Skip to main navigation Skip to search Skip to main content

Multi-context TLS (mcTLS): Enabling secure in-network functionality in TLS

  • David Naylor
  • , Kyle Schomp
  • , Matteo Varvello
  • , Ilias Leontiadis
  • , Jeremy Blackburn
  • , Diego Lopez
  • , Konstantina Papagiannaki
  • , Pablo Rodriguez Rodriguez
  • , Peter Steenkiste

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

80 Scopus citations

Abstract

A significant fraction of Internet trafic is now encrypted and HTTPS will likely be the default in HTTP/2. How- ever, Transport Layer Security (TLS), the standard protocol for encryption in the Internet, assumes that all functionality resides at the endpoints, making it impossible to use in-network services that optimize network resource usage, improve user experience, and protect clients and servers from security threats. Re-introducing in-network functionality into TLS sessions today is done through hacks, often weakening overall security. In this paper we introduce multi-context TLS (mcTLS), which extends TLS to support middleboxes. mcTLS breaks the current "all-or-nothing"security model by al- lowing endpoints and content providers to explicitly in- Troduce middleboxes in secure end-to-end sessions while controlling which parts of the data they can read or write. We evaluate a prototype mcTLS implementation in both controlled and "live" experiments, showing that its benefits come at the cost of minimal overhead. More importantly, we show that mcTLS can be incrementally deployed and requires only small changes to client, server, and middlebox software.

Original languageEnglish
Title of host publicationSIGCOMM 2015 - Proceedings of the 2015 ACM Conference on Special Interest Group on Data Communication
PublisherAssociation for Computing Machinery
Pages199-212
Number of pages14
ISBN (Electronic)9781450335423
DOIs
StatePublished - Aug 17 2015
EventACM Conference on Special Interest Group on Data Communication, SIGCOMM 2015 - London, United Kingdom
Duration: Aug 17 2015Aug 21 2015

Publication series

NameSIGCOMM 2015 - Proceedings of the 2015 ACM Conference on Special Interest Group on Data Communication

Conference

ConferenceACM Conference on Special Interest Group on Data Communication, SIGCOMM 2015
Country/TerritoryUnited Kingdom
CityLondon
Period08/17/1508/21/15

Keywords

  • HTTPS
  • SSL
  • TLS

Fingerprint

Dive into the research topics of 'Multi-context TLS (mcTLS): Enabling secure in-network functionality in TLS'. Together they form a unique fingerprint.

Cite this