An Approach to Implement Cryptographic Protocol Version Downgrade Within a Secure Internal Network: TLS 1.x to SSL

Authors

  • Ganeshkumar S Dept of Computer Science and Engineering SRM IST Chennai, India
  • Elango Govindaraju Dept of Computer Science and Engineering SRM IST Chennai, India

DOI:

https://doi.org/10.3991/ijim.v13i10.11308

Keywords:

SSL, TLS, POODLE, Vulnerabilities, protocol versions upgrade

Abstract


The end to end encryption of connections over the internet have evolved from SSL to TLS 1.3 over the years. Attacks have exposed vulnerabilities on each upgraded version of the cryptographic protocols used to secure connections over the internet. Organisations have to keep updating their web based applications to use the latest cryptographic protocol to ensure users are protected and feel comfortable using their web applications. But, the problem is that, web applications are not always standalone systems, there is usually a maze of systems that are integrated to provide services to the end user. The interactions between these systems happens within the controlled internal private network environment of the organisation. While only the front ending web application is visible to the end user. It is not often feasible to upgrade all internal systems to use the latest cryptographic protocol for internal interfaces/integration due to prohibitive cost of redevelopment and upgrades to infra and systems. Here we define an algorithm to setup internal & external firewalls to downgrade to a lower version of the cryptographic protocol (SSL) within the internal network for the integration/interfacing connections of internal systems while mandating the latest cryptographic protocol (TLS 1.x) for end user connections to the web application.

Author Biographies

Ganeshkumar S, Dept of Computer Science and Engineering SRM IST Chennai, India

Dept of Computer Science and Engineering SRM IST Chennai

Elango Govindaraju, Dept of Computer Science and Engineering SRM IST Chennai, India

Dept of Computer Science and Engineering SRM IST Chennai

Downloads

Published

2019-09-25

How to Cite

S, G., & Govindaraju, E. (2019). An Approach to Implement Cryptographic Protocol Version Downgrade Within a Secure Internal Network: TLS 1.x to SSL. International Journal of Interactive Mobile Technologies (iJIM), 13(10), pp. 179–187. https://doi.org/10.3991/ijim.v13i10.11308

Issue

Section

Short Papers