Contact emails [email protected]
Explainer https://github.com/w3c/webtransport/blob/main/explainer.md Specification https://www.w3.org/TR/webtransport/#dom-webtransport-exportkeyingmaterial Summary Adds WebTransport.exportKeyingMaterial(), which allows an application to derive cryptographic keying material bound to an established WebTransport session. The method accepts application provided binary label and context values and a requested output length and returns a Promise<Uint8Array>. Chromium supports label and context values up to 255 bytes and output lengths from 1 through 4096 bytes. For WebTransport over HTTP/3, Chromium includes the WebTransport CONNECT stream ID in the TLS exporter context. This ensures that separate WebTransport sessions derive different keying material even when they share the same underlying HTTP/3 connection. Blink component Blink>Network>WebTransport Web Feature ID webtransport Motivation Applications sometimes need cryptographic keying material bound to an authenticated transport session, for example to bind an application protocol, authentication exchange, or application-level encryption context to a WebTransport session without performing an additional key exchange. TLS exporters derive application-specific secret material without exposing the TLS traffic keys. WebTransport.exportKeyingMaterial() exposes this mechanism through application-provided binary label and context values and an explicit output length. Multiple WebTransport sessions can share one HTTP/3 connection. Chromium therefore includes the WebTransport CONNECT stream ID in the exporter context, ensuring that different sessions derive different keying material even when callers use identical application labels and contexts. Initial public proposal https://github.com/w3c/webtransport/issues/411 Goals for experimentation None Requires code in //chrome? False Tracking bug https://issues.chromium.org/issues/556304550 Measurement Measure correctness and interoperability through Web Platform Tests, the WebTransport IDL harness, wpt.fyi results, and feedback from WebTransport application and server implementers. Usage will be measured with a WebFeature use counter recorded when WebTransport.exportKeyingMaterial() is called. No dedicated UMA metric is currently planned, the use counter is sufficient to measure web-exposed API adoption Availability expectation Expected to become available across major browser engines as part of the W3C WebTransport specification. Firefox has implemented an earlier two-argument version of the method but has not yet been verified as supporting the current required three-argument signature. No WebKit implementation of this specific method has been verified. Adoption expectation Expected to be used by specialized WebTransport protocols that require transport-bound authentication, channel binding, or application key derivation. It is not expected to be used by most basic WebTransport applications. Adoption plan Adoption is expected to occur through WebTransport documentation, interoperable WPT coverage, and use by protocol implementations that require transport-bound keying material. No origin trial or broad developer campaign is currently planned Estimated milestones No milestones specified Anticipated spec changes Open questions about a feature may be a source of future web compat or interop issues. Please list open issues (eg links to known github issues in the project for the feature specification) whose resolution may introduce web compat/interop risk (eg, changing to naming or structure of the API in a non-backward-compatible way). No API-shape changes are currently anticipated. Chromium implements the current required three-argument method from the WebTransport Candidate Recommendation. The protocol-level exporter construction should be rechecked against the referenced WebTransport overview specification before stable launch. Link to entry on the Chrome Platform Status https://chromestatus.com/feature/4860330806214656?gate=4833344016744448 This intent message was generated by Chrome Platform Status. -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6aa97628.f13237a8.13ec.001a.GAE%40google.com.
