Paper 2023/734

TLS → Post-Quantum TLS: Inspecting the TLS landscape for PQC adoption on Android

Dimitri Mankowski, Ruhr University Bochum
Thom Wiggers, PQShield
Veelasha Moonsamy, Ruhr University Bochum
Abstract

The ubiquitous use of smartphones has contributed to more and more users conducting their online browsing activities through apps, rather than web browsers. In order to provide a seamless browsing experience to the users, apps rely on a variety of HTTP-based APIs and third-party libraries, and make use of the TLS protocol to secure the underlying communication. With NIST's recent announcement of the first standards for post-quantum algorithms, there is a need to better understand the constraints and requirements of TLS usage by Android apps in order to make an informed decision for migration to the post-quantum world. In this paper, we performed an analysis of TLS usage by highest-ranked apps from Google Play Store to assess the resulting overhead for adoption of post-quantum algorithms. Our results show that apps set up large numbers of TLS connections with a median of 94, often to the same hosts. At the same time, many apps make little use of resumption to reduce the overhead of the TLS handshake. This will greatly magnify the impact of the transition to post-quantum cryptography, and we make recommendations for developers, server operators and the mobile operating systems to invest in making more use of these mitigating features or improving their accessibility. Finally, we briefly discuss how alternative proposals for post-quantum TLS handshakes might reduce the overhead.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Keywords
PQCpost-quantum TLSAndroid
Contact author(s)
dimitri mankowski @ rub de
thom @ thomwiggers nl
email @ veelasha org
History
2023-05-25: approved
2023-05-22: received
See all versions
Short URL
https://ia.cr/2023/734
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/734,
      author = {Dimitri Mankowski and Thom Wiggers and Veelasha Moonsamy},
      title = {TLS → Post-Quantum TLS: Inspecting the TLS landscape for PQC adoption on Android},
      howpublished = {Cryptology ePrint Archive, Paper 2023/734},
      year = {2023},
      note = {\url{https://eprint.iacr.org/2023/734}},
      url = {https://eprint.iacr.org/2023/734}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.