ZTLS: A DNS-based Approach to Zero Round Trip Delay in TLS handshake
Sangwon Lim, Hyeonmin Lee, Hyunsoo Kim, Hyunwoo Lee, Ted Taekyoung Kwon
Abstract
Establishing secure connections fast to end-users is crucial to online services. However, when a client sets up a TLS session with a server, the TLS handshake needs one round trip time (RTT) to negotiate a session key. Additionally, establishing a TLS session also requires a DNS lookup (e.g., the A record lookup to fetch the IP address of the server) and a TCP handshake. In this paper, we propose ZTLS to eliminate the 1-RTT latency for the TLS handshake by leveraging the DNS. In ZTLS, a server distributes TLS handshakerelated data (i.e., Dife-Hellman elements), dubbed Z-data, as DNS records. A ZTLS client can fetch Z-data by DNS lookups and derive a session key. With the session key, the client can send encrypted data along with its ClientHello, achieving 0-RTT. ZTLS supports incremental deployability on the current TLS-based infrastructure. Our prototype-based experiments show that ZTLS is 1-RTT faster than TLS in terms of the frst response time. CCS CONCEPTS • Security and privacy → Web protocol security; Security protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f52c2b7-5439-42ed-8770-e02e1da3bc98Cited by top-tier papers2
- ExpressPQDelivery: Toward Efficient and Immediately Deployable Post-Quantum Key Delivery for Web-of-ThingsJane Kim, Jung-Hun Kang, Hyunwoo Lee, Seung-Hyun SeoWWW 2025 · 1 citation
- Looma: A Low-Latency PQTLS Authentication Architecture for Cloud ApplicationsXinshu Ma, Michio HondaNDSS 2026
Builds on2
- TLS 1.3 in Practice: How TLS 1.3 Contributes to the InternetHyunwoo Lee, Doowon Kim, Yonghwi KwonWWW 2021 · 47 citations
- Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKIPouyan Fotouhi Tehrani, Eric Osterweil, Jochen H. Schiller, Thomas C. Schmidt et al.WWW 2021 · 9 citations
Related papers
- Zero-Knowledge MiddleboxesPaul Grubbs, Arasu Arun, Ye Zhang, Joseph Bonneau et al.USENIX Security 2022
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- Comparing the Effects of DNS, DoT, and DoH on Web PerformanceAustin Hounsel, Kevin Borgolte, Paul Schmitt, Jordan Holland et al.WWW 2020 · 59 citations
- InviCloak: An End-to-End Approach to Privacy and Performance in Web Content DistributionShihan Lin, Rui Xin, Aayush Goel, Xiaowei YangCCS 2022 · 5 citations
- Protecting Insecure Communications with Topology-aware Network TunnelsGeorgios Kontaxis, Angelos D. KeromytisCCS 2016 · 1 citation
