½ñÄê6Ô£¬Î¬»ùýÌå»ù½ð»á·¢²¼¹«¸æ£¬ÆìÏÂËùÓÐÍøÕ¾½«Ä¬ÈÏ¿ªÆôHTTPS£¬ÕâÐ©ÍøÕ¾ÖÐ×îΪÈËËùÖªµÄµ±È»ÊÇÈ«Çò×î´óµÄÔÚÏß°Ù¿Æ-ά»ù°Ù¿Æ¡£¶ø¸üÔçʱºòµÄ3Ô£¬°Ù¶ÈÒѾ·¢²¼¹«¸æ£¬°Ù¶ÈȫվĬÈÏ¿ªÆôHTTPS¡£ÌÔ±¦Ò²Ä¬Ä¬×öÁËȫվHTTPS¡£
ÍøÕ¾ÊµÏÖHTTPS£¬ÔÚ¹úÍâÒѾ·Ç³£ÆÕ¼°£¬Ò²ÊDZØÈ»µÄÇ÷ÊÆ¡£Google¡¢Facebook¡¢TwitterµÈ¾ÞÍ·¹«Ë¾ÔçÒѾʵÏÖȫվHTTPS£¬¶øÇÒΪ¹ÄÀøÈ«ÇòÍøÕ¾µÄHTTPSʵÏÖ£¬GoogleÉõÖÁµ÷ÕûÁËËÑË÷ÒýÇæËã·¨£¬ÈòÉÓÃHTTPSµÄÍøÕ¾ÔÚËÑË÷ÖÐÅÅÃû¸ü¿¿Ç°¡£µ«ÊÇÔÚ¹úÄÚ£¬HTTPSÍøÕ¾½øÕ¹²¢²»ºÃ£¬´ó²¿·ÖµÄµçÉÌÍøÕ¾Ò²½ö½öÊǶÔÕË»§µÇ¼ºÍ½»Ò××öHTTPS£¬±ÈÈ義¶«£»ºÜ¶àÍøÕ¾ÉõÖÁÁ¬µÇÂ¼Ò³ÃæÒ²Ã»ÓÐʵÏÖHTTPS...ÕâÀïÃæÓкܶàµÄÔÒò£¬±ÈÈçÏÖÓмܹ¹¸Ä¶¯µÄ´ú¼Û¹ý´ó¡¢CDNʵÏÖÀ§ÄÑ¡¢¶ÔÓû§Òþ˽ºÍ°²È«µÄ²»ÖØÊӵȡ£
»¹ÓиöÖØÒªÔÒòÊǵ£ÐÄÍøÕ¾ÊµÏÖHTTPSºó£¬ÍøÕ¾µÄÓû§ÌåÑéºÍÐÔÄÜϽµÃ÷ÏÔ¡£ÊÂʵÉÏ£¬Í¨¹ýºÏÀí²¿ÊðºÍÓÅ»¯£¬HTTPSÍøÕ¾µÄ·ÃÎÊËٶȺÍÐÔÄÜ»ù±¾²»»áÊܵ½Ó°Ïì¡£
Ò»¡¢Ê²Ã´ÊÇHTTPSÍøÕ¾£¿
ÔÚ½éÉÜHTTPSÍøÕ¾Ç°£¬Ê×Ïȼòµ¥½éÉÜʲôÊÇHTTPS¡£
HTTPS¿ÉÒÔÀí½âΪHTTP+TLS£¬HTTPÊÇ»¥ÁªÍøÖÐʹÓÃ×îΪ¹ã·ºµÄÐÒ飬Ŀǰ²»²¿·ÖµÄWEBÓ¦ÓúÍÍøÕ¾¶¼ÊÇʹÓÃHTTPÐÒé´«Êä¡£Ö÷Á÷°æ±¾ÊÇHTTP1.1£¬HTTP2.0»¹Î´ÕýʽÆÕ¼°£¬2.0ÓÉGoogleµÄSPDYÐÒéÑÝ»¯¶øÀ´£¬ÔÚÐÔÄÜÉÏÓÐÃ÷ÏÔµÄÌáÉý¡£
TLSÊÇ´«Êä²ã¼ÓÃÜÐÒ飬ÊÇHTTPS°²È«µÄºËÐÄ£¬ÆäǰÉíÊÇSSL£¬Ö÷Á÷°æ±¾ÓÐSSL3.0¡¢TLS1.0¡¢TLS1.1¡¢TLS1.2¡£SSL3.0ºÍTLS1.0ÓÉÓÚ´æÔÚ°²È«Â©¶´£¬ÒѾºÜÉÙ±»Ê¹Óõ½¡£
ÄÇÍøÕ¾ÎªÊ²Ã´ÒªÊµÏÖHTTPS£¿
Ò»ÑÔ¸ÅÖ®£¬Îª±£»¤Óû§Òþ˽ºÍÍøÂ簲ȫ¡£Í¨¹ýÊý¾Ý¼ÓÃÜ¡¢Ð£ÑéÊý¾ÝÍêÕûÐÔºÍÉí·ÝÈÏÖ¤ÈýÖÖ»úÖÆÀ´±£Õϰ²È«¡£
ÓÉÓÚ±¾ÎĵÄÖØµãÊÇHTTPSÍøÕ¾µÄÐÔÄܼÓËÙ£¬¶ÔÓÚHTTPSͨÐŹý³ÌºÍ¼Ó½âÃÜËã·¨¾Í²»Õ¹¿ª½éÉÜÁË¡£
¸ÐÐËȤµÄͬѧ¿ÉÒÔGoogleÖ®£¬»ù´¡¶¼ÊÇÒ»ÑùµÄ¡£
¶þ¡¢HTTPSÍøÕ¾µÄÖ±¹ÛÁ˽â
ÍÆ¼öÒ»¸öÔÚÏß°æÈ«ÇòÖªÃûµÄHTTPSÍøÕ¾¼ì²â¹¤¾ß-SSL Labs¡£Qualys SSL LabsͬʱҲÊǺܾßÓÐÓ°ÏìÁ¦µÄSSL°²È«ºÍÐÔÄÜÑо¿»ú¹¹¡£ÔÚÏß¼ì²âµØÖ·Îª£ºhttps://www.ssllabs.com/ssltest/¡£
SSL Labs»á¶ÔHTTPSÍøÕ¾µÄÖ¤ÊéÁ´¡¢°²È«ÐÔ¡¢ÐÔÄÜ¡¢ÐÒéϸ½Ú½øÐÐÈ«Ãæ¼ì²â£¬¼ì²âÍê±Ïºó»á½øÐдò·Ö£¬Í¬Ê±¸ø³öÒ»·ÝÏêϸµÄ¼ì²â±¨¸æºÍ¸Ä½ø½¨Òé¡£
ÏÂÃæÎÒÃǶÔһЩ³£ÓÃÍøÕ¾½øÐмì²â¡£·Ö±ðÊÇ12306¹ºÆ±Ò³Ãæ¡¢ÌÔ±¦Ê×Ò³¡¢°Ù¶ÈÊ×Ò³¡¢Î¬»ù°Ù¿ÆÊ×Ò³¡¢WildDogÊ×Ò³µÄ¼ì²â½á¹û¡£
12306¹ºÆ±Ò³Ãæ
ÌÔ±¦Ê×Ò³
°Ù¶ÈÊ×Ò³
ά»ù°Ù¿ÆÊ×Ò³
WildDogÊ×Ò³
¿ÉÒÔ¿´µ½£¬ËäÈ»¶¼ÊÇHTTPSÍøÕ¾£¬µ«ÊDzî¾à¾ÍÊÇÄÇô´ó...... ÕâÀïҪ˳±ãÌáÏ£¬12306ÕæµÄºÜ´ì£¬°Ù¶ÈºÍÌÔ±¦Îª¼æÈÝһЩµÍ¶Ë°æ±¾µÄÓû§£¬Ò²ÊǸ÷ÖÖʹÓÃÈõ¼ÓÃܺÍÐÒé¡£
Èý¡¢Ìá¸ßHTTPSÍøÕ¾ÐÔÄܺͷÃÎÊËÙ¶È
Èç¹ûÄãÈÏÎªÍøÕ¾¼ÓÉÏTLSÖ¤Ê飬¾ÍÊÇHTTPSÍøÕ¾ÁË£¬ÄÇÄã¾Í¸ú12306·¸ÁËͬÑùµÄ´íÎó......
Ê×ÏÈ£¬ÍøÕ¾ÔÚ¼ÓÉÏTLSÖ¤Êéʱ£¬ÎªÊ²Ã´»á±äÂý£¿ÕâÖ÷ÒªÓÖÁ½·½ÃæÔì³É£º
-
HTTPS±ÈHTTPÔÚͨÐÅʱ»á²úÉú¸ü¶àµÄͨÐŹý³Ì£¬ËæÖ®RTTʱ¼ä¾Í»áÔö¼Ó£»
-
HTTPSͨÐŹý³ÌµÄ·Ç¶Ô³ÆºÍ¶Ô³Æ¼Ó½âÃܼÆËã»á²úÉú¸ü¶àµÄ·þÎñÆ÷ÐÔÄܺÍʱ¼äÉϵÄÏûºÄ¡£
µ«ÊÇ£¬Ã¿¸öHTTPSÍøÕ¾Æäʵ¶¼ÓÐמ޴óµÄÓÅ»¯¿Õ¼ä¡£ÏÂÃæÎÒÃǽáºÏWildDogÍøÕ¾£¬À´¿´¿´QPSÖµ´Ó30000µ½80000£¬¼ÓÔØÊ±ÑÓ´Ó800msµ½300ms£¬ÕâÖмäµÄÿ¸öÓÅ»¯µãÊÇÔõÑùµÄ¡£
HSTS
HTTPSÍøÕ¾Í¨³£µÄ×ö·¨ÊǶÔHTTPµÄ·ÃÎÊÔÚ·þÎñÆ÷¶Ë×ö302Ìø×ª£¬Ìø×ªµ½HTTPS¡£µ«Õâ¸ö302Ìø×ª´æÔÚÁ½¸öÎÊÌ⣺
-
ʹÓò»°²È«µÄHTTPÐÒé½øÐÐͨÐÅ£»
-
Ôö¼ÓÒ»¸öRound-Trip Time¡£
¶øHSTSÊÇHTTP Strict Transport SecurityµÄËõд£¬·þÎñÆ÷¶ËÅäÖÃÖ§³ÖHSTSºó£¬»áÔÚ¸øä¯ÀÀÆ÷·µ»ØµÄHTTP HeaderÖÐЯ´øHSTS×ֶΣ¬ä¯ÀÀÆ÷ÔÚ»ñÈ¡µ½¸ÃÐÅÏ¢ºó£¬ÔÚ½ÓÏÂÀ´µÄÒ»¶Îʱ¼äÄÚ£¬¶Ô¸ÃÍøÕ¾µÄËùÓÐHTTP·ÃÎÊ£¬ä¯ÀÀÆ÷¶¼½«ÇëÇóÔÚÄÚ²¿×ö307Ìø×ªµ½HTTPS£¬¶øÎÞÐèÈκÎÍøÂç¹ý³Ì¡£
Session Resume
Session Resume¼´»á»°¸´Óã¬ÕâÌáÉýHTTPSÍøÕ¾ÐÔÄÜ×î»ù´¡Ò²ÊÇ×îÓÐЧµÄ·½·¨¡£
ÔÚHTTPSÎÕÊֽ׶Σ¬¶Ô·þÎñÆ÷ÐÔÄÜÏûºÄ×îΪÑÏÖØµÄÊǷǶԳÆÃÜÔ¿½»»»¼ÆË㣬¶øSession Resumeͨ¹ý¶ÔÒѾ½¨Á¢TLS»á»°µÄºÏÀí¸´Ó㬽ÚÊ¡·Ç¶Ô³ÆÃÜÔ¿½»»»¼ÆËã´ÎÊý£¬¿É´ó·ùÌá¸ß·þÎñÆ÷µÄTLSÐÔÄÜ¡£
TLSÐÒéÌṩÁ½ÖÖʵÏÖ»úÖÆSession Resume£¬·Ö±ðÊÇSession cacheºÍSession ticket¡£
Session Cache
Session CacheµÄÔÀíÊÇʹÓÃSession ID²éѯ·þÎñÆ÷ÉϵÄsession cache£¬Èç¹ûÃüÖУ¬ÔòÖ±½ÓʹÓûº´æÐÅÏ¢¡£µ«Session CacheÓиöÃ÷ÏÔµÄȱµã£¬Ëü²»Ö§³Ö·Ö²¼Ê½»º´æ£¬Ö»Ö§³Öµ¥»ú½ø³Ì¼äµÄ¹²Ïí»º´æ¡£Õâ¶ÔÓÚ¶à¸ö½ÓÈë½ÚµãµÄ¼Ü¹¹ºÜÄÑÊÊÓá£
Session ticket
Session ticketµÄÔÀíÊÇ·þÎñÆ÷½µsessionÐÅÏ¢¼ÓÃܳÉticket·¢Ë͸øä¯ÀÀÆ÷£¬ä¯ÀÀÆ÷ºóÐø½øÐÐTLSÎÕÊÖʱ£¬»á·¢ËÍticket£¬Èç¹û·þÎñÆ÷Äܹ»½âÃܺʹ¦Àí¸Ãticket£¬Ôò¿ÉÒÔ¸´ÓÃsession¡£
Session ticket¿ÉÒԺܺõĽâ¾ö·Ö²¼Ê½ÎÊÌ⣬µ«Session ticketµÄÖ§³ÖÂÊ»¹²»ÊǺܸߣ¬¶øÇÒÐèÒª¿¼ÂÇ·þÎñÆ÷ÉÏkeyµÄ°²È«ÐÔ·½°¸¡£
OCSP Stapling
ÔÚHTTPSͨÐŹý³Ìʱ£¬ä¯ÀÀÆ÷»áÈ¥ÑéÖ¤·þÎñÆ÷¶ËÏ·¢µÄÖ¤ÊéÁ´ÊÇ·ñÒѾ±»³·Ïú¡£ÑéÖ¤µÄ·½·¨ÓÐÁ½ÖÖ£ºCRLºÍOCSP¡£
CRLÊÇÖ¤Êé³·ÏúÁÐ±í£¬CA»ú¹¹»áά»¤²¢¶¨ÆÚ¸üÐÂCRLÁÐ±í£¬µ«Õâ¸ö»úÖÆ´æÔÚ²»×㣺
1.CRLÁбíÖ»»áÔ½À´Ô½´ó£»
2.Èç¹ûä¯ÀÀÆ÷¸üв»¼°Ê±£¬»áÔì³ÉÎóÅС£
OCSPÊÇʵʱ֤ÊéÔÚÏßÑéÖ¤ÐÒ飬ÊǶÔCRL»úÖÆµÄÃÖ²¹£¬Í¨¹ýOCSPä¯ÀÀÆ÷¿ÉÒÔʵʱµÄÏòCA»ú¹¹ÑéÖ¤Ö¤Êé¡£µ«OCSPͬÑù´æÔÚ²»×㣺
-
¶ÔCA»ú¹¹ÒªÇó¹ý¸ß£¬ÒªÇóʵʱȫÇò¸ß¿ÉÓã»
-
¿Í»§¶ËµÄ·ÃÎÊÒþ˽»áÔÚCA»ú¹¹±»Ð¹Â¶£»
-
Ôö¼Óä¯ÀÀÆ÷µÄÎÕÊÖʱÑÓ¡£
¶øOCSP StaplingÊǶÔOCSPȱÏݵÄÃÖ²¹£¬·þÎñÆ÷¿ÉÊÂÏÈÄ£Äâä¯ÀÀÆ÷¶ÔÖ¤ÊéÁ´½øÐÐÑéÖ¤£¬²¢½«´øÓÐCA»ú¹¹Ç©ÃûµÄOCSPÏìÓ¦±£´æµ½±¾µØ£¬È»ºóÔÚÎÕÊֽ׶Σ¬½«OCSPÏìÓ¦ºÍÖ¤ÊéÁ´Ò»ÆðÏ·¢¸øä¯ÀÀÆ÷£¬Ê¡È¥ä¯ÀÀÆ÷µÄÔÚÏßÑéÖ¤¹ý³Ì¡£
SPDYºÍHTTP2.0
SPDY ÊÇ Google ÍÆ³öµÄÓÅ»¯ HTTP ´«ÊäЧÂʵÄÐÒ飬²ÉÓöà·¸´Ó÷½Ê½£¬Äܽ«¶à¸ö HTTP ÇëÇóÔÚͬһ¸öÁ¬½ÓÉÏÒ»Æð·¢³öÈ¥£¬¶ÔHTTPͨÐÅЧÂÊÌáÉýÃ÷ÏÔ¡£HTTP2.0ÊÇ IETF 2015 Äê 2 Ô·Ýͨ¹ýµÄ HTTP ÏÂÒ»´úÐÒ飬ËüÒÔ SPDY ΪÔÐÍ¡£SPDY ºÍ HTTP2 ĿǰµÄʵÏÖĬÈÏʹÓà HTTPS ÐÒé¡£
Nginx stable°æ±¾µ±Ç°Ö»ÄÜÖ§³Öµ½SPDY3.1£¬µ«×îз¢²¼µÄ1.9.5°æ±¾Í¨¹ý´òpatchµÄ·½Ê½£¬¿ÉÒÔÖ§³ÖHTTP2.0£¬Õâ¾ø¶ÔÊDz»Ò»ÑùµÄÆæÃîÌåÑé¡£²»¹ý²»½¨ÒéÖ±½ÓÔÚÏßÉÏ»·¾³²¿Ê𣬵ȵ½2015ÄêÄêµ×°É£¬Nginx»á·¢²¼Stable°æ±¾Ö§³ÖHTTP2.0.
TCPÓÅ»¯
ÒòΪTCPÊÇHTTPSµÄ³ÐÔØ£¬TCPµÄÐÔÄÜÌáÉý£¬ÉϲãÒµÎñ¶¼¿ÉÒÔÊÜÒæ¡£
ÂýÆô¶¯ÊÇTCP¹æ·¶ÖкÜÖØÒªµÄËã·¨£¬ÆäÄ¿µÄÊÇΪ±ÜÃâÍøÂçÓµÈû¡£Í¨¹ý¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄÊý¾Ý½»»»£¬´ÓÒ»¸öºÜ±£ÊصijõʼӵÈû´°¿ÚÖµ£¬ÊÕÁ²µ½Ë«·½¶¼ÈϿɵĿÉÓôø¿í¡£µ±¿Í»§¶ËºÍ·þÎñÆ÷ÊÕÁ²µ½Ò»¶¨´ø¿íʱ£¬Èç¹ûÒ»¶Îʱ¼äÄÚ£¬Ë«·½Ã»ÓÐÊÕ·¢Êý¾Ý°ü£¬·þÎñÆ÷¶ËµÄÓµÈû´°¿Ú»á±»ÖØÖÃΪ³õʼӵÈû´°¿ÚÖµ¡£Õâ¶ÔÓÚÁ¬½ÓÖеÄÍ»·¢Êý¾Ý´«ÊäÐÔÄÜÓ°ÏìÊǺÜÑÏÖØµÄ¡£
ÔÚûÓгä×ãµÄÀíÓÉʱ£¬·þÎñÆ÷¶ËÐèÒª½ûÓÿÕÏкóµÄÂýÆô¶¯»úÖÆ¡£
ÁíÍ⣬µ±Ç°ä¯ÀÀÆ÷ºÍ·þÎñÆ÷Ö®¼äµÄ¿ÉÓôø¿íÒѾÏà¶Ô½Ï´ó£¬ËùÒÔÎÒÃÇ»¹Ó¦¸Ã½«³õʼµÄÓµÈû´°¿ÚÖµÀ©´ó£¬ÐµÄRFCÖеĽ¨ÒéÊÇ10£¬GoogleÊÇ16¡£
TLS Record Size
·þÎñÆ÷ÔÚ½¨Á¢TLSÁ¬½Óʱ£¬»áΪÿ¸öÁ¬½Ó·ÖÅäBuffer£¬Õâ¸öBuffer½ÐTLS Record Size¡£Õâ¸öSizeÊǿɵ÷¡£
SizeÖµÈç¹û¹ýС£¬Í·²¿¸ºÔرÈÖØ¾Í»á¹ý´ó£¬×î¸ß¿É´ï6%¡£
SizeÖµÈç¹û¹ý´ó£¬Äǵ¥¸öRecordÔÚTCP²ã»á±»·Ö³É¶à¸ö°ü·¢ËÍ¡£ä¯ÀÀÆ÷±ØÐëµÈ´ýÕâЩȫ²¿´ïµ½ºó£¬²ÅÄܽâÃÜ£¬Ò»µ©³öÏÖ¶ª°ü¡¢ÓµÈû¡¢ÖØ´«¡¢ÉõÖÁÖØÐ½¨Á¢µÄÇé¿ö£¬Ê±ÑӾͻᱻÏàÓ¦Ôö¼Ó¡£
ÄÇTLS Record SizeÖµÈçºÎÑ¡ÔñÄØ£¿ÓÐÁ½¸ö²ÎÊý¿É²Î¿¼¡£
Ê×ÏÈ£¬TLS Record SizeÒª´óÓÚÖ¤ÊéÁ´ºÍOCSP StaplingÏìÓ¦´óС£¬Ö¤ÊéÁ´²»»á·Ö³É¶à¸örecord£»
Æä´Î£¬ÒªÐ¡ÓÚ³õʼӵÈû´°¿ÚÖµ£¬±£Ö¤·þÎñÆ÷ÔÚͨÐÅÖ®³õ¿ÉÒÔ·¢ËÍ×ã¹»Êý¾Ý¶ø²»ÐèÒªµÈ´ýä¯ÀÀÆ÷È·ÈÏ
Ò»°ãÀ´Ëµ£¬´Ó¸ùCA»ú¹¹ÉêÇëµÄÖ¤ÊéΪ2-3KB×óÓÒ£¬¼¶ÊýÔ½¶à£¬Ö¤ÊéÁ´Ô½´ó£¬ocspÏìӦΪ2KB×óÓÒ£¬ËùÒÔTLS Record SizeÊÇÐèÒª¸ù¾ÝÄãµÄʵ¼ÊÇé¿öÉèÖã¬GoogleµÄÖµ5KB¡£WildDogµ±Ç°µÄÖµÊÇ6KB¡£
Ö¤ÊéÁ´ÍêÕûÇÒ²»ÈßÓà
ä¯ÀÀÆ÷ÔÚÑéÖ¤·þÎñÆ÷Ï·¢µÄÖ¤ÊéÁ´Ê±£¬²»½ö½öÑéÖ¤ÍøÕ¾Ö¤Êé¡£Èç¹ûÊǶ༶֤Êé£¬ÍøÕ¾Ö¤ÊéºÍ¸ùÖ¤ÊéÖ®¼äËùÓеÄÖмäÖ¤Êé¶¼ÐèÒª±»ÑéÖ¤¡£Ò»µ©³öÏÖÖ¤ÊéÁ´³öÏÖ²»ÍêÕû£¬ä¯ÀÀÆ÷¾Í»áÔÝÍ£ÎÕÊÖ¹ý³Ì£¬×ÔÐе½ÒòÌØÍø½øÐÐÑéÖ¤£¬Õâ¸öʱ¼ä»ù±¾ÊDz»¿É¹ÀËãµÄ¡£
ÖÁÓÚÔõô²é¿´£¬Í¨¹ýopensslÃüÁî²é¿´£¬Ò²¿ÉÒÔͨ¹ýSSL Labs°ïÄãÔÚÏß¼ì²â¡£
ÒÆ¶¯É豸ÉϵÄChaCha20-Poly1305
È¥ÄêµÄʱºò£¬¹È¸èÒѾÔÚAndroidµÄChromeä¯ÀÀÆ÷ÉÏÔö¼ÓÖ§³ÖÒ»¸öеÄTLS¼ÓÃÜÌ×¼þ£¬Õâ¸ö¼ÓÃÜÌ×¼þ¾ÍÊÇChaCha20-Poly1305¡£ËüµÄÉè¼ÆÕßÊÇÒÁÀûŵÒÁ´óѧµÄ½ÌÊÚºÍÑо¿Ô±Dan BernsteinChaCha20±»ÓÃÀ´¼ÓÃÜ£¬Poly1305±»ÓÃÀ´ÏûÏ¢ÈÏÖ¤£¬Á½¸ö²Ù×÷¶¼ÐèÒªÔËÐÐÓÚTLSÉÏ¡£
µ±Ç°Á÷ÐеļÓÃÜÌ×¼þAES-GCMÔÚTLS 1.2Ö§³Ö£¬ËüÊDz»°²È«RC4ºÍAES-CBC¼ÓÃÜÌ×¼þµÄÌæ´úÆ·¡£µ«ÊÇ£¬ÔÚ²»Ö§³ÖÓ²¼þAESµÄÉ豸ÉÏ»áÒýÆðÐÔÄÜÎÊÌ⣬Èç´ó²¿·ÖµÄÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢¿É´©´÷É豸¡£
ChaCha20-Poly1305ÕýʽΪ½â¾öÕâ¸öÎÊÌâ¶øÉú¡£ÒÔÏÂÊÇGoogleµÄÏà¹Ø²âÊÔÊý¾Ý£¬ÔÚʹÓÃSnapdragon S4 Pro´¦ÀíÆ÷µÄNexus 4»òÆäËûÊÖ»úÖУ¬AES-GSMµÄ¼ÓÃÜÍÌÍÂÁ¿ÊÇ41.5MB/s£¬¶øChaCha20-Poly1305ÊÇ130.9MB/s¡£ÔÚʹÓÃOMAP 4460µÄÀϵÄGalaxy NexusÊÖ»úÉÏ£¬AES-GSMµÄÍÌÍÂÁ¿ÊÇ24.1MB/s£¬¶øChaCha20-Poly1305ÊÇ75.3MB/s¡£
µ±Ç°£¬OpenSSL 1.0.2µÄ·ÖÖ§ÉÏÒѾ¿ªÊ¼Ö§³ÖChaCha20-Poly1305£¬¶ø¶ÔChaCha20-Poly1305Ö§³Ö×îºÃµÄµ±ÊôBoringSSL¡£Í¨¹ýÖØÐ¶ÔNginxµÄSSL¿â±àÒ룬¿ÉÒÔÖ§³Öµ½ChaCha20-Poly1305£¬²»¹ý¶ÔÓÚÏßÉÏ»·¾³£¬½¨Òé¿´Ã÷°×Ô´ÂëÔÙʹÓá£
³ý´ËÖ®Í⣬»¹Óв»ÉÙÓÅ»¯µÄϸ½Ú£¬ÈçÓ²¼þ¼ÓËÙ¡¢False Start¡¢½ûÓÃTLSѹËõµÈµÈ£¬ÕâÀï¾Í²»°ÇÁË¡£
Èç¹û¾õµÃÕâÆªÎÄÕÂÓаïÖú£¬¾ÍÇëÊղػòÕß·ÖÏíһϣ¬Ï£Íû¿ÉÒÔ°ïµ½¸ü¶àÈË¡£
×÷ÕߣºÍõ¼Ì²¨
Ò°¹·¿Æ¼¼ÔËά×Ü¼à£¬ÔøÔÚ360¡¢TP-Link´ÓÊÂÍøÂçÔËάÏà¹Ø¹¤×÷£¬ÔÚÍøÕ¾ÐÔÄÜÓÅ»¯¡¢ÍøÂçÐÒéÑо¿ÉϾÑé·á¸»¡£
¹«ÖÚÕ˺ţºyeyegou
×ªÔØÇë×¢Ã÷£º ÎÄÕÂ×ªÔØ×Ô£º°®Ë¼×ÊÔ´Íø http://www.aseoe.com/show-26-682-1.html