[TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt
Ilari Liusvaara <ilariliusvaara@welho.com> Tue, 14 July 2026 12:33 UTC
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B5F6811679FA2 for <tls@mail2.ietf.org>; Tue, 14 Jul 2026 05:33:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784032430; bh=EC4xuTYJI7x/TwTLKxqPg2V67VX9I6GStPP5qzmAXPQ=; h=Date:From:To:Subject:References:In-Reply-To; b=Zk+4O02DlrvugM8fdM2RN07qREKHgvPleCW4XHEb2i3Sh8T4ZlN33MqFrFaBmTx4H ilFdIUwXcev3mGYW85pRFIYRkTEgy4T0g8IuuVerxSIJN6U0UIstuVLEg2ZoeVWEnx NAsKfUjPjiMs5v8VLE5kcK2FPtHpIqSREbMeYh3I=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=welho.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l52hrPRp_9i3 for <tls@mail2.ietf.org>; Tue, 14 Jul 2026 05:33:49 -0700 (PDT)
Received: from smtp.dnamail.fi (sender103.dnamail.fi [83.102.40.157]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CAEB611679F96 for <tls@ietf.org>; Tue, 14 Jul 2026 05:33:48 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id 24285409294A for <tls@ietf.org>; Tue, 14 Jul 2026 15:33:41 +0300 (EEST)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.157]) by localhost (dmail-psmtp02.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id 0WF2THURYLC4 for <tls@ietf.org>; Tue, 14 Jul 2026 15:33:40 +0300 (EEST)
Received: from LK-Perkele-VII2 (87-92-117-27.bb.dnainternet.fi [87.92.117.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id 87D30409A3BC for <tls@ietf.org>; Tue, 14 Jul 2026 15:33:40 +0300 (EEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.dnamail.fi 87D30409A3BC
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=welho.com; s=2025-03; t=1784032420; bh=vFPHKUEbOSewGhBSCAn/EwV5jliJLW2PPDQ4Upwjx3w=; h=Date:From:To:Subject:References:In-Reply-To:From; b=mgU3Y1tLhkcn0KxIox1maEIPMrHLpwSDe7o1YxITGQLyFDqet2QQCPIZileq900KP 4qFUShMUg/cxRyBoDa8SVCynVcWxJDBN1C35JEHb4yNvg9MQ0mKJxoaoCuzDBMTdDZ UaRoYTPUIpFV+vLnyT31IcjO8ifP6m4cy013cfWVp8cMLk691ppCDtKDDv2aENW+/I 3Fg7NapBcvui8ZVYUOdHjCMJvsRsG94n8xdb0coaXLxv8XXkVv0KdRH3XeAWFjVHPx z362PBnWNJ0wL8Uy0T3O19VlqskIHoWrWHBSFPNGMFl8hnd/ypbBDD4TBs0BxWiDzj 0TzgRuHUT3TIg==
Date: Tue, 14 Jul 2026 15:33:35 +0300
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: tls@ietf.org
Message-ID: <alYsn2rL59qHtRM8@LK-Perkele-VII2.locald>
References: <178337862867.322525.625506674684583095@dt-datatracker-57b5d8f849-zrqfx> <CAOjisRx62wHM_ePa5EzwLoJSxvUydYksAN4XhbQ8sF=URrJqHQ@mail.gmail.com> <CA+iU_qm0tDxSeKJRc2Baku+NKvm2GA5AtyXoLP1+t=nPVuFM6Q@mail.gmail.com> <6ab46c45-4a86-44ce-954b-6df6da74100c@gmx.net> <E793EE64-0ADD-437A-8EED-F7A1CE1AB117@thomwiggers.nl> <CAOjisRxDav1T3k7t9sTQZt7Sabee=+2K4g8dY6xS7nH+WqWyMQ@mail.gmail.com> <ff64101e-96f9-40e4-8ea0-6fee56686a18@noekeon.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <ff64101e-96f9-40e4-8ea0-6fee56686a18@noekeon.org>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: WTJOTN27KLX4UIPT2SFMDOR5VZVNMBLA
X-Message-ID-Hash: WTJOTN27KLX4UIPT2SFMDOR5VZVNMBLA
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/G8L6da99Cycl_DjZWitlIovT3xQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Tue, Jul 14, 2026 at 01:08:43PM +0200, Joan Daemen wrote: > Dear all, > > We are enthusiastic about Nick Sullivan's announcement of his RFC draft for > a TLS 1.3 key schedule based on Keccak and happy with the many reactions on > the mailing list, so we thought it would be good to give you our 2 cents. > > # Including a Keccak-based AEAD option > > In Table 1, the draft proposes AES-GCM and ChaCha20-Poly1305 as AEAD > schemes, but no Keccak-based scheme. As suggested by other participants, it > would be nice to also offer the option of a Keccak-based AEAD scheme. This > would allow one to potentially reduce the code size (or area) and trust > surface even further. One issue is that most hardware does not have any hardware acceleration for Keccak, and very high speed software-only versions are expensive. > # Instantiating the key derivation > > The EuroS&P paper also defines a duplex object and a deck function, both > also reducing to the security of (Turbo)SHAKE128/256. Thanks to this > reduction, the former could be used as primitives in the key derivation, > solving much of the domain separation. The use of "trailer" bytes that > accumulate all domain separation bits the final functions are very simple to > implement. Moreover, by overwriting input blocks (instead of XORing them > in), they have a nice property that each call to the underlying permutation > can be a ratchet: the only requirement is that at least 128/256 bits of the > output shall not be returned. I think the only place that needs to be ratchet is (Extended) Key Update updating the keys (since those keys can be intermediate-duration and it must not be possible to backtrack). Then TLS 1.3 key schedule is a bit whacky: There can be multiple PSKs, each with its own binder, traffic secret and exporter secret, or there might not be PSK at all. The key schedule continues from the option chosen by the server. To do that efficiently pretty much requires forking the state somehow. -Ilari
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Martin Thomson
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Thom Wiggers
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Hannes Tschofenig
- [TLS] Re: New Version Notification for draft-sull… Thom Wiggers
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Joan Daemen
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson