This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Transport Layer Security (TLS) | |
|---|---|
| Name | Transport Layer Security |
| Acronym | TLS |
| Developer | Internet Engineering Task Force, National Institute of Standards and Technology |
| Initial release | 1999 |
| Latest release | 1.3 |
| Status | Published |
Transport Layer Security (TLS) Transport Layer Security (TLS) is a cryptographic protocol designed to provide confidentiality, integrity, and authentication for communications over packet-switched networks. TLS is widely used to secure Hypertext Transfer Protocol traffic for World Wide Web browsing, protect Email exchange such as Simple Mail Transfer Protocol and Post Office Protocol, and secure other protocols like FTP and VoIP. Its design and deployment involve standards bodies, software vendors, and major service providers across the Internet Engineering Task Force ecosystem.
TLS evolved from the Netscape Communications work on Secure Sockets Layer (SSL) and was standardized through the Internet Engineering Task Force. Early TLS milestones intersect with developments at Netscape Navigator, the draft publications by IETF TLS WG, and standardization efforts influenced by organizations such as World Wide Web Consortium stakeholders. Major events influencing TLS adoption include increased e-commerce after the Dot-com bubble, comparative analyses by RSA Security researchers, and governmental cybersecurity initiatives by National Institute of Standards and Technology and European Union Agency for Cybersecurity. Academic contributions from institutions like Massachusetts Institute of Technology, Stanford University, and University of California, Berkeley helped reveal protocol weaknesses that shaped revisions.
TLS is layered above the Transmission Control Protocol and below application protocols such as Hypertext Transfer Protocol and Simple Mail Transfer Protocol. Its architecture separates the protocol into a record layer that provides encapsulation and compression, and a handshake layer that negotiates keys and algorithms; this model parallels designs from Open Systems Interconnection frameworks and influenced by cryptographic engineering at Bell Labs and Bellcore. TLS relies on public-key infrastructure that interconnects with X.509 certificate hierarchies maintained by certificate authorities such as DigiCert, Let's Encrypt, and GlobalSign. Interoperability considerations often involve vendors like Microsoft, Apple Inc., Google LLC, and Mozilla Foundation implementing TLS stacks in browsers like Internet Explorer, Safari, Chrome, and Firefox.
Official TLS versions have evolved through successive specifications published by the Internet Engineering Task Force and its Working Groups. Notable versions reflect responses to cryptanalytic advances and implementation findings from groups associated with IETF TLS WG and researchers at Google Project Zero. Backward compatibility issues frequently arise with legacy systems from vendors such as Cisco Systems and telecommunications providers like AT&T. Deprecated predecessors and alternatives include protocols from Netscape Communications and experimental drafts that influenced modern updates. Interoperability testing is coordinated through events such as the Internet Engineering Task Force] ] meetings and interoperability labs run by organizations like OpenSSL Project and Cloudflare, Inc..
TLS combines symmetric algorithms like Advanced Encryption Standard with modes such as Galois/Counter Mode and message authentication using constructs related to HMAC; these choices reflect standards from National Institute of Standards and Technology and research from cryptographers associated with RSA Laboratories and Academic Cryptography Groups. Key exchange mechanisms include Diffie–Hellman key exchange and variants such as Elliptic-curve cryptography; certificate verification relies on X.509 and cryptographic hash functions like SHA-256 standardized by NIST. Randomness sources and entropy considerations have been studied by teams at University of Cambridge and University of Oxford to mitigate attacks demonstrated in research from Princeton University and Cornell University.
The TLS handshake negotiates protocol version, cipher suites, and key material between endpoints such as servers operated by Amazon Web Services and clients like browsers from Google LLC and Mozilla Foundation. Authentication usually uses X.509 certificates issued by authorities including Let's Encrypt or DigiCert, while session resumption mechanisms reference constructs used in systems by Cloudflare, Inc. and Akamai Technologies. The handshake reflects cryptographic protocols analyzed in academic conferences such as CRYPTO, IEEE Symposium on Security and Privacy, and ACM CCS, and implemented in libraries like OpenSSL Project, GnuTLS, and BoringSSL.
TLS has been the subject of extensive analysis and has experienced vulnerabilities such as those revealed by researchers at Belgian Research Institute and teams from University of Illinois Urbana–Champaign; high-profile attacks include POODLE-style downgrade issues traced to legacy specifications from Netscape Communications and implementation flaws like Heartbleed discovered by security researchers associated with Google Project Zero and independent auditors. Other notable incidents involved certificate mis-issuance discovered through monitoring efforts by organizations such as Mozilla Foundation and Let's Encrypt transparency logs influenced by work at Cloudflare, Inc. and EFF. Defenses and mitigations have included protocol revisions from IETF TLS WG, adoption of Certificate Transparency promoted by Google LLC, and deployment best practices advocated by National Institute of Standards and Technology.
TLS is implemented in widely used libraries and products such as OpenSSL Project, GnuTLS, LibreSSL, BoringSSL, and vendor stacks from Microsoft, Apple Inc., and Oracle Corporation. Major service providers including Google LLC, Facebook, Amazon, and content delivery networks like Akamai Technologies and Cloudflare, Inc. have deployed TLS extensively for web and API traffic. Certification and compliance efforts involve standards and audit bodies like PCI Security Standards Council and national regulators influenced by National Institute of Standards and Technology. Testbeds and interoperability projects are coordinated through communities at IETF, security conferences such as Black Hat, and academic collaborations with institutions like Carnegie Mellon University.
Category:Cryptographic protocols