Accepted Paper to the Journal of Cryptology
This work provides a new security proof for version 1.3 of the Internet's most important security mechanism, Transport Layer Security (TLS). Compared to previous proofs, it provides a tight security bound, which implies that it is possible to deploy TLS efficiently without loosing a certain level of security.