%% You should probably cite draft-sullivan-tls-xof-schedule instead of this I-D. @techreport{sullivan-tls-xof-ciphers-00, number = {draft-sullivan-tls-xof-ciphers-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sullivan-tls-xof-ciphers/00/}, author = {Nick Sullivan}, title = {{TLS 1.3 Cipher Suites with Alternative Key-Schedule Profiles}}, pagetotal = 46, year = 2026, month = jul, day = 6, abstract = {TLS 1.3 builds its key schedule on HKDF over the cipher suite's hash. This document defines TLS 1.3 cipher suites that build it on a deck function over a single permutation instead, the one a deployment already carries when it uses SHA-3, ML-KEM, or ML-DSA. One permutation then runs the whole schedule, and a full handshake takes about a third of the permutation calls an HKDF schedule over that permutation would. Such a cipher suite names an AEAD algorithm together with a schedule profile that defines every key-schedule function the connection uses. The profile follows from the negotiated cipher suite alone, so no new extension is defined and the TLS 1.3 state machine and wire format are unchanged. Two profiles are defined, one on the standard SHA-3 function and one on a faster reduced-round variant of it.}, }