Panos Kampanakis PK
Wed 14 Oct · 10:30 · Main Stage

Panos Kampanakis

Reel · 60 sec ▷ play

— On the schedule —

TLS keyshare caching for faster handshakes

TLS 1.3 key exchange requires the client and the server to support the same key exchange parameters (keyshare) which enables faster key negotiation. Otherwise a TLS 1.3 key exchange requires a retry which introduces an additional round-trip. In cryptographic transitions where clients and servers do not all support or prefer the same key exchange algorithms, round-trips could slow down TLS 1.3 handshakes. One way to prevent them is to make the server supported keyshare algorithms available in DNS so the client can choose the right keyshare from its first ClientHello as it has been proposed in the IETF TLS working group. This puts the onus on server administrators to manage the DNS records. Another approach is to cache the server preference on the client after the first handshake and prevent round-trips in subsequent connections. This mechanism works well in use cases where the client connects to finite servers and can manage a caching mechanism. This talk explores keyshare caching mechanisms and shares experimental results of the round-trip savings based on the different cache eviction schemes, cache hit probabilities, and server distribution. It concludes that for use cases where the cache size is a fraction of the total servers that require a round-trip based on their keyshare policy, a simple caching mechanism can provide important savings while transitioning to new keyshare algorithms. It discusses how open-source TLS implementations can leverage such options. It also goes over an interesting finding regarding keyshare choices in popular servers on the internet.

— Compositor's note —

Panos is a Principal Security Engineer at AWS. He has experience with cybersecurity, applied cryptography, security automation, and vulnerability management. He has coauthored publications on cybersecurity and participated in various security standards bodies to provide common interoperable protocols and languages for security information sharing, cryptography, and public-key infrastructure. Currently, he works with engineers and industry partners to provide cryptographically secure tools, protocols, and standards.

PlateXLII · folio 40 of 91
Guild
DayWed 14 Oct · 10:30 · Main Stage
Track01 — Technical Deep Dive
Format40-min talk
← Back to all twelve plates