Is there any way to account a response of a TLS enabled server to it's public key?
Something like reverse fingerprinting?
Is there any way to account a response of a TLS enabled server to it's public key?
Something like reverse fingerprinting?
If the cipher suite used has authenticity in the symmetric part, that proof would be enough.
There are no implementations of this to my knowledge, and all the general zero knowledge proof caveats of speed, proof-size, etc all still apply.
It is definitely possible though. It would be cool to make. Why would anyone need this though?
If you want to fix this, you need the authenticity of the ciphertext to be proven to the recipient without the recipient being able to transfer it. An interactive zero knowledge proof could maybe do that.
I guess, the only reliable way is to sign the response, which requires changes to the server
If I sign any data, it's mathematically linked to the certificate, but that doesn't mean the cert was involved in creating the data.
I don't think this is possible if all you have is your own recording of the ciphertext, with no proof that it was actually transferred over the wire. This is the typical situation with packet capturing at one endpoint only.
But there was no background info. Just "We use ZKP to prove we got the right data"
So, it's technically possible?
I was hoping responses were signed.