A Cryptographic Analysis of the TLS 1.3 Handshake Protocol

A Cryptographic Analysis of the TLS 1.3 Handshake Protocol
复制标题

DOI:
10.1007/s00145-021-09384-1
复制
发表时间:
2020-08
影响因子:
3
通讯作者:
Benjamin Dowling;M. Fischlin;Felix Günther;D. Stebila
Benjamin Dowling;M. Fischlin;Felix Günther;D. Stebila
中科院分区:
计算机科学4区
文献类型:
--
作者:
Benjamin Dowling;M. Fischlin;Felix Günther;D. Stebila

文献摘要

相似文献

我们分析了传输层安全(TLS)协议1.3版的握手协议。我们解决了完整的TLS 1.3握手(一个往返时间模式,具有用于身份验证和(椭圆曲线)Diffie-Hellman临时((EC)DHE)密钥交换的签名),以及使用预共享密钥进行身份验证的缩写恢复/“PSK”模式(具有可选的(EC)DHE密钥交换和零往返时间密钥建立)。我们在还原论安全框架中的分析使用了多阶段密钥交换安全模型,其中在单个TLS 1.3握手中导出的许多会话密钥中的每一个都被标记了各种属性(例如未经身份验证、单方面身份验证、相互身份验证、是否旨在提供前向安全性、如何在协议中使用以及密钥是否受到保护以免受重播攻击)。我们证明了这些TLS 1.3握手协议模式在标准密码学假设下建立了具有所需安全属性的会话密钥。
We analyze the handshake protocol of the Transport Layer Security (TLS) protocol, version 1.3. We address both the full TLS 1.3 handshake (the one round-trip time mode, with signatures for authentication and (elliptic curve) Diffie–Hellman ephemeral ((EC)DHE) key exchange), and the abbreviated resumption/“PSK” mode which uses a pre-shared key for authentication (with optional (EC)DHE key exchange and zero round-trip time key establishment). Our analysis in the reductionist security framework uses a multi-stage key exchange security model, where each of the many session keys derived in a single TLS 1.3 handshake is tagged with various properties (such as unauthenticated versus unilaterally authenticated versus mutually authenticated, whether it is intended to provide forward security, how it is used in the protocol, and whether the key is protected against replay attacks). We show that these TLS 1.3 handshake protocol modes establish session keys with their desired security properties under standard cryptographic assumptions.