[TLS] Computation of static secret in anonymous DH

Douglas Stebila <stebila@qut.edu.au> Wed, 17 June 2015 07:34 UTC

Return-Path: <stebila@qut.edu.au>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E51F1A1B7C for <tls@ietfa.amsl.com>; Wed, 17 Jun 2015 00:34:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ixyaFoDAgSwv for <tls@ietfa.amsl.com>; Wed, 17 Jun 2015 00:34:02 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0691.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::691]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 31CAF1A1B8A for <tls@ietf.org>; Wed, 17 Jun 2015 00:33:49 -0700 (PDT)
Received: from BN3PR0101MB1139.prod.exchangelabs.com (10.161.219.15) by BN3PR0101MB1138.prod.exchangelabs.com (10.161.219.149) with Microsoft SMTP Server (TLS) id 15.1.190.14; Wed, 17 Jun 2015 07:33:32 +0000
Received: from BN3PR0101MB1139.prod.exchangelabs.com ([10.161.219.15]) by BN3PR0101MB1139.prod.exchangelabs.com ([10.161.219.15]) with mapi id 15.01.0190.013; Wed, 17 Jun 2015 07:33:32 +0000
From: Douglas Stebila <stebila@qut.edu.au>
To: "tls@ietf.org" <tls@ietf.org>
Thread-Topic: Computation of static secret in anonymous DH
Thread-Index: AQHQqM/pv0TL4/Ya7k2Y027UTUErwg==
Date: Wed, 17 Jun 2015 07:33:31 +0000
Message-ID: <2AA11887-2F82-48EF-BD45-4D85CFA83847@qut.edu.au>
Accept-Language: en-CA, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.2098)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=stebila@qut.edu.au;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [131.181.47.132]
x-microsoft-exchange-diagnostics: 1; BN3PR0101MB1138; 3:i/yDqgeczK1l9gIB83+o96ORnRhBhNudIg7DGcnaVFErqFPd0GTLBCfnA4iWgjv3SFHGFl8E5OzFblmP//dIs7hTf+52gD9TZXQZpc+4zK6x8K90gYIL2BjZGUgvPMPdcr/ZmlYQo6CwBJEsZ25zkg==; 10:dixtRma4DW/fip+FUADxfXLZEkOd5iDSypFcbV9n/GVXRScnOmO4H62pcj/aoJ5tpAWatXfGw14dU+Hrbygs5xfP/NefCJeMtQVROdoEVEQ=; 6:4pkrzz4zl8tdM+9QXT0SlnM8QAWWkq/lwF+xhYyzM6NNHxo9QLE0UyMk4/CZ79Je
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BN3PR0101MB1138;
x-microsoft-antispam-prvs: <BN3PR0101MB11380C49A373F3C2182B24D78EA60@BN3PR0101MB1138.prod.exchangelabs.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(520003)(5005006)(3002001); SRVR:BN3PR0101MB1138; BCL:0; PCL:0; RULEID:; SRVR:BN3PR0101MB1138;
x-forefront-prvs: 0610D16BBE
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(979002)(6009001)(86362001)(50226001)(57306001)(88552001)(15975445007)(102836002)(122556002)(77096005)(50986999)(2656002)(40100003)(87936001)(5002640100001)(66066001)(2351001)(229853001)(2501003)(33656002)(19580395003)(74482002)(558084003)(36756003)(106116001)(83716003)(110136002)(107886002)(5001960100002)(450100001)(62966003)(77156002)(189998001)(92566002)(2900100001)(46102003)(74826001)(82746002)(219293001)(104396002)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1101; SCL:1; SRVR:BN3PR0101MB1138; H:BN3PR0101MB1139.prod.exchangelabs.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
received-spf: None (protection.outlook.com: qut.edu.au does not designate permitted sender hosts)
Content-Type: text/plain; charset="us-ascii"
Content-ID: <F1153E7470CD554B98C52A173B057D66@prod.exchangelabs.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: qut.edu.au
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Jun 2015 07:33:31.9484 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: dc0b52a3-68c5-44f7-881d-9383d8850b96
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR0101MB1138
Archived-At: <http://mailarchive.ietf.org/arch/msg/tls/pXAiHQnzUbftqLeMglB559rrrrI>
Subject: [TLS] Computation of static secret in anonymous DH
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Jun 2015 07:34:05 -0000

In the DH-based draft of TLS 1.3 (https://github.com/ekr/tls13-spec/blob/ietf92_materials/draft-ietf-tls-tls13-dh-based.txt), how is the ServerParameters message containing the static secret SS constructed in the unauthenticated setting?

Douglas