Mixminion: Design of a Type III Anonymous Remailer Protocol Roger Dingledine The Free Haven Project
1
Mixminion: Design of a Type III Anonymous Remailer Protocol Roger - - PowerPoint PPT Presentation
Mixminion: Design of a Type III Anonymous Remailer Protocol Roger Dingledine The Free Haven Project 1 Threat Model (what we aim to defend against) Global passive adversary can observe everything Owns half the nodes We are not
1
2
3
4
M
E ...(E (M,to B), to 2)
2 1 2
E ...(M,to B)
5
Mixmaster Latent-Hist Latent Uptime-Hist Uptime Options
111032010010 :42 ++++++++++++ 100.0% PR O xganon 000000000000 :03 ++++++++++++ 100.0% PR green 00000000000? :09 +++++++++++0 97.8% 2 O lcs 151231221221 1:30 +++++++++7++ 97.8% M
up
6
“alice”=an4691@anon.penet.fi (A has told 1 her location.) This and the direct forward gets you type 0 remailers (anon.penet.fi) But: observers still know it goes to A. And 1 knows where A lives.
7
E(E(...(M)))
E(M),D("alice")
8
E(E(...(M))) M,alice@nym.alias.net M, "alice"
9
E(E(...(M))) E(E(...(M), to "NS")) M, "alice"
10
Encryption doesn’t matter if there’s only one message.
But: Different-sized messages can still be distinguished.
11
3
M M ... 2 3 ... 3
strip off
But: Replay attacks – a given message always decrypts the same way!
12
13
14
But you can flood a node so you know all but one message in the batch.
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41