Selective Security for TLS

  • Authors:
  • Marius Portmann;Aruna Seneviratne

  • Affiliations:
  • -;-

  • Venue:
  • ICON '01 Proceedings of the 9th IEEE International Conference on Networks
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Today's computing environments are becomingincreasingly heterogeneous, mostly due to the growth ofmobile computing. In this environment, application layerproxies that can adapt and tailor the content to theclient's needs and capabilities as well as to the availablenetwork resources are highly beneficial. The problem isthat content adaptation proxies are generallyincompatible with the notion of end-to-end security. Theonly generic solution to this problem is the concept ofSelective Security. The idea is to apply security selectivelyonly to the sensitive elements of a data stream and exposethe rest to any intermediary system for potential contentadaptation. None of the current security protocols in useprovide an API for fine-grained control for applyingsecurity mechanisms to a data stream. In this paper, wepropose a simple extension to the Transport LayerSecurity Protocol (TLS), which provides the applicationwith an interface for selectively protecting elementswithin a data stream. We also discuss a genericapplication scenario that shows how the proposedextended features can be used in conjunction with contentadaptation proxies.