论文标题

停止无声偷偷摸摸:防御拓扑工程的恶意混合

Stopping Silent Sneaks: Defending against Malicious Mixes with Topological Engineering

论文作者

Ma, Xinshu, Rochet, Florentin, Elahi, Tariq

论文摘要

混合网提供了强大的元数据隐私,并且最近的学术研究和工业项目在使其更安全,性能和可扩展方面取得了长足的进步。在本文中,我们将工作重点放在分层的混合网上 - 一种流行的设计,具有现实世界中的采用 - 并确定仍然存在迄今为止尚不在探索的实际方面,例如:继电器采样和拓扑放置,网络流失,由于现实世界的用法模式而引起的风险。我们表明,由于缺乏这些方面,这种类型的混音网比用户脱词更容易比预期。为了推理和解决这些问题,我们将混合网模型为三阶段的``样品置换式''管道,并使用评估结果提出了一种新型的混合网设计,Bow-tie。 Bow-tie通过对Tor的后卫设计进行新颖的改编,并具有工程设计的后卫层和用于分层混合网的客户卫队逻辑。我们表明,在动态设置中,Bow-tie在一段时间内使用混合网的用户匿名性明显更高,并且在静态设置中并不糟糕,在静态设置中,用户只会发送一条消息。我们在将后卫层和客户卫队逻辑的必要性以及将其纳入其他参考设计中时的效果。最终,Bow-tie是解决混合网与实际部署和更广泛采用之间差距的重要一步,因为它直接解决了现实世界中的用户和混合网操作员的关注。

Mixnets provide strong meta-data privacy and recent academic research and industrial projects have made strides in making them more secure, performance, and scalable. In this paper, we focus our work on stratified Mixnets -- a popular design with real-world adoption -- and identify that there still exist heretofore inadequately explored practical aspects such as: relay sampling and topology placement, network churn, and risks due to real-world usage patterns. We show that, due to the lack of incorporating these aspects, Mixnets of this type are far more susceptible to user deanonymization than expected. In order to reason and resolve these issues, we model Mixnets as a three-stage ``Sample-Placement-Forward'' pipeline, and using the results of our evaluation propose a novel Mixnet design, Bow-Tie. Bow-Tie mitigates user deanonymization through a novel adaption of Tor's guard design with an engineered guard layer and client guard-logic for stratified mixnets. We show that Bow-Tie has significantly higher user anonymity in the dynamic setting, where the Mixnet is used over a period of time, and is no worse in the static setting, where the user only sends a single message. We show the necessity of both the guard layer and client guard-logic in tandem as well as their individual effect when incorporated into other reference designs. Ultimately, Bow-Tie is a significant step towards addressing the gap between the design of Mixnets and practical deployment and wider adoption because it directly addresses real-world user and Mixnet operator concerns.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源