DocumentCode
153546
Title
When HTTPS Meets CDN: A Case of Authentication in Delegated Service
Author
Jinjin Liang ; Jian Jiang ; Haixin Duan ; Kang Li ; Tao Wan ; Jianping Wu
Author_Institution
Dept. of Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
fYear
2014
fDate
18-21 May 2014
Firstpage
67
Lastpage
82
Abstract
Content Delivery Network (CDN) and Hypertext Transfer Protocol Secure (HTTPS) are two popular but independent web technologies, each of which has been well studied individually and independently. This paper provides a systematic study on how these two work together. We examined 20 popular CDN providers and 10,721 of their customer web sites using HTTPS. Our study reveals various problems with the current HTTPS practice adopted by CDN providers, such as widespread use of invalid certificates, private key sharing, neglected revocation of stale certificates, and insecure back-end communication. While some of those problems are operational issues only, others are rooted in the fundamental semantic conflict between the end-to-end nature of HTTPS and the man-in-the-middle nature of CDN involving multiple parties in a delegated service. To address the delegation problem when HTTPS meets CDN, we proposed and implemented a lightweight solution based on DANE (DNS-based Authentication of Named Entities), an emerging IETF protocol complementing the current Web PKI model. Our implementation demonstrates that it is feasible for HTTPS to work with CDN securely and efficiently. This paper intends to provide a context for future discussion within security and CDN community on more preferable solutions.
Keywords
Internet; computer network security; protocols; CDN; DANE protocol; DNS-based authentication of named entities; HTTPS; Web technology; content delivery network; delegated service authentication; domain name system; hypertext transfer protocol secure; stale certificates; Authentication; Browsers; Protocols; Servers; Uniform resource locators;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy (SP), 2014 IEEE Symposium on
Conference_Location
San Jose, CA
ISSN
1081-6011
Type
conf
DOI
10.1109/SP.2014.12
Filename
6956557
Link To Document