TLS ngokumalunga ne-SSL

Ukhuseleko lwe-intanethi lusebenza njani

Ngenxa yeendlela ezininzi zokuphulwa kwedatha kwiindaba eziza kutshanje, unokuba uzibuza ukuba idatha yakho ikhuselwe njani xa usebenzisa intanethi. Uyazi, uya kwiwebhusayithi ukwenza enye yokuthenga, faka inombolo yakho yekhadi lesikweletu, kwaye uthemba ngemihla embalwa iphakheji iya kufika emnyango wakho. Kodwa ngaloo mzuzu ngaphambi kokuchofoza umyalelo , ngaba ucinga ukuba ukhuseleko lwe-intanethi lusebenza njani?

Iisiseko zoKhuseleko lwe-Intanethi

Kulo hlobo oluphambili, ukhuseleko lwe-intanethi-leyo yokhuseleko oluqhubekayo phakathi kwekhompyutheni yakho kunye newebhusayithi oyityelelayo-eyenziwa ngoluhlu lwemibuzo kunye nezimpendulo. Uthayiphe idilesi yewebhu kwisiphequluli sakho, kwaye isiphequluli sakho sicela loo ndawo ukuba iqinisekise ubungqina bayo, isiza siphendule ngolwazi olufanelekileyo, kwaye emva kokuvuma kokubili, isayithi ivuleka kwisiphequluli sakho sewebhu.

Phakathi kwemibuzo ebuzwayo kunye nolwazi olutshintshisayo lwedatha malunga nohlobo lokubhaliweyo olusetyenziswe ukudlulisa ulwazi lwenkcazelo yakho, ulwazi lwekhomputha, kunye nolwazi lomntu phakathi kwe-browser yakho kunye newebhusayithi. Le mibuzo neempendulo zibizwa ngokuba yi- handshake. Ukuba loo nto yokubamba ngesandla ayenzekanga, i-website ozama ukuyi tyelela iya kuthathwa ingaphephile.

HTTP neHTTPS

Into enye ongayibona xa u tyelela iiwebhu kwiwebhu kukuba abanye banayo idilesi eqala nge- http kwaye ezinye ziqala nge- https . I-HTTP ithetha iProtokholi yokuTshintshiselwa kwe-Hypertext ; ngumgaqo - nkqubo okanye isethi yezikhokelo ezibonisa uxhulumaniso olukhuselekileyo kwi-intanethi. Unokuba uqaphele ukuba ezinye iisayithi, ikakhulukazi iindawo apho uceliwe ukuba unikezele ngolwazi oluchanekileyo okanye oluthile luyakwazi ukubonisa ii- https okanye ezibomvu kunye nomgca. I-HTTPS ithetha iProtokholi yokuTshintshiselwa kweProtocol yokuPhepha, kunye nokuhlaza kuthetha ukuba isayithi sinesiqiniseko sokuqinisekisa isiqinisekiso. Olubomvu ngomgca kuthiwa isayithi ayinaso isatifikethi sezokhuseleko, okanye isatifikethi asichanekanga okanye siphelelwe yisikhathi.

Nakhu apho izinto zidibanisa khona. I-HTTP ayithethi idatha edluliselwe phakathi kwekhompyutha yakho kunye newebhusayithi ibhalwa. Kuthetha kuphela iwebhusayithi edibanisa nesiphequluli sakho isitifiketi sokukhusela esisebenzayo. Kuphela xa i- S (njengoko ku-HTTP S ) ifakiwe yidatha ekhutshiweyo ikhuselekile, kwaye kukho enye iteknoloji esebenzayo eyenza ukuba utyunjiweyo olukhuselekile lunokwenzeka.

Ukuqonda iProtocol ye-SSL

Xa ucinga ukwabelana ngokubambisana nomntu, oko kuthetha ukuba kukho iqela lesibini elibandakanyekayo. Ukhuseleko lwe-intanethi lufana ngendlela efanayo. Ukubamba isandla ngokuqinisekisa ukuba ukhuseleko lwe-intanethi luyenzeka, kufuneka kubekho iqela lesibini elibandakanyekayo. Ukuba i-HTTPS yinkqubo eyenziwa ngumkhangeli webhuseli ukuqinisekisa ukuba kukho ukhuseleko, ngoko-ke isiqingatha sesibini saloo nto ixhaswa ngumgaqo-nkqubo oqinisekisa ukubethela.

Ukubhalwa kweteknoloji iteknoloji esetyenziselwa ukuguqula idatha edluliselwe phakathi kwezixhobo ezimbini kwinethiwekhi. Kufezekiswa ngokuguqulela abalinganiswa ababonakalayo kwizinto ezinokungaziwayo ezinokubuyiselwa kwimo yaso yasekuqaleni usebenzisa ukhiye wokubhaliweyo. Oku kwasekuqaleni kwenziwa ngeteknoloji ebizwa ngokuba yokhuseleko lweSetter Socket Layer (SSL) .

Ngokwenene, i-SSL yile teknoloji ephendulele nayiphi na idatha ehamba phakathi kwewebhusayithi kunye nesiphequluli ukuba iguquke kwaye ibuye iphinde idatha kwakhona. Nantsi indlela esebenza ngayo:

Inkqubo iyaziphinda xa ufaka igama lakho lomsebenzisi kunye nephasiwedi, ngamanyathelo angaphezulu.

Inkqubo yenzeka kumasekhondi angama-nano, ngoko awuqapheli ixesha elithathayo le ngxoxo yonke kunye nokuxhaphaza ukuba kwenzeke phakathi kwesiphequluli sewebhu kunye newebhusayithi.

SSL vs TLS

I-SSL yimiyalelo yokukhusela yasekuqaleni eyayisetyenziselwa ukuqinisekisa ukuba iiwebhsayithi kunye nedatha edlulileyo phakathi kwazo zikhuselekile. Ngokutsho kwe-GlobalSign, i-SSL yaziswa ngo-1995 njengenguqulo 2.0. Inguqulelo yokuqala (1.0) ayizange ifake indlela yayo kwisiza karhulumente. I-2.0 yefayili yatshintshwa ngu-3.0 inguqu kunyaka ukujongana nokungonakali kwiprothotho. Ngo-1999, enye inguqu ye-SSL, ebizwa ngokuba yi-Transport Layer Security (TLS) yaziswa ukuba kuphuculwe ukukhawuleza kwencoko kunye nokukhuselwa kwesandla. I-TLS inguqulelo esetyenziswayo njengangoku, nangona ihlala ibizwa ngokuba ngu-SSL ngenxa yokulula.

TLS Ukubetha

I-encryption ye-TLS yaziswa ukuze kuphuculwe ukhuseleko lwe-data. Ngelixa i-SSL yayibugcisa obufanelekileyo, ukhuseleko luya kutshintshwa kwinqanaba elikhawulezayo, kwaye oko kwakhokelela ekufuneni ngcono, ukhuseleko olusesikhathini. I-TLS yakhiwe kwisakhelo se-SSL kunye nokuphucula okuphawulekayo kwiimpawu zokulungiswa ezilawula inkqubo yokunxibelelana kunye ne-handshake.

Yiyiphi i-TLS Version Eninzi kakhulu?

Njengoko nge-SSL, ukubethela kwe-TLS kuye kwaqhubeka ukuphucula. I-version ye-TLS yangoku i-1.2, kodwa i-TLSv1.3 ibhaliwe kwaye ezinye iinkampani kunye nezikhangeli ziye zasebenzisa ukhuseleko lwexesha elifutshane. Kwiimeko ezininzi, babuyela emuva kwi-TLSv1.2 kuba i-version 1.3 isacetyiswa.

Xa kugqityiwe, i-TLSv1.3 iya kuzisa ukuphucula amaninzi okukhuseleko, kuquka ukuxhaswa okuphuculweyo kwimiba ekhoyo yangoku yokubhala. Nangona kunjalo, i-TLSv1.3 iya kunika inkxaso kwiinguqu ezidala ze-SSL protocol kunye nezinye iikhompyutheni zokhuseleko ezingasenamandla okwaneleyo ukuqinisekisa ukhuseleko olufanelekileyo kunye nokubethelwa kwedatha yakho.