DocumentCode :
3097025
Title :
HTTPI: An HTTP with Integrity
Author :
Choi, Taehwan ; Gouda, Mohamed G.
Author_Institution :
Dept. of Comput. Sci., Univ. of Texas at Austin, Austin, TX, USA
fYear :
2011
fDate :
July 31 2011-Aug. 4 2011
Firstpage :
1
Lastpage :
6
Abstract :
The World Wide Web famously supports two transport protocols: HTTP and HTTPS. These two protocols are at the opposite ends of three dimensions: security guarantees, cost of use, and compatibility with middle boxes (e.g. cache proxies) in the Internet. At one end, HTTP provides no security guarantees, but it is inexpensive to use, and is compatible with middle boxes in the Internet. At the other end, HTTPS provides three security guarantees, but it is expensive to use and is not compatible with middle boxes. Although the three security guarantees provided by HTTPS, namely server authentication, message integrity, and message confidentiality, are important in general, many web servers (e.g. email servers) do not need the message confidentiality guarantee. In this paper, we present a new transport protocol for the Web, named HTTPI. This protocol provides both server authentication and message integrity, but not message confidentiality. Like HTTP, HTTPI is inexpensive to use and is compatible with middle boxes, and like HTTPS, it defends against many cyber attacks (e.g. Pharming attacks) that HTTP cannot defend against. We developed a preliminary implementation of HTTPI and showed through experimentation that the throughput of HTTPI is within 1.2% from that of HTTP and is 37% better than that of HTTPS.
Keywords :
Internet; message authentication; transport protocols; HTTP protocol; HTTPS protocol; Internet; Web server; World Wide Web; email server; message confidentiality; message integrity; security guarantee; server authentication; transport protocol; Authentication; Protocols; Throughput; Web pages; Web servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks (ICCCN), 2011 Proceedings of 20th International Conference on
Conference_Location :
Maui, HI
ISSN :
1095-2055
Print_ISBN :
978-1-4577-0637-0
Type :
conf
DOI :
10.1109/ICCCN.2011.6005788
Filename :
6005788
Link To Document :
بازگشت