EricssonResearch / EricssonResearch/Blind-Cache-Drafts
Prevent CDN Exploitation
Open
oob
- Dominant language
- Makefile
- Stars
- 2
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
The current model contains no proof for the CDN that the origin actually referred it. 7.2 defines using the encryption/integrity keys as proof _to the client_ that the origin actually can decrypt the content. An attacker who wished to spoof the origin could not only retrieve and rehost the content, but even use the same CDN address and key to steal the CDN's hosting services for its attack.
It seems like there needs to be something to demonstrate to the CDN that the requestor has (recently?) spoken to the origin server.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.