FINDING · DEFENSE

BTP achieves forward secrecy over unidirectional transports—where ephemeral in-band key exchange is impossible—by using a one-way key derivation function (NIST SP 800-108) to produce sequential temporary secrets from an initial shared secret. Once both devices destroy a given temporary secret, no keys derived from it can be reconstructed even if devices are later compromised.

From 2012-rogers-secureSecure Communication over Diverse Transports · §2, §5.2–5.3 · 2012 · Workshop on Privacy in the Electronic Society

Implications

Tags

censors
generic
defenses
meta-resistance

Extracted by claude-sonnet-4-6 — review before relying.