New Features in TLS 1.3
with a Focus on 0-RTT
by Nikita Malyschkin
nikita.malyschkin@rwth-aachen.de
RWTH Aachen University
Proseminar Netzwerke und Internet
24.01.2019
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Why TLS 1.3?
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Cryptography is
the science or practice
of securing communication between multiple parties.
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Different aspects of security
- Confidentiality
- Authenticity
- Integrity
- Nonrepudiation
- Forward Secrecy
- and more ...
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Tools of cryptography
- Symmetric cipher
- Asymmetric cipher
- Hash functions
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Symmetric Cipher
- one key
- same key is used to encrypt and decrypt
- two types
- block cipher
- stream cipher
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Block Cipher
Payload: 127
Key: 13
Encryption: 127 x 13 = 1651
Decryption: 1651 / 13 = 127
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Stream Cipher
Payload: Hello World
Key: 18
Encrypted data: Zwddg Ogjdv
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Asymmetric Cipher
- a pair of two keys
- public key
- private key
- public key encrypts
- private key decrypts
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Asymmetric Cipher
Relies on the fact that decryption can only be done with the private key which can not be deduced from the public key
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Hash Function
Consumes a block of data and computes a representative small block called hash.
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Cryptography in a nutshell
Hash Function Example: Digit sum
Input: 5129576
Digit sum 1: 5+1+2+9+5+7+6 = 35
Digit sum 2: 3+5 = 8
Output: 8
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Transport Layer Security
Transport Layer Security (TLS)
- first introduced in 1995 (called SSL)
- build on top of the transport layer
- protocol to ensure secure communication in the application layer
- consists of two protocols
- handshake protocol
- record protocol
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Transport Layer Security
Handshake protocol
- Establishes the connection between two parties
- Negotiates which cipher suite to use
- Establishes a common secret for the record protocol to use
- Uses asymmetric ciphers
- Further jobs like authentication by certificate
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Transport Layer Security
Record protocol
- Uses the cipher and common secret that are handed down from the handshake protocol
- Encrypts and decrypts the payloads from the application layer
- Ensures integrity of the messages by computing and checking hashes
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
Removal of static RSA
and Diffie-Hellman cipher suites
- "static" in this context means the reuse of of keys for multiple connection
- Problematic because those keys become a high value target
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
Encryption of most handshake messages
- in TLS 1.2 certificates where send before the encryption was established and would leak information about the participants
- in TLS 1.3 certificates are send encrypted
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
Redesign of the handshake protocol
- removing obsolete messages
- doing tasks coherently
- reducing the overall initialisation overhead from 2-RTT to 1-RTT
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
2-RTT (TLS 1.2)
client
server
+ ClientHello
+ Cipher Suites
+ ServerHello
+ Cipher Suite
+ key share
* Certificate
+ Data
+ key share
+ Finished
+ Finished
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
1-RTT (TLS 1.3)
client
server
+ ClientHello
+ Cipher Suites
+ keyshare
+ ServerHello
+ Cipher Suite
+ key share
* Certs
+ Finished
+ Finished
+ Data
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
Remove old ciphers, add new ones
- multiple ciphers have been removed
for example ciphers including MD5 or SHA1 - new ciphers were added
for example ciphers including elliptic curve algorithms
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
Remove compression support
- Since there were ways to exploit compression the leak the sessionID compression was removed completely
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
TLS 1.2 → TLS 1.3
0-RTT
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
0-RTT but how?
- 0-RTT actually means 0-RTT on resumption
- We can not use a 0-RTT handshake when connecting to a server for the first time
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
PreShared Key (PSK)
- key shared by two instances on their first connection
- needed for the 0-RTT handshake
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
0-RTT
client
server
+ ClientHello
+ Cipher Suites
+ key share
+ early data (PSK)
+ ServerHello
+ Cipher Suite
+ key share
+ response
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
BUT! There is a down side!
Using a 0-RTT handshake to resume a connection degrades our security in some way
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
1. Degraded Forward Security
- Since the PSK is reused an attacker that got access to the PSK could read all the early data or even construct valid early data himself
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
2. Possible Replay Attack
- An attacker could record the 0-RTT handshake and replay it to the server
- If the early data send by the client executed some side-effects on the server this could be potentially dangerous
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
0-RTT in depth
This sounds serious, could this be a reason
not to use TLS 1.3?
- No!
- 0-RTT is deactivated by default
- 0-RTT can still be used when the early data is not critical and does not executes side-effects
- for example when requesting static assets from the server
Outline
- Cryptography in a nutshell
- Transport Layer Security
- TLS 1.2 → TLS 1.3
- 0-RTT in depth
- Conclusion
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Conclusion
- Look out for TLS 1.3
- Use the 0-RTT handshake but with caution
Nikita Malyschkin
24.01.2019
New Features in TLS 1.3
Conclusion
Questions?
deck
By Nikita Malyschkin
deck
- 21