A Survey and Analysis of TLS Interception Mechanisms and Motivations: Exploring how end-to-end TLS is made "end-to-me" for web traffic

The work

TitleA Survey and Analysis of TLS Interception Mechanisms and Motivations: Exploring how end-to-end TLS is made "end-to-me" for web traffic
AuthorsXavier de Carné de Carnavalet; Paul C. van Oorschot
Typearticle
Year2023
Citekeycarnavalet2023survey

Where it appeared

Published inACM Computing Surveys
Volume55
Issue13s
Pages1--40

Identifiers

DOI10.1145/3580522
arXiv2010.16388

Access

Free full texthttps://dl.acm.org/doi/pdf/10.1145/3580522

Abstract

TLS is an end-to-end protocol designed to provide confidentiality and integrity guarantees that improve end-user security and privacy. While TLS helps defend against pervasive surveillance of intercepted unencrypted traffic, it also hinders several common beneficial operations typically performed by middleboxes on the network traffic. Consequently, various methods have been proposed that "bypass" the confidentiality goals of TLS by playing with keys and certificates essentially in a man-in-the-middle solution, as well as new proposals that extend the protocol to accommodate third parties, delegation schemes to trusted middleboxes, and fine-grained control and verification mechanisms. We first review the use cases expecting plain HTTP traffic and discuss the extent to which TLS hinders these operations. We retain 19 scenarios where access to unencrypted traffic is still relevant and evaluate the incentives of the stakeholders involved. Second, we survey 30 schemes by which TLS no longer delivers end-to-end security and by which the notion of an "end" changes, including caching middleboxes such as Content Delivery Networks. Finally, we compare each scheme based on deployability and security characteristics and evaluate their compatibility with the stakeholders' incentives. Our analysis leads to a number of key findings, observations, and research questions that we believe will be of interest to practitioners, policy makers, and researchers.

Copy held

KindPDF, 1.1 MB
Retrieved2026-08-11
Heldlocal, for personal reference
Where it came fromhttps://arxiv.org/pdf/2010.16388

Where this came from

How it got herealready cited · cited in bibtex
First seen2026-08-10
Recordreviewed by a person
Approved2026-08-11

Cite it as

@article{carnavalet2023survey,
  title = {A Survey and Analysis of TLS Interception Mechanisms and Motivations: Exploring how end-to-end TLS is made "end-to-me" for web traffic},
  author = {Xavier de Carné de Carnavalet and Paul C. van Oorschot},
  year = {2023},
  journal = {ACM Computing Surveys},
  volume = {55},
  number = {13s},
  pages = {1--40},
  doi = {10.1145/3580522},
  url = {https://dl.acm.org/doi/pdf/10.1145/3580522},
}

This record lives at https://refs.drheap.org/carnavalet2023survey/ and will keep doing so.