Evaluation of TLS session tickets / Simon Nachtigall ; Supervisors: Prof. Dr-Ing. Juraj Somorovsky, Paderborn University, Prof. Dr. Kenneth Paterson, ETH Zürich, Sven Niclas Hebrok, Paderborn University, Marcel Mahren, Ruhr University Bochum, Robert Merget, Ruhr University Bochum. Paderborn, 2021
Inhalt
- Introduction
- Background
- Library Analysis
- Proposal of Possible Security Vulnerabilities
- Implementation
- Used Tools
- Implementation of SessionTicketProbe
- SessionTicketProbe
- Handshake Implementation
- Session Cache: Evaluating and Manipulating Session Tickets
- IV Repetition
- Ciphersuite Change
- Replay Attack
- Unencrypted Ticket
- Version Change
- No Mac Check
- Zero HMAC Key
- Zero Encryption Key
- Padding Oracle
- Implementation Details
- Testing
- Large-scale scanning of Internet
- Conclusion and Future Work
- Appendix
- Bibliography
- List of Figures
- List of Tables
- List of Algorithms
- List of Listings
- Java Code
