Passer à la navigation principale Passer à la recherche Passer au contenu principal

Triple handshakes and cookie cutters: Breaking and fixing authentication over TLS

  • Karthikeyan Bhargavan
  • , Antoine Delignat-Lavaud
  • , Cédric Fournet
  • , Alfredo Pironti
  • , Pierre Yves Strub
  • INRIA Rocquencourt
  • Microsoft Research
  • IMDEA Software Institute

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

137 Citations (Scopus)

Résumé

TLS was designed as a transparent channel abstraction to allow developers with no cryptographic expertise to protect their application against attackers that may control some clients, some servers, and may have the capability to tamper with network connections. However, the security guarantees of TLS fall short of those of a secure channel, leading to a variety of attacks. We show how some widespread false beliefs about these guarantees can be exploited to attack popular applications and defeat several standard authentication methods that rely too naively on TLS. We present new client impersonation attacks against TLS renegotiations, wireless networks, challenge-response protocols, and channel-bound cookies. Our attacks exploit combinations of RSA and Diffie-Hellman key exchange, session resumption, and renegotiation to bypass many recent countermeasures. We also demonstrate new ways to exploit known weaknesses of HTTP over TLS. We investigate the root causes for these attacks and propose new countermeasures. At the protocol level, we design and implement two new TLS extensions that strengthen the authentication guarantees of the handshake. At the application level, we develop an exemplary HTTPS client library that implements several mitigations, on top of a previously verified TLS implementation, and verify that their composition provides strong, simple application security.

langue originaleAnglais
titreProceedings - IEEE Symposium on Security and Privacy
EditeurInstitute of Electrical and Electronics Engineers Inc.
Pages98-113
Nombre de pages16
ISBN (Electronique)9781479946860
Les DOIs
étatPublié - 13 nov. 2014
Modification externeOui
Evénement35th IEEE Symposium on Security and Privacy, SP 2014 - San Jose, États-Unis
Durée: 18 mai 201421 mai 2014

Série de publications

NomProceedings - IEEE Symposium on Security and Privacy
ISSN (imprimé)1081-6011

Une conférence

Une conférence35th IEEE Symposium on Security and Privacy, SP 2014
Pays/TerritoireÉtats-Unis
La villeSan Jose
période18/05/1421/05/14

Empreinte digitale

Examiner les sujets de recherche de « Triple handshakes and cookie cutters: Breaking and fixing authentication over TLS ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation