On the Security of TLS Resumption and Renegotiation

来源 :中国通信 | 被引量 : 0次 | 上传用户:loverbeyond
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The Transport Layer Security(TLS) protocol is the most important standard on the Internet for key exchange. TLS standard supports many additional handshake modes such as resumption and renegotiation besides the full handshake. The interaction and dependence of different modes may lead to some practical attacks on TLS. In 2014, Bhargavan et al. described a triple handshake attack on TLS 1.2 by exploiting the sequential running of three different modes of TLS, which can lead to a client impersonation attack after the third handshake. Subsequently, TLS 1.2 was patched with the extended master secret extension of RFC 7627 to prevent this attack. In this paper we introduce a new definition of “uniqueness” and present a renegotiable & resumable ACCE security model. We identify the triple handshake attack within the new model, and furthermore show TLS with the proposed fix can be proven secure in our model. The Transport Layer Security (TLS) protocol is the most important standard on the Internet for key exchange. TLS standard supports many additional handshake modes such as resumption and renegotiation besides the full handshake. The interaction and dependence of different modes may lead to some practical attacks on TLS. In 2014, Bhargavan et al. described a triple handshake attack on TLS 1.2 by exploiting the sequential running of three different modes of TLS, which can lead to a client impersonation attack after the third handshake. TLS 1.2 was patched with the extended master secret extension of RFC 7627 to prevent this attack. In this paper we introduce a new definition of “uniqueness” and present a renegotiable & resumable ACCE security model. We identify the triple handshake attack within the new model, and show TLS with the proposed fix can be proven secure in our model.
其他文献
期刊
新课程改革的背景下,教师应引导学生合理利用课程资源,以现有文本为基础,将文本教学与阅读教学、写作教学相结合,来提高学生的读写能力,促进每位学生的语文素养养成.初中语文
期刊
期刊
期刊
胸腔穿刺是治疗恶性胸腔积液主要手段之一。 1997年 4月— 2 0 0 0年 6月采用静脉留置针行胸腔穿刺治疗恶性胸腔积液 48例 ,取得满意疗效 ,现总结如下。1 临床资料  经查
该文从挂篮荷载计算、施工流程、支座及临时固结施工、挂篮安装及试验、合拢段施工、模板制作安装、钢筋安装、混凝土的浇筑及养生、测量监控等方面人手,介绍了S226海滨大桥
期刊
中考英语复习课教学,不单是学年的教学任务,也是整个初中阶段所有英语知识的综合。要让学生在短短几个月内把错综复杂的内容融会贯通显然是不可能的,因此采用有效的复习方法
随着全球经济的不断发展,水上运输发展迅速,船舶的种类越来越多,数量也迅猛增长。这给船舶航行带来了更多困难,尤其是在港口水域,大小船舶密度大,通航环境复杂,航行比海上更