<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.30 (Ruby 2.6.10) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-opennhp-ztcpp-nhp-01" category="info" submissionType="independent" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.31.0 -->
  <front>
    <title abbrev="NHP">Network-Infrastructure Hiding Protocol</title>
    <seriesInfo name="Internet-Draft" value="draft-opennhp-ztcpp-nhp-01"/>
    <author fullname="Benfeng Chen">
      <organization>OpenNHP</organization>
      <address>
        <email>benfeng@gmail.com</email>
      </address>
    </author>
    <author fullname="Justin Posey">
      <organization>LayerV</organization>
      <address>
        <email>justin@layerv.ai</email>
      </address>
    </author>
    <date year="2026" month="October" day="09"/>
    <keyword>zero trust</keyword>
    <keyword>session layer</keyword>
    <keyword>network obfuscation</keyword>
    <keyword>SDP</keyword>
    <abstract>
      <?line 66?>

<t>The Network-Infrastructure Hiding Protocol (NHP) is a cryptography-based session-layer protocol designed to operationalize Zero Trust principles by concealing protected network resources from unauthorized entities. NHP enforces authentication-before-connect access control, rendering IP addresses, ports, and domain names invisible to unauthorized users. This document defines the protocol architecture, cryptographic framework, message formats, and workflow to enable independent implementation of NHP. It represents the third generation of network hiding technology--evolving from first-generation port knocking to second-generation Single-Packet Authorization (SPA) and now to NHP with advanced asymmetric cryptography, mutual authentication, and scalability for modern threats. This specification also provides guidance for integration with Software-Defined Perimeter (SDP), DNS, FIDO, and Zero Trust policy engines.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://OpenNHP.github.io/ietf-rfc-nhp/draft-opennhp-ztcpp-nhp.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-opennhp-ztcpp-nhp/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        ztcpp Independent Submission mailing list (<eref target="mailto:ztcpp@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/ztcpp/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/ztcpp/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/OpenNHP/ietf-rfc-nhp"/>.</t>
    </note>
  </front>
  <middle>
    <?line 70?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Since its inception in the 1970s, the TCP/IP networking model has prioritized openness and interoperability, laying the foundation for the modern Internet. However, this design philosophy also exposes systems to reconnaissance and attack. As Vint Cerf, who personally designed many of these components, stated, "We didn't focus on how you could wreck this system intentionally."</t>
      <t>Today, the cyber threat landscape has been dramatically reshaped by the rise of AI-driven attacks, which bring unprecedented speed and scale to vulnerability discovery and exploitation. Automated tools continuously scan the global network space, identifying weaknesses in real-time. Large Language Models (LLMs) can now autonomously exploit one-day vulnerabilities, and AI systems can generate working exploits for published CVEs in minutes. As a result, the Internet is evolving into a "Dark Forest," where <strong>visibility equates to vulnerability</strong>. In such an environment, any exposed service becomes an immediate target.</t>
      <t>The Zero Trust model, which mandates continuous verification and eliminates implicit trust, has emerged as a modern approach to cybersecurity. Within this context, the Network-Infrastructure Hiding Protocol (NHP) offers a new architectural element: authenticated-before-connect access at the session layer.</t>
      <t>NHP builds upon foundational work in the Cloud Security Alliance's Software-Defined Perimeter (SDP) and Single-Packet Authorization (SPA) frameworks, representing the third generation of network hiding technology:</t>
      <ul spacing="normal">
        <li>
          <t><strong>First Generation - Port Knocking:</strong> Simple port sequences vulnerable to interception and replay attacks.</t>
        </li>
        <li>
          <t><strong>Second Generation - SPA:</strong> Encrypted single-packet authorization with improved security but limited scalability.</t>
        </li>
        <li>
          <t><strong>Third Generation - NHP:</strong> Advanced asymmetric cryptography, mutual authentication, Noise Protocol-based key exchange, and enterprise-grade scalability.</t>
        </li>
      </ul>
      <t>This document outlines the motivations behind NHP, its design objectives, message structures, integration options, and security considerations for adoption within Zero Trust frameworks.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

<t>The following terms are used throughout this document:</t>
      <dl>
        <dt>NHP</dt>
        <dd>
          <t>Network-Infrastructure Hiding Protocol</t>
        </dd>
        <dt>NHP-Agent</dt>
        <dd>
          <t>The client-side component that initiates NHP communication</t>
        </dd>
        <dt>NHP-Server</dt>
        <dd>
          <t>The control-plane service that validates requests and makes access decisions</t>
        </dd>
        <dt>NHP-AC</dt>
        <dd>
          <t>NHP Access Controller, the enforcement component near protected resources</t>
        </dd>
        <dt>SPA</dt>
        <dd>
          <t>Single-Packet Authorization</t>
        </dd>
        <dt>SDP</dt>
        <dd>
          <t>Software-Defined Perimeter</t>
        </dd>
        <dt>ZTA</dt>
        <dd>
          <t>Zero Trust Architecture</t>
        </dd>
        <dt>ECC</dt>
        <dd>
          <t>Elliptic Curve Cryptography</t>
        </dd>
        <dt>AEAD</dt>
        <dd>
          <t>Authenticated Encryption with Associated Data</t>
        </dd>
        <dt>ASP</dt>
        <dd>
          <t>Authorization Service Provider</t>
        </dd>
        <dt>PEP</dt>
        <dd>
          <t>Policy Enforcement Point</t>
        </dd>
        <dt>KGC</dt>
        <dd>
          <t>Key Generation Center</t>
        </dd>
      </dl>
    </section>
    <section anchor="design-objectives">
      <name>Design Objectives</name>
      <t>The NHP protocol is designed to achieve the following objectives:</t>
      <ol spacing="normal" type="1"><li>
          <t><strong>Infrastructure Invisibility:</strong> Eliminate unauthorized network visibility by enforcing authentication prior to session establishment. Protected resources remain invisible to unauthorized scanners and attackers.</t>
        </li>
        <li>
          <t><strong>Session Layer Operation:</strong> Operate at OSI Layer 5, complementing existing TCP, UDP, and QUIC <xref target="RFC9000"/> transports without requiring changes to underlying network infrastructure.</t>
        </li>
        <li>
          <t><strong>Decentralized Trust:</strong> Support decentralized trust using asymmetric cryptography and ephemeral key exchange, eliminating single points of trust failure.</t>
        </li>
        <li>
          <t><strong>Fine-Grained Access Control:</strong> Enable context-based policy enforcement across heterogeneous environments, supporting least-privilege access.</t>
        </li>
        <li>
          <t><strong>Integration Capability:</strong> Integrate with existing Zero Trust controllers, SDP gateways, identity systems (IAM), DNS infrastructure, and FIDO authentication.</t>
        </li>
        <li>
          <t><strong>Scalability:</strong> Support enterprise-scale deployments with clustered servers, distributed access controllers, and multi-tenant isolation.</t>
        </li>
        <li>
          <t><strong>AI Threat Mitigation:</strong> Reduce the attack surface against AI-driven reconnaissance and exploitation by denying visibility before authentication.</t>
        </li>
      </ol>
    </section>
    <section anchor="relationship-to-tls">
      <name>Relationship to TLS</name>
      <t>NHP and TLS (Transport Layer Security <xref target="RFC8446"/>) are complementary protocols that operate at different OSI layers and serve distinct security purposes. This section clarifies their differences and how they work together.</t>
      <section anchor="osi-layer-positioning">
        <name>OSI Layer Positioning</name>
        <artwork><![CDATA[
+-------------------+
| Application (L7)  |  HTTP, SMTP, SSH, etc.
+-------------------+
        v
+-------------------+
| Presentation (L6) |  TLS/SSL - Data encryption & integrity
+-------------------+
        v
+-------------------+
| Session (L5)      |  NHP - Authentication before connection
+-------------------+
        v
+-------------------+
| Transport (L4)    |  TCP, UDP, QUIC
+-------------------+
        v
+-------------------+
| Network (L3)      |  IP
+-------------------+
]]></artwork>
      </section>
      <section anchor="key-differences">
        <name>Key Differences</name>
        <table>
          <thead>
            <tr>
              <th align="left">Aspect</th>
              <th align="left">NHP (Layer 5)</th>
              <th align="left">TLS (Layer 6)</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Primary Purpose</strong></td>
              <td align="left">Infrastructure hiding and access control</td>
              <td align="left">Data encryption and integrity</td>
            </tr>
            <tr>
              <td align="left">
                <strong>When Authentication Occurs</strong></td>
              <td align="left">BEFORE connection establishment</td>
              <td align="left">AFTER TCP connection established</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Service Visibility</strong></td>
              <td align="left">Services are INVISIBLE to unauthorized users</td>
              <td align="left">Services are VISIBLE, communication is encrypted</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Attack Surface</strong></td>
              <td align="left">Eliminates pre-authentication attack surface</td>
              <td align="left">Protects data in transit, but service ports remain exposed</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Port Exposure</strong></td>
              <td align="left">No ports exposed until authenticated</td>
              <td align="left">Ports must be open to initiate TLS handshake</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Vulnerability Window</strong></td>
              <td align="left">None--no connection without authentication</td>
              <td align="left">TLS handshake vulnerabilities can be exploited</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="the-pre-authentication-problem">
        <name>The Pre-Authentication Problem</name>
        <t>TLS provides excellent protection for data in transit, but it has a fundamental limitation: <strong>the service must be reachable to initiate the TLS handshake</strong>. This creates a pre-authentication attack window:</t>
        <artwork><![CDATA[
Traditional TLS Flow:

Attacker    ------>  Open Port 443  ------>  TLS Handshake  ------>  Authentication
                         ^
                    Service is VISIBLE
                    Port scan succeeds
                    Pre-auth exploits possible
]]></artwork>
        <artwork><![CDATA[
NHP + TLS Flow:

Attacker    ------>  No Open Ports  ------>  BLOCKED (Service Invisible)
                         ^
                    Cannot discover service
                    Port scan fails

Authorized  ------>  NHP Knock  ------>  Port Opens  ------>  TLS  ------>  Application
User                     ^                    ^
                    Authenticated         Encrypted
                    BEFORE connect        data transfer
]]></artwork>
      </section>
      <section anchor="complementary-security-model">
        <name>Complementary Security Model</name>
        <t>NHP and TLS are designed to work together, not replace each other:</t>
        <ol spacing="normal" type="1"><li>
            <t><strong>NHP provides:</strong> Authentication-before-connect, infrastructure invisibility, access control</t>
          </li>
          <li>
            <t><strong>TLS provides:</strong> Data encryption, integrity verification, server authentication</t>
          </li>
        </ol>
        <t>A complete Zero Trust deployment <bcp14>SHOULD</bcp14> use both:</t>
        <ul spacing="normal">
          <li>
            <t><strong>NHP</strong> ensures only authorized users can discover and reach the service</t>
          </li>
          <li>
            <t><strong>TLS</strong> encrypts all data exchanged after access is granted</t>
          </li>
        </ul>
      </section>
      <section anchor="vulnerabilities-addressed-by-nhp-but-not-tls">
        <name>Vulnerabilities Addressed by NHP but Not TLS</name>
        <table>
          <thead>
            <tr>
              <th align="left">Vulnerability Type</th>
              <th align="left">TLS Protection</th>
              <th align="left">NHP Protection</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">Port scanning and service discovery</td>
              <td align="left">No: None</td>
              <td align="left">Yes: Service invisible</td>
            </tr>
            <tr>
              <td align="left">Pre-authentication exploits (e.g., Heartbleed)</td>
              <td align="left">No: Vulnerable</td>
              <td align="left">Yes: No connection possible</td>
            </tr>
            <tr>
              <td align="left">TLS implementation bugs before handshake</td>
              <td align="left">No: Vulnerable</td>
              <td align="left">Yes: No handshake initiated</td>
            </tr>
            <tr>
              <td align="left">DDoS attacks on exposed services</td>
              <td align="left">No: Service reachable</td>
              <td align="left">Yes: Service hidden</td>
            </tr>
            <tr>
              <td align="left">Credential stuffing on login pages</td>
              <td align="left">No: Page accessible</td>
              <td align="left">Yes: Page invisible</td>
            </tr>
            <tr>
              <td align="left">Zero-day exploits before authentication</td>
              <td align="left">No: Service exposed</td>
              <td align="left">Yes: Service protected</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="why-both-are-needed">
        <name>Why Both Are Needed</name>
        <t>NHP alone does not encrypt application data--it only controls access. TLS alone does not hide services--it only encrypts traffic. Together, they provide defense in depth:</t>
        <ul spacing="normal">
          <li>
            <t><strong>Without NHP:</strong> Attackers can scan, probe, and exploit services before any authentication occurs</t>
          </li>
          <li>
            <t><strong>Without TLS:</strong> Authorized traffic would be transmitted in plaintext after NHP grants access</t>
          </li>
          <li>
            <t><strong>With Both:</strong> Services are invisible to attackers, and all authorized traffic is encrypted</t>
          </li>
        </ul>
        <t>This layered approach aligns with Zero Trust principles: never trust, always verify, and minimize attack surface at every layer.</t>
      </section>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>NHP is designed to mitigate the following threat categories:</t>
      <section anchor="reconnaissance-and-scanning">
        <name>Reconnaissance and Scanning</name>
        <t>Automated scanning tools and AI-driven reconnaissance continuously probe Internet-facing services. NHP eliminates the ability to discover protected resources by requiring cryptographic authentication before any network visibility is granted.</t>
      </section>
      <section anchor="pre-authentication-exploits">
        <name>Pre-Authentication Exploits</name>
        <t>Many vulnerabilities can be exploited before authentication occurs. By enforcing authentication-before-connect, NHP prevents attackers from reaching vulnerable services.</t>
      </section>
      <section anchor="ddos-attacks">
        <name>DDoS Attacks</name>
        <t>NHP reduces DDoS attack surface by hiding service endpoints. Attackers cannot target what they cannot discover.</t>
      </section>
      <section anchor="credential-theft-and-replay">
        <name>Credential Theft and Replay</name>
        <t>NHP uses ephemeral keys and timestamp-based nonces to prevent credential replay attacks. Each session requires fresh cryptographic material.</t>
      </section>
      <section anchor="man-in-the-middle-attacks">
        <name>Man-in-the-Middle Attacks</name>
        <t>Mutual authentication using asymmetric cryptography ensures both parties verify each other's identity before establishing communication.</t>
      </section>
    </section>
    <section anchor="architectural-overview">
      <name>Architectural Overview</name>
      <t>NHP operates as a distributed session-layer protocol that enforces authentication-before-connect access between clients and protected resources.</t>
      <section anchor="core-components">
        <name>Core Components</name>
        <section anchor="nhp-agent">
          <name>NHP-Agent</name>
          <t>The NHP-Agent is a client-side process, SDK, or embedded module that initiates communication with the protected network. Its responsibilities include:</t>
          <ul spacing="normal">
            <li>
              <t>Generating and sending NHP-KNK (Knock) messages to the NHP-Server</t>
            </li>
            <li>
              <t>Performing cryptographic key exchange using Noise Protocol handshakes</t>
            </li>
            <li>
              <t>Managing client identity credentials and device attestation</t>
            </li>
            <li>
              <t>Handling session lifecycle including keepalives and re-authentication</t>
            </li>
          </ul>
        </section>
        <section anchor="nhp-server">
          <name>NHP-Server</name>
          <t>The NHP-Server is the core control-plane service responsible for:</t>
          <ul spacing="normal">
            <li>
              <t>Receiving and validating NHP-KNK messages from NHP-Agents</t>
            </li>
            <li>
              <t>Authenticating the NHP-Agent identity and device posture</t>
            </li>
            <li>
              <t>Interfacing with external Authorization Service Providers (ASP) or IAM systems</t>
            </li>
            <li>
              <t>Evaluating access policies based on identity, context, and resource attributes</t>
            </li>
            <li>
              <t>Instructing NHP-AC components to open or close access paths</t>
            </li>
            <li>
              <t>Managing session state and expiration</t>
            </li>
          </ul>
          <t>Functionally, the NHP-Server maps to the <strong>Policy Administrator</strong> role defined in NIST SP 800-207 Zero Trust Architecture <xref target="NIST.SP.800-207"/>.</t>
        </section>
        <section anchor="nhp-ac-access-controller">
          <name>NHP-AC (Access Controller)</name>
          <t>The NHP-AC is the enforcement component residing logically or physically near protected resources. Its responsibilities include:</t>
          <ul spacing="normal">
            <li>
              <t>Maintaining default-deny firewall rules for all protected resources</t>
            </li>
            <li>
              <t>Receiving NHP-AOP (AC Operations) commands from the NHP-Server</t>
            </li>
            <li>
              <t>Temporarily opening access paths for authorized NHP-Agents</t>
            </li>
            <li>
              <t>Automatically reverting to default-deny state when sessions expire</t>
            </li>
            <li>
              <t>Reporting access logs and status to the NHP-Server</t>
            </li>
          </ul>
          <t>The NHP-AC corresponds to the <strong>Policy Enforcement Point (PEP)</strong> in NIST SP 800-207 terminology.</t>
        </section>
        <section anchor="authorization-service-provider-asp">
          <name>Authorization Service Provider (ASP)</name>
          <t>The ASP is an external identity and policy service that the NHP-Server queries for authorization decisions. This may include:</t>
          <ul spacing="normal">
            <li>
              <t>Identity Providers (IdP) such as LDAP, Active Directory, or OIDC providers</t>
            </li>
            <li>
              <t>Policy Decision Points (PDP) implementing ABAC or RBAC policies</t>
            </li>
            <li>
              <t>Device posture assessment services</t>
            </li>
            <li>
              <t>Risk scoring engines</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="component-interactions">
        <name>Component Interactions</name>
        <t>The following diagram illustrates the relationship between NHP components:</t>
        <artwork><![CDATA[
+-------------+          +-------------+          +-------------+
|             |  NHP-KNK |             |  Auth    |             |
| NHP-Agent   |--------->| NHP-Server  |<-------->|    ASP      |
|             |<---------|             |  Query   |   (IAM)     |
+-------------+  NHP-ACK +-------------+          +-------------+
      |                        |
      |                        | NHP-AOP
      |                        v
      |                  +-------------+
      |    NHP-ACC       |             |
      +----------------->|   NHP-AC    |
      |                  |             |
      v                  +-------------+
+-------------+                |
|  Protected  |<---------------+
|  Resource   |   Data Plane
+-------------+
]]></artwork>
      </section>
      <section anchor="deployment-models">
        <name>Deployment Models</name>
        <t>NHP components can be deployed in different configurations:</t>
        <section anchor="standalone-deployment">
          <name>Standalone Deployment</name>
          <t>For small environments or testing scenarios, the NHP-Server and NHP-AC can coexist on the same host. This configuration simplifies setup while maintaining full protocol compliance.</t>
        </section>
        <section anchor="clustered-deployment">
          <name>Clustered Deployment</name>
          <t>In enterprise or cloud environments, multiple NHP-Servers can be deployed in a load-balanced cluster. Each server manages a pool of NHP-AC instances distributed across data centers or network segments. The NHP-Agent dynamically discovers the nearest NHP-Server through DNS or bootstrap configuration.</t>
        </section>
        <section anchor="edge-ac-deployment">
          <name>Edge AC Deployment</name>
          <t>Edge nodes (e.g., gateways, routers, or micro-segmentation agents) can host lightweight NHP-AC components. These edge ACs enforce fine-grained policies close to workloads, improving latency and fault isolation.</t>
        </section>
        <section anchor="multi-tenant-deployment">
          <name>Multi-Tenant Deployment</name>
          <t>In service-provider or multi-cloud environments, each tenant can operate an independent NHP-Server while sharing an underlying AC infrastructure. The NHP protocol's namespace isolation ensures complete tenant separation through identity-scoped keys and per-tenant policy databases.</t>
        </section>
      </section>
    </section>
    <section anchor="protocol-workflow">
      <name>Protocol Workflow</name>
      <section anchor="control-plane-vs-data-plane">
        <name>Control Plane vs Data Plane</name>
        <t>The <strong>Control Plane</strong> carries cryptographic authentication and authorization information among NHP-Agent, NHP-Server, NHP-AC, and optional external ASP. Control plane messages are encrypted using Noise Protocol handshakes.</t>
        <t>The <strong>Data Plane</strong> carries application data between the resource requester (NHP-Agent host) and the protected resource, but only after NHP-AC explicitly authorizes access.</t>
        <t>This strict separation enforces the <em>authenticate-before-connect</em> principle central to Zero Trust.</t>
      </section>
      <section anchor="workflow-steps">
        <name>Workflow Steps</name>
        <t>The complete NHP workflow consists of the following steps:</t>
        <ol spacing="normal" type="1"><li>
            <t><strong>Knock Request:</strong> NHP-Agent sends NHP-KNK message to NHP-Server containing encrypted identity claims and access request.</t>
          </li>
          <li>
            <t><strong>Authorization Query:</strong> NHP-Server validates the cryptographic envelope and queries ASP for authorization decision.</t>
          </li>
          <li>
            <t><strong>Authorization Response:</strong> ASP returns authorization decision with granted permissions and session parameters.</t>
          </li>
          <li>
            <t><strong>Door Opening:</strong> NHP-Server sends NHP-AOP command to NHP-AC instructing it to open access for the specific NHP-Agent.</t>
          </li>
          <li>
            <t><strong>AC Confirmation:</strong> NHP-AC enforces the access rule and replies with NHP-ART confirming the operation.</t>
          </li>
          <li>
            <t><strong>Agent Notification:</strong> NHP-Server sends NHP-ACK to NHP-Agent with access token and connection parameters.</t>
          </li>
          <li>
            <t><strong>Resource Access:</strong> NHP-Agent sends NHP-ACC to NHP-AC and establishes data plane connection to protected resource.</t>
          </li>
          <li>
            <t><strong>Session Maintenance:</strong> NHP-Server and NHP-AC maintain session state through NHP-KPL keepalive messages.</t>
          </li>
          <li>
            <t><strong>Logging and Audit:</strong> Logging is described in <xref target="logging-transmission"/>. Log transport is not defined in this revision.</t>
          </li>
        </ol>
      </section>
      <section anchor="sequence-diagram">
        <name>Sequence Diagram</name>
        <artwork><![CDATA[
NHP-Agent           NHP-Server            NHP-AC             ASP/IAM
    |                    |                    |                   |
    |--- NHP-KNK ------->|                    |                   |
    |                    |--- Auth Query -----|------------------>|
    |                    |<-- Auth Result ----|-------------------|
    |                    |                    |                   |
    |                    |--- NHP-AOP ------->|                   |
    |                    |<-- NHP-ART --------|                   |
    |                    |                    |                   |
    |<-- NHP-ACK --------|                    |                   |
    |                    |                    |                   |
    |--- NHP-ACC --------|------------------>|                   |
    |<================== Data Session ======>|                   |
    |                    |                    |                   |
]]></artwork>
      </section>
    </section>
    <section anchor="cryptographic-framework">
      <name>Cryptographic Framework</name>
      <t>NHP employs the Noise Protocol Framework <xref target="NoiseFramework"/> for all cryptographic operations. This section defines the required cryptographic primitives and handshake patterns.</t>
      <section anchor="cryptographic-primitives">
        <name>Cryptographic Primitives</name>
        <t>Implementations <bcp14>MUST</bcp14> support the following cryptographic primitives:</t>
        <table>
          <thead>
            <tr>
              <th align="left">Function</th>
              <th align="left">Algorithm</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">DH</td>
              <td align="left">Curve25519</td>
              <td align="left">RFC 7748</td>
            </tr>
            <tr>
              <td align="left">Cipher</td>
              <td align="left">ChaCha20-Poly1305</td>
              <td align="left">RFC 8439</td>
            </tr>
            <tr>
              <td align="left">Hash</td>
              <td align="left">SHA-256</td>
              <td align="left">RFC 6234</td>
            </tr>
            <tr>
              <td align="left">Key Derivation</td>
              <td align="left">HKDF</td>
              <td align="left">RFC 5869</td>
            </tr>
          </tbody>
        </table>
        <t>Implementations <bcp14>MAY</bcp14> additionally support:</t>
        <table>
          <thead>
            <tr>
              <th align="left">Function</th>
              <th align="left">Algorithm</th>
              <th align="left">Reference</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">DH</td>
              <td align="left">P-256 (secp256r1)</td>
              <td align="left">RFC 8422</td>
            </tr>
            <tr>
              <td align="left">Cipher</td>
              <td align="left">AES-256-GCM</td>
              <td align="left">RFC 5116</td>
            </tr>
            <tr>
              <td align="left">Hash</td>
              <td align="left">BLAKE2s</td>
              <td align="left">RFC 7693</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="noise-protocol-handshake-patterns">
        <name>Noise Protocol Handshake Patterns</name>
        <t>NHP supports the following Noise handshake patterns:</t>
        <section anchor="xx-pattern-default">
          <name>XX Pattern (Default)</name>
          <t>The XX pattern provides full forward secrecy and identity protection for both parties. It is the <bcp14>RECOMMENDED</bcp14> pattern for most deployments.</t>
          <artwork><![CDATA[
XX:
  -> e
  <- e, ee, s, es
  -> s, se
]]></artwork>
        </section>
        <section anchor="ik-pattern-performance-optimized">
          <name>IK Pattern (Performance Optimized)</name>
          <t>The IK pattern is used when the NHP-Agent knows the NHP-Server's static public key in advance, reducing round trips.</t>
          <artwork><![CDATA[
IK:
  <- s
  ...
  -> e, es, s, ss
  <- e, ee, se
]]></artwork>
        </section>
        <section anchor="k-pattern-one-way">
          <name>K Pattern (One-Way)</name>
          <t>The K pattern is used for one-way initiation where only the initiator needs to be authenticated by the responder.</t>
          <artwork><![CDATA[
K:
  <- s
  ...
  -> e, es, ss
]]></artwork>
        </section>
      </section>
      <section anchor="key-management">
        <name>Key Management</name>
        <section anchor="static-keys">
          <name>Static Keys</name>
          <t>Each NHP component maintains a static Curve25519 key pair:</t>
          <ul spacing="normal">
            <li>
              <t>NHP-Agent: Used for client identity and authentication</t>
            </li>
            <li>
              <t>NHP-Server: Used for server identity and authentication</t>
            </li>
            <li>
              <t>NHP-AC: Used for secure communication with NHP-Server</t>
            </li>
          </ul>
          <t>Static public keys <bcp14>MUST</bcp14> be distributed through a secure out-of-band mechanism or registered through the NHP-REG message flow.</t>
        </section>
        <section anchor="ephemeral-keys">
          <name>Ephemeral Keys</name>
          <t>Ephemeral keys are generated for each session to provide forward secrecy. Implementations <bcp14>MUST</bcp14> use cryptographically secure random number generators for ephemeral key generation.</t>
        </section>
        <section anchor="key-rotation">
          <name>Key Rotation</name>
          <t>Static keys <bcp14>SHOULD</bcp14> be rotated periodically. The NHP-REG and NHP-RAK messages support key re-registration without service interruption.</t>
        </section>
      </section>
    </section>
    <section anchor="message-format">
      <name>Message Format</name>
      <t>All NHP messages share a common header structure followed by an encrypted payload.</t>
      <section anchor="message-header">
        <name>Message Header</name>
        <t>Every NHP message begins with a fixed-length header. The header length depends on the cipher scheme. The reference implementation defines two layouts:</t>
        <table>
          <thead>
            <tr>
              <th align="left">Layout</th>
              <th align="left">Flags bit 0</th>
              <th align="left">Header size</th>
              <th align="left">Public key size</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">Curve (CIPHER_SCHEME_CURVE)</td>
              <td align="left">0</td>
              <td align="left">240 bytes</td>
              <td align="left">32 bytes</td>
            </tr>
            <tr>
              <td align="left">GMSM (CIPHER_SCHEME_GMSM)</td>
              <td align="left">1</td>
              <td align="left">304 bytes</td>
              <td align="left">64 bytes</td>
            </tr>
          </tbody>
        </table>
        <t>The header is followed by the encrypted body. All integers are in network byte order.</t>
        <section anchor="curve-header-layout">
          <name>Curve Header Layout</name>
          <table>
            <thead>
              <tr>
                <th align="left">Offset</th>
                <th align="left">Size</th>
                <th align="left">Field</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">0</td>
                <td align="left">4</td>
                <td align="left">Preamble: random 32-bit value, chosen per message</td>
              </tr>
              <tr>
                <td align="left">4</td>
                <td align="left">4</td>
                <td align="left">Type and Payload Size, XORed with the Preamble</td>
              </tr>
              <tr>
                <td align="left">8</td>
                <td align="left">1</td>
                <td align="left">Major Version</td>
              </tr>
              <tr>
                <td align="left">9</td>
                <td align="left">1</td>
                <td align="left">Minor Version</td>
              </tr>
              <tr>
                <td align="left">10</td>
                <td align="left">2</td>
                <td align="left">Flags</td>
              </tr>
              <tr>
                <td align="left">12</td>
                <td align="left">4</td>
                <td align="left">Unused (not written by the reference implementation)</td>
              </tr>
              <tr>
                <td align="left">16</td>
                <td align="left">8</td>
                <td align="left">Counter</td>
              </tr>
              <tr>
                <td align="left">24</td>
                <td align="left">32</td>
                <td align="left">Ephemeral Public Key</td>
              </tr>
              <tr>
                <td align="left">56</td>
                <td align="left">80</td>
                <td align="left">Identity: 64 bytes of encrypted identity plus a 16-byte AEAD tag</td>
              </tr>
              <tr>
                <td align="left">136</td>
                <td align="left">48</td>
                <td align="left">Static Public Key: 32 bytes plus a 16-byte AEAD tag</td>
              </tr>
              <tr>
                <td align="left">184</td>
                <td align="left">24</td>
                <td align="left">Timestamp: 8 bytes plus a 16-byte AEAD tag</td>
              </tr>
              <tr>
                <td align="left">208</td>
                <td align="left">32</td>
                <td align="left">HMAC</td>
              </tr>
            </tbody>
          </table>
          <t>The GMSM layout has the same field order. The Ephemeral Public Key is 64 bytes and the Static Public Key field is 80 bytes (64 bytes plus a 16-byte tag), which brings the header to 304 bytes.</t>
        </section>
        <section anchor="header-fields">
          <name>Header Fields</name>
          <dl>
            <dt>Preamble (32 bits)</dt>
            <dd>
              <t>A random value chosen per message. The Type and Payload Size field is masked with it, so the type and size are not visible on the wire in plaintext.</t>
            </dd>
            <dt>Type and Payload Size (32 bits)</dt>
            <dd>
              <t>The message type in the upper 16 bits and the length of the encrypted body in the lower 16 bits, XORed with the Preamble. The receiver recovers both by XORing the field with the Preamble. See <xref target="message-types"/> for type values.</t>
            </dd>
            <dt>Version (16 bits)</dt>
            <dd>
              <t>Major and minor protocol version. Each is one byte.</t>
            </dd>
            <dt>Flags (16 bits)</dt>
            <dd>
              <t>Bits are numbered from the least significant bit.
* Bit 0: Extended header. When set, the header uses the GMSM layout.
* Bit 1: Body compression enabled.
* Bit 2: Client public key flag.
* Bits 3-11: Reserved. Senders <bcp14>MUST</bcp14> set these to zero.
* Bits 12-15: Cipher scheme (0 = Curve, 1 = GMSM).</t>
            </dd>
            <dt>Counter (64 bits)</dt>
            <dd>
              <t>A per-session message counter in network byte order. It is used as the low 8 bytes of the 12-byte AEAD nonce, and the high 4 bytes of the nonce are zero. A counter value <bcp14>MUST NOT</bcp14> be reused within a session with the same key.</t>
            </dd>
            <dt>Ephemeral, Identity, Static, Timestamp, HMAC</dt>
            <dd>
              <t>Key and authentication fields for the handshake. Each encrypted field carries its own AEAD tag. The HMAC covers the header prefix.</t>
            </dd>
          </dl>
          <t>The encrypted body follows the header. Its length is given by the Payload Size field. The body is encrypted with the chain hash as additional authenticated data.</t>
        </section>
      </section>
      <section anchor="message-types">
        <name>Message Types</name>
        <table>
          <thead>
            <tr>
              <th align="left">Type Code</th>
              <th align="left">Name</th>
              <th align="left">Direction</th>
              <th align="left">Description</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">0x00</td>
              <td align="left">NHP-KPL</td>
              <td align="left">Any</td>
              <td align="left">Keepalive</td>
            </tr>
            <tr>
              <td align="left">0x01</td>
              <td align="left">NHP-KNK</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">Knock request</td>
            </tr>
            <tr>
              <td align="left">0x02</td>
              <td align="left">NHP-ACK</td>
              <td align="left">Server-&gt;Agent</td>
              <td align="left">Knock acknowledgment</td>
            </tr>
            <tr>
              <td align="left">0x03</td>
              <td align="left">NHP-AOP</td>
              <td align="left">Server-&gt;AC</td>
              <td align="left">AC operation request</td>
            </tr>
            <tr>
              <td align="left">0x04</td>
              <td align="left">NHP-ART</td>
              <td align="left">AC-&gt;Server</td>
              <td align="left">AC operation result</td>
            </tr>
            <tr>
              <td align="left">0x05</td>
              <td align="left">NHP-LST</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">List services and applications</td>
            </tr>
            <tr>
              <td align="left">0x06</td>
              <td align="left">NHP-LRT</td>
              <td align="left">Server-&gt;Agent</td>
              <td align="left">Service list result</td>
            </tr>
            <tr>
              <td align="left">0x07</td>
              <td align="left">NHP-COK</td>
              <td align="left">Server-&gt;Agent</td>
              <td align="left">Cookie for re-knock</td>
            </tr>
            <tr>
              <td align="left">0x08</td>
              <td align="left">NHP-RKN</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">Re-knock with cookie</td>
            </tr>
            <tr>
              <td align="left">0x09</td>
              <td align="left">NHP-RLY</td>
              <td align="left">Relay-&gt;Server</td>
              <td align="left">Relayed packet</td>
            </tr>
            <tr>
              <td align="left">0x0A</td>
              <td align="left">NHP-AOL</td>
              <td align="left">AC-&gt;Server</td>
              <td align="left">AC online notification</td>
            </tr>
            <tr>
              <td align="left">0x0B</td>
              <td align="left">NHP-AAK</td>
              <td align="left">Server-&gt;AC</td>
              <td align="left">Acknowledgment of AC online notification</td>
            </tr>
            <tr>
              <td align="left">0x0C</td>
              <td align="left">NHP-OTP</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">One-time passcode request</td>
            </tr>
            <tr>
              <td align="left">0x0D</td>
              <td align="left">NHP-REG</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">Agent registration</td>
            </tr>
            <tr>
              <td align="left">0x0E</td>
              <td align="left">NHP-RAK</td>
              <td align="left">Server-&gt;Agent</td>
              <td align="left">Registration acknowledgment</td>
            </tr>
            <tr>
              <td align="left">0x0F</td>
              <td align="left">NHP-ACC</td>
              <td align="left">Agent-&gt;AC</td>
              <td align="left">Access request</td>
            </tr>
            <tr>
              <td align="left">0x10</td>
              <td align="left">NHP-EXT</td>
              <td align="left">Agent-&gt;Server</td>
              <td align="left">Immediate disconnection request</td>
            </tr>
          </tbody>
        </table>
        <t>Values 0x11-0x16 are used by DHP message types in the reference implementation. They are not defined in this document. Values 0x17-0xFF are reserved.</t>
      </section>
      <section anchor="message-definitions">
        <name>Message Definitions</name>
        <t>Message bodies are JSON objects. Field names below are the JSON keys used by the reference implementation's message structures. A field is optional where the reference implementation marks it <tt>omitempty</tt>.</t>
        <section anchor="nhp-kpl-keepalive">
          <name>NHP-KPL (Keepalive)</name>
          <t>Keepalive messages maintain session state between components. This revision does not define a body structure.</t>
        </section>
        <section anchor="nhp-knk-knock">
          <name>NHP-KNK (Knock)</name>
          <t>Sent by NHP-Agent to NHP-Server to request access to a resource.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">headerType</td>
                <td align="left">integer</td>
                <td align="left">Yes</td>
                <td align="left">Header type value</td>
              </tr>
              <tr>
                <td align="left">usrId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">User identifier</td>
              </tr>
              <tr>
                <td align="left">devId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Device identifier</td>
              </tr>
              <tr>
                <td align="left">orgId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Organization identifier</td>
              </tr>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">resId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Resource identifier</td>
              </tr>
              <tr>
                <td align="left">results</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Results of client-side checks</td>
              </tr>
              <tr>
                <td align="left">usrData</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Additional user data</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-ack-knock-acknowledgment">
          <name>NHP-ACK (Knock Acknowledgment)</name>
          <t>Sent by NHP-Server to NHP-Agent in response to NHP-KNK.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">errCode</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Result code</td>
              </tr>
              <tr>
                <td align="left">errMsg</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Error description</td>
              </tr>
              <tr>
                <td align="left">resHost</td>
                <td align="left">object</td>
                <td align="left">Yes</td>
                <td align="left">Map of resource host addresses</td>
              </tr>
              <tr>
                <td align="left">opnTime</td>
                <td align="left">integer</td>
                <td align="left">Yes</td>
                <td align="left">Open time for access</td>
              </tr>
              <tr>
                <td align="left">aspToken</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Token for AC-side validation</td>
              </tr>
              <tr>
                <td align="left">agentAddr</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Source address observed for the agent</td>
              </tr>
              <tr>
                <td align="left">acTokens</td>
                <td align="left">object</td>
                <td align="left">Yes</td>
                <td align="left">Map of AC access tokens</td>
              </tr>
              <tr>
                <td align="left">preActions</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Pre-access actions</td>
              </tr>
              <tr>
                <td align="left">redirectUrl</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Redirect URL</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-aop-ac-operation-request">
          <name>NHP-AOP (AC Operation Request)</name>
          <t>Sent by NHP-Server to NHP-AC to open access for an agent.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">usrId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">User identifier</td>
              </tr>
              <tr>
                <td align="left">devId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Device identifier</td>
              </tr>
              <tr>
                <td align="left">orgId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Organization identifier</td>
              </tr>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">resId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Resource identifier</td>
              </tr>
              <tr>
                <td align="left">srcAddrs</td>
                <td align="left">array of NetAddress</td>
                <td align="left">Yes</td>
                <td align="left">Source addresses to allow</td>
              </tr>
              <tr>
                <td align="left">dstAddrs</td>
                <td align="left">array of NetAddress</td>
                <td align="left">Yes</td>
                <td align="left">Destination addresses to allow</td>
              </tr>
              <tr>
                <td align="left">opnTime</td>
                <td align="left">integer</td>
                <td align="left">Yes</td>
                <td align="left">Open time</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-art-ac-operation-result">
          <name>NHP-ART (AC Operation Result)</name>
          <t>Sent by NHP-AC to NHP-Server with the result of NHP-AOP.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">errCode</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Result code</td>
              </tr>
              <tr>
                <td align="left">errMsg</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Error description</td>
              </tr>
              <tr>
                <td align="left">opnTime</td>
                <td align="left">integer</td>
                <td align="left">Yes</td>
                <td align="left">Open time granted</td>
              </tr>
              <tr>
                <td align="left">token</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC access token</td>
              </tr>
              <tr>
                <td align="left">preAct</td>
                <td align="left">PreAccessInfo</td>
                <td align="left">No</td>
                <td align="left">Pre-access information</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-lst-list-request-and-nhp-lrt-list-result">
          <name>NHP-LST (List Request) and NHP-LRT (List Result)</name>
          <t>NHP-LST carries the same identity fields as NHP-KNK, without a resource identifier: usrId, devId, orgId (optional), aspId, and usrData (optional).</t>
          <t>NHP-LRT carries:</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">errCode</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Result code</td>
              </tr>
              <tr>
                <td align="left">errMsg</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Error description</td>
              </tr>
              <tr>
                <td align="left">list</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Services and applications</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-cok-cookie">
          <name>NHP-COK (Cookie)</name>
          <t>Sent by NHP-Server to NHP-Agent.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">trxId</td>
                <td align="left">integer (64-bit)</td>
                <td align="left">Yes</td>
                <td align="left">Transaction identifier</td>
              </tr>
              <tr>
                <td align="left">cookie</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Cookie for re-knock</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-rkn-re-knock">
          <name>NHP-RKN (Re-Knock)</name>
          <t>Sent by NHP-Agent to NHP-Server with the cookie from NHP-COK. This revision does not define the body structure.</t>
        </section>
        <section anchor="nhp-rly-relayed-packet">
          <name>NHP-RLY (Relayed Packet)</name>
          <t>Sent by a relay to NHP-Server to forward a packet on behalf of a client.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">srcAddr</td>
                <td align="left">NetAddress</td>
                <td align="left">Yes</td>
                <td align="left">Original client address</td>
              </tr>
              <tr>
                <td align="left">innerPkt</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Base64-encoded inner NHP packet</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-aol-ac-online">
          <name>NHP-AOL (AC Online)</name>
          <t>Sent by NHP-AC to NHP-Server to report the resources it serves.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">resIds</td>
                <td align="left">array of string</td>
                <td align="left">Yes</td>
                <td align="left">Resource identifiers</td>
              </tr>
              <tr>
                <td align="left">acId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">AC identifier</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-aak-ac-acknowledgment">
          <name>NHP-AAK (AC Acknowledgment)</name>
          <t>Sent by NHP-Server to NHP-AC after receiving NHP-AOL.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">errCode</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Result code</td>
              </tr>
              <tr>
                <td align="left">errMsg</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Error description</td>
              </tr>
              <tr>
                <td align="left">acAddr</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC address</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-otp-one-time-passcode-request">
          <name>NHP-OTP (One-Time Passcode Request)</name>
          <t>Sent by NHP-Agent to NHP-Server.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">usrId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">User identifier</td>
              </tr>
              <tr>
                <td align="left">devId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Device identifier</td>
              </tr>
              <tr>
                <td align="left">orgId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Organization identifier</td>
              </tr>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">pass</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Passcode</td>
              </tr>
              <tr>
                <td align="left">pubKey</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Agent public key</td>
              </tr>
              <tr>
                <td align="left">usrData</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Additional user data</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-reg-register">
          <name>NHP-REG (Register)</name>
          <t>Sent by NHP-Agent to NHP-Server to register its public key.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">usrId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">User identifier</td>
              </tr>
              <tr>
                <td align="left">devId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Device identifier</td>
              </tr>
              <tr>
                <td align="left">orgId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Organization identifier</td>
              </tr>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">otp</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">One-time passcode</td>
              </tr>
              <tr>
                <td align="left">pubKey</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Agent public key</td>
              </tr>
              <tr>
                <td align="left">usrData</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Additional user data</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-rak-register-acknowledgment">
          <name>NHP-RAK (Register Acknowledgment)</name>
          <t>Sent by NHP-Server to NHP-Agent.</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">errCode</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Result code</td>
              </tr>
              <tr>
                <td align="left">errMsg</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Error description</td>
              </tr>
              <tr>
                <td align="left">aspId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Authorization Service Provider identifier</td>
              </tr>
              <tr>
                <td align="left">expiresAt</td>
                <td align="left">integer</td>
                <td align="left">No</td>
                <td align="left">Unix time, in seconds, when the registered key expires</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-acc-access">
          <name>NHP-ACC (Access)</name>
          <t>Sent by NHP-Agent to NHP-AC to access a resource. The NHP-AC replies with an access acknowledgment carrying errCode, errMsg (optional), and agentAddr (optional).</t>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">usrId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">User identifier</td>
              </tr>
              <tr>
                <td align="left">devId</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Device identifier</td>
              </tr>
              <tr>
                <td align="left">orgId</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">Organization identifier</td>
              </tr>
              <tr>
                <td align="left">acToken</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">Access token from NHP-ACK</td>
              </tr>
              <tr>
                <td align="left">usrData</td>
                <td align="left">object</td>
                <td align="left">No</td>
                <td align="left">Additional user data</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="nhp-ext-disconnect">
          <name>NHP-EXT (Disconnect)</name>
          <t>Sent by NHP-Agent to NHP-Server to request immediate disconnection. This revision does not define the body structure.</t>
        </section>
        <section anchor="netaddress">
          <name>NetAddress</name>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">ip</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">IP address</td>
              </tr>
              <tr>
                <td align="left">port</td>
                <td align="left">integer</td>
                <td align="left">No</td>
                <td align="left">Port number</td>
              </tr>
              <tr>
                <td align="left">proto</td>
                <td align="left">string</td>
                <td align="left">No</td>
                <td align="left">"tcp" or "udp"; empty for any</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="preaccessinfo">
          <name>PreAccessInfo</name>
          <table>
            <thead>
              <tr>
                <th align="left">JSON Key</th>
                <th align="left">Type</th>
                <th align="left">Required</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">acIp</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC IP address</td>
              </tr>
              <tr>
                <td align="left">acPort</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC port</td>
              </tr>
              <tr>
                <td align="left">acPubKey</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC public key</td>
              </tr>
              <tr>
                <td align="left">acToken</td>
                <td align="left">string</td>
                <td align="left">Yes</td>
                <td align="left">AC access token</td>
              </tr>
              <tr>
                <td align="left">acCipherScheme</td>
                <td align="left">integer</td>
                <td align="left">Yes</td>
                <td align="left">Cipher scheme of the AC</td>
              </tr>
            </tbody>
          </table>
        </section>
      </section>
    </section>
    <section anchor="logging-and-auditing">
      <name>Logging and Auditing</name>
      <t>NHP provides comprehensive logging capabilities to support security monitoring, compliance, and forensic analysis.</t>
      <section anchor="log-types">
        <name>Log Types</name>
        <t>NHP defines the following log categories:</t>
        <dl>
          <dt>Access Logs</dt>
          <dd>
            <t>Record all access attempts, including source identity, timestamp, requested resource, and decision outcome.</t>
          </dd>
          <dt>Authentication Logs</dt>
          <dd>
            <t>Record authentication events including key exchanges, identity verification, and authentication failures.</t>
          </dd>
          <dt>Policy Logs</dt>
          <dd>
            <t>Record policy evaluation decisions and the factors considered.</t>
          </dd>
          <dt>System Logs</dt>
          <dd>
            <t>Record component health, configuration changes, and operational events.</t>
          </dd>
        </dl>
      </section>
      <section anchor="log-format">
        <name>Log Format</name>
        <t>All NHP logs <bcp14>SHOULD</bcp14> use structured JSON format with the following mandatory fields:</t>
        <sourcecode type="json"><![CDATA[
{
  "timestamp": "2025-01-01T12:00:00.000Z",
  "log_type": "access",
  "component": "nhp-ac-01",
  "session_id": "abc123...",
  "user_id": "user@example.com",
  "device_id": "device-uuid",
  "source_ip": "192.0.2.1",
  "resource_id": "resource-001",
  "action": "access_granted",
  "details": {}
}
]]></sourcecode>
      </section>
      <section anchor="logging-transmission">
        <name>Log Transmission</name>
        <t>NHP-LOG and NHP-LAK are not implemented in the reference implementation, and this revision does not register message types for them. The requirements below are intended for a future revision that defines the log transport:</t>
        <t>NHP-AC components transmit logs to NHP-Server. Implementations <bcp14>MUST</bcp14>:</t>
        <ul spacing="normal">
          <li>
            <t>Encrypt all log transmissions using the established Noise session</t>
          </li>
          <li>
            <t>Batch logs to reduce network overhead</t>
          </li>
          <li>
            <t>Implement retry logic for failed transmissions</t>
          </li>
          <li>
            <t>Store logs locally if transmission fails</t>
          </li>
        </ul>
      </section>
      <section anchor="compliance-considerations">
        <name>Compliance Considerations</name>
        <t>NHP logging supports compliance with:</t>
        <ul spacing="normal">
          <li>
            <t>SOC 2 Type II audit requirements</t>
          </li>
          <li>
            <t>GDPR access logging requirements</t>
          </li>
          <li>
            <t>HIPAA audit trail requirements</t>
          </li>
          <li>
            <t>PCI-DSS logging requirements</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="integration-with-sdp">
      <name>Integration with SDP</name>
      <t>NHP is designed to integrate seamlessly with existing Software-Defined Perimeter (SDP) deployments as defined in <xref target="CSA.SDP.Spec2.0"/>.</t>
      <section anchor="integration-architecture">
        <name>Integration Architecture</name>
        <t>In an SDP integration, NHP components map to SDP components as follows:</t>
        <table>
          <thead>
            <tr>
              <th align="left">NHP Component</th>
              <th align="left">SDP Component</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">NHP-Agent</td>
              <td align="left">SDP Initiating Host</td>
            </tr>
            <tr>
              <td align="left">NHP-Server</td>
              <td align="left">SDP Controller</td>
            </tr>
            <tr>
              <td align="left">NHP-AC</td>
              <td align="left">SDP Gateway</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="integration-process">
        <name>Integration Process</name>
        <ol spacing="normal" type="1"><li>
            <t><strong>Discovery:</strong> SDP Controller advertises NHP-Server endpoint to SDP Initiating Hosts.</t>
          </li>
          <li>
            <t><strong>Authentication:</strong> SDP Initiating Host uses NHP-KNK to authenticate with NHP-Server instead of SPA.</t>
          </li>
          <li>
            <t><strong>Authorization:</strong> NHP-Server queries SDP Controller for policy decisions.</t>
          </li>
          <li>
            <t><strong>Enforcement:</strong> NHP-AC opens ports on SDP Gateway based on NHP-AOP commands.</t>
          </li>
        </ol>
      </section>
      <section anchor="benefits-of-nhp-sdp-integration">
        <name>Benefits of NHP-SDP Integration</name>
        <ul spacing="normal">
          <li>
            <t><strong>Stronger Cryptography:</strong> NHP's Noise-based key exchange provides better forward secrecy than traditional SPA.</t>
          </li>
          <li>
            <t><strong>Mutual Authentication:</strong> Both client and server authenticate each other.</t>
          </li>
          <li>
            <t><strong>Scalability:</strong> NHP's architecture supports enterprise-scale deployments.</t>
          </li>
          <li>
            <t><strong>Extensibility:</strong> NHP message types support richer interaction patterns.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="integration-with-dns">
      <name>Integration with DNS</name>
      <t>NHP can integrate with DNS infrastructure to provide stealth resolution of protected resources.</t>
      <section anchor="dns-integration-architecture">
        <name>DNS Integration Architecture</name>
        <artwork><![CDATA[
+-------------+     +-------------+     +-------------+
| NHP-Agent   |---->| NHP-Server  |---->| DNS Server  |
|             |     |             |     | (Internal)  |
+-------------+     +-------------+     +-------------+
      |                   |
      v                   v
+-------------+     +-------------+
| Public DNS  |     | NHP-AC      |
| (No Records)|     |             |
+-------------+     +-------------+
]]></artwork>
      </section>
      <section anchor="integration-process-1">
        <name>Integration Process</name>
        <ol spacing="normal" type="1"><li>
            <t>Protected resources have no public DNS records.</t>
          </li>
          <li>
            <t>NHP-Agent authenticates with NHP-Server via NHP-KNK.</t>
          </li>
          <li>
            <t>NHP-Server returns resource IP addresses in NHP-ACK only after successful authentication.</t>
          </li>
          <li>
            <t>NHP-Agent can then connect to the resolved addresses.</t>
          </li>
        </ol>
        <t>This prevents DNS enumeration attacks and keeps resource addresses invisible to unauthorized users.</t>
      </section>
    </section>
    <section anchor="integration-with-fido">
      <name>Integration with FIDO</name>
      <t>NHP supports integration with FIDO2/WebAuthn for strong user authentication.</t>
      <section anchor="fido-integration-flow">
        <name>FIDO Integration Flow</name>
        <ol spacing="normal" type="1"><li>
            <t>User initiates NHP-KNK with FIDO assertion</t>
          </li>
          <li>
            <t>NHP-Server validates FIDO assertion with FIDO server</t>
          </li>
          <li>
            <t>Upon successful FIDO authentication, NHP-Server proceeds with access grant</t>
          </li>
        </ol>
      </section>
      <section anchor="recovery-and-fallback">
        <name>Recovery and Fallback</name>
        <t>For FIDO authentication failures, NHP supports fallback to:</t>
        <ul spacing="normal">
          <li>
            <t>One-Time Password (OTP) via NHP-OTP message</t>
          </li>
          <li>
            <t>SMS/Email verification codes</t>
          </li>
          <li>
            <t>Recovery codes</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <section anchor="infrastructure-invisibility">
        <name>Infrastructure Invisibility</name>
        <t>NHP ensures infrastructure invisibility by:</t>
        <ul spacing="normal">
          <li>
            <t>Encrypting all control plane traffic using Noise Protocol</t>
          </li>
          <li>
            <t>Requiring mutual authentication before any resource visibility</t>
          </li>
          <li>
            <t>Maintaining default-deny firewall rules on all NHP-AC components</t>
          </li>
          <li>
            <t>Supporting ephemeral port allocation for data plane connections</t>
          </li>
        </ul>
      </section>
      <section anchor="replay-attack-prevention">
        <name>Replay Attack Prevention</name>
        <t>NHP prevents replay attacks through:</t>
        <ul spacing="normal">
          <li>
            <t>Timestamp validation with configurable tolerance (<bcp14>RECOMMENDED</bcp14>: 60 seconds)</t>
          </li>
          <li>
            <t>Unique nonce per message</t>
          </li>
          <li>
            <t>Session-bound tokens that cannot be reused across sessions</t>
          </li>
        </ul>
      </section>
      <section anchor="key-security">
        <name>Key Security</name>
        <t>Implementations <bcp14>MUST</bcp14>:</t>
        <ul spacing="normal">
          <li>
            <t>Use cryptographically secure random number generators for all key generation</t>
          </li>
          <li>
            <t>Store private keys in secure enclaves or HSMs where available</t>
          </li>
          <li>
            <t>Implement key rotation policies</t>
          </li>
          <li>
            <t>Securely erase key material when no longer needed</t>
          </li>
        </ul>
      </section>
      <section anchor="session-security">
        <name>Session Security</name>
        <ul spacing="normal">
          <li>
            <t>Sessions <bcp14>MUST</bcp14> have configurable expiration (<bcp14>RECOMMENDED</bcp14> default: 4 hours)</t>
          </li>
          <li>
            <t>Sessions <bcp14>MUST</bcp14> be revocable by NHP-Server</t>
          </li>
          <li>
            <t>Session tokens <bcp14>MUST</bcp14> be bound to client identity and IP address</t>
          </li>
        </ul>
      </section>
      <section anchor="denial-of-service-mitigation">
        <name>Denial of Service Mitigation</name>
        <t>NHP provides DoS resistance through:</t>
        <ul spacing="normal">
          <li>
            <t>Cryptographic puzzles for computationally expensive operations</t>
          </li>
          <li>
            <t>Rate limiting on NHP-Server and NHP-AC</t>
          </li>
          <li>
            <t>Cookie-based session resumption to avoid repeated handshakes</t>
          </li>
        </ul>
      </section>
      <section anchor="limitations">
        <name>Limitations</name>
        <t>NHP does not protect against:</t>
        <ul spacing="normal">
          <li>
            <t>Compromised endpoints with valid credentials</t>
          </li>
          <li>
            <t>Insider threats with legitimate access</t>
          </li>
          <li>
            <t>Attacks on the data plane after access is granted</t>
          </li>
          <li>
            <t>Social engineering attacks targeting user credentials</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document requests IANA to establish a new registry named "NHP Message Types" with an 8-bit type field. The registration policy is Specification Required <xref target="RFC8126"/>. The initial values are:</t>
      <table>
        <thead>
          <tr>
            <th align="left">Value</th>
            <th align="left">Name</th>
            <th align="left">Reference</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">0x00</td>
            <td align="left">NHP-KPL</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x01</td>
            <td align="left">NHP-KNK</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x02</td>
            <td align="left">NHP-ACK</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x03</td>
            <td align="left">NHP-AOP</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x04</td>
            <td align="left">NHP-ART</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x05</td>
            <td align="left">NHP-LST</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x06</td>
            <td align="left">NHP-LRT</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x07</td>
            <td align="left">NHP-COK</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x08</td>
            <td align="left">NHP-RKN</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x09</td>
            <td align="left">NHP-RLY</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0A</td>
            <td align="left">NHP-AOL</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0B</td>
            <td align="left">NHP-AAK</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0C</td>
            <td align="left">NHP-OTP</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0D</td>
            <td align="left">NHP-REG</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0E</td>
            <td align="left">NHP-RAK</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x0F</td>
            <td align="left">NHP-ACC</td>
            <td align="left">This document</td>
          </tr>
          <tr>
            <td align="left">0x10</td>
            <td align="left">NHP-EXT</td>
            <td align="left">This document</td>
          </tr>
        </tbody>
      </table>
      <t>Values 0x11-0x16 are used by DHP message types in the reference implementation and are to be registered by the document that defines them. Values 0x17-0xFF are reserved for future use.</t>
    </section>
    <section anchor="reference-implementation">
      <name>Reference Implementation</name>
      <t>An open-source reference implementation of NHP is available at:</t>
      <t>https://github.com/OpenNHP/opennhp</t>
      <t>A live demo of the protocol is available at:</t>
      <t>https://opennhp.org/demo/</t>
      <section anchor="implementation-characteristics">
        <name>Implementation Characteristics</name>
        <t>The OpenNHP reference implementation is designed with the following characteristics:</t>
        <section anchor="memory-safe-language">
          <name>Memory-Safe Language</name>
          <t>OpenNHP is implemented in <strong>Go (Golang)</strong>, a memory-safe programming language that eliminates entire classes of vulnerabilities common in C/C++ implementations:</t>
          <ul spacing="normal">
            <li>
              <t><strong>No Buffer Overflows:</strong> Go's built-in bounds checking prevents buffer overflow attacks.</t>
            </li>
            <li>
              <t><strong>No Use-After-Free:</strong> Automatic garbage collection eliminates dangling pointer vulnerabilities.</t>
            </li>
            <li>
              <t><strong>No Null Pointer Dereferences:</strong> Go's type system and nil handling prevent null pointer crashes.</t>
            </li>
            <li>
              <t><strong>Race Condition Detection:</strong> Built-in race detector helps identify concurrency issues during development.</t>
            </li>
          </ul>
          <t>This choice aligns with recommendations from CISA, NSA, and other security agencies advocating for memory-safe languages in critical infrastructure software.</t>
        </section>
        <section anchor="cross-platform-support">
          <name>Cross-Platform Support</name>
          <t>OpenNHP provides native support across multiple platforms:</t>
          <table>
            <thead>
              <tr>
                <th align="left">Platform</th>
                <th align="left">Components</th>
                <th align="left">Description</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">Linux</td>
                <td align="left">Agent, Server, AC</td>
                <td align="left">Full production support for x86_64, ARM64</td>
              </tr>
              <tr>
                <td align="left">Windows</td>
                <td align="left">Agent, Server, AC</td>
                <td align="left">Native Windows service integration</td>
              </tr>
              <tr>
                <td align="left">macOS</td>
                <td align="left">Agent</td>
                <td align="left">Desktop client with system integration</td>
              </tr>
              <tr>
                <td align="left">FreeBSD</td>
                <td align="left">Agent, Server, AC</td>
                <td align="left">BSD-family operating system support</td>
              </tr>
              <tr>
                <td align="left">Android</td>
                <td align="left">Agent (Library)</td>
                <td align="left">Mobile SDK for Android applications</td>
              </tr>
              <tr>
                <td align="left">iOS</td>
                <td align="left">Agent (Library)</td>
                <td align="left">Mobile SDK for iOS applications</td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="modular-architecture">
          <name>Modular Architecture</name>
          <t>The implementation provides separate binaries for each NHP component:</t>
          <ul spacing="normal">
            <li>
              <t><strong>nhp-agent:</strong> Client-side agent for initiating NHP connections</t>
            </li>
            <li>
              <t><strong>nhp-server:</strong> Control plane server for authentication and authorization</t>
            </li>
            <li>
              <t><strong>nhp-ac:</strong> Access controller for policy enforcement</t>
            </li>
          </ul>
          <t>Each component can be deployed independently, enabling flexible deployment topologies from standalone to distributed enterprise configurations.</t>
        </section>
        <section anchor="cryptographic-implementation">
          <name>Cryptographic Implementation</name>
          <t>The reference implementation uses well-audited cryptographic libraries:</t>
          <ul spacing="normal">
            <li>
              <t><strong>Noise Protocol:</strong> flynn/noise library for Noise Framework handshakes</t>
            </li>
            <li>
              <t><strong>Curve25519:</strong> golang.org/x/crypto for elliptic curve operations</t>
            </li>
            <li>
              <t><strong>ChaCha20-Poly1305:</strong> Standard library crypto/cipher for AEAD encryption</t>
            </li>
            <li>
              <t><strong>HKDF:</strong> golang.org/x/crypto/hkdf for key derivation</t>
            </li>
          </ul>
        </section>
        <section anchor="performance-characteristics">
          <name>Performance Characteristics</name>
          <t>The Go implementation provides:</t>
          <ul spacing="normal">
            <li>
              <t><strong>Low Latency:</strong> Typical NHP handshake completes in under 10ms on local networks</t>
            </li>
            <li>
              <t><strong>High Throughput:</strong> Single NHP-Server can handle thousands of concurrent sessions</t>
            </li>
            <li>
              <t><strong>Minimal Footprint:</strong> Agent binary under 15MB, low memory consumption</t>
            </li>
            <li>
              <t><strong>Concurrent Design:</strong> Goroutine-based concurrency for efficient resource utilization</t>
            </li>
          </ul>
        </section>
        <section anchor="open-source-governance">
          <name>Open Source Governance</name>
          <t>The OpenNHP project operates under the Apache 2.0 license, fostering community collaboration and transparent development to accelerate adoption and ensure rigorous peer review of its security mechanisms.</t>
        </section>
      </section>
      <section anchor="practical-use-case-stealthdns">
        <name>Practical Use Case: StealthDNS</name>
        <t>StealthDNS is a Zero Trust DNS client powered by OpenNHP that demonstrates practical application of the NHP protocol for DNS-level infrastructure hiding. It is available at:</t>
        <t>https://github.com/OpenNHP/StealthDNS</t>
        <t>StealthDNS implements the NHP-DNS integration described in this specification, providing:</t>
        <ul spacing="normal">
          <li>
            <t><strong>Invisible DNS Resolution:</strong> Protected domains have no public DNS records. Only authenticated clients can resolve hidden service addresses.</t>
          </li>
          <li>
            <t><strong>NHP-Powered Authentication:</strong> Uses the OpenNHP library to perform cryptographic NHP knocking before DNS resolution.</t>
          </li>
          <li>
            <t><strong>Transparent Local Resolver:</strong> Runs as a local DNS resolver (127.0.0.1:53), requiring no application changes.</t>
          </li>
          <li>
            <t><strong>Cross-Platform Support:</strong> Available on Windows, macOS, Linux, Android, and iOS.</t>
          </li>
        </ul>
        <t>The StealthDNS workflow demonstrates the authenticate-before-connect principle:</t>
        <ol spacing="normal" type="1"><li>
            <t>Application performs DNS lookup for a protected domain.</t>
          </li>
          <li>
            <t>StealthDNS checks if the domain is NHP-protected.</t>
          </li>
          <li>
            <t>If protected, StealthDNS performs NHP knock with identity and device context.</t>
          </li>
          <li>
            <t>Upon successful authentication, the NHP Controller returns ephemeral address mappings.</t>
          </li>
          <li>
            <t>StealthDNS returns valid DNS records only to authorized clients.</t>
          </li>
          <li>
            <t>Unauthorized clients receive NXDOMAIN--the service remains invisible.</t>
          </li>
        </ol>
        <t>This enforces <strong>identity before visibility</strong> and <strong>authorization before connectivity</strong>, demonstrating real-world application of NHP principles.</t>
      </section>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
        <reference anchor="RFC9000">
          <front>
            <title>QUIC: A UDP-Based Multiplexed and Secure Transport</title>
            <author fullname="J. Iyengar" initials="J." role="editor" surname="Iyengar"/>
            <author fullname="M. Thomson" initials="M." role="editor" surname="Thomson"/>
            <date month="May" year="2021"/>
            <abstract>
              <t>This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TLS for key negotiation, loss detection, and an exemplary congestion control algorithm.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9000"/>
          <seriesInfo name="DOI" value="10.17487/RFC9000"/>
        </reference>
        <reference anchor="RFC8446">
          <front>
            <title>The Transport Layer Security (TLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <date month="August" year="2018"/>
            <abstract>
              <t>This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>This document updates RFCs 5705 and 6066, and obsoletes RFCs 5077, 5246, and 6961. This document also specifies new requirements for TLS 1.2 implementations.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8446"/>
          <seriesInfo name="DOI" value="10.17487/RFC8446"/>
        </reference>
        <reference anchor="NoiseFramework" target="https://noiseprotocol.org/noise.html">
          <front>
            <title>The Noise Protocol Framework</title>
            <author initials="T." surname="Perrin" fullname="Trevor Perrin">
              <organization/>
            </author>
            <date year="2018"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC8126">
          <front>
            <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
            <author fullname="M. Cotton" initials="M." surname="Cotton"/>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <author fullname="T. Narten" initials="T." surname="Narten"/>
            <date month="June" year="2017"/>
            <abstract>
              <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
              <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
              <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="26"/>
          <seriesInfo name="RFC" value="8126"/>
          <seriesInfo name="DOI" value="10.17487/RFC8126"/>
        </reference>
        <reference anchor="NIST.SP.800-207">
          <front>
            <title>Zero Trust Architecture</title>
            <author initials="S." surname="Rose" fullname="Scott Rose">
              <organization/>
            </author>
            <author initials="O." surname="Borchert" fullname="Oliver Borchert">
              <organization/>
            </author>
            <author initials="S." surname="Mitchell" fullname="Stu Mitchell">
              <organization/>
            </author>
            <author initials="S." surname="Connelly" fullname="Sean Connelly">
              <organization/>
            </author>
            <date year="2020"/>
          </front>
          <seriesInfo name="NIST" value="Special Publication 800-207"/>
        </reference>
        <reference anchor="CSA.SDP.Spec2.0">
          <front>
            <title>Software Defined Perimeter Specification v2.0</title>
            <author>
              <organization>Cloud Security Alliance</organization>
            </author>
            <date year="2022"/>
          </front>
        </reference>
        <reference anchor="CSA.NHP.Whitepaper">
          <front>
            <title>Stealth Mode SDP for Zero Trust Network Infrastructure: Introducing the Network-Infrastructure Hiding Protocol (NHP)</title>
            <author>
              <organization>Cloud Security Alliance</organization>
            </author>
            <date year="2026"/>
          </front>
        </reference>
      </references>
    </references>
    <?line 1104?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>This work builds upon foundational research from the Cloud Security Alliance (CSA) Zero Trust Working Group, particularly the "Stealth Mode SDP for Zero Trust Network Infrastructure" whitepaper <xref target="CSA.NHP.Whitepaper"/>. The authors acknowledge the contributions of the CSA Zero Trust Research Working Group.</t>
      <t>The authors would also like to thank the China Computer Federation (CCF) for their collaborative support, and the OpenNHP open source community for their contributions, testing, and feedback on early implementations of the Network-Infrastructure Hiding Protocol.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAMBbyWoAA+19a3fbVpLgd/4KrHzORlJI6mHZcbTdmaYpydZYD44o2+ne
s5sBCZBEGwQ4ACiZsdy/ZX/L/rKt532AoGynO3tOn5lMTyKS91m33lW3bqfT
aVVJlcbHwdZVXN3nxYfOeTYpwrIqluNqWcTB6yRKsmkwKPIqH+fpViscjYr4
Dju8Hmy1xmEVT/NidRwk2SRvRfk4C+cwXFSEk6qTL+Ismy06v1bjxaKDf+0f
tMrlaJ6UZZJn1WoRY8cohnZRnFUtGPdp60O8gpVEx62gE/waF3kAiykr/FTG
1C9Iw1Vc4BcZLzrIR5NlCWuBH/Hr4cmgdRdnyxjGCKZFvlzAemkRW/AFT7t1
bucNhmZN2GAeJql2+FMSV5NuXkzxh7AYz+CHWVUtyuO9PWyHXyV3cVeb7eEX
e6Mivy/jPRphD3tOk2q2HEHfa5gSILeH7TvFZIxQwQYpALKsnMGlYZd7dpPc
67K3AcDdWTWHQ2qFy2qWFwhCGDsIJss05YN5GWeTGA60P4sz+gnWHGbJrwS7
40BmpV9ihsOIe/xpih+743y+Pui/wvkkWTDIy3jVMOgFHtc7d8y/Uoc/0Tne
dcOk1cryYg7N7+jIbs76hwcHP8qfLw5+OJI/f9zf39dvj46e459XeVLGZwWs
AzHhmGZRnL6dxfy7wd/AtNyilgZO9A/v5hbwOy+CQVwUCcMogsM5Dg73D17w
8GExjeGs9KgynGIhMxAS0Dd0Fq0WEoa/txcHh7z08+Ftdzjovtjf7xzu/+Cv
/S+I+beI+UEPcayKiSCblt2RhQ/HeVUFN3AKtR+uU5i8CF7mMFBcVPVu1TK4
TCr4KU3rP8VhFvTzLIOfVh4oDvfpYxkXSVziFnUxuCnouIjHSZgGg+UoTZgw
A9kmtOsPe12g0S62Ouzu+xsf5pPqPgTWcxJPkiyO8CCSeVzBBmjUiY53B12b
wAEHcBz003wZwfrHyyKpVkEvTZMwG8f+Hg5lLUhn7xHEi3ARF7XlVHGYVrPg
Mo9iZCwBnGbgHI7wzcDnm8fwuSryaDlG7lkhHn4Vfw22YS07f9+unrdanU4n
CEcwSziuWq3bb5w+SMogDMbFalHl0yJczFadUVjCSQj/7RDdBorxQQQYMMWT
qvIAOFJBxxOmya+xC6gFUNM4WaRxGYxWwTiHdUMbmBzHAeSG/srOi7jMl8UY
Wk6KfB4sMwYFDBgFwK6TCnCuG8BS4RMcBzbEFvgT40ZnFMP3cWeMqDuugnAM
bUqcFA4lbcMEwPcLnPx8EIRRBBPC3trBIi8q+E+YRUGUA6vKiA5KkFF3SZmM
0hi36C1nCRQAa7mdAcxA+i3nKE4iwtySzt1AKXSouO1CNxnDNoUrtQOYrgyn
ccBMQxaDP03S/B6nj7MQF+KIzSCZA1hxZiaMfIKw6QbnFWx0AXuDX3gx1Swp
omAaZ3JI2FSBPmNUgBXOsjzNp6tOB/hgeodf0jFMkqKsOk5nhFbwIcvHH6hj
DvgBEI7cJkP4JY07g3D8IQZGJnDj37aHg94ObS/jneGB3oO4gxO5Q7SOgrBc
zYH0CwCRi44ApWW1BPbinzrDCvSANBwlKRII0uocCLfIYOtFDPCUoyo9ThKm
ZY4HdZcAKgfTZRLh9NQ7yUDBkc3Q2pQ9ddbZ0zawh512cHI1bAdn5yfXvB6X
BHJghis4wSmiR5fpdJ5EURq3Wk8MyyA1pgWggzUkFWLfOF7QCpKMjvHgxx/2
ATPwz9v+YA9wWA4RzwH3mwazsESKA2hXhKekKSAN4JJwUwVRKsOpjRqVMqpJ
vswi3jACAL8SEJ5jN5ipG7zO72OQKLgExHui/wAwOc3LHM6HARp/XIAoAliv
yiqel3jCBSJIFoKqRQDGtYRVBcjRDXpl8A7WFfTjYtIO7mdwIEBZyEfSleUw
8zBbIdLCqkCqgzKyyDPE7nZQAvLHUTvYeh8HURJl31Ww/PGyDGAfM8CvVb6E
9ssUiAlW8YFXzksjeGTMtNJVF9Sn2zwKVwzg8WoUF4I9AKYsAvxaxATfURxn
qOmicB/TOoHWZvBrhBwOOxeoe8Bye+edqAAZnMl2S9xhMp4FI2JCywyoFPAd
FoFcdhEj6gsqE8u5W6aZOS3YXjnOAfwragRgTvOESb+LJAaMqyJmnKfM8pJs
mS9LWB6Mxwg0TfMRkI+SfrkIx8CTElxAMiFMuI/DDxlxRUQ62HzaqQDNu6DM
gfID/86mS2RTKBZhmu2Li8tyJ8DxkZiBLvMsn/OsskA4iLgDYPU2k8TC4Xrn
Bk9wEGEhcaBYLYOUhJML1CrKGWyy/+6UFjiHPVYoFHoouuAYlmnF56dIi0LN
8DM48BzabZ2EsPszkBRl1d6CI4lBJO7uEq9nUMf/sUTFfO0MdneBvWZBuYQz
hOXGIB+KPEMWjNtZCe6jxCzuEsD0ESA+ChJomwBHixLcG+uRXRbQDpsgClYM
AYyPaAn2JAM4e4d5IQ6kCUCAmqEsSMYAbrKa2oSoIBtgJmSnsGkh5nABDC+E
CWBrhOOlaBXd4D3wOeI0Cc8afxRYfpMSkU8mMChMmMX3rvADvItZWh27/DuO
NghtIDuc27P9AGYoLEbLJI3KYLkgXqVsCyYgrBZmuUFn+q78Iisn0H5Zghnh
XbatvFVu+k0S97jV2gX8O0NBG7yyfTpgWoGofSOi9nh3F5aFMp9FcAlYGmeo
BSmOMtcgNq+iA/cCqwPwKQ/q0mRDktn+bLAtnOM0I6GLaMxAWDAQQg8IJBVh
NSA+CeEFzqMlsEvASupuRTJPektQ8eaE88Q5e79V9Pt2niisH2IkxfEMuFXM
fAZZbLFAvtyBAUGl99bW8vW4fFmlRpGb52DC0WTI+YFAIlxzmyS0SMB89FdA
XODzpdXjDJnAd64ykdOxCPczUIOzKIENFzIPMrsw4qYEaMBph1FYzOui/gCG
2h3LMRbzhNYJfWYeg+BA10oZbF2+Hd5utfm/wdU1/X1z+m9vz29OT/Dv4eve
xYX5oyUthq+v316c2L9sz/715eXp1Ql3hm8D76vW1mXvz1u8163rwe359VXv
YitQJmMAjmYfIO4oZtwFWqoIFVoA4HGRjGLUXYKX/cH//T8HR8GnT/9NPAWf
P8sH9BXAB+Dkog3mGUgg/giHuGoB24tDVOtAR0lB1CxAcqZ4CqAMgJoAugLI
AIDm7v9EyPyv4+APo/Hi4Ogn+QI37H2pMPO+JJitf7PWmYHY8FXDNAaa3vc1
SPvr7f3Z+6xwd778w78gfgedgxf/8lOLcWSSp2BoMF8qQBrjkSyRlkAFypfT
GdCEf2jHxItbx18pHah1pzdFd99xgDOO0wQ+dBDvrUYHcwDjJ/QlsYbsHn6c
LzOheB5nCPI1LnQgNu86wOSy2IheGugOTE0WowUyy7JiCpmHH1Aos6CJwCQo
mVhoiX3cE0zb45/7PHrKam+spifhrV12hthlLVpjyYI+P+jBgI+IE2hygnDc
LJZarb/c4iAbfEOt1mkfF30KIg5YxjjoLwE6Qd9hn61W77R3Am16ruRVTm/Y
ea8s83FCP52EVQi9hgPpZBn/UAA8YMMJVjc4xVYDtnJOHfgMcqDnVuvNK1ze
G+BCDuvvE0tG/nXCXPTacFFxXcAZGCvamBvsbgAFJgFLRAwXxVzLhwE5D7og
cGo4eZ5ZHY8knepPvnGvgtpRCEcrOXicx5dBbG+xHcy6CuBZSJoqAqFLJFBD
C/iL3AybHQyos2ekSBljCT0OrdZhl6Q3z0QuVvTeMlBxT/whRv3penguLZ61
CVdZ/2K9OinpDzAk28HbkwGzTWBqfWCp4nIFjloVYVaSe4QwBLkAUlJC9gsL
2JLXDpiQkgmh0Es82MPKn+LKT8DgAYIiN1HEyEx6zXJBOk3k/Uy6LLAhAnqz
YsDSfTFDXRfUA1/yq36M/VmXAc0pQa8I2pIsS8Mk5eUddUkHA2vlVRESAfoc
gFUjUrJEOxZtw5j3FvHDcZFDzxlSb45aIKrvjrWAhivvGJeWxgCnDqDRXZLG
oDswY4IlPWMcttpDP1yEFn31l5ip15ypwyfGhnvBlOjGnELz+3BVqtkHuK0G
2PZ575L9GLWzY9xA10YN9WGJzwkdrTLlHqajdLFJG4Eimq8IALzkcQqLBMnL
FhMtEqxcOGRQI1ED8Px3vAni32DmJR0w3kP0gpV5qqv5AVcDNuUt2+2XIEam
hjJu4mg5Zp7BBAVnUExCdEhM4cCRqxp7vcFj4RrcyA8AfITvLpcgS2YdSE9g
bl5jOUsWSC+3F0O2ZXBk+BBs3yqlCckay4XIEcMenz/vkFi2lBwWK8MiS5Z4
uSX/KEFTDNERGQEZUKWonSgfIsKWcWW10MWyINeNOsticknBIYVod7I+nBRm
XPK/wnDoZkEli80vIMwYPqGt9uSJw4IGeUk6KYCs1frb3/7W+r6z/s/3rYeg
t1iY2MH2xQ87QfAQBK9vb4FFDS/p38PXQNrVuLthiED+uds4xYCNNZ3j+Q5O
AaewNxxegE2Csg+Q18jG/y4aPMDoN0+pHHv74tkOt4UpEQE6rkwm1GIkEnMY
FYTfOqdFqe2Lox2Z0zJ8ZPa/eWyNf2xfPLX7OR9saI/njeiAOsCJRZ8WHjf6
ZCvojcDYFnGFB0JUwZ/xgFoPOtxDbfi1zzDq7u4AlCekjwEjNdD/Qy1Yo4Y4
SViP00DTOg6o/5SwIOAp3sOx1U/vegzEVNJsL0/Prm9OnYP0FQNo0Tu7Pb3B
E2lsBAyQ51GN653hNDS+fM26+vnVu/Ph+cuL0+ZQRb25NG77yjU5y4z1z5P3
mFUOmVXSxKfW7QSmWqemDtV464PqPyWGqkIy/hAvk6pNzgLV11nJEL1I/Why
lIjCp/gVnBqt4CqX9tpwCfOnvl8JZ6Y2cxSEYFuiL5z9I2xdEIbN0LU7A3tA
5nrnuVzfg7mf38uUoBl0stw9KlWJahB4qI1c83ySpxPWIwKFtonEgUovcKZO
DaMAfKBzzEEphkFNtAKUnBgkYlap1aGO+0YgJxU5BMNggt4yEh0pu2kkVr+7
y842PguFGAhRUKWMW0nARvEHd4PoFSWJMUapixj2CF7cE0iPWQYAh4oScd7h
kGcp/dQTfZdi0vTPTwHlKLBD7OjoqfM99nttYG2/98FoWNraP/+78SelOdiV
0EpjM1oP+dfLJbCQOCqbmwk4rD8b0JYUf2aN+C/kf99/EQqA+QYQpfP9y4vr
/pvTk2BbF36upsXOt269D5ZHXplwg2LFF/aPijQw9J5lPM6iYWvkxXS+o564
lbJ2ls4JWk2g9bZkQKzv4es35hu/+o9xdzb28Zm4fktERhQGosxIt76nmBkF
jmIlvraHLNi1Zz3NqR0g+MlpC+eIJBjk+L0atWIYEx8g3+ljMfB2TZdXk1MC
gL7cY+PS5TM4fk0Uth056EYk2qLD17ghoIRorJUX7bC2QCDOLxBUwQh2Ku5w
2CZMDviBTlR26K1JNUQ8g6fs6qbYhuVl7He+GNJQtIWSXIB0gmopgvyfoPtf
oAE0D2YVBuXoWN/V2HdPEgco3MfxiArosmKl/iHwRcjtahGLRBhYTs3qjvtF
q67GNOo2DV+0HiwVZqrPKCe3MUOUYMckxeDPP8PJWhZnnBAPrBvXObdhWttx
d9ptB6/jsKigfRztyLDvbABCBr/yBKVyO5oBQVFLXRgtp6Uqvo5E3jy2baRi
iZWFk5N8qIGOIM/qAblSxtStWwFXgwmohmDf0ZD9giK0mNZUVsvJhDxNWZDm
U5Cyi3BqBh2ExnZPnCHpax/GSAYUEzWQbbQca4s1SpG/VOt1ZDXi/WwVvMzR
m1dg6A4WHwnzSfHwoxwWjAxGyAEjgsbeQqrodChom66UK6intMusyx9lhu5b
ha7tamgNmCSAbAx9DXcjW1EYDObMAIkjgJAjGOJ/L5qVhofUAUYUj5jexhFG
Gt2RULM5ZQVntqqDNCf93JsDdqVsVJiLLBrYMiYOgCJErB60pYojEcCZE/IA
Cd9A6BLHUFCZ8ekkyCfiat+e288493gvyJzC9aW4mrnEq8iiR96lId0wBYEi
npXGDKzjIMP8DY0Rhyl6gpiJr8SzAuQ0xwyuuocE8IXYiMZhnxgfi5VuNSft
nL0vdS+t5FRICnFCzton6CFZ87gMhaORViHpDYbLcZ4D5xBs8Np4SRCELiYt
oAO7Iq+gHIuklVnDhrxEwsJhL0bINPj4UQw4TlEvwytstO0RLxuczFbusPOk
wRg4FYbRal3iIF+0LJr5ChNBN3i52au9pkaw1hHfkfPO4CyniBEbJV+Y5dUG
srQV4stMxRxngT7ojStdjm2wDQAqtrnKsTiL2HPb9XkBsiDOpwjuZ5wysNLv
9cx4BQ4bB0NrUhHq3FBknBe0xKQXz5PM6IX5L2CSzxfi7s1y8nxVuYIDzR4d
uhZqD06RLjUuwEhC6Y1xOathCqJ3AUPwauF0O0nWge10LilRzALvsikQ/gUn
uWpRqF6BzCoIWZjuHQXzu9I6hQVxjDOCUNv1FRAP6Hn5Hdd3eFrxPcNTPJEl
p5+4bt0N+aTkv/y2zM4REBFmY3Eskc+rgUIFA3BDfZM7ht89CWxUUoNO/FGS
YZ0YJYyLc6Ib/U07AEs7no9i0BIiTK1ZpnE9dOl7Vogpa2Kol/aKCZvo+CgX
mARgSBl4drqMYpKHGjYzyl1GxIGLfXP1Jtgm22pHcw8INyvZjERKdzGaiLml
6yzKDZkIGtWS542yhXINMDOc0igEG4sxlgr4HKKYKBdIAZGITIFdMtRTJmzJ
60km8Xg1psxW3DD+9iGOFyHmrpei03fqJoWenOzOHB1/xrOjHD7xozZEhw24
U8r3JCiDBIqTOwWyhI5dOBv4EtMzqIJQcdm0Zn5bVFIQOWABVY5itxzFKUQc
SRwHZRTQ0+NxV1DHe0NMuCqC896lRnFgwFNY+lKwhcmEIlSIVMzB0NEnS2rb
TC8GNVMMnhpTa0krZPNRYdHrOymYkv2d4TrGKSioZtKwmnkIo0dOKZuqtyWF
HOnZMhtrLma7hr7AHBcGq9EfSAG3XoTaCma7V3kBKhacciw52KSl4ZWEYDjQ
CwibwufBp0+1GxmfP3cd5tAHONdTAXYcbtFXdGvODACQsihDg4HTRTGVcbYq
5dOm1IGv4AuXqIbC/+PwsPFwmVYdDEthznZ8j5pkscTEe8ongk9NCQou3tN+
rgew4b4NKmN+J7Ay5AGM+Gus5TaGzRZhkeDeABVczEMk4PmtTlunnNzNpIUh
K8kr97bEWIMpPYpIJeNPTFvQWKrMC8CWWBd0WzZxRPcAgVEwnKN1LFvLZwi2
B6eDHcC3BhTD3JmEk/oEhR6nYSZhXgv8RUInswzAYxwSZvbyW2pk8h9Lupfj
wVsMO01yEU/tHJQUF5POdSaHu5xHwF041bUMLk56g3bQo/SK4ASgPgaiW5Ec
vD4/6as9R6aVQO5E5mSwwYADTK5M3DSE3kuAPgxxg/9VLgUjnHhMEubHI6cj
ULUSDz0pQWWEs6OEBk6uN344Jj7ireHYyYWzdkiUhCAC50GSYhC6MFp/4YZq
VcGQPCThecdNEczvrdPwa39oPXi+Ro4IkqhZ+wHxSP50f2g9OHIGPpuxf3pw
ESN4+IPzA7pCAdnMCN6IpmFnbQ3/tkQLkNdAyQIywtp2mazefD0czBTN/zx8
sYGyri81vNvc4JE18X76QVNfXdt64JMgLRzm8U00j3j35TVuBLCO9BA46Ufu
4ToYeKNCnxdC7t4Bakv14Y2j+8T6bvkiAGv8jlIghig7eVkc23QEUDkmyXQp
4uWYGeWwwox3ci7Z4UEtAO5QzlF4uekzyDNQrSS1YhxnIHvyck1rCLPIcHhY
zzinDBlUf8hBHM7jYAYcRoNX7qqCkhLqKeuhjKvlAtPyQb2YOxIXL8Ja64V8
3JRiLpy/b3Jb3P2cZ05ajOhMy6iWG0T5LZjnbTfTCNIQ5FwYgV2acvK0pNMY
s1N0p4yU1hDYKayTb4mR2gJqXUi2rJ9zQ6lL5B8f01IJ2ubOSDylRXYD31yK
Vlk4FyGuhjfzU9Rv4rJyD0ZySinVCMYe5XmFHHjhn4HA8TQCuwSW60KRvsty
DISKT9rmNcHQFXnT8BJYArvpyJolDEmKB99ZwdMHC2Q6AyaP/17XbmmbcFAx
L6JUJS9ALRNTyUnZNPo1K8AS0MGzwTwrypEnDRDWmI1ZmpNm4+Uu4V4vKbHp
lhObamgjkq+jkpb2R+2bUIjjIDwQbtXkBWXeFULnUBjBwc4r2ARyc/oIW7x0
Pj1+QwDflXxpEu8U2X0Zz4MJAcmaSjDxhNQUG1Tb6QD2LDiLXyz6uNBkL1GC
EDvRluEEeGOovpf7kqIFcC4HsbLgrnQZG6kCu7teE9DoxmFB+tOjPjxy0nrK
lbnqjb/Oc1Wkp3QtyEK4LeglGeoLiXtbcw8sELNqNleNxYleY5uZ8QUrvav7
szt2Nlf39xsdh5UfkQWSL40qqiVypBe+HuN7MrQXJxtwqE4d40hP6I/Ey0lu
CK+0aY6cbYZeKw8vjCuI9HE3t6PmDdq1Lu5A0keRBq29x/4fxQ4QNfFC1EGD
lnQJVRvQdYxS0kQ9pbHErhqI5ZD2DUMKnfwWUuiiKeuOA7nsqgSHlreIEnu0
1p2Shsm8dJOT5Eg0B9i3LEg30zXIBDb7nbwhHlIDt4hTIDOaQO0G1Ao32w6a
wutPfMMGakwhlCH6dYE/ZOWGMdjDIV5uJGypv6GJiewhQBSgzPdS83JP8pzy
nDO5B+Xs0oIaTVcxVRXUIubUe4H348RdIUDVu656M9ieoebfwhB9FEtC4eac
+z6C6iGhJ1AvXSFMacPU4eaW5Rs74bCPuTWvibSMPFd5ZaLqmzcL+rVuknrx
FWpeRZV/iJlTuUFYF6qUKWs0P3ZwbEJhVH0tPMlxY3LURFNgduVMRu7xOn+A
eV+46evkv0DGPo5r+3RUN1W5av4jlRpEY4ML6zQ0TBNm+xFnu8inU/Xq9ZZR
QqSqX3LMyl4y+vQp5V86EvOjOT9/7mIPmw6P/SjGYN1NdDumiO+UVlCnlRt6
YDCTrWkSfYzBpv+4tpr/ba/vqfRAYntgerU2WBLf8CWbGWgxGj7lmYjfMEZj
cxyYrFY2G9mkXDOSYLJHxviDjnFDV3uDDWN0HhvjH7UX5TCPAelLe1E+YNb9
jWN87Zcyhpmy/+bRKb8ZHt84hgEfMBKzjiZUeGQrf1z7hxU65SX83Tefytfv
hI1f91oVSAtTV4gt4HiOKjsLhE0ViNDf7BUv+vzZOGh9GW3EQz0j3y00IkHF
qNYXNCKMv2sMxebLLDAgAwJao6Jup4HpBBaHl6FTBnQNUi6t1JSiTTMfYzaU
+vUx3TnFgH81m8PfN7EkgfuZTy5WeH9jbs9r6Ed32w6fPTv4EQc56wc//HD0
gvN0ksUM2Cf8MQvhf4f7nUGerg6e7j+Tli+Onv5ILV+H5QwTol/3OofPnsuv
zw+fHtGvlKMO+tCd5uC8fnNyJo2evXiOQ6wDp/dnrCeTaABDAfV7QGBAi94G
XFjAH8XBjtne4aEPiN7pENt2XvUvdf0HB89dELy86L05PSwVlM9/fCpJRDXk
tfm1A0EfxnfZZllDCO69jnPi6vn5Zx0m2D5hH7/4wOEXaWszncnNAgRyHxZ0
Y7qIxYQ2qnItA9oNclM1HInPOBdmzSxcKcZLR0TKQFr/+WeswdT5KcDM1z90
ArxPBv+PtnXJP+AtrlidYk+C8zd2WxJtpTSUa7D0MKcmkk1CO50eVkaXbCms
4QcNP2T5fVnzaH1XkvKDREYFtih2i34gvj3f5qQKPIECyyKAupIsdDvnb455
H7j4brcre8Pd0KbK0t+mszFnX9dZ3HkfrmQn6xtBeGKi/D3FFygUTlo/ldgg
wxB3JL+QWynmmMsormXvaykVjstQFgcu6NFdlN5FEwo8xuw/EQ8jgg5+Auwl
D5nntDSKJrrKBMwOt0FQL8KEQ8XmmI6Dt7rtejxc/QRO3NpVcZ2e4qj7cs9e
3+s1XvJtsHqagRvlGtbxRTj5KPa8fqpNhzpsvqw6+aQzoqSwGLMDknKOLqci
nibi19ROiqQ3p69sHStgBerAMzk1Avpajg3MpnVfeGexmzRTmRJNdSYAtN0k
ozCN2JNIzJB5W6C/R/k8yJZzLO8j0+YF24H+NVJbvEP2gTh1k1d6aZsBS1uQ
BGa8MZFTPSK0bJM84rmtqxQBpJbNTc9JKFC5ivMWcYdh7JSfyp2LMlQioVgu
TBLOpYD8jJxQrVYP+CVith19hjAOCVWwLFIcovvQpoQz42aao6o26oxYhCt0
YkpKkkzzmrrDMVI+oDMR7H+aaP5hGEySj3HUSeNsCh95ToaEzC+/sC+yVK/8
mIVXOcaj4PaFEZS1rGGjBt3nmJcIQGKV44L+BqF2loaYVwxW/z7Kcdk3pjc+
SIlCgjh/s+mC2WOfVDDzjfvt/vng9enNL8P+69PL01/6b2/enaJ0xskPj/YB
vBUlCz891D+h66vL4WW9J36HHQ+w8f6R6fjc/Mn8VyCZlN4Rci6CnuEojwAD
EScobZ/ugFIKqnHp45BA2ZFkyj2R3Qi4GJgI1uvJpIwRrEOG4FkSp1ED3B4c
wODWj+gOWBzOR1hZUSjw6WEHzwVTVbAs3iwvQQIuMFwhyIS9j6Q35dAj4QwY
IWkF7eDn6xuUnZpZpXNQ1xcCvsvwr0DZ72DbkmUf/Ki/JFntlwM6KIM39NWh
LOFtRvJtG43++wIzgTMroprxc4dHQAUTV9MHkYw+Ufzy8IjR4MFhjoKQyGWw
CSmmL3BFGps/tuefT5pchot0ibLr4HmHjhRLPgRVOOVlPMXxUFVWOWjnO7YY
+egQL44CWfqt5kQew9a+3PNw/4Xu9/Vlr6/oS6jPhEvX00xUbkKYxShJLKAR
SoD2BiDqk17bm4wFbV8oAW6bXrU1w3J3vAptvCShMhBEhhaFUIREiBBAsBkE
3EZ4JlW5g8UzFOMJ1RswnXfYiOJ28fOw/KC4jpf6Ss5SqbQXsTCka8RPTS4X
lnqfML2brHV0uTdO564bF2X81tha6mqBpIK1A1ZjQwN3YebiL/e5j/ZEBmV6
bqRe5fmYkxQXlNJNoUTS6oHioJspWUjQaRhhGGNWl6y+g6svxcimndBJ4Bkq
8W/LonDfzDAkFz530lPvuLEEVxOUWDFhAwzEDMMd5iVBBw+EVA3UbDR3iso9
BJgnT15e0BmhE2qyu9gr2D8OTj9WGJ+LjNh8z2lPUo9NEJISliufjuwwB7AG
BD7qt4UWJqHyFZFtdIi1ZUltdQyKCWzGNCmDp50DGOsmJi01QuBmlB/EDoG4
kqKMQB5YtdvpeHDYOXh2rOYoS/Rgez/4IwuYNnDhP9LadwCCyh2JOA3pYORP
FUFFxrG0bJZgYu8RsxaWghGdF5Zx4lewNMulKKG7bVB5loBKe+S3pyZ0nLTH
oGdWwVStNaL40iybdFy2KzSKrMFTYnEA6K6jCrcNl28LD2tbJtsmrikldNaN
A6YDG8owdregqqVGJhgNBOIZYekrZdVMecSgnfC9IBvgECh0Elms0TcrH25z
zl0UpoDXGuh6hsjLdQ7HMzOvcG+gG5CB/QGwnKHTArPJjaelZjNiKMJXVpHP
lcGnJz4vQG2GOGAfqzs/BFd4Ig+S1saemhMKCiwa7ubVtJwGFRH1no/7+5KV
hMGJh6CX4RW8NyZIIY0OtBHlfJFJ2flJAgEPcmdW4n7a5VCznfpv5FY/EMlP
7DTQLuEY3QdA6lOuNMA9n9o8KbdnH2fuW29jfcIj7XZzSy2dBda6kY9eej2T
XhfD24adXWAijrmuRThtw9KljvFcx6CZ61vVZMoUx/In/0E69q+bYNTP8w8J
1/kFY4sqGWvHF9Lx5s1Vw6pvtDUXr+FhpOeP2vPiz9QS+LHXEy87oEVFBcCk
T88cyEUTZDOq0pY50UDt+FI79t6snaR/9FiF9tGh+jLU9e2gYcfo78ELMLDw
shwjtdSQ40S3DabteneGuGfOSr9T7ddrOqEbt0czMp8ZMujbiQUCbrhc2h8o
OZ7+3ISP56Y6KyUvmTCmHaT1jrQGHOqgA/96bkvkAV87ccxg4jGq9GwyDojl
rYzKVo8japW9bmCn/QGmPTujLoVKY4/ZeYUf9UvgqokkkPzr8PpKiqSVXTHf
uND5KEYhSWUYZ9KOHBu6vcd28l3ZUPQSRaRRXk2qC7sBHxsMFN3iA4qm4N9z
LCI6X1Srf3ey8ZGZbhsuutNqvVkL+24KGJu7Ql5ylxOztZda+TRAdpNIcmuY
mXXYazet1hDRku+Ci/PWT/SgCtiMRyY+z+WKNSr+wDAn209vjN9oYOcRYbQu
i9ZFEUtkGVR8AAHdIbY+EasWE7ksy+Ic50X/IOja2phqMEi16EQs2Si+a2oq
Cdy1xnkx9Rtf5chjnFdD6j3CctE0/Bey6muDAKCbBjHZD+vNQZRgC6YVXeeN
fA8s1atdOYvxsrnAjWKS9Z49q7Bg3QJOmXhw75goNtXYdw25LD45l4syvSNi
8osAOX9nnIqLQlSndZiiGCZJIQ0vy+nakZ8WBZaq8ZeA+3iNsRgHfDzqZbhA
qJvkNMrbNO83MGotMtSXG1CcyqWQDKMoKxOg4NYt5cnUV8ffYmsQyXTGehlM
Fko5pFgGYh0AQ7k/xYuDjTCjNsp5OFUZFo5pnnLjdjHXxknn4UWDHt4bi5JU
wzKq3CDFs8dWj4LjJr32bZGu7fRGfgve3lx4CFm/BKRZbo8jZL8puyqUnNvf
GSX/c/OsshgjPmITsO5CeizhKq6kVMkG7OSboiEabwyXsvqaQU4o8V50s+aR
voYaXXQD/b6ObiVHhT3Z2q8JVmMfivavue3Xg39K/vc1UNPUSWxf1bmXIJrP
Nxy2wUyC9ePzbJI3cA43l9k5IbTitsloU0ZgAllonOlPcmjaQz0NxuthXNXi
sghNjmzbFlOzfN4i+THTd5tpty1Uua2a5U6bqY69OCqG7c9dWdONWdPxPyOC
kKVbZ/vDR6xoc35oCG+z3ftlneJ3Jp6q+EisTZF8+/kRxoJ2DIyobiWLsDqf
U5u7DtZmk95sH835bbDev1Zjt44nGVcvfAMcv2Q1VOrKarIb0Duwrc4Argbu
LCeky4erdfNBI9+hOhColsgsTCfI87ROwe98biJjgocmoXBdJNMEFVxJg1AF
CDsmWMl68KFaP7aXYRnD6YMhmEdk/WZSTcf4SRyV5IJlBLkyviQZyOQyqWq2
VIsUCSLv/+8Jq3+cDuBJ4y9rA6Lajht0FsyFdyewoO29IdB+i+3RlxseRe3y
+MU/peQNx83aPG7TILKBF7rKKBOKpPVAPWPNKnIDe/kvTfhbqAA9j2uzGqBT
i+WIAVnD92ktsPX3mOjo39y+kdynr/X5cGsKtNhl/Nfpf8vp59VifdI1p/T/
NyxATqlY8M2+mn9O1viPOEUu1FH2Ks+2oVnfZslHMm2wrqg8JUnv5JkbiSbf
kCsV0Ui+98yUaHmMMFlHUAeJ9b7ai8x9/9JWaNwYtQgEmhB0LVYg3laIevYI
auPGT+SZIv9JyH+85l0T1HGNU1tKCcOZfwdpYlxn+8QEb77NLZ80h39+u6pv
FOTf97STxTp47dO2zBZRCV6jOqoYK1mw7B/Iq3zteLeq8WILk363ltFi638E
FI4Rp95Kge95FH5nrXp83rBhoNvansPxgHe93pLBwW3WBIZt5YuLzajc4GoJ
x5zxMuSEl3Vnjp8QIxkmnBXXehKs3VakAphXTs1nSekBBlli3EvuK+KjZrYQ
JL5GJDnF5nmPeZ4lFVXLaTvVKphT4XVqGG4MH8J0VSZyPQjvPFIKBa/AvXdk
b3vAAvxqnkLg0LlsHVNhz0LqmurTjhTYo5fxtOabZ8hgFkxls1/0Lrp70ZxL
qcml4nxZ4TubXS4/7mTG1JZQK2vMtSzdunO2Ep77QI5f5bopAYcfEUKgSe0j
f2J9IUgKs7n1mEza0SQcUyK6PgVIwd0hP1Trj2ZvLMzojfJ2rXSJ2QCXGTAP
c8uG7cnWE8apaJZTjNtwtYhpmj2D1jliUYBfK80LdexxgaS/lnnW+tQKgI/o
YW4dB1uH+4fPOvsH8L/bg8Pj/X34X3d/f/8vW21sCov4BcOR2JLxhb83u8Yf
stmiE45hBP5NAr2/JBH1Go0PDp92u13+EaWF/IJ//in+GGLIuQsDcgOuyCdN
+ENnuYSPPDYh3C8JLf3gx8PufvewK/MqOkpf/djZ14WxE8tu5Rdx3+rEFRbN
h58/fW59NndXiOicy8fBpyeNd5LFp3lt7xRcgHqqGQUmrq5ZBZuD7pr71ijq
jBXjpzdIPGuu6ZrE4Lk2j00moNvdkUS/8PEJum5g5qASZi5PSd0r1sf6Hp9X
bFAKMTOu+lZ143UQuq5zqqWuAdHNHKbyAFfToLxV5+kVvsMmmAVjvAyr8cxM
y9VrTQIipsthnB0rqekisBICFkzGsn8EAOQSXNHZTg4dhhWWqaSB05wvqyQT
r5W+raBPDBDfxqIEzpuhzKBVFph7eZbPE9kSNIbX/eCQRfP5ObAykDHeAWLB
0ZPBjVNKj8asNXl9Puj1pDcsNknrDQb9887JcNjcn589rz2xfjJorCOtz6fi
aYTzFNaEb3t6L5598Ulf9+WxsHTTbT596g97XWjUHS7iMZC3VH/01uc/t3iO
pRXoNTXnZde2f5sM01DopS9s5nwb6l0NjkBgH1uu7oFaO5/XHgVoeuvI6rfc
/1zu3QFcOJze8mrB6SRay9L8TslT+NsrrqUkV0FdOAy4Bq7UPznRxwWowLk/
aBhRIUeMDDpzaxlnBUxtqeZ9Q1+M6/D1jS11dMzGQdvOSQat34SjMiBAoahv
DQe9xlomtRoUWhWltjN6iVzKEJmqilKmxCkW6dQJyemVEybIPPNAbAqy1uqX
iJR+GWeAqZxzQisjKJjz4Fr5Q1hZhgqm++KnTP9dyYys4WFkq0+OYrzEuXbH
FtgzPSNk7C6CG84oJajXT4neHdAIgL40V/gHY+tNy0vU/uOBvOjQLdBquFn8
yIOCPBhlzrtPfF6tJeapXlwk4xnhhSkR6d2NX+dPJ1fyZt+Yimh5by+uP5ro
XlxEzANFjdTXdEkjwoFuLFSNg23mPpsqT37Fdx6zkGqR9UKR8h2uwXzXWisF
uVYlQb/b5gr7YbrTWBnyK9f5WB0G/m9DccS11+o2wUBuB+EWzbrdUiu4320w
gFnfLnca9/tVc6lKt4mHNj0NOwvvUINTGxRXWfBCusgc7QG6VFWu8bu7JLTJ
YE+77k9aosnE2a35zImr6o9xKnnR81ZlOVnWK893kfPZRSFt4M/mxSSpp0uo
j4lQZiIt/GUeFcCdxtlyrjkg+owLMhKs7uMs2F3tphd06YWgZkrGp0xrBQyS
pjaHe+/jEXI5zgYridGy+2n9jc8n/EKqO9kZ1aKDc2b3m/uqNcksMxFVuC2I
pR96R2VLePnNnK7MY/GI3y7yzD2ohhdb3Xp0XNEe79+7paPIQjEvctAdX3r9
FRTTERwHV+RsGNkYwawIGcBOpCOcD2mfXtwMX6UPtq9vQUNTfMXgmjBs1FUv
h3unc9QuXSOcXNlSupqXyF+0nthXt+rqMVHhxtegpXyLFCt85MmsYLRyTQry
1GDhFq9snz7a0lSnj1atj4XMG99ycF4JMRjvLPXr637n/Nz9mhnVMm/0khfb
XK4kuYhZXHqk+p5gvbxXKQhCj13IC5EDpuNE3mi3dO2/iaFVAwiK5oqTm2Ep
lyvEpcGkDYoXGTHbThGP4+D5vgYMdmCwt1kCKpvc1XIuWOJu5cWJEZfF4HRK
Mj/lrRB7b0vqn2qNcVNNQhGruTIO7ebtb648gKfk1xwwhuGCKtHEnI/PEZIl
F4NMQ6zuA71fDy9Lya0P74BWEGaeJUplBaRygVtmm/YU43NNgO40hXmGhAMw
IIZS1i0zeUiKqpqxVWohYgAstwJJhHknaCv9e0eo2HscHAUzQHQ6R38sOpk7
wEgcxout2aZ6otpBj7mxJocVdlLLOMPtolkgQSz7anTN74ov1WA5fy6b6yGy
X0dpsfz1V627j1S3rEJTGQggIY5bW94JeQKeMb3ImfD7Yg6ftsXwcCbKSBJ9
3r4sUy7n7FRHO+guT6gAYUy34pznO8i9ZJ79VK+uunpEIdXnsHlj6GvO5wnO
Zh7hYRIlknWf/eCnIij+x488ScM0nsK25lR+Vp/H6tk32lA9cLjMpqf44LTz
MR4Vl3qPuUytMhV6AyhR6ewuChWA3lVvTSDcuvds1MdcclsAovEFBSEg/71e
YlrRjZko2ELIebcMt0zU8AWVNqA7Fc71Ru8WlBiQsIKhFJ60adYUKeFXvw8O
n2PpwVtTMyeVy8voXiMHwju+tKFXGJuKSjVdWGy6ougDpPGCYmMT/0JiYxP/
5mFjE/+WYWMT/0phYxP/xmBjE/9uYGMT/xZgYxP/ul9jE/92X2MT/x5fYxP/
fl5jE/8OXmMT/7pdYxP/Ql1Tk9odunqTf/ANOQ60sCE98vIA5EKambruR55/
4dYce2PZGQ3LIxvBEo4v3lutHhXPzjqmMPKG5bKLhp7wUCEM7AmIdFZVi/J4
bw+Y4Gw5wrjDHuZzQ+M9HDibLfCNVLrDFsXzXCOCpvDA5hGlezcvpnvYdY/V
XH9d/VmI/g3glyVomFL3WBaweTeuD7Yh4DP2B5XCbpewhmLVGYaTOLgIs+kS
ta+WzgVD1oISu7uv8mD7VQ58f7qzu9sGVjvnIUocAiCAVVPnXDudh5NXwuxD
fcjmsQxWSo+EIPDWHsXjskcwX3+v//33tZ2W+txsHrxc4gsF9IzZhDy0u7vB
q/y7MhgtE9CwYQBSLEq+8oWrMjruiLvm0tU8AKdDg2rY6aFg65wVcSzPTfK7
N8E0LEZc2CBN9Q14u78INk4vZpHoRZPQ356Z4grr5A2k0UlsTtZugyQSvxNF
xJUlXDU8dbYCCiq+aiDDjEEvnOkcNyFHHdgfCFNI0T1y/CmECmwU0U9AZLM4
XeijchN6UBRUxoKK4CdliRQaLQu2Yqgc9ZyzpPg9hllO74c5j1qiH2QObSLR
vCl5pH8+7IHNif+igGdFwXU1AzEFh0rzh9FdLq9zUdE/B88Ut4gljaEbau51
I7CUEIPWSEIroTNIwwqjompOWWQ3SiNelLkzPkw1L8wLDwsZgcMBZrwH56G6
r8iaaPhAMv4iyZYfNQmuHWgdevL0n8nzFdGScU5XiND5+OL5L8+PoOHN5XOu
ivmenm0vN4x1xZvURm6psqlz73sejq+HJiePtvWhyheqptMZC37WuyLZvBye
bJgffulMwrk8QCVP5clIui8cpZdFBerGuoTti2RUhMUK7x5c5iN8AGF48oav
/knTtboEibOFR/pjs6bbGJf4WGBY1Jy6pOH5HNhgkJTEB7MmwYdOxK6I1woY
CiOj2PhUIhB956IqXz2ktdlACo9g7Xodgb1KNITn2hCPvlaJd7wWa+8i2NWM
ieF5T43XIinO22lSm9FmOaw/fGLer8Cn4qioDZF1Gn8kT6DztDhgF77GRUBD
ZlHaV2b4VVdTAdHGFmrv0xiCdy28upLwaJ06ilPdx2naoXDpWq3elJCIc2eY
mbsOI4TdJF1l2V5G33NrTsPilra0sPdS4+6uLV+Jg0xJzpKy8HGPV8CYlKbI
WsbBmOq+eWYpjFGvpkvROAJjEZnF8HB7Ur2P6AerythX42ksrKS7YSV7sw/R
hDqiFyIy9Xclx8wpp9qoz4AesYF8BKYXIJQv+P0VXAFYbMTkEf1tnVp9DYIE
AT1/Ehzsz0t+7hubS7yfIfMaCwXdshMATHyCC+Ch92wPPzODMhY1l3xZ0jN6
eINcRWFlXU0UWsMHmGGmszyv8FULGpaZDZH/Stf17PJlm0obsSSjvCHxAfC5
2QlOSJFjNQBfx8Gna9h/4ApkQgV0WyZsD4u+C81TJWg6C7qLKBdJX6HCQ/X7
fbUSgE+5m+YNWF40JbotgLrj4LC7D8gzxre/2zA1avakV3I1U3z/AnhEOMoL
y1w4MySkLTn6gmb1pvLATcSptvxOATl0gyKZ4sbLYBFT+AMfqcVDwMiqTY/T
Kqelvr6MUUE8dfTr9QFex/hyCAbyKBJo/+a3Yp3nJfE7kWkLLHrGNosCR8wV
0En12bmFmcp9nEXsgCvnkR06JBi9k+L+6yoKv5msJbC+3grZtCslKFuGmMOc
VjJ7TydQAlHpujPaQoX4aAeT4bkJ1+BQNyYeishpg2FRPqc6vI+EwvAe2KpW
/klfAUaak3gTwiSKzeNJXvSJWC1saiBHtB7OfqsV1vTolN1hbJdZUo2VYyO6
fYjILH58XrbuVCa+dZD5gnjLDa+YZO7NMpN3k5nvmCGQpWwfHP7Q3Yf/Ozh+
9nSn7bw9DqByEUgSAWXGZo2V2IvBFOgkOlyblbU2q5BtVYdYxwbdRiqBOehi
Xs/xUJtqHmx+use+3MOP6vSc5QuEOTCY5vmH5UISyRY1TKHAqLMUKcmRTMRP
gG2QJPC0TV+Kip47Yfi2O4SZ3JyoFF9seMtXntClSGg9BlcPvylFOwklGo61
cRjNZZ7DaWIZyi6+ROMsTnuwB9YhCymxnbuvrQpVdPGFmbfZ+g9aazG4+vnk
+rJ3ftXp0H1t81Iy06IJtKp9Zl6/2d2tvxpug1WAXQio3V3/OSBpp4rnHbVs
O5jDCWNh2gGsSqM6W2SWKIiD+A3mTsDRySe1Wzll69OxlmD849YkTMt467Ps
gGsHguUKgFsuKN61FNuSnnIvY0xDsYUb+/TOmokw9lLJrNvuD3s7Lv/Hl6Zw
B69A6CzaXIt+jFq/1D/fkrOk1xMpHwjx2hngSvIK/YjlFtYmrcAawOAW560B
JLrvzZfqK2Zgu/dWYrnNnLG+SwaJyBcYxp36RrftbULIXQe+z5d4KmmZA0v8
EHOQP8w+8IAzUFTIfsWH+IKzWJ3uAKj+2Y6mjiaFK+OtiWwrMSrXpYoioo5Y
BcEdxtlWWx+GlMT2OI4o/IxeFTqAmvvHiFkGeacWJH7NjzerMg5waLX+H3ol
YVRArwAA

-->

</rfc>
