Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
来源
2024 IEEE 49TH CONFERENCE ON LOCAL COMPUTER NETWORKS, LCN 2024 | 2024年
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [32] Towards Optimization of Privacy-Utility Trade-Off Using Similarity and Diversity Based Clustering
    Majeed, Abdul
    Khan, Safiullah
    Hwang, Seong Oun
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2024, 12 (01) : 368 - 385
  • [33] Where's Waldo? A framework for quantifying the privacy-utility trade-off in marketing applications
    Ponte, Gilian R.
    Wieringa, Jaap E.
    Boot, Tom
    Verhoef, Peter C.
    INTERNATIONAL JOURNAL OF RESEARCH IN MARKETING, 2024, 41 (03) : 529 - 546
  • [34] Efficiency-Fairness Trade-off in Privacy-Preserving Autonomous Demand Side Management
    Baharlouei, Zahra
    Hashemi, Massoud
    IEEE TRANSACTIONS ON SMART GRID, 2014, 5 (02) : 799 - 808
  • [35] AI in Healthcare Data Privacy-Preserving: Enhanced Trade-Off Between Security and Utility
    Peng, Lian
    Qiu, Meikang
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, KSEM 2024, 2024, 14886 : 349 - 360
  • [36] OptiSGD-DPWGAN: Integrating Metaheuristic Algorithms and Differential Privacy to Improve Privacy-Utility Trade-Off in Generative Models
    Ahmed Mohamed, Alshaymaa
    Saleh, Yasmine N. M.
    Abdel-Hamid, Ayman A.
    IEEE ACCESS, 2024, 12 : 176070 - 176086
  • [37] Balance or trade-off? Online security technologies and fundamental rights
    Hildebrandt M.
    Philosophy & Technology, 2013, 26 (4) : 357 - 379
  • [38] LONG-TERM CONVERSATION ANALYSIS: PRIVACY-UTILITY TRADE-OFF UNDER NOISE AND REVERBERATION
    Pohlhausen, Jule
    Nespoli, Francesco
    Bitzer, Joerg
    2024 18TH INTERNATIONAL WORKSHOP ON ACOUSTIC SIGNAL ENHANCEMENT, IWAENC 2024, 2024, : 404 - 408
  • [39] Evaluating the Impact of Face Anonymization Methods on Computer Vision Tasks: A Trade-Off Between Privacy and Utility
    Stenger, Roland
    Busse, Steffen
    Sander, Jonas
    Eisenbarth, Thomas
    Fudickar, Sebastian
    IEEE ACCESS, 2025, 13 : 11070 - 11079
  • [40] Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking
    Jueckstock, Jordan
    Snyder, Peter
    Sarker, Shaown
    Kapravelos, Alexandros
    Livshits, Benjamin
    PROCEEDINGS OF THE ACM WEB CONFERENCE 2022 (WWW'22), 2022, : 710 - 720