ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
key_schedule.h File Reference

TLS 1.3 key schedule (RFC 8446 sec 7.1) for the QUIC handshake. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

TLS 1.3 key schedule (RFC 8446 sec 7.1) for the QUIC handshake.

QUIC runs TLS 1.3 as its handshake protocol (RFC 9001), and mbedTLS exposes no QUIC-TLS callback API, so the handshake is hand-rolled here. This module is the key schedule: the chain of HKDF-Extract and Derive-Secret steps (RFC 8446 sec 7.1) that turns the (EC)DHE shared secret and the running handshake transcript hash into the traffic secrets for each encryption level, plus the per-message Finished MAC (sec 4.4.4).

RFC 8446 sec 7.1 keys the whole schedule off the negotiated cipher suite's hash, so a schedule binds SHA-256 or SHA-384 at Tls13KsNs::early and every secret is 32 or 48 bytes from there on. The term layout is stated at the wider of the two (TLS13_SECRET_MAX) so a connection's storage does not depend on what it negotiates, and the length actually in force is read back off Tls13KsNs::len rather than assumed.

The schedule is transcript-hash-driven: each step takes a Transcript-Hash over the handshake messages so far, so this module has no dependency on the message wire formats and is host-testable in isolation against the RFC 8448 sec 3 worked trace (which lists every intermediate secret and the (EC)DHE input directly). RFC 8446 sec 4.4.1 runs that hash under the same suite hash as the schedule, so Tls13KsNs::transcript_init and its two companions keep it here, in a borrow the caller owns, and a driver never names a hash to keep a transcript. The QUIC packet-protection keys ({key, iv, hp}) are then derived from these traffic secrets by QuicCrypto.keys_from_secret (RFC 9001 sec 5.1).

Pure, zero heap, host-tested against RFC 8448 sec 3.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file key_schedule.h.