Bidirectional TLS Handshake Caching for Constrained Industrial IoT Scenarios

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bodenhausen, Jörn, Mangel, Simon, Vogt, Thomas, Henze, Martin
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909723381465088
author Bodenhausen, Jörn
Mangel, Simon
Vogt, Thomas
Henze, Martin
author_facet Bodenhausen, Jörn
Mangel, Simon
Vogt, Thomas
Henze, Martin
contents While TLS has become the de-facto standard for end-to-end security, its use to secure critical communication in evolving industrial IoT scenarios is severely limited by prevalent resource constraints of devices and networks. Most notably, the TLS handshake to establish secure connections incurs significant bandwidth and processing overhead that often cannot be handled in constrained environments. To alleviate this situation, we present BiTHaC which realizes bidirectional TLS handshake caching by exploiting that significant parts of repeated TLS handshakes, especially certificates, are static. Thus, redundant information neither needs to be transmitted nor corresponding computations performed, saving valuable bandwidth and processing resources. By implementing BiTHaC for wolfSSL, we show that we can reduce the bandwidth consumption of TLS handshakes by up to 61.1% and the computational overhead by up to 8.5%, while incurring only well-manageable memory overhead and preserving the strict security guarantees of TLS.
format Preprint
id arxiv_https___arxiv_org_abs_2508_03321
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Bidirectional TLS Handshake Caching for Constrained Industrial IoT Scenarios
Bodenhausen, Jörn
Mangel, Simon
Vogt, Thomas
Henze, Martin
Networking and Internet Architecture
Cryptography and Security
While TLS has become the de-facto standard for end-to-end security, its use to secure critical communication in evolving industrial IoT scenarios is severely limited by prevalent resource constraints of devices and networks. Most notably, the TLS handshake to establish secure connections incurs significant bandwidth and processing overhead that often cannot be handled in constrained environments. To alleviate this situation, we present BiTHaC which realizes bidirectional TLS handshake caching by exploiting that significant parts of repeated TLS handshakes, especially certificates, are static. Thus, redundant information neither needs to be transmitted nor corresponding computations performed, saving valuable bandwidth and processing resources. By implementing BiTHaC for wolfSSL, we show that we can reduce the bandwidth consumption of TLS handshakes by up to 61.1% and the computational overhead by up to 8.5%, while incurring only well-manageable memory overhead and preserving the strict security guarantees of TLS.
title Bidirectional TLS Handshake Caching for Constrained Industrial IoT Scenarios
topic Networking and Internet Architecture
Cryptography and Security
url https://arxiv.org/abs/2508.03321