Predicting TLS performance from key exchange performance

Farhad Moghimifar, Douglas Stebila · Proceedings of the Australasian Computer Science Week Multiconference · 2016

Most benchmarking of cryptographic systems focuses on the performance of individual algorithms in a standalone setting. However, real-world applications such as the Transport Layer Security (TLS) protocol use a variety of cryptographic algorithms together. Benchmarking the performance of a web server using TLS is a more complex task, so fewer works include performance characteristics of full systems. In this work, we develop a model for the number of connections per second of a TLS-protected web server based on the runtime of individual cryptographic operations. Our model allows us to predict how performance scales with file size. Our model also allows us to predict the impact of improved key exchange algorithms: for example, on an HTTPS server with 1KiB files running ECDSA-nistp256 with AES-128-GCM and HMAC-SHA-256, a 2x improvement in ephemeral Diffie--Hellman key exchange performance only leads to a 10% improvement in connections per second, as signatures become the dominant cost.

Read the paper · More papers on PaperTik