Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
来源
2024 IEEE 49TH CONFERENCE ON LOCAL COMPUTER NETWORKS, LCN 2024 | 2024年
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [21] ACTIVE PRIVACY-UTILITY TRADE-OFF AGAINST A HYPOTHESIS TESTING ADVERSARY
    Erdemir, Ecenaz
    Dragotti, Pier Luigi
    Gunduz, Deniz
    2021 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP 2021), 2021, : 2660 - 2664
  • [22] Exploring Machine Learning Privacy/Utility Trade-Off from a Hyperparameters Lens
    Arous, Ayoub
    Guesmi, Amira
    Hanif, Muhammad Abdullah
    Alouani, Ihsen
    Shafique, Muhammad
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [23] Determining privacy utility trade-off for Online Social Network data publishing
    Srivastava, Agrima
    Geethakumari, G.
    2015 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2015,
  • [24] Privacy concerns and benefits in SaaS adoption by individual users: A trade-off approach
    Gashami, Jean Pierre Guy
    Chang, Younghoon
    Rho, Jae Jeung
    Park, Myeong-Cheol
    INFORMATION DEVELOPMENT, 2016, 32 (04) : 837 - 852
  • [25] The privacy-explainability trade-off: unraveling the impacts of differential privacy and federated learning on attribution methods
    Saifullah, Saifullah
    Mercier, Dominique
    Lucieri, Adriano
    Dengel, Andreas
    Ahmed, Sheraz
    FRONTIERS IN ARTIFICIAL INTELLIGENCE, 2024, 7
  • [26] Evaluating the trade-off between privacy, public health safety, and digital security in a pandemic
    Akinsanmi, Titi
    Salami, Aishat
    DATA & POLICY, 2021, 3
  • [27] Workspace satisfaction: The privacy-communication trade-off in open-plan offices
    Kim, Jungsoo
    de Dear, Richard
    JOURNAL OF ENVIRONMENTAL PSYCHOLOGY, 2013, 36 : 18 - 26
  • [28] Modeling the Trade-off of Privacy Preservation and Activity Recognition on Low-Resolution Images
    Wang, Yuntao
    Cheng, Zirui
    Yi, Xin
    Kong, Yan
    Wang, Xueyang
    Xu, Xuhai
    Yan, Yukang
    Yu, Chun
    Patel, Shwetak
    Shi, Yuanchun
    PROCEEDINGS OF THE 2023 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI 2023), 2023,
  • [29] Security and Privacy: Questioning and superseding the trade-off model, Part II: Legal and decision-supporting approaches
    Szekely Ivan
    Somody Bernadette
    Szabo Mate Daniel
    INFORMACIOS TARSADALOM, 2017, 17 (01): : 7 - +
  • [30] Secure Distributed Storage: Optimal Trade-Off Between Storage Rate and Privacy Leakage
    Chou, Remi A.
    Kliewer, Jorg
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2024, 70 (05) : 3658 - 3668