With the advent of cloud computing and the Internet, the commercialized website becomes capable of providing more web services, such as software as a service (SaaS) or function as a service (FaaS), for great user experiences. Undoubtedly, web services have been thriving in popularity that will continue growing to serve modern human life. As expected, there came the ineluctable need for preserving privacy, enhancing security, and building trust. However, HTTPS alone cannot provide a remote attestation for building trust with web services, which remains lacking in trust. At the same time, cloud computing is actively adopting the use of TEEs and will demand a web-based protocol for remote attestation with ease of use. Here, we propose HTTPA/2 as an upgraded version of HTTP-Attestable (HTTPA) by augmenting existing HTTP to enable end-to-end trusted communication between endpoints at layer 7 (L7). HTTPA/2 allows for L7 message protection without relying on TLS. In practice, HTTPA/2 is designed to be compatible with the in-network processing of the modern cloud infrastructure, including L7 gateway, L7 load balancer, caching, etc. We envision that \acs{httpa}/2 will further enable trustworthy web services and trustworthy AI applications in the future, accelerating the transformation of the web-based digital world to be more trustworthy.
翻译:随着云计算和互联网的到来,商业化网站能够提供更多网络服务,如软件服务(SAAS)或服务(FaAS)等软件(FaAS)等软件,以获取巨大的用户经验。毫无疑问,网络服务在为现代人类生活继续服务而不断增长的广受欢迎的网络服务中非常活跃。正如所预期的那样,保护隐私、加强安全和建立信任的需要无可争议。然而,光是HTTPP无法提供远程证明,用仍然缺乏信任的网络服务建立信任。与此同时,云计算正在积极采用TEE的使用,并将要求以网络为基础的协议进行远程认证。我们在这里建议HTTPA/2作为HTTPP-Attestable(HTTPPA)的升级版,通过增加现有的HTTP,使7层端之间的端端端能够端对端信任通信(L.7 HTTPPA/2允许L7信息保护L7信息,而无需依赖TLS。在实践中,HTPA/2将设计与现代云基础设施的网络内部处理兼容,包括L7+LS-Silvil+WS-S-SilfilableWefilableWard liflock) 将进一步推进全球服务。