mdTLS: How to Make Middlebox-Aware TLS More Efficient?

Taehyun Ahn, Jiwon Kwak, Seungjoo Kim

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    Abstract

    Recently, many organizations have been installing middleboxes in their networks in large numbers to provide various services to their customers. Although middleboxes have the advantage of not being dependent on specific hardware and being able to provide a variety of services, they can become a new attack target for hackers. Therefore, many researchers have proposed security-enchanced TLS protocols, but their results have some limitations. In this paper, we proposed a middlebox-delegated TLS (mdTLS) protocol that not only achieves the same security level but also requires relatively less computation compared to recent research results. mdTLS is a TLS protocol designed based on the proxy signature scheme, which requires about 39% less computation than middlebox-aware TLS (maTLS), which is the best in security and performance among existing research results. In order to substantiate the enhanced security of mdTLS, we conducted a formal verification using the Tamarin. Our verification demonstrates that mdTLS not only satisfies the security properties set forth by maTLS but also complies with the essential security properties required for proxy signature scheme (All of the formal models and lemmas are open to the public through the following url https://github.com/HackProof/mdTLS).

    Original languageEnglish
    Title of host publicationInformation Security and Cryptology – ICISC 2023 - 26th International Conference on Information Security and Cryptology, ICISC 2023, Revised Selected Papers
    EditorsHwajeong Seo, Suhri Kim
    PublisherSpringer Science and Business Media Deutschland GmbH
    Pages39-59
    Number of pages21
    ISBN (Print)9789819712373
    DOIs
    Publication statusPublished - 2024
    Event26th International Conference on Information Security and Cryptology on Information Security and Cryptology, ICISC 2023 - Seoul, Korea, Republic of
    Duration: 2023 Nov 292023 Dec 1

    Publication series

    NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
    Volume14562 LNCS
    ISSN (Print)0302-9743
    ISSN (Electronic)1611-3349

    Conference

    Conference26th International Conference on Information Security and Cryptology on Information Security and Cryptology, ICISC 2023
    Country/TerritoryKorea, Republic of
    CitySeoul
    Period23/11/2923/12/1

    Bibliographical note

    Publisher Copyright:
    © The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2024.

    Keywords

    • Formal verification
    • Middlebox
    • Proxy signature
    • maTLS

    ASJC Scopus subject areas

    • Theoretical Computer Science
    • General Computer Science

    Fingerprint

    Dive into the research topics of 'mdTLS: How to Make Middlebox-Aware TLS More Efficient?'. Together they form a unique fingerprint.

    Cite this