首页> 外文会议>International workshop on security >Key Management for Onion Routing in a True Peer to Peer Setting
【24h】

Key Management for Onion Routing in a True Peer to Peer Setting

机译:点对点设置中洋葱路由的密钥管理

获取原文

摘要

Onion routing is a technique for anonymous and privacy preserving communication at the base of popular Internet anonymity tools such as Tor. In onion routing, traffic is relayed by a number of intermediary nodes (called relays) before it reaches the intended destination. To guarantee privacy and prevent tampering, each packet is encrypted multiple times in a layered manner, using the public keys of the relays. Therefore, this mechanism makes two important assumptions: first, that the relays are able to communicate with each other; second, that the user knows the list of available relays and their respective public keys. Tor implements therefore a distributed directory listing the relays and their keys. When a user is not able to communicate with relays directly, he has to use special bridge servers to connect to the onion network. This construction, however, does not work in a fully peer to peer setting, where each peer only knows a limited number of other peers and may not be able to communicate with some of them due, for instance, to NAT or firewalls. In this paper we propose a key management scheme for onion routing that overcomes these problems. The proposed solution does not need a directory system and does not imply knowledge of all active relays, while it guarantees the secure distribution of public keys. We also present an alternative strategy for building circuit of relays based on bloom filters. The proposed construction overcomes some of the structural inefficiencies of the Tor design, and opens the way for implementing onion routing over a true peer to peer overlay network.
机译:洋葱路由是一种基于流行的Internet匿名工具(例如Tor)的匿名和隐私保护通信技术。在洋葱路由中,流量在到达预期目的地之前由许多中间节点(称为中继)进行中继。为了保证隐私并防止篡改,每个数据包都使用中继的公共密钥以分层的方式多次加密。因此,该机制有两个重要的假设:第一,继电器能够相互通信;第二,继电器能够相互通信。其次,用户知道可用中继列表及其各自的公共密钥。因此,Tor实现了列出继电器及其键的分布式目录。当用户无法直接与中继进行通信时,他必须使用特殊的桥接服务器来连接到洋葱网络。但是,这种构造无法在完全的对等设置中工作,在这种情况下,每个对等只能知道有限数量的其他对等,并且由于NAT或防火墙等原因,可能无法与其中一些进行通信。在本文中,我们提出了一种用于洋葱路由的关键管理方案,可以克服这些问题。所提出的解决方案不需要目录系统,并且不暗含所有活动中继的知识,同时还可以保证公钥的安全分发。我们还提出了一种基于布隆滤波器构建继电器电路的替代策略。所提出的构造克服了Tor设计的一些结构效率低下的问题,并为在真正的对等覆盖网络上实现洋葱路由选择开辟了道路。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号