We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: HTTPA/2: a Trusted End-to-End Protocol for Web Services

Abstract: We received positive feedback and inquiries on the previous version of HTTPA [11](HTTPA/1). As a result, we present a major revision of the HTTPA protocol (HTTPA/2) to protect sensitive data in HTTPA transactions from cyber attacks. Comparatively, the previous work [11] is mainly focused on how to include remote attestation (RA) and secret provisioning to the HTTP protocol with Transport Layer Security (TLS) protection across the Internet, which is great, but it comes at a price. In contrast, HTTPA/2 is not necessary to rely on the TLS protocol, such as TLS 1.3 [20], for secure communication over the Internet. The design of HTTPA/2 follows the SIGMA model [13] to establish a trusted (attested) and secure communication context between endpoints at layer 7 (L7) of the OSI model. Different from connection-based protocols, HTTPA/2 is transaction-based in which the TEE is considered to be a new type of requested resource over the Internet. In addition to protecting sensitive data transmitted to TEE-based services (TServices), HTTPA/2 can potentially be used to optimize the end-to-end performance of Internet or cloud backend traffic, thus saving energy and reducing the operational costs of Cloud Service Providers (CSPs). We envision that HTTPA/2 will further enable confidential web services and trustworthy AI applications in the future.
Comments: 24 pages, 6 figures
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2205.01052 [cs.CR]
  (or arXiv:2205.01052v4 [cs.CR] for this version)

Submission history

From: Hans Wang [view email]
[v1] Mon, 2 May 2022 17:37:54 GMT (289kb,D)
[v2] Fri, 20 May 2022 18:51:44 GMT (291kb,D)
[v3] Wed, 15 Jun 2022 15:44:21 GMT (291kb,D)
[v4] Fri, 17 Jun 2022 21:37:12 GMT (316kb,D)
[v5] Sun, 25 Sep 2022 20:27:35 GMT (304kb,D)

Link back to: arXiv, form interface, contact.