Meaning
Security protocol optimizations enable encrypted communication sessions to be restarted without repeating the full cryptographic handshake. By employing DTLS session resumption, a constrained wireless device and a gateway use stored session identifiers or session tickets to re-establish a secure channel. This process bypasses the computationally expensive process of public key exchange and signature verification.
Cryptographic Overhead
Full handshakes require multiple round trips and the transmission of large digital certificates that strain narrow bandwidth links. Resumption mechanisms reduce this traffic to a single round-trip exchange.
Handshake Acceleration
The resource savings are most pronounced on low-power wide-area networks where long on-air times degrade battery life. When using session resumption, the device avoids calculating heavy signatures, saving valuable processor cycles and reducing peak current draw. This speedup is achieved by retrieving the symmetric keys from the device RAM or secure storage.
If the session has expired on the server, the system falls back to a full negotiation automatically. Consequently, maintaining a reasonable session lifetime on the security gateway is essential for high-frequency reporting cycles.
Energy Conservation
Minimizing the radio wake-up time directly translates to extended operational lifetimes for battery-powered sensors. Reducing the payload size also lowers the risk of packet fragmentation over unstable radio connections.