发表机构
KU Leuven(鲁汶大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对现有混网缺乏同时保护收发双方隐私的安全实用隐藏服务协议的问题,基于SURBs及防御措施提出NymHS,经实验验证其可在混网上高效部署,性能优于当前Nym基线。
AI 中文摘要
混网络(mixnets)通过将每个通信数据包路由经过一系列称为混节点(mixnodes)的中介,这些中介在转发前会随机延迟并对数据包进行密码学变换,使观察者难以将混网的入口与出口关联起来,从而提供网络级隐私。虽然该机制能保护发送方隐私免受外部攻击者和接收方的侵害,但现有混网缺乏一种安全且实用的协议,该协议能同时保护接收方(目的地)隐私,尤其是免受发送方的侵害。我们填补了这一空白。我们引入了首个实用且安全的混网隐藏服务协议,在提供发送方匿名性的同时也提供接收方隐私。我们的设计基于一次性回复块(Single-Use Reply Blocks,SURBs),该技术支持匿名回复而不泄露接收方地址。然而,我们发现现有使用SURBs的方法存在两种实际攻击,当对方仅控制单个混节点时,这些攻击可能会损害发送方或接收方的匿名性。我们针对这两种漏洞开发了防御措施。基于这些防御措施,我们引入了NymHS,一种安全且实用的混网隐藏服务协议,支持匿名服务发现、认证双向会话以及异步SURB补充。我们在开源Nym代码库上实现了NymHS,并通过对118个网站的网页浏览实验评估其实用性,对27种配置各进行三次实验(共9558次页面加载)。我们的结果表明,隐藏服务可以在混网上高效部署。特别是,将Sphinx payload从2 KiB增加到10 KiB,相对于当前Nym基线,可将平均页面加载延迟降低约5.2倍,并将通信开销从21.7%降至4.3%。
英文摘要
Mix networks (mixnets) provide network-level privacy by routing each communication packet through a sequence of intermediaries, called mixnodes, that randomly delay and cryptographically transform packets before forwarding them, making it difficult for observers to link mixnet entries to exits. While this mechanism protects sender privacy from both external adversaries and the receiver, existing mixnets lack a secure and practical protocol that simultaneously protects receiver (destination) privacy, particularly from the sender. We close this gap. We introduce the first practical and secure hidden-service protocol for mixnets, providing receiver privacy alongside sender anonymity. Our design builds on Single-Use Reply Blocks (SURBs), which enable anonymous replies without revealing the receiver's address. We show, however, that existing approaches to using SURBs expose two practical attacks that can compromise sender or receiver anonymity when the opposing party controls only a single mixnode. We develop defenses against both vulnerabilities. Building on these defenses, we introduce NymHS, a secure and practical hidden-service protocol for mixnets that supports anonymous service discovery, authenticated bidirectional sessions, and asynchronous SURB replenishment. We implement NymHS on the open-source Nym codebase and evaluate its practicality through web-browsing experiments across 118 websites, measuring each of the 27 configurations three times (9,558 page loads). Our results demonstrate that hidden services can be deployed efficiently over mixnets. In particular, increasing the Sphinx payload from 2 KiB to 10 KiB reduces mean page-load latency by approximately 5.2x and decreases communication overhead from 21.7% to 4.3% relative to the current Nym baseline.