SSL.Crypto.KeySchedule (ex_ssl v0.16.7)

Copy Markdown View Source

Pure TLS 1.3 key-schedule derivations.

Callers supply exact transcript hashes at each protocol checkpoint. Derived traffic states start at sequence zero for a new traffic epoch.

Summary

Types

error_reason()

@type error_reason() ::
  :unsupported_hash
  | {:unsupported_cipher_suite, term()}
  | {:invalid_input, :psk | :shared_secret | :ticket_nonce | :transcript_hash}
  | {:invalid_secret_length, atom(), pos_integer()}
  | {:invalid_input, :empty_shared_secret}
  | {:invalid_transcript_hash_length, pos_integer()}
  | {:ticket_nonce_too_long, 255}

hash()

@type hash() :: :sha256 | :sha384

Functions

client_application_traffic_secret(hash, master_secret, transcript_hash)

@spec client_application_traffic_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

client_handshake_traffic_secret(hash, handshake_secret, transcript_hash)

@spec client_handshake_traffic_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

derived_secret(hash, secret)

@spec derived_secret(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}

early_secret(hash, psk)

@spec early_secret(hash(), binary() | nil) ::
  {:ok, binary()} | {:error, error_reason()}

exporter_master_secret(hash, master_secret, transcript_hash)

@spec exporter_master_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

finished_key(hash, traffic_secret)

@spec finished_key(atom(), term()) ::
  {:ok, binary()}
  | {:error,
     :unsupported_hash | {:invalid_secret_length, :traffic_secret, 32 | 48}}

finished_verify_data(hash, finished_key, transcript_hash)

@spec finished_verify_data(atom(), term(), term()) ::
  {:ok, binary()}
  | {:error,
     :unsupported_hash
     | {:invalid_secret_length, :finished_key, 32 | 48}
     | {:invalid_input, :transcript_hash}
     | {:invalid_transcript_hash_length, 32 | 48}}

handshake_secret(hash, early_secret, shared_secret)

@spec handshake_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

master_secret(hash, handshake_secret)

@spec master_secret(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}

resumption_master_secret(hash, master_secret, transcript_hash)

@spec resumption_master_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

resumption_secret(hash, resumption_master_secret, ticket_nonce)

@spec resumption_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

server_application_traffic_secret(hash, master_secret, transcript_hash)

@spec server_application_traffic_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

server_handshake_traffic_secret(hash, handshake_secret, transcript_hash)

@spec server_handshake_traffic_secret(hash(), binary(), binary()) ::
  {:ok, binary()} | {:error, error_reason()}

traffic_state(cipher_suite, traffic_secret)

@spec traffic_state(SSL.Crypto.TrafficState.cipher_suite(), binary()) ::
  {:ok, SSL.Crypto.TrafficState.t()} | {:error, error_reason()}

traffic_update(hash, traffic_secret)

@spec traffic_update(hash(), binary()) :: {:ok, binary()} | {:error, error_reason()}