Orca: Blocklisting in Sender-Anonymous Messaging

Orca: Blocklisting in Sender-Anonymous Messaging
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Nirvan Tyagi;Julia Len;Ian Miers;Thomas Ristenpart
Nirvan Tyagi;Julia Len;Ian Miers;Thomas Ristenpart
中科院分区:
其他
文献类型:
--
作者:
Nirvan Tyagi;Julia Len;Ian Miers;Thomas Ristenpart

文献摘要

被引文献

相似文献

发件人匿名端到端加密消息传递允许向收件人发送消息,而不会向消息传递平台透露发件人的身份。Signal最近推出了一项发件人匿名功能,其中包括一种滥用缓解机制,旨在允许平台代表收件人阻止恶意邮件。我们探讨发件人匿名和滥用缓解之间的紧张关系。我们首先展示Signal部署机制的局限性,观察到它导致匿名性相对较弱,并展示了一种新的令人悲伤的攻击,允许恶意发送者耗尽受害者的电池。因此,我们设计了一个名为Orca的新协议,允许接收者在平台上注册一个保护隐私的阻止列表。在不了解发件人身份的情况下,平台可以检查发件人是否不在阻止列表中,以及发件人是否可以被收件人识别。利用一种新的群签名方案构造了Orca,并给出了形式化的安全概念。我们的原型实现展示了Orca的实用性。
Sender-anonymous end-to-end encrypted messaging allows sending messages to a recipient without revealing the sender’s identity to the messaging platform. Signal recently introduced a sender anonymity feature that includes an abuse mitigation mechanism meant to allow the platform to block malicious senders on behalf of a recipient. We explore the tension between sender anonymity and abuse mitigation. We start by showing limitations of Signal’s deployed mechanism, observing that it results in relatively weak anonymity properties and showing a new griefing attack that allows a malicious sender to drain a victim’s battery. We therefore design a new protocol, called Orca, that allows recipients to register a privacy-preserving blocklist with the platform. Without learning the sender’s identity, the platform can check that the sender is not on the blocklist and that the sender can be identified by the recipient. We construct Orca using a new type of group signature scheme, for which we give formal security notions. Our prototype implementation showcases Orca’s practicality.