@techreport{putman-tls13-preshared-dh-00, number = {draft-putman-tls13-preshared-dh-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-putman-tls13-preshared-dh/00/}, author = {Tony Putman}, title = {{Authenticated Key Agreement using Pre-Shared Asymmetric Keypairs for (Datagram) Transport Layer Security ((D)TLS) Protocol version 1.3}}, pagetotal = 21, year = 2018, month = jan, day = 31, abstract = {This document defines an authenticated key agreement method for the Transport Layer Security (TLS) protocol version 1.3. The authentication method requires that the server (and optionally client) is pre-provisioned with a unique long-term static asymmetric Finite Field Diffie-Hellman (DH) or Elliptic Curve Diffie-Hellman (ECDH) keypair; the peer must be able to obtain the public key of the endpoint via an out-of-band mechanism (e.g. pre-provisioning). The handshake provides ephemeral (EC)DH keys, and a common key schedule is agreed using Double- or Triple-(EC)DH. Confirmation of knowledge of the key schedule provides server (and optionally client) authentication.}, }