Learning path

Full curriculum

Full curriculum

Unit content

Secure channels and TLS

A secure channel protects application data sent between endpoints against relevant network adversaries.

A practical channel protocol combines several jobs:

  1. authenticate the intended peer or its public key;
  2. establish fresh shared session keys;
  3. protect records with authenticated encryption;
  4. prevent old records from being accepted in the wrong protocol context.

TLS is the security protocol commonly used beneath HTTPS. During its handshake, the peers negotiate cryptographic parameters, establish shared secrets and authenticate the server using the configured certificate trust model. The resulting session keys then protect application records.

A secure channel is more than encryption. Without authentication, an active adversary may establish separate encrypted channels to each endpoint. Without integrity, ciphertext manipulation may remain possible.

TLS protects data in transit between the protocol endpoints. It does not make the application itself trustworthy and does not protect plaintext after a compromised endpoint has decrypted it.