Privacy Performance Trade-off in Web Services

被引:0
|
作者
Selvam, Hari Hara Sudhan [1 ]
Hanawal, Manjesh K. [2 ]
Kulkarni, Sameer G. [1 ]
机构
[1] Indian Inst Technol Gandhinagar, Palaj, India
[2] Indian Inst Technol, MLiONS Lab, IEOR, Mumbai, Maharashtra, India
来源
2024 IEEE 49TH CONFERENCE ON LOCAL COMPUTER NETWORKS, LCN 2024 | 2024年
关键词
Security; Privacy; HTTP/3; QUIC; TLS; ECH;
D O I
10.1109/LCN60385.2024.10639729
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and Privacy have become fundamental requirements of modern Internet services. Over the years, both Hypertext Transfer Protocol (HTTP) and Transport Layer Security (TLS) have evolved significantly to meet the performance, privacy and security demands of the web services. However, the usage of Service Name Identity (SNI) in TLS carry service-related information in plain-text, which potentially reveal the user's activity and compromise the privacy. In this work, we analyse the performance, security and privacy trade-offs offered by the recent developments in HTTP and TLS protocols namely HTTP/3 and TLS1.3. Our results indicate the end-to-end performance of HTTP/3 and HTTP/2 to be very similar, but HTTP/3 offers better security and privacy. Further, we quantify the overheads associated with HTTP/3 and find that the computational complexity with HTTP/3 for SNI obfuscation and extraction from 'ClientHello' packets is nearly 10 times more than HTTP/2. Further, we find that the user-space implementations of QUIC in HTTP/3 are more compute-intensive and prone to be unstable. We conclude that a leaner alternative would be the adoption of "Encrypted ClientHello" (ECH), that proposes to overcome this privacy issue by extending TLS 1.3, where all the information that could potentially reveal the service type is encrypted using a public key. The widespread adoption of TLS 1.3 with ECH is imperative to enable complete privacy in web services.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] Privacy-Accuracy Trade-Off in Differentially-Private Distributed Classification: A Game Theoretical Approach
    Xu, Lei
    Jiang, Chunxiao
    Qian, Yi
    Li, Jianhua
    Zhao, Youjian
    Ren, Yong
    IEEE TRANSACTIONS ON BIG DATA, 2021, 7 (04) : 770 - 783
  • [42] Privacy-utility Trade-off for Smart Meter Data Considering Tracing Household Power Usage
    Zheng, Peixiang
    Chen, Bin
    Lu, Xin
    Zhou, Xinyan
    PROCEEDINGS OF 2017 IEEE 2ND INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2017, : 939 - 943
  • [43] A New Performance Trade-Off Measurement Technique for Evaluating Image Watermarking Schemes
    Emami, Mir Shahriar
    Bin Sulong, Ghazali
    Zain, Jasni Mohamad
    SOFTWARE ENGINEERING AND COMPUTER SYSTEMS, PT 1, 2011, 179 : 567 - +
  • [44] PRIVACY-COST TRADE-OFF IN A SMART METER SYSTEM WITH A RENEWABLE ENERGY SOURCE AND A RECHARGEABLE BATTERY
    Erdemir, Ecenaz
    Dragotti, Pier Luigi
    Gunduz, Deniz
    2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 2687 - 2691
  • [45] The efficiency/security trade-off in criminal networks
    Morselli, Carlo
    Giguere, Cynthia
    Petit, Katia
    SOCIAL NETWORKS, 2007, 29 (01) : 143 - 153
  • [46] Achieving the Exactly Optimal Privacy-Utility Trade-Off With Low Communication Cost via Shared Randomness
    Nam, Seung-Hyun
    Park, Hyun-Young
    Lee, Si-Hyeon
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2024, 70 (10) : 7447 - 7462
  • [47] Trade-off of security and performance of lightweight block ciphers in Industrial Wireless Sensor Networks
    Pei, Chao
    Xiao, Yang
    Liang, Wei
    Han, Xiaojia
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2018,
  • [48] Double Time-Memory Trade-Off in OSK RFID Protocol
    Tomasevic, Violeta
    Tomasevic, Milo
    WIRELESS PERSONAL COMMUNICATIONS, 2019, 108 (01) : 551 - 568
  • [49] Solving Truthfulness-Privacy Trade-Off in Mixed Data Outsourcing by Using Data Balancing and Attribute Correlation-Aware Differential Privacy
    Majeed, Abdul
    Hwang, Seong Oun
    IEEE ACCESS, 2025, 13 : 23171 - 23194
  • [50] The Market for Privacy: Understanding How Consumers Trade Off Privacy Practices
    Eggers, Felix
    Beke, Frank T.
    Verhoef, Peter C.
    Wieringa, Jaap E.
    JOURNAL OF INTERACTIVE MARKETING, 2023, 58 (04) : 341 - 360