期刊文献+

TLS1.3协议更新发展及其攻击与防御研究 被引量:6

THE DEVELOPMENTS OF TLS1.3 AND ITS ATTACK AND DEFENSE
下载PDF
导出
摘要 SSL/TLS(Secure Sockets Layer/Transport Layer Security)协议旨在为网络通信提供安全的信道,为通信双方提供认证、机密性和完整性。由于协议的复杂及其设计和实现上的漏洞导致许多安全隐患,新版本TLS1.3的制定引起信息安全学术界和产业界广泛的关注。概述TLS1.3的协议结构。在此基础上,对TLS1.3几个革新性的改变:密钥编排表、PSK和0-RTT进行了系统性地分析与梳理。对近10年协议受到的攻击按照协议的层次分类进行概述,提炼出每种攻击的原理以及TLS1.3针对这些攻击作出的应对措施。对TLS协议的未来发展作出预测并提出建议。 Secure Sockets Layer/Transport Layer Security (SSL/TLS) is intended to provide a secure channel for network communications, providing authentication, confidentiality and integrity. Due to the complexity and loopholes in the design and implementation of protocol leading to many security risks, the development of the new version of TLS1.3 caused widespread concern in the information security academia and industry. We outlined the protocol structure of TLS1.3. On this basis, several innovative changes of TLS1.3 were systematically analysed and combed, such as key schedule, PSK and 0-RTT. We reviewed the attacks received by the protocols for the last 10 years, and extracted the principle of each attack and TLS1. 3 response to these attacks. And we made some predictions about the future development of TLS and make some recommendations.
出处 《计算机应用与软件》 2017年第11期264-269,329,共7页 Computer Applications and Software
基金 国家自然科学基金项目(61472084) 上海市科委项目(16DZ1100200)
关键词 TLS1. 3 SSL/TLS 攻击 0-RTT PSK 密钥生成表 TLS1.3 SSL/TLS attack 0-RTF PSK Key schedule
  • 相关文献

参考文献1

二级参考文献16

  • 1国家信息安全漏洞共享平台.关于Open SSL存在高危漏洞可被利用发起大规模攻击的情况通报[EB/OL].[2014-04-09].http://www.cnvd.org.cn/webinfo/show/3399.
  • 2CVE.CVE-2014-0160[EB/OL].[2014-04-07].http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160.
  • 3Open SSL.Open SSL security advisory[EB/OL].[2014-04-07].http://www.openssl.org/news/secadv_20140407.txt.
  • 4乌云漏洞平台.关键字“Heart Bleed”漏洞搜索结果[EB/OL].[2014-04-02].http://www.wooyun.org/searchbug.php?q=Heartbleed&showall=1.
  • 5Shankland S.‘Heartbleed’bug undoes Web encryption,reveals Yahoo passwords[EB/OL].[2014-04-08].http://www.cnet.com/news/heartbleed-bug-undoes-web-encryption-revealsuser-passwords/.
  • 6Metasploit.Weekly metasploit update:heartbleed and firefox passwords[EB/OL].[2014-04-17].https://community.rapid7.com/community/metasploit/blog/2014/04/17/weekly-metasploitupdate.
  • 7Freier A,Karlton P,Kocher P.RFC 6101 The Secure Sockets Layer(SSL)protocol[S].Version 3.0,2011-08.
  • 8Santesson S.RFC 4680 TLS Handshake message for supplemental data[S].2006-09.
  • 9Seggelmann R,Tuexen M,Williams M.RFC 6520 Transport Layer Security(TLS)and Datagram Transport Layer Security(DTLS)heartbeat extension[S].2012-02.
  • 10Hoffman P.RFC 2487 SMTP service extension for secure SMTP over TLS[S].1999-01.

共引文献4

同被引文献38

引证文献6

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部