{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T04:26:44Z","timestamp":1778128004946,"version":"3.51.4"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2021,5,25]],"date-time":"2021-05-25T00:00:00Z","timestamp":1621900800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,5,25]],"date-time":"2021-05-25T00:00:00Z","timestamp":1621900800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2021,7]]},"DOI":"10.1007\/s00145-021-09387-y","type":"journal-article","created":{"date-parts":[[2021,5,25]],"date-time":"2021-05-25T20:02:25Z","timestamp":1621972945000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Selfie: reflections on TLS 1.3 with PSK"],"prefix":"10.1007","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7273-4797","authenticated-orcid":false,"given":"Nir","family":"Drucker","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9145-7609","authenticated-orcid":false,"given":"Shay","family":"Gueron","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,5,25]]},"reference":[{"key":"9387_CR1","doi-asserted-by":"publisher","unstructured":"D. Adrian, L. Valenta, B. VanderSloot, E. Wustrow, S. Zanella-B\u00e9guelin, P. Zimmermann, K. Bhargavan, Z. Durumeric, P. Gaudry, M. Green, J.A. Halderman, N. Heninger, D. Springall, E. Thom\u00e9, L. Valenta, B. VanderSloot, E. Wustrow, S. Zanella-B\u00e9guelin, P. Zimmermann, Imperfect forward secrecy: how diffie-hellman fails in practice. in: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security - CCS \u201915, (ACM, New York, NY, USA), CCS \u201915, pp 5\u201317, (2015) https:\/\/doi.org\/10.1145\/2810103.2813707","DOI":"10.1145\/2810103.2813707"},{"key":"9387_CR2","unstructured":"N. Aviram, S. Schinzel, J. Somorovsky, N. Heninger, M. Dankel, J. Steube, L. Valenta, D. Adrian, J.A. Halderman, V. Dukhovni, E. K\u00e4sper, S. Cohney, S. Engels, C. Paar, Y. Shavitt, DROWN : Breaking TLS using SSLv2. in proceedings of the 25th USENIX security symposium (August):1\u201318, (2016) https:\/\/www.semanticscholar.org\/paper\/DROWN%3A-Breaking-TLS-Using-SSLv2-Aviram-Schinzel\/2aa0e44b8529de8ee75138eade8aba0bfb9f008f"},{"key":"9387_CR3","doi-asserted-by":"publisher","unstructured":"M. Bellare, P. Rogaway, Entity Authentication and Key Distribution. in Stinson DR (ed) Advances in Cryptology \u2014 CRYPTO\u2019 93, (Springer Berlin Heidelberg, Berlin, Heidelberg), pp. 232\u2013249, (1994) https:\/\/doi.org\/10.1007\/3-540-48329-2_21","DOI":"10.1007\/3-540-48329-2_21"},{"key":"9387_CR4","unstructured":"D. Benjamin, C.A. Wood, Importing External PSKs for TLS. Internet-Draft draft-ietf-tls-external-psk-importer-02, Internet Engineering Task Force, https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-tls-external-psk-importer-02, work in Progress (2019)"},{"key":"9387_CR5","doi-asserted-by":"publisher","unstructured":"K. Bhargavan, B. Blanchet, N. Kobeissi, Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate. in 2017 IEEE symposium on security and privacy (SP), IEEE, pp. 483\u2013502, (2017) https:\/\/doi.org\/10.1109\/SP.2017.26","DOI":"10.1109\/SP.2017.26"},{"key":"9387_CR6","doi-asserted-by":"publisher","unstructured":"C. Cremers, M. Horvat, S. Scott, T. van der Merwe, Automated Analysis and Verification of TLS 1.3: 0-RTT, resumption and delayed authentication. in: 2016 IEEE Symposium on Security and Privacy (SP), pp. 470\u2013485, (2016) https:\/\/doi.org\/10.1109\/SP.2016.35","DOI":"10.1109\/SP.2016.35"},{"key":"9387_CR7","doi-asserted-by":"publisher","unstructured":"C. Cremers, M. Horvat, J. Hoyland, S. Scott, T. van der Merwe, A Comprehensive Symbolic Analysis of TLS 1.3. in: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, (ACM, New York, NY, USA), CCS \u201917, pp. 1773\u20131788, (2017) https:\/\/doi.org\/10.1145\/3133956.3134063","DOI":"10.1145\/3133956.3134063"},{"key":"9387_CR8","unstructured":"B. David, C. Cas, D. Jannik, M. Simon, S. Ralf, S. Benedikt, Tamarin prover. (2019) https:\/\/tamarin-prover.github.io\/#"},{"key":"9387_CR9","doi-asserted-by":"publisher","unstructured":"A. Delignat-Lavaud, K. Bhargavan, Network-based origin confusion attacks against HTTPS virtual hosting. in: Proceedings of the 24th International Conference on World Wide Web, International World Wide Web Conferences Steering Committee, Republic and Canton of Geneva, Switzerland, WWW \u201915, pp. 227\u2013237, (2015) https:\/\/doi.org\/10.1145\/2736277.2741089","DOI":"10.1145\/2736277.2741089"},{"key":"9387_CR10","doi-asserted-by":"crossref","unstructured":"B. Dowling, M. Fischlin, F. G\u00fcnther, D. Stebila, A Cryptographic Analysis of the TLS 1.3 draft-10 Full and Pre-shared Key Handshake Protocol. IACR Cryptology ePrint Archive, https:\/\/eprint.iacr.org\/2016\/081 (2017)","DOI":"10.1145\/2810103.2813653"},{"key":"9387_CR11","unstructured":"N. Drucker, S. Gueron, Selfie : reflections on TLS 1.3 with PSK. IACR Cryptology ePrint Archive, https:\/\/eprint.iacr.org\/2019\/347 (2019)"},{"key":"9387_CR12","doi-asserted-by":"publisher","unstructured":"Z. Durumeric, F. Li, J. Kasten, J. Amann, J. Beekman, M. Payer, N. Weaver, D. Adrian, V. Paxson, M. Bailey, J.A. Halderman, The Matter of Heartbleed. in Proceedings of the 2014 Conference on Internet Measurement Conference, (ACM, New York, NY, USA), IMC \u201914, pp. 475\u2013488, (2014) https:\/\/doi.org\/10.1145\/2663716.2663755","DOI":"10.1145\/2663716.2663755"},{"key":"9387_CR13","doi-asserted-by":"publisher","unstructured":"M. Fischlin, F. G\u00fcnther, Multi-Stage Key Exchange and the Case of Google\u2019s QUIC Protocol. in Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, (ACM, New York, NY, USA), CCS \u201914, pp. 1193\u20131204, (2014) https:\/\/doi.org\/10.1145\/2660267.2660308","DOI":"10.1145\/2660267.2660308"},{"key":"9387_CR14","doi-asserted-by":"crossref","unstructured":"M. Fischlin, F. G\u00fcnther, Replay Attacks on Zero Round-Trip Time: The Case of the TLS 1.3 Handshake Candidates. IACR Cryptology ePrint Archive, https:\/\/eprint.iacr.org\/2017\/082.pdf (2017a)","DOI":"10.1109\/EuroSP.2017.18"},{"key":"9387_CR15","doi-asserted-by":"publisher","unstructured":"M. Fischlin, F. G\u00fcnther, Replay attacks on zero round-trip time: the case of the TLS 1.3 handshake candidates. in 2017 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 60\u201375, (2017b) https:\/\/doi.org\/10.1109\/EuroSP.2017.18","DOI":"10.1109\/EuroSP.2017.18"},{"key":"9387_CR16","doi-asserted-by":"publisher","unstructured":"M. Fischlin, F. Gunther, B. Schmidt, B. Warinschi, Key confirmation in key exchange: a formal treatment and implications for TLS 1.3. in 2016 IEEE Symposium on Security and Privacy (SP), pp. 452\u2013469, (2016) https:\/\/doi.org\/10.1109\/SP.2016.34","DOI":"10.1109\/SP.2016.34"},{"key":"9387_CR17","doi-asserted-by":"publisher","unstructured":"F. Hao, On Robust Key Agreement Based on Public Key Authentication. in R. Sion, (ed) Financial Cryptography and Data Security, (Springer Berlin Heidelberg, Berlin, Heidelberg), pp. 383\u2013390, (2010) https:\/\/doi.org\/10.1007\/978-3-642-14577-3_33","DOI":"10.1007\/978-3-642-14577-3_33"},{"key":"9387_CR18","doi-asserted-by":"publisher","unstructured":"F. Hao, S.F. Shahandashti, The SPEKE protocol revisited\u201d, Security Standardisation Research. (Springer International Publishing, Cham), pp. 26\u201338, (2014) https:\/\/doi.org\/10.1007\/978-3-319-14054-4_2","DOI":"10.1007\/978-3-319-14054-4_2"},{"key":"9387_CR19","unstructured":"N. Heninger, Z. Durumeric, E. Wustrow, J.A. Halderman, Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices. in Presented as part of the 21st$$\\{$$USENIX$$\\}$$Security Symposium ($$\\{$$USENIX$$\\}$$ Security 12), USENIX, (Bellevue, WA), pp. 205\u2013220, (2012) https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/heninger"},{"key":"9387_CR20","doi-asserted-by":"publisher","unstructured":"R. Holz, J. Amann, O. Mehani, M. Wachs, M.A. Kaafar, D. Csiro, TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic Communication. NDSS pp. 21\u201324, (2016) https:\/\/doi.org\/10.14722\/ndss.2016.23055","DOI":"10.14722\/ndss.2016.23055"},{"key":"9387_CR21","doi-asserted-by":"crossref","unstructured":"R. Housley, TLS 1.3 Extension for Certificate-based Authentication with an External Pre-Shared Key. Internet-Draft draft-ietf-tls-tls13-cert-with-extern-psk-00, Internet Engineering Task Force, https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-tls-tls13-cert-with-extern-psk-00, work in Progress (2019)","DOI":"10.17487\/RFC8773"},{"key":"9387_CR22","unstructured":"R. Housley, J. Hoyland, M. Sethi, C.A. Wood, Guidance for External PSK Usage in TLS. Internet-Draft draft-dt-tls-external-psk-guidance-01, Internet Engineering Task Force, https:\/\/datatracker.ietf.org\/doc\/html\/draft-dt-tls-external-psk-guidance-01, work in Progress (2020)"},{"key":"9387_CR23","doi-asserted-by":"publisher","unstructured":"T. Jager, J. Schwenk, J. Somorovsky, On the security of TLS 1.3 and QUIC against weaknesses in PKCS#1 V1.5 encryption. in: Proceedings of the 22Nd ACM SIGSAC Conference on Computer and Communications Security, (ACM, New York, NY, USA), CCS \u201915, pp. 1185\u20131196, (2015) https:\/\/doi.org\/10.1145\/2810103.2813657","DOI":"10.1145\/2810103.2813657"},{"key":"9387_CR24","doi-asserted-by":"crossref","unstructured":"H. Krawczyk, P. Eronen, HMAC-based extract-and-expand key derivation function (HKDF). (2010) https:\/\/tools.ietf.org\/html\/rfc5869","DOI":"10.17487\/rfc5869"},{"key":"9387_CR25","doi-asserted-by":"publisher","unstructured":"H. Krawczyk, H. Wee, The OPTLS Protocol and TLS 1.3. IEEE, pp 81\u201396, (2016) https:\/\/doi.org\/10.1109\/EuroSP.2016.18","DOI":"10.1109\/EuroSP.2016.18"},{"key":"9387_CR26","doi-asserted-by":"crossref","unstructured":"H. Krawczyk, M. Bellare, R. Canetti, HMAC: Keyed-Hashing for Message Authentication. (1997) https:\/\/tools.ietf.org\/html\/rfc2104","DOI":"10.17487\/rfc2104"},{"key":"9387_CR27","doi-asserted-by":"publisher","unstructured":"X. Li, J. Xu, Z. Zhang, D. Feng, H. Hu, Multiple handshakes security of TLS 1.3 candidates. in 2016 IEEE Symposium on Security and Privacy (SP), pp. 486\u2013505, (2016) https:\/\/doi.org\/10.1109\/SP.2016.36","DOI":"10.1109\/SP.2016.36"},{"key":"9387_CR28","doi-asserted-by":"publisher","unstructured":"N. Mavrogiannopoulos, F. Vercauteren, V. Velichkov, B. Preneel, A cross-protocol attack on the TLS protocol. in Proceedings of the 2012 ACM Conference on Computer and Communications Security, (ACM, New York, NY, USA), CCS \u201912, pp. 62\u201372, (2012) https:\/\/doi.org\/10.1145\/2382196.2382206","DOI":"10.1145\/2382196.2382206"},{"key":"9387_CR29","doi-asserted-by":"publisher","unstructured":"A. Menezes, B. Ustaoglu, On reusing ephemeral keys in diffie-hellman key agreement protocols. Int J Appl Cryptol 2(2), 154\u2013158, (2010) https:\/\/doi.org\/10.1504\/IJACT.2010.038308","DOI":"10.1504\/IJACT.2010.038308"},{"key":"9387_CR30","doi-asserted-by":"crossref","unstructured":"T. van der Merwe, An Analysis of the Transport Layer Security Protocol Thyla van der Merwe. PhD thesis, Royal Holloway, University of London, (2018) http:\/\/www.isg.rhul.ac.uk\/~kp\/theses\/TvdMthesis.pdf","DOI":"10.1287\/d2ef8129-4b9c-4711-b5e6-0f1d10ec4c2a"},{"key":"9387_CR31","unstructured":"Mininet Mininet - An Instant Virtual Network on your Laptop (or other PC) version mininet-2.2.2-170321-ubuntu-14.04.4-server-amd64.zip. (2019) http:\/\/mininet.org\/"},{"key":"9387_CR32","unstructured":"OpenSSL OpenSSL commit 38023b87f037f4b832c236dfce2a76272be08763. (2019) https:\/\/github.com\/openssl\/openssl\/commit\/38023b87f037f4b832c236dfce2a76272be08763"},{"key":"9387_CR33","unstructured":"Oracle VirtualBox 5.1. (2018) https:\/\/www.virtualbox.org\/"},{"key":"9387_CR34","unstructured":"T. Perrin, [noise] selfie attack. (2019) https:\/\/moderncrypto.org\/mail-archive\/noise\/2019\/002010.html"},{"key":"9387_CR35","doi-asserted-by":"publisher","unstructured":"E. Rescorla, The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446, (2018) https:\/\/doi.org\/10.17487\/RFC8446, https:\/\/rfc-editor.org\/rfc\/rfc8446.txt","DOI":"10.17487\/RFC8446"},{"key":"9387_CR36","unstructured":"S. Scott, TLS 1.3 modelled in Tamarin. (2018) https:\/\/samscott89.github.io\/TLS13_Tamarin\/"},{"key":"9387_CR37","doi-asserted-by":"publisher","unstructured":"M. Sethi, A. Peltonen, T. Aura, Misbinding Attacks on Secure Device Pairing and Bootstrapping. in Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, (Association for Computing Machinery, New York, NY, USA), Asia CCS \u201919, pp. 453\u2013464, (2019) https:\/\/doi.org\/10.1145\/3321705.3329813","DOI":"10.1145\/3321705.3329813"},{"key":"9387_CR38","doi-asserted-by":"publisher","unstructured":"H. Tschofenig, P. Eronen, Pre-Shared Key Ciphersuites for Transport Layer Security (TLS). RFC 4279, (2005) https:\/\/doi.org\/10.17487\/RFC4279, https:\/\/rfc-editor.org\/rfc\/rfc4279.txt","DOI":"10.17487\/RFC4279"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-021-09387-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-021-09387-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-021-09387-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T15:10:07Z","timestamp":1672240207000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-021-09387-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,25]]},"references-count":38,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2021,7]]}},"alternative-id":["9387"],"URL":"https:\/\/doi.org\/10.1007\/s00145-021-09387-y","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,25]]},"assertion":[{"value":"19 October 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 August 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 August 2020","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 May 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"27"}}