Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTT

Session Resumption Protocols and Efficient Forward Security for TLS 1.3 0-RTT
复制标题

TLS 1.3 0-RTT 的会话恢复协议和高效前向安全性

DOI:
10.1007/s00145-021-09385-0
复制
发表时间:
2019
影响因子:
3
通讯作者:
Tibor Jager
Tibor Jager
中科院分区:
计算机科学4区
文献类型:
--
作者:
Nimrod Aviram;Kai Gellert;Tibor Jager

文献摘要

参考文献

被引文献

相似文献

TLS 1.3 0-RTT模式使重新连接到服务器的客户端能够在“0-RTT”(“零往返时间”)中发送加密的应用层数据,而无需事先进行交互式握手。这基本上要求服务器在收到客户端的第一条消息时重建前一个会话的加密秘密。实现这一点的标准技术是会话缓存或会话票据。前者提供前向安全性和抵抗重放攻击,但需要大量的服务器端存储。后者需要的存储量可以忽略不计,但不提供前向安全性,并且已知容易受到重放攻击。在本文中,我们首先正式定义会话恢复协议作为一个抽象的角度对机制,如会话缓存和会话票。我们给出了一个新的通用建设,可证明提供前向安全性和重放弹性,基于可穿孔伪随机函数(PPRF)。我们表明,我们的构造可以立即用于TLS 1.3 0-RTT,并由服务器单方面部署,而不需要对客户端或协议进行任何更改。为此,我们使用TLS 1.3提出了新构造的通用组合,并证明了其安全性。这产生了第一个实现所有消息(包括0-RTT数据)的前向安全性的构造。然后,我们描述了两种新的PPRF结构,它们特别适合用于TLS 1.3中的前向安全和重放弹性会话恢复。第一种构造是基于强RSA假设。与标准会话缓存相比,对于“128位安全性”,当以这样一种方式实例化时,它将所需的服务器存储减少了近20倍,即密钥推导和打孔平均比RSA组中的一次完整求幂便宜。因此,1 GB的会话缓存可以仅用大约51 MB的存储来替换,这显著减少了所需的安全内存量。对于更大的安全参数或以更昂贵的计算作为交换,实现了甚至更大的存储减少。第二个构造结合了一个标准的二叉树PPRF与一个新的“域扩展”技术。对于合理的参数选择,与标准会话缓存相比,这将所需的存储减少了多达5倍。它只采用对称加密,适用于高流量场景,每秒可以处理数千张票。
The TLS 1.3 0-RTT mode enables a client reconnecting to a server to send encrypted application-layer data in “0-RTT” (“zero round-trip time”), without the need for a prior interactive handshake. This fundamentally requires the server to reconstruct the previous session’s encryption secrets upon receipt of the client’s first message. The standard techniques to achieve this are session caches or, alternatively, session tickets. The former provides forward security and resistance against replay attacks, but requires a large amount of server-side storage. The latter requires negligible storage, but provides no forward security and is known to be vulnerable to replay attacks. In this paper, we first formally define session resumption protocols as an abstract perspective on mechanisms like session caches and session tickets. We give a new generic construction that provably provides forward security and replay resilience, based on puncturable pseudorandom functions (PPRFs). We show that our construction can immediately be used in TLS 1.3 0-RTT and deployed unilaterally by servers, without requiring any changes to clients or the protocol. To this end, we present a generic composition of our new construction with TLS 1.3 and prove its security. This yields the first construction that achieves forward security for all messages, including the 0-RTT data. We then describe two new constructions of PPRFs, which are particularly suitable for use for forward-secure and replay-resilient session resumption in TLS 1.3. The first construction is based on the strong RSA assumption. Compared to standard session caches, for “128-bit security” it reduces the required server storage by a factor of almost 20, when instantiated in a way such that key derivation and puncturing together are cheaper on average than one full exponentiation in an RSA group. Hence, a 1 GB session cache can be replaced with only about 51 MBs of storage, which significantly reduces the amount of secure memory required. For larger security parameters or in exchange for more expensive computations, even larger storage reductions are achieved. The second construction combines a standard binary tree PPRF with a new “domain extension” technique. For a reasonable choice of parameters, this reduces the required storage by a factor of up to 5 compared to a standard session cache. It employs only symmetric cryptography, is suitable for high-traffic scenarios, and can serve thousands of tickets per second.
DOI: 10.1145/2660267.2660308
发表时间: 2014-11
期刊: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
M. Fischlin;Felix Günther
通讯作者: M. Fischlin;Felix Günther