首页> 外文期刊>International Journal of Interactive Mobile Technologies >An Approach to Implement Cryptographic Protocol Version Downgrade Within a Secure Internal Network: TLS 1.x to SSL
【24h】

An Approach to Implement Cryptographic Protocol Version Downgrade Within a Secure Internal Network: TLS 1.x to SSL

机译:实现加密协议版本在安全内部网络中降级的方法:TLS 1.x到SSL

获取原文
       

摘要

The end to end encryption of connections over the internet have evolved from SSL to TLS 1.3 over the years. Attacks have exposed vulnerabilities on each upgraded version of the cryptographic protocols used to secure connections over the internet. Organisations have to keep updating their web based applications to use the latest cryptographic protocol to ensure users are protected and feel comfortable using their web applications. But, the problem is that, web applications are not always standalone systems, there is usually a maze of systems that are integrated to provide services to the end user. The interactions between these systems happens within the controlled internal private network environment of the organisation. While only the front ending web application is visible to the end user. It is not often feasible to upgrade all internal systems to use the latest cryptographic protocol for internal interfaces/integration due to prohibitive cost of redevelopment and upgrades to infra and systems. Here we define an algorithm to setup internal & external firewalls to downgrade to a lower version of the cryptographic protocol (SSL) within the internal network for the integration/interfacing connections of internal systems while mandating the latest cryptographic protocol (TLS 1.x) for end user connections to the web application.
机译:在互联网上结束的结束加密已经从SSL演变为TLS 1.3多年来。攻击在用于通过Internet的连接的加密协议的每个升级版本上具有暴露的漏洞。组织必须继续更新基于Web的应用程序以使用最新的加密协议来确保用户受到保护,并使用其Web应用程序感到舒适。但是,问题是,Web应用程序并不总是独立的系统,通常有一个系统的迷宫被集成来为最终用户提供服务。这些系统之间的交互发生在组织的受控内部专用网络环境中。虽然最终用户只能看到前端的Web应用程序。升级所有内部系统通常不可行,以使用最新的加密协议因内部接口/集成而导致的内部接口/集成,因为重新开发和升级到INFRA和Systems。在这里,我们定义了一种算法来设置内部和外部防火墙,以降级到内部网络内的加密协议(SSL)的较低版本,用于内部系统的集成/接口连接,同时授权最新的加密协议(TLS 1.x)最终用户连接到Web应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号