Efficient encrypted network traffic management with zero-knowledge proof
Abstract
Abstract In the digital age, the reliance on network communication for information exchange has surged, making encrypted network traffic a linchpin of secure digital interactions. However, while encryption safeguards data, it creates hurdles for network management and security surveillance. Conventional deep packet inspection (DPI) falters when faced with encrypted traffic, and existing studies in this area have drawbacks like reliance on trusted third parties and limited detection capabilities. To address these issues, we present a novel zero knowledge proof based encrypted traffic management( $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> ) scheme. By integrating a third-party verifier operating under the honest-but-curious (HBC) model, $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> establishes a trustless verification system that effectively and efficiently curbs metadata leakage. $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> is implemented with two applications: HTTP traffic blocking and blacklist management. For HTTP traffic blocking, the BTHP circuit is developed to extract version details from TLS traffic and verify compliance, enabling precise traffic control. In blacklist management, tailored extraction algorithms for DoT and DoH encrypted DNS traffic are implemented, and Merkle tree based membership proofs are utilized to decide whether to intercept traffic. Experimental evaluations demonstrate that $$\mathbb {ZKP}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ZKP</mml:mi> </mml:math> - $$\mathbb {PET}$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>PET</mml:mi> </mml:math> can efficiently enforce diverse network policies on encrypted traffic. It not only safeguards security and privacy but also exhibits outstanding performance, offering a dependable, efficient, and privacy-centric solution for encrypted network traffic management.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.