New Features in TLS 1.3

with a Focus on 0-RTT

by Nikita Malyschkin
nikita.malyschkin@rwth-aachen.de

        RWTH Aachen University
        Proseminar Netzwerke und Internet

24.01.2019

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Why TLS 1.3?

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Cryptography is

the science or practice

of securing communication between multiple parties.

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Different aspects of security

 

  • Confidentiality
  • Authenticity
  • Integrity
  • Nonrepudiation
  • Forward Secrecy
  • and more ...

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Tools of cryptography

 

  • Symmetric cipher
  • Asymmetric cipher
  • Hash functions

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Symmetric Cipher

 

  • one key
  • same key is used to encrypt and decrypt
  • two types
    • block cipher
    • stream cipher

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Block Cipher

 

Payload: 127

Key: 13

 

Encryption: 127 x 13 = 1651

Decryption: 1651 / 13 = 127

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Stream Cipher

 

Payload: Hello World

Key: 18

 

Encrypted data: Zwddg Ogjdv

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Asymmetric Cipher

 

  • a pair of two keys
    • public key
    • private key
  • public key encrypts
  • private key decrypts

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Asymmetric Cipher

 

Relies on the fact that decryption can only be done with the private key which can not be deduced from the public key

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Hash Function

 

Consumes a block of data and computes a representative small block called hash.

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Cryptography in a nutshell

Hash Function Example: Digit sum

 

Input: 5129576
Digit sum 1: 5+1+2+9+5+7+6 = 35

Digit sum 2: 3+5 = 8

Output: 8

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Transport Layer Security

Transport Layer Security (TLS)

 

  • first introduced in 1995 (called SSL)
  • build on top of the transport layer
  • protocol to ensure secure communication in the application layer
  • consists of two protocols
    • handshake protocol
    • record protocol

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Transport Layer Security

Handshake protocol

 

  • Establishes the connection between two parties
  • Negotiates which cipher suite to use
  • Establishes a common secret for the record protocol to use
  • Uses asymmetric ciphers
  • Further jobs like authentication by certificate

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Transport Layer Security

Record protocol

 

  • Uses the cipher and common secret that are handed down from the handshake protocol
  • Encrypts and decrypts the payloads from the application layer
  • Ensures integrity of the messages by computing and checking hashes

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

Removal of static RSA

and Diffie-Hellman cipher suites

 

  • "static" in this context means the reuse of of keys for multiple connection
  • Problematic because those keys become a high value target

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

Encryption of most handshake messages

 

  • in TLS 1.2 certificates where send before the encryption was established and would leak information about the participants
  • in TLS 1.3 certificates are send encrypted

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

Redesign of the handshake protocol

 

  • removing obsolete messages
  • doing tasks coherently
  • reducing the overall initialisation overhead from 2-RTT to 1-RTT

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

2-RTT (TLS 1.2)

client

server

+ ClientHello

+ Cipher Suites

+ ServerHello

+ Cipher Suite

+ key share

* Certificate

+ Data

+ key share
+ Finished

+ Finished

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

1-RTT (TLS 1.3)

client

server

+ ClientHello

+ Cipher Suites

+ keyshare

+ ServerHello

+ Cipher Suite

+ key share

* Certs

+ Finished

+ Finished

+ Data

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

Remove old ciphers, add new ones

 

  • multiple ciphers have been removed
    for example ciphers including MD5 or SHA1
  • new ciphers were added
    for example ciphers including elliptic curve algorithms

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

Remove compression support

 

  • Since there were ways to exploit compression the leak the sessionID compression was removed completely

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

TLS 1.2 → TLS 1.3

0-RTT

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

0-RTT but how?

 

  • 0-RTT actually means 0-RTT on resumption
  • We can not use a 0-RTT handshake when connecting to a server for the first time

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

PreShared Key (PSK)

 

  • key shared by two instances on their first connection
  • needed for the 0-RTT handshake

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

0-RTT

client

server

+ ClientHello

+ Cipher Suites

+ key share

+ early data (PSK)

+ ServerHello

+ Cipher Suite

+ key share

+ response

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

BUT! There is a down side!

 

Using a 0-RTT handshake to resume a connection degrades our security in some way

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

1. Degraded Forward Security

 

  • Since the PSK is reused an attacker that got access to the PSK could read all the early data or even construct valid early data himself

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

2. Possible Replay Attack

 

  • An attacker could record the 0-RTT handshake and replay it to the server
  • If the early data send by the client executed some side-effects on the server this could be potentially dangerous

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

0-RTT in depth

This sounds serious, could this be a reason

not to use TLS 1.3?

 

  • No!
  • 0-RTT is deactivated by default
  • 0-RTT can still be used when the early data is not critical and does not executes side-effects
  • for example when requesting static assets from the server

Outline

  • Cryptography in a nutshell
  • Transport Layer Security
  • TLS 1.2 → TLS 1.3
  • 0-RTT in depth
  • Conclusion

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Conclusion

  1. Look out for TLS 1.3
  2. Use the 0-RTT handshake but with caution

​Nikita Malyschkin

24.01.2019

New Features in TLS 1.3

Conclusion

Questions?

Made with Slides.com