论文标题

HTTPA/2:Web服务的值得信赖的端到端协议

HTTPA/2: a Trusted End-to-End Protocol for Web Services

论文作者

King, Gordon, Wang, Hans

论文摘要

随着云计算和Internet的出现,商业化网站能够提供更多的Web服务,例如服务(SaaS)或功能作为服务(FAAS),以提供出色的用户体验。毫无疑问,网络服务一直在流行,将继续发展以服务于现代人类生活。正如预期的那样,不可避免的是保留隐私,增强安全性和建立信任的需求。但是,仅HTTPS不能为建立信任提供Web服务的远程证明,而Web服务仍然缺乏信任。同时,云计算正在积极采用TEE的使用,并需要一项基于Web的协议以易于使用。在这里,我们通过增强现有的HTTP来启用第7层(L7)的端点之间的端到端可信通信,将HTTPA/2作为HTTP访问(HTTPA)的升级版本(HTTPA)提出。 HTTPA/2允许在不依赖TLS的情况下进行L7消息保护。 In practice, HTTPA/2 is designed to be compatible with the in-network processing of the modern cloud infrastructure, including L7 gateway, L7 load balancer, caching, etc. We envision that \acs{httpa}/2 will further enable trustworthy web services and trustworthy AI applications in the future, accelerating the transformation of the web-based digital world to be more trustworthy.

With the advent of cloud computing and the Internet, the commercialized website becomes capable of providing more web services, such as software as a service (SaaS) or function as a service (FaaS), for great user experiences. Undoubtedly, web services have been thriving in popularity that will continue growing to serve modern human life. As expected, there came the ineluctable need for preserving privacy, enhancing security, and building trust. However, HTTPS alone cannot provide a remote attestation for building trust with web services, which remains lacking in trust. At the same time, cloud computing is actively adopting the use of TEEs and will demand a web-based protocol for remote attestation with ease of use. Here, we propose HTTPA/2 as an upgraded version of HTTP-Attestable (HTTPA) by augmenting existing HTTP to enable end-to-end trusted communication between endpoints at layer 7 (L7). HTTPA/2 allows for L7 message protection without relying on TLS. In practice, HTTPA/2 is designed to be compatible with the in-network processing of the modern cloud infrastructure, including L7 gateway, L7 load balancer, caching, etc. We envision that \acs{httpa}/2 will further enable trustworthy web services and trustworthy AI applications in the future, accelerating the transformation of the web-based digital world to be more trustworthy.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源