2020
DOI: 10.1007/978-3-030-61078-4_14
|View full text |Cite
|
Sign up to set email alerts
|

rTLS: Lightweight TLS Session Resumption for Constrained IoT Devices

Abstract: The Transport Layer Security (TLS) 1.3 protocol supports a fast zero round-trip time (0-RTT) session resumption mechanism, enabling clients to send data in their first flight of messages. This protocol has been designed with Web infrastructure in mind, and requires these first messages to not change any state on the server side, as it is susceptible to replay attacks. This is disastrous for common IoT scenarios, where sensors often transmit state-changing data to servers. As bandwidth is a huge concern in the … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
1

Relationship

1
3

Authors

Journals

citations
Cited by 4 publications
(3 citation statements)
references
References 13 publications
0
3
0
Order By: Relevance
“…• Tiny physical area is required for the design of the assembly • Required less battery power • Required real-time processing and quick response IoT devices such as sensors and RFID tags are often small in size, have a limited amount of usable memory (RAM or ROM) for storing and running programs, and have limited processing power [5]. As well as limited physical space for the installation of the IoT devices [16].…”
Section: Significant Challenges Required To Implement Traditional Cry...mentioning
confidence: 99%
“…• Tiny physical area is required for the design of the assembly • Required less battery power • Required real-time processing and quick response IoT devices such as sensors and RFID tags are often small in size, have a limited amount of usable memory (RAM or ROM) for storing and running programs, and have limited processing power [5]. As well as limited physical space for the installation of the IoT devices [16].…”
Section: Significant Challenges Required To Implement Traditional Cry...mentioning
confidence: 99%
“…Additionally, in our previous work [ 5 ], we introduced rTLS, a TLS 1.3 protocol extension that focuses specifically on the 0-RTT session resumption protocol, with the goal of making it more usable for the IoT. In our original work, we presented the protocol and included numerical estimates on its performance but did not include a thorough analysis of its security properties.…”
Section: Related Workmentioning
confidence: 99%
“…In previous work, we introduced rTLS [ 5 ], a TLS extension that can authenticate two endpoints and set up a secure connection with minimal additional overhead, given that the client and server have initiated a session in the past. We described how the extension changes the 0-RTT session resumption protocol to reduce overhead compared to the standard protocol, while adding new security features including replay protection, forward secrecy, and break-in protection.…”
Section: Introductionmentioning
confidence: 99%