Network Working Group U. Blumenthal
Request for Comments: 4785 P. Goel
Category: Standards Track Intel Corporation
January 2007
Pre-Shared Key (PSK) Ciphersuites with NULL Encryption for Transport Layer Security (TLS)
Blumenthal & Goel Standards Track [Page 1]
RFC 4785 PSK NULL Encryption Ciphersuites for TLS January 2007 1. IntroductionThe RFC for Pre-Shared Key (PSK) based Transport Layer Security (TLS) [TLS-PSK] specifies ciphersuites for supporting TLS using pre-shared symmetric keys. However, all the ciphersuites defined in [TLS-PSK] require encryption. However there are cases when only authentication and integrity protection is required, and confidentiality is not needed. There are also cases when confidentiality is not permitted - e.g., for implementations that must meet import restrictions in some countries. Even though no encryption is used, these ciphersuites support authentication of the client and server to each other, and message integrity. This document augments [TLS-PSK] by adding three more ciphersuites (PSK, DHE_PSK, RSA_PSK) with authentication and integrity only - no encryption. The reader is expected to become familiar with [TLS-PSK] standards prior to studying this document.
1.1. Applicability Statement
The ciphersuites defined in this document are intended for a rather limited set of applications, usually involving only a very small number of clients and servers. Even in such environments, other alternatives may be more appropriate.
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
Blumenthal & Goel Standards Track [Page 2]
RFC 4785 PSK NULL Encryption Ciphersuites for TLS January 2007 3. Cipher UsageThe three new ciphersuites proposed here match the three cipher suites defined in [TLS-PSK], except that we define suites with null encryption.
4. Security Considerations
As with all schemes involving shared keys, special care should be taken to protect the shared values and to limit their exposure over time. As this document augments [TLS-PSK], everything stated in its Security Consideration section applies here. In addition, as cipher suites defined here do not support confidentiality, care should be taken not to send sensitive information (such as passwords) over connections protected with one of the ciphersuites defined in this document.
5. IANA Considerations
This document defines three new ciphersuites whose values are in the TLS Cipher Suite registry defined in [TLS].
6. Acknowledgments
The ciphersuites defined in this document are an augmentation to and based on [TLS-PSK].
Blumenthal & Goel Standards Track [Page 3]
RFC 4785 PSK NULL Encryption Ciphersuites for TLS January 2007 7. References 7.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
7.2. Informative References
[SRP] Taylor, D., Wu, T., Mavrogiannopoulos, N., and T. Perrin,
Blumenthal & Goel Standards Track [Page 4]
RFC 4785 PSK NULL Encryption Ciphersuites for TLS January 2007
Full Copyright Statement