{
  "n_procedures": 17,
  "counts": {
    "KNOWN_COUNTEREXAMPLE": 3,
    "CANDIDATE_COUNTEREXAMPLE": 1,
    "PROVEN_SAFE": 13
  },
  "known_counterexamples": [
    "ieee_4way_handshake_krack",
    "pqc_hybrid_downgrade",
    "interconnect_cyclic_deadlock"
  ],
  "candidate_counterexamples": [
    "3gpp_xn_handover_premature_release"
  ],
  "classification_mismatches": [],
  "ledger": [
    {
      "procedure": "ieee_4way_handshake_krack",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11-2020 \u00a712.7.6 (4-way handshake) / IEEE 802.11i",
      "property": "nonce_never_reused",
      "verdict": "KNOWN_COUNTEREXAMPLE",
      "citation": "Vanhoef & Piessens, \"Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2\", ACM CCS 2017; CVE-2017-13077..13088 (KRACK).",
      "known_finding": "Retransmitted/replayed EAPOL-Key msg3 triggers PTK reinstallation, resetting the TX nonce and replay counter -> nonce reuse."
    },
    {
      "procedure": "ieee_ft_handshake_802_11r",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11-2020 \u00a713 (Fast BSS Transition)",
      "property": "no_data_before_key_confirm",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_mlo_tid_to_link",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11be/bn MLO TID-to-link mapping (\u00a735)",
      "property": "no_tx_on_inactive_link",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_block_ack_scoreboard",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11-2020 \u00a710.25 (Block Ack reordering / scoreboard)",
      "property": "no_duplicate_delivered",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_twt_wake_sleep",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11ax/be Target Wake Time (\u00a726.8)",
      "property": "no_delivery_while_asleep",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_uapsd_pspoll",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11-2020 \u00a711.2 (U-APSD / PS-Poll power save)",
      "property": "no_delivery_without_trigger",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_sa_query",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11-2020 \u00a711.3 / \u00a712 (SA Query, protected management frames / 802.11w)",
      "property": "no_spoofed_disassoc_accepted",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "ieee_fils_auth",
      "standards_body": "IEEE",
      "spec_clause": "IEEE 802.11ai Fast Initial Link Setup (\u00a712.12)",
      "property": "no_data_before_key",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_rrc_state_machine",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.331 \u00a74.2 (RRC states: IDLE/INACTIVE/CONNECTED)",
      "property": "no_data_in_idle",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_pdcp_reordering",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.323 \u00a75.2 (PDCP reordering / duplication discard)",
      "property": "no_duplicate_delivered",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_rlc_am_retx",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.322 \u00a75.2/\u00a75.3 (RLC AM retransmission, maxRetxThreshold)",
      "property": "retx_bounded_no_runaway",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_drx_timers",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.321 \u00a75.7 (DRX onDuration / inactivity / RTT timers)",
      "property": "awake_when_pdcch_expected",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_rach_contention",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.321 \u00a75.1 (Random access, contention resolution)",
      "property": "no_undetected_collision",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_beam_failure_recovery",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.321 \u00a75.17 / TS 38.213 \u00a76 (Beam failure recovery)",
      "property": "recover_before_rlf",
      "verdict": "PROVEN_SAFE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "3gpp_xn_handover_premature_release",
      "standards_body": "3GPP",
      "spec_clause": "3GPP TS 38.300 \u00a79.2.3 / TS 38.423 (Xn handover, data forwarding & path switch)",
      "property": "always_one_serving_context",
      "verdict": "CANDIDATE_COUNTEREXAMPLE",
      "citation": null,
      "known_finding": null
    },
    {
      "procedure": "pqc_hybrid_downgrade",
      "standards_body": "IEEE/PQC",
      "spec_clause": "IEEE 802.11bt (PQC amendment, PAR) \u2014 hybrid post-quantum key exchange",
      "property": "no_insecure_handshake",
      "verdict": "KNOWN_COUNTEREXAMPLE",
      "citation": "Stebila, Fluhrer & Gueron, \"Hybrid Key Exchange in TLS 1.3\" (IETF draft-ietf-tls-hybrid-design): downgrade-resilience requires binding the negotiated groups into the handshake transcript.",
      "known_finding": "Accepting a peer's classical/weaker fallback without binding the negotiated suite into the transcript admits a SILENT HYBRID-DOWNGRADE; transcript binding removes it."
    },
    {
      "procedure": "interconnect_cyclic_deadlock",
      "standards_body": "CXL/PCIe",
      "spec_clause": "Cache-coherent interconnect (CXL.cache/.mem) shared-resource acquisition",
      "property": "ordered_acquisition",
      "verdict": "KNOWN_COUNTEREXAMPLE",
      "citation": "Coffman, Elphick & Shoshani, \"System Deadlocks\", ACM Computing Surveys 3(2), 1971: circular wait is a necessary deadlock condition; a global resource ordering removes it.",
      "known_finding": "Ungated out-of-order acquisition of two shared resources by two agents forms a circular hold-and-wait -> DEADLOCK; a global acquisition order eliminates it."
    }
  ]
}