arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.13685cs.CRcs.NI

传输层安全中的怪异机器

Weird Machines in Transport Layer Security

Michael Collins, Jada Cumberland, Brianne Dunn, Ross Gore, Samuel Jackson, Sachin Shetty, Jonathan Takeshita

首次发表
浏览论文内容

中文总结 AI 辅助

本文将怪异机器理论扩展至TLS领域,基于OpenSSL和BoringSSL实现,验证了TLS原语可组合为图灵完备系统,并通过哨兵系统和认证绕过两个演示展示了其防御与攻击应用。

中文摘要 AI 辅助

怪异机器是由架构组件组合产生的潜在计算能力。现有研究已在软件系统中广泛探讨过该现象,包括x86指令、ELF元数据和页表,近期还在工业控制网络等网络物理系统中开展了相关研究。本文将怪异机器理论扩展至新领域:传输层安全(TLS)握手及其两种主流实现OpenSSL和BoringSSL。研究表明,合法的TLS原语(包括会话缓存条目、重新协商逻辑、扩展解析及证书验证步骤)可组合成与认证和信任决策耦合而非物理驱动的图灵完备系统。本文将这种耦合形式化为“信任驱动”,并提出任何提供会话存储、序列号计数器运算、握手状态条件分支及恢复或重试循环迭代的TLS实现,均满足任意计算的条件。本文通过基于真实OpenSSL代码路径构建的两个可运行演示验证了该理论:第一个是哨兵系统,将标准TLS原语组合为检测异常握手行为的防御机制;第二个是认证绕过,通过连接中途重新协商将同类原语组合为攻击,在无内存损坏或外部恶意软件的情况下绕过密码强度策略检查。两个演示均在Docker中针对真实服务器和客户端二进制文件运行。

英文摘要

Weird machines are latent computational capabilities that emerge from the composition of architectural components. Prior work has studied this phenomenon extensively in software systems, including x86 instructions, ELF metadata, and page tables, and more recently in cyber-physical systems such as industrial control networks. This paper extends weird machine theory to a new domain: the Transport Layer Security (TLS) handshake and its two dominant implementations, OpenSSL and BoringSSL. We show that legitimate TLS primitives, including session cache entries, renegotiation logic, extension parsing, and certificate verification steps, compose into Turing-complete systems whose computation is coupled to authentication and trust decisions rather than physical actuation. We formalize this coupling, which we call trust actuation, and argue that any TLS implementation providing session storage, arithmetic on sequence counters, conditional branching on handshake state, and iteration through resumption or retry loops satisfies the conditions for arbitrary computation. We validate this theory with two working demonstrations built on real OpenSSL code paths. The first, a sentinel system, composes standard TLS primitives into a defensive mechanism that detects anomalous handshake behavior. The second, an authentication bypass, composes the same class of primitives into an attack that defeats a cipher-strength policy check through mid-connection renegotiation, without any memory corruption or external malware. Both demonstrations run against real server and client binaries in Docker.

补充信息

↑