vix.ing · top · new · best · stats · spec

An Experimental Study of TLS Forward Secrecy Deployments

2014/08/01 by Lin-Shung Huang, Shrikant Adhikarla, Dan Boneh +1 · 1 citation
Engineering · Computer Science · #IPv6, Mobility, Handover, Networks, Security #Cryptography and Data Security #Mobile Ad Hoc Networks #Forward secrecy #Server #Secrecy #Transport Layer Security #Computer science #Computer security #Cryptography #Computer network #Key exchange #Key (lock) #Throughput #Side channel attack #Public-key cryptography #Ephemeral key #Encryption #Operating system #Wireless

paper · doi:10.1109/mic.2014.86

openalex publication_date 2014/08/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/06/11

Abstract

Many Transport Layer Security (TLS) servers use the ephemeral Diffie-Hellman (DHE) key exchange to support forward secrecy. However, in a survey of 473,802 TLS servers, the authors found that 82.9 percent of the DHE-enabled servers use weak DH parameters, resulting in a false sense of security. They compared the server throughput of various TLS setups, and measured real-world client-side latencies using an advertisement network. Their results indicate that using forward secrecy is no harder, and can even be faster using elliptic curve cryptography (ECC), than no forward secrecy.

Cited by