Collected research
A Messy State of the Union: Taming the Composite State Machines of TLS
Systematic testing of mainstream TLS stacks shows their composite state machines accept message sequences no valid handshake produces, because per-ciphersuite machines were merged carelessly. A network attacker can skip handshake messages to impersonate a server, or force export-grade RSA and factor the key (FREAK), breaking authentication; the paper adds a verified OpenSSL state machine.
Record
- Researcher
- Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub and Jean Karim Zinzindohoue
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Crypto
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub and Jean Karim Zinzindohoue, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .