Skip to content

Feign East, Strike West! Constructing Covert Channel on TLS 1.3

2026 · IEEE Transactions on Information Forensics and Security · Vol 21, pp. 8416-8430 · 0 citations · 48 references

Abstract

The transport layer is a critical component of the Internet protocol stack, providing reliable data delivery and securing the communication channel between clients and servers. TLS 1.3, the de facto standard protocol for this layer, is deployed on billions of devices and provides the confidentiality and integrity of most web traffic. Yet the very standardization and protocol transparency that make TLS so successful also enable mandatory network auditing and censorship. Network intermediaries can require disclosure of session keys or perform deep packet inspection (DPI) to verify that the communication complies with local policies, effectively breaking the promise of end-to-end encryption. Existing countermeasures either deviate from standard TLS or introduce non-compliant traffic patterns, rendering them detectable by modern censors. In this paper, we propose CCCC, a covert communication scheme that is fully compliant with standard TLS 1.3. Our key insight is twofold: (i) we efficiently construct collision ciphertexts, which allow a single AES ciphertext-tag pair to be decrypted successfully; (ii) we reduce the transmission of a covert message to the transmission of an innocuous vector, which is embedded within a standard EdDSA signature during the TLS handshake without undermining public verifiability. For a compulsory auditor who holds only the session key, every message—the handshake with its valid signature and all subsequent application records—appears perfectly normal and decrypts to a harmless overt message. The intended receiver, who holds a pre-shared secret key, recovers the vector from the signature and reconstructs the hidden message via the collision ciphertext. We formally define the security properties of collision ciphertexts, provide an efficient instantiation using AES-GCM and EdDSA, and implement a full prototype. Comprehensive performance evaluation demonstrates practical efficiency of our scheme, with only moderate overhead compared to standard TLS 1.3.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.