我们也应该聊天吗?微信MMTLS加密协议的安全分析.pdf

编号:981830 PDF 48页 3.85MB 下载积分:VIP专享
下载报告请您先登录!

我们也应该聊天吗?微信MMTLS加密协议的安全分析.pdf

1、Security Analysis of WeChats MMTLS Encryption ProtocolPellaeon Lin,Mona WangThursday,April 3 2025AgendaSecurity Analysis of WeChats MMTLS Encryption ProtocolIntroduction,motivation,methodologiesWeChat network request lifecycleMMTLS encryption,Business-layer encryptionDiscussion,recommendations,futur

2、e workPellaeon LinResearcher at Citizen Lab,University of TorontoSecurity and privacy of mobile appsPast studiesTikTok vs Douyin-A Security and Privacy AnalysisUnmasked II:An Analysis of Indonesia and the Philippines Government-launched COVID-19 AppsUnmasked:COVID-KAYA and the Exposure of Healthcare

3、 Worker Data in the PhilippinesMona WangNetworking security researcher,PhD student at Princeton CITPOTF Information Controls Research Fellow at Citizen LabPreviously technologist at EFFOther workNetwork measurement(CoNEXT 22)Traffic fingerprinting resistance and censorship circumvention(PETS 22)Thre

4、at modelling and security training for organizers(CSCW 22)https:/MotivationWhats being sent?Is the encryption sound?Why custom encryption?MotivationWeChat MMTLSSecures 1+billion users trafficDeployed for 8 yearsOne public blog postSSL/TLSSecures billions of users traffic30+years of developmentOpen s

5、tandard,lots of academic and public scrutinyMMTLS deserves just as much scrutiny as TLS!WeChat network request lifecycleAnatomy of a Wechat network requestAPI endpoint is referred to as“Scene”,has unique“type”number and URIAnatomy of a Wechat network requestRequest and response formats are defined u

6、sing ProtobufScreenshot shows a portion of the request Protobuf fieldsAPI object(NetSceneBase)Defines structure of API data,what type of encryption to useSerializer(reqToBuf)Serialize the object into bytearraysEncryptor(MMProtocalJni.so)Encrypts byte arrays using crypto specified by API typeOpenSSLO

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(我们也应该聊天吗?微信MMTLS加密协议的安全分析.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠