SSL Record Protocol and Handshake Protocols
This section describes the SSL protocol operation, including SSL connection negotiation, key derivation, and secure data transfer. The section explains how the various cryptographic elements described earlier are used in SSL to build a secure communication.
An SSL connection is established in two main phases. The handshake phase (phase 1) negotiates cryptographic algorithms, authenticates the server, and establishes keys for data encryption and MAC. The secure data transfer phase (phase 2) is under the protection of an established SSL connection. This chapter describes each phase in detail, but we first look at the structure of the SSL protocol.
SSL is a layered protocol. At the lowest layer is the SSL record protocol. The record protocol consists of several message types or protocols carrying out different tasks. Figure 2-7 shows the SSL protocol structure.
Figure 2-7 SSL/TLS Protocol Structure TLS/SSL
Figure 2-7 SSL/TLS Protocol Structure TLS/SSL
Record Protocol
The following list describes the primary functions of each protocol defined in SSL/TLS:
• Record protocol is mainly an encapsulation protocol. It transmits various higherlevel protocols and application data. The record protocol takes messages to be transmitted from upper-client protocols; performs the necessary tasks such as fragmentation, compression, applying MAC, and encryption; and then transmits the final data. It also performs the reverse actions—decryption, verification, decompression, and reassembly—to the receiving data. The record protocol consists of four upper-layer client protocols: Handshake Protocol, Alerts Protocol, Change Cipher Spec Protocol, and Application Data Protocol.
• Handshake protocols are responsible for establishing and resuming SSL sessions. Three subprotocols exist:
— Handshake Protocol negotiates the security attributes of an SSL session.
— Alerts Protocol is a housekeeping protocol that is used to convey alert messages between the SSL peers. The alert messages contain errors, exception conditions such as a bad MAC or decryption failure, or notification such as a closure of the session.
— Change Cipher Spec Protocol is used to signal transitions in cipher strategies in the subsequent records.
• Application Data Protocol handles the transmission of upper-layer application data.
Note that the TLS record protocol was designed as a framework, and new client protocols can be easily added in the future. The client protocols previously described are those that are used in SSL connections.
Continue reading here: SSL Connection Setup
Was this article helpful?