ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
record.h File Reference

TLS 1.3 record layer over a reliable stream (RFC 8446 sec 5). More...

Go to the source code of this file.

Detailed Description

TLS 1.3 record layer over a reliable stream (RFC 8446 sec 5).

The TCP counterpart to protocore_dtls_record: it protects and unprotects individual records on a byte stream. TCP delivers them in order, exactly once, so this half of the protocol is the smaller one - there is no epoch, no sequence number on the wire, no anti-replay window and no fragment reassembly. What remains is the header, the AEAD, and a record counter each side keeps itself.

Two record shapes (RFC 8446 sec 5.1, 5.2):

  • TLSPlaintext - the 5-byte header (type, legacy_record_version, length) followed by the fragment, sent unencrypted for the first handshake flight and for alerts before keys exist.
  • TLSCiphertext - the same header with opaque_type = application_data(23) over an AEAD-sealed body. The sealed plaintext is content || real_type, so the true content type travels inside the encryption; the header's type is a constant that reveals nothing.

The record sequence number is never transmitted. It starts at zero when a key is installed and counts records under that key (sec 5.3), so both ends derive the same nonce from their own count.

– Reuse – The AEAD and the key/iv derivation follow the negotiated suite (TlsCipher), and the derivation runs through ::Tls13Ks under the "tls13 " label prefix (TLS13_KDF). Two suites: TLS_AES_128_GCM_SHA256 over AEAD_AES_128_GCM with a SHA-256 schedule, and TLS_AES_256_GCM_SHA384 over AEAD_AES_256_GCM with a SHA-384 one. Which AEAD a record uses is read off the key it was derived into, so nothing below the key derivation branches on the suite.

Pure, zero heap, host-tested. This is the portable record layer; a build whose vendor ships a TLS compiles with PROTOCORE_ENABLE_TLS.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file record.h.