Improving the security of Internet exchanges

March 20, 2009

(PhysOrg.com) -- TLS is the main protocol used today to secure exchanges over the Internet. The protocol has been subject to attacks in recent years, resulting in identity theft and data tampering. To address these problems, Mohamad Badra, CNRS researcher at LIMOS (France), has worked in collaboration with the Ineovation company to develop two new extensions to the TLS protocol. These standards were recently published by the Internet Engineering Task Force, an international community which develops Internet standards. These are available to programmers and software vendors for use in information systems.

The SSL/TLS was developed in 1995 by Netscape and has become the main protocol used worldwide to and transactions over the Internet (e-commerce, banking, online auctions, , etc.). Due to problems related to the encryption algorithms used by TLS, the protocol has several major drawbacks, notably concerning collision attacks. This also raises concerns about authentication based on digital certificates. In association with Ineovation, Mohamad Badra—CNRS researcher at the Laboratoire d'information, de modélisation et d'optimisation des systčmes in Clermont-Ferrand, France—has developed two new extensions to the TLS protocol in order to improve its security.

The first extension concerns the key exchange method. A key is a parameter required to encrypt and decrypt data. Keys are either symmetric or asymmetric. With a symmetric key, the same key is used for both encryption and decryption. To ensure secure exchanges, this key must remain secret; it must be exchanged between the sender and the receiver over a secure channel prior to the data exchange. In the case of , a “public” key (known to all) is used to encrypt the data to be sent to the recipient. The recipient then uses a private (secret) key to decrypt the data. The advantage is that asymmetric keys do not require a secure channel prior to the key exchange. The extension developed by Badra uses a new method for exchanging keys, based on the association between an asymmetric algorithm and a symmetric key. A “fresh” key is therefore generated at the start of each session, and authenticated by the symmetric key. This new method is more reliable and more secure than the current method. It simplifies the deployment of TLS in network equipment, notably wireless devices and for access providers (as opposed to asymmetric keys, more complex to implement).

The second extension concerns the data hashing function. This function transforms the message into a , i.e. a fairly short series of characters which represent the message. The slightest change to the message requires a change to the message digest. Furthermore, it is very difficult to reconstruct the original message based on the message digest. are used both to ensure data integrity (HMAC functions(8)) and for the digital signature. In the first case, once the recipient receives the message, he calculates its HMAC value and checks that it matches the value transmitted by the message sender.

In the second case, the sender wishing to transmit a signed message must first calculate the message digest and then sign (encrypt) the digest using his private key. The recipient uses the sender's public key to decrypt the message digest and checks that it matches the key calculated by the recipient. Since 2005, the most commonly-used hash functions (notably MD5) have been subject to “collision attacks”, i.e. two different messages could have identical message digests, which brings into question the digital signature authentication used with the TLS protocol. The second extension developed by Badra uses new hash functions which provide better protection against collision attacks.

More information:

SSL/TLS protocol

http://www.ietf.org/rfc/rfc5246.txt

New extensions to SSL/TLS protocol:

http://www.rfc-editor.org/rfc/rfc5487.txt
http://www.rfc-editor.org/rfc/rfc5489.txt (active link to publication)

Other ongoing standardization work at LIMOS:

TLS client identity protection and VPN services
http://www.ietf.org/internet-drafts/draft-hajjeh-tls-identity-protection-08.txt
http://ftp.ist.utl.pt/pub/drafts/draft-badra-hajjeh-mtls-04.txt

Provided by CNRS


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4 /5 (2 votes)


March 20, 2009 all stories

Comments: 0

4 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • Changing the language options on your phone.
    created Nov 03, 2009
  • HP strange RPN operation???
    created Nov 02, 2009
  • Databases in physics
    created Oct 31, 2009
  • TI-89 Titanium Problem
    created Oct 29, 2009
  • More from Physics Forums - Computing & Technology

Other News

Oracle logo

EU objects to Oracle's takeover of Sun

Technology / Business

created 3 hours ago | popularity 5 / 5 (1) | comments 0

(AP) -- European antitrust regulators have formally objected to Sun Microsystems Inc.'s planned $7.4 billion sale to Oracle Corp., escalating a battle over a deal that has already been cleared in the U.S.


Video fingerprinting offers search solution

Video fingerprinting offers search solution

Technology / Computer Sciences

created 9 hours ago | popularity not rated yet | comments 0

(PhysOrg.com) -- The explosive growth of video on the internet calls for new ways of sorting and searching audiovisual content. A team of European researchers has developed a groundbreaking solution that is ...


Commercialization of new solar technology to boost solar efficiency

Technology / Energy

created 9 hours ago | popularity 3.8 / 5 (5) | comments 0

A pioneer in solar power in the 1990s before it became "sexy," University of Houston Professor Alex Freundlich recently entered into a collaborative research agreement with U.K.-based start-up QuantaSol for the development ...


Solar LED lamps

Solar Cells with LEDs Provide Inexpensive Lighting

Technology / Energy

created 11 hours ago | popularity 4.8 / 5 (11) | comments 1

(PhysOrg.com) -- Of the 1.5 billion people in developing countries who do not have electricity, many rely on kerosene lamps for light after the sun goes down. But now, researchers from Denmark have designed ...


Tesla Roadster

Tesla Roadster Goes 313 Miles on a Single Charge

Technology / Energy

created 12 hours ago | popularity 4.5 / 5 (12) | comments 1

(PhysOrg.com) -- Tesla is becoming synonymous with high performance electric cars. Indeed, the Tesla car company has been making efforts to create a brand of sports car that runs on electricity, and does so ...