Transport Layer Security and Secure Sockets Layer
Mostafa Hashem Sherif
Abstract
Mostafa Hashem Sherif
Abstract
This chapter focuses on the exchanges and during session and connection establishment for both Secure Sockets Layer (SSL) and Transport Layer Security (TLS), explaining the main differences between the successive versions. SSL and TLS are two widely used protocols to secure exchanges at the transport layer between a client and a server. SSL/TLS define a framework to use the encryption and hashing algorithms that have been negotiated between the two parties to offer three security services: authentication, integrity, and confidentiality. SSL/TLS combine the operations of key establishment, confidentiality, signature, and hashing into one package denoted as cipher suite. The initial SSL/TLS protocols are four subprotocols: Handshake, Record, ChangeCipherSpec, and Alert; in 2012, the Heartbeat subprotocol was added. The concept of a connection in SSL/TLS has been introduced to allow an application to refresh certain security attributes without affecting all the other attributes that have been negotiated at the start of a session.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This chapter focuses on the exchanges and during session and connection establishment for both Secure Sockets Layer (SSL) and Transport Layer Security (TLS), explaining the main differences between the successive versions. SSL and TLS are two widely used protocols to secure exchanges at the transport layer between a client and a server. SSL/TLS define a framework to use the encryption and hashing algorithms that have been negotiated between the two parties to offer three security services: authentication, integrity, and confidentiality. SSL/TLS combine the operations of key establishment, confidentiality, signature, and hashing into one package denoted as cipher suite. The initial SSL/TLS protocols are four subprotocols: Handshake, Record, ChangeCipherSpec, and Alert; in 2012, the Heartbeat subprotocol was added. The concept of a connection in SSL/TLS has been introduced to allow an application to refresh certain security attributes without affecting all the other attributes that have been negotiated at the start of a session.
Key concepts: Layer (electronics), Transport Layer Security, Application layer, Transport layer, Computer science, Computer security, Computer network, Materials science