Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
来源
2024 IEEE 49TH CONFERENCE ON LOCAL COMPUTER NETWORKS, LCN 2024 | 2024年
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] On the Trade-Off Between Privacy and Utility in Mobile Services: A Qualitative Study
    Liu, Yang
    Simpson, Andrew
    COMPUTER SECURITY, ESORICS 2019, 2020, 11980 : 261 - 278
  • [2] On the Trade-off between Privacy and Information Quality in Location Based Services
    Apollonio, Francesco
    Bedogni, Luca
    Gori, Giacomo
    Melis, Andrea
    Prandini, Marco
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 994 - 997
  • [3] Frequency Shaping for Improving a Trade-Off Between Control and Privacy Performance: Beyond Differential Privacy
    Watanabe, Rintaro
    Kawano, Yu
    Wada, Nobutaka
    Cao, Ming
    INTERNATIONAL JOURNAL OF ROBUST AND NONLINEAR CONTROL, 2024,
  • [4] Privacy/performance trade-off in private search on bio-medical data
    Perl, H.
    Mohammed, Y.
    Brenner, M.
    Smith, M.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2014, 36 : 441 - 452
  • [5] A utility-driven surveillance approach to trade-off security and privacy
    Lloyd, C.
    Mannucci, T.
    Bouma, H.
    Schutte, K.
    Huizing, A.
    COUNTERTERRORISM, CRIME FIGHTING, FORENSICS, AND SURVEILLANCE TECHNOLOGIES III, 2019, 11166
  • [6] Privacy Versus Collective Security Drivers and Barriers Behind a Trade-off
    van Schoonhoven, Bas
    Roosendaal, Arnold
    Huijboom, Noor
    PRIVACY AND IDENTITY MANAGEMENT FOR EMERGING SERVICES AND TECHNOLOGIES, 2014, 421 : 93 - 101
  • [7] Privacy and Security Perceptions of European Citizens: A Test of the Trade-Off Model
    Friedewald, Michael
    van Lieshout, Marc
    Rung, Sven
    Ooms, Merel
    Ypma, Jelmer
    PRIVACY AND IDENTITY MANAGEMENT FOR THE FUTURE INTERNET IN THE AGE OF GLOBALISATION, 2015, 457 : 39 - 53
  • [8] Optimal Accuracy-Privacy Trade-Off of Inference as Service
    Jin, Yulu
    Lai, Lifeng
    IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2022, 70 : 4031 - 4046
  • [9] Athenian University Students on Facebook and Privacy: A Fair "Trade-Off"?
    Papathanassopoulos, Stylianos
    Athanasiadis, Elias
    Xenofontos, Maria
    SOCIAL MEDIA + SOCIETY, 2016, 2 (03):
  • [10] On a security vs privacy trade-off in interconnected dynamical systems
    Katewa, Vaibhav
    Anguluri, Rajasekhar
    Pasqualetti, Fabio
    AUTOMATICA, 2021, 125