[TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt
Nick Sullivan <nicholas.sullivan@gmail.com> Tue, 21 July 2026 10:32 UTC
Return-Path: <nicholas.sullivan@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 304CA11B404A1 for <tls@mail2.ietf.org>; Tue, 21 Jul 2026 03:32:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784629928; bh=GUzus0bXU0jm4g3cY7jq1w/x5PwYfqwxA/hVowCWD+U=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=pTbgUIgxnEwREDJes6UADz7neLF46q5vfbocWgEJfwwel5bWyQQeJP4xpoG0J9zPp XV/T+ViW9uBCDcAdwu2m0NvY2FRjfWIzlyeCitwqi/kv8z1/OgZ72gdSUEl9YhUzhO bfOHTcAdaGg2io1C9lDBe1XXYrN7hObIx9oxgbMg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nJry-OBNSt6T for <tls@mail2.ietf.org>; Tue, 21 Jul 2026 03:32:07 -0700 (PDT)
Received: from mail-yw1-x1130.google.com (mail-yw1-x1130.google.com [IPv6:2607:f8b0:4864:20::1130]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9C44911B4049A for <TLS@ietf.org>; Tue, 21 Jul 2026 03:32:07 -0700 (PDT)
Received: by mail-yw1-x1130.google.com with SMTP id 00721157ae682-7dbcb505578so74178147b3.3 for <TLS@ietf.org>; Tue, 21 Jul 2026 03:32:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1784629927; cv=none; d=google.com; s=arc-20260327; b=TQSd0wHAY3HJk/ps7ekFUc98+FlKxB5tteGKVfnb5ObcXEwBNd8vdlxUEmbsxyJgIg KOs9jI8ZvEFx50IWhyUtyfy2LXfDrQLfkNYtu/YoW45WPRzAmnbmx10olty4TGKF37QU M+SnCClw1QbBIk0VhK2uhWPoJmXxz2+dxGrmV0cXRDNfUFGZmfYtO4z0yl7VC01UJz7r r+YQRAe3wTIxtM435WM5iDwU/sfWD5qicH2oqEkObC5PvD6aiqwyUkss0lLBcKaHw2FH SOeASqrYiVIP0RuGu6z5c2DRUAPsAHZq7ParSjA2T6lIZXj1pZyD2SfMX2CuQdjI/qBI dwvg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=ySpzg8oYoDiaIYJc4K9EsvN3FWoEwESEc30ZNm8Ca0U=; fh=bwUncO6sMSuMm1ZsjOsDZ+RD5WMETW0tAyJPHNvqNSE=; b=rf3EQY2OJZuqTZznRW+k1jSt97VfUC2rd8s/+B5WeEzAtOYnNYr9hXC4BeHyvqk9kp SA/Pe7g39P05QYxv1QPiRnP6XlS3TrngG8dBjRjd9FZEwGE0PCUaU1xMerjFbGooO7mp XZKJVj8eKwdbT+W0ylX3X3G1aIh+QvHXgAXGXgo4KRR5dQwbjLfAnVUAgeKcON617Z/0 5fjbmxwqgXwPiqtR5uWPADBmAr7upbgAtPLtuZ/XQz2XdklegAIYOhRtFgJlCS45tq/N CwZvNLt8KWzYB0tqzzeiYEZk82SEbqet3SvMBHPGEGLHdsxkuhwPCybAxjNjxznW0N+B y+9A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784629927; x=1785234727; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ySpzg8oYoDiaIYJc4K9EsvN3FWoEwESEc30ZNm8Ca0U=; b=eb6yShg6TUtK1tINA9zzAXXwyVe1/efelJ7m9xwM70VAlmZ5lQgyFj/UZ66HgIhTsl 3/flsqKsfU7FNgk0nl+gUDjYig4pbkQ8Ps3HupnwTAsETwZwyYM01l99+eVN3vtNF2sD EdUDiZ8dTcR+7KB62zxy3XcUXxAPtAHaL91RhSNZCgZ8UQFfXXoFa87Wcnxp6aCWIsVQ aFEPmSm9jEl2s4DpSu0xS2Ro3tj3J7TiLNkBDYopmycZqyqJ77o0oRlGJYUMmjZTZngB QowU0uduh9Leb1z/vwlTp56ATsfTxrGV3tiF1G7gn8kJGHiCJhSs3uHEVoXQkf8j4mZe I5yg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784629927; x=1785234727; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=ySpzg8oYoDiaIYJc4K9EsvN3FWoEwESEc30ZNm8Ca0U=; b=F++qDh1n+DHS/mF5P5/iR99eHEEyuh1Ml/s8v+3pYXFlqk0SgNZz863NWDSFFGJrlk JHczkdBq+21e19rbyTL9xauczX7wIKEXOQ7PmNRvhSxoeFSli6AvR6BUEcF4/I2lEgg1 nyuvrK6xWpU1c8sbFjmCDKbQ/yP1h2V8HwLu6o+2TlvsPGGuYp+qRGc3FbUVTx+V6BhC YuBKDS2Vct3OTxWZVOOSLHiP1pLA1pUBh/d5NcrRaQS/sYTaILPlr80U5Q9ztzBPkIGq poh8XjJnLU860EljUZ8YP0jisC2ZNlT42AaZ9U8W0liCdZ0ZbaG0fF+PRUDub8MaqFvB xwDQ==
X-Gm-Message-State: AOJu0YwkErUdxdlwQewZWuaQDJRAe9vg1R6/UQrSoW44m4bFUUdIMZO2 OQhUe2Ke0gBW9cjK+lH4Icul2gmaipjkJiER1q/JyXNespGGTXzj0MrirhdZfBBgsBLXee1VwWX DRStc07Y4IQl/RV8nBP6pOZnr32Ufuq0exPZwRqsluQ==
X-Gm-Gg: AR+sD11RrxZBdRl5L6ViH8Pw4NLJa4QHqaBm450qhQ2/xg4U1y2tSr9weOEEBYC37mt /iZZaztXZ6T+9/DPtpiE0BM5wGuSDQCV8HVOMgHzvVKBgg6RLJ3EciHHi28d9mdKjSKK6UKtjKO MTEcYZwmwzH+6omheAgDiP510KER0CLE4Ts+XrY5MwnumV+HWFO96hIWzZFtmsghdVmNrqGLbC0 zB0vwOKvZw2cAkBdiiY4UG7deQrpohbjPRa5URyFlxKLBnImbO6MQlDiklRUF1CPmZSNeRReh2r TuyxET6LzZ9FEBbXqD6vwhpIF5F09dqfYbmpAxgDIi80fqZtKwFk7OaW2/ozsg1yDEGH5dDZOkj Us+nZY3OFFSvWdjJk6U558DysdV4q537qTBrmcMFA+kd1oTceow==
X-Received: by 2002:a05:690c:6e8d:b0:81e:8988:a8f8 with SMTP id 00721157ae682-81ef240d52cmr55981827b3.27.1784629926931; Tue, 21 Jul 2026 03:32:06 -0700 (PDT)
MIME-Version: 1.0
References: <178337862867.322525.625506674684583095@dt-datatracker-57b5d8f849-zrqfx> <CAOjisRx62wHM_ePa5EzwLoJSxvUydYksAN4XhbQ8sF=URrJqHQ@mail.gmail.com> <al5HL3yuz_Qv4I6L@LK-Perkele-VII2.locald>
In-Reply-To: <al5HL3yuz_Qv4I6L@LK-Perkele-VII2.locald>
From: Nick Sullivan <nicholas.sullivan@gmail.com>
Date: Tue, 21 Jul 2026 12:31:55 +0200
X-Gm-Features: AUfX_myyZi5McqDfL323GP-qoChvOvcgEkP6pWKDjzaeOaAi7jPS0OStgVNk1kA
Message-ID: <CAOjisRx=q3XftOkYU79075vpeTHcF0GtxLRw_Wp2SW6iZB+dwA@mail.gmail.com>
To: Ilari Liusvaara <ilariliusvaara@welho.com>
Content-Type: multipart/alternative; boundary="000000000000d9b19206571c882e"
Message-ID-Hash: 4QLNOD2NE6SCWHZKUCCHONCGWBHMNK6I
X-Message-ID-Hash: 4QLNOD2NE6SCWHZKUCCHONCGWBHMNK6I
X-MailFrom: nicholas.sullivan@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <TLS@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: New Version Notification for draft-sullivan-tls-xof-ciphers-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/gZBypSUterp4U532ZnCUuBAXekg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Hi Ilari, I'm in the middle of a major revamp of the draft based on the feedback on the list (including yours, thanks!) and just further refinement. I expect most of these points will be addressed in a new draft by the end of the week. It's already much slimmer. I also have some nice diagrams I'll be presenting at the TLS meeting that should make the design much more comprehensible. It's more aligned with the existing TLS 1.3 key schedule while still keeping the performance benefits of the deck structure. It's still a very conservative design. I haven't looked deeply enough into the duplex construction you sketched out, so I expect further optimization or state management designs may be possible. Best, Nick On Mon, Jul 20, 2026 at 6:07 PM Ilari Liusvaara <ilariliusvaara@welho.com> wrote: > On Mon, Jul 06, 2026 at 07:23:41PM -0400, Nick Sullivan wrote: > > > > I'm sharing a draft for the group's consideration. > > draft-sullivan-tls-xof-ciphers-00 runs the entire TLS 1.3 key schedule > > on a single Keccak permutation, instead of HKDF built on HMAC built on > > the cipher suite's hash, which today is always SHA-2. This is newly > > practical because deployments using SHA-3, ML-KEM, or ML-DSA already > > carry a Keccak permutation, so the primitive is already in the stack. > > > > Each derived value comes out in one pass, so a full handshake costs > > about a third of the permutation calls an HKDF schedule over the same > > permutation would spend. > > > > https://datatracker.ietf.org/doc/draft-sullivan-tls-xof-ciphers/ > > > > This is a big change to the key schedule, and the draft is very > > preliminary. Feedback on the approach, or interest in implementing it, > > would help a lot. > > I took a new look. There seems to be a lot of extraneous stuff. > > - Extraneous labels. > > An example of 3 labels when only one would do: > > c_e_traffic = Squeeze(Absorb(Fork(E, "c e traffic", suite), > "th", TH_CH), "out", SecretLen) > > There is at least one another triplicate label, and number of > duplicate ones. > > - Ciphersuite seems to get re-injected a lot, should only be > injected once. > > - Both c_e_traffic and e_exp_master have TH_CH, whereas rest of the > handshake pre-injects transcript hashes to state instead. > > - Exporters and resumption PSK fork the state without using the > original. > > - Ratchet() is not useful: The only place that needs it (key update) > does not use it. > > There is no long-term hash state, and early/rest can be handled by > cloning the state, so nothing needs ratchet. > > - Binders/Finished probably do not need two layers of hashing. Might > have been needed with SHA-2, but Keccak is far stronger. > > - There also looks to be a lot more text than what is needed. > > > Other stuff: > > - The two-layer exporter construct from TLS 1.3 can not be replaced by > single-layer one without changing semantics. > > - The labels from TLS 1.3 lack the implicit prefix. > > - The split shared secret is going to be very nasty surprise for > implementations. Many implementations have no idea if group is > hybrid or not. > > - Also, using postfix syntax would probably look cleaner than prefix > syntax. > > > > > -Ilari > > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org >
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Martin Thomson
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Thom Wiggers
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Markku-Juhani O. Saarinen
- [TLS] Re: New Version Notification for draft-sull… Hannes Tschofenig
- [TLS] Re: New Version Notification for draft-sull… Thom Wiggers
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Joan Daemen
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson
- [TLS] Re: New Version Notification for draft-sull… Ilari Liusvaara
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… Nick Sullivan
- [TLS] Re: New Version Notification for draft-sull… John Mattsson