Content delivery over TLS: a cryptographic analysis of keyless SSL

Content delivery over TLS: a cryptographic analysis of keyless SSL
复制标题

通过 TLS 进行内容交付:无密钥 SSL 的加密分析

DOI:
--
复制
发表时间:
2017
期刊:
European Symposium on Security and Privacy
影响因子:
--
通讯作者:
Benjamin Richard
Benjamin Richard
中科院分区:
--
文献类型:
--
作者:
K. Bhargavan;Ioana Boureanu;Pierre;Cristina Onete;Benjamin Richard

文献摘要

被引文献

相似文献

传输层安全(TLS)协议旨在允许客户端和服务器这两方在不安全的网络上安全地通信。然而,当TLS连接通过中间体代理时,如内容分发网络(CDN),该协议的标准端到端安全保证不再适用。在本文中,我们研究了Keyless SSL提供的安全保证,这是CloudFlare目前部署的CDN架构,它包含两个TLS 1.2握手以获得代理TLS连接。我们展示了新的攻击,表明无密钥SSL不符合其预期的安全目标。这些攻击已报告给CloudFlare,我们正在讨论修复程序。我们认为,代理TLS握手需要一个新的,更强大的,三方安全定义。我们提出了3(S)ACCE安全性,这是对2方ACCE安全性定义的概括,该定义已在以前的几个TLS证明中使用。我们修改了Keyless SSL,并证明我们的修改保证了3(S)ACCE安全性,假设每个TLS 1.2连接都是ACCE安全性。我们还提出了一个新的设计,无钥TLS 1.3,并证明它实现了3(S)ACCE安全,假设TLS 1.3握手实现了认证的2方密钥交换。值得注意的是,我们表明,在无密钥TLS 1.3中的安全认证计算量更小,并且需要对证书基础设施进行更简单的假设,而不是我们为无密钥SSL提出的修复方案。我们的研究结果表明,代理TLS架构,目前使用的一些CDN,可能容易受到微妙的攻击,值得密切关注。
The Transport Layer Security (TLS) protocol is designed to allow two parties, a client and a server, to communicate securely over an insecure network. However, when TLS connections are proxied through an intermediate middlebox, like a Content Delivery Network (CDN), the standard endto- end security guarantees of the protocol no longer apply. In this paper, we investigate the security guarantees provided by Keyless SSL, a CDN architecture currently deployed by CloudFlare that composes two TLS 1.2 handshakes to obtain a proxied TLS connection. We demonstrate new attacks that show that Keyless SSL does not meet its intended security goals. These attacks have been reported to CloudFlare and we are in the process of discussing fixes. We argue that proxied TLS handshakes require a new, stronger, 3-party security definition. We present 3(S)ACCEsecurity, a generalization of the 2-party ACCE security definition that has been used in several previous proofs for TLS. We modify Keyless SSL and prove that our modifications guarantee 3(S)ACCE-security, assuming ACCE-security for the individual TLS 1.2 connections. We also propose a new design for Keyless TLS 1.3 and prove that it achieves 3(S)ACCEsecurity, assuming that the TLS 1.3 handshake implements an authenticated 2-party key exchange. Notably, we show that secure proxying in Keyless TLS 1.3 is computationally lighter and requires simpler assumptions on the certificate infrastructure than our proposed fix for Keyless SSL. Our results indicate that proxied TLS architectures, as currently used by a number of CDNs, may be vulnerable to subtle attacks and deserve close attention.