<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.tiloca-tls-dos-handshake" target="https://datatracker.ietf.org/doc/html/draft-tiloca-tls-dos-handshake-01">
   <front>
      <title>Extension for protecting (D)TLS handshakes against Denial of Service</title>
      <author initials="M." surname="Tiloca" fullname="Marco Tiloca">
         <organization>RISE SICS AB</organization>
      </author>
      <author initials="L." surname="Seitz" fullname="Ludwig Seitz">
         <organization>RISE SICS AB</organization>
      </author>
      <author initials="M." surname="Hoeve" fullname="Maarten Hoeve">
         <organization>ENCS</organization>
      </author>
      <author initials="O." surname="Bergmann" fullname="Olaf Bergmann">
         <organization>Universitaet Bremen TZI</organization>
      </author>
      <date month="October" day="28" year="2017" />
      <abstract>
	 <t>   This document describes an extension for TLS and DTLS to protect the
   server from Denial of Service attacks against the handshake protocol,
   carried out by an on-path adversary.  The extension includes a nonce
   and a Message Authentication Code (MAC) over that nonce, encoded as a
   Handshake Token that a Trust Anchor entity computes and provides to
   the client.  The server registered at the Trust Anchor verifies the
   MAC to determine whether continuing or aborting the handshake.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-tiloca-tls-dos-handshake-01" />
   
</reference>
