Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] NO TRADE-OFF
    NICOLINI, M
    NATION, 1977, 224 (20) : 610 - 610
  • [42] TRADE-OFF
    MANKIW, NG
    NEW REPUBLIC, 1991, 204 (13) : 4 - 4
  • [43] Optimal Utility-Privacy Trade-Off With Total Variation Distance as a Privacy Measure
    Rassouli, Borzoo
    Gunduz, Deniz
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 594 - 603
  • [44] Privacy and security trade-off in interconnected systems with known or unknown privacy noise covariance☆
    Wang, Haojun
    Liu, Kun
    Li, Baojia
    Fridman, Emilia
    Xia, Yuanqing
    AUTOMATICA, 2025, 173
  • [45] Optimal Utility-Privacy Trade-off with Total Variation Distance as a Privacy Measure
    Rassouli, Borzoo
    Gunduz, Deniz
    2018 IEEE INFORMATION THEORY WORKSHOP (ITW), 2018, : 460 - 464
  • [46] Privacy vs Accuracy Trade-Off in Privacy Aware Face Recognition in Smart Systems
    Abbasi, Wisam
    Mori, Paolo
    Saracino, Andrea
    Frascolla, Valerio
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [47] PERFORMANCE TRADE-OFF OF COAXIAL AND FIBEROPTIC CABLES
    HODARA, H
    FIBER AND INTEGRATED OPTICS, 1985, 5 (02) : 203 - 237
  • [48] MALE MOTHS TRADE-OFF SPEED FOR PERFORMANCE
    Knight, Kathryn
    JOURNAL OF EXPERIMENTAL BIOLOGY, 2012, 215 (13): : III - III
  • [49] Uncertainty trade-off and disturbance trade-off for quantum measurements
    Srinivas, M. D.
    Mandayam, Prabha
    CURRENT SCIENCE, 2015, 109 (11): : 2044 - 2051
  • [50] How Trade-off between increasing crop yield and privacy protection
    Li, Ling
    PROCEEDINGS OF THE 2017 3RD INTERNATIONAL CONFERENCE ON ECONOMICS, SOCIAL SCIENCE, ARTS, EDUCATION AND MANAGEMENT ENGINEERING (ESSAEME 2017), 2017, 119 : 835 - 838