Re: [TLS] TLS1.3

"Lewis, Nick" <nick.lewis@usa.g4s.com> Fri, 08 February 2013 11:48 UTC

Return-Path: <nick.lewis@usa.g4s.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4313021F854C for <tls@ietfa.amsl.com>; Fri, 8 Feb 2013 03:48:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.094
X-Spam-Level:
X-Spam-Status: No, score=-5.094 tagged_above=-999 required=5 tests=[AWL=1.504, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, UNPARSEABLE_RELAY=0.001]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id szUMUVzeCNxK for <tls@ietfa.amsl.com>; Fri, 8 Feb 2013 03:48:44 -0800 (PST)
Received: from mail1.bemta14.messagelabs.com (mail1.bemta14.messagelabs.com [193.109.254.98]) by ietfa.amsl.com (Postfix) with ESMTP id 6AF1E21F8955 for <tls@ietf.org>; Fri, 8 Feb 2013 03:48:44 -0800 (PST)
Received: from [85.158.140.195:20068] by server-10.bemta-14.messagelabs.com id 05/B3-12679-B16E4115; Fri, 08 Feb 2013 11:48:43 +0000
X-Env-Sender: nick.lewis@usa.g4s.com
X-Msg-Ref: server-7.tower-193.messagelabs.com!1360324123!13544186!1
X-Originating-IP: [89.206.228.155]
X-StarScan-Received:
X-StarScan-Version: 6.7; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 15784 invoked from network); 8 Feb 2013 11:48:43 -0000
Received: from unallocated.star.net.uk (HELO gbtwk10s037.Technology.local) (89.206.228.155) by server-7.tower-193.messagelabs.com with RC4-SHA encrypted SMTP; 8 Feb 2013 11:48:43 -0000
Received: from GBTWK10E001.Technology.local ([10.234.1.29]) by gbtwk10s037.Technology.local ([10.234.1.39]) with mapi; Fri, 8 Feb 2013 11:48:43 +0000
From: "Lewis, Nick" <nick.lewis@usa.g4s.com>
To: "tls@ietf.org" <tls@ietf.org>
Date: Fri, 08 Feb 2013 11:48:42 +0000
Thread-Topic: Re: [TLS] TLS1.3
Thread-Index: Ac4F8kVNx4hExgXuSR+yTxN28WBR5A==
Message-ID: <AAE0766F5AF36B46BAB7E0EFB9273206194A67DCD9@GBTWK10E001.Technology.local>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [TLS] TLS1.3
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Feb 2013 11:48:45 -0000

>So here's the first cut, if there's anything that needs clarifying/changing let me know before I upload it.
>Peter.

While I believe that the responsibility for the mechanism that combines mac, crypt and pad should move from TLS to the cipher suites in the longer term, this extension seems to give most of the benefits without needing to port any cipher suites to AEAD

The document could be a little clearer if it used the same terminology as used in [TLS] such as "+" for concatenation and if it was more explict about the MAC e.g.

MAC(MAC_write_key, seq_num +
   TLSCompressed.type +
   TLSCompressed.version +
   TLSCompressed.length +
   ENC(TLSCompressed.fragment + padding + padding_length));

   where "+" denotes concatenation.

-- Nick

The details of this company are as follows:
G4S Technology Limited, Registered Office: Challenge House, International Drive, Tewkesbury, Gloucestershire GL20 8UQ, Registered in England No. 2382338.

This communication may contain information which is confidential, personal and/or privileged.

It is for the exclusive use of the intended recipient(s).
If you are not the intended recipient(s), please note that any distribution, forwarding, copying or use of this communication or the information in it is strictly prohibited.

Any personal views expressed in this e-mail are those of the individual sender and the company does not endorse or accept responsibility for them.

Prior to taking any action based upon this e-mail message, you should seek appropriate confirmation of its authenticity.

This e-mail has been scanned for all viruses by MessageLabs.