Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] On a security vs privacy trade-off in interconnected dynamical systems
    Katewa, Vaibhav
    Anguluri, Rajasekhar
    Pasqualetti, Fabio
    AUTOMATICA, 2021, 125
  • [32] Utility Privacy Trade-off for Noisy Channels in OFDM Systems
    Demir, Mehmet Ozgun
    Gokceli, Selahattin
    Dartmann, Guido
    Luecken, Volker
    Ascheid, Gerd
    Kurt, Gunes Karabulut
    2017 IEEE 86TH VEHICULAR TECHNOLOGY CONFERENCE (VTC-FALL), 2017,
  • [33] Utility/Privacy Trade-off through the lens of Optimal Transport
    Boursier, Etienne
    Perchet, Vianney
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 108, 2020, 108 : 591 - 600
  • [34] The Trade-Off Between Privacy and Fidelity via Ehrhart Theory
    Padakandla, Arun
    Kumar, P. R.
    Szpankowski, Wojciech
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2020, 66 (04) : 2549 - 2569
  • [35] TRADE-OFF ANALYSIS OF PREFERENCES FOR PUBLIC-SERVICES
    SMIT, B
    JOSEPH, A
    ENVIRONMENT AND BEHAVIOR, 1982, 14 (02) : 238 - 258
  • [36] A secure location-based alert system with tunable privacy-performance trade-off
    Ghinita, Gabriel
    Nguyen, Kien
    Maruseac, Mihai
    Shahabi, Cyrus
    GEOINFORMATICA, 2020, 24 (04) : 951 - 985
  • [37] Growing Connected Networks under Privacy Constraint: Achieving Trade-Off between Performance and Security
    Gusrialdi, Azwirman
    Qu, Zhihua
    2015 54TH IEEE CONFERENCE ON DECISION AND CONTROL (CDC), 2015, : 312 - 317
  • [38] A secure location-based alert system with tunable privacy-performance trade-off
    Gabriel Ghinita
    Kien Nguyen
    Mihai Maruseac
    Cyrus Shahabi
    GeoInformatica, 2020, 24 : 951 - 985
  • [39] Trade-off analysis of ecosystem services in Eastern Europe
    Ruijs, A.
    Wossink, A.
    Kortelainen, M.
    Alkemade, R.
    Schulp, C. J. E.
    ECOSYSTEM SERVICES, 2013, 4 : 82 - 94
  • [40] The trade-off
    Rothschild, M
    COMMUNICATIONS NEWS, 2004, 41 (09): : 19 - 21