Skip to main navigation Skip to search Skip to main content

Provable Unlinkability Against Traffic Analysis with Low Message Overhead

  • Ron Berman
  • , Amos Fiat
  • , Marcin Gomułkiewicz
  • , Marek Klonowski
  • , Mirosław Kutyłowski
  • , Tomer Levinboim
  • , Amnon Ta-Shma

Research output: Contribution to journalArticlepeer-review

Abstract

Rackoff and Simon proved that a variant of Chaum’s protocol for anonymous communication, later developed as the Onion Routing Protocol, is unlinkable against a passive adversary that controls all communication links and most of the nodes in a communication system. A major drawback of their analysis is that the protocol is secure only if (almost) all nodes participate at all times. That is, even if only n≪N nodes wish to send messages, allN nodes have to participate in the protocol at all times. This suggests necessity of sending dummy messages and a high message overhead. Our first contribution is showing that this is unnecessary. We relax the adversary model and assume that the adversary only controls a certain fraction of the communication links in the communication network. We think this is a realistic adversary model. For this adversary model we show that a low message overhead variant of Chaum’s protocol is provably secure. Furthermore, all previous security proofs assumed the a priori distribution on the messages is uniform. We feel this assumption is unrealistic. The analysis we give holds for any a priori information on the communication distribution. We achieve that by combining Markov chain techniques together with information theory tools in a simple and elegant way.

Original languageEnglish GB
Pages (from-to)623-640
Number of pages18
JournalJournal of Cryptology
Volume28
Issue number3
DOIs
StatePublished - 12 Jul 2015

Keywords

  • Markov Chain
  • Mix protocol
  • Mixing time
  • Traffic analysis
  • Unlinkability

ASJC Scopus subject areas

  • Software
  • Computer Science Applications
  • Applied Mathematics

Fingerprint

Dive into the research topics of 'Provable Unlinkability Against Traffic Analysis with Low Message Overhead'. Together they form a unique fingerprint.

Cite this