Content area

Abstract

Web applications have become increasingly popular, as they are convenient for many computing tasks and are accessible from any device with a web browser. Although existing web security mechanisms such as TLS, CSP and SRI protect against a variety of threats, web applications are still vulnerable to insider attacks in which a malicious hosting server delivers an altered version of the application. This threat is particularly critical for web applications that employ trusted execution environments (TEE), as a lack of verifiability of the application’s code undermines the confidentiality guarantees provided by TEE. To ensure that sensitive data is sent to an authentic TEE, such web applications rely on browser extensions to perform critical operations such as attestation and communication, as they are isolated from the web application and thereby shielded from tampering. However, this is not a scalable approach as it is infeasible for users to install application-specific browser extensions for every TEE-enabled web application. In this work, we present a scalable method for trustworthy delivery and user-verifiable attestation for web applications that use TEEs to provide privacy guarantees for user input. To evaluate a proof-of-concept of our method, we implemented a web application that uses a TEE-based password authentication service called SafeKeeper. We then extended Meta’s Code Verify browser extension to validate the integrity of our web application’s code, which includes TEE-specific operations, thereby eliminating the need for a separate application-specific browser extension. This method ensures both the integrity of the delivered application and the confidentiality of user input, offering a unified and scalable solution for the trustworthy delivery of web applications that use TEEs.

Details

1010268
Business indexing term
Title
A Verifiable Delivery Framework for Web Applications That Use Trusted Execution Environments
Number of pages
57
Publication year
2025
Degree date
2025
School code
0283
Source
MAI 86/10(E), Masters Abstracts International
ISBN
9798311908900
University/institution
Queen's University (Canada)
University location
Canada -- Ontario, CA
Degree
M.S.
Source type
Dissertation or Thesis
Language
English
Document type
Dissertation/Thesis
Dissertation/thesis number
31923477
ProQuest document ID
3214130941
Document URL
https://www.proquest.com/dissertations-theses/verifiable-delivery-framework-web-applications/docview/3214130941/se-2?accountid=208611
Copyright
Database copyright ProQuest LLC; ProQuest does not claim copyright in the individual underlying works.
Database
2 databases
  • ProQuest One Academic
  • ProQuest One Academic