摘要
基于SSL/TLS构建的安全应用中通常采用了独立端口和磋商升级的策略。本文详细论述了这两种策略的基本原理,比较了它们各自的优缺点,进而对实施过程中遇到降级攻击以及因代理语义不能交互而导致连接失败的问题进行了分析,并针对这些问题提出了相应的解决办法。
Most SSL/TLS-based security applications adopt two strategies: the separate port strategy and the upward negotiation strategy. This paper discusses the principle of the two strategies and compares the advantages and disadvantages of the two, and then analyzes the problems of downgrade attacks and the difference of semantics causing connection failures which emerge when the two strategies are being implemented. And the solutions to these problems are also promoted.
出处
《计算机工程与科学》
CSCD
2006年第4期23-25,83,共4页
Computer Engineering & Science