Enhancing the Privacy of Network Services through Trusted Computing

The addressing and discovering service is a vital infrastructure of the Internet. New applications and scenarios in next-generation networks rely on the secure and stable operation of domain name services, which puts forward new security challenges for the original domain name mechanism. While previ...

Full description

Bibliographic Details
Main Authors: Denghui Zhang, Lijing Ren, Zhaoquan Gu
Format: Article
Language:English
Published: MDPI AG 2022-09-01
Series:Applied Sciences
Subjects:
Online Access:https://www.mdpi.com/2076-3417/12/18/9191
_version_ 1797491516241870848
author Denghui Zhang
Lijing Ren
Zhaoquan Gu
author_facet Denghui Zhang
Lijing Ren
Zhaoquan Gu
author_sort Denghui Zhang
collection DOAJ
description The addressing and discovering service is a vital infrastructure of the Internet. New applications and scenarios in next-generation networks rely on the secure and stable operation of domain name services, which puts forward new security challenges for the original domain name mechanism. While previous security enhancements of network services struggled to strike a balance between security, performance, and compatibility, hindering further use of core network services, the TEE (Trusted Computing Environment) technology can provide trusted and confidential services in untrusted network environments by verifiable hardware signatures. In this paper, we present a novel trustworthy service architecture with the preservation of security and privacy for addressing messages. The scheme provides a secure enclave to generate authenticatable responses between clients and targets, thus ensuring the privacy of services. We further build a new TEE compilation model to ensure that the built resolver application can provide trusted and secure services within TEE while keeping the availability without the TEE hardware. Experimental results show that our approach can enhance the privacy and security of addressing services such as DNS (Domain Name System) without sacrificing the quality of service and breaking the infrastructures of existing services.
first_indexed 2024-03-10T00:49:33Z
format Article
id doaj.art-fd54a53d7d9a4939a6709bd8930b8332
institution Directory Open Access Journal
issn 2076-3417
language English
last_indexed 2024-03-10T00:49:33Z
publishDate 2022-09-01
publisher MDPI AG
record_format Article
series Applied Sciences
spelling doaj.art-fd54a53d7d9a4939a6709bd8930b83322023-11-23T14:54:28ZengMDPI AGApplied Sciences2076-34172022-09-011218919110.3390/app12189191Enhancing the Privacy of Network Services through Trusted ComputingDenghui Zhang0Lijing Ren1Zhaoquan Gu2Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, ChinaDepartment of New Networks, Peng Cheng Laboratory, Shenzhen 518055, ChinaDepartment of New Networks, Peng Cheng Laboratory, Shenzhen 518055, ChinaThe addressing and discovering service is a vital infrastructure of the Internet. New applications and scenarios in next-generation networks rely on the secure and stable operation of domain name services, which puts forward new security challenges for the original domain name mechanism. While previous security enhancements of network services struggled to strike a balance between security, performance, and compatibility, hindering further use of core network services, the TEE (Trusted Computing Environment) technology can provide trusted and confidential services in untrusted network environments by verifiable hardware signatures. In this paper, we present a novel trustworthy service architecture with the preservation of security and privacy for addressing messages. The scheme provides a secure enclave to generate authenticatable responses between clients and targets, thus ensuring the privacy of services. We further build a new TEE compilation model to ensure that the built resolver application can provide trusted and secure services within TEE while keeping the availability without the TEE hardware. Experimental results show that our approach can enhance the privacy and security of addressing services such as DNS (Domain Name System) without sacrificing the quality of service and breaking the infrastructures of existing services.https://www.mdpi.com/2076-3417/12/18/9191privacyTEEcompatibilityDNSdigital signature
spellingShingle Denghui Zhang
Lijing Ren
Zhaoquan Gu
Enhancing the Privacy of Network Services through Trusted Computing
Applied Sciences
privacy
TEE
compatibility
DNS
digital signature
title Enhancing the Privacy of Network Services through Trusted Computing
title_full Enhancing the Privacy of Network Services through Trusted Computing
title_fullStr Enhancing the Privacy of Network Services through Trusted Computing
title_full_unstemmed Enhancing the Privacy of Network Services through Trusted Computing
title_short Enhancing the Privacy of Network Services through Trusted Computing
title_sort enhancing the privacy of network services through trusted computing
topic privacy
TEE
compatibility
DNS
digital signature
url https://www.mdpi.com/2076-3417/12/18/9191
work_keys_str_mv AT denghuizhang enhancingtheprivacyofnetworkservicesthroughtrustedcomputing
AT lijingren enhancingtheprivacyofnetworkservicesthroughtrustedcomputing
AT zhaoquangu enhancingtheprivacyofnetworkservicesthroughtrustedcomputing