InviCloak: An End-to-End Approach to Privacy and Performance in Web Content Distribution
Shihan Lin, Rui Xin, Aayush Goel, Xiaowei Yang
摘要
In today's web ecosystem, a website that uses a Content Delivery Network (CDN) shares its Transport Layer Security (TLS) private key or session key with the CDN. In this paper, we present the design and implementation of InviCloak, a system that protects the confidentiality and integrity of a user and a website's private communications without changing TLS or upgrading a CDN. Invi-Cloak builds a lightweight but secure and practical key distribution mechanism using the existing DNS infrastructure to distribute a new public key associated with a website's domain name. A web client and a website can use the new key pair to build an encryption channel inside TLS. InviCloak accommodates the current web ecosystem. A website can deploy InviCloak unilaterally without a client's involvement to prevent a passive attacker inside a CDN from eavesdropping on their communications. If a client also installs InviCloak's browser extension, the client and the website can achieve end-to-end confidential and untampered communications in the presence of an active attacker inside a CDN. Our evaluation shows that InviCloak increases the median page load times (PLTs) of realistic web pages from 2.0s to 2.1s, which is smaller than the median PLTs (2.8s) of a state-of-the-art TEE-based solution. CCS CONCEPTS • Networks → Web protocol security; • Security and privacy → Key management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery NetworksShihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu 等NSDI 2025 · 被引用 2 次
- Snatch: Online Streaming Analytics at the Network EdgeYunming Xiao, Yibo Zhao, Sen Lin, Aleksandar KuzmanovicEuroSys 2024 · 被引用 1 次
它引用的顶会 Paper8
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- CDN-on-Demand: An affordable DDoS Defense via Untrusted CloudsYossi Gilad, Amir Herzberg, Michael Sudkovitch, Michael GobermanNDSS 2016 · 被引用 59 次
- Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web ApplicationsJiyeon Lee, Hayeon Kim, Junghwan Park, Insik Shin 等CCS 2018 · 被引用 40 次
- maTLS: How to Make TLS middlebox-aware?Hyunwoo Lee, Zach Smith, Junghwan Lim, Gyeongjae Choi 等NDSS 2019 · 被引用 38 次
- Master of Web Puppets: Abusing Web Browsers for Persistent and Stealthy ComputationPanagiotis Papadopoulos, Panagiotis Ilia, Michalis Polychronakis, Evangelos P. Markatos 等NDSS 2019 · 被引用 36 次
相关 Paper
- Veil: Private Browsing Semantics Without Browser-side AssistanceFrank Wang, James Mickens, Nickolai ZeldovichNDSS 2018 · 被引用 5 次
- Achieving Keyless CDNs with ConclavesStephen Herwig, Christina Garman, Dave LevinUSENIX Security 2020
- Comparing the Effects of DNS, DoT, and DoH on Web PerformanceAustin Hounsel, Kevin Borgolte, Paul Schmitt, Jordan Holland 等WWW 2020 · 被引用 59 次
- ZTLS: A DNS-based Approach to Zero Round Trip Delay in TLS handshakeSangwon Lim, Hyeonmin Lee, Hyunsoo Kim, Hyunwoo Lee 等WWW 2023 · 被引用 5 次
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker 等USENIX Security 2021 · 被引用 23 次
