Can We Securely Use CBC Mode in TLS1.0?
Abstract
Currently, TLS1.0 is one of the most widely deployed protocol versions for SSL/TLS. In TLS1.0, there are only two choices for the bulk encryption, i.e., RC4 or block ciphers in the CBC mode, which have been criticized to be insecure.In this paper, we explore the current status of the CBC mode in TLS1.0 and prove theoretically that the current version of the (patched) CBC mode in TLS1.0 satisfies indistinguishability, which implies that it is secure against BEAST type of attacks.
Origin | Files produced by the author(s) |
---|
Loading...