2019 ◽  
Vol 45 (8) ◽  
pp. 544-556 ◽  
Author(s):  
S. Iturriaga ◽  
S. Nesmachnow ◽  
G. Goñi ◽  
B. Dorronsoro ◽  
A. Tchernykh

Author(s):  
Subrata Acharya

There is a need to be able to verify plaintext HTTP content transfers. Common sense dictates authentication and sensitive content should always be protected by SSL/HTTPS, but there is still great exploitation potential in the modification of static content in transit. Pre-computed signatures and client-side verification offers integrity protection of HTTP content in applications where SSL is not feasible. In this chapter, the authors demonstrate a mechanism by which a Web browser or other HTTP client can verify that content transmitted over an untrusted channel has not been modified. Verifiable HTTP is not intended to replace SSL. Rather, it is intended to be used in applications where SSL is not feasible, specifically, when serving high-volume static content and/or content from non-secure sources such as Content Distribution Networks. Finally, the authors find content verification is effective with server-side overhead similar to SSL. With future optimization such as native browser support, content verification could achieve comparable client-side efficiency.


IEEE Access ◽  
2020 ◽  
Vol 8 ◽  
pp. 195240-195252
Author(s):  
Anas Ahmad Abudaqa ◽  
Ashraf Mahmoud ◽  
Marwan Abu-Amara ◽  
Tarek R. Sheltami

2012 ◽  
Vol 8 (3) ◽  
pp. 1-19 ◽  
Author(s):  
Mohammadhossein Bateni ◽  
Mohammadtaghi Hajiaghayi

Sign in / Sign up

Export Citation Format

Share Document