Basic Concepts

HTTP(HyperText Transfer Protocol) is an application-layer protocol used for distributed, collaborative, and hypermedia information systems. Simply put, it is a method for publishing and receiving HTML pages, used to transfer information between web browsers and web servers.

HTTP works by default on port 80 of the TCP protocol. When users visit websiteshttp://with the [http://] prefix, these are standard HTTP services.

The HTTP protocol sends content in plaintext and does not provide any form of data encryption. If an attacker intercepts the transmission messages between a web browser and a web server, they can directly read the information contained in them. Therefore, the HTTP protocol is not suitable for transmitting sensitive information, such as credit card numbers, passwords, and other payment information.

HTTPS(Hypertext Transfer Protocol Secure) is a transport protocol for secure communication over computer networks. HTTPS communicates via HTTP but uses SSL/TLS to encrypt data packets. The main purpose of HTTPS development is to provide identity authentication for web servers and protect the privacy and integrity of exchanged data.

HTTPS works by default on port 443 of the TCP protocol. Its workflow is generally as follows:

  • 1. TCP three-way synchronization handshake
  • 2. The client verifies the server's digital certificate
  • 3. The DH algorithm negotiates the key for the symmetric encryption algorithm and the key for the hash algorithm
  • 4. SSL secure encryption tunnel negotiation is complete
  • 5. The webpage is transmitted in encrypted form, encrypted with the negotiated symmetric encryption algorithm and key, ensuring data confidentiality; the negotiated hash algorithm is used for data integrity protection, ensuring data is not tampered with.

As of June 2018, 34.6% of the top 1 million websites in the Alexa ranking used HTTPS as the default, 43.1% of the 141,387 most popular websites on the internet had securely implemented HTTPS, and 45% of page loads (recorded via Firefox) used HTTPS. In March 2017, 0.11% of the total registered domain names in China used HTTPS.

According to Mozilla statistics, since January 2017, more than half of website traffic has been encrypted.

Difference between HTTP and HTTPS

  • HTTP transmits in plaintext, and data is unencrypted, so security is poor. HTTPS (SSL+HTTP) encrypts the data transmission process, so security is better.
  • Using the HTTPS protocol requires applying for a certificate from a CA (Certificate Authority). There are generally few free certificates, so a certain fee is required. Certificate issuing authorities include: Symantec, Comodo, GoDaddy, GlobalSign, etc.
  • HTTP page response speed is faster than HTTPS, mainly because HTTP uses a TCP three-way handshake to establish a connection, requiring the client and server to exchange 3 packets, while HTTPS, in addition to the three TCP packets, also requires the 9 packets needed for the SSL handshake, so a total of 12 packets.
  • HTTP and HTTPS use completely different connection methods and different ports: the former uses 80, and the latter uses 443.
  • HTTPS is actually the HTTP protocol built on top of SSL/TLS, so HTTPS consumes more server resources than HTTP.

TCP Three-Way Handshake

In the TCP/IP protocol, the TCP protocol establishes a reliable connection through a three-way handshake.

  • First handshake: The client attempts to connect to the server and sends a SYN packet (Synchronize Sequence Numbers), syn=j. The client enters the SYN_SEND state and waits for the server's acknowledgment.
  • Second handshake: The server receives the client's SYN packet and acknowledges it (ack=j+1), while also sending a SYN packet (syn=k) to the client, i.e., a SYN+ACK packet. At this point, the server enters the SYN_RECV state.
  • Third handshake: The client receives the server's SYN+ACK packet and sends an acknowledgment packet ACK (ack=k+1) to the server. After this packet is sent, the client and server enter the ESTABLISHED state, completing the three-way handshake.

Simplified:

How HTTPS Works

We all know that HTTPS can encrypt information to prevent sensitive information from being obtained by third parties, so many high-security services such as banking websites or email services adopt the HTTPS protocol.

1. The client initiates an HTTPS request

There's nothing much to say here: the user enters an HTTPS URL in the browser and then connects to the server's port 443.

2. Server-side configuration

A server using the HTTPS protocol must have a digital certificate, which can be self-made or applied for from an organization. The difference is that self-issued certificates require client verification to pass before access can continue, while certificates applied for from trusted companies will not pop up a prompt page (StartSSL is a good choice, with 1 year of free service).

This certificate is actually a pair of a public key and a private key. If you don't quite understand public and private keys, imagine a key and a padlock. Only you in the whole world have this key. You can give the padlock to others. Others can use the padlock to lock up important things and then send them to you. Because only you have the key, only you can see the things locked by this padlock.

3. Transmit the certificate

This certificate is actually the public key, but it contains a lot of information, such as the certificate issuing authority, expiration time, and so on.

4. The client parses the certificate

This part of the work is done by the client's TLS. First, it verifies whether the public key is valid, such as the issuing authority, expiration time, etc. If an abnormality is found, a warning box will pop up indicating that there is a problem with the certificate.

If the certificate has no problem, a random value is generated, and then the certificate is used to encrypt the random value, just like what was said above: lock the random value with a padlock, so unless you have the key, you cannot see the locked content.

5. Transmit the encrypted information

What is transmitted here is the random value encrypted with the certificate. The purpose is to let the server obtain this random value, so that future communication between the client and the server can be encrypted and decrypted using this random value.

6. The server decrypts the information

After the server decrypts with the private key, it obtains the random value (symmetric key) sent by the client, and then symmetrically encrypts the content with this value. The so-called symmetric encryption means mixing the information and the private key together through some algorithm, so that unless you know the private key, you cannot obtain the content. And since both the client and the server know this private key, as long as the encryption algorithm is robust enough and the private key is complex enough, the data is secure enough.

7. Transmit the encrypted information

This part of the information is encrypted by the server side with the private key and can be restored on the client side.

8. The client decrypts the information

The client uses the previously generated private key to decrypt the information sent by the server side, thereby obtaining the decrypted content. Throughout the entire process, even if a third party intercepts the data, they can do nothing about it.