NOTE
2.7 HTTPS
Historical notes on HTTPS, its simplified handshake model, encryption, certificates, and packet capture.
This is a historical learning note and may contain outdated or incomplete understanding.
1. What Is HTTPS?
- HTTPS = HTTP + SSL/TLS.
2. Why Is HTTPS Needed?
HTTP is transmitted in plaintext. If someone captures the message, they can parse all of its data. HTTPS is encrypted transmission: the data is visible only to the sender and destination, and not to intermediate nodes.
2.1. HTTP vs. HTTPS
| HTTP | HTTPS | |
|---|---|---|
| URL | http:// | https:// |
| Secure | No, plaintext | Yes (data is encrypted during transmission), ciphertext |
| Port | 80 | 443 |
| OSI network model | Application layer | Application layer |
3. How It Works
3.1. TCP Three-Way Handshake
3.2. Obtain a Sequence Number (Asymmetric Encryption)
-
The browser sends the encryption algorithms it supports to the server.
-
The server chooses an encryption algorithm and a hash algorithm and returns them with its certificate, while keeping the private key itself.
- Encryption algorithm (used to encrypt data and prevent disclosure).
- Hash algorithm (used to verify whether data has been tampered with).
- The certificate contains the public key (used to encrypt data and prevent disclosure) and the certificate authority (to prevent man-in-the-middle attacks).
-
The browser receives the certificate, encryption algorithm, and hash algorithm.
- Verify with an authority whether the certificate is valid.
- If the certificate is valid:
- Randomly generate a sequence number, encrypt it using the public key in the server certificate, and call it A.
- Use the server’s hash algorithm to calculate the hash of the sequence number, and call it B.
- Send the encrypted sequence number (A) and hash value (B) to the server.
-
The server receives the encrypted sequence number and hash value.
- Use the private key to decrypt the sequence number.
- Use the hash algorithm to calculate the hash of the sequence number and compare it with the browser’s hash value.
- If the hash values are identical, the sequence number has not been tampered with. At this point the server and browser have agreed on the encryption algorithm and the sequence number used for symmetric encryption.
3.3. Transfer Data (Symmetric Encryption)
- The server prepares the data, encrypts it with the sequence number, calculates the data’s hash value with the hash algorithm, and sends them to the browser.
- The browser receives the encrypted data and hash value.
- Use the sequence number to decrypt the data.
- Use the hash algorithm to calculate the data’s hash value and compare it with the server’s hash value.
4. Questions
4.1. Why Use a Hash Algorithm to Calculate the Data Hash?
Encryption cannot verify data integrity; it only converts plaintext to ciphertext. If data is modified during transmission, the decrypted data will be garbage.
4.2. Why Not Use Asymmetric Encryption for the Entire Data Transfer?
Because asymmetric algorithms are much less efficient than symmetric algorithms, they are generally used only during the HTTPS handshake.
4.3. Common Encryption Algorithms
Asymmetric encryption: RSA, DSA/DSS
Symmetric encryption: AES, 3DES
Hash algorithms: MD5, SHA1, SHA256
4.4. Why Is a Certificate Issued by a CA Needed?
To prevent man-in-the-middle attacks.
4.5. Why Can a Packet-Capture Tool Still Show Plaintext After Encryption?
The reason is that a packet-capture tool works as a man in the middle: it establishes a connection with the browser using the capture tool’s certificate, and a connection with the server using the server’s certificate. When the browser sends data, it first encrypts the data with the capture tool’s certificate. The capture tool obtains the data and decrypts it using its own certificate (so it can see the plaintext). The capture tool then encrypts the data using the server’s certificate and sends it to the server. The server decrypts the data using its own certificate.
4.6. What If the Local Random Number Is Stolen?
HTTPS does not include guarantees for local random-number security. HTTPS guarantees only the security of the transmission process. Random numbers are stored locally, and local security belongs to another security domain. Countermeasures include antivirus software, anti-malware software, and browser upgrades that fix vulnerabilities.
Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub