TLS Handshake & Encryption Lab (Interactive)
Compute the real Diffie-Hellman shared secret with BigInt modular exponentiation and compare TLS 1.2 vs 1.3. Step through ClientHello to Finished with live g^a mod p math, forward-secrecy reasoning, and 2-RTT versus 1-RTT versus 0-RTT latency.
TLS Handshake & ECDHE Key Exchange Lab
Compute the real Diffie-Hellman shared secret (g^ab mod p) with BigInt modular exponentiation, then compare 1.2 vs 1.3 handshake latency.
ClientHello
SENTClient sends supported groups + ECDHE key_share A = g^a mod p = 132 in the very first flight. TLS 1.3 removed RC4, 3DES, MD5 and static RSA key exchange — only ECDHE with AES-GCM/ChaCha20 remains.
ServerHello + Certificate + Finished
PENDINGServer replies with key_share B = g^b mod p = 173, its X.509 certificate chain (Root CA → Intermediate → end-entity), and a signed CertVerify. Both sides now derive S = g^(ab) mod p independently — the secret itself never crosses the wire.
Finished + encrypted HTTP request
PENDINGClient verifies the certificate chain against its ~150 trusted roots and sends Finished plus the first AES-256-GCM encrypted request. Secure channel established in 1 RTT.
Forward secrecy: because a and b are ephemeral and discarded, stealing the server certificate key later cannot decrypt recorded past traffic.
How It Works Under the Hood
TLS uses hybrid encryption: slow asymmetric operations only to negotiate keys, then fast symmetric AES-256-GCM or ChaCha20 for the payload. With ECDHE, the client picks a private value a and publishes g^a mod p; the server does the same with b; both independently compute S = g^(ab) mod p, a secret that never crosses the wire. Because a and b are ephemeral and discarded, Perfect Forward Secrecy holds even if the certificate key is stolen later. TLS 1.3 folded the key share into the first flight, halving handshake latency to 1 RTT and enabling 0-RTT resumption — at the price of replay vulnerability on non-idempotent requests.
Core Architectural Principles
- Shared secret S = B^a mod p = A^b mod p computed on both sides via modular exponentiation.
- TLS 1.2 costs 2 RTTs and allowed RC4/3DES/static RSA; TLS 1.3 allows only ECDHE AEAD suites in 1 RTT.
- Trust chain: Root CA → Intermediate CA → end-entity certificate, verified against ~150 browser-trusted roots.
Explain handshake cost architecturally: TLS 1.3 is 1 RTT (0-RTT for returning clients), so edge CDNs that terminate TLS near users cut hundreds of milliseconds globally. Mention OCSP stapling as the latency-free revocation check and mTLS for service-to-service identity — the follow-ups interviewers always probe after a security answer.
1-RTT and 0-RTT speed versus 0-RTT replay risk on side-effecting requests, mitigated by server-side anti-replay caches.