, ok I misunderstood. That sounds a lot more feasible :-)

Konrad

On 21.10.19 15:28, Benjamin Beurdouche wrote:
> 
> 
>> On Oct 21, 2019, at 2:20 PM, Konrad Kohbrok <konrad.kohbrok@datashrine.de
>> <mailto:konrad.kohbrok@datashrine.de>> wrote:
>>
>> Hi Karthik,
>>
>> I think you got it right with regard to the additional guarantees gained by
>> RTreeKEM.
>>
>> Regarding your UPKE proposal: Wouldn't A then also have to send the private keys
>> of each key pair to all leaves of the sub-tree blonging to the node that the key
>> pair is generated for? Otherwise, only A could decrypt updates sent to those
>> keys. These private keys would have to be encrypted under some previous one-time
>> key that is subsequently deleted.
> 
> No, I think Karthik suggested to KDF (K=100) keypairs from the new secret
> (instead of K=1 today)
> and immediately kill the received node secret for FS…
> 
> B.
> 
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Mon Oct 21 14:16:02 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4FA2B12090B for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:16:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l_HW6T-PboUL for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:15:58 -0700 (PDT)
Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5118B1209AF for <mls@ietf.org>; Mon, 21 Oct 2019 14:15:58 -0700 (PDT)
Received: by mail-wr1-x42f.google.com with SMTP id s1so6822067wro.0 for <mls@ietf.org>; Mon, 21 Oct 2019 14:15:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=O7YW+RO3Z41Gi8k10p7Wcg8GRs73Fl90hxJeV7xHkzg=; b=XgnnyWOvlq45qXzDFDPPj/+ImLJwdoK93TejWGPnAf3n/jm46mTbh2+2jgxySDsjYg aP1C19gGfhOTiEcl9dv0BtxmJ5Hv77I5K4r1swi8zNLNokHsV4PdE0TjaiiTVFSlU6vO YWh/ycC2qzHkfj3NnUGg6EfZLnrZEY9IHNQA5QyyUufmZ8yLumm+IyWiYmwyonjAnar7 28PgpbjycTTV9kZFw6lKevyyzmvIt9i0ilrGnOMgY0nYIrnHbXasyCCyhXVjp4rbZOem fpgN+WYrB1Y99hRVfHPFrzl9jHprYaVuntRqJBVPrrsoCpRBVvXXvl2j5M3ven61q1qJ 5cVA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=O7YW+RO3Z41Gi8k10p7Wcg8GRs73Fl90hxJeV7xHkzg=; b=nRfpV12jvCD1HpLSSRMIrbQdwupYooOxBgJBF8AiIotKzwf6/J2FUnqmW/aQeU8kdU TzAMw2UlAlZ3W81NQ6g82Bf9POFa9A3K7MTJxOmWZDgC1DplPUZcjtDR2TTgp0ULSSf6 7tyeVkpSah8N3pAD7ZuWflfA5FluTLujnyEkAcDV0zbGK4PWYZR+/iXkw2DzvfD3We0t 8oNJZDZQZcoW8UPu3niepzZz2gUO+o7eIEqOf1qsKRYczgLwQN0YfEqBOJL1OhI6s3k0 kpOqEQUrFHfl8Ux1Hx5m6QmraAPYSl0X7mVpbnqXnWdqafWF3C9K9Izz39oyIbbmMd8l 9uuA==
X-Gm-Message-State: APjAAAWPLMbLr+z1NZuDtfIE1kreU7q0e3ha2rQP3aF5rJjFg7EHZy0k eQo4Vnwbsg53AbqaO3jF1VgsERIMFQ8=
X-Google-Smtp-Source: APXvYqwYYCXn7W8OK4GJkWOk026bpGtBPq6iaLXnIhZQ7AEcjTA46GpVko7thqHcw7zdEiJIgBumAQ==
X-Received: by 2002:adf:ed02:: with SMTP id a2mr235895wro.11.1571692556384; Mon, 21 Oct 2019 14:15:56 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id a13sm17458131wrf.73.2019.10.21.14.15.55 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Oct 2019 14:15:55 -0700 (PDT)
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <5715b312-bced-51e9-2b0b-abf681754958@wickr.com>
Date: Mon, 21 Oct 2019 23:15:55 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/q-D6MsdbVjsII1KVz9DGr1r2HsM>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 21:16:00 -0000

> - Every time a member A sends an update, it generates fresh node secrets
> for nodes on the path from A to the root
> - From each node secret, A generates a large number K (= 100)
> private-public encryption keypairs and sends the public keys with the
> update.
> - On receiving the update, each member B stores all K public keys for
> each node in its co-path
> - Each of these public keys can be used only once for sending an update,
> after which the private key is deleted from all recipients.
> - The last public key at each node is not deleted; it can only be
> replaced when one of the members under that node sends a new update
> (with a fresh batch of public keys).
> 
> As far as I understand, the above scheme can be seen as an (inefficient)
> implementation of UPKE, right?

I think your right. I think its similar to UPKE with the caveat that
only K ciphertext can be sent per call to UPKE-KeyGen. (In other words,
as you point out below, after K nodes encrypted to a ciphertext it
effectively becomes blank.)

But I think it does achieves the same properties for TreeKEM as the UPKE
constructions based on re-randomization, at least for the corruption
model we've been looking at.

> Of course, it increases the size of each update by K, and only provides
> FS for K updates, after which some member has to send an update.
> Conversely, it does not require any new crypto algorithm. Is this a good
> baseline to compare UPKE schemes against?

Well, its close but but has the limit on how many ciphertexts can be
sent to any given key-pair which UPKE normally doesnt have. On the other
hand if sender knows the old SK and then they can compute the new SK in
UPKE which is not the case in your construction. So I'd say its (at
least formally speaking) incomparable to UPKE.

- Joël


From nobody Mon Oct 21 14:20:49 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6ADD812001A for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:20:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o_zmWZZglwxC for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:20:45 -0700 (PDT)
Received: from mail-wm1-x32f.google.com (mail-wm1-x32f.google.com [IPv6:2a00:1450:4864:20::32f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5DC50120019 for <mls@ietf.org>; Mon, 21 Oct 2019 14:20:45 -0700 (PDT)
Received: by mail-wm1-x32f.google.com with SMTP id r141so4572236wme.4 for <mls@ietf.org>; Mon, 21 Oct 2019 14:20:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=to:from:subject:openpgp:autocrypt:message-id:date:user-agent :mime-version:content-language:content-transfer-encoding; bh=a1QBPnMIhQmuQK58B397uI+ZdUVu7MHKSl6zeNAFGqA=; b=fXpVhneDcVMDEvcUf+J548KVcINd8Y25wE36OaoW8Djla50RQIB+SgrG/nc2O+YzDw RWW+SedYX1YOH66AfWztj9JEU15k83w+kmQ3AvwkT+WbHklj87zBKxjrQKDM8SJAo10n qY2XKN6zt82pqmkFq4q9FHkNcBrMyAlYNNRn6Hl1cWfEwjBdIixwgJ/kzPsojD6ImBGn NGTjPuzlkP8MUoU7JFUWlGasUc0XxnMhr4o8pxcvrjClSZfdaUnqRDP2e2TZfRluooAX IHY7EDNhVduTqwbUooRRc3/MZM/CpwHGine9eg8NSUuzOvc9PHPGeMBh1zz1fdi9QF0q g4kw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:openpgp:autocrypt:message-id :date:user-agent:mime-version:content-language :content-transfer-encoding; bh=a1QBPnMIhQmuQK58B397uI+ZdUVu7MHKSl6zeNAFGqA=; b=tmUxE+GlOJqh0thfdb3/5f/5dUCM01RVQw3yn79jiVykAtNabGzdETtkb74I7HpdP6 E/JJ/w1+uEdMWdxSvmUN/eU8EMiFvgVGU+zw41Aqhhtyq0CuXFF/9n8H4V1rGDjhbiw3 cLRlisSWXIPnJM5TN+XiNS0lNIrU7Y7OPmx31GVlTP3BhS8DcigDmDMepsHNc/KSHblq PWute99+a7FSitveJGP3HBi5F/1C+YZ116OvyapRTtvFUDzJu7cyTbCGSVuHhAxP6pPS u/0MM1/svjj8tgQTdbT42lJOe8TdcIfGJ8ImMqhBkZ9XvdxQXUR5EWXY33Ja32D3N6zx PQHA==
X-Gm-Message-State: APjAAAWgknIdacE7BwQ4/vklYelnoCrl3XtAKLh43d5fVOyLGhXwlSuG tJoYA1uP8QJglEh7obwZbXIKwVWuR9Q=
X-Google-Smtp-Source: APXvYqxxRCg37Xf4YUZPUFuU6pMehA7LStZz0qGP7ybW/e276Ba+5M+zLXJFTDZS7RupItOPpVftag==
X-Received: by 2002:a05:600c:2c2:: with SMTP id 2mr23394wmn.112.1571692843330;  Mon, 21 Oct 2019 14:20:43 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id v10sm13239002wmg.48.2019.10.21.14.20.42 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Oct 2019 14:20:42 -0700 (PDT)
To: mls@ietf.org
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
Date: Mon, 21 Oct 2019 23:20:42 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/y5ikXqQh7VAojXrNSt9odxgNVmE>
Subject: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 21:20:47 -0000

Hey,

This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
separate thread as it changes whats in that first email and I didn't
want it getting lost in the other thread when people evaluate whether to
adopt RTreeKEM for MLS.)

In short, after some very helpful back and forth with Mike Hamburg, it
is looking like we have a reasonable way to do Re-randomizable TreeKEM
(RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
longer have to choose between RTreeKEM and those suits. IMO that removes
the biggest barrier to using RTreeKEM.

To be clear, we're still doing a some coding & testing to build
confidence. And we will also run it past the CFRG / a few more ECC
experts besides Mike, to make absolutely sure it works as intended.
But at this point we are pretty optimistic already.

The rest of this email contains the details for how RTreeKEM can be made
to work with the X* groups.

- Joël

-----------------------------------------------------------


Essentially, all we really need for RTreeKEM is to build "Updateable
Public Key Encryption" (UPKE) as defined in [1].

Rather than the construction in [1] which is based additive
key-homomorphism we can use the following construction based on a
multiplicative key-homomorphism. (It turns out the later is easier to
implement for X* groups than the former.)

To minimize the diff between current TreeKEM and this new variant of
RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
black boxes.

Inherited from Cipher Suite
---------------------------
- sksize = # of bits for secret key scalars. (e.g. 32 for X25518)
- order = order of prime-order subgroup (e.g. as in RFC 7748)
- DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
- Mult(a,b) : Multiplication of secret keys. See below.


Multiplication
--------------
- NIST curves : Mult(a,b) = a*b mod order.
- X25519 : let Clamp(k) = decodeScalar25519(k) as in RFC 7748.
- X448 : let Clamp(k) = decodeScalar448(k) as in RFC 7748.

For both X25519 & X448 use
 Mult(a,b) {
   c = (Clamp(a) - Clamp(b)) mod order
   if msb(c) = 0
     c = (order - c) mod order
   return c
 }


UPKE Construction (from HPKE & HKDF)
------------------------------------
- UPKE-KeyGen = HPKE-KeyGen

- UPKE-Encrypt(pk, m):
  d'  <-- {0,1}^secpar
  d   := HKDF(sksize, d', "", "derive UPKE delta")
  c1, context := HPKE.SetupBaseI(pk, "")
  c2  <-- context.Seal("", d' || m)
  pk' := DH(pk, d)
  return ((c1, c2), pk')

- UPKE-Decrypt(sk, (c1, c2)):
  epk, context := HPKE.SetupBaseR(c1, sk, "")
  d' || m := context.Open("", c2)
  d := HKDF(sksize, d', "", "derive UPKE delta")
  sk' := Mult(sk, d)
  return (m, sk')


References
----------
[1] http:\\ia.cr\2019\1189.


From nobody Mon Oct 21 14:50:42 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58ED11209AF for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:50:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id akTzCfyEggHv for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:50:38 -0700 (PDT)
Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com [IPv6:2a00:1450:4864:20::42b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF81C12001A for <mls@ietf.org>; Mon, 21 Oct 2019 14:50:37 -0700 (PDT)
Received: by mail-wr1-x42b.google.com with SMTP id z9so15640551wrl.11 for <mls@ietf.org>; Mon, 21 Oct 2019 14:50:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=xP0puNht2FNPaxZ3s6FD2Kith9jZgAFLr4GyN6rBwBI=; b=iNBQk6V4qmmr3tmV4vWPjM7CFPPMDMbHPzC4zujSFblnLbU1Ti+oavrj6iQS89YgNZ vzYx0M6c2VOhDNwMLXl+uevgxppi7/zb6w6PUANQp5AI0yAkj4yhUozbao0nnXdRdAQC c01+uV6bXRy5e2vtNPSP7qF3YQTPbkFSREEKXEo8JnD9tQzMU/2i1g/jCIElw8qxwo6+ Nb+r39/sRg4XWuMm/CmPXtKCIipxWmG9B/HsHEq639n/PcbbF6WsylbT4qq7X4D5jm9G Sa0C6mvbLW3a1FFd8DSjZNAgJWCzlcZMUiPKHJPUb9KW4f3/ARnBsV1caqrtG9zOhteW VZQQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=xP0puNht2FNPaxZ3s6FD2Kith9jZgAFLr4GyN6rBwBI=; b=kEgYSivw6+n5rsLBvqtTuBsxTX5IyCxOl4ra9PwhDNnmCS2eVaNqFqu0Twf9bB/iyJ IffGWHL7aM+IgcwNC1H5hftEN0mfnc6nFCfxbmx/HTMiiR07tCkHZp8OrhsJ96rv/gCB SYDKlmvA0grKXQfj2+mrmTGXH513fAHCBq35rIyVkvJkjFscESERd/OttuXyBY+uI8oI 5ivuA3K6zYNf+F/jcyiaoP3eLXAvZUjrH+Fh1GRuI7O375gp66z6tGUiEhBRo8vbv9gf NITsn/SbnvCAA0Wy2vJ6VwNV2/f7c7APXyMm0k8FUjqpHdhSjkKDeewmUWN2Z1NBSGmH GUsw==
X-Gm-Message-State: APjAAAWsqN5/PR5MqXvcYPSTeQo04yKL+IK87vAlHU+7BQkS6CdEBzm9 WFssraNwoktmdOXPC7mi/ekZxevcjfw=
X-Google-Smtp-Source: APXvYqwRIqiTTX4XLmQv8j+kzyl1mRQcscrUBxIyD9u3gPzxkaafGbYiebR1+c6IqsZqod2vlf/awg==
X-Received: by 2002:a5d:540c:: with SMTP id g12mr317146wrv.335.1571694635563;  Mon, 21 Oct 2019 14:50:35 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id x7sm19865928wrg.63.2019.10.21.14.50.34 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Oct 2019 14:50:35 -0700 (PDT)
To: Brendan McMillion <brendan@cloudflare.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com>
Date: Mon, 21 Oct 2019 23:50:34 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/BGfRnWHkP1UJb5ENX13m2K-5UJY>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 21:50:40 -0000

Hey Brendan,

Thanks for taking the time to look at this stuff and answer! :-)

> This actually makes TreeKEM more attractive to me because it encourages
> implementors to keep the Update frequency high, 

If one can afford high update frequency then that's great. It helps
RTreeKEM too by the way. The longer between updates the less PCS we have
and the longer the corruption windows. So there's still plenty of
incentive in RTreeKEM to update as often as you can.

But more generally, to me a primary design goal for MLS is to get as
much security for as little bandwidth as possible. So I'm particularly
interested in the protocols behavior when there *isn't* that much
bandwidth to spare for frequent updates.

> and it provides an
> explicit signal to the group that everyone has processed every update.
> With TreeKEM, the policy would be “everybody Updates at least once per
> day”. But with RTreeKEM, the equivalent policy is “at least one person
> Updates every day” which isn’t as strong, because you don’t know whether
> or not everybody came online that day and processed the one Update.

If your not coming online then I'm not sure I see the difference between
using TreeKEM or RTreeKEM. I mean, either way your not refreshing any
key material so your preventing the group from achieving FS. Moreover,
coming online to send a daily update TreeKEM means already requires
processing other peoples updates first.

If, on the other hand, the concern is the lack of an explicit signal
wouldnt it be enough to have parties send out ACK msgs to the group when
they process an update? That would consume far less bandwidth (and
computation) than doing a full update alla TreeKEM.

> But RTreeKEM has costs like being harder to implement, and restricting what
> algorithms we can use.

FYI: In the mean time it looks like we may have found a way to make
RTreeKEM work with X25519/X448 groups. (See the email I just sent to the
group for more on this.) Harder to implement I do agree with. Albeit IMO
the difference is rather marginal compared to how much code is needed to
implement the rest of MLS, not to mention all the surrounding
infrastructure; e.g. the servers, the rest of the client, UX etc need to
actually deploy MLS. At the end of the day, I don't think we're talking
about much more than a few lines of code wrapping HPKE. But I might be
wrong here.

> It’s on this basis that I’m opposed to including RTreeKEM in the spec.

Fair enough! :-)

- Joël


From nobody Mon Oct 21 14:57:29 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D027120AA0 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:57:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level: 
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OC_v6iI1Mdkr for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 14:57:19 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D4E9120A7F for <mls@ietf.org>; Mon, 21 Oct 2019 14:57:19 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,325,1566856800"; d="scan'208";a="323592350"
Received: from 37-166-43-191.coucou-networks.fr (HELO [172.20.10.9]) ([37.166.43.191]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 21 Oct 2019 23:57:17 +0200
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
In-Reply-To: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
Date: Mon, 21 Oct 2019 23:57:12 +0200
Cc: ML Messaging Layer Security <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <8E0E25A7-2839-4D45-8C8E-07B79637FABC@inria.fr>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
To: Joel Alwen <jalwen@wickr.com>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/tdQ2eoGyxipHb9kNHm64hCGz6dU>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 21:57:27 -0000

That look excellent !
If that works as expected, that would indeed be very nice=E2=80=A6 : )

B.

> On Oct 21, 2019, at 11:20 PM, Joel Alwen <jalwen@wickr.com> wrote:
>=20
> Hey,
>=20
> This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
> separate thread as it changes whats in that first email and I didn't
> want it getting lost in the other thread when people evaluate whether =
to
> adopt RTreeKEM for MLS.)
>=20
> In short, after some very helpful back and forth with Mike Hamburg, it
> is looking like we have a reasonable way to do Re-randomizable TreeKEM
> (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
> longer have to choose between RTreeKEM and those suits. IMO that =
removes
> the biggest barrier to using RTreeKEM.
>=20
> To be clear, we're still doing a some coding & testing to build
> confidence. And we will also run it past the CFRG / a few more ECC
> experts besides Mike, to make absolutely sure it works as intended.
> But at this point we are pretty optimistic already.
>=20
> The rest of this email contains the details for how RTreeKEM can be =
made
> to work with the X* groups.
>=20
> - Jo=C3=ABl
>=20
> -----------------------------------------------------------
>=20
>=20
> Essentially, all we really need for RTreeKEM is to build "Updateable
> Public Key Encryption" (UPKE) as defined in [1].
>=20
> Rather than the construction in [1] which is based additive
> key-homomorphism we can use the following construction based on a
> multiplicative key-homomorphism. (It turns out the later is easier to
> implement for X* groups than the former.)
>=20
> To minimize the diff between current TreeKEM and this new variant of
> RTreeKEM, the new construction is formulated it to use HPKE and HKDF =
as
> black boxes.
>=20
> Inherited from Cipher Suite
> ---------------------------
> - sksize =3D # of bits for secret key scalars. (e.g. 32 for X25518)
> - order =3D order of prime-order subgroup (e.g. as in RFC 7748)
> - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
> - Mult(a,b) : Multiplication of secret keys. See below.
>=20
>=20
> Multiplication
> --------------
> - NIST curves : Mult(a,b) =3D a*b mod order.
> - X25519 : let Clamp(k) =3D decodeScalar25519(k) as in RFC 7748.
> - X448 : let Clamp(k) =3D decodeScalar448(k) as in RFC 7748.
>=20
> For both X25519 & X448 use
> Mult(a,b) {
>   c =3D (Clamp(a) - Clamp(b)) mod order
>   if msb(c) =3D 0
>     c =3D (order - c) mod order
>   return c
> }
>=20
>=20
> UPKE Construction (from HPKE & HKDF)
> ------------------------------------
> - UPKE-KeyGen =3D HPKE-KeyGen
>=20
> - UPKE-Encrypt(pk, m):
>  d'  <-- {0,1}^secpar
>  d   :=3D HKDF(sksize, d', "", "derive UPKE delta")
>  c1, context :=3D HPKE.SetupBaseI(pk, "")
>  c2  <-- context.Seal("", d' || m)
>  pk' :=3D DH(pk, d)
>  return ((c1, c2), pk')
>=20
> - UPKE-Decrypt(sk, (c1, c2)):
>  epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
>  d' || m :=3D context.Open("", c2)
>  d :=3D HKDF(sksize, d', "", "derive UPKE delta")
>  sk' :=3D Mult(sk, d)
>  return (m, sk')
>=20
>=20
> References
> ----------
> [1] http:\\ia.cr\2019\1189.
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


From nobody Mon Oct 21 15:15:44 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 077FA120891 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 15:15:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ko_hz7E4Qb_U for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 15:15:40 -0700 (PDT)
Received: from mail-io1-f41.google.com (mail-io1-f41.google.com [209.85.166.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A69D7120A5F for <mls@ietf.org>; Mon, 21 Oct 2019 15:15:40 -0700 (PDT)
Received: by mail-io1-f41.google.com with SMTP id c6so17861982ioo.13 for <mls@ietf.org>; Mon, 21 Oct 2019 15:15:40 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=M+yIKDQrrLo7ikijFIThevWGqfNaXLjFQ8XIai9a10A=; b=cSBssgHXNsQ4cXsjeQDyLPL0ImLsGeTSFBl9l6vu6iFWW1Wy+NpMw+Qi/579uP7dK3 ammmtbpRN9y46wCBMBgXGVLr5/ZwXo1auKqMV6WpMGHXEcOttFxR+3O5cS+dNCtbcLeA hJEGuxbMudvHhbpKqt4oh/SVKhXltfZIfR5ar3oZzSpkCP8vOC6iVqm8NDLmpxIjR+8b DS5qZpXxbCE+fCc1wJH7zXij71IEQMLINuDragrES/AOkvllmjpRs4f/lL226ThjkGOQ M1LtAN0u83ssXLhM+LE4LuhagYXDvi/HuyF0y0M3c/h0nDWje2OROE3Ul4N9LniTkLIa GRKg==
X-Gm-Message-State: APjAAAWLKwl5ORUoQ0tiLwQYW7VjmOluZ+Px/zRayP6XzXAfiscYJrYM FwtdU5dvNJ4f210Z4PCljNL5AwaEdF8QdB1DmXo=
X-Google-Smtp-Source: APXvYqzjdmVXX0Q4ilRkXyrkpPBfja2baAwhyzj4gHJPtukCqcPMJSF7Ctk7q8d5EnCROnjSMH7YuiHwPebJEm1XmkA=
X-Received: by 2002:a6b:f708:: with SMTP id k8mr538540iog.188.1571696139521; Mon, 21 Oct 2019 15:15:39 -0700 (PDT)
MIME-Version: 1.0
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <8E0E25A7-2839-4D45-8C8E-07B79637FABC@inria.fr>
In-Reply-To: <8E0E25A7-2839-4D45-8C8E-07B79637FABC@inria.fr>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Mon, 21 Oct 2019 18:15:28 -0400
Message-ID: <CAMvzKsh=PpYk7mvJ6kyg7jSsO82WY6hmOhXmavqXEP6FiaH-rw@mail.gmail.com>
To: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Cc: Joel Alwen <jalwen@wickr.com>, ML Messaging Layer Security <mls@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000017536f05957306d4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/xEBElbIuPWY4pDCjDHb3dyGyFMU>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 22:15:43 -0000

--00000000000017536f05957306d4
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thank you Benjamin.

We hope there will be no more surprises, like the lack of additive
homomorphism for the X-curves. So we would certainly love to get
guidance from other people on the list, in case we missed something else.

There is definitely some cost involved, but we hope it is small, and we
believe using UPKE in place of PKE gives a substantial security
enhancement to justify the (small) cost.

We could also follow Karthik's nice suggestion to compare our scheme with
"naive" UPKE, where for each updated tree node one prepares K (say, 100)
public-secret key pairs, and erases them one-by-one as they get used on
various co-paths. If one runs out of fresh pairs, the last key pair is not
erased, and gets used until the update happens. Ironically, K=3D1 correspon=
ds
to the current scheme, so in this sense the naive scheme -- call it
K-TreeKEM -- is a natural generalization of TreeKEM. However, we believe
already for small K (like 3 or 4), K-TreeKEM will start becoming less
efficient overall than RTreeKEM, while still offering inferior security.
But this is a good thing to test if people are interested.

Thank you in advance for your comments,
Yevgeniy

On Mon, Oct 21, 2019 at 5:57 PM Benjamin Beurdouche <
benjamin.beurdouche@inria.fr> wrote:

> That look excellent !
> If that works as expected, that would indeed be very nice=E2=80=A6 : )
>
> B.
>
> > On Oct 21, 2019, at 11:20 PM, Joel Alwen <jalwen@wickr.com> wrote:
> >
> > Hey,
> >
> > This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
> > separate thread as it changes whats in that first email and I didn't
> > want it getting lost in the other thread when people evaluate whether t=
o
> > adopt RTreeKEM for MLS.)
> >
> > In short, after some very helpful back and forth with Mike Hamburg, it
> > is looking like we have a reasonable way to do Re-randomizable TreeKEM
> > (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
> > longer have to choose between RTreeKEM and those suits. IMO that remove=
s
> > the biggest barrier to using RTreeKEM.
> >
> > To be clear, we're still doing a some coding & testing to build
> > confidence. And we will also run it past the CFRG / a few more ECC
> > experts besides Mike, to make absolutely sure it works as intended.
> > But at this point we are pretty optimistic already.
> >
> > The rest of this email contains the details for how RTreeKEM can be mad=
e
> > to work with the X* groups.
> >
> > - Jo=C3=ABl
> >
> > -----------------------------------------------------------
> >
> >
> > Essentially, all we really need for RTreeKEM is to build "Updateable
> > Public Key Encryption" (UPKE) as defined in [1].
> >
> > Rather than the construction in [1] which is based additive
> > key-homomorphism we can use the following construction based on a
> > multiplicative key-homomorphism. (It turns out the later is easier to
> > implement for X* groups than the former.)
> >
> > To minimize the diff between current TreeKEM and this new variant of
> > RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
> > black boxes.
> >
> > Inherited from Cipher Suite
> > ---------------------------
> > - sksize =3D # of bits for secret key scalars. (e.g. 32 for X25518)
> > - order =3D order of prime-order subgroup (e.g. as in RFC 7748)
> > - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
> > - Mult(a,b) : Multiplication of secret keys. See below.
> >
> >
> > Multiplication
> > --------------
> > - NIST curves : Mult(a,b) =3D a*b mod order.
> > - X25519 : let Clamp(k) =3D decodeScalar25519(k) as in RFC 7748.
> > - X448 : let Clamp(k) =3D decodeScalar448(k) as in RFC 7748.
> >
> > For both X25519 & X448 use
> > Mult(a,b) {
> >   c =3D (Clamp(a) - Clamp(b)) mod order
> >   if msb(c) =3D 0
> >     c =3D (order - c) mod order
> >   return c
> > }
> >
> >
> > UPKE Construction (from HPKE & HKDF)
> > ------------------------------------
> > - UPKE-KeyGen =3D HPKE-KeyGen
> >
> > - UPKE-Encrypt(pk, m):
> >  d'  <-- {0,1}^secpar
> >  d   :=3D HKDF(sksize, d', "", "derive UPKE delta")
> >  c1, context :=3D HPKE.SetupBaseI(pk, "")
> >  c2  <-- context.Seal("", d' || m)
> >  pk' :=3D DH(pk, d)
> >  return ((c1, c2), pk')
> >
> > - UPKE-Decrypt(sk, (c1, c2)):
> >  epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
> >  d' || m :=3D context.Open("", c2)
> >  d :=3D HKDF(sksize, d', "", "derive UPKE delta")
> >  sk' :=3D Mult(sk, d)
> >  return (m, sk')
> >
> >
> > References
> > ----------
> > [1] http:\\ia.cr\2019\1189.
> >
> > _______________________________________________
> > MLS mailing list
> > MLS@ietf.org
> > https://www.ietf.org/mailman/listinfo/mls
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--00000000000017536f05957306d4
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thank you Benjamin.<div><br></div><div>We hope there will =
be no more surprises, like the lack of additive homomorphism for the X-curv=
es. So we would certainly love to get=C2=A0</div><div>guidance from other p=
eople on the list, in case we missed something=C2=A0else.</div><div><br></d=
iv><div>There is definitely some cost involved, but we hope it is small, an=
d we believe=C2=A0using UPKE in place of PKE gives a substantial security</=
div><div>enhancement to justify the (small) cost.</div><div><br></div><div>=
We could also follow Karthik&#39;s nice suggestion to compare our scheme wi=
th &quot;naive&quot; UPKE, where for each updated tree node one prepares K =
(say, 100) public-secret key pairs, and erases them one-by-one as they get =
used on various co-paths. If one runs out of fresh pairs, the last key pair=
 is not erased, and gets used until the update happens. Ironically, K=3D1 c=
orresponds to the current scheme, so in this sense the naive scheme -- call=
 it K-TreeKEM -- is a natural=C2=A0generalization of TreeKEM. However, we b=
elieve already for=C2=A0small K (like 3 or 4), K-TreeKEM will start becomin=
g less efficient overall than RTreeKEM, while still offering inferior secur=
ity. But this is a good thing to test if people are interested.</div><div><=
br></div><div>Thank you in advance for your comments,</div><div>Yevgeniy</d=
iv></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_att=
r">On Mon, Oct 21, 2019 at 5:57 PM Benjamin Beurdouche &lt;<a href=3D"mailt=
o:benjamin.beurdouche@inria.fr">benjamin.beurdouche@inria.fr</a>&gt; wrote:=
<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8=
ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">That look excel=
lent !<br>
If that works as expected, that would indeed be very nice=E2=80=A6 : )<br>
<br>
B.<br>
<br>
&gt; On Oct 21, 2019, at 11:20 PM, Joel Alwen &lt;<a href=3D"mailto:jalwen@=
wickr.com" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:<br>
&gt; <br>
&gt; Hey,<br>
&gt; <br>
&gt; This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a=
<br>
&gt; separate thread as it changes whats in that first email and I didn&#39=
;t<br>
&gt; want it getting lost in the other thread when people evaluate whether =
to<br>
&gt; adopt RTreeKEM for MLS.)<br>
&gt; <br>
&gt; In short, after some very helpful back and forth with Mike Hamburg, it=
<br>
&gt; is looking like we have a reasonable way to do Re-randomizable TreeKEM=
<br>
&gt; (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no=
<br>
&gt; longer have to choose between RTreeKEM and those suits. IMO that remov=
es<br>
&gt; the biggest barrier to using RTreeKEM.<br>
&gt; <br>
&gt; To be clear, we&#39;re still doing a some coding &amp; testing to buil=
d<br>
&gt; confidence. And we will also run it past the CFRG / a few more ECC<br>
&gt; experts besides Mike, to make absolutely sure it works as intended.<br=
>
&gt; But at this point we are pretty optimistic already.<br>
&gt; <br>
&gt; The rest of this email contains the details for how RTreeKEM can be ma=
de<br>
&gt; to work with the X* groups.<br>
&gt; <br>
&gt; - Jo=C3=ABl<br>
&gt; <br>
&gt; -----------------------------------------------------------<br>
&gt; <br>
&gt; <br>
&gt; Essentially, all we really need for RTreeKEM is to build &quot;Updatea=
ble<br>
&gt; Public Key Encryption&quot; (UPKE) as defined in [1].<br>
&gt; <br>
&gt; Rather than the construction in [1] which is based additive<br>
&gt; key-homomorphism we can use the following construction based on a<br>
&gt; multiplicative key-homomorphism. (It turns out the later is easier to<=
br>
&gt; implement for X* groups than the former.)<br>
&gt; <br>
&gt; To minimize the diff between current TreeKEM and this new variant of<b=
r>
&gt; RTreeKEM, the new construction is formulated it to use HPKE and HKDF a=
s<br>
&gt; black boxes.<br>
&gt; <br>
&gt; Inherited from Cipher Suite<br>
&gt; ---------------------------<br>
&gt; - sksize =3D # of bits for secret key scalars. (e.g. 32 for X25518)<br=
>
&gt; - order =3D order of prime-order subgroup (e.g. as in RFC 7748)<br>
&gt; - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)<br>
&gt; - Mult(a,b) : Multiplication of secret keys. See below.<br>
&gt; <br>
&gt; <br>
&gt; Multiplication<br>
&gt; --------------<br>
&gt; - NIST curves : Mult(a,b) =3D a*b mod order.<br>
&gt; - X25519 : let Clamp(k) =3D decodeScalar25519(k) as in RFC 7748.<br>
&gt; - X448 : let Clamp(k) =3D decodeScalar448(k) as in RFC 7748.<br>
&gt; <br>
&gt; For both X25519 &amp; X448 use<br>
&gt; Mult(a,b) {<br>
&gt;=C2=A0 =C2=A0c =3D (Clamp(a) - Clamp(b)) mod order<br>
&gt;=C2=A0 =C2=A0if msb(c) =3D 0<br>
&gt;=C2=A0 =C2=A0 =C2=A0c =3D (order - c) mod order<br>
&gt;=C2=A0 =C2=A0return c<br>
&gt; }<br>
&gt; <br>
&gt; <br>
&gt; UPKE Construction (from HPKE &amp; HKDF)<br>
&gt; ------------------------------------<br>
&gt; - UPKE-KeyGen =3D HPKE-KeyGen<br>
&gt; <br>
&gt; - UPKE-Encrypt(pk, m):<br>
&gt;=C2=A0 d&#39;=C2=A0 &lt;-- {0,1}^secpar<br>
&gt;=C2=A0 d=C2=A0 =C2=A0:=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;deri=
ve UPKE delta&quot;)<br>
&gt;=C2=A0 c1, context :=3D HPKE.SetupBaseI(pk, &quot;&quot;)<br>
&gt;=C2=A0 c2=C2=A0 &lt;-- context.Seal(&quot;&quot;, d&#39; || m)<br>
&gt;=C2=A0 pk&#39; :=3D DH(pk, d)<br>
&gt;=C2=A0 return ((c1, c2), pk&#39;)<br>
&gt; <br>
&gt; - UPKE-Decrypt(sk, (c1, c2)):<br>
&gt;=C2=A0 epk, context :=3D HPKE.SetupBaseR(c1, sk, &quot;&quot;)<br>
&gt;=C2=A0 d&#39; || m :=3D context.Open(&quot;&quot;, c2)<br>
&gt;=C2=A0 d :=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive UPKE delt=
a&quot;)<br>
&gt;=C2=A0 sk&#39; :=3D Mult(sk, d)<br>
&gt;=C2=A0 return (m, sk&#39;)<br>
&gt; <br>
&gt; <br>
&gt; References<br>
&gt; ----------<br>
&gt; [1] http:\\<a href=3D"http://ia.cr" rel=3D"noreferrer" target=3D"_blan=
k">ia.cr</a>\2019\1189.<br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; MLS mailing list<br>
&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--00000000000017536f05957306d4--


From nobody Mon Oct 21 15:53:48 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14032120A47 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 15:53:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PT6H4eeGKzfh for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 15:53:44 -0700 (PDT)
Received: from mail-io1-f44.google.com (mail-io1-f44.google.com [209.85.166.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CB67120018 for <mls@ietf.org>; Mon, 21 Oct 2019 15:53:44 -0700 (PDT)
Received: by mail-io1-f44.google.com with SMTP id c11so8940451iom.10 for <mls@ietf.org>; Mon, 21 Oct 2019 15:53:44 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=cuRoBYdpV+yYvKtPQZFa1NKUXPFqRX2j6XuSZlTcJ5g=; b=h9tDTaIKnSn7iYY7YDIXoyTc97YECM0QrpD3+Hq8TsIDh2yenFFI1lFkGbbo4vFgD8 FY0YxZDBxdqr+/m1PIDEsCoSVpjqkah7iwEftpt7jE2OAoU827elBNcn1dOOa8+7asTN Au9f1OslQeoCrM5xMbxqpWtiVnofIUfxK/41jmkTT0G8N3HTGkIs9M1/kKkcOIlg6O2a +RScDRNMxj4rdqJVkPOw6kRM/oLNSlN5exDtPtkifYfhPx+TW7uTvZ03lcgNhEDVyBQv ETpSN9QX5WEdHgsJ1sJOmu7WtRehcLbz9KDJCZzP5wpY2Ty9goBI8CXWpKmjSOkjylLf /ZdA==
X-Gm-Message-State: APjAAAXMSQZWINqrR6d9IjR2K0STHbk1B/mRtwKg+Vyr1V07nNL7SvmR zlINxzi5oACobc3XbgX5ns7RGD3+k0stYxtA/UE=
X-Google-Smtp-Source: APXvYqxAOgC+txfFJhl/x43VjBQ85L9H9j3/D8MPTV8SpVHPJxh0METuZTOVLWmLyGL88EKtyToQlBXtXXBAgucspYA=
X-Received: by 2002:a5e:d90f:: with SMTP id n15mr735681iop.20.1571698423184; Mon, 21 Oct 2019 15:53:43 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
In-Reply-To: <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Mon, 21 Oct 2019 18:53:30 -0400
Message-ID: <CAMvzKsh-Vt3VeF3Jb37j39a=DNs5gFCR67eREAAZbBUvKxxY2A@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Joel Alwen <jalwen@wickr.com>, mls@ietf.org
Content-Type: multipart/alternative; boundary="0000000000003545640595738ed4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/6FXS2mlD_sUgoArKw8pnE4KLMec>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 22:53:47 -0000

--0000000000003545640595738ed4
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Great summary, Karthik!

As I put in the other thread, comparison with the "naive" UPKE (for K=3D100
or less) might be a good idea.

Pros of Naive Scheme:
- more general, uses any PKE
- using stream ciphers to generate K key pairs as needed makes the
efficiency hit noticeably less than a factor of K,
and perhaps closer to a factor of 2 (see below), but unclear a-priori.
- for K>1, offers non-trivial (but still sub-optimal) security enhancement
over basic TreeKEM (K=3D1)

Cons (pros of RTreeKEM):
- Public key storage increases by at least factor of K
- While the naive use increases secret storage and computation by a factor
of K, using stream cipher, after i uses one can only store the
current seed to generate last (K-i) keys. However, K public keys should be
published right away, so we must
lose at least factor of 2 compared to TreeKEM to generate all keys twice
(but possibly factor of K if people update too frequently, so all but
1 of the K keys gets used). So overall efficiency hit between 2 and K,
which might already be comparable or worse than RTreeKEM.
- Still much worse security than RTreeKEM, but possibly more expensive too,
already for small K!

Please let us know if you think this should be explored further.
Yevgeniy

On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan <
karthik.bhargavan@gmail.com> wrote:

> I see. So, here=E2=80=99s how I read the improvements proposed in RTreeKE=
M.
>
> Currently, in TreeKEM (like in ART before it) we rely on each member to
> regularly *send* updates in order to get both PCS and FS for the group
> secrets.
> The informal secrecy guarantees we get are that:
> - (FS) if member A sends an update in epoch N (moving the epoch to N+1),
> and if A gets compromised in epoch N+1, the messages sent in epoch N rema=
in
> secret
> - (PCS) if member A sends an update in epoch N (moving the epoch to N+1),
> and if A was (passively) compromised in epoch N, the messages sent in epo=
ch
> N+1 remain secret
> In other words, each member who sends an update gets local protection
> against compromise, encouraging vulnerable members to keep sending update=
s.
>
> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we
> could do better, at least for FS, if we use one-time decryption keys.
> If each recipient deletes the old decryption key after processing an
> update, then even just by *processing* an update, we get an additional
>  guarantee:
> - (FS=E2=80=99) if member A processes an update in epoch N (moving the ep=
och to
> N+1), and if A gets compromised in epoch N+1, the messages sent in epoch =
N
> remain secret
>
> It is also worth remembering that Signal also has a notion of one-time
> prekeys that work similarly for new messaging sessions.
> Although the following would be a bit ridiculous to use in large dynamic
> groups, here  is a sketch to achieve the receiver FS guarantee without th=
e
> need for new crypto.
> - Every time a member A sends an update, it generates fresh node secrets
> for nodes on the path from A to the root
> - From each node secret, A generates a large number K (=3D 100)
> private-public encryption keypairs and sends the public keys with the
> update.
> - On receiving the update, each member B stores all K public keys for eac=
h
> node in its co-path
> - Each of these public keys can be used only once for sending an update,
> after which the private key is deleted from all recipients.
> - The last public key at each node is not deleted; it can only be replace=
d
> when one of the members under that node sends a new update (with a fresh
> batch of public keys).
>
> As far as I understand, the above scheme can be seen as an (inefficient)
> implementation of UPKE, right?
> Of course, it increases the size of each update by K, and only provides F=
S
> for K updates, after which some member has to send an update.
> Conversely, it does not require any new crypto algorithm. Is this a good
> baseline to compare UPKE schemes against?
>
> If I am mis-reading something, do let me know!
>
> -Karthik
>
>
>
>
>
>
> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com> wrote:
>
> I think the challenge with the hash-forward approach is how to do that
> homomorphically. I.e. what we need are two algorithms; one to refresh
> the PK without knowing the SK (but possibly knowing a secret
> rerandomizer delta if needed) and one to update SK (again possibly using
> delta). So to use a hash-forward approach their must be:
>
> 1) a way to evolve PK forward to PK' and
> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>
> One-wayness is what gives us Forward Secrecy and "compatibility" between
> the two key evolution methods is what allows for asynchronous (i.e. 1
> packet) updates.
>
> Currently we use a secret re-randomizer delta to ensure the SK update
> method is one-way. That is, without the delta you cant "undo" the
> update. But that would break if we (at least naively) used some public
> delta, say hash(ciphertext). So I think this is the challenge that we'd
> have to overcome. Basically, make sure we SK evolution is one-way but
> also compatible the public evolution of PK.
>
>
>
> Now one way sweet way to get all this (and more) would be to use a HIBE.
>
> Initial, PK for a ratchet tree node (i.e. its "identity" since this is a
> HIBE now) is simply the empty vector PK :=3D () while the secret key is
> the master public key for a fresh HIBE instance SK :=3D MSK. We also
> include, as a second component of the nodes PK, the master public key
> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a ciphertex=
t
> C to that node we can do:
>
> PK' :=3D (PK, hash(C)).
> SK' :=3D DeriveHIBEKey(PK, SK).
>
> So simply append hash(C) to the identity for that node and derive the
> corresponding HIBE key.
>
> Ignoring the problems with using HIBE for a second, this is a very cool
> solution. We don't need to send out the updated PK since everyone in the
> group (and even the adversary) can compute it for themselves. We also
> dont need a re-randomize delta as part of the plaintext because we're
> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
> Moreover, HIBE security means that learning SK' doesn't tell you
> anything interesting about SK. In particular, we have forward security.
> (In fact, FS will hold even if hash(C) were chosen *completely*
> adversarially, say, as part of a malicious update in an insider attack!)
>
> Of course, the problem with this solution is that we're using HIBE.
> Worse, with unbounded depth because each new ciphertext sent to a node
> results in going one depth further into the hierarchy. AFAIK all HIBE
> constructions have pretty horrible (read exponential) efficiency as a
> function of their depth. (And I won't mention the state of
> standardization and open implementations for HIBE.)
>
> Now there could be a totally different approach that entirly avoids
> HIBE. But even with this approach there's at least some glimer of hope
> to improve on it because, if we don't wory about insider attacks we can
> assume C is honestly generated which means hash(C) really has a ton of
> entropy. So we dont seem to need the full expresivity HIBE identities
> allow us. Rather we only need HIBE for "random" identities. Still, that
> seems like a pretty slim hope for major efficiency improvement. It also
> doesn't do anything to address the lack of implementations and standards.
>
> - Jo=C3=ABl
>
> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>
> Thanks Yevgeniy,
>
> This helps a lot.
>
> To further my understanding, another question:
>
>  Intuitively, the sender will not only encrypt the message, but also a
> random Delta value. It will change public key using homomorthism by
> multiplying with g^Delta (in specific DH based scheme), while the
> recipient will decrypt Delta (using old secret key), and add it to the
> old secret key to get there new one. So now corrupting (old sk plus
> Delta) will not help decrypting the ciphertext just decepted, emailing
> forward secrecy.
>
>
> I see that in the DH-based scheme, this Delta needs to be private,
> otherwise the adversary can compute sk once it knows sk+Delta.
> But, in general, is it possible to conceive of a UPKE scheme where the
> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric key,
> where this one way hash-forward function does not have to rely on an
> externally chosen secret value?
>
> Best,
> Karthik
>
> This is the high level, hope it makes sense.
> Thanks for your question,
> Yevgeniy
>
> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
> <karthikeyan.bhargavan@inria.fr
> <mailto:karthikeyan.bhargavan@inria.fr <karthikeyan.bhargavan@inria.fr>>>
> wrote:
>
>    Hi Joel,
>
>    This looks very interesting. It is new to me since I was not at
>    the interim.
>    After reading the paper and the slides, I am still a bit fuzzy
>    about what the recipient of an update needs to do.
>
>    For example, for the running example in your slide deck, it would
>    help if I could see:
>    - what secret keys does each leaf need to keep
>    - how do these secrets change when an update from some other node
>    is received.
>    Just working this out for one update is enough.
>
>    I know that this is made precise in the eprint, but it would be
>    faster if you could help us understand it :)
>
>    Best,
>    Karthik
>
> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>
>    <mailto:jalwen@wickr.com <jalwen@wickr.com>>> wrote:
>
>
> <FS-TreeKEM.pdf>
>
>
>    _______________________________________________
>    MLS mailing list
>    MLS@ietf.org <mailto:MLS@ietf.org <MLS@ietf.org>>
>    https://www.ietf.org/mailman/listinfo/mls
>
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000003545640595738ed4
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Great summary, Karthik!<div><br></div><div>As I put in the=
 other thread, comparison with the &quot;naive&quot; UPKE (for K=3D100 or l=
ess) might be a good idea.</div><div><br></div><div>Pros of Naive Scheme:=
=C2=A0</div><div>- more general, uses any PKE</div><div>- using stream ciph=
ers to generate K key pairs as needed makes the efficiency hit noticeably l=
ess than a factor of K,</div><div>and perhaps closer to a factor of 2 (see =
below), but unclear a-priori.</div><div>- for K&gt;1, offers non-trivial (b=
ut still sub-optimal) security enhancement over basic TreeKEM (K=3D1)</div>=
<div><br></div><div>Cons (pros of RTreeKEM):</div><div>- Public key storage=
 increases by at least factor of K</div><div>- While the naive use increase=
s secret storage and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the=C2=A0</div><div>current seed to genera=
te last (K-i) keys. However, K public keys should=C2=A0be published right a=
way, so we must=C2=A0</div><div>lose at least factor of 2 compared to TreeK=
EM to generate all keys twice (but possibly factor of K if people update to=
o frequently, so all but=C2=A0</div><div>1 of the K keys gets used). So ove=
rall efficiency hit between 2 and K, which might already be comparable or w=
orse than RTreeKEM.</div><div>- Still much worse security than RTreeKEM, bu=
t possibly more expensive too, already for small K!</div><div><br></div><di=
v>Please let us know if you think this should be explored further.</div><di=
v>Yevgeniy</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<=
a href=3D"mailto:karthik.bhargavan@gmail.com">karthik.bhargavan@gmail.com</=
a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0p=
x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><d=
iv style=3D"overflow-wrap: break-word;">I see. So, here=E2=80=99s how I rea=
d the improvements proposed in RTreeKEM.<div><br></div><div>Currently, in T=
reeKEM (like in ART before it) we rely on each member to regularly *send* u=
pdates in order to get both PCS and FS for the group secrets.</div><div>The=
 informal secrecy guarantees we get are that:</div><div>- (FS) if member A =
sends an update in epoch N (moving the epoch to N+1), and if A gets comprom=
ised in epoch N+1, the messages sent in epoch N remain secret</div><div>- (=
PCS) if member A sends an update in epoch N (moving the epoch to N+1), and =
if A was (passively) compromised in epoch N, the messages sent in epoch N+1=
 remain secret</div><div>In other words, each member who sends an update ge=
ts local protection against compromise, encouraging vulnerable members to k=
eep sending updates.</div><div><br></div><div>However, as Joel, Sandro, Yev=
geniy, and Yiannis note in their paper, we could do better, at least for FS=
, if we use one-time decryption keys.</div><div>If each recipient deletes t=
he old decryption key after processing an update, then even just by *proces=
sing* an update, we get an additional =C2=A0guarantee:</div><div>- (FS=E2=
=80=99) if member A processes an update in epoch N (moving the epoch to N+1=
), and if A gets compromised in epoch N+1, the messages sent in epoch N rem=
ain secret</div><div><br></div><div>It is also worth remembering that Signa=
l also has a notion of one-time prekeys that work similarly for new messagi=
ng sessions.</div><div>Although the following would be a bit ridiculous to =
use in large dynamic groups, here =C2=A0is a sketch to achieve the receiver=
 FS guarantee without the need for new crypto.</div><div>- Every time a mem=
ber A sends an update, it generates fresh node secrets for nodes on the pat=
h from A to the root</div><div>- From each node secret, A generates a large=
 number K (=3D 100) private-public encryption keypairs and sends the public=
 keys with the update.</div><div>- On receiving the update, each member B s=
tores all K public keys for each node in its co-path</div><div>- Each of th=
ese public keys can be used only once for sending an update, after which th=
e private key is deleted from all recipients.</div><div>- The last public k=
ey at each node is not deleted; it can only be replaced when one of the mem=
bers under that node sends a new update (with a fresh batch of public keys)=
.</div><div><br></div><div>As far as I understand, the above scheme can be =
seen as an (inefficient) implementation of UPKE, right?</div><div>Of course=
, it increases the size of each update by K, and only provides FS for K upd=
ates, after which some member has to send an update.</div><div>Conversely, =
it does not require any new crypto algorithm. Is this a good baseline to co=
mpare UPKE schemes against?</div><div><br></div><div>If I am mis-reading so=
mething, do let me know!</div><div><br></div><div>-Karthik</div><div><br></=
div><div><br></div><div><br></div><div><br></div><div><br></div><div><div><=
br><blockquote type=3D"cite"><div>On 17 Oct 2019, at 17:18, Joel Alwen &lt;=
<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@wickr.com</a>&=
gt; wrote:</div><br><div><span style=3D"font-family:Helvetica;font-size:12p=
x;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spac=
ing:normal;text-align:start;text-indent:0px;text-transform:none;white-space=
:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">I =
think the challenge with the hash-forward approach is how to do that</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none;float:none;display:inline">homomor=
phically. I.e. what we need are two algorithms; one to refresh</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">the PK withou=
t knowing the SK (but possibly knowing a secret</span><br style=3D"font-fam=
ily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><=
span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none;float:none;display:inline">rerandomizer delta if needed=
) and one to update SK (again possibly using</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px;text-decoration:none"><spa=
n style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">delta). So to use a hash-forwar=
d approach their must be:</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">1) a way to evolve PK forward =
to PK&#39; and</span><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">2) a *one-way* method to evolve SK forward to SK&#39; compati=
ble PK&#39;.</span><br style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none;float:none;display:inline">One-wayness is what gives us Forward Secrec=
y and &quot;compatibility&quot; between</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none;float:none;display:inline">the two key evolution methods is wha=
t allows for asynchronous (i.e. 1</span><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none;float:none;display:inline">packet) updates.</span><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">Curren=
tly we use a secret re-randomizer delta to ensure the SK update</span><br s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none;float:none;display:inline">method is on=
e-way. That is, without the delta you cant &quot;undo&quot; the</span><br s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none;float:none;display:inline">update. But =
that would break if we (at least naively) used some public</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">delta, say hash(=
ciphertext). So I think this is the challenge that we&#39;d</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">have to overcome=
. Basically, make sure we SK evolution is one-way but</span><br style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norm=
al;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0p=
x;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none;float:none;display:inline">also compatible the pu=
blic evolution of PK.</span><br style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><br sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">Now one way sweet way to get all this (and more) would be to use a HI=
BE.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:=
12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-s=
pacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none;floa=
t:none;display:inline">Initial, PK for a ratchet tree node (i.e. its &quot;=
identity&quot; since this is a</span><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne;float:none;display:inline">HIBE now) is simply the empty vector PK :=3D =
() while the secret key is</span><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">the master public key for a fresh HIBE instance S=
K :=3D MSK. We also</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">include, as a second component of the nodes PK, the mast=
er public key</span><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none;float:none;dis=
play:inline">PK_0 =3D MPK. To &quot;hash forward&quot; / &quot;re-randomize=
&quot; when sending a ciphertext</span><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none;float:none;display:inline">C to that node we can do:</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:nor=
mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spa=
cing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inli=
ne">PK&#39; :=3D (PK, hash(C)).</span><br style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norm=
al;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0p=
x;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">SK&#39; :=3D DeriveHIBEKey(PK, SK).</span><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">So simply append hash(C) to the identity for that node and deriv=
e the</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text=
-align:start;text-indent:0px;text-transform:none;white-space:normal;word-sp=
acing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">corresponding HIBE key.</span><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none">=
<span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none;float:none;display:inline">Ignoring the problems with =
using HIBE for a second, this is a very cool</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px;text-decoration:none"><spa=
n style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">solution. We don&#39;t need to =
send out the updated PK since everyone in the</span><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">group (and even the adversary)=
 can compute it for themselves. We also</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none;float:none;display:inline">dont need a re-randomize delta as pa=
rt of the plaintext because we&#39;re</span><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:n=
ormal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">using delta :=3D hash(ciphertext) so t=
he plaintext is shorter again.</span><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne;float:none;display:inline">Moreover, HIBE security means that learning S=
K&#39; doesn&#39;t tell you</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">anything interesting about SK. In particular, we=
 have forward security.</span><br style=3D"font-family:Helvetica;font-size:=
12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-s=
pacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none;floa=
t:none;display:inline">(In fact, FS will hold even if hash(C) were chosen *=
completely*</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">adversarially, say, as part of a malicious update in an insider =
attack!)</span><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">Of course, the problem with this solution is th=
at we&#39;re using HIBE.</span><br style=3D"font-family:Helvetica;font-size=
:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-=
spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-s=
pace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fami=
ly:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font=
-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none;flo=
at:none;display:inline">Worse, with unbounded depth because each new cipher=
text sent to a node</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">results in going one depth further into the hierarchy. A=
FAIK all HIBE</span><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none;float:none;dis=
play:inline">constructions have pretty horrible (read exponential) efficien=
cy as a</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">function of their depth. (And I won&#39;t mention the state of</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">standa=
rdization and open implementations for HIBE.)</span><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><br=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px;text-decoration:none;float:none;display:inline">Now there =
could be a totally different approach that entirly avoids</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">HIBE. But even w=
ith this approach there&#39;s at least some glimer of hope</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">to improve on it=
 because, if we don&#39;t wory about insider attacks we can</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">assume C is hone=
stly generated which means hash(C) really has a ton of</span><br style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal=
;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-ali=
gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none;float:none;display:inline">entropy. So we dont s=
eem to need the full expresivity HIBE identities</span><br style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none">=
<span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none;float:none;display:inline">allow us. Rather we only ne=
ed HIBE for &quot;random&quot; identities. Still, that</span><br style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal=
;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-ali=
gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none;float:none;display:inline">seems like a pretty s=
lim hope for major efficiency improvement. It also</span><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">doesn&#39;t do anything t=
o address the lack of implementations and standards.</span><br style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne"><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none;float:none;display:inline">- J=
o=C3=ABl</span><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">On 17/10/2019 16:37, Karthik Bhargavan wrote:</=
span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0=
px;text-decoration:none"><blockquote type=3D"cite" style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none">Thanks Y=
evgeniy,<br><br>This helps a lot.<br><br>To further my understanding, anoth=
er question:<br><br><blockquote type=3D"cite">=C2=A0Intuitively, the sender=
 will not only encrypt the message, but also a<br>random Delta value. It wi=
ll change public key using homomorthism by<br>multiplying with g^Delta (in =
specific DH based scheme), while the<br>recipient will decrypt Delta (using=
 old secret key), and add it to the<br>old secret key to get there new one.=
 So now corrupting (old sk plus<br>Delta) will not help decrypting the ciph=
ertext just decepted, emailing<br>forward secrecy.=C2=A0<br></blockquote><b=
r>I see that in the DH-based scheme, this Delta needs to be private,<br>oth=
erwise the adversary can compute sk once it knows sk+Delta.<br>But, in gene=
ral, is it possible to conceive of a UPKE scheme where the<br>recipient eff=
ectively =E2=80=9Chashes forward=E2=80=9D its symmetric key,<br>where this =
one way hash-forward function does not have to rely on an<br>externally cho=
sen secret value?<br><br>Best,<br>Karthik<br><br><blockquote type=3D"cite">=
This is the high level, hope it makes sense.<br>Thanks for your question,<b=
r>Yevgeniy<br><br>On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan<br>&lt;<a=
 href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank">karthikey=
an.bhargavan@inria.fr</a><br>&lt;<a href=3D"mailto:karthikeyan.bhargavan@in=
ria.fr" target=3D"_blank">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt;=
 wrote:<br><br>=C2=A0=C2=A0=C2=A0Hi Joel,<br><br>=C2=A0=C2=A0=C2=A0This loo=
ks very interesting. It is new to me since I was not at<br>=C2=A0=C2=A0=C2=
=A0the interim.<br>=C2=A0=C2=A0=C2=A0After reading the paper and the slides=
, I am still a bit fuzzy<br>=C2=A0=C2=A0=C2=A0about what the recipient of a=
n update needs to do.<br><br>=C2=A0=C2=A0=C2=A0For example, for the running=
 example in your slide deck, it would<br>=C2=A0=C2=A0=C2=A0help if I could =
see:<br>=C2=A0=C2=A0=C2=A0- what secret keys does each leaf need to keep<br=
>=C2=A0=C2=A0=C2=A0- how do these secrets change when an update from some o=
ther node<br>=C2=A0=C2=A0=C2=A0is received.<br>=C2=A0=C2=A0=C2=A0Just worki=
ng this out for one update is enough.<br><br>=C2=A0=C2=A0=C2=A0I know that =
this is made precise in the eprint, but it would be<br>=C2=A0=C2=A0=C2=A0fa=
ster if you could help us understand it :)<br><br>=C2=A0=C2=A0=C2=A0Best,<b=
r>=C2=A0=C2=A0=C2=A0Karthik<br><br><blockquote type=3D"cite">On 16 Oct 2019=
, at 23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_b=
lank">jalwen@wickr.com</a><br></blockquote>=C2=A0=C2=A0=C2=A0&lt;<a href=3D=
"mailto:jalwen@wickr.com" target=3D"_blank">mailto:jalwen@wickr.com</a>&gt;=
&gt; wrote:<br><blockquote type=3D"cite"><br>&lt;FS-TreeKEM.pdf&gt;<br></bl=
ockquote><br>=C2=A0=C2=A0=C2=A0____________________________________________=
___<br>=C2=A0=C2=A0=C2=A0MLS mailing list<br>=C2=A0=C2=A0=C2=A0<a href=3D"m=
ailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><span>=C2=A0</span>&l=
t;<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">mailto:MLS@ietf.org</a>=
&gt;<br>=C2=A0=C2=A0=C2=A0<a href=3D"https://www.ietf.org/mailman/listinfo/=
mls" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br><br=
></blockquote><br><br>_______________________________________________<br>ML=
S mailing list<br><a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@iet=
f.org</a><br><a href=3D"https://www.ietf.org/mailman/listinfo/mls" target=
=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br><br></blockquo=
te><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none;float:none;display:inline">____=
___________________________________________</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none;float:none;display:inline">MLS mailing list</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><a href=3D"mailto:MLS@ietf.org" style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px" target=3D"_blank">MLS@ietf.org</a><br=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none"><a href=3D"https://www.ietf.org/mailman/listinfo/mls" styl=
e=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-ca=
ps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/mls</a></div></blockquote></=
div><br></div></div>_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--0000000000003545640595738ed4--


From nobody Mon Oct 21 16:08:32 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17ACB120A77 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 16:08:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qiL3CEfJqozf for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 16:08:29 -0700 (PDT)
Received: from mail-il1-f182.google.com (mail-il1-f182.google.com [209.85.166.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ACE8112083B for <mls@ietf.org>; Mon, 21 Oct 2019 16:08:28 -0700 (PDT)
Received: by mail-il1-f182.google.com with SMTP id d83so5162995ilk.7 for <mls@ietf.org>; Mon, 21 Oct 2019 16:08:28 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=y0H5VmJ0GCjXoSvIiWpMuKdOE5X0Ya5MEpHlNfra6wI=; b=KwWMfs+E0oCO7bqNIPAeOEVX5d2+raq7Ctv/lnRHLEXQlxkn1ZbtSvlo3m7J5YAF0t 2KrHSAbgROYLBe2Xux30sbY4SLMCHwbuSapC6w+QYTnD7sxG4IbITmmmd4oc9kzhtghP QjLA3Hh4pijE6OB8oxvUA/SWc+ecT9s3KWlD+sm+nazOegWjSpUz2Y6VNEndCQ1061kV q6VRdqFdjY1QQvP4boyf8uWChzvB9qX6KWmdJoXWwAoEH+q3SR4hK1Dmjph/cjQFa5G5 Q5YtmDADm6TK1JC5OW/kABeWPNQBh7Y+XVuAmfupJmgPBfF6UbPGVdwBaJq+L0oMxtkd BMoA==
X-Gm-Message-State: APjAAAVRv/iwYFCY8Km/s4ady65HD+ZddSDzT3q5YaQS4a+m4XXaPRoU gjyXvkOXIpRUW4eejkH/z/nolKhOy1fFS5aPjqI=
X-Google-Smtp-Source: APXvYqx+mlu5jAOyAvV2PvNcj27aOrZeHq6CkU8zPbTtsmHb4PTNHsz40+ORzold/IViCnNjmL3rVCUvcbJsVNOBpCc=
X-Received: by 2002:a92:d38b:: with SMTP id o11mr13660011ilo.20.1571699307621;  Mon, 21 Oct 2019 16:08:27 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
In-Reply-To: <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Mon, 21 Oct 2019 19:08:16 -0400
Message-ID: <CAMvzKsh+eugid-KHoAT1vJtHzJHadnmxDjeRWszxYxCOPP=+=Q@mail.gmail.com>
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>
Cc: Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000ecb391059573c2f3"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/7ihGgxQDcZJzLf4WXxw_6Z87Qx4>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Oct 2019 23:08:31 -0000

--000000000000ecb391059573c2f3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Brandan.

To re-iterate Joel's answer, in terms of security RTreeKEM is at least as
good (and often strictly better) than TreeKEM in every dimension.
So whatever update policy somebody might apply to TreeKEM, applying the
same policy to RTReeKEM will be equally good and *likely
better* for security.

You correctly observed that RTreeKEM, by being strictly more secure, allows
for "lazier" update policies which nobody would ever consider
in the basic TreeKEM. And this leads to a potential danger of somebody
using a policy which is "too lazy" even for the more secure scheme.
But I think it is unfair to say that one would prefer a less secure scheme
because it is less likely to be mis-used.

So, in my opinion, the one and only consideration should be if efficiency
cost and slight loss of generality (as of now) justifies the gain in
security.  I hope the answer is yes, but would love to hear other opinions.

Thank you for voicing this though.
Yevgeniy

On Fri, Oct 18, 2019 at 1:49 PM Brendan McMillion <brendan=3D
40cloudflare.com@dmarc.ietf.org> wrote:

> Hey Joel
>
> This is a pretty subtle topic so I want to state the assumption that my
> conclusion is based on upfront: RTreeKEM achieves FS and PCS after a sing=
le
> Update (and all users come online and process the update), while normal
> TreeKEM requires everyone in the group to Update before achieving the sam=
e
> security guarantee.
>
> This actually makes TreeKEM more attractive to me because it encourages
> implementors to keep the Update frequency high, and it provides an explic=
it
> signal to the group that everyone has processed every update. With TreeKE=
M,
> the policy would be =E2=80=9Ceverybody Updates at least once per day=E2=
=80=9D. But with
> RTreeKEM, the equivalent policy is =E2=80=9Cat least one person Updates e=
very day=E2=80=9D
> which isn=E2=80=99t as strong, because you don=E2=80=99t know whether or =
not everybody came
> online that day and processed the one Update.
>
> And if you have a high Update frequency, I don=E2=80=99t think the securi=
ty
> properties of TreeKEM and RTreeKEM are materially different. But RTreeKEM
> has costs like being harder to implement, and restricting what algorithms
> we can use.
>
> It=E2=80=99s on this basis that I=E2=80=99m opposed to including RTreeKEM=
 in the spec.
>
> On Oct 17, 2019, at 8:18 AM, Joel Alwen <jalwen@wickr.com> wrote:
>
> I think the challenge with the hash-forward approach is how to do that
> homomorphically. I.e. what we need are two algorithms; one to refresh
> the PK without knowing the SK (but possibly knowing a secret
> rerandomizer delta if needed) and one to update SK (again possibly using
> delta). So to use a hash-forward approach their must be:
>
> 1) a way to evolve PK forward to PK' and
> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>
> One-wayness is what gives us Forward Secrecy and "compatibility" between
> the two key evolution methods is what allows for asynchronous (i.e. 1
> packet) updates.
>
> Currently we use a secret re-randomizer delta to ensure the SK update
> method is one-way. That is, without the delta you cant "undo" the
> update. But that would break if we (at least naively) used some public
> delta, say hash(ciphertext). So I think this is the challenge that we'd
> have to overcome. Basically, make sure we SK evolution is one-way but
> also compatible the public evolution of PK.
>
>
>
> Now one way sweet way to get all this (and more) would be to use a HIBE.
>
> Initial, PK for a ratchet tree node (i.e. its "identity" since this is a
> HIBE now) is simply the empty vector PK :=3D () while the secret key is
> the master public key for a fresh HIBE instance SK :=3D MSK. We also
> include, as a second component of the nodes PK, the master public key
> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a ciphertex=
t
> C to that node we can do:
>
> PK' :=3D (PK, hash(C)).
> SK' :=3D DeriveHIBEKey(PK, SK).
>
> So simply append hash(C) to the identity for that node and derive the
> corresponding HIBE key.
>
> Ignoring the problems with using HIBE for a second, this is a very cool
> solution. We don't need to send out the updated PK since everyone in the
> group (and even the adversary) can compute it for themselves. We also
> dont need a re-randomize delta as part of the plaintext because we're
> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
> Moreover, HIBE security means that learning SK' doesn't tell you
> anything interesting about SK. In particular, we have forward security.
> (In fact, FS will hold even if hash(C) were chosen *completely*
> adversarially, say, as part of a malicious update in an insider attack!)
>
> Of course, the problem with this solution is that we're using HIBE.
> Worse, with unbounded depth because each new ciphertext sent to a node
> results in going one depth further into the hierarchy. AFAIK all HIBE
> constructions have pretty horrible (read exponential) efficiency as a
> function of their depth. (And I won't mention the state of
> standardization and open implementations for HIBE.)
>
> Now there could be a totally different approach that entirly avoids
> HIBE. But even with this approach there's at least some glimer of hope
> to improve on it because, if we don't wory about insider attacks we can
> assume C is honestly generated which means hash(C) really has a ton of
> entropy. So we dont seem to need the full expresivity HIBE identities
> allow us. Rather we only need HIBE for "random" identities. Still, that
> seems like a pretty slim hope for major efficiency improvement. It also
> doesn't do anything to address the lack of implementations and standards.
>
> - Jo=C3=ABl
>
> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>
> Thanks Yevgeniy,
>
> This helps a lot.
>
> To further my understanding, another question:
>
>  Intuitively, the sender will not only encrypt the message, but also a
> random Delta value. It will change public key using homomorthism by
> multiplying with g^Delta (in specific DH based scheme), while the
> recipient will decrypt Delta (using old secret key), and add it to the
> old secret key to get there new one. So now corrupting (old sk plus
> Delta) will not help decrypting the ciphertext just decepted, emailing
> forward secrecy.
>
>
> I see that in the DH-based scheme, this Delta needs to be private,
> otherwise the adversary can compute sk once it knows sk+Delta.
> But, in general, is it possible to conceive of a UPKE scheme where the
> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric key,
> where this one way hash-forward function does not have to rely on an
> externally chosen secret value?
>
> Best,
> Karthik
>
> This is the high level, hope it makes sense.
> Thanks for your question,
> Yevgeniy
>
> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
> <karthikeyan.bhargavan@inria.fr
> <mailto:karthikeyan.bhargavan@inria.fr <karthikeyan.bhargavan@inria.fr>>>
> wrote:
>
>    Hi Joel,
>
>    This looks very interesting. It is new to me since I was not at
>    the interim.
>    After reading the paper and the slides, I am still a bit fuzzy
>    about what the recipient of an update needs to do.
>
>    For example, for the running example in your slide deck, it would
>    help if I could see:
>    - what secret keys does each leaf need to keep
>    - how do these secrets change when an update from some other node
>    is received.
>    Just working this out for one update is enough.
>
>    I know that this is made precise in the eprint, but it would be
>    faster if you could help us understand it :)
>
>    Best,
>    Karthik
>
> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>
>    <mailto:jalwen@wickr.com <jalwen@wickr.com>>> wrote:
>
>
> <FS-TreeKEM.pdf>
>
>
>    _______________________________________________
>    MLS mailing list
>    MLS@ietf.org <mailto:MLS@ietf.org <MLS@ietf.org>>
>    https://www.ietf.org/mailman/listinfo/mls
>
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000ecb391059573c2f3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Brandan.<div><br></div><div>To re-iterate Joel&#39;s an=
swer, in terms of security RTreeKEM is at least as good (and often strictly=
 better) than TreeKEM in every dimension.=C2=A0</div><div>So whatever updat=
e policy somebody might apply to TreeKEM, applying the same policy to RTRee=
KEM will be equally good and *likely</div><div>better* for security.</div><=
div><br></div><div>You correctly observed that RTreeKEM, by being strictly =
more secure, allows for &quot;lazier&quot; update policies which nobody wou=
ld ever consider</div><div>in the basic TreeKEM. And this leads to a potent=
ial danger of somebody using a policy which is &quot;too lazy&quot; even fo=
r the more secure scheme.=C2=A0</div><div>But I think it is unfair to say t=
hat one would prefer a less secure scheme because it is less likely to be m=
is-used.=C2=A0</div><div><br></div><div>So, in my opinion, the one and only=
 consideration should be if efficiency cost and slight loss of generality (=
as of now) justifies the gain in</div><div>security.=C2=A0 I hope the answe=
r is yes, but would love to hear other opinions.</div><div><br></div><div>T=
hank you for voicing this though.</div><div>Yevgeniy</div></div><br><div cl=
ass=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Oct 18, 2=
019 at 1:49 PM Brendan McMillion &lt;brendan=3D<a href=3D"mailto:40cloudfla=
re.com@dmarc.ietf.org" target=3D"_blank">40cloudflare.com@dmarc.ietf.org</a=
>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px=
 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><di=
v>Hey Joel<div><br></div><div>This is a pretty subtle topic so I want to st=
ate the assumption that my conclusion is based on upfront: RTreeKEM achieve=
s FS and PCS after a single Update (and all users come online and process t=
he update), while normal TreeKEM requires everyone in the group to Update b=
efore achieving the same security guarantee.</div><div><br></div><div>This =
actually makes TreeKEM more attractive to me because it encourages implemen=
tors to keep the Update frequency high, and it provides an explicit signal =
to the group that everyone has processed every update. With TreeKEM, the po=
licy would be =E2=80=9Ceverybody Updates at least once per day=E2=80=9D. Bu=
t with RTreeKEM, the equivalent policy is =E2=80=9Cat least one person Upda=
tes every day=E2=80=9D which isn=E2=80=99t as strong, because you don=E2=80=
=99t know whether or not everybody came online that day and processed the o=
ne Update.</div><div><br></div><div>And if you have a high Update frequency=
, I don=E2=80=99t think the security properties of TreeKEM and RTreeKEM are=
 materially different. But RTreeKEM has costs like being harder to implemen=
t, and restricting what algorithms we can use.</div><div><br></div><div>It=
=E2=80=99s on this basis that I=E2=80=99m opposed to including RTreeKEM in =
the spec.<br><div><br><blockquote type=3D"cite"><div>On Oct 17, 2019, at 8:=
18 AM, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank"=
>jalwen@wickr.com</a>&gt; wrote:</div><br><div><span style=3D"font-family:H=
elvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:n=
one;display:inline">I think the challenge with the hash-forward approach is=
 how to do that</span><br style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:n=
ormal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;d=
isplay:inline">homomorphically. I.e. what we need are two algorithms; one t=
o refresh</span><br style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none;float:none;display=
:inline">the PK without knowing the SK (but possibly knowing a secret</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">rerand=
omizer delta if needed) and one to update SK (again possibly using</span><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">delta). S=
o to use a hash-forward approach their must be:</span><br style=3D"font-fam=
ily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><=
br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none;float:none;display:inline">1) a way=
 to evolve PK forward to PK&#39; and</span><br style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">2) a *one-way* method to evolve SK for=
ward to SK&#39; compatible PK&#39;.</span><br style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none;float:none;display:inline">One-wayness is what =
gives us Forward Secrecy and &quot;compatibility&quot; between</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">the two key e=
volution methods is what allows for asynchronous (i.e. 1</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:n=
ormal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent=
:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoratio=
n:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none;float:none;display:inline">packet) updates.</s=
pan><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none=
;display:inline">Currently we use a secret re-randomizer delta to ensure th=
e SK update</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">method is one-way. That is, without the delta you cant &quot;und=
o&quot; the</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">update. But that would break if we (at least naively) used some =
public</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">delta, say hash(ciphertext). So I think this is the challenge that we=
&#39;d</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">have to overcome. Basically, make sure we SK evolution is one-way but=
</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">=
also compatible the public evolution of PK.</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none"><br s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">Now one way sweet way to get all this (and more=
) would be to use a HIBE.</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">Initial, PK for a ratchet tree=
 node (i.e. its &quot;identity&quot; since this is a</span><br style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align=
:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:=
0px;text-decoration:none;float:none;display:inline">HIBE now) is simply the=
 empty vector PK :=3D () while the secret key is</span><br style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none">=
<span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none;float:none;display:inline">the master public key for a=
 fresh HIBE instance SK :=3D MSK. We also</span><br style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><span s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none;float:none;display:inline">include, as a second component of =
the nodes PK, the master public key</span><br style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">PK_0 =3D MPK. To &quot;hash forward&qu=
ot; / &quot;re-randomize&quot; when sending a ciphertext</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:n=
ormal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent=
:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoratio=
n:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none;float:none;display:inline">C to that node we c=
an do:</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">PK&#39; :=3D (PK, hash(C)).</span><br style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norm=
al;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0p=
x;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none;float:none;display:inline">SK&#39; :=3D DeriveHIB=
EKey(PK, SK).</span><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none;float:none;display:inline">So simply append hash(C) to the identity f=
or that node and derive the</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">corresponding HIBE key.</span><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none;float:none;display:inline">Ignor=
ing the problems with using HIBE for a second, this is a very cool</span><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">solution.=
 We don&#39;t need to send out the updated PK since everyone in the</span><=
br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none;float:none;display:inline">group (a=
nd even the adversary) can compute it for themselves. We also</span><br sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none;float:none;display:inline">dont need a re=
-randomize delta as part of the plaintext because we&#39;re</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">using delta :=3D=
 hash(ciphertext) so the plaintext is shorter again.</span><br style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align=
:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:=
0px;text-decoration:none;float:none;display:inline">Moreover, HIBE security=
 means that learning SK&#39; doesn&#39;t tell you</span><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none;float:none;display:inline">anything interesting about=
 SK. In particular, we have forward security.</span><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">(In fact, FS will hold even if=
 hash(C) were chosen *completely*</span><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none;float:none;display:inline">adversarially, say, as part of a malicious=
 update in an insider attack!)</span><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">Of course, the problem wi=
th this solution is that we&#39;re using HIBE.</span><br style=3D"font-fami=
ly:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font=
-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><s=
pan style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none;float:none;display:inline">Worse, with unbounded depth b=
ecause each new ciphertext sent to a node</span><br style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><span s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none;float:none;display:inline">results in going one depth further=
 into the hierarchy. AFAIK all HIBE</span><br style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">constructions have pretty horrible (re=
ad exponential) efficiency as a</span><br style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norm=
al;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0p=
x;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">function of their depth. (And I won&#39;t me=
ntion the state of</span><br style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:non=
e;display:inline">standardization and open implementations for HIBE.)</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">Now there could be a totally different approach that entirly =
avoids</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">HIBE. But even with this approach there&#39;s at least some glimer of=
 hope</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text=
-align:start;text-indent:0px;text-transform:none;white-space:normal;word-sp=
acing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">to improve on it because, if we don&#39;t wory about insider attacks w=
e can</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text=
-align:start;text-indent:0px;text-transform:none;white-space:normal;word-sp=
acing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">assume C is honestly generated which means hash(C) really has a ton of=
</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">=
entropy. So we dont seem to need the full expresivity HIBE identities</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">allow =
us. Rather we only need HIBE for &quot;random&quot; identities. Still, that=
</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">=
seems like a pretty slim hope for major efficiency improvement. It also</sp=
an><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none;float:none;display:inline">does=
n&#39;t do anything to address the lack of implementations and standards.</=
span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0=
px;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:non=
e;display:inline">- Jo=C3=ABl</span><br style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none;float:none;display:inline">On 17/10/2019 16:37, Karth=
ik Bhargavan wrote:</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><blockquote type=3D"cite" sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none">Thanks Yevgeniy,<br><br>This helps a lot.<br><br>To further my=
 understanding, another question:<br><br><blockquote type=3D"cite">=C2=A0In=
tuitively, the sender will not only encrypt the message, but also a<br>rand=
om Delta value. It will change public key using homomorthism by<br>multiply=
ing with g^Delta (in specific DH based scheme), while the<br>recipient will=
 decrypt Delta (using old secret key), and add it to the<br>old secret key =
to get there new one. So now corrupting (old sk plus<br>Delta) will not hel=
p decrypting the ciphertext just decepted, emailing<br>forward secrecy.=C2=
=A0<br></blockquote><br>I see that in the DH-based scheme, this Delta needs=
 to be private,<br>otherwise the adversary can compute sk once it knows sk+=
Delta.<br>But, in general, is it possible to conceive of a UPKE scheme wher=
e the<br>recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetr=
ic key,<br>where this one way hash-forward function does not have to rely o=
n an<br>externally chosen secret value?<br><br>Best,<br>Karthik<br><br><blo=
ckquote type=3D"cite">This is the high level, hope it makes sense.<br>Thank=
s for your question,<br>Yevgeniy<br><br>On Thu, Oct 17, 2019, 1:43 AM Karth=
ik Bhargavan<br>&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.fr" targe=
t=3D"_blank">karthikeyan.bhargavan@inria.fr</a><br>&lt;<a href=3D"mailto:ka=
rthikeyan.bhargavan@inria.fr" target=3D"_blank">mailto:karthikeyan.bhargava=
n@inria.fr</a>&gt;&gt; wrote:<br><br>=C2=A0=C2=A0=C2=A0Hi Joel,<br><br>=C2=
=A0=C2=A0=C2=A0This looks very interesting. It is new to me since I was not=
 at<br>=C2=A0=C2=A0=C2=A0the interim.<br>=C2=A0=C2=A0=C2=A0After reading th=
e paper and the slides, I am still a bit fuzzy<br>=C2=A0=C2=A0=C2=A0about w=
hat the recipient of an update needs to do.<br><br>=C2=A0=C2=A0=C2=A0For ex=
ample, for the running example in your slide deck, it would<br>=C2=A0=C2=A0=
=C2=A0help if I could see:<br>=C2=A0=C2=A0=C2=A0- what secret keys does eac=
h leaf need to keep<br>=C2=A0=C2=A0=C2=A0- how do these secrets change when=
 an update from some other node<br>=C2=A0=C2=A0=C2=A0is received.<br>=C2=A0=
=C2=A0=C2=A0Just working this out for one update is enough.<br><br>=C2=A0=
=C2=A0=C2=A0I know that this is made precise in the eprint, but it would be=
<br>=C2=A0=C2=A0=C2=A0faster if you could help us understand it :)<br><br>=
=C2=A0=C2=A0=C2=A0Best,<br>=C2=A0=C2=A0=C2=A0Karthik<br><br><blockquote typ=
e=3D"cite">On 16 Oct 2019, at 23:51, Joel Alwen &lt;<a href=3D"mailto:jalwe=
n@wickr.com" target=3D"_blank">jalwen@wickr.com</a><br></blockquote>=C2=A0=
=C2=A0=C2=A0&lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">mailt=
o:jalwen@wickr.com</a>&gt;&gt; wrote:<br><blockquote type=3D"cite"><br>&lt;=
FS-TreeKEM.pdf&gt;<br></blockquote><br>=C2=A0=C2=A0=C2=A0__________________=
_____________________________<br>=C2=A0=C2=A0=C2=A0MLS mailing list<br>=C2=
=A0=C2=A0=C2=A0<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.o=
rg</a><span>=C2=A0</span>&lt;<a href=3D"mailto:MLS@ietf.org" target=3D"_bla=
nk">mailto:MLS@ietf.org</a>&gt;<br>=C2=A0=C2=A0=C2=A0<a href=3D"https://www=
.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://www.ietf.org/mail=
man/listinfo/mls</a><br><br></blockquote><br><br>__________________________=
_____________________<br>MLS mailing list<br><a href=3D"mailto:MLS@ietf.org=
" target=3D"_blank">MLS@ietf.org</a><br><a href=3D"https://www.ietf.org/mai=
lman/listinfo/mls" target=3D"_blank">https://www.ietf.org/mailman/listinfo/=
mls</a><br><br></blockquote><br style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:=
none;display:inline">_______________________________________________</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none;float:none;display:inline">MLS mai=
ling list</span><br style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none"><a href=3D"mailto:MLS@ietf.org" style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px" target=3D"=
_blank">MLS@ietf.org</a><br style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none"><a href=3D"https://www.ietf.org=
/mailman/listinfo/mls" style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px" target=3D"_blank">https://www.ietf.org/mailman/listinfo/m=
ls</a></div></blockquote></div><br></div></div>____________________________=
___________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--000000000000ecb391059573c2f3--


From nobody Mon Oct 21 18:09:11 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 662F7120AB5 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 18:09:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a7zYyjbTOldD for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 18:09:07 -0700 (PDT)
Received: from mail-qt1-x829.google.com (mail-qt1-x829.google.com [IPv6:2607:f8b0:4864:20::829]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 10E1D120AB1 for <mls@ietf.org>; Mon, 21 Oct 2019 18:09:07 -0700 (PDT)
Received: by mail-qt1-x829.google.com with SMTP id g50so10092754qtb.4 for <mls@ietf.org>; Mon, 21 Oct 2019 18:09:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=WR68MsIgxlG4tEeDCvv9BpwT/tfzMb9jXJqN7P40jUI=; b=bfSHJiFxYv7Lw24J9MBqEgB0PNYgirfOWq7t7Mtz7LtCoZMmTDgXFcAT4owW2Fe6Uy Bo0Pbsb0SdhQXpEBj5fssju+Bqf5wquVRLWUWB3hiEfuSqFcghWGAQtcI27il7NsLvXk FKA6Misa2uwyNND8qpEnz68eeu0r0SgIi7IhA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=WR68MsIgxlG4tEeDCvv9BpwT/tfzMb9jXJqN7P40jUI=; b=YsDP1+JG8DlyhK087b3G/ErqoeV+TrKVA7X23pwHLnRou0d/9aLEyQWRJhnhef6Wm2 r5RAhB9Dh2qIUxC8sSZsR6D4iRLL6ZngVmweQbF3GOhm7DaXVBirkzFHemkS8l8udSu4 YpUJ5uyCuI3ZXGmv45HFZbmZkge6iub+F+PzskP4/PwBAoqGl3pbYBN5is7uhwsd9c0Y KVHwhJRwlKpAmij9mzqbZ/X8dHw3yAMvgKm6bm+b60q8g0ZfLLiIwDxIwUlZAaQKjBhd BoZsrg1Zu8yXgzmsiyAPQ4sWstVkiynA6hhDkBUnJgBzCz1jd/UdVw9pmuDv+pDcbu6b BXaA==
X-Gm-Message-State: APjAAAUX9e31EB8yTArnJcn8OxI44CjD7/unAYskVJar+AVpwruSIves 2ZjGmkC8PNdysR9D7y3PehLHYv9r16wpuVXnRW1LT3VPxA8D1w==
X-Google-Smtp-Source: APXvYqxR4pxq6lTPiISKznnMIxo83MUiNdxM7+y2mCnCutRwWMYhmgMVIwPGzb0jqjiHDeYfmDE+h0cAKzrGr0QjNPY=
X-Received: by 2002:ad4:538b:: with SMTP id i11mr569732qvv.211.1571706545759;  Mon, 21 Oct 2019 18:09:05 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com>
In-Reply-To: <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Mon, 21 Oct 2019 18:08:53 -0700
Message-ID: <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com>
To: Joel Alwen <jalwen@wickr.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000005a2a4c0595757267"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/BAPec5_6ol_fgbASuiXLr0nL-QE>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 01:09:09 -0000

--0000000000005a2a4c0595757267
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

>
> If, on the other hand, the concern is the lack of an explicit signal
> wouldnt it be enough to have parties send out ACK msgs to the group when
> they process an update? That would consume far less bandwidth (and
> computation) than doing a full update alla TreeKEM.
>

Right, my concern is the lack of an explicit signal. I'm taking the
perspective of an individual user thinking, "What policy do I need to
enforce, to ensure that after X amount of time without compromise, my group
is back to a secure state?" And the answer to that question is the same
whether you're using TreeKEM or RTreeKEM: you need to require everybody to
Update, and you need to Remove the users who haven't Updated. RTreeKEM
might get to a secure state faster but it's not that much faster, and it
doesn't change the promises we can make to our users. That's what I meant
when I said the security of the two schemes isn't materially different.

Having everybody send an ACK requires either quadratic bandwidth or
trusting the server, which isn't worth it imo.

On Mon, Oct 21, 2019 at 2:50 PM Joel Alwen <jalwen@wickr.com> wrote:

> Hey Brendan,
>
> Thanks for taking the time to look at this stuff and answer! :-)
>
> > This actually makes TreeKEM more attractive to me because it encourages
> > implementors to keep the Update frequency high,
>
> If one can afford high update frequency then that's great. It helps
> RTreeKEM too by the way. The longer between updates the less PCS we have
> and the longer the corruption windows. So there's still plenty of
> incentive in RTreeKEM to update as often as you can.
>
> But more generally, to me a primary design goal for MLS is to get as
> much security for as little bandwidth as possible. So I'm particularly
> interested in the protocols behavior when there *isn't* that much
> bandwidth to spare for frequent updates.
>
> > and it provides an
> > explicit signal to the group that everyone has processed every update.
> > With TreeKEM, the policy would be =E2=80=9Ceverybody Updates at least o=
nce per
> > day=E2=80=9D. But with RTreeKEM, the equivalent policy is =E2=80=9Cat l=
east one person
> > Updates every day=E2=80=9D which isn=E2=80=99t as strong, because you d=
on=E2=80=99t know whether
> > or not everybody came online that day and processed the one Update.
>
> If your not coming online then I'm not sure I see the difference between
> using TreeKEM or RTreeKEM. I mean, either way your not refreshing any
> key material so your preventing the group from achieving FS. Moreover,
> coming online to send a daily update TreeKEM means already requires
> processing other peoples updates first.
>
> If, on the other hand, the concern is the lack of an explicit signal
> wouldnt it be enough to have parties send out ACK msgs to the group when
> they process an update? That would consume far less bandwidth (and
> computation) than doing a full update alla TreeKEM.
>
> > But RTreeKEM has costs like being harder to implement, and restricting
> what
> > algorithms we can use.
>
> FYI: In the mean time it looks like we may have found a way to make
> RTreeKEM work with X25519/X448 groups. (See the email I just sent to the
> group for more on this.) Harder to implement I do agree with. Albeit IMO
> the difference is rather marginal compared to how much code is needed to
> implement the rest of MLS, not to mention all the surrounding
> infrastructure; e.g. the servers, the rest of the client, UX etc need to
> actually deploy MLS. At the end of the day, I don't think we're talking
> about much more than a few lines of code wrapping HPKE. But I might be
> wrong here.
>
> > It=E2=80=99s on this basis that I=E2=80=99m opposed to including RTreeK=
EM in the spec.
>
> Fair enough! :-)
>
> - Jo=C3=ABl
>

--0000000000005a2a4c0595757267
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=
=3D"ltr">
If, on the other hand, the concern is the lack of an explicit signal<br>
wouldnt it be enough to have parties send out ACK msgs to the group when<br=
>
they process an update? That would consume far less bandwidth (and<br>
computation) than doing a full update alla TreeKEM.

</div></blockquote><div><br></div><div>Right, my concern is the lack of an =
explicit signal. I&#39;m taking the perspective of an individual user think=
ing, &quot;What policy do I need to enforce, to ensure that after X amount =
of time without compromise, my group is back to a secure state?&quot; And t=
he answer to that question is the same whether you&#39;re using TreeKEM or =
RTreeKEM: you need to require everybody to Update, and you need to Remove t=
he users who haven&#39;t Updated. RTreeKEM might get to a secure state fast=
er but it&#39;s not that much faster, and it doesn&#39;t change the promise=
s we can make to our users. That&#39;s what I meant when I said the securit=
y of the two schemes isn&#39;t materially different.</div><div><br></div><d=
iv>Having everybody send an ACK requires either quadratic bandwidth or trus=
ting the server, which isn&#39;t worth it imo.<br></div><br><div class=3D"g=
mail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct 21, 2019 at 2=
:50 PM Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com">jalwen@wickr.com<=
/a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">H=
ey Brendan,<br>
<br>
Thanks for taking the time to look at this stuff and answer! :-)<br>
<br>
&gt; This actually makes TreeKEM more attractive to me because it encourage=
s<br>
&gt; implementors to keep the Update frequency high, <br>
<br>
If one can afford high update frequency then that&#39;s great. It helps<br>
RTreeKEM too by the way. The longer between updates the less PCS we have<br=
>
and the longer the corruption windows. So there&#39;s still plenty of<br>
incentive in RTreeKEM to update as often as you can.<br>
<br>
But more generally, to me a primary design goal for MLS is to get as<br>
much security for as little bandwidth as possible. So I&#39;m particularly<=
br>
interested in the protocols behavior when there *isn&#39;t* that much<br>
bandwidth to spare for frequent updates.<br>
<br>
&gt; and it provides an<br>
&gt; explicit signal to the group that everyone has processed every update.=
<br>
&gt; With TreeKEM, the policy would be =E2=80=9Ceverybody Updates at least =
once per<br>
&gt; day=E2=80=9D. But with RTreeKEM, the equivalent policy is =E2=80=9Cat =
least one person<br>
&gt; Updates every day=E2=80=9D which isn=E2=80=99t as strong, because you =
don=E2=80=99t know whether<br>
&gt; or not everybody came online that day and processed the one Update.<br=
>
<br>
If your not coming online then I&#39;m not sure I see the difference betwee=
n<br>
using TreeKEM or RTreeKEM. I mean, either way your not refreshing any<br>
key material so your preventing the group from achieving FS. Moreover,<br>
coming online to send a daily update TreeKEM means already requires<br>
processing other peoples updates first.<br>
<br>
If, on the other hand, the concern is the lack of an explicit signal<br>
wouldnt it be enough to have parties send out ACK msgs to the group when<br=
>
they process an update? That would consume far less bandwidth (and<br>
computation) than doing a full update alla TreeKEM.<br>
<br>
&gt; But RTreeKEM has costs like being harder to implement, and restricting=
 what<br>
&gt; algorithms we can use.<br>
<br>
FYI: In the mean time it looks like we may have found a way to make<br>
RTreeKEM work with X25519/X448 groups. (See the email I just sent to the<br=
>
group for more on this.) Harder to implement I do agree with. Albeit IMO<br=
>
the difference is rather marginal compared to how much code is needed to<br=
>
implement the rest of MLS, not to mention all the surrounding<br>
infrastructure; e.g. the servers, the rest of the client, UX etc need to<br=
>
actually deploy MLS. At the end of the day, I don&#39;t think we&#39;re tal=
king<br>
about much more than a few lines of code wrapping HPKE. But I might be<br>
wrong here.<br>
<br>
&gt; It=E2=80=99s on this basis that I=E2=80=99m opposed to including RTree=
KEM in the spec.<br>
<br>
Fair enough! :-)<br>
<br>
- Jo=C3=ABl<br>
</blockquote></div></div>

--0000000000005a2a4c0595757267--


From nobody Mon Oct 21 21:41:32 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C42D912008C for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 21:41:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level: 
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GGhjrrKOCVSH for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 21:41:28 -0700 (PDT)
Received: from mail-ot1-x32c.google.com (mail-ot1-x32c.google.com [IPv6:2607:f8b0:4864:20::32c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B9B0120086 for <mls@ietf.org>; Mon, 21 Oct 2019 21:41:28 -0700 (PDT)
Received: by mail-ot1-x32c.google.com with SMTP id 53so1428008otv.4 for <mls@ietf.org>; Mon, 21 Oct 2019 21:41:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=HDb/O27LGAxr+5Q9NggfCk2xEgdA4HiI4D8Oie9/Phg=; b=eKCwtGQzKin7DzzopU8Ga4JqvLqGLKmXJZrc2HA0XhyPj3DSzAEBBs2YyHw3YBUHbD I+qnIuxIVdLl4s0djBDS7CLnb1UR8jVfPIPE23tsCaq2IOBUI1frg2QQbMV80jaZ0uJ5 eP71GthtzP7XYw67bg21VVb5Gr4Ab/G1WUg08Sv9APcmhj1AF7xUVZusYiA8Xy6J/P6S UWPmGn+lrdiJkfuX0dNmkqYIQ7Vl266FC6ktpWY3iBIfY243GqKc47NxJuPCx+5OjJrj HGwrsB00qVuPkoDp9MQZlA2VIvTsOi3iuc4Cg9bRj0a81HKCVlSlsPByv/s1NFpCjl5L zSaw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=HDb/O27LGAxr+5Q9NggfCk2xEgdA4HiI4D8Oie9/Phg=; b=M27S/wo3hhS/fYwm0CdDNTTAg6MhR8m3rR34vA20jn4avO4ahGe/0s/5bJcEPKOQbK e14T6iD31ucZWJPvzVrDcevcbrQN10ECXc1d5nGyF2bKWIVI6JICy6k+7kRVcjJkAvFt jetWy21eRZ14vBX3LcrJ8genZgAaSzNs7Mt3RdvvuhDYnvX/Q+1XASBJUKWGeZ7ZKoP+ 6bSj3xAiZbNp8eNLUj9hrN4x7Rcn+S51PSMettJsPXgM2IcSi15ZUdTQfSiRadtae2/4 ich4AgoXjNknOYE/vI7ataVdkuX7hyId0gEx+eE8OiqL7fM/WiRpHQTE6uIMvHQipenl 8lfQ==
X-Gm-Message-State: APjAAAXvN90+0BXcnTZBEdYsH7qPEn0pwrQjSzLkgsc9DWrXwhAGZscl PzbGJ9S1Ss7PeeINlw8V/Gysl1l69fOwJLK7qs5WGY69rHo=
X-Google-Smtp-Source: APXvYqwzNTFfQw1ud08KV3gh1WADEyVajl9SmfNZC8sxZwY/ZEe1fiQlDT0m9lz+bvg2YuddIz27Af8fSbpH1/GJUs4=
X-Received: by 2002:a05:6830:13d8:: with SMTP id e24mr1057272otq.42.1571719287646;  Mon, 21 Oct 2019 21:41:27 -0700 (PDT)
MIME-Version: 1.0
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
In-Reply-To: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Tue, 22 Oct 2019 00:41:05 -0400
Message-ID: <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
To: Joel Alwen <jalwen@wickr.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d3bfbf0595786984"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/K7HcifXj0Z69LLFh2YyaKptudRk>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 04:41:31 -0000

--000000000000d3bfbf0595786984
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

FWIW, I tried to update this and it appears not to work, either in the
sense of pk' =3D pk(sk'), or in the sense of pk' and sk' producing equivale=
nt
DH results.

https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a90ca

It seems odd to me that the *Mult* functions computes Clamp(a) - Clamp(b),
instead of multiplying ... well anything.  But even when I changed the Sub
to a Mul in my test code, things still didn't work.

The problem I observed in the CFRG thread on this long ago is that there
are X25519 DH outputs that are not valid public keys, which I think implies
that you can't have any homomorphism in which the DH function is the public
transformation.  Maybe that's what we're running into here?

Also possible that I'm just missing something :)

On Mon, Oct 21, 2019 at 5:21 PM Joel Alwen <jalwen@wickr.com> wrote:

> Hey,
>
> This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
> separate thread as it changes whats in that first email and I didn't
> want it getting lost in the other thread when people evaluate whether to
> adopt RTreeKEM for MLS.)
>
> In short, after some very helpful back and forth with Mike Hamburg, it
> is looking like we have a reasonable way to do Re-randomizable TreeKEM
> (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
> longer have to choose between RTreeKEM and those suits. IMO that removes
> the biggest barrier to using RTreeKEM.
>
> To be clear, we're still doing a some coding & testing to build
> confidence. And we will also run it past the CFRG / a few more ECC
> experts besides Mike, to make absolutely sure it works as intended.
> But at this point we are pretty optimistic already.
>
> The rest of this email contains the details for how RTreeKEM can be made
> to work with the X* groups.
>
> - Jo=C3=ABl
>
> -----------------------------------------------------------
>
>
> Essentially, all we really need for RTreeKEM is to build "Updateable
> Public Key Encryption" (UPKE) as defined in [1].
>
> Rather than the construction in [1] which is based additive
> key-homomorphism we can use the following construction based on a
> multiplicative key-homomorphism. (It turns out the later is easier to
> implement for X* groups than the former.)
>
> To minimize the diff between current TreeKEM and this new variant of
> RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
> black boxes.
>
> Inherited from Cipher Suite
> ---------------------------
> - sksize =3D # of bits for secret key scalars. (e.g. 32 for X25518)
> - order =3D order of prime-order subgroup (e.g. as in RFC 7748)
> - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
> - Mult(a,b) : Multiplication of secret keys. See below.
>
>
> Multiplication
> --------------
> - NIST curves : Mult(a,b) =3D a*b mod order.
> - X25519 : let Clamp(k) =3D decodeScalar25519(k) as in RFC 7748.
> - X448 : let Clamp(k) =3D decodeScalar448(k) as in RFC 7748.
>
> For both X25519 & X448 use
>  Mult(a,b) {
>    c =3D (Clamp(a) - Clamp(b)) mod order
>    if msb(c) =3D 0
>      c =3D (order - c) mod order
>    return c
>  }
>
>
> UPKE Construction (from HPKE & HKDF)
> ------------------------------------
> - UPKE-KeyGen =3D HPKE-KeyGen
>
> - UPKE-Encrypt(pk, m):
>   d'  <-- {0,1}^secpar
>   d   :=3D HKDF(sksize, d', "", "derive UPKE delta")
>   c1, context :=3D HPKE.SetupBaseI(pk, "")
>   c2  <-- context.Seal("", d' || m)
>   pk' :=3D DH(pk, d)
>   return ((c1, c2), pk')
>
> - UPKE-Decrypt(sk, (c1, c2)):
>   epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
>   d' || m :=3D context.Open("", c2)
>   d :=3D HKDF(sksize, d', "", "derive UPKE delta")
>   sk' :=3D Mult(sk, d)
>   return (m, sk')
>
>
> References
> ----------
> [1] http:\\ia.cr\2019\1189.
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000d3bfbf0595786984
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>FWIW, I tried to update this and it appears not to wo=
rk, either in the sense of pk&#39; =3D pk(sk&#39;), or in the sense of pk&#=
39; and sk&#39; producing equivalent DH results.</div><div><br></div><div><=
a href=3D"https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a9=
0ca">https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a90ca</=
a></div><div><br></div><div>It seems odd to me that the *Mult* functions co=
mputes Clamp(a) - Clamp(b), instead of multiplying ... well anything.=C2=A0=
 But even when I changed the Sub to a Mul in my test code, things still did=
n&#39;t work.</div><div><br></div><div>The problem I observed in the CFRG t=
hread on this long ago is that there are X25519 DH outputs that are not val=
id public keys, which I think implies that you can&#39;t have any homomorph=
ism in which the DH function is the public transformation.=C2=A0 Maybe that=
&#39;s what we&#39;re running into here?</div><div><br></div><div>Also poss=
ible that I&#39;m just missing something :)<br></div></div><br><div class=
=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct 21, 2019=
 at 5:21 PM Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com">jalwen@wickr=
.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1=
ex">Hey,<br>
<br>
This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a<br>
separate thread as it changes whats in that first email and I didn&#39;t<br=
>
want it getting lost in the other thread when people evaluate whether to<br=
>
adopt RTreeKEM for MLS.)<br>
<br>
In short, after some very helpful back and forth with Mike Hamburg, it<br>
is looking like we have a reasonable way to do Re-randomizable TreeKEM<br>
(RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no<br>
longer have to choose between RTreeKEM and those suits. IMO that removes<br=
>
the biggest barrier to using RTreeKEM.<br>
<br>
To be clear, we&#39;re still doing a some coding &amp; testing to build<br>
confidence. And we will also run it past the CFRG / a few more ECC<br>
experts besides Mike, to make absolutely sure it works as intended.<br>
But at this point we are pretty optimistic already.<br>
<br>
The rest of this email contains the details for how RTreeKEM can be made<br=
>
to work with the X* groups.<br>
<br>
- Jo=C3=ABl<br>
<br>
-----------------------------------------------------------<br>
<br>
<br>
Essentially, all we really need for RTreeKEM is to build &quot;Updateable<b=
r>
Public Key Encryption&quot; (UPKE) as defined in [1].<br>
<br>
Rather than the construction in [1] which is based additive<br>
key-homomorphism we can use the following construction based on a<br>
multiplicative key-homomorphism. (It turns out the later is easier to<br>
implement for X* groups than the former.)<br>
<br>
To minimize the diff between current TreeKEM and this new variant of<br>
RTreeKEM, the new construction is formulated it to use HPKE and HKDF as<br>
black boxes.<br>
<br>
Inherited from Cipher Suite<br>
---------------------------<br>
- sksize =3D # of bits for secret key scalars. (e.g. 32 for X25518)<br>
- order =3D order of prime-order subgroup (e.g. as in RFC 7748)<br>
- DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)<br>
- Mult(a,b) : Multiplication of secret keys. See below.<br>
<br>
<br>
Multiplication<br>
--------------<br>
- NIST curves : Mult(a,b) =3D a*b mod order.<br>
- X25519 : let Clamp(k) =3D decodeScalar25519(k) as in RFC 7748.<br>
- X448 : let Clamp(k) =3D decodeScalar448(k) as in RFC 7748.<br>
<br>
For both X25519 &amp; X448 use<br>
=C2=A0Mult(a,b) {<br>
=C2=A0 =C2=A0c =3D (Clamp(a) - Clamp(b)) mod order<br>
=C2=A0 =C2=A0if msb(c) =3D 0<br>
=C2=A0 =C2=A0 =C2=A0c =3D (order - c) mod order<br>
=C2=A0 =C2=A0return c<br>
=C2=A0}<br>
<br>
<br>
UPKE Construction (from HPKE &amp; HKDF)<br>
------------------------------------<br>
- UPKE-KeyGen =3D HPKE-KeyGen<br>
<br>
- UPKE-Encrypt(pk, m):<br>
=C2=A0 d&#39;=C2=A0 &lt;-- {0,1}^secpar<br>
=C2=A0 d=C2=A0 =C2=A0:=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive U=
PKE delta&quot;)<br>
=C2=A0 c1, context :=3D HPKE.SetupBaseI(pk, &quot;&quot;)<br>
=C2=A0 c2=C2=A0 &lt;-- context.Seal(&quot;&quot;, d&#39; || m)<br>
=C2=A0 pk&#39; :=3D DH(pk, d)<br>
=C2=A0 return ((c1, c2), pk&#39;)<br>
<br>
- UPKE-Decrypt(sk, (c1, c2)):<br>
=C2=A0 epk, context :=3D HPKE.SetupBaseR(c1, sk, &quot;&quot;)<br>
=C2=A0 d&#39; || m :=3D context.Open(&quot;&quot;, c2)<br>
=C2=A0 d :=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive UPKE delta&qu=
ot;)<br>
=C2=A0 sk&#39; :=3D Mult(sk, d)<br>
=C2=A0 return (m, sk&#39;)<br>
<br>
<br>
References<br>
----------<br>
[1] http:\\<a href=3D"http://ia.cr" rel=3D"noreferrer" target=3D"_blank">ia=
.cr</a>\2019\1189.<br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--000000000000d3bfbf0595786984--


From nobody Mon Oct 21 23:47:08 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 401F5120059 for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 23:47:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 083bg3GMyjCZ for <mls@ietfa.amsl.com>; Mon, 21 Oct 2019 23:47:04 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [IPv6:2001:67c:2050:104:0:2:25:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 647DD12002F for <mls@ietf.org>; Mon, 21 Oct 2019 23:47:03 -0700 (PDT)
Received: from smtp1.mailbox.org (smtp1.mailbox.org [80.241.60.240]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id 2DB0AA3408 for <mls@ietf.org>; Tue, 22 Oct 2019 08:46:58 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp1.mailbox.org ([80.241.60.240]) by spamfilter04.heinlein-hosting.de (spamfilter04.heinlein-hosting.de [80.241.56.122]) (amavisd-new, port 10030) with ESMTP id aRhCZ3CYHD65 for <mls@ietf.org>; Tue, 22 Oct 2019 08:46:53 +0200 (CEST)
To: mls@ietf.org
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <54a0f5b5-2236-38e5-f228-684ab900f2d3@datashrine.de>
Date: Tue, 22 Oct 2019 08:46:52 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/sscJ9cVFRrakTLCz66-bpY6aG4g>
Subject: [MLS] Next Interim
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 06:47:06 -0000

Hi everyone,

I'm currently planning my travel to RWC in January and was wondering what the
status is on the next MLS interim. Any chance it will be colocated similar to
last January? I know it's still relatively early, but it would help planning
quite a bit to know roughly where/when the options are.

Cheers,
Konrad


From nobody Tue Oct 22 04:18:33 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C236E12081F for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 04:18:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LxpgwRss6VHK for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 04:18:29 -0700 (PDT)
Received: from mail-wm1-x335.google.com (mail-wm1-x335.google.com [IPv6:2a00:1450:4864:20::335]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A9621201E4 for <mls@ietf.org>; Tue, 22 Oct 2019 04:18:28 -0700 (PDT)
Received: by mail-wm1-x335.google.com with SMTP id r19so16798679wmh.2 for <mls@ietf.org>; Tue, 22 Oct 2019 04:18:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=X3A3E1gAcM8rdlFNx0r0sDotsEKOeK0JD1MzkPF+l8s=; b=L9l9SvtWQ2vhc4tkrxAPy/+51/pHwescqDduBYECqrWuqmEty9R6+K4QhM+BRR7K+H ufBGsYfneD3py+wyXvUTVJl6NdJOmj5TzpUiEPGx4quOFuJzeDArGv9HxhibywDgMiPv f2D7swCj3VWoI4Ld0T59QIMwmre+Qi0A+YPnZX0vI2C5RQR5dmUwcXNXDbUj1Xtd+EE7 GkRpkz54+oLaY+jf7zRcEyfleQk7QMDNZO1HMoJYVp5VgHPJE0wEbKKEad79bzRWam4R xdqLSrGlen17/S+VANvzEXkM3zz5k01yPLSzVItxh3LvKCJCuz1n0+/eii/wTfejOJlc yQFQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=X3A3E1gAcM8rdlFNx0r0sDotsEKOeK0JD1MzkPF+l8s=; b=V+nTB2FZp8rJ6THJNpUQ6pZFF86nB5Yg0q8g5mNR5iKE5I37fX5PO7FlhYabdoFl2K IiTcOK48feery7c7nkf9Zw3cA3c6C9BVvp+3H8zLbk5JDz3vhpmjtgYjcbfndrA6ZPk3 doSo4W/qX4VDSepV89kmYwaDKmTQFDnDaGrVTeNFu6+75LWlbDAmdHbPGjbJZnPle8Sz jtKt4a4qrdk2qiA//B5UCE11n3u/ictJ2JtlvDZ/WfWnS4DrSCRgHq8JcZ9bbNo+OyDE nVuQEXGuhDhqhH2NWxLdGBxKzeOjMPuWELoAjm8w0Seuv/XAMyNF/F4zhNIR4pIawTMf 80IQ==
X-Gm-Message-State: APjAAAXR32JkJTCZDBFdJmliOED/F1UbdxjVVG77mWCQpbQPPa8Xcvb8 vL1xu0gt3JTtbZWWajZSikusFDdYvlE=
X-Google-Smtp-Source: APXvYqy+/frVgSf2MeSOnvntkZZLxgpLBbiLcxbW3EBYtt/U43IJgb94MzwbP/jGqBrmS6rVJCo94w==
X-Received: by 2002:a1c:64d6:: with SMTP id y205mr2382066wmb.136.1571743106177;  Tue, 22 Oct 2019 04:18:26 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id b1sm10434924wru.83.2019.10.22.04.18.25 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 04:18:25 -0700 (PDT)
To: Richard Barnes <rlb@ipv.sx>, Messaging Layer Security WG <mls@ietf.org>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <d5a52f39-ac2c-5118-8a15-d7706861dc9b@wickr.com>
Date: Tue, 22 Oct 2019 13:18:26 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/n1YPHk8oDGJMt29D4IMyxOJOtnQ>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 11:18:32 -0000

Hey Richard,

Thanks for the code to help testing this stuff!

On 22/10/2019 06:41, Richard Barnes wrote:
> FWIW, I tried to update this and it appears not to work, either in the
> sense of pk' = pk(sk'), or in the sense of pk' and sk' producing
> equivalent DH results.
> 
> https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a90ca
> 
> It seems odd to me that the *Mult* functions computes Clamp(a) -
> Clamp(b), instead of multiplying ... well anything.

The reasoning here is based on the view of X25519(pk, s) first does
Clamp(s)->s' and then pk^(s') mod order. So Mult() first maps the scalar
inputs the their clamped representatives and only then does the
multiplication.

But it could be this is not the right view of X25519 (though, in my
defense, Mike H. also seemed to think the construction should work and
he knows way more about this stuff than I do).

> The problem I observed in the CFRG thread on this long ago is that there
> are X25519 DH outputs that are not valid public keys, which I think
> implies that you can't have any homomorphism in which the DH function is
> the public transformation.  Maybe that's what we're running into here?

Indeed, from a formal mathematical point of view Mult() is *not* aiming
to be a multiplicative homomorphism because of some rare exceptions. But
Mike believed that the probability of running into such an output, when
using uniform randomly chosen inputs was around 1/2^{-126} or so.
Moreover, for X448 he thought the probability was 0. To be clear, he
wasn't 100% and recommended testing.

> Also possible that I'm just missing something :)

Yeah, same here. I'll see if I can figure out whats going on here and
get back to the mailinglist if I make any progress.

- Joël

> On Mon, Oct 21, 2019 at 5:21 PM Joel Alwen <jalwen@wickr.com
> <mailto:jalwen@wickr.com>> wrote:
> 
>     Hey,
> 
>     This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
>     separate thread as it changes whats in that first email and I didn't
>     want it getting lost in the other thread when people evaluate whether to
>     adopt RTreeKEM for MLS.)
> 
>     In short, after some very helpful back and forth with Mike Hamburg, it
>     is looking like we have a reasonable way to do Re-randomizable TreeKEM
>     (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
>     longer have to choose between RTreeKEM and those suits. IMO that removes
>     the biggest barrier to using RTreeKEM.
> 
>     To be clear, we're still doing a some coding & testing to build
>     confidence. And we will also run it past the CFRG / a few more ECC
>     experts besides Mike, to make absolutely sure it works as intended.
>     But at this point we are pretty optimistic already.
> 
>     The rest of this email contains the details for how RTreeKEM can be made
>     to work with the X* groups.
> 
>     - Joël
> 
>     -----------------------------------------------------------
> 
> 
>     Essentially, all we really need for RTreeKEM is to build "Updateable
>     Public Key Encryption" (UPKE) as defined in [1].
> 
>     Rather than the construction in [1] which is based additive
>     key-homomorphism we can use the following construction based on a
>     multiplicative key-homomorphism. (It turns out the later is easier to
>     implement for X* groups than the former.)
> 
>     To minimize the diff between current TreeKEM and this new variant of
>     RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
>     black boxes.
> 
>     Inherited from Cipher Suite
>     ---------------------------
>     - sksize = # of bits for secret key scalars. (e.g. 32 for X25518)
>     - order = order of prime-order subgroup (e.g. as in RFC 7748)
>     - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
>     - Mult(a,b) : Multiplication of secret keys. See below.
> 
> 
>     Multiplication
>     --------------
>     - NIST curves : Mult(a,b) = a*b mod order.
>     - X25519 : let Clamp(k) = decodeScalar25519(k) as in RFC 7748.
>     - X448 : let Clamp(k) = decodeScalar448(k) as in RFC 7748.
> 
>     For both X25519 & X448 use
>      Mult(a,b) {
>        c = (Clamp(a) - Clamp(b)) mod order
>        if msb(c) = 0
>          c = (order - c) mod order
>        return c
>      }
> 
> 
>     UPKE Construction (from HPKE & HKDF)
>     ------------------------------------
>     - UPKE-KeyGen = HPKE-KeyGen
> 
>     - UPKE-Encrypt(pk, m):
>       d'  <-- {0,1}^secpar
>       d   := HKDF(sksize, d', "", "derive UPKE delta")
>       c1, context := HPKE.SetupBaseI(pk, "")
>       c2  <-- context.Seal("", d' || m)
>       pk' := DH(pk, d)
>       return ((c1, c2), pk')
> 
>     - UPKE-Decrypt(sk, (c1, c2)):
>       epk, context := HPKE.SetupBaseR(c1, sk, "")
>       d' || m := context.Open("", c2)
>       d := HKDF(sksize, d', "", "derive UPKE delta")
>       sk' := Mult(sk, d)
>       return (m, sk')
> 
> 
>     References
>     ----------
>     [1] http:\\ia.cr <http://ia.cr>\2019\1189.
> 
>     _______________________________________________
>     MLS mailing list
>     MLS@ietf.org <mailto:MLS@ietf.org>
>     https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Tue Oct 22 06:19:40 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CF2B120802 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 06:19:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jWzQgBariWL3 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 06:19:37 -0700 (PDT)
Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A05131200F6 for <mls@ietf.org>; Tue, 22 Oct 2019 06:19:36 -0700 (PDT)
Received: by mail-wr1-x42f.google.com with SMTP id l10so17629645wrb.2 for <mls@ietf.org>; Tue, 22 Oct 2019 06:19:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=qb29iRnrqlX84EDkTUNNpubrroomaheQTDW3GsJK/Tw=; b=K3BsLLSbrwHl2hqrPQpK+qjDv0I//NuQe0TEN3ejTN8GrUyHVYUBsLAM7wc77DEqHi c6VDlon8ZI+0y6yVxKvzZ3uUt0AsFmjZqMBMMj/ZIo93SUjPg1a9ISIJv8sK4wgvte5w BlB277xsbNLKf14QB02HrCHO362uAQTLs5L0pN1w/Y+cYiuxdpUwPg/vT4DUjgwEouJ1 BgS8FDTusVJd0ZRHhFEIT+eDj0DR/tLzZ9B3NWZt41vD7eZqCZfu71I0WIbnq9wXyEWY 14vczQ2ZlmW3qUM3c7oq5JHvEwWhp7MK6u1tTwKbyOGDHoPO+vXgVjqny9gQwubxc2La EYgA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=qb29iRnrqlX84EDkTUNNpubrroomaheQTDW3GsJK/Tw=; b=Kpf4STbUBzu4EPspYB+pSrhM1rWkC0WCrQ3eCNgahp4b9T8R8ta4opUB0RfLXSu+lW cOMo1fU9sSwLTxy05Lly+dXhNO9B5TjQBZS8IosxhuskQvYip74vSVp8UAM/u+oA3mU9 3q7XmapSZqYCXYnh0OWsisiW457Md477AM6KNgwZkPJZRRXMKrS6ntVpRDq9Ga/El3RV yEMkZ9jlYQTiDdncd2wWUW715CZSE3R7e6sJgwNmVU43r1v/Ixs9h0UriF3IFWoCRiB0 SVqqjYEqk24k5nm03bSw08oekvNV+Tprn4uuIQLEW1XDlvtyieJYDNisK6zug8VUjvaA 4FfA==
X-Gm-Message-State: APjAAAVY6yYQXgKRv6t1F8zIwGZ5+1Z3ugCsmP8uUDNYjA9wGHAAOpyB A59CdmhvpdIp4fTxUTfQGniWj3wVmUI=
X-Google-Smtp-Source: APXvYqwPKHfB/dEp2bHFqFVhEuQGQve4GXhlR306zxx6+HHkRUuPPjeOm4i8T/sWrrCKfpL4wq0HYQ==
X-Received: by 2002:adf:dc42:: with SMTP id m2mr3690190wrj.314.1571750374426;  Tue, 22 Oct 2019 06:19:34 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id a3sm16372697wmc.3.2019.10.22.06.19.33 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 06:19:33 -0700 (PDT)
To: Richard Barnes <rlb@ipv.sx>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <fd1956c3-3c48-877d-ceab-221cda615a85@wickr.com>
Date: Tue, 22 Oct 2019 15:19:32 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/YHEjTKtnLKASoUeE1iZ2_V8FvGc>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 13:19:39 -0000

Ah crap. I had a typo in my original email in this thread. Mult() is supposed to _multiply_ the clamped values, not
subtract them. *facepalm*

So the correct pseudocode for Mult() is:

 Mult(a,b) {
   c = (Clamp(a) * Clamp(b)) mod order
   if msb(c) = 0
     c = (order - c) mod order
   return c
 }

Sorry about that. Unfortunately, I think the code *still* doesnt give us what we want though. I'll keep playing with this...

- Joël

On 22/10/2019 06:41, Richard Barnes wrote:
> FWIW, I tried to update this and it appears not to work, either in the sense of pk' = pk(sk'), or in the sense of pk'
> and sk' producing equivalent DH results.
> 
> https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a90ca
> 
> It seems odd to me that the *Mult* functions computes Clamp(a) - Clamp(b), instead of multiplying ... well anything. 
> But even when I changed the Sub to a Mul in my test code, things still didn't work.
> 
> The problem I observed in the CFRG thread on this long ago is that there are X25519 DH outputs that are not valid public
> keys, which I think implies that you can't have any homomorphism in which the DH function is the public transformation. 
> Maybe that's what we're running into here?
> 
> Also possible that I'm just missing something :)
> 
> On Mon, Oct 21, 2019 at 5:21 PM Joel Alwen <jalwen@wickr.com <mailto:jalwen@wickr.com>> wrote:
> 
>     Hey,
> 
>     This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
>     separate thread as it changes whats in that first email and I didn't
>     want it getting lost in the other thread when people evaluate whether to
>     adopt RTreeKEM for MLS.)
> 
>     In short, after some very helpful back and forth with Mike Hamburg, it
>     is looking like we have a reasonable way to do Re-randomizable TreeKEM
>     (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
>     longer have to choose between RTreeKEM and those suits. IMO that removes
>     the biggest barrier to using RTreeKEM.
> 
>     To be clear, we're still doing a some coding & testing to build
>     confidence. And we will also run it past the CFRG / a few more ECC
>     experts besides Mike, to make absolutely sure it works as intended.
>     But at this point we are pretty optimistic already.
> 
>     The rest of this email contains the details for how RTreeKEM can be made
>     to work with the X* groups.
> 
>     - Joël
> 
>     -----------------------------------------------------------
> 
> 
>     Essentially, all we really need for RTreeKEM is to build "Updateable
>     Public Key Encryption" (UPKE) as defined in [1].
> 
>     Rather than the construction in [1] which is based additive
>     key-homomorphism we can use the following construction based on a
>     multiplicative key-homomorphism. (It turns out the later is easier to
>     implement for X* groups than the former.)
> 
>     To minimize the diff between current TreeKEM and this new variant of
>     RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
>     black boxes.
> 
>     Inherited from Cipher Suite
>     ---------------------------
>     - sksize = # of bits for secret key scalars. (e.g. 32 for X25518)
>     - order = order of prime-order subgroup (e.g. as in RFC 7748)
>     - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
>     - Mult(a,b) : Multiplication of secret keys. See below.
> 
> 
>     Multiplication
>     --------------
>     - NIST curves : Mult(a,b) = a*b mod order.
>     - X25519 : let Clamp(k) = decodeScalar25519(k) as in RFC 7748.
>     - X448 : let Clamp(k) = decodeScalar448(k) as in RFC 7748.
> 
>     For both X25519 & X448 use
>      Mult(a,b) {
>        c = (Clamp(a) - Clamp(b)) mod order
>        if msb(c) = 0
>          c = (order - c) mod order
>        return c
>      }
> 
> 
>     UPKE Construction (from HPKE & HKDF)
>     ------------------------------------
>     - UPKE-KeyGen = HPKE-KeyGen
> 
>     - UPKE-Encrypt(pk, m):
>       d'  <-- {0,1}^secpar
>       d   := HKDF(sksize, d', "", "derive UPKE delta")
>       c1, context := HPKE.SetupBaseI(pk, "")
>       c2  <-- context.Seal("", d' || m)
>       pk' := DH(pk, d)
>       return ((c1, c2), pk')
> 
>     - UPKE-Decrypt(sk, (c1, c2)):
>       epk, context := HPKE.SetupBaseR(c1, sk, "")
>       d' || m := context.Open("", c2)
>       d := HKDF(sksize, d', "", "derive UPKE delta")
>       sk' := Mult(sk, d)
>       return (m, sk')
> 
> 
>     References
>     ----------
>     [1] http:\\ia.cr <http://ia.cr>\2019\1189.
> 
>     _______________________________________________
>     MLS mailing list
>     MLS@ietf.org <mailto:MLS@ietf.org>
>     https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Tue Oct 22 07:47:22 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2809120013 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 07:47:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sYVMkMz9CYxz for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 07:47:17 -0700 (PDT)
Received: from mail-wm1-x32b.google.com (mail-wm1-x32b.google.com [IPv6:2a00:1450:4864:20::32b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 83EF2120086 for <mls@ietf.org>; Tue, 22 Oct 2019 07:47:17 -0700 (PDT)
Received: by mail-wm1-x32b.google.com with SMTP id g24so8447334wmh.5 for <mls@ietf.org>; Tue, 22 Oct 2019 07:47:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=IjIT/avS65uPl63N4P097coy5dLcnXtfHyp3CdJChhs=; b=v19FUb842+psnKFBxVZtCkPqbdJ1C6wjMCyjnC1/LdLyiJWJqy2qamlLow+bjiVVqb FAobMQrVgT4SYXLA+xjiK/58WZEcLYnKyPePFEaR98ncc4E6dn5qi+cPTnGt6nSKc5Oa G/wfIVgwBcR2YWQSqjEkGe3oAPPjkf43nStOS3UTqHI2GHwh5+kl26QU0oCmXnZQ3i/W C9wQWlPBpj3vwku4tdsV6qP0TYIn9PcehD87GMN3BcBLA4CFK4bHO9VQCeKmStChj6+1 GqcLneZ87FgpqbYJTS6HP9fs9CwLzkjdMn8q2976/ThvLQ5606011ehuFpWPHZqWQN8S dt8g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=IjIT/avS65uPl63N4P097coy5dLcnXtfHyp3CdJChhs=; b=XErgEiSr1Rv2MikqgEdJqrMjFCuuIGGeXlCKl1gUXsIeZ4KkyiN5Z3+h1JXTEJe1tn Govh9/AjZZBghaWrtb5c27YIeyuCFZD866U6r9qcfs81PW8adaYqC76KUjX3dyQjDlL4 TL7K9rjn4Jn/JKZffctskwCBFZTcSmKASwjYLvzXAd5W+Dy/BJ0Bc2KuPV2jZrLU6hWR gLHvvw594Q7n738sG5Pme94BVUakc8oispTvV6GNAVGhhTKpuIWihnU/lu7IhOY58PER cjqxh8jnknvaNsB6RZJ1mHKELPzcZSY1qvqpdvdrVIjRBgLt6P0GMi0aovXClxt5LBBL Y/HQ==
X-Gm-Message-State: APjAAAVQGj6Er/zV5iwDU5uvn7DzbEB9q2su2nsoDxrW/rJL5++0zgjg RGypC6EUu0DLYw9en7sybn1VGXrFgjI=
X-Google-Smtp-Source: APXvYqwpjxbEvPV0xXJfvRoPNPGjP1VwFGlA0Xm8KJC7jp7AjQfkoZAPpu/AagWDjjSdoV3lNXg6Uw==
X-Received: by 2002:a7b:c019:: with SMTP id c25mr3105575wmb.61.1571755635269;  Tue, 22 Oct 2019 07:47:15 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id v10sm11935257wrm.26.2019.10.22.07.47.14 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 07:47:14 -0700 (PDT)
To: Richard Barnes <rlb@ipv.sx>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <71d9cd8a-4d00-118e-bf03-1c90534dc474@wickr.com>
Date: Tue, 22 Oct 2019 16:47:14 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CAL02cgRDKN9b8eLdh=uCApP7Mi+-JTYo8jxv1AOXR2mxXo=15g@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/SW0hNjsaRn5UmgxFRPunYWC-cEA>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 14:47:21 -0000

EUREKA!

I got it to work with the following changes:

1) clamp both scalars befor doing the Mul (instead of just le2bn)
2) using the composite order (n25519*8) instead of prime order (n25519)
3) mul instead of sub
4) condition on bit 254 == 0 instead of 255.

Here's the (now working I think) code. https://play.golang.org/p/UaFVV6HG-Nf

Reasoning for changes:
1) Was as originally intended. Basically X25519 clamps the scalar, then does exponentiation.
2) Mike had already mentioned I should use composite not prime order. I just missed it. more *facepalm*
3) Multiplicative not additive homomorphism
4) Goal here is msb should be set to 1. If it isn't then we need the negative. Basically, msb is bit 254 instead of 255.

- Joël

On 22/10/2019 06:41, Richard Barnes wrote:
> FWIW, I tried to update this and it appears not to work, either in the sense of pk' = pk(sk'), or in the sense of pk'
> and sk' producing equivalent DH results.
> 
> https://gist.github.com/bifurcation/795dd09ca399acfda5db87bc825a90ca
> 
> It seems odd to me that the *Mult* functions computes Clamp(a) - Clamp(b), instead of multiplying ... well anything. 
> But even when I changed the Sub to a Mul in my test code, things still didn't work.
> 
> The problem I observed in the CFRG thread on this long ago is that there are X25519 DH outputs that are not valid public
> keys, which I think implies that you can't have any homomorphism in which the DH function is the public transformation. 
> Maybe that's what we're running into here?
> 
> Also possible that I'm just missing something :)
> 
> On Mon, Oct 21, 2019 at 5:21 PM Joel Alwen <jalwen@wickr.com <mailto:jalwen@wickr.com>> wrote:
> 
>     Hey,
> 
>     This is a follow up to the earlier Re-Randomized TreeKEM email. (Its a
>     separate thread as it changes whats in that first email and I didn't
>     want it getting lost in the other thread when people evaluate whether to
>     adopt RTreeKEM for MLS.)
> 
>     In short, after some very helpful back and forth with Mike Hamburg, it
>     is looking like we have a reasonable way to do Re-randomizable TreeKEM
>     (RTreeKEM) based on the X25519/X448 ciphersuits. That would mean we no
>     longer have to choose between RTreeKEM and those suits. IMO that removes
>     the biggest barrier to using RTreeKEM.
> 
>     To be clear, we're still doing a some coding & testing to build
>     confidence. And we will also run it past the CFRG / a few more ECC
>     experts besides Mike, to make absolutely sure it works as intended.
>     But at this point we are pretty optimistic already.
> 
>     The rest of this email contains the details for how RTreeKEM can be made
>     to work with the X* groups.
> 
>     - Joël
> 
>     -----------------------------------------------------------
> 
> 
>     Essentially, all we really need for RTreeKEM is to build "Updateable
>     Public Key Encryption" (UPKE) as defined in [1].
> 
>     Rather than the construction in [1] which is based additive
>     key-homomorphism we can use the following construction based on a
>     multiplicative key-homomorphism. (It turns out the later is easier to
>     implement for X* groups than the former.)
> 
>     To minimize the diff between current TreeKEM and this new variant of
>     RTreeKEM, the new construction is formulated it to use HPKE and HKDF as
>     black boxes.
> 
>     Inherited from Cipher Suite
>     ---------------------------
>     - sksize = # of bits for secret key scalars. (e.g. 32 for X25518)
>     - order = order of prime-order subgroup (e.g. as in RFC 7748)
>     - DH(A,b) : A Diffie-Hellman function. (E.g. X25519 or X448)
>     - Mult(a,b) : Multiplication of secret keys. See below.
> 
> 
>     Multiplication
>     --------------
>     - NIST curves : Mult(a,b) = a*b mod order.
>     - X25519 : let Clamp(k) = decodeScalar25519(k) as in RFC 7748.
>     - X448 : let Clamp(k) = decodeScalar448(k) as in RFC 7748.
> 
>     For both X25519 & X448 use
>      Mult(a,b) {
>        c = (Clamp(a) - Clamp(b)) mod order
>        if msb(c) = 0
>          c = (order - c) mod order
>        return c
>      }
> 
> 
>     UPKE Construction (from HPKE & HKDF)
>     ------------------------------------
>     - UPKE-KeyGen = HPKE-KeyGen
> 
>     - UPKE-Encrypt(pk, m):
>       d'  <-- {0,1}^secpar
>       d   := HKDF(sksize, d', "", "derive UPKE delta")
>       c1, context := HPKE.SetupBaseI(pk, "")
>       c2  <-- context.Seal("", d' || m)
>       pk' := DH(pk, d)
>       return ((c1, c2), pk')
> 
>     - UPKE-Decrypt(sk, (c1, c2)):
>       epk, context := HPKE.SetupBaseR(c1, sk, "")
>       d' || m := context.Open("", c2)
>       d := HKDF(sksize, d', "", "derive UPKE delta")
>       sk' := Mult(sk, d)
>       return (m, sk')
> 
> 
>     References
>     ----------
>     [1] http:\\ia.cr <http://ia.cr>\2019\1189.
> 
>     _______________________________________________
>     MLS mailing list
>     MLS@ietf.org <mailto:MLS@ietf.org>
>     https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Tue Oct 22 08:02:33 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C4E131200DB for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 08:02:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z0P0IufjFuIl for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 08:02:22 -0700 (PDT)
Received: from mail-wm1-x334.google.com (mail-wm1-x334.google.com [IPv6:2a00:1450:4864:20::334]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A685A120013 for <mls@ietf.org>; Tue, 22 Oct 2019 08:02:21 -0700 (PDT)
Received: by mail-wm1-x334.google.com with SMTP id g24so8510364wmh.5 for <mls@ietf.org>; Tue, 22 Oct 2019 08:02:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=ch0zsyLXNNO1wH2OtQ02l9i1KKer2xkrhbIf734qxCI=; b=D73sCD4/USmJJBr96IzZve0hvZH0PLXaiTnoHALBjPGlLLMdh7hhl/hIsyny4LXcRR fuk+cSeMJY5BKjJDruGKfJmHKf7HQK3ovoeem+pnVHNLGwH90hXNMfPhta3UMfkCUn2A W2Bqi6OlLtqSFW3wUIdMVmfltN4IrcwRbuLzRE2XGFfvLldxJ7xlq6788PDhxj00ttuU 7WtgWx9mwd+odT/Kjog/PDT55LN8mHy7LXzxcLoyXKQoQMdGDHCWMKHczo4fXT7hrJpE LHDzg3HInJ/Y4Pcl5k6v6fk5hWDiHb2hw6xilMe3Md1s1WPuo99+80a9dPfx51q5naEI LfSQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=ch0zsyLXNNO1wH2OtQ02l9i1KKer2xkrhbIf734qxCI=; b=YN/tpY8zd+VNa0lTYF0lAVEJHzTOzbwRQNuT1eBgaS4hof7yQhsiuOe++heU94sPhY 7NQzuxMraJnh86yIdwWVLc9oGthRbznUhhDuiQNem0ZrL920tJdj5ndxm9climruseqq +QblPHd5vAWy3boxW1YBQKx0wra6ajknFgINDbFICEU3Kx4onoOPtLqtMI7i3S+Co6jC f9OgTnT6t5NXrmry9LJ49xsBcg78TQcavX9xf4FB3/rOopTHWEPkByERkFJCke8jU1Ho XR9HdPpDkKpFQdE0I2nCMgR20iSV1IpPDHVlA8DcCgQT8bmRKSGJwOf45AbNoE7My0qk uddQ==
X-Gm-Message-State: APjAAAWMKyQJbsv02DaTbTNCM33tgphiDqRrT0Bp7XZsPqzu2CaAdXeZ 9BJho/kQ9wO8gkaHRIvrO2APWhJZrmM=
X-Google-Smtp-Source: APXvYqwWLd4ifs1FyGI5WBW+jEHrwJ+KyKMU0+n72X2PBQxDjbWlRjhGAK2f6VEUOkCnG/56DFduzg==
X-Received: by 2002:a7b:c40a:: with SMTP id k10mr3741588wmi.115.1571756539689;  Tue, 22 Oct 2019 08:02:19 -0700 (PDT)
Received: from wifi-pro-83-029.paris.inria.fr (wifi-pro-83-029.paris.inria.fr. [128.93.83.29]) by smtp.gmail.com with ESMTPSA id n187sm15623504wmb.47.2019.10.22.08.02.18 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 08:02:18 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
In-Reply-To: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
Date: Tue, 22 Oct 2019 17:02:16 +0200
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com>
To: Joel Alwen <jalwen@wickr.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/NVxHypXc_1-d_NozloYVsOLbuSM>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 15:02:24 -0000

Sorry if this is already in the paper, but a question.

> - UPKE-Decrypt(sk, (c1, c2)):
>  epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
>  d' || m :=3D context.Open("", c2)
>  d :=3D HKDF(sksize, d', "", "derive UPKE delta")
>  sk' :=3D Mult(sk, d)
>  return (m, sk=E2=80=99)

I believe it is important for the recipient to do some validation before =
returning from UPKE-Decrypt.

For example, what if the (malicious) sender set d to =E2=80=9C0=E2=80=9D =
(whatever that means in the DH group).
This would mean that the resulting key sk=E2=80=99 becomes =E2=80=9C0=E2=80=
=9D too, hence a non-member has been able to force the recipient =
group=E2=80=99s private key to a particular value, which is not ideal.
What conditions should we add to avoid this kind of key-forcing attack =
from happening?

-Karthik



>=20
>=20
> References
> ----------
> [1] http:\\ia.cr\2019\1189.
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


From nobody Tue Oct 22 08:05:31 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 27CA9120043 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 08:05:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i_RAlgBn7hoj for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 08:05:28 -0700 (PDT)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com [IPv6:2a00:1450:4864:20::333]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D0D88120013 for <mls@ietf.org>; Tue, 22 Oct 2019 08:05:27 -0700 (PDT)
Received: by mail-wm1-x333.google.com with SMTP id c22so7400370wmd.1 for <mls@ietf.org>; Tue, 22 Oct 2019 08:05:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=Yd85EumD+Ip1AP8U/jWat5HQXJaU7NpknW8zRk1DQbQ=; b=eqrX+cBbRekOYeTYbasGTfICdqRD8wOexAjdzoGu8doz8DEe2uAOFfw5R8Vwv0Vs2/ ZCHBga7gFSkghte6t4PaX/nUuqxO+kpiddJasGP35mbYF3/cMb7pftj3arIU/yFpHq2l 3TeMRHJSl8bzHAwScqEcAHfkT+XOK/oCzuflFVnO2W/TZ9vrBrjHoq5vt5+YqRlNRE2X 5yTiaCDnzOqEv+eBQ8M95Xp8GEloPlji/Gncnsfzm7Fl+loHsM1UGJZ9UJbuGkYRHSuT 4xaOKOx4XXk0FwvHG90ct7H16uLLhpRJYi/QU5ebLnJA1cpVxKDEN4RwMT6ZycJ6HWDm SSxg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=Yd85EumD+Ip1AP8U/jWat5HQXJaU7NpknW8zRk1DQbQ=; b=nShkVQZVj936U3hB3W0VJqbyv8DLjrQzJ76Do/smn7mgvp7PHf7i60phi4zmXmFmQb a4auK58I7a1N0H7B+3LhmZiFIqcylbdecl7YNO3gh/UMSXfrq+hS79B3Cs2P+z6Om02l g3Ms0hpyGEGKFxvab5y/zeUJe/NygfUpV9HxiKxrElMMv6/ZH2M+6gAt4ApgPUqUKyjX Yrj14QqlYGlYFLHGMEjiuOT3mTHzWKGOxFP0U0ARykPCBizRwRMtW0ttD/iNe9R3WnOv cON9mnku1AekoTgisSxFB1GAKalRwrS2sYo0kSH6hxxTZuS1CvheZ1i1ojG+N0KkJnxh 2W7w==
X-Gm-Message-State: APjAAAWv0JvuD2uM5QGygq5QWW+p0B0QkZleDCUZ0Iw7kie9Ow3QaApy PgdRmlRIilpibBVtr9fGVy09sgudm8M=
X-Google-Smtp-Source: APXvYqz9Wr2opUHqn2aIOaFRqUTBN5SeQejnQ/ExMXyuFRInTwmJiDPP4JyZW1mg9c2IdZ14rodjrw==
X-Received: by 2002:a1c:2c88:: with SMTP id s130mr3655624wms.66.1571756725580;  Tue, 22 Oct 2019 08:05:25 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id q66sm19494979wme.39.2019.10.22.08.05.24 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 08:05:24 -0700 (PDT)
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com>
Date: Tue, 22 Oct 2019 17:05:23 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/0Y-yIM4nIW6VwlGqZmfbCQ5XVlU>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 15:05:30 -0000

Good question!

I'll see if I can think of anything intelligent to say about it. :-)

But one thing that comes to mind is that the sender gets to choose "only" d', not d. Instead d := HKDF(d') so to get d=0
you'd have to first invert HKDF.

- Joel

On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:
> Sorry if this is already in the paper, but a question.
> 
>> - UPKE-Decrypt(sk, (c1, c2)):
>>  epk, context := HPKE.SetupBaseR(c1, sk, "")
>>  d' || m := context.Open("", c2)
>>  d := HKDF(sksize, d', "", "derive UPKE delta")
>>  sk' := Mult(sk, d)
>>  return (m, sk’)
> 
> I believe it is important for the recipient to do some validation before returning from UPKE-Decrypt.
> 
> For example, what if the (malicious) sender set d to “0” (whatever that means in the DH group).
> This would mean that the resulting key sk’ becomes “0” too, hence a non-member has been able to force the recipient group’s private key to a particular value, which is not ideal.
> What conditions should we add to avoid this kind of key-forcing attack from happening?
> 
> -Karthik
> 
> 
> 
>>
>>
>> References
>> ----------
>> [1] http:\\ia.cr\2019\1189.
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Tue Oct 22 09:29:58 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB07E120096 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 09:29:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GRvwrF5yO4Vw for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 09:29:54 -0700 (PDT)
Received: from mail-wr1-x429.google.com (mail-wr1-x429.google.com [IPv6:2a00:1450:4864:20::429]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B00312004A for <mls@ietf.org>; Tue, 22 Oct 2019 09:29:54 -0700 (PDT)
Received: by mail-wr1-x429.google.com with SMTP id t16so13658472wrr.1 for <mls@ietf.org>; Tue, 22 Oct 2019 09:29:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=hYXSH5nhhTUOCZWDit0pNky3bAAPq/NwJ4+Al+UaIC8=; b=Hxk8z91lesp7XSsmz3aLJzH9go6/vGpqbkgFEPkV3ds733qKJ6HFw7yQ0TTlgO2g+c 310K15fzetLwHx/jZqgmhfydUS6tNKwqo7Xq5KZxdg6rPr6B8oqo9OOCo+n5hnZXigsO 5fd/GyDzj3RTt3FmF4NDA1jM3PXiUrnvHywyYecwRnSlfZhiLzhIrcJy4RKxH6ypTFFk Jx9fgLlDk2MFUt5utFfoy44FN110Plfz/Qo5NOJNjvOp50gx+/glnesSXL1hIlNFrPGY qD0TAZm7DWUyF089+3qhvV+ggShlK3mQpkiuv+6m/N0+YDEYQFqBhvfcLRnyi0TZVMx/ DXVQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=hYXSH5nhhTUOCZWDit0pNky3bAAPq/NwJ4+Al+UaIC8=; b=jPJKu2Eo5uxFPPjrcpjuCXr+BWoHjIMQhRJAI0QE1omUdeB6UT16tlIENn9+C1K9ik rbU0qZhTqON7Vzi+kzJyg/yZi1QvOFuXZFhYPPFVrdkXiGEeqU5WoK6Eo54RTcQ6FBkL xo2mm3x2xADuk7em8A9pm+5VTyCi26S4g5OgISmQhZsT/lbASh8b+iD0gY3so09TQ56s JuCVEMWyRfJfNf/uEAOevKU5Jw/HlRtKRARqS8QAre8erej/ZH2P8NwT4vhT/h/cZtds QRqDx/PPwxjm/sKr75fwDxy9cnkdPDcY+wLr/YKs8fN3xQFCnB3i2tnKqU7s3lEWruQK X61Q==
X-Gm-Message-State: APjAAAV8xiaOJJaKrfJD1QivYyudAMQBubXF8YyFHzKlTAF28JZTPfcQ zRZkIijDCEb8DwsPyejw40M=
X-Google-Smtp-Source: APXvYqxpWxpah8NoJlRjVaUbTrTowdCWfWjFUNFa+JGmcX9/sDDSqScQx3v17+yRDJFjG/DVAF3XtA==
X-Received: by 2002:adf:828c:: with SMTP id 12mr4264864wrc.40.1571761792530; Tue, 22 Oct 2019 09:29:52 -0700 (PDT)
Received: from wifi-pro-83-029.paris.inria.fr (wifi-pro-83-029.paris.inria.fr. [128.93.83.29]) by smtp.gmail.com with ESMTPSA id z13sm21879761wrm.64.2019.10.22.09.29.51 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 09:29:51 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
In-Reply-To: <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com>
Date: Tue, 22 Oct 2019 18:29:50 +0200
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <5DAAF42C-C4CE-4631-A6E3-A5A5C1D0143A@gmail.com>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com> <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com>
To: Joel Alwen <jalwen@wickr.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/FJ3gdPFV1K50-1rGEvIWDPaHlR0>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 16:29:57 -0000

Yes, the sender would have to find a =E2=80=9Cd=E2=80=99=E2=80=9D such =
that HKDF(sksize, d', "", "derive UPKE delta=E2=80=9D) falls in a small =
set of values.
This is a small risk, but it can be further reduced if we used epk in =
the derivation.
E.g. why not define:

d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D)

This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=99=
s old public key, which makes it harder for it to do malicious things.

-Karthik


> On 22 Oct 2019, at 17:05, Joel Alwen <jalwen@wickr.com> wrote:
>=20
> Good question!
>=20
> I'll see if I can think of anything intelligent to say about it. :-)
>=20
> But one thing that comes to mind is that the sender gets to choose =
"only" d', not d. Instead d :=3D HKDF(d') so to get d=3D0
> you'd have to first invert HKDF.
>=20
> - Joel
>=20
> On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:
>> Sorry if this is already in the paper, but a question.
>>=20
>>> - UPKE-Decrypt(sk, (c1, c2)):
>>> epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
>>> d' || m :=3D context.Open("", c2)
>>> d :=3D HKDF(sksize, d', "", "derive UPKE delta")
>>> sk' :=3D Mult(sk, d)
>>> return (m, sk=E2=80=99)
>>=20
>> I believe it is important for the recipient to do some validation =
before returning from UPKE-Decrypt.
>>=20
>> For example, what if the (malicious) sender set d to =E2=80=9C0=E2=80=9D=
 (whatever that means in the DH group).
>> This would mean that the resulting key sk=E2=80=99 becomes =E2=80=9C0=E2=
=80=9D too, hence a non-member has been able to force the recipient =
group=E2=80=99s private key to a particular value, which is not ideal.
>> What conditions should we add to avoid this kind of key-forcing =
attack from happening?
>>=20
>> -Karthik
>>=20
>>=20
>>=20
>>>=20
>>>=20
>>> References
>>> ----------
>>> [1] http:\\ia.cr\2019\1189.
>>>=20
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>=20
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


From nobody Tue Oct 22 10:45:25 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D84251200CD for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 10:45:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.423
X-Spam-Level: 
X-Spam-Status: No, score=-1.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.226, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 83U3IxOj6bvE for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 10:45:20 -0700 (PDT)
Received: from mail-io1-f46.google.com (mail-io1-f46.google.com [209.85.166.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DFE161200F3 for <mls@ietf.org>; Tue, 22 Oct 2019 10:45:19 -0700 (PDT)
Received: by mail-io1-f46.google.com with SMTP id p6so13275483iod.7 for <mls@ietf.org>; Tue, 22 Oct 2019 10:45:19 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=6M2QrLQvhdTxnmF2dKfPhQMxDDY16zfvpmzPAuX/B8o=; b=Rmz+OuCSekJkiVgmRawCq8rvKFkbbylhElGdYkKbA7SqP7esD+jiA268cI4CMmqH5b WgjMlpDNCQBc4ihUWOqu+NIyvc3c3MsF6E53lxMzL7u56CcipBmslc3RJW61ekGpwvKs BaRq23760AuA2e0+MSw7huwClZ//VGe3niscgy4LJN29z157NsiAfVS3/szWyMYy0Wdc 1lAcfKa+XIwipvWhU2XoaizWeoRRJszSZAAetZLkxR9cmJOV7aYAexCwuh5NFQ7AEF7/ BJzn9URsL39gsme5jvap19pVxuy3wF0oB5iSNE41Jbtuyuygtw/oFVFqWjvz1akBUV+V DqpQ==
X-Gm-Message-State: APjAAAUz/qRtjult4nWrKkr2E3SKlV1FkEFJKxr0ucWIasM6glxPd0Nr Aod/j8cfXi4/L9r2bBblRBMJewfldkFImqYm4yI=
X-Google-Smtp-Source: APXvYqwXmf/GcvXGzUr8qRuRqIsvTgr6UkSivIrz/Rt9TlwRrhWfnX9Mf1py0h0SO4Tm7Z+w6Ha010uwPq3pAT127Pk=
X-Received: by 2002:a05:6638:a0e:: with SMTP id 14mr4973938jan.4.1571766318700;  Tue, 22 Oct 2019 10:45:18 -0700 (PDT)
MIME-Version: 1.0
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com> <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com> <5DAAF42C-C4CE-4631-A6E3-A5A5C1D0143A@gmail.com>
In-Reply-To: <5DAAF42C-C4CE-4631-A6E3-A5A5C1D0143A@gmail.com>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Tue, 22 Oct 2019 13:45:08 -0400
Message-ID: <CAMvzKsg0895RkaffJA7ZMQxKUr3uF3w-FZ3=T40YUDZd8TkisQ@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000189a990595835d6f"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/oupc_z4dsIkIFt-5i_SvP4HPVC4>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 17:45:22 -0000

--000000000000189a990595835d6f
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Good point, Karthik, we should definitely add this check (and possibly
something else).

As a small theoretical note, in our current model the users are considered
honest rather than malicious.
However, to model and prevent double-join attacks, the attacker is allowed
to request honest people not
to erase their local randomness (e.g., things like d' used above). So this
is why in our current description
we do not have to explicitly worry about d' being malicious.

We are pretty sure that with a check like the one you suggest we can also
withstand adversarial randomness
for UPKE. But we did not explore this yet - it is on the next to-do list.
In general, we don't consider too many insider
attacks (beside double join) for now, since TreeKEM and variants are not
secure against them anyway. Great
direction for the future.

Yevgeniy

On Tue, Oct 22, 2019 at 12:30 PM Karthikeyan Bhargavan <
karthik.bhargavan@gmail.com> wrote:

> Yes, the sender would have to find a =E2=80=9Cd=E2=80=99=E2=80=9D such th=
at HKDF(sksize, d', "",
> "derive UPKE delta=E2=80=9D) falls in a small set of values.
> This is a small risk, but it can be further reduced if we used epk in the
> derivation.
> E.g. why not define:
>
> d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D)
>
> This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=
=99s old public
> key, which makes it harder for it to do malicious things.
>
> -Karthik
>
>
> > On 22 Oct 2019, at 17:05, Joel Alwen <jalwen@wickr.com> wrote:
> >
> > Good question!
> >
> > I'll see if I can think of anything intelligent to say about it. :-)
> >
> > But one thing that comes to mind is that the sender gets to choose
> "only" d', not d. Instead d :=3D HKDF(d') so to get d=3D0
> > you'd have to first invert HKDF.
> >
> > - Joel
> >
> > On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:
> >> Sorry if this is already in the paper, but a question.
> >>
> >>> - UPKE-Decrypt(sk, (c1, c2)):
> >>> epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
> >>> d' || m :=3D context.Open("", c2)
> >>> d :=3D HKDF(sksize, d', "", "derive UPKE delta")
> >>> sk' :=3D Mult(sk, d)
> >>> return (m, sk=E2=80=99)
> >>
> >> I believe it is important for the recipient to do some validation
> before returning from UPKE-Decrypt.
> >>
> >> For example, what if the (malicious) sender set d to =E2=80=9C0=E2=80=
=9D (whatever that
> means in the DH group).
> >> This would mean that the resulting key sk=E2=80=99 becomes =E2=80=9C0=
=E2=80=9D too, hence a
> non-member has been able to force the recipient group=E2=80=99s private k=
ey to a
> particular value, which is not ideal.
> >> What conditions should we add to avoid this kind of key-forcing attack
> from happening?
> >>
> >> -Karthik
> >>
> >>
> >>
> >>>
> >>>
> >>> References
> >>> ----------
> >>> [1] http:\\ia.cr\2019\1189.
> >>>
> >>> _______________________________________________
> >>> MLS mailing list
> >>> MLS@ietf.org
> >>> https://www.ietf.org/mailman/listinfo/mls
> >>
> >
> > _______________________________________________
> > MLS mailing list
> > MLS@ietf.org
> > https://www.ietf.org/mailman/listinfo/mls
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000189a990595835d6f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Good point, Karthik, we should definitely add this check (=
and possibly something else).<div><br></div><div>As a small theoretical not=
e, in our current model the users are considered honest rather than malicio=
us.</div><div>However, to model and prevent double-join attacks, the attack=
er is allowed to request honest=C2=A0people not</div><div>to erase their lo=
cal randomness (e.g., things like d&#39; used above). So this is why in our=
 current description</div><div>we do not have to explicitly worry about d&#=
39; being malicious.</div><div><br></div><div>We are pretty sure that with =
a check like the one you suggest we can also withstand adversarial randomne=
ss</div><div>for UPKE. But we did not explore this yet - it is on the next =
to-do list. In general, we don&#39;t consider too many insider</div><div>at=
tacks (beside double join) for now, since TreeKEM and variants are not secu=
re against them anyway. Great=C2=A0</div><div>direction for the future.</di=
v><div><br></div><div>Yevgeniy</div></div><br><div class=3D"gmail_quote"><d=
iv dir=3D"ltr" class=3D"gmail_attr">On Tue, Oct 22, 2019 at 12:30 PM Karthi=
keyan Bhargavan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com">karthik.=
bhargavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex">Yes, the sender would have to find a =E2=80=9Cd=E2=80=99=
=E2=80=9D such that HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive UPKE de=
lta=E2=80=9D) falls in a small set of values.<br>
This is a small risk, but it can be further reduced if we used epk in the d=
erivation.<br>
E.g. why not define:<br>
<br>
d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D)<b=
r>
<br>
This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=99s=
 old public key, which makes it harder for it to do malicious things.<br>
<br>
-Karthik<br>
<br>
<br>
&gt; On 22 Oct 2019, at 17:05, Joel Alwen &lt;<a href=3D"mailto:jalwen@wick=
r.com" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:<br>
&gt; <br>
&gt; Good question!<br>
&gt; <br>
&gt; I&#39;ll see if I can think of anything intelligent to say about it. :=
-)<br>
&gt; <br>
&gt; But one thing that comes to mind is that the sender gets to choose &qu=
ot;only&quot; d&#39;, not d. Instead d :=3D HKDF(d&#39;) so to get d=3D0<br=
>
&gt; you&#39;d have to first invert HKDF.<br>
&gt; <br>
&gt; - Joel<br>
&gt; <br>
&gt; On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:<br>
&gt;&gt; Sorry if this is already in the paper, but a question.<br>
&gt;&gt; <br>
&gt;&gt;&gt; - UPKE-Decrypt(sk, (c1, c2)):<br>
&gt;&gt;&gt; epk, context :=3D HPKE.SetupBaseR(c1, sk, &quot;&quot;)<br>
&gt;&gt;&gt; d&#39; || m :=3D context.Open(&quot;&quot;, c2)<br>
&gt;&gt;&gt; d :=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive UPKE de=
lta&quot;)<br>
&gt;&gt;&gt; sk&#39; :=3D Mult(sk, d)<br>
&gt;&gt;&gt; return (m, sk=E2=80=99)<br>
&gt;&gt; <br>
&gt;&gt; I believe it is important for the recipient to do some validation =
before returning from UPKE-Decrypt.<br>
&gt;&gt; <br>
&gt;&gt; For example, what if the (malicious) sender set d to =E2=80=9C0=E2=
=80=9D (whatever that means in the DH group).<br>
&gt;&gt; This would mean that the resulting key sk=E2=80=99 becomes =E2=80=
=9C0=E2=80=9D too, hence a non-member has been able to force the recipient =
group=E2=80=99s private key to a particular value, which is not ideal.<br>
&gt;&gt; What conditions should we add to avoid this kind of key-forcing at=
tack from happening?<br>
&gt;&gt; <br>
&gt;&gt; -Karthik<br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; References<br>
&gt;&gt;&gt; ----------<br>
&gt;&gt;&gt; [1] http:\\<a href=3D"http://ia.cr" rel=3D"noreferrer" target=
=3D"_blank">ia.cr</a>\2019\1189.<br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; _______________________________________________<br>
&gt;&gt;&gt; MLS mailing list<br>
&gt;&gt;&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org=
</a><br>
&gt;&gt;&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"n=
oreferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><=
br>
&gt;&gt; <br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; MLS mailing list<br>
&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--000000000000189a990595835d6f--


From nobody Tue Oct 22 11:42:53 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBDE2120918 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 11:42:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PJddlnvLyLoJ for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 11:42:48 -0700 (PDT)
Received: from mail-wm1-x32a.google.com (mail-wm1-x32a.google.com [IPv6:2a00:1450:4864:20::32a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A4FC1120913 for <mls@ietf.org>; Tue, 22 Oct 2019 11:42:47 -0700 (PDT)
Received: by mail-wm1-x32a.google.com with SMTP id 3so17166756wmi.3 for <mls@ietf.org>; Tue, 22 Oct 2019 11:42:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=qqYqLW10Y5wyM+sr+qq5f2evRW6Gx7jFf5/ncFmoOPM=; b=q0pfGQE4gWyXC2yYz9Ro7x1yRdhU6xCSAkIXvuqS+mqJBWMCtvygl7ITtIBwy4Uij6 Yq8qn4z/ev28cxGb6kmjBB4rnEQusqwrgwOtvpiDREs8V0QHrH6lv0BS1deoK0sI1CVe ihjOYEcd3XPWCrEX8XQwRM6KGG2GK/IHQPYWVDZNq+YAEluhnf44cmLb5WCWZ6cyrodE dKtjaOALaTIfKO9tTH4RbkubSbQasY7bVFtUN+lXviC4PmVcbjKJN7L0uK0JLVtCp/Mz qe7pNAAq7UYZFRemEFtNkyuBLuzdIfcdiDT7HLhsKSDyN50Q8DT6tJur6a/zUUGnoGgn jYTA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=qqYqLW10Y5wyM+sr+qq5f2evRW6Gx7jFf5/ncFmoOPM=; b=SwW9nMxF4MoAUw+pcYcrhMyEF1L4nIAITYtHdbdZlCLNB7389gmSYHJ2sVpCmhKcDd 2e/UEUQ9MJ4LI/+0x0iz/32ot4xuew8uHR3IonVuOtlNM23Njd+0mDnwzh7ubSiZSavr GCKJqQlEqQi9Q4PmDnlNlXbCf6D7KCFTnKs87YMdn/eNqudH8tDWIXiA3gg+djxxNc/V PGnlh7jDRIVD+tpb10oPqaSwMro5UTC4cF13GG9XcQOaUNVTdkrYO2jDNfrtsteSpob+ WeDdXh4wDYr2jEXXZrKvppExT1q4ClgqoB5iW4PzrnpfkIHvJXJcL50z1bABz243ypGt U0Sw==
X-Gm-Message-State: APjAAAUxpXibUuRaXBKFY8pjjA7R7Fhjghi/csJQwtKw7OrLtnKpclyU 8S0Rxrh6QaadNqgzOANQZXzPicXgsR4=
X-Google-Smtp-Source: APXvYqzH+ZsCnANmmLFDmbmiqSiYRkGPkZlaEQHVj/Gs9xARXA505zsMsMS61pk5xunja92HwKhzWg==
X-Received: by 2002:a1c:f714:: with SMTP id v20mr4404129wmh.55.1571769765776;  Tue, 22 Oct 2019 11:42:45 -0700 (PDT)
Received: from [192.168.0.62] (89-156-101-160.rev.numericable.fr. [89.156.101.160]) by smtp.gmail.com with ESMTPSA id d8sm5973809wrr.71.2019.10.22.11.42.44 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 11:42:45 -0700 (PDT)
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Message-Id: <16FB72F8-FBAF-4600-8CCE-0C17C3BA8B2A@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_87213DAA-37E5-4352-85E5-B2516CAEED99"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Tue, 22 Oct 2019 20:42:42 +0200
In-Reply-To: <CAMvzKsg0895RkaffJA7ZMQxKUr3uF3w-FZ3=T40YUDZd8TkisQ@mail.gmail.com>
Cc: Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
To: Yevgeniy Dodis <dodis@cs.nyu.edu>
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com> <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com> <5DAAF42C-C4CE-4631-A6E3-A5A5C1D0143A@gmail.com> <CAMvzKsg0895RkaffJA7ZMQxKUr3uF3w-FZ3=T40YUDZd8TkisQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/CWzRz2HfONaHZVUbxTKeei7fvE8>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 18:42:51 -0000

--Apple-Mail=_87213DAA-37E5-4352-85E5-B2516CAEED99
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Yevgeniy,

Thanks for the clarification,

We have been formally analyzing TreeKEM against malicious insiders and =
it actually has some nice invariants.

In particular: the secret (and private key) for each node is only =
determined by the members of the
subtree rooted at that node. So if one of these subgroup members is =
malicious, it can of course
set the subgroup key to whatever it likes. But outsiders do not have the =
ability to influence a subgroup=E2=80=99s keys.
(There is an exception to this rule for late joiners, making the =
invariant a bit more complicated than the one I have informally stated =
here.)

I believe this agains-outsiders guarantee is a good invariant to have, =
and some of my questions about UPKE were in order to see how we could =
keep a version of this invariant.

Best,
Karthik



> On 22 Oct 2019, at 19:45, Yevgeniy Dodis <dodis@cs.nyu.edu> wrote:
>=20
> Good point, Karthik, we should definitely add this check (and possibly =
something else).
>=20
> As a small theoretical note, in our current model the users are =
considered honest rather than malicious.
> However, to model and prevent double-join attacks, the attacker is =
allowed to request honest people not
> to erase their local randomness (e.g., things like d' used above). So =
this is why in our current description
> we do not have to explicitly worry about d' being malicious.
>=20
> We are pretty sure that with a check like the one you suggest we can =
also withstand adversarial randomness
> for UPKE. But we did not explore this yet - it is on the next to-do =
list. In general, we don't consider too many insider
> attacks (beside double join) for now, since TreeKEM and variants are =
not secure against them anyway. Great=20
> direction for the future.
>=20
> Yevgeniy
>=20
> On Tue, Oct 22, 2019 at 12:30 PM Karthikeyan Bhargavan =
<karthik.bhargavan@gmail.com <mailto:karthik.bhargavan@gmail.com>> =
wrote:
> Yes, the sender would have to find a =E2=80=9Cd=E2=80=99=E2=80=9D such =
that HKDF(sksize, d', "", "derive UPKE delta=E2=80=9D) falls in a small =
set of values.
> This is a small risk, but it can be further reduced if we used epk in =
the derivation.
> E.g. why not define:
>=20
> d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D=
)
>=20
> This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=99=
s old public key, which makes it harder for it to do malicious things.
>=20
> -Karthik
>=20
>=20
> > On 22 Oct 2019, at 17:05, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
> >=20
> > Good question!
> >=20
> > I'll see if I can think of anything intelligent to say about it. :-)
> >=20
> > But one thing that comes to mind is that the sender gets to choose =
"only" d', not d. Instead d :=3D HKDF(d') so to get d=3D0
> > you'd have to first invert HKDF.
> >=20
> > - Joel
> >=20
> > On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:
> >> Sorry if this is already in the paper, but a question.
> >>=20
> >>> - UPKE-Decrypt(sk, (c1, c2)):
> >>> epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
> >>> d' || m :=3D context.Open("", c2)
> >>> d :=3D HKDF(sksize, d', "", "derive UPKE delta")
> >>> sk' :=3D Mult(sk, d)
> >>> return (m, sk=E2=80=99)
> >>=20
> >> I believe it is important for the recipient to do some validation =
before returning from UPKE-Decrypt.
> >>=20
> >> For example, what if the (malicious) sender set d to =E2=80=9C0=E2=80=
=9D (whatever that means in the DH group).
> >> This would mean that the resulting key sk=E2=80=99 becomes =E2=80=9C0=
=E2=80=9D too, hence a non-member has been able to force the recipient =
group=E2=80=99s private key to a particular value, which is not ideal.
> >> What conditions should we add to avoid this kind of key-forcing =
attack from happening?
> >>=20
> >> -Karthik
> >>=20
> >>=20
> >>=20
> >>>=20
> >>>=20
> >>> References
> >>> ----------
> >>> [1] http:\\ia.cr <http://ia.cr/>\2019\1189.
> >>>=20
> >>> _______________________________________________
> >>> MLS mailing list
> >>> MLS@ietf.org <mailto:MLS@ietf.org>
> >>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> >>=20
> >=20
> > _______________________________________________
> > MLS mailing list
> > MLS@ietf.org <mailto:MLS@ietf.org>
> > https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>


--Apple-Mail=_87213DAA-37E5-4352-85E5-B2516CAEED99
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Yevgeniy,<div class=3D""><br class=3D""></div><div class=3D"">Thanks for =
the clarification,</div><div class=3D""><br class=3D""></div><div =
class=3D"">We have been formally analyzing TreeKEM against malicious =
insiders and it actually has some nice invariants.</div><div =
class=3D""><br class=3D""></div><div class=3D"">In particular: the =
secret (and private key) for each node is only determined by the members =
of the</div><div class=3D"">subtree rooted at that node. So if one of =
these subgroup members is malicious, it can of course</div><div =
class=3D"">set the subgroup key to whatever it likes. But outsiders do =
not have the ability to influence a subgroup=E2=80=99s keys.</div><div =
class=3D"">(There is an exception to this rule for late joiners, making =
the invariant a bit more complicated than the one I have informally =
stated here.)</div><div class=3D""><br class=3D""></div><div class=3D"">I =
believe this agains-outsiders guarantee is a good invariant to have, and =
some of my questions about UPKE were in order to see how we could keep a =
version of this invariant.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><div class=3D""><br =
class=3D""></div><div class=3D""><br class=3D""><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On 22 =
Oct 2019, at 19:45, Yevgeniy Dodis &lt;<a href=3D"mailto:dodis@cs.nyu.edu"=
 class=3D"">dodis@cs.nyu.edu</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D"">Good point, Karthik, we should definitely add this check (and =
possibly something else).<div class=3D""><br class=3D""></div><div =
class=3D"">As a small theoretical note, in our current model the users =
are considered honest rather than malicious.</div><div class=3D"">However,=
 to model and prevent double-join attacks, the attacker is allowed to =
request honest&nbsp;people not</div><div class=3D"">to erase their local =
randomness (e.g., things like d' used above). So this is why in our =
current description</div><div class=3D"">we do not have to explicitly =
worry about d' being malicious.</div><div class=3D""><br =
class=3D""></div><div class=3D"">We are pretty sure that with a check =
like the one you suggest we can also withstand adversarial =
randomness</div><div class=3D"">for UPKE. But we did not explore this =
yet - it is on the next to-do list. In general, we don't consider too =
many insider</div><div class=3D"">attacks (beside double join) for now, =
since TreeKEM and variants are not secure against them anyway. =
Great&nbsp;</div><div class=3D"">direction for the future.</div><div =
class=3D""><br class=3D""></div><div class=3D"">Yevgeniy</div></div><br =
class=3D""><div class=3D"gmail_quote"><div dir=3D"ltr" =
class=3D"gmail_attr">On Tue, Oct 22, 2019 at 12:30 PM Karthikeyan =
Bhargavan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com" =
class=3D"">karthik.bhargavan@gmail.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex">Yes, the sender would have to find a =
=E2=80=9Cd=E2=80=99=E2=80=9D such that HKDF(sksize, d', "", "derive UPKE =
delta=E2=80=9D) falls in a small set of values.<br class=3D"">
This is a small risk, but it can be further reduced if we used epk in =
the derivation.<br class=3D"">
E.g. why not define:<br class=3D"">
<br class=3D"">
d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D)<=
br class=3D"">
<br class=3D"">
This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=99=
s old public key, which makes it harder for it to do malicious =
things.<br class=3D"">
<br class=3D"">
-Karthik<br class=3D"">
<br class=3D"">
<br class=3D"">
&gt; On 22 Oct 2019, at 17:05, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:<br class=3D"">
&gt; <br class=3D"">
&gt; Good question!<br class=3D"">
&gt; <br class=3D"">
&gt; I'll see if I can think of anything intelligent to say about it. =
:-)<br class=3D"">
&gt; <br class=3D"">
&gt; But one thing that comes to mind is that the sender gets to choose =
"only" d', not d. Instead d :=3D HKDF(d') so to get d=3D0<br class=3D"">
&gt; you'd have to first invert HKDF.<br class=3D"">
&gt; <br class=3D"">
&gt; - Joel<br class=3D"">
&gt; <br class=3D"">
&gt; On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:<br class=3D"">
&gt;&gt; Sorry if this is already in the paper, but a question.<br =
class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt;&gt; - UPKE-Decrypt(sk, (c1, c2)):<br class=3D"">
&gt;&gt;&gt; epk, context :=3D HPKE.SetupBaseR(c1, sk, "")<br class=3D"">
&gt;&gt;&gt; d' || m :=3D context.Open("", c2)<br class=3D"">
&gt;&gt;&gt; d :=3D HKDF(sksize, d', "", "derive UPKE delta")<br =
class=3D"">
&gt;&gt;&gt; sk' :=3D Mult(sk, d)<br class=3D"">
&gt;&gt;&gt; return (m, sk=E2=80=99)<br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt; I believe it is important for the recipient to do some =
validation before returning from UPKE-Decrypt.<br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt; For example, what if the (malicious) sender set d to =E2=80=9C0=E2=
=80=9D (whatever that means in the DH group).<br class=3D"">
&gt;&gt; This would mean that the resulting key sk=E2=80=99 becomes =
=E2=80=9C0=E2=80=9D too, hence a non-member has been able to force the =
recipient group=E2=80=99s private key to a particular value, which is =
not ideal.<br class=3D"">
&gt;&gt; What conditions should we add to avoid this kind of key-forcing =
attack from happening?<br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt; -Karthik<br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt; <br class=3D"">
&gt;&gt;&gt; <br class=3D"">
&gt;&gt;&gt; <br class=3D"">
&gt;&gt;&gt; References<br class=3D"">
&gt;&gt;&gt; ----------<br class=3D"">
&gt;&gt;&gt; [1] http:\\<a href=3D"http://ia.cr/" rel=3D"noreferrer" =
target=3D"_blank" class=3D"">ia.cr</a>\2019\1189.<br class=3D"">
&gt;&gt;&gt; <br class=3D"">
&gt;&gt;&gt; _______________________________________________<br =
class=3D"">
&gt;&gt;&gt; MLS mailing list<br class=3D"">
&gt;&gt;&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
&gt;&gt;&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" =
rel=3D"noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
&gt;&gt; <br class=3D"">
&gt; <br class=3D"">
&gt; _______________________________________________<br class=3D"">
&gt; MLS mailing list<br class=3D"">
&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" =
rel=3D"noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
<br class=3D"">
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div>
</div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_87213DAA-37E5-4352-85E5-B2516CAEED99--


From nobody Tue Oct 22 14:05:23 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 258CF12008D for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:05:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aLb3DXwcMKGs for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:05:20 -0700 (PDT)
Received: from mail-wm1-x335.google.com (mail-wm1-x335.google.com [IPv6:2a00:1450:4864:20::335]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB866120077 for <mls@ietf.org>; Tue, 22 Oct 2019 14:05:19 -0700 (PDT)
Received: by mail-wm1-x335.google.com with SMTP id f22so17500824wmc.2 for <mls@ietf.org>; Tue, 22 Oct 2019 14:05:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=YTze+rgmsITtLYLsgOApC0dyG9joyN86rFIP8S+XjgU=; b=A1gqTn0g0YRCc58qGgYXgCKWjx6PD8PZsHd1TlJSFJo/zdKpPtf1S8m0fhVpbmweJy mTxZ17IsmY/ffMhpPX8KWY5uOtgHeNaBAJXVNhdhklaTjU0cGvMGK+6B8mp8dmYcL3un yP9ok6AJ32DAEIRguY6BEajvlXbpKJoE4XKIZc9MNJAs5fIFuYErLzas3on7T/kXg5Mc p8BmjRThu2FmvuThZWG2Pdkv1kdQaxXw0LK0GcBlfWvJbYp/xhTF/6rVczj0uYORbRZe DivS7LK5LNgsezR5z5ugqRbAn4RrmlNjN7FZPQmsFtM+IQ9nFOzbnDEvG5FJCkNyYJQi wrXg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=YTze+rgmsITtLYLsgOApC0dyG9joyN86rFIP8S+XjgU=; b=Urk81ELZW4EnSd+WMAou6N9lKzAofqb3QTcikqIxMR3z/M3VOqt/NExtIvp16NKALl rqq88hCwQiBnfRUCGmIwUgzNUhWB02i9A/we5nYc+ZQOtETd8fJSVH4dWnhWnBM3xsI4 u8W9NIuXyOvAbwOZlM/3vLKz7XsHusZxjfyxzicJlICT/Ek+lCWGy4G5I/Gd1WkOx/Tm qhmS7/CocmrEu8YFO2wDGWekw84uKVlT64q2eZQxQOeH2K/38u+RIwAWJ2btcZN7Dp9N Heqnl128+6osLWpAN+DstjkcfVi2i0kM3muDjpcaQFSB75yPeOELkv61rPjvK7tJQhgL qW8g==
X-Gm-Message-State: APjAAAUflXgKKlMOdoUUlFFqpIQJ5go5TGwkK1Ui14P/u/ujgJlko6W8 n0ZwpeZOmIvgNCgfg3kqT8sJAUfiYdg=
X-Google-Smtp-Source: APXvYqyaiTkAvMcI42VDV50iNlGQg52lpUaC5mhMpwsqo76AcyQLaVQlB/2/tnu7KzVLRxdjxP8dyg==
X-Received: by 2002:a05:600c:2503:: with SMTP id d3mr5013154wma.44.1571778317750;  Tue, 22 Oct 2019 14:05:17 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id u68sm23677114wmu.12.2019.10.22.14.05.16 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 14:05:16 -0700 (PDT)
To: Brendan McMillion <brendan@cloudflare.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com>
Date: Tue, 22 Oct 2019 23:05:16 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/sqLTTz9sxdf2MAWJbaU_9Of359c>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 21:05:22 -0000

> RTreeKEM might get to a secure state faster but it's not that much faster, and it doesn't change the promises we can make to our users.

I'm curious what leads you to this conclusion. Suppose Alice produces an update defining new group key K. If the
adversary can't already process the update then with RTreeKEM we get FS for K once the update is processed by all
parties. For TreeKEM not only must that hold but we then need a further order n other parties to send out their own
updates too. At least in terms of # of message flows and total bandwidth (and, most likely, in terms of time) that gap
seems pretty big to me.

Moreover, to me this sounds like both a qualitative and quantitative change in the security promise. E.g.
  Quantitative: FS is achieved with fewer message flows & bandwidth.
  Qualitative : FS can be maintained even when there o(n*log(n)) bandwidth. Instead, O(log n) suffices.

> Having everybody send an ACK requires either quadratic bandwidth or trusting the server, which isn't worth it imo.

I dont follow. If I understood your earlier email correctly you said that updates in TreeKEM serve as a signal to others
guiding their update policy. All I was proposing was to use a much more lightweight ACK msg in exactly the same way you
thought updates were being used to guide policy.

Regardless, I don't really understand the problem here. RTreeKEM needs linear updates too for PCS. So people should
still be doing regular updates if they can afford to. That means if I don't see updates from Alice for a long time I'll
eventually want her removed from the group because she's harming the group's PCS. In other words, there's still reason
to do frequent updates which means they still serve as a signal that people are present. The main difference to me is
what we can say about time periods where we can't afford linear number of updates. For those cases RTreeKEM can still
give us FS but not TreeKEM.

- Joël


From nobody Tue Oct 22 14:20:45 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B3DE61200F5 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:20:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level: 
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xCwDsnNLlSdj for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:20:40 -0700 (PDT)
Received: from mail-oi1-x229.google.com (mail-oi1-x229.google.com [IPv6:2607:f8b0:4864:20::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9240212008D for <mls@ietf.org>; Tue, 22 Oct 2019 14:20:40 -0700 (PDT)
Received: by mail-oi1-x229.google.com with SMTP id o205so15475900oib.12 for <mls@ietf.org>; Tue, 22 Oct 2019 14:20:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=j+tyXaREkcjRb1FNJ8ezjrWQSEmY7ZowrQXZCr7pDxU=; b=Lt8GyZWNhUfPNQuhBhnqPB9TnhnFkOyY4ixkXPb4oQu+tl59BSVbdVxW4WH5HVxwkX Qj//wnoTL3LmImWaLoX91h7xfWJ5FXHLfkOMuFw+HYYUDHVZnKvdGwtuUx51Te8BW+FM lmJWKj25OFPLRGsoagUmIyeDbH35540x0VKF2ozg23wHxFoN2Z20ArwbOi+OEW32Ipah Q30PTnPqG+ZZ5CCX8MXbXUvRHR7e5hE2sqlpt+7fCiaTpZcywdmsEM14zBvuVf9ZjFpl BdPlMYWg2lpCfHxiVdmi0vW+zu08uznw5R/2WXW3oUgfCjz95dwrRYsfAtgkh+wgb0SS 1Rfw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=j+tyXaREkcjRb1FNJ8ezjrWQSEmY7ZowrQXZCr7pDxU=; b=DvgCgJiiYWFt979NeB4VPGsEwj8veKcXk9GDQU3q8ZJAEiZF6ltu+OyWktmFAOiYk6 I0aOPtG/+dz0z4/f9Q8HEQDjXLiODkUeqhHe1y8UwfGThEZskRJ9cjyyGNUflkPQSAhi TCTzzVtY+q31U7DeViXO/8kYk1Sa2QxpUhwq3ctGppPV8nkwVZ8RNv5+flZps8WoslNl KnKlalFWTEPckF7R4UtLc9zV+2LDFP+1jcuOtnncSS86BUxjq3l23dYMb+JuFZYxaFYU JWuVFRxVmn9KUuhinWxiRps8Y5EgJzUI+7zi+7jhd5BYGGyK5zgg4RM/9BLgZR+5nLXu 27LQ==
X-Gm-Message-State: APjAAAVYjsx3I5+vwSTe050PVvsYBZgg/y8BrKkOks7l3JzpmldYBsDT SdhbRxnloQAD00P/iisjcZt9tBWoKveH8MSGRAtMcA==
X-Google-Smtp-Source: APXvYqzt5QMDvUH481xLuswzIW8fawARpnvgR4F+ABCEnl2mJPs6f4ojN2fxtxXuXVUB6g8xLsURQh8qoAAZudm8jGg=
X-Received: by 2002:aca:56d6:: with SMTP id k205mr1516257oib.51.1571779239712;  Tue, 22 Oct 2019 14:20:39 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com> <CAMvzKsh-Vt3VeF3Jb37j39a=DNs5gFCR67eREAAZbBUvKxxY2A@mail.gmail.com>
In-Reply-To: <CAMvzKsh-Vt3VeF3Jb37j39a=DNs5gFCR67eREAAZbBUvKxxY2A@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Tue, 22 Oct 2019 17:20:19 -0400
Message-ID: <CAL02cgRO+Wdj41xoC7mJ9nQCGtmU8Uk3B3MRP-XkMs7faMPNpA@mail.gmail.com>
To: Yevgeniy Dodis <dodis@cs.nyu.edu>
Cc: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Messaging Layer Security WG <mls@ietf.org>, Joel Alwen <jalwen@wickr.com>
Content-Type: multipart/alternative; boundary="0000000000003fa2eb0595865f07"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/oDUPuiRMp6w_7m7XfGxHrICPdwI>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 21:20:44 -0000

--0000000000003fa2eb0595865f07
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Just so we're clear, I would be *strongly* opposed to putting anything like
this na=C3=AFve UPKE scheme into MLS.  For the simple reason that it expand=
s the
size of Welcome message by a factor of K.  RTreeKEM or nothing :)

--Richard


On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis <dodis@cs.nyu.edu> wrote:

> Great summary, Karthik!
>
> As I put in the other thread, comparison with the "naive" UPKE (for K=3D1=
00
> or less) might be a good idea.
>
> Pros of Naive Scheme:
> - more general, uses any PKE
> - using stream ciphers to generate K key pairs as needed makes the
> efficiency hit noticeably less than a factor of K,
> and perhaps closer to a factor of 2 (see below), but unclear a-priori.
> - for K>1, offers non-trivial (but still sub-optimal) security enhancemen=
t
> over basic TreeKEM (K=3D1)
>
> Cons (pros of RTreeKEM):
> - Public key storage increases by at least factor of K
> - While the naive use increases secret storage and computation by a facto=
r
> of K, using stream cipher, after i uses one can only store the
> current seed to generate last (K-i) keys. However, K public keys should b=
e
> published right away, so we must
> lose at least factor of 2 compared to TreeKEM to generate all keys twice
> (but possibly factor of K if people update too frequently, so all but
> 1 of the K keys gets used). So overall efficiency hit between 2 and K,
> which might already be comparable or worse than RTreeKEM.
> - Still much worse security than RTreeKEM, but possibly more expensive
> too, already for small K!
>
> Please let us know if you think this should be explored further.
> Yevgeniy
>
> On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan <
> karthik.bhargavan@gmail.com> wrote:
>
>> I see. So, here=E2=80=99s how I read the improvements proposed in RTreeK=
EM.
>>
>> Currently, in TreeKEM (like in ART before it) we rely on each member to
>> regularly *send* updates in order to get both PCS and FS for the group
>> secrets.
>> The informal secrecy guarantees we get are that:
>> - (FS) if member A sends an update in epoch N (moving the epoch to N+1),
>> and if A gets compromised in epoch N+1, the messages sent in epoch N rem=
ain
>> secret
>> - (PCS) if member A sends an update in epoch N (moving the epoch to N+1)=
,
>> and if A was (passively) compromised in epoch N, the messages sent in ep=
och
>> N+1 remain secret
>> In other words, each member who sends an update gets local protection
>> against compromise, encouraging vulnerable members to keep sending updat=
es.
>>
>> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we
>> could do better, at least for FS, if we use one-time decryption keys.
>> If each recipient deletes the old decryption key after processing an
>> update, then even just by *processing* an update, we get an additional
>>  guarantee:
>> - (FS=E2=80=99) if member A processes an update in epoch N (moving the e=
poch to
>> N+1), and if A gets compromised in epoch N+1, the messages sent in epoch=
 N
>> remain secret
>>
>> It is also worth remembering that Signal also has a notion of one-time
>> prekeys that work similarly for new messaging sessions.
>> Although the following would be a bit ridiculous to use in large dynamic
>> groups, here  is a sketch to achieve the receiver FS guarantee without t=
he
>> need for new crypto.
>> - Every time a member A sends an update, it generates fresh node secrets
>> for nodes on the path from A to the root
>> - From each node secret, A generates a large number K (=3D 100)
>> private-public encryption keypairs and sends the public keys with the
>> update.
>> - On receiving the update, each member B stores all K public keys for
>> each node in its co-path
>> - Each of these public keys can be used only once for sending an update,
>> after which the private key is deleted from all recipients.
>> - The last public key at each node is not deleted; it can only be
>> replaced when one of the members under that node sends a new update (wit=
h a
>> fresh batch of public keys)..
>>
>> As far as I understand, the above scheme can be seen as an (inefficient)
>> implementation of UPKE, right?
>> Of course, it increases the size of each update by K, and only provides
>> FS for K updates, after which some member has to send an update.
>> Conversely, it does not require any new crypto algorithm. Is this a good
>> baseline to compare UPKE schemes against?
>>
>> If I am mis-reading something, do let me know!
>>
>> -Karthik
>>
>>
>>
>>
>>
>>
>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com> wrote:
>>
>> I think the challenge with the hash-forward approach is how to do that
>> homomorphically. I.e. what we need are two algorithms; one to refresh
>> the PK without knowing the SK (but possibly knowing a secret
>> rerandomizer delta if needed) and one to update SK (again possibly using
>> delta). So to use a hash-forward approach their must be:
>>
>> 1) a way to evolve PK forward to PK' and
>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>
>> One-wayness is what gives us Forward Secrecy and "compatibility" between
>> the two key evolution methods is what allows for asynchronous (i.e. 1
>> packet) updates.
>>
>> Currently we use a secret re-randomizer delta to ensure the SK update
>> method is one-way. That is, without the delta you cant "undo" the
>> update. But that would break if we (at least naively) used some public
>> delta, say hash(ciphertext). So I think this is the challenge that we'd
>> have to overcome.. Basically, make sure we SK evolution is one-way but
>> also compatible the public evolution of PK.
>>
>>
>>
>> Now one way sweet way to get all this (and more) would be to use a HIBE.
>>
>> Initial, PK for a ratchet tree node (i.e. its "identity" since this is a
>> HIBE now) is simply the empty vector PK :=3D () while the secret key is
>> the master public key for a fresh HIBE instance SK :=3D MSK. We also
>> include, as a second component of the nodes PK, the master public key
>> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a cipherte=
xt
>> C to that node we can do:
>>
>> PK' :=3D (PK, hash(C)).
>> SK' :=3D DeriveHIBEKey(PK, SK).
>>
>> So simply append hash(C) to the identity for that node and derive the
>> corresponding HIBE key.
>>
>> Ignoring the problems with using HIBE for a second, this is a very cool
>> solution. We don't need to send out the updated PK since everyone in the
>> group (and even the adversary) can compute it for themselves. We also
>> dont need a re-randomize delta as part of the plaintext because we're
>> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
>> Moreover, HIBE security means that learning SK' doesn't tell you
>> anything interesting about SK. In particular, we have forward security.
>> (In fact, FS will hold even if hash(C) were chosen *completely*
>> adversarially, say, as part of a malicious update in an insider attack!)
>>
>> Of course, the problem with this solution is that we're using HIBE.
>> Worse, with unbounded depth because each new ciphertext sent to a node
>> results in going one depth further into the hierarchy. AFAIK all HIBE
>> constructions have pretty horrible (read exponential) efficiency as a
>> function of their depth. (And I won't mention the state of
>> standardization and open implementations for HIBE.)
>>
>> Now there could be a totally different approach that entirly avoids
>> HIBE. But even with this approach there's at least some glimer of hope
>> to improve on it because, if we don't wory about insider attacks we can
>> assume C is honestly generated which means hash(C) really has a ton of
>> entropy. So we dont seem to need the full expresivity HIBE identities
>> allow us. Rather we only need HIBE for "random" identities. Still, that
>> seems like a pretty slim hope for major efficiency improvement. It also
>> doesn't do anything to address the lack of implementations and standards=
.
>>
>> - Jo=C3=ABl
>>
>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>
>> Thanks Yevgeniy,
>>
>> This helps a lot.
>>
>> To further my understanding, another question:
>>
>>  Intuitively, the sender will not only encrypt the message, but also a
>> random Delta value. It will change public key using homomorthism by
>> multiplying with g^Delta (in specific DH based scheme), while the
>> recipient will decrypt Delta (using old secret key), and add it to the
>> old secret key to get there new one. So now corrupting (old sk plus
>> Delta) will not help decrypting the ciphertext just decepted, emailing
>> forward secrecy.
>>
>>
>> I see that in the DH-based scheme, this Delta needs to be private,
>> otherwise the adversary can compute sk once it knows sk+Delta.
>> But, in general, is it possible to conceive of a UPKE scheme where the
>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric key=
,
>> where this one way hash-forward function does not have to rely on an
>> externally chosen secret value?
>>
>> Best,
>> Karthik
>>
>> This is the high level, hope it makes sense.
>> Thanks for your question,
>> Yevgeniy
>>
>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>> <karthikeyan.bhargavan@inria.fr
>> <mailto:karthikeyan.bhargavan@inria.fr <karthikeyan.bhargavan@inria.fr>>=
>
>> wrote:
>>
>>    Hi Joel,
>>
>>    This looks very interesting. It is new to me since I was not at
>>    the interim.
>>    After reading the paper and the slides, I am still a bit fuzzy
>>    about what the recipient of an update needs to do.
>>
>>    For example, for the running example in your slide deck, it would
>>    help if I could see:
>>    - what secret keys does each leaf need to keep
>>    - how do these secrets change when an update from some other node
>>    is received.
>>    Just working this out for one update is enough.
>>
>>    I know that this is made precise in the eprint, but it would be
>>    faster if you could help us understand it :)
>>
>>    Best,
>>    Karthik
>>
>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>>
>>    <mailto:jalwen@wickr.com <jalwen@wickr.com>>> wrote:
>>
>>
>> <FS-TreeKEM.pdf>
>>
>>
>>    _______________________________________________
>>    MLS mailing list
>>    MLS@ietf.org <mailto:MLS@ietf.org <MLS@ietf.org>>
>>    https://www.ietf.org/mailman/listinfo/mls
>>
>>
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000003fa2eb0595865f07
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">Just so we&#39;re clear, I would be *stro=
ngly* opposed to putting anything like this na=C3=AFve UPKE scheme into MLS=
.=C2=A0 For the simple reason that it expands the size of Welcome message b=
y a factor of K.=C2=A0 RTreeKEM or nothing :)<br></div><div dir=3D"ltr"><br=
></div><div>--Richard</div><div><br></div><br><div class=3D"gmail_quote"><d=
iv dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct 21, 2019 at 6:53 PM Yevgeni=
y Dodis &lt;<a href=3D"mailto:dodis@cs.nyu.edu">dodis@cs.nyu.edu</a>&gt; wr=
ote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D=
"ltr">Great summary, Karthik!<div><br></div><div>As I put in the other thre=
ad, comparison with the &quot;naive&quot; UPKE (for K=3D100 or less) might =
be a good idea.</div><div><br></div><div>Pros of Naive Scheme:=C2=A0</div><=
div>- more general, uses any PKE</div><div>- using stream ciphers to genera=
te K key pairs as needed makes the efficiency hit noticeably less than a fa=
ctor of K,</div><div>and perhaps closer to a factor of 2 (see below), but u=
nclear a-priori.</div><div>- for K&gt;1, offers non-trivial (but still sub-=
optimal) security enhancement over basic TreeKEM (K=3D1)</div><div><br></di=
v><div>Cons (pros of RTreeKEM):</div><div>- Public key storage increases by=
 at least factor of K</div><div>- While the naive use increases secret stor=
age and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the=C2=A0</div><div>current seed to genera=
te last (K-i) keys. However, K public keys should=C2=A0be published right a=
way, so we must=C2=A0</div><div>lose at least factor of 2 compared to TreeK=
EM to generate all keys twice (but possibly factor of K if people update to=
o frequently, so all but=C2=A0</div><div>1 of the K keys gets used). So ove=
rall efficiency hit between 2 and K, which might already be comparable or w=
orse than RTreeKEM.</div><div>- Still much worse security than RTreeKEM, bu=
t possibly more expensive too, already for small K!</div><div><br></div><di=
v>Please let us know if you think this should be explored further.</div><di=
v>Yevgeniy</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<=
a href=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank">karthik.bha=
rgavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" =
style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pa=
dding-left:1ex"><div>I see. So, here=E2=80=99s how I read the improvements =
proposed in RTreeKEM.<div><br></div><div>Currently, in TreeKEM (like in ART=
 before it) we rely on each member to regularly *send* updates in order to =
get both PCS and FS for the group secrets.</div><div>The informal secrecy g=
uarantees we get are that:</div><div>- (FS) if member A sends an update in =
epoch N (moving the epoch to N+1), and if A gets compromised in epoch N+1, =
the messages sent in epoch N remain secret</div><div>- (PCS) if member A se=
nds an update in epoch N (moving the epoch to N+1), and if A was (passively=
) compromised in epoch N, the messages sent in epoch N+1 remain secret</div=
><div>In other words, each member who sends an update gets local protection=
 against compromise, encouraging vulnerable members to keep sending updates=
.</div><div><br></div><div>However, as Joel, Sandro, Yevgeniy, and Yiannis =
note in their paper, we could do better, at least for FS, if we use one-tim=
e decryption keys.</div><div>If each recipient deletes the old decryption k=
ey after processing an update, then even just by *processing* an update, we=
 get an additional =C2=A0guarantee:</div><div>- (FS=E2=80=99) if member A p=
rocesses an update in epoch N (moving the epoch to N+1), and if A gets comp=
romised in epoch N+1, the messages sent in epoch N remain secret</div><div>=
<br></div><div>It is also worth remembering that Signal also has a notion o=
f one-time prekeys that work similarly for new messaging sessions.</div><di=
v>Although the following would be a bit ridiculous to use in large dynamic =
groups, here =C2=A0is a sketch to achieve the receiver FS guarantee without=
 the need for new crypto.</div><div>- Every time a member A sends an update=
, it generates fresh node secrets for nodes on the path from A to the root<=
/div><div>- From each node secret, A generates a large number K (=3D 100) p=
rivate-public encryption keypairs and sends the public keys with the update=
.</div><div>- On receiving the update, each member B stores all K public ke=
ys for each node in its co-path</div><div>- Each of these public keys can b=
e used only once for sending an update, after which the private key is dele=
ted from all recipients.</div><div>- The last public key at each node is no=
t deleted; it can only be replaced when one of the members under that node =
sends a new update (with a fresh batch of public keys)..</div><div><br></di=
v><div>As far as I understand, the above scheme can be seen as an (ineffici=
ent) implementation of UPKE, right?</div><div>Of course, it increases the s=
ize of each update by K, and only provides FS for K updates, after which so=
me member has to send an update.</div><div>Conversely, it does not require =
any new crypto algorithm. Is this a good baseline to compare UPKE schemes a=
gainst?</div><div><br></div><div>If I am mis-reading something, do let me k=
now!</div><div><br></div><div>-Karthik</div><div><br></div><div><br></div><=
div><br></div><div><br></div><div><br></div><div><div><br><blockquote type=
=3D"cite"><div>On 17 Oct 2019, at 17:18, Joel Alwen &lt;<a href=3D"mailto:j=
alwen@wickr.com" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:</div><br=
><div><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal=
;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-ali=
gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none;float:none;display:inline">I think the challenge=
 with the hash-forward approach is how to do that</span><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none;float:none;display:inline">homomorphically. I.e. what=
 we need are two algorithms; one to refresh</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none;float:none;display:inline">the PK without knowing the SK (b=
ut possibly knowing a secret</span><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">rerandomizer delta if needed) and one to update=
 SK (again possibly using</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fam=
ily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;fl=
oat:none;display:inline">delta). So to use a hash-forward approach their mu=
st be:</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">1) a way to evolve PK forward to PK&#39; and</spa=
n><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none;float:none;display:inline">2) a =
*one-way* method to evolve SK forward to SK&#39; compatible PK&#39;.</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none;float:none;dis=
play:inline">One-wayness is what gives us Forward Secrecy and &quot;compati=
bility&quot; between</span><br style=3D"font-family:Helvetica;font-size:12p=
x;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spac=
ing:normal;text-align:start;text-indent:0px;text-transform:none;white-space=
:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:H=
elvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:n=
one;display:inline">the two key evolution methods is what allows for asynch=
ronous (i.e. 1</span><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">packet) updates.</span><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">Currently we use a secret=
 re-randomizer delta to ensure the SK update</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px;text-decoration:none"><spa=
n style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">method is one-way. That is, wit=
hout the delta you cant &quot;undo&quot; the</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px;text-decoration:none"><spa=
n style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">update. But that would break if=
 we (at least naively) used some public</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none;float:none;display:inline">delta, say hash(ciphertext). So I th=
ink this is the challenge that we&#39;d</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none;float:none;display:inline">have to overcome.. Basically, make s=
ure we SK evolution is one-way but</span><br style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norm=
al;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:no=
ne;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:n=
ormal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent=
:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoratio=
n:none;float:none;display:inline">also compatible the public evolution of P=
K.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:H=
elvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none"><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">Now one way s=
weet way to get all this (and more) would be to use a HIBE.</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:nor=
mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spa=
cing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inli=
ne">Initial, PK for a ratchet tree node (i.e. its &quot;identity&quot; sinc=
e this is a</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">HIBE now) is simply the empty vector PK :=3D () while the secret=
 key is</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">the master public key for a fresh HIBE instance SK :=3D MSK. We also=
</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;=
font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">=
include, as a second component of the nodes PK, the master public key</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">PK_0 =
=3D MPK. To &quot;hash forward&quot; / &quot;re-randomize&quot; when sendin=
g a ciphertext</span><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">C to that node we can do:</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none;float:none;display:inline">PK&#39; :=3D (PK=
, hash(C)).</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displ=
ay:inline">SK&#39; :=3D DeriveHIBEKey(PK, SK).</span><br style=3D"font-fami=
ly:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font=
-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">So simply=
 append hash(C) to the identity for that node and derive the</span><br styl=
e=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-ca=
ps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none;float:none;display:inline">corresponding H=
IBE key.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">Ignoring the problems with using HIBE for a sec=
ond, this is a very cool</span><br style=3D"font-family:Helvetica;font-size=
:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-=
spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-s=
pace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fami=
ly:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font=
-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none;flo=
at:none;display:inline">solution. We don&#39;t need to send out the updated=
 PK since everyone in the</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fam=
ily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;fl=
oat:none;display:inline">group (and even the adversary) can compute it for =
themselves. We also</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">dont need a re-randomize delta as part of the plaintext =
because we&#39;re</span><br style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none=
;display:inline">using delta :=3D hash(ciphertext) so the plaintext is shor=
ter again.</span><br style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displa=
y:inline">Moreover, HIBE security means that learning SK&#39; doesn&#39;t t=
ell you</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">anything interesting about SK. In particular, we have forward securi=
ty.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none;float:none;display:inlin=
e">(In fact, FS will hold even if hash(C) were chosen *completely*</span><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">adversari=
ally, say, as part of a malicious update in an insider attack!)</span><br s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant=
-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text=
-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:=
inline">Of course, the problem with this solution is that we&#39;re using H=
IBE.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:nor=
mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spa=
cing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inli=
ne">Worse, with unbounded depth because each new ciphertext sent to a node<=
/span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align=
:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:=
0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">r=
esults in going one depth further into the hierarchy. AFAIK all HIBE</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none;float:none;display:inline">constru=
ctions have pretty horrible (read exponential) efficiency as a</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">function of t=
heir depth. (And I won&#39;t mention the state of</span><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none;float:none;display:inline">standardization and open i=
mplementations for HIBE.)</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">Now there could be a totally d=
ifferent approach that entirly avoids</span><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:n=
ormal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">HIBE. But even with this approach ther=
e&#39;s at least some glimer of hope</span><br style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">to improve on it because, if we don&#3=
9;t wory about insider attacks we can</span><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:n=
ormal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">assume C is honestly generated which m=
eans hash(C) really has a ton of</span><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none;float:none;display:inline">entropy. So we dont seem to need the full e=
xpresivity HIBE identities</span><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">allow us. Rather we only need HIBE for &quot;rand=
om&quot; identities. Still, that</span><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:=
none;float:none;display:inline">seems like a pretty slim hope for major eff=
iciency improvement. It also</span><br style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">doesn&#39;t do anything to address the lack of =
implementations and standards.</span><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">- Jo=C3=ABl</span><br sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">On 17/10/2019 16:37, Karthik Bhargavan wrote:</span><br style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e"><blockquote type=3D"cite" style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none">Thanks Yevgeniy,<br><br>This h=
elps a lot.<br><br>To further my understanding, another question:<br><br><b=
lockquote type=3D"cite">=C2=A0Intuitively, the sender will not only encrypt=
 the message, but also a<br>random Delta value. It will change public key u=
sing homomorthism by<br>multiplying with g^Delta (in specific DH based sche=
me), while the<br>recipient will decrypt Delta (using old secret key), and =
add it to the<br>old secret key to get there new one. So now corrupting (ol=
d sk plus<br>Delta) will not help decrypting the ciphertext just decepted, =
emailing<br>forward secrecy.=C2=A0<br></blockquote><br>I see that in the DH=
-based scheme, this Delta needs to be private,<br>otherwise the adversary c=
an compute sk once it knows sk+Delta.<br>But, in general, is it possible to=
 conceive of a UPKE scheme where the<br>recipient effectively =E2=80=9Chash=
es forward=E2=80=9D its symmetric key,<br>where this one way hash-forward f=
unction does not have to rely on an<br>externally chosen secret value?<br><=
br>Best,<br>Karthik<br><br><blockquote type=3D"cite">This is the high level=
, hope it makes sense.<br>Thanks for your question,<br>Yevgeniy<br><br>On T=
hu, Oct 17, 2019, 1:43 AM Karthik Bhargavan<br>&lt;<a href=3D"mailto:karthi=
keyan.bhargavan@inria.fr" target=3D"_blank">karthikeyan.bhargavan@inria.fr<=
/a><br>&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_bla=
nk">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br><br>=C2=A0=
=C2=A0=C2=A0Hi Joel,<br><br>=C2=A0=C2=A0=C2=A0This looks very interesting. =
It is new to me since I was not at<br>=C2=A0=C2=A0=C2=A0the interim.<br>=C2=
=A0=C2=A0=C2=A0After reading the paper and the slides, I am still a bit fuz=
zy<br>=C2=A0=C2=A0=C2=A0about what the recipient of an update needs to do.<=
br><br>=C2=A0=C2=A0=C2=A0For example, for the running example in your slide=
 deck, it would<br>=C2=A0=C2=A0=C2=A0help if I could see:<br>=C2=A0=C2=A0=
=C2=A0- what secret keys does each leaf need to keep<br>=C2=A0=C2=A0=C2=A0-=
 how do these secrets change when an update from some other node<br>=C2=A0=
=C2=A0=C2=A0is received.<br>=C2=A0=C2=A0=C2=A0Just working this out for one=
 update is enough.<br><br>=C2=A0=C2=A0=C2=A0I know that this is made precis=
e in the eprint, but it would be<br>=C2=A0=C2=A0=C2=A0faster if you could h=
elp us understand it :)<br><br>=C2=A0=C2=A0=C2=A0Best,<br>=C2=A0=C2=A0=C2=
=A0Karthik<br><br><blockquote type=3D"cite">On 16 Oct 2019, at 23:51, Joel =
Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@wick=
r.com</a><br></blockquote>=C2=A0=C2=A0=C2=A0&lt;<a href=3D"mailto:jalwen@wi=
ckr.com" target=3D"_blank">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br><b=
lockquote type=3D"cite"><br>&lt;FS-TreeKEM.pdf&gt;<br></blockquote><br>=C2=
=A0=C2=A0=C2=A0_______________________________________________<br>=C2=A0=C2=
=A0=C2=A0MLS mailing list<br>=C2=A0=C2=A0=C2=A0<a href=3D"mailto:MLS@ietf.o=
rg" target=3D"_blank">MLS@ietf.org</a><span>=C2=A0</span>&lt;<a href=3D"mai=
lto:MLS@ietf.org" target=3D"_blank">mailto:MLS@ietf.org</a>&gt;<br>=C2=A0=
=C2=A0=C2=A0<a href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br><br></blockquote>=
<br><br>_______________________________________________<br>MLS mailing list=
<br><a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><=
a href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">http=
s://www.ietf.org/mailman/listinfo/mls</a><br><br></blockquote><br style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none;float:none;display:inline">____________________=
___________________________</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">MLS mailing list</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none"><a hr=
ef=3D"mailto:MLS@ietf.org" style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px" target=3D"_blank">MLS@ietf.org</a><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><a href=3D"https://www.ietf.org/mailman/listinfo/mls" style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px" target=3D"_blank">https:/=
/www.ietf.org/mailman/listinfo/mls</a></div></blockquote></div><br></div></=
div>_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div></div>

--0000000000003fa2eb0595865f07--


From nobody Tue Oct 22 14:26:36 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AFFC51200F5 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:26:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xO4gXlASks_y for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:26:31 -0700 (PDT)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com [IPv6:2a00:1450:4864:20::333]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91CB7120096 for <mls@ietf.org>; Tue, 22 Oct 2019 14:26:30 -0700 (PDT)
Received: by mail-wm1-x333.google.com with SMTP id c22so8423174wmd.1 for <mls@ietf.org>; Tue, 22 Oct 2019 14:26:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=J7wVzBbrA2FaShAgVGNDBcwFC83g7jWwWKqRMFu5tWo=; b=vTD77vg+3dJqWT70YBQxuy4JBbrmeNQ12EUK/SFlDPiSnQn0Dfh1LVpBlJeuCmSBDm 2ZpPy8WBEqRpcc64hc1VLDajC/zJ+g2iLBpHs52inwRM8h9ynDT1Rsdu5HxuVT6w8Og9 GwA36OTB8KgwPPxXCi1wgsBq83Z0QKOpizeBfUrawjzRVL5FRBBnSe24SQaFKzQp1cMd lyia7l0Z01ZXo3bCH88zrQR8ko+3LSmMtb6fpk3zisR28Wp8zGiYzmT1Lx7/F2hMe1h0 LN725zH4Ro7lfkzy6BB7djxuQ3dkXeS2hFu0Rfi5+o4Hf2ElNmWgflbsQ4fw3/P/lxnh ev+A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=J7wVzBbrA2FaShAgVGNDBcwFC83g7jWwWKqRMFu5tWo=; b=Liap4kNmbcbG+oN8GxcnLmq7d0nFhpT44N0vlvnr9+fphGl40nSnT76vG53HV0a08r 99z6X1wda1N7QlgDAHYMuhPEmASjMDODMt2PYhc3AgslWsfAU/LX5GhxLTzBweDSJkQq YWPbUYX1MTZom3xj20Is+NDie76zoq7O9R/yd4PYtgga75mRst1Yy9wYJAYN7F2ohtyO dBfKhzORr1viJkGG51O6BfKvAqApvrfv1P6ARiS7D/pv2SD3cU+r3LPsA0/JbAVcjuJ/ sq0V5qITaKnF83+VG0uK3YASokeczM9mrac1+pvnvrL/LFBBut52pfiA+VjxPSheBFeo pe3g==
X-Gm-Message-State: APjAAAVi/1GQqCLkYe6xysDwHz70nkWsUVh/RxwIUuf/CncYpG+Ii3ol uz0v5U0f6UIGE5sNgcAvfCo=
X-Google-Smtp-Source: APXvYqy5sxzVE6ToDYKbmDxWDDK5+muysgp0Al6kqgdwAQiMp6XJU3Fx97BJNoo1UlquY1rdUTPBjg==
X-Received: by 2002:a1c:2c88:: with SMTP id s130mr4993658wms.66.1571779588640;  Tue, 22 Oct 2019 14:26:28 -0700 (PDT)
Received: from [192.168.0.62] (89-156-101-160.rev.numericable.fr. [89.156.101.160]) by smtp.gmail.com with ESMTPSA id a3sm17342499wmc.3.2019.10.22.14.26.27 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Oct 2019 14:26:27 -0700 (PDT)
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Message-Id: <D47CF4DE-95F0-4C18-B2AF-934CA53607E3@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_32B02845-F0A9-486A-8E3B-C8A793480942"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Tue, 22 Oct 2019 23:26:26 +0200
In-Reply-To: <CAL02cgRO+Wdj41xoC7mJ9nQCGtmU8Uk3B3MRP-XkMs7faMPNpA@mail.gmail.com>
Cc: Yevgeniy Dodis <dodis@cs.nyu.edu>, Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
To: Richard Barnes <rlb@ipv.sx>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com> <CAMvzKsh-Vt3VeF3Jb37j39a=DNs5gFCR67eREAAZbBUvKxxY2A@mail.gmail.com> <CAL02cgRO+Wdj41xoC7mJ9nQCGtmU8Uk3B3MRP-XkMs7faMPNpA@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/V0HYByyZs68nlqT5AMIcZELryBI>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 21:26:35 -0000

--Apple-Mail=_32B02845-F0A9-486A-8E3B-C8A793480942
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Indeed!

Like I said, it would be a ridiculous design for MLS.
I was simply trying to understand the guarantees.

-Karthik

> On 22 Oct 2019, at 23:20, Richard Barnes <rlb@ipv.sx> wrote:
>=20
> Just so we're clear, I would be *strongly* opposed to putting anything =
like this na=C3=AFve UPKE scheme into MLS..  For the simple reason that =
it expands the size of Welcome message by a factor of K.  RTreeKEM or =
nothing :)
>=20
> --Richard
>=20
>=20
> On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis <dodis@cs.nyu.edu =
<mailto:dodis@cs.nyu.edu>> wrote:
> Great summary, Karthik!
>=20
> As I put in the other thread, comparison with the "naive" UPKE (for =
K=3D100 or less) might be a good idea.
>=20
> Pros of Naive Scheme:=20
> - more general, uses any PKE
> - using stream ciphers to generate K key pairs as needed makes the =
efficiency hit noticeably less than a factor of K,
> and perhaps closer to a factor of 2 (see below), but unclear a-priori.
> - for K>1, offers non-trivial (but still sub-optimal) security =
enhancement over basic TreeKEM (K=3D1)
>=20
> Cons (pros of RTreeKEM):
> - Public key storage increases by at least factor of K
> - While the naive use increases secret storage and computation by a =
factor of K, using stream cipher, after i uses one can only store the=20
> current seed to generate last (K-i) keys. However, K public keys =
should be published right away, so we must=20
> lose at least factor of 2 compared to TreeKEM to generate all keys =
twice (but possibly factor of K if people update too frequently, so all =
but=20
> 1 of the K keys gets used). So overall efficiency hit between 2 and K, =
which might already be comparable or worse than RTreeKEM.
> - Still much worse security than RTreeKEM, but possibly more expensive =
too, already for small K!
>=20
> Please let us know if you think this should be explored further.
> Yevgeniy
>=20
> On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan =
<karthik.bhargavan@gmail.com <mailto:karthik.bhargavan@gmail.com>> =
wrote:
> I see. So, here=E2=80=99s how I read the improvements proposed in =
RTreeKEM.
>=20
> Currently, in TreeKEM (like in ART before it) we rely on each member =
to regularly *send* updates in order to get both PCS and FS for the =
group secrets.
> The informal secrecy guarantees we get are that:
> - (FS) if member A sends an update in epoch N (moving the epoch to =
N+1), and if A gets compromised in epoch N+1, the messages sent in epoch =
N remain secret
> - (PCS) if member A sends an update in epoch N (moving the epoch to =
N+1), and if A was (passively) compromised in epoch N, the messages sent =
in epoch N+1 remain secret
> In other words, each member who sends an update gets local protection =
against compromise, encouraging vulnerable members to keep sending =
updates..
>=20
> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, =
we could do better, at least for FS, if we use one-time decryption keys.
> If each recipient deletes the old decryption key after processing an =
update, then even just by *processing* an update, we get an additional  =
guarantee:
> - (FS=E2=80=99) if member A processes an update in epoch N (moving the =
epoch to N+1), and if A gets compromised in epoch N+1, the messages sent =
in epoch N remain secret
>=20
> It is also worth remembering that Signal also has a notion of one-time =
prekeys that work similarly for new messaging sessions.
> Although the following would be a bit ridiculous to use in large =
dynamic groups, here  is a sketch to achieve the receiver FS guarantee =
without the need for new crypto.
> - Every time a member A sends an update, it generates fresh node =
secrets for nodes on the path from A to the root
> - =46rom each node secret, A generates a large number K (=3D 100) =
private-public encryption keypairs and sends the public keys with the =
update..
> - On receiving the update, each member B stores all K public keys for =
each node in its co-path
> - Each of these public keys can be used only once for sending an =
update, after which the private key is deleted from all recipients.
> - The last public key at each node is not deleted; it can only be =
replaced when one of the members under that node sends a new update =
(with a fresh batch of public keys)..
>=20
> As far as I understand, the above scheme can be seen as an =
(inefficient) implementation of UPKE, right?
> Of course, it increases the size of each update by K, and only =
provides FS for K updates, after which some member has to send an =
update.
> Conversely, it does not require any new crypto algorithm. Is this a =
good baseline to compare UPKE schemes against?
>=20
> If I am mis-reading something, do let me know!
>=20
> -Karthik
>=20
>=20
>=20
>=20
>=20
>=20
>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
>>=20
>> I think the challenge with the hash-forward approach is how to do =
that
>> homomorphically. I.e. what we need are two algorithms; one to refresh
>> the PK without knowing the SK (but possibly knowing a secret
>> rerandomizer delta if needed) and one to update SK (again possibly =
using
>> delta). So to use a hash-forward approach their must be:
>>=20
>> 1) a way to evolve PK forward to PK' and
>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>=20
>> One-wayness is what gives us Forward Secrecy and "compatibility" =
between
>> the two key evolution methods is what allows for asynchronous (i.e. 1
>> packet) updates.
>>=20
>> Currently we use a secret re-randomizer delta to ensure the SK update
>> method is one-way. That is, without the delta you cant "undo" the
>> update. But that would break if we (at least naively) used some =
public
>> delta, say hash(ciphertext). So I think this is the challenge that =
we'd
>> have to overcome.. Basically, make sure we SK evolution is one-way =
but
>> also compatible the public evolution of PK.
>>=20
>>=20
>>=20
>> Now one way sweet way to get all this (and more) would be to use a =
HIBE.
>>=20
>> Initial, PK for a ratchet tree node (i.e. its "identity" since this =
is a
>> HIBE now) is simply the empty vector PK :=3D () while the secret key =
is
>> the master public key for a fresh HIBE instance SK :=3D MSK. We also
>> include, as a second component of the nodes PK, the master public key
>> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a =
ciphertext
>> C to that node we can do:
>>=20
>> PK' :=3D (PK, hash(C)).
>> SK' :=3D DeriveHIBEKey(PK, SK).
>>=20
>> So simply append hash(C) to the identity for that node and derive the
>> corresponding HIBE key.
>>=20
>> Ignoring the problems with using HIBE for a second, this is a very =
cool
>> solution. We don't need to send out the updated PK since everyone in =
the
>> group (and even the adversary) can compute it for themselves. We also
>> dont need a re-randomize delta as part of the plaintext because we're
>> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
>> Moreover, HIBE security means that learning SK' doesn't tell you
>> anything interesting about SK. In particular, we have forward =
security.
>> (In fact, FS will hold even if hash(C) were chosen *completely*
>> adversarially, say, as part of a malicious update in an insider =
attack!)
>>=20
>> Of course, the problem with this solution is that we're using HIBE.
>> Worse, with unbounded depth because each new ciphertext sent to a =
node
>> results in going one depth further into the hierarchy. AFAIK all HIBE
>> constructions have pretty horrible (read exponential) efficiency as a
>> function of their depth. (And I won't mention the state of
>> standardization and open implementations for HIBE.)
>>=20
>> Now there could be a totally different approach that entirly avoids
>> HIBE. But even with this approach there's at least some glimer of =
hope
>> to improve on it because, if we don't wory about insider attacks we =
can
>> assume C is honestly generated which means hash(C) really has a ton =
of
>> entropy. So we dont seem to need the full expresivity HIBE identities
>> allow us. Rather we only need HIBE for "random" identities. Still, =
that
>> seems like a pretty slim hope for major efficiency improvement. It =
also
>> doesn't do anything to address the lack of implementations and =
standards.
>>=20
>> - Jo=C3=ABl
>>=20
>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>> Thanks Yevgeniy,
>>>=20
>>> This helps a lot.
>>>=20
>>> To further my understanding, another question:
>>>=20
>>>>  Intuitively, the sender will not only encrypt the message, but =
also a
>>>> random Delta value. It will change public key using homomorthism by
>>>> multiplying with g^Delta (in specific DH based scheme), while the
>>>> recipient will decrypt Delta (using old secret key), and add it to =
the
>>>> old secret key to get there new one. So now corrupting (old sk plus
>>>> Delta) will not help decrypting the ciphertext just decepted, =
emailing
>>>> forward secrecy.=20
>>>=20
>>> I see that in the DH-based scheme, this Delta needs to be private,
>>> otherwise the adversary can compute sk once it knows sk+Delta.
>>> But, in general, is it possible to conceive of a UPKE scheme where =
the
>>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric =
key,
>>> where this one way hash-forward function does not have to rely on an
>>> externally chosen secret value?
>>>=20
>>> Best,
>>> Karthik
>>>=20
>>>> This is the high level, hope it makes sense.
>>>> Thanks for your question,
>>>> Yevgeniy
>>>>=20
>>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>>> <karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>
>>>> <mailto:karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>>> wrote:
>>>>=20
>>>>    Hi Joel,
>>>>=20
>>>>    This looks very interesting. It is new to me since I was not at
>>>>    the interim.
>>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>>    about what the recipient of an update needs to do.
>>>>=20
>>>>    For example, for the running example in your slide deck, it =
would
>>>>    help if I could see:
>>>>    - what secret keys does each leaf need to keep
>>>>    - how do these secrets change when an update from some other =
node
>>>>    is received.
>>>>    Just working this out for one update is enough.
>>>>=20
>>>>    I know that this is made precise in the eprint, but it would be
>>>>    faster if you could help us understand it :)
>>>>=20
>>>>    Best,
>>>>    Karthik
>>>>=20
>>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>
>>>>    <mailto:jalwen@wickr.com <mailto:jalwen@wickr.com>>> wrote:
>>>>>=20
>>>>> <FS-TreeKEM.pdf>
>>>>=20
>>>>    _______________________________________________
>>>>    MLS mailing list
>>>>    MLS@ietf.org <mailto:MLS@ietf.org> <mailto:MLS@ietf.org =
<mailto:MLS@ietf.org>>
>>>>    https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>>>=20
>>>=20
>>>=20
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>>=20
>>=20
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org <mailto:MLS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_32B02845-F0A9-486A-8E3B-C8A793480942
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Indeed!<div class=3D""><br class=3D""></div><div =
class=3D"">Like I said, it would be a ridiculous design for =
MLS.</div><div class=3D"">I was simply trying to understand the =
guarantees.</div><div class=3D""><br class=3D""></div><div =
class=3D"">-Karthik<br class=3D""><div><br class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D"">On 22 Oct 2019, at 23:20, =
Richard Barnes &lt;<a href=3D"mailto:rlb@ipv.sx" =
class=3D"">rlb@ipv.sx</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D""><div dir=3D"ltr" class=3D"">Just so we're clear, I would be =
*strongly* opposed to putting anything like this na=C3=AFve UPKE scheme =
into MLS..&nbsp; For the simple reason that it expands the size of =
Welcome message by a factor of K.&nbsp; RTreeKEM or nothing :)<br =
class=3D""></div><div dir=3D"ltr" class=3D""><br class=3D""></div><div =
class=3D"">--Richard</div><div class=3D""><br class=3D""></div><br =
class=3D""><div class=3D"gmail_quote"><div dir=3D"ltr" =
class=3D"gmail_attr">On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis =
&lt;<a href=3D"mailto:dodis@cs.nyu.edu" =
class=3D"">dodis@cs.nyu.edu</a>&gt; wrote:<br class=3D""></div><blockquote=
 class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px =
solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr" class=3D"">Great=
 summary, Karthik!<div class=3D""><br class=3D""></div><div class=3D"">As =
I put in the other thread, comparison with the "naive" UPKE (for K=3D100 =
or less) might be a good idea.</div><div class=3D""><br =
class=3D""></div><div class=3D"">Pros of Naive Scheme:&nbsp;</div><div =
class=3D"">- more general, uses any PKE</div><div class=3D"">- using =
stream ciphers to generate K key pairs as needed makes the efficiency =
hit noticeably less than a factor of K,</div><div class=3D"">and perhaps =
closer to a factor of 2 (see below), but unclear a-priori.</div><div =
class=3D"">- for K&gt;1, offers non-trivial (but still sub-optimal) =
security enhancement over basic TreeKEM (K=3D1)</div><div class=3D""><br =
class=3D""></div><div class=3D"">Cons (pros of RTreeKEM):</div><div =
class=3D"">- Public key storage increases by at least factor of =
K</div><div class=3D"">- While the naive use increases secret storage =
and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the&nbsp;</div><div class=3D"">current =
seed to generate last (K-i) keys. However, K public keys should&nbsp;be =
published right away, so we must&nbsp;</div><div class=3D"">lose at =
least factor of 2 compared to TreeKEM to generate all keys twice (but =
possibly factor of K if people update too frequently, so all =
but&nbsp;</div><div class=3D"">1 of the K keys gets used). So overall =
efficiency hit between 2 and K, which might already be comparable or =
worse than RTreeKEM.</div><div class=3D"">- Still much worse security =
than RTreeKEM, but possibly more expensive too, already for small =
K!</div><div class=3D""><br class=3D""></div><div class=3D"">Please let =
us know if you think this should be explored further.</div><div =
class=3D"">Yevgeniy</div></div><br class=3D""><div =
class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct =
21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<a =
href=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank" =
class=3D"">karthik.bhargavan@gmail.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex"><div class=3D"">I see. So, here=E2=80=99=
s how I read the improvements proposed in RTreeKEM.<div class=3D""><br =
class=3D""></div><div class=3D"">Currently, in TreeKEM (like in ART =
before it) we rely on each member to regularly *send* updates in order =
to get both PCS and FS for the group secrets.</div><div class=3D"">The =
informal secrecy guarantees we get are that:</div><div class=3D"">- (FS) =
if member A sends an update in epoch N (moving the epoch to N+1), and if =
A gets compromised in epoch N+1, the messages sent in epoch N remain =
secret</div><div class=3D"">- (PCS) if member A sends an update in epoch =
N (moving the epoch to N+1), and if A was (passively) compromised in =
epoch N, the messages sent in epoch N+1 remain secret</div><div =
class=3D"">In other words, each member who sends an update gets local =
protection against compromise, encouraging vulnerable members to keep =
sending updates..</div><div class=3D""><br class=3D""></div><div =
class=3D"">However, as Joel, Sandro, Yevgeniy, and Yiannis note in their =
paper, we could do better, at least for FS, if we use one-time =
decryption keys.</div><div class=3D"">If each recipient deletes the old =
decryption key after processing an update, then even just by =
*processing* an update, we get an additional &nbsp;guarantee:</div><div =
class=3D"">- (FS=E2=80=99) if member A processes an update in epoch N =
(moving the epoch to N+1), and if A gets compromised in epoch N+1, the =
messages sent in epoch N remain secret</div><div class=3D""><br =
class=3D""></div><div class=3D"">It is also worth remembering that =
Signal also has a notion of one-time prekeys that work similarly for new =
messaging sessions.</div><div class=3D"">Although the following would be =
a bit ridiculous to use in large dynamic groups, here &nbsp;is a sketch =
to achieve the receiver FS guarantee without the need for new =
crypto.</div><div class=3D"">- Every time a member A sends an update, it =
generates fresh node secrets for nodes on the path from A to the =
root</div><div class=3D"">- =46rom each node secret, A generates a large =
number K (=3D 100) private-public encryption keypairs and sends the =
public keys with the update..</div><div class=3D"">- On receiving the =
update, each member B stores all K public keys for each node in its =
co-path</div><div class=3D"">- Each of these public keys can be used =
only once for sending an update, after which the private key is deleted =
from all recipients.</div><div class=3D"">- The last public key at each =
node is not deleted; it can only be replaced when one of the members =
under that node sends a new update (with a fresh batch of public =
keys)..</div><div class=3D""><br class=3D""></div><div class=3D"">As far =
as I understand, the above scheme can be seen as an (inefficient) =
implementation of UPKE, right?</div><div class=3D"">Of course, it =
increases the size of each update by K, and only provides FS for K =
updates, after which some member has to send an update.</div><div =
class=3D"">Conversely, it does not require any new crypto algorithm. Is =
this a good baseline to compare UPKE schemes against?</div><div =
class=3D""><br class=3D""></div><div class=3D"">If I am mis-reading =
something, do let me know!</div><div class=3D""><br class=3D""></div><div =
class=3D"">-Karthik</div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><div class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On 17 Oct 2019, at 17:18, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:</div><br class=3D""><div =
class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">I think the =
challenge with the hash-forward approach is how to do that</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">homomorphically. =
I.e. what we need are two algorithms; one to refresh</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the PK without =
knowing the SK (but possibly knowing a secret</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">rerandomizer =
delta if needed) and one to update SK (again possibly using</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">delta). So to =
use a hash-forward approach their must be:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">1) a way to =
evolve PK forward to PK' and</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">2) a *one-way* =
method to evolve SK forward to SK' compatible PK'.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">One-wayness is =
what gives us Forward Secrecy and "compatibility" between</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the two key =
evolution methods is what allows for asynchronous (i.e. 1</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">packet) =
updates.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Currently we use =
a secret re-randomizer delta to ensure the SK update</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">method is =
one-way. That is, without the delta you cant "undo" the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">update. But that =
would break if we (at least naively) used some public</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">delta, say =
hash(ciphertext). So I think this is the challenge that we'd</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">have to =
overcome.. Basically, make sure we SK evolution is one-way but</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">also compatible =
the public evolution of PK.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Now one way =
sweet way to get all this (and more) would be to use a HIBE.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Initial, PK for =
a ratchet tree node (i.e. its "identity" since this is a</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">HIBE now) is =
simply the empty vector PK :=3D () while the secret key is</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the master =
public key for a fresh HIBE instance SK :=3D MSK. We also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">include, as a =
second component of the nodes PK, the master public key</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">PK_0 =3D MPK. To =
"hash forward" / "re-randomize" when sending a ciphertext</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">C to that node =
we can do:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">PK' :=3D (PK, =
hash(C)).</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">SK' :=3D =
DeriveHIBEKey(PK, SK).</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">So simply append =
hash(C) to the identity for that node and derive the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">corresponding =
HIBE key.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Ignoring the =
problems with using HIBE for a second, this is a very cool</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">solution. We =
don't need to send out the updated PK since everyone in the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">group (and even =
the adversary) can compute it for themselves. We also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">dont need a =
re-randomize delta as part of the plaintext because we're</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">using delta :=3D =
hash(ciphertext) so the plaintext is shorter again.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Moreover, HIBE =
security means that learning SK' doesn't tell you</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">anything =
interesting about SK. In particular, we have forward security.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">(In fact, FS =
will hold even if hash(C) were chosen *completely*</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">adversarially, =
say, as part of a malicious update in an insider attack!)</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Of course, the =
problem with this solution is that we're using HIBE.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Worse, with =
unbounded depth because each new ciphertext sent to a node</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">results in going =
one depth further into the hierarchy. AFAIK all HIBE</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">constructions =
have pretty horrible (read exponential) efficiency as a</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">function of =
their depth. (And I won't mention the state of</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">standardization =
and open implementations for HIBE.)</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Now there could =
be a totally different approach that entirly avoids</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">HIBE. But even =
with this approach there's at least some glimer of hope</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">to improve on it =
because, if we don't wory about insider attacks we can</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">assume C is =
honestly generated which means hash(C) really has a ton of</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">entropy. So we =
dont seem to need the full expresivity HIBE identities</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">allow us. Rather =
we only need HIBE for "random" identities. Still, that</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">seems like a =
pretty slim hope for major efficiency improvement. It also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">doesn't do =
anything to address the lack of implementations and standards.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">- =
Jo=C3=ABl</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">On 17/10/2019 =
16:37, Karthik Bhargavan wrote:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><blockquote type=3D"cite" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D"">Thanks Yevgeniy,<br class=3D""><br =
class=3D"">This helps a lot.<br class=3D""><br class=3D"">To further my =
understanding, another question:<br class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D"">&nbsp;Intuitively, the sender will not only =
encrypt the message, but also a<br class=3D"">random Delta value. It =
will change public key using homomorthism by<br class=3D"">multiplying =
with g^Delta (in specific DH based scheme), while the<br =
class=3D"">recipient will decrypt Delta (using old secret key), and add =
it to the<br class=3D"">old secret key to get there new one. So now =
corrupting (old sk plus<br class=3D"">Delta) will not help decrypting =
the ciphertext just decepted, emailing<br class=3D"">forward =
secrecy.&nbsp;<br class=3D""></blockquote><br class=3D"">I see that in =
the DH-based scheme, this Delta needs to be private,<br =
class=3D"">otherwise the adversary can compute sk once it knows =
sk+Delta.<br class=3D"">But, in general, is it possible to conceive of a =
UPKE scheme where the<br class=3D"">recipient effectively =E2=80=9Chashes =
forward=E2=80=9D its symmetric key,<br class=3D"">where this one way =
hash-forward function does not have to rely on an<br class=3D"">externally=
 chosen secret value?<br class=3D""><br class=3D"">Best,<br =
class=3D"">Karthik<br class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D"">This is the high level, hope it makes sense.<br =
class=3D"">Thanks for your question,<br class=3D"">Yevgeniy<br =
class=3D""><br class=3D"">On Thu, Oct 17, 2019, 1:43 AM Karthik =
Bhargavan<br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank" =
class=3D"">karthikeyan.bhargavan@inria.fr</a><br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank" =
class=3D"">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br =
class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Hi Joel,<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;This looks very interesting. It is new to =
me since I was not at<br class=3D"">&nbsp;&nbsp;&nbsp;the interim.<br =
class=3D"">&nbsp;&nbsp;&nbsp;After reading the paper and the slides, I =
am still a bit fuzzy<br class=3D"">&nbsp;&nbsp;&nbsp;about what the =
recipient of an update needs to do.<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;For example, for the running example in =
your slide deck, it would<br class=3D"">&nbsp;&nbsp;&nbsp;help if I =
could see:<br class=3D"">&nbsp;&nbsp;&nbsp;- what secret keys does each =
leaf need to keep<br class=3D"">&nbsp;&nbsp;&nbsp;- how do these secrets =
change when an update from some other node<br =
class=3D"">&nbsp;&nbsp;&nbsp;is received.<br =
class=3D"">&nbsp;&nbsp;&nbsp;Just working this out for one update is =
enough.<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;I know that this =
is made precise in the eprint, but it would be<br =
class=3D"">&nbsp;&nbsp;&nbsp;faster if you could help us understand it =
:)<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Best,<br =
class=3D"">&nbsp;&nbsp;&nbsp;Karthik<br class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D"">On 16 Oct 2019, at =
23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
target=3D"_blank" class=3D"">jalwen@wickr.com</a><br =
class=3D""></blockquote>&nbsp;&nbsp;&nbsp;&lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" =
class=3D"">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br =
class=3D""><blockquote type=3D"cite" class=3D""><br =
class=3D"">&lt;FS-TreeKEM.pdf&gt;<br class=3D""></blockquote><br =
class=3D"">&nbsp;&nbsp;&nbsp;_____________________________________________=
__<br class=3D"">&nbsp;&nbsp;&nbsp;MLS mailing list<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><span =
class=3D"">&nbsp;</span>&lt;<a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">mailto:MLS@ietf.org</a>&gt;<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">MLS mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" =
class=3D"">_______________________________________________</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">MLS mailing =
list</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><a href=3D"mailto:MLS@ietf.org" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a></div></blockquote=
></div><br =
class=3D""></div></div>_______________________________________________<br =
class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div>
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_32B02845-F0A9-486A-8E3B-C8A793480942--


From nobody Tue Oct 22 14:34:03 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 83D4C1200FD for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:34:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level: 
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BNremStDT6B9 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 14:33:58 -0700 (PDT)
Received: from mail-ot1-x332.google.com (mail-ot1-x332.google.com [IPv6:2607:f8b0:4864:20::332]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1E7B7120096 for <mls@ietf.org>; Tue, 22 Oct 2019 14:33:58 -0700 (PDT)
Received: by mail-ot1-x332.google.com with SMTP id 53so3939153otv.4 for <mls@ietf.org>; Tue, 22 Oct 2019 14:33:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=irD3trXMmS8EujHA6HOGT7vScqwVuA36Ma/ekSthCkM=; b=KF+ozqQCNH9Yi3j/xfD3zefFtHemeALHd0i1rZYuJ0It/FlTeRQlxWIko4sf3LlnMA JGHc8mp+uooEUwaS+fgay0332o2ok7x11j8S72UIOKQy8mfFz+ObkNzxXjvWOYkvPshd Z3WkDeqq/c0dXmQFonmDfsLZMp9J5EJqd/5l4/rUQJpuzQweceLO9Y8QlkuVKRfTFmRC G6C87E1DZ/r4l+gHnulx04K4voDqa6FzjX6L7973rEx28t5aePCNgl8zKUqCxWMvKsSY CY6hmOIv4oAr/U/cEaPljsoXfqkHkaRCSb4Nt5GzaD9wpcO9qyHayHx1TyY0GSzb5MQu RPPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=irD3trXMmS8EujHA6HOGT7vScqwVuA36Ma/ekSthCkM=; b=gAT0fDsO1WbaOY9eoPqrEvVir4Zcfd38vsWK858Jx8sItII3UTLfR6BH6TlvJy7syd A/kVSpMutqUFypInbZ17Fg8C6FbviV5sakC9+n8FP/AlGj07hut63ryxppKtocqm6CI5 QMC87tzhhuwruWLcbbJBYQv8RAETeKvUagpAPv2IIHhRsyD5k0vldMMPAJ/CQWf8KGAT FssjvY/ZwmqbFpi+ombhk6YJMjaTgmldiFbHNR7T0wO2b7vaY6gqdR6w25gAlzwzAMWJ 4YDFie1lRak9/rSxpuBDqv60oa5NbDMyCtAJYw6NmKa2dn34MzqgWZf6N+GgcGgpP44Y 0fTA==
X-Gm-Message-State: APjAAAVoz7Z6jRtHEbHa+EORRBVUOqP5P5B8nVwP6T5cMYOOjdr30Rpa gR9q+AmBo/1hTKIbGX5vgrHpAxixyXObGyNWM7o5eg==
X-Google-Smtp-Source: APXvYqyuF6PqxjcwlcwI22l/IDgK8PsjTH69cJATcX022t/KBRkCEDOhsh1Egtc+5UPRC8T91DK61k1qkQfu1pLl31c=
X-Received: by 2002:a05:6830:22f6:: with SMTP id t22mr4336800otc.237.1571780037039;  Tue, 22 Oct 2019 14:33:57 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <8E87A52E-62CB-4CC0-A715-F236B03AC9E1@gmail.com> <CAMvzKsh-Vt3VeF3Jb37j39a=DNs5gFCR67eREAAZbBUvKxxY2A@mail.gmail.com> <CAL02cgRO+Wdj41xoC7mJ9nQCGtmU8Uk3B3MRP-XkMs7faMPNpA@mail.gmail.com> <D47CF4DE-95F0-4C18-B2AF-934CA53607E3@gmail.com>
In-Reply-To: <D47CF4DE-95F0-4C18-B2AF-934CA53607E3@gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Tue, 22 Oct 2019 17:33:37 -0400
Message-ID: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Yevgeniy Dodis <dodis@cs.nyu.edu>, Joel Alwen <jalwen@wickr.com>,  Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c6423e0595868e93"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/ICPdO4HeJbOJakwGbV0VKFZGONc>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 21:34:02 -0000

--000000000000c6423e0595868e93
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Since it appears I haven't chimed in on this thread -- I am generally OK
with this change, if folks think it would improve the FS properties of the
protocol, and assuming that Jo=C3=ABl's / Mike's solution to the X25519 pro=
blem
works out.

On the one hand, if we have to shove X25519 overboard, my bias would
probably be against making this change, barring some really strong security
rationale.

On the other hand, if we can get confidence that the X25519 solution works
(or that the failures are rare and tolerable), then this seems like a
pretty minor burden from an engineering POV (a little more code, 2x the DH
operations on Update/Commit), so if there's security benefit, great.

On Tue, Oct 22, 2019 at 5:26 PM Karthikeyan Bhargavan <
karthik.bhargavan@gmail.com> wrote:

> Indeed!
>
> Like I said, it would be a ridiculous design for MLS.
> I was simply trying to understand the guarantees.
>
> -Karthik
>
> On 22 Oct 2019, at 23:20, Richard Barnes <rlb@ipv.sx> wrote:
>
> Just so we're clear, I would be *strongly* opposed to putting anything
> like this na=C3=AFve UPKE scheme into MLS..  For the simple reason that i=
t
> expands the size of Welcome message by a factor of K.  RTreeKEM or nothin=
g
> :)
>
> --Richard
>
>
> On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis <dodis@cs.nyu.edu> wrote:
>
>> Great summary, Karthik!
>>
>> As I put in the other thread, comparison with the "naive" UPKE (for K=3D=
100
>> or less) might be a good idea.
>>
>> Pros of Naive Scheme:
>> - more general, uses any PKE
>> - using stream ciphers to generate K key pairs as needed makes the
>> efficiency hit noticeably less than a factor of K,
>> and perhaps closer to a factor of 2 (see below), but unclear a-priori.
>> - for K>1, offers non-trivial (but still sub-optimal) security
>> enhancement over basic TreeKEM (K=3D1)
>>
>> Cons (pros of RTreeKEM):
>> - Public key storage increases by at least factor of K
>> - While the naive use increases secret storage and computation by a
>> factor of K, using stream cipher, after i uses one can only store the
>> current seed to generate last (K-i) keys. However, K public keys
>> should be published right away, so we must
>> lose at least factor of 2 compared to TreeKEM to generate all keys twice
>> (but possibly factor of K if people update too frequently, so all but
>> 1 of the K keys gets used). So overall efficiency hit between 2 and K,
>> which might already be comparable or worse than RTreeKEM.
>> - Still much worse security than RTreeKEM, but possibly more expensive
>> too, already for small K!
>>
>> Please let us know if you think this should be explored further.
>> Yevgeniy
>>
>> On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan <
>> karthik.bhargavan@gmail.com> wrote:
>>
>>> I see. So, here=E2=80=99s how I read the improvements proposed in RTree=
KEM.
>>>
>>> Currently, in TreeKEM (like in ART before it) we rely on each member to
>>> regularly *send* updates in order to get both PCS and FS for the group
>>> secrets.
>>> The informal secrecy guarantees we get are that:
>>> - (FS) if member A sends an update in epoch N (moving the epoch to N+1)=
,
>>> and if A gets compromised in epoch N+1, the messages sent in epoch N re=
main
>>> secret
>>> - (PCS) if member A sends an update in epoch N (moving the epoch to
>>> N+1), and if A was (passively) compromised in epoch N, the messages sen=
t in
>>> epoch N+1 remain secret
>>> In other words, each member who sends an update gets local protection
>>> against compromise, encouraging vulnerable members to keep sending upda=
tes..
>>>
>>> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we
>>> could do better, at least for FS, if we use one-time decryption keys.
>>> If each recipient deletes the old decryption key after processing an
>>> update, then even just by *processing* an update, we get an additional
>>>  guarantee:
>>> - (FS=E2=80=99) if member A processes an update in epoch N (moving the =
epoch to
>>> N+1), and if A gets compromised in epoch N+1, the messages sent in epoc=
h N
>>> remain secret
>>>
>>> It is also worth remembering that Signal also has a notion of one-time
>>> prekeys that work similarly for new messaging sessions.
>>> Although the following would be a bit ridiculous to use in large dynami=
c
>>> groups, here  is a sketch to achieve the receiver FS guarantee without =
the
>>> need for new crypto.
>>> - Every time a member A sends an update, it generates fresh node secret=
s
>>> for nodes on the path from A to the root
>>> - From each node secret, A generates a large number K (=3D 100)
>>> private-public encryption keypairs and sends the public keys with the
>>> update..
>>> - On receiving the update, each member B stores all K public keys for
>>> each node in its co-path
>>> - Each of these public keys can be used only once for sending an update=
,
>>> after which the private key is deleted from all recipients.
>>> - The last public key at each node is not deleted; it can only be
>>> replaced when one of the members under that node sends a new update (wi=
th a
>>> fresh batch of public keys)..
>>>
>>> As far as I understand, the above scheme can be seen as an (inefficient=
)
>>> implementation of UPKE, right?
>>> Of course, it increases the size of each update by K, and only provides
>>> FS for K updates, after which some member has to send an update.
>>> Conversely, it does not require any new crypto algorithm. Is this a goo=
d
>>> baseline to compare UPKE schemes against?
>>>
>>> If I am mis-reading something, do let me know!
>>>
>>> -Karthik
>>>
>>>
>>>
>>>
>>>
>>>
>>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com> wrote:
>>>
>>> I think the challenge with the hash-forward approach is how to do that
>>> homomorphically. I.e. what we need are two algorithms; one to refresh
>>> the PK without knowing the SK (but possibly knowing a secret
>>> rerandomizer delta if needed) and one to update SK (again possibly usin=
g
>>> delta). So to use a hash-forward approach their must be:
>>>
>>> 1) a way to evolve PK forward to PK' and
>>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>>
>>> One-wayness is what gives us Forward Secrecy and "compatibility" betwee=
n
>>> the two key evolution methods is what allows for asynchronous (i.e. 1
>>> packet) updates.
>>>
>>> Currently we use a secret re-randomizer delta to ensure the SK update
>>> method is one-way. That is, without the delta you cant "undo" the
>>> update. But that would break if we (at least naively) used some public
>>> delta, say hash(ciphertext). So I think this is the challenge that we'd
>>> have to overcome.. Basically, make sure we SK evolution is one-way but
>>> also compatible the public evolution of PK.
>>>
>>>
>>>
>>> Now one way sweet way to get all this (and more) would be to use a HIBE=
.
>>>
>>> Initial, PK for a ratchet tree node (i.e. its "identity" since this is =
a
>>> HIBE now) is simply the empty vector PK :=3D () while the secret key is
>>> the master public key for a fresh HIBE instance SK :=3D MSK. We also
>>> include, as a second component of the nodes PK, the master public key
>>> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a ciphert=
ext
>>> C to that node we can do:
>>>
>>> PK' :=3D (PK, hash(C)).
>>> SK' :=3D DeriveHIBEKey(PK, SK).
>>>
>>> So simply append hash(C) to the identity for that node and derive the
>>> corresponding HIBE key.
>>>
>>> Ignoring the problems with using HIBE for a second, this is a very cool
>>> solution. We don't need to send out the updated PK since everyone in th=
e
>>> group (and even the adversary) can compute it for themselves. We also
>>> dont need a re-randomize delta as part of the plaintext because we're
>>> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
>>> Moreover, HIBE security means that learning SK' doesn't tell you
>>> anything interesting about SK. In particular, we have forward security.
>>> (In fact, FS will hold even if hash(C) were chosen *completely*
>>> adversarially, say, as part of a malicious update in an insider attack!=
)
>>>
>>> Of course, the problem with this solution is that we're using HIBE.
>>> Worse, with unbounded depth because each new ciphertext sent to a node
>>> results in going one depth further into the hierarchy. AFAIK all HIBE
>>> constructions have pretty horrible (read exponential) efficiency as a
>>> function of their depth. (And I won't mention the state of
>>> standardization and open implementations for HIBE.)
>>>
>>> Now there could be a totally different approach that entirly avoids
>>> HIBE. But even with this approach there's at least some glimer of hope
>>> to improve on it because, if we don't wory about insider attacks we can
>>> assume C is honestly generated which means hash(C) really has a ton of
>>> entropy. So we dont seem to need the full expresivity HIBE identities
>>> allow us. Rather we only need HIBE for "random" identities. Still, that
>>> seems like a pretty slim hope for major efficiency improvement. It also
>>> doesn't do anything to address the lack of implementations and standard=
s.
>>>
>>> - Jo=C3=ABl
>>>
>>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>>
>>> Thanks Yevgeniy,
>>>
>>> This helps a lot.
>>>
>>> To further my understanding, another question:
>>>
>>>  Intuitively, the sender will not only encrypt the message, but also a
>>> random Delta value. It will change public key using homomorthism by
>>> multiplying with g^Delta (in specific DH based scheme), while the
>>> recipient will decrypt Delta (using old secret key), and add it to the
>>> old secret key to get there new one. So now corrupting (old sk plus
>>> Delta) will not help decrypting the ciphertext just decepted, emailing
>>> forward secrecy.
>>>
>>>
>>> I see that in the DH-based scheme, this Delta needs to be private,
>>> otherwise the adversary can compute sk once it knows sk+Delta.
>>> But, in general, is it possible to conceive of a UPKE scheme where the
>>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric ke=
y,
>>> where this one way hash-forward function does not have to rely on an
>>> externally chosen secret value?
>>>
>>> Best,
>>> Karthik
>>>
>>> This is the high level, hope it makes sense.
>>> Thanks for your question,
>>> Yevgeniy
>>>
>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>> <karthikeyan.bhargavan@inria.fr
>>> <mailto:karthikeyan.bhargavan@inria.fr <karthikeyan.bhargavan@inria.fr>=
>>
>>> wrote:
>>>
>>>    Hi Joel,
>>>
>>>    This looks very interesting. It is new to me since I was not at
>>>    the interim.
>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>    about what the recipient of an update needs to do.
>>>
>>>    For example, for the running example in your slide deck, it would
>>>    help if I could see:
>>>    - what secret keys does each leaf need to keep
>>>    - how do these secrets change when an update from some other node
>>>    is received.
>>>    Just working this out for one update is enough.
>>>
>>>    I know that this is made precise in the eprint, but it would be
>>>    faster if you could help us understand it :)
>>>
>>>    Best,
>>>    Karthik
>>>
>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>>>
>>>    <mailto:jalwen@wickr.com <jalwen@wickr.com>>> wrote:
>>>
>>>
>>> <FS-TreeKEM.pdf>
>>>
>>>
>>>    _______________________________________________
>>>    MLS mailing list
>>>    MLS@ietf.org <mailto:MLS@ietf.org <MLS@ietf.org>>
>>>    https://www.ietf.org/mailman/listinfo/mls
>>>
>>>
>>>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>>
>>>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>>
>>>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>
>
>

--000000000000c6423e0595868e93
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Since it appears I haven&#39;t chimed in on this thre=
ad -- I am generally OK with this change, if folks think it would improve t=
he FS properties of the protocol, and assuming that Jo=C3=ABl&#39;s / Mike&=
#39;s solution to the X25519 problem works out.=C2=A0 <br></div><div><br></=
div><div>On the one hand, if we have to shove X25519 overboard, my bias wou=
ld probably be against making this change, barring some really strong secur=
ity rationale.=C2=A0 <br></div><div><br></div><div>On the other hand, if we=
 can get confidence that the X25519 solution works (or that the failures ar=
e rare and tolerable), then this seems like a pretty minor burden from an e=
ngineering POV (a little more code, 2x the DH operations on Update/Commit),=
 so if there&#39;s security benefit, great.</div></div><br><div class=3D"gm=
ail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Oct 22, 2019 at 5:=
26 PM Karthikeyan Bhargavan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.c=
om">karthik.bhargavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex"><div style=3D"overflow-wrap: break-word;">=
Indeed!<div><br></div><div>Like I said, it would be a ridiculous design for=
 MLS.</div><div>I was simply trying to understand the guarantees.</div><div=
><br></div><div>-Karthik<br><div><br><blockquote type=3D"cite"><div>On 22 O=
ct 2019, at 23:20, Richard Barnes &lt;<a href=3D"mailto:rlb@ipv.sx" target=
=3D"_blank">rlb@ipv.sx</a>&gt; wrote:</div><br><div><div dir=3D"ltr"><div d=
ir=3D"ltr">Just so we&#39;re clear, I would be *strongly* opposed to puttin=
g anything like this na=C3=AFve UPKE scheme into MLS..=C2=A0 For the simple=
 reason that it expands the size of Welcome message by a factor of K.=C2=A0=
 RTreeKEM or nothing :)<br></div><div dir=3D"ltr"><br></div><div>--Richard<=
/div><div><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis &lt;<a href=
=3D"mailto:dodis@cs.nyu.edu" target=3D"_blank">dodis@cs.nyu.edu</a>&gt; wro=
te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"=
ltr">Great summary, Karthik!<div><br></div><div>As I put in the other threa=
d, comparison with the &quot;naive&quot; UPKE (for K=3D100 or less) might b=
e a good idea.</div><div><br></div><div>Pros of Naive Scheme:=C2=A0</div><d=
iv>- more general, uses any PKE</div><div>- using stream ciphers to generat=
e K key pairs as needed makes the efficiency hit noticeably less than a fac=
tor of K,</div><div>and perhaps closer to a factor of 2 (see below), but un=
clear a-priori.</div><div>- for K&gt;1, offers non-trivial (but still sub-o=
ptimal) security enhancement over basic TreeKEM (K=3D1)</div><div><br></div=
><div>Cons (pros of RTreeKEM):</div><div>- Public key storage increases by =
at least factor of K</div><div>- While the naive use increases secret stora=
ge and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the=C2=A0</div><div>current seed to genera=
te last (K-i) keys. However, K public keys should=C2=A0be published right a=
way, so we must=C2=A0</div><div>lose at least factor of 2 compared to TreeK=
EM to generate all keys twice (but possibly factor of K if people update to=
o frequently, so all but=C2=A0</div><div>1 of the K keys gets used). So ove=
rall efficiency hit between 2 and K, which might already be comparable or w=
orse than RTreeKEM.</div><div>- Still much worse security than RTreeKEM, bu=
t possibly more expensive too, already for small K!</div><div><br></div><di=
v>Please let us know if you think this should be explored further.</div><di=
v>Yevgeniy</div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<=
a href=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank">karthik.bha=
rgavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" =
style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pa=
dding-left:1ex"><div>I see. So, here=E2=80=99s how I read the improvements =
proposed in RTreeKEM.<div><br></div><div>Currently, in TreeKEM (like in ART=
 before it) we rely on each member to regularly *send* updates in order to =
get both PCS and FS for the group secrets.</div><div>The informal secrecy g=
uarantees we get are that:</div><div>- (FS) if member A sends an update in =
epoch N (moving the epoch to N+1), and if A gets compromised in epoch N+1, =
the messages sent in epoch N remain secret</div><div>- (PCS) if member A se=
nds an update in epoch N (moving the epoch to N+1), and if A was (passively=
) compromised in epoch N, the messages sent in epoch N+1 remain secret</div=
><div>In other words, each member who sends an update gets local protection=
 against compromise, encouraging vulnerable members to keep sending updates=
..</div><div><br></div><div>However, as Joel, Sandro, Yevgeniy, and Yiannis=
 note in their paper, we could do better, at least for FS, if we use one-ti=
me decryption keys.</div><div>If each recipient deletes the old decryption =
key after processing an update, then even just by *processing* an update, w=
e get an additional =C2=A0guarantee:</div><div>- (FS=E2=80=99) if member A =
processes an update in epoch N (moving the epoch to N+1), and if A gets com=
promised in epoch N+1, the messages sent in epoch N remain secret</div><div=
><br></div><div>It is also worth remembering that Signal also has a notion =
of one-time prekeys that work similarly for new messaging sessions.</div><d=
iv>Although the following would be a bit ridiculous to use in large dynamic=
 groups, here =C2=A0is a sketch to achieve the receiver FS guarantee withou=
t the need for new crypto.</div><div>- Every time a member A sends an updat=
e, it generates fresh node secrets for nodes on the path from A to the root=
</div><div>- From each node secret, A generates a large number K (=3D 100) =
private-public encryption keypairs and sends the public keys with the updat=
e..</div><div>- On receiving the update, each member B stores all K public =
keys for each node in its co-path</div><div>- Each of these public keys can=
 be used only once for sending an update, after which the private key is de=
leted from all recipients.</div><div>- The last public key at each node is =
not deleted; it can only be replaced when one of the members under that nod=
e sends a new update (with a fresh batch of public keys)..</div><div><br></=
div><div>As far as I understand, the above scheme can be seen as an (ineffi=
cient) implementation of UPKE, right?</div><div>Of course, it increases the=
 size of each update by K, and only provides FS for K updates, after which =
some member has to send an update.</div><div>Conversely, it does not requir=
e any new crypto algorithm. Is this a good baseline to compare UPKE schemes=
 against?</div><div><br></div><div>If I am mis-reading something, do let me=
 know!</div><div><br></div><div>-Karthik</div><div><br></div><div><br></div=
><div><br></div><div><br></div><div><br></div><div><div><br><blockquote typ=
e=3D"cite"><div>On 17 Oct 2019, at 17:18, Joel Alwen &lt;<a href=3D"mailto:=
jalwen@wickr.com" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:</div><b=
r><div><span style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none;float:none;display:inline">I think the challeng=
e with the hash-forward approach is how to do that</span><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;t=
ext-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">homomorphically. I.e. wha=
t we need are two algorithms; one to refresh</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px;text-decoration:none"><spa=
n style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">the PK without knowing the SK (=
but possibly knowing a secret</span><br style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e;float:none;display:inline">rerandomizer delta if needed) and one to updat=
e SK (again possibly using</span><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">delta). So to use a hash-forward approach their m=
ust be:</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">1) a way to evolve PK forward to PK&#39; and</sp=
an><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none;float:none;display:inline">2) a=
 *one-way* method to evolve SK forward to SK&#39; compatible PK&#39;.</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">One-wayness is what gives us Forward Secrecy and &quot;compat=
ibility&quot; between</span><br style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:=
none;display:inline">the two key evolution methods is what allows for async=
hronous (i.e. 1</span><br style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:n=
ormal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;d=
isplay:inline">packet) updates.</span><br style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0=
px;text-decoration:none;float:none;display:inline">Currently we use a secre=
t re-randomizer delta to ensure the SK update</span><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">method is one-way. That is, wi=
thout the delta you cant &quot;undo&quot; the</span><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline">update. But that would break i=
f we (at least naively) used some public</span><br style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none;float:none;display:inline">delta, say hash(ciphertext). So I t=
hink this is the challenge that we&#39;d</span><br style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none;float:none;display:inline">have to overcome.. Basically, make =
sure we SK evolution is one-way but</span><br style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-ind=
ent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">also compatible the public evolution o=
f PK.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text=
-align:start;text-indent:0px;text-transform:none;white-space:normal;word-sp=
acing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-famil=
y:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-=
weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-t=
ransform:none;white-space:normal;word-spacing:0px;text-decoration:none"><br=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px;text-decoration:none;float:none;display:inline">Now one wa=
y sweet way to get all this (and more) would be to use a HIBE.</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">Initial, PK for a ratchet tree node (i.e. its &quot;identity&quot; s=
ince this is a</span><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:=
none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;di=
splay:inline">HIBE now) is simply the empty vector PK :=3D () while the sec=
ret key is</span><br style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displa=
y:inline">the master public key for a fresh HIBE instance SK :=3D MSK. We a=
lso</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter=
-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none;float:none;display:inlin=
e">include, as a second component of the nodes PK, the master public key</s=
pan><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none;float:none;display:inline">PK_=
0 =3D MPK. To &quot;hash forward&quot; / &quot;re-randomize&quot; when send=
ing a ciphertext</span><br style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helve=
tica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:=
normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfor=
m:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;=
display:inline">C to that node we can do:</span><br style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><br sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word=
-spacing:0px;text-decoration:none;float:none;display:inline">PK&#39; :=3D (=
PK, hash(C)).</span><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetic=
a;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none;float:none;dis=
play:inline">SK&#39; :=3D DeriveHIBEKey(PK, SK).</span><br style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none">=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none;float:none;display:inline">So simp=
ly append hash(C) to the identity for that node and derive the</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">corresponding=
 HIBE key.</span><br style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;l=
etter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne;float:none;display:inline">Ignoring the problems with using HIBE for a s=
econd, this is a very cool</span><br style=3D"font-family:Helvetica;font-si=
ze:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">solution. We don&#39;t need to send out the updat=
ed PK since everyone in the</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">group (and even the adversary) can compute it fo=
r themselves. We also</span><br style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:=
none;display:inline">dont need a re-randomize delta as part of the plaintex=
t because we&#39;re</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">using delta :=3D hash(ciphertext) so the plaintext is sh=
orter again.</span><br style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norm=
al;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:no=
ne;white-space:normal;word-spacing:0px;text-decoration:none;float:none;disp=
lay:inline">Moreover, HIBE security means that learning SK&#39; doesn&#39;t=
 tell you</span><br style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;=
text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none;float:none;display=
:inline">anything interesting about SK. In particular, we have forward secu=
rity.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text=
-align:start;text-indent:0px;text-transform:none;white-space:normal;word-sp=
acing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">(In fact, FS will hold even if hash(C) were chosen *completely*</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start=
;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;te=
xt-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none;float:none;display:inline">adversa=
rially, say, as part of a malicious update in an insider attack!)</span><br=
 style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-sty=
le:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none;float:none;displa=
y:inline">Of course, the problem with this solution is that we&#39;re using=
 HIBE.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:n=
ormal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;tex=
t-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:in=
line">Worse, with unbounded depth because each new ciphertext sent to a nod=
e</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal=
;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-ali=
gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:=
12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-s=
pacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none;float:none;display:inline"=
>results in going one depth further into the hierarchy. AFAIK all HIBE</spa=
n><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none;float:none;display:inline">const=
ructions have pretty horrible (read exponential) efficiency as a</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varian=
t-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;tex=
t-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-d=
ecoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none;float:none;display:inline">function of=
 their depth. (And I won&#39;t mention the state of</span><br style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0=
px;text-decoration:none;float:none;display:inline">standardization and open=
 implementations for HIBE.)</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-fam=
ily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><=
span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-v=
ariant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none;float:none;display:inline">Now there could be a totally=
 different approach that entirly avoids</span><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><span sty=
le=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-deco=
ration:none;float:none;display:inline">HIBE. But even with this approach th=
ere&#39;s at least some glimer of hope</span><br style=3D"font-family:Helve=
tica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:=
normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfor=
m:none;white-space:normal;word-spacing:0px;text-decoration:none"><span styl=
e=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-ca=
ps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none;float:none;display:inline">to improve on it because, if we don&#=
39;t wory about insider attacks we can</span><br style=3D"font-family:Helve=
tica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:=
normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfor=
m:none;white-space:normal;word-spacing:0px;text-decoration:none"><span styl=
e=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-ca=
ps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none;float:none;display:inline">assume C is honestly generated which =
means hash(C) really has a ton of</span><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none;float:none;display:inline">entropy. So we dont seem to need the full =
expresivity HIBE identities</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">allow us. Rather we only need HIBE for &quot;ran=
dom&quot; identities. Still, that</span><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non=
e;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none;float:none;display:inline">seems like a pretty slim hope for major ef=
ficiency improvement. It also</span><br style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e;float:none;display:inline">doesn&#39;t do anything to address the lack of=
 implementations and standards.</span><br style=3D"font-family:Helvetica;fo=
nt-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal=
;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0=
px;text-decoration:none;float:none;display:inline">- Jo=C3=ABl</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-=
indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-dec=
oration:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:=
normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">On 17/10/2019 16:37, Karthik Bhargavan wrote:</span><br style=3D"fon=
t-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne"><blockquote type=3D"cite" style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none">Thanks Yevgeniy,<br><br>This =
helps a lot.<br><br>To further my understanding, another question:<br><br><=
blockquote type=3D"cite">=C2=A0Intuitively, the sender will not only encryp=
t the message, but also a<br>random Delta value. It will change public key =
using homomorthism by<br>multiplying with g^Delta (in specific DH based sch=
eme), while the<br>recipient will decrypt Delta (using old secret key), and=
 add it to the<br>old secret key to get there new one. So now corrupting (o=
ld sk plus<br>Delta) will not help decrypting the ciphertext just decepted,=
 emailing<br>forward secrecy.=C2=A0<br></blockquote><br>I see that in the D=
H-based scheme, this Delta needs to be private,<br>otherwise the adversary =
can compute sk once it knows sk+Delta.<br>But, in general, is it possible t=
o conceive of a UPKE scheme where the<br>recipient effectively =E2=80=9Chas=
hes forward=E2=80=9D its symmetric key,<br>where this one way hash-forward =
function does not have to rely on an<br>externally chosen secret value?<br>=
<br>Best,<br>Karthik<br><br><blockquote type=3D"cite">This is the high leve=
l, hope it makes sense.<br>Thanks for your question,<br>Yevgeniy<br><br>On =
Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan<br>&lt;<a href=3D"mailto:karth=
ikeyan.bhargavan@inria.fr" target=3D"_blank">karthikeyan.bhargavan@inria.fr=
</a><br>&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_bl=
ank">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br><br>=C2=A0=
=C2=A0=C2=A0Hi Joel,<br><br>=C2=A0=C2=A0=C2=A0This looks very interesting. =
It is new to me since I was not at<br>=C2=A0=C2=A0=C2=A0the interim.<br>=C2=
=A0=C2=A0=C2=A0After reading the paper and the slides, I am still a bit fuz=
zy<br>=C2=A0=C2=A0=C2=A0about what the recipient of an update needs to do.<=
br><br>=C2=A0=C2=A0=C2=A0For example, for the running example in your slide=
 deck, it would<br>=C2=A0=C2=A0=C2=A0help if I could see:<br>=C2=A0=C2=A0=
=C2=A0- what secret keys does each leaf need to keep<br>=C2=A0=C2=A0=C2=A0-=
 how do these secrets change when an update from some other node<br>=C2=A0=
=C2=A0=C2=A0is received.<br>=C2=A0=C2=A0=C2=A0Just working this out for one=
 update is enough.<br><br>=C2=A0=C2=A0=C2=A0I know that this is made precis=
e in the eprint, but it would be<br>=C2=A0=C2=A0=C2=A0faster if you could h=
elp us understand it :)<br><br>=C2=A0=C2=A0=C2=A0Best,<br>=C2=A0=C2=A0=C2=
=A0Karthik<br><br><blockquote type=3D"cite">On 16 Oct 2019, at 23:51, Joel =
Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@wick=
r.com</a><br></blockquote>=C2=A0=C2=A0=C2=A0&lt;<a href=3D"mailto:jalwen@wi=
ckr.com" target=3D"_blank">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br><b=
lockquote type=3D"cite"><br>&lt;FS-TreeKEM.pdf&gt;<br></blockquote><br>=C2=
=A0=C2=A0=C2=A0_______________________________________________<br>=C2=A0=C2=
=A0=C2=A0MLS mailing list<br>=C2=A0=C2=A0=C2=A0<a href=3D"mailto:MLS@ietf.o=
rg" target=3D"_blank">MLS@ietf.org</a><span>=C2=A0</span>&lt;<a href=3D"mai=
lto:MLS@ietf.org" target=3D"_blank">mailto:MLS@ietf.org</a>&gt;<br>=C2=A0=
=C2=A0=C2=A0<a href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D=
"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br><br></blockquote>=
<br><br>_______________________________________________<br>MLS mailing list=
<br><a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><=
a href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">http=
s://www.ietf.org/mailman/listinfo/mls</a><br><br></blockquote><br style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:=
0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration=
:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none;float:none;display:inline">____________________=
___________________________</span><br style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;=
float:none;display:inline">MLS mailing list</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tra=
nsform:none;white-space:normal;word-spacing:0px;text-decoration:none"><a hr=
ef=3D"mailto:MLS@ietf.org" style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px" target=3D"_blank">MLS@ietf.org</a><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"=
><a href=3D"https://www.ietf.org/mailman/listinfo/mls" style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-w=
eight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tr=
ansform:none;white-space:normal;word-spacing:0px" target=3D"_blank">https:/=
/www.ietf.org/mailman/listinfo/mls</a></div></blockquote></div><br></div></=
div>_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div></div>
_______________________________________________<br>MLS mailing list<br><a h=
ref=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><a href=
=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://ww=
w.ietf.org/mailman/listinfo/mls</a><br></div></blockquote></div><br></div><=
/div></blockquote></div>

--000000000000c6423e0595868e93--


From nobody Tue Oct 22 15:10:51 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53D7012001A for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 15:10:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.897
X-Spam-Level: 
X-Spam-Status: No, score=-6.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kihdPeDhRiHX for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 15:10:46 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7B1F11200FD for <mls@ietf.org>; Tue, 22 Oct 2019 15:10:45 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.68,217,1569276000";  d="scan'208,217";a="407606584"
Received: from unknown (HELO [10.115.242.142]) ([37.166.245.78]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/AES256-GCM-SHA384; 23 Oct 2019 00:10:42 +0200
Content-Type: multipart/alternative; boundary=Apple-Mail-1D087BA6-9141-4A85-85F6-D8F4BAACD0DD
Content-Transfer-Encoding: 7bit
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Mime-Version: 1.0 (1.0)
Date: Wed, 23 Oct 2019 00:10:38 +0200
Message-Id: <3B5BE109-6C78-474F-A0E5-138DE6931CF6@inria.fr>
References: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com>
Cc: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Messaging Layer Security WG <mls@ietf.org>, Joel Alwen <jalwen@wickr.com>, Yevgeniy Dodis <dodis@cs.nyu.edu>
In-Reply-To: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
X-Mailer: iPhone Mail (17A878)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/Hoo45REkRCg_a-SmAblHVYhlv04>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Oct 2019 22:10:50 -0000

--Apple-Mail-1D087BA6-9141-4A85-85F6-D8F4BAACD0DD
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

That=E2=80=99s my opinion as well... :)
B.

> On Oct 22, 2019, at 11:34 PM, Richard Barnes <rlb@ipv.sx> wrote:
>=20
> =EF=BB=BF
> Since it appears I haven't chimed in on this thread -- I am generally OK w=
ith this change, if folks think it would improve the FS properties of the pr=
otocol, and assuming that Jo=C3=ABl's / Mike's solution to the X25519 proble=
m works out. =20
>=20
> On the one hand, if we have to shove X25519 overboard, my bias would proba=
bly be against making this change, barring some really strong security ratio=
nale. =20
>=20
> On the other hand, if we can get confidence that the X25519 solution works=
 (or that the failures are rare and tolerable), then this seems like a prett=
y minor burden from an engineering POV (a little more code, 2x the DH operat=
ions on Update/Commit), so if there's security benefit, great.
>=20
>> On Tue, Oct 22, 2019 at 5:26 PM Karthikeyan Bhargavan <karthik.bhargavan@=
gmail.com> wrote:
>> Indeed!
>>=20
>> Like I said, it would be a ridiculous design for MLS.
>> I was simply trying to understand the guarantees.
>>=20
>> -Karthik
>>=20
>>> On 22 Oct 2019, at 23:20, Richard Barnes <rlb@ipv.sx> wrote:
>>>=20
>>> Just so we're clear, I would be *strongly* opposed to putting anything l=
ike this na=C3=AFve UPKE scheme into MLS..  For the simple reason that it ex=
pands the size of Welcome message by a factor of K.  RTreeKEM or nothing :)
>>>=20
>>> --Richard
>>>=20
>>>=20
>>>> On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis <dodis@cs.nyu.edu> wrote=
:
>>>> Great summary, Karthik!
>>>>=20
>>>> As I put in the other thread, comparison with the "naive" UPKE (for K=3D=
100 or less) might be a good idea.
>>>>=20
>>>> Pros of Naive Scheme:=20
>>>> - more general, uses any PKE
>>>> - using stream ciphers to generate K key pairs as needed makes the effi=
ciency hit noticeably less than a factor of K,
>>>> and perhaps closer to a factor of 2 (see below), but unclear a-priori.
>>>> - for K>1, offers non-trivial (but still sub-optimal) security enhancem=
ent over basic TreeKEM (K=3D1)
>>>>=20
>>>> Cons (pros of RTreeKEM):
>>>> - Public key storage increases by at least factor of K
>>>> - While the naive use increases secret storage and computation by a fac=
tor of K, using stream cipher, after i uses one can only store the=20
>>>> current seed to generate last (K-i) keys. However, K public keys should=
 be published right away, so we must=20
>>>> lose at least factor of 2 compared to TreeKEM to generate all keys twic=
e (but possibly factor of K if people update too frequently, so all but=20
>>>> 1 of the K keys gets used). So overall efficiency hit between 2 and K, w=
hich might already be comparable or worse than RTreeKEM.
>>>> - Still much worse security than RTreeKEM, but possibly more expensive t=
oo, already for small K!
>>>>=20
>>>> Please let us know if you think this should be explored further.
>>>> Yevgeniy
>>>>=20
>>>>> On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan <karthik.bhargav=
an@gmail.com> wrote:
>>>>> I see. So, here=E2=80=99s how I read the improvements proposed in RTre=
eKEM.
>>>>>=20
>>>>> Currently, in TreeKEM (like in ART before it) we rely on each member t=
o regularly *send* updates in order to get both PCS and FS for the group sec=
rets.
>>>>> The informal secrecy guarantees we get are that:
>>>>> - (FS) if member A sends an update in epoch N (moving the epoch to N+1=
), and if A gets compromised in epoch N+1, the messages sent in epoch N rema=
in secret
>>>>> - (PCS) if member A sends an update in epoch N (moving the epoch to N+=
1), and if A was (passively) compromised in epoch N, the messages sent in ep=
och N+1 remain secret
>>>>> In other words, each member who sends an update gets local protection a=
gainst compromise, encouraging vulnerable members to keep sending updates...=

>>>>>=20
>>>>> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, w=
e could do better, at least for FS, if we use one-time decryption keys.
>>>>> If each recipient deletes the old decryption key after processing an u=
pdate, then even just by *processing* an update, we get an additional  guara=
ntee:
>>>>> - (FS=E2=80=99) if member A processes an update in epoch N (moving the=
 epoch to N+1), and if A gets compromised in epoch N+1, the messages sent in=
 epoch N remain secret
>>>>>=20
>>>>> It is also worth remembering that Signal also has a notion of one-time=
 prekeys that work similarly for new messaging sessions.
>>>>> Although the following would be a bit ridiculous to use in large dynam=
ic groups, here  is a sketch to achieve the receiver FS guarantee without th=
e need for new crypto.
>>>>> - Every time a member A sends an update, it generates fresh node secre=
ts for nodes on the path from A to the root
>>>>> - =46rom each node secret, A generates a large number K (=3D 100) priv=
ate-public encryption keypairs and sends the public keys with the update..
>>>>> - On receiving the update, each member B stores all K public keys for e=
ach node in its co-path
>>>>> - Each of these public keys can be used only once for sending an updat=
e, after which the private key is deleted from all recipients.
>>>>> - The last public key at each node is not deleted; it can only be repl=
aced when one of the members under that node sends a new update (with a fres=
h batch of public keys)..
>>>>>=20
>>>>> As far as I understand, the above scheme can be seen as an (inefficien=
t) implementation of UPKE, right?
>>>>> Of course, it increases the size of each update by K, and only provide=
s FS for K updates, after which some member has to send an update.
>>>>> Conversely, it does not require any new crypto algorithm. Is this a go=
od baseline to compare UPKE schemes against?
>>>>>=20
>>>>> If I am mis-reading something, do let me know!
>>>>>=20
>>>>> -Karthik
>>>>>=20
>>>>>=20
>>>>>=20
>>>>>=20
>>>>>=20
>>>>>=20
>>>>>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com> wrote:
>>>>>>=20
>>>>>> I think the challenge with the hash-forward approach is how to do tha=
t
>>>>>> homomorphically. I.e. what we need are two algorithms; one to refresh=

>>>>>> the PK without knowing the SK (but possibly knowing a secret
>>>>>> rerandomizer delta if needed) and one to update SK (again possibly us=
ing
>>>>>> delta). So to use a hash-forward approach their must be:
>>>>>>=20
>>>>>> 1) a way to evolve PK forward to PK' and
>>>>>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>>>>>=20
>>>>>> One-wayness is what gives us Forward Secrecy and "compatibility" betw=
een
>>>>>> the two key evolution methods is what allows for asynchronous (i.e. 1=

>>>>>> packet) updates.
>>>>>>=20
>>>>>> Currently we use a secret re-randomizer delta to ensure the SK update=

>>>>>> method is one-way. That is, without the delta you cant "undo" the
>>>>>> update. But that would break if we (at least naively) used some publi=
c
>>>>>> delta, say hash(ciphertext). So I think this is the challenge that we=
'd
>>>>>> have to overcome.. Basically, make sure we SK evolution is one-way bu=
t
>>>>>> also compatible the public evolution of PK.
>>>>>>=20
>>>>>>=20
>>>>>>=20
>>>>>> Now one way sweet way to get all this (and more) would be to use a HI=
BE.
>>>>>>=20
>>>>>> Initial, PK for a ratchet tree node (i.e. its "identity" since this i=
s a
>>>>>> HIBE now) is simply the empty vector PK :=3D () while the secret key i=
s
>>>>>> the master public key for a fresh HIBE instance SK :=3D MSK. We also
>>>>>> include, as a second component of the nodes PK, the master public key=

>>>>>> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a ciphe=
rtext
>>>>>> C to that node we can do:
>>>>>>=20
>>>>>> PK' :=3D (PK, hash(C)).
>>>>>> SK' :=3D DeriveHIBEKey(PK, SK).
>>>>>>=20
>>>>>> So simply append hash(C) to the identity for that node and derive the=

>>>>>> corresponding HIBE key.
>>>>>>=20
>>>>>> Ignoring the problems with using HIBE for a second, this is a very co=
ol
>>>>>> solution. We don't need to send out the updated PK since everyone in t=
he
>>>>>> group (and even the adversary) can compute it for themselves. We also=

>>>>>> dont need a re-randomize delta as part of the plaintext because we're=

>>>>>> using delta :=3D hash(ciphertext) so the plaintext is shorter again.
>>>>>> Moreover, HIBE security means that learning SK' doesn't tell you
>>>>>> anything interesting about SK. In particular, we have forward securit=
y.
>>>>>> (In fact, FS will hold even if hash(C) were chosen *completely*
>>>>>> adversarially, say, as part of a malicious update in an insider attac=
k!)
>>>>>>=20
>>>>>> Of course, the problem with this solution is that we're using HIBE.
>>>>>> Worse, with unbounded depth because each new ciphertext sent to a nod=
e
>>>>>> results in going one depth further into the hierarchy. AFAIK all HIBE=

>>>>>> constructions have pretty horrible (read exponential) efficiency as a=

>>>>>> function of their depth. (And I won't mention the state of
>>>>>> standardization and open implementations for HIBE.)
>>>>>>=20
>>>>>> Now there could be a totally different approach that entirly avoids
>>>>>> HIBE. But even with this approach there's at least some glimer of hop=
e
>>>>>> to improve on it because, if we don't wory about insider attacks we c=
an
>>>>>> assume C is honestly generated which means hash(C) really has a ton o=
f
>>>>>> entropy. So we dont seem to need the full expresivity HIBE identities=

>>>>>> allow us. Rather we only need HIBE for "random" identities. Still, th=
at
>>>>>> seems like a pretty slim hope for major efficiency improvement. It al=
so
>>>>>> doesn't do anything to address the lack of implementations and standa=
rds.
>>>>>>=20
>>>>>> - Jo=C3=ABl
>>>>>>=20
>>>>>>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>>>>>> Thanks Yevgeniy,
>>>>>>>=20
>>>>>>> This helps a lot.
>>>>>>>=20
>>>>>>> To further my understanding, another question:
>>>>>>>=20
>>>>>>>>  Intuitively, the sender will not only encrypt the message, but als=
o a
>>>>>>>> random Delta value. It will change public key using homomorthism by=

>>>>>>>> multiplying with g^Delta (in specific DH based scheme), while the
>>>>>>>> recipient will decrypt Delta (using old secret key), and add it to t=
he
>>>>>>>> old secret key to get there new one. So now corrupting (old sk plus=

>>>>>>>> Delta) will not help decrypting the ciphertext just decepted, email=
ing
>>>>>>>> forward secrecy.=20
>>>>>>>=20
>>>>>>> I see that in the DH-based scheme, this Delta needs to be private,
>>>>>>> otherwise the adversary can compute sk once it knows sk+Delta.
>>>>>>> But, in general, is it possible to conceive of a UPKE scheme where t=
he
>>>>>>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its symmetric=
 key,
>>>>>>> where this one way hash-forward function does not have to rely on an=

>>>>>>> externally chosen secret value?
>>>>>>>=20
>>>>>>> Best,
>>>>>>> Karthik
>>>>>>>=20
>>>>>>>> This is the high level, hope it makes sense.
>>>>>>>> Thanks for your question,
>>>>>>>> Yevgeniy
>>>>>>>>=20
>>>>>>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>>>>>>> <karthikeyan.bhargavan@inria.fr
>>>>>>>> <mailto:karthikeyan.bhargavan@inria.fr>> wrote:
>>>>>>>>=20
>>>>>>>>    Hi Joel,
>>>>>>>>=20
>>>>>>>>    This looks very interesting. It is new to me since I was not at
>>>>>>>>    the interim.
>>>>>>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>>>>>>    about what the recipient of an update needs to do.
>>>>>>>>=20
>>>>>>>>    For example, for the running example in your slide deck, it woul=
d
>>>>>>>>    help if I could see:
>>>>>>>>    - what secret keys does each leaf need to keep
>>>>>>>>    - how do these secrets change when an update from some other nod=
e
>>>>>>>>    is received.
>>>>>>>>    Just working this out for one update is enough.
>>>>>>>>=20
>>>>>>>>    I know that this is made precise in the eprint, but it would be
>>>>>>>>    faster if you could help us understand it :)
>>>>>>>>=20
>>>>>>>>    Best,
>>>>>>>>    Karthik
>>>>>>>>=20
>>>>>>>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com
>>>>>>>>>    <mailto:jalwen@wickr.com>> wrote:
>>>>>>>>>=20
>>>>>>>>> <FS-TreeKEM.pdf>
>>>>>>>>=20
>>>>>>>>    _______________________________________________
>>>>>>>>    MLS mailing list
>>>>>>>>    MLS@ietf.org <mailto:MLS@ietf.org>
>>>>>>>>    https://www.ietf.org/mailman/listinfo/mls
>>>>>>>>=20
>>>>>>>=20
>>>>>>>=20
>>>>>>> _______________________________________________
>>>>>>> MLS mailing list
>>>>>>> MLS@ietf.org
>>>>>>> https://www.ietf.org/mailman/listinfo/mls
>>>>>>>=20
>>>>>>=20
>>>>>> _______________________________________________
>>>>>> MLS mailing list
>>>>>> MLS@ietf.org
>>>>>> https://www.ietf.org/mailman/listinfo/mls
>>>>>=20
>>>>> _______________________________________________
>>>>> MLS mailing list
>>>>> MLS@ietf.org
>>>>> https://www.ietf.org/mailman/listinfo/mls
>>>> _______________________________________________
>>>> MLS mailing list
>>>> MLS@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/mls
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>=20
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls

--Apple-Mail-1D087BA6-9141-4A85-85F6-D8F4BAACD0DD
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div dir=3D"ltr">That=E2=80=99s my opinion a=
s well... :)</div><div dir=3D"ltr">B.</div><div dir=3D"ltr"><br><blockquote t=
ype=3D"cite">On Oct 22, 2019, at 11:34 PM, Richard Barnes &lt;rlb@ipv.sx&gt;=
 wrote:<br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr"=
>=EF=BB=BF<div dir=3D"ltr"><div>Since it appears I haven't chimed in on this=
 thread -- I am generally OK with this change, if folks think it would impro=
ve the FS properties of the protocol, and assuming that Jo=C3=ABl's / Mike's=
 solution to the X25519 problem works out.&nbsp; <br></div><div><br></div><d=
iv>On the one hand, if we have to shove X25519 overboard, my bias would prob=
ably be against making this change, barring some really strong security rati=
onale.&nbsp; <br></div><div><br></div><div>On the other hand, if we can get c=
onfidence that the X25519 solution works (or that the failures are rare and t=
olerable), then this seems like a pretty minor burden from an engineering PO=
V (a little more code, 2x the DH operations on Update/Commit), so if there's=
 security benefit, great.</div></div><br><div class=3D"gmail_quote"><div dir=
=3D"ltr" class=3D"gmail_attr">On Tue, Oct 22, 2019 at 5:26 PM Karthikeyan Bh=
argavan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com">karthik.bhargavan=
@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-lef=
t:1ex"><div style=3D"overflow-wrap: break-word;">Indeed!<div><br></div><div>=
Like I said, it would be a ridiculous design for MLS.</div><div>I was simply=
 trying to understand the guarantees.</div><div><br></div><div>-Karthik<br><=
div><br><blockquote type=3D"cite"><div>On 22 Oct 2019, at 23:20, Richard Bar=
nes &lt;<a href=3D"mailto:rlb@ipv.sx" target=3D"_blank">rlb@ipv.sx</a>&gt; w=
rote:</div><br><div><div dir=3D"ltr"><div dir=3D"ltr">Just so we're clear, I=
 would be *strongly* opposed to putting anything like this na=C3=AFve UPKE s=
cheme into MLS..&nbsp; For the simple reason that it expands the size of Wel=
come message by a factor of K.&nbsp; RTreeKEM or nothing :)<br></div><div di=
r=3D"ltr"><br></div><div>--Richard</div><div><br></div><br><div class=3D"gma=
il_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct 21, 2019 at 6:53=
 PM Yevgeniy Dodis &lt;<a href=3D"mailto:dodis@cs.nyu.edu" target=3D"_blank"=
>dodis@cs.nyu.edu</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padd=
ing-left:1ex"><div dir=3D"ltr">Great summary, Karthik!<div><br></div><div>As=
 I put in the other thread, comparison with the "naive" UPKE (for K=3D100 or=
 less) might be a good idea.</div><div><br></div><div>Pros of Naive Scheme:&=
nbsp;</div><div>- more general, uses any PKE</div><div>- using stream cipher=
s to generate K key pairs as needed makes the efficiency hit noticeably less=
 than a factor of K,</div><div>and perhaps closer to a factor of 2 (see belo=
w), but unclear a-priori.</div><div>- for K&gt;1, offers non-trivial (but st=
ill sub-optimal) security enhancement over basic TreeKEM (K=3D1)</div><div><=
br></div><div>Cons (pros of RTreeKEM):</div><div>- Public key storage increa=
ses by at least factor of K</div><div>- While the naive use increases secret=
 storage and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the&nbsp;</div><div>current seed to generat=
e last (K-i) keys. However, K public keys should&nbsp;be published right awa=
y, so we must&nbsp;</div><div>lose at least factor of 2 compared to TreeKEM t=
o generate all keys twice (but possibly factor of K if people update too fre=
quently, so all but&nbsp;</div><div>1 of the K keys gets used). So overall e=
fficiency hit between 2 and K, which might already be comparable or worse th=
an RTreeKEM.</div><div>- Still much worse security than RTreeKEM, but possib=
ly more expensive too, already for small K!</div><div><br></div><div>Please l=
et us know if you think this should be explored further.</div><div>Yevgeniy<=
/div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_at=
tr">On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<a href=3D"mai=
lto:karthik.bhargavan@gmail.com" target=3D"_blank">karthik.bhargavan@gmail.c=
om</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin=
:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">=
<div>I see. So, here=E2=80=99s how I read the improvements proposed in RTree=
KEM.<div><br></div><div>Currently, in TreeKEM (like in ART before it) we rel=
y on each member to regularly *send* updates in order to get both PCS and FS=
 for the group secrets.</div><div>The informal secrecy guarantees we get are=
 that:</div><div>- (FS) if member A sends an update in epoch N (moving the e=
poch to N+1), and if A gets compromised in epoch N+1, the messages sent in e=
poch N remain secret</div><div>- (PCS) if member A sends an update in epoch N=
 (moving the epoch to N+1), and if A was (passively) compromised in epoch N,=
 the messages sent in epoch N+1 remain secret</div><div>In other words, each=
 member who sends an update gets local protection against compromise, encour=
aging vulnerable members to keep sending updates...</div><div><br></div><div=
>However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, we cou=
ld do better, at least for FS, if we use one-time decryption keys.</div><div=
>If each recipient deletes the old decryption key after processing an update=
, then even just by *processing* an update, we get an additional &nbsp;guara=
ntee:</div><div>- (FS=E2=80=99) if member A processes an update in epoch N (=
moving the epoch to N+1), and if A gets compromised in epoch N+1, the messag=
es sent in epoch N remain secret</div><div><br></div><div>It is also worth r=
emembering that Signal also has a notion of one-time prekeys that work simil=
arly for new messaging sessions.</div><div>Although the following would be a=
 bit ridiculous to use in large dynamic groups, here &nbsp;is a sketch to ac=
hieve the receiver FS guarantee without the need for new crypto.</div><div>-=
 Every time a member A sends an update, it generates fresh node secrets for n=
odes on the path from A to the root</div><div>- =46rom each node secret, A g=
enerates a large number K (=3D 100) private-public encryption keypairs and s=
ends the public keys with the update..</div><div>- On receiving the update, e=
ach member B stores all K public keys for each node in its co-path</div><div=
>- Each of these public keys can be used only once for sending an update, af=
ter which the private key is deleted from all recipients.</div><div>- The la=
st public key at each node is not deleted; it can only be replaced when one o=
f the members under that node sends a new update (with a fresh batch of publ=
ic keys)..</div><div><br></div><div>As far as I understand, the above scheme=
 can be seen as an (inefficient) implementation of UPKE, right?</div><div>Of=
 course, it increases the size of each update by K, and only provides FS for=
 K updates, after which some member has to send an update.</div><div>Convers=
ely, it does not require any new crypto algorithm. Is this a good baseline t=
o compare UPKE schemes against?</div><div><br></div><div>If I am mis-reading=
 something, do let me know!</div><div><br></div><div>-Karthik</div><div><br>=
</div><div><br></div><div><br></div><div><br></div><div><br></div><div><div>=
<br><blockquote type=3D"cite"><div>On 17 Oct 2019, at 17:18, Joel Alwen &lt;=
<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@wickr.com</a>&g=
t; wrote:</div><br><div><span style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">I think=
 the challenge with the hash-forward approach is how to do that</span><br st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none;float:none;display:inline">homomorphically. I.e=
. what we need are two algorithms; one to refresh</span><br style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><sp=
an style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-vari=
ant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-d=
ecoration:none;float:none;display:inline">the PK without knowing the SK (but=
 possibly knowing a secret</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-=
spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">rerandomizer delta if needed) and one to update SK (again=
 possibly using</span><br style=3D"font-family:Helvetica;font-size:12px;font=
-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:nor=
mal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;=
word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:=
inline">delta). So to use a hash-forward approach their must be:</span><br s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none"><br style=3D"font-family:Helvetica;font-size:12px;font-style:nor=
mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:=
12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">1)=
 a way to evolve PK forward to PK' and</span><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">2) a *one-way* method to evolve SK forward to=
 SK' compatible PK'.</span><br style=3D"font-family:Helvetica;font-size:12px=
;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacin=
g:normal;text-align:start;text-indent:0px;text-transform:none;white-space:no=
rmal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helveti=
ca;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:nor=
mal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:no=
ne;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"=
font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:nor=
mal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0p=
x;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:no=
ne;float:none;display:inline">One-wayness is what gives us Forward Secrecy a=
nd "compatibility" between</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-=
spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">the two key evolution methods is what allows for asynchro=
nous (i.e. 1</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">packet) updates.</span><br style=3D"font-family:Helvetica;font-size:12p=
x;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">Currently we use a secret re-randomizer delta=
 to ensure the SK update</span><br style=3D"font-family:Helvetica;font-size:=
12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-sp=
acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac=
e:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:H=
elvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weig=
ht:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transf=
orm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none=
;display:inline">method is one-way. That is, without the delta you cant "und=
o" the</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size=
:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-s=
pacing:normal;text-align:start;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">u=
pdate. But that would break if we (at least naively) used some public</span>=
<br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none;float:none;display:inline">delta, say has=
h(ciphertext). So I think this is the challenge that we'd</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">have to overcome.. Basical=
ly, make sure we SK evolution is one-way but</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><span st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">also compatible the public evolution of=
 PK.</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:12p=
x;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"f=
ont-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norm=
al;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px=
;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:non=
e"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none;float:none;display:inline">Now one way sweet way to get=
 all this (and more) would be to use a HIBE.</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><br styl=
e=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-cap=
s:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-inde=
nt:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decorati=
on:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norm=
al;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-al=
ign:start;text-indent:0px;text-transform:none;white-space:normal;word-spacin=
g:0px;text-decoration:none;float:none;display:inline">Initial, PK for a ratc=
het tree node (i.e. its "identity" since this is a</span><br style=3D"font-f=
amily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fo=
nt-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><s=
pan style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-var=
iant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-=
decoration:none;float:none;display:inline">HIBE now) is simply the empty vec=
tor PK :=3D () while the secret key is</span><br style=3D"font-family:Helvet=
ica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:no=
rmal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:n=
one;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">the master public key for a fresh HIBE instan=
ce SK :=3D MSK. We also</span><br style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-space=
:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;=
display:inline">include, as a second component of the nodes PK, the master p=
ublic key</span><br style=3D"font-family:Helvetica;font-size:12px;font-style=
:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;te=
xt-align:start;text-indent:0px;text-transform:none;white-space:normal;word-s=
pacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-s=
ize:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lette=
r-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-=
space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline=
">PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a ciphertext=
</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none;float:none;display:inline">C to th=
at node we can do:</span><br style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">PK' :=3D (PK, hash(C)).</span><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><=
span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">SK' :=3D DeriveHIBEKey(PK, SK).<=
/span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fo=
nt-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:s=
tart;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px=
;text-decoration:none"><br style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display=
:inline">So simply append hash(C) to the identity for that node and derive t=
he</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal=
;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-alig=
n:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:=
0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12p=
x;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spaci=
ng:normal;text-align:start;text-indent:0px;text-transform:none;white-space:n=
ormal;word-spacing:0px;text-decoration:none;float:none;display:inline">corre=
sponding HIBE key.</span><br style=3D"font-family:Helvetica;font-size:12px;f=
ont-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:=
normal;text-align:start;text-indent:0px;text-transform:none;white-space:norm=
al;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">Ignoring the problems with using HIBE for a seco=
nd, this is a very cool</span><br style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-space=
:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;=
display:inline">solution. We don't need to send out the updated PK since eve=
ryone in the</span><br style=3D"font-family:Helvetica;font-size:12px;font-st=
yle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal=
;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor=
d-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;fon=
t-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whi=
te-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inl=
ine">group (and even the adversary) can compute it for themselves. We also</=
span><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none;float:none;display:inline">dont need=
 a re-randomize delta as part of the plaintext because we're</span><br style=
=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps=
:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-inden=
t:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoratio=
n:none"><span style=3D"font-family:Helvetica;font-size:12px;font-style:norma=
l;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-ali=
gn:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing=
:0px;text-decoration:none;float:none;display:inline">using delta :=3D hash(c=
iphertext) so the plaintext is shorter again.</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none;float:none;display:inline">Moreover, HIBE security means that lea=
rning SK' doesn't tell you</span><br style=3D"font-family:Helvetica;font-siz=
e:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-=
spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-sp=
ace:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:no=
ne;display:inline">anything interesting about SK. In particular, we have for=
ward security.</span><br style=3D"font-family:Helvetica;font-size:12px;font-=
style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norm=
al;text-align:start;text-indent:0px;text-transform:none;white-space:normal;w=
ord-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline">(In fact, FS will hold even if hash(C) were chosen *completely*</span=
><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-s=
tyle:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:norma=
l;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wo=
rd-spacing:0px;text-decoration:none;float:none;display:inline">adversarially=
, say, as part of a malicious update in an insider attack!)</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;fon=
t-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:st=
art;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;=
text-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fo=
nt-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:n=
ormal;text-align:start;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px;text-decoration:none;float:none;display:inline">Of course=
, the problem with this solution is that we're using HIBE.</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">Worse, with unbounded dept=
h because each new ciphertext sent to a node</span><br style=3D"font-family:=
Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-wei=
ght:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-trans=
form:none;white-space:normal;word-spacing:0px;text-decoration:none"><span st=
yle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-c=
aps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-in=
dent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decora=
tion:none;float:none;display:inline">results in going one depth further into=
 the hierarchy. AFAIK all HIBE</span><br style=3D"font-family:Helvetica;font=
-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;let=
ter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;whit=
e-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font-fa=
mily:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;fon=
t-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-=
transform:none;white-space:normal;word-spacing:0px;text-decoration:none;floa=
t:none;display:inline">constructions have pretty horrible (read exponential)=
 efficiency as a</span><br style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display=
:inline">function of their depth. (And I won't mention the state of</span><b=
r style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;tex=
t-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-de=
coration:none"><span style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none;float:none;display:inline">standardization a=
nd open implementations for HIBE.)</span><br style=3D"font-family:Helvetica;=
font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal=
;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;=
white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><=
span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-va=
riant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;=
text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text=
-decoration:none;float:none;display:inline">Now there could be a totally dif=
ferent approach that entirly avoids</span><br style=3D"font-family:Helvetica=
;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:norma=
l;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none=
;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"fo=
nt-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:norma=
l;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;=
text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none=
;float:none;display:inline">HIBE. But even with this approach there's at lea=
st some glimer of hope</span><br style=3D"font-family:Helvetica;font-size:12=
px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spac=
ing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px;text-decoration:none"><span style=3D"font-family:Hel=
vetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight=
:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfor=
m:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;d=
isplay:inline">to improve on it because, if we don't wory about insider atta=
cks we can</span><br style=3D"font-family:Helvetica;font-size:12px;font-styl=
e:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;t=
ext-align:start;text-indent:0px;text-transform:none;white-space:normal;word-=
spacing:0px;text-decoration:none"><span style=3D"font-family:Helvetica;font-=
size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;lett=
er-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white=
-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inlin=
e">assume C is honestly generated which means hash(C) really has a ton of</s=
pan><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">entropy. S=
o we dont seem to need the full expresivity HIBE identities</span><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">allow us. Rather we only n=
eed HIBE for "random" identities. Still, that</span><br style=3D"font-family=
:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-we=
ight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=
sform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span s=
tyle=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-=
caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-i=
ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decor=
ation:none;float:none;display:inline">seems like a pretty slim hope for majo=
r efficiency improvement. It also</span><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">doesn't do anything to address the lack of impleme=
ntations and standards.</span><br style=3D"font-family:Helvetica;font-size:1=
2px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spa=
cing:normal;text-align:start;text-indent:0px;text-transform:none;white-space=
:normal;word-spacing:0px;text-decoration:none"><br style=3D"font-family:Helv=
etica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weight:=
normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform=
:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one;float:none;display:inline">- Jo=C3=ABl</span><br style=3D"font-family:He=
lvetica;font-size:12px;font-style:normal;font-variant-caps:normal;font-weigh=
t:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transfo=
rm:none;white-space:normal;word-spacing:0px;text-decoration:none"><br style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one"><span style=3D"font-family:Helvetica;font-size:12px;font-style:normal;f=
ont-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:=
start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x;text-decoration:none;float:none;display:inline">On 17/10/2019 16:37, Karth=
ik Bhargavan wrote:</span><br style=3D"font-family:Helvetica;font-size:12px;=
font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing=
:normal;text-align:start;text-indent:0px;text-transform:none;white-space:nor=
mal;word-spacing:0px;text-decoration:none"><blockquote type=3D"cite" style=3D=
"font-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:no=
rmal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0=
px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:n=
one">Thanks Yevgeniy,<br><br>This helps a lot.<br><br>To further my understa=
nding, another question:<br><br><blockquote type=3D"cite">&nbsp;Intuitively,=
 the sender will not only encrypt the message, but also a<br>random Delta va=
lue. It will change public key using homomorthism by<br>multiplying with g^D=
elta (in specific DH based scheme), while the<br>recipient will decrypt Delt=
a (using old secret key), and add it to the<br>old secret key to get there n=
ew one. So now corrupting (old sk plus<br>Delta) will not help decrypting th=
e ciphertext just decepted, emailing<br>forward secrecy.&nbsp;<br></blockquo=
te><br>I see that in the DH-based scheme, this Delta needs to be private,<br=
>otherwise the adversary can compute sk once it knows sk+Delta.<br>But, in g=
eneral, is it possible to conceive of a UPKE scheme where the<br>recipient e=
ffectively =E2=80=9Chashes forward=E2=80=9D its symmetric key,<br>where this=
 one way hash-forward function does not have to rely on an<br>externally cho=
sen secret value?<br><br>Best,<br>Karthik<br><br><blockquote type=3D"cite">T=
his is the high level, hope it makes sense.<br>Thanks for your question,<br>=
Yevgeniy<br><br>On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan<br>&lt;<a hr=
ef=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank">karthikeyan.b=
hargavan@inria.fr</a><br>&lt;<a href=3D"mailto:karthikeyan.bhargavan@inria.f=
r" target=3D"_blank">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote=
:<br><br>&nbsp;&nbsp;&nbsp;Hi Joel,<br><br>&nbsp;&nbsp;&nbsp;This looks very=
 interesting. It is new to me since I was not at<br>&nbsp;&nbsp;&nbsp;the in=
terim.<br>&nbsp;&nbsp;&nbsp;After reading the paper and the slides, I am sti=
ll a bit fuzzy<br>&nbsp;&nbsp;&nbsp;about what the recipient of an update ne=
eds to do.<br><br>&nbsp;&nbsp;&nbsp;For example, for the running example in y=
our slide deck, it would<br>&nbsp;&nbsp;&nbsp;help if I could see:<br>&nbsp;=
&nbsp;&nbsp;- what secret keys does each leaf need to keep<br>&nbsp;&nbsp;&n=
bsp;- how do these secrets change when an update from some other node<br>&nb=
sp;&nbsp;&nbsp;is received.<br>&nbsp;&nbsp;&nbsp;Just working this out for o=
ne update is enough.<br><br>&nbsp;&nbsp;&nbsp;I know that this is made preci=
se in the eprint, but it would be<br>&nbsp;&nbsp;&nbsp;faster if you could h=
elp us understand it :)<br><br>&nbsp;&nbsp;&nbsp;Best,<br>&nbsp;&nbsp;&nbsp;=
Karthik<br><br><blockquote type=3D"cite">On 16 Oct 2019, at 23:51, Joel Alwe=
n &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@wickr.com=
</a><br></blockquote>&nbsp;&nbsp;&nbsp;&lt;<a href=3D"mailto:jalwen@wickr.co=
m" target=3D"_blank">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br><blockquo=
te type=3D"cite"><br>&lt;FS-TreeKEM.pdf&gt;<br></blockquote><br>&nbsp;&nbsp;=
&nbsp;_______________________________________________<br>&nbsp;&nbsp;&nbsp;M=
LS mailing list<br>&nbsp;&nbsp;&nbsp;<a href=3D"mailto:MLS@ietf.org" target=3D=
"_blank">MLS@ietf.org</a><span>&nbsp;</span>&lt;<a href=3D"mailto:MLS@ietf.o=
rg" target=3D"_blank">mailto:MLS@ietf.org</a>&gt;<br>&nbsp;&nbsp;&nbsp;<a hr=
ef=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://w=
ww.ietf.org/mailman/listinfo/mls</a><br><br></blockquote><br><br>___________=
____________________________________<br>MLS mailing list<br><a href=3D"mailt=
o:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><a href=3D"https://www=
.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://www.ietf.org/mailm=
an/listinfo/mls</a><br><br></blockquote><br style=3D"font-family:Helvetica;f=
ont-size:12px;font-style:normal;font-variant-caps:normal;font-weight:normal;=
letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;w=
hite-space:normal;word-spacing:0px;text-decoration:none"><span style=3D"font=
-family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;=
font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;te=
xt-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;f=
loat:none;display:inline">_______________________________________________</s=
pan><br style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font=
-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:sta=
rt;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;t=
ext-decoration:none"><span style=3D"font-family:Helvetica;font-size:12px;fon=
t-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:no=
rmal;text-align:start;text-indent:0px;text-transform:none;white-space:normal=
;word-spacing:0px;text-decoration:none;float:none;display:inline">MLS mailin=
g list</span><br style=3D"font-family:Helvetica;font-size:12px;font-style:no=
rmal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-=
align:start;text-indent:0px;text-transform:none;white-space:normal;word-spac=
ing:0px;text-decoration:none"><a href=3D"mailto:MLS@ietf.org" style=3D"font-=
family:Helvetica;font-size:12px;font-style:normal;font-variant-caps:normal;f=
ont-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;tex=
t-transform:none;white-space:normal;word-spacing:0px" target=3D"_blank">MLS@=
ietf.org</a><br style=3D"font-family:Helvetica;font-size:12px;font-style:nor=
mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a=
lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci=
ng:0px;text-decoration:none"><a href=3D"https://www.ietf.org/mailman/listinf=
o/mls" style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-=
variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:star=
t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" t=
arget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a></div></blockq=
uote></div><br></div></div>_______________________________________________<b=
r>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" tar=
get=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" tar=
get=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div></div>
_______________________________________________<br>MLS mailing list<br><a hr=
ef=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br><a href=3D"=
https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank">https://www.iet=
f.org/mailman/listinfo/mls</a><br></div></blockquote></div><br></div></div><=
/blockquote></div>
<span>_______________________________________________</span><br><span>MLS ma=
iling list</span><br><span>MLS@ietf.org</span><br><span>https://www.ietf.org=
/mailman/listinfo/mls</span><br></div></blockquote></body></html>=

--Apple-Mail-1D087BA6-9141-4A85-85F6-D8F4BAACD0DD--


From nobody Tue Oct 22 18:35:17 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94B5C120048 for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 18:35:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y2Qh4acq7kWg for <mls@ietfa.amsl.com>; Tue, 22 Oct 2019 18:35:13 -0700 (PDT)
Received: from mail-qk1-x734.google.com (mail-qk1-x734.google.com [IPv6:2607:f8b0:4864:20::734]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7B97120026 for <mls@ietf.org>; Tue, 22 Oct 2019 18:35:12 -0700 (PDT)
Received: by mail-qk1-x734.google.com with SMTP id 71so14446132qkl.0 for <mls@ietf.org>; Tue, 22 Oct 2019 18:35:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=igm55mC39kMoAah44BQdQXZ65ztj2Mv+AVfqNoHcFjI=; b=gkGxGjzFbrztufNtIf8wTV7yHEgAFR6b+rA+rOxEDzC8ddCW0PFSBTVs4QZfDx9jkp tHVCofhjTwMNmaPpu8zcdHybYT4jTVSliZimgI8HA1cnXx2+dYLnv7zYIC+Tb8F6DWBv gNK6UB1PTFve61vgVST02Rcp7cZJmKPO1Xp2U=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=igm55mC39kMoAah44BQdQXZ65ztj2Mv+AVfqNoHcFjI=; b=k6TwwdE3T7nyX9EDjLMS1ui53hRZhv8F5H6tlP40z1mBJ5cV/gZzZ1zvvYL3gg24IZ 1X/YpOF7G7V9m4a/TkcPfWoe33SUJf8NSIxoSutucX5jPR4iKgNvJaLZ4747ML74vdl+ RZpAkgrouqjaa9QBBkILcl4gxMnngCBXzzvBkXl4lwZCcJJR57Kp4zjhTwe587prPEr5 lvTOq34QiHrOvC3rmVAC/gr0cqIty4LQlZTXookISlw3S9YjfAj5Oy+Dygj11PSSlYjV 9rRpNGEXC7U8gy/0As6itPsVsc/7uEHbx8O6fm+A+b8757b/cGQoFTy48Rolwbxhkg1X Uw6A==
X-Gm-Message-State: APjAAAUnnyLHL/3TyojrGECMyWdSpXtKq8KY7/lpJBPCoiRHmQTUazLq fEhmCQJSZoHe/S3FAlrEfsvHu1z/KCtxZvFVMkQToA==
X-Google-Smtp-Source: APXvYqyeYYIh0ktyC0yrj7VuSaYsFLD6YCus7GcfDeosD9TYoB6P7d+x/xoI1X3lPSZoG/kap2InCdn2wkozEe46DTw=
X-Received: by 2002:a05:620a:2092:: with SMTP id e18mr6120075qka.222.1571794511365;  Tue, 22 Oct 2019 18:35:11 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com>
In-Reply-To: <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Tue, 22 Oct 2019 18:34:59 -0700
Message-ID: <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
To: Joel Alwen <jalwen@wickr.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000082c931059589ed30"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/IZGlKklULm2qxwtRmgEM7nnDItA>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 01:35:15 -0000

--00000000000082c931059589ed30
Content-Type: text/plain; charset="UTF-8"

> I'm curious what leads you to this conclusion. Suppose Alice produces an
> update defining new group key K. If the
> adversary can't already process the update then with RTreeKEM we get FS
> for K once the update is processed by all
> parties. For TreeKEM not only must that hold but we then need a further
> order n other parties to send out their own
> updates too. At least in terms of # of message flows and total bandwidth
> (and, most likely, in terms of time) that gap
> seems pretty big to me.
>

Let's work an example. Say we set a policy that everyone should try to
Update every 12h and those that don't will be removed after 24h. One user
is compromised. How long is it until full FS and PCS is restored?

   - If the user is prevented from sending new Updates:
      - Whether you use TreeKEM or RTreeKEM, the group is secure again
      after the user is removed. So after 24h at most, but 12h on
average if the
      user is compromised at a random time.
   - If the user is not prevented from sending new Updates:
   - With TreeKEM, you must wait until everyone sends an Update. We're
      secure again after 24h at most, per policy. The average would
trend toward
      12h if everybody's Updates are uniformly distributed.
      - With RTreeKEM, you must wait until the compromised user sends an
      Update. The user could be compromised immediately after sending
an Update,
      so we're secure again after 12h max. On average, you could say that it's
      more like 6h.

Yes, RTreeKEM has very good best-case behavior when you know exactly who is
compromised and when. But in reality, RTreeKEM can only be expected to
recover twice as fast in the best-case (6h vs 12h), and is the same in the
worst-case (24h).


> I dont follow. If I understood your earlier email correctly you said that
> updates in TreeKEM serve as a signal to others
> guiding their update policy. All I was proposing was to use a much more
> lightweight ACK msg in exactly the same way you
> thought updates were being used to guide policy.
>

The purpose of an ACK would be to let us know when everyone has processed
the most recent Update message -- that is, when FS has been achieved.
Without an ACK, the fact that RTreeKEM achieves FS faster than TreeKEM is
useless for applying any sort of policy to manage the FS properties of the
group, because nobody knows when FS is achieved.

Although of course, PCS still won't be achieved until everybody Updates. So
everybody Updates, everybody ACKs everybody's Updates, and the number of
messages sent is n^2. That's not scalable so the fact that RTreeKEM
achieves FS faster can't be enforced, which means it can't be relied on.

--00000000000082c931059589ed30
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"></div><div class=3D"gmail_quote"><blockqu=
ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px=
 solid rgb(204,204,204);padding-left:1ex">
I&#39;m curious what leads you to this conclusion. Suppose Alice produces a=
n update defining new group key K. If the<br>
adversary can&#39;t already process the update then with RTreeKEM we get FS=
 for K once the update is processed by all<br>
parties. For TreeKEM not only must that hold but we then need a further ord=
er n other parties to send out their own<br>
updates too. At least in terms of # of message flows and total bandwidth (a=
nd, most likely, in terms of time) that gap<br>
seems pretty big to me.<br></blockquote><div><br></div><div>Let&#39;s work =
an example. Say we set a policy that everyone should try to Update every 12=
h and those that don&#39;t will be removed after 24h. One user is compromis=
ed. How long is it until full FS and PCS is restored?</div><div><ul><li>If =
the user is prevented from sending new Updates:</li><ul><li>Whether you use=
 TreeKEM or RTreeKEM, the group is secure again after the user is removed. =
So after 24h at most, but 12h on average if the user is compromised at a ra=
ndom time.</li></ul><li>If the user is not prevented from sending new Updat=
es:<br></li><ul><li>With TreeKEM, you must wait until everyone sends an Upd=
ate. We&#39;re secure again after 24h at most, per policy. The average woul=
d trend toward 12h if everybody&#39;s Updates are uniformly distributed.<br=
></li><li>With RTreeKEM, you must wait until the compromised user sends an =
Update. The user could be compromised immediately after sending an Update, =
so we&#39;re secure again after 12h max. On average, you could say that it&=
#39;s more like 6h.<br></li></ul></ul><div>Yes, RTreeKEM has very good best=
-case behavior when you know exactly who is compromised and when. But in re=
ality, RTreeKEM can only be expected to recover twice as fast in the best-c=
ase (6h vs 12h), and is the same in the worst-case (24h).<br></div></div><d=
iv>=C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I dont follow. If I understood your earlier email correctly you said that u=
pdates in TreeKEM serve as a signal to others<br>
guiding their update policy. All I was proposing was to use a much more lig=
htweight ACK msg in exactly the same way you<br>
thought updates were being used to guide policy.<br></blockquote><div><br><=
/div><div>The purpose of an ACK would be to let us know when everyone has p=
rocessed the most recent Update message -- that is, when FS has been achiev=
ed. Without an ACK, the fact that RTreeKEM achieves FS faster than TreeKEM =
is useless for applying any sort of policy to manage the FS properties of t=
he group, because nobody knows when FS is achieved.</div><div><br></div><di=
v>Although of course, PCS still won&#39;t be achieved until everybody Updat=
es. So everybody Updates, everybody ACKs everybody&#39;s Updates, and the n=
umber of messages sent is n^2. That&#39;s not scalable so the fact that RTr=
eeKEM achieves FS faster can&#39;t be enforced, which means it can&#39;t be=
 relied on.<br></div></div></div>

--00000000000082c931059589ed30--


From nobody Wed Oct 23 05:39:00 2019
Return-Path: <dennis.jackson@cs.ox.ac.uk>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE36B12002E for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 05:38:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZoHU8eziH29l for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 05:38:57 -0700 (PDT)
Received: from relay12.mail.ox.ac.uk (relay12.mail.ox.ac.uk [129.67.1.163]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0548D120072 for <mls@ietf.org>; Wed, 23 Oct 2019 05:38:56 -0700 (PDT)
Received: from smtp6.mail.ox.ac.uk ([163.1.2.206]) by relay12.mail.ox.ac.uk with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNFuh-0003Yf-dL; Wed, 23 Oct 2019 13:38:55 +0100
Received: from 61.ip-51-38-113.eu ([51.38.113.61] helo=[192.168.2.2]) by smtp6.mail.ox.ac.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNFug-00038H-LV; Wed, 23 Oct 2019 13:38:54 +0100
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>, Joel Alwen <jalwen@wickr.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
From: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
Openpgp: preference=signencrypt
Autocrypt: addr=dennis.jackson@cs.ox.ac.uk; prefer-encrypt=mutual; keydata= mQINBFbAmb8BEADCLixsrAJyvknI95ZIZNVeDJbYvldeXpw7iyhrdUdRK69USU5S9EESulYh k1KlxDB5VfG8CCA/WzG1IonONdXmgLFa1NcmdVvkFjbXf5mbGYG+9pTkieM+UHikniAizIOi ibdTWEEc2opOAvpVypek4SSsfCoXfXqj0j5AXSapHiVzhhWuaXhKVuFdLtYwJDU/x0FXgStm erFMIOeZ5FLFnjkkNyEa1t3XCcf7bfgw8J86UmWzgkVLmtBYbDK0ZAFjtFep5Kps11iTDIa3 xYXzuqgkWwkg7b1mhn5gQUl/kKZqQbuG+Sk+BydjH8e1PJkO6p2eAprO0AoucRuuBl1pmg/F bf/WJC6/XD3AV87ERAdXbb9cH+vrRT8GpiNX5r+7OuXavc3/LNU9stqsdshXwdZlDyPyDIG2 Llj6hB4eS0tEpat3otcPDkXUjXjyOUQ6jKTNSZ+xTBtVTXznflDCGdn9GV0q+4ZbdRZ5tfXM DXM+uMqVxjvh2IjCrka7zf1rRWg1WZu+NrzAUrvPMPddDJfd8JNrIcvV+DIBxPVsUTJLEGt9 PW8LkQb5FrG7T6a813JYNoAtL4w7296UYmUpV1Kvv8otO+uH860x5Ci83ZCXb7gKr9Rankn5 Jcg+shWnDFgSq6uM/u3MmyRV2iw7aCSgcgfy4EPTojJdy3KjzQARAQABtCtEZW5uaXMgSmFj a3NvbiA8ZGVubmlzLmphY2tzb25AY3Mub3guYWMudWs+iQIwBBMBCgAaBAsJCAcCFQoCFgEC GQAFglsIFtUCngECmwMACgkQYQWndYzSRqzvkA//djyyIydK5jhxNFqmMvJTkTZwawKWV7Tc cEntsIwYsHw8ec9Edo/M6fwp8aFmddPnzRo0EBmh6KNm887VxgH0FXmcR7k8bD3qUzIhfq11 4ezWtTk0nWjpieEsFb20lCMZjK9dsfXVRgFrfe00x2lhjPWQ5G5mTkfX8KYcDs5nmc+13qHK Ux6e6aSdEa4mnxrT0NsEg2H2xKgwrGkNIxJO6snrh3A3mT6+2F8ZCiRWwmOhcHBzNCFp1enR bMJpNRhcmGBDNJ9TpnQHDRVE67ds3PC/vKDkYQ3tEIkdgc/KVGOo7+kZxSU/n1gARDZ4PYUw IGOM81aEhmrbXoF33Jbic2jnuLfqsC8uXeP6wGgGpEdGThQ+7zslOPDradgDZBlUmYenuwOb JwJEj+JbbZPcND17VrgVDzcM1rh1w9wcKrRDMIw/zLCpEDOfLRe2ad/V380q/Eh3qa4QrZE7 tnXcOTIZfxd1zZ6TcpOvMVYQPN5Zfrlazmw9bTsdkm3WVrzvxc9DJ/D5Ws+aMu+JfSD+C5Nd n5w2fW7OOiDudeFXj88CL7oBehPJ2ajCDmHd/vc1W7CSoPte6aHBgSGER9cWm5hpEOXacQt+ pEz/uMvq+zkDIydy9YL/8hDo5TsVA4Yo8wNdKOuyaStk/oh3WNda05N0jr8VhRMdxnLN/hWY Ely5Ag0EVsCZvwEQAOBD1BmNy7FWbpg9Tm3OfMNC/yLs6G7rk3OFw7BhpjHXHSsEge48HbvP lfdR9abA1cmbgYR7EyaOav1s9ugU7EtDCcK8zHZcaUg3gC+FdjsnkIQCkf/3HK2sxcbBSrkX 2Uu2jjufvZu10g/aavkCuTHIUiYAHhQU5kCkRI7NYvXIKmaPY2Km3YIVJ50x+4GlE/WVZk8w HpvisxDInBioziUjAIqTt0at5tE1ObZksl2eNHNCwlo15WE2hKIYCuJKb57wCBKaOKo/gSw/ yN2DX3HaU/PF+8rCikkKDhHDrefFwGkqBf3zHlrLiHIr+ONVZ8i9dxMyg5TERxjd3vZ4ha+7 8cr8G83HC8lSBEpPYmoeU4J8vWf8kjBlai0UmzyZRF3SeZlqldxo7zJhYq3xIsDGKVuSCn68 2TcoEsR5WS/Zjc0ZoH/YIpdVy8FRu45dJ2IUzHVyszMfNWKob7ZsQ9JCXiXypmIF6ut5mwv8 ddCMdG6Jdpvg1fr0coABNbJSrUM8uFEldmRFpBdbNx5xSCJjNo+QuTHOXWuO3/GFRmux8/kW TlfF3+dvff2Pw3CKENoysgcOflYShcjOv/03sQ6AfxTm2Jnh5dqJSoVnPWpcDyPqn3k4zoZW 0ISqorI8yehJbfT3C0J5iEX75c8vJWfUUjIhyO0CpHxATNW3j3QxABEBAAGJAh8EGAEIABMF AlbAmccJEGEFp3WM0kasAhsMAAD8JhAAtkUWMLjr1RYTSMPrmTp3NGZfNSblv0GGHtL7TvT1 kFwdT/hs29Gjrj0FffZE6RKDEGls9AL6LY/g3wA5WQsXaK0wqwb8MBeIPWvFPvVQbqrifN3A bpukTl4OCBOwJbHS/GO1V3AwaLl4l3U/+kzR7UsnszWs4kizE9lBJ0AYFbxB0xbPF6iI32Cm K3nrLPfkXBXw2xX01nOLxTx9E7YdVpP3Re1c96aBTflm4CAGUfTZ5xgQMW6rgJ8FBc3oLckt 9MT0qB5XkmKGI1kkRypN7hIFRBcPxegeO8S3fpBUOop5F0el24TVx6KJTktpLmlIfUsEQ0Lx CqNtUk1v3eMCoKmeky8WbFcUArRV4DKXDAK1e3C8poMaehRgfl8sjz6SuH1VXpCMLNPpNMtZ EK4FU+C0jGgJyHS9N1UZjq8Qa8FnYKruyPgTpKEAsqlo5vB6J8phiaKXxnren8HqIfzQdrt8 3M+raXc7+Fqis4pYS49vfIpxUzcqvKUiSgDGKemqMw9w9U5dBEQeLNW08uOKSjyENU4e1Ob/ IiimIpEPA5LEIhSfOP9CN9TculGqvo0g12XnB+g5AAtm1ohMkb33T17IR3rKkhlvIITuY1qi fZz7OgGbXh4G5oUHXNBOhXHaqRIzQCCRbBUFA09OyJBLWAGH6HcM/DeM0I7Ng55uMl8=
Message-ID: <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk>
Date: Wed, 23 Oct 2019 13:38:53 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Oxford-Username: exet4027
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/P7WRmzT9lddBmmrNek5JOTtXnZo>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 12:39:00 -0000

# PCS and Eviction

I think it is worth noting the trade off between evictions and leaving
members in the group. Evicting a member who is not updating improves the
group's PCS, but it harms the member's PCS. Worse, if the evicted member
subsequently rejoins then the group's PCS is also destroyed.

In short, quick eviction policies are not a panacea for PCS and in fact
are harmful in the current protocol. This motivates some kind of ability
to rejoin a group by proving knowledge of a recent epoch secret. This
was discussed as a way to recover from a faulty update / device state
loss at the last interim, but it would also be useful in this context.

# PFS Frequency

I think it is important to achieve PFS very quickly - ideally after
receiving a message the PFS guarantee should kick in. If a user receives
a message and immediately deletes it, then has their device compromised
it should indeed be gone forever.

Key Point: PFS should be a function of how frequently a user receives
messages, not limited by how frequently they send them, because we might
to 'use' the PFS property after receiving any particular message.

RTreeKEM achieves this, TreeKEM does not. TreeKEM with ACKS does, but
requires O(n) messages per content message which seems infeasible.

# PCS Frequency

I think in most use cases PCS can have a looser time bound than PFS. For
example, as frequently as user sends a message or a most a week is not
inherently unreasonable. On the other hand, a PFS window of a week would
have clear real world repercussions.

On 23/10/2019 02:34, Brendan McMillion wrote:
> [...]
> The purpose of an ACK would be to let us know when everyone has
> processed the most recent Update message -- that is, when FS has been
> achieved. Without an ACK, the fact that RTreeKEM achieves FS faster than
> TreeKEM is useless for applying any sort of policy to manage the FS
> properties of the group, because nobody knows when FS is achieved.
> 
> Although of course, PCS still won't be achieved until everybody Updates.
> So everybody Updates, everybody ACKs everybody's Updates, and the number
> of messages sent is n^2. That's not scalable so the fact that RTreeKEM
> achieves FS faster can't be enforced, which means it can't be relied on.

I'm not sure this is a good way to think about FS. If a device goes
offline permanently, FS can never be achieved in this definition. FS can
never be enforced in manner you seem to want in any realistic setting.

It is worthwhile clarifying what we mean by PFS in this context. It is
quite common for people to talk about PFS being a property of the
plaintext of a message and ask "at what point is it impossible to
recover that plaintext?". This leads to some requirement on the entire
set of recipients involving deletion of their key material and the
stored plaintext. The involvement of every recipient makes this a
non-local property which can't be meaningfully enforced.

I think a more useful notion is to talk about PFS with respect to some
particular ciphertext and recipient. At what future time, would an
adversary with a copy of the network traffic and the compromised state
of the recipient at that time, be incapable of decrypting the
ciphertext? This definition means we do not have to worry about whether
the application stores the decrypted plaintext or not. Nor do we have to
worry about what other recipients do. This gives us a property that can
actually be enforced locally and will hold globally IF the other
recipients are also honest and received our message.

Best,
Dennis


From nobody Wed Oct 23 07:51:02 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36CBA1209A2 for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 07:50:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l8HhaUZvQ5XA for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 07:50:52 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [80.241.60.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96D87120932 for <mls@ietf.org>; Wed, 23 Oct 2019 07:50:51 -0700 (PDT)
Received: from smtp2.mailbox.org (smtp2.mailbox.org [80.241.60.241]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id CBB70A373D for <mls@ietf.org>; Wed, 23 Oct 2019 16:50:49 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp2.mailbox.org ([80.241.60.241]) by spamfilter05.heinlein-hosting.de (spamfilter05.heinlein-hosting.de [80.241.56.123]) (amavisd-new, port 10030) with ESMTP id V4ZTtYunsPRr for <mls@ietf.org>; Wed, 23 Oct 2019 16:50:46 +0200 (CEST)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <30eb3e89-7d6b-f23a-fdd8-38c34f298fae@datashrine.de>
Date: Wed, 23 Oct 2019 16:50:45 +0200
MIME-Version: 1.0
In-Reply-To: <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/PQFie2InT75c9pzSGn4vye7Abv8>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 14:50:58 -0000

> Let's work an example. Say we set a policy that everyone should try to Update
> every 12h and those that don't will be removed after 24h. One user is
> compromised. How long is it until full FS and PCS is restored?
> 
>   * If the user is prevented from sending new Updates:
>       o Whether you use TreeKEM or RTreeKEM, the group is secure again after the
>         user is removed. So after 24h at most, but 12h on average if the user is
>         compromised at a random time.
>   * If the user is not prevented from sending new Updates:
>       o With TreeKEM, you must wait until everyone sends an Update. We're secure
>         again after 24h at most, per policy. The average would trend toward 12h
>         if everybody's Updates are uniformly distributed.
>       o With RTreeKEM, you must wait until the compromised user sends an Update.
>         The user could be compromised immediately after sending an Update, so
>         we're secure again after 12h max. On average, you could say that it's
>         more like 6h.
> 

You're right in this particular example (although I think that eviction after
24h is pretty draconic). However, if you're looking at larger groups (>10.000
members) you might want to scale down the update frequency to avoid everyone
having to process 10.000 updates of a 10.000-member group every 12h. I'm not an
implementer, but I could imagine that this is pretty costly on battery powered
devices (please feel free to correct me if I'm wrong). In those cases, getting
FS for everyone just by processing a single update of any member is pretty
significant. I guess my expectation is that in large groups, other constraints
that also exist with "simple" TreeKEM will dictate a lower update frequency and
thus PCS guarantees will be rather weak, but that doesn't mean that FS
guarantees have to be.

Also keep in mind that even if it's not very beneficial in the example, we
generally get substantially better FS guarantees at a relatively small price in
bandwidth and local computation. Throwing that away because the upside is not
very big in some cases seems unnecessary to me.

If I understand you correctly, then your concern is that implementers could
think that due to the guarantees provided by RTreeKEM, they can get away with a
lower update frequency while maintaining the same security guarantees. That
seems to be a problem that can be solved by providing clear information on what
guarantees are provided upon an update and/or emphasizing the difference between
FS and PCS.

Cheers,
Konrad


From nobody Wed Oct 23 08:59:25 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C96112004D for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 08:59:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.423
X-Spam-Level: 
X-Spam-Status: No, score=-1.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.226, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NGoSqR5WqZuy for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 08:59:19 -0700 (PDT)
Received: from mail-io1-f45.google.com (mail-io1-f45.google.com [209.85.166.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60D9C120043 for <mls@ietf.org>; Wed, 23 Oct 2019 08:59:19 -0700 (PDT)
Received: by mail-io1-f45.google.com with SMTP id w12so25539927iol.11 for <mls@ietf.org>; Wed, 23 Oct 2019 08:59:19 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=q4ZId6xynGTHW4w/iVfHrRATTz0F21MZxNdR6zeSR08=; b=kgcxGwzBM3C/TVrLuR9vPrtQHBlgaWoCqt0CsK+g3kP4H71Knodkqew8ETg/Pkb3bf rLkNEEeL07Gwqn5uCnNMV0ipC9MAHh030iy9AK0t8oGIDzraHYzesv5HoUR3h1QFaFQl waoWQGSod4hrd7zwwinOe87Z7jUQ6GxQFJACA5QWkIGmdQsiRlAzHRizZwOQ1XjQvCNL VhtNkHa2DBHsliKRd2pzuSsMBrdSaUCJ7vyRntOLogDwC6Z4UsolXyjzxQYMu/HcqP/T AUJynYtxmQwkPtXTLi88RDBSl/vRLA+TcMuDdSO8vBQV7GIElbF0TyCOWM7NLHIY3XRT BddA==
X-Gm-Message-State: APjAAAXu55HFBEbr9h2oHOjc6z9pubBg8wMD1kTYwl541O+f5r+CnhIt x//HCYnbNVNTxyIszsfV6Vb7XX0facWsg1DkoY4=
X-Google-Smtp-Source: APXvYqx+8c6ZlxM1ljTqD3LuR+7DXnsfKINziyx5P2Q8SaBFD4A04DLxRa869UFd1aoQandXWCg3JR4JINUTQXGpBfk=
X-Received: by 2002:a05:6638:a0e:: with SMTP id 14mr9963237jan.4.1571846358260;  Wed, 23 Oct 2019 08:59:18 -0700 (PDT)
MIME-Version: 1.0
References: <71e63449-abba-854d-2962-eac3a64a80d0@wickr.com> <398CD178-3DB6-4D70-B230-3362BE63A3BE@gmail.com> <44b5f5f7-79e1-c9e3-cde0-d75074168469@wickr.com> <5DAAF42C-C4CE-4631-A6E3-A5A5C1D0143A@gmail.com> <CAMvzKsg0895RkaffJA7ZMQxKUr3uF3w-FZ3=T40YUDZd8TkisQ@mail.gmail.com> <16FB72F8-FBAF-4600-8CCE-0C17C3BA8B2A@gmail.com>
In-Reply-To: <16FB72F8-FBAF-4600-8CCE-0C17C3BA8B2A@gmail.com>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Wed, 23 Oct 2019 11:59:08 -0400
Message-ID: <CAMvzKsjoC401fiaQEowGf0sFcfkjbF=rPk+PH5Guv7fF+pie5A@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d35f63059595ffd6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/DHlGxF3quHadpxB9EXquouPAY3Q>
Subject: Re: [MLS] UPKE for X25519/X448
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 15:59:22 -0000

--000000000000d35f63059595ffd6
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Karthik.

Yes, our scheme already withstands malicious randomness when analyzed as
UPKE in isolation. We actually gave
both definitions in the paper, and satisfy the strongest. But we have not
propagated the stronger UPKE notion
into a formal continuous group key agreement game. Will not be hard, but we
wanted to get the paper out.

We have not captured yes a clean way to get fine-grained resilience to
insider attacks at the level you are suggesting,
since in the general notion there are no trees, or specific TreeKEM
structure (however, our safety predicate for TreeKEM
is scheme specific, --- because it has to be, --- which cold be viewed as
yet another advantage of RTreeKEM). But
resilience to bad update randomness is correlated to the property you are
saying: even though people outside a given sub-ttree
could somehow influence public-secret keys (by being on co-path and using
UPKE in place of PKE), they cannot violate
security of these nodes by being malicious. Hopefully we will add this to
the paper soon, but for now we wanted to make sure
we can support the X-curves, which we hopefully can.

Yevgeniy




On Tue, Oct 22, 2019 at 2:42 PM Karthikeyan Bhargavan <
karthik.bhargavan@gmail.com> wrote:

> Hi Yevgeniy,
>
> Thanks for the clarification,
>
> We have been formally analyzing TreeKEM against malicious insiders and it
> actually has some nice invariants.
>
> In particular: the secret (and private key) for each node is only
> determined by the members of the
> subtree rooted at that node. So if one of these subgroup members is
> malicious, it can of course
> set the subgroup key to whatever it likes. But outsiders do not have the
> ability to influence a subgroup=E2=80=99s keys.
> (There is an exception to this rule for late joiners, making the invarian=
t
> a bit more complicated than the one I have informally stated here.)
>
> I believe this agains-outsiders guarantee is a good invariant to have, an=
d
> some of my questions about UPKE were in order to see how we could keep a
> version of this invariant.
>
> Best,
> Karthik
>
>
>
> On 22 Oct 2019, at 19:45, Yevgeniy Dodis <dodis@cs.nyu.edu> wrote:
>
> Good point, Karthik, we should definitely add this check (and possibly
> something else).
>
> As a small theoretical note, in our current model the users are considere=
d
> honest rather than malicious.
> However, to model and prevent double-join attacks, the attacker is allowe=
d
> to request honest people not
> to erase their local randomness (e.g., things like d' used above). So thi=
s
> is why in our current description
> we do not have to explicitly worry about d' being malicious.
>
> We are pretty sure that with a check like the one you suggest we can also
> withstand adversarial randomness
> for UPKE. But we did not explore this yet - it is on the next to-do list.
> In general, we don't consider too many insider
> attacks (beside double join) for now, since TreeKEM and variants are not
> secure against them anyway. Great
> direction for the future.
>
> Yevgeniy
>
> On Tue, Oct 22, 2019 at 12:30 PM Karthikeyan Bhargavan <
> karthik.bhargavan@gmail.com> wrote:
>
>> Yes, the sender would have to find a =E2=80=9Cd=E2=80=99=E2=80=9D such t=
hat HKDF(sksize, d', "",
>> "derive UPKE delta=E2=80=9D) falls in a small set of values.
>> This is a small risk, but it can be further reduced if we used epk in th=
e
>> derivation.
>> E.g. why not define:
>>
>> d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D=
)
>>
>> This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=
=99s old public
>> key, which makes it harder for it to do malicious things.
>>
>> -Karthik
>>
>>
>> > On 22 Oct 2019, at 17:05, Joel Alwen <jalwen@wickr.com> wrote:
>> >
>> > Good question!
>> >
>> > I'll see if I can think of anything intelligent to say about it. :-)
>> >
>> > But one thing that comes to mind is that the sender gets to choose
>> "only" d', not d. Instead d :=3D HKDF(d') so to get d=3D0
>> > you'd have to first invert HKDF.
>> >
>> > - Joel
>> >
>> > On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:
>> >> Sorry if this is already in the paper, but a question.
>> >>
>> >>> - UPKE-Decrypt(sk, (c1, c2)):
>> >>> epk, context :=3D HPKE.SetupBaseR(c1, sk, "")
>> >>> d' || m :=3D context.Open("", c2)
>> >>> d :=3D HKDF(sksize, d', "", "derive UPKE delta")
>> >>> sk' :=3D Mult(sk, d)
>> >>> return (m, sk=E2=80=99)
>> >>
>> >> I believe it is important for the recipient to do some validation
>> before returning from UPKE-Decrypt.
>> >>
>> >> For example, what if the (malicious) sender set d to =E2=80=9C0=E2=80=
=9D (whatever
>> that means in the DH group).
>> >> This would mean that the resulting key sk=E2=80=99 becomes =E2=80=9C0=
=E2=80=9D too, hence a
>> non-member has been able to force the recipient group=E2=80=99s private =
key to a
>> particular value, which is not ideal.
>> >> What conditions should we add to avoid this kind of key-forcing attac=
k
>> from happening?
>> >>
>> >> -Karthik
>> >>
>> >>
>> >>
>> >>>
>> >>>
>> >>> References
>> >>> ----------
>> >>> [1] http:\\ia.cr\2019\1189.
>> >>>
>> >>> _______________________________________________
>> >>> MLS mailing list
>> >>> MLS@ietf.org
>> >>> https://www.ietf.org/mailman/listinfo/mls
>> >>
>> >
>> > _______________________________________________
>> > MLS mailing list
>> > MLS@ietf.org
>> > https://www.ietf.org/mailman/listinfo/mls
>>
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
>
>

--000000000000d35f63059595ffd6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Karthik.<div><br></div><div>Yes, our scheme already wit=
hstands malicious randomness when analyzed as UPKE in isolation. We actuall=
y gave=C2=A0</div><div>both definitions in the paper, and satisfy the stron=
gest. But we have not propagated the stronger UPKE notion</div><div>into a =
formal continuous group key agreement game. Will not be hard, but we wanted=
 to get the paper out.=C2=A0</div><div><br></div><div>We have not captured =
yes a clean way to get fine-grained resilience=C2=A0to insider attacks at t=
he level you=C2=A0are suggesting,</div><div>since in the general notion the=
re are no trees, or specific TreeKEM structure (however, our safety predica=
te for TreeKEM</div><div>is scheme specific, --- because it has to be, --- =
which cold be viewed as yet another advantage of RTreeKEM). But</div><div>r=
esilience to bad update randomness is correlated to the property you are sa=
ying: even though people outside a given sub-ttree</div><div>could somehow =
influence public-secret keys (by being on co-path and using UPKE in place o=
f PKE), they cannot violate</div><div>security of these nodes by being mali=
cious. Hopefully we will add this to the paper soon, but for now we wanted =
to make sure</div><div>we can support the X-curves, which we hopefully can.=
</div><div><br></div><div>Yevgeniy</div><div><br></div><div><br></div><div>=
<br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gm=
ail_attr">On Tue, Oct 22, 2019 at 2:42 PM Karthikeyan Bhargavan &lt;<a href=
=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank">karthik.bhargavan=
@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex"><div>Hi Yevgeniy,<div><br></div><div>Thanks for the clarificatio=
n,</div><div><br></div><div>We have been formally analyzing TreeKEM against=
 malicious insiders and it actually has some nice invariants.</div><div><br=
></div><div>In particular: the secret (and private key) for each node is on=
ly determined by the members of the</div><div>subtree rooted at that node. =
So if one of these subgroup members is malicious, it can of course</div><di=
v>set the subgroup key to whatever it likes. But outsiders do not have the =
ability to influence a subgroup=E2=80=99s keys.</div><div>(There is an exce=
ption to this rule for late joiners, making the invariant a bit more compli=
cated than the one I have informally stated here.)</div><div><br></div><div=
>I believe this agains-outsiders guarantee is a good invariant to have, and=
 some of my questions about UPKE were in order to see how we could keep a v=
ersion of this invariant.</div><div><br></div><div>Best,</div><div>Karthik<=
/div><div><br></div><div><br><div><br><blockquote type=3D"cite"><div>On 22 =
Oct 2019, at 19:45, Yevgeniy Dodis &lt;<a href=3D"mailto:dodis@cs.nyu.edu" =
target=3D"_blank">dodis@cs.nyu.edu</a>&gt; wrote:</div><br><div><div dir=3D=
"ltr">Good point, Karthik, we should definitely add this check (and possibl=
y something else).<div><br></div><div>As a small theoretical note, in our c=
urrent model the users are considered honest rather than malicious.</div><d=
iv>However, to model and prevent double-join attacks, the attacker is allow=
ed to request honest=C2=A0people not</div><div>to erase their local randomn=
ess (e.g., things like d&#39; used above). So this is why in our current de=
scription</div><div>we do not have to explicitly worry about d&#39; being m=
alicious.</div><div><br></div><div>We are pretty sure that with a check lik=
e the one you suggest we can also withstand adversarial randomness</div><di=
v>for UPKE. But we did not explore this yet - it is on the next to-do list.=
 In general, we don&#39;t consider too many insider</div><div>attacks (besi=
de double join) for now, since TreeKEM and variants are not secure against =
them anyway. Great=C2=A0</div><div>direction for the future.</div><div><br>=
</div><div>Yevgeniy</div></div><br><div class=3D"gmail_quote"><div dir=3D"l=
tr" class=3D"gmail_attr">On Tue, Oct 22, 2019 at 12:30 PM Karthikeyan Bharg=
avan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank">k=
arthik.bhargavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gma=
il_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,2=
04,204);padding-left:1ex">Yes, the sender would have to find a =E2=80=9Cd=
=E2=80=99=E2=80=9D such that HKDF(sksize, d&#39;, &quot;&quot;, &quot;deriv=
e UPKE delta=E2=80=9D) falls in a small set of values.<br>
This is a small risk, but it can be further reduced if we used epk in the d=
erivation.<br>
E.g. why not define:<br>
<br>
d :=3D HKDF(sksize, d=E2=80=99, epk, =E2=80=9Cderive UPKE delta=E2=80=9D)<b=
r>
<br>
This way, the attacker has to choose d=E2=80=99 based on the node=E2=80=99s=
 old public key, which makes it harder for it to do malicious things.<br>
<br>
-Karthik<br>
<br>
<br>
&gt; On 22 Oct 2019, at 17:05, Joel Alwen &lt;<a href=3D"mailto:jalwen@wick=
r.com" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:<br>
&gt; <br>
&gt; Good question!<br>
&gt; <br>
&gt; I&#39;ll see if I can think of anything intelligent to say about it. :=
-)<br>
&gt; <br>
&gt; But one thing that comes to mind is that the sender gets to choose &qu=
ot;only&quot; d&#39;, not d. Instead d :=3D HKDF(d&#39;) so to get d=3D0<br=
>
&gt; you&#39;d have to first invert HKDF.<br>
&gt; <br>
&gt; - Joel<br>
&gt; <br>
&gt; On 22/10/2019 17:02, Karthikeyan Bhargavan wrote:<br>
&gt;&gt; Sorry if this is already in the paper, but a question.<br>
&gt;&gt; <br>
&gt;&gt;&gt; - UPKE-Decrypt(sk, (c1, c2)):<br>
&gt;&gt;&gt; epk, context :=3D HPKE.SetupBaseR(c1, sk, &quot;&quot;)<br>
&gt;&gt;&gt; d&#39; || m :=3D context.Open(&quot;&quot;, c2)<br>
&gt;&gt;&gt; d :=3D HKDF(sksize, d&#39;, &quot;&quot;, &quot;derive UPKE de=
lta&quot;)<br>
&gt;&gt;&gt; sk&#39; :=3D Mult(sk, d)<br>
&gt;&gt;&gt; return (m, sk=E2=80=99)<br>
&gt;&gt; <br>
&gt;&gt; I believe it is important for the recipient to do some validation =
before returning from UPKE-Decrypt.<br>
&gt;&gt; <br>
&gt;&gt; For example, what if the (malicious) sender set d to =E2=80=9C0=E2=
=80=9D (whatever that means in the DH group).<br>
&gt;&gt; This would mean that the resulting key sk=E2=80=99 becomes =E2=80=
=9C0=E2=80=9D too, hence a non-member has been able to force the recipient =
group=E2=80=99s private key to a particular value, which is not ideal.<br>
&gt;&gt; What conditions should we add to avoid this kind of key-forcing at=
tack from happening?<br>
&gt;&gt; <br>
&gt;&gt; -Karthik<br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt; <br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; References<br>
&gt;&gt;&gt; ----------<br>
&gt;&gt;&gt; [1] http:\\<a href=3D"http://ia.cr/" rel=3D"noreferrer" target=
=3D"_blank">ia.cr</a>\2019\1189.<br>
&gt;&gt;&gt; <br>
&gt;&gt;&gt; _______________________________________________<br>
&gt;&gt;&gt; MLS mailing list<br>
&gt;&gt;&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org=
</a><br>
&gt;&gt;&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"n=
oreferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><=
br>
&gt;&gt; <br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; MLS mailing list<br>
&gt; <a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
&gt; <a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>
</div></blockquote></div><br></div></div></blockquote></div>

--000000000000d35f63059595ffd6--


From nobody Wed Oct 23 11:08:38 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D37412008C for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 11:08:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.423
X-Spam-Level: 
X-Spam-Status: No, score=-1.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.226, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v-cqO2S3FztG for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 11:08:34 -0700 (PDT)
Received: from mail-il1-f174.google.com (mail-il1-f174.google.com [209.85.166.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E98DD120090 for <mls@ietf.org>; Wed, 23 Oct 2019 11:08:33 -0700 (PDT)
Received: by mail-il1-f174.google.com with SMTP id m16so13390335iln.13 for <mls@ietf.org>; Wed, 23 Oct 2019 11:08:33 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=rWBsd0NQ/5tzhemI7Ig2D13Oq9Ut3KDIEa4vWE3qa4Y=; b=g9Og1MktQ0AycFfxpOxH5sQXPhDbieOOc1XS0muga7oclIUxLgqIMFI11tXgCy3CXr 8vZ7XmZi3hiFUCcL0XDGNeAFxalh66eXdX+ihksvKwJeDvxC5YpFwr1Udk02nTkbg5C8 UMWC0ACHIE6N8547L5U1wkIGTS1fvS6U4fd04gWwmYXZufeUzRe+0timQt/iwKkdvy3o 8IgtMCiSLoo1AnJF4MGfcJeJ/DGJr5LxpymATvXKkcy0tVQop8BEbhTaQVBHCBzE2BON piD4fai3QcVoATQpVbq2AzW4C8NwuxtqsD2xOr8FHYtRUtstkNjjartwXUO7cHJtOB85 0rmA==
X-Gm-Message-State: APjAAAUwbyJAlKdvm68YebSjWRthzQluIbVz0+Jj8YFm7fUUQcTF7VbF ljTuyJ5BtrPSH8pfN5F7DaWnmHd3JqgXHmt7+20=
X-Google-Smtp-Source: APXvYqySFcELRd5yjj8bk+qLXf7gO6n5qsUuKYC/7LdheZ3G+EEoSgViDfbn28qd7IVqRwiPGS/deAskm8bRnkBl1R8=
X-Received: by 2002:a92:380e:: with SMTP id f14mr40799411ila.47.1571854111956;  Wed, 23 Oct 2019 11:08:31 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <30eb3e89-7d6b-f23a-fdd8-38c34f298fae@datashrine.de>
In-Reply-To: <30eb3e89-7d6b-f23a-fdd8-38c34f298fae@datashrine.de>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Wed, 23 Oct 2019 14:08:21 -0400
Message-ID: <CAMvzKsi01Np1-rtu-TVHxR1UG6_XLxXqh3wLL3e96FkayakOAg@mail.gmail.com>
To: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Cc: ML Messaging Layer Security <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fb63f3059597cdbc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/zzQGnpku6Tth9IC8XDDB15O_poE>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 18:08:36 -0000

--000000000000fb63f3059597cdbc
Content-Type: text/plain; charset="UTF-8"

Thank you, Konrad, Joel and Dennis, totally agree with your responses. But
also grateful for Brendan
for voicing his concern, as it clarifies some confusion people might have
about combination of FS and PCS.
Couple of small points to hopefully reach consensus and convince Brendan.

1) As others said, the view "what should be done by users so that given
epoch key k is secure NO MATTER
WHAT THE ATTACKER DOES FROM NOW ON" is useful, but way too limiting. In
particular, under such limiting
and narrow point of view, no "security" is possible if one user is not
processing updates for a while, unless one mandates
"kicking out" such users. Which, as others pointed, is problematic in many
settings. But also does not allow to compare
schemes, as none of them will be secure under such a narrow viewpoint.

2) But even with the above super-narrow and restrictive view of forward
security, RTreeKEM has a clear advantage over
TreeKEM. Imagine the system is currently secure, and some control operation
(update/add/remove) is issued.
What should happen for the current key to be secure no matter what?
- In RTreeKEM, as long as all users PROCESSED this operation, the key is
secure no matter what.
- In TreeKEM, as Brandon pointed out, if you want to be absolutely sure,
more or less every user has to UPDATE
(sometimes you could get lucky and need less, but this is super-dependent
on what happened up to now).

So this is a huge difference - just passively processing something vs
issuing an actual update operation.

3) As others pointed out, a better way to think of FS/PCS combination might
be this. Assuming some sequence of
operations (Init, Add, Remove, Update, Corrupt) happened. Never mind how
and why. The question is which "epoch keys"
are secure? Ignoring the subtlety explained in the paper (about attacker
forcing honest users to "not delete" stuff),
in RTreeKEM, the answer is very clear, intuitive, and clearly OPTIMAL:
- All keys k_t, where all users corrupted at some time t' before t, updated
their keys from time t' to t.

In contrast, I cannot give an easy answer for TreeKEM. On a positive, we
have a polynomial time predicate which
gives an answer to this question. And has to do with graph reachability
question we explain in the paper. On a negative,
this predicate is very non-intuitive, and it very hard to visualize or
understand. In is also intricately specific to TreeKEM
(i.e., cannot be described as some general property of group messaging
protocols). More importantly, in most situations
the set of secure keys under TreeKEM will be dramatically smaller than for
RTreeKEM (see examples given in the
paper, by Joel, and in the slides we sent).

Thus, in many concrete situations "here is what the attacker knows; what is
secure?", RTreeKEM simply leaves more keys
secure.

Yevgeniy

On Wed, Oct 23, 2019 at 10:51 AM Konrad Kohbrok <
konrad.kohbrok@datashrine.de> wrote:

> > Let's work an example. Say we set a policy that everyone should try to
> Update
> > every 12h and those that don't will be removed after 24h. One user is
> > compromised. How long is it until full FS and PCS is restored?
> >
> >   * If the user is prevented from sending new Updates:
> >       o Whether you use TreeKEM or RTreeKEM, the group is secure again
> after the
> >         user is removed. So after 24h at most, but 12h on average if the
> user is
> >         compromised at a random time.
> >   * If the user is not prevented from sending new Updates:
> >       o With TreeKEM, you must wait until everyone sends an Update.
> We're secure
> >         again after 24h at most, per policy. The average would trend
> toward 12h
> >         if everybody's Updates are uniformly distributed.
> >       o With RTreeKEM, you must wait until the compromised user sends an
> Update.
> >         The user could be compromised immediately after sending an
> Update, so
> >         we're secure again after 12h max. On average, you could say that
> it's
> >         more like 6h.
> >
>
> You're right in this particular example (although I think that eviction
> after
> 24h is pretty draconic). However, if you're looking at larger groups
> (>10.000
> members) you might want to scale down the update frequency to avoid
> everyone
> having to process 10.000 updates of a 10.000-member group every 12h. I'm
> not an
> implementer, but I could imagine that this is pretty costly on battery
> powered
> devices (please feel free to correct me if I'm wrong). In those cases,
> getting
> FS for everyone just by processing a single update of any member is pretty
> significant. I guess my expectation is that in large groups, other
> constraints
> that also exist with "simple" TreeKEM will dictate a lower update
> frequency and
> thus PCS guarantees will be rather weak, but that doesn't mean that FS
> guarantees have to be.
>
> Also keep in mind that even if it's not very beneficial in the example, we
> generally get substantially better FS guarantees at a relatively small
> price in
> bandwidth and local computation. Throwing that away because the upside is
> not
> very big in some cases seems unnecessary to me.
>
> If I understand you correctly, then your concern is that implementers could
> think that due to the guarantees provided by RTreeKEM, they can get away
> with a
> lower update frequency while maintaining the same security guarantees. That
> seems to be a problem that can be solved by providing clear information on
> what
> guarantees are provided upon an update and/or emphasizing the difference
> between
> FS and PCS.
>
> Cheers,
> Konrad
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000fb63f3059597cdbc
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thank you, Konrad, Joel and Dennis, totally agree with you=
r responses. But also grateful for Brendan<div>for voicing his concern, as =
it clarifies some confusion people might have about combination of FS and P=
CS.</div><div>Couple of small points to hopefully reach consensus and convi=
nce Brendan.</div><div><br></div><div>1) As others said, the view &quot;wha=
t should be done by users so that given epoch key k is secure NO MATTER=C2=
=A0</div><div>WHAT THE ATTACKER DOES FROM NOW ON&quot; is useful, but way t=
oo limiting. In particular, under such limiting=C2=A0</div><div>and narrow =
point of view, no &quot;security&quot; is possible if one user is not proce=
ssing updates for a while, unless one mandates=C2=A0</div><div>&quot;kickin=
g out&quot; such users. Which, as others pointed, is problematic in many se=
ttings. But also does not allow to compare</div><div>schemes, as none of th=
em will be secure under such a narrow viewpoint.</div><div><br></div><div>2=
) But even with the above super-narrow and restrictive view of forward secu=
rity, RTreeKEM has a clear advantage over</div><div>TreeKEM. Imagine the sy=
stem is currently secure, and some control operation (update/add/remove) is=
 issued.</div><div>What should happen for the current key to be secure no m=
atter what?</div><div>- In RTreeKEM, as long as all users PROCESSED this op=
eration, the key is secure no matter what.</div><div>- In TreeKEM, as Brand=
on pointed out, if you want to be absolutely sure, more or less every user =
has to UPDATE</div><div>(sometimes you could get lucky and need less, but t=
his is super-dependent on what happened up to now).</div><div><br></div><di=
v>So this is a huge difference - just passively processing something vs iss=
uing an actual update operation.</div><div><br></div><div>3) As others poin=
ted out, a better way to think of FS/PCS combination might be this. Assumin=
g some sequence of=C2=A0</div><div>operations (Init, Add, Remove, Update, C=
orrupt) happened. Never mind how and why. The question is which &quot;epoch=
 keys&quot;</div><div>are secure? Ignoring the subtlety explained in the pa=
per (about attacker forcing honest users to &quot;not delete&quot; stuff),=
=C2=A0</div><div>in RTreeKEM, the answer is very clear, intuitive, and clea=
rly OPTIMAL:</div><div>- All keys k_t, where all users corrupted at some ti=
me t&#39; before t, updated their keys from time t&#39; to t.</div><div><br=
></div><div>In contrast, I cannot give an easy answer for TreeKEM. On a pos=
itive, we have a polynomial time predicate which</div><div>gives an answer =
to this question.  And has to do with graph reachability=C2=A0 question we =
explain in the paper. On a negative,=C2=A0</div><div>this predicate is very=
 non-intuitive, and it very hard to visualize or understand. In is also int=
ricately specific to TreeKEM</div><div>(i.e., cannot be described as some g=
eneral property of group messaging protocols). More importantly, in most si=
tuations</div><div>the set of secure keys under TreeKEM will be dramaticall=
y smaller than for RTreeKEM (see examples given in the</div><div>paper, by =
Joel, and in the slides we sent).=C2=A0</div><div><br></div><div>Thus, in m=
any concrete situations &quot;here is what the attacker knows; what is secu=
re?&quot;, RTreeKEM simply leaves more keys</div><div>secure.</div><div><br=
></div><div>Yevgeniy</div></div><br><div class=3D"gmail_quote"><div dir=3D"=
ltr" class=3D"gmail_attr">On Wed, Oct 23, 2019 at 10:51 AM Konrad Kohbrok &=
lt;<a href=3D"mailto:konrad.kohbrok@datashrine.de">konrad.kohbrok@datashrin=
e.de</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1=
ex">&gt; Let&#39;s work an example. Say we set a policy that everyone shoul=
d try to Update<br>
&gt; every 12h and those that don&#39;t will be removed after 24h. One user=
 is<br>
&gt; compromised. How long is it until full FS and PCS is restored?<br>
&gt; <br>
&gt;=C2=A0 =C2=A0* If the user is prevented from sending new Updates:<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0o Whether you use TreeKEM or RTreeKEM, the g=
roup is secure again after the<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0user is removed. So after 24h at most=
, but 12h on average if the user is<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0compromised at a random time.<br>
&gt;=C2=A0 =C2=A0* If the user is not prevented from sending new Updates:<b=
r>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0o With TreeKEM, you must wait until everyone=
 sends an Update. We&#39;re secure<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0again after 24h at most, per policy. =
The average would trend toward 12h<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0if everybody&#39;s Updates are unifor=
mly distributed.<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0o With RTreeKEM, you must wait until the com=
promised user sends an Update.<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0The user could be compromised immedia=
tely after sending an Update, so<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0we&#39;re secure again after 12h max.=
 On average, you could say that it&#39;s<br>
&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0more like 6h.<br>
&gt; <br>
<br>
You&#39;re right in this particular example (although I think that eviction=
 after<br>
24h is pretty draconic). However, if you&#39;re looking at larger groups (&=
gt;10.000<br>
members) you might want to scale down the update frequency to avoid everyon=
e<br>
having to process 10.000 updates of a 10.000-member group every 12h. I&#39;=
m not an<br>
implementer, but I could imagine that this is pretty costly on battery powe=
red<br>
devices (please feel free to correct me if I&#39;m wrong). In those cases, =
getting<br>
FS for everyone just by processing a single update of any member is pretty<=
br>
significant. I guess my expectation is that in large groups, other constrai=
nts<br>
that also exist with &quot;simple&quot; TreeKEM will dictate a lower update=
 frequency and<br>
thus PCS guarantees will be rather weak, but that doesn&#39;t mean that FS<=
br>
guarantees have to be.<br>
<br>
Also keep in mind that even if it&#39;s not very beneficial in the example,=
 we<br>
generally get substantially better FS guarantees at a relatively small pric=
e in<br>
bandwidth and local computation. Throwing that away because the upside is n=
ot<br>
very big in some cases seems unnecessary to me.<br>
<br>
If I understand you correctly, then your concern is that implementers could=
<br>
think that due to the guarantees provided by RTreeKEM, they can get away wi=
th a<br>
lower update frequency while maintaining the same security guarantees. That=
<br>
seems to be a problem that can be solved by providing clear information on =
what<br>
guarantees are provided upon an update and/or emphasizing the difference be=
tween<br>
FS and PCS.<br>
<br>
Cheers,<br>
Konrad<br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br>
</blockquote></div>

--000000000000fb63f3059597cdbc--


From nobody Wed Oct 23 16:40:26 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9AD47120103 for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 16:40:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NJc9-b_xxEQs for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 16:40:23 -0700 (PDT)
Received: from mail-wm1-x32d.google.com (mail-wm1-x32d.google.com [IPv6:2a00:1450:4864:20::32d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9864C12001A for <mls@ietf.org>; Wed, 23 Oct 2019 16:40:23 -0700 (PDT)
Received: by mail-wm1-x32d.google.com with SMTP id q70so692030wme.1 for <mls@ietf.org>; Wed, 23 Oct 2019 16:40:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=aNG+yaphvebGktBP2KBQbMj/3fetF2pnGhCoNYWJ1y0=; b=OpjmpcqUw3ip84X4fsY36dFhdWk46DtnL8ANYMeWZL5UMQiprXmq2tiiThkocDJnrn XzAs6gcfz34wXMZtGe9RbOPMtb2UoupBdIeEgwZ1RBVqQfmTlZJqDWGh1Uf5QOg/pK3K UdcfiOfZ2OUClQ3bQTLPwe02qx6tsXHaX0BAQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=aNG+yaphvebGktBP2KBQbMj/3fetF2pnGhCoNYWJ1y0=; b=E0X4YODcSACQ+tXJQjlMNZzqBdgv4GZr8PU+yw20AF8C5rpsAsiCwDNqGwfDp5UmwH 1fnJhVpgqXrEO0d53j4MmJ+0aLuZArEUzIgdUP/mINKJQaiI7GXOmzPGYVaJ6ryN3iza UuYdv+DR1CaUFQhz1m+6qF5xV7c5pqbadCd8aUkwvm8bQXwL1AIcszblvoyXK+8e27+n viVAcXmVK1loWXsH182ApzzoHiqGFzw/lq0dsOysOiUNf7mCC7cxQf87YF1pzcnLlKIh yMIXydlIWlvGQFqHW7ZyLjwaOpqOa+XppK3op/PJP2dpHb1L/AH5d+5+ed+plvRQjhQ0 U3jQ==
X-Gm-Message-State: APjAAAXbjA6o3nkWJzWiRHzUlJgP0VUleHvfgtqJpu1W12/kC5rh1eBQ ps5Eo0ajSK82pD6FEQoL77MpSK7TWaCxyb4w/J3LKQ==
X-Google-Smtp-Source: APXvYqz2Qvid49iwC+LiKcD7SxVwLaOiIqoEjDu02cDu4YNDbRes3WOKgwRfDuNyKfXWHeoIkxxkLolEseqwG1k2qYI=
X-Received: by 2002:a7b:c3c8:: with SMTP id t8mr1883678wmj.87.1571874021766; Wed, 23 Oct 2019 16:40:21 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk>
In-Reply-To: <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Wed, 23 Oct 2019 16:40:10 -0700
Message-ID: <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
To: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>, konrad.kohbrok@datashrine.de,  dodis@cs.nyu.edu
Cc: Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b32f3205959c7077"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/q1mSfrmXbafkBBPrmB1eUAKncZw>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Oct 2019 23:40:26 -0000

--000000000000b32f3205959c7077
Content-Type: text/plain; charset="UTF-8"

Hey Dennis

I think it is worth noting the trade off between evictions and leaving
> members in the group. Evicting a member who is not updating improves the
> group's PCS, but it harms the member's PCS. Worse, if the evicted member
> subsequently rejoins then the group's PCS is also destroyed.
>

I'm not sure I understand what you mean by "member's PCS" or how allowing a
previously compromised user to rejoin harms the group's PCS. Do you mind
explaining in more detail?

I think it is important to achieve PFS very quickly - ideally after
> receiving a message the PFS guarantee should kick in. If a user receives
> a message and immediately deletes it, then has their device compromised
> it should indeed be gone forever.
>

TreeKEM does give you that property, assuming that there's been no
compromises, or you've fully recovered from any compromise. All that
RTreeKEM improves is how quickly the group recovers from compromise. Your
statement that TreeKEM doesn't achieve this, or needs ACKs to achieve it,
is simply not true.

I'm not sure this is a good way to think about FS. If a device goes
> offline permanently, FS can never be achieved in this definition. FS can
> never be enforced in manner you seem to want in any realistic setting.
>

It can be enforced. If a user is compromised and goes offline permanently,
then eventually you'll remove them and messages sent *after* the removal
will have forward-security again (assuming nobody else has been
compromised). Forward-security doesn't apply to messages sent while the
compromised user is in the group, that ship has obviously sailed.

---

Hey Konrad

In those cases, getting
> FS for everyone just by processing a single update of any member is pretty
> significant. I guess my expectation is that in large groups, other
> constraints
> that also exist with "simple" TreeKEM will dictate a lower update
> frequency and
> thus PCS guarantees will be rather weak, but that doesn't mean that FS
> guarantees have to be.
>

There's no benefit to processing random Updates from random users. Even in
RTreeKEM, the benefit comes from processing the one Update from the one
compromised user. In TreeKEM, you need to process the compromised user's
Update and then everybody else's, which takes 2-4 times as long or so. So
this is the same, regardless of the group size.

Although I'll say that, especially in large groups, the biggest threat to
forward-security is most likely going to be devices going offline
permanently and being removed once somebody notices. TreeKEM vs RTreeKEM
doesn't improve anything there. Large groups seems like a case where
RTreeKEM is really giving up a lot to optimize the best-case scenario and
ignoring the most-likely scenario.

---

Hey Yevgeniy

In particular, under such limiting
> and narrow point of view, no "security" is possible if one user is not
> processing updates for a while, unless one mandates
> "kicking out" such users. Which, as others pointed, is problematic in many
> settings. But also does not allow to compare
> schemes, as none of them will be secure under such a narrow viewpoint.
>

I don't think that removing users who aren't updating is controversial.
That's always been my understanding of what we should do with users who
aren't updating.

So this is a huge difference - just passively processing something vs
> issuing an actual update operation.
>

 That RTreeKEM recovers faster from compromise is a clear benefit of using
the scheme, but it's not a gargantuan difference. It's only recovers about
2-4x faster than TreeKEM best-case, is the same in the worst-case, and
doesn't reduce the total number of Updates that have to be sent.

--000000000000b32f3205959c7077
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div>Hey Dennis</div><div><br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:=
1px solid rgb(204,204,204);padding-left:1ex"><div>I think it is worth notin=
g the trade off between evictions and leaving<br>
members in the group. Evicting a member who is not updating improves the<br=
>
group&#39;s PCS, but it harms the member&#39;s PCS. Worse, if the evicted m=
ember<br>
subsequently rejoins then the group&#39;s PCS is also destroyed.</div></blo=
ckquote><div><br></div><div>I&#39;m not sure I understand what you mean by =
&quot;member&#39;s PCS&quot; or how allowing a previously compromised user =
to rejoin harms the group&#39;s PCS. Do you mind explaining in more detail?=
</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div=
>I think it is important to achieve PFS very quickly - ideally after<br>
receiving a message the PFS guarantee should kick in. If a user receives<br=
>
a message and immediately deletes it, then has their device compromised<br>
it should indeed be gone forever.</div></blockquote><div><br></div><div>Tre=
eKEM does give you that property, assuming that there&#39;s been no comprom=
ises, or you&#39;ve fully recovered from any compromise. All that RTreeKEM =
improves is how quickly the group recovers from compromise. Your statement =
that TreeKEM doesn&#39;t achieve this, or needs ACKs to achieve it, is simp=
ly not true.</div><div><br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le=
ft:1ex"><div>I&#39;m not sure this is a good way to think about FS. If a de=
vice goes<br>
offline permanently, FS can never be achieved in this definition. FS can<br=
>
never be enforced in manner you seem to want in any realistic setting.</div=
></blockquote><div><br></div><div>It can be enforced. If a user is compromi=
sed and goes offline permanently, then eventually you&#39;ll remove them an=
d messages sent *after* the removal will have forward-security again (assum=
ing nobody else has been compromised). Forward-security doesn&#39;t apply t=
o messages sent while the compromised user is in the group, that ship has o=
bviously sailed.<br></div></div><div><br></div><div>---</div><div><br></div=
><div>Hey Konrad</div><div><br></div><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddin=
g-left:1ex"><div>In those cases, getting<br>
FS for everyone just by processing a single update of any member is pretty<=
br>
significant. I guess my expectation is that in large groups, other constrai=
nts<br>
that also exist with &quot;simple&quot; TreeKEM will dictate a lower update=
 frequency and<br>
thus PCS guarantees will be rather weak, but that doesn&#39;t mean that FS<=
br>
guarantees have to be.</div></blockquote><div><br></div><div>There&#39;s no=
 benefit to processing random Updates from random users. Even in RTreeKEM, =
the benefit comes from processing the one Update from the one compromised u=
ser. In TreeKEM, you need to process the compromised user&#39;s Update and =
then everybody else&#39;s, which takes 2-4 times as long or so. So this is =
the same, regardless of the group size.<br></div><div><br></div><div>Althou=
gh I&#39;ll say that, especially in large groups, the biggest threat to for=
ward-security is most likely going to be devices going offline permanently =
and being removed once somebody notices. TreeKEM vs RTreeKEM doesn&#39;t im=
prove anything there. Large groups seems like a case where RTreeKEM is real=
ly giving up a lot to optimize the best-case scenario and ignoring the most=
-likely scenario.</div><div><br></div><div>---</div><div><br></div><div>Hey=
 Yevgeniy</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"ma=
rgin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:=
1ex"><div><div>In particular, under such limiting=C2=A0</div><div>and narro=
w point of view, no &quot;security&quot; is possible if one user is not pro=
cessing updates for a while, unless one mandates=C2=A0</div><div>&quot;kick=
ing out&quot; such users. Which, as others pointed, is problematic in many =
settings. But also does not allow to compare</div><div>schemes, as none of =
them will be secure under such a narrow viewpoint.</div></div></blockquote>=
<div><br></div><div>I don&#39;t think that removing users who aren&#39;t up=
dating is controversial.=C2=A0 That&#39;s always been my understanding of w=
hat we should do with users who aren&#39;t updating.</div><div><br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-le=
ft:1px solid rgb(204,204,204);padding-left:1ex"><div><div>So this is a huge=
 difference - just passively processing something vs issuing an actual upda=
te operation.</div></div></blockquote><div><br></div><div>=C2=A0That RTreeK=
EM recovers faster from compromise is a clear benefit of using the scheme, =
but it&#39;s not a gargantuan difference. It&#39;s only recovers about 2-4x=
 faster than TreeKEM best-case, is the same in the worst-case, and doesn&#3=
9;t reduce the total number of Updates that have to be sent.<br></div></div=
>

--000000000000b32f3205959c7077--


From nobody Wed Oct 23 17:39:01 2019
Return-Path: <dennis.jackson@cs.ox.ac.uk>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5371E1200FB for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:38:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vODdaS2UR9VL for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:38:55 -0700 (PDT)
Received: from relay14.mail.ox.ac.uk (relay14.mail.ox.ac.uk [163.1.2.162]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4006C12006A for <mls@ietf.org>; Wed, 23 Oct 2019 17:38:55 -0700 (PDT)
Received: from smtp6.mail.ox.ac.uk ([163.1.2.206]) by relay14.mail.ox.ac.uk with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNR9R-00065y-kS; Thu, 24 Oct 2019 01:38:53 +0100
Received: from 61.ip-51-38-113.eu ([51.38.113.61] helo=[192.168.2.2]) by smtp6.mail.ox.ac.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNR9Q-000A6X-KS; Thu, 24 Oct 2019 01:38:52 +0100
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>, konrad.kohbrok@datashrine.de, dodis@cs.nyu.edu
Cc: Messaging Layer Security WG <mls@ietf.org>, Joel Alwen <jalwen@wickr.com>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
From: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
Openpgp: preference=signencrypt
Autocrypt: addr=dennis.jackson@cs.ox.ac.uk; prefer-encrypt=mutual; keydata= mQINBFbAmb8BEADCLixsrAJyvknI95ZIZNVeDJbYvldeXpw7iyhrdUdRK69USU5S9EESulYh k1KlxDB5VfG8CCA/WzG1IonONdXmgLFa1NcmdVvkFjbXf5mbGYG+9pTkieM+UHikniAizIOi ibdTWEEc2opOAvpVypek4SSsfCoXfXqj0j5AXSapHiVzhhWuaXhKVuFdLtYwJDU/x0FXgStm erFMIOeZ5FLFnjkkNyEa1t3XCcf7bfgw8J86UmWzgkVLmtBYbDK0ZAFjtFep5Kps11iTDIa3 xYXzuqgkWwkg7b1mhn5gQUl/kKZqQbuG+Sk+BydjH8e1PJkO6p2eAprO0AoucRuuBl1pmg/F bf/WJC6/XD3AV87ERAdXbb9cH+vrRT8GpiNX5r+7OuXavc3/LNU9stqsdshXwdZlDyPyDIG2 Llj6hB4eS0tEpat3otcPDkXUjXjyOUQ6jKTNSZ+xTBtVTXznflDCGdn9GV0q+4ZbdRZ5tfXM DXM+uMqVxjvh2IjCrka7zf1rRWg1WZu+NrzAUrvPMPddDJfd8JNrIcvV+DIBxPVsUTJLEGt9 PW8LkQb5FrG7T6a813JYNoAtL4w7296UYmUpV1Kvv8otO+uH860x5Ci83ZCXb7gKr9Rankn5 Jcg+shWnDFgSq6uM/u3MmyRV2iw7aCSgcgfy4EPTojJdy3KjzQARAQABtCtEZW5uaXMgSmFj a3NvbiA8ZGVubmlzLmphY2tzb25AY3Mub3guYWMudWs+iQIwBBMBCgAaBAsJCAcCFQoCFgEC GQAFglsIFtUCngECmwMACgkQYQWndYzSRqzvkA//djyyIydK5jhxNFqmMvJTkTZwawKWV7Tc cEntsIwYsHw8ec9Edo/M6fwp8aFmddPnzRo0EBmh6KNm887VxgH0FXmcR7k8bD3qUzIhfq11 4ezWtTk0nWjpieEsFb20lCMZjK9dsfXVRgFrfe00x2lhjPWQ5G5mTkfX8KYcDs5nmc+13qHK Ux6e6aSdEa4mnxrT0NsEg2H2xKgwrGkNIxJO6snrh3A3mT6+2F8ZCiRWwmOhcHBzNCFp1enR bMJpNRhcmGBDNJ9TpnQHDRVE67ds3PC/vKDkYQ3tEIkdgc/KVGOo7+kZxSU/n1gARDZ4PYUw IGOM81aEhmrbXoF33Jbic2jnuLfqsC8uXeP6wGgGpEdGThQ+7zslOPDradgDZBlUmYenuwOb JwJEj+JbbZPcND17VrgVDzcM1rh1w9wcKrRDMIw/zLCpEDOfLRe2ad/V380q/Eh3qa4QrZE7 tnXcOTIZfxd1zZ6TcpOvMVYQPN5Zfrlazmw9bTsdkm3WVrzvxc9DJ/D5Ws+aMu+JfSD+C5Nd n5w2fW7OOiDudeFXj88CL7oBehPJ2ajCDmHd/vc1W7CSoPte6aHBgSGER9cWm5hpEOXacQt+ pEz/uMvq+zkDIydy9YL/8hDo5TsVA4Yo8wNdKOuyaStk/oh3WNda05N0jr8VhRMdxnLN/hWY Ely5Ag0EVsCZvwEQAOBD1BmNy7FWbpg9Tm3OfMNC/yLs6G7rk3OFw7BhpjHXHSsEge48HbvP lfdR9abA1cmbgYR7EyaOav1s9ugU7EtDCcK8zHZcaUg3gC+FdjsnkIQCkf/3HK2sxcbBSrkX 2Uu2jjufvZu10g/aavkCuTHIUiYAHhQU5kCkRI7NYvXIKmaPY2Km3YIVJ50x+4GlE/WVZk8w HpvisxDInBioziUjAIqTt0at5tE1ObZksl2eNHNCwlo15WE2hKIYCuJKb57wCBKaOKo/gSw/ yN2DX3HaU/PF+8rCikkKDhHDrefFwGkqBf3zHlrLiHIr+ONVZ8i9dxMyg5TERxjd3vZ4ha+7 8cr8G83HC8lSBEpPYmoeU4J8vWf8kjBlai0UmzyZRF3SeZlqldxo7zJhYq3xIsDGKVuSCn68 2TcoEsR5WS/Zjc0ZoH/YIpdVy8FRu45dJ2IUzHVyszMfNWKob7ZsQ9JCXiXypmIF6ut5mwv8 ddCMdG6Jdpvg1fr0coABNbJSrUM8uFEldmRFpBdbNx5xSCJjNo+QuTHOXWuO3/GFRmux8/kW TlfF3+dvff2Pw3CKENoysgcOflYShcjOv/03sQ6AfxTm2Jnh5dqJSoVnPWpcDyPqn3k4zoZW 0ISqorI8yehJbfT3C0J5iEX75c8vJWfUUjIhyO0CpHxATNW3j3QxABEBAAGJAh8EGAEIABMF AlbAmccJEGEFp3WM0kasAhsMAAD8JhAAtkUWMLjr1RYTSMPrmTp3NGZfNSblv0GGHtL7TvT1 kFwdT/hs29Gjrj0FffZE6RKDEGls9AL6LY/g3wA5WQsXaK0wqwb8MBeIPWvFPvVQbqrifN3A bpukTl4OCBOwJbHS/GO1V3AwaLl4l3U/+kzR7UsnszWs4kizE9lBJ0AYFbxB0xbPF6iI32Cm K3nrLPfkXBXw2xX01nOLxTx9E7YdVpP3Re1c96aBTflm4CAGUfTZ5xgQMW6rgJ8FBc3oLckt 9MT0qB5XkmKGI1kkRypN7hIFRBcPxegeO8S3fpBUOop5F0el24TVx6KJTktpLmlIfUsEQ0Lx CqNtUk1v3eMCoKmeky8WbFcUArRV4DKXDAK1e3C8poMaehRgfl8sjz6SuH1VXpCMLNPpNMtZ EK4FU+C0jGgJyHS9N1UZjq8Qa8FnYKruyPgTpKEAsqlo5vB6J8phiaKXxnren8HqIfzQdrt8 3M+raXc7+Fqis4pYS49vfIpxUzcqvKUiSgDGKemqMw9w9U5dBEQeLNW08uOKSjyENU4e1Ob/ IiimIpEPA5LEIhSfOP9CN9TculGqvo0g12XnB+g5AAtm1ohMkb33T17IR3rKkhlvIITuY1qi fZz7OgGbXh4G5oUHXNBOhXHaqRIzQCCRbBUFA09OyJBLWAGH6HcM/DeM0I7Ng55uMl8=
Message-ID: <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
Date: Thu, 24 Oct 2019 01:38:50 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="SLqZDJLnZjp1XPqMLcupXkS5KXA0mNPIs"
X-Oxford-Username: exet4027
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/YHdmQED0q0Q267YGsVAkZ-WBMbI>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 00:38:58 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--SLqZDJLnZjp1XPqMLcupXkS5KXA0mNPIs
Content-Type: multipart/mixed; boundary="yI1gZbcM0zBO8frnru1Rt9jl2VlZu03sG";
 protected-headers="v1"
From: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>,
 konrad.kohbrok@datashrine.de, dodis@cs.nyu.edu
Cc: Messaging Layer Security WG <mls@ietf.org>, Joel Alwen <jalwen@wickr.com>
Message-ID: <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
Subject: Re: [MLS] Re-randomized TreeKEM
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com>
 <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr>
 <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com>
 <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr>
 <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com>
 <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com>
 <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com>
 <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com>
 <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com>
 <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com>
 <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk>
 <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
In-Reply-To: <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>

--yI1gZbcM0zBO8frnru1Rt9jl2VlZu03sG
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Hi Brendan,

On 24/10/2019 00:40, Brendan McMillion wrote:
> Hey Dennis
>=20
>     I think it is worth noting the trade off between evictions and leav=
ing
>     members in the group. Evicting a member who is not updating improve=
s the
>     group's PCS, but it harms the member's PCS. Worse, if the evicted m=
ember
>     subsequently rejoins then the group's PCS is also destroyed.
>=20
>=20
> I'm not sure I understand what you mean by "member's PCS" or how
> allowing a previously compromised user to rejoin harms the group's PCS.=

> Do you mind explaining in more detail?

Informally, in this context, the PCS property w.r.t to some set of
participants is the earliest timepoint at which a compromise of the
state of one of the participants allows the adversary to recover the
current state of a participant (or equiv recover a 'current' group
secret). Note: the adversary is required to have been passive at some
point between the earliest compromise and the current timepoint
otherwise no security can hold.

The better the PCS guarantee, the more recently the adversary must have
acted in order to recover the current group secret. Conversely, the PCS
guarantee is weak/non-existent if the adversary could have compromised
an agent a very long time ago and still recover the current group secret.=


Let us assume the adversary compromised the initial state of some member
of a group at t=3D0. In either version of TreeKEM: once that group member=

has successfully updated their state, the adversary will no longer have
access to the current group secret. However, if we ever throw out that
member and have them rejoin, the adversary has a way back into the
group. The group does not know whether the initial member rejoined, or
the adversary posing as the initial member. Likewise, the initial member
loses their guarantee on the rest of the group's identity/security.

>     I think it is important to achieve PFS very quickly - ideally after=

>     receiving a message the PFS guarantee should kick in. If a user rec=
eives
>     a message and immediately deletes it, then has their device comprom=
ised
>     it should indeed be gone forever.
>=20
>=20
> TreeKEM does give you that property, assuming that there's been no
> compromises, or you've fully recovered from any compromise. All that
> RTreeKEM improves is how quickly the group recovers from compromise.
> Your statement that TreeKEM doesn't achieve this, or needs ACKs to
> achieve it, is simply not true.

I'm not sure where the misunderstanding lies so I will expand on this poi=
nt:

Timepoint: Event
t: User receives a message AEAD(m,...) and decrypts it
t+1: User deletes the message m
t+2: Adversary compromises user's device.

At t+3, can the adversary learn m?

In TreeKEM, the following attack works:

1. At t: the adversary records AEAD(m,...) as it is sent to the user.
2. At t+3, the adversary uses the user's state to decode AEAD(m,...)

This attack doesn't work in RTreeKEM because the user updated their
state after receiving the message at timepoint t. This attack doesn't
work in TreeKEM with ACKs because the user will have updated their state
and sent an update message at t+0.5.

The ability to achieve PFS immediately after receiving a message, rather
than after the transmission of the next message makes a huge difference
in practice. It's clear that having every member of a group ACK each
message isn't going to scale. Having a PFS window of hours, days or
weeks is much much worse than a PFS window of "immediately".

Think about the practical implications for individuals. In many
situations, e.g. inspection at a border, users are aware their device
has been compromised. This guides their future actions (which PCS aims
to protect), but it is typically too late for their past actions (which
PFS aims to protect). Consequently,weak PFS guarantees are much worse in
practice than weak PCS guarantees because future compromise is harder to
predict than deducing past compromise. Although obviously we want strong
forms of both to hold :).

Best,
Dennis


--yI1gZbcM0zBO8frnru1Rt9jl2VlZu03sG--

--SLqZDJLnZjp1XPqMLcupXkS5KXA0mNPIs
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEW5Pwudaom8FUa8mMYQWndYzSRqwFAl2w8poACgkQYQWndYzS
RqzujRAAsZODTzId8oxObYpd0AxxiZQmoTEU0LMpi+aihNMJy1M75XO5EQ1PHMfi
mEumV6QobM9rX/r3Mm5Ic19TTb10+MsCk3EPrvKVkzQ7bOCnj+STWKLKg+8VAnok
LyUhkKbO+ydIkbsCXphjPcmopitfyh6Ti1rbou4fkQk5YjW3D1YQliaPlEPjb6Tw
tQqIIH84nc6bjxLCjH27OIWyErA66JBlOj1qhkD8RGUw8CCScA2WOAdGb7QVwxpM
tzaxA2rgN2ey7dTaJmY3vXdVf0AjfQD01LhGDBhDzMDpbYYVgAv2pXcBw8+xYFg6
0Cyh9z5IHQmRQjoXUj0mM0befUPzb1LbtPixXdIQSHORBtAQIwyfvOPWgn2mKusG
JPxogG4HfAlj+lu+BsuoTxZZCvM1OMHGwpnZfmZEOzMAxiJgxu8LirCGQNZtbN1L
pXZ4lPI3QojSoLIcfDWSUFoEsc5Mz8VIh9LAaODdxlvm7fkBhUc0cfCe2jJSDkV7
XAX87ei5YbaduG/VdCZ5AtsStrUNdXJF4Mnb3ECNOA2GCHqowf73xxEROIIvHI0E
bpF0naDzfsway8JU1YFQWSExjQUFh54/VLZLf5MJnHcqp46QMqxgJKjKTxDEQxek
QhPPb8KPS6ANevUoDtJlL5IJ4BIDpFhdRfGy6gIwg8WSfvEpUFY=
=Nr0F
-----END PGP SIGNATURE-----

--SLqZDJLnZjp1XPqMLcupXkS5KXA0mNPIs--


From nobody Wed Oct 23 17:45:49 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E002D12003F for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:45:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.423
X-Spam-Level: 
X-Spam-Status: No, score=-1.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.226, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bV13NMsSMPIQ for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:45:45 -0700 (PDT)
Received: from mail-io1-f53.google.com (mail-io1-f53.google.com [209.85.166.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2AA0812006A for <mls@ietf.org>; Wed, 23 Oct 2019 17:45:45 -0700 (PDT)
Received: by mail-io1-f53.google.com with SMTP id c25so27262123iot.12 for <mls@ietf.org>; Wed, 23 Oct 2019 17:45:45 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=8awisM6JkLHBOJ2+yK0F0/l8SifLOcvzAs/TdCT0ggI=; b=L3W83KLk6yYjBsBn2dK5vxJlIHX7XEQvdyWkUIUKZJqkSI18lTHt0ctEjqzJoSq9G1 MfB1jFfb/XgiV02iSr1Fbaw9PIoiBerxDLa/K8b6pqN8s+FzTqKh/AzKq6k374DHL0yi xwx7mMtyYi5ovN1c60SxWiNSrcebVOa2KOTxamHAhhWy7HC14aeVLhPlXXtzTma6peGf CmQ0SzsqczsxR3Q0qRu+x5vRKSTN8fytvB006Jver+s0gg37o1UYGRp6FXaghd/s3bmd vBdncHORM4fvERc0JJ6p0ORgr2t8YwnQr04eh5RyfRh1u7LV+P0kZ4pyuG/a0CTxZpVd hU9Q==
X-Gm-Message-State: APjAAAWN5QQOX9NSCgUEBBklZSy9kr4R6pZ5yqiobwXqxRwL0RnrWZS+ TNdRr9B6Lz6f/r164kYe/WTM7nBnD6qptlcjWZY=
X-Google-Smtp-Source: APXvYqyA9Spy8r0R77dbLi4GC9ojFqfjeQ7VvRfUcHy74ZZ9b+BfAqnMKeTiU5jvumy7KKYtxnOhKFMzIqHe3YH+UZc=
X-Received: by 2002:a5d:83c1:: with SMTP id u1mr6947768ior.78.1571877943858; Wed, 23 Oct 2019 17:45:43 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
In-Reply-To: <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Wed, 23 Oct 2019 20:45:33 -0400
Message-ID: <CAMvzKshiqtLVbTGjAeZR8FSz2nAJvRknduQvYVeBDYHphFd8Fw@mail.gmail.com>
To: Brendan McMillion <brendan@cloudflare.com>
Cc: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>,  Konrad Kohbrok <konrad.kohbrok@datashrine.de>, Joel Alwen <jalwen@wickr.com>,  Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000795c2305959d5a7f"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/NEhMS4wKIXLzbJQyH2j740Y3Kj0>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 00:45:48 -0000

--000000000000795c2305959d5a7f
Content-Type: text/plain; charset="UTF-8"

I think I got your point, Brendan, and why we kept speaking past each
other! And we are partially guilty here, by occasionally using the
term "recover" to mean  two different things, contributing to the confusion.

1) "Recover" = achieve PCS. Namely, if attacker corrupts current state of
some user U (including current group key),
how long until the group key is secure, assuming no further corruptions. In
this sense the answer is the same in RTReeKEM
and TreeKEM (or any other secure scheme): corrupted user U should issue an
update (or be removed from group).
So, for multiple corruptions, we should wait until all corrupted uses
UPDATE. And, indeed, we formally show that
TreeKEM is what we call "backward secure" = "achieves PCS in isolation". So
here *you are right* and there is indeed
no security benefit of RTreeKEM over TreeKEM: a corrupted user should
update in order to recover
in *any secure scheme*, more or less by definition.

2) "Recover" = achieve FS. Namely, assuming an UPDATE (or ADD/REMOVE)
operation just happened resulting in a new
group key. What should happen from now until the FUTURE corruption to
guarantee this corruption does not harm the
current key? So I suggest we use the term "preempt" rather than "recover"
for this, as we are not recovering from anything which
happened, but  instead trying to prevent damage from a future hypothetical
corruption. For this notion, the difference between the
schemes is very clear:
 - in RTreeKEM, a user who already moved to the next key (i.,e. merely
PROCESSED)  is not helpful to the attacker. This is
clearly the best we can hope for.
 - in TreeKEM, only if a user  issues an UPDATE one can be sure this user
is not helpful (although sometimes one could get lucky, but this is hard
to describe concisely).

Whether this difference is "gargantuan" is a matter of taste. But I believe
it is, especially in large groups. And here I think
the dual point of view I advocated in my earlier email could be very
useful. Namely, rather than thinking as a policy maker,
what do we do to ensure the given key is secure (against either past or
future corruption), or how long it takes to preempt
(let's use this instead of "recover" going forward!), etc. Think of any
given situation instead: some sequence of operations
happens, including attacker corrupting several states of the users. Never
mind how and why, it just happened.
Which keys are compromised? I believe in majority of even typical cases,
the set of compromised keys in TreeKEM will be noticeably
larger than in RTreeKEM. Certainly in most examples I can think of. To me
this is the reason RTreeKEM offers substantially
more security than TreeKEM.

Do you agree?
Yevgeniy

On Wed, Oct 23, 2019 at 7:40 PM Brendan McMillion <brendan@cloudflare.com>
wrote:

> Hey Dennis
>
> I think it is worth noting the trade off between evictions and leaving
>> members in the group. Evicting a member who is not updating improves the
>> group's PCS, but it harms the member's PCS. Worse, if the evicted member
>> subsequently rejoins then the group's PCS is also destroyed.
>>
>
> I'm not sure I understand what you mean by "member's PCS" or how allowing
> a previously compromised user to rejoin harms the group's PCS. Do you mind
> explaining in more detail?
>
> I think it is important to achieve PFS very quickly - ideally after
>> receiving a message the PFS guarantee should kick in. If a user receives
>> a message and immediately deletes it, then has their device compromised
>> it should indeed be gone forever.
>>
>
> TreeKEM does give you that property, assuming that there's been no
> compromises, or you've fully recovered from any compromise. All that
> RTreeKEM improves is how quickly the group recovers from compromise. Your
> statement that TreeKEM doesn't achieve this, or needs ACKs to achieve it,
> is simply not true.
>
> I'm not sure this is a good way to think about FS. If a device goes
>> offline permanently, FS can never be achieved in this definition. FS can
>> never be enforced in manner you seem to want in any realistic setting.
>>
>
> It can be enforced. If a user is compromised and goes offline permanently,
> then eventually you'll remove them and messages sent *after* the removal
> will have forward-security again (assuming nobody else has been
> compromised). Forward-security doesn't apply to messages sent while the
> compromised user is in the group, that ship has obviously sailed.
>
> ---
>
> Hey Konrad
>
> In those cases, getting
>> FS for everyone just by processing a single update of any member is pretty
>> significant. I guess my expectation is that in large groups, other
>> constraints
>> that also exist with "simple" TreeKEM will dictate a lower update
>> frequency and
>> thus PCS guarantees will be rather weak, but that doesn't mean that FS
>> guarantees have to be.
>>
>
> There's no benefit to processing random Updates from random users. Even in
> RTreeKEM, the benefit comes from processing the one Update from the one
> compromised user. In TreeKEM, you need to process the compromised user's
> Update and then everybody else's, which takes 2-4 times as long or so. So
> this is the same, regardless of the group size.
>
> Although I'll say that, especially in large groups, the biggest threat to
> forward-security is most likely going to be devices going offline
> permanently and being removed once somebody notices. TreeKEM vs RTreeKEM
> doesn't improve anything there. Large groups seems like a case where
> RTreeKEM is really giving up a lot to optimize the best-case scenario and
> ignoring the most-likely scenario.
>
> ---
>
> Hey Yevgeniy
>
> In particular, under such limiting
>> and narrow point of view, no "security" is possible if one user is not
>> processing updates for a while, unless one mandates
>> "kicking out" such users. Which, as others pointed, is problematic in
>> many settings. But also does not allow to compare
>> schemes, as none of them will be secure under such a narrow viewpoint.
>>
>
> I don't think that removing users who aren't updating is controversial.
> That's always been my understanding of what we should do with users who
> aren't updating.
>
> So this is a huge difference - just passively processing something vs
>> issuing an actual update operation.
>>
>
>  That RTreeKEM recovers faster from compromise is a clear benefit of using
> the scheme, but it's not a gargantuan difference. It's only recovers about
> 2-4x faster than TreeKEM best-case, is the same in the worst-case, and
> doesn't reduce the total number of Updates that have to be sent.
>

--000000000000795c2305959d5a7f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I think I got your point, Brendan, and why we kept speakin=
g past each other! And we are partially guilty here, by occasionally using =
the=C2=A0<div>term &quot;recover&quot; to mean=C2=A0 two different things, =
contributing to the confusion.<div><div><br></div><div>1) &quot;Recover&quo=
t; =3D achieve PCS. Namely, if attacker corrupts current state of some user=
 U (including current group key),</div><div>how long until the group key is=
 secure, assuming no further corruptions. In this sense the answer=C2=A0is =
the same in RTReeKEM</div><div>and TreeKEM (or any other secure scheme): co=
rrupted user U should=C2=A0issue an update (or be removed from group).</div=
><div>So, for multiple corruptions, we should wait until all corrupted uses=
 UPDATE. And, indeed, we formally show that=C2=A0</div><div>TreeKEM is what=
 we call &quot;backward secure&quot; =3D &quot;achieves PCS in isolation&qu=
ot;. So here *you are right* and there is indeed=C2=A0</div><div>no securit=
y benefit of RTreeKEM over TreeKEM: a corrupted user should update in order=
 to recover=C2=A0</div><div>in *any secure scheme*, more or less by definit=
ion.</div><div><br></div><div>2) &quot;Recover&quot; =3D achieve FS. Namely=
, assuming an UPDATE (or ADD/REMOVE) operation just happened resulting in a=
 new</div><div>group key. What should happen from now until the FUTURE corr=
uption to guarantee this corruption does not harm the</div><div>current key=
? So I suggest we use the term &quot;preempt&quot; rather than &quot;recove=
r&quot; for this, as we are not recovering from anything which</div><div>ha=
ppened, but=C2=A0 instead trying to prevent damage from a future hypothetic=
al corruption. For this notion, the difference between the</div><div>scheme=
s is very clear:</div><div><div>=C2=A0- i<span style=3D"color:rgb(0,0,0)">n=
=C2=A0</span><span style=3D"color:rgb(0,0,0)">RTreeKEM, a user who already =
m</span><span style=3D"color:rgb(0,0,0)">oved to the next key (i.,e. merely=
 PROCESSED)=C2=A0=C2=A0</span><span style=3D"color:rgb(0,0,0)">is not helpf=
ul to the attacker. This is</span></div><div><span style=3D"color:rgb(0,0,0=
)">clearly the best we can hope for.</span></div><div><span style=3D"color:=
rgb(0,0,0)">=C2=A0- in TreeKEM, only if a user=C2=A0=C2=A0</span><span styl=
e=3D"color:rgb(0,0,0)">issues an UPDATE one can be sure this user is=C2=A0<=
/span><span style=3D"color:rgb(0,0,0)">not helpful (although sometimes one =
could get lucky, but this is hard=C2=A0</span></div><div><span style=3D"col=
or:rgb(0,0,0)">t</span><span style=3D"color:rgb(0,0,0)">o describe concisel=
y).</span></div></div><div><br></div><div>Whether this difference is &quot;=
<span style=3D"color:rgb(0,0,0)">gargantuan&quot; is a matter of taste. But=
 I believe it is, especially in large groups. And here I think=C2=A0</span>=
</div><div><span style=3D"color:rgb(0,0,0)">the dual point of view I advoca=
ted in my earlier email could be very useful. Namely, rather than thinking =
as a policy maker,</span></div><div><span style=3D"color:rgb(0,0,0)">what d=
o we do to ensure the given key is secure (against either past or future co=
rruption), or how long it takes to preempt</span></div><div><span style=3D"=
color:rgb(0,0,0)">(let&#39;s use this instead of &quot;recover&quot; going =
forward!), etc. T</span><span style=3D"color:rgb(0,0,0)">hink of any given =
situation instead: s</span><span style=3D"color:rgb(0,0,0)">ome sequence of=
 operations=C2=A0</span></div><div><span style=3D"color:rgb(0,0,0)">happens=
, including attacker corrupting several states of the users. Never mind how=
 and why, it just happened.</span></div><div><span style=3D"color:rgb(0,0,0=
)">Which keys are=C2=A0</span><span style=3D"color:rgb(0,0,0)">compromised?=
 I believe in majority of even typical cases, the set of compromised keys i=
n TreeKEM will be noticeably=C2=A0</span></div><div><span style=3D"color:rg=
b(0,0,0)">larger than in RTreeKEM. Certainly in most examples I can think o=
f. To me this is the reason RTreeKEM offers substantially</span></div><div>=
<span style=3D"color:rgb(0,0,0)">more security than TreeKEM.=C2=A0</span></=
div><div><span style=3D"color:rgb(0,0,0)"><br></span></div><div><span style=
=3D"color:rgb(0,0,0)">Do you agree?</span></div><div>Yevgeniy</div></div></=
div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_at=
tr">On Wed, Oct 23, 2019 at 7:40 PM Brendan McMillion &lt;<a href=3D"mailto=
:brendan@cloudflare.com" target=3D"_blank">brendan@cloudflare.com</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=
=3D"ltr"><div dir=3D"ltr"><div>Hey Dennis</div><div><br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli=
d rgb(204,204,204);padding-left:1ex"><div>I think it is worth noting the tr=
ade off between evictions and leaving<br>
members in the group. Evicting a member who is not updating improves the<br=
>
group&#39;s PCS, but it harms the member&#39;s PCS. Worse, if the evicted m=
ember<br>
subsequently rejoins then the group&#39;s PCS is also destroyed.</div></blo=
ckquote><div><br></div><div>I&#39;m not sure I understand what you mean by =
&quot;member&#39;s PCS&quot; or how allowing a previously compromised user =
to rejoin harms the group&#39;s PCS. Do you mind explaining in more detail?=
</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div=
>I think it is important to achieve PFS very quickly - ideally after<br>
receiving a message the PFS guarantee should kick in. If a user receives<br=
>
a message and immediately deletes it, then has their device compromised<br>
it should indeed be gone forever.</div></blockquote><div><br></div><div>Tre=
eKEM does give you that property, assuming that there&#39;s been no comprom=
ises, or you&#39;ve fully recovered from any compromise. All that RTreeKEM =
improves is how quickly the group recovers from compromise. Your statement =
that TreeKEM doesn&#39;t achieve this, or needs ACKs to achieve it, is simp=
ly not true.</div><div><br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le=
ft:1ex"><div>I&#39;m not sure this is a good way to think about FS. If a de=
vice goes<br>
offline permanently, FS can never be achieved in this definition. FS can<br=
>
never be enforced in manner you seem to want in any realistic setting.</div=
></blockquote><div><br></div><div>It can be enforced. If a user is compromi=
sed and goes offline permanently, then eventually you&#39;ll remove them an=
d messages sent *after* the removal will have forward-security again (assum=
ing nobody else has been compromised). Forward-security doesn&#39;t apply t=
o messages sent while the compromised user is in the group, that ship has o=
bviously sailed.<br></div></div><div><br></div><div>---</div><div><br></div=
><div>Hey Konrad</div><div><br></div><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddin=
g-left:1ex"><div>In those cases, getting<br>
FS for everyone just by processing a single update of any member is pretty<=
br>
significant. I guess my expectation is that in large groups, other constrai=
nts<br>
that also exist with &quot;simple&quot; TreeKEM will dictate a lower update=
 frequency and<br>
thus PCS guarantees will be rather weak, but that doesn&#39;t mean that FS<=
br>
guarantees have to be.</div></blockquote><div><br></div><div>There&#39;s no=
 benefit to processing random Updates from random users. Even in RTreeKEM, =
the benefit comes from processing the one Update from the one compromised u=
ser. In TreeKEM, you need to process the compromised user&#39;s Update and =
then everybody else&#39;s, which takes 2-4 times as long or so. So this is =
the same, regardless of the group size.<br></div><div><br></div><div>Althou=
gh I&#39;ll say that, especially in large groups, the biggest threat to for=
ward-security is most likely going to be devices going offline permanently =
and being removed once somebody notices. TreeKEM vs RTreeKEM doesn&#39;t im=
prove anything there. Large groups seems like a case where RTreeKEM is real=
ly giving up a lot to optimize the best-case scenario and ignoring the most=
-likely scenario.</div><div><br></div><div>---</div><div><br></div><div>Hey=
 Yevgeniy</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"ma=
rgin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:=
1ex"><div><div>In particular, under such limiting=C2=A0</div><div>and narro=
w point of view, no &quot;security&quot; is possible if one user is not pro=
cessing updates for a while, unless one mandates=C2=A0</div><div>&quot;kick=
ing out&quot; such users. Which, as others pointed, is problematic in many =
settings. But also does not allow to compare</div><div>schemes, as none of =
them will be secure under such a narrow viewpoint.</div></div></blockquote>=
<div><br></div><div>I don&#39;t think that removing users who aren&#39;t up=
dating is controversial.=C2=A0 That&#39;s always been my understanding of w=
hat we should do with users who aren&#39;t updating.</div><div><br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-le=
ft:1px solid rgb(204,204,204);padding-left:1ex"><div><div>So this is a huge=
 difference - just passively processing something vs issuing an actual upda=
te operation.</div></div></blockquote><div><br></div><div>=C2=A0That RTreeK=
EM recovers faster from compromise is a clear benefit of using the scheme, =
but it&#39;s not a gargantuan difference. It&#39;s only recovers about 2-4x=
 faster than TreeKEM best-case, is the same in the worst-case, and doesn&#3=
9;t reduce the total number of Updates that have to be sent.<br></div></div=
>
</blockquote></div>

--000000000000795c2305959d5a7f--


From nobody Wed Oct 23 17:48:46 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C2B9F1200A1 for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:48:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.423
X-Spam-Level: 
X-Spam-Status: No, score=-1.423 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.226, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9U8ybOKGfugq for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 17:48:42 -0700 (PDT)
Received: from mail-io1-f53.google.com (mail-io1-f53.google.com [209.85.166.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7B71112003F for <mls@ietf.org>; Wed, 23 Oct 2019 17:48:42 -0700 (PDT)
Received: by mail-io1-f53.google.com with SMTP id u8so27301900iom.5 for <mls@ietf.org>; Wed, 23 Oct 2019 17:48:42 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=R/wPM/obqDk8yU6wFA33/JsizstQvXAshDNOgeBX0ck=; b=pAyf/DCA56NWtJzcn8uzGn9yX99bHJiO6jiGe5lFB/MHGZzq9ZB3x4lMwDtU3UBqG3 3C42tJO0vIB6VHCvRWJhs2DrzQtB2wTkOwRUuM5lXW5VT4UR0cPPNC324iQ0m7OU92H9 7KNoqGRdtVQpm/UpzN2B6OwloKY4+Rj/MjHQL7+u9eKNeyOf8tFAUkp4ylhM5B4dEnZR YwCojShZpl310DzpCE1Cysn0FINoGkdvSGZJzBDI8seoT0PFgOaK3WkSjeWRCfRTJBxB oFHcKTKU936rawvBx2GDZATHbuEDUofuFmmqezSHC1/caYGKaixcsQzn09G1zYRUZ1lm 3m7Q==
X-Gm-Message-State: APjAAAVIiYd2Ds7bnZ+7C+IzDfzrQ0qsU2JNt7c89kVgatqRgVokFixc vmVPd53BH/iX1ibcOp8xurxMjcoeJ3YLSmMTMZI=
X-Google-Smtp-Source: APXvYqyJb7AAmSV30/YR2P22h2nXChQGstjSJ+36AJ61Zk+ln5v/Iwzw+WLhFh2g7SM1IYv88gMcO5N7wYHLTqjhOgk=
X-Received: by 2002:a5e:d90f:: with SMTP id n15mr833848iop.20.1571878121419; Wed, 23 Oct 2019 17:48:41 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
In-Reply-To: <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
From: Yevgeniy Dodis <dodis@cs.nyu.edu>
Date: Wed, 23 Oct 2019 20:48:31 -0400
Message-ID: <CAMvzKsiMqSeMEgj3m26TGrH9znQ7DcQdHeZMwOfJ+nSynDbr3Q@mail.gmail.com>
To: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
Cc: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>,  Konrad Kohbrok <konrad.kohbrok@datashrine.de>, Messaging Layer Security WG <mls@ietf.org>, Joel Alwen <jalwen@wickr.com>
Content-Type: multipart/alternative; boundary="0000000000000eb95e05959d65f9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/DBo9wsSDGI0ThzxP2D3sNBm_jUc>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 00:48:45 -0000

--0000000000000eb95e05959d65f9
Content-Type: text/plain; charset="UTF-8"

I love your email, Dennis! Will use it in the future. Thank you!

"Think about the practical implications for individuals. In many
situations, e.g. inspection at a border, users are aware their device
has been compromised. This guides their future actions (which PCS aims
to protect), but it is typically too late for their past actions (which
PFS aims to protect). Consequently,weak PFS guarantees are much worse in
practice than weak PCS guarantees because future compromise is harder to
predict than deducing past compromise. Although obviously we want strong
forms of both to hold :)."

On Wed, Oct 23, 2019 at 8:39 PM Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
wrote:

> Hi Brendan,
>
> On 24/10/2019 00:40, Brendan McMillion wrote:
> > Hey Dennis
> >
> >     I think it is worth noting the trade off between evictions and
> leaving
> >     members in the group. Evicting a member who is not updating improves
> the
> >     group's PCS, but it harms the member's PCS. Worse, if the evicted
> member
> >     subsequently rejoins then the group's PCS is also destroyed.
> >
> >
> > I'm not sure I understand what you mean by "member's PCS" or how
> > allowing a previously compromised user to rejoin harms the group's PCS.
> > Do you mind explaining in more detail?
>
> Informally, in this context, the PCS property w.r.t to some set of
> participants is the earliest timepoint at which a compromise of the
> state of one of the participants allows the adversary to recover the
> current state of a participant (or equiv recover a 'current' group
> secret). Note: the adversary is required to have been passive at some
> point between the earliest compromise and the current timepoint
> otherwise no security can hold.
>
> The better the PCS guarantee, the more recently the adversary must have
> acted in order to recover the current group secret. Conversely, the PCS
> guarantee is weak/non-existent if the adversary could have compromised
> an agent a very long time ago and still recover the current group secret.
>
> Let us assume the adversary compromised the initial state of some member
> of a group at t=0. In either version of TreeKEM: once that group member
> has successfully updated their state, the adversary will no longer have
> access to the current group secret. However, if we ever throw out that
> member and have them rejoin, the adversary has a way back into the
> group. The group does not know whether the initial member rejoined, or
> the adversary posing as the initial member. Likewise, the initial member
> loses their guarantee on the rest of the group's identity/security.
>
> >     I think it is important to achieve PFS very quickly - ideally after
> >     receiving a message the PFS guarantee should kick in. If a user
> receives
> >     a message and immediately deletes it, then has their device
> compromised
> >     it should indeed be gone forever.
> >
> >
> > TreeKEM does give you that property, assuming that there's been no
> > compromises, or you've fully recovered from any compromise. All that
> > RTreeKEM improves is how quickly the group recovers from compromise.
> > Your statement that TreeKEM doesn't achieve this, or needs ACKs to
> > achieve it, is simply not true.
>
> I'm not sure where the misunderstanding lies so I will expand on this
> point:
>
> Timepoint: Event
> t: User receives a message AEAD(m,...) and decrypts it
> t+1: User deletes the message m
> t+2: Adversary compromises user's device.
>
> At t+3, can the adversary learn m?
>
> In TreeKEM, the following attack works:
>
> 1. At t: the adversary records AEAD(m,...) as it is sent to the user.
> 2. At t+3, the adversary uses the user's state to decode AEAD(m,...)
>
> This attack doesn't work in RTreeKEM because the user updated their
> state after receiving the message at timepoint t. This attack doesn't
> work in TreeKEM with ACKs because the user will have updated their state
> and sent an update message at t+0.5.
>
> The ability to achieve PFS immediately after receiving a message, rather
> than after the transmission of the next message makes a huge difference
> in practice. It's clear that having every member of a group ACK each
> message isn't going to scale. Having a PFS window of hours, days or
> weeks is much much worse than a PFS window of "immediately".
>
> Think about the practical implications for individuals. In many
> situations, e.g. inspection at a border, users are aware their device
> has been compromised. This guides their future actions (which PCS aims
> to protect), but it is typically too late for their past actions (which
> PFS aims to protect). Consequently,weak PFS guarantees are much worse in
> practice than weak PCS guarantees because future compromise is harder to
> predict than deducing past compromise. Although obviously we want strong
> forms of both to hold :).
>
> Best,
> Dennis
>
>

--0000000000000eb95e05959d65f9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>I love your email, Dennis! Will use it in the future.=
 Thank you!</div><div><br></div><div>&quot;Think about the practical implic=
ations for individuals. In many</div>
situations, e.g. inspection at a border, users are aware their device<br>
has been compromised. This guides their future actions (which PCS aims<br>
to protect), but it is typically too late for their past actions (which<br>
PFS aims to protect). Consequently,weak PFS guarantees are much worse in<br=
>
practice than weak PCS guarantees because future compromise is harder to<br=
>
predict than deducing past compromise. Although obviously we want strong<br=
>
forms of both to hold :).&quot;<div><br><div class=3D"gmail_quote"><div dir=
=3D"ltr" class=3D"gmail_attr">On Wed, Oct 23, 2019 at 8:39 PM Dennis Jackso=
n &lt;<a href=3D"mailto:dennis.jackson@cs.ox.ac.uk">dennis.jackson@cs.ox.ac=
.uk</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e=
x">Hi Brendan,<br>
<br>
On 24/10/2019 00:40, Brendan McMillion wrote:<br>
&gt; Hey Dennis<br>
&gt; <br>
&gt;=C2=A0 =C2=A0 =C2=A0I think it is worth noting the trade off between ev=
ictions and leaving<br>
&gt;=C2=A0 =C2=A0 =C2=A0members in the group. Evicting a member who is not =
updating improves the<br>
&gt;=C2=A0 =C2=A0 =C2=A0group&#39;s PCS, but it harms the member&#39;s PCS.=
 Worse, if the evicted member<br>
&gt;=C2=A0 =C2=A0 =C2=A0subsequently rejoins then the group&#39;s PCS is al=
so destroyed.<br>
&gt; <br>
&gt; <br>
&gt; I&#39;m not sure I understand what you mean by &quot;member&#39;s PCS&=
quot; or how<br>
&gt; allowing a previously compromised user to rejoin harms the group&#39;s=
 PCS.<br>
&gt; Do you mind explaining in more detail?<br>
<br>
Informally, in this context, the PCS property w.r.t to some set of<br>
participants is the earliest timepoint at which a compromise of the<br>
state of one of the participants allows the adversary to recover the<br>
current state of a participant (or equiv recover a &#39;current&#39; group<=
br>
secret). Note: the adversary is required to have been passive at some<br>
point between the earliest compromise and the current timepoint<br>
otherwise no security can hold.<br>
<br>
The better the PCS guarantee, the more recently the adversary must have<br>
acted in order to recover the current group secret. Conversely, the PCS<br>
guarantee is weak/non-existent if the adversary could have compromised<br>
an agent a very long time ago and still recover the current group secret.<b=
r>
<br>
Let us assume the adversary compromised the initial state of some member<br=
>
of a group at t=3D0. In either version of TreeKEM: once that group member<b=
r>
has successfully updated their state, the adversary will no longer have<br>
access to the current group secret. However, if we ever throw out that<br>
member and have them rejoin, the adversary has a way back into the<br>
group. The group does not know whether the initial member rejoined, or<br>
the adversary posing as the initial member. Likewise, the initial member<br=
>
loses their guarantee on the rest of the group&#39;s identity/security.<br>
<br>
&gt;=C2=A0 =C2=A0 =C2=A0I think it is important to achieve PFS very quickly=
 - ideally after<br>
&gt;=C2=A0 =C2=A0 =C2=A0receiving a message the PFS guarantee should kick i=
n. If a user receives<br>
&gt;=C2=A0 =C2=A0 =C2=A0a message and immediately deletes it, then has thei=
r device compromised<br>
&gt;=C2=A0 =C2=A0 =C2=A0it should indeed be gone forever.<br>
&gt; <br>
&gt; <br>
&gt; TreeKEM does give you that property, assuming that there&#39;s been no=
<br>
&gt; compromises, or you&#39;ve fully recovered from any compromise. All th=
at<br>
&gt; RTreeKEM improves is how quickly the group recovers from compromise.<b=
r>
&gt; Your statement that TreeKEM doesn&#39;t achieve this, or needs ACKs to=
<br>
&gt; achieve it, is simply not true.<br>
<br>
I&#39;m not sure where the misunderstanding lies so I will expand on this p=
oint:<br>
<br>
Timepoint: Event<br>
t: User receives a message AEAD(m,...) and decrypts it<br>
t+1: User deletes the message m<br>
t+2: Adversary compromises user&#39;s device.<br>
<br>
At t+3, can the adversary learn m?<br>
<br>
In TreeKEM, the following attack works:<br>
<br>
1. At t: the adversary records AEAD(m,...) as it is sent to the user.<br>
2. At t+3, the adversary uses the user&#39;s state to decode AEAD(m,...)<br=
>
<br>
This attack doesn&#39;t work in RTreeKEM because the user updated their<br>
state after receiving the message at timepoint t. This attack doesn&#39;t<b=
r>
work in TreeKEM with ACKs because the user will have updated their state<br=
>
and sent an update message at t+0.5.<br>
<br>
The ability to achieve PFS immediately after receiving a message, rather<br=
>
than after the transmission of the next message makes a huge difference<br>
in practice. It&#39;s clear that having every member of a group ACK each<br=
>
message isn&#39;t going to scale. Having a PFS window of hours, days or<br>
weeks is much much worse than a PFS window of &quot;immediately&quot;.<br>
<br>
Think about the practical implications for individuals. In many<br>
situations, e.g. inspection at a border, users are aware their device<br>
has been compromised. This guides their future actions (which PCS aims<br>
to protect), but it is typically too late for their past actions (which<br>
PFS aims to protect). Consequently,weak PFS guarantees are much worse in<br=
>
practice than weak PCS guarantees because future compromise is harder to<br=
>
predict than deducing past compromise. Although obviously we want strong<br=
>
forms of both to hold :).<br>
<br>
Best,<br>
Dennis<br>
<br>
</blockquote></div></div></div>

--0000000000000eb95e05959d65f9--


From nobody Wed Oct 23 19:06:12 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4862912011E for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 19:06:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K2RuVhPphRuX for <mls@ietfa.amsl.com>; Wed, 23 Oct 2019 19:06:09 -0700 (PDT)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0ED3512010D for <mls@ietf.org>; Wed, 23 Oct 2019 19:06:09 -0700 (PDT)
Received: by mail-qk1-x72a.google.com with SMTP id w2so21896952qkf.2 for <mls@ietf.org>; Wed, 23 Oct 2019 19:06:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=OZiMSUye13gETSzB+k/aSQBzfLMTQIwHtGGE3INXLg8=; b=B0E80WDhs32Thi1robcIiDvENgoivxNdd4mTk7jiqVNsZY2HHxLwtM9DMYvvjR9nv5 BdKkTD8/RToG2fNVUcQxC3tzlXAD6fL2W6759/9j4eraqxWvqmDdmeBiunkoqmb0i0Ts 7D8ZpU1pnfev6Io0YQ4TiX+3q82b2cN24RJhg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=OZiMSUye13gETSzB+k/aSQBzfLMTQIwHtGGE3INXLg8=; b=MPBfVpCiLX7EhdTfhh3xDW5TwEWv/Mgz0F4UZ1WHVnoHokqX0e221Q2Kx8V15FyxgE 8wiPvhw8dQDHuEPpLI1T9jaE55rPgJp18EkC2S60980G/M2UU9HstwY466aYmF3DVkDy 9u9rgVI+xZgbXPUkqUCj5ycUxe+jIpvQLDmMDpbeAyzBN70qBMPmcp9p+42ie95q/Lay 5e3Jdc+cpexlHSwBaiFOxaK5RBUajsVjtESB329FXFFkbIalsz4TQNTLrbF92XYAUSrF NPphB9dHZBb+XMwBo5kmKvyvo6d2WQ72TP7xDmRidJhOEoX+Q4/4I75M1iRBsfvRQ43N wwGg==
X-Gm-Message-State: APjAAAXuxCtx+BClupThvsYTf+dOy66H2DS/jVBbQSI5TqSA3pdKJBV3 z8Hhxljv/DjtY58HTVbVrhIoUzheCOqzAHkzP6XxoJVSpVpEfA==
X-Google-Smtp-Source: APXvYqyno36sm2WTgfpxpYFtqFPqb76RGNNwlZbIhgpfwRaik9WgWNI6i5fZc0PmTJNQClxI5Wxxee/vxt7aXCg9hNs=
X-Received: by 2002:ae9:e508:: with SMTP id w8mr231194qkf.131.1571882767714; Wed, 23 Oct 2019 19:06:07 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
In-Reply-To: <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Wed, 23 Oct 2019 19:05:55 -0700
Message-ID: <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com>
To: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>, dodis@cs.nyu.edu
Cc: konrad.kohbrok@datashrine.de, Messaging Layer Security WG <mls@ietf.org>,  Joel Alwen <jalwen@wickr.com>
Content-Type: multipart/alternative; boundary="000000000000fff06805959e79e7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/EgMwwu2kd3S09EF1qwEBhqdE0wA>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 02:06:11 -0000

--000000000000fff06805959e79e7
Content-Type: text/plain; charset="UTF-8"

>
> Let us assume the adversary compromised the initial state of some member
> of a group at t=0. In either version of TreeKEM: once that group member
> has successfully updated their state, the adversary will no longer have
> access to the current group secret. However, if we ever throw out that
> member and have them rejoin, the adversary has a way back into the
> group. The group does not know whether the initial member rejoined, or
> the adversary posing as the initial member. Likewise, the initial member
> loses their guarantee on the rest of the group's identity/security.
>

 Ah, when an adversary compromises a user, the user's ClientInitKeys are
also compromised. That's a really interesting point.

This attack doesn't work in RTreeKEM because the user updated their
> state after receiving the message at timepoint t. This attack doesn't
> work in TreeKEM with ACKs because the user will have updated their state
> and sent an update message at t+0.5.
>

This doesn't agree with my understanding of MLS. The way I'm reading your
example, AEAD(m, ...) is application data? There's a section in the spec
titled "Sender Ratchets" that describes how after application data is
decrypted, the symmetric decryption key and anything that you might be able
to derive it from is erased. So all of that erasing happens at t+1 and the
adversary has nothing to work with at t+2.

If on the other hand, AEAD(m, ...) is referring to something in the
handshake messages, that shouldn't be an issue either. Yes, the ciphertexts
can still be decrypted but epoch_secret[n] = HKDF(init_secret[n-1] ||
update_secret) where update_secret is what's decrypted, and
init_secret[n-1] was deleted after the handshake message was processed. The
adversary shouldn't have access to init_secret[n-1], so he can't compute
the next epoch secret.

---

I think I got your point, Brendan, and why we kept speaking past each
> other! And we are partially guilty here, by occasionally using the
> term "recover" to mean  two different things, contributing to the
> confusion.
>

I think I was using "recover" to refer to achieving both FS and PCS
simultaneously. Once the adversary is kicked out of the group, you have
PCS, but in TreeKEM you need to wait a bit to ensure future compromises
won't reveal past messages.

Whether this difference is "gargantuan" is a matter of taste.
>

I agree it's a matter of taste, which is why I don't expect to change my
mind. It's also why you won't hear me complain if the change is adopted
anyways. RTreeKEM has objectively better security.

--000000000000fff06805959e79e7
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
Let us assume the adversary compromised the initial state of some member<br=
>
of a group at t=3D0. In either version of TreeKEM: once that group member<b=
r>
has successfully updated their state, the adversary will no longer have<br>
access to the current group secret. However, if we ever throw out that<br>
member and have them rejoin, the adversary has a way back into the<br>
group. The group does not know whether the initial member rejoined, or<br>
the adversary posing as the initial member. Likewise, the initial member<br=
>
loses their guarantee on the rest of the group&#39;s identity/security.<spa=
n class=3D"gmail-im"><br></span>

</div></blockquote><div><br></div><div>=C2=A0Ah, when an adversary compromi=
ses a user, the user&#39;s ClientInitKeys are also compromised. That&#39;s =
a really interesting point. <br></div><div><br></div><blockquote class=3D"g=
mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204=
,204,204);padding-left:1ex"><div dir=3D"ltr">This attack doesn&#39;t work i=
n RTreeKEM because the user updated their<br>
state after receiving the message at timepoint t. This attack doesn&#39;t<b=
r>
work in TreeKEM with ACKs because the user will have updated their state<br=
>
and sent an update message at t+0.5.

</div></blockquote><div><br></div><div>This doesn&#39;t agree with my under=
standing of MLS. The way I&#39;m reading your example, AEAD(m, ...) is appl=
ication data? There&#39;s a section in the spec titled &quot;Sender Ratchet=
s&quot; that describes how after application data is decrypted, the symmetr=
ic decryption key and anything that you might be able to derive it from is =
erased. So all of that erasing happens at t+1 and the adversary has nothing=
 to work with at t+2.</div><div><br></div><div>If on the other hand, AEAD(m=
, ...) is referring to something in the handshake messages, that shouldn&#3=
9;t be an issue either. Yes, the ciphertexts can still be decrypted but epo=
ch_secret[n] =3D HKDF(init_secret[n-1] || update_secret) where update_secre=
t is what&#39;s decrypted, and init_secret[n-1] was deleted after the hands=
hake message was processed. The adversary shouldn&#39;t have access to init=
_secret[n-1], so he can&#39;t compute the next epoch secret.</div><div><br>=
</div><div>---</div><div><br></div><div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pad=
ding-left:1ex">
I think I got your point, Brendan, and why we kept speaking past each=20
other! And we are partially guilty here, by occasionally using the=C2=A0<di=
v>term &quot;recover&quot; to mean=C2=A0 two different things, contributing=
 to the confusion.</div></blockquote><div><br></div><div>I think I was usin=
g &quot;recover&quot; to refer to achieving both FS and PCS simultaneously.=
 Once the adversary is kicked out of the group, you have PCS, but in TreeKE=
M you need to wait a bit to ensure future compromises won&#39;t reveal past=
 messages.<br></div><div><br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex"><div>
Whether this difference is &quot;<span style=3D"color:rgb(0,0,0)">gargantua=
n&quot; is a matter of taste.</span></div></blockquote><div><br></div><div>=
I agree it&#39;s a matter of taste, which is why I don&#39;t expect to chan=
ge my mind. It&#39;s also why you won&#39;t hear me complain if the change =
is adopted anyways. RTreeKEM has objectively better security.<br></div>

</div></div>

--000000000000fff06805959e79e7--


From nobody Thu Oct 24 00:24:33 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EACFB120824 for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 00:24:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ehHi6jJuh-Cd for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 00:24:28 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [80.241.60.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68071120860 for <mls@ietf.org>; Thu, 24 Oct 2019 00:24:27 -0700 (PDT)
Received: from smtp2.mailbox.org (smtp2.mailbox.org [80.241.60.241]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id 81073A3369 for <mls@ietf.org>; Thu, 24 Oct 2019 09:24:23 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp2.mailbox.org ([80.241.60.241]) by spamfilter02.heinlein-hosting.de (spamfilter02.heinlein-hosting.de [80.241.56.116]) (amavisd-new, port 10030) with ESMTP id Pco-9pNpX-5L for <mls@ietf.org>; Thu, 24 Oct 2019 09:24:20 +0200 (CEST)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com>
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de>
Date: Thu, 24 Oct 2019 09:24:18 +0200
MIME-Version: 1.0
In-Reply-To: <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/P4BjcEyTdprV9oVYw5VJAAYmj3I>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 07:24:31 -0000

Hi Brendan,

> There's no benefit to processing random Updates from random users. Even in
> RTreeKEM, the benefit comes from processing the one Update from the one
> compromised user. In TreeKEM, you need to process the compromised user's Update
> and then everybody else's, which takes 2-4 times as long or so. So this is the
> same, regardless of the group size.

I might be confused what we're talking about here. In RTreeKEM processing a
random update from a random user allows the processing party to achieve FS.
Meaning that if previous messages and key material are deleted properly, even a
full compromise of the processing party doesn't give the adversary access to
those deleted messages. In regular TreeKEM on the other hand, processing the
update only gives the sending party FS guarantees.

Regarding Dennis' example:

> This doesn't agree with my understanding of MLS. The way I'm reading your
> example, AEAD(m, ...) is application data? There's a section in the spec titled
> "Sender Ratchets" that describes how after application data is decrypted, the
> symmetric decryption key and anything that you might be able to derive it from
> is erased. So all of that erasing happens at t+1 and the adversary has nothing
> to work with at t+2.
>
> If on the other hand, AEAD(m, ...) is referring to something in the handshake
> messages, that shouldn't be an issue either. Yes, the ciphertexts can still be
> decrypted but epoch_secret[n] = HKDF(init_secret[n-1] || update_secret) where
> update_secret is what's decrypted, and init_secret[n-1] was deleted after the
> handshake message was processed. The adversary shouldn't have access to
> init_secret[n-1], so he can't compute the next epoch secret.

You have a good point in that the deletion of the init_secret gives you some
form of FS, but it's somewhat fragile in that if the adversary has gotten hold
of an init_secret in the past by some other means (e.g. compromise of another
party), that fragile FS is gone.

The way I understand MLS (and I might well be confused about this) and the way
FS works is as follows.

Example:
The adversary compromises A and thus gets the init_secret of epoch t. Then A
issues an update, recovering from the compromise. Some messages are sent and
some parties send updates. However, in TreeKEM if the adversary compromises some
party B at epoch t+x that has not issued an update since the compromise of A,
all messages sent in epochs t..t+x are exposed. This is because that party's
HPKE keys have not changed. Those compromised HPKE keys of B allow the adversary
to decrypt the update messages from the wire and, together with the init_secret
of epoch t, lets them decrypt any message that was sent since then. Handshake or
otherwise. In RTreeKEM on the other hand, the HPKE keys are updated as soon as
A's (or any other) update is processed and thus every processing party
immediately achieves FS.

Note, that if I understand the key schedule correctly, deleting the encryption
key doesn't give you FS, because the adversary can still derive all the
necessary keys once they have compromised the handshake secrets and get the
group key as detailed in the example. Feel free to correct me on this, though.


From nobody Thu Oct 24 03:09:51 2019
Return-Path: <raphael@wire.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CF93120DAB for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 03:09:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wire-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XzAHh_vS1WHu for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 03:09:47 -0700 (PDT)
Received: from mail-wr1-x42c.google.com (mail-wr1-x42c.google.com [IPv6:2a00:1450:4864:20::42c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6A9E120DA8 for <mls@ietf.org>; Thu, 24 Oct 2019 03:09:46 -0700 (PDT)
Received: by mail-wr1-x42c.google.com with SMTP id l10so24960590wrb.2 for <mls@ietf.org>; Thu, 24 Oct 2019 03:09:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wire-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=JmcOJw7n6NKrtEwJihsamlS7cV9+qaS7D2BcO17LFNo=; b=zhwc6LgObV4NULo7EQj3MuKApicTHtYnZHfpfwEEVSHy2DN3aQHsfTkkX3EfXi93gk FvbmvOfkP0JXDjm4555arXb0rn6YxVqXC5jfnZ5d5IIchEb5hTlWzq9YTD/ToQ0qy5m9 nZZU050Sb9/n7HYaOmscTU9ZW/VhHEUNZg0JgaF/6LkBHqp3g9dzWX7bgdSWPhGjkK6M EP9eCbPcud1xSEVcWkKVEVIJfpShOitCZWZWtWFiab7jlZnRq12VdEDhxUU3wM+2hjXa eUozD5wax0DlG36c7FXMWuVLNDWMG8FeC1/UJxEt3kUlzObevTnUBKXqCXVTYIOHKE1t b8aA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=JmcOJw7n6NKrtEwJihsamlS7cV9+qaS7D2BcO17LFNo=; b=NKnirpHhqErCg4OozlXXKyYFhoRp6EjTPqjGxj3Qg92MjSmVCKcrE+hraK4UpNUC0L vlOtlrI2iPBRF1LY5xRr9OT8UCWeIKC+uzAZjCiLDmD34mMRhrAP+9OLorkgzPac/ETn V5tvRDqRyGMZfvKJlBqIgGQY+kTDGP1OIlB+MdYIV+TdxSZ9S3515YifZA08q4JLzaTw CvY4g7nNVt4DBPlhoNHaX1MsSMVHBJw4KKYW+NQrkL9LkRhDoTForQMSoBlDrgjjrs/B pjaw0GvddYgnacOVYXTnOcGoqZS3FLx2Fu6SbnH7u1+W9GN43lxEUXKp3VSmBQEh+ARy 9c4Q==
X-Gm-Message-State: APjAAAVONlMo1aUCNl0Qg2tHjXrxKjPSFtIuyny062yePUtRpu+AhMbH VX617W1v3ostwiBPBKARfouwRA==
X-Google-Smtp-Source: APXvYqzqxVmZCwfIzrMCyl3bpgdUJRAA+5pUVqbJBMeYKwhhOeBBI4FhBGOd4dazwIc4+SAREcBYFg==
X-Received: by 2002:adf:f90f:: with SMTP id b15mr3106468wrr.76.1571911785016;  Thu, 24 Oct 2019 03:09:45 -0700 (PDT)
Received: from rmbp.wire.local (h-62.96.148.44.host.de.colt.net. [62.96.148.44]) by smtp.gmail.com with ESMTPSA id r188sm2316559wmr.17.2019.10.24.03.09.43 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 24 Oct 2019 03:09:43 -0700 (PDT)
From: Raphael Robert <raphael@wire.com>
Message-Id: <6E36D92F-E700-4B57-9784-CFD366ECA912@wire.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_50F0AA02-7EF9-41A6-985D-6643AEB6957C"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Thu, 24 Oct 2019 12:09:41 +0200
In-Reply-To: <3B5BE109-6C78-474F-A0E5-138DE6931CF6@inria.fr>
Cc: Richard Barnes <rlb@ipv.sx>, Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Joel Alwen <jalwen@wickr.com>, Messaging Layer Security WG <mls@ietf.org>, Yevgeniy Dodis <dodis@cs.nyu.edu>
To: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
References: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com> <3B5BE109-6C78-474F-A0E5-138DE6931CF6@inria.fr>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/tSDugbf5YZzdUofVVTU5d7bwnTs>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 10:09:51 -0000

--Apple-Mail=_50F0AA02-7EF9-41A6-985D-6643AEB6957C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Chiming in as well, I think that RTreeKEM starts to sound like a =
promising improvement to TreeKEM. Thanks to all who participated!

I like the idea that better FS can be achieved at a relatively moderate =
cost (slightly larger message size).
Particularly in very large groups, it is unreasonable to assume that all =
members can issue Updates at a high frequency, because this would simply =
be unfeasible in terms of bandwidth/processing power. RTreeKEM seems to =
address this particular issue elegantly.

For me the fundamental new development since the interim is that we =
wouldn=E2=80=99t need to throw away crypto primitives like curve 25519. =
I would however like to point out that the current proposal with =
UPKE/clamping means that the usual crypto libraries (libsodium, =
WebCrypto, etc.) still cannot be used out of the box. This means that =
vendors/implementors have to implement something at a new layer that is =
somewhere in between the crypto library and the protocol layer. This =
poses a new risk, because it requires a higher expertise than just =
implementing the protocol layer (as it would be the case with TreeKEM). =
If we move to adopting RTreeKEM, we should pay special attention to =
that.

Finally I also understand that because of the clamping the actual =
security level of DH operations with curve 25519 is not as clearly =
understood as it is the case with X25519 now.

But none of the above is a good enough reason to discard RTreeKEM at =
this point! I=E2=80=99m looking forward to further discussions!

Raphael

> On 23 Oct 2019, at 00:10, Benjamin Beurdouche =
<benjamin.beurdouche@inria.fr> wrote:
>=20
> That=E2=80=99s my opinion as well... :)
> B.
>=20
>> On Oct 22, 2019, at 11:34 PM, Richard Barnes <rlb@ipv.sx> wrote:
>>=20
>> =EF=BB=BF
>> Since it appears I haven't chimed in on this thread -- I am generally =
OK with this change, if folks think it would improve the FS properties =
of the protocol, and assuming that Jo=C3=ABl's / Mike's solution to the =
X25519 problem works out. =20
>>=20
>> On the one hand, if we have to shove X25519 overboard, my bias would =
probably be against making this change, barring some really strong =
security rationale. =20
>>=20
>> On the other hand, if we can get confidence that the X25519 solution =
works (or that the failures are rare and tolerable), then this seems =
like a pretty minor burden from an engineering POV (a little more code, =
2x the DH operations on Update/Commit), so if there's security benefit, =
great.
>>=20
>> On Tue, Oct 22, 2019 at 5:26 PM Karthikeyan Bhargavan =
<karthik.bhargavan@gmail.com <mailto:karthik.bhargavan@gmail.com>> =
wrote:
>> Indeed!
>>=20
>> Like I said, it would be a ridiculous design for MLS.
>> I was simply trying to understand the guarantees.
>>=20
>> -Karthik
>>=20
>>> On 22 Oct 2019, at 23:20, Richard Barnes <rlb@ipv.sx =
<mailto:rlb@ipv.sx>> wrote:
>>>=20
>>> Just so we're clear, I would be *strongly* opposed to putting =
anything like this na=C3=AFve UPKE scheme into MLS..  For the simple =
reason that it expands the size of Welcome message by a factor of K.  =
RTreeKEM or nothing :)
>>>=20
>>> --Richard
>>>=20
>>>=20
>>> On Mon, Oct 21, 2019 at 6:53 PM Yevgeniy Dodis <dodis@cs.nyu.edu =
<mailto:dodis@cs.nyu.edu>> wrote:
>>> Great summary, Karthik!
>>>=20
>>> As I put in the other thread, comparison with the "naive" UPKE (for =
K=3D100 or less) might be a good idea.
>>>=20
>>> Pros of Naive Scheme:=20
>>> - more general, uses any PKE
>>> - using stream ciphers to generate K key pairs as needed makes the =
efficiency hit noticeably less than a factor of K,
>>> and perhaps closer to a factor of 2 (see below), but unclear =
a-priori.
>>> - for K>1, offers non-trivial (but still sub-optimal) security =
enhancement over basic TreeKEM (K=3D1)
>>>=20
>>> Cons (pros of RTreeKEM):
>>> - Public key storage increases by at least factor of K
>>> - While the naive use increases secret storage and computation by a =
factor of K, using stream cipher, after i uses one can only store the=20
>>> current seed to generate last (K-i) keys. However, K public keys =
should be published right away, so we must=20
>>> lose at least factor of 2 compared to TreeKEM to generate all keys =
twice (but possibly factor of K if people update too frequently, so all =
but=20
>>> 1 of the K keys gets used). So overall efficiency hit between 2 and =
K, which might already be comparable or worse than RTreeKEM.
>>> - Still much worse security than RTreeKEM, but possibly more =
expensive too, already for small K!
>>>=20
>>> Please let us know if you think this should be explored further.
>>> Yevgeniy
>>>=20
>>> On Mon, Oct 21, 2019 at 8:03 AM Karthikeyan Bhargavan =
<karthik.bhargavan@gmail.com <mailto:karthik.bhargavan@gmail.com>> =
wrote:
>>> I see. So, here=E2=80=99s how I read the improvements proposed in =
RTreeKEM.
>>>=20
>>> Currently, in TreeKEM (like in ART before it) we rely on each member =
to regularly *send* updates in order to get both PCS and FS for the =
group secrets.
>>> The informal secrecy guarantees we get are that:
>>> - (FS) if member A sends an update in epoch N (moving the epoch to =
N+1), and if A gets compromised in epoch N+1, the messages sent in epoch =
N remain secret
>>> - (PCS) if member A sends an update in epoch N (moving the epoch to =
N+1), and if A was (passively) compromised in epoch N, the messages sent =
in epoch N+1 remain secret
>>> In other words, each member who sends an update gets local =
protection against compromise, encouraging vulnerable members to keep =
sending updates...
>>>=20
>>> However, as Joel, Sandro, Yevgeniy, and Yiannis note in their paper, =
we could do better, at least for FS, if we use one-time decryption keys.
>>> If each recipient deletes the old decryption key after processing an =
update, then even just by *processing* an update, we get an additional  =
guarantee:
>>> - (FS=E2=80=99) if member A processes an update in epoch N (moving =
the epoch to N+1), and if A gets compromised in epoch N+1, the messages =
sent in epoch N remain secret
>>>=20
>>> It is also worth remembering that Signal also has a notion of =
one-time prekeys that work similarly for new messaging sessions.
>>> Although the following would be a bit ridiculous to use in large =
dynamic groups, here  is a sketch to achieve the receiver FS guarantee =
without the need for new crypto.
>>> - Every time a member A sends an update, it generates fresh node =
secrets for nodes on the path from A to the root
>>> - =46rom each node secret, A generates a large number K (=3D 100) =
private-public encryption keypairs and sends the public keys with the =
update..
>>> - On receiving the update, each member B stores all K public keys =
for each node in its co-path
>>> - Each of these public keys can be used only once for sending an =
update, after which the private key is deleted from all recipients.
>>> - The last public key at each node is not deleted; it can only be =
replaced when one of the members under that node sends a new update =
(with a fresh batch of public keys)..
>>>=20
>>> As far as I understand, the above scheme can be seen as an =
(inefficient) implementation of UPKE, right?
>>> Of course, it increases the size of each update by K, and only =
provides FS for K updates, after which some member has to send an =
update.
>>> Conversely, it does not require any new crypto algorithm. Is this a =
good baseline to compare UPKE schemes against?
>>>=20
>>> If I am mis-reading something, do let me know!
>>>=20
>>> -Karthik
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>>=20
>>>> On 17 Oct 2019, at 17:18, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
>>>>=20
>>>> I think the challenge with the hash-forward approach is how to do =
that
>>>> homomorphically. I.e.. what we need are two algorithms; one to =
refresh
>>>> the PK without knowing the SK (but possibly knowing a secret
>>>> rerandomizer delta if needed) and one to update SK (again possibly =
using
>>>> delta). So to use a hash-forward approach their must be:
>>>>=20
>>>> 1) a way to evolve PK forward to PK' and
>>>> 2) a *one-way* method to evolve SK forward to SK' compatible PK'.
>>>>=20
>>>> One-wayness is what gives us Forward Secrecy and "compatibility" =
between
>>>> the two key evolution methods is what allows for asynchronous (i.e. =
1
>>>> packet) updates.
>>>>=20
>>>> Currently we use a secret re-randomizer delta to ensure the SK =
update
>>>> method is one-way. That is, without the delta you cant "undo" the
>>>> update. But that would break if we (at least naively) used some =
public
>>>> delta, say hash(ciphertext). So I think this is the challenge that =
we'd
>>>> have to overcome.. Basically, make sure we SK evolution is one-way =
but
>>>> also compatible the public evolution of PK.
>>>>=20
>>>>=20
>>>>=20
>>>> Now one way sweet way to get all this (and more) would be to use a =
HIBE.
>>>>=20
>>>> Initial, PK for a ratchet tree node (i.e. its "identity" since this =
is a
>>>> HIBE now) is simply the empty vector PK :=3D () while the secret =
key is
>>>> the master public key for a fresh HIBE instance SK :=3D MSK. We =
also
>>>> include, as a second component of the nodes PK, the master public =
key
>>>> PK_0 =3D MPK. To "hash forward" / "re-randomize" when sending a =
ciphertext
>>>> C to that node we can do:
>>>>=20
>>>> PK' :=3D (PK, hash(C)).
>>>> SK' :=3D DeriveHIBEKey(PK, SK).
>>>>=20
>>>> So simply append hash(C) to the identity for that node and derive =
the
>>>> corresponding HIBE key.
>>>>=20
>>>> Ignoring the problems with using HIBE for a second, this is a very =
cool
>>>> solution. We don't need to send out the updated PK since everyone =
in the
>>>> group (and even the adversary) can compute it for themselves. We =
also
>>>> dont need a re-randomize delta as part of the plaintext because =
we're
>>>> using delta :=3D hash(ciphertext) so the plaintext is shorter =
again.
>>>> Moreover, HIBE security means that learning SK' doesn't tell you
>>>> anything interesting about SK. In particular, we have forward =
security.
>>>> (In fact, FS will hold even if hash(C) were chosen *completely*
>>>> adversarially, say, as part of a malicious update in an insider =
attack!)
>>>>=20
>>>> Of course, the problem with this solution is that we're using HIBE.
>>>> Worse, with unbounded depth because each new ciphertext sent to a =
node
>>>> results in going one depth further into the hierarchy. AFAIK all =
HIBE
>>>> constructions have pretty horrible (read exponential) efficiency as =
a
>>>> function of their depth. (And I won't mention the state of
>>>> standardization and open implementations for HIBE.)
>>>>=20
>>>> Now there could be a totally different approach that entirly avoids
>>>> HIBE. But even with this approach there's at least some glimer of =
hope
>>>> to improve on it because, if we don't wory about insider attacks we =
can
>>>> assume C is honestly generated which means hash(C) really has a ton =
of
>>>> entropy. So we dont seem to need the full expresivity HIBE =
identities
>>>> allow us. Rather we only need HIBE for "random" identities. Still, =
that
>>>> seems like a pretty slim hope for major efficiency improvement. It =
also
>>>> doesn't do anything to address the lack of implementations and =
standards.
>>>>=20
>>>> - Jo=C3=ABl
>>>>=20
>>>> On 17/10/2019 16:37, Karthik Bhargavan wrote:
>>>>> Thanks Yevgeniy,
>>>>>=20
>>>>> This helps a lot.
>>>>>=20
>>>>> To further my understanding, another question:
>>>>>=20
>>>>>>  Intuitively, the sender will not only encrypt the message, but =
also a
>>>>>> random Delta value. It will change public key using homomorthism =
by
>>>>>> multiplying with g^Delta (in specific DH based scheme), while the
>>>>>> recipient will decrypt Delta (using old secret key), and add it =
to the
>>>>>> old secret key to get there new one. So now corrupting (old sk =
plus
>>>>>> Delta) will not help decrypting the ciphertext just decepted, =
emailing
>>>>>> forward secrecy.=20
>>>>>=20
>>>>> I see that in the DH-based scheme, this Delta needs to be private,
>>>>> otherwise the adversary can compute sk once it knows sk+Delta.
>>>>> But, in general, is it possible to conceive of a UPKE scheme where =
the
>>>>> recipient effectively =E2=80=9Chashes forward=E2=80=9D its =
symmetric key,
>>>>> where this one way hash-forward function does not have to rely on =
an
>>>>> externally chosen secret value?
>>>>>=20
>>>>> Best,
>>>>> Karthik
>>>>>=20
>>>>>> This is the high level, hope it makes sense.
>>>>>> Thanks for your question,
>>>>>> Yevgeniy
>>>>>>=20
>>>>>> On Thu, Oct 17, 2019, 1:43 AM Karthik Bhargavan
>>>>>> <karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>
>>>>>> <mailto:karthikeyan.bhargavan@inria.fr =
<mailto:karthikeyan.bhargavan@inria.fr>>> wrote:
>>>>>>=20
>>>>>>    Hi Joel,
>>>>>>=20
>>>>>>    This looks very interesting. It is new to me since I was not =
at
>>>>>>    the interim.
>>>>>>    After reading the paper and the slides, I am still a bit fuzzy
>>>>>>    about what the recipient of an update needs to do.
>>>>>>=20
>>>>>>    For example, for the running example in your slide deck, it =
would
>>>>>>    help if I could see:
>>>>>>    - what secret keys does each leaf need to keep
>>>>>>    - how do these secrets change when an update from some other =
node
>>>>>>    is received.
>>>>>>    Just working this out for one update is enough.
>>>>>>=20
>>>>>>    I know that this is made precise in the eprint, but it would =
be
>>>>>>    faster if you could help us understand it :)
>>>>>>=20
>>>>>>    Best,
>>>>>>    Karthik
>>>>>>=20
>>>>>>> On 16 Oct 2019, at 23:51, Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>
>>>>>>    <mailto:jalwen@wickr.com <mailto:jalwen@wickr.com>>> wrote:
>>>>>>>=20
>>>>>>> <FS-TreeKEM.pdf>
>>>>>>=20
>>>>>>    _______________________________________________
>>>>>>    MLS mailing list
>>>>>>    MLS@ietf.org <mailto:MLS@ietf.org> <mailto:MLS@ietf.org =
<mailto:MLS@ietf.org>>
>>>>>>    https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>>>>>=20
>>>>>=20
>>>>>=20
>>>>> _______________________________________________
>>>>> MLS mailing list
>>>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www..ietf.org/mailman/listinfo/mls>
>>>>>=20
>>>>=20
>>>> _______________________________________________
>>>> MLS mailing list
>>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org <mailto:MLS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
>>=20
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_50F0AA02-7EF9-41A6-985D-6643AEB6957C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Chiming in as well, I think that RTreeKEM starts to sound =
like a promising improvement to TreeKEM. Thanks to all who =
participated!<div class=3D""><br class=3D""></div><div class=3D"">I like =
the idea that better FS can be achieved at a relatively moderate cost =
(slightly larger message size).<div class=3D"">Particularly in very =
large groups, it is unreasonable to assume that all members can issue =
Updates at a high frequency, because this would simply be unfeasible in =
terms of bandwidth/processing power. RTreeKEM seems to address this =
particular issue elegantly.</div><div class=3D""><br class=3D""></div><div=
 class=3D"">For me the fundamental new development since the interim is =
that we wouldn=E2=80=99t need to throw away crypto primitives like curve =
25519. I would however like to point out that the current proposal with =
UPKE/clamping means that the usual crypto libraries (libsodium, =
WebCrypto, etc.) still cannot be used out of the box. This means that =
vendors/implementors have to implement something at a new layer that is =
somewhere in between the crypto library and the protocol layer. This =
poses a new risk, because it requires a higher expertise than just =
implementing the protocol layer (as it would be the case with TreeKEM). =
If we move to adopting RTreeKEM, we should pay special attention to =
that.</div><div class=3D""><br class=3D""></div><div class=3D"">Finally =
I also understand that because of the clamping the actual security level =
of DH operations with curve 25519 is not as clearly understood as it is =
the case with X25519 now.</div><div class=3D""><br class=3D""></div><div =
class=3D"">But none of the above is a good enough reason to discard =
RTreeKEM at this point! I=E2=80=99m looking forward to further =
discussions!</div><div class=3D""><br class=3D""></div><div =
class=3D"">Raphael<br class=3D""><div><br class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D"">On 23 Oct 2019, at 00:10, =
Benjamin Beurdouche &lt;<a href=3D"mailto:benjamin.beurdouche@inria.fr" =
class=3D"">benjamin.beurdouche@inria.fr</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><meta =
http-equiv=3D"content-type" content=3D"text/html; charset=3Dutf-8" =
class=3D""><div dir=3D"auto" class=3D""><div dir=3D"ltr" =
class=3D"">That=E2=80=99s my opinion as well... :)</div><div dir=3D"ltr" =
class=3D"">B.</div><div dir=3D"ltr" class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D"">On Oct 22, 2019, at 11:34 PM, Richard Barnes =
&lt;<a href=3D"mailto:rlb@ipv.sx" class=3D"">rlb@ipv.sx</a>&gt; =
wrote:<br class=3D""><br class=3D""></blockquote></div><blockquote =
type=3D"cite" class=3D""><div dir=3D"ltr" class=3D"">=EF=BB=BF<div =
dir=3D"ltr" class=3D""><div class=3D"">Since it appears I haven't chimed =
in on this thread -- I am generally OK with this change, if folks think =
it would improve the FS properties of the protocol, and assuming that =
Jo=C3=ABl's / Mike's solution to the X25519 problem works out.&nbsp; <br =
class=3D""></div><div class=3D""><br class=3D""></div><div class=3D"">On =
the one hand, if we have to shove X25519 overboard, my bias would =
probably be against making this change, barring some really strong =
security rationale.&nbsp; <br class=3D""></div><div class=3D""><br =
class=3D""></div><div class=3D"">On the other hand, if we can get =
confidence that the X25519 solution works (or that the failures are rare =
and tolerable), then this seems like a pretty minor burden from an =
engineering POV (a little more code, 2x the DH operations on =
Update/Commit), so if there's security benefit, great.</div></div><br =
class=3D""><div class=3D"gmail_quote"><div dir=3D"ltr" =
class=3D"gmail_attr">On Tue, Oct 22, 2019 at 5:26 PM Karthikeyan =
Bhargavan &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com" =
class=3D"">karthik.bhargavan@gmail.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex"><div style=3D"overflow-wrap: =
break-word;" class=3D"">Indeed!<div class=3D""><br class=3D""></div><div =
class=3D"">Like I said, it would be a ridiculous design for =
MLS.</div><div class=3D"">I was simply trying to understand the =
guarantees.</div><div class=3D""><br class=3D""></div><div =
class=3D"">-Karthik<br class=3D""><div class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D"">On 22 =
Oct 2019, at 23:20, Richard Barnes &lt;<a href=3D"mailto:rlb@ipv.sx" =
target=3D"_blank" class=3D"">rlb@ipv.sx</a>&gt; wrote:</div><br =
class=3D""><div class=3D""><div dir=3D"ltr" class=3D""><div dir=3D"ltr" =
class=3D"">Just so we're clear, I would be *strongly* opposed to putting =
anything like this na=C3=AFve UPKE scheme into MLS..&nbsp; For the =
simple reason that it expands the size of Welcome message by a factor of =
K.&nbsp; RTreeKEM or nothing :)<br class=3D""></div><div dir=3D"ltr" =
class=3D""><br class=3D""></div><div class=3D"">--Richard</div><div =
class=3D""><br class=3D""></div><br class=3D""><div =
class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct =
21, 2019 at 6:53 PM Yevgeniy Dodis &lt;<a href=3D"mailto:dodis@cs.nyu.edu"=
 target=3D"_blank" class=3D"">dodis@cs.nyu.edu</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr" class=3D"">Great =
summary, Karthik!<div class=3D""><br class=3D""></div><div class=3D"">As =
I put in the other thread, comparison with the "naive" UPKE (for K=3D100 =
or less) might be a good idea.</div><div class=3D""><br =
class=3D""></div><div class=3D"">Pros of Naive Scheme:&nbsp;</div><div =
class=3D"">- more general, uses any PKE</div><div class=3D"">- using =
stream ciphers to generate K key pairs as needed makes the efficiency =
hit noticeably less than a factor of K,</div><div class=3D"">and perhaps =
closer to a factor of 2 (see below), but unclear a-priori.</div><div =
class=3D"">- for K&gt;1, offers non-trivial (but still sub-optimal) =
security enhancement over basic TreeKEM (K=3D1)</div><div class=3D""><br =
class=3D""></div><div class=3D"">Cons (pros of RTreeKEM):</div><div =
class=3D"">- Public key storage increases by at least factor of =
K</div><div class=3D"">- While the naive use increases secret storage =
and computation by a factor of K, using stream cipher,=20

 after i uses one can only store the&nbsp;</div><div class=3D"">current =
seed to generate last (K-i) keys. However, K public keys should&nbsp;be =
published right away, so we must&nbsp;</div><div class=3D"">lose at =
least factor of 2 compared to TreeKEM to generate all keys twice (but =
possibly factor of K if people update too frequently, so all =
but&nbsp;</div><div class=3D"">1 of the K keys gets used). So overall =
efficiency hit between 2 and K, which might already be comparable or =
worse than RTreeKEM.</div><div class=3D"">- Still much worse security =
than RTreeKEM, but possibly more expensive too, already for small =
K!</div><div class=3D""><br class=3D""></div><div class=3D"">Please let =
us know if you think this should be explored further.</div><div =
class=3D"">Yevgeniy</div></div><br class=3D""><div =
class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Oct =
21, 2019 at 8:03 AM Karthikeyan Bhargavan &lt;<a =
href=3D"mailto:karthik.bhargavan@gmail.com" target=3D"_blank" =
class=3D"">karthik.bhargavan@gmail.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex"><div class=3D"">I see. So, here=E2=80=99=
s how I read the improvements proposed in RTreeKEM.<div class=3D""><br =
class=3D""></div><div class=3D"">Currently, in TreeKEM (like in ART =
before it) we rely on each member to regularly *send* updates in order =
to get both PCS and FS for the group secrets.</div><div class=3D"">The =
informal secrecy guarantees we get are that:</div><div class=3D"">- (FS) =
if member A sends an update in epoch N (moving the epoch to N+1), and if =
A gets compromised in epoch N+1, the messages sent in epoch N remain =
secret</div><div class=3D"">- (PCS) if member A sends an update in epoch =
N (moving the epoch to N+1), and if A was (passively) compromised in =
epoch N, the messages sent in epoch N+1 remain secret</div><div =
class=3D"">In other words, each member who sends an update gets local =
protection against compromise, encouraging vulnerable members to keep =
sending updates...</div><div class=3D""><br class=3D""></div><div =
class=3D"">However, as Joel, Sandro, Yevgeniy, and Yiannis note in their =
paper, we could do better, at least for FS, if we use one-time =
decryption keys.</div><div class=3D"">If each recipient deletes the old =
decryption key after processing an update, then even just by =
*processing* an update, we get an additional &nbsp;guarantee:</div><div =
class=3D"">- (FS=E2=80=99) if member A processes an update in epoch N =
(moving the epoch to N+1), and if A gets compromised in epoch N+1, the =
messages sent in epoch N remain secret</div><div class=3D""><br =
class=3D""></div><div class=3D"">It is also worth remembering that =
Signal also has a notion of one-time prekeys that work similarly for new =
messaging sessions.</div><div class=3D"">Although the following would be =
a bit ridiculous to use in large dynamic groups, here &nbsp;is a sketch =
to achieve the receiver FS guarantee without the need for new =
crypto.</div><div class=3D"">- Every time a member A sends an update, it =
generates fresh node secrets for nodes on the path from A to the =
root</div><div class=3D"">- =46rom each node secret, A generates a large =
number K (=3D 100) private-public encryption keypairs and sends the =
public keys with the update..</div><div class=3D"">- On receiving the =
update, each member B stores all K public keys for each node in its =
co-path</div><div class=3D"">- Each of these public keys can be used =
only once for sending an update, after which the private key is deleted =
from all recipients.</div><div class=3D"">- The last public key at each =
node is not deleted; it can only be replaced when one of the members =
under that node sends a new update (with a fresh batch of public =
keys)..</div><div class=3D""><br class=3D""></div><div class=3D"">As far =
as I understand, the above scheme can be seen as an (inefficient) =
implementation of UPKE, right?</div><div class=3D"">Of course, it =
increases the size of each update by K, and only provides FS for K =
updates, after which some member has to send an update.</div><div =
class=3D"">Conversely, it does not require any new crypto algorithm. Is =
this a good baseline to compare UPKE schemes against?</div><div =
class=3D""><br class=3D""></div><div class=3D"">If I am mis-reading =
something, do let me know!</div><div class=3D""><br class=3D""></div><div =
class=3D"">-Karthik</div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><div class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On 17 Oct 2019, at 17:18, Joel Alwen &lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" =
class=3D"">jalwen@wickr.com</a>&gt; wrote:</div><br class=3D""><div =
class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">I think the =
challenge with the hash-forward approach is how to do that</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">homomorphically. =
I.e.. what we need are two algorithms; one to refresh</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the PK without =
knowing the SK (but possibly knowing a secret</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">rerandomizer =
delta if needed) and one to update SK (again possibly using</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">delta). So to =
use a hash-forward approach their must be:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">1) a way to =
evolve PK forward to PK' and</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">2) a *one-way* =
method to evolve SK forward to SK' compatible PK'.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">One-wayness is =
what gives us Forward Secrecy and "compatibility" between</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the two key =
evolution methods is what allows for asynchronous (i.e. 1</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">packet) =
updates.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Currently we use =
a secret re-randomizer delta to ensure the SK update</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">method is =
one-way. That is, without the delta you cant "undo" the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">update. But that =
would break if we (at least naively) used some public</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">delta, say =
hash(ciphertext). So I think this is the challenge that we'd</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">have to =
overcome.. Basically, make sure we SK evolution is one-way but</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">also compatible =
the public evolution of PK.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Now one way =
sweet way to get all this (and more) would be to use a HIBE.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Initial, PK for =
a ratchet tree node (i.e. its "identity" since this is a</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">HIBE now) is =
simply the empty vector PK :=3D () while the secret key is</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">the master =
public key for a fresh HIBE instance SK :=3D MSK. We also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">include, as a =
second component of the nodes PK, the master public key</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">PK_0 =3D MPK. To =
"hash forward" / "re-randomize" when sending a ciphertext</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">C to that node =
we can do:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">PK' :=3D (PK, =
hash(C)).</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">SK' :=3D =
DeriveHIBEKey(PK, SK).</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">So simply append =
hash(C) to the identity for that node and derive the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">corresponding =
HIBE key.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Ignoring the =
problems with using HIBE for a second, this is a very cool</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">solution. We =
don't need to send out the updated PK since everyone in the</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">group (and even =
the adversary) can compute it for themselves. We also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">dont need a =
re-randomize delta as part of the plaintext because we're</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">using delta :=3D =
hash(ciphertext) so the plaintext is shorter again.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Moreover, HIBE =
security means that learning SK' doesn't tell you</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">anything =
interesting about SK. In particular, we have forward security.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">(In fact, FS =
will hold even if hash(C) were chosen *completely*</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">adversarially, =
say, as part of a malicious update in an insider attack!)</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Of course, the =
problem with this solution is that we're using HIBE.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Worse, with =
unbounded depth because each new ciphertext sent to a node</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">results in going =
one depth further into the hierarchy. AFAIK all HIBE</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">constructions =
have pretty horrible (read exponential) efficiency as a</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">function of =
their depth. (And I won't mention the state of</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">standardization =
and open implementations for HIBE.)</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">Now there could =
be a totally different approach that entirly avoids</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">HIBE. But even =
with this approach there's at least some glimer of hope</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">to improve on it =
because, if we don't wory about insider attacks we can</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">assume C is =
honestly generated which means hash(C) really has a ton of</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">entropy. So we =
dont seem to need the full expresivity HIBE identities</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">allow us. Rather =
we only need HIBE for "random" identities. Still, that</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">seems like a =
pretty slim hope for major efficiency improvement. It also</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">doesn't do =
anything to address the lack of implementations and standards.</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">- =
Jo=C3=ABl</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">On 17/10/2019 =
16:37, Karthik Bhargavan wrote:</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><blockquote type=3D"cite" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D"">Thanks Yevgeniy,<br class=3D""><br =
class=3D"">This helps a lot.<br class=3D""><br class=3D"">To further my =
understanding, another question:<br class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D"">&nbsp;Intuitively, the sender will not only =
encrypt the message, but also a<br class=3D"">random Delta value. It =
will change public key using homomorthism by<br class=3D"">multiplying =
with g^Delta (in specific DH based scheme), while the<br =
class=3D"">recipient will decrypt Delta (using old secret key), and add =
it to the<br class=3D"">old secret key to get there new one. So now =
corrupting (old sk plus<br class=3D"">Delta) will not help decrypting =
the ciphertext just decepted, emailing<br class=3D"">forward =
secrecy.&nbsp;<br class=3D""></blockquote><br class=3D"">I see that in =
the DH-based scheme, this Delta needs to be private,<br =
class=3D"">otherwise the adversary can compute sk once it knows =
sk+Delta.<br class=3D"">But, in general, is it possible to conceive of a =
UPKE scheme where the<br class=3D"">recipient effectively =E2=80=9Chashes =
forward=E2=80=9D its symmetric key,<br class=3D"">where this one way =
hash-forward function does not have to rely on an<br class=3D"">externally=
 chosen secret value?<br class=3D""><br class=3D"">Best,<br =
class=3D"">Karthik<br class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D"">This is the high level, hope it makes sense.<br =
class=3D"">Thanks for your question,<br class=3D"">Yevgeniy<br =
class=3D""><br class=3D"">On Thu, Oct 17, 2019, 1:43 AM Karthik =
Bhargavan<br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank" =
class=3D"">karthikeyan.bhargavan@inria.fr</a><br class=3D"">&lt;<a =
href=3D"mailto:karthikeyan.bhargavan@inria.fr" target=3D"_blank" =
class=3D"">mailto:karthikeyan.bhargavan@inria.fr</a>&gt;&gt; wrote:<br =
class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Hi Joel,<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;This looks very interesting. It is new to =
me since I was not at<br class=3D"">&nbsp;&nbsp;&nbsp;the interim.<br =
class=3D"">&nbsp;&nbsp;&nbsp;After reading the paper and the slides, I =
am still a bit fuzzy<br class=3D"">&nbsp;&nbsp;&nbsp;about what the =
recipient of an update needs to do.<br class=3D""><br =
class=3D"">&nbsp;&nbsp;&nbsp;For example, for the running example in =
your slide deck, it would<br class=3D"">&nbsp;&nbsp;&nbsp;help if I =
could see:<br class=3D"">&nbsp;&nbsp;&nbsp;- what secret keys does each =
leaf need to keep<br class=3D"">&nbsp;&nbsp;&nbsp;- how do these secrets =
change when an update from some other node<br =
class=3D"">&nbsp;&nbsp;&nbsp;is received.<br =
class=3D"">&nbsp;&nbsp;&nbsp;Just working this out for one update is =
enough.<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;I know that this =
is made precise in the eprint, but it would be<br =
class=3D"">&nbsp;&nbsp;&nbsp;faster if you could help us understand it =
:)<br class=3D""><br class=3D"">&nbsp;&nbsp;&nbsp;Best,<br =
class=3D"">&nbsp;&nbsp;&nbsp;Karthik<br class=3D""><br =
class=3D""><blockquote type=3D"cite" class=3D"">On 16 Oct 2019, at =
23:51, Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
target=3D"_blank" class=3D"">jalwen@wickr.com</a><br =
class=3D""></blockquote>&nbsp;&nbsp;&nbsp;&lt;<a =
href=3D"mailto:jalwen@wickr.com" target=3D"_blank" =
class=3D"">mailto:jalwen@wickr.com</a>&gt;&gt; wrote:<br =
class=3D""><blockquote type=3D"cite" class=3D""><br =
class=3D"">&lt;FS-TreeKEM.pdf&gt;<br class=3D""></blockquote><br =
class=3D"">&nbsp;&nbsp;&nbsp;_____________________________________________=
__<br class=3D"">&nbsp;&nbsp;&nbsp;MLS mailing list<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><span =
class=3D"">&nbsp;</span>&lt;<a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">mailto:MLS@ietf.org</a>&gt;<br =
class=3D"">&nbsp;&nbsp;&nbsp;<a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">MLS mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br class=3D""><a =
href=3D"https://www..ietf.org/mailman/listinfo/mls" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D""><br=
 class=3D""></blockquote><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" =
class=3D"">_______________________________________________</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><span =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none;float:none;display:inline" class=3D"">MLS mailing =
list</span><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><a href=3D"mailto:MLS@ietf.org" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;tex=
t-decoration:none" class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
style=3D"font-family:Helvetica;font-size:12px;font-style:normal;font-varia=
nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;t=
ext-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a></div></blockquote=
></div><br =
class=3D""></div></div>_______________________________________________<br =
class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div>
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer" =
target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br =
class=3D""></div></blockquote></div><br =
class=3D""></div></div></blockquote></div>
<span class=3D"">_______________________________________________</span><br=
 class=3D""><span class=3D"">MLS mailing list</span><br class=3D""><span =
class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a></span><br class=3D""><span class=3D""><a =
href=3D"https://www.ietf.org/mailman/listinfo/mls" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a></span><br =
class=3D""></div></blockquote></div>______________________________________=
_________<br class=3D"">MLS mailing list<br class=3D""><a =
href=3D"mailto:MLS@ietf.org" class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br =
class=3D""></div></div></body></html>=

--Apple-Mail=_50F0AA02-7EF9-41A6-985D-6643AEB6957C--


From nobody Thu Oct 24 10:59:34 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B308120115 for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 10:59:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z522TMHKihCo for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 10:59:27 -0700 (PDT)
Received: from mail-qt1-x836.google.com (mail-qt1-x836.google.com [IPv6:2607:f8b0:4864:20::836]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EFDEB120802 for <mls@ietf.org>; Thu, 24 Oct 2019 10:59:26 -0700 (PDT)
Received: by mail-qt1-x836.google.com with SMTP id t20so39154378qtr.10 for <mls@ietf.org>; Thu, 24 Oct 2019 10:59:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=bE4MwQ7oe99jozbDkM4pHYfTNdgpnh/8lFowyTFeq68=; b=QxeqtJoC6xqnXzDCTpcOkyIiH1HURQsRmd9J0GVz62qTTPhbka//eF3d8n5PdXKUt2 NsjgDQSf76zjmRIhBBx9LOSSH/f1gaAbAxTRzcPbQ/ECGcql3OiEIVs46W8MzsrOg3FF l43URw9c0Tt3bGiVoKNeXjh9CeK4pAsd5MgRM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=bE4MwQ7oe99jozbDkM4pHYfTNdgpnh/8lFowyTFeq68=; b=UZF47YUPwlvmxFJ4/hZ36lLAc/wBt8tAXJMfiaO8L682QcRVfmuNRlNwQlF5HtwwYE xBtOArARPjhm1V9wXkgV4Pl49PcXpeJ+TvXRJDO+DVvjIP4lmXGFCblWoYsCToe/E+MT BioxsYyRhLpZRfQVsduE+tWuVjxrVka31cB1X2ySWJBmaJ//bzxf0gBXaALANWHNSoLg Hvh5ib8aUu1WwjsQnm9D494wA45NrXvbD8+ZbMsuOtnISCnVsju1KrrP7strkPuHkQ8I OHvHVuB70Ko2CsgFhb4434TPV358T2ALsfIeA98uLiw3q2gPkJHUZnTiC+IRg5M0EbKV wLHQ==
X-Gm-Message-State: APjAAAWy71JVPtPnZrVPDjXu3HgWI04/lLgPxqhGdQNDOSOgei1s6s/o HsOLrNQByJYz9CLxBW+griXQzk4mKLnTiyToOzriZjeU+mW4LA==
X-Google-Smtp-Source: APXvYqxOzQU1gWUDmBnDgcnMAo22YeoVgoC3XRlSH/f9ug8mNn4eoWfeKrY7bp+FPfcbHbW+KLZKC7gkdZC8qdyur+Y=
X-Received: by 2002:ac8:6793:: with SMTP id b19mr3027965qtp.99.1571939965522;  Thu, 24 Oct 2019 10:59:25 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com> <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de>
In-Reply-To: <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Thu, 24 Oct 2019 10:59:08 -0700
Message-ID: <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com>
To: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000412f520595abcb01"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/iogICC8p9PR4CcNoFYhhWP1x-B0>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 17:59:30 -0000

--000000000000412f520595abcb01
Content-Type: text/plain; charset="UTF-8"

>
> I might be confused what we're talking about here. In RTreeKEM processing a
> random update from a random user allows the processing party to achieve FS.
> Meaning that if previous messages and key material are deleted properly,
> even a
> full compromise of the processing party doesn't give the adversary access
> to
> those deleted messages. In regular TreeKEM on the other hand, processing
> the
> update only gives the sending party FS guarantees.
>

 Sorry, I think i confused PCS and FS. But still, if Alice and Bob are
talking and Alice is compromised, then having Bob send an Update doesn't
accomplish anything. In RTreeKEM, Alice needs to send and Update and Bob
needs to process it, and then we know that any messages sent after Bob
processes the Update are forward-secure again. I think we probably agree,
we're just talking past each other.

You have a good point in that the deletion of the init_secret gives you some
> form of FS, but it's somewhat fragile in that if the adversary has gotten
> hold
> of an init_secret in the past by some other means (e.g. compromise of
> another
> party), that fragile FS is gone.
>

Yes, this is the vulnerability that motivated the development of RTreeKEM,
but you're assuming multiple compromises while I wasn't. I want to state my
position again very clearly:

Assume that a single user was compromised and their state was given to an
adversary. Assume that the compromise has been *immediately healed* by an
Update/Remove message affecting the compromised user, meaning that the
adversary is no longer able to read messages. How long is it until we know
that messages sent after the compromise was healed are again
forward-secure, meaning that no future compromises will expose them?

   - *TreeKEM:* You need to wait until everyone sends an Update.
   - *RTreeKEM:* You need to wait until everyone processes the
   Update/Remove. How do you know everyone has processed the Update/Remove,
   and aren't offline with old key material waiting to be compromised? By
   waiting until everyone sends an Update.

Therefore RTreeKEM offers no material improvement over TreeKEM. RTreeKEM's
improvement over TreeKEM is unmeasurable, unenforceable.

--000000000000412f520595abcb01
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=
=3D"ltr">I might be confused what we&#39;re talking about here. In RTreeKEM=
 processing a<br>
random update from a random user allows the processing party to achieve FS.=
<br>
Meaning that if previous messages and key material are deleted properly, ev=
en a<br>
full compromise of the processing party doesn&#39;t give the adversary acce=
ss to<br>
those deleted messages. In regular TreeKEM on the other hand, processing th=
e<br>
update only gives the sending party FS guarantees.</div></blockquote><div><=
br></div><div>=C2=A0Sorry, I think i confused PCS and FS. But still, if Ali=
ce and Bob are talking and Alice is compromised, then having Bob send an Up=
date doesn&#39;t accomplish anything. In RTreeKEM, Alice needs to send and =
Update and Bob needs to process it, and then we know that any messages sent=
 after Bob processes the Update are forward-secure again. I think we probab=
ly agree, we&#39;re just talking past each other.</div><div><br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:=
1px solid rgb(204,204,204);padding-left:1ex"><div>You have a good point in =
that the deletion of the init_secret gives you some<br>
form of FS, but it&#39;s somewhat fragile in that if the adversary has gott=
en hold<br>
of an init_secret in the past by some other means (e.g. compromise of anoth=
er<br>
party), that fragile FS is gone.</div></blockquote><div><br></div><div>Yes,=
 this is the vulnerability that motivated the development of RTreeKEM, but =
you&#39;re assuming multiple compromises while I wasn&#39;t. I want to stat=
e my position again very clearly:</div><div><br></div><div>Assume that a si=
ngle user was compromised and their state was given to an adversary. Assume=
 that the compromise has been <b>immediately healed</b> by an Update/Remove=
 message affecting the compromised user, meaning that the adversary is no l=
onger able to read messages. How long is it until we know that messages sen=
t after the compromise was healed are again forward-secure, meaning that no=
 future compromises will expose them?</div><div><ul><li><b>TreeKEM:</b> You=
 need to wait until everyone sends an Update.<br></li><li><b>RTreeKEM:</b> =
You need to wait until everyone processes the Update/Remove. How do you kno=
w everyone has processed the Update/Remove, and aren&#39;t offline with old=
 key material waiting to be compromised? By waiting until everyone sends an=
 Update.</li></ul><div>Therefore RTreeKEM offers no material improvement ov=
er TreeKEM. RTreeKEM&#39;s improvement over TreeKEM is unmeasurable, unenfo=
rceable.<br></div></div></div>

--000000000000412f520595abcb01--


From nobody Thu Oct 24 12:05:08 2019
Return-Path: <dennis.jackson@cs.ox.ac.uk>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2470912008F for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 12:05:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jmep9-ddAlhN for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 12:05:06 -0700 (PDT)
Received: from relay15.mail.ox.ac.uk (relay15.mail.ox.ac.uk [163.1.2.163]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A70C120025 for <mls@ietf.org>; Thu, 24 Oct 2019 12:05:06 -0700 (PDT)
Received: from smtp4.mail.ox.ac.uk ([129.67.1.207]) by relay15.mail.ox.ac.uk with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNiPw-000AXW-oh; Thu, 24 Oct 2019 20:05:04 +0100
Received: from 61.ip-51-38-113.eu ([51.38.113.61] helo=[192.168.2.2]) by smtp4.mail.ox.ac.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNiPw-0003jL-EA; Thu, 24 Oct 2019 20:05:04 +0100
To: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>, Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Cc: Messaging Layer Security WG <mls@ietf.org>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com> <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de> <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com>
From: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
Openpgp: preference=signencrypt
Autocrypt: addr=dennis.jackson@cs.ox.ac.uk; prefer-encrypt=mutual; keydata= mQINBFbAmb8BEADCLixsrAJyvknI95ZIZNVeDJbYvldeXpw7iyhrdUdRK69USU5S9EESulYh k1KlxDB5VfG8CCA/WzG1IonONdXmgLFa1NcmdVvkFjbXf5mbGYG+9pTkieM+UHikniAizIOi ibdTWEEc2opOAvpVypek4SSsfCoXfXqj0j5AXSapHiVzhhWuaXhKVuFdLtYwJDU/x0FXgStm erFMIOeZ5FLFnjkkNyEa1t3XCcf7bfgw8J86UmWzgkVLmtBYbDK0ZAFjtFep5Kps11iTDIa3 xYXzuqgkWwkg7b1mhn5gQUl/kKZqQbuG+Sk+BydjH8e1PJkO6p2eAprO0AoucRuuBl1pmg/F bf/WJC6/XD3AV87ERAdXbb9cH+vrRT8GpiNX5r+7OuXavc3/LNU9stqsdshXwdZlDyPyDIG2 Llj6hB4eS0tEpat3otcPDkXUjXjyOUQ6jKTNSZ+xTBtVTXznflDCGdn9GV0q+4ZbdRZ5tfXM DXM+uMqVxjvh2IjCrka7zf1rRWg1WZu+NrzAUrvPMPddDJfd8JNrIcvV+DIBxPVsUTJLEGt9 PW8LkQb5FrG7T6a813JYNoAtL4w7296UYmUpV1Kvv8otO+uH860x5Ci83ZCXb7gKr9Rankn5 Jcg+shWnDFgSq6uM/u3MmyRV2iw7aCSgcgfy4EPTojJdy3KjzQARAQABtCtEZW5uaXMgSmFj a3NvbiA8ZGVubmlzLmphY2tzb25AY3Mub3guYWMudWs+iQIwBBMBCgAaBAsJCAcCFQoCFgEC GQAFglsIFtUCngECmwMACgkQYQWndYzSRqzvkA//djyyIydK5jhxNFqmMvJTkTZwawKWV7Tc cEntsIwYsHw8ec9Edo/M6fwp8aFmddPnzRo0EBmh6KNm887VxgH0FXmcR7k8bD3qUzIhfq11 4ezWtTk0nWjpieEsFb20lCMZjK9dsfXVRgFrfe00x2lhjPWQ5G5mTkfX8KYcDs5nmc+13qHK Ux6e6aSdEa4mnxrT0NsEg2H2xKgwrGkNIxJO6snrh3A3mT6+2F8ZCiRWwmOhcHBzNCFp1enR bMJpNRhcmGBDNJ9TpnQHDRVE67ds3PC/vKDkYQ3tEIkdgc/KVGOo7+kZxSU/n1gARDZ4PYUw IGOM81aEhmrbXoF33Jbic2jnuLfqsC8uXeP6wGgGpEdGThQ+7zslOPDradgDZBlUmYenuwOb JwJEj+JbbZPcND17VrgVDzcM1rh1w9wcKrRDMIw/zLCpEDOfLRe2ad/V380q/Eh3qa4QrZE7 tnXcOTIZfxd1zZ6TcpOvMVYQPN5Zfrlazmw9bTsdkm3WVrzvxc9DJ/D5Ws+aMu+JfSD+C5Nd n5w2fW7OOiDudeFXj88CL7oBehPJ2ajCDmHd/vc1W7CSoPte6aHBgSGER9cWm5hpEOXacQt+ pEz/uMvq+zkDIydy9YL/8hDo5TsVA4Yo8wNdKOuyaStk/oh3WNda05N0jr8VhRMdxnLN/hWY Ely5Ag0EVsCZvwEQAOBD1BmNy7FWbpg9Tm3OfMNC/yLs6G7rk3OFw7BhpjHXHSsEge48HbvP lfdR9abA1cmbgYR7EyaOav1s9ugU7EtDCcK8zHZcaUg3gC+FdjsnkIQCkf/3HK2sxcbBSrkX 2Uu2jjufvZu10g/aavkCuTHIUiYAHhQU5kCkRI7NYvXIKmaPY2Km3YIVJ50x+4GlE/WVZk8w HpvisxDInBioziUjAIqTt0at5tE1ObZksl2eNHNCwlo15WE2hKIYCuJKb57wCBKaOKo/gSw/ yN2DX3HaU/PF+8rCikkKDhHDrefFwGkqBf3zHlrLiHIr+ONVZ8i9dxMyg5TERxjd3vZ4ha+7 8cr8G83HC8lSBEpPYmoeU4J8vWf8kjBlai0UmzyZRF3SeZlqldxo7zJhYq3xIsDGKVuSCn68 2TcoEsR5WS/Zjc0ZoH/YIpdVy8FRu45dJ2IUzHVyszMfNWKob7ZsQ9JCXiXypmIF6ut5mwv8 ddCMdG6Jdpvg1fr0coABNbJSrUM8uFEldmRFpBdbNx5xSCJjNo+QuTHOXWuO3/GFRmux8/kW TlfF3+dvff2Pw3CKENoysgcOflYShcjOv/03sQ6AfxTm2Jnh5dqJSoVnPWpcDyPqn3k4zoZW 0ISqorI8yehJbfT3C0J5iEX75c8vJWfUUjIhyO0CpHxATNW3j3QxABEBAAGJAh8EGAEIABMF AlbAmccJEGEFp3WM0kasAhsMAAD8JhAAtkUWMLjr1RYTSMPrmTp3NGZfNSblv0GGHtL7TvT1 kFwdT/hs29Gjrj0FffZE6RKDEGls9AL6LY/g3wA5WQsXaK0wqwb8MBeIPWvFPvVQbqrifN3A bpukTl4OCBOwJbHS/GO1V3AwaLl4l3U/+kzR7UsnszWs4kizE9lBJ0AYFbxB0xbPF6iI32Cm K3nrLPfkXBXw2xX01nOLxTx9E7YdVpP3Re1c96aBTflm4CAGUfTZ5xgQMW6rgJ8FBc3oLckt 9MT0qB5XkmKGI1kkRypN7hIFRBcPxegeO8S3fpBUOop5F0el24TVx6KJTktpLmlIfUsEQ0Lx CqNtUk1v3eMCoKmeky8WbFcUArRV4DKXDAK1e3C8poMaehRgfl8sjz6SuH1VXpCMLNPpNMtZ EK4FU+C0jGgJyHS9N1UZjq8Qa8FnYKruyPgTpKEAsqlo5vB6J8phiaKXxnren8HqIfzQdrt8 3M+raXc7+Fqis4pYS49vfIpxUzcqvKUiSgDGKemqMw9w9U5dBEQeLNW08uOKSjyENU4e1Ob/ IiimIpEPA5LEIhSfOP9CN9TculGqvo0g12XnB+g5AAtm1ohMkb33T17IR3rKkhlvIITuY1qi fZz7OgGbXh4G5oUHXNBOhXHaqRIzQCCRbBUFA09OyJBLWAGH6HcM/DeM0I7Ng55uMl8=
Message-ID: <1e5c700d-6ec8-1264-7f0c-d16deb144dd9@cs.ox.ac.uk>
Date: Thu, 24 Oct 2019 20:05:03 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Oxford-Username: exet4027
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/wqzUsgm7gyOn41kLEzoWUtKmDy4>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 19:05:08 -0000

Hi Brendan,

On 24/10/2019 18:59, Brendan McMillion wrote:
> I want to state my position again very clearly:
> 
> Assume that a single user was compromised and their state was given to
> an adversary. Assume that the compromise has been *immediately healed*
> by an Update/Remove message affecting the compromised user, meaning that
> the adversary is no longer able to read messages. How long is it until
> we know that messages sent after the compromise was healed are again
> forward-secure, meaning that no future compromises will expose them?
> 
>   * *TreeKEM:* You need to wait until everyone sends an Update.
>   * *RTreeKEM:* You need to wait until everyone processes the
>     Update/Remove. How do you know everyone has processed the
>     Update/Remove, and aren't offline with old key material waiting to
>     be compromised? By waiting until everyone sends an Update.
> 
> Therefore RTreeKEM offers no material improvement over TreeKEM.
> RTreeKEM's improvement over TreeKEM is unmeasurable, unenforceable.

Your perspective seems quite warped. You've selected an arbitrary
scenario and criteria, decided there's no difference between the schemes
in that circumstance and concluded there's no difference between the two
under any circumstances. Spot the problem?

Typically, we analyze security protocols from the perspective of an
adversary who is trying to achieve some goal (learn a secret, forge a
message, etc). It is the adversary we wish to frustrate. RTreeKEM is
significantly better than TreeKEM in this light. There are many
situations (elucidated in earlier examples and the accompanying paper)
in which RTreeKEM resists attacks that TreeKEM does not.

The adversary is absolutely aware of the material improvement of
RTreeKEM over TreeKEM and can measure it quite easily. This difference
has numerous real world impacts, including the scenario I described in
an earlier email. The position that RTreeKEM doesn't offer security
benefits over TreeKEM is factually incorrect.

There are reasonable criticisms of RTreeKEM. It's more complex, it might
require different primitives, it increases message sizes etc. However,
"no material improvement in security" isn't a defendable position.

Regards,
Dennis



From nobody Thu Oct 24 13:03:24 2019
Return-Path: <brendan@cloudflare.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 76FD7120047 for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:03:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bWd9ika94zB6 for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:03:19 -0700 (PDT)
Received: from mail-qt1-x82f.google.com (mail-qt1-x82f.google.com [IPv6:2607:f8b0:4864:20::82f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6E0A120020 for <mls@ietf.org>; Thu, 24 Oct 2019 13:03:18 -0700 (PDT)
Received: by mail-qt1-x82f.google.com with SMTP id w14so39721604qto.9 for <mls@ietf.org>; Thu, 24 Oct 2019 13:03:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=w0uKvo7oxd2KuWoh5e2GcSQ/uTJme1p+eqRKb94OBRQ=; b=Ru9NfknTN1y0cqFD0su7izq7PwcpxDj90kBS5Dhwwm+FMSxaa1UQ/q+b2AeuZcrN8h T7IU/xnV5TFw6RlCoTHq3gpf+z06Fi9EqZQO+1eEsH9WD9c1wIubhIMz2bCBMfJLupxF TNlxUz6zjuZo5O+xdwa2nTkP7RmIBA4rJiCa8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=w0uKvo7oxd2KuWoh5e2GcSQ/uTJme1p+eqRKb94OBRQ=; b=amYkvZSbQSLCYToBXfShs/+5HlzU4i797imFvFfX8LnM1E3uZV3ySRz4N2UBPdBRMT IUxM9cL+bOERmvYoDQmz1DpDMMCy42B+Qkuy7HmtDwxNDUgz/Co7ec7x7wafSAAv5KSL fIWW5DusAkkbZtwofP/WzK4KTFz/IJ8V18HTiz+yOnrIvZveWWXkh1dJzQ8/gQl8TDEr xVLLgTOoZtTz8yW5PCz3/ySUQK3OVxOYux/C1l2v31qhzqjEZv1SN6hZLBzEyMuBgG9w koJYQRZD8mBD4ENzOAwzDBXEblcO0BM+YH281ENa7KSEDMqDPXSh85HksAqs0F2paITV /lng==
X-Gm-Message-State: APjAAAVUA1OuNDPX7r4q/rDDsuB1x9/VPmC9akdmfkEARUTT5IzAT6PR 9vyAX5pb4WxyPMu3z/5oZ9N1d+Qg/Y92LGlTlOipTT0G5T4=
X-Google-Smtp-Source: APXvYqzJzOzoOBdqC16EHKoMMlrXE/U2LogABFaE2ch7hs8i8FPze2iC7NDwYQMUhiRiezqOJtjqJjfzmFNM7EBTyQc=
X-Received: by 2002:ac8:6744:: with SMTP id n4mr6206954qtp.26.1571947397664; Thu, 24 Oct 2019 13:03:17 -0700 (PDT)
MIME-Version: 1.0
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <4BEAE096-9597-4619-ADD4-CE13E899481B@inria.fr> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com> <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de> <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com> <1e5c700d-6ec8-1264-7f0c-d16deb144dd9@cs.ox.ac.uk>
In-Reply-To: <1e5c700d-6ec8-1264-7f0c-d16deb144dd9@cs.ox.ac.uk>
From: Brendan McMillion <brendan@cloudflare.com>
Date: Thu, 24 Oct 2019 13:03:05 -0700
Message-ID: <CABP-pSSe8+RVR2txPKqcxGzyfYKURaPWFAG2g9E0KrYGWZ=UXA@mail.gmail.com>
To: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
Cc: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>,  Konrad Kohbrok <konrad.kohbrok@datashrine.de>, Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000003e87b30595ad8666"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/zzSpdsaBDmiBQVVzQFI5X61mNjk>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 20:03:23 -0000

--0000000000003e87b30595ad8666
Content-Type: text/plain; charset="UTF-8"

I feel like I'm the only one with a realistic perspective, while everyone
else is focusing on the Platonic benefits of RTreeKEM.

Does it use less bandwidth? No.
Does it guarantee faster PCS? No.
Does it guarantee faster FS? No.
Is it easy to implement in JavaScript? No.


On Thu, Oct 24, 2019, 12:05 PM Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
wrote:

> Hi Brendan,
>
> On 24/10/2019 18:59, Brendan McMillion wrote:
> > I want to state my position again very clearly:
> >
> > Assume that a single user was compromised and their state was given to
> > an adversary. Assume that the compromise has been *immediately healed*
> > by an Update/Remove message affecting the compromised user, meaning that
> > the adversary is no longer able to read messages. How long is it until
> > we know that messages sent after the compromise was healed are again
> > forward-secure, meaning that no future compromises will expose them?
> >
> >   * *TreeKEM:* You need to wait until everyone sends an Update.
> >   * *RTreeKEM:* You need to wait until everyone processes the
> >     Update/Remove. How do you know everyone has processed the
> >     Update/Remove, and aren't offline with old key material waiting to
> >     be compromised? By waiting until everyone sends an Update.
> >
> > Therefore RTreeKEM offers no material improvement over TreeKEM.
> > RTreeKEM's improvement over TreeKEM is unmeasurable, unenforceable.
>
> Your perspective seems quite warped. You've selected an arbitrary
> scenario and criteria, decided there's no difference between the schemes
> in that circumstance and concluded there's no difference between the two
> under any circumstances. Spot the problem?
>
> Typically, we analyze security protocols from the perspective of an
> adversary who is trying to achieve some goal (learn a secret, forge a
> message, etc). It is the adversary we wish to frustrate. RTreeKEM is
> significantly better than TreeKEM in this light. There are many
> situations (elucidated in earlier examples and the accompanying paper)
> in which RTreeKEM resists attacks that TreeKEM does not.
>
> The adversary is absolutely aware of the material improvement of
> RTreeKEM over TreeKEM and can measure it quite easily. This difference
> has numerous real world impacts, including the scenario I described in
> an earlier email. The position that RTreeKEM doesn't offer security
> benefits over TreeKEM is factually incorrect.
>
> There are reasonable criticisms of RTreeKEM. It's more complex, it might
> require different primitives, it increases message sizes etc. However,
> "no material improvement in security" isn't a defendable position.
>
> Regards,
> Dennis
>
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--0000000000003e87b30595ad8666
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div>I feel like I&#39;m the only one with a realistic pe=
rspective, while everyone else is focusing on the Platonic benefits of RTre=
eKEM.<div dir=3D"auto"><br></div><div dir=3D"auto">Does it use less bandwid=
th? No.</div><div dir=3D"auto">Does it guarantee faster PCS? No.</div><div =
dir=3D"auto">Does it guarantee faster FS? No.</div><div dir=3D"auto">Is it =
easy to implement in JavaScript? No.</div><br><br><div class=3D"gmail_quote=
"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Oct 24, 2019, 12:05 PM Denn=
is Jackson &lt;<a href=3D"mailto:dennis.jackson@cs.ox.ac.uk">dennis.jackson=
@cs.ox.ac.uk</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Bren=
dan,<br>
<br>
On 24/10/2019 18:59, Brendan McMillion wrote:<br>
&gt; I want to state my position again very clearly:<br>
&gt; <br>
&gt; Assume that a single user was compromised and their state was given to=
<br>
&gt; an adversary. Assume that the compromise has been *immediately healed*=
<br>
&gt; by an Update/Remove message affecting the compromised user, meaning th=
at<br>
&gt; the adversary is no longer able to read messages. How long is it until=
<br>
&gt; we know that messages sent after the compromise was healed are again<b=
r>
&gt; forward-secure, meaning that no future compromises will expose them?<b=
r>
&gt; <br>
&gt;=C2=A0 =C2=A0* *TreeKEM:* You need to wait until everyone sends an Upda=
te.<br>
&gt;=C2=A0 =C2=A0* *RTreeKEM:* You need to wait until everyone processes th=
e<br>
&gt;=C2=A0 =C2=A0 =C2=A0Update/Remove. How do you know everyone has process=
ed the<br>
&gt;=C2=A0 =C2=A0 =C2=A0Update/Remove, and aren&#39;t offline with old key =
material waiting to<br>
&gt;=C2=A0 =C2=A0 =C2=A0be compromised? By waiting until everyone sends an =
Update.<br>
&gt; <br>
&gt; Therefore RTreeKEM offers no material improvement over TreeKEM.<br>
&gt; RTreeKEM&#39;s improvement over TreeKEM is unmeasurable, unenforceable=
.<br>
<br>
Your perspective seems quite warped. You&#39;ve selected an arbitrary<br>
scenario and criteria, decided there&#39;s no difference between the scheme=
s<br>
in that circumstance and concluded there&#39;s no difference between the tw=
o<br>
under any circumstances. Spot the problem?<br>
<br>
Typically, we analyze security protocols from the perspective of an<br>
adversary who is trying to achieve some goal (learn a secret, forge a<br>
message, etc). It is the adversary we wish to frustrate. RTreeKEM is<br>
significantly better than TreeKEM in this light. There are many<br>
situations (elucidated in earlier examples and the accompanying paper)<br>
in which RTreeKEM resists attacks that TreeKEM does not.<br>
<br>
The adversary is absolutely aware of the material improvement of<br>
RTreeKEM over TreeKEM and can measure it quite easily. This difference<br>
has numerous real world impacts, including the scenario I described in<br>
an earlier email. The position that RTreeKEM doesn&#39;t offer security<br>
benefits over TreeKEM is factually incorrect.<br>
<br>
There are reasonable criticisms of RTreeKEM. It&#39;s more complex, it migh=
t<br>
require different primitives, it increases message sizes etc. However,<br>
&quot;no material improvement in security&quot; isn&#39;t a defendable posi=
tion.<br>
<br>
Regards,<br>
Dennis<br>
<br>
<br>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" rel=3D"noreferrer">MLS@ie=
tf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br=
>
</blockquote></div></div></div>

--0000000000003e87b30595ad8666--


From nobody Thu Oct 24 13:08:17 2019
Return-Path: <dennis.jackson@cs.ox.ac.uk>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46C82120090 for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:08:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level: 
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hZWtm5Etzl4h for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:08:12 -0700 (PDT)
Received: from relay14.mail.ox.ac.uk (relay14.mail.ox.ac.uk [163.1.2.162]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5CF5120020 for <mls@ietf.org>; Thu, 24 Oct 2019 13:08:12 -0700 (PDT)
Received: from smtp4.mail.ox.ac.uk ([129.67.1.207]) by relay14.mail.ox.ac.uk with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNjP1-000ClX-jV; Thu, 24 Oct 2019 21:08:11 +0100
Received: from 61.ip-51-38-113.eu ([51.38.113.61] helo=[192.168.2.2]) by smtp4.mail.ox.ac.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <dennis.jackson@cs.ox.ac.uk>) id 1iNjP0-000Ajn-Et; Thu, 24 Oct 2019 21:08:10 +0100
From: Dennis Jackson <dennis.jackson@cs.ox.ac.uk>
To: Brendan McMillion <brendan@cloudflare.com>
Cc: Brendan McMillion <brendan=40cloudflare.com@dmarc.ietf.org>, Konrad Kohbrok <konrad.kohbrok@datashrine.de>, Messaging Layer Security WG <mls@ietf.org>
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com> <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de> <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com> <1e5c700d-6ec8-1264-7f0c-d16deb144dd9@cs.ox.ac.uk> <CABP-pSSe8+RVR2txPKqcxGzyfYKURaPWFAG2g9E0KrYGWZ=UXA@mail.gmail.com>
Message-ID: <96aed028-564e-0f5b-72b4-fd68654653ca@cs.ox.ac.uk>
Date: Thu, 24 Oct 2019 21:08:09 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CABP-pSSe8+RVR2txPKqcxGzyfYKURaPWFAG2g9E0KrYGWZ=UXA@mail.gmail.com>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Oxford-Username: exet4027
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/Ypz0An6WUfhqXO_XPtrBzKq8gtY>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 20:08:15 -0000

>> Does it guarantee faster FS? *Yes*

Fixed that for you :)
On 24/10/2019 21:03, Brendan McMillion wrote:
> I feel like I'm the only one with a realistic perspective, while
> everyone else is focusing on the Platonic benefits of RTreeKEM.
>
> Does it use less bandwidth? No.
> Does it guarantee faster PCS? No.
> Does it guarantee faster FS? No.
> Is it easy to implement in JavaScript? No.
>
>
> On Thu, Oct 24, 2019, 12:05 PM Dennis Jackson
> <dennis.jackson@cs.ox.ac.uk <mailto:dennis.jackson@cs.ox.ac.uk>> wrote:
>
>     Hi Brendan,
>
>     On 24/10/2019 18:59, Brendan McMillion wrote:
>     > I want to state my position again very clearly:
>     >
>     > Assume that a single user was compromised and their state was given to
>     > an adversary. Assume that the compromise has been *immediately healed*
>     > by an Update/Remove message affecting the compromised user,
>     meaning that
>     > the adversary is no longer able to read messages. How long is it until
>     > we know that messages sent after the compromise was healed are again
>     > forward-secure, meaning that no future compromises will expose them?
>     >
>     >   * *TreeKEM:* You need to wait until everyone sends an Update.
>     >   * *RTreeKEM:* You need to wait until everyone processes the
>     >     Update/Remove. How do you know everyone has processed the
>     >     Update/Remove, and aren't offline with old key material waiting to
>     >     be compromised? By waiting until everyone sends an Update.
>     >
>     > Therefore RTreeKEM offers no material improvement over TreeKEM.
>     > RTreeKEM's improvement over TreeKEM is unmeasurable, unenforceable.
>
>     Your perspective seems quite warped. You've selected an arbitrary
>     scenario and criteria, decided there's no difference between the schemes
>     in that circumstance and concluded there's no difference between the two
>     under any circumstances. Spot the problem?
>
>     Typically, we analyze security protocols from the perspective of an
>     adversary who is trying to achieve some goal (learn a secret, forge a
>     message, etc). It is the adversary we wish to frustrate. RTreeKEM is
>     significantly better than TreeKEM in this light. There are many
>     situations (elucidated in earlier examples and the accompanying paper)
>     in which RTreeKEM resists attacks that TreeKEM does not.
>
>     The adversary is absolutely aware of the material improvement of
>     RTreeKEM over TreeKEM and can measure it quite easily. This difference
>     has numerous real world impacts, including the scenario I described in
>     an earlier email. The position that RTreeKEM doesn't offer security
>     benefits over TreeKEM is factually incorrect.
>
>     There are reasonable criticisms of RTreeKEM. It's more complex, it might
>     require different primitives, it increases message sizes etc. However,
>     "no material improvement in security" isn't a defendable position.
>
>     Regards,
>     Dennis
>
>
>     _______________________________________________
>     MLS mailing list
>     MLS@ietf.org <mailto:MLS@ietf.org>
>     https://www.ietf.org/mailman/listinfo/mls
>


From nobody Thu Oct 24 13:19:36 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7AAE612008C for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:19:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2KXypV0IOQ1d for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 13:19:32 -0700 (PDT)
Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C873120071 for <mls@ietf.org>; Thu, 24 Oct 2019 13:19:32 -0700 (PDT)
Received: by mail-wr1-x42f.google.com with SMTP id p4so27481072wrm.8 for <mls@ietf.org>; Thu, 24 Oct 2019 13:19:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=vfKr3hXbRRcg3FrTh60FGQwPZBbwvyAatCM3/bNEw3M=; b=dpyRIiA2LKlBhAz5HOt/NIda4WgjRNKzCg6sLg0RfMaytn+j2ejedEYA3jusaIkC58 gCebBxUWwH5HGxFx/FHv1B1CSCWykcF1p2rDRMx8dI/+21JnOiash+mrT3Dggsep52nQ CQpbcZTMnKfYU4wTU6LACAe6V0ktxhXpLXltnHZSJxX9JdPqhU2BDvtoXRnqhI/zk+TC N4MCerPdVQgDkh4tm2XKnhoYYn9ghO0r01kS9M2LuG9gf1osdLLh0UwI41YSdOzuYAyB 5w6bTpgLHu5a2DhV1NKpyvu17lqenuUz1a/KXf+gELKtB8Hy3hTqqwFDCLCIaEP5W63y s9aA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=vfKr3hXbRRcg3FrTh60FGQwPZBbwvyAatCM3/bNEw3M=; b=URI/v/+AJ+slkhWCPwsgDQkNECkT9IiPCH9jbr0qdei/eXr+8Yt2+mM7qPVw5icxZb J5/G8XHinYruTNu7DD7+od0bJCiTQLXwfYFI4kVoF0GUlLFEAU8dAoT3uzCMSVAngvD8 MKeXriImGjbuBVx0K4sLV8la80Oz7lejgCDnpjOXfOB7sT/tWlGfJTX4Y9D09BsE5qj8 GJ0gItccT5YKjCO/8lyU9rlFz/MqYwi+5fgQ5GtOCutuliV0QReBf6eUcVcx9PhcvpZI SS2xaPORMaP6FK+/rJlSmNfCNYV990e7eJq56LGIeujqbQ6hoN0mFmUTGYH/XjTz/0i/ pf1Q==
X-Gm-Message-State: APjAAAVVFiTSahs5mSPzAvuguN/xTzvikzVtkVuqr8VMo4/CUzULpXuC 8SzoPVBaByH49Eb8fs5XFZ+8hj0gSFI=
X-Google-Smtp-Source: APXvYqx/360/SRJr487n/TNc9fUd+6xIvukCIToyAI5E9StjgFVlSyprXa4bGjnQShTSbdMTEU5vpg==
X-Received: by 2002:a5d:4112:: with SMTP id l18mr5506454wrp.123.1571948369761;  Thu, 24 Oct 2019 13:19:29 -0700 (PDT)
Received: from [192.168.1.137] (84-114-27-5.cable.dynamic.surfer.at. [84.114.27.5]) by smtp.gmail.com with ESMTPSA id v10sm19890867wrm.26.2019.10.24.13.19.28 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 24 Oct 2019 13:19:29 -0700 (PDT)
To: Raphael Robert <raphael@wire.com>, Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Cc: Richard Barnes <rlb@ipv.sx>, Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Messaging Layer Security WG <mls@ietf.org>, Yevgeniy Dodis <dodis@cs.nyu.edu>
References: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com> <3B5BE109-6C78-474F-A0E5-138DE6931CF6@inria.fr> <6E36D92F-E700-4B57-9784-CFD366ECA912@wire.com>
From: Joel Alwen <jalwen@wickr.com>
Openpgp: preference=signencrypt
Autocrypt: addr=jalwen@wickr.com; keydata= mQENBFyIZvABCAC65JupY1w7gzhhNo41ftIk09n7Lid9p31jDR8Jefv9R5sWL+HZFGDeABAY 1J1JvV6vOaMsfdy9iUFfGS1GhMJ3+mh799SIsB3JSfPq/eq6Jut57D2yPtILmc7ZbuJyBHg0 xuYfKCQQAYikW+v2LJQU1Y+BUDbVldpzxSc8Z3PPSfunWdzhY6qAAhyCv+Y8EzJlQivMwD5B f6737krf8SoBsjsqCHQrRo/r+BSj5Wtd5/K3FkmWLOUAFoYK23+cpoFntGJKZfss27gDPhyS gX9ibXcBGQqBEF4qDPEzEHK8iQmXTxLul5Y7lQ6ADf69xH15WM4GmRBeCvR3Uanxcr2/ABEB AAG0HUpvZWwgQWx3ZW4gPGphbHdlbkB3aWNrci5jb20+iQFUBBMBCAA+FiEEYFNg9IH2SV6e 03O3FR5tDZv8eygFAlyIZvICGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ FR5tDZv8eyjSywgApQNIRcL4IKTJ0I4XwcQRhICu1Bht3c2fUnG2YziJXjGf6DZ49uKKtuIu fk8mNS+vKRLoLZ7+u+Pv/Yjmk8jtrr6Saz1vnfsle3GgmXG5JaKOM5cOfeo5JnlNUP3QonR7 LMZwY1qVKg2mzNmwi0jG1zIGgQ5fiAwqe+YTNFli5bc/H1O9LcSmbrLV9OyucARq11DIiAvU fDknZ17OahQls+9mgfAXH5vZjzo296tYvzkOJQ2A6GPxdMHIXGbJM/vjuMe2QJl6C0zaqOtm JvFcx/HpNhmugYI9OsNAd7846HASDp8BKyfY5FYP7bn0/JBuCpg18Aykru6xyFjG3gv0L7kB DQRciGbxAQgA0Qx9LlxvJ0LGZlZRVyV8kPIxg8pNMmxJwJJ+JnTciW0LpfigfdAvGVf6PU0x 3V6SJKtz8D61c8KLyztxwPGRgJX2TRK3zvTlT5mqqnGYMAANttCF1+8DNpiYOMg3ibPRby46 4JPhMgWgvCJ1vHGu9cghjn1ttWIwBuKBXMc8HgACKYWsYZJiYtFEsnOdsD6aPWCg6NiImoc7 vRwNMKNNtDPxY95Yj4CRiLPVrZje3LyJlA9S+y2/p3w69R4AVLSRzAwDlupjXYs03QdNjGjP 2IR2u8RhstDgqW8+Bk3p7wjJ1kHTHgyox81/aHbnIRGKksPGPMPT3bvbpxevfqZ7ywARAQAB iQE8BBgBCAAmFiEEYFNg9IH2SV6e03O3FR5tDZv8eygFAlyIZvECGwwFCQHhM4AACgkQFR5t DZv8eygbLQf+OHSG6K9qiPdYxe61IR2kZdyogc2ArEGrl6AmcNzySXC8wlnreZo3FjfkD6xV CQWwWDxI7B0JPM86IcfCfn45ADeI8rwm6yYIs00B4ag9Mmo0GQ4kQd2aTy60/QaE2ZSrnEtt 0fuz1G8DGnhPnOnMyCnCnkSNuTNG20OlI0cn5EJSxBS4fXVeBMBaV91DEmvLU6DjL+fOBQPq CXIbFY7XffOmC4VxtAGhTadJ8WmUD8ZezXNs8c40Btpukr7j4piUshITfazPGEMXzTUTkimf fAhNX1QQBsfP9kjfjxBn6jDl+lDJY34mANWwEJ8BKjgr09P0sOz4zjjFL62GcFczQA==
Message-ID: <3b841c7a-07c6-d415-825f-fc930831a78b@wickr.com>
Date: Thu, 24 Oct 2019 22:19:29 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <6E36D92F-E700-4B57-9784-CFD366ECA912@wire.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/FX3bgumcofIjGG_NbNfLhy83vHU>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Oct 2019 20:19:34 -0000

On 24/10/2019 12:09, Raphael Robert wrote:
> This means that vendors/implementors have to implement something at a new layer that is somewhere in between the crypto library and the protocol layer.

Yeah, thats a good point. To me, proposing a reasonable way to build UPKE on top of, say, libsodium is one of the main
things I want to figure out right now (along with better understanding of how Mult() for X25519 can fail). Basically,
this means implementing Mult() from, say, libsodium as going from Mult() -> multiplicative UPKE should be very
straightforward using what I'd expect even the most basic interface for any X25519 implementation to provide. I guess
the challenge here is going to be that both clamp() and the composite order are neither exported nor directly accessible
in libsodium?

In any case, if Mult() needs implementing from scratch then some of the risks I see here are:
- Side-Channels: Mult() operates on secret keys so really it should be implemented with side-channel free code (e.g.
constant time, memory access, etc.). We could mitigate this by proposing a specific implementation similar to whats done
in RFC 7748.
- Memory management: Secret keys being exported out of an X25519 library need to be handled safely in memory (e.g. 0-ed
out before free, don't swap to disk, etc.) Libsodium does provide some memory-management functions for this very purpose.
- Good Entropy: The re-randomizer d' needs to be sampled uniformly and independently. (Again I think most crypto
libraries provide functions to do this.)

Probably a naïve attempt at such a list of risks & mitigations. But making this stuff explicit seems useful for later on
if we put this into the MLS RFCs (not to mention for a separate addendum RFC for 7748 describing the key-rerandomization
technique on its own). So any input on the expected risks (and possible mitigations) would be very appreciated!


On 24/10/2019 12:09, Raphael Robert wrote:
> Finally I also understand that because of the clamping the actual security level of DH operations with curve 25519 is
> not as clearly understood as it is the case with X25519 now.

Not sure I follow what you mean here. One the one hand the UPKE construction is built on top of the X25519 (or X448)
group not just Curve25519. In particular, Mult() uses the same point representation, clamping of scalars and scalar
multiplication as specified in RFC 7748.

On the other hand, if anything, I'd have thought questions about exact bit security are the other way round. It's X25519
that does the clamping so that's where the question about exact bit security would arise no? Clamping isn't inherent to
Curve25519 though; rather its just one way to do scalar multiplication mapping into a prime order sub-group based on the
composite order Curve25519 group. But, as shown by Ristretto, other methods are possible that completely avoid clamping
(and also happen to be both additively and multiplicatively homomorphic). In particular, I believe CDH, DDH and all the
other usual crypto hardness assumptions are equivalent for Curve25519's prime order subgroup and for the Ristretto
group. Not sure thats true for X25519 though.

In any case, I'm no expert on this stuff so feel free to correct me if I'm wrong. :-)

- Joël


From nobody Thu Oct 24 23:02:53 2019
Return-Path: <konrad.kohbrok@datashrine.de>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4F9212006F for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 23:02:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level: 
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V5o_PUzK4jJW for <mls@ietfa.amsl.com>; Thu, 24 Oct 2019 23:02:49 -0700 (PDT)
Received: from mx2a.mailbox.org (mx2a.mailbox.org [IPv6:2001:67c:2050:104:0:2:25:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A939412003F for <mls@ietf.org>; Thu, 24 Oct 2019 23:02:48 -0700 (PDT)
Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:105:465:1:1:0]) (using TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)) (No client certificate requested) by mx2a.mailbox.org (Postfix) with ESMTPS id 668C5A1BB7 for <mls@ietf.org>; Fri, 25 Oct 2019 08:02:44 +0200 (CEST)
X-Virus-Scanned: amavisd-new at heinlein-support.de
Received: from smtp1.mailbox.org ([80.241.60.240]) by spamfilter03.heinlein-hosting.de (spamfilter03.heinlein-hosting.de [80.241.56.117]) (amavisd-new, port 10030) with ESMTP id stoGOpaRVeZw for <mls@ietf.org>; Fri, 25 Oct 2019 08:02:38 +0200 (CEST)
To: mls@ietf.org
References: <5b1d9cb1-509a-da7d-1361-188dfe0f21d6@wickr.com> <CAMvzKsgMvLP5mmk8fOoTopKhFM6+EQzognv4Eq_FfMHSs9qwiA@mail.gmail.com> <5673C061-B15D-4DD2-A90C-4F179E82C31A@inria.fr> <133ba15a-037f-6a3b-182c-836b14ba233b@wickr.com> <B8059BBC-8368-4C6B-B64C-3B98153F9A4E@cloudflare.com> <a1033442-7394-bdb7-5be3-24b92d75290d@wickr.com> <CABP-pSQ5fQ8ohsnB2XJDLgXEh=PcHmhrrPY-76Pr9evx0g1_QQ@mail.gmail.com> <924d06c6-aa9e-2a8f-ba2e-abaae1b152e2@wickr.com> <CABP-pSSwjq33c7Rg3BWHEgAJH2hkGzvOczjuXtv7GNwHbtFpYw@mail.gmail.com> <0c91edbb-2426-c175-2d35-2ca3fed76902@cs.ox.ac.uk> <CABP-pSTiR7aYhDKT3P5jqjBHvFQ7a8C7SZUDLtvZqc7gSkEBcg@mail.gmail.com> <5a2a13e8-30d5-a3be-a49c-c4495f45e498@cs.ox.ac.uk> <CABP-pSQGQEc39hJ-WDp7rJcJGzOrW-03NY5gyVhm_WywFRL__g@mail.gmail.com> <360fb300-6171-3def-4ca7-8d56b5f8bef0@datashrine.de> <CABP-pSRqDfnkzTtXuo2_inpwcZQWSuU2BZdmro0wPLSOhwGu3g@mail.gmail.com> <1e5c700d-6ec8-1264-7f0c-d16deb144dd9@cs.ox.ac.uk> <CABP-pSSe8+RVR2txPKqcxGzyfYKURaPWFAG2g9E0KrYGWZ=UXA@mail.gmail.com>
From: Konrad Kohbrok <konrad.kohbrok@datashrine.de>
Message-ID: <be5e5f84-fd39-9ce1-172b-836bb21b59c1@datashrine.de>
Date: Fri, 25 Oct 2019 08:02:37 +0200
MIME-Version: 1.0
In-Reply-To: <CABP-pSSe8+RVR2txPKqcxGzyfYKURaPWFAG2g9E0KrYGWZ=UXA@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/HghxC4odCQc36DrFzex_eRuvB0k>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Oct 2019 06:02:52 -0000

Hi Brendan,

I'm sorry you feel frustrated with this discussion and I can see why. I agree
with you that we should be very careful with adding new stuff to MLS that
increases costs (be it bandwidth, complexity or otherwise). I also think it's
good to keep an eye on the measurability and enforcability of security
guarantees, which is something I hadn't thought about too much until now.
Although I have to admit that I can't follow your argument with those points
(who is measuring?).

I think one reason we're talking past each other is that to a certain degree I
(and probably a few of the other cryptographers here) am guilty of thinking very
much along the lines of the formal definitions of things like PCS and FS, while
losing sight of the probabilities for certain scenarios in the real world. Under
the formal definition of FS it shouldn't matter if A was compromised in the
past. B should get FS guarantees independent of that.

With a weaker definition of FS there might not be a difference between RTreeKEM
and TreeKEM. However, as Dennis said, it's then easy to lose track of the
scenarios where we're actually secure and the security model becomes complicated
very quickly (especially in a protocol like MLS with a lot of keys flying around
in a lot of different places). I've not been in the community for that long, but
I think sticking to the formal definitions and looking out for nuances and has
proven to be a good idea in the past.

Just as an afterthought: I think the attack would also work in a more likely
real-world scenario, where the adversary is part of the group and subsequently
gets kicked out (maybe a disgruntled employee). Then they have a past init
secret and the attack still works and everyone needs to issue an update to gain
FS. That sounds more likely in a real-world scenario.

Cheers,
Konrad

On 24.10.19 23:03, Brendan McMillion wrote:
> I feel like I'm the only one with a realistic perspective, while everyone else
> is focusing on the Platonic benefits of RTreeKEM.
> 
> Does it use less bandwidth? No.
> Does it guarantee faster PCS? No.
> Does it guarantee faster FS? No.
> Is it easy to implement in JavaScript? No.
> 
> 
> On Thu, Oct 24, 2019, 12:05 PM Dennis Jackson <dennis.jackson@cs.ox.ac.uk
> <mailto:dennis.jackson@cs.ox.ac.uk>> wrote:
> 
>     Hi Brendan,
> 
>     On 24/10/2019 18:59, Brendan McMillion wrote:
>     > I want to state my position again very clearly:
>     >
>     > Assume that a single user was compromised and their state was given to
>     > an adversary. Assume that the compromise has been *immediately healed*
>     > by an Update/Remove message affecting the compromised user, meaning that
>     > the adversary is no longer able to read messages. How long is it until
>     > we know that messages sent after the compromise was healed are again
>     > forward-secure, meaning that no future compromises will expose them?
>     >
>     >   * *TreeKEM:* You need to wait until everyone sends an Update.
>     >   * *RTreeKEM:* You need to wait until everyone processes the
>     >     Update/Remove. How do you know everyone has processed the
>     >     Update/Remove, and aren't offline with old key material waiting to
>     >     be compromised? By waiting until everyone sends an Update.
>     >
>     > Therefore RTreeKEM offers no material improvement over TreeKEM.
>     > RTreeKEM's improvement over TreeKEM is unmeasurable, unenforceable..
> 
>     Your perspective seems quite warped. You've selected an arbitrary
>     scenario and criteria, decided there's no difference between the schemes
>     in that circumstance and concluded there's no difference between the two
>     under any circumstances. Spot the problem?
> 
>     Typically, we analyze security protocols from the perspective of an
>     adversary who is trying to achieve some goal (learn a secret, forge a
>     message, etc). It is the adversary we wish to frustrate. RTreeKEM is
>     significantly better than TreeKEM in this light. There are many
>     situations (elucidated in earlier examples and the accompanying paper)
>     in which RTreeKEM resists attacks that TreeKEM does not.
> 
>     The adversary is absolutely aware of the material improvement of
>     RTreeKEM over TreeKEM and can measure it quite easily. This difference
>     has numerous real world impacts, including the scenario I described in
>     an earlier email. The position that RTreeKEM doesn't offer security
>     benefits over TreeKEM is factually incorrect.
> 
>     There are reasonable criticisms of RTreeKEM. It's more complex, it might
>     require different primitives, it increases message sizes etc. However,
>     "no material improvement in security" isn't a defendable position.
> 
>     Regards,
>     Dennis
> 
> 
>     _______________________________________________
>     MLS mailing list
>     MLS@ietf.org <mailto:MLS@ietf.org>
>     https://www.ietf.org/mailman/listinfo/mls
> 
> 
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
> 


From nobody Fri Oct 25 14:15:11 2019
Return-Path: <agenda@ietf.org>
X-Original-To: mls@ietf.org
Delivered-To: mls@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 49196120908; Fri, 25 Oct 2019 14:12:08 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "\"IETF Secretariat\"" <agenda@ietf.org>
To: <mls-chairs@ietf.org>, <sean+ietf@sn3rd.com>
Cc: mls@ietf.org, kaduk@mit.edu
X-Test-IDTracker: no
X-IETF-IDTracker: 6.108.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <157203792829.2724.10059292088312201482.idtracker@ietfa.amsl.com>
Date: Fri, 25 Oct 2019 14:12:08 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/UrXu9RC6-v0Rr5Ba7U3EoEW7IwQ>
Subject: [MLS] mls - Requested session has been scheduled for IETF 106
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Oct 2019 21:12:14 -0000

Dear Sean Turner,

The session(s) that you have requested have been scheduled.
Below is the scheduled session information followed by
the original request. 


    mls Session 1 (2:00 requested)
    Friday, 22 November 2019, Morning Session I 1000-1200
    Room Name: Canning size: 250
    ---------------------------------------------


iCalendar: https://datatracker.ietf.org/meeting/106/sessions/mls.ics

Request Information:


---------------------------------------------------------
Working Group Name: Messaging Layer Security
Area Name: Security Area
Session Requester: Sean Turner

Number of Sessions: 1
Length of Session(s):  2 Hours
Number of Attendees: 125
Conflicts to Avoid: 
 Chair Conflict: cfrg iasa2 httpbis quic saag secdispatch tls pearg

 Key Participant Conflict: acme artarea dispatch perc


People who must be present:
  Eric Rescorla
  Sean Turner
  Richard Barnes
  Benjamin Kaduk
  Nick Sullivan

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Fri Oct 25 14:44:14 2019
Return-Path: <rlb@ipv.sx>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC97812008F for <mls@ietfa.amsl.com>; Fri, 25 Oct 2019 14:44:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level: 
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S4jq_WfrFbfa for <mls@ietfa.amsl.com>; Fri, 25 Oct 2019 14:44:09 -0700 (PDT)
Received: from mail-oi1-x22e.google.com (mail-oi1-x22e.google.com [IPv6:2607:f8b0:4864:20::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B16FE12004A for <mls@ietf.org>; Fri, 25 Oct 2019 14:44:09 -0700 (PDT)
Received: by mail-oi1-x22e.google.com with SMTP id a15so2590339oic.0 for <mls@ietf.org>; Fri, 25 Oct 2019 14:44:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=snVuOSeiRtrgtAo+pS3BDk3VKlmImB3uuU+KFU22pwk=; b=zL3duBJllMtX3YtHWna2lkqeQkVlt4o+jSjqn4+ypnvX6YJ/2jL9P9DIqcuT6v/wng YI5ttLMmv6Ky/Cz3eHwsIpV9eZ5oQaxMWuF6UmP7DdzRAvD3sYNxOPFLMpnjoLlHVajj kzMXQ0azPQoGvnxc5Ae6IU8cH1lk9qjLgcIFwFNoog2qAW6l5NGttOsco6ZaHFOv7S77 Pc9zg4ssJjM0QaFAZy3OvzohYxWlZsAZ/5BBtGr9pthiGZMVuOygQYgPxs6xMhU2gaJl fbmSm7C9oJKJjYv2PEYNk5p61+8fw6cAjMKGqDvZQhKIU7MrAhURXq/BH+HE8216cyDe GjNA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=snVuOSeiRtrgtAo+pS3BDk3VKlmImB3uuU+KFU22pwk=; b=qoxayDOa5IejidkBZcXoB2Gaqitoz9Fu5ptenNfoTFcNPC4/iTtIVRtbhl2p7Dkb8E Sjg1X00wLOkiIULDczv6vjM0oUgyfjGxeoNFGPrD/gXabaQrj+jvMz5CtKE5iWZughf/ P4zdxBMwyXVrnpyV58N6VI/jeDjlhplDlWI5WC7FQ9cKerePrIptdwSwdLrreSPXpFfC U9wJvOEOKlrrzLnxWZWuJQrMRxSaa07vdkzVuxU8VJZITcX9agnHrXI9N5QnNvx1PU1+ AOwuDe3OCjJeUFJNUJOCI5tkixR1+M6elLjEz8zydlXPBGstwOUmCCUQ0VGzGe43B5A0 YV8Q==
X-Gm-Message-State: APjAAAWkWLq8dtXOFY5S6EfIDRpQ4CrNtJaKbFf9fp/ixHn8lbX7JUCZ Wrx+mLKxofHKpukAMyVr937Q+cxLGoDF/zZ3f9UvOQ==
X-Google-Smtp-Source: APXvYqzyabdS8KranwUtzGWzZVkseIkaaBOVmeleq535E3JZsE3syBjE0XQDWTVFtsl+nGhgqLZseV+8uYSqCzMQdKE=
X-Received: by 2002:aca:810:: with SMTP id 16mr4645310oii.149.1572039848563; Fri, 25 Oct 2019 14:44:08 -0700 (PDT)
MIME-Version: 1.0
References: <CAL02cgSykPGZhaS26MuR78XBS9OVfBzGYVEzcRRROqbP-P-t6A@mail.gmail.com> <3B5BE109-6C78-474F-A0E5-138DE6931CF6@inria.fr> <6E36D92F-E700-4B57-9784-CFD366ECA912@wire.com> <3b841c7a-07c6-d415-825f-fc930831a78b@wickr.com>
In-Reply-To: <3b841c7a-07c6-d415-825f-fc930831a78b@wickr.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Fri, 25 Oct 2019 17:43:47 -0400
Message-ID: <CAL02cgR+_VzJUZYp3Za1qzmqPPbtamRoyKW3GBTsjAPCseTq-A@mail.gmail.com>
To: Joel Alwen <jalwen@wickr.com>
Cc: Raphael Robert <raphael@wire.com>, Benjamin Beurdouche <benjamin.beurdouche@inria.fr>,  Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Messaging Layer Security WG <mls@ietf.org>,  Yevgeniy Dodis <dodis@cs.nyu.edu>
Content-Type: multipart/alternative; boundary="000000000000bf27cd0595c30cdb"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/9wDz0hu62OSui0W3rOxfIat1V04>
Subject: Re: [MLS] Re-randomized TreeKEM
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Oct 2019 21:44:14 -0000

--000000000000bf27cd0595c30cdb
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

FWIW: I did a quick PoC implementing the update primitive on top of
OpenSSL, within the crypto framework of mlspp.  It wasn't trivial, but it
wasn't too painful.  It is almost certainly not constant-time.

https://github.com/cisco/mlspp/pull/59/files#diff-8c57ca8ea136d0bb8c846c77a=
e5b9e78R665

On Thu, Oct 24, 2019 at 4:19 PM Joel Alwen <jalwen@wickr.com> wrote:

> On 24/10/2019 12:09, Raphael Robert wrote:
> > This means that vendors/implementors have to implement something at a
> new layer that is somewhere in between the crypto library and the protoco=
l
> layer.
>
> Yeah, thats a good point. To me, proposing a reasonable way to build UPKE
> on top of, say, libsodium is one of the main
> things I want to figure out right now (along with better understanding of
> how Mult() for X25519 can fail). Basically,
> this means implementing Mult() from, say, libsodium as going from Mult()
> -> multiplicative UPKE should be very
> straightforward using what I'd expect even the most basic interface for
> any X25519 implementation to provide. I guess
> the challenge here is going to be that both clamp() and the composite
> order are neither exported nor directly accessible
> in libsodium?
>
> In any case, if Mult() needs implementing from scratch then some of the
> risks I see here are:
> - Side-Channels: Mult() operates on secret keys so really it should be
> implemented with side-channel free code (e.g.
> constant time, memory access, etc.). We could mitigate this by proposing =
a
> specific implementation similar to whats done
> in RFC 7748.
> - Memory management: Secret keys being exported out of an X25519 library
> need to be handled safely in memory (e.g. 0-ed
> out before free, don't swap to disk, etc.) Libsodium does provide some
> memory-management functions for this very purpose.
> - Good Entropy: The re-randomizer d' needs to be sampled uniformly and
> independently. (Again I think most crypto
> libraries provide functions to do this.)
>
> Probably a na=C3=AFve attempt at such a list of risks & mitigations. But =
making
> this stuff explicit seems useful for later on
> if we put this into the MLS RFCs (not to mention for a separate addendum
> RFC for 7748 describing the key-rerandomization
> technique on its own). So any input on the expected risks (and possible
> mitigations) would be very appreciated!
>
>
> On 24/10/2019 12:09, Raphael Robert wrote:
> > Finally I also understand that because of the clamping the actual
> security level of DH operations with curve 25519 is
> > not as clearly understood as it is the case with X25519 now.
>
> Not sure I follow what you mean here. One the one hand the UPKE
> construction is built on top of the X25519 (or X448)
> group not just Curve25519. In particular, Mult() uses the same point
> representation, clamping of scalars and scalar
> multiplication as specified in RFC 7748.
>
> On the other hand, if anything, I'd have thought questions about exact bi=
t
> security are the other way round. It's X25519
> that does the clamping so that's where the question about exact bit
> security would arise no? Clamping isn't inherent to
> Curve25519 though; rather its just one way to do scalar multiplication
> mapping into a prime order sub-group based on the
> composite order Curve25519 group. But, as shown by Ristretto, other
> methods are possible that completely avoid clamping
> (and also happen to be both additively and multiplicatively homomorphic).
> In particular, I believe CDH, DDH and all the
> other usual crypto hardness assumptions are equivalent for Curve25519's
> prime order subgroup and for the Ristretto
> group. Not sure thats true for X25519 though.
>
> In any case, I'm no expert on this stuff so feel free to correct me if I'=
m
> wrong. :-)
>
> - Jo=C3=ABl
>

--000000000000bf27cd0595c30cdb
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>FWIW: I did a quick PoC implementing the update primi=
tive on top of OpenSSL, within the crypto framework of mlspp.=C2=A0 It wasn=
&#39;t trivial, but it wasn&#39;t too painful.=C2=A0 It is almost certainly=
 not constant-time.<br></div><div><br></div><div><a href=3D"https://github.=
com/cisco/mlspp/pull/59/files#diff-8c57ca8ea136d0bb8c846c77ae5b9e78R665">ht=
tps://github.com/cisco/mlspp/pull/59/files#diff-8c57ca8ea136d0bb8c846c77ae5=
b9e78R665</a></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" cl=
ass=3D"gmail_attr">On Thu, Oct 24, 2019 at 4:19 PM Joel Alwen &lt;<a href=
=3D"mailto:jalwen@wickr.com">jalwen@wickr.com</a>&gt; wrote:<br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:=
1px solid rgb(204,204,204);padding-left:1ex">On 24/10/2019 12:09, Raphael R=
obert wrote:<br>
&gt; This means that vendors/implementors have to implement something at a =
new layer that is somewhere in between the crypto library and the protocol =
layer.<br>
<br>
Yeah, thats a good point. To me, proposing a reasonable way to build UPKE o=
n top of, say, libsodium is one of the main<br>
things I want to figure out right now (along with better understanding of h=
ow Mult() for X25519 can fail). Basically,<br>
this means implementing Mult() from, say, libsodium as going from Mult() -&=
gt; multiplicative UPKE should be very<br>
straightforward using what I&#39;d expect even the most basic interface for=
 any X25519 implementation to provide. I guess<br>
the challenge here is going to be that both clamp() and the composite order=
 are neither exported nor directly accessible<br>
in libsodium?<br>
<br>
In any case, if Mult() needs implementing from scratch then some of the ris=
ks I see here are:<br>
- Side-Channels: Mult() operates on secret keys so really it should be impl=
emented with side-channel free code (e.g.<br>
constant time, memory access, etc.). We could mitigate this by proposing a =
specific implementation similar to whats done<br>
in RFC 7748.<br>
- Memory management: Secret keys being exported out of an X25519 library ne=
ed to be handled safely in memory (e.g. 0-ed<br>
out before free, don&#39;t swap to disk, etc.) Libsodium does provide some =
memory-management functions for this very purpose.<br>
- Good Entropy: The re-randomizer d&#39; needs to be sampled uniformly and =
independently. (Again I think most crypto<br>
libraries provide functions to do this.)<br>
<br>
Probably a na=C3=AFve attempt at such a list of risks &amp; mitigations. Bu=
t making this stuff explicit seems useful for later on<br>
if we put this into the MLS RFCs (not to mention for a separate addendum RF=
C for 7748 describing the key-rerandomization<br>
technique on its own). So any input on the expected risks (and possible mit=
igations) would be very appreciated!<br>
<br>
<br>
On 24/10/2019 12:09, Raphael Robert wrote:<br>
&gt; Finally I also understand that because of the clamping the actual secu=
rity level of DH operations with curve 25519 is<br>
&gt; not as clearly understood as it is the case with X25519 now.<br>
<br>
Not sure I follow what you mean here. One the one hand the UPKE constructio=
n is built on top of the X25519 (or X448)<br>
group not just Curve25519. In particular, Mult() uses the same point repres=
entation, clamping of scalars and scalar<br>
multiplication as specified in RFC 7748.<br>
<br>
On the other hand, if anything, I&#39;d have thought questions about exact =
bit security are the other way round. It&#39;s X25519<br>
that does the clamping so that&#39;s where the question about exact bit sec=
urity would arise no? Clamping isn&#39;t inherent to<br>
Curve25519 though; rather its just one way to do scalar multiplication mapp=
ing into a prime order sub-group based on the<br>
composite order Curve25519 group. But, as shown by Ristretto, other methods=
 are possible that completely avoid clamping<br>
(and also happen to be both additively and multiplicatively homomorphic). I=
n particular, I believe CDH, DDH and all the<br>
other usual crypto hardness assumptions are equivalent for Curve25519&#39;s=
 prime order subgroup and for the Ristretto<br>
group. Not sure thats true for X25519 though.<br>
<br>
In any case, I&#39;m no expert on this stuff so feel free to correct me if =
I&#39;m wrong. :-)<br>
<br>
- Jo=C3=ABl<br>
</blockquote></div>

--000000000000bf27cd0595c30cdb--


From nobody Fri Oct 25 15:57:00 2019
Return-Path: <britta.hale@nps.edu>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 393A7120091 for <mls@ietfa.amsl.com>; Fri, 25 Oct 2019 15:56:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hHTXg8VGoucS for <mls@ietfa.amsl.com>; Fri, 25 Oct 2019 15:56:57 -0700 (PDT)
Received: from mule.nps.edu (mule.nps.edu [205.155.65.106]) by ietfa.amsl.com (Postfix) with ESMTP id B7F18120041 for <mls@ietf.org>; Fri, 25 Oct 2019 15:56:57 -0700 (PDT)
X-ASG-Debug-ID: 1572044216-0e394539684ce0a0001-bGA3T6
Received: from mail.nps.edu (skywalker.ern.nps.edu [172.20.4.117]) by mule.nps.edu with ESMTP id 4F3AVIYzANs0qx0F for <mls@ietf.org>; Fri, 25 Oct 2019 15:56:56 -0700 (PDT)
X-Barracuda-Envelope-From: britta.hale@nps.edu
Received: from skywalker.ern.nps.edu (172.20.4.117) by skywalker.ern.nps.edu (172.20.4.117) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1531.3; Fri, 25 Oct 2019 15:56:56 -0700
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (104.47.37.52) by skywalker.ern.nps.edu (172.20.4.117) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1531.3 via Frontend Transport; Fri, 25 Oct 2019 15:56:56 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VhXJc1iCbLI4cKmNG4t326KtpILTjh+KZ4/tcjY7AJqcRzHKRT+mIlcFeSK7uYZzEnRmm6M6AdKzGxIU1W1O+ebH2Xsi108Sl4OpWHzfhJktB5cGWnCAP171OvD80dP+vhZ9FPJLPhvHuzASLM/KI9guM9xMYbJtH1Wr9k2K7RKVWldwFd8KeKPr75KsEWRUx+K9d4wfqc1wfHeE+ifgeKqcgbJzOfvjEnpUNsMboKBG2zT0FpFaoOjqgRtTKXmcediXuz+7LixFlM4+sRN4V7UJ0HvIEcdUlmYzslo9eaEtAKCwhscMw3tlk1ki5JCsaPNt3sbvN1OYekys/ECMwQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;  s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zY875EbRRU1V0oHPrsO9gDEr4Jwl3KUDpSO39F3xjwc=; b=cYgwgJYGMCowA6AA4FNnIzwJe+aCSxoCeR0XHldQAuIeeHiQTRCDZy0rZmz5pPVf8i8+c8vJWlWVcLL1q+kBp120XTO1U/AAPac9v8aXcJNoYe/yEhLpjqsv5LVfX6ETJKgUxJwRN3nNg4+AOc7nGQssXNqMqdkKVeMT9bu7BpOKmxMadcQWX0COR4Pw48pWmp+MUfoKAX+JFjG7bRoc4eV/ai6xc/4aZvPWdaOb7E+mDFLiYCZLgnOi5TZ4DsShc1dBoOOjN8BDnhEf53RBLGhL8Y7sBDq56GI6oZRMb4/Wu7DSirnKhU9CTwZGkbCSwuILZMTxujCPPJeUbC8+Og==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nps.edu; dmarc=pass action=none header.from=nps.edu; dkim=pass header.d=nps.edu; arc=none
Received: from BYAPR13MB2533.namprd13.prod.outlook.com (52.135.228.150) by BYAPR13MB2517.namprd13.prod.outlook.com (52.135.222.152) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2387.17; Fri, 25 Oct 2019 22:56:55 +0000
Received: from BYAPR13MB2533.namprd13.prod.outlook.com ([fe80::3889:47fb:38b6:398c]) by BYAPR13MB2533.namprd13.prod.outlook.com ([fe80::3889:47fb:38b6:398c%5]) with mapi id 15.20.2387.021; Fri, 25 Oct 2019 22:56:55 +0000
X-Barracuda-Effective-Source-IP: UNKNOWN[52.135.222.152]
X-Barracuda-Apparent-Source-IP: 52.135.222.152
From: "Hale, Britta (CIV)" <britta.hale@nps.edu>
To: "mls@ietf.org" <mls@ietf.org>
Thread-Topic: [MLS] Next Interim
X-ASG-Orig-Subj: Re: [MLS] Next Interim
Thread-Index: AQHViKSKfryWaNyvZkmNd7LLkK1SsqdriFkA
Date: Fri, 25 Oct 2019 22:56:54 +0000
Message-ID: <AC2F4A7B-F895-4E6D-9699-4A1E91DC1845@nps.edu>
References: <54a0f5b5-2236-38e5-f228-684ab900f2d3@datashrine.de>
In-Reply-To: <54a0f5b5-2236-38e5-f228-684ab900f2d3@datashrine.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=britta.hale@nps.edu; 
x-originating-ip: [69.226.211.106]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b444e745-550a-434c-0d4a-08d7599ea1f0
x-ms-traffictypediagnostic: BYAPR13MB2517:
x-ms-exchange-purlcount: 1
x-microsoft-antispam-prvs: <BYAPR13MB2517AE8158E0DBBC8A64CDECFB650@BYAPR13MB2517.namprd13.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-forefront-prvs: 02015246A9
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(366004)(136003)(346002)(39850400004)(396003)(376002)(189003)(199004)(53754006)(66556008)(66946007)(11346002)(786003)(8676002)(476003)(6306002)(66066001)(81166006)(76116006)(256004)(446003)(71190400001)(1730700003)(81156014)(6246003)(66476007)(486006)(76176011)(966005)(71200400001)(64756008)(99286004)(75432002)(36756003)(25786009)(4744005)(2906002)(102836004)(33656002)(6506007)(186003)(5660300002)(478600001)(2351001)(2616005)(316002)(26005)(229853002)(6916009)(88552002)(7736002)(305945005)(86362001)(5640700003)(8936002)(6512007)(6486002)(14454004)(3846002)(6116002)(2501003)(6436002)(66446008); DIR:OUT; SFP:1101; SCL:1; SRVR:BYAPR13MB2517; H:BYAPR13MB2533.namprd13.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1; 
received-spf: None (protection.outlook.com: nps.edu does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: PK2axftIrFCiXNtT+bVFyoCmTXaCPNmu5zpmu9yrSjMcTkllZnJZkge5ii6tr5QkW9l8wzFKhMFT3JKqwc9P2givcFGyTh0q1JHan5EG7JFplzT/6ZDUPBZjfQtugTcz2zKTk4LdQ4psauaZgKzmFN4kUiv98D6h1Hcby/9OCCIQ3tUlcvPLf+k5y/2bZXITuVlhf7kCUdECKKnS0Ogqt586y7UsdIt+b8PAe2oJgkYYmwwG6lfcZdala+4j9KFYcJFh6h/XFurvuYcoEWXQMD+AGbZDriTYEl6uOZeFN6mNqKBuAj8bA3clCzNduOeubZRSy2jqJxHvamAh94cBQRriu8Q7V/IChciyLYIu7n9wpBLFWKASPDBDaSxTVepuFQ2TFmhnC6KFyzZwMaOiV3B8riDfhExeenvY81/aAQc5OhLhnXokqhIdKvBehonX7PxjbJB5wtZ6eIqK99qJrkzn2+Ea2wc8gIW3SyVc1zc=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <E38107D69A879B4AB7703464BBAF4116@namprd13.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: b444e745-550a-434c-0d4a-08d7599ea1f0
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Oct 2019 22:56:54.5497 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 6d936231-a517-40ea-9199-f7578963378e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: DQeV1b7XZ7WB/MxzgdSyNwOAJ+wnHLhohR3tyAggN7jU2A2T8DC1WD8EqmdS1krsL+yj80wz8l779D0oyUECUg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR13MB2517
X-OriginatorOrg: nps.edu
X-Barracuda-Connect: skywalker.ern.nps.edu[172.20.4.117]
X-Barracuda-Start-Time: 1572044216
X-Barracuda-URL: https://205.155.65.106:443/cgi-mod/mark.cgi
X-Virus-Scanned: by bsmtpd at nps.edu
X-Barracuda-Scan-Msg-Size: 858
X-Barracuda-BRTS-Status: 1
X-Barracuda-Spam-Score: 0.00
X-Barracuda-Spam-Status: No, SCORE=0.00 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=9.0 tests=
X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.77591 Rule breakdown below pts rule name              description ---- ---------------------- --------------------------------------------------
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/0AKUp7W-pWlgFH38eTXd8jhR8Lw>
Subject: Re: [MLS] Next Interim
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Oct 2019 22:56:59 -0000

SSB0aGluayB0aGlzIGluZm9ybWF0aW9uIHdvdWxkIGhlbHAgYSBsb3Qgb2YgdXMgd2l0aCBwbGFu
bmluZyBhbmQgd291bGQgYmUgbXVjaCBhcHByZWNpYXRlZC4gU29saWRpZnlpbmcgZGF0ZXMgYW5k
IGEgY2l0eSBlYXJseSB3b3VsZCBhbHNvIGdpdmUgYW4gb3Bwb3J0dW5pdHkgZm9yIGdyZWF0ZXIg
cGFydGljaXBhdGlvbi4NCg0KLS0gQnJpdHRhDQogDQoNCu+7v09uIDEwLzIxLzE5LCAxMTo0NyBQ
TSwgIk1MUyBvbiBiZWhhbGYgb2YgS29ucmFkIEtvaGJyb2siIDxtbHMtYm91bmNlc0BpZXRmLm9y
ZyBvbiBiZWhhbGYgb2Yga29ucmFkLmtvaGJyb2tAZGF0YXNocmluZS5kZT4gd3JvdGU6DQoNCiAg
ICBIaSBldmVyeW9uZSwNCiAgICANCiAgICBJJ20gY3VycmVudGx5IHBsYW5uaW5nIG15IHRyYXZl
bCB0byBSV0MgaW4gSmFudWFyeSBhbmQgd2FzIHdvbmRlcmluZyB3aGF0IHRoZQ0KICAgIHN0YXR1
cyBpcyBvbiB0aGUgbmV4dCBNTFMgaW50ZXJpbS4gQW55IGNoYW5jZSBpdCB3aWxsIGJlIGNvbG9j
YXRlZCBzaW1pbGFyIHRvDQogICAgbGFzdCBKYW51YXJ5PyBJIGtub3cgaXQncyBzdGlsbCByZWxh
dGl2ZWx5IGVhcmx5LCBidXQgaXQgd291bGQgaGVscCBwbGFubmluZw0KICAgIHF1aXRlIGEgYml0
IHRvIGtub3cgcm91Z2hseSB3aGVyZS93aGVuIHRoZSBvcHRpb25zIGFyZS4NCiAgICANCiAgICBD
aGVlcnMsDQogICAgS29ucmFkDQogICAgDQogICAgX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX18NCiAgICBNTFMgbWFpbGluZyBsaXN0DQogICAgTUxTQGlldGYu
b3JnDQogICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9tbHMNCiAgICAN
Cg0K


From nobody Thu Oct 31 00:27:50 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6746F120803 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 00:27:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YMN1gqdHbypq for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 00:27:46 -0700 (PDT)
Received: from mail-lj1-x233.google.com (mail-lj1-x233.google.com [IPv6:2a00:1450:4864:20::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EA7951200C1 for <mls@ietf.org>; Thu, 31 Oct 2019 00:27:45 -0700 (PDT)
Received: by mail-lj1-x233.google.com with SMTP id 139so5518376ljf.1 for <mls@ietf.org>; Thu, 31 Oct 2019 00:27:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=from:mime-version:subject:message-id:date:to; bh=YV74r7YaV/FH4ffMVpjM7Hlx6a2uBN+f3ZH0hJemeQY=; b=uOGGEKOf2xzI632v0vyqZ+RBOpSF7OrxJqvkEhsmjYkftpdnhVjmy2T6elG9b+qFLA 3f8AKnITIVAfT3kvBimpWd3SIuVMSN3rhmGQZqRDUj6HF21qIhcgq+ZjWkhFTvSiqtmu s1jLBtJQuggflMU7BVcIGmL75PM5hZwvEhgcyQ5tHl+ZrA28tl1apuPxoqdgeAbzp/VT 3unPCc494uwVU1k2gevhG/sPIPDY108NwCdPiqucYB0qqNNV71nGsg+PKX+j80m/0tDw 9D6rMB2Eey0gm3WCbN9nZvFBwaQeLnPRAjq/QovXAnBEKZTU71W+gXH+Sxl3sJDDlNY1 PV8w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:to; bh=YV74r7YaV/FH4ffMVpjM7Hlx6a2uBN+f3ZH0hJemeQY=; b=mMEm0LD/mc4FG9gMnI44VTu+T8/8hGD+r9F6BlRSaE/abB9qp4NVuNen0qjUN6qvU2 2L94FtF7JpoMl5iGy1cWTWtUm/1+X8DP/7DGOch3kVur77LGnZ27J4E75cIr/YuDcMOW DcKmbRV/LxNBqFv1TCnaFS0fH9SpCV0BbGB9eKMKc33XnH/zSNv3XmuZ01mPLYQxf+g9 R790zRQde6wsK9JV4UnfjIShS3jdUq60MIfRH3tZpJ1FtAQ4S5pV68V4JST7ETBlbfYI Z6VRnIaQjfXlkwkF8GDNQfMRz7Yy2oKUI/dB5VIN0VgiLz/YiccawIJcVu8svjjG9ko7 8qAQ==
X-Gm-Message-State: APjAAAXKS/KdvMZOePMiPUQGCtb2viBXh6/bavGU18VoHK1CqJ+4g5Ai CE09zawA5YJQkYat5DFt3JSnEnDYQTu8LQ==
X-Google-Smtp-Source: APXvYqy2tjbtDetcRuVGxILZkoYBvaIVjbxTtHOjw/dFmF1QV/YUnkjscFSlN3L/wTsOdmEqSNcv3Q==
X-Received: by 2002:a2e:87c9:: with SMTP id v9mr2838219ljj.65.1572506863663; Thu, 31 Oct 2019 00:27:43 -0700 (PDT)
Received: from [192.168.1.123] (host103-147-static.7-79-b.business.telecomitalia.it. [79.7.147.103]) by smtp.gmail.com with ESMTPSA id i190sm1397881lfi.45.2019.10.31.00.27.42 for <mls@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 31 Oct 2019 00:27:43 -0700 (PDT)
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_68F0EF5B-575D-423E-A103-A16B7AF4203C"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Message-Id: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com>
Date: Thu, 31 Oct 2019 08:27:39 +0100
To: Messaging Layer Security WG <mls@ietf.org>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/DMFACd68aZ3iAi2gMmNnBT-qjK8>
Subject: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 07:27:49 -0000

--Apple-Mail=_68F0EF5B-575D-423E-A103-A16B7AF4203C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

I must begin by saying that I have been enjoying reading Alwen et al=E2=80=
=99s work [1] and they make some excellent points.
I particularly like the idea of using a primitive like UPKE (or SkuPke =
as [2] calls it) to improve the forward secrecy guarantees of TreeKEM.
If this can be made to work with standards-compliant EC implementations, =
we should definitely consider adding this mechanism to MLS.

For my own better understanding, however, I am trying to figure out the =
exact forward secrecy improvement this will bring to the protocol.
It is clear from [1] that the *update secret* and each *subgroup secret* =
in TreeKEM provides weak Forward Secrecy (since each update
only modifies one leaf key, leaving the attacker N-1 members to =
compromise.)

However, the public key part of TreeKEM is only part of the Forward =
Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=80=9D =
which
changes with every update. As far as I can see, the discussion in [1] =
appears to ignore the =E2=80=9Cinit_secret -> update_secret -> =
epoch_secret+init_secret=E2=80=9D
ratchet which has always been part of MLS. So I don=E2=80=99t fully see =
how the attack of [1] works, and maybe someone can explain.

One may argue that the goal of TreeKEM is to provide FS and PCS for the =
epoch_secret, not the update_secret.
If every member of the group is honest, then A sends an update , then B =
accepts the update (ratcheting forward its init_secret),=20
and then B is compromised, then how can the attacker learn the new epoch =
secret?

Perhaps we are worried about post-compromise forward secrecy (PCFS), but =
I don=E2=80=99t see any attack on that either.
It is likely I am missing something, so do chime in and explain.

Best,
Karthik


[1] https://eprint.iacr.org/2019/1189.pdf =
<https://eprint.iacr.org/2019/1189.pdf>
[2] https://eprint.iacr.org/2018/954 <https://eprint.iacr.org/2018/954>=

--Apple-Mail=_68F0EF5B-575D-423E-A103-A16B7AF4203C
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">I =
must begin by saying that I have been enjoying reading Alwen et al=E2=80=99=
s work [1] and they make some excellent points.<div class=3D"">I =
particularly like the idea of using a primitive like UPKE (or SkuPke as =
[2] calls it) to improve the forward secrecy guarantees of =
TreeKEM.</div><div class=3D"">If this can be made to work with =
standards-compliant EC implementations, we should definitely consider =
adding this mechanism to MLS.</div><div class=3D""><br =
class=3D""></div><div class=3D"">For my own better understanding, =
however, I am trying to figure out the exact forward secrecy improvement =
this will bring to the protocol.</div><div class=3D"">It is clear from =
[1] that the *update secret* and each *subgroup secret* in TreeKEM =
provides weak Forward Secrecy (since each update</div><div class=3D"">only=
 modifies one leaf key, leaving the attacker N-1 members to =
compromise.)</div><div class=3D""><br class=3D""></div><div =
class=3D"">However, the public key part of TreeKEM is only part of the =
Forward Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=
=80=9D which</div><div class=3D"">changes with every update. As far as I =
can see, the discussion in [1] appears to ignore the =E2=80=9Cinit_secret =
-&gt; update_secret -&gt; epoch_secret+init_secret=E2=80=9D</div><div =
class=3D"">ratchet which has always been part of MLS. So I don=E2=80=99t =
fully see how the attack of [1] works, and maybe someone can =
explain.</div><div class=3D""><br class=3D""></div><div class=3D"">One =
may argue that the goal of TreeKEM is to provide FS and PCS for the =
epoch_secret, not the update_secret.</div><div class=3D"">If every =
member of the group is honest, then A sends an update , then B accepts =
the update (ratcheting forward its init_secret),&nbsp;</div><div =
class=3D"">and then B is compromised, then how can the attacker learn =
the new epoch secret?</div><div class=3D""><br class=3D""></div><div =
class=3D"">Perhaps we are worried about post-compromise forward secrecy =
(PCFS), but I don=E2=80=99t see any attack on that either.</div><div =
class=3D"">It is likely I am missing something, so do chime in and =
explain.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><div class=3D""><br =
class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D"">[1]&nbsp;<a href=3D"https://eprint.iacr.org/2019/1189.pdf" =
class=3D"">https://eprint.iacr.org/2019/1189.pdf</a></div><div =
class=3D"">[2]&nbsp;<a href=3D"https://eprint.iacr.org/2018/954" =
class=3D"">https://eprint.iacr.org/2018/954</a></div></body></html>=

--Apple-Mail=_68F0EF5B-575D-423E-A103-A16B7AF4203C--


From nobody Thu Oct 31 01:37:50 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 87C37120882 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 01:37:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.897
X-Spam-Level: 
X-Spam-Status: No, score=-6.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CUVTQkC1sKiI for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 01:37:47 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FF5B120876 for <mls@ietf.org>; Thu, 31 Oct 2019 01:37:47 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.68,250,1569276000";  d="scan'208,217";a="325203234"
Received: from aannecy-653-1-78-207.w90-41.abo.wanadoo.fr (HELO [192.168.1.19]) ([90.41.199.207]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/AES256-GCM-SHA384; 31 Oct 2019 09:37:44 +0100
Content-Type: multipart/alternative; boundary=Apple-Mail-EACF21CC-5E71-4E71-8AA2-151CF29E2FA0
Content-Transfer-Encoding: 7bit
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Mime-Version: 1.0 (1.0)
Date: Thu, 31 Oct 2019 09:37:44 +0100
Message-Id: <E1A50840-7F20-49ED-9878-D446B735159E@inria.fr>
References: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
In-Reply-To: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
X-Mailer: iPhone Mail (17A878)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/TXSOvcgmrPdJVxoS1n9QGGNTU7E>
Subject: Re: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 08:37:50 -0000

--Apple-Mail-EACF21CC-5E71-4E71-8AA2-151CF29E2FA0
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

I think I perfectly agree with most of what=E2=80=99s been discussed in the m=
ailing list about rtreekem but even though, I agree with Karthik that I don=E2=
=80=99t fully understand how to break epoch level FS here...

I might not have understood something either :) input very very welcome !
B.

> On Oct 31, 2019, at 8:28 AM, Karthikeyan Bhargavan <karthik.bhargavan@gmai=
l.com> wrote:
>=20
> =EF=BB=BFI must begin by saying that I have been enjoying reading Alwen et=
 al=E2=80=99s work [1] and they make some excellent points.
> I particularly like the idea of using a primitive like UPKE (or SkuPke as [=
2] calls it) to improve the forward secrecy guarantees of TreeKEM.
> If this can be made to work with standards-compliant EC implementations, w=
e should definitely consider adding this mechanism to MLS.
>=20
> For my own better understanding, however, I am trying to figure out the ex=
act forward secrecy improvement this will bring to the protocol.
> It is clear from [1] that the *update secret* and each *subgroup secret* i=
n TreeKEM provides weak Forward Secrecy (since each update
> only modifies one leaf key, leaving the attacker N-1 members to compromise=
.)
>=20
> However, the public key part of TreeKEM is only part of the Forward Secrec=
y story, we must also account for the =E2=80=9Cinit_secret=E2=80=9D which
> changes with every update. As far as I can see, the discussion in [1] appe=
ars to ignore the =E2=80=9Cinit_secret -> update_secret -> epoch_secret+init=
_secret=E2=80=9D
> ratchet which has always been part of MLS. So I don=E2=80=99t fully see ho=
w the attack of [1] works, and maybe someone can explain.
>=20
> One may argue that the goal of TreeKEM is to provide FS and PCS for the ep=
och_secret, not the update_secret.
> If every member of the group is honest, then A sends an update , then B ac=
cepts the update (ratcheting forward its init_secret),=20
> and then B is compromised, then how can the attacker learn the new epoch s=
ecret?
>=20
> Perhaps we are worried about post-compromise forward secrecy (PCFS), but I=
 don=E2=80=99t see any attack on that either.
> It is likely I am missing something, so do chime in and explain.
>=20
> Best,
> Karthik
>=20
>=20
> [1] https://eprint.iacr.org/2019/1189.pdf
> [2] https://eprint.iacr.org/2018/954
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls

--Apple-Mail-EACF21CC-5E71-4E71-8AA2-151CF29E2FA0
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div dir=3D"ltr">I think I perfectly agree w=
ith most of what=E2=80=99s been discussed in the mailing list about rtreekem=
 but even though, I agree with Karthik that I don=E2=80=99t fully understand=
 how to break epoch level FS here...</div><div dir=3D"ltr"><br></div><div di=
r=3D"ltr">I might not have understood something either :) input very very we=
lcome !</div><div dir=3D"ltr">B.</div><div dir=3D"ltr"><br><blockquote type=3D=
"cite">On Oct 31, 2019, at 8:28 AM, Karthikeyan Bhargavan &lt;karthik.bharga=
van@gmail.com&gt; wrote:<br><br></blockquote></div><blockquote type=3D"cite"=
><div dir=3D"ltr">=EF=BB=BF<meta http-equiv=3D"Content-Type" content=3D"text=
/html; charset=3Dutf-8">I must begin by saying that I have been enjoying rea=
ding Alwen et al=E2=80=99s work [1] and they make some excellent points.<div=
 class=3D"">I particularly like the idea of using a primitive like UPKE (or S=
kuPke as [2] calls it) to improve the forward secrecy guarantees of TreeKEM.=
</div><div class=3D"">If this can be made to work with standards-compliant E=
C implementations, we should definitely consider adding this mechanism to ML=
S.</div><div class=3D""><br class=3D""></div><div class=3D"">For my own bett=
er understanding, however, I am trying to figure out the exact forward secre=
cy improvement this will bring to the protocol.</div><div class=3D"">It is c=
lear from [1] that the *update secret* and each *subgroup secret* in TreeKEM=
 provides weak Forward Secrecy (since each update</div><div class=3D"">only m=
odifies one leaf key, leaving the attacker N-1 members to compromise.)</div>=
<div class=3D""><br class=3D""></div><div class=3D"">However, the public key=
 part of TreeKEM is only part of the Forward Secrecy story, we must also acc=
ount for the =E2=80=9Cinit_secret=E2=80=9D which</div><div class=3D"">change=
s with every update. As far as I can see, the discussion in [1] appears to i=
gnore the =E2=80=9Cinit_secret -&gt; update_secret -&gt; epoch_secret+init_s=
ecret=E2=80=9D</div><div class=3D"">ratchet which has always been part of ML=
S. So I don=E2=80=99t fully see how the attack of [1] works, and maybe someo=
ne can explain.</div><div class=3D""><br class=3D""></div><div class=3D"">On=
e may argue that the goal of TreeKEM is to provide FS and PCS for the epoch_=
secret, not the update_secret.</div><div class=3D"">If every member of the g=
roup is honest, then A sends an update , then B accepts the update (ratcheti=
ng forward its init_secret),&nbsp;</div><div class=3D"">and then B is compro=
mised, then how can the attacker learn the new epoch secret?</div><div class=
=3D""><br class=3D""></div><div class=3D"">Perhaps we are worried about post=
-compromise forward secrecy (PCFS), but I don=E2=80=99t see any attack on th=
at either.</div><div class=3D"">It is likely I am missing something, so do c=
hime in and explain.</div><div class=3D""><br class=3D""></div><div class=3D=
"">Best,</div><div class=3D"">Karthik</div><div class=3D""><br class=3D""></=
div><div class=3D""><br class=3D""></div><div class=3D"">[1]&nbsp;<a href=3D=
"https://eprint.iacr.org/2019/1189.pdf" class=3D"">https://eprint.iacr.org/2=
019/1189.pdf</a></div><div class=3D"">[2]&nbsp;<a href=3D"https://eprint.iac=
r.org/2018/954" class=3D"">https://eprint.iacr.org/2018/954</a></div><span>_=
______________________________________________</span><br><span>MLS mailing l=
ist</span><br><span>MLS@ietf.org</span><br><span>https://www.ietf.org/mailma=
n/listinfo/mls</span><br></div></blockquote></body></html>=

--Apple-Mail-EACF21CC-5E71-4E71-8AA2-151CF29E2FA0--


From nobody Thu Oct 31 04:35:33 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 47C5612001E for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 04:35:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id luTHC7sQtBLO for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 04:35:31 -0700 (PDT)
Received: from mail-io1-xd35.google.com (mail-io1-xd35.google.com [IPv6:2607:f8b0:4864:20::d35]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0828A120074 for <mls@ietf.org>; Thu, 31 Oct 2019 04:35:31 -0700 (PDT)
Received: by mail-io1-xd35.google.com with SMTP id k1so6303633iom.9 for <mls@ietf.org>; Thu, 31 Oct 2019 04:35:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:from:date:message-id:subject:to; bh=UZ4ILXltEAlrAwDkEF3Iglz6zVL27R4CORgoXMor15Q=; b=dxNfxQSfi2EOvbvIToiXCWXJLsmxmLBtPZBa1eA0rbd4r/EY0ueYLntu26/xXu7Zco RKiAG1K8OniH0Y0TngMBMEv19Mx3iHbRb/qHS1NA7CCH2f1pd5EVJRw51MfNIwFVGVYN mqnSibgXh0o1l7vVI5lbOlmSGpl/mzy27oFu8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=UZ4ILXltEAlrAwDkEF3Iglz6zVL27R4CORgoXMor15Q=; b=BVhBZCCgAV1fCNVci6dBRP+echS35czSPQBSgP1XoWclxUwTNX9Hq6cJOl56vVjMhN gbpUIfCdBhFD/p226P8gpe6r3HEED+e9ZD46BKK7+t8DC6PFDOjgmt9frx3/OSATomuH hogtyBRfmu2NE6lWMOcOk0LO+dnHdvDw+Wz1yVpwKdNAPjqHVfNXb8pbY8eHo2bp/wRt 2kVmrYX9kHkifrelUO4gt0Q/geV2u50tOnoOWSKyCNNy0cgupsEBHwPSIbl/vCz2qUkk 2MOPcqWgY/ueRqcNJd0lV55a9JwgBcO2aEnvniDqsJ9tswIkc0a6SbYj/g7ULYuDmjo2 JCxA==
X-Gm-Message-State: APjAAAW3pfc/uXG6UmdQB0PAS381XdeRGru+gpT4TCNPSk22i36KtsML QJpsMoqPY14PDeRdzG8tsxglQv9ulIXG/twQlUhqpIUZo+mPrw==
X-Google-Smtp-Source: APXvYqxEwayCl3Tlsp4H7mufb/oKLJT1vWpGlQMXs5HVDx/nEQYFPdTP0oxEXxcpsPqb+mxcf6m6j06GVxOx1nTeH8I=
X-Received: by 2002:a6b:b4ca:: with SMTP id d193mr4619648iof.71.1572521730052;  Thu, 31 Oct 2019 04:35:30 -0700 (PDT)
MIME-Version: 1.0
From: Pascal Junod <pascalj@snap.com>
Date: Thu, 31 Oct 2019 12:35:19 +0100
Message-ID: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com>
To: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000001f4faf0596333ffd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/LYAMUMYklEuqQfoPNvOzwaaNLsU>
Subject: [MLS] [Metadata encryption]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 11:35:32 -0000

--0000000000001f4faf0596333ffd
Content-Type: text/plain; charset="UTF-8"

Hi !

I have a question regarding the current draft and related to section 8.1:
what is the purpose of including the sender_data_nonce into the attached
data? To cover AEAD schemes relying on a non-randomized MAC, like, e.g., an
AES-CBC-HMAC construction ? Are there plans to support ciphersuites of this
type in the future ?

Best,

Pascal

--0000000000001f4faf0596333ffd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi !<div><br></div><div>I have a question regarding the cu=
rrent draft and related to section 8.1: what is the purpose of including th=
e <font face=3D"monospace">sender_data_nonce</font> into the attached data?=
 To cover AEAD schemes relying on a non-randomized MAC, like, e.g., an AES-=
CBC-HMAC construction ? Are there plans to support ciphersuites of this typ=
e in the future ?</div><div><br></div><div>Best,=C2=A0</div><div><br>Pascal=
</div></div>

--0000000000001f4faf0596333ffd--


From nobody Thu Oct 31 04:50:03 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 487B2120099 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 04:50:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vMFDTH4MOd9T for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 04:50:00 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B03B12001E for <mls@ietf.org>; Thu, 31 Oct 2019 04:49:59 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.68,250,1569276000";  d="scan'208,217";a="409781525"
Received: from aannecy-653-1-78-207.w90-41.abo.wanadoo.fr (HELO pc54.home) ([90.41.199.207]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 31 Oct 2019 12:49:56 +0100
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <24F9C4C5-EC56-4C77-8940-E2BF828F6265@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_F7BB76C3-A9BE-40F0-BFBE-BE3F3537FEDE"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
Date: Thu, 31 Oct 2019 12:49:56 +0100
In-Reply-To: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Pascal Junod <pascalj=40snap.com@dmarc.ietf.org>
References: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/PAfolNCKUd04om3Bjb1uHFEOxHo>
Subject: Re: [MLS] [Metadata encryption]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 11:50:02 -0000

--Apple-Mail=_F7BB76C3-A9BE-40F0-BFBE-BE3F3537FEDE
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Pascal !


> I have a question regarding the current draft and related to section =
8.1: what is the purpose of including the sender_data_nonce into the =
attached data? To cover AEAD schemes relying on a non-randomized MAC, =
like, e.g., an AES-CBC-HMAC construction ? Are there plans to support =
ciphersuites of this type in the future ?


To decrypt messages, a member must
1. Look at the group_id and the epoch number to find the correct secrets =
to decrypt in its local state.
2. Determine which sender encrypted the message.
3. Compute or retrieve the correct sender-specific decryption key from =
its state.

Since we want to protect the sender data for privacy reason, we have to =
encrypt
it under a group key. That group key is outputed by the key schedule so =
is fully deterministic
and independent of the sender that will encrypt. Since everybody could =
use that key,
we want to avoid them to also use a deterministic nonce, so we use a =
random nonce
that we have to prepend in the header of the message.

Most, if not all other messages are encrypted under member specific keys =
in MLS,=20
so nonce reuse is less of a problem except in the case state loss and we =
have a pending fix for it=E2=80=A6 : )

Does this make sense ?
Best,

Benjamin=

--Apple-Mail=_F7BB76C3-A9BE-40F0-BFBE-BE3F3537FEDE
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Pascal !<div class=3D""><br class=3D""></div><div class=3D""><br =
class=3D""><div class=3D""><div><blockquote type=3D"cite" class=3D""><div =
class=3D""><div dir=3D"ltr" class=3D""><div class=3D"">I have a question =
regarding the current draft and related to section 8.1: what is the =
purpose of including the <font face=3D"monospace" =
class=3D"">sender_data_nonce</font> into the attached data? To cover =
AEAD schemes relying on a non-randomized MAC, like, e.g., an =
AES-CBC-HMAC construction ? Are there plans to support ciphersuites of =
this type in the future ?</div></div></div></blockquote><br =
class=3D""></div><div><br class=3D""></div><div>To decrypt messages, a =
member must</div><div>1. Look at the group_id and the epoch number to =
find the correct secrets to decrypt in its local state.</div><div>2. =
Determine which sender encrypted the message.</div><div>3. Compute or =
retrieve the correct sender-specific decryption key from its =
state.</div><div><br class=3D""></div><div>Since we want to protect the =
sender data for privacy reason, we have to =
encrypt</div></div></div><div>it under a group key. That group key is =
outputed by the key schedule so is fully deterministic</div><div>and =
independent of the sender that will encrypt. Since everybody could use =
that key,</div><div>we want to avoid them to also use a deterministic =
nonce, so we use a random nonce</div><div>that we have to prepend in the =
header of the message.</div><div><br class=3D""></div><div>Most, if not =
all other messages are encrypted under member specific keys in =
MLS,&nbsp;</div><div>so nonce reuse is less of a problem except in the =
case state loss and we have a pending fix for it=E2=80=A6 : =
)</div><div><br class=3D""></div><div>Does this make sense =
?</div><div>Best,</div><div><br =
class=3D""></div><div>Benjamin</div></body></html>=

--Apple-Mail=_F7BB76C3-A9BE-40F0-BFBE-BE3F3537FEDE--


From nobody Thu Oct 31 06:12:19 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE5FC1200A1 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 06:12:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9nGk1OOF376b for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 06:12:13 -0700 (PDT)
Received: from mail-qk1-x736.google.com (mail-qk1-x736.google.com [IPv6:2607:f8b0:4864:20::736]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC0FD120058 for <mls@ietf.org>; Thu, 31 Oct 2019 06:12:13 -0700 (PDT)
Received: by mail-qk1-x736.google.com with SMTP id u184so6929302qkd.4 for <mls@ietf.org>; Thu, 31 Oct 2019 06:12:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Wli093s4LTLptH8/Ic1xw0+qE74ppizsrmUuh/NPKUk=; b=KbG0CnhAG55NTwZ13Pp9IdHK3kIrNS5CgFMqINA///kraNlUjq1XhZBWi8XeA7Iwl7 dCtPbkUTWtmX/cknbRVIaVT6aGKMicZVVb8fEKQq2gZohL+454uNwJvTWWFxkzMkq5PP 6b/k1rMHqjgU26batezqmwelgIaN3RX1bHokABCKyKcgATZfLLbA6tqWGiTwOUY/j+BI O8qK4keZPnNoFsrpdcq1DyXz06RdtCjmXcPwx28ThDiBASn/kbJzco9GS4yaYrXT3V1T K+OgKaTmmlOg/fChfzepGVc7ukvPb5ozQN4F/A/WRVoQQZLt8GzCjzvIuvD6hGAYxxa9 JCRA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Wli093s4LTLptH8/Ic1xw0+qE74ppizsrmUuh/NPKUk=; b=bYhRyFy/u73OSwVHo5B7Sj7HRDRZ/058qFWQYtp0cpSescry/9RthStaEEraPJZgZ7 9PbGrZAI+cvnyhyQvPUoFJ+k+IhYS4gbqGbHYU/4adqAzUiKBSbY6HfLyKmNr2pbxcP6 WT6Cy1WgH+X7pLdXnWCZAyPqEOxjsNe4fVsnEpgluQu24TxFXnRR/R9fUV1wyuFylZ8x 4swHcDJAT5EiG+iLkOh7z1VF3pw87e73xyi8S7EDtWPZNoLa4sGACbq54vtgPbywraqY fwkUlAiK+YvH2bmmxyPiSUBq/oI9sjapt4g39+/FmI6iUVPdiHa0ujmZJaxwFsCJzOPO 9+OQ==
X-Gm-Message-State: APjAAAUFIag1PG7a1H8BiLsO3R5oPeneaDgnsYsuwmpOhWlY2seulFYY TwaqJEqpy3mcHjIbraLfIWIrWy+TAnHW5o1vSABdMw==
X-Google-Smtp-Source: APXvYqzkJGJPMovIhYjh/jg1iqUoa+52SdKf1WeAeJ7Q2VYK1eEi9wkudGNrUwFlmOlzmEuw0bExYDltu7NZFt85Kd0=
X-Received: by 2002:a05:620a:1346:: with SMTP id c6mr1447868qkl.236.1572527532585;  Thu, 31 Oct 2019 06:12:12 -0700 (PDT)
MIME-Version: 1.0
References: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com>
In-Reply-To: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Date: Thu, 31 Oct 2019 14:12:00 +0100
Message-ID: <CANYP603VS5iRtdG+n-TSsrVzynUMy4VqutSqjmWMzTYJiSaPgA@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fac969059634983c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/m01h3nE-uXmZBeasQqttxHhZaRg>
Subject: Re: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 13:12:17 -0000

--000000000000fac969059634983c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hey,

Yeah, we should have been more explicite about how this all plays out for
MLS. Good that you asked. :-)

"PCFS" is exactly the term we were using to talk about how change from
TreeKEM -> RTreeKEM affects MLS. In a nutshell, FS for epochs after a
compromise is healed (with an update) takes no less but (potentially quite
a bit) longer to kick in for "MLS" (MLS+TreeKEM) than for "RMLS"
(MLS+RTreeKEM).

Here's an example scenario that highlights the difference for MLS.

Suppose Alice's state leaked in the past and now she does an update
defining epoch_secret[i]. Intuitively, until the next corruption (say of
Bob when he's in epoch j>i) we'd like that all epoch_secrets in [i,j)
remain secure. (This property is what we've informally been calling PCFS.
I.e. Forward Security for epochs after a compromise.) We consider what
security we get for (R)MLS.

MLS: Assume (for a moment) all handshake messages are delivered in the same
order to all group messages. Because TreeKEM lets Bob keep HPKE keys around
even after using them Bob could still have the keys to process Alice's
update. Whether this is true or not depends on who's update between [i,j)
and their, Alice and Bob's possitions in the ratchet tree. To guarantee Bob
doesn't have said keys we'd need to know e.g. Bob updated between [i,j) or
someone strictly closer to Bob than Alice has updated. (Closer =3D shorter
path ratchet tree from Bob's leaf to Charlie's leaf than from Alice's leaf
to Charlie's.)

RMLS: Now consider RMLS when the same assumption holds. All epoch_secrets
in [i,j) remain secure even after Bob's compromise because Bob already
deleted any keys he had that can proccess Alice's update. In more detail:
the adversary knows init_secret[n-1] (from having corrupted Alice). So to
get epoch_secret[n] she still needs update_secret[n] defined by Alice's
update. By assumption Bob processed that update himself. So RTreeKEM (but
not TreeKEM) guarantees Bob no longer has the keys to re-process it. Thus,
corrupting him doesnt let the adversary recover epoch_secret[i] (nor any
ones after that since its always missing at least the required init_secret)=
.



Now lets consider what happens if the global ordering assumption doesn't
hold.

RMLS: Suppose we know only that Bob processed Alice's update. Then just as
above (and regardless of anything else in the execution) corrupting Bob
reveals nothing about any epoch_secrets (or init_secrets) other than the
ones currently held by Bob. So the Adversary breaks no other "epoch
security" (besides the one Bob is in at the time of corruption).

MLS: Assuming Bob processed Alice's update doesn't help us like it did for
RMLS because TreeKEM doesnt require him to then delete the keys he used.
Instead, any keys Bob still has for processing handshake messages starting
just before Alice's update let the adversary recover the corresponding
update_secrets. So the adversary can ratchet the global key schedule
forward through all those epochs (startin with init_secret[n-1] she had
from corrupting Alice).



Suppose finally, that we have neither global ordering nor did Bob ever
process Alice's message.

RMLS: For RMLS, this is the only way that corrupting Bob can (potentially)
help the adversary break "epoch security" for any epoch besides the one Bob
is in during corruption. That is, it might be that Bob still has keys to
proccess Alice's update (and even some further sequences of handshake
messages as long as they depend directly on Alice's update. This works
until the Adversary hits the first handshake message in a sequence for
which Bob doesn't have keys to process.

MLS: First (and as in all cases) anything the adversary could compute for
RMLS they can compute for MLS too. So the above "forking attack" exhists
for MLS. But even here RMLS can behave better than MLS because RTreeKEM
generally causes Bob to refresh his key material more frequently than
TreeKEM.


Let me know if this helps clarify stuff a bit.

- Joel


On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, <
karthik.bhargavan@gmail.com> wrote:

> I must begin by saying that I have been enjoying reading Alwen et al=E2=
=80=99s
> work [1] and they make some excellent points.
> I particularly like the idea of using a primitive like UPKE (or SkuPke as
> [2] calls it) to improve the forward secrecy guarantees of TreeKEM.
> If this can be made to work with standards-compliant EC implementations,
> we should definitely consider adding this mechanism to MLS.
>
> For my own better understanding, however, I am trying to figure out the
> exact forward secrecy improvement this will bring to the protocol.
> It is clear from [1] that the *update secret* and each *subgroup secret*
> in TreeKEM provides weak Forward Secrecy (since each update
> only modifies one leaf key, leaving the attacker N-1 members to
> compromise.)
>
> However, the public key part of TreeKEM is only part of the Forward
> Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=80=9D=
 which
> changes with every update. As far as I can see, the discussion in [1]
> appears to ignore the =E2=80=9Cinit_secret -> update_secret ->
> epoch_secret+init_secret=E2=80=9D
> ratchet which has always been part of MLS. So I don=E2=80=99t fully see h=
ow the
> attack of [1] works, and maybe someone can explain.
>
> One may argue that the goal of TreeKEM is to provide FS and PCS for the
> epoch_secret, not the update_secret.
> If every member of the group is honest, then A sends an update , then B
> accepts the update (ratcheting forward its init_secret),
> and then B is compromised, then how can the attacker learn the new epoch
> secret?
>
> Perhaps we are worried about post-compromise forward secrecy (PCFS), but =
I
> don=E2=80=99t see any attack on that either.
> It is likely I am missing something, so do chime in and explain.
>
> Best,
> Karthik
>
>
> [1] https://eprint.iacr.org/2019/1189.pdf
> [2] https://eprint.iacr.org/2018/954
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000fac969059634983c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div>Hey,</div><div dir=3D"auto"><br></div><div dir=3D"au=
to">Yeah, we should have been more explicite about how this all plays out f=
or MLS. Good that you asked. :-)<br><br>&quot;PCFS&quot; is exactly the ter=
m we were using to talk about how change from TreeKEM -&gt; RTreeKEM affect=
s MLS. In a nutshell, FS for epochs after a compromise is healed (with an u=
pdate) takes no less but (potentially quite a bit) longer to kick in for &q=
uot;MLS&quot; (MLS+TreeKEM) than for &quot;RMLS&quot; (MLS+RTreeKEM).<br><b=
r>Here&#39;s an example scenario that highlights the difference for MLS.<br=
><br>Suppose Alice&#39;s state leaked in the past and now she does an updat=
e defining epoch_secret[i]. Intuitively, until the next corruption (say of =
Bob when he&#39;s in epoch j&gt;i) we&#39;d like that all epoch_secrets in =
[i,j) remain secure. (This property is what we&#39;ve informally been calli=
ng PCFS. I.e. Forward Security for epochs after a compromise.) We consider =
what security we get for (R)MLS.<br><br>MLS: Assume (for a moment) all hand=
shake messages are delivered in the same order to all group messages. Becau=
se TreeKEM lets Bob keep HPKE keys around even after using them Bob could s=
till have the keys to process Alice&#39;s update. Whether this is true or n=
ot depends on who&#39;s update between [i,j) and their, Alice and Bob&#39;s=
 possitions in the ratchet tree. To guarantee Bob doesn&#39;t have said key=
s we&#39;d need to know e.g. Bob updated between [i,j) or someone strictly =
closer to Bob than Alice has updated. (Closer =3D shorter path ratchet tree=
 from Bob&#39;s leaf to Charlie&#39;s leaf than from Alice&#39;s leaf to Ch=
arlie&#39;s.)=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">RMLS=
: Now consider RMLS when the same assumption holds. All epoch_secrets in [i=
,j) remain secure even after Bob&#39;s compromise because Bob already delet=
ed any keys he had that can proccess Alice&#39;s update. In more detail: th=
e adversary knows init_secret[n-1] (from having corrupted Alice). So to get=
 epoch_secret[n] she still needs update_secret[n] defined by Alice&#39;s up=
date. By assumption Bob processed that update himself. So RTreeKEM (but not=
 TreeKEM) guarantees Bob no longer has the keys to re-process it. Thus, cor=
rupting him doesnt let the adversary recover epoch_secret[i] (nor any ones =
after that since its always missing at least the required init_secret).</di=
v><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto"=
><br></div><div dir=3D"auto">Now lets consider what happens if the global o=
rdering assumption doesn&#39;t hold.</div><div dir=3D"auto"><br></div><div =
dir=3D"auto">RMLS: Suppose we know only that Bob processed Alice&#39;s upda=
te. Then just as above (and regardless of anything else in the execution) c=
orrupting Bob reveals nothing about any epoch_secrets (or init_secrets) oth=
er than the ones currently held by Bob. So the Adversary breaks no other &q=
uot;epoch security&quot; (besides the one Bob is in at the time of corrupti=
on).<br><br>MLS: Assuming Bob processed Alice&#39;s update doesn&#39;t help=
 us like it did for RMLS because TreeKEM doesnt require him to then delete =
the keys he used. Instead, any keys Bob still has for processing handshake =
messages starting just before Alice&#39;s update let the adversary recover =
the corresponding update_secrets. So the adversary can ratchet the global k=
ey schedule forward through all those epochs (startin with init_secret[n-1]=
 she had from corrupting Alice).</div><div dir=3D"auto"><br></div><div dir=
=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">Suppose f=
inally, that we have neither global ordering nor did Bob ever process Alice=
&#39;s message.</div><div dir=3D"auto"><br>RMLS: For RMLS, this is the only=
 way that corrupting Bob can (potentially) help the adversary break &quot;e=
poch security&quot; for any epoch besides the one Bob is in during corrupti=
on. That is, it might be that Bob still has keys to proccess Alice&#39;s up=
date (and even some further sequences of handshake messages as long as they=
 depend directly on Alice&#39;s update. This works until the Adversary hits=
 the first handshake message in a sequence for which Bob doesn&#39;t have k=
eys to process.</div><div dir=3D"auto"><br></div><div dir=3D"auto">MLS: Fir=
st (and as in all cases) anything the adversary could compute for RMLS they=
 can compute for MLS too. So the above &quot;forking attack&quot; exhists f=
or MLS. But even here RMLS can behave better than MLS because RTreeKEM gene=
rally causes Bob to refresh his key material more frequently than TreeKEM.<=
/div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"au=
to">Let me know if this helps clarify stuff a bit.</div><div dir=3D"auto"><=
br></div><div dir=3D"auto">- Joel</div><div dir=3D"auto"><br><br></div><div=
 dir=3D"auto"><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr" clas=
s=3D"gmail_attr">On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, &lt;<a h=
ref=3D"mailto:karthik.bhargavan@gmail.com">karthik.bhargavan@gmail.com</a>&=
gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0=
 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style=3D"word-wrap:=
break-word;line-break:after-white-space">I must begin by saying that I have=
 been enjoying reading Alwen et al=E2=80=99s work [1] and they make some ex=
cellent points.<div>I particularly like the idea of using a primitive like =
UPKE (or SkuPke as [2] calls it) to improve the forward secrecy guarantees =
of TreeKEM.</div><div>If this can be made to work with standards-compliant =
EC implementations, we should definitely consider adding this mechanism to =
MLS.</div><div><br></div><div>For my own better understanding, however, I a=
m trying to figure out the exact forward secrecy improvement this will brin=
g to the protocol.</div><div>It is clear from [1] that the *update secret* =
and each *subgroup secret* in TreeKEM provides weak Forward Secrecy (since =
each update</div><div>only modifies one leaf key, leaving the attacker N-1 =
members to compromise.)</div><div><br></div><div>However, the public key pa=
rt of TreeKEM is only part of the Forward Secrecy story, we must also accou=
nt for the =E2=80=9Cinit_secret=E2=80=9D which</div><div>changes with every=
 update. As far as I can see, the discussion in [1] appears to ignore the =
=E2=80=9Cinit_secret -&gt; update_secret -&gt; epoch_secret+init_secret=E2=
=80=9D</div><div>ratchet which has always been part of MLS. So I don=E2=80=
=99t fully see how the attack of [1] works, and maybe someone can explain.<=
/div><div><br></div><div>One may argue that the goal of TreeKEM is to provi=
de FS and PCS for the epoch_secret, not the update_secret.</div><div>If eve=
ry member of the group is honest, then A sends an update , then B accepts t=
he update (ratcheting forward its init_secret),=C2=A0</div><div>and then B =
is compromised, then how can the attacker learn the new epoch secret?</div>=
<div><br></div><div>Perhaps we are worried about post-compromise forward se=
crecy (PCFS), but I don=E2=80=99t see any attack on that either.</div><div>=
It is likely I am missing something, so do chime in and explain.</div><div>=
<br></div><div>Best,</div><div>Karthik</div><div><br></div><div><br></div><=
div>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2019/1189.pdf" target=3D"_b=
lank" rel=3D"noreferrer">https://eprint.iacr.org/2019/1189.pdf</a></div><di=
v>[2]=C2=A0<a href=3D"https://eprint.iacr.org/2018/954" target=3D"_blank" r=
el=3D"noreferrer">https://eprint.iacr.org/2018/954</a></div></div>_________=
______________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" target=3D"_blank" rel=3D"noreferrer">MLS@ie=
tf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br=
>
</blockquote></div></div></div>

--000000000000fac969059634983c--


From nobody Thu Oct 31 06:54:39 2019
Return-Path: <jalwen@wickr.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F81F120044 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 06:54:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wickr-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PO4F6DoJe7Iw for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 06:54:33 -0700 (PDT)
Received: from mail-qt1-x836.google.com (mail-qt1-x836.google.com [IPv6:2607:f8b0:4864:20::836]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F140120048 for <mls@ietf.org>; Thu, 31 Oct 2019 06:54:33 -0700 (PDT)
Received: by mail-qt1-x836.google.com with SMTP id e14so8691558qto.1 for <mls@ietf.org>; Thu, 31 Oct 2019 06:54:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wickr-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=/EKNpgCWg38N/mkZCrAXNZJrFE+wCSZbVyP4sHbuJLQ=; b=0h+c+gY7HBYJQpTKeYPvAuJlwAmaDExIvdZp0PZPvhSsoob+NL8IfDkCKHOYNyr0+Y yDA7Yscuyl5sfLg91mo6A+b10b7ujSlS+ZIjp26W9F9jJPK4TcZZX7GI4DapW3YGQbgp oq5QMSjwXrImgY1Jd9WeeOC62uV56g7nHkqGu79lLydvumEIAbxv59gaS+ZfLdaIS71U vJrlYxvMEApH74OpxYMR22mIPWEL/IqO+bfKzEcmnJFYCpjk3PlFJ8YetWRChEX7DAYA lFd0IHaA1pAC/3t371B6jmaEgcJbFeODjvXuJUPx2CADI89n5Vn7byNE9AHnEyf1YPOs QraA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=/EKNpgCWg38N/mkZCrAXNZJrFE+wCSZbVyP4sHbuJLQ=; b=c4ocRSBadDu0pjT6e4BirTiPiDrL4SDcLWw+EEchnmEwBho13B5wFc3km8XV3chsMX 2x9/8PR2j11pz/Q12vAMl0ichJ0wCuvNoMzlNpPqlln90H3bNwyTcF86Kl4t6mn1ujSc USUYv9iGJloUcETR9DILU59/WkHo8DPvzvn3esZvXY/nBlxyuvs8aQbJgGnNOdIOZwTL oAIZeLnf5bEX2gqEDIAmEtkH4DUbSX4ktf+XLwYglqkGoMKXMRiZSFo9wWgD4f19f8Vq i+l3MG7b+TypfW5mcv/EpIUyhkPWraJ8ByeeGaRl0czV+aBsceo8+PDuUOzbMn2W73yD julw==
X-Gm-Message-State: APjAAAWChigR9JKNa3zPkoD0IvIqrfAbtKStyRhgvWIqDIQ4zM2LDyEP 7FGTnXy2pBgzPUZErXSbyqivA6ShXJHgedl/pABWGw==
X-Google-Smtp-Source: APXvYqz7WfGiEQqJU8jFLHOwiIsHBsf2TKpSUmKcyzgKMZnb59EL5sTIL7StiENmMsn6j+WLk/j+zv3KtmxjwLnzdQ0=
X-Received: by 2002:a0c:c78b:: with SMTP id k11mr4782450qvj.47.1572530072317;  Thu, 31 Oct 2019 06:54:32 -0700 (PDT)
MIME-Version: 1.0
References: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com> <CANYP603VS5iRtdG+n-TSsrVzynUMy4VqutSqjmWMzTYJiSaPgA@mail.gmail.com>
In-Reply-To: <CANYP603VS5iRtdG+n-TSsrVzynUMy4VqutSqjmWMzTYJiSaPgA@mail.gmail.com>
From: Joel Alwen <jalwen@wickr.com>
Date: Thu, 31 Oct 2019 14:51:39 +0100
Message-ID: <CANYP600nSwSAXDPu=3a-jCOxSKho5GWJ8=U79Nkh1zVFXqKH5w@mail.gmail.com>
To: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Cc: Messaging Layer Security WG <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000005c0af60596353050"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/Bb169THCDrZZ--Kt9jyDLFORxsk>
Subject: Re: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 13:54:38 -0000

--0000000000005c0af60596353050
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Crap. Sent that last email to soon. Here are some correction.

The concern is not just Bob leaking keys that *directly* allow processing
Alice's (and subsequent) updates as described in my previous email. As
pointed out in the thread introducing RTreeKEM, there are only log(n) such
keys for any given update (assuming no blanks). Unfortunately, we must also
ensure that Bob leaks no keys that allow recovering other keys (from past
network traffic) that in turn then allow proccessing Alice's (or other)
updates. And so on and so forth. So there are really about n/2 keys to
worry about for any given update not just the log(n) that allow processing
the update.

IMO this accentuates the gap bewteen the PCFS guarantees of MLS and RMLS as
the former refreshes those critical keys slower than RMLS. The more
critical keys the worse for MLS in some sense.

As an aside: Its also worth noting that its probably pretty clear to the
adversary who still has which keys in their state just by watching the
encrypted network traffic making it easier to select the right target for
compromising a target epoch.

- Jo=C3=ABl

On Thu, 31 Oct 2019, 14:12 Joel Alwen, <jalwen@wickr.com> wrote:

> Hey,
>
> Yeah, we should have been more explicite about how this all plays out for
> MLS. Good that you asked. :-)
>
> "PCFS" is exactly the term we were using to talk about how change from
> TreeKEM -> RTreeKEM affects MLS. In a nutshell, FS for epochs after a
> compromise is healed (with an update) takes no less but (potentially quit=
e
> a bit) longer to kick in for "MLS" (MLS+TreeKEM) than for "RMLS"
> (MLS+RTreeKEM).
>
> Here's an example scenario that highlights the difference for MLS.
>
> Suppose Alice's state leaked in the past and now she does an update
> defining epoch_secret[i]. Intuitively, until the next corruption (say of
> Bob when he's in epoch j>i) we'd like that all epoch_secrets in [i,j)
> remain secure. (This property is what we've informally been calling PCFS.
> I.e. Forward Security for epochs after a compromise.) We consider what
> security we get for (R)MLS.
>
> MLS: Assume (for a moment) all handshake messages are delivered in the
> same order to all group messages. Because TreeKEM lets Bob keep HPKE keys
> around even after using them Bob could still have the keys to process
> Alice's update. Whether this is true or not depends on who's update betwe=
en
> [i,j) and their, Alice and Bob's possitions in the ratchet tree. To
> guarantee Bob doesn't have said keys we'd need to know e.g. Bob updated
> between [i,j) or someone strictly closer to Bob than Alice has updated.
> (Closer =3D shorter path ratchet tree from Bob's leaf to Charlie's leaf t=
han
> from Alice's leaf to Charlie's.)
>
> RMLS: Now consider RMLS when the same assumption holds. All epoch_secrets
> in [i,j) remain secure even after Bob's compromise because Bob already
> deleted any keys he had that can proccess Alice's update. In more detail:
> the adversary knows init_secret[n-1] (from having corrupted Alice). So to
> get epoch_secret[n] she still needs update_secret[n] defined by Alice's
> update. By assumption Bob processed that update himself. So RTreeKEM (but
> not TreeKEM) guarantees Bob no longer has the keys to re-process it. Thus=
,
> corrupting him doesnt let the adversary recover epoch_secret[i] (nor any
> ones after that since its always missing at least the required init_secre=
t).
>
>
>
> Now lets consider what happens if the global ordering assumption doesn't
> hold.
>
> RMLS: Suppose we know only that Bob processed Alice's update. Then just a=
s
> above (and regardless of anything else in the execution) corrupting Bob
> reveals nothing about any epoch_secrets (or init_secrets) other than the
> ones currently held by Bob. So the Adversary breaks no other "epoch
> security" (besides the one Bob is in at the time of corruption).
>
> MLS: Assuming Bob processed Alice's update doesn't help us like it did fo=
r
> RMLS because TreeKEM doesnt require him to then delete the keys he used.
> Instead, any keys Bob still has for processing handshake messages startin=
g
> just before Alice's update let the adversary recover the corresponding
> update_secrets. So the adversary can ratchet the global key schedule
> forward through all those epochs (startin with init_secret[n-1] she had
> from corrupting Alice).
>
>
>
> Suppose finally, that we have neither global ordering nor did Bob ever
> process Alice's message.
>
> RMLS: For RMLS, this is the only way that corrupting Bob can (potentially=
)
> help the adversary break "epoch security" for any epoch besides the one B=
ob
> is in during corruption. That is, it might be that Bob still has keys to
> proccess Alice's update (and even some further sequences of handshake
> messages as long as they depend directly on Alice's update. This works
> until the Adversary hits the first handshake message in a sequence for
> which Bob doesn't have keys to process.
>
> MLS: First (and as in all cases) anything the adversary could compute for
> RMLS they can compute for MLS too. So the above "forking attack" exhists
> for MLS. But even here RMLS can behave better than MLS because RTreeKEM
> generally causes Bob to refresh his key material more frequently than
> TreeKEM.
>
>
> Let me know if this helps clarify stuff a bit.
>
> - Joel
>
>
> On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, <
> karthik.bhargavan@gmail.com> wrote:
>
>> I must begin by saying that I have been enjoying reading Alwen et al=E2=
=80=99s
>> work [1] and they make some excellent points.
>> I particularly like the idea of using a primitive like UPKE (or SkuPke a=
s
>> [2] calls it) to improve the forward secrecy guarantees of TreeKEM.
>> If this can be made to work with standards-compliant EC implementations,
>> we should definitely consider adding this mechanism to MLS.
>>
>> For my own better understanding, however, I am trying to figure out the
>> exact forward secrecy improvement this will bring to the protocol.
>> It is clear from [1] that the *update secret* and each *subgroup secret*
>> in TreeKEM provides weak Forward Secrecy (since each update
>> only modifies one leaf key, leaving the attacker N-1 members to
>> compromise.)
>>
>> However, the public key part of TreeKEM is only part of the Forward
>> Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=80=
=9D which
>> changes with every update. As far as I can see, the discussion in [1]
>> appears to ignore the =E2=80=9Cinit_secret -> update_secret ->
>> epoch_secret+init_secret=E2=80=9D
>> ratchet which has always been part of MLS. So I don=E2=80=99t fully see =
how the
>> attack of [1] works, and maybe someone can explain.
>>
>> One may argue that the goal of TreeKEM is to provide FS and PCS for the
>> epoch_secret, not the update_secret.
>> If every member of the group is honest, then A sends an update , then B
>> accepts the update (ratcheting forward its init_secret),
>> and then B is compromised, then how can the attacker learn the new epoch
>> secret?
>>
>> Perhaps we are worried about post-compromise forward secrecy (PCFS), but
>> I don=E2=80=99t see any attack on that either.
>> It is likely I am missing something, so do chime in and explain.
>>
>> Best,
>> Karthik
>>
>>
>> [1] https://eprint.iacr.org/2019/1189.pdf
>> [2] https://eprint.iacr.org/2018/954
>> _______________________________________________
>> MLS mailing list
>> MLS@ietf.org
>> https://www.ietf.org/mailman/listinfo/mls
>>
>

--0000000000005c0af60596353050
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Crap. Sent that last email to soon. Here are some correct=
ion.<div dir=3D"auto"><br></div><div dir=3D"auto">The concern is not just B=
ob leaking keys that *directly* allow processing Alice&#39;s (and subsequen=
t) updates as described in my previous email. As pointed out in the thread =
introducing RTreeKEM, there are only log(n) such keys for any given update =
(assuming no blanks). Unfortunately, we must also ensure that Bob leaks no =
keys that allow recovering other keys (from past network traffic) that in t=
urn then allow proccessing Alice&#39;s (or other) updates. And so on and so=
 forth. So there are really about n/2 keys to worry about for any given upd=
ate not just the log(n) that allow processing the update.</div><div dir=3D"=
auto"><br></div><div dir=3D"auto">IMO this accentuates the gap bewteen the =
PCFS guarantees of MLS and RMLS as the former refreshes those critical keys=
 slower than RMLS. The more critical keys the worse for MLS in some sense.<=
/div><div dir=3D"auto"><br></div><div dir=3D"auto">As an aside: Its also wo=
rth noting that its probably pretty clear to the adversary who still has wh=
ich keys in their state just by watching the encrypted network traffic maki=
ng it easier to select the right target for compromising a target epoch.</d=
iv><div dir=3D"auto"><br></div><div dir=3D"auto">- Jo=C3=ABl</div></div><br=
><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 3=
1 Oct 2019, 14:12 Joel Alwen, &lt;<a href=3D"mailto:jalwen@wickr.com">jalwe=
n@wickr.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=
=3D"auto"><div>Hey,</div><div dir=3D"auto"><br></div><div dir=3D"auto">Yeah=
, we should have been more explicite about how this all plays out for MLS. =
Good that you asked. :-)<br><br>&quot;PCFS&quot; is exactly the term we wer=
e using to talk about how change from TreeKEM -&gt; RTreeKEM affects MLS. I=
n a nutshell, FS for epochs after a compromise is healed (with an update) t=
akes no less but (potentially quite a bit) longer to kick in for &quot;MLS&=
quot; (MLS+TreeKEM) than for &quot;RMLS&quot; (MLS+RTreeKEM).<br><br>Here&#=
39;s an example scenario that highlights the difference for MLS.<br><br>Sup=
pose Alice&#39;s state leaked in the past and now she does an update defini=
ng epoch_secret[i]. Intuitively, until the next corruption (say of Bob when=
 he&#39;s in epoch j&gt;i) we&#39;d like that all epoch_secrets in [i,j) re=
main secure. (This property is what we&#39;ve informally been calling PCFS.=
 I.e. Forward Security for epochs after a compromise.) We consider what sec=
urity we get for (R)MLS.<br><br>MLS: Assume (for a moment) all handshake me=
ssages are delivered in the same order to all group messages. Because TreeK=
EM lets Bob keep HPKE keys around even after using them Bob could still hav=
e the keys to process Alice&#39;s update. Whether this is true or not depen=
ds on who&#39;s update between [i,j) and their, Alice and Bob&#39;s possiti=
ons in the ratchet tree. To guarantee Bob doesn&#39;t have said keys we&#39=
;d need to know e.g. Bob updated between [i,j) or someone strictly closer t=
o Bob than Alice has updated. (Closer =3D shorter path ratchet tree from Bo=
b&#39;s leaf to Charlie&#39;s leaf than from Alice&#39;s leaf to Charlie&#3=
9;s.)=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"auto">RMLS: Now co=
nsider RMLS when the same assumption holds. All epoch_secrets in [i,j) rema=
in secure even after Bob&#39;s compromise because Bob already deleted any k=
eys he had that can proccess Alice&#39;s update. In more detail: the advers=
ary knows init_secret[n-1] (from having corrupted Alice). So to get epoch_s=
ecret[n] she still needs update_secret[n] defined by Alice&#39;s update. By=
 assumption Bob processed that update himself. So RTreeKEM (but not TreeKEM=
) guarantees Bob no longer has the keys to re-process it. Thus, corrupting =
him doesnt let the adversary recover epoch_secret[i] (nor any ones after th=
at since its always missing at least the required init_secret).</div><div d=
ir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></d=
iv><div dir=3D"auto">Now lets consider what happens if the global ordering =
assumption doesn&#39;t hold.</div><div dir=3D"auto"><br></div><div dir=3D"a=
uto">RMLS: Suppose we know only that Bob processed Alice&#39;s update. Then=
 just as above (and regardless of anything else in the execution) corruptin=
g Bob reveals nothing about any epoch_secrets (or init_secrets) other than =
the ones currently held by Bob. So the Adversary breaks no other &quot;epoc=
h security&quot; (besides the one Bob is in at the time of corruption).<br>=
<br>MLS: Assuming Bob processed Alice&#39;s update doesn&#39;t help us like=
 it did for RMLS because TreeKEM doesnt require him to then delete the keys=
 he used. Instead, any keys Bob still has for processing handshake messages=
 starting just before Alice&#39;s update let the adversary recover the corr=
esponding update_secrets. So the adversary can ratchet the global key sched=
ule forward through all those epochs (startin with init_secret[n-1] she had=
 from corrupting Alice).</div><div dir=3D"auto"><br></div><div dir=3D"auto"=
><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">Suppose finally, t=
hat we have neither global ordering nor did Bob ever process Alice&#39;s me=
ssage.</div><div dir=3D"auto"><br>RMLS: For RMLS, this is the only way that=
 corrupting Bob can (potentially) help the adversary break &quot;epoch secu=
rity&quot; for any epoch besides the one Bob is in during corruption. That =
is, it might be that Bob still has keys to proccess Alice&#39;s update (and=
 even some further sequences of handshake messages as long as they depend d=
irectly on Alice&#39;s update. This works until the Adversary hits the firs=
t handshake message in a sequence for which Bob doesn&#39;t have keys to pr=
ocess.</div><div dir=3D"auto"><br></div><div dir=3D"auto">MLS: First (and a=
s in all cases) anything the adversary could compute for RMLS they can comp=
ute for MLS too. So the above &quot;forking attack&quot; exhists for MLS. B=
ut even here RMLS can behave better than MLS because RTreeKEM generally cau=
ses Bob to refresh his key material more frequently than TreeKEM.</div><div=
 dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">Let m=
e know if this helps clarify stuff a bit.</div><div dir=3D"auto"><br></div>=
<div dir=3D"auto">- Joel</div><div dir=3D"auto"><br><br></div><div dir=3D"a=
uto"><div class=3D"gmail_quote" dir=3D"auto"><div dir=3D"ltr" class=3D"gmai=
l_attr">On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, &lt;<a href=3D"ma=
ilto:karthik.bhargavan@gmail.com" target=3D"_blank" rel=3D"noreferrer">kart=
hik.bhargavan@gmail.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_=
quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1=
ex"><div style=3D"word-wrap:break-word;line-break:after-white-space">I must=
 begin by saying that I have been enjoying reading Alwen et al=E2=80=99s wo=
rk [1] and they make some excellent points.<div>I particularly like the ide=
a of using a primitive like UPKE (or SkuPke as [2] calls it) to improve the=
 forward secrecy guarantees of TreeKEM.</div><div>If this can be made to wo=
rk with standards-compliant EC implementations, we should definitely consid=
er adding this mechanism to MLS.</div><div><br></div><div>For my own better=
 understanding, however, I am trying to figure out the exact forward secrec=
y improvement this will bring to the protocol.</div><div>It is clear from [=
1] that the *update secret* and each *subgroup secret* in TreeKEM provides =
weak Forward Secrecy (since each update</div><div>only modifies one leaf ke=
y, leaving the attacker N-1 members to compromise.)</div><div><br></div><di=
v>However, the public key part of TreeKEM is only part of the Forward Secre=
cy story, we must also account for the =E2=80=9Cinit_secret=E2=80=9D which<=
/div><div>changes with every update. As far as I can see, the discussion in=
 [1] appears to ignore the =E2=80=9Cinit_secret -&gt; update_secret -&gt; e=
poch_secret+init_secret=E2=80=9D</div><div>ratchet which has always been pa=
rt of MLS. So I don=E2=80=99t fully see how the attack of [1] works, and ma=
ybe someone can explain.</div><div><br></div><div>One may argue that the go=
al of TreeKEM is to provide FS and PCS for the epoch_secret, not the update=
_secret.</div><div>If every member of the group is honest, then A sends an =
update , then B accepts the update (ratcheting forward its init_secret),=C2=
=A0</div><div>and then B is compromised, then how can the attacker learn th=
e new epoch secret?</div><div><br></div><div>Perhaps we are worried about p=
ost-compromise forward secrecy (PCFS), but I don=E2=80=99t see any attack o=
n that either.</div><div>It is likely I am missing something, so do chime i=
n and explain.</div><div><br></div><div>Best,</div><div>Karthik</div><div><=
br></div><div><br></div><div>[1]=C2=A0<a href=3D"https://eprint.iacr.org/20=
19/1189.pdf" rel=3D"noreferrer noreferrer" target=3D"_blank">https://eprint=
.iacr.org/2019/1189.pdf</a></div><div>[2]=C2=A0<a href=3D"https://eprint.ia=
cr.org/2018/954" rel=3D"noreferrer noreferrer" target=3D"_blank">https://ep=
rint.iacr.org/2018/954</a></div></div>_____________________________________=
__________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" rel=3D"noreferrer noreferrer" target=3D"_bl=
ank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer noreferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo=
/mls</a><br>
</blockquote></div></div></div>
</blockquote></div>

--0000000000005c0af60596353050--


From nobody Thu Oct 31 07:42:41 2019
Return-Path: <pjunod@snapchat.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 315451200FF for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 07:42:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.748
X-Spam-Level: 
X-Spam-Status: No, score=-1.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=snap.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SNdrGBsKxrDv for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 07:42:38 -0700 (PDT)
Received: from mail-il1-x136.google.com (mail-il1-x136.google.com [IPv6:2607:f8b0:4864:20::136]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 044B21200B8 for <mls@ietf.org>; Thu, 31 Oct 2019 07:42:38 -0700 (PDT)
Received: by mail-il1-x136.google.com with SMTP id p8so5615182ilp.2 for <mls@ietf.org>; Thu, 31 Oct 2019 07:42:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snap.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=6ubR83+FjiWON+kjODzjw3sLoEsKqfW82LWILa2ervg=; b=T0xdxnAkMnsLaKa/J3UZef0s0bCMuYNnw0wTeKUAZGD+Lo+pCwEjeA4q24Ht9nnbJG 8U5C9pg8KbRBVaAJbB8aNXqfMNhjs2TcEW5WEicURE8F9x5BkYjPnXabVpnzTZmEbgQj fcjoXW8Z9RGv1WVFMIgpD0bDuHBTwjIpzBFBA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=6ubR83+FjiWON+kjODzjw3sLoEsKqfW82LWILa2ervg=; b=Nc35gZkRlx57sq5V6gGz4RKtKXs9etyRdGV+bX4uLmj8xcNznq3UFusyVlddRPudy4 CZX7kVKpbM4W+L4+CqOOblvZoYpIkYx5gh4vu4eTWPYuDBDvWz0Vqns9nABUG28gkub8 FhX/dplxUayiIMgn1gWcYvQidx9VlRNEMZ5GilNAgqv/6tmc7nZ2+i67++iMTULon518 o9HSm0R/e6J/cx96TkkNLCV3ffKMKQoMXVG6b9c5MKH4DH1XAC5XetIEHs/y1jiYKp7m 7x+2ps81YL2p02oo2dZrTKGUwPD3mo8kgbc6VWWYjpBpM0w4N8ZnLlEDrNpEPwkwnqWu nZHQ==
X-Gm-Message-State: APjAAAWKVzV4UBtWx52kYGH/TSVA4skW6l+k0RY/juGO73DNwGTGIqdI 7qO5Rtp3LbmzQnuM+kMTrTAwc8xfuJ6+2Vt46uFtCQ==
X-Google-Smtp-Source: APXvYqzkauAYYjwKdmu6lEiG6ijTvfX9XC6IjSUBdFmbD6RdvvposeD9LZhP+RcENXRQVYfOf+76+6YQkrM1H6b+bgc=
X-Received: by 2002:a92:db0c:: with SMTP id b12mr6611919iln.71.1572532950569;  Thu, 31 Oct 2019 07:42:30 -0700 (PDT)
MIME-Version: 1.0
References: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com> <24F9C4C5-EC56-4C77-8940-E2BF828F6265@inria.fr>
In-Reply-To: <24F9C4C5-EC56-4C77-8940-E2BF828F6265@inria.fr>
From: Pascal Junod <pascalj@snap.com>
Date: Thu, 31 Oct 2019 15:42:19 +0100
Message-ID: <CAPOUjt7=a6PMVr+37J5s5reOUUzH7WanU8nBMFRxGXhavi8OGA@mail.gmail.com>
To: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Cc: ML Messaging Layer Security <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000eac8ba059635db92"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/UEKJE0Vl54b9flevPCllevwL2ss>
Subject: Re: [MLS] [Metadata encryption]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 14:42:39 -0000

--000000000000eac8ba059635db92
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Benjamin ! Thank you for you answer. Actually, it does not really
answer my initial question, so let me be more specific:

 - starting from the sender_data_key (computed in a deterministic way from
the group secret) and a randomly generated (for obvious nonce-reuse-related
reasons) sender_data_nonce, we would like to encrypt sender metadata using
the AEAD scheme (which is AES128-GCM in both currently supported
ciphersuites).

- An AES-GCM API takes a key, a nonce, data to be encrypted, and additional
data to be authenticated, but not encrypted.

- The data to be encrypted are the ones contained in the MLSSenderData
structure (senderID + generation)

- The additional data to be authenticated are the ones contained in the
MLSCiphertextSenderDataAAD structure (group_id, epoch, content_type and
sender_data_nonce).

Why is the MLSCiphertextSenderDataAAD structure containing the
sender_data_nonce ? That nonce will in any case "influence" the AES-GCM
authentication tag, so there is no need to repeat it as attached data to be
authenticated, isn't it ? What did I miss ?

A+

Pascal

On Thu, Oct 31, 2019 at 12:50 PM Benjamin Beurdouche <
benjamin.beurdouche@inria.fr> wrote:

> Hi Pascal !
>
>
> I have a question regarding the current draft and related to section 8.1:
> what is the purpose of including the sender_data_nonce into the attached
> data? To cover AEAD schemes relying on a non-randomized MAC, like, e.g., =
an
> AES-CBC-HMAC construction ? Are there plans to support ciphersuites of th=
is
> type in the future ?
>
>
>
> To decrypt messages, a member must
> 1. Look at the group_id and the epoch number to find the correct secrets
> to decrypt in its local state.
> 2. Determine which sender encrypted the message.
> 3. Compute or retrieve the correct sender-specific decryption key from it=
s
> state.
>
> Since we want to protect the sender data for privacy reason, we have to
> encrypt
> it under a group key. That group key is outputed by the key schedule so i=
s
> fully deterministic
> and independent of the sender that will encrypt. Since everybody could us=
e
> that key,
> we want to avoid them to also use a deterministic nonce, so we use a
> random nonce
> that we have to prepend in the header of the message.
>
> Most, if not all other messages are encrypted under member specific keys
> in MLS,
> so nonce reuse is less of a problem except in the case state loss and we
> have a pending fix for it=E2=80=A6 : )
>
> Does this make sense ?
> Best,
>
> Benjamin
>

--000000000000eac8ba059635db92
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Benjamin ! Thank you for you answer. Actually, it does =
not really answer=C2=A0my initial question, so let me be more=C2=A0specific=
:<div><br></div><div>=C2=A0- starting from the <font face=3D"monospace">sen=
der_data_key</font> (computed in a deterministic way from the group secret)=
 and a randomly generated (for obvious nonce-reuse-related reasons) <font f=
ace=3D"monospace">sender_data_nonce</font>, we would like to encrypt sender=
 metadata using the AEAD scheme (which is AES128-GCM in both currently supp=
orted ciphersuites).=C2=A0</div><div><br></div><div>- An AES-GCM API takes =
a key, a nonce, data to be encrypted, and additional data to be authenticat=
ed, but not encrypted.</div><div><br></div><div>- The data to be encrypted=
=C2=A0are the ones contained in the <font face=3D"monospace">MLSSenderData<=
/font> structure (<font face=3D"monospace">senderID</font> + <font face=3D"=
monospace">generation</font>)<br><br>- The additional data to be authentica=
ted are the ones contained in the <font face=3D"monospace">MLSCiphertextSen=
derDataAAD</font> structure (<font face=3D"monospace">group_id</font>, <fon=
t face=3D"monospace">epoch</font>, <font face=3D"monospace">content_type</f=
ont> and <font face=3D"monospace" color=3D"#ff0000">sender_data_nonce</font=
>). <br></div><div><br></div><div>Why is the=C2=A0<font face=3D"monospace">=
MLSCiphertextSenderDataAAD</font> structure containing the <font face=3D"mo=
nospace">sender_data_nonce</font> ? That nonce will in any case &quot;influ=
ence&quot; the AES-GCM authentication tag, so there is no need to repeat it=
 as attached data to be authenticated, isn&#39;t it ? What did I miss ?</di=
v><div><br></div><div>A+</div><div><br>Pascal</div></div><br><div class=3D"=
gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Oct 31, 2019 at =
12:50 PM Benjamin Beurdouche &lt;<a href=3D"mailto:benjamin.beurdouche@inri=
a.fr">benjamin.beurdouche@inria.fr</a>&gt; wrote:<br></div><blockquote clas=
s=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid r=
gb(204,204,204);padding-left:1ex"><div style=3D"overflow-wrap: break-word;"=
>Hi Pascal !<div><br></div><div><br><div><div><blockquote type=3D"cite"><di=
v><div dir=3D"ltr"><div>I have a question regarding the current draft and r=
elated to section 8.1: what is the purpose of including the <font face=3D"m=
onospace">sender_data_nonce</font> into the attached data? To cover AEAD sc=
hemes relying on a non-randomized MAC, like, e.g., an AES-CBC-HMAC construc=
tion ? Are there plans to support ciphersuites of this type in the future ?=
</div></div></div></blockquote><br></div><div><br></div><div>To decrypt mes=
sages, a member must</div><div>1. Look at the group_id and the epoch number=
 to find the correct secrets to decrypt in its local state.</div><div>2. De=
termine which sender encrypted the message.</div><div>3. Compute or retriev=
e the correct sender-specific decryption key from its state.</div><div><br>=
</div><div>Since we want to protect the sender data for privacy reason, we =
have to encrypt</div></div></div><div>it under a group key. That group key =
is outputed by the key schedule so is fully deterministic</div><div>and ind=
ependent of the sender that will encrypt. Since everybody could use that ke=
y,</div><div>we want to avoid them to also use a deterministic nonce, so we=
 use a random nonce</div><div>that we have to prepend in the header of the =
message.</div><div><br></div><div>Most, if not all other messages are encry=
pted under member specific keys in MLS,=C2=A0</div><div>so nonce reuse is l=
ess of a problem except in the case state loss and we have a pending fix fo=
r it=E2=80=A6 : )</div><div><br></div><div>Does this make sense ?</div><div=
>Best,</div><div><br></div><div>Benjamin</div></div></blockquote></div>

--000000000000eac8ba059635db92--


From nobody Thu Oct 31 08:32:38 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B3B93120811 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 08:32:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.203
X-Spam-Level: ***
X-Spam-Status: No, score=3.203 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DC_PNG_UNO_LARGO=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_SBL=10, URIBL_SBL_A=0.1] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ete_-exAfuJM for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 08:32:33 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D1DA12081C for <mls@ietf.org>; Thu, 31 Oct 2019 08:32:31 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.68,252,1569276000";  d="png'150?scan'150,208,217,150";a="409819260"
Received: from aannecy-653-1-78-207.w90-41.abo.wanadoo.fr (HELO pc54.home) ([90.41.199.207]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 31 Oct 2019 16:32:29 +0100
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
Message-Id: <034A69CB-4C6D-4247-A04C-691A514BDD9E@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_E0F631DC-BFB8-4FA0-BB94-E419674A60D8"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
Date: Thu, 31 Oct 2019 16:32:28 +0100
In-Reply-To: <CAPOUjt7=a6PMVr+37J5s5reOUUzH7WanU8nBMFRxGXhavi8OGA@mail.gmail.com>
Cc: ML Messaging Layer Security <mls@ietf.org>
To: Pascal Junod <pascalj@snap.com>
References: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com> <24F9C4C5-EC56-4C77-8940-E2BF828F6265@inria.fr> <CAPOUjt7=a6PMVr+37J5s5reOUUzH7WanU8nBMFRxGXhavi8OGA@mail.gmail.com>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/DVKyAyQlDAUeE4BG4jEI0yC5bHk>
Subject: Re: [MLS] [Metadata encryption]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 15:32:35 -0000

--Apple-Mail=_E0F631DC-BFB8-4FA0-BB94-E419674A60D8
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8



> On Oct 31, 2019, at 3:42 PM, Pascal Junod <pascalj@snap.com> wrote:
>=20
> Hi Benjamin ! Thank you for you answer. Actually, it does not really =
answer my initial question, so let me be more specific:
>=20
>  - starting from the sender_data_key (computed in a deterministic way =
from the group secret) and a randomly generated (for obvious =
nonce-reuse-related reasons) sender_data_nonce, we would like to encrypt =
sender metadata using the AEAD scheme (which is AES128-GCM in both =
currently supported ciphersuites).=20
>=20
> - An AES-GCM API takes a key, a nonce, data to be encrypted, and =
additional data to be authenticated, but not encrypted.
>=20
> - The data to be encrypted are the ones contained in the MLSSenderData =
structure (senderID + generation)
>=20
> - The additional data to be authenticated are the ones contained in =
the MLSCiphertextSenderDataAAD structure (group_id, epoch, content_type =
and sender_data_nonce).=20
>=20
> Why is the MLSCiphertextSenderDataAAD structure containing the =
sender_data_nonce ? That nonce will in any case "influence" the AES-GCM =
authentication tag, so there is no need to repeat it as attached data to =
be authenticated, isn't it ? What did I miss ?

Ah, ok sorry I am a bit exhausted=E2=80=A6
Since we have to send the fresh nonce for the recipient to decrypt the =
encrypted sender_data
we place it in the header. If you look at the message format on the =
wire, we have the practice of
authenticating the entire prefix of what=E2=80=99s encrypted (because we =
can).


Hopefully the visualization will help here (don=E2=80=99t mind new field =
it is a thing we introduced in PR208).

The nice thing of doing that is that you don=E2=80=99t have to =
=E2=80=9Cconstruct=E2=80=9D the AADs, they already are right there for =
you.

Does that help ? (Hopefully I understood this time xD... )
Best,

Benjamin=

--Apple-Mail=_E0F631DC-BFB8-4FA0-BB94-E419674A60D8
Content-Type: multipart/related; type="text/html";
 boundary="Apple-Mail=_4D42D4EB-0D29-444B-AA3A-7926F7CBB905"


--Apple-Mail=_4D42D4EB-0D29-444B-AA3A-7926F7CBB905
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><br =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Oct 31, 2019, at 3:42 PM, Pascal Junod &lt;<a =
href=3D"mailto:pascalj@snap.com" class=3D"">pascalj@snap.com</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
dir=3D"ltr" class=3D"">Hi Benjamin ! Thank you for you answer. Actually, =
it does not really answer&nbsp;my initial question, so let me be =
more&nbsp;specific:<div class=3D""><br class=3D""></div><div =
class=3D"">&nbsp;- starting from the <font face=3D"monospace" =
class=3D"">sender_data_key</font> (computed in a deterministic way from =
the group secret) and a randomly generated (for obvious =
nonce-reuse-related reasons) <font face=3D"monospace" =
class=3D"">sender_data_nonce</font>, we would like to encrypt sender =
metadata using the AEAD scheme (which is AES128-GCM in both currently =
supported ciphersuites).&nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">- An AES-GCM API takes a key, a nonce, =
data to be encrypted, and additional data to be authenticated, but not =
encrypted.</div><div class=3D""><br class=3D""></div><div class=3D"">- =
The data to be encrypted&nbsp;are the ones contained in the <font =
face=3D"monospace" class=3D"">MLSSenderData</font> structure (<font =
face=3D"monospace" class=3D"">senderID</font> + <font face=3D"monospace" =
class=3D"">generation</font>)<br class=3D""><br class=3D"">- The =
additional data to be authenticated are the ones contained in the <font =
face=3D"monospace" class=3D"">MLSCiphertextSenderDataAAD</font> =
structure (<font face=3D"monospace" class=3D"">group_id</font>, <font =
face=3D"monospace" class=3D"">epoch</font>, <font face=3D"monospace" =
class=3D"">content_type</font> and <font face=3D"monospace" =
color=3D"#ff0000" class=3D"">sender_data_nonce</font>). <br =
class=3D""></div><div class=3D""><br class=3D""></div><div class=3D"">Why =
is the&nbsp;<font face=3D"monospace" =
class=3D"">MLSCiphertextSenderDataAAD</font> structure containing the =
<font face=3D"monospace" class=3D"">sender_data_nonce</font> ? That =
nonce will in any case "influence" the AES-GCM authentication tag, so =
there is no need to repeat it as attached data to be authenticated, =
isn't it ? What did I miss ?</div></div></div></blockquote><br =
class=3D""></div><div>Ah, ok sorry I am a bit =
exhausted=E2=80=A6</div><div>Since we have to send the fresh nonce for =
the recipient to decrypt the encrypted sender_data</div><div>we place it =
in the header. If you look at the message format on the wire, we have =
the practice of</div><div>authenticating the entire prefix of what=E2=80=99=
s encrypted (because we can).</div><div><img apple-inline=3D"yes" =
id=3D"9510556C-24BD-49D0-8AAF-EFA6627834C5" width=3D"640" height=3D"167" =
src=3D"cid:0EB3024B-A54F-4143-8C08-3E68ED579458@home" =
class=3D""></div><div><br class=3D""></div><div>Hopefully the =
visualization will help here (don=E2=80=99t mind new field it is a thing =
we introduced in PR208).</div><div><br class=3D""></div><div>The nice =
thing of doing that is that you don=E2=80=99t have to =E2=80=9Cconstruct=E2=
=80=9D the AADs, they already are right there for you.</div><div><br =
class=3D""></div><div>Does that help ? (Hopefully I understood this time =
xD... )</div><div>Best,</div><div><br =
class=3D""></div><div>Benjamin</div></body></html>=

--Apple-Mail=_4D42D4EB-0D29-444B-AA3A-7926F7CBB905
Content-Transfer-Encoding: base64
Content-Disposition: inline;
 filename="Screen Shot 2019-10-31 at 4.27.15 PM.png"
Content-Type: image/png;
	name="Screen Shot 2019-10-31 at 4.27.15 PM.png"
Content-Id: <0EB3024B-A54F-4143-8C08-3E68ED579458@home>

iVBORw0KGgoAAAANSUhEUgAABQAAAAFMCAYAAACUMRHzAAAAAXNSR0IArs4c6QAAAJZlWElmTU0A
KgAAAAgABAEaAAUAAAABAAAAPgEbAAUAAAABAAAARgEoAAMAAAABAAIAAIdpAAQAAAABAAAATgAA
AAAAAACQAAAAAQAAAJAAAAABAASShgAHAAAAEgAAAISgAQADAAAAAQABAACgAgAEAAAAAQAABQCg
AwAEAAAAAQAAAUwAAAAAQVNDSUkAAABTY3JlZW5zaG90scFwIAAAAAlwSFlzAAAWJQAAFiUBSVIk
8AAAAqhpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6
bnM6bWV0YS8iIHg6eG1wdGs9IlhNUCBDb3JlIDUuNC4wIj4KICAgPHJkZjpSREYgeG1sbnM6cmRm
PSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4KICAgICAgPHJk
ZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIKICAgICAgICAgICAgeG1sbnM6ZXhpZj0iaHR0cDov
L25zLmFkb2JlLmNvbS9leGlmLzEuMC8iCiAgICAgICAgICAgIHhtbG5zOnRpZmY9Imh0dHA6Ly9u
cy5hZG9iZS5jb20vdGlmZi8xLjAvIj4KICAgICAgICAgPGV4aWY6VXNlckNvbW1lbnQ+U2NyZWVu
c2hvdDwvZXhpZjpVc2VyQ29tbWVudD4KICAgICAgICAgPGV4aWY6UGl4ZWxYRGltZW5zaW9uPjEz
MjY8L2V4aWY6UGl4ZWxYRGltZW5zaW9uPgogICAgICAgICA8ZXhpZjpQaXhlbFlEaW1lbnNpb24+
MzQ0PC9leGlmOlBpeGVsWURpbWVuc2lvbj4KICAgICAgICAgPHRpZmY6WFJlc29sdXRpb24+MTQ0
PC90aWZmOlhSZXNvbHV0aW9uPgogICAgICAgICA8dGlmZjpSZXNvbHV0aW9uVW5pdD4yPC90aWZm
OlJlc29sdXRpb25Vbml0PgogICAgICAgICA8dGlmZjpZUmVzb2x1dGlvbj4xNDQ8L3RpZmY6WVJl
c29sdXRpb24+CiAgICAgIDwvcmRmOkRlc2NyaXB0aW9uPgogICA8L3JkZjpSREY+CjwveDp4bXBt
ZXRhPgqMQtJGAABAAElEQVR4Aezdd7xlVX3//z3DIL1KV2CQLtUKKAoWBAv22EWi2GJJzCMmj6h/
/P5Ivn8keST5Q2OMBTuoqKhYUcEuIChgoUkVEZHe6/zOc+GH7BzOnbkzc+fee859r3mcOefusspr
rfXZa733Z+29aPfdd1923nnndQkhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAKTR2DxsmXLJq9U
KVEIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAjsDgcQiAEQiAEQiAEQiAEQiAEQiAEQiAEQiAE
QiAEJpdABMDJrduULARCIARCIARCIARCIARCIARCIARCIARCIAS6CIBpBCEQAiEQAiEQAiEQAiEQ
AiEQAiEQAiEQAiEwwQQWL1q0aIKLl6KFQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEwMImEA/AhV3/
KX0IhEAIhEAIhEAIhEAIhEAIhEAIhEAIhMCEE4gAOOEVnOKFQAiEQAiEQAiEQAiEQAiEQAiEQAiE
QAgsbAIRABd2/af0IRACIRACIRACIRACIRACIRACIRACIRACE04gAuCEV3CKFwIhEAIhEAIhEAIh
EAIhEAIhEAIhEAIhsLAJRABc2PWf0odACIRACIRACIRACIRACIRACIRACIRACEw4gQiAE17BKV4I
hEAIhEAIhEAIhEAIhEAIhEAIhEAIhMDCJhABcGHXf0ofAiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEw
4QQiAE54Bad4IRACIRACIRACIRACIRACIRACIRACIRACC5tABMCFXf8pfQiEQAiEQAiEQAiEQAiE
QAiEQAiEQAiEwIQTiAA44RWc4oVACIRACIRACIRACIRACIRACIRACIRACCxsAouXLVu2sAmk9CEQ
AiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEwwQQiAE5w5aZoIRACIRACIRACIRACIRACIRACIRACIRAC
IZAlwGkDIRACIRACIRACIRACIRACIRACIRACIRACITDBBCIATnDlpmghEAIhEAIhEAIhEAIhEAIh
EAIhEAIhEAIhEAEwbSAEQiAEQiAEQiAEQiAEQiAEQiAEQiAEQiAEJpjA4kWLFk1w8VK0EAiBEAiB
EAiBEAiBEAiBEAiBEAiBEAiBEFjYBOIBuLDrP6UPgRAIgRAIgRAIgRAIgRAIgRAIgRAIgRCYcAIR
ACe8glO8EAiBEAiBEAiBEAiBEAiBEAiBEAiBEAiBhU0gS4AXdv2n9CEQAiEQAiEQAiEQAiEQAiEQ
AiEQAiEQAhNOIB6AE17BKV4IhEAIhEAIhEAIhEAIhEAIhEAIhEAIhMDCJhABcGHXf0ofAiEQAiEQ
AiEQAiEQAiEQAiEQAiEQAiEw4QQiAE54Bad4IRACIRACIRACIRACIRACIRACIRACIRACC5vA4mXL
li1sAil9CIRACIRACIRACIRACIRACIRACIRACIRACEwwgQiAE1y5KVoIhEAIhEAIhEAIhEAIhEAI
hEAIhEAIhEAIZAlw2kAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAITDCBCIATXLkpWgiEQAiEQAiE
QAiEQAiEQAiEQAiEQAiEQAhEAEwbCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEJJhABcIIrN0UL
gRAIgRAIgRAIgRAIgRAIgRAIgRAIgRAIgcWLFi0KhRAIgRAIgRAIgRAIgRAIgRAIgRAIgRAIgRAI
gQklEA/ACa3YFCsEQiAEQiAEQiAEQiAEQiAEQiAEQiAEQiAEEIgAmHYQAiEQAiEQAiEQAiEQAiEQ
AiEQAiEQAiEQAhNMYPGyZcsmuHgpWgiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAgsbAIRABd2/af0
IRACIRACIRACIRACIRACIRACIRACIRACE04gLwGZ8ApO8UIgBEIgBEIgBEIgBEIgBEIgBEIgBEIg
BBY2gQiAC7v+U/oQCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEJJxABcMIrOMULgRAIgRAIgRAIgRAI
gRAIgRAIgRAIgRBY2ATyFuCFXf8pfQiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEwIQTiAA44RWc4oVA
CIRACIRACIRACIRACIRACIRACIRACCxsAnkL8MKu/5Q+BEIgBEIgBEIgBEIgBEIgBEIgBEIgBEJg
wglEAJzwCk7xQiAEQiAEQiAEQiAEQiAEQiAEQiAEQiAEFjaBLAFe2PWf0odACIRACIRACIRACIRA
CIRACIRACIRACEw4gQiAE17BKV4IhEAIhEAIhEAIhEAIhEAIhEAIhEAIhMDCJpAlwAu7/lP6EAiB
EAiBEAiBEAiBEAiBEAiBEAiBEAiBCScQD8AJr+AULwRCIARCIARCIARCIARCIARCIARCIARCYGET
WLxo0aKFTSClD4EQCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEJJrB4ECa4eClaCIRACIRACIRACIRA
CIRACIRACIRACIRACCxsAlH/Fnb9p/QhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAITTiAC4IRXcIoX
AiEQAiEQAiEQAiEQAiEQAiEQAiEQAiGwsAlEAFzY9Z/Sh0AIhEAIhEAIhEAIhEAIhEAIhEAIhEAI
TDiBCIATXsEpXgiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEwMImsHjZsmULm0BKHwIhEAIhEAIhEAIh
EAIhEAIhEAIhEAIhEAITTCAC4ARXbooWAiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAosXLVoUCiEQ
AiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAhNKIM8AnNCKTbFCIARCIARCIARCIARCIARCIARCIARC
IARCAIEsAU47CIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEJJhABcIIrN0ULgRAIgRAIgRAIgRAI
gRAIgRAIgRAIgRAIgTwDMG0gBEIgBEIgBEIgBEIgBEIgBEIgBEIgBEIgBCaYQATACa7cFC0EQiAE
QiAEQiAEQiAEQiAEQiAEQiAEQiAE8hKQtIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEQCIEQmGACEQAn
uHJTtBAIgRAIgRAIgRAIgRAIgRAIgRAIgRAIgRCIAJg2EAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIh
EAITTCAC4ARXbooWAiEQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAhEA0wZCIARCIARCIARCIARCIARC
IARCIARCIARCYIIJ5C3AE1y5KVoIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIxAMwbSAEQiAEQiAE
QiAEQiAEQiAEQiAEQiAEQiAEJphABMAJrtwULQRCIARCIARCIARCIARCIARCIARCIARCIASWLFu2
LBRCIARCIATmKYH77ruv82Gr63vRokXd4sWLu/63/ffee2/bttZaa7XveVqkicvWXXfd1WHuM9NB
nap3cavz6YRqMys6VvsRqh2t6PjsD4EQCIEQCIEQCIEQCIEQGF8CS8Y368l5CIRACEwuASLO3Xff
3f3+97/vrr/++u7GG29s3/fcc0+34YYbdhtttNEDn4033ri74447uksvvbRt22233br1119/cuHM
o5Lddttt3emnn95ts8023dKlS7t11113RnN3wQUXdH/4wx+6vfbaq9tqq61WGLc2c9VVV3VXX311
E/ZK5KsT66af7UTFddZZp33kf8mSJWtMyKz08x0CIRACIRACIRACIRACITA3BCIAzg33pBoCIRAC
UxIg4hBwfv7zn3ennnpqd/nll3dXXHFFEwEJTBtssEET+jbffPMmPBFvbrnllu6cc87pHve4x3Vb
b711BMAp6c7sjl/+8pfdP/3TP3WPf/zju2OOOabbaaedZsz7kvffZz7zme4b3/hG9+53v7s74ogj
urXXXnu5Bbj99tu7c889t/vOd77TXXvttd1NN93Uji/hr7wIfRP/tKVNNtmkCYw77LBDt8UWW3QP
f/jDO6IyQTAhBEIgBEIgBEIgBEIgBEJgMghkdD8Z9ZhShEAITAgB3n6/+MUvum9/+9vd17/+9ebN
RZAh8vHs8y1cd911zTvQscQ/HoBEnV133bWzJHW+BfkjXq2JZbKrW1aCK4+4lRW8CHTf+ta3mvDK
S+/ggw/utttuuxnzAvztb3/b/eAHP+hOO+207nvf+1633377dUS65YWHPOQh3cMe9rBujz326H78
4x93P/vZz5rnqHOIerZrT8qsTniWEjG/8pWvdA996EObgElEPuigg1p742k6H+tseQyyLwRCIARC
IARCIARCIARC4MEEIgA+mEm2hEAIhMCcECDGfOITn+g+8pGPdBdddFF7pt/Tn/707uUvf3l34IEH
dptttlkT0XhzEfkIRCeffHL3pS99qXkL8uay3TLh+RLk1XJmXmyPfvSjm/hUXmjzIY9EMAIYcXLf
ffddKe+9Cy+8sAmAxNhrrrmm/d599927RzziESsVzygOmH3xi1/szj777Lb7C1/4QveEJzyhLQNe
3jJjXn177713t8suu3Q77rhj8x495ZRTWhzy9o53vKN74hOf2N15553dzTff3ARA7ei73/1u95Of
/KS1JWKgunruc5/bPetZz+p23nnnlRZHR5Up20IgBEIgBEIgBEIgBEIgBOaOQATAuWOflEMgBELg
AQJEO95exx57bPerX/2qiWbPec5zure97W1tWa9lmsOBRxePM55b73//+9syYQIg7675EgiAv/nN
b7r//M//7N7znve05clEqvkQiGznnXded9xxxzXRbs899+x40E0nKBfR7JJLLmlCrXMIbc94xjO6
7bffftrxTJWWZd8EOR6hgr95Aj72sY9t8Q8/26/iKU9Gz4m0FNxH4MVHQOZFaum4wJuUF+MjH/nI
bv/992/5P/7447szzjijeQ/yaiQUvvSlL21i4nwSblsB8l8IhEAIhEAIhEAIhEAIhMC0CUzvlYLT
ji4HhkAIhEAIrCwB4h+R7EMf+lD79jdx5s1vfnPz+hol/kmD15rlnLy0jjzyyHaOZ8DNJw9ALzH5
wAc+0P30pz9tHmcry2ZNHU/A81zFE088sS21/tOf/tTetDzd9P74xz+25zPiXc/lO//889sLQXgE
in91AnHRMx0JkpYmE+ps006mI/ASNwl2/WXN/u4v5y2xkOco70BC39vf/vbm/Sc9LyAhjp46eA5l
PUtwdcqUc0MgBEIgBEIgBEIgBEIgBOaOQATAuWOflEMgBEKgEbAM9ctf/nL3wx/+sHlcEWae97zn
Nc+/6bzN1zPfDj/88Lb0k/BDvBkOtvMOJFh5ZqCP37aNOr7Or/O87ZY3GGHL8fJ86623ts8o0dEx
XkLhJRZENucSJm0fdbz0pOU4aVUepTOVoDmcN3GIXxz9vNnWD84j+FmWLG+EQMdIR3oEthUJeJ6v
5yUtnpfnuXqEOul+//vf7y4dvI15Ref38zP8Gx/PgMTBcwW33XbbdoiXe3im3w033DCt+Ed5CU6V
L8fyDPSikRe96EXd0sEbjXH69a9/3Z4PSNwc5jic7/wdAiEQAiEQAiEQAiEQAiEwfwksGTVBmL/Z
Tc5CIARCYPIIePYfwYfnmGBJ7yte8Yr20obplJZXl6Wdnu3muW7Dz4gjaHmrMBHHt3Rsq7cIExC9
PISIVdcEYhhByzLQiy++uL1wxLPtLJP1vDtxXXnllU00s8zUc+csJeVlRjgiqn3ta19rS5odJ/zo
Rz9qcfKY22uvvVqatRxYfpwj3quuuqo9m05c4pY3z7Sz5Fn+CFGEOmWxBNfzEolw3sRrqSwvud/9
7nctb8pIpPMcO+UjgPFK9OxEz1t0rDgtu/bMPd5wBDflsYx2VMCFeEjgfNe73tXy4LmNynnWWWe1
l7jIz6abbjrq9BVuUybLcOXhTW96U/fxj3+8MZHuqQNvPM+F1Eb63nwrjHSaByg/8fnMM89saRIh
iZpPecpTWt2rg4QQCIEQCIEQCIEQCIEQCIHxI5BnAI5fnSXHIRACE0SA0Ebw6XuN8b4itNXS0ukU
l9hEGCLYEIcq8KTjxUVg5D1GBCMcEQoJgeutt14T13h+PfnJT35AtCKqnX766e0FGV5EQZSz1JjA
RuTiAUdk40FIpCMQvfOd72xLkpXJs/WIVZdddtkD3mqeaUckI7jJgzfaEgCJefL2ne98p52nDPIn
Tfsf85jHNM+0Qw45pL0Ew3bLYZXLMlni3Stf+cp2DrHKsxTljWCGBe9Iy6mJiERFvOXfSzzk3zJZ
QqBA9CMkqoOpBEBvXrakmTDp2XnezqusJVxK30tb7FvZQNxUJiLla17zmpZ3LOWX1yJO9hMYp1oa
vrJpDh+v7J41iCVvREKn5cCeR+itwCUSD5+Xv0MgBEIgBEIgBEIgBEIgBOYvgSVTLQeav1lOzkIg
BEJgcggQWAhYlqxW2GmnnZrwVX9P55uwR5Bi0+u5byWs8SAj5njO22GHHdZeeEHMIfB5u6xvopY8
EPmIPARJ53zve99rnnlEH0uULUOV53rJhDfIyj8xkQfiC17wgiYQEaekJV5Cm7DPPvs0r7YS/wic
vAUJjJ4TSPQiPBHqiIBEL3k44YQTmpBIvHv2s5/dPBBt9yFIEvp4zBEmldnLLsRLOONRyIuRoLrl
llu2fSXyERA9y09+vDHXcltLrnk6TrX0Wrxf//rXm1fkW97yliZ48opTNmwsz5VvbxYm0g17Y66o
LuUVZy93ISLKK+HTm54JceLnSWkfj0t5n+mAs7h5hhJstSniJgHSC04iAM408cQXAiEQAiEQAiEQ
AiEQAmueQATANc84KYRACITAlAQIVsQiglcFIsvKCjtEGSJgP/B0+9SnPtWddNJJzUvvmGOO6Z72
tKc1cZGQdeihh7bDP/jBDzbPMm/q3WqrrZoQxquNQEf4IQLJJ2++gw46qHvhC1/YBCLbCYjitxyX
V9yTnvSk9jIS3m+W+X76059+QAAkZPE0lE/CmG+eeo4h4L385S/vjjrqqCbU8YTj+WdpsOf0ESkJ
UoQ8y3lf8pKXNCFQngRecZb6vvrVr24vsSCkeakKr0KiGSGTQEkcFIe45JdYRzB91KMe1b3qVa9q
bPw9lXAnv7wPiX7lMYmTt/+KiwhoKTNvR4Iib7rpBnWiHKcOvAkJsfgJRNFHP/rRzeORSKssxFUc
phIqp5vmVMfxztxiiy1aO5Qv9evjN4EwIQRCIARCIARCIARCIARCYLwILI4H4HhVWHIbAiEwWQQs
l+VZReiqYNnq6npZEex4ihGriEaEP+Id4cqyWkt/vWn4r//6r5tnIMHNSy0IegQz+whqPNuITEQf
nnlHH310e1usZbJEL0IV7znlIMZ5W6y8i19a/WXMni9nG+9AeXAcsUseiW6EOWlZ/surz/P7CGji
ss1z6Qhk4jjggAOaaCdOgWjqDbYve9nL2pLcpz71qe1lFpYnC5Y0K5dA3CsO/i7x1DafKq99/eB6
6dmBBFvLrXn4VfmIi57ZJ24sseeBiMt0g/yddtppzatR/omxgjiJjVjIK4GRIMp7cU0FXqDYSk8o
70NlSwiBEAiBEAiBEAiBEAiBEBg/AotrcD9+WU+OQyAEQmAyCBC/+l5VfW/AVS0h0Y+wRiyyjJQ3
He+34cDTizcZ0YtY9c1vfrMJS64NxC3b5c9vS4iJdOLjoWgfTzqeYoJlxZ6pN1UgoPVvOkmvlhg7
jxjIa+/DH/5wxyvx+OOPb0t4pSUPBC9LfgV/EwZ9C8Q3YiXRCksCoyXR9cw6S5QtXa4wnBfb+3mr
4/rfRDAvNiGuYmaZLkHMB9snPOEJbZv0PVOQSOec6QZLpdXZ0oHQpzxCxX/owFuTR2AJjFhZwkwo
XRNBGfrjA55/PgkhEAIhEAIhEAIhEAIhEALjSSBvAR7PekuuQyAEJoSAZbDeOktgIywJPOlW19OK
iCgenoXS8Pw7othwIPLwDvQWW6IhwdBSz2Ehz3HEtr5QaZu4ywuOoLcyIhHB0DMEeffx9uMxJ/0S
4nyLk3gpXuKe40aJXvLQz5tyOn5V8zbMyd+WDHumIdGTKMmrsMrrb56bxFBvTcbPy0B47pUX4qg4
a5v6EjfR0NJhnpQEvmKh7pSdAEjItI/HJjY8BftiXcW5Ot/agnQqfWXzoplhxquTRs4NgRAIgRAI
gRAIgRAIgRCYPQJ5C/DssU5KIRACIfAgAkQ1S2gJPIQwgYBE+FqdQEC68cYbWxREnBKqRsXpWXIl
lBEeedoRDqcj9jhmOseNSpf4RwR0vucDHj1YXmwpb4lOw+c4zhJdee0vmR4+rv5e1XzV+f1v4qzn
CXoGICHOi1V4F1YgwKkzz0ys4I29RDpLqYmRUwXlJdZ6hiDhUP3/67/+6/9pA9oJgbSEWWnxnvTM
ReJceUJOlcbKbr/mmmuaCFl14cU0vEUJnQkhEAIhEAIhEAIhEAIhEALjRyAC4PjVWXIcAiEwQQR4
dC0dLPn0XeHSwRt4CU6elbcqgdjHg6tERN+eM8hzbpQXIA+yEgClV6LPqqS9MucQKQl50vPNS9Eb
eKdKn8hm30x7u00nz9507MUeRD/1hWV5bNb58mVZ8C233NKW/hJgvdGXRx8RcKogHt5/3mr88Ic/
vMXvJSZ9DuLmgUcgtQyax6DnBRIZvbBlVdvKVHniYUjsJAgTUtULz8eZFFWnSjvbQyAEQiAEQiAE
QiAEQiAEZp5A3gI880wTYwiEQAhMmwDhjQegpaPeqkv04X1leSlPs74wN91IiTSez1fnEgAt67Wk
c5QA6Fl6FXiSEbEs7S0BsfbN9Hc9X1CZeb3V8/KmEviIbrwklWGqY2Y6j+Ijgnk2ojrx9uF3vOMd
rW5GeVXK37ve9a7uS1/6UhMILen1hmNvGR7lpafsPC4tLybS/t3f/V2Lf9QyZ+X+8pe/3LwDvYiE
gOo8AqM3Bc+UOEfAJEjyZpQ/7YEAuDwvxjXBPXGGQAiEQAiEQAiEQAiEQAjMHIHFMxdVYgqBEAiB
EFhZAkQbSyu9TbeWlBLePvrRj3ZeXEGAmU5wHIHPm2R50/EIqxdgEJN4dBGMRgXCU6VjOaln1pV4
OOr4Vd1WadT5nn1IBCSk8bDzGfaqq2NtJ3oR1pRlTeSv0hr+Jkx6OQe+hx9+eHsbMk48Foc/lsp6
7h9PPSIlTz4CYL28ZDhudWOZ8KmDl3p4q7C3C1vmPByvv22338tASsjllXjWWWeNfC7icFrT+Vvb
++pXv9qWIysvIdgbiQmMs8l8OnnNMSEQAiEQAiEQAiEQAiEQAtMnEAFw+qxyZAiEQAisEQLeqvu6
172uCUAEQULZcccd15aPEmGGhbPhTNhPLLTc9HOf+1x3wQUXNAHQ0lBx8+iyz5LOUXF5+2wJb49/
/OOb0DScxqr+3ffU8/y6St/3Ntts05a1eq6cJcuf/vSnWz77x0mXoCmPmHjuHfGr4llRvqZ7HC8/
n+EgbV58REfCHvGtX6bh4+0jmHkjsboUJy89S3VHeQyqN8/+Ez8vQULb8gJmBx10UHtxjLTUKRFw
VN2OSm95cRMjzzzzzO7YY4/tzjnnnMbYm41f8YpXtDcq5/l/y6OXfSEQAiEQAiEQAiEQAiEwvwks
Xt5EZn5nPbkLgRAIgckgUF6Ar3nNax54zhpB7B/+4R/ac94sCSYkEbNK0KrfRBviz4knntj9v//3
/5qHHFGJ8PeUpzylWzp4Xh07zxPtRz/60YO8AHl8WVYqPc+Y8yIO3mYVShSTHkGp0q/9zi+hqfJU
+3z3n21oibN0CHy///3vW74OPPDA5nEoHc+0++AHP9iehWc/zztLl4ln73//+7tTTjmlvfRi//33
bzykW2mPyhs2tX9U3giJPNwcg5n05A1vXpGC7Z7NZzks7zvP6FtR4Mm39957NyFVul52QuSz1Lcf
iK5nn312Kxdhj/hann3944Z/e/GHNMojrwRGYmU/qBsMKmDsmGLhW9kdo24sc373u9/d8qPNWPar
TT7xiU+cVr4qnXyHQAiEQAiEQAiEQAiEQAjMPwJ5Ccj8q5PkKARCYAES8Hy4o446qj3j7sMf/nB3
ySWXtOfiveAFL+je8IY3dC972cvac+cIajyxiDvENJ5xJ5xwQhNtiE7vfOc72zPhCDjerHvuuec2
MYuQ9pGPfKR5chGQLA8mdvE8++IXv9ieT/fa1762I8hJgzhEoCpRzN+WF/Mm9FsgHBHKbBfs8ww8
QlN5i3lxhPjE9YUvfKHbfffd27JfS5zf9ra3dS984QubwCcd8X32s59tYpmXZjiWAMfrz/JlnmjP
fOYzW1pegiHtEr2IdtInaBFUfRO1eFBW3uqlI0Q/x1jGa6m0NCzTPemkk5qwJr3NNtus+8u//Mv2
5l/bBS9LEZR/qptn9ik/8czx3nLsb28Q5hWoHj1z0bZLBy97sdyWwPmYxzymPQdSebSFqeJXrl12
2eUBD0D54fFJvBM/ZsqGj/L7CPKFF88+z/ITjzbkIx+8/r797W+3+sNkt9126/7mb/6mLXkmJieE
QAiEQAiEQAiEQAiEQAiMN4G1Bg+e///e+ta3jncpkvsQCIEQGHMCBBreX5Z3Lh147REAiTSEHJ57
3/rWt5qHHEHPCxr8TdCzbJa4d+SRR3Zvf/vb2xLSEt8IPV4wQnxzDJGMxxnhj9BE9HrPe97TxLVX
vvKVTfDx/D8CErHI0lLLbglE8uI8L4RwDAHLSzGIegQz8dlGVPNsP8+rI2QRwKRDGCwvM6KX5a7E
PEIZQY4Xo7fmEqQce/7557f0CZQEqBe/+MXdMccc044n5PGo+8xnPtM4ya90PH/Py1Ske8UVVzSv
QUta5Zu4aJ+883SUJuHyvPPOa/ni4cfTj1BHoCOS8tz7n//5n7YsVhrO8eGt139xSr/pERPFSTQk
7EmXmCd/yoeL9Hk4fuhDH2plUD/KLQ1xE+BGeQLiixPe3/jGN9pvaTsPW20Fe/ws+SYMO1bdyYPy
EgAtaf7KV77S0v7kJz/ZvuVHeyH8ESl5n/L8s20qMbJf7vwOgRAIgRAIgRAIgRAIgRCY3wQWDbwF
lpmsJIRACIRACMwPAkQjL40gSFn2+pvf/KZ5t8kdscfST0IUL7V99923e9rTntbxmPPWYPv7gk15
fnmJxcknn9w8BglFjiMyEcWe//znd89+9rNbfM4lGBGwPvWpTzVhifAk2CdNz8LzfEEinHgdLx3B
Sz0sZXVjyXJZnn3//M//3I4jxBHziGtvfOMbm5hHrCOA/eAHP2ieiF5oUS8rkb9dd921iZuW3xK3
CGVEvX//93/vLrvsspam/+RNXIcddlgrz8c+9rF2HJaVN8x4yb3+9a/vLCO2LJoA5rmJvAfl7YAD
DmheieKzHJkIWOfjTuj8t3/7t+Zl+UDivR/ETcKkvClvnesQ+eMRqb6ItOKXTh0jf3vuuWfzPOSJ
ORxw+a//+q/u1MELQ4h8fe7icT4BWdzEW3n1qSAd+9S9D3GP4Ijrzjvv3F5cQgDkuYh9Ccl1fr5D
IARCIARCIARCIARCIATGl8CiwWB/GU+LhBAIgRAIgflFgIBE8OL1dfHFF7elqkQfHmREGt59PMoI
U8Sl5YUSgywbvnTg0Ud04zEnLmJPPU+u4iCcSX84EJGkRRwiDMof8alCiUy1VNnfBEfLVIlWPP4I
leVBV+eKS5q8FJXX37wNlZOoWOUTnzTl3+86X/r+dhwhzH6shveX8Km8jif8lfchMZRA53z7Ko1+
2fyW92FedUxxG85b7fftXPly7PLy1z/H78qTuuyfV8fZX5wwEqY6zr4SAuu7xMFR5zg+IQRCIARC
IARCIARCIARCYHwJLBgB0ETQxwQnk5vxbbDJeQgsRAJsF9HHt0CwYctW1Z4Rh8RVQtSaZFpCWKVJ
XFtecLxjS8xS1jUdiI14EM9yfVjTtBN/CIRACMwcAbbb9UJwTUwIgRAIgRAIgRCYmsDyXUamPm9s
9tRkst4o6eHpPGYSQiAEQmBcCBDBeOnNVCgvsZmKb3nxlKA23TQdP5V33fLSWZ19JaauThw5NwRC
IARCYPYJ8DD3yAXXDo+MyI2c2a+DpBgCIRACITA+BJbU5Gx8srzinJboZ3mVB8F7iLwH5vOg+fu/
//sIgCtGmCNCIARCIARCIARCIARCYF4T8HKl448/vvv5z3/eXhTlTeieP+sxFBED53XVJXMhEAIh
EAJzQGCiPADreVQelE7482xDD6n3MHR3Bz203jEJIRACIRACIRACIRACIRAC403AEmDPjvWSKy92
8gIlbzC34mfp0qXdRhtt1ITA6XqhjzeN5D4EQiAEQiAElk9gST03Y/mHzd+9nhVF1POw9quvvrqz
1NcbM0877bTujDPOaIOBG264oT0fJOLf/K3H5CwEQiAEQiAEQiAEQiAEVoaAlUw+XlrFC9Cb2085
5ZR20/8JT3hCVx6B3njOK9AjJiIGrgzhHBsCIRACITBJBMbOA9CdPkKej+d+uOt31VVXdZcO3mr5
q1/9qjvnnHPa2zL/9Kc/dYS/CvWwfIJn/4HBtT/fIRACIRACIRACIRACIRAC40PAfMC4XvBt7O9z
5ZVXdqeffnq34447dnvvvXe3zz77NI/Abbfdttt66627DTbYoAmB5gez8bKp8SGanIZACIRACEwy
gbHwACTaeX6fu3ue9UHcI/zV8/08488dv+uvv75d9B03KvASNCDYcMMNH3hj2Kjjsi0EQiAEQiAE
QiAEQiAEQmB+E7Dy55ZbbnlQJs0XfC6//PLmHLD55pt3O+ywQxMC99hjjyYM8grcYostuk022aTz
hnregZP4bPQHwcmGEAiBEAiBBUtgLDwACXo8/Ih8Ppb4XnjhhW1573XXXdeEv9tvv325lUhEtET4
61//eveLX/wizwJcLq3sDIEQCIEQCIEQCIEQCIH5S4BYR+S76KKLpswkBwKOAz6eB/7LX/6yIwYS
/ywPJgbutttu3SMe8Yhuu+22a04CU0aWHSEQAiEQAiEw5gTm/VuACXcEwN/97nfd2Wef3V7sQfy7
5JJLuptvvvkBz8AV1YN4HM9bkBegvxNCIARCIARCIARCIARCIATGk4DHARH3phPMJzgO8Bj0zXng
1ltvbc8R91xAwqBVQgkhEAIhEAIhMKkE5r0HoLt76623Xrfvvvt2W221VbfXXns18Y8ASBTk2k/Q
cwfQXT6fUeKeeLbccsvuGc94Rrf99tuPPGZSKznlCoEQCIEQCIEQCIEQCIFJI3Dttdc2R4GLL754
ZNGM/4l7lvduvPHG3cMe9rDu4Q9/eFsOzOuvPp4LaH9CCIRACIRACEwygbF4BqALN/HOczp22WWX
dreON1+98fe8885rS4OJgURBd/bc5fOG4AoGAM4/5JBDuj333DMCYIHJdwiEQAiEQAiEQAiEQAiM
GQFje04AZ5111oNy7uUenuvHo8/SXs//23nnndscwLJf2zbddNNu/fXXb44G4koIgRAIgRAIgUkn
MO89APsV4OLMG9CHmOcO3iMf+cgm+BkAeDbgueee25YJe1YgMfDOO+98QAgkJBoIxL2/TzW/QyAE
QiAEQiAEQiAEQmD8CBjT8+6rYKy/zjrrNIGP4Lfrrru2uYI3AfP+88KPjTba6P+cU+fmOwRCIARC
IAQmncBYCYDDleGCv9lmm7WPO3k8+w477LCOR+AZZ5zRnXnmmd0FF1zQHvrrDcCWBt97773D0eTv
EAiBEAiBEAiBEAiBEAiBMSNw3333tRxzEiAGeswPD79HPepR3YEHHti8/swViH68AhNCIARCIARC
YCETGGsBsF9xLuru6vl4VuB+++3XHXHEEd1Pf/rT7kc/+lF78y/Pwbj496nldwiEQAiEQAiEQAiE
QAiMJwHjeg4BnuH39Kc/vTvooIPah7efJb6WASeEQAiEQAiEQAjcT2DevwV4VSrKxb6eGejhvgcf
fHB38skndzfddFN71seqxJlzQiAEQiAEQiAEQiAEQiAE5g8BS349DujVr351d/TRR7dlvl7mkRv+
86eOkpMQCIEQCIH5Q2DR7rvvvsyS2UkOlv5ef/317bPNNtt0G2ywwSQXN2ULgRAIgRAIgRAIgRAI
gYkncPvtt3fXXHNNW97L6y8hBEIgBEIgBEJgagITswR46iJ27S7g5ptv3p4VuLzjsi8EQiAEQiAE
QiAEQiAEQmA8CKy77rrtuX/x+BuP+kouQyAEQiAE5pbAghAAC3EGB0Ui3yEQAiEQAiEQAiEQAiEw
3gQyth/v+kvuQyAEQiAEZpfAYstjE0IgBEIgBEIgBEIgBEIgBEIgBEIgBEIgBEIgBCaTwOLJLFZK
FQIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAIhgEA8ANMOQiAEQiAEQiAEQiAEQiAEQiAEQiAEQiAE
QmCCCUQAnODKTdFCIARCIARCIARCIARCIARCIARCIARCIARCIEuA0wZCIARCIARCIARCIARCIARC
IARCIARCIARCYIIJLB6ECS5eihYCIRACIRACIRACIRACIRACIRACIRACIRACC5tA1L+FXf8pfQiE
QAiEQAiEQAiEQAiEQAiEQAiEQAiEwIQTiAA44RWc4oVACIRACIRACIRACIRACIRACIRACIRACCxs
AhEAF3b9p/QhEAIhEAIhEAIhEAIhEAIhEAIhEAIhEAITTiBvAZ7wCk7xQiAEQiAEQiAEQiAEQiAE
QiAEQiAEQiAEFjaBeAAu7PpP6UMgBEIgBEIgBEIgBEIgBEIgBEIgBEIgBCacQATACa/gFC8EQiAE
QiAEQiAEQiAEQiAEQiAEQiAEQmBhE4gAuLDrP6UPgRAIgRAIgRAIgRAIgRAIgRAIgRAIgRCYcAJL
Fi1aNO+LuGzZsnmfx2RwbghoG+PQhueGzvxPtfp26nD+19Xycph+uDw6D94XXg9mMh+2pF7mQy08
OA+5TjyYSbasGQKxAWuGa2INgRAIgRB4MIG5mv/OawHQhfjOO+/sbr/99u6+++57MLVsWbAEtI17
7rmnu/vuu7uHPOQh3ZIlSxYsi3EtuD6t/tTl2muv3a211lrjWpQFnW91qC+qP30xYWoC1eZ9a/Ox
W1Ozmu092vBdd93V2vE666wz28knvSkI6CvqRWBfFi/OwpUpUGXzahLItWw1Aeb0EAiBEAiBlSJg
HrDBBhvM+nxgicn3fA0G5Jdcckn361//urvpppsy8JuvFTUH+br33nu72267rbv11lu7jTbaqNtw
ww2bkDQHWUmSq0hAHd5www1N3N944427TLpXEeQcnmZyrg/qi+uuu263ySabzGFu5n/S2rxrmYkm
u7X++uvHbs2DanMHVju++eabWztWNxGa5kHFDLJQ1wlj1bpOzOdx6/ygllysCgE24JZbbmk2YNNN
N41tXhWIOScEQiAEQmCFBGoc89CHPrQ74IADuq222mqF58zkAfPabYr33znnnNN9/OMfb0IBhTSD
8pms/vGNywT6uuuu62688cZus80267beeut4iY5ZderfV111Vas3BjCT7jGrwEF23aTRD4laJudb
bLFFbPQU1ehif8cdd3TXXntt+9bmfYioCXNLgADoWnL11Ve3m0kGYnO1LGNuScyv1NUB7z/XCf1n
m222aeJMDZznV26Tm3EmoE25Ick+u5HlWpYQAiEQAiEQAmuCQDkE7Lrrrt32228fAbAP2cTommuu
6X772982MI94xCPasqn+Mfm9MAnUZI2HKOFojz32aF41C5PG+JXaclGT7TPPPLN5eOywww7dzjvv
POsu0ONHbv7k2OSc598f//jH5qm91157dbHRU9ePCSZWF198cfeHP/yh23LLLbvdd9+9iahTn5U9
s0GAPbLSgD1aunRpt+OOO+aRBLMBfgVpqBeizFlnndXqY5999mljQQPnhBCYaQLa2aWXXto9cs9H
NjuQdjbThBNfCIRACITA4kWLu2uvu7a76KKL2s1N3uezHeb1EuCCYZnU4Ycf3h155JHdeuutF7f8
ArNAv02kr7zyyuY586tf/ap77GMf273tbW+LADhG7YEn73nnndf95Cc/aQKg/n3EEUfEu2OM6pAA
aHJukkSIf/SjH9295S1vSR1OUYfs1i9/+csmAlpmdsghh3RveMMbIgBOwWs2NxOaTjrppCY07b33
3t3rX//61o5nMw9J68EEPCfz8ssv704//fR2c+glL3lJp36sAEgIgZkkwJvdaqOzzz6722+//bo3
vuGNDzx7cibTSVwhEAIhEAILm8Bai9fqLvzthe2RE+YDc7HiZF4vAa7mYXBuiSdviTwnrKgs7G/P
G7P0V/C90047LWwgY1h6S4A91J2AtO2227b+nZdIjFdFXn/99Z1nJRF0LWdlo1OHU9ehZ8x5lIVr
Gg9AHpMJ84MAG6ReLGXfZZdd2vMZ50fOFm4uPBybbTHuIwbyFLdchliTEAIzSUCbqkdYbLb5Zt2u
u+za3XnXnTOZROIKgRAIgRAIgTauuevuu9ojZwiAcxHGQgAExnJgF+gIgHPRTOZXmtoC0YhHjVDf
8yuXyc2KCFQdqr/q3xGPVkRtfu2vOpSr1OHy6warYV7LPyN7Z5OA9iuwR+opItNs0h+dlrvi1Weq
XlI3o1ll6+oR0N/LBrRr2b33tLa3erHm7BAIgRAIgRD4vwRqPON7rsLiuXA7nKvCJt0QCIEQCIEQ
CIEQCIEQCIEQCIEQCIEQCIEQWGgEFi+0Aqe8IRACIRACIRACIRACIRACIRACIRACIRACIbCQCEQA
XEi1nbKGQAiEQAiEQAiEQAiEQAiEQAiEQAiEQAgsOAJZArzgqjwFDoEQCIEQCIEQCIEQCIEQCIEQ
CIEQCIEQWEgEFs/lAwgXEuiUNQRCIARCIARCIARCIARCIARCIARCIARCIATmgkAEwLmgnjRDIARC
IARCIARCIARCIARCIARCIARCIARCYJYI5BmAswQ6yYRACIRACIRACIRACITAfCWwaNGizichBEIg
BEIgBEJgMgksyYV+Mis2pQqBEAiBEAiBEAiBEAiB5REo0c/3XXfd1Xk00JIlS5Z3SvaFQAiEQAiE
QAiMKYFc4ce04pLtEAiBEAiBEAiBEAiBEFhVAosXL+6uv/767qqrruouv/zy7rzzzuv22Wef7rGP
fWy34YYbxhtwVcHmvBAIgRAIgRCYpwQiAM7Tikm2QiAEJovAfffd11155ZXdbbfd1m2//fbd+uuv
P+8K+MMf/rDbfffduy222CITv3lXO8lQCKx5ArzA8nK4Nc95PqSgrtn8H/zgB90ll1zSxL8rrrii
O+aYY7pHPvKRTQCcD/lMHkIgBEIgBEIgBGaOwGIDgIQQCIGFTYA4dcMNN3R33333wgaxBkt/7bXX
dl/60pe673znO92NN964BlNatah/85vfdO9973u7Cy+8sLvnnntWLZKcFQLTIHDvvfd2t9xyS9rZ
NFjNxiHGgWuttVYT/W+66abuzjvvjAg4G+DnMA117nP11Vd3f/zjH7uf/OQn3bnnnttdc8017SaV
MUFCCIRACIRACITA5BGIB+Dk1WlKFAIrJMDDw7N+fv/737dlP5b+8Ew78sgju2222aazLChh5gjc
euutzdOCALjffvt1821yZQL4wQ9+sDvllFO6V77ylZn8z1zVJ6Y/E7j99tubvfnd737XXXrppd0m
m2zSPfGJT+y23HLLMJpDAsRYIpAloJdddlnnRsWTn/zkbuedd85z4OawXtZ00sYAPgcffHC31157
dRdffHEbC6zpdBN/CIRACIRACITA3BKIADi3/JN6CMwJAd5+3/zmN7uf/exn3fnnn98+2223XXfA
AQd0W2211VgJgHfccUfzXll77bVXiiURjqeb81bGE1p666677gNpiYeY2t/2wM7BD940Z555Znf8
8cc3ziZb001PvPI43eXCJvMmdeXNIx+8OqU31UPdb7755u5zn/tc94UvfKH705/+NO/EyT7L/B5P
AsSlr33ta92vf/3r5mHqOWNPf/rTm/AQAXDu6pRt+vrXv96dc8453W9/+9u2BJSd8IiCRzziEc1u
sCcJk0vA4x7U90477dS8AN0ITAiBEAiBEAiBEJhcAhEAJ7duU7IQGEnAhI6wZFLOA/B73/tex0PN
xG8clgCXxwoRgWDlAeYEr4c+9KEdEXPvvffuNthgg5Flt+yQp4Ny83Qx2dl4443buTwfd9hhh26j
jTb6PwKd9K677rqO5xIPGXHwkuM1R9AQFxFN+rvttlv7rLfeei19y+nOOOOM7rjjjuu+//3vt3Mt
sf3Wt77VPJ8222yz5hFY+VU38mRCrn6ka5JOJHn4wx/eBBP57QuIPKvkpbx3HvawhzXvHWnXki7H
K9/+++/fbbvttg+cL++EmY985COtHMTM0047rYmA66yzTnseoMnhQx7ykJE8szEEpkNAG9WetX32
Rh/ykgHitjbfb8/TiS/HzAwBtk29+Jx66qkdm7H55pt3bnIkLAwCdXPINSie/wujzlPKEAiBEAiB
hU1gSe7urlwDwKsm6TyHyntoRRMY5wx755R3j8n1KO+lSsvkyX4CjXRGpeXY4dA/bkX7++c6lugg
PR9/y7v8GiDKbwaKfWLj9Vu72HTTTbsXvvCFTVQ64YQTxsbri1BJHDNZPfvss1tbVB4iIDFr1113
7Z75zGd2z3rWs5ogV32gJrr1wHPP4NO2TXSJEQKBzZJEH0Kg/TwlPSCdl6Rn5P3yl79snn6EtG98
4xtNzCAo6qOEwyc84Qndq171qiZuENAIlD/+8Y+bp6U8EtiIIF/96ldbHeyyyy5NrDP50s/EJT1i
of4mXg9ll39L8pSL5xSRzzb5wuNXv/pV+1auQw45pImg8up5g57pJF3C3/Of//yWv6233rqVWZm+
/e1vtzyV+PujH/2oiZ08Gl/0ohd1jl1TAqAy+ygrG0fILXsjP/4uG9syPMV/zhHE4yPv6q/qv06r
4+rv+q7jptrvuOUdU/sqvnz/XwLE51e84hVNbLfMXHtcHuv/e3b+WlME9JPnPOc57aYFj3A2JWHl
CGjHPiVmszv98dFUtqHOY69wZ2OdK4w6p443NuuPwZwrDufWOHLU+VWqikd+fcRl2/LOqXN9O1aQ
Lhvtb3H0vc7bAb3/HONYadRxytEv93TT70WbnyEQAiEQAiEQAqtAIB6A04RmAEMMuOCCC5q3jYm9
Cb7nGLljzkPHbwNqg78S7Ex0TMo9Y+0Pf/hDx+PHUovyHuLtw8OGcFDL/AyULh08I8nxRANeQOIl
2kiLOMHbqAZ79hMOeDQJBlLyQjCwvEO+eQeJr4Ly7LPPPk1IsE0+Dcg8C6g8iR73uMe1NHg+EVek
Y5BJfCBcEBRqwFrx5ns8CGi72hHxy29tbr4HYt3pp5/efeITn2iClaW0j3/841tf0P7/5V/+pS1j
I4qZZLzkJS9p7Vdb5+FiCa7lbiY9RD7tX7snlBHcfv7zn7ePN/W+9KUvbf1S/7SdKEdw1Jf1wQ9/
+MNNdOPpp+9fdNFFbfkcu6AfL126tPUTEyP9fY899mhvACZg8lLcd99923mEEX1bHgl18sg70BsY
eUjp48pz4oknNqGOXTDZe9nLXtbqjTj405/+tOVPHmpyRdgjHrIZ6tgbHpXLb16Khx9+eJu0yetT
n/rUtvSLF6NgP7baBfFvTfRxEz/psSs+fqtLPNUlm8MbCZsdd9yxCbu4DwfcMHVO2Sh1xv5Zyr7n
nnu29oEL+4eDeCuw1eqv+oJ42MF+cC4b7e3IAs5spDJoP4Rjdbzhhhv2T8vvHgHtDCPeua5dJbr3
DsnPOSCg/Wvb+rr+wn4lTJ8AG8AWsMt1g8fNHLaA3XQdYEPZkApsBpvFXrFzmLv+ls1yE8s4sQSx
spXGjGy48dyBBx7YbKN0y1aynWylcR+7PxzYStc++ZW2dF0j9E3Xm7L/w+f1/5YX1ylxOJ8tFS/b
rB358FAXbFdWx8ijJebsrPwZDxtLS9PfrsXKX2Xup5nfIRACIRACIRACM0sgAuA0eBrEmGiffPLJ
zaPGgMnE1ECIKGaw5nk5JvMGfibtJjoGZAY+5aXj96Me9ai2j5BBVDDZJA4YKBLVxOd5YUQAAyyD
SYM2AyWTJvF7icCTnvSkNmiSFxNeaZw68IoywTXwMll9zWte0wRAgzyDL295s1++DbT+8R//sYkU
zudBJA6fs846q4kM0rPPkkBeSwaeNRmW/rOf/ew2we4PbqeBM4fMEwLaAIGqhOR5kq2R2dAHTBg+
9alPNbHuKU95SmvfJg/6ogkEz6KTTjqpteUvf/nLzdtN2bRhnnAf//jH22TE8t0Xv/jFrc9JTH8y
+bCfN50+qV8dddRRbTuPOqIbzzjfJnomXk972tPaklr9S9879thjm8ikXxMQCX3EJX3F5M1SYBM9
Ezx9x36TRH3chJA4+dnPfrZN4ngRsin6ln5nEvXJT36y5c8xxHmTNrZD+QhX+rAJGjtDnOcJScyz
VPrzn/986/+1BNMNB0IMgYzd+e///u92HltnH75EAV6N2shMBgx4RcpX2R3pqmMiL49EIhuxVdrK
yRPx0EMPbba28qKsJsTsGhEUI3EQe/3GnriJg3ai3sTNnuGt/RPv1KMbJepIGyL0OhZ7k1mMCKYl
ABISvcxF/sXBs43tV4/+ThhNAJu6do4+IlvnggARkA3VfhOmT0B7/sUvftGuOQQxopvrCNtijMUW
sQ3sCztfAhz75FrAzjjO9cNYz3WHHXG9Oeyww5ptYhcd61ETrn++2T22iX1kR9lK9s61jq30Ii/2
m+2WpuDbdYLNcjOJDWPffYzzxMMWy/NUgW2WPntrPCnfzpV3gZ10rXP9IHqyp9JzM8p5xpVWHbg+
ffe7323jXKyc97d/+7dtbBz7ORX9bA+BEAiBEAiBmSMQAXAFLA2cTAY9IP+jH/1om8C/8Y1vbJN4
A69Pf/rTbSBnAFXeKibWBnw+thswmaAbXBkw+U1QNPgzSDLwk4YBFeGPh5P9vJTc6TUwr2f0iMsE
llD3ute9rgkQBEiCowEWbyYDw4pT8UxiefQYABrkiUOQviBdoqNngTnf4NBEzUcQlwGnb/lQbkKi
ASGRhGfHpAUDbwNtH6KPgan6xcGEaThoJ3WsejcYrzicb3+JbaPOr/gqnhJEtBmD9Ep3eedWHM71
IbT4VH6cK57hMDzolgfp+vTPd+7wscNxram/9Q8iHgGHCE4QevSjH93YSBMj27Rf7dzf8qos2qpJ
jwmUpbsmV/pDCVsmSuru0oGoR1AyYdHf9T+CPc804b3vfW/rK9iWIKWvO9fEzZJg/VL/8cFOPhxj
cqge5El/dryPID793XMCTayIh8Srqj9xPOYxj+k+85nPtImeiaO+TiDkcaEcBDDLm9kXXhYmgcQv
6Zb4ZRLGS5gNcFzlSx6Khd/sCXGyv832mQp4ycOpA9GULWOHMMEcC5NCtsd2PNSLtshDSZ0I6pW3
MiHOcmr71K0JOJbqmxCrPkyOjz766HYMXsRQE1PtGR9lVWaBYIqlfKkrdpX4R7StQDB1c0cd+K2u
1rR4gpkPW6Ifa0tlC6bqlxjhWf3YNxvGNjl3VF92vA9b7zifsgdlB7WLasvFZPjbOfJbaUtL2rZX
vofP6f9d+ag+4Bz9QFmnOr/KKk15dKw8V1mcP9W5/bRX5neVs8qqnJVHafksj3PVqTSrfM4fDsXD
8T5YCpWu76ov6Y1K0/HyKy7HY+O3vubvqc5xXoU6v+rF9moPKyqr9ORR+aRn/CDoS7ZNJ/12wjz4
T17ZFTekLJ0m8nlzstURrjdf/OIX280aYl71O6yJZa5jxnnKzb64nrk220V4gAAAQABJREFUeTYm
G218ZUzmJhC74nrkxgRPdONF57nB5Rj1oC2Il51k+7Bl51wz/Bawdr6XPbl+uHbyMOe551rFA16+
1dGoIO9sqWsU7z12knDneCIoe6kMxrbSdIOLfZZv12yin5vbrnnSl6b9rkfK4VsaM90/R5Ul20Ig
BEIgBEJgoROIALiCFmDwZqJn4ERcsPTOM3MMZAyieOa9733va0sqDArdASUamHQbCPHQMeAx+DG4
cafYINEAybkGfCatBoFEOA/jJxqawBsAOt8Am6hBaPNtoPiVr3ylnWPi6hgTVOmaDBtYGRgaUAkG
+MQCQqDBGk8jofabeIjDwFNeDRaVm+hiwu2uskGmybhzvTmWJ5FBqCUnBIdRk5aWyJj9Z4Kj/Aao
eGBgoG/CS2RY+mdPTXUiYGgAa2Bu8O3bwJhHUS3xMbjF011x9YRXiat9PNqLY8vbkpArL0QKH+dr
O9rLqMmSvMuLdA3StTlCj0mX83mF8WKS9qjz5UU+lV079S0Pjldug37tbS4G6YRnXgPqQzu3hFa7
raCMBC91wGPOxEsd6QdehGHygw/BRput+nO+urXdBE4a+Jvs6I/V9ollVW7n8iozeSqO+BCCTIKk
KZ8mR/10Kq++5aWCOpZHohixwmSJGFZxO0759THxiVf+CGXagvphP5QDE30dnxIYtVvlM5kkqlV7
rPRHfffzN2r/6mxTVwcddFDj5GaENqvta7fsjYmrcqgzE05iHS8YjJynHjA4dSAgWjKt/Dw6SxAW
n/x/4AMfaH3YMbw8n/GMZ7SJujouDxbM1CM20tRu9B2eoOyovOqvRMIK+hHe0jh04JUobvaxX191
7Ex8u05ok8Rptkj5pU8I8FHf6rqfftkSE3JtRxyYsQPEAef027Tjxa19aH/6vnIpt78xYdukwQax
I75H2X02RDzyrK2J13G42V7XnVFsMNUHlFWahA15V09sqrpwbVVuwfHSK5stTb+9zdz2EhvYTu1K
eaofj0p/ZbZJu+pG23VtVk51o5/KL7vgBkO/btRDCTbFB3/2Qz1iq3zOwUp52BP1KB37eACz7UQb
28WpPvVzjPq2scokLue4rqkHdlK62oS8+r2iwOboO64Pyo4BG6RNGZ8oK762i08duA45Xn26mYKP
vsxWq1e2SpmnspUrytNc7FdG9tpYTFs9dGAH2A5jLO2z7Li6q/aOHaGMlzouz33uc7uDDz641ZV6
Vd9l79gsdUyk8y0e1yPxig87nnZueqhr7dyzfF1/anym/8qneihR0k1e3oFuMhnzsW+uV9qd8rB5
owJ74FxjU2NcN8D0Z3lxM037czPGyhZtyRhIuzJmIHhqA4Lxp/ONb7Vb41/t1jn9PjIqD9kWAiEQ
AiEQAiEwMwQiAK6Ao4EXzxoDFYMdEwsTHxM+k8bnPe95bUBnciSYhBocGRQ73rEmsLxKDPpMxj3E
n4BgMGcgZ5AmLs8VMyE2KPawfoO/GsgbWBtgGmwa5BnEE+CkZ8AvPyYQ0h0OBlYGeia6BlvDwYRC
WvIhfRM+A3gDNYKnZXLyRAwSv28DTvkwoD3iiCMeEBuG4x6nv5XZpMjkRH0RWUrMMWHDGCeDVxMZ
TNSHgbn2YXDrOPvVs8Gwu/fahkG4QS6mPIrEU5NYjIgWlw7u4JtQOE9dmEyaVJq0qUMTLB6hhw4m
G8MDZnk3yCaayLsBv3O0QXkyCTco1+5MOrSF4VATBekTXEzYxKmclthavmPyYGA/m0G+tEn9SJkI
ePpDP9hucm/Zu8mIvoCfSZc6UK/VB6pP9c8nIhFnxaFvmdw6T/8fFnekRQj1XQEjfVia6kK7wX46
QRr6k34lj9LGXjwVxKXtYGGiTNDQRgTHVV5sUxZ5riBP8iaPArsjnrkK8qM9yacbHupWMKG1ZG7p
QDRRDu1dv1LvhBKTZPWp7rVLN0H0ude+9rVN0BKHfiR+E2Nt3ISWKMROle3Wf0yS9W99Th9mR/HB
Vd82qTXp9XFMBaz1SeeKn2jcr4s6bqa+lYcnI1vPDuh77Ib2rL0QHNwoYm+UW9D+CX8m69WunMsO
2GdS7lpSywydgy1hVLnc6GKzxKs/sCc4Y6Edut6wcW5i+d0P2rK0ef6wI3jpb9Xe9Avte6rATsmz
6xAbpvzEL/Wv3MR/N+CIeYQkcREu1JF8l+3UH+TDDTFCg+vw29/+9sZpJoQm8WuL7DWBQ761B2XF
WpuSx7/4i794wFbVOSVo+1Y+56obbZ4QpnzsvPLZpx61YX2BbSLy4eq3uiGuicc1QdtWN2xZ9Xes
8Ven+BDO5Z2t0Wb81q5KpBlVN9LT5lzrjIe0F+VUN9oEMcm1QR9me6WnLbFjxgnaj7/f+c53tvP0
XXUmfS82evOb39zqZro2c1QeZ3ObfBu7YSbPWPhWx2UXcCo7jJ/+wxvO+ELfU4/qXJ9knzHUn/Vr
1x7XYOIoW8nm8TbE3TiSLfOMW9fCspXaE9bqyXHslPP0EfZO/9Y/pW38of7ly/lujljNok3po8NB
vWvn2pmbB8roOOXV7gjA+hUObpjrw2y5sQ77pY/KtzatfbuWiUt+jSmJpvKREAIhEAIhEAIhsOYJ
RABcAWODFoMig2TBgKo/UDGZMggz4DGxNjA0mDagE/xtgGRi4DyDPBNMoprg2yCsJj0GUAZ9jhsW
KkyYDx0M8D0DzODZxNnAjKCz9M+TZulNFQzWRgXnGJiZ7ElDfuTfpLh/Z17ZDRRrMG8wWd4A5W00
Kv5x2WZAiqellgbr6sHE2oDcRMtETFswucPJwFw9WFJIeCshQ71pA84zuNeGDMixMmkwmXU+vurE
MfZ5xptBunNxNrnWHngjlTBocG3gbgLvuKpTaRlo8wIw0TMB5AEgHeIHD1YTBPk1MTTpGg7i4OHp
/GoTJqA1kdMuDPSJK/3J5XA8M/23iQxuJjb6kDINBxzkWf76QZ9ULxg7ZqoJpn0mItoxviY3vGTU
3aiAxXDo9z37Rx0zfI6/9SMTfO1PHtxUICoNn192R14J+Y4dFUal7VznCcPxjopjTW/TfthFrOVL
nzGpZfeqbRFt2EcTS/WgLdakVh80kfa3dmtyWkF8NSE3AVde/ctx6lc6+gfmRCLCUT0zSx3q82XP
CIhsM4GGsCFuk1k2kGcO+1/5rfRn8lvfI5Lq924K8XJlq9kbdkcZTOi1a3lXVn2cBykRDUNipvrX
/9kRk27nOZYnkP5U4gT7R7Qh4OBQAoIy2aYvEebwVX+uGVV+dSRtQgKhg0h+6OB6RcjV/4gQxCf2
b1TQV4ke7K9jCCTaAwFDWeRNvu2TJrGJACVO+9UT28Uu8lZSDuViO9Sfb2WYiYA3jh/60IeawEgM
1R6wlA+ctT0CCM7qBgPnqDfXkaWDazbhAzftiWBkuzyrL3WtzSsbdkQhf2vH+o2ysxlYKLc2TpBS
fvWCv3xKny2z7NTSVH2GJ60bQvqdeC0Bncr7Cy/puI7gqg+49sm3axNRUb7xtq2uLdqovPtIX75x
0XeV0bc6FwcbqMxT2eeZqLOZjANTYp16EHBV38Z2bLe+of7YEXXveqJvsB3qzceYwj5Bu8S/bKFt
2opxp3TY++pnzmHD+raHneSRJz/qQP/ElK0Qr36l77J7+hQxXXsUpD187Ws7/vyfOtH+2Er2QL6U
v+pKPOLW9m1Xz/5Wn2ymT9lwYwfjnrKvWClPceynm98hEAIhEAIhEAJrhkAEwGlyNbARTCIMWsuL
wLfBnsGZgZABXB3reL/tMxgy0DGQM0CvYADuGIN3ngqCiVcJiHVcfROFTIwM6AgiBmMG0yZZMxnk
yyBRvvvBQJMwZlBnkGfCIf1xDwazBrgmZ9ia0PGAUVfq1WTJQNpE3DN/TN4wV5/qxCTIoFsdq0f7
iHQmYc4j7HmJhMmzSZQJmoG4QbP9PCIs/zEQPvroo5sXh7RNHNytN7nwkgmTKe3NPpM49SR/Jscm
3iZznkdkYm9yqX1Ki8hhkmfSYeJQk7R+vZloYyA9SzHVsfg8+454oIxEFyxqMtI/f039NpExqTBR
8fG738dGpWu/vljH+/a3c02QRgUsTYTUAaYVnLcmg7zpy761Q6K7Z0Mtr4z2DffNNZnHNRF3n6vf
Jqv9dmUbG6QN46Le9AecStSxT7vlBVX16jx8MGQrnesmTcWtb5qEas/EJEKFfsmulfBLsBAP4UPf
IVLoV9qFZz2qL38T2By3pgLBhO0wUSZSSlOZ9W1249SB+IVHBcICoccyQ/2el5BJv7aCmXO98IW9
YEMwIlo4lqigfxMd2DG2gMh26EDEk/6lAwGD0MGOYYYfgYtAgTdm2LBD6u2YY45pNzLYQHlkNwhY
0hgViJ1uVNgvXkI4oUCdqDNlkyb7Kz+19No1yd+uR+pa3fCW42Uk/8Q1bUNdzVSf0S7YUvZY3njd
1XNFtTX51C6ki43f8qde3EjS/qwUqBsWBDVsCKdu5Kgb9VLfrrPSUz5t1oed1r6NRzzzUlsgkBJr
tBPnVhuWH88WVodegsQ7i2CknnlV6huue8OhyqBuLPHUz1796lc3cav6mDKqd/kzblEv6sT1Y+ng
Ounaxu4KjuHd6NqljlwrcXN9U7ZxCdqzvqP+1AVx1PVfn9GP2HDtTz9QNu2FjdFntUF/aw/9vqud
E8hc7wRtGv9hLraxleKptmWbtFy7bGOn1IuPfk+g1U6MLbULx/SDv+VzuH+IV38yPtU+ef75Wzkr
X3WuepUeGyMdeZAfn4qXnZF35/jIs+B3QgiEQAiEQAiEwOwQiAC4As4GLwQTwoBBuAG/wbOBrkGN
AY8Bm8EQMciExUBqquCcGgzVMQaB7oaXl2ENrGp//9vgyuBa+gbVBp8GngZqMxmmig8P6Zs8lBhq
MDvugVeEiZOJjImLwayJrbowOVo6mMgY8BMAtQNL3CyJNXl5wQte0AQCg+KaGFg67flxBrjqFTPt
xHm8AYlxJoAm8rwCeHWaDBHmbDf4r2ACbSmZSRjxkCBgMm1ib1JrUiHf4jSZq+Xj6kqQR0t/TUDU
61SDbW3LpNMyWnETJy33EW9NXnh5GNhPJVBXnmfy2yRV3vQbbd0kVNtXP6OCOlNHNUkqYQl/IoW6
HhWwkY6AnUlMMRx1/ExtUy6sfcujiTFxeKq0TRRNHtkkE7JJCaPapTpR//pV7ffbTQdtgK3lAc37
yvZ+cF61d22g+hTW+jexRd8h8OmD+gkxkbhFKCG0S8Pkl20gwLHT+vDSgT0g4ohrTQZpE77qeVuu
N4RqwgMvYfmpNisfbARboH0QIIhTdb1h18r7h00i+Jw6EI1KAGTP/M2DDUs2gIDIptT1Rv+xX57Y
f6KAfsgmYFhvGGWDPONMH6ogHnaIdyKuFdQRcYLYKe9sIjFW21bn7K9yuA4TWni71c0UQgsPSPXL
hsqP8iqnpeFYsVn6PPs9VZ+qvEznW/zKyybqr/KoXtgdZZF/wmPZW9v0WSKy8mFL8MOm2rRxg/zx
ZFU3vAHVpXbqkSHS4RnpXNcU3mVYaqOCdou/NF1HjAuq7l1vXDe0c3lTN/jIl8CryzWMN+PwzTzH
iFvdYK8dGufUuf7WToiWbK7rIwFX+5R31w/CIdFIUKdHD25wKa98akOOKRG5HTQG/6k31151oL7K
RuCH86ED0VwbILZpv9qLesAIb8vD1aF2UQFTbcu3+Nl37XpUqHbT31fn9/eJn43TZ8TNXrEX/WP6
cYz6XfnWxonb7KDvGqdKtz7OZ3e1bduGQ9nk2r4y+ahz8h0CIRACIRACIbB6BCIAroCfwZKBLK8D
k0CTJh4WhBoDYZMLgz+DPM+DMpg1yFnZYOJiEiSYXBnwTxUMovt3TmdzECUtg9IamCp3fwI6VZ7n
+3aDZF4xJiQEN55vJlPFVt2YRFZZTYTdVTeQNxEwgTHgtZ8HhMmuAbxgwG/Q7HjiguVoJuiEHpNy
7Up6mJoEllBRzMRL8DNh4D1iMO8cXjLuqPMCtZ0Qa2JJyOhPdJXHsSZhJiK8Q0YF7dnzHPvnG8gv
HYgdhBbim3Y6LLSMimsmt2nr8oatSQiOJtM4VX1UeuoLH+KO/oi9/BMC1J8JGtFEPx0+V9zK6Ftd
mEA7ptpApbG63+Lrx6kPVVnUj2XYPGSGn68mXewJzWyQ8pWXz+rmqX9+P2/97XPxe3gSWX9r6/ok
dkQNLJaX79rnfL8JTD76PCFCeyKYaR/6lv7MG8cNH9t4kek/PJh4WRGXtI81HbRf7Z+98BxA1xb5
0i/1U32Z/VEuE3I2hUBn4q+dE36059ov70QA+wk7bIfziAOuK31hn8BJHMRCYAOUWd9wjSJ8sAcC
YcO1kX1j03inyWM/SMONEOn0BUDH6LPEI3XhGCKSMgvyru86p+ya9JSFvSMmsYPsnPz4xoVgKOCD
ARsgrtUN2o+yqBvBtcNLG/Bw06fKr0+zW+rM9UIbc03B5dKBwKxuKj/qQ5mqfNo3QY+IhLs461ii
n/ZOhJEXfcBv5Ra/c8tOi1ebIN45Hy9eg87zEWzHUBraej/Y53pVwqsyu9awQc7HVfmVka2UtvGQ
dKvs8ouXoF5c4xwrTQKu8tlf+emnP19/y6s8e/mQb/bYNVybJb7i4+N5d/qCPqYNG9fpT2w7Gy+M
KjfubL3vEtpWlkWdq6/qOxXnysTnHHaCrfWbLTIWUabljQOUyfGjyray5cjxIRACIRACIRACM0tg
SS7QywdqcG0i5K65CaC78pbSGOgSEUx4iAZEQp6Bthn4rGwwsKrBvwG1OKcKBs/yJZ2atM1WPQ6X
jchloD/uwcRT3eJokG7wXgNwZbMdcyKBAbTJ1rDQa7s6NImuuiwu6okoaHJrgmBQXR40ltcaYDtm
WPyr803aCRb2myybQJpsaIfy6m/pir/E2TpXezHRIlook8nyqOA4k7V+HSuzeE1yTPYIVCszgRiV
zspuM3HnaVITVMIGrxITe5ORYi1fJjonn3xyW2qHt8k2QRZbEyF9S5/FUnz94FwTYPFgJG5Mptu3
lnccpj7iNjmuY33LP7thIqztyT+vNl6f2Fc7U3fajGWEykCc6ddVvyzDvyu92j58nvqtoC3W8dK0
b/j4Ona2v+XLR7v0qb5qcr08bzxeLNoRe4W3ds6uu7Gj7xCfCH8lLLHnxApCCua8eurZbtIlwJTA
vyYZEGx4UxHqCEbaL48wS/S1Gd5vyq2NsClsAbGJTXa9IjoVM/nEy00LbVDd6ld+YzMc2BHtvx+0
UR+hbw+kSbDCiyBLZBoVtKU6v79fHfDs1T/UJSFLnQmVf+exv4J+rR4E+4WyA/oMZhWqrdTfM/GN
ObtCgGc3LHNll7UZfJcObjqoHwzVDT7KVNzZMNeBftDvShRS1ur3/WP8Vs6yyWVL1JMxhKBeSrBR
H65r7Jo6Vi/DdeocDOt8f1fQRrQ59aPtqB83PfWT4i4t9lRexKHMZesc309P26h9vh1b9Vtpjss3
wVf/4e3vesF7k10ue4ERJq5T5QmoTnFU//azQ8WxX27bXN+JhcYaqxPUoTYhTjbCmGFl7Ln6k291
qWzVbvvXjMqfNMSvT2hvrrsTHQZD/cGV/f423A1Ez8G/iQlVlD+vzh5ceVevfBXfAJB2MqushtJW
R7Oafr9RVF7GfdV7lUPZBmWZsn0Mjpv1+u7zzu8QCIGRBOIBOBLL/240yDGZ8kw4Hg4mVQZCBnom
W4Q6kxLeWe7Wl1fA/8aw4l8GYyXcuNtugGUyZILaHzxXTAaehJg6zyByODC4Pv0walt//3R+i8Mg
0sTCxIqI4k7+uAeTN4NbvE2SLIdTz/2Adw16TcJ4XQjT4exck1YTBZNyEwNtR12aDIyKp23s/Wcw
jTXvGO1QHZhEOF+d2D9qci0K26ealPeSeFCZldfgX/6F4bL2z11Tv+XBhF5/4F1CIOBxYXLEw4Io
qnx4EGl44yirtqk+TU6dixNuvLoIKASc6l/4mSibpJuUEuCIpsquzOqrgnZhQmVfBcfok759TLp8
C/IvHcc7Rp2ZILEr+ru4CT3ahvwRo734wcTPhLkmgNqopXZEKwKV49VLpSdf/d/9vEmj2rPv+l3H
EDSqjk08tU15JcLgW3mo4+fyG0d1p87lk1ee5bA84qoM/fyxp5Ze2q8t6LtslzahjtU5Lylc1au6
OvTPS/g8O82SXwKI59/xGCS8Oq9sQT+tmf5tabNniWovRKRTB0t05UV+iX/aATFIubUrQo+6Jky4
JilztUN5c1zl23Z9pP4ezrv9/XOHz+8fj7F2I6iX8hrsH7O839oZoUl68uz5f8rVT7+fd+JC2d/h
eB3X75vD+1f3b3nSRvRZQjCPOHXj0QzqhljshqFyOA5fNx+UUd2wZTytiUL9ftjPt/zr3+zIqCAP
w2ycPxxcX4wltGs8V8ZjWHxsAHtUgo4yaVdsV+V9ON+uc+pnOH/+Vq7a7rt+D+d7vv+tHMZ/xC42
xYoQS6H1T/bCdUh9+62uicLYu7aoE2K5G38E3+F6w1V78gZr1yF9afiY6fDB1nlsu7rXBl1D9NXp
cK801TVh19/EX3lnA5VnOB7txTXaMZaZjxqbTifv43LMsvsG1/r77u1uvW3w3NTFa3XrrjcQ7gff
ExEGw19lu+PO+x9zsM7a63RLHjJwPBj8W5WAlbZ9z933PzZpgw03eOAmzqrEN61z/iw+dQMzet+y
+7q77ryr2WB9Ysnasz/9rfKz64vWun/F0OJF/3vzdVplmi8HDdqH/q8sd9498BBetqi1/8VrDcrz
56nnwMJ39951b5ufrP2QtZstmmq8MV+KVflQV+yZG1zaShsjr2LbrzjzHQLziUA8AFdQGwycAZvJ
jcm5pZwGeyaR9pkYG6gTHEx8phOGB00MIm8jIqAJBINjom/w5+5xPzBKhCqChYGh82qQZVDqIxiY
OqYflKO/TVxThcpjDQLrOAbRINBA0iTcMiuTzXEPRCWTHEwMeE1yiuVUZcNomM9Ux9puEG3QrL59
TA7xlK5gkqaNTRX6d9Sr7tSn89tFeNBu1HvtmyqeVdle7WFVzp2Jc/Qxz1sifppc6QOe+cUzSt/T
Fk24iKsY88bVL3DWr0zITYSdy9PLMlv91bnqQLyWDeNHVCEAE1vVr7YhPfUjON7fBAh2AHsTNgIM
9ib5/tbf5IvYxE6Y/DnXxI9YQHiSJxNHkyVtjoBjguZmw3/8x380oYkIKBAonbt06dIHhE/pEcGk
XR46JTDKl/LbT/xUNqGEY+WRNwEjv53jeV/KpuwmuV5wgOnKtPUW6Qz8p90Ntz1lIlxhq/0TdE2W
bfORTx/nmfQS/wjGyujcCjjy4iIgEp8cp5xu5JjgsgO8SHfaaafGndcpPm9605uamF/xrMlvSwW9
dIEtIi5oLybX7G89poAIzg5joa6V3WDVclRL/4f5rYn8alPyJGC0sjZIvvUz57meuPapy+WF5ZVr
efuWF+d094nftdmLTlyHPZOw7A/BDAv26tCBkKwvuaarH2y0W+2LELiifDp+VYO2rs+zRRWP7xWl
2U+PvdKH2DTtirjHPuo7FWf/+IXyG1vXGkK8duD6ZFmststefOxjH2ttQjtwrSASOsZ1wDXeIwV4
DNbxxU3dOIct0t+9UGRF45A6d9S365PrmHqTD23Ttc4ybKKg/qZeBXVd/da3j/ywg66l4pJ3+SIE
s5PiqKCNu6a5kSKd/nMm65hJ+SYm3XH7Hd311w1E1Wv+2F126WXddg/brtvrkXt1hK1xDurcWOLG
mwY3na6+prviyiu6jTbYqNttj926LbcYXF8X399epltGrO68485mR667/v6bVOzSQQce1D10i8Hz
RNegqHLfPfd1N918U3fDjTd0N15/Y/f7P/y+pVfX95WxhdMt71TH6WfG6hdceEF3w/U3dFttuVW3
x573vwhwNvMxVf6mu11e2Yqbb7nfEcR49bprr+u22nqrNl7dcP0Nu4H14GLZ3XPXPd2vf/PrZifZ
CteO1ob+bHOmm+ZsH6eMVVfmu1tsvkWzxRtsNLgpORCyE0JgEgjM/i2QMaNmkkw0eP/7398mXiZb
PEeIBybMvg0GDZAN1GyrAVUVtQZS/hZfDbJqv+OJAPUWRobHnWNpGXgRfioQIk38iAsGYAadJq2C
7/JANOgnjhi8M7ziNGAlIFRguMXT7mz0DLL8MPAmdQZ1dfdXvg0i8XCutN3BJmyMe1B3fTGHYDKV
h4my4mYwbGA93dBvF5g7V9sp4digyyRyqlDtTTzqGXd5lncfE0wDbxPp/sC8H5/2Z786de64BOUh
ChDITTx5GWBlssRLC0Mf3mpHH310E26wFfQfS/O0WdxrOSXe2i9uBDf9qsQ/A0R8DFQtD7UsV7o4
C15kwPPXxE6e9Ff5KVvgHB5C8mzSR3yyJNDEzzMMefgRd0zOHOfbm5sJgF4AIK+ELWKPCZg6JxiL
w1s8TeDkRTv1fC4TUTZIEL9zCRPSlhcCBZHFOWwBkQ+v8lJiS0xItR8eTZjwKJW3vv1pCczQf30x
woBr2C7apr36CPb7YLF0IEAQUDD3+dSnPtU4qTdlVk7l1TY++clPtkm6Oqg2X33I8YRf9c+2saG8
ukzWxUFE44VHfDUQ1F7Y/zXFZBgtO0yElC/2SDvTJth3deybXVBX8qt8uJXw4LeyjgraCxtmf91E
GnXcirZVPblWiKtEpxWd19+vDFU36lO5SsDvH1e/2TB5L2Gits/Wt7arLWo/+pm68bIk7YQAry/5
LjtfdSN/vH6VkXBk+6ig3tkC9qy4jDpuRdvks24MiBNX9TXdwJ6xO/KpftmbsiOj4pEG21XXp+mm
M27H4VL1zMNPO8SJTXJd9nxK4yT8a2zoRo524nqBo5tQjiUU46XvaNNslhe+ENCqjZQNxAl38VZw
XvVB2+WtbKW2s3RgK90gkB91p236u8axzmfbjC0rHe3Eh93Rhl0H2Bv55gV9wgkntDwYt9qvjNo0
+yT/rnvKKx/y5FvQPvyuPFcZxulb3m++YfCyqLN/3mwxj183Znhkq99xFgCJezffdHNrKxecf0F3
ztnndBdfenEbb7iuEkI6Jmv6JqS7/bbbW3znnHtOG5tc/NuLW7vfbdfdui0eOohv9OVptZsE78Xf
Xfm77uxfnN1deNGFTZy+/IrLu2232bbbZdddWto81GYraDfGrcYj+sohTz6k22HHHVp7WXbv7OVj
dct7+x23t+vc+b85v7vs8stama697truiMOP6HbcfsdWtzwuCbvmkG7UswnrPGSdZiusaFh7yTyZ
e2h7w+gH23ipqit517+NB9XVHpvu0d193/+uBlpdljl/JQmMqq+VjGKNHj7f8zdU+AiAQ0CG/zTo
PXVwx9Pg3qTDRLEG9ibQBlgGfiYBBB0DNoNA+wx0ytvGAMnfBv8mZyb/BmoVeAV4a2J5BzE+n//8
59vA0nIz6RDzPP/L4JJB8rZYQoB9BoDuJkvbZMqxJvnyY+Jr0MnzyQTFfgM9A7qlS5e2Ce+wtwWB
i7BgP9FBGeVd+gaAymrgSrTsl6PKM27fBuAm0UQAg2EemLiNmqCpS6KKuuIpNt2g/RBW1JX61gYI
W9IRTNQMJLUZ7Wk4SFe9CAQjdWZQJi75FD8Ri9dWCQL9OLQ/k0p5J2QM13n/2Pn2WxszGfbQdWz0
SW1ame0zkeLNRTQnZvUFGgMvZVVX+o1+oZ5x0k+ww/bQgbcOodBLFrQHAe/q89p6TV70I/EuHfQP
HhX+1hf1K/nxMXDgYaiO9EsTRfzZD/lTbzyKnUeQNSF761vf2voskUd/Y3/YEsdK3ySDIGXSZR8G
jlV+5Ra0KZ4Y8mUSRhyUL8vQKv/O04/lT9/2XDmDNOcQcJRNu/ToA3bF3zMdiI3KIMgf4UAfUF59
xGQVA5NGdaRfEC/1G3kjwKpD3nsYuElDvFQmcSgjm6d8bJXz+v3ZbwKuj0c6OEfd48RGyoMJnb95
/8kPL011PhtB+vKvzZqAm4zLn0k2QVqb8yFgahM8j/QN52FLbMZvVD93jD5AbFZGg/LVCdhpg+Il
Yrh++T3ddqNs1efYMHnXZ0bZQX2emMH+sgeuf7MdtEn9u+rE9VAdsUuYypu6s42t1V8dq82Z/Olr
xBN2ejiwRdo1r9WjjjqqtcXhY6bzN/41NtGe9TX1gp/6mk5wfolbysyuaFPi9ukHQo8+Z1yhb051
E6p/zjj/rrrkrefaxC7gzMay/35jx1ax3/qntuAGFLHNOO7Tn/50u+Zr687BT7vCzpuZ9V19SH9m
GwXxq4Oylf5mm9hPdaQ/sJPGGuIUtxtbrmPqn8ezvspu2idoj2yotie4DnjmKA9iq0zUp/YsXXHz
YJcnN0iMRbQt/dbYiXDpeqLM8iBf7Lug7bv+4SJv4xjUx/U3Xt+EpZ+e9tPGzjXTdfzue8ZbHLAc
9Zabbmn2VX3XzcCNN9q4I/wQzAg70xXOHGd5NHt++hmnN1auD/qC+AZRrZkwiPfeewbPTL78iu6s
n5/V6oonmvbopuddd9z/CKVB9mYlaDPaxnnnn9duxrKVhw7Gm2yIpbNjEwZZJeief9753Wmnn9b6
PDt2z733jy/vuW/wwrFepbJL5htsi8Du3Xfv4GaAS/YssW8JT/Ef9sNteTB6b+Vh3zjNyPt1fxo8
tmfgETuuNmuK4o/d5lH1NZ8KMd/zN8wqAuAwkSn+NmEnFlhqZvBkAG2Ax4D7+NtkxWTRw/sNgog5
BsMMoAGSiwCD4s6vAdHSpUvb5E6S9jnXixoMrE3ODcAM5txNlabJnuUVPII884oY4Hedb4IhDsKd
wZh0DdgIEAaJBqkuvCZ+gvwZvBIJ+pNEeXGBcqfYZMGk04CUZ5EJjvKaeFkaaCA3CcFEjNBhoGIQ
S+gkyBjg9gOO2B533HGNA1EJr+kEdeECaFJFjMDdxFAaLiyYqxtixKgJOQHERQl/9UgY0OYMwE2e
DawM3IkDyiKNfpC+9mOCyquowvBErl+e4X11zlx8V7m1PfmvyQSeGBC767l9w/nD134iHN5YEOL1
aXWv/Rcz8VUgzPF0NbiXfgX913H6hTT1A88tK3bqkk0Qt23qSZ/1twmQyZHJlzag3wrSIuIRE9Sz
tmJi4RyfpQN7oU7ZHUF+lElbcV4NTrRRv9kGH5NO+a/z1Klj5KnEE3H/1V/9VZuUmlhqWyauxLQ6
piU6Q/9pp16cUB5JJp6ELeVkw9gdIjx7ibU863eOkW91hbdJLKHEN3vHRqkLeRan35aDm8Cyof2g
XsTDvomDjcexJsX2q18iDnvOLphIS382gvQxkrY8+Wjn6kS9H3vssY2P6wJbTgDXjrVLA2/XAbyI
4uxMP2j/rmUYW9IsSG9VgvPUm/ypLxN+Nkzdasv9oN2VGNC3LY7TVrVpdchOEcjY4Gq34lGnBuQn
nnhis5e8Zlc13/18rcxvfUv7JIJUvySiur7qz/oNMZq3FEFH29SOlFG7ZHdcW01EtUvtrljgo53x
MFavlhhPN1Qcdby/patepKtfY1c3iOq44lfij+0Vl/Pku9o8uyRfbAr7Jr/Or2uXsY1+qp9UvJXO
JH5ry/oo28IbFG/1R2TDzA0l/Vef1FbqMQ/GXW4GEQO1D2M0vHz0bcIvO6jtqzNvANdn1YuPG9LO
0T+IGgQ8N3rUg+C363y1O8+8ZSPEo/6lL+0a96lHY1Rxq1ftWxyuldq0b3ZEHgiU8uw6Jm/KWdc7
NqjGv8YyREc2odoWu8DW6gPavzLUdWtc2gdGm26yaXuOMPZsqMB29cWPcSlPP5+WN2648YbdgQcc
2OzF977/vba7lW3QNlc2mBBvuMGG7QaVpcBuVgmrGt9005euZzFuv8P2zdNO+/vF2b94IO2eRjXd
KFfruHbNuPG2jlelNsMDd/99929s2nLZ1Yp99k7G1Th1n3336TzTjyh2/gXntz6sjMPt3zMx2Q72
xBhkp6U73V/3I4S32SvF/SmxeewYe2cMXterZYsGz6odtB3L043t2Xhjrs02vX8ePdv5THoDAgPT
4/mdbj6ttWStdi2dDwJy1U15TptPWgrP23UcwpJq9OOQ2bnIo8E57woTYgbOpMQAwGCaYaiPijfA
cjfEQMrA3QTAgJnxMHETaiDOQ8CgUbwVDNYMGA0UDd7crXVH1+DOsS5i5aFigG2i0R88yas7ry6u
pw6EOgKC+mXc5NtkQz6lI10ikjhqEFj5UD7HuEgZgBoIilNZCS8GbpbJKdektB8TOEKPwRyhzQD7
fe97Xxv0YkWwMalWv4RZg+jXv/71TXjTFgQs1BEjZRuGFQz2TQq0kaVLl7bnSBIfBINzg32DZW3G
8hqCTYm7jqk7aSbHLqjaiYmC9uRYIoVBtfM/97nPtTaovmvSaeCuHSlff9m4utbGBBfEGqi3DX/e
pt4rGOg7Z64CxkQdH/kmkGmbw+LOVPlTJzwaBOfrqwY0fZGhf67jtfXlhb6Yurzj1DcREGN9Vd0N
B/kwYfRR5441cHL8cHAs71yf5QUCwIoCO2IyKV11XN5YKzpvVfZrP2ybutOOtTsBa/1KefRBApK6
0jcFAzVM2FT2lC0kWrJTbJTjDTQdZ1IqHoKeGyj60ihbhatjiIkm6Y7ts8YFE97Z+pd+pr3NVjCJ
Jriw9+yuNsPummS7WUFswRND5ZY/+03MnffhD3+4sezbE8K5G1NEKBN28QrqverC334P9/W63tlf
6fqtjblOuu6oAxN93k24us4I7KI8Ew4EPC8dCGTsK5soH258uUbJm34pr+q/b39NItm5o48+uh1T
eZR/Qb6H7VjbMYP/SYstlld9mjCv/bDNQuVRXhyLj7phf+WdWE3AddNGOyWEsEfEI6It7xvCtT6B
eZVN3OIcrhv7y05XvdhmLOHa4oYW1sYEbl5VXrUnrNSL+hD87Vh/62c+bINrF3GXiFRjCvUiHfuM
WXhmuiHhulP9zf6qI/Z2EoIyEcbcBFU29sr1W5nZKG2aLSH4uU6rL/ZaG/dMT22azcJTf9HW2Vzj
NJ7eBFZ1L+6ylYcOPIbEI9injuTBtV1dsVPaoXPsrxuG6kIf9LZi7VA96YPam/jYStc4dpSHJyFb
m9Qn2V92hU1kq+VTOR2nPztfWtqZ9i3f+oD2xR47ThziqyBf7Ja81M2v2jcO3/hutvlmjdn1N1zf
feTYj7Txnu3jHoh02sPBTzy4eUGx4VfdftWDvKSmXc5F97dVz/sjGGk/tYpl2nGswoG8uggF2v3S
HZc2m+amylzYn0XdAMKgaeinrsvC7rvt3vqXfoL5uARc199g/TZuYONcT1zLXMdaOXsFcazrGnvH
LrhW7P+o/Vu92DeXgdDt+u1GCLvF/i1Za7Dqw79BP/bSjz332LN79ate3V31h6vasnHjd56OCbNP
wJJs10vjot332L3V13yxt7ymb7v9tu7UU05tjxpwnd1u2+1aW5p9UiuXYgTA5fDSwAzQGAqDa55H
lpIJBnkGUPUh+BiEedbWqYNJkKUTBnuMpElkDYbFadBkEjksvImXkTSANmEzUGJYTXiJACaxBkwG
aP1JqvME6RhoidektgRAfzvH+TWp9re4Rk305dGF2hJjZXDhUn7nG+iJb7qCy/05m///42Gwbnmo
SRrBzkTJxc3AWpkNmk1QDSKIf9qCC3gZInWsPTjfJNxFD2NtyIWG14p6JCZYWll1SEAiGKtrg32e
OerfcdLV1sTp7bYmHi95yUua0GugJqgjExGTMEbSIMOdLeeYaEjHPh9LTl2Qq961rRIwDcwM2AmE
JXIQaRxTE2plkU+85jpg77OqYXXPX5V01UXV+4rOn4s+pn2u6aCfGHSZ7LJZFdhFf2vz+o3+RVyp
Y/Qz59pnMo0jrxuTYO1Smzcp1bbZKfZKO622XOn0v8VtgsrzusS1/n6/xcH2y5/J/GwGbZQ3nJsC
yuR6IuCAh48JN7uPCR6YEc6IU25kXDoQCtgTE26BjbDNNcLzJKsv4+ecCv5mE6pNsG2ucTwYBKwd
jyGRiG1x/eOBTMj6wAc+0MQugobrCXGXDWM/BHbqox/9aIvPuTzaeYayW/Lv+TsEJcJE2d+aQBlk
OR4HNpGNcr0U5M8123XU/jUVXBMJnZaHy48JAhbSxEr/dR2Qdzcs8Hb8/8/efQDbVV334z9UIYQA
AaIj7hMIEKIKRMcIYXrHDXAJtuMWx8kvkzaT8TiTieefzCSZyaQ4TlywDXZi3AEbTBU2vfcqQCC6
6KJj7P/+rKf1fHR0X9FTe0+cDVf3vnN2XXvttdf67rX3Jt/RgCcUmohjIQ6tASPmaPLcFlB54Tv9
5VsQTz8wbvW5YI5OunqvX9CFPkGezyzgER4yl7jNGo3Md3hKOs/kKUjPq0169QAqma94jFlEspBl
LlRvbTYfqrcyLTpJo1zBuNSeDHjPuAYqyT/nznw/Wr7VHV1z3KGrtuYChDGFNuiAJ1J2AcvM92in
z3zwLV5J/UqfZBr0SFlZl2PJC+mdicdcTpf8nnRVvnQ+9BgyADCpT8zt3ivXc7yoL/3tOTmqHvWy
9B29Bq+kXsjIlwaPa4c0xga+USf8kPXSHrSTp/jijsYAQEDjtdfqPR+zWxsSEAEqLEmIdDCjkv9Q
Qrdyuj0bcl5FzAClxq4zNsZppBukKgOVpx3O41t7zV59jXzpFuQxXFohcbe0tpvisRyH3cod7rPg
6X7KXSTPwuJuUnaW4sNzHw79xcLbhI0nlIm8xOyC/w0574UFNWmX/eF1N7osTNb3tUTpS5vRlZfc
+PXGx9xe1xv6Mi3xjI/pe0yPy3HoMsoZCuC5pPXPMiMdmg7QL+LMf25+9eOf/Lj3HNbx61UHH3Rw
VZlKSzofoA6Qnz5FVgGTpRvKBSBZ96HQPevtO/KPCvQ+HW4+9TyH8nu45QwnXbc03Z7V660v5j4y
t/rJj39S3XbHbdX49ct5ufqiRqt6/PrvwfKux/W7W74D5WGcvvO7d0Jv/fZZ3465ja5UUdPx0ggP
7S3AA3QQBQlw8/Wvfz0mQkq+1XQTGgWHYKh/ACmUmrPOOisUKUpVGl0DFLPYK0wlHx+BMZFK3GKR
uzyguDFqKZlC3dOIoUYxjQmmS9p85D1FlOGojdpczyfjrSrfDCmKtq036G3bikktt9YwWNCh0+mE
VwvDmVJRD2jmY4sMzxteFRRzQCyjSb6nnXZafPRBBnSmWDMEeO/xDv33f//3SMfIY1gw5H0DZes3
1MpDfzOGGWVAS16KjHfxGZwUIAo6Q/zjH/941SltEJenCW9GCrkgPgPdRM3jAz87A4bHQIKEAFGr
wrYDOTttqGBWFND+01JgIQWAdoMFxu1QAt72kSeg2lhOYGQo6YFT5Jyx2y0d2Stv7/1e0QHQZlyS
PwwHATBGvgD/LBSQ98Y5gJDXHePc+CZ78swx7RQAqMAoiw7aLQCYyCwAXAbp9QEj3jg39oFWCTQB
DJxTa14AhpCf5AswBFBHDrkN1RyqbPVDX/IF0AAsAESRO/4mn8hVfUhuKceKL3BJ+dIDFbTXXAxM
4U0HIFUvdBLIbZcoKAtAI9/lIafMiehM5tIVLMQIPKTIX0DLzAK8mcfxju1E5Lc2m1fIYHMFOqIP
OWxeIMs/+clPxvyiLWQ0r7uU0xan8AM663cLO7beAkEF7/1tfgLImfN5jKIPz0/xgJBoaxHJvKSf
Ab3i4A/11S/qmv1r3tFP6pz1znkR4MWTnddip8wv5ovZZSHUNnTtw7sCT0Q8amEKfZIn4+Uo+kff
m7fJHXzpb3TUR2QEHvcsdadsmmdoi8aAM/M7XVIa/OqdPMTLII7n3YK4+rmbTpfl1+tQ1w09V6b+
9Zu+6He2xzOfDPIzjpSFp7RXkIf618uTB9oMJMO1u97OLGdUf5duAoygB28hYAfPIqHZr9lOBubq
a6we6cRPugJP9Lt8mnSKNIXG0kU5BZARV7kMZmexSbPWGr19C4DrL4gvneCcOvm4pEE7Bgr1Oqg3
UEg6z4MXyjNtztDNYI+yC7gCWNGOoFWhoby6AUX1MuWLVi7Q4F0oL+V1S5d1aH5n2xcbX6UOWaek
fZSd/VTGBVm41pi1qjVXL+d+lvr2R+M1Vuu9oO+eu+8JebrTjjtVO+y4QzVubLmFu9BIiL4r9DZu
PLPdsRxFV62zdrE70LGcZ9ikX6aRPvqt0D36f2EeSU/1Vrdsh/iC9Mrz0ZakBZ5S5ttvvR10te23
W/rMIzIb6J9Cy1hELCLtrbfL2YvlP/83Q9I3acDrC/C21uq/5+FmG+Sh3uosHTq4eZgHX/I+GZa0
E+eVV1+pLp99ecyR5mk0W3PtEr/wEDrrS/FjG3kp3zjAV+i5GJ8sbET0hbFX8k9sAC/bGppytFl3
7fVe/ZUXYwX4iMdKXiEfy/Nu7WjSbkn/zr6WDs3U29hVV/Vo1jXzFy/kQuk/6YS40KXUu6+dpc71
EP1a0kkLLIt+Le2Tj/bT97R5zdXWDD6TTwZxgLW/vLDoeJdcFPqCOYpsxJNZ34yfNA1vziL/3ny7
9+g18UOm1Hgh0wT/lLpFHxgnRRYpVx+gg37Hh6UFfX0ibYyf0ncPP/Rwdc73zwnnIDqg+dD8H7Ko
HzmWZa/s796ZaWXXYgSWj7F4IfDaouzyUKC46lihm0FhVZTCzkuEcresQpa5pPkZKM1gEA4lYPwU
BBj63RD0GfSeQs2LhXHJCCUIGErAPN41ubW2SRM8wyBiVOMBXjBzi2GN5gx1gBnPUEZpvR/8xlvA
QQYusI8Rx3DnkcdI4iEyq3hs2OJNUVenDARRp9MJo5jSDbRj5DHC8I528Tpw/l0CHd4xrPUz4zCD
+Mrs6ekJZUUbGJk+gviMQvXTpm7jIPNqv1sKrEgKGBP1cbEkZXeTlfX0K0sG2ubMyFG/lEeUdWPQ
O1tXbM3L+UY9LVKJz8MSSEiGSUMJBzx4D2SirGS7xQH4WPEGmAnkkvEP5CLX/Ab0ABgzmCNsUybb
5E0+kQm2wAJ+eHvoE/Uje8guYJZnylEHHn7AFHIuzyskA5UHkCLfABdkpPby7PObvAWCkWPS8pjL
QI4BM5UDnFzWQRvRUfuVra7mf8qsOpHzMwv4p2y0o8wDLIFe6qZvyFn6gnYAQ9EPMEvXMA94zqPM
ghAQEfCZAU+grzkJ/dXB/JBBmcBfi0op/z/zmc8ECIknPJe/uU7eQF7fgEx10y88xsw7aKh/zI3m
QcCw9poLkqdsUde2nJvUz/yFr+r1Uj9e7vhCGnno39EY1N0HHQVjL+UEvhgoZBpjDD8I+ayZDu8M
FvpL20yX8bKe6p/5kwX+Hqju9fcpO+rP6uUpK8urP19Vf4dOV2zfx594vHriySdiEeDNN8pCx7j1
qp7JvcftNPUlvE9mzH+ibJd+5OHquWcL6P5KubylGJbOIOvp9IQskA6dGbiMUUDKM08/E3re0089
XW3b2TZAdTLcTbfPzX8u+nHiZhNjTG46cdNIX6e9vPz/2huvVQ/OebB6+pmnQ9Zrx7aTto0FCmV2
C+rNAAeguNWXR6kxT05vsOEG1bh1x1UuDlGvbnlI7/Piyy/GRR3ycZ4ceaJs8s9vdWSYC2iiTPPR
I3MfCXn74ksvRv5k56RtJgWd0XsofAd8mP/M/LjJljySP3oEmFfGr9ucp+44NeR2ADkFFJv3yLzw
RiK3zcHK3XyzzaOdEzeZGOBB1ledo/7lTDmLPbyftXm77berttpiqwCdAE7iAEXmPjE3ZPkLz79Q
vbzg5QBWNt+inG295VbRhwvJEPOyPnrt1deCz/Cbv21ZzfnYXISPyPdOp1Nts3W5mHJMuVyt/Ked
ZLpLWJ54/Ilq3mPzQh7TCZ58+snqsUcfi/5c8OqC6EN9wR7I9No1WNAmZThP78UXenex4UsLAmwJ
3qB1OqmTvx9/7PGYW+Y/Oz+AunXHlp1vZRxsvdXWsa3SOMADgjKEl195uXps3mO9ux4K7V5/8/Xg
Hf0yZYcpsRABhJU/PrXLC2Azt9hm6mh+vfyyy2MOlWbLrbeslGtcPjv/2dC78Mmuu+xabbHlFovJ
RwCYOT90gPnPVOouLdpvusmm1SYTN4ktxOR81l1/AVlffunlXlnxZDmLcN1yXuLUnYOfze3o9c7b
ZYFnwgbxHO2STtHwYfwT467Q7aUFL4X+YdzpH7J8owkbVVttvVVsmQeG1seQcqU19vCLb8cfeOZm
8I0n9u62MQZWL/9pm/4xbgBo6I7XnnyiHN9TeHr33XavHnj4geg3Mst8hLbbTS5nopfzVeUrD7dM
s8XtSKDPWHiCx1x6+aWxWKC/2NPoKo1Aht4/5/7q+eeejzGqbfifDN5o4+Jdj9eKXNMH6uiSoqee
firqAjik/+iLuQ/PjefhoV9kCl0IcA/wx0t06jkPzomdKhf+8sKwt3OR1ZhETw5gZOLS9tswunpI
SdotwP2QCfMT2oQEBYmyblWdgYQJTU5CGmOUcKv6VtUZKEPxcOmn6JX2uD5Rp1K40iqzEgomEBi4
jDeAmUk0V4gYWj6EsAHdXzChMFKBbYwfEwMlQb7AOYaUOM3gGaOWIeYsLekA0AxAaRlnDLmB0nfK
RA/MUz6AjoLCMMSvWf8sWz62NernFJzqhAdMVOJ7Z7W/GUd8dWFktqGlQEuB5UcBXle8g41bRocP
kAYQY1xbaKBokl0ZgEnAKUo7GUYWMHCMWfLL2Db+EwSQjuz4/Oc/v4gs8Nw8qBzlS6MuzUAeArfI
BXLKIglPRYClOZQCpp7Klg+FLetCNiYAIl91U4Z5ti5/yU7v5K+9gvLITF7bfvtkIMd80KlpdGec
4X6jifn/pJNOCnBL+8h6bU0jmIeb9qaekGWpD0854BrFV98w2tBW27QTTQT199vCkN/Zvmwb2S4d
WqYnZ8ZRR+1WB0E98ESn9LN5hUKu3Jxbkifwjjqgsd/1YC4wPwGeeR2aF9RPvaX3Gx+qn/Js/aQf
1Xkz645mq9r8oW1LGoaTZknL6Ba/W7ndnnVLm8+WNH6mW1W/Gf1unLUgcesttwagxpPLRQj0yVNO
PiXGIN7PQC7ffsftcaHQA/c9UI1Zd0yAI88UIIH+Rk4cfeTR1UEH93rLMqbvu/u+KOPBhx4MUImO
auGEZ9nV11xd3XjDjdVzzz8XsnuLzbcIeWrcpizIshnYAI7ZxVPXx7xCFutXhjtZon4CQ7kvlJ+/
/c1vAzS84JcXxEKLNgHeyD9AHjln8eOMyWcsBpjIh3xi0N90402xYA3sAGitPWbtapdpu8Qul333
KUdHrFu81suwUhfbaB+Y80B1xewr4kIPz9Q3ZG8x9s13FhssVAwFrIr2FeP/jtvvCO8dRrt2Ttx0
YrXl5uWM9AIYdIq8XHe9das3Xn8jbLvZV/Sere5v4ONLL74UYKVt8UcdeVQ1qTOpSrAp6FWmZSAw
IOOhhx8KeU1WA3WiXaU8YMzNN90cC//ah3ZkJoDX2WLTdp5WfeCDH6j22rPsPiv/kd2864Ggd9x1
Ryy0mF8BeOzQq668KkAli/zm5j332DMWCffdb99qvXXXq5594dnoOzL8jjvvCEDFXALguOjii8Jr
G0/pSzJ6t117HRfyHL/Bxj268rya99C86tFHHo122xFw9113Vyccf0I1Zfsp4cGl/QKa88oD7KAv
4AWgA/wCMtEZpu0yLexqO5MARLy0xDGXOXaE08MrC16J7aH4GEiFHy2onXzSydXWk8pCVvHqcguz
NroR2njVFsc6AcHMdwcceEAA7Owu4A5gXN2B41/84hfjUpn6AgnACN8o34U55jvt0W/GDvpP7kyu
9jtgv9hVBRSSnoMGQNhRJS5RgTMAnl4/+vVoP4AL7cRdb/x6wdd2RwCDk2691Fuyf9UPj1x51ZXB
z3gEffEaeuw0tfcG9/322S+AfLkDr7zp2JMAAEAASURBVPDCnIfmBI+ih7jGMDr57YIU45acstMB
PynLGCcTgaPkIp6zSEy2AfXuvOvOWIxUhsUC/GEBlA7CA9XFPZdcekmMH+XRf+1iILfonPp3+x22
r377VvHILePs/gfuDx66/bbbo37i69vNtig7FA44sDps1mGBzYxZZ0yAmOI/+MCDwRd33X1XLKIc
cfgRUSeXvOkXbSTDAcB2nihTvwDpyU3x6HKCbzs2Nlh/g2rabtOqo486Ovjwd2sWZl9y9SDyXJ7/
vDtcu4ZBQUKMcm1QOkwdA//Hf/xHDGLPEgQyyCnxBrRAQDFgmpPtMKqwwpNoIwRbwPQGr+9s6wqv
0EooUL9rrw8jLgR6ecaYIigHCjkxMp4IQUoRQeG7rvT1l4eyTUJpeOEz6U3Cg5UtT0oDnvWpb4ek
JMm7HuRJuRwsMOza0FKgpcDKoUCnGCA5dskC8ogiRJ50G9dZS/Iqt+qRRcAa8X26BeCNz0CBXBks
1GUYzwH1JZcohN6pu3IGqjsDyEd6Cqp03eSv5+S0rccrOgBPGV0+6rEkfYMWVoaBl2S8eQM99Km8
ch7xezA5LW4Cot1okHl5pww8QaZT6L2Tv7boFyAFOtcBu3qenicwqG+k71ZvabRlsEXQet3q5bS/
WwqMRgrweH3isSfCA8k4YgNwHHjkvkcCqLANzfjj4VYwgpDJ993be1GTI2d4zx5/eDk/c/wG1e13
3h7b5W3VtxBC9gLUAB9zH5kbYANPXsY8L7KxY8aGtzfwLcE7don3wAggwvtPeX+Ui7byAWp8/5zv
h2MD/ZLh2+npRH7AmKuvvTrAteiLmvoISHnsyceq884/r/rFBb+I9hx6RNkhVQ6+B8gAWBx5Y2GA
DOsWeNWcd+55AZ6QQWgFdGJrsTsAgeSUA/953ABVeEV997vfDQ8u9ACokqNABXS6+JKLA/hBY0AE
ugwUyJ+NJ2xcrb/B+tVjjz8WnsnmSnoxYx/YwovxrTfeCpDp7O+eHdkB8MxhQNbLL708wBRg0fMv
PF994uOfCG8v9QXWATa0lTc6L6PJPZPDmwsQBxDgrQawPfNbZ0b58gZSOOcMYPLVr341eIin2OT/
b3LUB50uvvTi6rprrwuQiAcTj1NAqPmWTUpW89KaWwAMC3H6RV/wun7+2eerSy+7tLrq6qsivXT6
6mtf/1rEF4/8xj/eSSt/cxznFuf+DRhKl7/5+psBgjvP13EleI1tyUu8KffffuftAHmcpQtQ3WXX
XQIk5OnKqcZugAA8Sz/b7m0HFv548fkXq/N/fn4cQ6KeFuS0j83q2BGefkByYM/pp54egBZeM8/x
+lMfdNLPO0/bOQAlnrL6C2h16SWXBqAEbMLz2lTnZ55/vHZ/+IMfVhdceEHQBYDY0+kJwPje+++N
84yNU0DticefWB1+xOHVxhv1nsV/w403BJhFbug3gLKygVYC0CkugJr7ehVevkVuALcBX8MJgDog
7A9++IOoD684uzD0vSNX7MxAL/XRR4ccfEgA8Lw41dWZiXfecWcAdRYTtYO36s233hwA9i233lLd
98B9Ad4fdEAZf4VfgKN2DAA7yaJYECnb2nkNWzC1UKgfHn3s0fB4tAhAFgDZLFAY58YjmYA24vP0
1V9AfguYZNlbv3mruue+e6pvfP0bwatAb/oVR5rrb7g++Ij8wIeAVN6yykWP2VfMDpAXsM57EJBs
TPEEduGNegLvjQc8OXm7ydVmm24WY5v+t/dee8cY1V714yWIpp1JZfGg/F0cIkck+IeHWgCwn5Fk
QsRAH/rQhwJ8CQFeGIBggfhSfAE1Oti3ydvKPs+FTqcTArSfrEfcYwqGVRDnJhkkBj+BRCAwFAxA
W7xMyHUBOOIasowrxDCqe8kMNXv0QydK4NIEk9VwA/70aUNLgZYCo5cCdXlrTgqFYgmaI/3SyJEl
KGqxqIwIn3qgcA9VLmrvcJXdepnL6/fS9I05Ai2a/el5M3R7Vo8z2Pt6XL+b85r02gKYHCyIu6zq
PVhZ7fuWAqOJArx5HIsy85CZ4QFN/3I26bnnnRvGIx3bO6BVAkM33nRjNbt4kZCTPPiOO+a4OCer
M7kT4MvXvva16qYbbqquKWDcXjP2ClvEkQkAIUbpm3PeDEMbEOFSiSMPPzK28c17dF71y4t+GZ5J
gCSA3HHHHhcXewCmbA/99ZW/jvPKjelPf+rTYbibK8gCRwAwaBnIzUAu86S67PLLwijfc3rxMDu0
gFYbjO/dcle2DwLleMn1FxjfwA32EmOf1x2QwMVR0jpvts+WGr9WeCfyBmJ7AcAAZXbquKgBzXmD
XXvdtZHHJRdfEl5EAwGA2gg4APzddedd1euvvh7AEo8dto6tgs7fE+687844cxUI8dnPfDYuwUGn
N996s5q09aTqS3/7pQDOeP7YwnnMsb1n5q72WzBg71mqgBPAAu93nna2WAIGAFduvHdWqjwBWDyg
yOKdd9o52hsg2JW/CjAKsBEOBjvsGPRzrqCtvIALgA6QuKfTE95Ts381u/DNNbHNGW0ANj09PdFP
QAr013bAEM8lAAhwDX8BYoBgztf1HO8C/jhFWHDTrn5DOREBUML7lO2YR07kPNNM5/33vvu9AJ/s
eADkSStsvunmwQ+8vniLou+0XafFtuu5BdwE0gHzjKlDZx5a7TNjn+gXHmTyzZ17nHLQTdtsGwVM
AhWBeDzaTznplDjPcczaY6LtbP9J204KmvNODNCz1mTtBzo5IuycH5wT4+D//en/q9572HurjTbZ
KBbUZuw7I3joRz/+UZwLzKZeb/31qiPee0Rsd8XfQCUedRY6ny7bgPXRvjP2jduSea65nOua664J
8Fid955RLp4qHoUDkb9JX3U1PsiEn57705ALtmHbWYCe5JR+AvqjMzCQRyPP057xPUHDH/7oh4F9
AMh5G8/Ye0aAgwC9Haf2LjDjYx9yA0COrp1tO3GjOP7UT+rCG3annXeqDnvvYQHw6Yc8+z49qN0W
7RgBYxEQd+899wa/6kM0OPGEE3t1luIhjH9tHXdJCKDSUSlnfOyM2MYLZCcfAPQ8Ko1RWI3+5Y0p
L31A9qi337b+24XHAxnwi/7AaTgJz+7bbr2tOvqYowOknzlzZniz6mPp8Z3+BRICqemvZP1IDS0A
OEDPEMJ5Ho8JFKMShlZYDBooL7SaULXlqVOAPww6HNBogGos91fccQ0AXgDcvDPwrrAaYLI0cWlr
GxangIlNQCdCoL+JbvGU7ZOWAi0FWgq0FGgp0FKgpUBLgdFMAQvktr0D+QBawAVeLLa5Aa14gPGk
8sw5WYznZ597NuwJnizOxuKNZisbwzk9m20RfejBh8N4Zkxus9U21brrrBvGOmOUd7ezsxjFPHPo
7a/u9moAQ7yv6PfO3rKdcuwW5bKh37wTgNXPfvqzsGd4LZ140onhTQMoUAZAgC0A3ADWAQ0z0HOd
icazjM0ASFt9zdXDI8eFBc73AsSoV38B2LX/AftXp37o1ADELITwvrpi9hWRL0OcN6VtgOrjYgfe
Rrza6NfoxTtIPmtvtna0W71s/7zrnrvCcO+vbAsY6h3eW+VmdFv/pu89vTrmqGPC+4y3pDLFQ7PZ
BaC96eabgibsvFiUKmDQuDXGVbvutmvUheMEerhcYtasWb1bkFcvjhQFJAS82NYKOEXX9LR3yQQe
4JXEU4m3Ic9q3n94x7ZFPOBSKe8BdmiLt9xa+/KLL4f3IABQnrZWKhuwgceAHLaoAvF4T91y2y0B
aElrO+Qbr70Rno25DZRHJQDRkRL6zpZOvMIRBGB82+23VQBHZxjaXttfwCu87oI2pQ2AW7cfo3kz
AEWBaLYiayvvRyAd4AVYBCiavtf0aLv+KI/CmwoP2IJpqzyby9hjnzq7DZi+/77799GZV6m2qhdn
HcAuvhF4y6L3ppttGkAOutl2vuc6e4YdD0AENNaDepXhW91x6x0Bitk5xzPSOLLVGM0FoOEJJ54Q
W3yB5WxsADbwzTboPXbbI/K2hZnXon4jO447/rjKWXrO+eS9C2x/8qkno++Agr/rlAW7IES9Vv3/
5sEHs7jhphviPD0LsHAN23wB0Whp8eGgAw8KOotrLAlAzsuvuDxkjbFFvvB4w4PGyO/G/67aY+we
4aGIVkBEWAm8AP+EN27x+gTA2SKtD5z1d9qpp1U9nZ4AyeI8wIKtoDM6kJELXl4QfWVMGOe5aAxb
gbFstnmv51/JLrz1yDngngUBR2BZjAAc4hlet2SmLfPkCmDYdnjP1dG4tRjiHY8/AOz7PvC+Pk/t
DSdsWD0056HqkqcvCS9f24aPW/24GKMwIIsFSS+8528gc11m9t87K/dNCwAOQH+divlMqFZtTISE
JSQfIxIiJi7vCWDPkhEGyHbEvSI8ndvEPVsgEARt8THhidOG7hSw/ZubMLrxmPS3lb2md0f31O3T
lgItBVoKtBRoKdBSoKVAS4HRSgHgDs8R28KAPW627OnpCSOYbQDEAVowWgWeJuExWLxIgBfh7VIA
CLY9I5wRLCTY4Zsx74bTDTfaMDxk0t7Yfsr2sbURkAEckLetxuwS4A+QiNegbbq8u2w55i0DEJm+
5/TwHsubZJXD4FYn79k9i4RSfw4Q7B9Gs62ktlHut/9+Ydyrw6GzDq2efPzJPltikfTlD/ViqPPG
0R7n5gEA5cOIRisXhLjNGL3URxulEQCMwAsgxKtvvBpbR9ECyET3DuMbnXtxjEiT/9DReSPx6HP+
2l7T9wrgDPAEAOgDV0paW1J5Q8VZYiVfYJq+jFDeA5YAIwK7kDcXejkDTP8DXwGSzzz7TJ/nHnsK
0CQAG/EM4ANgB5SICzJKPwM8AXDapU/8HQDVWmPDU8wFLzztvHdOLyClp9MTbdcGHlgAZgA0EIyX
HwBv//32j/TAGXwqAP0AvoBVoJiAh44/4fjwBEQvdAVGHfziwWHzRqR+/gHgAbMF2yX1KU+telBH
wBDvRzRUL8BR3Hpb6IPXnS0HrKoKuQB9wBnHg+hfvHzA/gcE3aRlq+OHN98p22lLXROAxkt4W5oC
63bliahXabY62aoP9DGO0WWxUOLhV95unILwnG3FW2y2RR/4Jw3a8gQDqgJBOQ8Bn+Y8MCculxk7
bmy0JcEtgG96zenvceU/HnfoCADUf8lri9VpgAe2TTvjj/eabbiHzDwkPE1tMU4a4SMAsvzZsu85
6D1x+cpTTz4VZwWyaXm3AS6NXXQW0Iun3u577B51B3KqJ/kCcONpCrBzbmMGIDd64WXp0dolL8aF
cUBOkX/6vOrn1C3p9Ge5ZirGBfoCDrXJPQw8W9GwRIs2apOgrx64/4FYXJi87eQAe4GMnL28A+jt
uvuu1ZTtyjmV65QddCUL2I+zPQVjnDdjvf3xovlPKVfakR5aAHCQHiJcTXaEJSEbTFVL431+ao9H
1U8AJkUk26Y9Qv3vWH0ZVa1a/pUFBptY030ZvQjUK6+8MgBTCh2lIhXC5V+jtoSWAi0FWgq0FGgp
0FKgpUBLgRVJAYbu+uut3weqMADHjxvfd/4p4MknA7CJFw6gbdzYcXHBwCMPPxKeaUACnjQZgCc8
7Ri0PgzQBGrEkZ5XFuCFIeubF1Z6OtFLlc1oBkLyegNOdTqdMHZDv68brOU3oIvtE6H2juHutlBg
De8ZoAbgwEUePMuc/bnP3vtUC6YuiLr0ZrDovwAhgIJvQb0Aei7cUBftjfqWNvtvjbXWCKASICTY
nvnCcy9Ucx+dGxcpABy0W4h0RRf3H6CgGQAUvNps/w2vs8MOC/tH+Rnft0soACe8++StXgCrui3k
+Q5Tdqh6enrC4HfjK6AKjYBNgAdgBEDDea/ABAATT0vgBdvL5SE8kQBYQFBbJOc+Mjc8xvRT9GcB
k4APpUnR//o+veS0z621gBh9lqAO4AgozTuU9yBwBQAkH8AugDJtPc4K4flY2phhzFpjYhvyjjv0
bjdGVyCL89GSThm327c48gfwZjmLxCtFOTcOMCa4sRc90CVCaSv+223abnFrMpptsvEmvd5g5R1a
fvgjHw6AG4CEHgBYHlraqZ8Fdpk+SdrFw0H+Mb7Qsg/srcXHV84t5LUIXBRsWQY+NQNvQ9vVAat5
qRm+c6FNjOFCn+QnQKA+ABxGHxbW9XeOEf020Lb2Ztn+1gdv//bt4HXgLV6yrZqHsd8ZeMvhT+fj
8VoF2pJld9x2RwDlygaGAvKAhfWgb4GfvAgBafgMYOiIgqk7T42+zzZKh9fwKz4SgKnA5mynse9W
bHQeLJCJT89/OsaKftYmtw27LKkeeB3yDpQlLMcYBDD7qFvyJ34DRAbPFtr53zN8KegXfef5qhDa
W4CH2IsYJJlkiElGTTTtypWgUVPpEVBRgsoqIoHHNdr2AMHk6jnBwXPSyl4bWgq0FGgp0FKgpUBL
gZYCLQVWPQqEfdAwDIEsafwyUH0yACxspWNw8vBxXlt4ahUPE2AAIzRDpC3WK4O+a+jyGMBQ1+uj
7FK8M81s1xPoqLwJ6/Xqmn/tISDGOWQz3zMzthYDxZyRbnsuwMpOIp5ZnU6n33y72VPqG8b4wjbW
66TdttYBDwBGPNnuufee8DIMp66F9lnQqUbjWrX7fvIOs6UXeANEii2wpS+U31dmAaecYQisAZSi
Ex3/0EMODeCsL7PyI9IUugIsxq5TbmZfuCUQaDK3bGt0sQJwY9rUaQGiAB0ilC9bfdUBuAK4cG4f
EEvd1AcAFXwl/wHa1Y33gIRAaWAtIBiA55KYBAjrvBT90eAt9QTIdno6ASbzHA1vumL31NP2Nqb/
f6NuXV7LQ1vZT4Its8HzC8njmbTjxo+LegBvtCnLBiLtOGXH6vkXn4+LSmzjfLhsleftGp6wJW2G
gWiXcYb6bes2j9Dcjh7pfl/UotkUPkJ//SDoA/wH/ErPv0zQrQ+M30XkByIsSSj1cmM3+eJsTXlZ
GLD4UKeJ33hkm0nbYOSgs74A+KqvEHQv+SX969XgLRfbYQuIHd7LZczwPsXDXUONXsaNeg2nnQBA
ILtxJpBLH/jAB/p4Kh6Wf6KtpV0xRgtI6cbh2KrdIGf0QY1vpPcs6xb5NdLEs1H6z+9nmFHagLba
LQVWFgUIcCuIVncImBSoKUSshni3iPBYWZVty20p0FKgpUBLgZYCLQVaCrQUWGEU6GYwZ+GAAGer
OeDf9jmXAPAGsxXQ5R0uAVimoRivtq06kzAD75+B6pjx8tuWQiDXoYcdGmeEXXDBBeGFB2AAigAX
fVxo4oKQPBMt0/f3zTjvrx50avXm3XXVr6+Km0eBcm7zpIPzjPrOd77T6+nVXwELn9Pb0Rnw58wy
57MBL3g0AmWzHraNupmVVxEdnoeeSwMW8wqrgRkAD2Cf+IDD2++4PWht22TcNFs8ncKTs9RFW9kM
PDKd5ej8QGAqL0BbJHneeW+L7LBC6esAeEvZ6sRhwd9oOaRQ0vPOQitApXTySRoNKY9BIuFD9ZI3
4Eg/rrn2mtEHmRSdos4N8Ok3v/tN9fiTj1fXXXNd9eurfh3pbXt3uQb62a7NQ3WZh1KPV195Nfgn
817w0oJoB5uvHtSd11weB6U/w/OuON8BEldE4I3qrEVHAeBL504aS00QUF0CsFtIZ2ArHjZOBAsH
8bsLAMbblRdfesppJ6/LPrA7clj2/xirzkxNkBJgTeaEB2GpQ1+okVpdjeHWLm9vAe7jj/ZHS4El
pYDJ1OqdLb79BUJmyBNuf5m0z1sKtBRoKdBSoKVAS4GWAi0FVgkK8HxyLtfZZ58dZ6s5D++oo4/q
XVQuW/Cef6H33Kpl2VgG+Tu/e6d3O2nJmEHPg4axP9TA6OYFaCshkM8ul9nlogwH8T/xxBNxcSCw
Qfu23GrL0JEBAsMOpWpAImfp/fiHP66uvf7aAONOOvGkOHfQgfvKHaqerb6zDptVXX/d9bGN01lu
tpbaQu0cNgBBaWKAIQmY8dxy2QPgILdVN9ujjTzknGHmJlh0veP2O2J7tO2RzvezrRYgE6G0S/wr
f31l5ZZVF4XYRYSmO++yc3iNDRv8W1g5AFQG4J22+9a+oQT8wobRNls/gaDhuTbE9IOVwcNNvwHF
5hYvLsDamE3G9J7/1kgMUNIPvGrd1stj8vzzzq8u/OWFAW655fq9h7+36unpCZusv35qZDusP9Gg
7l1rG6qx5HzCZoizKgsNBfxjh5iLRoyhFRIKC6y2RtmKXS4n4ZXKM+/xJx6vdtxpx14wslEJPAPs
0+/qjl/0Ea9HYDX5UTZHL5qqlCH/BMfHFU9dwGeC3YtGXoZ/lXLxgzriUWd2PvvMs9H/zW3ASgVw
8hjFSzxObQV+N4d+/DNHN0kIE4iwCSjQ9mE0BzMRNiYyk89oCpjbaoq6p7v3UOuvrQa68xOg/0ua
fqjlrCrxCEkTQX+foSolqwo92na0FBguBcgtCjHZ4yBtygo5vLyCvJVBVg5XxqszOWuuWJ51XV40
aPNtKdBSoKVAS4EVTIEyrT0277G4udLWRV54sw6dVb3n4PfERRgBsvweu1lmlWPcM3rTU4eO/8Cc
cpHBEngB0nkffujh8MbbeJONq8MOO6z6+B98vDr9tNPjcgEAhzPAgFe33HLLUnva8EKz7ffSSy6t
Lrr4l+Fl6IxBF430dHrCk0mdhhpsud5vv/0CbOWZ53w8XoxXX3N1AAgATv+hE8CLbk9P4KGJVt3m
eXQFXrkQ5eZbb65eefmVOBORRx9QZNou0wJchC0K4gMo3I7rPMJrr7k2QFg3wLqhFKi5tOCEMtwk
q4/pJ26OnrTNpAAw+87Z661O13+lB+C4CZkdqD5bbbFVAKVDSd810/rDMgbskOJdSI9yKc0TTz2x
GGikHjwDH3/s8biQxI3WaIdm551/XnXvPffGZTJHHnFktfuuu8fFIUP1Os3q6O+hBnHX37DcTltu
7U377r5774vt1d14g4cajzQB7wGbw1Nw6EUOtWpd4wG0gdvOhERn50s6e7HbmDeOnnrmqRgL8x6f
F/1DVmgn3dy45k3YJBea4DEfcTco4J+jr4aLv3RtSHkY9K3RTdtsBXeeqDDvsXnVlVdfGfyBb+pB
vXhcX33V1dUtN98Sev+S9Hs9r4F+L488Bypvad41YNylyWrkpHUehY+JiKC36lFH6/urKWYl6Bl0
XJPdcIWh5cFFfDQEA5wrvkNx1d0BpG4SGqj9jF+rW9z3AafaTuATUgaxFRUXoFgNa0NLgZYCLQWW
FQVM6A5HJmsBfwn+MYDI7W222SY+3VZWh1MHco1CDGC00KFcK8XTpk2Lw9gHy1N9zRHSW+GXnty0
7URdUyEcLJ/2fUuBlgItBVZFCtCjecPQRW19A4B0M4xXhbYz9uptaxp/i/zNHl1ovAJQHn7k4Qr4
Zy6x/dQtt26PtfUUwGGrXoYsp36m1iJ5Z8QhfLssYttttw0byVzIcw8oYP7SZ4K8/e77u8x7aczz
BHMBgm2+zq7rdDrV+D3HV1tuXW6xLe34wdgfVBdddFHMi854O+nkk8oVrr0VW4RWJc9uodkuHj48
/ACKT5b51o6bydtPriZuMjHAxbTbFqvrovb/IkWxa2wXtfX2V7/+VbTn/J+fH+3Zd999A6jh/eQy
BAAIu4hd9dOf/DSAH7cV14ObiK+74brqgl9cUB1yyCHhQaXtgEs0YodtslGxIfPehQIEvv7K6xXg
yDbhBa8sqHbaYKew1XgmZX/n+XjRHwN5jHUhJR5jy9oGi6c223KzuMXVOYV9XogLG1Hvl2wX7z+X
u/DMYyOi2Xbbbxdn8vW1IyOX72a/1V71/azH8XunHcrFEcUbTvuBxVdddVUAZOzttFmNhceeeKy6
4ldXVPOfmV8dccQR1dtvvV1dd/11cQuvzHs6PdXW25QLVsaUC1YK3xo79Qszor01GqWept10Qtva
I2ScBu/U623r7jpj1ql22323AC0BY8YDOuOpRezkkh8dUT8A14yV0BPT4zbL6y198X8He794ikWe
qLfx46Ih/edsegsPV1xxRbXbrrtVPZN7AoAt0UJ3xecXXnBhbEXH+9tvt33cEA78JtMdS2As4um6
LHJhDn2aTgw3cJag/kiZsUiluvzRjf8yGiAv+wtoiZf7wL3ST3HOZZEJbmQGDhuDO0/dOS7AyXjS
v/7a63FD8CWXXhKettOnT4fED863hTYD1U89cwFCe/Fd8Ev2XYOXsl0j4XuVAwAN5m984xtxg5aB
+Jd/+ZfVrFmz+la8+iO6DsbAgEPgmQ/BZ4XCTa6jBQAkjC6++OLqrLPOiqYed9xx1ac+9ak+hLzZ
fvG19cILe92oDV4Dfc6cOWGMG+jvec974mBNQGAOxGY+7d8tBUYrBerCveXvFdeLFDWr77bguGlP
0BcUDIoKBdBN2ieffHJ1wAEHLKpYDaOaynPmD3mnPB9KmzIoSD6DBYrcjTfeGPOEulM6zDnSOg6g
DS0FWgq0FHg3UsDcScaSqTfffHOAB4APiysMpPo8u6rQh0Ga7WL4+bsePANgCLypbPvL+MA3i18C
L/SnnyzbCN96o3rrjbfi8gkXamSwmM8TC/DgEH90rm+vA3CEsZ1GZ0mo3PRsV2Z6/Gyw4QbVHrvv
EXaCxSwXj/zkpz+p3v/+98d5b+ZdXj5uo1UvQV0TyGAjvPjCi9HHnAvcqglU2nKLLQM4s3X5sssu
i3aaG/OsM3VUbyEM5QIaAB4Y4WGIA2MW0kqcMKQLzfCVesx/dn6kU+dnnnomdnjZCoqGwKOkqzIs
JMrbRQbq2wS88CMw65hjj4ktkW4ytiXYQiP6og9vLYuQzhjk+YQGF1x4QbXhhA3DJuI9aKESrdDw
Z+f+rDRjtbgNlaeRPNlSkyZNipuRnU+WnnPiAanUM0E+tphbh9HTOx5vPA4zvPxi2WlQnuOF+o2z
2v3q66+GdxN6C/Jf8PKCqBdbTv/st+9+0WY3Kv/2zUX5VB20A2CfwA6vNd51PjzqpHerMJpHOwp9
8XOCPL4D+KgBHuqmvtk39d/i7jVjrwB00QFYyhtS3zgDk6ecvrfAev31vdu1d522azijqNvTz/Ru
u2XnP/X0UwGks1dtA31k3iMxXpJ2QHbbV3kxrr5m2UJc+g2fq/Pzzz3ft7VVHfDLxI0nBv/hQUH9
c8suYBR9Z82cFUAanVL9r7362gDMjAOgG/5zYyx9U115qUUfbLddr5wo75Vfp5/f8s5g/NbHTJOP
M16/36UMgH1nUif4GE8aS24Y58FoKzwwGz08v/GmG2NLNXCM9yvQ0LmXt952a9ysfPdddwfYCeCz
WKF/0OaZZ5+Jrf8umQEaug0cDbN92Qb19Cz5IepdmhuyszyP92RZ+WTAr3khkq3JQEYXvfCsfPb5
Z6NP8cvVV18dz6+/4frqe//7ver4448PeWYcG4/3339/4BzGyKStJwWvozU5mn2gXvk7y7flOfkg
6kfm69yFwZmY6GesA8zJoylvTgl+drQCPl4EFM6EI+B7lQQAMbcJAXPybMtJcCB663QAoNUwBqnV
JozmTAYdO5ICJvXRPp96IMhNRmjAswV46Vm6yNbjoss111wTgKkJDtDHkwUzW8H78Y9/3HeuBzoA
ANswMimQArXJDyOztiOnVuhm1YuCAOTnNdyGFUMBHgTOP/rVr34VcurAAw+MBZd77703AEBAG5BO
v8QKevlemkDGW8GkTJoflEM2UhCGKuPxSs4RFovITYYA4yDH4NLUsU3bUqClQEuB0UoBcpRO+dWv
fjUWRo4++ugAP8jYVUo+FvvvtddfCxsBqCE4WwswBgBgdJtvgBd0C78ZwcAJf0/YcELo57xXGLV2
3Vx6+aXV+PXHB2hgnrrpppvCcJQ/YOLiiy6O2yudJ4fOAI0EHIFDL778YqQH4DBEX3j+hb55SXzA
HBCDR9vee+0dtg2glp3zox/9KNrAkOYhCLC4/LLLI70XbsPlreigfyAGw/aRuY9Us2fPDoN/8naT
q7XWKGfLFbsdyAJcAcbssOMOUeabb71ZPVduN8551rcbRnd5a5doI5AQHdAPrQTte+GlF6ot3t4i
aAWcky/6XXXNVXG7KrCOjoBWgBvtBqT98qJfxrw+dcepcdMyozxBCGU/O//ZaocpO8RtxYA29OXh
pz3oByRwGYv+4EDCm2/evHnx+d///d/QHZzpp/+0gy4gjRtIt560dXXzTTcHeGd7K2+kzSZuFpdn
ZNvgBzwM5R9n8pX2AlhtRdZuN+4CgC2GGjfSuQDl6muvDtoAWPRB6vv0EH3p3DWAA4Duztt7LzhB
L4uch806LBYq0boOYMgQgKV/95q+V2VbNyBW2ef9/Lzg66k7T62OOPKIvkVOgMiCVxdEOvRUP7z9
2ivl2K1y66z2oTe9yBhIGxyfA2P0FTpP2W5KeEyqvz4ApgGi6GfbbL1NgIF4z6LCdgU422e/fcIr
E68HAFvASB5hdDKXuQCkxb3rzruCF4CJ6kbno7vpM16qLjZhH6s7D0xt53nJ09DFMhuuv2H13PPP
xSUw6KP++Je+qN7ot9seu1XHHH1M5GvB+qJLLorxedDBB0X+6gV0si0cb+y///7Vwe85uNpk4iZB
G2A/wAy/CraQwyACBC/0+81vfxO39+IFQV3RGABuIaCGE8b7/v5R300337Tad599q+uuvS7OG9UP
5553btxQPWXKlOBjdHO79hZbblEdfPDBcZMy4MqxBJ5ffMnFvXLh8ssDhN19t90DWMavgbmUbcUu
sDn00EMrNCAD0c2iOR7IgCd8AGfaoP34j4eegF+B1+gQZyaOWy/4Wl96B1B1aRJw1Xl/0/eaXu2/
3/4hr3hiyuu8884LT0dyiRPXU08+FVv4pXF2qAt54Bzqh6Z4TlAXMsjW+XVWXyd4BzBOHgoRf0Hp
s/IMXfE5MN5Cgbppp/5W14cefqjaZqttKh7FQPPmmIsMV/I/qxwAiGEIOx1FyBjsQzkMVIdBvGfM
mBGDEEMbtClgV3I/LVK8wUOYAfUoVvWgrdz7TeQG79SpU7seTCqNCe/MM8+Mc0jOOOOMmLwIA+m4
2RM4XIVNUISoiWgk0qPe/nfbb32CTyk+eFj/GwNtGBoF8DiDhTfX4YcfHiucQ0vZxloaClBifvaz
n1XnnHNOTNBHHnlkKA6ME2AfmUPZpxTi8VTel6ZM48NqPsWR/KTUL6mMp/ADKk32lE7phVYuLk3P
rHpp8SzZQg+haJpTVzSPqEPOD0AEdfBpQ0uBpaUAvhLqPO0ZPQQgw4Anv11sQdavSgtrvEZeKkYg
zygeM2hA53KJgwsqxowdE4Yww9J5U5wQMs6DDz1YXXPtNdWMvWdUW2+1dQAu5iLAwpVXXhmgC7sF
eEaPB8LQ0xnnZ3/37PCGd5YbfUW+DGhlP/hwyffqa6rVDlgtQKUH5zwY8xPD1ntlqOtWW29VdTqd
avsdtq8+9KEPhdH96LxHYzvv9773vdiCaY7jYQXQNA9LzwMMUKaN03aeFrfD8sLRz7+44BfVfvvs
V/FwU99rr7s2DGKG774z9u3dDnvHXVE/PCI/7eWxA2zo6fQEkAmI4a1mrhdn3qPzquuvvT48dQA2
AAfbFwGZPJnMweqKt3jg4zVbFQEOZ37rzLhFl+zFj86LY8PIl/EOCHELKs8onoD6AggFNJ19xeyQ
208f8nS18847V3vvvXd11FFHhVMEkA4QCDS9ZcItfZ547DC7rYAf2qgtPMsmbDQh8uB1CSzIAKDj
bcfeAmxpi75CS2nlB/AE1KKJueSee++JBdO99torwBx8mEH/AsBcQNLp6QQ99cMD9z8QHrguyKD7
kP/dgAi04cGIF9RJeUA0/YuuQBM369quywsRDeg/6A00URd0vuGmG8KLFRBEdwNiqr+2o71FV7Y1
8NX203XWXSfo9tQTTwVI9+TTTwZvo7P24z82DUcWQCwwFfAJZMYP6jC37NQzPr7/f98P8NL4sRVX
37mdl3ckYFVdebni/52m7hQglrEFdNRePOQdfrz7nrvDLjDG1FufOqMQmDRlhymBFYwbO6464cQT
Aqy6/IrLw/MLqIYegEbjg21hW6qxcPxxx8fYARwB+pRBBxVfGc/MfyaAbBfnAJR4g159ZTmXsoCE
3huTN99yc9jm6j9+3PgY/8kDA32jCUzgxBNPrKpzq74jv9SPHPOe16LFC3GA32hsLMJQTjjhhADk
brjhhqgzXgGI8oYFrjk/ky587DHHVscefWy1xeZbBDALaNffeFcbBH1l2/2uu+wafMPL9d777g1A
TxzvAfr6w5mVxg6ehs8Yd94ZwxwDHJsAUN18i82rU953SmWhAW8CAZVx5113xlgif403PATQRF8y
SFluYZevstMJzBjguUtv4oiAb71HDzxhqzo+UL8JG0yo9txjz5B9gEu3Tz/04ENxU7r34b24Wml4
bfyjw0gIa2LsVSnoJFtebRlLQG8oACAGyfgY2WRIgI20wKAwaAlVZyFg1HpgQDOmndkn8NzzrBkw
sm2/tgsb/NIACwlcwW+goPxNGgQwA7oNI4sCBBReIKD0nUme4KJ8t2FgChgDlAKeriYMihV5SBa0
YflSgLL485//PJS9973vfXHOKvkrWHygcPjbBE0Bp+gvbTAmgIu2sViZZYDkyt9Q8wYeUubwiVVG
9WtDS4E6BcyTDBjKPcWSPMZz3ebherpl9RtvMmhyoZD3Cz43p9um3s7jy4rS77588Ba+SvCFXPZM
MG/SFZ1xBSzwnBFO/844qwTFihpMX3AGGVqYnwReHnQxxu/q5b/759wfZ2k5q27s9LERhxHK4I5z
7ApIEIZ1sTccXs+bj2cV43TmzJmxNQ99ebvQVfwGLNhud/e9d8ffqbPwXrI9D6Dmdl6GL4868x3a
M+bnP108rG6/M+rHaOURps+uuvKq8AQiM3iwsH+UQ5dUX3olEGDK9lPi5lDAzMTNJgZ4ycuJwS0t
kBAQ9cZrb1QAJwuqzgUEhN14842xTTNpxfsHsAHIsz2VNyXPHh5xth+qM2BvzkNzqm17tg2wgI0C
TKbr+hZ4vO1/wP4BcqE7+887HlI9PT2xTZCBDxTkGALowqOAJmUDCAEynU4BzX7X66WJJmjHq084
6oijqg994EMByvLsA9TwVuLhhD6dbTvh8cQrb8vNt4z3+AOAAdxjO/GqBPr1hYWA2PaTt69OPOHE
GCO8srTblkSXbbjkxBZMwCRgjtx2mYPtyeodcUt89aWXeBdnvBWPOc9skUTvAw48IIBEQArwrw4c
Zn3wFtAOsOx2XXV94/U34pw4O8Ocg08fQyteVMArQCV6szEF8xtPMUDV7nvsHjcgi4f/19u7d2cN
Prz15lsDfNE2YwZ9Tv/I6dU2224TXozsbnnIGxC+6267Voe855DgAaAtL1bpDjzowPDSAzAZh/pD
u/H8EYcfEQCyegGleWICY7bdZtu4NAKwOvOQmXEZBt510QxACb30lUsyANB4Sh3kC9yxM9ClE8bP
O2u8E0DjqaefGnV3sQSvQdtleX/hcd57vOksGqsXGhnLxhnbA6/iSwFt8MBtt9wWz/Df/Ofmh+6A
bwUAlfzVC0hMzgwl6DeYgC3v+hrN1JH9KBhrADnnV87YZ0a13vjSX4VH8RgAa6+99wr+IgN42fFW
hEPADrSHTDBu0dTCBXo5F9ClLsY1mubY99tiBVDfmAMy6088o0xjF8imfsA9W43JOX2K59BCOosZ
Bx90cHjX4uujjzo6xoWFFPpX6vbGChCblyAvTDoQ71vjCvhrQcE4TbvZeZS339bL23iDN7a6Zv3J
WtuMnTcpDY/ZI486Mracy5Mc5Jmszn3zn4aNwLBKugox0Ci7hDMhsiSBkYiZhwIaLkm+yyKuwUhA
AydNaLbrNoP2EqgGoWCAdgsUuMuLKy9BhLEJ4wT/xDfZUOIoc36bYNow8ihgwgBEnH/++dF/f/AH
fxAru/31+8hrwcqpkUmEooF2QHAKOXDdZGby8hGMuW7BmKjHyQk643onjiCPmLRKmZ755DNlimvs
1fPMfOrfmUZe0pFVxvtg6ep5jJTfjBrGEmPDGVGUrAzoYZI+5phjYhJf1vIYvZRnjGT/Zl9mHQb7
piyOxDlisHq375c/BfASpfY73/lOGB/m149+9KOhDBrnyXPLoyZ4m5HASKa4Og7EB69++tOfjnle
nDa0FBgOBRhEDDoLKPRPxr85U8DXdG7GLtlqnmLc5u/hlDci0xSVwI2adgvRkXM8MULRYtNNNg3P
r+16tot5Bl0SdPEbGAGkA8gAMRi5j897vHrrN2/F9kZnwDEsAVWMTfMjr6tJ204KUI7ODuw5dOah
v9dBStnozZMNMAAksnif5Ub/lDjmUsb2amusFkAjjx0efcCO51/s9YIBQJp/yQzvgAFupd14Ytlx
VIx3QAvvqzijrXhj8aR58fnixfjGaxXQbdPNNq16OuVShlIXIAjAZPqe06Mdse1vYaeqrzLsZFr/
7fXDaQNP5VyMVmjLu0cdyFEglJtzeU357fwyNgpgxZlm4U334ktxAQGjn34hLZ4EgmRQNr50Thnw
Qx3oVBmULQBLeL1N2XFK2EAABDo3zybP6QHAGHVQjrqjL/AUHdlhaMlrrX5mo7zxywYTNojbiAGs
gCrlbrb5ZuGJBVjUT5/7o8+FRxG6dwpQyQsOHbOO8qK/AhK1JUCIAtpsveXWvXkV205dS3G9n17V
VrK+gC8++rGPxiUbztPTL/o8vLAKLxrXgjLxJTrjXzSt95c24T+AiUUvdiVHlTof2toJ1EEnAWAy
fY/p0Wbby223BN7IJ3mRZxrAJWmILrYPf/ADH4wxqD/EB3IZJ8YQXnRbL4BaPwKvYlyts3bQ8dTT
To0xzFNPffWh+vJiplvjH/yXdQc6+XviphOjX7TV/868Yx/jT2D3k089Wb35+pvVhhuV7diFP9Sd
52DWH73w6t7T9w4a5ZiI/Ao9jO2NNt6o2nHqjsH76pKBfDGe1lu/8Fr5b0kCW4Fn5ITjCqha+BNY
bPuufIwxAKlt11HPhfwvfzQP4HnPPXpBt7KNmfefftIWY8iCgHFAlkWakh6tbH1/73vf2wvOLqyv
dlrs0Lf4iRx1oUq2x3vtRDdgoDLIobEfHRtnbgOA5WtsAQGd6agf0nHATdDq5rPm6r0gMnA55YT8
ok1lrDiiQNulz6Cf0Vj9lKX+hx9x+CL1S0DVgo0twBzOyCDgufGB9/AaD0ljv55/ljMSvpcMHRsJ
NR5CHTAVQUj4E+oYX6c3g3g+mM1HwLSeDTWYSMRXjt/KMmBDcDTKzPLE8xFHfL+Vr75p1Ktvvc7i
mHh++MMfxgG7nU4n4tfrnfF9Q729S6BAWYI6yCtWiooAEAhO5WZe8XDhPyZGzzNd5lOP47c8xRG3
2Y5uaTK/jJvlq6/6M5Q8a8PAFLDSaCWTmzI6U1Cs6lBu2tCdAniVEu3sOdtQjQUKgu0AgCHKj+88
T6Y5LvClySeVIsoopQvd8TXeNfFTqgTKjPKA9hQT6ayU6ztAvH4zzihbvsmEZjBOxOdRZLVTXiYa
SrCy1NeYH8khx7w6Aki0QcCrxnyTzuSSd9Jpfze6SJ/56teUH3U5LE4zoHk3udSMJ+/MP/PWv0LK
22aa9u93LwWSJ3i4ksm878gT3wyi5R2UT07wVLBCb5xZDSevyBq8/G4LaDJa270i6j7UMshnfG3O
xM8AJjI0dT98lXMjQ9xzc91gtFe+MFi8iDQC/lFP4NemB23aZxTWq8WAFAcQVgedMk4YwPTlYljz
YNtn732q13d9Pbz/zHlpE4gHeAJo8LRbb91i9Bdjcv3x6wfokPnVv6MvSjp6RtK1/l69GLUMUu/p
KIxvsom+I39bC4FNblrVj4Aa2wPVV3rGO2PbLZ/AC38D/95+8+0wxm2NjIsmShuVM278uPDSSwN/
kfqUCOrsXaen052e5b04a623VrXLrrsE3zmjy1botcaUBZWF9UrgB0gNOI2LGEphjPFuIftB2U2w
NOPX6bX5lpuHhyXPOjodL6IERIPuaFP+c04icFaf8W5ki+KJxUKhDf7gIQeA4gWJXsAWAJc8/W27
uLPt0Dp1zvTcyjzpSbbV7rjTjgGOaru4xmfSJ+N2+8ZzzpZ0MyyvNaCKttX7XTr04N00bZdysU8N
UK3nGTxS2gtM68aDmU/yob+VByiVRv/hPfQ1d4aMMaZKP/eF8nPNtdcMz1SgFRBPfMCNgHa8SQ/c
/8Dqld1eiX4QP0JJKy4gFfBKt9RPuTgnHVCoG79Kr95Rl4XVIRcBenH2Yqkn+gE5gz9LOULIhIX1
155NNi3yo5zL162MpF+/Y9iYKWNOvCUNymYr+PBOw8suNVl/vfX7eK5bvp7hBXTRR2gG+Ne/eC9k
VqOPzAU8gF0Y0i1E/5cX3nejA5rlGDCGeFDaro/2eJuMyvfyVxdnq26010bBP7wUyTP1YytpQ7St
kE3eQFv2UzcercuGns7i8sN79UibRbl4zRhWrxyndT7pRoOV/WxxS3Nl12gpyte5GIJBTgmmpDCo
Ib8EST2Ix5AWz4q53xgBiitdMFY9QeO3shiEVm0o1uH6buKxElWYysRpcg0BvLBeBFsa/n6LY2UA
sAdAYBBjVs/qdVYWkOKnP/1pnJklrjIoYxgNcxuUysOQ8k6wwMCERAM45KMMBgEDQbsFA9ltloI4
+Z1tNNmpk3wMxHoQx2QkL3RDR/ETnABqSIu24vqoo3g8sHKLlHZrl7oRHJ1OJyYE9W9D/xTQH1bj
CEc0pMgkQNF/qnf3G+MDaMprkneMsY4XbUl1poiVH1sePHOwsjGe8sDEyZh2fk4KefGcMcJln0zw
3qqRCRzwx9ON14Tx4SwZSr5zLHjpkAfGBlmgTNtcjDNjIIPxJQ9ecy7OIG+MGwq78cUL4aCDDgol
fiSDgMY9D2bf5I1+EGyj5a1UbzN6i2eLBBlKHqBnM4iDhmQomeK3fPQT2viQRd0m+WZezb/JKjRO
WaovySOKA5mZPNFM1/797qVAznHGM6M6FW0yJXWB5Ukd5ZvrbT/Bo+QXPlX2cMbA8qzriso7ZQmj
hWzwQYuh0kN6H+nRkQzw3Qzyy/73TTYpK/s96yGePAYrXx5Zru8st1l2lqs+4vl4pmx1UG9/0wua
ZYqrHPOWb3Hk3yxDPPMg8O+SSy4JfVN52c6Mn/nTt6VJmudzaZpBvIwrn6H2T6aTH9rU6ZX5ZL2a
ZS7t39Hu4v0xUAgjsgBCAwX52MWXwIU0+qwe0NJ/3omf7azHaf4uLg3NR13/jvJLFQAiPH9KEVGO
OgBl1lmzd/s2wKEeoj9L3KjragvrD3tZmH6R+OINgVaDkKoPAAp6FJqgR7OcbEedRvhkoCCfwcqW
njHvP6DjhHXKjoWFbV2kv8ozAABPKKBGpNDH5f/+groCKgB/QqR55/cJ1B+gGe/ELWN5sVCaCNSw
XZMNmnEXoc9iiX7/QBnaoe685qJtpayu6UvVPPffQGGoPBh5yLPUv5As7Jj0WKz342JllTRoBdhb
f0xvnet9rb8Aqexi8fzfFxb+BvwJ3velLe8SnOqLP8gP9Uw+SLtgkTwb6QM8AsQPEJaIfgPk03yl
rkKOlV7SlNrWeK6ZJv4uyaKdRbYEvy7EArQz295Mp50uMxkoDIXWylUmUFoI2jZkUjwv8bQDH/Ou
zWd9fRtPev+p91nt8SI/o5xB5IcE8iIv+8ZeafdoCKvEGYCILwDEAGWMeKvvPqeffnr1h3/4h2Fg
Z4dQSuwxd9uvwxwZeHVFwQTDyB4oMOYZ8Qx/BmwCWvK24nTssceGsW9Vg3JlywTQIT+euTHKVmVn
kPFGYhBTfmyb+NznPte3lQIA8H//93/xAQQYbHPLwaff+MY3wsDlAfSRj3yk6hQjmWEN1NB2+9tt
B/7zP//zMAoMAqCDW6x4BwDcBPG/8pWvBFiaAyW9lrRLm0455ZTqM5/5zCIAoLiAP14G6q88Rodn
gEbGz8yZM+NMRqAIY547tn4ClrhghOH+yU9+MuiPDupvgvvgBz9YfeELX+hq9A/UL++2d/ocr+A3
Ew/eAwS2oX8KGD9AITxJYAN5AGeMdEB6rgz523j79re/HeCdHJ1rY6xZWBDwKpCJsf+v//qvkZf+
kAf+ZjCRRwA7Y9uYM24sUqgHwIr8MMbIEueG/cVf/EWAgPIm25zX8c///M+Rhocn+WCMXXbZZbEg
cO6550a9jBfu9MoZiYEs+Z//+Z8wJNEkV7EdaeA4AjJYe3NBAc38JkP/6q/+ajFZQEaRqwxSchVN
PGOo6ldHQThf0LYif3dVnPshlD4C+Jkf5E/eMo4911cWaAC/bWgp0KQAHiYnbCEyH+JfMgJIsbwD
/qQPOIwez5uXc55f3mWPtPzRgkwwdn3T6cyNDELy2cdijLmA7NE/ZGfqgmQPPY88Iad9xDUv8IDy
ycU2fU4ukHH0Sen0vYU5+iS9x+Km9+qAJ3Jhtkk3eZmT6KhkUMo1+pS+5bWiDeoqrnbSrchLdVUu
PUC5dDt1USZd05ynfeJn28xFylD/XDiRXhniem4epIN+//vfj3agGx3OvIlu5CEeRzPlk410OzI3
bpYt8dW1HuSLJuqBLuogLwC2vpGf+qC5kG1FG3Hl79vCED03d7V4rl5obHHUOMg+rZc/Yn4zrFnh
/YQm3fqJtnSP1aHRP6o0UL36Csx4/TehL+qy+LFYPeuZdmtH/f2y+D1YGQvfD4l2WR9ploAH0MD4
Mfb95m3od4COzX7MMmrfyuJFmYE8CABusLZlguX1nXQo30MOA9U58+snswF5qZ80gz1eHnkOVuaw
3g9Et8EyHISugyUf1vslKXNp2jasypVES1K/4ZaxjNMtf410GVe4W3aUDMKPwc0o5ilDWQNC+XiX
gdHNi4YyA3CiHDijgFENlHNduDPBUnnJdPVvwvIHP/hB5AEwYGhSWuTLi2j27NmheFE4P/zhD4cy
wpD80Y9+FJ4uFDVgjbgOogcAUHQoMKkoqgsFk9JG0FNkGPfqRQES3/krFDrKkvIZ1doF/JOneDwF
pRcoQYAL6ShelDohn2kLWvmo4y9+8Yvw2JGeklino3SeMTC++c1vBniZB2yqI6MZLYF9FNU/+ZM/
iYlK/6C7A1Apb97xbFQ3caVlxFNc1aGb14+y29BLAQYIPuFliYbo2YaBKWDs8ZDxbRwzQNDPLW4O
skVDBo5vnn7GqAtzyA7jkrFRB1nlwxPTxM+tXj7iAPQZQnmLn1rhb4cqkxnGMI84/A/kUw/gvPHp
zDBGDIPu3/7t3wLg+tu//dvwEFSeMcm4/OIXvxjAu3HF+5PR4zMSA5qRs+qHpgxlAa0AqOiNxoxB
nksMTDKUIcuwrAfxLDz893//dzW3GPhAPnRFF2Ai+YPu6Ps3f/M3Qe96n9Xzav4m5/QF+Ue2kVM8
Mw877LCQgeru7Ejyug0tBZoUIAfIA2d3CSsafEgDxHgiQ3IhoVnPVf1vABo5cNFFF4VsQRdjmeww
Z9Kp6DzkKXlPDgHXcgHYgiad0iIDPZK+Q37Tl8jvk08+OWQ1gIpOaBFCGos4vj3/xCc+EbLL/JGX
F+AHctCNlGQW3S37zDfdjA6n7gBAepxnyuiUBT+LfWSRNgDbyD+6kzKl098ulyDHAHZkmTadeuqp
lTOCyUGyU/4Wsb3TfvJYOYBJC75kHt1S+eKSq+KgHz3V4pb0ANGjjz46ytVGMhct0EFeX/7ylwNM
TD1U/eh4vL7dmGjR1zv5ao85Fo15tjtAnw6sftpPx5Y3/VF76YjKnlkWmunXdE66PxrrS4t1aAXM
bENLgVWBAsY1HYmNZ6wILjJwdp/nPDn7254rrvSvLng19KPUq4wZ+owxQ24NlF4ebWgp0FJg9FNg
lQA55oQrAABAAElEQVQAdQOlgrIxa9asylXVFAzPfOqBEkdx4XVC6WBon3baaaHoEIwUM2koJylc
Mz3lzDugF8OTIsXbh6JPaFJeKJP/+Z//GUoQcME72wEpKBQYypgVecoORclKPc8dq52UTV59BDGD
nuJJKaWgUWIEW3elB4wdf/zxUV/KjrrInyGsDACaunqXNPCNRq75Vj7QgQJFkeSNSCEWtFPbc1Jg
hDMmfDJ4TwGjYFIGHTB+0kknRftNKvICfqDjWWedFdsbAYRp7HsOIFEniiLQxBZIRj/FHZAyGpQ2
bW3SJmnU/MZfaJt01Ac+eKdbENf7wTxH0BAQmPEz/2555jN10YcMxCUJ6qM8fJXBOPJ3/Vm+G4nf
6AP4Ty8KdfTM34wZ7ctgbOBroI+xYiuvscUAzIAHjEu0MZ6B8sYsWaIcPC2NMrw3VnhM6Fc8rwyG
lXGgDCA+41LfAJpmlwUF49YCgHGu76Q1xjrFIJS3sUZ+kH8jFQDUHjILnc4+++yQG2jIW4qMRHc8
jJ8Ym+QYIND4qPO0OOj13e9+N2Txxz/+8TC00VpgVANOGYMWg3hIoh9aDYVHySX9/bWvfS2MU4Zz
eiMrG0hMNgIYydyVEdQDH2hP8qu/kzeWtE76RKjTebA8upXnmbzSM2qwPPK9PteOJSlf2jRg+pOh
mf/K+E65rW1Ck/ey3/QlWYxm+Qwdpct2idNfyDTey0c54g+VlvX03eiZZWe8/M765Pv8u/7eu+b7
jLc8v+l/5ANZSq6TEbZlA6zIA7KWrkYmeU8eA73ITv1GntNbAHCAKJcIMK7pZd4B3OgpFmV4y5EZ
CZIBtOiZFl8tdvodhnmRY+QGuQZI1L+ALvJKv6GTuOqn3halzA8AQnlaMCbP6IXys7uFbsZzHMhJ
HvkbaKfv5Q8wIyvxhDwAoOr91a9+tXJbojmElzR9S5v+6Z/+KeYR4AKamHPwot8OjgcQ+ihDGotO
5K5P6oPARfJXW8yDKVv0N97QTrKZN7i50eH59Fu0oNuS/RbM0VmedvBYsENj8y/amPO0y5gBDlrM
RhfjBQ+jsTaQz2R//bKO5cl3bd4tBZYnBYxFNwLbwXXZ5ZeFnas8NiP5QC44C5AOmovSWR9jj5wx
fq+59poA39msAnnJJt53xr7V9lO2D+/1JZ3Ds5z2u6VAS4HRQYFVCgBklFMUbO0lEK1c1gNFxMoh
zw5KkBVYxmfdy4yy4Cpsnjji1AMBKs//+q//itVcW2sJWgojwUzZoTBRNBnkFBJgJAXHIa6Eb26V
pXg6t+vzn/98KFEUF8oYUI7iQiArnwJDUaVwEehpVPimdNkSkkEZVrRNAlaCgQnNoByKKaUpDRJ5
UTKBkPVAAVVPQdy6Ym9FPBVeCiwFWT3RQX7qQukC9AEIKa7ooI+AGBS5BEKBllamO8VAp9ShnT5B
x2UR5pYVcgphPVBC1Vc5FE9tUzYlOg02z3hp2cpVD5RoeVLmfbQHcERJllfT8KIIp+KM9ngMf1LO
Kavyr3tA6TfKuLwpvdn3+kI/6eN6GfqbQUHp9t6KeRqO9XrjXTyl/vKWTp+rkw961/PNtNIxhPCl
wODBP9kmeamb9HgYXUdDwKv10PzbO3QkD9DU2NRWt3uSM2iFR/Tv7ALSGZ/GtD4QyAO/PTd+/G07
FPrhGcG3NLyQ8YM+yXL0CaWOUUd2WLio05bypt/xMtmGZ/CAduTYjkJGyD9opU1CXbkkxzzPZ9rC
EE86NqtvfJIfjHH0Iz+MUzQSyGQLDTyi0chZjxYYjLvB6KJsY4QXOEOWzOJN0ymySf0FgK1nDFWG
6IoM5K6xSKaiGwNcu8lS49FYRTdtJSeSpt3qKC9yCE/nXEF+SW8s+27KA2WJT56qB/lhzPsb78lH
/ygbzbK/u5WPr8kU+ZBJ+gYYY95BY+MmaZ7p8XaCGMqShzYqT13I4JUdtMO8rZ76hYxXv5Sv2oTP
yI2kIzqbL41//Kdt3qOFsYAe2t6kh7/NEegoL2V6Zl5D15zLBqIJniE70NIcqBy0VLZ8jDH1VSc8
pm05jsge871+IyuzTHVIOWRuS3k3UD2W1TtlA/oYtHjyj//4j8Nrjq7EuzqNXXoG/qS/GOdkhnkM
Lc8555zQXSwQ0xPNwWhJf6GzoRc9k75HdyGXLW6ghf4zRnxykZd+RP7Tg8hx6dURwEX+C+hq4UG9
tUE55gt5euf7zDPPDB1FHHXGG+gLAJtbdBLx9JM6KNM8xWNOXXJuVj49FK987GMfCw86tMF/gAXt
p7dZfKHHka25AO2ZOQc/8xBEOzzgY/5SHj6i++KZ5JPsW3xOZlpcIb/R0xEw+gXt0Vh7tANAyXOS
HEB/z8l6/WcBSd+SR4BN9XdEjTYCD4G3aEz/VhfgZTedKOvVfrcUGA0UMKbm3D+nuvGGG0OmWiAQ
jDPj3rg2b4TNML6cKVhfNyrqi/TGKfvQvJnp5eEG04teuqh6acFLoT8MpDuI34aWAi0FRjcFVhkA
UDcwiATKCeFFsa0HinIe1k/ZoHxwea4HCgrlN/Oqv/MbgMiwpKgwwqwyU8wEShCliiAWKCpWmhkB
lH+giXIFCjEPIYpJpheHAeNvig0FVZ3T6KdQK0NIpSv+WPiPPE0ElCFKE2W8v5D55Ht5NwMltKnA
iWMS0XYGsjIYHoAK8TNouziCvE044qVxx2BQB22lAPOURHPvtV0/+CyLACyg0AP31F1AH1d384Zk
BKg7Y5jiSCkHHAD1eH8lAMiQo2xSSnlbpbJtwmUo8WICNFBUBf1OEbcthlJKSQc4U9wpsBRztKFE
f+lLXwplXh0p98BV9FBP9FAG/kkPMu2gqItPobairj9cMvHXf/3Xiyi74qI944N3AQUd7Y0P/KUv
8CGFngJPeRC8V2eGChoqw9jiKSEYSwwCdNFXDKhPfepTkU/ydEQcxf/gC31rKzD64ouf/OQnca4m
oElAI33AWMMrdcWpPq7QiBHYHFMMLHzBswEAYOzoWwAM+UHW4AEeEXW66kN9R475jY/JAGU2yxhp
XaC+GdS3/rff6F6XJ/XfaEEOky9kJu8XYzbHNhk7txjD+FLw29iWrk6/LL/+LQ2jkXGvXsaFMVEv
X3wgrn5bUYHRjRfIEnIDSExu2A7IwCUvgA1ogMcY7Ix7PNkMOXfZfscIx9NoTsZIj6YMg1nFmxTw
jac8Z1CjM68d4558A4TOLN7ttt8xPvCuvMgJnpPGDT6uB+/JIzfaAxxyvvRNpgIdyDH51kFbskob
yR3yVH0BG4BMwKV5hFdUevE3+6xeh+XxW3naj9cAKGhlzJLbjgLRJ2gJuNCX+k1fkh28qQBV+tFc
So/QT+Ifc8wx4TVsXq+3yW9tJ5fRPxcD8C0e8NFHQj1dtl08780LPI3RFz31gzrjHfMfz30yzVwj
nv4XTzDWyDzzkvkKT5krjDV8BJBx/Id2rKhA9gG50MN4BxqRjegBSDXP4Xu0Uy/bTPGx3+pNV9Fv
6g/gM87RSr7p9YYW+ppeYc4nhx3JII4jHZQNcDI+jUPjQR8A7PQ/I1z56J/zpzT0SbzzZ3/2ZzGf
ys/YQ2fjUd7SmXPUE309lzfdhM6oHWQDzzn6lPL0l7K1RZn4yzj0no6hHHom3YQ8NQ8Z78oytsTB
Eyk/8YM2yw/N0Ifeg77yQj91qQd1xNN2jQA6tQt9gH/yEvQRfkOfBCLVh0yw2GHOxWt4TPvNqdL/
6Z/+aZ8uTWYbW/qIDmM8khV4oA0tBUYzBYy/GfvOqHaaulPB9srFA+W/qphdxrKPMWb8u8l2sTs6
iolHJu2xZ+8idD09mhjDLm1wi7E82tBSoKXAqk2BNQmMVS0Qkt3axbigcFN+KGSUlQTXkgbSSU+J
6RYoNpQpigcFSV71QAhTUgB58gIedAveUepSoRJH2lSyKFU+ni1JIMTlrX7LMzC+5xbDWv0ZcwxS
yl0G9VaHXGFC62yL5+jrbxMNwClXZ9U9f2deS/vNAGA4A7IoyQLQhKGor7Kv9RllknJKwfZePIGy
6tk//MM/BA9ZXWcMANMYG9qvDHRhyFGsrWAzcgFHadApiwFFeU1vCn0OKKRkMwB4mMrb+UGABsqs
reEMbAaxQEH3t7LxNKONsp5bdiJS+QeN1QmwaUu6/mKwaKc8GI+MOrRRX6vojD5GOwOHoe0SDHTT
VsaecaQ9lGv9pVzKPoWbMQMIFM+7VSHgUecM8Vpg1Os3hh8PYPQFFqEJL76BjAxx81OnC35n3Oj/
DOgJJGC4oKO86zcPZzzvks6MMosXy3vsZ9kr4xv98BvZA7Ag74wnYyRD0iSBO2nIWnEHC/I0zuUv
DRCgW5+idcqNwfJcFu/VB8jD65ABbw4CuOQcZNxpJ1lsnIpjrJMfdQCOHAM4kSfAhFzkAPQxuhnb
s4s3K3lGRv3RH/1RACjyAowy3skbCz/KMzbQH2iB7sYBw1298C7Z7kKnesDbyifr8D0AgxyWD3Ad
AKYMbSEDARD6Dujr6A3vgFOAG7xARpGFZBQ6OReT7F7RQfvJYR6n5DI66CfyEMgqoBnakMVkrn7C
c+imbWiMt8ST3jt5AlocHWBse4f3yG+LUeSz3wBQXlz6WN9ZpDKviN8MnunDr3/96yH/0dNc7bk5
QVryHE/QQ2YWMFY7eEPzEgTckv/pOWY+MV7UH3/hTYsawJo6/zXrsTz+1g94CR3QEu3Qy9/opx3m
euMcX/mIRxfUH2Q8HiWPjQdgN91GHvLGl/ISzPn+7nQ6kTcgy1gRzOt0D3Oh+NIbb3RC5cnTGDF2
pSHDyHx9DrQy1oR6f+finT4BgpmXyCj6bM4f2ktvAUhqmzHoW/nyAvLpI0G/abfysy7iCHhKOYJn
+cm/k3a+Bf0vkJfqgob1gPZoDnCmP5BN+oIMyTJ9mw/xMlmHJvKhQ9FjyAv1lUbI/gQaoqf0aExP
Uh/jzvjxjS76rw0tBUYrBfDvhA0mVBtNKE4L5b9mAOrFOC1Anv/qwd/SbzC+XLKzwYZd04vvMpAc
0/X07e+WAi0FVi0KrJIAYCoT9a7yjNKRyhslwqebQtAtfeZF6UqjnEJOgWoGeeaHEkhB6xa6lZNK
pvjd3nfLZ0U/MzlQlK0soyEPBavcqRRnfZIG/rayawVaqLeLAtd8Fg+W4T/ozzOE94g6MxqVSyHM
lWfF+btTFHl9ZmVdmyic6gv0YWjx0HCwNJCPkaPNFPp/+Zd/CWWVAcub0XYgRq3flF4KPboxlCnk
8qbcUsTFobQy1mwvZRAA6XjBUHQZENJSgCm5fidoRJlnKPqoZ5OftZXXH1DRO6CVMy8ZZfKaWQw7
v51byWhkfPhb+drHawXNeCdQpOcWA1s6AKh+p+zzpgCIMRYZT4xH9GvWZRl26QrNyphkYDknk8HH
KOKlmRd14AkgBY/SNEyWtIIMJnyXwd8M7RxTDDSeDXV+zbjvpm+8byzid/3CUDSWAJ/eCcZBXY56
ZowOZWEB6G2O0MfGgX4YCXxMBuA3RjmATAByGGdAAGAYIxeo54gL4A4wxng0VjOgHeDNggCeBfBJ
b6wDdJxvSJYZ0/Iht9GBjJIPGgO1Ut6QX+SZfNTR3/K3iKJsHmHOGEs5b+4kI4FdQDqeO4AK8wiw
JGUMMM+40i4yBhjFQxY46XxMCxXGAlkkjj4zNwNs9PU//uM/DnssJq2G8238A1OBlbkgkryYfMmb
SRs8B+riNfMDOqbHnf4DEuprc61FGnJbn+FHaYC06AhQRH9bVbVd0I9415ZRMr0epNfX8tRXQMO/
+7u/i35WJ8CdfgYuJuhrpwQPL+NNX5nHAGPGC71Knsoxh2mHOdIHQJiAWL0Oy/s3uYneKS/wifGv
nuqf9fJePEEcvK0N5mDjCUjblBuAJfTNoCz5JI/nc2WJ69t7AX09AwB6pkzlox3wDy2Vh//NufUg
XuoCntNX5Oe5MnwE7TNm1Uf+4vgI4vKAtMCIVwGhypxb5nXyhHctGghokPWOB4P8I++sS5MWknqm
XcaqfPWBumbdMnt5qBfdy5yIx4wP+g/AUMi2+kYvH/XNIF80FtBgSdqRebTfLQVGIgXitt7e9Ydh
VW9p0w+r0DZRS4GWAiOOAqvUFuD+qEtJoABQPCh1gr+HoxSkUS4tQIsR003ZqdcllZX6s9H8m4JG
KWOMUu4pokPxuOhGB3mtiADAAWYxmii6wCqAoJXjNFAYVQxbijejkpLvHWOJVwSjGVDHeKO8prLL
646yCujDY7xEgUEMKwqsPJUlH/HOOOOMKBcvMRIZuFas1U29/C2k4cGQU4Y6UZYZHPLltcHTkLHI
8K4rwNJTfBlqDEll8QrgjZNGojiMaMCCFXbGOqMdmAdYRDMAg3J52KgrxZrHDs8chjslm1HKSKWg
4wvG74rqV21YEQEQAsjgBaidDBnGkv5kgKcnRtOYGWrd6rIIz+VWsRwzjEP9OVBgRJJvDLvhApED
5T8S3qGTNpI9eAz/AVSA7QPxXNKxvzbke8YvEEpQVgKw/aVbUc/JBGOSvCIn1BHQYmspeYRf8Ad6
kENkEFkEzEgAEH8AbXglWxgA8tv6SH4LeIYXGBmBp/EckIgckz8ZxROV95f8yRvA4Gc/+9lIRzb4
W/+Ql+Qdw53XkvqjJ5DO4f+AQPUG+iXwrXx1JWu0QZ/oU+VoM6868gqAQQ4LZCRPIjJK3sriYWRx
pdviXCRaTv+oK+BlZllUUQ+LBfqpzpfalIsF5Db66hfzibPkHCOhX3kEkvvOotR+8lV/6ivywZwi
rTK0X7/on5zLACW89YC4yc/ZbHyiX771rW+FvNbf6qR/yC9zivlrdgFb9ROPS/MCHtA+CxEWf8yT
ZCGQTDn63W88SlbmPFNvf9ZheX4rz9xkTtMm/MoTEZ+hvzGNpuKhMV7Ce2iedCbvbaO1kIfn5JMB
jVJeeAaU608H7NZ2aevp/cYDeJ5cU0+LGuRaU+bXywbam6ObZTTr0nyPh7QJ/5EHPP/pCYI+zNBM
l8+H+63u5JE2CgPlT47hQ2OBrDKeyOY63bIezXz8Xaexv5txMm373VKgpUBLgZYCLQXejRR4VwCA
OpZCkCu1/qbYWvn0rKkwed9foDiJLx1llwFDKe4WKB0UHmX35wXYLd1If6Y9FGQGHzoCrRgUVm37
CwAw6cRZGcoY5ZNBxLPFajdPGFvHGJwUbe8ZM5RhijVPDCv1FH+GDmNIGn3PawJIloHhwODEE4Iz
IinzjBBbnymy8qfUMqbVg8HlOePBO4YbmjKU8aUyBN4YjGp041FBERZXGvRnAPB+SsMvEi38h8LM
E0d9tAmgKX4zAPl4l/DcY4jgawY3UIsxohwGkn5TFjCSl0sa7urGO0T7pG96LjTLG6l/D8SX6M3Q
dpvkl7/85TAW3aSYW8idJcmYHE7AY/o1DSPeNvgA3fWrejHUbIkC2uDLZmAk8ZjS5zMLANE827QZ
f7T+nbIH76Eb0McWMf3gXbcAlDa2ARLk90BBnj4CkAB4YmEAb6/MoG14wVyT/a+PzT+AH/XznDxJ
UIBsxg+CNpFfxjh5bRyTBwn+ZdvkQebY1g4E1H6yz+KBcY9++FIwJsgB4FvKAnKNPFFPiw5AQN/4
GY/y0AMmkWlApkyX+ckL6GHelDfZDPgijyxAqLfzU3k6ZtBPFnUyiAeAXBkAoD5CH7IdDZo8aSyn
7AZu+C1oFxAP/QT9qS+BU8A+bUQHcjZltH6Rn63uwDlzU/Ku9PKSHkiYsk199AlQzKKRQG6gV8bx
PbfMkeIJ+MYcAtjL/ieH9KvL0vAJUNf8pX5nlAWulTXPq6/6m7+T1/EcXnLeHD7UFoCXOc2ioHdJ
O7ICfdHRWPAObXNul38G5aAnELrb+4w3lG95kf/6WV3oDQD/7M9ueYin/GbZ8hooGNN0H+CyhSyL
WOYMi7iAfX2fc9FA+SzpO7xuntNGAf+gdX/B+Eh5rZ05VvqL3z5vKdBSoKVAS4GWAi0FhkaBNQdT
FoaWzciOpY2UBwpFelVRbinAlBDK91ADI5JiSImxPQdIAuihjDUDRYqhwji1kkyJWVZhZfabdlDM
fIBVjHBAky2S3ZQ0K822tiaQtSzpsCT0ZAwB/Bg/jFDbmwArFGB1AlIyDij9efYfOjO8gGJ+A9IY
DqnEKp+xJV/GuDj4CeCLFvgieUM8PCgPwXtGkyAdg025zpBCU7TlhcPjRf4MAsZx8rB09fz9XQ+M
fzyO14FTCUTW4/iNnyn/3jOejQnl8vRjoKNN9pmyE5jKfNLo9bd2AER9j/RQbxdDC219Z38166/f
XYACgGD06iNAr77hFaN/BwtJx3o8vMTLBkCCJ3hl4RHgDF4yfvSJc9PIH15a9XHGiAIG8PRUjzqo
Ui9nVfitb9AlF12MWcasMdtfu4FZAHqgQBqUTVokvxonCeQC/owHYBRQqx669WP9/fL6XedZssPY
rfOCv/GpgJdTTmkfOQYMwufayOusWyAnAW9kFdmBxhZ4AIb18qVVhwQE/e19ygg8qyzyQEggT53I
OiBHMwAvgeniyFufAikANtrjb+X5nQFP2NIIoNdO7SfLVlZQB31CLg4U6jxEduS8kGm0K3lRnvhR
GiCVfrTQghb0C7TyTrwM6tBNJulTgJ/89DGa1ukpvb6xpViQB/7XHvkrB/jMC5D8szAxt+g6gDKe
duZ5aep1iYxW0D/aYq50CYZz9MxlAEoyAM+T23iUl6I2aqs02oWO3uFZfI/W3WioKdkX4gHhpR1O
SJriWzRWtv4l5/VvNzriDeVK0wTx+6uD+hqP+osnO099i5FoYN4wJo3zwfi2v/wHe64deC3piX/N
eWhfl2GZj2fa6Zu8185utMj47XdLgZYCLQVaCrQUaCkwNAqskgBgXUmo/6b8MaCBP7Y6AIJmlpXP
OgBISaKQ+AhN5YRXAUXPCimjHbDlHCMKYD1YteclBlBimAxFqVJ2vb71/PyuK0mU94Hi5jvf+buZ
X/6t3G6hv+fioiPFmTcJI8BZRp1Opw84y/woswATnnW2rA6FDpl2WX+jH68TYBdjQN0BgDxeKKW8
SBieAB2GUQYr5gAfgSHk7MfmynWdVvLCU5TXOu3FqcfL/H17zmh1c6Yz99RL/ayY41fbmYDNebFB
PW1/vynXPJ/wsHokGNAtPmBEfwI8tI1XFR4bSlB3tM221ds8lPQrK446M/YEdEYrbdbfDDCgUhMk
0f+2Xf793/99xMXfPEvq/NKtPWgj7wRF6nFsO7OdGOALeAFUMezwD08bIC4vD0DXV77ylTC2bfFj
FEmDN5zXpT3GGENuVQ3oiFfJH7/JYVtaeUs5MxPN6oHcAZyiSzeQJOMmz2be4hovZII8mgCgfs85
Qt+oC/qv7NDfOFRXCwJ4XAAE+HQL8iCL8BfeNB6Mj6RRtzT1Z2jhkyHT4dXcamgeaPaV+MpugrTK
B0wI+tlN45lnPFz4T5YpX+NWnHxWjzdafqt7nUbZZvIZPfAnuUNWdOO9bm33THoyxW8Ak+Mc8EK3
+GilDnjBRx189B/QyJZlY0R9ct7Ieq5MOgNT1Y33H2CSvDRO8bEFP55/5lLj2nytzr7RU1r0oCOY
h4GdgPUc79qFVuYOZ8GS6c4YFme4AT3xbOqW5gNgKmBbqNNUf6C3sp3JyDN3sKC+6m8sWbi2oKmd
FpssXKq7OtTbOFCe6lOv00Bx8x2aorfxDfwDrgIxyXB0r/Of34BqH8GihM9Q65dltt8tBVoKtBRo
KdBSoKXA4hQYeIl68fij4kkdHKsbOVbTbWNx2QFvBACeCxIYO7auCLZNAVx43QiMFgCXLS0UJgAS
hdB7cRmfma+VeEok8M/2E1treHTxEKTQUEBTgaE85e8oqPxDiVdf8YSmgpUrxPIC0FDmBEYahQqA
Q7mSPvNQRrMcabzP/Os08i6D55lW/PxNAUUDK/08CSjVjGSru+iKVowF9UuQFB0Y4ankKdtvRox8
83mWvby+AbW8A9R3bvFaANDqX4o3pVjd9XHWRz3VUV8L2s4ITdp1q6e0+en2vr9n+IjXHXDBgfcA
anwGyKPwM9ps1QU4qe9gwThIBVqeyS/d0jFmKNgZ8GLSIJ+tat9oyOhi+NjmxvMSrfU148R4bgYG
s9t4v/nNb8a44+lp26KxOVBAT4sOvNF4OTE+yRNjl5ewrelAY+eAGVf4TOClYqsWmcVQYhjmti0e
EfgDqGLc2yIuX+0ZTcFYao4nf6e8qcsq7TJO0Ej7U8a4DMFvACo+xvfGiwUaBnp9u6u+qJeX5chb
/1ogYKjyHALCmyOABuSCoD48nvWdoF8ZsmQf8BX9R+LYIQ+ANILv3B4cDxr/2CqJzgJeTJotTbvq
ZZJH6GbcDJYn+as/0V1dLKgNZbwNlm+jyaPiT/2QQJv+RBPzdJ2fB2sIfifnpPWhN2Rf95eWXiNd
loO2nvnkM/xEjhknPvoq3/WX7/J4rm5kJVnrG8CpPuqqTnQTstfHvKeOPt6RKeYEeRjPxr55wKKg
uOiVfEUuuxjMIs3Sjnl5d8oCKh1KnQGPFpC/8IUvhH6atFdOLi4DXgGAQ5X38pCWXDOetNVcpO/x
knw8T30wy8RzQrYbrcRBC8F7H/GF/vpcfKAxHYy8FN8uDJ6k6lIP6kO+kt3AQQCuRZ/+8q6n9Xuo
8Zrp2r9bCrQUaCnQUqClwLuBAqvcLcAUE8AOo4ESYPsWY15g3AFYGNNWhhnPjH5prKJSvihIvGkA
fwJg4FvlsGyeUVZ5GfyMcmUA3QAzjEyKDFCMIke58QH88UpJIIGCnPkqk3JD4fr/2bsXeNuqqn7g
i8slNdPMxEchHVNRErPyjY+uiqaiRaZmBYiCphFaWWIPCVOzNEEDzRSCRKUSITBLFOkqKvjAV4ry
0guIirwFLeT139/5b9ymi7WfZ+9z9j5nzM9nn73PWnPNOeZvjjlec6y1wpkRSGP0MH4UbXOUojCA
1DUufXsoujHI6mC02s11LZr1o55vwcJ2UYehqegz6Ip6jDUOdTiMcIk6DEHBik297EkBQBlIjGW4
wQkODDrH3G6jrttM7MQr6gR9xhdztJwd9KB72DcnwI63nXW4uQ0GPwigcPZlA6K/Lq4Jwxze6OWE
9ivwhps5GdUQVY9BrB+3i0dQWqCSoS8rkEOjnkCq/sMw70cHXsTz5gvOEbDoqq+OcSp4DJ/H/131
18IxjiAsOVv4kUzADwK8nDoOYrvAXHDIsxzxgg0FQWPO46ACX3On/SOOOKIEoPVvjVs/8CYr3GLs
eBR8KuPJPJIx6BRUF9zisHHeBKcEhWW84Ll5L2RPyBW0kqX+j/UPK7KDPFQEK2oZhi/Nm0C+NSFg
68URZKIAIDnpGNlEvgqaqx9ylm6AO3lsTsi56EsdAUBywJpTR+Yl2tAJb/0I0KNR0Z4MaHR6oQL5
MYwfyoUr+CfWNz5S4BP0d5GB/pAvgoHko//hNWnRpqA7nKwdfDAoW9Xc6Q+fuy7mityOzKguWlyn
jsBWyL+ueot4LPD3bT7wHv6lO8zxsBLX4WP1BWFlOwuQRUCnbkMdNgWdB0vBGPOoHRtndKf/yS9z
KrgkaEZGWoerVTb3HokgQ46NQ5dav+inE/FSYIV2v9ljCtmLt+jhkCGxiWBMxs+elB3oNlq423QJ
2RLz0zVu/fjAucbaNSF32IrWhTVy/PHHl/5sXuBlco8O95IbL13xkhLBNGOoS9iPsX7jnH7Md9iU
xmcO6TB02UiysRGyEA3GR+fADHbWonYc8/GbbCZLImvYNUGD3+rEuAUc6Sl8Ypx0GhvR+GCuGI87
LtRBgyCnACye1Va0WY8rfvs2bvMZGLsmSyKQCCQCiUAikAj8HwKLlSryf3Tf4hfDRjBPcMmDjMPB
lEXFUGNE+AjKyZRROHaCPgxF2XoMEB+GFoOMEcFg8TuMCcaJW/Q4hjJ3OOKcDUYQh9N5AS8BAplC
jENGOoPUM7oEcxSGqYADg9JzWBg1/ke73wr63vSmNxWnUoYiI0m7AhaMN9mHDHC3Kro91G/GlCwh
hhPDh1Hn7bWCja7Vn3YZ6WHoof+oo44qDi7Hl3GrHfX0ozDU1EG3dhjKsvpkLMFLUIIRCBe/Izhh
59YtswKsMGJg6ptxhz4f88ZA5ND7wK9tvBYipvQHXvqBNZr1b47RzBFi7EZBB57gqDJY8YtbaPbf
f/9Cc9SLb84B/PGBh7ob1yjFnAuyyhz1Vl5ZZYJ8cEOf5/bAzxybU4b/MIwEsNRTGP3mWR/4qF3w
d/ADR4kjYl7XcuFQWDfWJ55XBPPwhtuvBD3aBb8Gf3AqBd7gNayYX/U4c3jJurJGOVX6wpPmfKmX
BVLzDL4U2BeEsXbMIcfL3FvLgk2xbswrvpvXQp5yXCP7FpaK4Bn+FACFqUzcE044oWQ6Oi8QxxmG
C2dVkA9fk+PG6wURMInAaDj58CCDvW1WgAJmAoXWkDUlkGdeBEDISGsDlubANeaITBYsRLdsYbLA
nNjgwD+CTZFFoy2fev7QPy8FD8ENTvTlll5AU/DI8XYhxyJQIJDDuYdf6MF2/VH+x/9kO5mLj9Eh
2B7rqW5DMMm8whlP4HW4uo6MdJ15bhdrmd4i21/4wheOtDbbbcz7//QU2e7bPNls9N21YdE1FnLd
fCr4lx1BLrXlPbzxM76Hp7VH7+MD80APCiAJ6FiH3kpsTckCFETzOAtrJdZ5Fy2zOIYW9hyZ7jd7
Ay/hP7xknHjH+sXb5Ak5am2rQ+ein5xgN2krNjbJbnqSjIJPvK3XXPioB1PF+sHreNI5hcynx51D
B7nFVsXneJoMZGO4TltH9zafyUu2AJrNtQxw9LHV0G9NCtBqSyG3yCw8YW0JxpkD82atx3pz3iYy
WuDErtB+BEMF4chhc+45xMZuPhUy+eSTTy5yxHhgaeMSLf5nByrwg5f2Q3YYo37wnXHKdIS9jVk8
rG06wZ04gq70n00ZbRgHGxSfKdokw8gLdKLdeYHS8AH8honxKyvNj6XT/JMIJAKJQCKQCMwRAmvm
GYAMVUYAI4hDHcYGo0FhkDAOGFoCbgw9hh/nzzWMK7eOMTgEAXwYRjJH3LbAAIuAgN/eBsqpFIxj
YDCmGEccFc8J5Mz7dk04+84zloM2NDjng379oS3OMxoZMZw1RovrPSDd/wxv59FpJ1hQTjCS8cM4
jMBPGH2RbahP4zX2yMjTNgOMIQUjBpv6gpdutVP0pX/tq8P4dT16IqgIBzirC+elniONtk29TEGG
nfa1y1BjBBqzol34oSvaLidm9Ef/jHxzzcgXuDV+zwVqvznSOI2PcS5oybhlnOILAeW6mKvNvUCv
oIH28V6Msa7X77cAhMwi2WcMdcFTPIbfOC7O4XEGMh6pHbYuoxY/G485D6NZQDwe7l7TYd4Y/PjF
vAk4h6NQ11tLv/FpBOQ4FOZagIJzzNkJ2dEes7qcS/wjYNQViGhfgw/gKcDs4e7WvHVsnZgnPOaD
pnZBD7mB58w/How15lq0Wl/96G23t5r/ox8WeDzWhrVn/cPDMbyI7zmUwdewcTycazJDgB1+ZBSH
kmxRHxaCf7Amh8nImCOyTTttGUlOw1X71gt5CmOBcAEQ56wNeJMF5kK2pfZsKtERjus3HM3VxLnd
t7EIFqBTQIScxcM2pOicdhFAMGZyB1bGpY3QTe36o/wPO1hx7AVCBIxgZg3G/GjHOdnkZJXAgwAr
XWMTyiaM68gner4uaCPLZWyRn3jEml6tEry7nP672sCfdAJ5AisBIbIbvqFzYtzmOdpwzMec0v8C
eIJT9JW1YmPTPFiD6vnGIzY69UNu4QF2ikC6TDSySbCcLsIvAuVbeoFlgSNrhP4JWpaDwzjXGq81
LyjF5hAwRjdsrM34RjPZSVfHs/Bgiidl8qpnI9S4jB/fugZfWUtsHxtIZAecBcSMmx5X6FzYoQd2
/ldHMBK2sJf9LRCmHW3aUCLHbFDAUTCQvsfXcDTHNotsbFiX1oONIfXVVdBrjQv8CZypR34aD7kq
0KZtOkiwXFY6WWZNWW+ud0zbXqLChnPnjHVI1grcG4uNTjYRO4UMEUB0HX5yXsGXngFNntgwhvdS
z75wN425wEeCqdYuOQtLdeFiDtlkPuQ8+0p/MGa3KcYIG4+AIA/ob1gImkYWIhvdJj8+hYX1kyUR
SAQSgUQgEVjPCNzS21xQNBi1HEJGAuOqLgwnxiDjwm9GiFsKGC6MK4EnBiKngQHBCGY4MQb97zpG
nzqKbwa4QArDSBuMKYaFthlpDCr/6087jC636rVLGKGMRMY0Q7IujnO+1NMWZ4kxx8g0Zn0xHNHo
IyihuC4KQ0tdtKEFzehpF3VgoA/tMMra7TDEONgKmtDmGS6MaIarj+Pa0R/80KvAhDEnk6AuxqWg
33Xxf11nmr+1zznx4QAz7tHJQIVnXdRlNKOZc8OoZLAefvjhZfdagMA1xs1ZsKOOVxiaeI4hHBjC
06dfgEDwgbEq289t5vgM3oJMDGmBx2graMTrNb9rP4r+zaVArsCk4AvjnLFej9OYONeyOvQnOIu/
g9/1Gf3Wv6Mf/QevxPlZz2H0vdxvPMehkgGCZmuAo9SPfuMTgOCkHHjggcUpGpUGbVoTnG99WOv6
gzOe6Nen49YQWjlFZJzrySnfPotQjJGTRlYEP6Hb+IzBGlSHfMGj7TrGq05cg4cF+MyfTBIfBVZk
DXnqd/Cxc9aDucazXe3HurB2yAfyTaYNp1jRrjpoJHeDJv0IZNZ9lQum/Kemu1730U3IGP+3z+M9
gR6yiaNOppAHMAmZ7jqOfwQ+yA4BgMAdZvVH/XZxXnAjSuAMO/MqcCBwSibRkYIO5gR/k8Wce89X
gz09pG+BJJlYrnOew0+22uiiM/wWgJApuqUX3HjpS19adF3QsNLfMQ/Gbh7ac4Ge+lhg1KZTsE1x
PtqCE/vEfMJL9pdgnjkUoCFT4GFD0FwqZIb5xsfq0WdkvQAZWeYtueSR4Jd20a8+zOlIOl4Q1lp1
3Byqbz2bG+tWwN45QZoIbFkj9Ge/8RXipvwHjXS55/NZk3QZfvSh69Dt28fY6W7rFr+RzbFBiV9l
Pqpj08AYyQUyWPs+xkd2mSdYwg4OUWCMZ21w+MCB/IOZol90Oad9tHrJlHYjCGdjxDjMuwC6uQv7
wvziAcE5cxQl1pKxGSdM8Ju5Z7fiEZvI+ILs0q+1qX00CgyyR6y9CMK7VqASfubZuGEhuIkf2aRw
smZDjqKHPWjTLHjZ//jUJrqgIz5FB5zZp2Qq+9xmBdlEjqMfT7Kz/bb5Cn/FWOCnb3MHjxpjdMJW
nXrNlYvzTyKQCCQCiUAisA4RWDPPAGRUMGL6GZqMBoaAwhhgIIUxxzBxLBxqdRgw6ofx4FhdHGeY
qKdfRhYafNrXOMa4ZNR1FX0rjMeu4nzUCSOfkaUfbTMijU/7aOoqzkcbglZdOEUdRli/dmpa9KN/
hjInjGHIkFOHUdbGIYzxrr61Ff37PetifIxLwTbGrGBwZDi0+2bECzQwvO1YM0I5qAxe18FdEJij
ZNxuC2IQ46cITDBeGfqyJDlhXbwAFwa7W2IY4pwRmDjOCcBj+Gipt4MOd0VQT5uwV1zvGJrhj09k
MzDAGdqyIdyKbjeccc8otoPumHnnRPhwCqJwYBjX6OBYGlP0p4423K4UTq+6MGKMz3uBLywDz5pe
4zFXPngXJnjl2GOPLWtVtoZg77hFX7Aet8S6wmOLWNAvYNNv/TtvPvBNV522fFC/luNkj2LdkYn4
3zV1GVVGuk5wioPrmnBeYa9thf7wO+Rvu6+632n9tvasQcU6tzbrglcjEIpmm1v4GBZoJ1ee8Yxn
lOdQCh7Y1CBnOPb427UC3IJsZI1nUpKTsFAii9v8cKb9H4EP58ko7ZIBCjlAPpGH1grHXTarftEv
W0eWmc0x/aNfVr6AhsAjfnEd2WvTirwm49xmSqa5jixHgwwi/RmfflZiPsogqz940gc9gYGABFxh
g1dCjsLJ3Cjku/8FQuMYLGCkBK5+kx2CI5t6mfXm3xwLyNEvgiLWD8wFd30r6sg+U2TfCiCZB9lU
2rbxJOBDnwn0WUsCUPqHpb7oeXpOO/HsOIGa0BXmyFzSBegyx+YPD9E1KxV8gRtewPP6hglsQoca
r7XhQ4cLVtKNxhY6F++TLQJ1MPAxr7Gxye5zPniMTIeTzGEl5Jfz5FEEVX3rvy7Ow0f71qg5UM+c
xeYyu0/f5sA5PKBt68TGt7Wi1P0aPxnl2jjumI0N/Rm7Odemj2PqCxAaN3yM0xziKdfajIxrjdlv
8pF80EbI9+gPTei0hvEJHnDO/8apffLMWH2sD+ODrfHSu/pV4CRgqB+l7kMd9dGBv2v7JObIdYuq
O8uA808ikAgkAolAIjAlBNZMABAeYSiMgg2jQH2fLqNglLbC2Ge0DCtRd1A9dYYVdDO8fNpllD5c
M2xs+hiFluh/GJbtevH/an7DT3YLh5ijxiiW/dBV1OUYeJsg490tMIxVWXOyHRjjDE+OU7yMwTVu
YYtbfjggjF+OtWcp2qG2C86Aj+I8w9UtQocddljJltS2nXHOFEPbbnzQzGmxU68fQTjFbUpuubGb
b0wMdxlMjGzOntuEjjzyyOJoczY5atrgoLqtyHObONXmn3PAoXM7nlssFQ4J51tWB/zU43wKLHIY
GOXocsuNgGo4ROXiBfvDkRSMlVkkoCrQIMgrA3SfffYpOI2y9mvHt/69YHBMhdxhskcno9QJYmrZ
w0EcVkaVkdGO+trtajuCYlF3lt+CQ4IaXnoSQR1BGAE0NHKm1ZEBJ4CmCDy5PdBtiBx3Gz/WraCI
AA+ZIntM9pdggKAH+eD2OU64QBp5hu/hbB0IKgmYhIPtd8gb9cgi8oAsUGQVy1wWWCAvbEjI/CFH
I5gn+CTYRGaqx8l3e6WAiv/1LeDlZS6uI0MFZMhJmAgmmB/yUfaV2wsFA1ajmAMymMzc0stEVAQq
N/eyHckQ8yCoASebSIJSCpw8h9JGE7lNx8jqE9BU6Chtwlgg1Fht4pD75su8uZXUb+3DxBzBxXoS
BCJ7BCbJdXNN3tMLcKTPyDY85doIxKAXv6hvjmQE0iPGpF1tRiBG4NJvc+RbINDb0vGaIBUexauz
LPp2++s73/nOrcFHG7ToRF98o88HH8HLnMESrynGRncKRNHr+Nk5eOJTv6Ou+salXr8SdfFAV6nb
0755FhyzAYFm9OjbvERb2rE+0N+vRF1jjaK+dWhOtc3+jTGpQ0YYe5yr+8RHbKGl3iaktl0bOpCt
IsgWfUZ/8e14TYc+BRCN07wFxnWbdVsw0D7Z1FWibpcdp19zFHW6rs9jiUAikAgkAonAekFgzTwD
cL1MWI5zeggIdLmFyc60HXTGfr/CcHdrLOOZExy3BanPWObcyIYQ2OMIcKg4QJxwzmsYpZwrTofA
GuM+AoAMU4ZwONyMYc9YYrRy2ji0++67b3GkGM0CcbLRBKmMg0OoMML1zSFEE7rtysfbSbWpf9fG
mx05G5xzwcWlnmGPRiUyFv2GTzj98OKwop9Rrj19hQPEsBdQgNGiBgA5DDAWyIQVpwS25pMDJMtz
kOMFMw5UZPHAEi5wE3TVVpZEYFQEBGoEZ6xVGbr4k8ywJskZjrE1R27IxOJQK9Y/WSDYLwAoiEBe
CMLhY9m/eFrQcEsvYOU8eSXwQ5aRHfhWEfSxUeCWa20p1oCApLUuIIq/yVHPVFPIB3TaQJBVJGAh
sGc9CUA4bmzqRfDPIyrqW/+0w+kXRCJrBc7qlx4ISqBTuz5om3WgCU1dJbAkQzf1subIAOOHCYzI
TL/hZM5kXppLGMOBXoCvuTC3zivRBrxk7xkzmS34Ym5tSuhbO+bc3NIJsHDcnLvOcTTAXyARna7X
HzkuSGZO6SLn8RLZbhzmXlsCaks9PWFO8FuMUWBR//Vzjv2PbwRGtTProi8BaZtQxiqYBW8Y1wWe
jhkP2Wwu6LW6njo+sLIuFP/3K6Pw3KDr63bVizWBpn7XOd7vXN1e/TvaNs9dbTvfb3PDOXPq0y7R
bvv4sP9dB9/AeFB9dX0GlWHnB12b5xKBRCARSAQSgfWAwPDUtfWAQo5xXSLAMRAAFKTiLAwyHBn3
nCLOjdvZOEsCRK7haDnnwzFjuHNU4zk2HKRwLNTXFqeCMx/FMY7YQQcdVBwW2QhudeNUORe32vjm
9HG+ZIugvd2+PjjTgoZ+M6w5ff5Xn6PJmfPNQdIWLKLtoImDwGl3bdyW5pw20R9ZNhwnzmqMUR0O
AgwWtRijeRSok8FivmEkO8lbrTnTzvcrMns45YIVMqfMkWObe5lA5sb1Ai14JksiMAwBMkaAXiC+
XmdkA36yBvGSIEvXWq35TNBHBpCgh4BZ3KaL58kAfE4mWL81j+NZMqte67FOBJ3QYQNDAK+mUR1t
RtBbuwJL5IrgobVFpqFR+2jQlrFFcR4G2pY57RrXqhPXoRkd9XVx/Up9o988beoF/9oYGIN5IhsF
SCNTLmhDN7kKKxncgrDtNpw3TvMCI/JckA9f2PjRhnkl19Uhv307BncyHR0xJ4KIsWElQGluYag+
XP2mPxyXeS5o67eCj9QLvJ2TLegWzLoETVGvPjft3zAQRIWtl6PY8EK3ccAOngJ+dB/+kf1o3ILd
S72gZr12atrgtVplln3Psu3Vwiv7TQQSgUQgEUgEEoHBCGQAcDA+eXYNI8D4lRnB6A/ndNBwOTAc
OA4aZ0FwThuu5VTVDg5ng0NUZ/hpOxw617WNb+1y6DhsAkYCT2jTrvY4jnENR44DVrfXbr+mR5va
5zRqW+YGR067HLwueoyJI8khV6Jvfdb1BQLjWNBQny8XL+Af87fXXnuV7CKZJbDg3Lulehi/CPa5
pU52luxPTjZMzJsXLMgCdKwOzCwgREnyCiGAb2wQ1OtM1/E/3rK+8ajif6U+Xw787x9r27oVGCEP
IkMZX5MVteyI6/CqgE+06bjfStRHZ9d59EQd9dXTp8w9wRrnyaK2HFU3iutD/t6jl4UW8pf86ifD
4tqV+iZffQKXdr8xL8bRr45xCo72K9GGbzjSA+Ymsj4DR+0LFsLUnKof12rbb9eaA7LIfOCFwBMd
UV8bMf81XXWbxq2NrnFFO/W1s/gNVwFRQW0BQC/rkk2KX9BHnzonI1EA0P82YmwE4m3jz5IIJAKJ
QCKQCCQCicBaRiADgGt5dnNsQxHgLI1bOEbhJA26Vr1xCicpbq1xLYdlUBm3fW25xodDN0pBE+dx
UFkp524QDbM4J0ASzyITMBUcEQwdJbNRMMatmjKsaoc4sNJWBIdnQXu2ubYQwDfBO/1GNux8+7po
kzyQuTysRP1B9cahgVwRgPIZp6B3FPk7TpvTqhvjj+9B7Q6qY4yjFnXJE592GQVb1/sM4wH0DqI5
zsV3m5aV+F+Q8gUveEFz4oknltvaZfcJ9NGrESyFk9+Cgl4QIguSLB6m51aC/uwjEUgEEoFEIBFI
BBKBWSMwWhRg1lRk+4lAIpAIzBkCnGJZIbJooozq3ApQyEQR/GtfE8fax6OP/E4EEoFEIBEYHwEb
ejZePEfRy6o8KzKeXRgZsrJk3SqvjsCfjTayPksikAgkAolAIpAIJALrAYF8Cch6mOUcYyKQCEyM
wKSBOtd1Xdt1bGLi8sJEIBFIBBKBggDZ6jZgt/W6rdmjGGRvu9VXhp8AYWQAyo7MrL9knEQgEUgE
EoFEIBFYbwhkBuB6m/EcbyKQCCQCiUAikAgkAmsUgXhm4RodXg4rEUgEEoFEIBFIBBKBiRHYkNko
E2OXFyYCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAnOPQD74ZO6nKAlMBBKBRCARSAQSgUQg
EUgEEoFEIBFIBBKBRCARSAQmRyAzACfHLq9MBBKBRCARSAQSgUQgEUgEEoFEIBFIBBKBRCARSATm
HoHMAJz7KUoCE4FEIBFIBBKBRCARSAQSgUQgEUgEEoFEIBFIBBKByRHIAODk2OWViUAikAgkAolA
IpAIJAKJQCKQCCQCiUAikAgkAonA3COQAcC5n6IkMBFIBBKBRCARSAQSgUQgEUgEEoFEIBFIBBKB
RCARmByBDABOjl1emQgkAolAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIzD0CG+eewv8lcNttt222
2267RSE36ZwhAhs2bGg2btzYbLPNNqUX/2dZPARiDs1jru/Fmz8Um7dYfzmHg+cQPng+8IrvwVfl
2ZVCwPyQRT7mySfL6iIQ8xDzEmvo5ptvXl3Csvc1iQD+UsjmjdtubG7aeNOaHGcOKhFIBBKBRGD1
ENiwzYbiP7FtVqsshIV70003Nd/61reac845p7n1rW+9Wlhlv3OCAH74xje+0Vx99dWFoiuuuKI5
77zz5oS6JGNUBLZs2dJ8//vfb+r1fatb3WrUy7PeHCBgDV555ZVlDq1DMjrnsHtibrzxxuaCCy5o
rr322sbvSy+9NOVWN1SrcpROueGGG5rvfOc7ZV7S1liVafiBTgUAL7zwwua6664ra+aiiy5qbn/7
25d5+oGK+U8isEwErH0yWXCZTjvvq+c113//+mW2mpcnAolAIpAIJAI/iMA2G7Zp2DP8gdUqCxEA
ZJAfe+yxzemnn14ipqsFVvY7PwhYNOeee24h6NRTTy0GG6c6y2IgYNfjqquuKoF9BvcxxxzTmMfM
ulmM+QsqOeZf+cpXmu9973tl/i655JKcwwCn41uQ9Etf+lJzzTXXNCeeeGJz9tlnl+BpR9U8tIII
kEeMMQFtdsZBBx2UtsYK4t+vK5lYdP3FF19cMjPf8IY3NHe84x1zzfQDLI9PjAA75Pzzz2+uv/76
5rTTTmuuuPyK5qabMwNwYkDzwkQgEUgEEoFOBNicV3/n6ubcc85t7n73u5eNp86KMzw41wFAxt/2
22/f3Pve9y6Bgssvv7wYgXn7xww5YkGaxgN3utOdmjvc4Q7FURN4kEmWZTEQIPwEbO9zn/sUgt3e
LziSZXEQMIfWHIdcVo7grTl0PGV09zzCa8cddyy44XlyK7Hqxmolj+JZt//tvPPO5Tuyy1eShuyr
GwHrY6eddirrRJbWZZdd1l0xjyYCy0Tgdre7XbPLLrsUXXbV1VelbF4mnnl5IpAIJAKJwC0RCP9p
hx12aO573/s2t73tbW9ZacZH5joAeJvb3KZ55CMfWRym7373u8WxnDEe2fyCIMAp8OFQCxT7ZFks
BGL+UE0Y5hwu1vwFtdZgrsNAY/h34jUco9WokfOyGqgP77PWE3QEXZElEZgFAikDZoFqtpkIJAKJ
QCLQRoBtw56RQLG0tNQ+PfP/NyJgXosd+bvd7W7Nne9859yJm9dJWkW6at5Np2AVJ2IZXccc5vwt
A8RVvjTmEBk5j8MnI/BKrIZjtdI1cm5WGvHR+st5GQ2nrLV8BJLXlo9htpAIJAKJQCIwGgJ8gdV4
/NVcZwCCLrO7RmOgrJUIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCHQhsCGzELpgyWOJQCKQ
CCQCiUAikAgkAolAIpAIJAKJQCKQCCQCicDaQCAfnLY25jFHkQgkAolAIpAIJAKJQCKQCCQCiUAi
kAgkAolAIpAIdCKQGYCdsOTBRCARSAQSgUQgEUgEEoFEIBFIBBKBRCARSAQSgURgbSCQGYBrYx5z
FIlAIpAIJAKJQCKQCCQCiUAikAgkAolAIpAIJAKJQCcCG+KNV51n82AikAgkAolAIpAIJAKJQCKQ
CCQCiUAikAgkAolAIpAILDQCmQG40NOXxCcCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAikAgkAoMR
yADgYHzybCKQCCQCiUAikAgkAolAIpAIJAKJQCKQCCQCiUAisNAIFk5zHwAAQABJREFUZABwoacv
iU8EEoFEIBFIBBKBRCARSAQSgUQgEUgEEoFEIBFIBAYjkG8BHoxPnk0EEoFEIBFIBBKBRCARSAQS
gUQgEUgEEoFEIBFIBBYagcwAXOjpS+ITgUQgEUgEEoFEIBFIBBKBRCARSAQSgUQgEUgEEoHBCGQA
cDA+eTYRSAQSgUQgEUgEEoFEIBFIBBKBRCARSAQSgUQgEVhoBDIAuNDTl8QnAolAIpAIJAKJQCKQ
CCQCiUAikAgkAolAIpAIJAKDEdhw8803D66RZxOBRCARSAQSgUQgEUgEEoFEIBFIBBKBRCARSAQS
gURgYRHIDMCFnbokPBFIBBKBRCARSAQSgUQgEUgEEoFEIBFIBBKBRCARGI7AugkA3nTTTc11113X
3HDDDcNRyRqJQCKQCCQCiUAiMPcIzJtud1cFW+P6669v8g6LuWefJHANIBAywJqbhzJv9MwDJklD
IpAIJAJrBQG65nvf+95CD2fN3wLMAP+f//mf5lvf+lbziU98ornqqqsWesKS+EQgEUgEEoFEIBH4
/whcc801zWc+85nm/PPPL7qezl+twBuj8JJLLmnOOuus8n3jjTfmNCUCicCMEfjOd77TfOlLX2rO
PvvsVQ+8C/5/4xvfaD7/+c833/zmN5uUATOe/Gw+EUgEEoEVRoCd94EPfKD57ne/W3TOCnc/le62
veMd73jwAQccMJXG5q0R0dnLLrusTNKrXvWq4iQ85CEPabbffvt5IzXpSQQSgUQgEUgEEoExEBDo
u/TSS5u3ve1tzete97rmVre6VXPXu9612bBhQ/NDP/RDzTbbbDNGa5NX/f73v99ceeWVzZlnntkc
euihzcc+9rHmnve8Z/OTP/mTzbbbbjt5w3llIpAIDEWAnf+Wt7ylef3rX9/c/e53b25/+9s3Gzdu
LJ+VkgH//d//XWTAqaee2rz61a8usuBe97pXs8MOO6QMGDqDWSERSAQSgcVB4FOf+lTz7Gc/u2zy
iCnd+ta3Lvpmkey9jYsD92iUcggo4muvvbY55ZRTmne9613NJz/5ycYO4a677rpqmQGjUZ+1EoFE
IBFIBBKBRGAcBOzCfvGLX2xe9rKXNUceeWSz1157NU95ylOaO93pTlsNs3HaG7WubB8ZiP/1X//V
HHvssc373//+5vLLL28e/ehHZ+bPqCBmvURgmQiE3S8LcN99920e/OAHN895znOahz/84U0vyaHI
AJsCsygSDfgXH/3oR5tjjjmm3GlkM+BRj3pUyoBZAJ5tJgKJQCKwygh4nJyNp6OOOqo56aSTmt13
37151rOe1dzvfvdrfvRHf7TZbrvtVpnC4d1vXKndseGkLK8GJezz9a9/vRjh73vf+5pzzz237MjZ
nV+kqOzykMirE4FEIBFIBBKB9YWA525FFt4555zTHHHEEc3jHve45olPfGLzgAc8oPmRH/mRqQQC
BP0EHGUeyvYR9JP5p282SJS1YlvFePI7EZh3BNxuyyn70Ic+VDb+73Of+5T1//jHP765xz3u0dzu
drebugw44YQTigxw+zEZQD5kSQQSgUQgEVi7CIR9F7Gnt7/97Y240wMf+MBm7733bn72Z3+2bEDf
5ja3KXejzCMSC5sBSNHL9AO+5/uddtppJePvs5/97FZDvP3CDxM2q13AeZzcpCkRSAQSgUQgEVir
CIROD2PMONkGnvUrK8dzAd0F8KAHPah57GMfW+4CcIugYOAP//APl1s2hmET2UWCfldccUVzxhln
FFvj4x//+FZbo+30B11pbwxDN88nAstHoL3ObPrLxHX3j8xgjwi4//3v3+y2224lK/Cnfuqnigzg
nLlVeFghA8LRE2D89Kc/XR4tpH3PgiIb+vkbbdqG9ZXnE4FEIBFIBOYbgbZcpx/EpL797W+XbHAb
To94xCOaxzzmMSUr8Md+7MeKzelW4XkpC5MBGG/Vitt7t2zZUnbdGeHS/il7t+I4368wCihvO/dZ
EoFEIBFIBBKBRGBxEeCY0+ldep/N4FEgPh/84AfLrXluB/yZn/mZxrOABQV/+qd/ujwvTDCQYcao
0yZbwcvDXMvB5+j7eNmI/x3n9KvbVQQEZQMxBkcJMHS1kccSgURgNATIAOu1XQTlbAT4WIvW8I//
+I8Xh4wMcKswGSAzkAzwDNFaBoS/4aUegn6uj5d7WP+DZAAZYsMgZUB7VvL/RCARSAQWGwH2Xbuw
B9l+Yf+5E+Xd7353yT7/uZ/7ueahD31oyQy8853vvDUY6FnVq1W22WmnnW6Wuj7PhSK98MILS8DP
gxe/8IUvNBdffHExsAX9RF4Z+4OKHXkPB49nggyrP6itPJcIJAKJQCKQCCQCq48AJ/xzn/tceQPo
MGo497J+OPxeFLDjjjtuDQi6dcNLOwT3ZA194hOfaNxR4FEiMgqvvvrq4vCP8lZPWYZuAWHo1dmJ
w+jL84lAIjA+ApPIAOvfRzbgLrvs0jzsYQ9rOGn8BOtdoI+/Iegv4SCyivU1igz4iZ/4ifLoAe2l
DBh/TvOKRCARSATmFQGbQh7/MqyQ/TaB2Zw+bEIvh7IB7eOZgbID2xmFw9qdxvnhue/T6GUZbYio
CvJRxB/+8IfLw7YFA+N5O/124NtdqseAFzzkAGRJBBKBRCARSAQSgcVGwG7rqFn9Nv448DYN2QOC
fRHYc05bHinykY98pGT8uIVYdhEbZJxNQ/bJl7/85eaCCy5I53+x2SupXwAEJAlMKgPIgrh7SMbg
zjvvXBIM/vM//7NsAAj+kQFkxaj+BsgEDL/yla80F110UcqABeChJDERSAQSgVERoDNGKXTG9ddf
X7LBIxvdtexQWeveTyEQKPt8pcvCZABKo5dOzzg/66yzyg69729+85vFgGfEDzLQRVcp9uc973nN
0tLSLZ7XsdLAZ3+JQCKQCCQCiUAisDwEPP7DbRannHLKwIYYWp795w1td7vb3Zre3Q8lS49dIPPP
G4Odj1v3BBQ48N7wKyPQxiM7w4dBN6j8/M//fPO0pz2t8RICu7+DbJNB7eS5RCARGI4A3+A973lP
c/LJJw+szA+QhUEGyNCzPr0g6L73vW+RATIxnOeYkSv8DrdxSRzwqCHBPE7cKDJABjAZ4JEDq5Hd
MRCIPJkIJAKJQCIwEQJsSZnhr3zlK4de79Ey9I1HT8g2pxdknHv0xPbbb1+y/+id1XhR7dxnAELX
PdKUNaOdonarjt212GEzEZ7PQTkzBCjndpGGaQIe9ahHlZTLcXby2m3l/4lAIpAIJAKJQCKwugjQ
41//+tfLizn6UeLZXoJ7Nv4YX3Zb733vexfj6w53uENx+LfbbruSpRO36rEV7nnPe5YXBzzhCU8o
wYD6MSRuC5blJxjQdTug/jzvxXPGVmNntx8WeTwRWIsIsP3dst+vuNWXExYywLp0G5bbscgA5zlg
1r+P/zlnNgncFuxN4rIAZfSGv3HeeecVGcDn6CpkiGcMehB8yoAuhPJYIpAIJAKLhwAdMShgR97T
N3e5y11KzIrNKejn0TCCffQLu1Q7Nod8r0ZZmJeAxA4a0D3IG4h21RnplLndes8ydKswQ8D92Xbw
6p1614rGpjJeDVbLPhOBRCARSAQSgeki4JEebWOMQcVOYIAJ+nkTm2wfG4kce5l+YXh1GV/a84ng
gAxB18vse+pTn9p87WtfK3aGjUe/BQHcShhF22yN2972tvkSkAAlvxOBGSHQ9TZfiQPW7w477FCC
ePwECQSjyICQCWQAX4MzFzJAAsIee+yxVQZ4XEA8lkj2cBQyAF0pAwKR/E4EEoFEYG0g0BVHIutt
/Ng0oidkly/1Np4j049OCrtzHlBYiAzANlCUsw8gKWbRVK9cptwpeQb6mWeeWV7FLH3fbcPe5iVb
IDP/2mjm/4lAIpAIJAKJwOIhEDo99LrbbWX1uL3CC7/svNokZISxE9gM4xpgcY22OfQCAW7rEwyU
fegW4dNPP718+19WoBK0LR6qSXEisFgI1GvNGuVwubV/1113LevUrVfW7XJlgI0DmRva4m+QAY99
7GNLVuAZZ5xRHhngsUTxYsKarsVCNKlNBBKBRCARGAWB2CCiD8Sg2J02ntwJIuhnIyk2lUZpb6Xq
LGQAsAanDgbGTp3be+z6U8wCgaeeemp5mK/bfLIkAolAIpAIJAKJwNpBQHBOxp8d18c97nHljZ6C
fh4bMk0DLIKBAgERWGRreLSIZ4Rt3ry5Oe2008pdBhGUXDso50gSgflEwFrjZJEBj370o4vtzxmT
GMAJIx/GDfz3G2ktA7Tvti5yZ7fddiv+hpeHuAtJIDJLIpAIJAKJwNpEQEzJYyI85oHesTFMHwgI
0kd0xTyXhQ8A1uAKBgLdh+EvE4CRLh3zox/9aHnTl9tysiQCiUAikAgkAonAYiNA54cRtvfeeze7
7757Mcjuete7bnX6ZzXCsDXc8uFWQ1mH97vf/cpzvzyfWLZRlkQgEZg9AoL8MvL23HPP5pnPfGZ5
xqeEgFk7YSED3FYcmccCj24L9vghLxSZx8yP2c9I9pAIJAKJwNpFQJBPktlv/dZvlRiTLHPZ4XTC
osj8bXrPtbnZm+7WarEzeMMNN5QXg3jtslsDTFKWRCARSAQSgUQgEVhsBK677rryDGC7rXW2z2qM
iq3h9j+3ATMQZQouijG4Gnhln4nANBCIt/Zaa2x8GX+rse7C37D+PXbIJkAGAacxw9lGIpAIJALz
g8A111xTXjwrC9wmNJ2zaGXNBwDrCfHSkHlPyazpzd+JwGohwKm2VvK2+dWagew3EUgERkWAbufw
r4bT30Vj3P47L/R00biox0I3rVaQZ9FwixdTyJJby2Xe1ty8yaS1PPc5tvlGwKaYu+9W2/8mI1In
zzevLAp1eMlntXl6OXgtXshyGaNd5IlaxrDz0ikjIJP0ggsuKFmlFJs3/8j2sNvrVjBvhPRxS4iP
lOB5LzfeeGPjtjV0e4O2MbqdzcOuZ72zQYhee+21zbe//e2SrTtoncISPZwZmbzr4TY72QRnnXVW
ucXJeAfhMwmfffnLXy63K3nLadebreo2zVVkXJmzQenu6DRXPp6H5JasNL5qNPP3OAgIZFx99dXN
5ZdfXtbAJLzEKSej8eIsAyKT0DYOFuupLpkTuumSSy4pPODRLrHzvhws8BS9c+mll259eQt97lly
ZC0e8WIXxS3ei/AIGbeeWid0ubHR5Wj3bOx5K+wO9gY7yprpt27oktD95iDmph5Pv2vrOiv5e9p6
eiVpn1ZfMjMvvvjiYl9MYgdb+zahzTeZnZhOa2Zm2w4bkQy67LLLyks4/fZsXvM4rcL+pBfYx2Sc
bzwm6z5e1kOW+40HyUI2Lj7KkggsF4FB+mq5ba/U9esqALhSoGY/axMBzqM3Sn/sYx9r/v3f/70E
AcOhFOjbcccdi5F93nnnFafhl3/5l8szAiYxfFYSQcb3Jz/5yfIQe48D8FZLivqAAw5o4llas6aH
Y/fBD36w+drXvtYwGhl+BKxvGPsojH+BPwFXb1niCLrtj1PvWVxrsXz6059uDjnkkOaFL3xh4adp
PVw8MP77v//74gC/9rWvbTzLaJgjxeiyBr74xS8Wx43DGddw6MyVtgUTzZdboO5yl7uUZ7P5Nndx
m9ZanK8c02wQ4FQIhHvIPmNf8CYcQjyH9+L/oCB4EX+Sw27R9bDmJzzhCUVeBN9G/fyeLwTMOX1K
3tBNXrRijvfbb7+ib5eToR4bKx/4wAfKS+KuvPLKEmygS5Z6L5DxIau80EFA8Hd+53fmOgBI5hoD
ufz5z3++Ofvsswt25PBzn/vcuQwAWo8f//jHC630Sq1LrN34mGd6j0NP39/rXvcq+t/8mJt8rM98
rVvUBD9aX4Lo5jdsYedq2RzUxzH/W+fks/l95CMfWeT2tGyf6C+/p4sAHWyD7rOf/WyRQ/T1Oeec
U4Jw3o46jQCgPvgLYYNeeOGFTbx5O+xNMpzvwkeQxECG0yN/8id/kgHA6U55trbACGQAcIEnL0lf
OQQYLHaq/+Ef/qE57rjjys6WgJ8HfzJqGDiUHgM2DB0vn2HQzHuxk/b+97+/+cxnPlMcB06E7ArH
V6Iw8mKX1y7dpz71qYIvzGWPCa4KGMGZ8vcRJIxn7Hj4t7cveROn32vJGTDWf/mXfylvFhXgxFMM
mmkUuDPO/uM//qMEtn/913+9GNuDjGzXmBNBPYWzyciL28wY6+jjdMYxTrznZTgmYCsThUHv7akC
glkSgVEQsP4FAPARo1/gQABBwbNLvYCNNRIyl/ywfshk/Gfzhmx2/cMe9rA1u2EwCpaLUkdmx5ln
ntn867/+a5E1HD8veDOPMc+TjAU/bO69sfmYY45pbLDQGXQ5/iGvOIwCF/iLQ/vgBz+46JtJ+lqp
a+CBx73wDu0cXpmNZK5g5zwW+oSzbv3ahIxNJbRa6+ZakC/0vm8blta2zSp3KXjpxoMe9KASEI4A
0zyOdb3RFLaC+XXHjDVFbivOycSSmVpnYsc8s+8ig5VNoQ0ye5Btst7wncfxkpfm+uSTTy76+fzz
zy+ZgGRr6OpJ6bbm8YSNoFNPPbXoBJmFbNHYGMAr/AK+2he+8IUi95zjV7he/SyJQCLw/xHIAGBy
QiIwAgKCYR/+8Iebt73tbWW3SRbJi170omJcu5zhLYgmM1C6OSeTk8GgmfdCgf7ar/1aCf4w0jjM
USjNlSh263bbbbeSYcHJ++pXv1ocMcG/X/zFX2ye/OQnF+NPcNJHdsPpp59e6skK+dCHPlQcuuc8
5znFUHQd2hma0yjRlkCvtmujdRrt92uDwczY4QjLfBKwkwGBv6ZRONaMJfx9/PHHF0fKLuog3Dhk
jHGvu4fDueeeW9qwY29deCuWwB6n01xZD6eddlrJ3uGUWkfm6xnPeEbzpCc9qVnqBW5WCs9pYJZt
rA4CeN4tPIx8O/sCBuSustNOOzUveMELikNZUycoIhCN70444YTmlFNOKcEjMi7WdF0/fw9GAJ4c
LM4cx8pmwCyLPh7xiEeUeSbzzeVyAn9oRTs5+va3v71knZOnT3va04qOIdv0YROKbBRMo8c5kLVe
nOWYJ22b/BUU82ZCspfuMJaV0uGT0G3jT3A1Hj9hjt02qAhc0iUPeMADCs9x/mX6cOyt/TPOOKN8
28Ay5mc961nNzjvvXLKNJqGl3zXwE3Skg21EDtKN/dpYr8cF7tz6KVDLFn79619foDDvu+66a7Gh
6w1bWKtnrm1I/9u//VtZexm4mYyDyEp8S3ax8+E+y0IfsOee8pSnlDUjWBdyc7lyiFywsWFDHG+w
WW0i8118x0aC4LFzgpB0vk0FMt+twMulYRbYmSM6Bo1sm3mTL3Bnn9PFucEyCw5YvTY3zuOCWD04
sudE4JYIWCMczfe9730l0GFX+jd+4zfKbWQRiGHAymxy7sgjjywOBiW0XGflltRM/4hdVbvoaD3i
iCOK87DScgGOAmv3v//9ixMvuEeRU4gPfehDS8YYJcQ4dJyD89SnPrXcBiCLw3PszBGnR2DJ7VqR
pTYNxChl2RR/8zd/07zsZS8rtxdMo91+bcBfnwxgATrj5oS6TXqXXXYpjki/a0c9LrPlve99bzHU
XMORet7znleyYIKvu9piRJoXfMOwN29btmwpwQAZijIxOdL4iQNqHbjl8nOf+1zzjne8owRuOXCc
OcHD3/7t3y4OYAYBu9DOY4EA45MRzxDlEMoeueiii8o64Zg/5jGPKcHxqB/f1hIHAU9aQ9YVvswy
PgLWsk0iARHB/lk/T4kcWuo5lA9/+MOLQ+cREcstApgCezL/OKeykffYY48SaMIb+EV2P/4i4+h9
AYl55xm043EBM/S6RQ5ejs9rQRse4rzTHYKxNv/MAXsKj8nq97/MTHP3S7/0S8Wpt9lqbjj4dKRs
o3322afM5TTHi9fxi+Ckx3DMOogyTdpXuy1Ykc3m2DpjPyl0vU0bQcB2UMFcs3fYpNbfP//zP5d1
ugi29Grj3e6fnpQpL2OaDWYuZlnMpTUsqE/XsimnEbwVxDSOo48+unzjjyc+8Ynl0QZ0A/lhAyQK
XpF16M4gPOeRCPwGQTb8NU8y0Sa5jUn02fCY9aZaYDTKN/1o/dmMsVancQv3KP1mnZVBYLbbtysz
huwlEZg5AoJLghYUCyHYvtWU4uM07LnnnkXxvfWtby2Bj9j9mjmBy+yA0jGu1RTwlDKHz45wGIUM
SP/7jo8MNXQKtlJMHLXXve51xTGNtH8ZhTIC1J1GoaQFdmWFcAK0P+vC2ZaVF46nbwFBzqpb1WqD
Z1xaGEKCiTJhwrAW4ORUcbyGZTqYK3MkGMNIjyJAA3NzpZhPxwQJl3qOvAyNN77xjSXwKGj4T//0
T2V+BQHNZZZEYBACYbjjK8GOKHgRH/YznjmgggmCIuqEfInr83s4AuSP23Hf+c53Fv3H8VqJYq5s
5pAjZB4HbjlFEMnjOsg7fERvk+c17+AXmYfGbFNJ5jcndN6L9UH2Whtk8yIUNPug13xEofdD9zsm
aIQH6D5zFhuuMjkFAOkzQUKBxKWerplG0R6etzFKvoSunEbb66WN4EmbhlGsY3Ptu153cR4Pe5QI
GSOLzHrUTpbRESDnbNZYHzKD3UmzEsU8mVtz1jW349JABnsuucy/SAywofe7v/u7hT/IiDZv0Bn4
Ryai6//8z/+8yHF27zyVOrDJNuazTAOzaY1RYFKChccDecxClrWFwIblGlNrC44cTSLQjYBgDCNT
kX1mZ729dhgzbn18/OMfX3ae7Oi4rl2vq4dR6nRdN81jlKgxzLIMG6f+2zS0lTv61GEkCizB28N9
Ba0oeHPjxRZu+xvW3yhjpaQpQgFATuM02hylX7fKur2Zs8Og0u+WXtBMNgK+Wk6R1SC46NvtlLDU
vmOyqsYZY8yP767rHGeQCdra1f/jP/7jkqWiT5kqdhjt7i6Cg70czPPa6SIwThCP4y4z4elPf3rj
5Uw2D9pyZrrUjd9ae+20/x+/xf5XdLXddaxuQYbVu971ruYjH/lIycgZFf9h7dZ99PtNhkxrvmSP
kOMcZBt0MpFt8NRFfzYyOD0yTTiZMqZHCQBNY7w1LeP+Ni+wMoZFKm2au+h3zPgEC2Wf79PL+OOc
Cg5Gpp5HZpjb5RZ8wpagnwQX5y14sNzxrfT1o8qLmi5B3mc/+9lbHw9Tn4vfq7ne6r7r30HbtL61
3W6//X+7L0EzwRu3yvNFJsG/3eao/1vL+utaw6O2EfVkErqV1+2/bESbALJJ3RlEDvTrw3F16Xub
f2Q4eT+KDI++x/keNh/ttgQm2fdh/5I3s5yjcenzbO+jjjqqZE+Sp/1wbo8r/18cBDIDcHHmKild
RQQYmJQNQch5kLnkdlUp5vWuNSH5C7/wC2VnijBnlBK8beFJ2DtHoQnm+LZjZufeTrP+2sVutI+g
CWWmPoXmWmn2FJtUeNkSnJd2n9GevvWpf7cGKAKXoxrNaAjaBUP1Y3cXTRRuu98Yqz71ITUfzRwq
3661q1/jGLQO+9aXwBIF702Hf/3Xf11uH2H8yML0f52hhhbGEPrRg379Bm7qhqNp3tQRcPPsGrcm
qYtuPKDA2rEYM6VujMalbX3hm2i/rjtobNo5une7g3a8nffwww8vihjdsgDtbE6arWlcnqEiswGv
7r777uUtw569yMnn4HvLYp1h1Y/WGHe/8+3jdjdlzz7/+c8vjrcgrWcEujXYrq7b17IkAtNGwOaN
teTlRiFjo4+QCZ7DQ55aq+SndWwN+1jDrrPmQj7E9fV3Letcp7jWh3y0/utS1ydXyUbXkTHoscHh
GvXaBR3add6aRq+P34rz+gz5J4DhPJlGLukrZKG+9EsOG6d2Y5z6JvtkkrjlUl1tcMwUgXz1w3kJ
WuBNXtFXcNMu/TBIBtJhaHRtzIdr/T8tx43MCh2rL88nJXvoQEHiWqbhBRtMsv+NGYZt3Wy8aIWl
QCLZHfIeLvCpi/qhJ7QJD9ho2zjpZHUc047+aprqtvBr4MUGMAf6hPugon1t4jl9agPP6Uuf5glG
MafRluviGn3oy8e4fdSXTTmpbop+fOtrUIGr9ewZYLLEZK/Dk973SBYZnHUJu8VYYWwO6O8Yr3mI
oq7Mz3e/+90l88j8OobnI8O9nttoGybmIdo2h/oYNIfRZ37/HwLwlHWLv9kEMPeJ4ryPeYH1Ui/j
0zcZhgd8yE58TAYqXWvImjNneMK1+jNfrjG/XbJKv7FOyQvrBO97Vhr+d6yfrNIemsjWWO/ojuJ6
/Oh86Aa0GSdeJ2P0HWMM/kVrZI7p24s4ju7ZjwLX2tdGPMtN29ZnvbZdY/zGRl7DwTi0W7cddNbf
2kcXvkeneYKJtpZbtG1ty/wjn6x5a5u9b+yjFHi6a8YjH4zTpx47OQOf+MAWRq4zX8ZTy4aQneYn
9Kf5l2WpLn4K/oBDyAB94sGQoR5bJEBLbsHKde400xd5YXzoiIIuNAaPm0N1fLrkS8yLOVH4WdoL
/vHtWuM0x7E+8OWWXqLBm9/85mZz70VZxqhvPg/s0Gd9BL8Fffm9eAhkAHDx5iwpXgUECEnPLKFE
CVZOw1/8xV+UhxjbjaqNfIJWgEM9aei1ECf8CVg7yyeddFLJfJKBoC7DwMsVKCvfIZApY8pPUEsw
ijJk9HrmFcfEw27dykmJUI6egec5OYR7u6gj6CLgQrFSOOiTZSYFnbDvV9BO+bitwAtP7BAxFhyn
/Chlu/GRXYNu7ckoY4jIomPEvPSlLy0B1BNPPLEYDA984AObAw44oGSHxZj70dDvOGXouYxvectb
iiFCuckEMF8y3LQLd0a9nUTzJ/BEoRq/efKwaruFfivOeVmF4J9bxig/83TQQQcV49Kc77vvvuXZ
GH5TkoJqnGS3Ivtf/Qh6eWah57BQtsOKnUFzbU7QhUfMMWXumUeMGZjjmXELmvCegN+LX/zi5jd/
8zdL5h8Fb87c5oxWhsssCkNI+7KJzAd68DG+NF7GTJZEYJoIkD/461d/9VfL2rXmGfDkBGNXBipj
F296DiZ5bx2QtdZJyGa3HXE2u0rIdQa9F/aQPdYTJ0C2Erkua0Fb6pKN+ian3JpM7ni+qDfNy3hQ
h1wWMOfQoZesVcgzspSsl1VrDZFVnrkkSEFWudZ4PY9JW4L7sooF+AVp3Balvv45I2jl9NkQ+JVf
+ZXSPpwE/970pjc15DUsFPTRH2SE/j36QgY2+vRP1pOzxgdj9FrbMjDJMw6EY3VBI11Bt8CDfIaR
do0Vnkr7urqNUX5zYLRHP2qTLoY5fL0MhL4IB5FcN76DDz64zE/b6UGzQAV9alOFPkUz/oE7PS2A
EQ4k/atPMpwOokO94IoNIVOHLsen5sL87b///kWvcizb49aWZ1vRN77ZCAr68RKHvF/RFv1Ex9hQ
MpfqG4+XOwl64gE6xphhg8foezoOnZxePC1wCj80GDee3G+//baOuR8N0zhufgRv0Yvf0O9Zs2h5
yEMestUuM1Z2i2fe4nX/q2tePFPXPJkD/xsrnji6F0Axr4Gr661/vMvO8sIxQXSOO/mhbTjid1jR
Y+qxiTw/axJdPQ2MFrENGzYeNUB2ygDEV2SLdYHvYv2wg6zlV77ylUWuCdh6VqO1wQ5l25jbLpvL
/Ft/ZKB2yLaYN7KKHGTTknH61ia+wVvWDJuQD6DtN7zhDcU+Z4fiOzSqSw67lhw1Fna5do1Hf+i1
nsIOtfH6h3/4h2XNhd1MrtuY8Sw7644uw2eu4WuQp+SWa/FcyCP6i6yx1sl4fKxfcoXdJ0CqGBdZ
6zZ3uJLfcNAnPwT/4mNrrV3wOr8EXeQXGYIGj+WBv7aXU1xvPuOuFHLQLf4+4xTPpXZ7rbGbiyjW
OoxgShZu6ekrPg6ZR67RvTYS4AA7xXxa83Qy+8D8wO+QQw4pvHDccccV2c6eJk9cT1bgKXOhTzj/
3d/9XdGpNiNijtCCT4zPo4boKDzkuHbRaH75AeSQBBQ61a3y5IuxmTttknN0PX41H9YC+a0dc6YN
/MMW56/GGuFn4GfyTL9KvEzFeDZt2lSuoSfQnWVxEcgA4OLOXVK+QggQcks9p4/iZugplDuDkzB2
+6lgHENBXR/KmKIIRyJIJZwJ5b/9278ttxTLImSwE9YcAoEfzs+BBx5YhCzh7/hrXvOaZktPORHs
DBfK1ZsK0UP5UEj64zwwLPTLsSCwFef0TYG8+tWvLm0JvO21115FwVDgnLzYLeoS7PqRBcL4oeQp
H46k4A0DgyGD/j/90z/delwKueMMIm1Trt6kzLgW1DI+WFLQjIyufgO7Qd8UH6eHwcYh0q4+Oa9o
ZLwwmgTz4A8/+HB4jZ1jzHFg/HiBCKeTscmgoegYe/BTGAIUszbhoG/GmGeUUOoUv7fbMho4hOih
TGEja5NB0GVMxfjQ7lZcytebptHIkdd2YKhN7Y/rVOADPIsPKH9vT2TowQIPmh+OLAMBRmEUBG3T
+rZWBEPwsHHiX/yNF9CVJREYBwF8HaX+TZ4IyFi/5CKHJc6TlZwesss6tdY5k4LjHEOGs2PWvXY4
IuqRgbUToV+OiqCXTF1BbWucLCJ/OAjWEweJM8tZ0z55wfEkc1wvEIEebYThTUZyBqJ9zgMHwbql
cxj2nBX0CFQx3tGBZhtWZId+yVsYcAKtNX0x8t1+FM4qXOgNcpKD8opXvKLIAPXJOXIinGRyhwzk
8HJEAg+Yeh4rvcR5QpOxRHCEw+RtzZ75Wcsu44IJmug/MpdO0Ce56Xo4qTepjgj+0C+nGU5oI+f1
7dmkxr333nuXvmNM6tOV/o9j0RbeOfTQQwtfmCe6nPykS2wC+c2h39Rzmsh1cltgA2+R5Y6ZIzoe
ZvClS8yFuSST8ZugQm1LuI79gVfUE2DCD/iEfnOHAluhTW/QjQ9ciwfJeXaIawWv8TmdDZPf+73f
K8/a4+xyAp0np/GMuWFfGIcgiuv9rz0bXW7fXIlifjjX+B3N6EAjXYZGa4HNIZjnGNo4zIIKxgQr
Y7YxKUCj4Hl8Zj7ZPXA0tniumTUYwWA2jvbJCnrU2icntPue97ynzM8f/MEf/IA9thK4zHsfIYfR
Gb9jbZObAq5hR6vD7rVOrFMyCg+aa3wuAC1jCV9H4M2cCiSaN0GSev24jg3k7gpyxQaNQIjrbUAI
zOnLddYv+thfZLm1QG6QRda4NeQ7NjrUJZ+tdXT6nw1K9rPZwqay7vEhnmWDsl/ZeeiWxWoN6sc4
0XfYYYcVeY238Kf+Q16TE+i0jiOYyI4S8CEryGiy2lrxCbkAB32T2dYGeuhAcpreIMfIsD/7sz8r
MpAeiGLdk0F0lpe5WVf6RzMMtet3zGlcN843+mxcGbNizZEv7PNxCjlA59BZwQfwo1vwDlq1SWeb
F3NAjpLvNr7obLKQ7W+dv+pVrypBQ3PjIzBJBrJn6XQ8iXZjR7++BPTIKPxgjswJvsBz5kMb2ucb
4JGgU5uCi3STzQ4bS+bbvDhmnbzkJS8p/Ot6fG1MjqMVHWxt/W7ubXLS0cE/+sWj6OLfKtYD3tEW
XwbtwT/WEtkXtI0zB1l3/hDYtsfsB8u+yZIIJAL9ESCcKQgCkdJQOA7+57AwJp2nPAhVAtJ3W/kR
yoJQFJpdOLetUjoMA8qNgOYE+DDqKS7Cl9BlzFC0hLcdav0T2vv0noMjeEbYcxh9KGoOgesURjDF
JKPAtXbuOXiUSdx6ydClUCgK/e62227FiEcXhcZZZEQzthkb2mDoMPQZMRSdNig3Y6LYKBNGhKAT
GhwzNkYyTP1mVDMeBBQZUQKKlJt27MIZhz6GKR2GDlwpbWOAAceNUYJ+RhVjjULj5MkYNH5GAQed
UtWnjA2GP2Vnhx+2HB9tOMYAZRAY41IvMKwfTtgf/dEfFd4wjnD6YOU8XGFk1xXejLCugm5Gk0wg
Bu9f/dVfFSMBjRS1ftDIWEO7AAA+G7XgHRgYD2PTHOIR43UcD+ErWHM6zU2/AsctPUeLweEbn3Cs
YW7MwwoDUqYUA8o6YYQIGAzqc1ibeX59IGCNWOfWBN4hr/CdNUoGkCvkJVktmP6P//iPpY6gEl7H
3/iVvLYmrH/XWlecTwYwh4EDaH1Yd/jVec5Y/cIackfwxsYHPWCnPR5QThZoV/CNbNQXB4vsQye5
4BpBSmPym0x1nswUKBc8oAs4W+pY7/5HG/lo/D5kBOfUZobgG7vOmiJ3YQErwUl9cQz1ry/ZCYJX
1r56HGh0kAMeEcDh4oiTO+gll575zGeWQJ6ACXnGWUAvR2VzT4fJGqHf6BAPn4c5maNfctA6J1tD
dsFXRqIx6pP85JD7jTZ6lnxGO0y0Sa4P2kjptxLMPXp9m2s6yRyaX84R/eMcmjlisPV/0EpGO8ZJ
/P3f//2C2V/+5V+WMdNVPnQwrGBizPSAoCZd7mMeXA9Tc4YvyGKbT+bOeWPGO8brWYSui2ITTp/4
2/xxLvE2XPGnfp0jo9klzsXjFfAwp52TKOvNBqYNK/rM9ewENgJbI7Jg8AJdjmZzhS54WWfWij79
T3/jB3wh4DBOwY8ccXgo1jM7QfvDChwFVdGnCKbEtfhO8MYalCko28W4jRWvm2/jhRNeo5thbkwK
njT38OH442m6l8yBkewzNs6mXpCXfQVrGMDZcXaR9uDvG++sx0Km4DnFumW7WGP43Nz7wEqQjbxm
K5NfcDUn1qA1YE1aX+RIyE3XmRcbptYKXiVvrT28IZs1bBLr15zbVNcOW5Csxy82RhR9ux5/O0YG
mms8LjCIz60Ja4wsIY/Rb72RWdYkW5EdS67iYTToI+igf/CVAA+5Q2bKnnVev8ZHPulHG2wsfCuQ
qA9yHf34LHQLW5V+kekGVzJfgY0AFn8B76IHHwoykrVkoOdmo5FsZcdZ59aTedO/9RhrUZ82yiQy
wF6WJT2lbevKvFlvsZZdB2dYjVrMEzlGf9PPCpnimazW2DjrSF28E/pC29Y8HhCkRy99CX/YGgfZ
Z2z6Nhfkt3rasY7NdQT7zIV6bFfyhX+AZ9FPZwcfkSn4mOxgGziH18w5Gfzyl7+86GRyiD5Ho+Br
JIXgU+uBv4T38R9dYf7NvTWF79DhGLrpFryAFjKIXja/eNj84Gk2jnkzrrCl8J726XsZ/vq2wUG2
mU/jyLLYCGQG4GLPX1K/QghQ1IJQnDwGiF1fhXKmIAXGOIFe4y7VnGHTVlAEtfRripFzIwCjLYXx
6X+3RVLG6vhNIQgaOUfp2pkj+Al7Cp2zQSkycghlz7wj7PVFuVAE6GCcaI9BwBmxY8RICBoJdcFI
Bjhl3y6cOlkklBJHhTEQwUXGj/EwFhheMiv26QUlKRQ4UI5uX1AoOoYAJ5nisXPK2aVwKS6KedLC
oDKmKHa+GFacuzD0YYMmhogP7Ch146fs0M/QMz4KHKYUZRgO8GIYcDAU/xsf54OCpSwZCJSo682v
3TfGAwc2Agl2/roKfrJzbL4YEQxPvAcbfGV+0GMccGbs9murq308ZEcTDwkghJPGGWdU4Rntc3oY
mvCE6ywKuo0LhubIOkJflkRgHATIDIYu2WutRHGckc4A5ggyfkPeqcPYtX7IBk6YNeV6QTFGMhnL
yI0gnnVJNjL6GeBRGOk2dcg/zomNhQhukZcC6TIinOcI4HGOHDlERglOWI/kBrnJ2CYbOY/kDvlB
vns8gSxtv8kq7YQcQgvZRb5b02QyR1Cb5BuHlJwVNLK+/Xb7GjrIKTJM0EYAikymg2Q0kEH6p5/o
EnjA0LjcHuq4/wXxBVpco1/yXZA08OZYeTwDusk2WW2cYbLFONyuxslBl7oyUUK/GA/H1UaDwNM0
CvlMnsIXpviHDEKL8QvqCEQIrMEy5L++Y0weBcGB9lKjCDY5r2244SkOpGCDbBr2Az0gCLWl58wH
FvASSHScviCH6UnBVPJYH+ZMsFpBI3sDneaG006nh0MmYIEPjcmnLsYogCE7zTjwGmcz1o1AgTbD
6WevWA/a1A9+whvG5HrOMsff2IxVANm8j6OTavom/Y2HAx9t0MXBKzEPZIE1j4/VN2Z631plb3F4
XYenjZOeN5dR8COeD740fk62NadtfKptc+gc+4dDLkhDRmjb/Mc8Rbvr8ZtMlmXHzoBVFDiSReQs
W0qpz7OFBSGctwGkLsytU5sS5pdMFWjBr+wpa43cNafmXNBDINK6YgOxZ61B5yKYd+yxx5a1R65Z
C9YkuW6dkwvmkn4hB8kPvCezGS9YE3SHtcbWolfwovVu3NZ2FLpH4AhtAkDGBwN6AC1sfONx7ODe
YwgEoR03LjrIJv7mnm2OThlrZDh5j4dhYUw+2rcm8a8CUxjaYGaX0gtscPJXwffGa+1Y72SG3+xR
beF72bNohw3dhLf1pdCr8CcTjH+SYv7pNGOLYm3FuOLYqN81H8GPDMRD5gn98Iy1qw8+jXmjr4xX
gJQc5BsYHyzoO+MzP+Q3/Yn36Au4OIfHtcEnI8f1Qf6YI/yjoM1vbZoD/xu/Pt2ebC7wR+3f4Hf+
IFlso4H+JM+0sakXJMTn5Jp+ySZ6FY+aW+uGfAu/CG/C2hyiA30hI9HnWK3vHcuy+AjMxrNbfFxy
BInALRDgrDC0Gf6MO8I5jD8OGyEqlV4AyXOkGNa140AZEtIEO4XBkQylxJhggFIOFK6Puoo6FBIj
I4xHCoiCIcSdp5RlaRDulA4nQRuOMSAEqOx0EeSMGEZv9K0PdBLwFADDAD2K/ihgzqhgGgVDiTEG
olAmYay5Tr8UD4ebkkNDFP3a6aSk6kAa+pdbAqcYF4wpcLRpn2EEczRxUmChMOgZVQwzzrVggWuj
RHv1//Ux2HGAKFl9MQDMl6Kefsyrgk8Cq3Kg9UcggGFizgRKtaloh2EJf04hOmXPcWJHdbbMkyA1
Z4Tjb17CYMPb2mJMml+4CVrgYUbpLAoDI/hZ+/jO+LMkAuMgYG0I1AteWMMhu3zjKTKaTIrj0bbr
1LdWrU/nySROlqBfyCSBOoa/ACD+FOSIYk0xwDkS5IqX8wjK1etKMIsBL3hvDfvoUx3y0Brwe6mX
TWzNo8GaIyPRiA4yikPFMSXf6Qpr1do3doWjSy7TAYJWITsE2R3Trr7IKw6qwE5c63o6jcPJSTBO
TovsBGNvbwKgKz6u5WDDgGySwcaprHHSXshbzhc5xBk2NnqFbiJzOFH6iyCLtmGDdvNAx7bnUZ1x
C9phTBfdo+f8uy3X/KKB7Ofgy7KDs8wHzlPgqS+BNUE9828M9GvIMvTRv8EDZD4e5GCRucZm/s2L
uRBwcwdABLDwJB4hH+GJllouwop+1Te86LLoG20cSGOCWTsAaGycebYI3tM2JzL0nb45xDHfHEt8
QJfTkdr1rcCDLREBUrxEt2kjri8VV+CPMdc8Yx4DM/xobToWwZGYG/MQfEnv+UTBI3UJfq+PmzPr
1BybW//HeTjByP8cbXWmwbs1TYv6G98LjrJjzUXgwu6x5mTPwqtd1CWr8ZrfsIW/zR8yTsEH7HT8
j7/JGTy81JOvZA+etgasPzLQ9cEPvl1LDltn1oi1qa528RQ5pF3H1CNLjUf/eA19/net9rf05LJ1
bAMDHbF+tEVOkudkr/r69xHUrIN1+FaAquYva9LGDn8DZuSLoCbbLuzNwA9O8XEMDjYQ2MMwJ2vo
sSjmw/HAhR41J7IDyQebz3SNccKHzRt1taF/OtS38U1a0BmyKdowjuUUY4OZMZgPNi76YRDFWPAY
H8u8mW+b936bCzKD7o2AqeskaWgr7AbzSV76H5ZsEDwdc6OP9ljqY/Qi2czW15//8VKUWp7QBWS9
QCV+1ic+80034Eu8iHf1iZf5LNagebdJQUZFqXnFsfi/TW/Uz+/FRGBjTuhiTlxSvToIUHh2YWRH
MX45ZJ7/wuBn/FJ2Mu0Ym3b17RYxiCkdO4kUNWVqZ9CtWnUhxCmJqK8epR4BmHqtUlYUSX2MsA8l
RmmGAaxNih5tnFO3TtXKOmhgtNdGtOPa58gJGoXx5FatoNF5BgEl5dtx9dRX9MNQUigiSpOh5Dr/
B72lwhT+wCyK8TCkFIaTW3TtmlHsFLNibAJp8GH8G795MJZRi7EwdtxCqw0OmTFS+nbhOJaMBwU2
/QKA5oyBYVeVUcXQUKK++bZTyXCj6PGT3WhKPHikXNDnD0PYbRv4gLECm2jbJYw7xqzzaEe3TB7O
kzFOuzBg9G9t4BMGS21QTbu/bG/tIkAme4YXhxs/RQm5K0uLHOpa13g7DG/yi7HtO4rfIUe0VwcJ
8HBkaDGoyYE2DzO6ZQZwUsnocOLIv+iHXuGwhhPrXAQm0IFG8kAmHJ3DYLc+rVnyzLgEmcgFDiBa
6iCM8flE0XY4InEM3drjWJKHZDqHg8xCz6BCT3FAOBGCe+Sda2IufKsT4w2nnLyFH1mGXmMMrOv+
4GP+jCHarM9P8humsJNFT+75prvD6TLPAm2emev3Pr2snAgCGiOdr8gAas85zOrx0jORyRL85lq/
6cBa7zqGD2qsaidYoNX8w9c8R0BBe4rr0RPXxzHf5LogKtrZIrUuj3px26TrYS24a77wjHkIPoIF
fR791GPQ1koWOhu/RsFDMSeC8uQDDDnCxmF+BAFk1+Bx43RMO+MUwSK3U7sWD8GETtOmzB9Ou7Yd
G7ftcehYtLp4RnBF9iieijVNjpknMi5uF26PDX/X8qi286IuWWFtC9xoD2+4Dt8LALJx2Exsp+CT
uNbas9ZtuDhHLgfP61fbit/mX//aNqZYC85rXybu5t5GDVlgvQm20AfWfAQFXSuQX69jx2r5TVbj
W8ej0CWy9mwKk5/sfXLGGIfZ1XiRjCevtSkT0DzURR3njcn86IMcMG7XRrDJ2oJ1XeAFu3qe6vOj
/DZ+mNRyRf+1jT9KO+06xmLtC/4p5rdNv+P6F9QXnKVr6QC6Cl+Yi/bYbCbUtMKAPMAv5K7PODKA
nW8+FY9fkm0YxZxZK/gKHT7kdOgY9dQJvjUXXf4imhXrgwzLsr4QyAzA9TXfOdopIBCCneJlANvp
cUuwwA0hSlHIHpBNR7kwMhjVgmLO3aMXfPLyDcq7XSin+BDOwxR5fX0t8B3XjsJJtePvf8oodhbL
ySF/jDVuYWHEyrIRFGJgR/uaCJr9pjiNPQq6ojAy6v/j+DS+0YfWoMtYObPhtDBUzBfFSfkzzMwT
Jet/16HN+XEL5cpQCCfCDrOMH5khjBbzP6y41q1w6lLsHohfG2XoQms4Ogw9TgbjcViQjuGBPzm0
jDpjjyBt0GWuAwfHGM/q4W/tT7sYZxgd+ub8RwBk2n1le2sbAWudw8VhiPUfI3ZcQH1LzykfpXTJ
p9oZq+UDZ8SaUhj/1kld13FrWNDPR+lqH/+7zne/Ymdf4N6aJwdkj8jQW1paKhtOZE3Ioa4gWrvd
Ljo4LLIhOMlkBjnkm7PZr5BHZIn1rB79IFuF01HPhd/xv7FGUIYzRkZyNGHkuq7SRW9XvXGOaVN/
ZJznWNkcszlnU4+DTqfYxPE/+UT/oR3uaDZewWXXt+mL8ZpT4+JM1iXqx3d9ruahwMx5Tr5buvTN
aWUj9OOZrnbJ95Dx9IYMyPaaCbr157eMzJh/bUa74Xiqt9qFXVU7v+YqdBaedhu+QBAn3IYfh17A
2uYoParU4x51PHhWFpu2rRPBWY56ZHYFTfUcjtr2Wq6HhwRR2Me1jRNjloVNnrF/a3kb5+vvmifr
4+01ZJ3YmI8AuDVrDbXXD762XsMWCX6v247fXbTHOe1a8zZkyDhBRxu8Ap/ktHUokIYGvkAdPIo2
4rsfDda/DWfXhp0Zwc64tusbr8ZztvUvAKitNp8G9sZirtjPAn9od84cWl9d9HUd66Kl3zHXm4da
l6GbXKZ30TtJMUbBTG3oA5/0o5XcM2Y06Nd17Oeu0tUGXuo63nV9+xg+xTOwl4XuToL2/Pg/jsGj
rWPqNtt0aBd9SrRR18/fax+BDACu/TnOES4TAcadQAVlHwJTkxQHp8xtAJSwB+LK6qOAfRiDFLsd
P0qDsaktzqqgoGyLtlAOUuO4uqOWuKZdXwCQE6OoQ/CPWtSnKBmyMKAIOdMyCY2lq7imxqmrziyO
Me5lb4TRwshyK1U4lJQcBe7WDplzxsOhFhAVrJPBtxxFyDmTGeIWXs6FQK+sH4pZlojgZL/C0fSM
MM9xUTj48Zym+prgRXPot2v0iZ8YS/0KHnBLr3YZNZyg2kCO68IZMofwFJB064C2HZtmEWQIYwq/
CDwMGsM0+8621h4CwZ/xHSPE57K7BLQZ8+PIv2ij3zc5T6Yo1rBABPnT7qNNU7/2Bh23RmxoGIvn
L+lXMNADvY1NgN/4BCTIvkkKrMhD3+Sj72G0kxN0m/rGzVGUHc857CdP1aNPOVUCsxw7wRTHh/U3
ybjiGvToSx/6j75gKxBGXxg/WmQgwdV8yt7xzDIZ/QJLsDffxmzjp19WffQb443/J/1GD1neD9dh
7dLlAgWK8bJPbNYN0uV4AP3zXOg1QRbFnMrEtRYUWJkn9pgMT9mp5mu//fYr61Vwt779sVw0xh9t
u51Qlg59LBNwn14GGdngZRZ0+qTzNQYZC1nVXMUarAfAnvYMNnwX9lt9ftLf5gSv4Hcf//crXXS1
6w6rwz8gn/GeDRKbRbLIyGfy2nr03D71JinWJj4nr+iefni22ya74EAWkgceQ6CdQXxKRjrvurAT
2+1O+39zbwOPH0TPkMWCYvTNcgKAApjsdeMhT+HQrwhwkpU2w2DcT1b2u37S4zL6wp4gU9jhg/o2
9/ggSyIwKgIZABwVqay3LhGgcOzmesA5x6udtUfoUhDOKeoLAlJWsu7cAhJCmwJVn/IUDKLc/N+v
UNLhGPWrM8pxBiolp2iP0zVOQTdDQ0G7j+yNfruflKp+VtJp0Kdxwd5vNMsCCCcAPYz8N7/5zeVb
cM7zU9weJLjpeSZh4IyDTdS1s8xh5GAw6jwEXnBR9oS5DoccbV2FMSIrgZEooMz47afM8ZQdW86g
fgXz7Cr3C57hP042R4RT7oHPAobBlzU9+JHT8t73vrfwDN6HDYN8UoOrbj9+Wx+yaNCvCJLjqWka
+9FXficCHByBGuuQjA751G+NjYqY9RJyjiNlrVtb/TZurH/9kzWTFPKMzJJhLBPMc5lsepAbnAWZ
TpzJQXplUL/oCtphI9hFzveTW9EWDPQJVw6i/6OdqFN/kz3qwoI+oescIzsdn1Wx4WBTAx/YgIss
n+iPnhMAtHFjPF7QEs4iOYg+mMR40W/OPftp0HjpYGMMPRr9jfsNK20p5lsAw9yMOt/o9lHME5rM
bz9dbnz6Q3dcVy6eoz90J53oFnjFnMqEiflgFwjyCeDCy/Mc6Wa3T8uCWo7OseYPP/zwcsuq+ZD9
6jEdbjUW7MFno87NHEG66qTISpOhCjv2db1+loOna+N6vCCYpO1+/L9ceW3NCN7QP2wwwWd2mI10
2X/O189rHRd48tra9G0MZJMN3mHyWj+ugYXxsyXZX4FNFx3kMhlNhoaMhmFsKHRds9xjdBB5LAAn
IMZuJLfMGz07adGu8ZNvbNDYiG63p47sSh9zxcZers3Q7qPf//rzgTkdZJ4iE7vrmnqNdJ3PY4lA
G4GNowiK9kX5fyKwXhCwPjhXsqfsADH0u4wFRqQgoCATo5KiYhBSLIzs2EWiYCkvz3dgzPcLqjhn
p5CCsoO4nIJegR+FshaYHLUYPyPWrRholwlh55Ly7bo9WX3KipEDD+NeiQJnGXwR3GRAMvIpbjRx
lr2F0u05jCQvvPA8Lc6CawcZPsPoZwzJxDnyyCNLP9rVvuAf7Ic5fehzW4UgM4XvhQHS/f1uF3U9
d0YGo7FyfvCS22VkPRhvuzBwNtWVbJ8AACd/SURBVPdu5WXkycyx48yo0lZXMR5ZhXAROJbdgB63
vE+j4Gm3XgsuWiccNca+W3KyJAKzQCDkn3XOMbdRIKjtVtXlrH3rm6xRyHXyv18wiIEuWEQGT+q8
WCuy1GT5acualg2okGsy1PrplFJpyB/Ohg0R3+Q+p1CfaO9X6D4OLSzII7KIDnCsC1ttx3NMZWKh
l4x0LTlNb86qRN8y4mWxo7EtZ/1vg0iglVzneJJZ5C1drrgWzdrDS5x4+HeNV9AQXxinIHRXnVHH
yxEOfWJO6A14denirjbp4wh4CR7T54JlbQziWkELt6LhaZs081bMB/rMEzyMw3PX6F7F/NiU89Zp
do+3xdKvxsyRh+Wk80F/mld6H47Pfe5zi97XtrUQAZZ5w2wR6DEvEZxnj9jwYC+wKQVuJy0hr809
u94akFVtXbUL3rHmBZzClmvXGeX/yAL00iB3PbDr9U9OsnkEi9E1SUEjGy3sKNnX5HY/2y76gK/M
Ov3Cl39DNvULMNEJXkpI7pEfEQQTAOQX0Wn9ro0+J/k2FvrOnNOvxunuGvMmGaOf3Orqy7XqW+/G
bhxwQr+2yfh2e87Dx8d6pg9XyqcRbGTPk2t4R1IAm6VLXqnj9nLzaR5jfrpwyGOJQCCwYZigiIr5
nQisRwQIWw4Q5eCB0Xbt+q0ZCoXjwKlQOJ2UhTYY6BwEgpnS1I6ML4qlXSgqWR2HHHLI1oBWu844
/1OiFDe6OSPaptC7inHWxTXGwxijXOxgCqL5Zny0C8fPLbaeo9RWpu260/pfsJTye+tb31rGSGl6
UC+FydCBsaAsI9L4KXFGHwVrboyZI9FvXtt0hhMYxzmuxx9/fMEERpxwfOC3ot02rnGtbwYcB4aD
wqgR4AsjC7/UH7zIeBHEY+wpDBhOaNzmXQ7+7x99c6q1z1F0nSwitNXt1r8FCeNlBmF8MFyNc7kF
djI1zBW64M95fvrTnz7xbTDLpSmvX/sI4DMfa43cFYAWQFMcn7SQrda6NjiL1hkHpS0brX8OrOxa
a5WMn7RfsvxJT3pSkV9knz7JP46mIH3XJsCo40OXYIZ1KrDJOQ1HKdoIeRby0nmyKPqVjeXxBW7T
6irWveebknd0RAQZ9W1zSf+D5GW0OQl++iNDOZBwo6+6CmePnLRREoEcYwyZLoBLtygCsLIDuzJh
bKLYrLE55TmJcX1Xn6McQwObwjhgxCnvGkPMTbtNgY5wYOkNwTF4dxW8dfTRR5c+ZhmU7ep7lGN4
dEsvQMnesEml4CUvaIsAu+AN/PEk7OnmpaWlrQ4yDPth1aZB3Xpdm1trGX54SqBC2zHHsU7a7eT/
oyEQ65vcFMC1KQnTSe1K15LXAtlkVmyMsmXbNp26bvMnr+kKsmnSoi9yWXY2O0vgz7qjL2LjYNK2
+RLoRJ+1je99oz+K3/GJY2QXXvXtnLeg2xjr8kfIATqTDBM0JRfDryEXjKf9PGn91DREv+N+W0uC
r5IgyD5t2vRw10uX3OvXvrVK3pP7xuhxM7FxxyawIdXVnjXPZ+Av0W/0YVewuF+/4xxvyyJ8Ghs7
fE+3kZuLdsG7NiLe8Y53FBtj0vXRbrf+n9xr01efz9+LicAtU0wWcxxJdSIwMwQE8ig9ysOz3LqU
nc4JYsoiAiV29ziHlCxF5rdjDBtGo1tGKSVKlYLiQDAKGJWvfe1rSzuetzdqIaB92kXAiPGBBsqP
wUOZ6zMKxarvCAwK/BgLmigiio/xZGyUEdrhwYhShxJljHP8fATYujJRKJIw7KLv+hv9+g7jIb67
rtEvA1/w7eUvf3nJhmGIC6J5uxxHWWEcmTPKU3u+Xeu3vjhClD9s0Oe7pkPfDLcoMkIUdc2dtmQh
mH/XwUQbShhojinOw9C1Pv4XuHNbGrr22GOPrQHkckHHHwZl7IRT9vpnAHQF6fSLn8y5XVTzAqNB
hYEjizFuKbY7ysFiaLZLjCGOw7RrruCBt2SGvuIVryhOpXlxm7YHHMtoqjGO9vI7EWgjgL/wWayx
9vl+/1tfsmwFbPAt+UAmais+/a5Vv6vYHPGQd86BtWxjxy2BnCmygVwkRzlJZKbj+rWG9RnFtf7v
WjtRJ77JYY6j28r0a41rz9rmJA0r+oFd15g8w8yt+daiZw65fQ1NPgJh5A05B8uQd5xADqG1TNfR
IxxcOkaGorrkIBzISetfkNQYOGHGQVegiw6hEwUHa/rIjniGruPaJEdrDIeN23n00eV0n1tCBYe0
1VXQrJ5xkpkyK8Ih27Rp01b9JqBJX9tYIyvh4UOvGIsggvmVGaageRjd9djruuYeHfDWJtkuCBh6
W/t0GjpC58AJPY67nvOLX/zvUQ82Y8y7+Ykxc7I909h6Ma9dfBU8q89plOCnaKsedxzzrZ7xyqQ6
7LDDygvYrDP6yqM3rEe8qpgbuh2exhZ865z/jdM6VawJH+PSh4Lv8Txa1IeRQueyKTx3UNv+r9uG
OX2JZ12rXXirG22XhtbJn8Aghut/n0HBCjjBkG1kg0OGGVs25iPa6vddryF1zKuNbPLGZrz/BZK8
wE+GlTUT8pp8ctyzocnAsJnwA7qjaGOU4jmb7nKwjqxFm09osNnaZSe32+yS1+jAg+w+xV0akX3u
XMhrfIdvg+9CFvAJom9y96CDDiqBMDyrjo+1IwBKhrEL+S/GABOyRB36gl2H56P4zTaPY77VDRqi
3ijfcHryk59c1rV50M7m3h0t+IJ+GdSmsbPXPcrh0EMPLRs1sCQDYVWPwcZ0PbdoIxsEoLXBRqWz
XKO065aDrT/4o1+90Km+1TOu8Ml8wziyrsm7kMd4B5+SOWQ83iUHzTEfM3gVKcP4M8530cg2ivWp
7ZhLcg59cW1ryPnvAiGQzwBcoMlKUlceAcJZAJDTRuDZCeMEvPjFL97qyFG0hKOAGGOcIcHA9iYz
u8IR2KB0BG4obcLejibB6vlthD0Dx06UnR7lwAMPLDvaflNkBG8IasZoe1eSQvCJ+vpQOKmMAw4i
B5UyczustihWCoOytoMUu2AUjkAf5cugZjQxwmQ6GB/nSeDKjrpdR7RFEEqgSUYXBYJGY1TgR2Gh
HT5dhcLVdyh1Y2AEohk+2oCFepHVx4iDKQdA8M/cwNPcKZw+DlM4BdozNs4z2swp2tGqLufTXPpt
fK7TNmWILk6TMcJMYMxYw5CimBlDAreUMeNB+xws9Bg/uo0DtrDnZIURh0dqBd6FkWOuFZRlfOmT
IcRYdcxuM1r1weFmwMFrU89pjezUfu06jk6GKYMPVnAx9/riPMftlHi+djT1x6FioDC0/Q+vWBsy
MPE2mvTBAHNLlt1d85MlERgFAeufjCATojBIyYDYYMFf5Bse5AgKxlirHtRvrXnGmzVsnZBHPgrn
QFshZx3TX2SzaSvO64MM4RRwpshza9F6JlcEaugNATHyxTd5y5EgG8lq9YNG15B3EWTSd7+y1Mve
8Kwx+sK4jUV/sTb7Xee4MZDdgpFuwSVXrVPyzO2M6CSH3CppvSvoJQ/oMniQa2Sktc5xcl7AkOOs
bRtcb3zjG4vMoHdkJ5IlbjVz3gsYZBlzpshYchvGMODYac9miHHSLWQYGar4nxyBLR0bQYFycsgf
Mt11ZDo5dMQRR5TfngcoGKlfc08PkqfxXDl8Be/IGkEvvX3SSScV3hH8swlF7huXfgR9OWd4ZK+9
9irHkad9c4/nzD1+Cn3nPL4yB3hRUS9++9+jLfATeUzeeq6t88Zg/ukvdAVecKWT8Aja3CJLFqOP
Pjq6l+WnLr50i5k5CHkPX7qA3kA3WsPuINfNhTGEo4i+SQqehLn1EIVuoddgHmsEFlt6wQr0+7Bn
rBnBVbjsu+++P2Bb0Cu1PsU3cJDZiX9tHuJLYyMjzDeex+ex6akNOOmXrQET+MDZmogiKEGn4S/r
QGaitalt+tcmHPuJrSCryTyvl2KO6kxTMsR8w5wtGPxTz7P6ZClbE68JRJONeCXkJmzxIz4MGwym
+ISOULSpvuv0Ze2S1/o3L8cdd9xW/heoQ6t5MndsX+ucXFC0aw0o2tUGGoYV/ZJzZDSZaRx+y1gd
xgfaF8gW8GbbBQbWvk0WOFm35CW7V0EvPHzDB+9Z736TSXha/+QV2Up+kBEveclLCjbkv37JGR/r
3x016FXYkvQdHQInAULrJuxlegmu5JgCJ+uBjoB9+ETl5JA/ZCm55fma5lm/dJUscuPy9na8AWN1
FfLUXAUd5LOx8sfoO/LfG9BhBw/jcGcTX0bQDT/qyzrn05Gr8VifIJdMwMdR8AUeq2kgS2ELSzK/
luPmnf7TNv6UpawvY0UTXoQzXeu879e85jVFBpEz5pDcRqN+nv/855c5RTs68LF1o+jbpy7odZ2C
L9rnyTaY6pvP4uMafIIPzCXdlmVxEdi256gdfMABByzuCJLyRGDGCFD0hLPdfL8pcP9TAJQER5RQ
pAQZpYQvwe1lDhysUHaEPYXsetcQ0BQjIU4BEf6UNOUkK8puNgEciowCjeCRtigqgSk0MRAockYo
oe8Yp0sQiqKgZAhrhimBrl8KhXLXryAVg5jRjX5KJBSWMRD4lCqD3LgpAgax9hhLFBZlyhB/0Yte
VAwVxpVbuo7uORjwUrTBmaJc9AEbihAWDAm3DnMSGTeKsVNSjHS0MuAF7wThZG9o37UMagqaEhSs
DINNG/BUh6I0PuMKxa9NY2EUoBc2jFJYOM5o0BZDQ+CAouTAOm+uGWMcL7jAAvaMHufNhWvCuWOQ
+sga8HHc3B9zzDEFS3MWt/+aV3S3C0OCQ+d6/MiJdR3DwnGYcojxjTHK7oAXPoW5efSNF9RtFwYN
rPEh49tcK66HIV5yvb44X+aLI6p/fAM/xpnrOUuCLviSM60e3ucgyTA0V3bFOXjDjOA2nfn/+kMA
f+E7jhDe9AkD3LojM6wLMlIdMolcJk9kJeNDMs96jowC8sX6UAevW5P4UZCAbNKu9qxR68JaY+CT
C9aYdcTRIgfIL+vbOiEjBBOsEbRom8HMiWHYq+ccmU5uaNfaJtO1Z23WgYv2bBuDOtYZWe7WfoGd
2gmur7E+9WOcZJgPHRQynrxyGxhM6QyBec9HJBcVYzYGmMKZjNMe+UmmkrlksPVv7NolT82Htl1H
T6CVw+YFTORUOEHwgy/Za44FV+DOcSNDYKUf4yAXzYs+4EWehNNVj7nrt/7QBQf9kGvmDV1oNy/6
FnQQLKZX6dF99tmnBJjIPwX2+MT4tIePyLbQ5ZxU44YfO8At266lU+AmQGdMeBqf0Zs2TRS65Nhj
jy36BX+bK9jSCXCCGxzQTTeaD/2Sr/gdXvQCulyPVm3oG1YcfzxKPzjm4ze6tGGurBOBEoFafWuH
vg8bA06OGRN+NgY82aWzyqD6/MHz5h29Agbm27wqYVtZR3StdYo/OepoNDfsGgE5t/1y6PGu8UaB
lzbhY22bZzp5c083s7msYePAdzCBqTmV5SQI4rh6MEYPOwDPo0mwQ9CDHtY2/oy2za2517bjeAu9
7CDBFDbVetB51gVMzdfRPTsQnynwgqc1AzMYwwz/svFsAuAHv9kTeMzLW9iO5kDgVn38Y+2bd+vH
fJor9gaZ77y+nBPcwQ/WLdmqnv7RgQfxCJmjXbLR/LJRrE3rlFxAH7lA/mgXrwk+6YdNXvNe8GB8
ow0P6APf7LnnniVgbN20i/5gpS+/8REc8Ki1HOvFeiAXyCcyJmSIdYjX8aqxkN3Bu/jb2rau6YuQ
YWQK2QMHOotfgM+t8f3337/YucaobesOHTAkZ+BIZpAf1pZ5g5dzdBu80UBuWK+wGKeQL+Qe+xXG
ZLe+jYkO1Lff8CXH2PpkOL8GHbvttluREcasb2sPVuiyxmFlDGQPfrJmZVfjQf3Als6y8W6uXaNt
cpz8VMgMNMJUO/gaD6ILBvrFxyEvXaNfQcqYI3iHbEMzfwBvqofn6N0YMx2Dl/5fe3eMI0mxBGCY
3cctQGgtDE6xF8DFwngmBgYO2GvgIU6BxyneURAS55g3X6OQSqXuquqdHdja/VPq6emuzMjIPyMj
MrOqq/gWvs96kQ7ysR1jSB+yHe2lm3mNpB/0kXFEpr63iWwcmdNgoI3Ggnd5+C51+t9GtPz3+vtL
5f15bwi0AfjedEWKvI8EOE4BRxAQEAQvjo9D/uNxQmySb4LJaQucNkfcPNyE1JmuWTBoGzkmH4I/
uZyu7wQHTprTNTk36V5ebSCA+fmYzS7lyPROB4HYRMSEh7MXeHwnUJsskEtfwW4Wl+qVz3FBT5Cm
tyuxBDMBzATBZ+11VlHwsHggV310Ht19Vt5mjiDprKkgJAj7KZjAIYCTK7gIIOrVDmfiyTEJsehR
xkRBPfJ7N9HQVsHdJMiEjTyBlJ54f/PNN5f66bqeUGFl4kdPE4fhTa4JgSv4TMgFOhNW+miPTQKB
TuCmt/7FzoRMPlz/+zjx8m5ST0dc1YctPVwdRD+6qtv3Jh0mMuQI4AL8tFcwx8tZZ3Wuk/7U1zbe
MBt7wIr9qH90MKk2STFh0R5JX9NLoKfHOukb99v53+MkziSBDmTrK23Hnt4W8/Qw0fBZHi91aae+
8rJAxdvEyVlLNmIi72yyK07Gltd69DkCawLGBj/Lp5jk8zFjd8Yoe+VXLDhnIc8++Wn+mx2yN2fY
jUkLJ5NgGwvsno+waOcnZpz63uYfOepQn/FjHBk/429sEpE3vsW4NBa8LDxNzk3SbSrwsRaSJugm
8+MbyVMfP6Ie/norGY8WXNrtaj3ji6xrSV7MbHzxIcajmOA7CxALPm202P3uu+8uCx6xapL28C98
s/HN/+EvLth85K/EBy868K2ScurDVHs8KMHVl3wmPytZRFi4zOJKWfyxsBBz3GIcf4y002bq68eT
bPqSniPrInDjD33obUMJY1cnahcfrC/4Y4scvpPvUpdYLkZom/KT9Dm/Tl/to4P+x5qNiP8W+U52
aJvvsbaJph6y6KAcm/COHbtw8oRfZa/ysH0vC0KxBku+eexNv2BFZ8fnShd1iEFiubisPL3FXfME
LNgoBuqjo/rorK/4aLFJ7KOXORA9fKe8vjXmyNGH9L0nKW+TQ5xiizhOmzFUl7Erlkzsdlw7Xj/2
v3HlyidtM69a2wGeOLElOmoj22JLyps3yGMBjoM62ZTNdO1he+IpfzK2ow6/5DCesTQ/I1N5/Ygl
fYxJPsV4dkw5418M1H9LW7qH2VnyajPb8MsSfpZ/mfkEG5P0i7H3x6OPxtHcB2snEWauIq/xr6/N
P8gzPmf8kMkHYm8zTnywKctHKctO9aH+N+/Sr+Nv9Bub08/09WJH7iHtql3zcf1JvpOp5qf0Itec
ytjXv+alfMm1OdX0FznaJ4a5upR98CnXEjvFazYA+Q962SCyDuCvceJ/+FNjgC2OTXlnb/wCxvwE
HuKbEztskJ/AgQ74qBOH8WHGBb/O/ykj/yTjnz7GonI4qMcc2pjlX/zqyP/iopPkNrR8p4+wuDfp
Z7qKHd7pqk3YsyH2YyPQmsyLPvqb7/bCfPoHHyzo6UUWXcnCmH3xR+xBfHMSh97KsRf9YvNPGWOc
PWDAbtVjg9ZFCmThyFb0Bxsd/80H4eA7+quLjWonVl761Ka3xDdP//KbuPNVTipq36vHq+XVwVeL
MexMPrrRASufMcBJG8SMWXs4zl7MV+iob20Is/exH20VG/TnrCnu7cfyvz8EXjwa9QODKUUgAtcJ
cMyCrntHmfhxfBynCanJKSfJaQumArJNJe8TbNZSBVuBwrhTltPlpDl7wc2ikrxx9iZRNlwEnvmO
TpyyBRt9ZsK0rEsejtzkiTOXX10Cm8AkQJJHVxtCArpNRIFJ0BE8LRIFR/nI024bT+qbRfVsLtKF
HPkFMvnUM+VHN4FL+0ziJ2iZRDmTJxiqa9qpjHonCZgClkBkYjfB17vgtyw3ZbyTIbibOJkoSHjb
4BPw9AnG9LUIEOwtfibImSjOVR2CqDNp+koAppPg7IzfTDz0p7bpS/XgRr5JmwkH+eRoNx6jtz6S
LEC0c53YgEUk/to05Saf7/S1CZLJiYUT/hLZ/tevFiLX7NME26aCd7KX8pXHxqIfDxODdd+qZ/pL
f7Al+iz7i0065lWKwFECfIrxY3I9trm0z7G7eSfXcZ8nn/+Nab6HbfJR/OuyDDs39saXGW8jy/uM
I8ct+ibxXTaRvEzoJYsf+Yx3/pXNGzvqtegla3STny+wMKGfcluJr/npp58uPtO9acWdpaxlWbq5
IuKHH364+DpXML558+ayyOSDjFE+Xyzg07BZy+J78HdVgLilbdpFV2Nafu3hc2Yhb2OFLG236YEX
33ht7A8XPlhsUZ++wkF5C2I2MHqKt3zvWs9lu6/9bzHvyg59PFf3iIWzkMfKpiI/zc9rHz2u1UNH
8RQX/akNWPL5ZM9VR8rKyy6wsVG39Mv8Kj7qZN90nOPaoCydbCqKe+yVzuzIYs7/8iv/6jHuYCzO
aYsFKdnKj7+e8uYgYok+k/SpvFOGXpIxoh7zB2lYkKMv9Y8yEy8vmQ780S7xBnsyR+4UnXHpe3Yk
jsxLG9XHBq7Z08hgM+YWxjGuOLAh/aqf2JXFMobawUbFbazop18dZ5P6Vr+Kn8qyd3MKGwbYmAuJ
r1iIwbiaU9kYUa85BZu6FntH3w/lXd+x85lPjO0t2zf+b9nPy+P+l4dd6xfzEqz16djKlGULxod5
1oyHycOvshcybKb53pyPDzWGZh7Gj+k/PlCddJaMI5vf6l3aGt3Ur5xN361+tUH0yy+/XHyPn6v7
5R2buJbMJ13Ja9PT//T+9ddfL36GrnwX+3r1ONbZk7ZNW0ceXdk2f238qsuc1clu43zyk299w1b5
MRtB2sO++XdljL110vZZD4h5bNy8Xjl+TxxTN934cFyNXeP1KUm97Ip/o7M26m9681f8oz7GRp10
Wa6nlnXrO+WMcbJwIouO+HpN/Jl+Z0su+pB32ZaxBXZgbkzm2k7Zk/7yoiubmE1h60l95Bj/Ib5J
6pt4qq1k639tnPXixF/toZcYOvNzMnyvv8c/WRvw5/QfO1CP/uGj2Icyxgf/pp/VgeXafsgvnZNA
G4Dn7Le0/ocJmNibPJogCgScoxdHytFy5gIdx3xtorNWV7DwItdERIDifMmeQDNl1MM5X0vycuAT
fNZ5HJtJzBwjS+AxqZE49mmT9gigI3eCw5Sli7rIEIR9prczTOt2Txun7PpdHV7SVhvX5eg0ei3/
X+dbf546TCKlmYyMDtMm7XDsGjeTfO0aZlOWPN+bTEx/6lPH6ahuEy3HTIzYi++8rqXlxGJ9nJ63
ysk7TG7Jp9NS77V8i56tNOy3dJjyk3d0ms9zvPcI3ENgz6cckcUGx/7Ju2XHyzzX5F4bR+SNH1GG
LzWW5V3a/l471r50XT//bUPPjcFN2H/++eebi0ll+frZAOSjXEHnCgUnIfjD2Vy51qZl3fS2qCFD
rOPH1n4ST/noKEZMbCR7nXcp2//K8T/iEI7qoBuZ6hRnrvFcy9n6TL5FHv88m2nkY0FfPpr/t9lz
rX1r2dOXOGoz/07vayzVo13X0tglefJdS8u4II+8+sM8Qn10xtgx39Pfi+yl/ZE95ckwh/HZHGba
vMw/eb1fS/Lu9e21cr7bi2fLctOO0W3el3mu/a8O9jN2a6MGL+WHIV76jo05Nkmb9SubVG76dupW
Hn/lHVvKVpY9jew5NrI/hve9+cQRBliPXW+NH3m27Mnx6Tf16jvjXt/qq5nLjm0sddtrx3JsLsvN
/06aOAFjDvnjjz9efLCxdi2tNwBdOecqSvryM2x05ulLW13Lkn/snm2zv2vjVD4v/k/d7Fh+srfk
Y6Yc+zYGtGf0wmvsfk/OWu8jn0dnPMU3emsbvfXjzL+39J96yNKWsQV9ScbovbQZZfZsbLiM/OX7
yJzvht+sDcZHLOskT53yeC37f92fU7f3dSJT/ZNnfdzn5RihG/tR59q3XSvbd+ci8LSt+HO1NW0j
8NYEJiAunTJhNoLmrPf62FZlEwRMuE3at8o6tje5WAeBrbonSAqQ0rJu7dlK8irv5QyUQLIsvyw7
bVx+d+v/I228Vfbo91PHrbOu2nTrmDocdwbtVtJeduK1TuoW2L2emujxnGnP1p6z7mRHYIvAPT5l
S84cOzKW1Hk0jX7OoG+lybeVZ3nMJNwCx8Sfzq4IcP8nY/X169eXRdcy/5H/+W6LJXHglg9fy6G3
Ml63Ell0vFc2eeRrIz+7ji0Wlu8iYebqinWbfb+80mV9/Fbd05dix1rndRky9/zrEZskdzjfmptY
wG6lKa8+V3VLt9o8ebfkve2xo+19W/nKqQOPa0z2bFrb2cXSNpa6KM82yV7z8/nWnGAp40P+f8/e
72k7nnvy7rEnfXd0XrZX77IdNmv4bP6AP7Ox5BcirgB2v1RXeN3a/FvKmf/J8eKr2eHazibf+l37
jtiffF7X/O5a5vIzPfC+5oO02+u50ugs1q7n5Uf5jG5kSdpya5xP3sm3/Lz+X/0jc31s/Vm+IzGV
/Vkr8jVb7Zs+Wdez/HxUP7odsZ+l7P4/D4FPOZVSBCKwT+CW0731/b7Ev3M8tfzRetb53kW970LG
Wq8+RyACEYjA3wTm52duYeAKdAsA97BzHzk/efPzsHsWk6Q6sz8LlOf04U+R/ZSye7ZzS/at7/fk
zfGnlh85974/td6nlr9X3w8xfww/xF69v002//yUln92BRyfbTPQAxds4Lkn52y435K+tiX+er6b
91tln/r928p/23JP1Vf5f7Pud6H/PTI+prbew6W89xNoA/B+ZpWIQAQiEIEIRCACz07APdrcO8rP
Vl3pYBHpXkDOzM8DBfaU8HMsPx2bK0lsKlqUvqur6vbq73gEIhCBj4EA3+oBab///vvF57pCzU/I
/QTYw0U8uI4P30o2Ef20de2v38UvSLbq7VgEIvDxEPh0zgJ/PE2upRGIQAQiEIEIROD9JmAB6L5M
btJuQejsv58peUiBp8V7QqGNwFvJT8/cXNyDCCxK3cvH4tKN7z0t02LUTdu9ShGIQAQi8DQCNvv+
eHwABB/rIUh8thMtrvzzZOFXjw+nuJVc6ed+nK4edM9Wt32QXFHo6ceu+PagJrffuecnybfq6/sI
RODjJfCfx7MTb77//vuPl0Atj0AEIhCBCEQgAu8ZAYtHCz1XldgMdOWITbtvv/32k6+//vryU7Kt
k7hubu/nwp56axGpvPvOuueQxamnwEqehl6KQAQiEIGnEXCCxi0ZPBTDyRYnVzx0yeafp69v3a7B
5qEnTv/222+XDUT+2n253V/SU3ZtKooJnkT9nPfXexqBSkcgAmcg8OLxTPKDR0aXIhCBCEQgAhGI
QATeHwKuCvHzsb/++utyTykLwi+++OKyMLQY3EruQaXsn3/+eVmMzmahzcS5r9Rnn332yVdffbUl
pmMRiEAEInCQgM0/D/ywaWdD0BV7n3/++ebDk4i2Yaichzzx0eOv5xh/z19/+eWXXQF4sC/KFoEI
XCfQBuB1Ln0bgQhEIAIRiEAE/nUCFoPzsghcLgz3lLPRp+ytdK+8W3L6PgIRiEAE/iaw9Lv89d7J
muHGVyt7K+Wvb5Hp+whE4B4CPQTkHlrljUAEIhCBCEQgAv8gAYu+owvItVr3bBauy/Y5AhGIQATu
J/C2fpefd9VgKQIRiMBzEni5dWb4OStOdgQiEIEIRCACEYhABCIQgQhEIAIRiEAEIvD8BNoAfH7G
1RCBCEQgAhGIQAQiEIEIRCACEYhABCIQgX+NwMu3/VnJv6ZxFUcgAhGIQAQiEIEIRCACEYhABCIQ
gQhEIAKHCbw8nLOMEYhABCIQgQhEIAIRiEAEIhCBCEQgAhGIwOkI9BPg03VZCkcgAhGIQAQiEIEI
RCACEYhABCIQgQhE4DiBrgA8zqqcEYhABCIQgQhEIAIRiEAEIhCBCEQgAhE4HYHHJ5W3B3i6Xkvh
CEQgAhGIQAQiEIEIRCACEYhABCIQgQgcJNBDQA6CKlsEIhCBCEQgAhGIQAQiEIEIRCACEYhABM5I
oMv/zthr6RyBCEQgAhGIQAQiEIEIRCACEYhABCIQgYME2gA8CKpsEYhABCIQgQhEIAIRiEAEIhCB
CEQgAhE4I4E2AM/Ya+kcgQhEIAIRiEAEIhCBCEQgAhGIQAQiEIGDBNoAPAiqbBGIQAQiEIEIRCAC
EYhABCIQgQhEIAIROCOBlw8PD2fUO50jEIEIRCACEYhABCIQgQhEIAIRiEAEIhCBAwTaADwAqSwR
iEAEIhCBCEQgAhGIQAQiEIEIRCACETgrgZcvXrw4q+7pHYEIRCACEYhABCIQgQhEIAIRiEAEIhCB
COwQ6B6AO4A6HIEIRCACEYhABCIQgQhEIAIRiEAEIhCBMxPoJ8Bn7r10j0AEIhCBCEQgAhGIQAQi
EIEIRCACEYjADoE2AHcAdTgCEYhABCIQgQhEIAIRiEAEIhCBCEQgAmcm0D0Az9x76R6BCEQgAhGI
QAQiEIEIRCACEYhABCIQgR0CbQDuAOpwBCIQgQhEIAIRiEAEIhCBCEQgAhGIQATOTKCHgJy599I9
AhGIQAQiEIEIRCACEYhABCIQgQhEIAI7BNoA3AHU4QhEIAIRiEAEIhCBCEQgAhGIQAQiEIEInJlA
G4Bn7r10j0AEIhCBCEQgAhGIQAQiEIEIRCACEYjADoE2AHcAdTgCEYhABCIQgQhEIAIRiEAEIhCB
CEQgAmcm0AbgmXsv3SMQgQhEIAIRiEAEIhCBCEQgAhGIQAQisEOgpwDvAOpwBCIQgQhEIAIRiEAE
IhCBCEQgAhGIQATOTKArAM/ce+kegQhEIAIRiEAEIhCBCEQgAhGIQAQiEIEdAi8fHh52snQ4AhGI
QAQiEIEIRCACEYhABCIQgQhEIAIROCuBrgA8a8+ldwQiEIEIRCACEYhABCIQgQhEIAIRiEAEDhBo
A/AApLJEIAIRiEAEIhCBCEQgAhGIQAQiEIEIROCsBNoAPGvPpXcEIhCBCEQgAhGIQAQiEIEIRCAC
EYhABA4QaAPwAKSyRCACEYhABCIQgQhEIAIRiEAEIhCBCETgrATaADxrz6V3BCIQgQhEIAIRiEAE
IhCBCEQgAhGIQAQOEGgD8ACkskQgAhGIQAQiEIEIRCACEYhABCIQgQhE4KwE2gA8a8+ldwQiEIEI
RCACEYhABCIQgQhEIAIRiEAEDhBoA/AApLJEIAIRiEAEIhCBCEQgAhGIQAQiEIEIROCsBF6+ePHi
rLqndwQiEIEIRCACEYhABCIQgQhEIAIRiEAEIrBDoCsAdwB1OAIRiEAEIhCBCEQgAhGIQAQiEIEI
RCACZybw8uHh4cz6p3sEIhCBCEQgAhGIQAQiEIEIRCACEYhABCKwQaANwA04HYpABCIQgQhEIAIR
iEAEIhCBCEQgAhGIwNkJtAF49h5M/whEIAIRiEAEIhCBCEQgAhGIQAQiEIEIbBD4P6Gc/Tp2it+z
AAAAAElFTkSuQmCC
--Apple-Mail=_4D42D4EB-0D29-444B-AA3A-7926F7CBB905--

--Apple-Mail=_E0F631DC-BFB8-4FA0-BB94-E419674A60D8--


From nobody Thu Oct 31 10:14:23 2019
Return-Path: <benjamin.beurdouche@inria.fr>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 09FFC120888 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 10:14:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.201
X-Spam-Level: ***
X-Spam-Status: No, score=3.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_SBL=10, URIBL_SBL_A=0.1] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9rypyvDJKtIW for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 10:14:21 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 367251200D7 for <mls@ietf.org>; Thu, 31 Oct 2019 10:14:20 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.68,252,1569276000"; d="scan'208";a="409834711"
Received: from aannecy-653-1-78-207.w90-41.abo.wanadoo.fr (HELO pc54.home) ([90.41.199.207]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 31 Oct 2019 18:14:19 +0100
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
From: Benjamin Beurdouche <benjamin.beurdouche@inria.fr>
In-Reply-To: <CAPOUjt7qjPTF+sS9RmgDBN9N1K-90VUMomqTRHZcpoV6e7ybMw@mail.gmail.com>
Date: Thu, 31 Oct 2019 18:14:18 +0100
Cc: ML Messaging Layer Security <mls@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <80EC298F-0E50-443D-B798-ADB880DE062A@inria.fr>
References: <CAPOUjt7zw=ULd5+RMK07T-Tif4A6ej7jBRY7M0NA=JhrwENtgw@mail.gmail.com> <24F9C4C5-EC56-4C77-8940-E2BF828F6265@inria.fr> <CAPOUjt7=a6PMVr+37J5s5reOUUzH7WanU8nBMFRxGXhavi8OGA@mail.gmail.com> <034A69CB-4C6D-4247-A04C-691A514BDD9E@inria.fr> <CAPOUjt7qjPTF+sS9RmgDBN9N1K-90VUMomqTRHZcpoV6e7ybMw@mail.gmail.com>
To: Pascal Junod <pascalj@snap.com>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/MgEp99zbcWjga2YfOXO74Xb-NFE>
Subject: Re: [MLS] [Metadata encryption]
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 17:14:23 -0000

> On Oct 31, 2019, at 4:43 PM, Pascal Junod <pascalj@snap.com> wrote:
>=20
> It does help, thank you! Still, the SenderDataAAD window could stop =
with "new field", this would decrease the number of AAD hashed bytes by =
12 and be somewhat consistent with the ContentAAD window that does not =
contain the content nonce, right ?

Stylistically, maybe we could, but I liked having the explicit nonce =
under AEAD
just in case a malicious insider wants to play with it in some fancy =
ciphersuite.
It basically doesn=E2=80=99t cost much in terms of performance but might =
help us with
unforeseen cornercases =E2=80=A6 : )

B.=


From nobody Thu Oct 31 13:43:40 2019
Return-Path: <zaumka@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B44DB12024E for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 13:43:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KPjNuXcremte for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 13:43:35 -0700 (PDT)
Received: from mail-il1-x130.google.com (mail-il1-x130.google.com [IPv6:2607:f8b0:4864:20::130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 84B3512004D for <mls@ietf.org>; Thu, 31 Oct 2019 13:43:35 -0700 (PDT)
Received: by mail-il1-x130.google.com with SMTP id z10so6668908ilo.8 for <mls@ietf.org>; Thu, 31 Oct 2019 13:43:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=NUOirXvKtDEripYWYhRGr8i6QRFn8uVGpvzung9pDI8=; b=Fy3XkCdgQN6AXsoCQ4FMjAYOTp4ZfJOOEqyVWpMLrAN1L2vkOtQfm2YHUG2hiH/u2I XZQh/oWsq/qNckFZY0cVunT9SAsSrLYTrZJQlxSqIo1uwX1QoXuZ5vZE706UpI2mZlTt f5PiJXJ/Tk/1chXD8xPpPkivhO1W684y4jPmW5nWP0BBULTyV0Yn5+qEsfjjdsJYqjkw DPEFY0DaR/J5BAy+Yy3ojyO9lJuCJOwy9TRLkx/sa58aDg/UDS3/TJgoDA0gn3jJv7sI A8IiBIECfeFzaThHs72us5MiIFc0pAIuYGVs/uymePVP1vNnBlKNRbGBL89W/2tecyWd CouQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=NUOirXvKtDEripYWYhRGr8i6QRFn8uVGpvzung9pDI8=; b=MqkXzoSn55q0H32MRbEQvDYwCCyBVS+GBAPOHZ3YYc2kpFvio9JX0KZ1BYNuIp2Y7+ wCmAzVDqKQv8zvrbSbH9mf1nPhjLsx5XaQ4Z2r/biNlXvkCZe6E8+1kz2hE2NVTrUMKR 1aSmGZsqCprbAdQeyUuSRU9nBtAZfj+Py5PeOzugaP+lo2vZrSnBVJCBFo9j/VZ+hF0x 060u0FwC3QKill8wyEk0KZU1rc+7IPWbk18W3XLw6Ex0/u7+MbgFGsoGnDQFDa/BQIHq zEghIuYOKTDjFXz2jS+N5GgVK6aK6H08lmb6Xqyml/ku8TzYPnjAAFVK8xcEHNwQ8QJa 4BwA==
X-Gm-Message-State: APjAAAVRxyCK7NjN3G3JLL+CiwUNnPVfQn+fkOcfcOkdNJ1+gokoFT0k 9ZqWQ1m9p058G9ICgzmpXfau2ozBNFP76JHkaso=
X-Google-Smtp-Source: APXvYqxv7JSy5+xZMu6WL/uuE5JPLnFaG41cbOOIBfZHRGL2jtmzQwaP8/XXgaAOchKgWm0lUkqVI2GVxkSNMTRUsQA=
X-Received: by 2002:a92:cb84:: with SMTP id z4mr8975066ilo.78.1572554614537; Thu, 31 Oct 2019 13:43:34 -0700 (PDT)
MIME-Version: 1.0
References: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com> <CANYP603VS5iRtdG+n-TSsrVzynUMy4VqutSqjmWMzTYJiSaPgA@mail.gmail.com> <CANYP600nSwSAXDPu=3a-jCOxSKho5GWJ8=U79Nkh1zVFXqKH5w@mail.gmail.com>
In-Reply-To: <CANYP600nSwSAXDPu=3a-jCOxSKho5GWJ8=U79Nkh1zVFXqKH5w@mail.gmail.com>
From: Yevgeniy Dodis <zaumka@gmail.com>
Date: Thu, 31 Oct 2019 16:43:22 -0400
Message-ID: <CAMvzKshVBTHOERTPxZF++PvYiLCMrYJr3LbuXUji6rNJ2kNy_Q@mail.gmail.com>
To: Joel Alwen <jalwen@wickr.com>
Cc: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, ML Messaging Layer Security <mls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000308c1e05963ae765"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/WpUM293qRa0qEGnUyTB1Z1IqHD0>
Subject: Re: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 20:43:39 -0000

--000000000000308c1e05963ae765
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Just to add to an excellent summary by Joel, you guys are right that "full
MLS" is a combination of continuous group key agreement (CGKA) - which is
what we call TreeKEM - and purely symmetric component which we called
forward secure authenticated encryption. Indeed, CGKA defines only update
secret, which is then used to generate new epoch secret by hashing it with
the old epoch secret (more or less).

As such, it is indeed slightly harder to attack the full MLS than to attack
TreeKEM. In particular, while TreeKEM is not even forward secure in
isolation, full MLS at least achieves FS in isolation, and breaking full
MLS requires at least two compromises. Unfortunately, the good news stops
here. Every attack on TreeKEM easily extends to only marginally more
complex attack on full MLS.
- corrupt some user A
- either update A or remove A  (so we should recover in the ideal world)
- do more or less the same attack on full MLS as you did on TreeKEM

In particular, when TreeKEM would have update secret i insecure by future
corruption at epoch j >i, in full MLS we will
have epoch secret i insecure by corruption at some time k<i, recovery
before i (by update or delete), and future corruption at j>i.
So, yes, marginally more complicated, but nothing changes conceptually:
periods between k and j which should be secure
in the ideal world, are not secure.

We will definitely add a section to our paper to emphasize that,
unfortunately, all our attacks on TreeKEM easily extends to the "full MLS".

Thank you for bringing this important point.
Yevgeniy

On Thu, Oct 31, 2019, 9:54 AM Joel Alwen <jalwen@wickr.com> wrote:

> Crap. Sent that last email to soon. Here are some correction.
>
> The concern is not just Bob leaking keys that *directly* allow processing
> Alice's (and subsequent) updates as described in my previous email. As
> pointed out in the thread introducing RTreeKEM, there are only log(n) suc=
h
> keys for any given update (assuming no blanks). Unfortunately, we must al=
so
> ensure that Bob leaks no keys that allow recovering other keys (from past
> network traffic) that in turn then allow proccessing Alice's (or other)
> updates. And so on and so forth. So there are really about n/2 keys to
> worry about for any given update not just the log(n) that allow processin=
g
> the update.
>
> IMO this accentuates the gap bewteen the PCFS guarantees of MLS and RMLS
> as the former refreshes those critical keys slower than RMLS. The more
> critical keys the worse for MLS in some sense.
>
> As an aside: Its also worth noting that its probably pretty clear to the
> adversary who still has which keys in their state just by watching the
> encrypted network traffic making it easier to select the right target for
> compromising a target epoch.
>
> - Jo=C3=ABl
>
> On Thu, 31 Oct 2019, 14:12 Joel Alwen, <jalwen@wickr.com> wrote:
>
>> Hey,
>>
>> Yeah, we should have been more explicite about how this all plays out fo=
r
>> MLS. Good that you asked. :-)
>>
>> "PCFS" is exactly the term we were using to talk about how change from
>> TreeKEM -> RTreeKEM affects MLS. In a nutshell, FS for epochs after a
>> compromise is healed (with an update) takes no less but (potentially qui=
te
>> a bit) longer to kick in for "MLS" (MLS+TreeKEM) than for "RMLS"
>> (MLS+RTreeKEM).
>>
>> Here's an example scenario that highlights the difference for MLS.
>>
>> Suppose Alice's state leaked in the past and now she does an update
>> defining epoch_secret[i]. Intuitively, until the next corruption (say of
>> Bob when he's in epoch j>i) we'd like that all epoch_secrets in [i,j)
>> remain secure. (This property is what we've informally been calling PCFS=
.
>> I.e. Forward Security for epochs after a compromise.) We consider what
>> security we get for (R)MLS.
>>
>> MLS: Assume (for a moment) all handshake messages are delivered in the
>> same order to all group messages. Because TreeKEM lets Bob keep HPKE key=
s
>> around even after using them Bob could still have the keys to process
>> Alice's update. Whether this is true or not depends on who's update betw=
een
>> [i,j) and their, Alice and Bob's possitions in the ratchet tree. To
>> guarantee Bob doesn't have said keys we'd need to know e.g. Bob updated
>> between [i,j) or someone strictly closer to Bob than Alice has updated.
>> (Closer =3D shorter path ratchet tree from Bob's leaf to Charlie's leaf =
than
>> from Alice's leaf to Charlie's.)
>>
>> RMLS: Now consider RMLS when the same assumption holds. All epoch_secret=
s
>> in [i,j) remain secure even after Bob's compromise because Bob already
>> deleted any keys he had that can proccess Alice's update. In more detail=
:
>> the adversary knows init_secret[n-1] (from having corrupted Alice). So t=
o
>> get epoch_secret[n] she still needs update_secret[n] defined by Alice's
>> update. By assumption Bob processed that update himself. So RTreeKEM (bu=
t
>> not TreeKEM) guarantees Bob no longer has the keys to re-process it. Thu=
s,
>> corrupting him doesnt let the adversary recover epoch_secret[i] (nor any
>> ones after that since its always missing at least the required init_secr=
et).
>>
>>
>>
>> Now lets consider what happens if the global ordering assumption doesn't
>> hold.
>>
>> RMLS: Suppose we know only that Bob processed Alice's update. Then just
>> as above (and regardless of anything else in the execution) corrupting B=
ob
>> reveals nothing about any epoch_secrets (or init_secrets) other than the
>> ones currently held by Bob. So the Adversary breaks no other "epoch
>> security" (besides the one Bob is in at the time of corruption).
>>
>> MLS: Assuming Bob processed Alice's update doesn't help us like it did
>> for RMLS because TreeKEM doesnt require him to then delete the keys he
>> used. Instead, any keys Bob still has for processing handshake messages
>> starting just before Alice's update let the adversary recover the
>> corresponding update_secrets. So the adversary can ratchet the global ke=
y
>> schedule forward through all those epochs (startin with init_secret[n-1]
>> she had from corrupting Alice).
>>
>>
>>
>> Suppose finally, that we have neither global ordering nor did Bob ever
>> process Alice's message.
>>
>> RMLS: For RMLS, this is the only way that corrupting Bob can
>> (potentially) help the adversary break "epoch security" for any epoch
>> besides the one Bob is in during corruption. That is, it might be that B=
ob
>> still has keys to proccess Alice's update (and even some further sequenc=
es
>> of handshake messages as long as they depend directly on Alice's update.
>> This works until the Adversary hits the first handshake message in a
>> sequence for which Bob doesn't have keys to process.
>>
>> MLS: First (and as in all cases) anything the adversary could compute fo=
r
>> RMLS they can compute for MLS too. So the above "forking attack" exhists
>> for MLS. But even here RMLS can behave better than MLS because RTreeKEM
>> generally causes Bob to refresh his key material more frequently than
>> TreeKEM.
>>
>>
>> Let me know if this helps clarify stuff a bit.
>>
>> - Joel
>>
>>
>> On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, <
>> karthik.bhargavan@gmail.com> wrote:
>>
>>> I must begin by saying that I have been enjoying reading Alwen et al=E2=
=80=99s
>>> work [1] and they make some excellent points.
>>> I particularly like the idea of using a primitive like UPKE (or SkuPke
>>> as [2] calls it) to improve the forward secrecy guarantees of TreeKEM.
>>> If this can be made to work with standards-compliant EC implementations=
,
>>> we should definitely consider adding this mechanism to MLS.
>>>
>>> For my own better understanding, however, I am trying to figure out the
>>> exact forward secrecy improvement this will bring to the protocol.
>>> It is clear from [1] that the *update secret* and each *subgroup secret=
*
>>> in TreeKEM provides weak Forward Secrecy (since each update
>>> only modifies one leaf key, leaving the attacker N-1 members to
>>> compromise.)
>>>
>>> However, the public key part of TreeKEM is only part of the Forward
>>> Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=80=
=9D which
>>> changes with every update. As far as I can see, the discussion in [1]
>>> appears to ignore the =E2=80=9Cinit_secret -> update_secret ->
>>> epoch_secret+init_secret=E2=80=9D
>>> ratchet which has always been part of MLS. So I don=E2=80=99t fully see=
 how the
>>> attack of [1] works, and maybe someone can explain.
>>>
>>> One may argue that the goal of TreeKEM is to provide FS and PCS for the
>>> epoch_secret, not the update_secret.
>>> If every member of the group is honest, then A sends an update , then B
>>> accepts the update (ratcheting forward its init_secret),
>>> and then B is compromised, then how can the attacker learn the new epoc=
h
>>> secret?
>>>
>>> Perhaps we are worried about post-compromise forward secrecy (PCFS), bu=
t
>>> I don=E2=80=99t see any attack on that either.
>>> It is likely I am missing something, so do chime in and explain.
>>>
>>> Best,
>>> Karthik
>>>
>>>
>>> [1] https://eprint..iacr.org/2019/1189.pdf
>>> <https://eprint.iacr.org/2019/1189.pdf>
>>> [2] https://eprint.iacr.org/2018/954
>>> _______________________________________________
>>> MLS mailing list
>>> MLS@ietf.org
>>> https://www.ietf.org/mailman/listinfo/mls
>>>
>> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>

--000000000000308c1e05963ae765
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"auto"><div>Just to add to an excellent summary=
 by Joel, you guys are right that &quot;full MLS&quot; is a combination of =
continuous group key agreement (CGKA) - which is what we call TreeKEM - and=
 purely symmetric component which we called forward secure authenticated en=
cryption. Indeed, CGKA defines only update secret, which is then used to ge=
nerate new epoch secret by hashing it with the old epoch secret (more or le=
ss).</div><div><br></div><div>As such, it is indeed slightly harder to atta=
ck the full MLS than to attack TreeKEM. In particular, while TreeKEM is not=
 even forward secure in isolation, full MLS at least achieves FS in isolati=
on, and breaking full MLS requires at least two compromises. Unfortunately,=
 the good news stops here. Every attack on TreeKEM easily extends to only m=
arginally more complex attack on full MLS.=C2=A0</div><div>- corrupt some u=
ser A</div><div>- either update A or remove A=C2=A0

(so we should recover in the ideal world)=20

</div><div>- do more or less the same attack on full MLS as you did on Tree=
KEM</div><div><br></div><div>In particular, when TreeKEM would have update =
secret i insecure by future corruption at epoch j &gt;i, in full MLS we wil=
l=C2=A0</div><div>have epoch secret i insecure by corruption at some time k=
&lt;i, recovery before i (by update or delete), and future corruption at j&=
gt;i.</div><div>So, yes, marginally more complicated, but nothing changes c=
onceptually: periods between k and j which should be secure=C2=A0</div><div=
>in the ideal world, are not secure.</div><div><br></div><div>We will defin=
itely add a section to our paper to emphasize that, unfortunately, all our =
attacks on TreeKEM easily extends to the &quot;full MLS&quot;.</div><div><b=
r></div><div>Thank you for bringing this important point.</div><div>Yevgeni=
y</div><div><br></div><div dir=3D"auto"><div class=3D"gmail_quote" dir=3D"a=
uto"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Oct 31, 2019, 9:54 AM Jo=
el Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" target=3D"_blank">jalwen@w=
ickr.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D=
"auto">Crap. Sent that last email to soon. Here are some correction.<div di=
r=3D"auto"><br></div><div dir=3D"auto">The concern is not just Bob leaking =
keys that *directly* allow processing Alice&#39;s (and subsequent) updates =
as described in my previous email. As pointed out in the thread introducing=
 RTreeKEM, there are only log(n) such keys for any given update (assuming n=
o blanks). Unfortunately, we must also ensure that Bob leaks no keys that a=
llow recovering other keys (from past network traffic) that in turn then al=
low proccessing Alice&#39;s (or other) updates. And so on and so forth. So =
there are really about n/2 keys to worry about for any given update not jus=
t the log(n) that allow processing the update.</div><div dir=3D"auto"><br><=
/div><div dir=3D"auto">IMO this accentuates the gap bewteen the PCFS guaran=
tees of MLS and RMLS as the former refreshes those critical keys slower tha=
n RMLS. The more critical keys the worse for MLS in some sense.</div><div d=
ir=3D"auto"><br></div><div dir=3D"auto">As an aside: Its also worth noting =
that its probably pretty clear to the adversary who still has which keys in=
 their state just by watching the encrypted network traffic making it easie=
r to select the right target for compromising a target epoch.</div><div dir=
=3D"auto"><br></div><div dir=3D"auto">- Jo=C3=ABl</div></div><br><div class=
=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 31 Oct 2019,=
 14:12 Joel Alwen, &lt;<a href=3D"mailto:jalwen@wickr.com" rel=3D"noreferre=
r" target=3D"_blank">jalwen@wickr.com</a>&gt; wrote:<br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;=
padding-left:1ex"><div dir=3D"auto"><div>Hey,</div><div dir=3D"auto"><br></=
div><div dir=3D"auto">Yeah, we should have been more explicite about how th=
is all plays out for MLS. Good that you asked. :-)<br><br>&quot;PCFS&quot; =
is exactly the term we were using to talk about how change from TreeKEM -&g=
t; RTreeKEM affects MLS. In a nutshell, FS for epochs after a compromise is=
 healed (with an update) takes no less but (potentially quite a bit) longer=
 to kick in for &quot;MLS&quot; (MLS+TreeKEM) than for &quot;RMLS&quot; (ML=
S+RTreeKEM).<br><br>Here&#39;s an example scenario that highlights the diff=
erence for MLS.<br><br>Suppose Alice&#39;s state leaked in the past and now=
 she does an update defining epoch_secret[i]. Intuitively, until the next c=
orruption (say of Bob when he&#39;s in epoch j&gt;i) we&#39;d like that all=
 epoch_secrets in [i,j) remain secure. (This property is what we&#39;ve inf=
ormally been calling PCFS. I.e. Forward Security for epochs after a comprom=
ise.) We consider what security we get for (R)MLS.<br><br>MLS: Assume (for =
a moment) all handshake messages are delivered in the same order to all gro=
up messages. Because TreeKEM lets Bob keep HPKE keys around even after usin=
g them Bob could still have the keys to process Alice&#39;s update. Whether=
 this is true or not depends on who&#39;s update between [i,j) and their, A=
lice and Bob&#39;s possitions in the ratchet tree. To guarantee Bob doesn&#=
39;t have said keys we&#39;d need to know e.g. Bob updated between [i,j) or=
 someone strictly closer to Bob than Alice has updated. (Closer =3D shorter=
 path ratchet tree from Bob&#39;s leaf to Charlie&#39;s leaf than from Alic=
e&#39;s leaf to Charlie&#39;s.)=C2=A0</div><div dir=3D"auto"><br></div><div=
 dir=3D"auto">RMLS: Now consider RMLS when the same assumption holds. All e=
poch_secrets in [i,j) remain secure even after Bob&#39;s compromise because=
 Bob already deleted any keys he had that can proccess Alice&#39;s update. =
In more detail: the adversary knows init_secret[n-1] (from having corrupted=
 Alice). So to get epoch_secret[n] she still needs update_secret[n] defined=
 by Alice&#39;s update. By assumption Bob processed that update himself. So=
 RTreeKEM (but not TreeKEM) guarantees Bob no longer has the keys to re-pro=
cess it. Thus, corrupting him doesnt let the adversary recover epoch_secret=
[i] (nor any ones after that since its always missing at least the required=
 init_secret).</div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div=
><div dir=3D"auto"><br></div><div dir=3D"auto">Now lets consider what happe=
ns if the global ordering assumption doesn&#39;t hold.</div><div dir=3D"aut=
o"><br></div><div dir=3D"auto">RMLS: Suppose we know only that Bob processe=
d Alice&#39;s update. Then just as above (and regardless of anything else i=
n the execution) corrupting Bob reveals nothing about any epoch_secrets (or=
 init_secrets) other than the ones currently held by Bob. So the Adversary =
breaks no other &quot;epoch security&quot; (besides the one Bob is in at th=
e time of corruption).<br><br>MLS: Assuming Bob processed Alice&#39;s updat=
e doesn&#39;t help us like it did for RMLS because TreeKEM doesnt require h=
im to then delete the keys he used. Instead, any keys Bob still has for pro=
cessing handshake messages starting just before Alice&#39;s update let the =
adversary recover the corresponding update_secrets. So the adversary can ra=
tchet the global key schedule forward through all those epochs (startin wit=
h init_secret[n-1] she had from corrupting Alice).</div><div dir=3D"auto"><=
br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=
=3D"auto">Suppose finally, that we have neither global ordering nor did Bob=
 ever process Alice&#39;s message.</div><div dir=3D"auto"><br>RMLS: For RML=
S, this is the only way that corrupting Bob can (potentially) help the adve=
rsary break &quot;epoch security&quot; for any epoch besides the one Bob is=
 in during corruption. That is, it might be that Bob still has keys to proc=
cess Alice&#39;s update (and even some further sequences of handshake messa=
ges as long as they depend directly on Alice&#39;s update. This works until=
 the Adversary hits the first handshake message in a sequence for which Bob=
 doesn&#39;t have keys to process.</div><div dir=3D"auto"><br></div><div di=
r=3D"auto">MLS: First (and as in all cases) anything the adversary could co=
mpute for RMLS they can compute for MLS too. So the above &quot;forking att=
ack&quot; exhists for MLS. But even here RMLS can behave better than MLS be=
cause RTreeKEM generally causes Bob to refresh his key material more freque=
ntly than TreeKEM.</div><div dir=3D"auto"><br></div><div dir=3D"auto"><br><=
/div><div dir=3D"auto">Let me know if this helps clarify stuff a bit.</div>=
<div dir=3D"auto"><br></div><div dir=3D"auto">- Joel</div><div dir=3D"auto"=
><br><br></div><div dir=3D"auto"><div class=3D"gmail_quote" dir=3D"auto"><d=
iv dir=3D"ltr" class=3D"gmail_attr">On Thu, 31 Oct 2019, 08:27 Karthikeyan =
Bhargavan, &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com" rel=3D"norefe=
rrer noreferrer" target=3D"_blank">karthik.bhargavan@gmail.com</a>&gt; wrot=
e:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex"><div style=3D"word-wrap:break-wo=
rd;line-break:after-white-space">I must begin by saying that I have been en=
joying reading Alwen et al=E2=80=99s work [1] and they make some excellent =
points.<div>I particularly like the idea of using a primitive like UPKE (or=
 SkuPke as [2] calls it) to improve the forward secrecy guarantees of TreeK=
EM.</div><div>If this can be made to work with standards-compliant EC imple=
mentations, we should definitely consider adding this mechanism to MLS.</di=
v><div><br></div><div>For my own better understanding, however, I am trying=
 to figure out the exact forward secrecy improvement this will bring to the=
 protocol.</div><div>It is clear from [1] that the *update secret* and each=
 *subgroup secret* in TreeKEM provides weak Forward Secrecy (since each upd=
ate</div><div>only modifies one leaf key, leaving the attacker N-1 members =
to compromise.)</div><div><br></div><div>However, the public key part of Tr=
eeKEM is only part of the Forward Secrecy story, we must also account for t=
he =E2=80=9Cinit_secret=E2=80=9D which</div><div>changes with every update.=
 As far as I can see, the discussion in [1] appears to ignore the =E2=80=9C=
init_secret -&gt; update_secret -&gt; epoch_secret+init_secret=E2=80=9D</di=
v><div>ratchet which has always been part of MLS. So I don=E2=80=99t fully =
see how the attack of [1] works, and maybe someone can explain.</div><div><=
br></div><div>One may argue that the goal of TreeKEM is to provide FS and P=
CS for the epoch_secret, not the update_secret.</div><div>If every member o=
f the group is honest, then A sends an update , then B accepts the update (=
ratcheting forward its init_secret),=C2=A0</div><div>and then B is compromi=
sed, then how can the attacker learn the new epoch secret?</div><div><br></=
div><div>Perhaps we are worried about post-compromise forward secrecy (PCFS=
), but I don=E2=80=99t see any attack on that either.</div><div>It is likel=
y I am missing something, so do chime in and explain.</div><div><br></div><=
div>Best,</div><div>Karthik</div><div><br></div><div><br></div><div>[1]=C2=
=A0<a href=3D"https://eprint.iacr.org/2019/1189.pdf" rel=3D"noreferrer nore=
ferrer noreferrer" target=3D"_blank">https://eprint..iacr.org/2019/1189.pdf=
</a></div><div>[2]=C2=A0<a href=3D"https://eprint.iacr.org/2018/954" rel=3D=
"noreferrer noreferrer noreferrer" target=3D"_blank">https://eprint.iacr.or=
g/2018/954</a></div></div>_______________________________________________<b=
r>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" rel=3D"noreferrer noreferrer noreferrer" ta=
rget=3D"_blank">MLS@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer noreferrer noreferrer" target=3D"_blank">https://www.ietf.org/mailm=
an/listinfo/mls</a><br>
</blockquote></div></div></div>
</blockquote></div>
_______________________________________________<br>
MLS mailing list<br>
<a href=3D"mailto:MLS@ietf.org" rel=3D"noreferrer" target=3D"_blank">MLS@ie=
tf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mls</a><br=
>
</blockquote></div></div></div>
</div>

--000000000000308c1e05963ae765--


From nobody Thu Oct 31 14:00:48 2019
Return-Path: <karthik.bhargavan@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE32D120834 for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 14:00:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level: 
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xI4LA3aIL5Bv for <mls@ietfa.amsl.com>; Thu, 31 Oct 2019 14:00:43 -0700 (PDT)
Received: from mail-wm1-x32d.google.com (mail-wm1-x32d.google.com [IPv6:2a00:1450:4864:20::32d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5064712085F for <mls@ietf.org>; Thu, 31 Oct 2019 14:00:43 -0700 (PDT)
Received: by mail-wm1-x32d.google.com with SMTP id c22so7278315wmd.1 for <mls@ietf.org>; Thu, 31 Oct 2019 14:00:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=lV6OgUvDJcNDqt0oU75k/NwyFcVwBgU4QkJabyY4Gcs=; b=LmhKIb3aQo4nKK6+Uu0gBR6EbhN6XG79sjTnqAjR0ErsrW/Squanin/8HdKfuD0so6 AzZrH1FNmzqKpF827CMbXj35GxdneOvVdeQ6nAE2R4zBFfCEd/do1lIzUpjeQAgWRJqj BVW1AQep5/7QAWj8gMLLAqM14BOz7Rg2MiZir8VbuGO9QyV5fwTQhfRErdCXJsi+UOYH UzRYN6OUjUiYGBjt/IB5At4fCrmkCe9cVYEvrY7jaBht7zA5ZeQYOrPcqYDamXEWSaVI L21hSFkLivIWNRgGx0goaF2I2Jizt4dqp2pkX+T0BFEwX2J7OwwVSOyPamajUPcM8LuV 3Dtw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=lV6OgUvDJcNDqt0oU75k/NwyFcVwBgU4QkJabyY4Gcs=; b=j3Xx6xeX5Wy0442ETQ9C6PkQwbqzCe8Qkp0kwtPX26uhpSvqQLNIyDXfNloP7Kv8Kk p2RbjS+0DyBWH6SAeiosmyiZXvRa42s5rfU87Rll5cvfUzhUYibNPMW84DbEpq1OndN0 9TSJ1zLQmNQBNF6fHuzo0ukVCwOgjwZTFP5i3ZG0mti48J+2LVrIW+SRzDuFkPID/WA8 pkrrKfIZxElld6Osp64kvYNarja4cpbXjLRrhyUOEOV9fuGE1l5K87FFEBiZ4JJkf9WS L3rXsfZK6OtQ7fGCFvBACwEldqR/PRPnOYmflzN00/QyfqJB5eRREZa2bxH5G1JnUdRo MXLg==
X-Gm-Message-State: APjAAAU+YfM74j4CDPtzOxnGDOuAPL4HubvVdO3DPwK4hOFt0QgrEWCl MOn0eUdITEKdkF9/OBBTQgY=
X-Google-Smtp-Source: APXvYqxELCnKDo5Fv5dBNghLudeBR43GtUbo3PKRVy8rd1JnpSqgLLgb897R0l5oxZ5hQSECEQR5Gg==
X-Received: by 2002:a1c:9dd3:: with SMTP id g202mr7335059wme.43.1572555641684;  Thu, 31 Oct 2019 14:00:41 -0700 (PDT)
Received: from [192.168.1.104] (host103-147-static.7-79-b.business.telecomitalia.it. [79.7.147.103]) by smtp.gmail.com with ESMTPSA id z6sm5173622wro.18.2019.10.31.14.00.40 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 31 Oct 2019 14:00:40 -0700 (PDT)
From: Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>
Message-Id: <98B1DE5E-5C9B-4FAC-A3C5-350B55299AAB@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_6457F7CC-E90D-47B8-BCF5-86BFB6F433E3"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Thu, 31 Oct 2019 22:00:17 +0100
In-Reply-To: <CAMvzKshVBTHOERTPxZF++PvYiLCMrYJr3LbuXUji6rNJ2kNy_Q@mail.gmail.com>
Cc: Joel Alwen <jalwen@wickr.com>, ML Messaging Layer Security <mls@ietf.org>
To: Yevgeniy Dodis <zaumka@gmail.com>
References: <2E73A0A5-1D4A-4E76-A2FA-AFFE51598407@gmail.com> <CANYP603VS5iRtdG+n-TSsrVzynUMy4VqutSqjmWMzTYJiSaPgA@mail.gmail.com> <CANYP600nSwSAXDPu=3a-jCOxSKho5GWJ8=U79Nkh1zVFXqKH5w@mail.gmail.com> <CAMvzKshVBTHOERTPxZF++PvYiLCMrYJr3LbuXUji6rNJ2kNy_Q@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/FpX8sZwJcGtCoGJrXYm3Yd3dquo>
Subject: Re: [MLS] UPKE and Epoch Forward Secrecy
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Oct 2019 21:00:47 -0000

--Apple-Mail=_6457F7CC-E90D-47B8-BCF5-86BFB6F433E3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Thanks Joel and Yevgeniy, this discussion is very useful, and I would =
have struggled to understand it just from the paper.

To further my understanding, am I correct in thinking that the same =
=E2=80=9Cattack=E2=80=9D works on two-party Signal conversations if one =
party only receives but does not send messages?
Suppose A and B are engaged in two-party Signal.
The attacker obtains A=E2=80=99s state and hence the current root+chain =
keys.
A sends a new flight of messages, and hence DH-ratchets the key forward.
We expect the session to be =E2=80=9Chealed=E2=80=9D because of PCS.
But until B sends a message back, the conversation is vulnerable to an =
FS attack on B.

Of course, it is much more reasonable in Signal to expect B to respond =
at some point, and much less reasonable for MLS to assume that all =
members in a 1000-member group will send updates very soon.
I am just checking if I am missing something. I find that many MLS =
intuitions are easier to understand if they have a 2-party counterpart.

Best,
Karthik

> On 31 Oct 2019, at 21:43, Yevgeniy Dodis <zaumka@gmail.com> wrote:
>=20
> Just to add to an excellent summary by Joel, you guys are right that =
"full MLS" is a combination of continuous group key agreement (CGKA) - =
which is what we call TreeKEM - and purely symmetric component which we =
called forward secure authenticated encryption. Indeed, CGKA defines =
only update secret, which is then used to generate new epoch secret by =
hashing it with the old epoch secret (more or less).
>=20
> As such, it is indeed slightly harder to attack the full MLS than to =
attack TreeKEM. In particular, while TreeKEM is not even forward secure =
in isolation, full MLS at least achieves FS in isolation, and breaking =
full MLS requires at least two compromises. Unfortunately, the good news =
stops here. Every attack on TreeKEM easily extends to only marginally =
more complex attack on full MLS.=20
> - corrupt some user A
> - either update A or remove A  (so we should recover in the ideal =
world)
> - do more or less the same attack on full MLS as you did on TreeKEM
>=20
> In particular, when TreeKEM would have update secret i insecure by =
future corruption at epoch j >i, in full MLS we will=20
> have epoch secret i insecure by corruption at some time k<i, recovery =
before i (by update or delete), and future corruption at j>i.
> So, yes, marginally more complicated, but nothing changes =
conceptually: periods between k and j which should be secure=20
> in the ideal world, are not secure.
>=20
> We will definitely add a section to our paper to emphasize that, =
unfortunately, all our attacks on TreeKEM easily extends to the "full =
MLS".
>=20
> Thank you for bringing this important point.
> Yevgeniy
>=20
> On Thu, Oct 31, 2019, 9:54 AM Joel Alwen <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
> Crap. Sent that last email to soon. Here are some correction.
>=20
> The concern is not just Bob leaking keys that *directly* allow =
processing Alice's (and subsequent) updates as described in my previous =
email. As pointed out in the thread introducing RTreeKEM, there are only =
log(n) such keys for any given update (assuming no blanks). =
Unfortunately, we must also ensure that Bob leaks no keys that allow =
recovering other keys (from past network traffic) that in turn then =
allow proccessing Alice's (or other) updates. And so on and so forth. So =
there are really about n/2 keys to worry about for any given update not =
just the log(n) that allow processing the update.
>=20
> IMO this accentuates the gap bewteen the PCFS guarantees of MLS and =
RMLS as the former refreshes those critical keys slower than RMLS. The =
more critical keys the worse for MLS in some sense.
>=20
> As an aside: Its also worth noting that its probably pretty clear to =
the adversary who still has which keys in their state just by watching =
the encrypted network traffic making it easier to select the right =
target for compromising a target epoch.
>=20
> - Jo=C3=ABl
>=20
> On Thu, 31 Oct 2019, 14:12 Joel Alwen, <jalwen@wickr.com =
<mailto:jalwen@wickr.com>> wrote:
> Hey,
>=20
> Yeah, we should have been more explicite about how this all plays out =
for MLS. Good that you asked. :-)
>=20
> "PCFS" is exactly the term we were using to talk about how change from =
TreeKEM -> RTreeKEM affects MLS. In a nutshell, FS for epochs after a =
compromise is healed (with an update) takes no less but (potentially =
quite a bit) longer to kick in for "MLS" (MLS+TreeKEM) than for "RMLS" =
(MLS+RTreeKEM).
>=20
> Here's an example scenario that highlights the difference for MLS.
>=20
> Suppose Alice's state leaked in the past and now she does an update =
defining epoch_secret[i]. Intuitively, until the next corruption (say of =
Bob when he's in epoch j>i) we'd like that all epoch_secrets in [i,j) =
remain secure. (This property is what we've informally been calling =
PCFS. I.e. Forward Security for epochs after a compromise.) We consider =
what security we get for (R)MLS.
>=20
> MLS: Assume (for a moment) all handshake messages are delivered in the =
same order to all group messages. Because TreeKEM lets Bob keep HPKE =
keys around even after using them Bob could still have the keys to =
process Alice's update. Whether this is true or not depends on who's =
update between [i,j) and their, Alice and Bob's possitions in the =
ratchet tree. To guarantee Bob doesn't have said keys we'd need to know =
e.g. Bob updated between [i,j) or someone strictly closer to Bob than =
Alice has updated. (Closer =3D shorter path ratchet tree from Bob's leaf =
to Charlie's leaf than from Alice's leaf to Charlie's.)=20
>=20
> RMLS: Now consider RMLS when the same assumption holds. All =
epoch_secrets in [i,j) remain secure even after Bob's compromise because =
Bob already deleted any keys he had that can proccess Alice's update. In =
more detail: the adversary knows init_secret[n-1] (from having corrupted =
Alice). So to get epoch_secret[n] she still needs update_secret[n] =
defined by Alice's update. By assumption Bob processed that update =
himself. So RTreeKEM (but not TreeKEM) guarantees Bob no longer has the =
keys to re-process it. Thus, corrupting him doesnt let the adversary =
recover epoch_secret[i] (nor any ones after that since its always =
missing at least the required init_secret).
>=20
>=20
>=20
> Now lets consider what happens if the global ordering assumption =
doesn't hold.
>=20
> RMLS: Suppose we know only that Bob processed Alice's update. Then =
just as above (and regardless of anything else in the execution) =
corrupting Bob reveals nothing about any epoch_secrets (or init_secrets) =
other than the ones currently held by Bob. So the Adversary breaks no =
other "epoch security" (besides the one Bob is in at the time of =
corruption).
>=20
> MLS: Assuming Bob processed Alice's update doesn't help us like it did =
for RMLS because TreeKEM doesnt require him to then delete the keys he =
used. Instead, any keys Bob still has for processing handshake messages =
starting just before Alice's update let the adversary recover the =
corresponding update_secrets. So the adversary can ratchet the global =
key schedule forward through all those epochs (startin with =
init_secret[n-1] she had from corrupting Alice).
>=20
>=20
>=20
> Suppose finally, that we have neither global ordering nor did Bob ever =
process Alice's message.
>=20
> RMLS: For RMLS, this is the only way that corrupting Bob can =
(potentially) help the adversary break "epoch security" for any epoch =
besides the one Bob is in during corruption. That is, it might be that =
Bob still has keys to proccess Alice's update (and even some further =
sequences of handshake messages as long as they depend directly on =
Alice's update. This works until the Adversary hits the first handshake =
message in a sequence for which Bob doesn't have keys to process.
>=20
> MLS: First (and as in all cases) anything the adversary could compute =
for RMLS they can compute for MLS too. So the above "forking attack" =
exhists for MLS. But even here RMLS can behave better than MLS because =
RTreeKEM generally causes Bob to refresh his key material more =
frequently than TreeKEM.
>=20
>=20
> Let me know if this helps clarify stuff a bit.
>=20
> - Joel
>=20
>=20
> On Thu, 31 Oct 2019, 08:27 Karthikeyan Bhargavan, =
<karthik.bhargavan@gmail.com <mailto:karthik.bhargavan@gmail.com>> =
wrote:
> I must begin by saying that I have been enjoying reading Alwen et =
al=E2=80=99s work [1] and they make some excellent points.
> I particularly like the idea of using a primitive like UPKE (or SkuPke =
as [2] calls it) to improve the forward secrecy guarantees of TreeKEM.
> If this can be made to work with standards-compliant EC =
implementations, we should definitely consider adding this mechanism to =
MLS.
>=20
> For my own better understanding, however, I am trying to figure out =
the exact forward secrecy improvement this will bring to the protocol.
> It is clear from [1] that the *update secret* and each *subgroup =
secret* in TreeKEM provides weak Forward Secrecy (since each update
> only modifies one leaf key, leaving the attacker N-1 members to =
compromise.)
>=20
> However, the public key part of TreeKEM is only part of the Forward =
Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=80=9D =
which
> changes with every update. As far as I can see, the discussion in [1] =
appears to ignore the =E2=80=9Cinit_secret -> update_secret -> =
epoch_secret+init_secret=E2=80=9D
> ratchet which has always been part of MLS. So I don=E2=80=99t fully =
see how the attack of [1] works, and maybe someone can explain.
>=20
> One may argue that the goal of TreeKEM is to provide FS and PCS for =
the epoch_secret, not the update_secret.
> If every member of the group is honest, then A sends an update , then =
B accepts the update (ratcheting forward its init_secret),=20
> and then B is compromised, then how can the attacker learn the new =
epoch secret?
>=20
> Perhaps we are worried about post-compromise forward secrecy (PCFS), =
but I don=E2=80=99t see any attack on that either.
> It is likely I am missing something, so do chime in and explain.
>=20
> Best,
> Karthik
>=20
>=20
> [1] https://eprint..iacr.org/2019/1189.pdf =
<https://eprint.iacr.org/2019/1189.pdf>
> [2] https://eprint.iacr.org/2018/954 =
<https://eprint.iacr.org/2018/954>________________________________________=
_______
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org <mailto:MLS@ietf.org>
> https://www.ietf.org/mailman/listinfo/mls =
<https://www.ietf.org/mailman/listinfo/mls>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls


--Apple-Mail=_6457F7CC-E90D-47B8-BCF5-86BFB6F433E3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Thanks Joel and Yevgeniy, this discussion is very useful, and =
I would have struggled to understand it just from the paper.<div =
class=3D""><br class=3D""></div><div class=3D"">To further my =
understanding, am I correct in thinking that the same =E2=80=9Cattack=E2=80=
=9D works on two-party Signal conversations if one party only receives =
but does not send messages?</div><div class=3D"">Suppose A and B are =
engaged in two-party Signal.</div><div class=3D"">The attacker obtains =
A=E2=80=99s state and hence the current root+chain keys.</div><div =
class=3D"">A sends a new flight of messages, and hence DH-ratchets the =
key forward.</div><div class=3D"">We expect the session to be =
=E2=80=9Chealed=E2=80=9D because of PCS.</div><div class=3D"">But until =
B sends a message back, the conversation is vulnerable to an FS attack =
on B.</div><div class=3D""><br class=3D""></div><div class=3D"">Of =
course, it is much more reasonable in Signal to expect B to respond at =
some point, and much less reasonable for MLS to assume that all members =
in a 1000-member group will send updates very soon.</div><div class=3D"">I=
 am just checking if I am missing something. I find that many MLS =
intuitions are easier to understand if they have a 2-party =
counterpart.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><div =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On 31 Oct 2019, at 21:43, Yevgeniy Dodis &lt;<a =
href=3D"mailto:zaumka@gmail.com" class=3D"">zaumka@gmail.com</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
dir=3D"ltr" class=3D""><div dir=3D"auto" class=3D""><div class=3D"">Just =
to add to an excellent summary by Joel, you guys are right that "full =
MLS" is a combination of continuous group key agreement (CGKA) - which =
is what we call TreeKEM - and purely symmetric component which we called =
forward secure authenticated encryption. Indeed, CGKA defines only =
update secret, which is then used to generate new epoch secret by =
hashing it with the old epoch secret (more or less).</div><div =
class=3D""><br class=3D""></div><div class=3D"">As such, it is indeed =
slightly harder to attack the full MLS than to attack TreeKEM. In =
particular, while TreeKEM is not even forward secure in isolation, full =
MLS at least achieves FS in isolation, and breaking full MLS requires at =
least two compromises. Unfortunately, the good news stops here. Every =
attack on TreeKEM easily extends to only marginally more complex attack =
on full MLS.&nbsp;</div><div class=3D"">- corrupt some user A</div><div =
class=3D"">- either update A or remove A&nbsp;

(so we should recover in the ideal world)=20

</div><div class=3D"">- do more or less the same attack on full MLS as =
you did on TreeKEM</div><div class=3D""><br class=3D""></div><div =
class=3D"">In particular, when TreeKEM would have update secret i =
insecure by future corruption at epoch j &gt;i, in full MLS we =
will&nbsp;</div><div class=3D"">have epoch secret i insecure by =
corruption at some time k&lt;i, recovery before i (by update or delete), =
and future corruption at j&gt;i.</div><div class=3D"">So, yes, =
marginally more complicated, but nothing changes conceptually: periods =
between k and j which should be secure&nbsp;</div><div class=3D"">in the =
ideal world, are not secure.</div><div class=3D""><br =
class=3D""></div><div class=3D"">We will definitely add a section to our =
paper to emphasize that, unfortunately, all our attacks on TreeKEM =
easily extends to the "full MLS".</div><div class=3D""><br =
class=3D""></div><div class=3D"">Thank you for bringing this important =
point.</div><div class=3D"">Yevgeniy</div><div class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D""><div class=3D"gmail_quote" =
dir=3D"auto"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Oct 31, 2019, =
9:54 AM Joel Alwen &lt;<a href=3D"mailto:jalwen@wickr.com" =
target=3D"_blank" class=3D"">jalwen@wickr.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto" =
class=3D"">Crap. Sent that last email to soon. Here are some =
correction.<div dir=3D"auto" class=3D""><br class=3D""></div><div =
dir=3D"auto" class=3D"">The concern is not just Bob leaking keys that =
*directly* allow processing Alice's (and subsequent) updates as =
described in my previous email. As pointed out in the thread introducing =
RTreeKEM, there are only log(n) such keys for any given update (assuming =
no blanks). Unfortunately, we must also ensure that Bob leaks no keys =
that allow recovering other keys (from past network traffic) that in =
turn then allow proccessing Alice's (or other) updates. And so on and so =
forth. So there are really about n/2 keys to worry about for any given =
update not just the log(n) that allow processing the update.</div><div =
dir=3D"auto" class=3D""><br class=3D""></div><div dir=3D"auto" =
class=3D"">IMO this accentuates the gap bewteen the PCFS guarantees of =
MLS and RMLS as the former refreshes those critical keys slower than =
RMLS. The more critical keys the worse for MLS in some sense.</div><div =
dir=3D"auto" class=3D""><br class=3D""></div><div dir=3D"auto" =
class=3D"">As an aside: Its also worth noting that its probably pretty =
clear to the adversary who still has which keys in their state just by =
watching the encrypted network traffic making it easier to select the =
right target for compromising a target epoch.</div><div dir=3D"auto" =
class=3D""><br class=3D""></div><div dir=3D"auto" class=3D"">- =
Jo=C3=ABl</div></div><br class=3D""><div class=3D"gmail_quote"><div =
dir=3D"ltr" class=3D"gmail_attr">On Thu, 31 Oct 2019, 14:12 Joel Alwen, =
&lt;<a href=3D"mailto:jalwen@wickr.com" rel=3D"noreferrer" =
target=3D"_blank" class=3D"">jalwen@wickr.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto" =
class=3D""><div class=3D"">Hey,</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">Yeah, we should have been =
more explicite about how this all plays out for MLS. Good that you =
asked. :-)<br class=3D""><br class=3D"">"PCFS" is exactly the term we =
were using to talk about how change from TreeKEM -&gt; RTreeKEM affects =
MLS. In a nutshell, FS for epochs after a compromise is healed (with an =
update) takes no less but (potentially quite a bit) longer to kick in =
for "MLS" (MLS+TreeKEM) than for "RMLS" (MLS+RTreeKEM).<br class=3D""><br =
class=3D"">Here's an example scenario that highlights the difference for =
MLS.<br class=3D""><br class=3D"">Suppose Alice's state leaked in the =
past and now she does an update defining epoch_secret[i]. Intuitively, =
until the next corruption (say of Bob when he's in epoch j&gt;i) we'd =
like that all epoch_secrets in [i,j) remain secure. (This property is =
what we've informally been calling PCFS. I.e. Forward Security for =
epochs after a compromise.) We consider what security we get for =
(R)MLS.<br class=3D""><br class=3D"">MLS: Assume (for a moment) all =
handshake messages are delivered in the same order to all group =
messages. Because TreeKEM lets Bob keep HPKE keys around even after =
using them Bob could still have the keys to process Alice's update. =
Whether this is true or not depends on who's update between [i,j) and =
their, Alice and Bob's possitions in the ratchet tree. To guarantee Bob =
doesn't have said keys we'd need to know e.g. Bob updated between [i,j) =
or someone strictly closer to Bob than Alice has updated. (Closer =3D =
shorter path ratchet tree from Bob's leaf to Charlie's leaf than from =
Alice's leaf to Charlie's.)&nbsp;</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">RMLS: Now consider RMLS =
when the same assumption holds. All epoch_secrets in [i,j) remain secure =
even after Bob's compromise because Bob already deleted any keys he had =
that can proccess Alice's update. In more detail: the adversary knows =
init_secret[n-1] (from having corrupted Alice). So to get =
epoch_secret[n] she still needs update_secret[n] defined by Alice's =
update. By assumption Bob processed that update himself. So RTreeKEM =
(but not TreeKEM) guarantees Bob no longer has the keys to re-process =
it. Thus, corrupting him doesnt let the adversary recover =
epoch_secret[i] (nor any ones after that since its always missing at =
least the required init_secret).</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D""><br class=3D""></div><div =
dir=3D"auto" class=3D""><br class=3D""></div><div dir=3D"auto" =
class=3D"">Now lets consider what happens if the global ordering =
assumption doesn't hold.</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">RMLS: Suppose we know only =
that Bob processed Alice's update. Then just as above (and regardless of =
anything else in the execution) corrupting Bob reveals nothing about any =
epoch_secrets (or init_secrets) other than the ones currently held by =
Bob. So the Adversary breaks no other "epoch security" (besides the one =
Bob is in at the time of corruption).<br class=3D""><br class=3D"">MLS: =
Assuming Bob processed Alice's update doesn't help us like it did for =
RMLS because TreeKEM doesnt require him to then delete the keys he used. =
Instead, any keys Bob still has for processing handshake messages =
starting just before Alice's update let the adversary recover the =
corresponding update_secrets. So the adversary can ratchet the global =
key schedule forward through all those epochs (startin with =
init_secret[n-1] she had from corrupting Alice).</div><div dir=3D"auto" =
class=3D""><br class=3D""></div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D""><br class=3D""></div><div =
dir=3D"auto" class=3D"">Suppose finally, that we have neither global =
ordering nor did Bob ever process Alice's message.</div><div dir=3D"auto" =
class=3D""><br class=3D"">RMLS: For RMLS, this is the only way that =
corrupting Bob can (potentially) help the adversary break "epoch =
security" for any epoch besides the one Bob is in during corruption. =
That is, it might be that Bob still has keys to proccess Alice's update =
(and even some further sequences of handshake messages as long as they =
depend directly on Alice's update. This works until the Adversary hits =
the first handshake message in a sequence for which Bob doesn't have =
keys to process.</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">MLS: First (and as in all =
cases) anything the adversary could compute for RMLS they can compute =
for MLS too. So the above "forking attack" exhists for MLS. But even =
here RMLS can behave better than MLS because RTreeKEM generally causes =
Bob to refresh his key material more frequently than TreeKEM.</div><div =
dir=3D"auto" class=3D""><br class=3D""></div><div dir=3D"auto" =
class=3D""><br class=3D""></div><div dir=3D"auto" class=3D"">Let me know =
if this helps clarify stuff a bit.</div><div dir=3D"auto" class=3D""><br =
class=3D""></div><div dir=3D"auto" class=3D"">- Joel</div><div =
dir=3D"auto" class=3D""><br class=3D""><br class=3D""></div><div =
dir=3D"auto" class=3D""><div class=3D"gmail_quote" dir=3D"auto"><div =
dir=3D"ltr" class=3D"gmail_attr">On Thu, 31 Oct 2019, 08:27 Karthikeyan =
Bhargavan, &lt;<a href=3D"mailto:karthik.bhargavan@gmail.com" =
rel=3D"noreferrer noreferrer" target=3D"_blank" =
class=3D"">karthik.bhargavan@gmail.com</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div =
style=3D"word-wrap:break-word;line-break:after-white-space" class=3D"">I =
must begin by saying that I have been enjoying reading Alwen et al=E2=80=99=
s work [1] and they make some excellent points.<div class=3D"">I =
particularly like the idea of using a primitive like UPKE (or SkuPke as =
[2] calls it) to improve the forward secrecy guarantees of =
TreeKEM.</div><div class=3D"">If this can be made to work with =
standards-compliant EC implementations, we should definitely consider =
adding this mechanism to MLS.</div><div class=3D""><br =
class=3D""></div><div class=3D"">For my own better understanding, =
however, I am trying to figure out the exact forward secrecy improvement =
this will bring to the protocol.</div><div class=3D"">It is clear from =
[1] that the *update secret* and each *subgroup secret* in TreeKEM =
provides weak Forward Secrecy (since each update</div><div class=3D"">only=
 modifies one leaf key, leaving the attacker N-1 members to =
compromise.)</div><div class=3D""><br class=3D""></div><div =
class=3D"">However, the public key part of TreeKEM is only part of the =
Forward Secrecy story, we must also account for the =E2=80=9Cinit_secret=E2=
=80=9D which</div><div class=3D"">changes with every update. As far as I =
can see, the discussion in [1] appears to ignore the =E2=80=9Cinit_secret =
-&gt; update_secret -&gt; epoch_secret+init_secret=E2=80=9D</div><div =
class=3D"">ratchet which has always been part of MLS. So I don=E2=80=99t =
fully see how the attack of [1] works, and maybe someone can =
explain.</div><div class=3D""><br class=3D""></div><div class=3D"">One =
may argue that the goal of TreeKEM is to provide FS and PCS for the =
epoch_secret, not the update_secret.</div><div class=3D"">If every =
member of the group is honest, then A sends an update , then B accepts =
the update (ratcheting forward its init_secret),&nbsp;</div><div =
class=3D"">and then B is compromised, then how can the attacker learn =
the new epoch secret?</div><div class=3D""><br class=3D""></div><div =
class=3D"">Perhaps we are worried about post-compromise forward secrecy =
(PCFS), but I don=E2=80=99t see any attack on that either.</div><div =
class=3D"">It is likely I am missing something, so do chime in and =
explain.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Best,</div><div class=3D"">Karthik</div><div class=3D""><br =
class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D"">[1]&nbsp;<a href=3D"https://eprint.iacr.org/2019/1189.pdf" =
rel=3D"noreferrer noreferrer noreferrer" target=3D"_blank" =
class=3D"">https://eprint..iacr.org/2019/1189.pdf</a></div><div =
class=3D"">[2]&nbsp;<a href=3D"https://eprint.iacr.org/2018/954" =
rel=3D"noreferrer noreferrer noreferrer" target=3D"_blank" =
class=3D"">https://eprint.iacr.org/2018/954</a></div></div>_______________=
________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" rel=3D"noreferrer noreferrer noreferrer" =
target=3D"_blank" class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer =
noreferrer noreferrer noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div></div>
</blockquote></div>
_______________________________________________<br class=3D"">
MLS mailing list<br class=3D"">
<a href=3D"mailto:MLS@ietf.org" rel=3D"noreferrer" target=3D"_blank" =
class=3D"">MLS@ietf.org</a><br class=3D"">
<a href=3D"https://www.ietf.org/mailman/listinfo/mls" rel=3D"noreferrer =
noreferrer" target=3D"_blank" =
class=3D"">https://www.ietf.org/mailman/listinfo/mls</a><br class=3D"">
</blockquote></div></div></div>
</div>
_______________________________________________<br class=3D"">MLS =
mailing list<br class=3D""><a href=3D"mailto:MLS@ietf.org" =
class=3D"">MLS@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/mls<br =
class=3D""></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_6457F7CC-E90D-47B8-BCF5-86BFB6F433E3--

