[TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt

Martin Thomson <mt@lowentropy.net> Fri, 31 July 2026 07:46 UTC

Return-Path: <mt@lowentropy.net>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CE27F1217725C for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 00:46:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785483973; bh=sVQ1weTJl0IUoBehBcfWe/sHLkSq55DerPAvCMmWEjs=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=Dts/chx6ieBKsoCkuxZ7QWTyvO8Sc9fXnGQd5YlCOmLGIJX2z7EaywHXCAJYc7Zzy dLtGTktHZYlCLYrBzz7/+uZ6rjkYry/QF9PMfX2Ld6W8FbsdZ6pzyp0N8u2XF/WFML 0McTtEEfkv/a1NhPJE6RaTQuEXfw4VU/jMRr/Jj8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="i50ru33G"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="pbc71l5L"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iXB9Azb5yKXj for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 00:46:12 -0700 (PDT)
Received: from fout-a2-smtp.messagingengine.com (fout-a2-smtp.messagingengine.com [103.168.172.145]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 887541217724E for <tls@ietf.org>; Fri, 31 Jul 2026 00:46:12 -0700 (PDT)
Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfout.phl.internal (Postfix) with ESMTP id 45496EC014B; Fri, 31 Jul 2026 03:46:06 -0400 (EDT)
Received: from phl-imap-15 ([10.202.2.104]) by phl-compute-04.internal (MEProxy); Fri, 31 Jul 2026 03:46:06 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:cc:content-transfer-encoding:content-type:content-type :date:date:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:subject:subject:to:to; s=fm3; t=1785483966; x=1785570366; bh=SNe7zvzRRbWyNbCEEZoYGU113Oz08dle BbNLko8PEng=; b=i50ru33GWymeYL1NmOESOn9e/8el3o9F4K6xfcgEEIubLT/s HrMUkXvo4ZGogGXgM/Trlcrklq1rDNlLTE7if8e67Sa3pzRHXRdB//CPRON05Igj MCsJRHW/yRHklfVgnbhWN8v6WcRLAma2fVIXVwepXo57f22tEaeZRwIR/E6ep8sH 1cGp2s6srxp9nYaASJP5+xSpW1DDdETiqELX6uWxMZtxVKYMJ1EDqmL+nusIlUcH VEr2l9L+ieNBuoORaqmBPpIz7FcHudNdtse0KeIldtbnus8n0AokcKsEwt9U8ztk bQ7aU7lLDQxYM01btZ4ZAQ0RQ85dm4BAUwhRuA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1785483966; x= 1785570366; bh=SNe7zvzRRbWyNbCEEZoYGU113Oz08dleBbNLko8PEng=; b=p bc71l5L7rsyg5Qok6nC8BsZ5M/Z+VyZ+XMLTCGF4bNhi6AEmakuRVpQhmFNfNnES Kba7ZkPYV4HJC+Ne0IDTOx0NE4KeyICCkXd1pXD9ppK+lRHAFARUNHuK4Tv+bpQ4 N5/oiK/QyqtNdy2Hf26P614OEkcf8LJ664hCL0/WaPo/6gFdpBsScYg4N5oza7nv Nu4IlmaZbE2LBV2xf2DlUbfuT5hl2DaaNbbTssgJb99LpgKKVJfCdrmL4xItJOK2 985mC6x2yFktdjFI1I7Jpd60vJEJsCSyTYHKzcjDE9U91kE2aVI6SYkHMAyl7WyD Rtwr8CHYntCsKn44jiNVg==
X-ME-Sender: <xms:vlJsaqBs7jj7YRh2MHv7fLG1knXjRvOgTJGG9OLJ6-UVcoAYOY6l0w> <xme:vlJsavXTKjL-1aHTlIxcF-BGb9GF7xLAE7kNq9D3D4342hXHerSxqXNAUZWezhTRT Tjpw7J3YZvqRnsDpLGyLsHojXcmF7dc0k4xzGNqibaXvZeti5xm4d8>
X-ME-Proxy-Cause: dmFkZTEQsyvBNYo+BR2QoexSWF8OuZrvBuMFu0mTFGjnOgu7ay32eCxD1kR+vjzsoBCECR GYg7vZlqIm6vVnRL6H5VWF8Mmyu7PVjI16VDtlF1f9QNrsnzkSNzxKYS9axSXuZbinjiOU ldpqNS6Tk6do41i3jGHTSGtT+G1t7Cw+PvuxDFmWMfpnqN2AMCPN4g/thlbZYFcQrcylIY seC3ik9e8R116jgTvTBiMWGJKDrMN9rwxF+baihfINhP9nchtDExQA2+EhdK/VLcWmX9Rs voUMovEbdagnla1/ZjSjgbAgf2JWbfhpO0dj13SbMEDPO7Uqd8kQUN4oJrYJEdrKSw8zXw R4xgKNl2RHQ9nxOP/dFDNKLZJJxggmDFqxRWV/7ga+0MqNo0N7egRLWcxIDe/QQPEt9qBO cvRND0kwCm96GD460UHg1CNb7MTmDp4WsI3DQZoy5YQZIJtUtoxHM2Wc/fUjbZOp4TEls5 ixr90fZuK4pwgIGbnya1DRc7K8+C0Wv2yf/30KQo2i42lo+9OEgYSVplF0FJe7gEWyPrQ9 cPT2zbgmnx1VXk5yPcJeTtcE6hR85bxXYfk5dTbQ+mNs8wayT8NzUXIW9uXWPifgX/2KaC VhEhldAZ5XUYBxG8sJs73HYQie4/qjBjRb8j1/k2j/lfW1T1a+WISK96Vv8w
X-ME-Proxy: <xmx:vlJsavecWSH1fyUzh6IuXgIS5d-7A3pSsxO8xNvw8abIo4mGUtydEg> <xmx:vlJsas9CrIRd2Dfbeebiver3wn2frLmoZ79yLp-rX3wF45MPojG6pA> <xmx:vlJsarnnk8Rnw9ONVSj0no5vErvml3S84WkfXo03EeXk1jC-jdV0zg> <xmx:vlJsau9gR6w5Aj1jgxaBAyIHTmDhUq4SdnTbjLuYsglhteja7OSD4g> <xmx:vlJsamxshRkWQtZA76KWM8zQiXU7MJC1yc-jt5AzkcZvxoTBhV_o-HIV>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.phl.internal (Postfix, from userid 501) id 0038A780070; Fri, 31 Jul 2026 03:46:05 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
MIME-Version: 1.0
Date: Fri, 31 Jul 2026 17:45:45 +1000
From: Martin Thomson <mt@lowentropy.net>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>, Nick Sullivan <nicholas.sullivan@gmail.com>
Message-Id: <bea3e553-53d7-4822-a3a3-1c4126ee3609@betaapp.fastmail.com>
In-Reply-To: <AS4PR07MB88252535766DC2F2F8924C5D89C82@AS4PR07MB8825.eurprd07.prod.outlook.com>
References: <AS4PR07MB88254ED7B2770683737DCADB89CB2@AS4PR07MB8825.eurprd07.prod.outlook.com> <CAOjisRyNkJLnMcZHPb8K2_1Q0y_FH=+ZfMnUExN5CRQ0mpJ5VQ@mail.gmail.com> <AS4PR07MB88252535766DC2F2F8924C5D89C82@AS4PR07MB8825.eurprd07.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: UG4Z6GALBFCD2MSCI3X2CZSIUPPBELIA
X-Message-ID-Hash: UG4Z6GALBFCD2MSCI3X2CZSIUPPBELIA
X-MailFrom: mt@lowentropy.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/CzldYF9s8jLNicgAeHQCnp9_d58>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Fri, Jul 31, 2026, at 17:08, John Mattsson wrote:
> Familiarizing myself further with deck functions, I have come to 
> understand that a deck function is a keyed function. However, I am not 
> particularly fond of the term “dec function”.

dec as in decimal or the work that sounds like something more crude?  Either way, I agree.  But it *is* an accepted term.

If a rename is on the cards (pun fully intended), it's a function that has (arbitrarily) extendable output that can be drawn at multiple points in an extendable input sequence.  So maybe XIXOF or XIMXOF (eXtendable Input with Multiple eXtendable Output Function).  Of course, forking state is so useful here as to be basically essential, so you might as well add another F somewhere (XIMFXOF) or just XIFXOF because forking implies multiplicity.

As for the basic problem of mapping to HKDF-Extract/HKDF-Expand...

Extract:
If you treat either salt or IKM as fixed size, you could just stack them to produce Extract.  The output (PRK) is the XIFXOF and its internal state.

The length thing is probably not a big deal because HMAC has that whole zero-pad ambiguity thing going already.  Though if you cared about fixing that bug, you could length-prefix.

Expand:
A state fork, plus stacking the info argument into the input in an unambiguous manner. This almost certainly needs a length prefix in the general case, but TLS doesn't need it because it already provides its own (it also packs the value of L in for good measure; a general thing might choose to do the same). This is followed by taking L from the resulting XIFXOF output.

Or did I miss something here?