TY - GEN
T1 - TLS tandem
AU - Badra, Mohamad
AU - Urien, Pascal
PY - 2008/12/1
Y1 - 2008/12/1
N2 - Nowadays, the TLS protocol (Transport Layer Security) is the de facto standard for securing transactions across the Internet. It provides end-to-end secure communications with one way or mutual authentication between two network nodes. However, this protocol suffers from serious vulnerabilities because classical software implementations are not trusted and allow the use of falsified credentials (e.g. revoked and false certificates) and provide an unsecured storage of credentials (private keys, passwords, etc.). In this paper, we introduce the TLS smart card to prevent those issues and we describe the TLS Tandem protocol, a TLS extension cohabiting between two TLS software installed in both a docking host and a smart card. The card of our architecture, after which the TLS authentication is successfully performed, derives secret keys from the master secret key, and transmits these values to the TLS software installed in the docking host. We discuss the performance and the efficiency of TLS Tandem. The implementation and performances analysis are performed using smart cards and Java Card libraries.
AB - Nowadays, the TLS protocol (Transport Layer Security) is the de facto standard for securing transactions across the Internet. It provides end-to-end secure communications with one way or mutual authentication between two network nodes. However, this protocol suffers from serious vulnerabilities because classical software implementations are not trusted and allow the use of falsified credentials (e.g. revoked and false certificates) and provide an unsecured storage of credentials (private keys, passwords, etc.). In this paper, we introduce the TLS smart card to prevent those issues and we describe the TLS Tandem protocol, a TLS extension cohabiting between two TLS software installed in both a docking host and a smart card. The card of our architecture, after which the TLS authentication is successfully performed, derives secret keys from the master secret key, and transmits these values to the TLS software installed in the docking host. We discuss the performance and the efficiency of TLS Tandem. The implementation and performances analysis are performed using smart cards and Java Card libraries.
KW - Public key infrastructures
KW - Secure software
KW - Smart cards
KW - Transport layer security (TLS)
U2 - 10.1109/NTMS.2008.ECP.99
DO - 10.1109/NTMS.2008.ECP.99
M3 - Conference contribution
AN - SCOPUS:58049155776
SN - 9782953244304
T3 - Proceedings of New Technologies, Mobility and Security Conference and Workshops, NTMS 2008
BT - Proceedings of New Technologies, Mobility and Security Conference and Workshops, NTMS 2008
T2 - New Technologies, Mobility and Security Conference and Workshops, NTMS 2008
Y2 - 5 November 2008 through 7 November 2008
ER -