[TLS] I-D Action: draft-ietf-tls-extended-key-update-05.txt
internet-drafts@ietf.org Mon, 07 July 2025 19:28 UTC
Return-Path: <internet-drafts@ietf.org>
X-Original-To: tls@ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from [10.244.8.159] (unknown [104.131.183.230]) by mail2.ietf.org (Postfix) with ESMTP id 8803F406E633; Mon, 7 Jul 2025 12:28:53 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.43.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <175191653336.1915521.10407698545595344695@dt-datatracker-6fcb845cd4-p6tkq>
Date: Mon, 07 Jul 2025 12:28:53 -0700
Message-ID-Hash: Y2BK54JX45UIYTJBPWX57KJ76DI5O74Y
X-Message-ID-Hash: Y2BK54JX45UIYTJBPWX57KJ76DI5O74Y
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: tls@ietf.org
Subject: [TLS] I-D Action: draft-ietf-tls-extended-key-update-05.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/yMr5isKNpPQ1wfREypMSv_lAVvw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Internet-Draft draft-ietf-tls-extended-key-update-05.txt is now available. It
is a work item of the Transport Layer Security (TLS) WG of the IETF.
Title: Extended Key Update for Transport Layer Security (TLS) 1.3
Authors: Hannes Tschofenig
Michael Tüxen
Tirumaleswar Reddy
Steffen Fries
Yaroslav Rosomakho
Name: draft-ietf-tls-extended-key-update-05.txt
Pages: 18
Dates: 2025-07-07
Abstract:
TLS 1.3 ensures forward secrecy by performing an ephemeral Diffie-
Hellman key exchange during the initial handshake, protecting past
communications even if a party's long-term keys are later
compromised. While the built-in KeyUpdate mechanism allows traffic
keys to be refreshed during a session, it does not introduce new
forward-secret key material. This limitation can pose a security
risk in long-lived sessions, such as those found in industrial IoT or
telecommunications environments.
To address this, this specification defines an extended key update
mechanism that performs a fresh Diffie-Hellman exchange within an
active session, thereby re-establishing forward secrecy beyond the
initial handshake. By forcing attackers to exfiltrate new key
material repeatedly, this approach mitigates the risks associated
with static key compromise. Regular renewal of session keys helps
contain the impact of such compromises. The extension is applicable
to both TLS 1.3 and DTLS 1.3.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-tls-extended-key-update/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-tls-extended-key-update-05
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-tls-extended-key-update-05
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
- [TLS] I-D Action: draft-ietf-tls-extended-key-upd… internet-drafts