THE DEVELOPMENTS OF TLS1.3 AND ITS ATTACK AND DEFENSE

Ruoyu Shen,Shengqi Lu,Yunlei Zhao
DOI: https://doi.org/10.3969/j.issn.1000-386x.2017.11.049
2017-01-01
Abstract:Secure Sockets Layer/Transport Layer Security (SSL/TLS) is intended to provide a secure channel for network communications,providing authentication,confidentiality and integrity.Due to the complexity and loopholes in the design and implementation of protocol leading to many security risks,the development of the new version of TLS1.3 caused widespread concern in the information security academia and industry.We outlined the protocol structure of TLS1.3.On this basis,several innovative changes of TLS1.3 were systematically analysed and combed,such as key schedule,PSK and 0-RTT.We reviewed the attacks received by the protocols for the last 10 years,and extracted the principle of each attack and TLS1.3 response to these attacks.And we made some predictions about the future development of TLS and make some recommendations.
What problem does this paper attempt to address?