Simplified SSL ProtocolRACertB, RB(S)B, E(K, h(msgs Il K))h(msgs /K)BobData encrypted under KAliceSis randomlychosenbyAliceK = h(S,RA,Rb)msgs = all previous messagesForwardsecrecy?SSLandIPSec6
SSL and IPSec 6 Simplified SSL Protocol Alice Bob RA CertB , RB {S}B , E(K, h(msgs || K)) Data encrypted under K h(msgs || K) ◼ S is randomly chosen by Alice ◼ K = h(S,RA,RB) ◼ msgs = all previous messages ◼ Forward secrecy?
SSL Sessions vs ConnectionsSSL designed for use with HTTP 1.0HTTP 1.0 usually opens multiplesimultaneous (parallel) connectionsSSL session establishment is costlyDuetopublickeyoperationsSSL has an efficient protocol foropening new connections given anexisting sessionSSLandIPSec7
SSL and IPSec 7 SSL Sessions vs Connections ◼ SSL designed for use with HTTP 1.0 ◼ HTTP 1.0 usually opens multiple simultaneous (parallel) connections ◼ SSL session establishment is costly ❑ Due to public key operations ◼ SSL has an efficient protocol for opening new connections given an existing session
SSL ConnectionRARb, h(msgs II K)h(msgs Il K)Data encrypted under KBobAliceAssumingSSLsessionexistsSo S is already known to Alice and BobAgain, K = h(S,Ra,Rb) No public key operations!(relieson known S)SSL and IPSec8
SSL and IPSec 8 SSL Connection Alice Bob RA RB, h(msgs || K) h(msgs || K) Data encrypted under K ◼ Assuming SSL session exists ◼ So S is already known to Alice and Bob ◼ Again, K = h(S,RA,RB ) ❑ No public key operations! (relies on known S)
IPSecSSL and IPSec9
SSL and IPSec 9 IPSec