Network Working Group E. Rescorla Request for Comments: 5289 RTFM, Inc. Category: Informational August 2008TLS Elliptic Curve Cipher Suites with SHA-256/384 and AES Galois Counter Mode (GCM)
Rescorla Informational [Page 1]
RFC 5289 TLS ECC New MAC August 2008 1. IntroductionRFC 4492 [RFC4492] describes Elliptic Curve Cryptography (ECC) cipher suites for Transport Layer Security (TLS). However, all of the RFC 4492 suites use HMAC-SHA1 as their MAC algorithm. Due to recent analytic work on SHA-1 [Wang05], the IETF is gradually moving away from SHA-1 and towards stronger hash algorithms. This document specifies TLS ECC cipher suites that use SHA-256 and SHA-384 [SHS] rather than SHA-1.
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Cipher Suites
This document defines 16 new cipher suites to be added to TLS. All use Elliptic Curve Cryptography for key exchange and digital signature, as defined in RFC 4492.
3.1. HMAC-Based Cipher Suites
The first eight cipher suites use AES [AES] in Cipher Block Chaining (CBC) [CBC] mode with an HMAC-based MAC:
Rescorla Informational [Page 2]
RFC 5289 TLS ECC New MAC August 2008
o For cipher suites ending with _SHA256, the PRF is the TLS PRF [RFC5246] with SHA-256 as the hash function. The MAC is HMAC [RFC2104] with SHA-256 as the hash function.
3.2. Galois Counter Mode-Based Cipher Suites
The second eight cipher suites use the same asymmetric algorithms as those in the previous section but use the new authenticated encryption modes defined in TLS 1.2 with AES in Galois Counter Mode (GCM) [GCM]:
4. Security Considerations
The security considerations in RFC 4346, RFC 4492, and [RFC5288] apply to this document as well. In addition, as described in [RFC5288], these cipher suites may only be used with TLS 1.2 or greater.
Rescorla Informational [Page 3]
RFC 5289 TLS ECC New MAC August 2008 5. IANA ConsiderationsIANA has assigned the following values for these cipher suites:
6. Acknowledgements
This work was supported by the US Department of Defense.7. References 7.1. Normative References[RFC2104] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed-
Rescorla Informational [Page 4]
RFC 5289 TLS ECC New MAC August 2008
[RFC5288] Salowey, J., Choudhury, A., and D. McGrew, "AES-GCM Cipher
7.2. Informative References
[Wang05] Wang, X., Yin, Y., and H. Yu, "Finding Collisions in the
Rescorla Informational [Page 5]
RFC 5289 TLS ECC New MAC August 2008
Full Copyright Statement