The TLS handshake is the exchange that opens a TLS connection: the two sides agree on a protocol version and cipher, exchange key shares, the server proves its identity with its certificate, and both derive the keys that protect the records that follow; in TLS 1.3 it takes one round trip. Session resumption opens a new connection with a key derived from an earlier one (a pre-shared key sent to the client as a ticket), skipping the certificate and part of the key exchange.
| Operation (loopback, laptop) | Cost |
|---|---|
TLS 1.3 full handshake (Python ssl, both ends) | |
TLS 1.3 resumed handshake (Python ssl, both ends) | |
| Round trip of 300 bytes over TLS (Python) | |
| Round trip of 300 bytes over plain TCP (Python) | |
| AES-128-GCM seal of a 300-byte record (OpenSSL, C++) | |
| AES-128-GCM open of a 300-byte record (OpenSSL, C++) |
bench_web.py, measured_tls.csv and measured_web.csv.