Intel is developing the HTTPA protocol, which complements HTTPS.

Engineers from Intel have proposed a new protocol, HTTPA (HTTPS Attestable), which expands HTTPS with additional guarantees for the security of the computations performed. HTTPA ensures the integrity of user request processing on the server and verifies that the web service is trustworthy and that the code running in the TEE (Trusted Execution Environment) on the server has not been altered due to hacking or administrator tampering.

HTTPS protects the transmitted data during network transmission but cannot eliminate the risk of data integrity breaches due to attacks on the server. Isolated enclaves created using technologies like Intel SGX (Software Guard Extension), ARM TrustZone, and AMD PSP (Platform Security Processor) allow for the protection of critical computations and reduce the risk of leaks or alterations of sensitive information at the endpoint.

HTTPA, to guarantee the authenticity of transmitted information, utilizes the attestation features provided by Intel SGX, confirming the authenticity of the enclave where computations are performed. Essentially, HTTPA extends HTTPS with the capability of remote attestation of the enclave, allowing verification that it is executed in a genuine Intel SGX environment, thus ensuring that the web service can be trusted. The protocol is initially being developed as a universal solution and can also be implemented for other TEE systems besides Intel SGX.

Intel is developing the HTTPA protocol, which complements HTTPS.

In addition to the standard HTTPS process of establishing a secure connection, HTTPA additionally requires the negotiation of a trustworthy session key. The protocol introduces a new HTTP method, 'ATTEST,' which allows processing of three types of requests and responses:

  • 'preflight' to check if the remote side supports enclave attestation;
  • 'attest' to negotiate attestation parameters (selecting a cryptographic algorithm, exchanging session-specific random sequences, generating a session identifier, and transmitting the enclave's public key to the client);
  • 'trusted session' — generating a session key for trustworthy information exchange. The session key is formed based on a previously agreed pre-session secret generated by the client using the received data from server the public key of TEE, and randomly generated sequences by each party.

Intel is developing the HTTPA protocol, which complements HTTPS.

HTTPA implies that the client is trusted, while the server is not, meaning the client can utilize this protocol to verify computations in a TEE environment. However, HTTPA does not guarantee that the computations performed during this process web server were compromised, which necessitates a separate approach to developing web services. Thus, HTTPA is primarily aimed at use with specialized services that have enhanced integrity requirements, such as financial and medical systems.

For situations where computations in TEE need to be verified for both the server and the client, a mutual protocol variant mHTTPA (Mutual HTTPA) is proposed, which performs two-way verification. This variant is more complex due to the necessity for bidirectional session key generation for both the server and client.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster