Performance analysis for extended TLS with mutual attestation for platform integrity assurance

Nor Azwady Abd. Aziz, N. Udzir, R. Mahmod
{"title":"Performance analysis for extended TLS with mutual attestation for platform integrity assurance","authors":"Nor Azwady Abd. Aziz, N. Udzir, R. Mahmod","doi":"10.1109/CYBER.2014.6917428","DOIUrl":null,"url":null,"abstract":"A web service is a web-based application connected via the internet connectivity. The common web-based applications are deployed using web browsers and web servers. However, the security of Web Service is a major concern issues since it is not widely studied and integrated in the design stage of Web Service standard. They are add-on modules rather a well-defined solutions in standards. So, various web services security solutions have been defined in order to protect interaction over a network. Remote attestation is an authentication technique proposed by the Trusted Computing Group (TCG) which enables the verification of the trusted environment of platforms and assuring the information is accurate. To incorporate this method in web services framework in order to guarantee the trustworthiness and security of web-based applications, a new framework called TrustWeb is proposed. The TrustWeb framework integrates the remote attestation into SSL/TLS protocol to provide integrity information of the involved endpoint platforms. The framework enhances TLS protocol with mutual attestation mechanism which can help to address the weaknesses of transferring sensitive computations, and a practical way to solve the remote trust issue at the client-server environment. In this paper, we describe the work of designing and building a framework prototype in which attestation mechanism is integrated into the Mozilla Firefox browser and Apache web server. We also present framework solution to show improvement in the efficiency level.","PeriodicalId":183401,"journal":{"name":"The 4th Annual IEEE International Conference on Cyber Technology in Automation, Control and Intelligent","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 4th Annual IEEE International Conference on Cyber Technology in Automation, Control and Intelligent","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CYBER.2014.6917428","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

A web service is a web-based application connected via the internet connectivity. The common web-based applications are deployed using web browsers and web servers. However, the security of Web Service is a major concern issues since it is not widely studied and integrated in the design stage of Web Service standard. They are add-on modules rather a well-defined solutions in standards. So, various web services security solutions have been defined in order to protect interaction over a network. Remote attestation is an authentication technique proposed by the Trusted Computing Group (TCG) which enables the verification of the trusted environment of platforms and assuring the information is accurate. To incorporate this method in web services framework in order to guarantee the trustworthiness and security of web-based applications, a new framework called TrustWeb is proposed. The TrustWeb framework integrates the remote attestation into SSL/TLS protocol to provide integrity information of the involved endpoint platforms. The framework enhances TLS protocol with mutual attestation mechanism which can help to address the weaknesses of transferring sensitive computations, and a practical way to solve the remote trust issue at the client-server environment. In this paper, we describe the work of designing and building a framework prototype in which attestation mechanism is integrated into the Mozilla Firefox browser and Apache web server. We also present framework solution to show improvement in the efficiency level.
基于平台完整性保证的互认证扩展TLS的性能分析
web服务是通过internet连接的基于web的应用程序。常见的基于web的应用程序使用web浏览器和web服务器进行部署。然而,由于Web服务的安全性在Web服务标准的设计阶段没有得到广泛的研究和集成,因此Web服务的安全性一直是人们关注的主要问题。它们是附加模块,而不是标准中定义良好的解决方案。因此,已经定义了各种web服务安全解决方案,以保护网络上的交互。远程认证是可信计算组(TCG)提出的一种认证技术,可以对平台的可信环境进行验证,保证信息的准确性。为了将该方法整合到web服务框架中,以保证基于web的应用程序的可信性和安全性,提出了一个新的框架——TrustWeb。TrustWeb框架将远程认证集成到SSL/TLS协议中,提供相关端点平台的完整性信息。该框架通过相互认证机制对TLS协议进行了增强,有助于解决敏感计算传输的弱点,为解决客户端-服务器环境下的远程信任问题提供了一种实用的方法。在本文中,我们描述了设计和构建一个框架原型的工作,该框架原型将认证机制集成到Mozilla Firefox浏览器和Apache web服务器中。我们还提出了框架解决方案,以显示效率水平的提高。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信