首页> 外文期刊>IEEE/ACM Transactions on Networking >SGX-Tor: A Secure and Practical Tor Anonymity Network With SGX Enclaves
【24h】

SGX-Tor: A Secure and Practical Tor Anonymity Network With SGX Enclaves

机译:SGX-Tor:使用SGX Enclaves的安全实用的Tor匿名网络

获取原文
获取原文并翻译 | 示例

摘要

With Tor being a popular anonymity network, many attacks have been proposed to break its anonymity or leak information of a private communication on Tor. However, guaranteeing complete privacy in the face of an adversary on Tor is especially difficult, because Tor relays are under complete control of world-wide volunteers. Currently, one can gain private information, such as circuit identifiers and hidden service identifiers, by running Tor relays and can even modify their behaviors with malicious intent. This paper presents a practical approach to effectively enhancing the security and privacy of Tor by utilizing Intel SGX, a commodity trusted execution environment. We present a design and implementation of Tor, called SGX-Tor, that prevents code modification and limits the information exposed to untrusted parties. We demonstrate that our approach is practical and effectively reduces the power of an adversary to a traditional network-level adversary. Finally, SGX-Tor incurs moderate performance overhead; the end-to-end latency and throughput overheads for HTTP connections are 3.9% and 11.9%, respectively.
机译:由于Tor是流行的匿名网络,因此提出了许多攻击方法,以破坏其匿名性或泄漏Tor上的私人通信信息。但是,面对Tor的对手,要确保完全的隐私特别困难,因为Tor的接力者受到全世界志愿者的完全控制。当前,人们可以通过运行Tor中继来获取诸如电路标识符和隐藏服务标识符之类的私人信息,甚至可以恶意地修改其行为。本文提出了一种实用方法,可通过利用商品信任的执行环境Intel SGX有效地增强Tor的安全性和隐私性。我们提出了一种称为SGX-Tor的Tor的设计和实现,该设计和实现可防止代码修改并限制暴露给不受信任方的信息。我们证明了我们的方法是可行的,并且可以有效地将对手的力量降低到传统的网络级对手。最后,SGX-Tor会产生中等的性能开销; HTTP连接的端到端延迟和吞吐量开销分别为3.9%和11.9%。

著录项

  • 来源
    《IEEE/ACM Transactions on Networking》 |2018年第5期|2174-2187|共14页
  • 作者单位

    Graduate School of Information Security, Korea Advanced Institute of Science Technology, Daejeon, South Korea;

    School of Electrical Engineering, Korea Advanced Institute of Science Technology, Daejeon, South Korea;

    School of Electrical Engineering, Korea Advanced Institute of Science Technology, Daejeon, South Korea;

    School of Computer Science, Georgia Institute of Technology, Atlanta, GA, USA;

    School of Electrical Engineering, Korea Advanced Institute of Science Technology, Daejeon, South Korea;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Relays; Servers; Hardware; Privacy; Security; IP networks; Software;

    机译:中继;服务器;硬件;隐私;安全性;IP网络;软件;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号