Enhanced Performance for the encrypted Web through TLS Resumption across Hostnames

02/07/2019
by   Erik Sy, et al.
0

TLS can resume previous connections via abbreviated resumption handshakes that significantly decrease the delay and save expensive cryptographic operations. For that, cryptographic TLS state from previous connections is reused. TLS version 1.3 recommends to avoid resumption handshakes, and thus the reuse of cryptographic state, when connecting to a different hostname. In this work, we reassess this recommendation, as we find that sharing cryptographic TLS state across hostnames is a common practice on the web. We propose a TLS extension that allows the server to inform the client about TLS state sharing with other hostnames. This information enables the client to efficiently resume TLS sessions across hostnames. Our evaluation indicates that our TLS extension provides huge performance gains for the web. For example, about 58.7 20.24 full TLS handshakes that are required to retrieve an average website on the web can be converted to resumed connection establishments. This yields to a reduction of 44 Furthermore, our TLS extension accelerates the connection establishment with an average website by up to 30.6 reduces the (energy) costs and the delay overhead in the encrypted web.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/11/2021

Practical Encrypted Computing for IoT Clients

Privacy and energy are primary concerns for sensor devices that offload ...
research
03/22/2019

Surfing the Web quicker than QUIC via a shared Address Validation

QUIC is a performance-optimized secure transport protocol and a building...
research
07/02/2019

Accelerating QUIC's Connection Establishment on High-Latency Access Networks

A significant amount of connection establishments on the web require a p...
research
04/12/2019

QUICker connection establishment with out-of-band validation tokens

QUIC is a secure transport protocol and aims to improve the performance ...
research
09/04/2022

InviCloak: An End-to-End Approach to Privacy and Performance in Web Content Distribution

In today's web ecosystem, a website that uses a Content Delivery Network...
research
09/20/2023

Data Exfiltration by Hotjar Revisited

Session replay scripts allow website owners to record the interaction of...
research
11/04/2022

On the Interplay between TLS Certificates and QUIC Performance

In this paper, we revisit the performance of the QUIC connection setup a...

Please sign up or login with your details

Forgot password? Click here to reset