Source file
src/crypto/tls/key_schedule.go
1
2
3
4
5 package tls
6
7 import (
8 "crypto/ecdh"
9 "crypto/hmac"
10 "crypto/internal/mlkem768"
11 "errors"
12 "fmt"
13 "hash"
14 "io"
15
16 "golang.org/x/crypto/cryptobyte"
17 "golang.org/x/crypto/hkdf"
18 "golang.org/x/crypto/sha3"
19 )
20
21
22
23
24 const (
25 resumptionBinderLabel = "res binder"
26 clientEarlyTrafficLabel = "c e traffic"
27 clientHandshakeTrafficLabel = "c hs traffic"
28 serverHandshakeTrafficLabel = "s hs traffic"
29 clientApplicationTrafficLabel = "c ap traffic"
30 serverApplicationTrafficLabel = "s ap traffic"
31 exporterLabel = "exp master"
32 resumptionLabel = "res master"
33 trafficUpdateLabel = "traffic upd"
34 )
35
36
37 func (c *cipherSuiteTLS13) expandLabel(secret []byte, label string, context []byte, length int) []byte {
38 var hkdfLabel cryptobyte.Builder
39 hkdfLabel.AddUint16(uint16(length))
40 hkdfLabel.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
41 b.AddBytes([]byte("tls13 "))
42 b.AddBytes([]byte(label))
43 })
44 hkdfLabel.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
45 b.AddBytes(context)
46 })
47 hkdfLabelBytes, err := hkdfLabel.Bytes()
48 if err != nil {
49
50
51
52
53
54
55
56
57
58
59
60
61 panic(fmt.Errorf("failed to construct HKDF label: %s", err))
62 }
63 out := make([]byte, length)
64 n, err := hkdf.Expand(c.hash.New, secret, hkdfLabelBytes).Read(out)
65 if err != nil || n != length {
66 panic("tls: HKDF-Expand-Label invocation failed unexpectedly")
67 }
68 return out
69 }
70
71
72 func (c *cipherSuiteTLS13) deriveSecret(secret []byte, label string, transcript hash.Hash) []byte {
73 if transcript == nil {
74 transcript = c.hash.New()
75 }
76 return c.expandLabel(secret, label, transcript.Sum(nil), c.hash.Size())
77 }
78
79
80 func (c *cipherSuiteTLS13) extract(newSecret, currentSecret []byte) []byte {
81 if newSecret == nil {
82 newSecret = make([]byte, c.hash.Size())
83 }
84 return hkdf.Extract(c.hash.New, newSecret, currentSecret)
85 }
86
87
88
89 func (c *cipherSuiteTLS13) nextTrafficSecret(trafficSecret []byte) []byte {
90 return c.expandLabel(trafficSecret, trafficUpdateLabel, nil, c.hash.Size())
91 }
92
93
94 func (c *cipherSuiteTLS13) trafficKey(trafficSecret []byte) (key, iv []byte) {
95 key = c.expandLabel(trafficSecret, "key", nil, c.keyLen)
96 iv = c.expandLabel(trafficSecret, "iv", nil, aeadNonceLength)
97 return
98 }
99
100
101
102
103 func (c *cipherSuiteTLS13) finishedHash(baseKey []byte, transcript hash.Hash) []byte {
104 finishedKey := c.expandLabel(baseKey, "finished", nil, c.hash.Size())
105 verifyData := hmac.New(c.hash.New, finishedKey)
106 verifyData.Write(transcript.Sum(nil))
107 return verifyData.Sum(nil)
108 }
109
110
111
112 func (c *cipherSuiteTLS13) exportKeyingMaterial(masterSecret []byte, transcript hash.Hash) func(string, []byte, int) ([]byte, error) {
113 expMasterSecret := c.deriveSecret(masterSecret, exporterLabel, transcript)
114 return func(label string, context []byte, length int) ([]byte, error) {
115 secret := c.deriveSecret(expMasterSecret, label, nil)
116 h := c.hash.New()
117 h.Write(context)
118 return c.expandLabel(secret, "exporter", h.Sum(nil), length), nil
119 }
120 }
121
122 type keySharePrivateKeys struct {
123 curveID CurveID
124 ecdhe *ecdh.PrivateKey
125 kyber *mlkem768.DecapsulationKey
126 }
127
128
129 func kyberDecapsulate(dk *mlkem768.DecapsulationKey, c []byte) ([]byte, error) {
130 K, err := mlkem768.Decapsulate(dk, c)
131 if err != nil {
132 return nil, err
133 }
134 return kyberSharedSecret(K, c), nil
135 }
136
137
138 func kyberEncapsulate(ek []byte) (c, ss []byte, err error) {
139 c, ss, err = mlkem768.Encapsulate(ek)
140 if err != nil {
141 return nil, nil, err
142 }
143 return c, kyberSharedSecret(ss, c), nil
144 }
145
146 func kyberSharedSecret(K, c []byte) []byte {
147
148
149
150 h := sha3.NewShake256()
151 h.Write(K)
152 ch := sha3.Sum256(c)
153 h.Write(ch[:])
154 out := make([]byte, 32)
155 h.Read(out)
156 return out
157 }
158
159 const x25519PublicKeySize = 32
160
161
162
163 func generateECDHEKey(rand io.Reader, curveID CurveID) (*ecdh.PrivateKey, error) {
164 curve, ok := curveForCurveID(curveID)
165 if !ok {
166 return nil, errors.New("tls: internal error: unsupported curve")
167 }
168
169 return curve.GenerateKey(rand)
170 }
171
172 func curveForCurveID(id CurveID) (ecdh.Curve, bool) {
173 switch id {
174 case X25519:
175 return ecdh.X25519(), true
176 case CurveP256:
177 return ecdh.P256(), true
178 case CurveP384:
179 return ecdh.P384(), true
180 case CurveP521:
181 return ecdh.P521(), true
182 default:
183 return nil, false
184 }
185 }
186
187 func curveIDForCurve(curve ecdh.Curve) (CurveID, bool) {
188 switch curve {
189 case ecdh.X25519():
190 return X25519, true
191 case ecdh.P256():
192 return CurveP256, true
193 case ecdh.P384():
194 return CurveP384, true
195 case ecdh.P521():
196 return CurveP521, true
197 default:
198 return 0, false
199 }
200 }
201
View as plain text