| 摘要: |
| TLS协议在保障网络通信的隐私性、完整性和可靠性方面发挥着至关重要的作用. 近年来, 工业界和学术界积极推动TLS协议相关研究和发展, 尤其在TLS 1.3中取得了巨大进展. 然而, 随着网络环境的日益复杂化和攻击手段的不断进步, TLS 1.3的安全性也面临着严峻挑战, 如重放攻击、前向安全风险, 以及OpenSSL软件实现漏洞. 这些攻击和漏洞不仅严重威胁用户隐私与企业数据安全, 也对互联网的信任体系乃至整个社会的数字经济产生深远影响. 首先对TLS 1.3协议发展历程和原理进行详细介绍. 其次, 对TLS 1.3协议相关安全研究进行分类梳理和对比分析, 从协议机制、软件实现和应用配置这3个方面系统分析和归纳. 最后, 总结TLS 1.3协议安全研究现状和瓶颈挑战, 为未来的研究方向提供建议. |
| 关键词: TLS 1.3 握手安全 0-RTT 形式化分析 模糊测试 |
| DOI:10.13328/j.cnki.jos.007614 |
| 分类号:TP393 |
| 基金项目:国家重点研发计划(2024YFB31NL00105) |
|
| Survey on Security Research of TLS 1.3 Protocol |
|
BAI Jun-Yang1, ZHANG Yu1,2, ZHANG Bin1, ZHANG Wei-Zhe1,2
|
|
1.Pengcheng Laboratory, Shenzhen 518055, China;2.School of Cyberspace Science, Harbin Institute of Technology, Harbin 150001, China
|
| Abstract: |
| TLS protocol plays a critical role in ensuring the privacy, integrity, and reliability of network communications. In recent years, both industry and academia have actively promoted research and development related to TLS protocol, achieving significant progress, particularly in TLS 1.3. However, with the increasing complexity of network environments and the continuous evolution of attack methods, the security of the TLS 1.3 protocol also faces severe challenges, including replay attacks, risks to forward secrecy and vulnerabilities in software implementations such as OpenSSL. These attacks and vulnerabilities not only pose serious threats to user privacy and enterprise data security but also profoundly impact the trust system of the Internet and the broader digital economy. This study first provides a detailed introduction to the development and underlying principles of TLS 1.3. Subsequently, recent security research on the TLS 1.3 protocol is systematically categorized, compared, and analyzed from three aspects: protocol mechanism, software implementation, and application configuration. Finally, the current state and challenges in the TLS 1.3 protocol security research are summarized, and suggestions for future research directions are provided. |
| Key words: TLS 1.3 handshake security 0-RTT formal analysis fuzzing |