Contact emails
[email protected]

Explainer
https://github.com/w3c/webtransport/blob/main/explainer.md


Specification
https://www.w3.org/TR/webtransport/#dom-webtransport-exportkeyingmaterial


Summary
Adds WebTransport.exportKeyingMaterial(), which allows an application to derive 
cryptographic keying material bound to an established WebTransport session. The 
method accepts application provided binary label and context values and a 
requested output length and returns a Promise<Uint8Array>. Chromium supports 
label and context values up to 255 bytes and output lengths from 1 through 4096 
bytes. For WebTransport over HTTP/3, Chromium includes the WebTransport CONNECT 
stream ID in the TLS exporter context. This ensures that separate WebTransport 
sessions derive different keying material even when they share the same 
underlying HTTP/3 connection.


Blink component
Blink>Network>WebTransport


Web Feature ID
webtransport


Motivation
Applications sometimes need cryptographic keying material bound to an 
authenticated transport session, for example to bind an application protocol, 
authentication exchange, or application-level encryption context to a 
WebTransport session without performing an additional key exchange. TLS 
exporters derive application-specific secret material without exposing the TLS 
traffic keys. WebTransport.exportKeyingMaterial() exposes this mechanism 
through application-provided binary label and context values and an explicit 
output length. Multiple WebTransport sessions can share one HTTP/3 connection. 
Chromium therefore includes the WebTransport CONNECT stream ID in the exporter 
context, ensuring that different sessions derive different keying material even 
when callers use identical application labels and contexts.


Initial public proposal
https://github.com/w3c/webtransport/issues/411


Goals for experimentation
None


Requires code in //chrome?
False


Tracking bug
https://issues.chromium.org/issues/556304550


Measurement
Measure correctness and interoperability through Web Platform Tests, the 
WebTransport IDL harness, wpt.fyi results, and feedback from WebTransport 
application and server implementers. Usage will be measured with a WebFeature 
use counter recorded when WebTransport.exportKeyingMaterial() is called. No 
dedicated UMA metric is currently planned, the use counter is sufficient to 
measure web-exposed API adoption


Availability expectation
Expected to become available across major browser engines as part of the W3C 
WebTransport specification. Firefox has implemented an earlier two-argument 
version of the method but has not yet been verified as supporting the current 
required three-argument signature. No WebKit implementation of this specific 
method has been verified.


Adoption expectation
Expected to be used by specialized WebTransport protocols that require 
transport-bound authentication, channel binding, or application key derivation. 
It is not expected to be used by most basic WebTransport applications.


Adoption plan
Adoption is expected to occur through WebTransport documentation, interoperable 
WPT coverage, and use by protocol implementations that require transport-bound 
keying material. No origin trial or broad developer campaign is currently 
planned


Estimated milestones

No milestones specified



Anticipated spec changes

Open questions about a feature may be a source of future web compat or interop 
issues. Please list open issues (eg links to known github issues in the project 
for the feature specification) whose resolution may introduce web 
compat/interop risk (eg, changing to naming or structure of the API in a 
non-backward-compatible way).
No API-shape changes are currently anticipated. Chromium implements the current 
required three-argument method from the WebTransport Candidate Recommendation. 
The protocol-level exporter construction should be rechecked against the 
referenced WebTransport overview specification before stable launch.


Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/4860330806214656?gate=4833344016744448


This intent message was generated by Chrome Platform Status.

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6aa97628.f13237a8.13ec.001a.GAE%40google.com.

Reply via email to