Enhancing Web-based E-Transaction Platform's Security Using A Locally Trusted SSL Proxy

Li Wen · Microelectronics & Computer · 2004

The lack of full control of standard browsers' embedded SSL module and the security limitations of security-related products posed by oversea exporting laws, make the pure browser-based SSL connection unsuitable for some Web-based E-Transaction scenarios where more security protection is required. This paper designed and implemented a Locally-Trusted SSL proxy (LT-SSL Proxy) aimed to address such security issues. The LT-SSL Proxy splits the previous End-to-End SSL connection into two independent parts: the local SSL connection from the browser to the LT-SSL Proxy and the remote SSL connection from the LT-SSL Proxy to the remote secure Web server. Since the remote SSL connection is free of the security limitations posed by the standard browsers and the end-user can configure more secure encryption algorithms on demand, the LT-SSL Proxy can enhance existing Web-based E-Transaction platform's security greatly.

Read the paper · More papers on PaperTik