On the Interplay between TLS Certificates and QUIC Performance

11/04/2022
by   Marcin Nawrocki, et al.
0

In this paper, we revisit the performance of the QUIC connection setup and relate the design choices for fast and secure connections to common Web deployments. We analyze over 1M Web domains with 272k QUIC-enabled services and find two worrying results. First, current practices of creating, providing, and fetching Web certificates undermine reduced round trip times during the connection setup since sizes of 35 amplification limit. Second, non-standard server implementations lead to larger amplification factors than QUIC permits, which increase even further in IP spoofing scenarios. We present guidance for all involved stakeholders to improve the situation.

READ FULL TEXT

page 5

page 9

page 10

research
07/02/2019

Accelerating QUIC's Connection Establishment on High-Latency Access Networks

A significant amount of connection establishments on the web require a p...
research
08/13/2019

Enhanced Performance and Privacy via Resolver-Less DNS

The domain name resolution into IP addresses can significantly delay con...
research
10/12/2022

IPv6 over Bluetooth Advertisements: An alternative approach to IP over BLE

The IPv6 over Bluetooth Low Energy (BLE) standard defines the transfer o...
research
09/04/2020

Short-Lived Forward-Secure Delegation for TLS

On today's Internet, combining the end-to-end security of TLS with Conte...
research
12/27/2022

Poseidon: Non-server WEB Forms Off-line Processing System

The proposed Poseidon system is based on email services of filled forms ...
research
02/07/2019

Enhanced Performance for the encrypted Web through TLS Resumption across Hostnames

TLS can resume previous connections via abbreviated resumption handshake...
research
04/12/2019

QUICker connection establishment with out-of-band validation tokens

QUIC is a secure transport protocol and aims to improve the performance ...

Please sign up or login with your details

Forgot password? Click here to reset