Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Encrypted Client Hello, balancing privacy enhancements with security implications
University of Skövde, School of Informatics.
University of Skövde, School of Informatics.
2024 (English)Independent thesis Basic level (degree of Bachelor), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

With the addition of Transport Layer Security (TLS) 1.3 extension Encrypted Client Hello (ECH), new challenges are present for network- and system administrators in relation to web content moderation. Notable concerns have been issued for ECH circumventing content filtering efforts as ECH introduces new functionality to cover up previous metadata leaks. Core Information Technology (IT) security implementations used these metadata leaks to perform necessary evaluations of client network traffic. Encryption of metadata such as Server Name Indication (SNI), Application-Layer Protocol Negotiation (ALPN) and more, requires a new outlook for how to safely adapt to current day privacy improvements. Authors present current day issues observed with ECH, a general outlook on protocol improvement areas and how to adapt to new challenges ahead in organisational environments. IT-security solutions are presented for their intended ability of securing IT-infrastructure and evaluated if they can continue operational functionality in relation to ECH. Authors present a simple and open source solution for content filtering, and examining the solution in various environments. The solution is deemed to be primarily applicable for organisations as supporting implementations are required for the solution to be deemed as effective. The report addresses concerns issued by researchers on how to safely incorporate DNS over HTTPS (DoH) and ECH-enabled websites to foster the adoption process. 

Place, publisher, year, edition, pages
2024. , p. 68
Keywords [en]
Encrypted Client Hello, ECH, encrypted server name indication, ESNI, TLS 1.3, privacy, privacy enhancements, security implementations, content blocking, TLS extensions, RPZ, response policy zone, DNS filtering
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-24188OAI: oai:DiVA.org:his-24188DiVA, id: diva2:1882070
Subject / course
Informationsteknologi
Educational program
Network and Systems Administration
Supervisors
Examiners
Available from: 2024-07-04 Created: 2024-07-04 Last updated: 2024-07-04Bibliographically approved

Open Access in DiVA

fulltext(979 kB)208 downloads
File information
File name FULLTEXT01.pdfFile size 979 kBChecksum SHA-512
ed481e43c433217da5d43d466fa0da70d79b405b2cc755d378e81192304b8b01a238a7fb22c72c1a75fe3ea78cd5302e8c36e16f0ed96601512b73109cc89156
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 209 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1153 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf