Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@philipch07
Copy link
Contributor

@philipch07 philipch07 commented Sep 30, 2025

Description

This adds the HKDF related functions for the key scheduling feature in accordance with DTLS v1.3 section 5.9. Note that it links to TLS 1.3 section 7.1.

This aims to add:

  • HKDF-Expand-Label
  • HKDF-Extract
  • Derive-Secret

Note that the architecture is still a WIP (see #738) so the current file structures are subject to change.

Reference issue

Closes #740

@philipch07 philipch07 changed the title Initial effort for implementing key scheduling Add key scheduling for DTLS v1.3 Sep 30, 2025
@codecov
Copy link

codecov bot commented Sep 30, 2025

Codecov Report

❌ Patch coverage is 89.09091% with 6 lines in your changes missing coverage. Please review.
✅ Project coverage is 78.64%. Comparing base (6ff535f) to head (05b7a50).

Files with missing lines Patch % Lines
pkg/crypto/hkdf13/hkdf_13.go 89.09% 4 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master     #737      +/-   ##
==========================================
+ Coverage   78.55%   78.64%   +0.08%     
==========================================
  Files         102      103       +1     
  Lines        6916     6971      +55     
==========================================
+ Hits         5433     5482      +49     
- Misses       1103     1107       +4     
- Partials      380      382       +2     
Flag Coverage Δ
go 78.66% <89.09%> (+0.08%) ⬆️
wasm 57.69% <89.09%> (+0.23%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@philipch07 philipch07 force-pushed the pch07/dtls13-initial-key-schedule branch from 64f9a92 to 36beefc Compare September 30, 2025 23:14
@philipch07 philipch07 force-pushed the pch07/dtls13-initial-key-schedule branch from 86be4d1 to 05b7a50 Compare October 2, 2025 00:26
@theodorsm
Copy link
Member

theodorsm commented Oct 8, 2025

Thanks for starting on this!

I think this PR should be scoped to implement the HKDF functions: HKDF-Expand-Label and Derive-Secret as you have started on. This will be one part of multiple to complete issue #736.

@philipch07
Copy link
Contributor Author

Thanks for starting on this!

I think this PR should be scoped down to adding the HKDF functions HKDF-Expand-Label and Derive-Secret as you have started on. This will be one part of multiple to complete issue #736.

No problem! I agree, this seems to be a rather large thing and due to the current block that you mentioned #736 (comment), I think it would make sense to tackle #736 in multiple parts. Just to clarify, I should still include hkdfExtract though, correct?

@philipch07 philipch07 changed the title Add key scheduling for DTLS v1.3 Add HKDF funcs for Key Scheduling - DTLS v1.3 Oct 8, 2025
@theodorsm
Copy link
Member

@philipch07, yes we should also export a HkdfExtract function, good catch.

@theodorsm theodorsm mentioned this pull request Oct 8, 2025
10 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DTLS v1.3 HKDF functions for key scheduling

2 participants