VLDB 2026 Research / reviewers in the wild / expert
Ian Goldberg 0001
dblp:04/6434
· DBLP profile ↗
77ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-1176-2882ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 72 · 6 first-author · 15 since 2021Systems, architecture and hardware · 2Computer networks · 2Human-computer interaction and ubiquitous computing · 2Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Troll Patrol: Anonymous User Reporting of Bridge CensorshipabstractBridges are circumvention proxies that provide routes around censorship. In order to be effective, most bridges must be kept secret from censors, lest they be added to censors’ blocklists. Reputation-based bridge distribution systems including rBridge, Hyphae, and Lox have been proposed with the goal of enabling regular users to learn about bridges while preventing censors from learning about and blocking these bridges. These three examples use anonymous credentials to preserve user anonymity while still allowing the anonymous users to gain reputation within the system if the bridges distributed to them remain unblocked for some period of time and penalizing them by reducing their reputations if the bridges distributed to them become blocked by censors. Performing these reputation changes requires these systems to have knowledge of which bridges have been discovered and blocked by censors and which are still accessible. The obvious way to test whether a given bridge is accessible from a given region is by attempting to connect directly to that bridge from within that region; however, this approach carries risks, including that these scans may inadvertently reveal previously undiscovered bridges to a censor. Rather than actively scanning all bridges, we favor soliciting users to submit reports when their bridges are inaccessible and scanning only the bridges for which user reports have been received, to validate those reports. This approach reduces the set of bridges that must be actively scanned but also introduces new risks if implemented naïvely; namely, censors or malicious users might submit inaccurate reports in order to disrupt the bridge distribution system or induce additional scans. It might be tempting to tie users’ reports to their identities in order to penalize users who submit inaccurate reports, but doing so would violate user anonymity. Building on the anonymous credential systems used in, e.g., Hyphae and Lox, we design Troll Patrol, a scheme for users to submit reports that is resilient against malicious behavior, both by censors and by regular users, while still preserving the anonymity of the users who submit them. Vecna, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Arctic: Lightweight and Stateless Threshold Schnorr Signatures
Chelsea Komlo, Ian Goldberg 0001 |
PKC (5) | 2 |
| 2025 | TEEMS: A Trusted Execution Environment based Metadata-protected Messaging SystemabstractEnsuring privacy of online messaging remains a challenge. While the contents or data of online communications are often protected by end-to-end encryption, the metadata of communications are not. Metadata such as who is communicating with whom, how much, and how often, are leaked by popular messaging systems today. In the last four decades we have witnessed a rich literature of designs towards metadata-protecting communications systems (MPCS). While recent MPCS works often target metadata-protected messaging systems, no existing construction simultaneously attains four desirable properties for messaging systems, namely (i) low latency, (ii) high throughput, (iii) horizontal scalability, and (iv) asynchronicity. Existing designs often capture disjoint subsets of these properties. For example, PIR-based approaches achieve low latency and asynchronicity but have low throughput and lack horizontal scalability, mixnet-based approaches achieve high throughput and horizontal scalability but lack asynchronicity, and approaches based on trusted execution environments (TEEs) achieve high throughput and asynchronicity but lack horizontal scalability. In this work, we present TEEMS, the first MPCS designed for metadata-protected messaging that simultaneously achieves all four desirable properties. Our distributed TEE-based system uses an oblivious mailbox design to provide metadata-protected messaging. TEEMS presents novel oblivious routing protocols that adapt prior work on oblivious distributed sorting. Moreover, we introduce the notion of ID and token channels to circumvent shortcomings of prior designs. We empirically demonstrate TEEMS' ability to support 2^20 clients engaged in metadata-protected conversations in under 1 s, with 205 cores, achieving an 18× improvement over prior work for latency and throughput, while supporting significantly better scalability and asynchronicity properties. Sajin Sasy, Aaron Johnson 0001, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | SoK: Metadata-Protecting Communication SystemsabstractProtecting metadata of communications has been an area of active research since the dining cryptographers problem was introduced by David Chaum in 1988. The Snowden revelations from 2013 resparked research in this direction. Consequently over the last decade we have witnessed a flurry of novel systems designed to protect metadata of users' communications online. However, such systems leverage different assumptions and design choices to achieve their goal; resulting in a scattered view of the desirable properties, potential vulnerabilities, and limitations of existing metadata-protecting communication systems (MPCS). In this work we survey 31 systems targeting metadata-protected communications, and present a unified view of the current state of affairs. We provide two different taxonomies for existing MPCS, first into four different categories by the precise type of metadata protections they offer, and next into six families based on the core techniques that underlie them. By contrasting these systems we identify potential vulnerabilities, as well as subtle privacy implications of design choices of existing MPCS. Furthermore, we identify promising avenues for future research for MPCS, and desirable properties that merit more attention. Sajin Sasy, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | PRAC: Round-Efficient 3-Party MPC for Dynamic Data StructuresabstractWe present Private Random Access Computations (PRAC), a 3-party Secure Multi-Party Computation (MPC) framework to support random-access data structure algorithms for MPC with efficient communication in terms of rounds and bandwidth. PRAC extends the state-of-the-art DORAM Duoram with a new implementation, more flexibility in how the DORAM memory is shared, and support for Incremental and Wide DPFs. We then use these DPF extensions to achieve algorithmic improvements in three novel oblivious data structure protocols for MPC. PRAC exploits the observation that a secure protocol for an algorithm can gain efficiency if the protocol explicitly reveals information leaked by the algorithm inherently. We first present an optimized binary search protocol that reduces the bandwidth from O(lg² n) to O(lg n) for obliviously searching over n items. We then present an oblivious heap protocol with rounds reduced from O(lg n) to O(lg lg n) for insertions, and bandwidth reduced from O(lg² n) to O(lg n) for extractions. Finally, we also present the first oblivious AVL tree protocol for MPC where no party learns the data or the structure of the AVL tree, and can support arbitrary insertions and deletions with O(lg n) rounds and bandwidth. We experimentally evaluate our protocols with realistic network settings for a wide range of memory sizes to demonstrate their efficiency. For instance, we observe our binary search protocol provides >27× and >3× improvements in wall-clock time and bandwidth respectively over other approaches for a memory with 2^26 items; for the same setting our heap's extract-min protocol achieves >31× speedup in wall-clock time and >13× reduction in bandwidth. Sajin Sasy, Adithya Vadapalli, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Waks-On/Waks-Off: Fast Oblivious Offline/Online Shuffling and Sorting with Waksman NetworksabstractAs more privacy-preserving solutions leverage trusted execution environments (TEEs) like Intel SGX, it becomes pertinent that these solutions can by design thwart TEE side-channel attacks that research has brought to light. In particular, such solutions need to be fully oblivious to circumvent leaking private information through memory or timing side channels. Sajin Sasy, Aaron Johnson 0001, Ian Goldberg 0001 |
CCS | 3 |
| 2023 | Investigating Membership Inference Attacks under Data DependenciesabstractTraining machine learning models on privacy-sensitive data has become a popular practice, driving innovation in ever-expanding fields. This has opened the door to new attacks that can have serious privacy implications. One such attack, the Membership Inference Attack (MIA), exposes whether or not a particular data point was used to train a model. A growing body of literature uses Differentially Private (DP) training algorithms as a defence against such attacks. However, these works evaluate the defence under the restrictive assumption that all members of the training set, as well as non-members, are independent and identically distributed. This assumption does not hold for many real-world use cases in the literature. Motivated by this, we evaluate membership inference with statistical dependencies among samples and explain why DP does not provide meaningful protection (the privacy parameter$\epsilon$scales with the training set size$n$) in this more general case. We conduct a series of empirical evaluations with off-the-shelf MIAs using training sets built from real-world data showing different types of dependencies among samples. Our results reveal that training set dependencies can severely increase the performance of MIAs, and therefore assuming that data samples are statistically independent can significantly underestimate the performance of MIAs. Thomas Humphries, Simon Oya, Lindsey Tulloch, Matthew Rafuse, Ian Goldberg 0001, Urs Hengartner, Florian Kerschbaum |
CSF | 5 |
| 2023 | Duoram: A Bandwidth-Efficient Distributed ORAM for 2- and 3-Party Computation
Adithya Vadapalli, Ryan Henry, Ian Goldberg 0001 |
USENIX Security Symposium | 3 |
| 2023 | Lox: Protecting the Social Graph in Bridge DistributionabstractIn regions of the world where censorship of the Internet is used to limit access to information, monitor the activity of Internet users, and quash dissent, anti-censorship proxies, or bridges, can offer a connection to the open Internet beyond a censor's area of influence. Bridge distribution systems, built to publicly distribute large pools of bridges to users in censored regions, face the inherent conflict of providing bridges to unknown users when some of them may be malicious. If not designed with care, bridge distribution systems can be quickly overwhelmed by attacks from censors, undermining the integrity of the system and the safety of users. It is therefore crucial to prioritize protecting users when developing such systems. In this paper, we present a new bridge distribution system, Lox. Lox prioritizes protecting the privacy of users and their social graphs and incorporates enumeration resistance mechanisms to improve access to bridges and limit the malicious behaviour of censors. We use an updated unlinkable multi-show anonymous credential scheme, suitable for a single credential issuer and verifier, to protect Lox bridge users and their social networks from being identified by malicious actors. We formalize a trust level scheme that is compatible with anonymous credentials and effectively limits malicious behaviour while maintaining user anonymity. Our work includes an open-sourced, Rust implementation of our Lox protocols as well as an evaluation of their performance. With reasonable performance and latency for the expected user base of our system, we demonstrate Lox as a practical, social graph protective bridge distribution system. Lindsey Tulloch, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Astrape: Anonymous Payment Channels with Boring Cryptography
Yuhao Dong, Ian Goldberg 0001, Sergey Gorbunov 0001, Raouf Boutaba |
ACNS | 2 |
| 2022 | Improving the Privacy of Tor Onion Services
Edward Eaton, Sajin Sasy, Ian Goldberg 0001 |
ACNS | 3 |
| 2022 | Fast Fully Oblivious Compaction and ShufflingabstractSeveral privacy-preserving analytics frameworks have been proposed that use trusted execution environments (TEEs) like Intel SGX. Such frameworks often use compaction and shuffling as core primitives. However, due to advances in TEE side-channel attacks, these primitives, and the applications that use them, should be fully oblivious; that is, perform instruction sequences and memory accesses that do not depend on the secret inputs. Such obliviousness would eliminate the threat of leaking private information through memory or timing side channels, but achieving it naively can result in a significant performance cost. Sajin Sasy, Aaron Johnson 0001, Ian Goldberg 0001 |
CCS | 3 |
| 2021 | Weaving a Faster Tor: A Multi-Threaded Relay Architecture for Improved ThroughputabstractThe Tor anonymity network has millions of daily users and thousands of volunteer-run relays. Increasing the number of Tor users will enhance the privacy of not just new users, but also existing users by increasing their anonymity sets. However, growing the network further has several research and deployment challenges. One such challenge is supporting the increase in bandwidth required by additional users joining the network. While adding more Tor relays to the network would increase the total available bandwidth, it requires network architecture changes to reduce the impact of Tor’s growing directory documents. In order to increase the total available network bandwidth without needing to grow Tor’s directory documents, this work provides a multi-threaded relay architecture designed to improve the throughput of individual multi-core relays with available network capacity. We built an implementation of a subset of this new design on top of the standard Tor code base to demonstrate the potential throughput improvements of this architecture on both high- and low-performance hardware. Steven Engler, Ian Goldberg 0001 |
ARES | 2 |
| 2021 | Once is Never Enough: Foundations for Sound Statistical Inference in Tor Network Experimentation
Rob Jansen, Justin Tracey, Ian Goldberg 0001 |
USENIX Security Symposium | 3 |
| 2021 | SoK: Privacy-Preserving Reputation SystemsabstractAbstract Trust and user-generated feedback have become increasingly vital to the normal functioning of the modern internet. However, deployed systems that currently incorporate such feedback do not guarantee users much in the way of privacy, despite a wide swath of research on how to do so spanning over 15 years. Meanwhile, research on systems that maintain user privacy while helping them to track and update each others’ reputations has failed to standardize terminology, or converge on what privacy guarantees should be important. Too often, this leads to misunderstandings of the tradeoffs underpinning design decisions. Further, key insights made in some approaches to designing such systems have not circulated to other approaches, leaving open significant opportunity for new research directions. This SoK investigates 42 systems describing privacy-preserving reputation systems from 2003–2019 in order to organize previous work and suggest directions for future work. Our three key contributions are the systematization of this body of research, the detailing of the tradeoffs implied by overarching design choices, and the identification of underresearched areas that provide promising opportunities for future work. Stan Gurtler, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | FROST: Flexible Round-Optimized Schnorr Threshold Signatures
Chelsea Komlo, Ian Goldberg 0001 |
SAC | 2 |
| 2020 | Walking Onions: Scaling Anonymity Networks while Protecting Users
Chelsea Komlo, Nick Mathewson, Ian Goldberg 0001 |
USENIX Security Symposium | 3 |
| 2020 | Mind the Gap: Ceremonies for Applied Secret SharingabstractAbstract Secret sharing schemes are desirable across a variety of real-world settings due to the security and privacy properties they can provide, such as availability and separation of privilege. However, transitioning secret sharing schemes from theoretical research to practical use must account for gaps in achieving these properties that arise due to the realities of concrete implementations, threat models, and use cases. We present a formalization and analysis, using Ellison’s notion of ceremonies, that demonstrates how simple variations in use cases of secret sharing schemes result in the potential loss of some security properties, a result that cannot be derived from the analysis of the underlying cryptographic protocol alone. Our framework accounts for such variations in the design and analysis of secret sharing implementations by presenting a more detailed user-focused process and defining previously overlooked assumptions about user roles and actions within the scheme to support analysis when designing such ceremonies. We identify existing mechanisms that, when applied to an appropriate implementation, close the security gaps we identified. We present our implementation including these mechanisms and a corresponding security assessment using our framework. Bailey Kacsmar, Chelsea Komlo, Florian Kerschbaum, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | Mitigator: Privacy policy compliance using trusted hardwareabstractAbstract Through recent years, much research has been conducted into processing privacy policies and presenting them in ways that are easy for users to understand. However, understanding privacy policies has little utility if the website’s data processing code does not match the privacy policy. Although systems have been proposed to achieve compliance of internal software to access control policies, they assume a large trusted computing base and are not designed to provide a proof of compliance to an end user. We design Mitigator, a system to enforce compliance of a website’s source code with a privacy policy model that addresses these two drawbacks of previous work. We use trusted hardware platforms to provide a guarantee to an end user that their data is only handled by code that is compliant with the privacy policy. Such an end user only needs to trust a small module in the hardware of the remote back-end machine and related libraries but not the entire OS. We also provide a proof-of-concept implementation of Mitigator and evaluate it for its latency. We conclude that it incurs only a small overhead with respect to an unmodified system that does not provide a guarantee of privacy policy compliance to the end user. Miti Mazmudar, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | ConsenSGX: Scaling Anonymous Communications Networks with Trusted Execution EnvironmentsabstractAbstract Anonymous communications networks enable individuals to maintain their privacy online. The most popular such network is Tor, with about two million daily users; however, Tor is reaching limits of its scalability. One of the main scalability bottlenecks of Tor and similar network designs originates from the requirement of distributing a global view of the servers in the network to all network clients. This requirement is in place to avoidepistemic attacks, in which adversaries who know which parts of the network certain clients do and do not know about can rule in or out those clients from being responsible for particular network traffic. In this work, we introduce a novel solution to this scalability problem by leveraging oblivious RAM constructions and trusted execution environments in order to enable clients to fetch only the parts of the network view they require, without the directory servers learning which parts are being fetched. We compare the performance of our design with the current Tor mechanism and other related works to show one to two orders of magnitude better performance from an end-to-end perspective. We analyse the requirements to actually deploy such a scheme today and conclude that it would only require a small fraction (<2.5%) of the relays to have the required hardware support; moreover, these relays can perform their roles with minimal network bandwidth requirements. Sajin Sasy, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Settling Payments Fast and Private: Efficient Decentralized Routing for Path-Based Transactions
Stefanie Roos, Pedro Moreno-Sanchez, Aniket Kate, Ian Goldberg 0001 |
NDSS | 4 |
| 2018 | Secure asymmetry and deployability for decoy routing systemsabstractAbstract Censorship circumvention is often characterized as a cat-and-mouse game between a nation-state censor and the developers of censorship resistance systems. Decoy routing systems offer a solution to censor- ship resistance that has the potential to tilt this race in the favour of the censorship resistor by using real connections to unblocked, overt sites to deliver censored content to users. This is achieved by employing the help of Internet Service Providers (ISPs) or Autonomous Systems (ASes) that own routers in the middle of the net- work. However, the deployment of decoy routers has yet to reach fruition. Obstacles to deployment such as the heavy requirements on routers that deploy decoy router relay stations, and the impact on the quality of service for customers that pass through these routers have deterred potential participants from deploying existing systems. Furthermore, connections from clients to overt sites often follow different paths in the upstream and downstream direction, making some existing designs impractical. Although decoy routing systems that lessen the burden on participating routers and accommodate asymmetric flows have been proposed, these arguably more deployable systems suffer from security vulnerabilities that put their users at risk of discovery or make them prone to censorship or denial of service attacks. In this paper, we propose a technique for supporting route asymmetry in previously symmetric decoy routing systems. The resulting asymmetric solution is more secure than previous asymmetric proposals and provides an option for tiered deployment, allowing more cautious ASes to deploy a lightweight, non-blocking relay station that aids in defending against routing-capable adversaries. We also provide an experimental evaluation of relay station performance on off-the-shelf hardware and additional security improvements to recently proposed systems. Cecylia Bocovich, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Privacy Pass: Bypassing Internet Challenges AnonymouslyabstractAbstract The growth of content delivery networks (CDNs) has engendered centralized control over the serving of internet content. An unwanted by-product of this growth is that CDNs are fast becoming global arbiters for which content requests are allowed and which are blocked in an attempt to stanch malicious traffic. In particular, in some cases honest users-especially those behind shared IP addresses, including users of privacy tools such as Tor, VPNs, and I2P - can be unfairly targeted by attempted ‘catch-all solutions’ that assume these users are acting maliciously. In this work, we provide a solution to prevent users from being exposed to a disproportionate amount of internet challenges such as CAPTCHAs. These challenges are at the very least annoying and at their worst - when coupled with bad implementations - can completely block access from web resources. We detail a 1-RTT cryptographic protocol (based on an implementation of an oblivious pseudorandom function) that allows users to receive a significant amount of anonymous tokens for each challenge solution that they provide. These tokens can be exchanged in the future for access without having to interact with a challenge. We have implemented our initial solution in a browser extension named “Privacy Pass”, and have worked with the Cloudflare CDN to deploy compatible server-side components in their infrastructure. However, we envisage that our solution could be used more generally for many applications where anonymous and honest access can be granted (e.g., anonymous wiki editing). The anonymity guarantee of our solution makes it immediately appropriate for use by users of Tor/VPNs/ I2P. We also publish figures from Cloudflare indicating the potential impact from the global release of Privacy Pass. Alex Davidson, Ian Goldberg 0001, Nick Sullivan, George Tankersley, Filippo Valsorda |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Improved Strongly Deniable Authenticated Key Exchanges for Secure MessagingabstractAbstract A deniable authenticated key exchange (DAKE) protocol establishes a secure channel without producing cryptographic evidence of communication. A DAKE offersstrong deniabilityif transcripts provide no evidence even if long-term key material is compromised (offline deniability) and no outsider can obtain evidence even when interactively colluding with an insider (online deniability). Unfortunately, existing strongly deniable DAKEs have not been adopted by secure messaging tools due to security and deployability weaknesses. In this work, we propose three new strongly deniable key exchange protocols—DAKEZ, ZDH, and XZDH—that are designed to be used in modern secure messaging applications while eliminating the weaknesses of previous approaches. DAKEZ offers strong deniability in synchronous network environments, while ZDH and XZDH can be used to construct asynchronous secure messaging systems with offline and partial online deniability. DAKEZ and XZDH provide forward secrecy against active adversaries, and all three protocols can provide forward secrecy against future quantum adversaries while remaining classically secure if attacks against quantum-resistant cryptosystems are found. We seek to reduce barriers to adoption by describing our protocols from a practitioner’s perspective, including complete algebraic specifications, cryptographic primitive recommendations, and prototype implementations. We evaluate concrete instantiations of our DAKEs and show that they are the most efficient strongly deniable schemes; with all of our classical security guarantees, our exchanges require only 1 ms of CPU time on a typical desktop computer and at most 464 bytes of data transmission. Our constructions are nearly as efficient as key exchanges with weaker deniability, such as the ones used by the popular OTR and Signal protocols. Nik Unger, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Some Results on the Existence of t-All-or-Nothing Transforms Over Arbitrary AlphabetsabstractA (t, s, v)-all-or-nothing transform (AONT) is a bijective mapping defined on s-tuples over an alphabet of size v, which satisfies the condition that the values of any t input co-ordinates are completely undetermined, given only the values of any s - t output co-ordinates. The main question we address in this paper is: for which choices of parameters does a (t, s, v)-AONT exist? More specifically, if we fix t and v, we want to determine the maximum integer s such that a (t, s, v)-AONT exists. We mainly concentrate on the case t = 2 for arbitrary values of v, where we obtain various necessary as well as sufficient conditions for existence of these objects. This includes computer searches that establish the existence of (2, q, q)-AONT for all odd primes not exceeding 29. We also show some connections between AONT, orthogonal arrays, and resilient functions. Navid Nasr Esfahani, Ian Goldberg 0001, Douglas Robert Stinson |
IEEE Trans. Inf. Theory | 2 |
| 2017 | Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks
Tao Wang 0012, Ian Goldberg 0001 |
USENIX Security Symposium | 2 |
| 2016 | Low-Cost Mitigation Against Cold Boot Attacks for an Authentication Token
Ian Goldberg 0001, Graeme Jenkinson, Frank Stajano |
ACNS | 1 |
| 2016 | Slitheen: Perfectly Imitated Decoy Routing through Traffic ReplacementabstractAs the capabilities of censors increase and their ability to perform more powerful deep-packet inspection techniques grows, more powerful systems are needed in turn to disguise user traffic and allow users under a censor's influence to access blocked content on the Internet. Decoy routing is a censorship resistance technique that hides traffic under the guise of a HTTPS connection to a benign, uncensored overt site. However, existing techniques far from perfectly mimic a typical access of content on the overt server. Artificial latency introduced by the system, as well as differences in packet sizes and timings betray their use to a censor capable of performing basic packet and latency analysis. While many of the more recent decoy routing systems focus on deployability concerns, they do so at the cost of security, adding vulnerabilities to both passive and active attacks. We propose Slitheen, a decoy routing system capable of perfectly mimicking the traffic patterns of overt sites. Our system is secure against previously undefended passive attacks, as well as known active attacks. Further, we show how recent innovations in traffic-shaping technology for ISPs mitigate previous deployability challenges. Cecylia Bocovich, Ian Goldberg 0001 |
CCS | 2 |
| 2016 | A Framework for the Game-theoretic Analysis of Censorship ResistanceabstractAbstract We present a game-theoretic analysis of optimal solutions for interactions between censors and censorship resistance systems (CRSs) by focusing on the data channel used by the CRS to smuggle clients’ data past the censors. This analysis leverages the inherent errors (false positives and negatives) made by the censor when trying to classify traffic as either non-circumvention traffic or as CRS traffic, as well as the underlying rate of CRS traffic. We identify Nash equilibrium solutions for several simple censorship scenarios and then extend those findings to more complex scenarios where we find that the deployment of a censorship apparatus does not qualitatively change the equilibrium solutions, but rather only affects the amount of traffic a CRS can support before being blocked. By leveraging these findings, we describe a general framework for exploring and identifying optimal strategies for the censorship circumventor, in order to maximize the amount of CRS traffic not blocked by the censor. We use this framework to analyze several scenarios with multiple data-channel protocols used as cover for the CRS. We show that it is possible to gain insights through this framework even without perfect knowledge of the censor’s (secret) values for the parameters in their utility function. Tariq Elahi, John A. Doucette, Hadi Hosseini, Steven J. Murdoch, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2016 | SoK: Making Sense of Censorship Resistance SystemsabstractAbstract An increasing number of countries implement Internet censorship at different scales and for a variety of reasons. Several censorship resistance systems (CRSs) have emerged to help bypass such blocks. The diversity of the censor’s attack landscape has led to an arms race, leading to a dramatic speed of evolution of CRSs. The inherent complexity of CRSs and the breadth of work in this area makes it hard to contextualize the censor’s capabilities and censorship resistance strategies. To address these challenges, we conducted a comprehensive survey of CRSs-deployed tools as well as those discussed in academic literature-to systematize censorship resistance systems by their threat model and corresponding defenses. To this end, we first sketch a comprehensive attack model to set out the censor’s capabilities, coupled with discussion on the scope of censorship, and the dynamics that influence the censor’s decision. Next, we present an evaluation framework to systematize censorship resistance systems by their security, privacy, performance and deployability properties, and show how these systems map to the attack model. We do this for each of the functional phases that we identify for censorship resistance systems: communication establishment, which involves distribution and retrieval of information necessary for a client to join the censorship resistance system; and conversation, where actual exchange of information takes place. Our evaluation leads us to identify gaps in the literature, question the assumptions at play, and explore possible mitigations. Sheharbano Khattak, Tariq Elahi, Colleen Swanson, Steven J. Murdoch, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 6 |
| 2016 | Lower-Cost ∈-Private Information RetrievalabstractAbstract Private Information Retrieval (PIR), despite being well studied, is computationally costly and arduous to scale. We explore lower-cost relaxations of information-theoretic PIR, based on dummy queries, sparse vectors, and compositions with an anonymity system. We prove the security of each scheme using a flexible differentially private definition for private queries that can capture notions of imperfect privacy. We show that basic schemes are weak, but some of them can be made arbitrarily safe by composing them with large anonymity systems. Raphael R. Toledo, George Danezis, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2016 | On Realistically Attacking Tor with Website FingerprintingabstractAbstract Website fingerprinting allows a local, passive observer monitoring a web-browsing client’s encrypted channel to determine her web activity. Previous attacks have shown that website fingerprinting could be a threat to anonymity networks such as Tor under laboratory conditions. However, there are significant differences between laboratory conditions and realistic conditions. First, in laboratory tests we collect the training data set together with the testing data set, so the training data set is fresh, but an attacker may not be able to maintain a fresh data set. Second, laboratory packet sequences correspond to a single page each, but for realistic packet sequences the split between pages is not obvious. Third, packet sequences may include background noise from other types of web traffic. These differences adversely affect website fingerprinting under realistic conditions. In this paper, we tackle these three problems to bridge the gap between laboratory and realistic conditions for website fingerprinting. We show that we can maintain a fresh training set with minimal resources. We demonstrate several classification-based techniques that allow us to split full packet sequences effectively into sequences corresponding to a single page each. We describe several new algorithms for tackling background noise. With our techniques, we are able to build the first website fingerprinting system that can operate directly on packet sequences collected in the wild. Tao Wang 0012, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2015 | Deniable Key Exchanges for Secure MessagingabstractIn the wake of recent revelations of mass government surveillance, secure messaging protocols have come under renewed scrutiny. A widespread weakness of existing solutions is the lack of strong deniability properties that allow users to plausibly deny sending messages or participating in conversations if the security of their communications is later compromised. Deniable authenticated key exchanges (DAKEs), the cryptographic protocols responsible for providing deniability in secure messaging applications, cannot currently provide all desirable properties simultaneously. We introduce two new DAKEs with provable security and deniability properties in the Generalized Universal Composability framework. Our primary contribution is the introduction of Spawn, the first non-interactive DAKE that offers forward secrecy and achieves deniability against both offline and online judges; Spawn can be used to improve the deniability properties of the popular TextSecure secure messaging application. We also introduce an interactive dual-receiver cryptosystem that can improve the performance of the only existing interactive DAKE with competitive security properties. To encourage adoption, we implement and evaluate the performance of our schemes while relying solely on standard-model assumptions. Nik Unger, Ian Goldberg 0001 |
CCS | 2 |
| 2015 | Leading Johnny to Water: Designing for Usability and Trust
Erinn Atwater, Cecylia Bocovich, Urs Hengartner, Ed Lank, Ian Goldberg 0001 |
SOUPS | 5 |
| 2015 | SoK: Secure MessagingabstractMotivated by recent revelations of widespread state surveillance of personal communication, many solutions now claim to offer secure and private messaging. This includes both a large number of new projects and many widely adopted tools that have added security features. The intense pressure in the past two years to deliver solutions quickly has resulted in varying threat models, incomplete objectives, dubious security claims, and a lack of broad perspective on the existing cryptographic literature on secure communication. In this paper, we evaluate and systematize current secure messaging solutions and propose an evaluation framework for their security, usability, and ease-of-adoption properties. We consider solutions from academia, but also identify innovative and promising approaches used "in-the-wild" that are not considered by the academic literature. We identify three key challenges and map the design landscape for each: trust establishment, conversation security, and transport privacy. Trust establishment approaches offering strong security and privacy features perform poorly from a usability and adoption perspective, whereas some hybrid approaches that have not been well studied in the academic literature might provide better trade-offs in practice. In contrast, once trust is established, conversation security can be achieved without any user involvement in most two-party conversations, though conversations between larger groups still lack a good solution. Finally, transport privacy appears to be the most difficult problem to solve without paying significant performance penalties. Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg 0001, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 6 |
| 2015 | DP5: A Private Presence ServiceabstractAbstract Users of social applications like to be notified when their friends are online. Typically, this is done by a central server keeping track of who is online and offline, as well as of all of the users’ “buddy lists”, which contain sensitive information. We present DP5, a cryptographic service that implements online presence indication in a privacy-friendly way. DP5 allows clients to register their online presence and query the presence of their list of friends while keeping this list secret. Besides presence, high-integrity status updates are supported, to facilitate key update and rendezvous protocols. While infrastructure services are required for DP5 to operate, they are designed to not require any long-term secrets and provide perfect forward secrecy in case of compromise. We provide security arguments for the indistinguishability properties of the protocol, as well as an evaluation of its scalability and performance. Nikita Borisov, George Danezis, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2014 | A Systematic Approach to Developing and Evaluating Website Fingerprinting DefensesabstractFingerprinting attacks have emerged as a serious threat against privacy mechanisms, such as SSL, Tor, and encrypting tunnels. Researchers have proposed numerous attacks and defenses, and the Tor project now includes both network- and browser-level defenses against these attacks, but published defenses have high overhead, poor security, or both. Xiang Cai, Rishab Nithyanand, Tao Wang 0012, Rob Johnson 0001, Ian Goldberg 0001 |
CCS | 5 |
| 2014 | PrivEx: Private Collection of Traffic Statistics for Anonymous Communication NetworksabstractIn addition to their common use for private online communication, anonymous communication networks can also be used to circumvent censorship. However, it is difficult to determine the extent to which they are actually used for this purpose without violating the privacy of the networks' users. Knowing this extent can be useful to designers and researchers who would like to improve the performance and privacy properties of the network. To address this issue, we propose a statistical data collection system, PrivEx, for collecting egress traffic statistics from anonymous communication networks in a secure and privacy-preserving manner. Our solution is based on distributed differential privacy and secure multiparty computation; it preserves the security and privacy properties of anonymous communication networks, even in the face of adversaries that can compromise data collection nodes or coerce operators to reveal cryptographic secrets and keys. Tariq Elahi, George Danezis, Ian Goldberg 0001 |
CCS | 3 |
| 2014 | The Best of Both Worlds: Combining Information-Theoretic and Computational PIR for Communication Efficiency
Casey Devet, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 2 |
| 2014 | Effective Attacks and Provable Defenses for Website Fingerprinting
Tao Wang 0012, Xiang Cai, Rishab Nithyanand, Rob Johnson 0001, Ian Goldberg 0001 |
USENIX Security Symposium | 5 |
| 2013 | Batch Proofs of Partial Knowledge
Ryan Henry, Ian Goldberg 0001 |
ACNS | 2 |
| 2013 | PCTCP: per-circuit TCP-over-IPsec transport for anonymous communication overlay networksabstractRecently, there have been several research efforts to design a transport layer that meets the security requirements of anonymous communications while maximizing the network performance experienced by users. In this work, we argue that existing proposals suffer from several performance and deployment issues and we introduce PCTCP, a novel anonymous communication transport design for overlay networks that addresses the shortcomings of the previous proposals. In PCTCP, every overlay path, or circuit, is assigned a separate kernel-level TCP connection that is protected by IPsec, the standard security layer for IP. Mashael Al Sabah, Ian Goldberg 0001 |
CCS | 2 |
| 2013 | One (Block) Size Fits All: PIR and SPIR with Variable-Length Records via Multi-Block Queries
Ryan Henry, Ian Goldberg 0001 |
NDSS | 3 |
| 2013 | The Path Less Travelled: Overcoming Tor's Bottlenecks with Traffic Splitting
Mashael Al Sabah, Kevin S. Bauer, Tariq Elahi, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 4 |
| 2013 | Anonymity and one-way authentication in key exchange protocols
Ian Goldberg 0001, Douglas Stebila, Berkant Ustaoglu |
Des. Codes Cryptogr. | 1 |
| 2013 | Towards Practical Communication in Byzantine-Resistant DHTsabstractThere are several analytical results on distributed hash tables (DHTs) that can tolerate Byzantine faults. Unfortunately, in such systems, operations such as data retrieval and message sending incur significant communication costs. For example, a simple scheme used in many Byzantine fault-tolerant DHT constructions ofnnodes requiresO(log3n) messages; this is likely impractical for real-world applications. The previous best known message complexity isO(log2n) in expectation. However, the corresponding protocol suffers from prohibitive costs owing to hidden constants in the asymptotic notation and setup costs. In this paper, we focus on reducing the communication costs against a computationally bounded adversary. We employ threshold cryptography and distributed key generation to define two protocols, both of which are more efficient than existing solutions. In comparison, our first protocol is deterministic withO(log2n) message complexity, and our second protocol is randomized with expectedO(logn) message complexity. Furthermore, both the hidden constants and setup costs for our protocols are small, and no trusted third party is required. Finally, we present results from microbenchmarks conducted over PlanetLab showing that our protocols are practical for deployment under significant levels of churn and adversarial behavior. Maxwell Young, Aniket Kate, Ian Goldberg 0001, Martin Karsten |
IEEE/ACM Trans. Netw. | 3 |
| 2012 | Enhancing Tor's performance using real-time traffic classificationabstractTor is a low-latency anonymity-preserving network that enables its users to protect their privacy online. It consists of volunteer-operated routers from all around the world that serve hundreds of thousands of users every day. Due to congestion and a low relay-to-client ratio, Tor suffers from performance issues that can potentially discourage its wider adoption, and result in an overall weaker anonymity to all users. Mashael Al Sabah, Kevin S. Bauer, Ian Goldberg 0001 |
CCS | 3 |
| 2012 | Adding query privacy to robust DHTsabstractInterest in anonymous communication over distributed hash tables (DHTs) has increased in recent years. However, almost all known solutions solely aim at achieving sender or requestor anonymity in DHT queries. In many application scenarios, it is crucial that the queried key remains secret from intermediate peers that (help to) route the queries towards their destinations. In this paper, we satisfy this requirement by presenting an approach for providing privacy for the keys in DHT queries. Michael Backes 0001, Ian Goldberg 0001, Aniket Kate, Tomas Toft |
AsiaCCS | 2 |
| 2012 | SkypeMorph: protocol obfuscation for Tor bridgesabstractThe Tor network is designed to provide users with low-latency anonymous communications. Tor clients build circuits with publicly listed relays to anonymously reach their destinations. However, since the relays are publicly listed, they can be easily blocked by censoring adversaries. Consequently, the Tor project envisioned the possibility of unlisted entry points to the Tor network, commonly known as bridges. We address the issue of preventing censors from detecting the bridges by observing the communications between them and nodes in their network. We propose a model in which the client obfuscates its messages to the bridge in a widely used protocol over the Internet. We investigate using Skype video calls as our target protocol and our goal is to make it difficult for the censoring adversary to distinguish between the obfuscated bridge connections and actual Skype calls using statistical comparisons. Hooman Mohajeri Moghaddam, Baiyu Li, Mohammad Derakhshani, Ian Goldberg 0001 |
CCS | 4 |
| 2012 | Provably Secure and Practical Onion RoutingabstractThe onion routing network Tor is undoubtedly the most widely employed technology for anonymous web access. Although the underlying onion routing (OR) protocol appears satisfactory, a comprehensive analysis of its security guarantees is still lacking. This has also resulted in a significant gap between research work on OR protocols and existing OR anonymity analyses. In this work, we address both issues with onion routing by defining a provably secure OR protocol, which is practical for deployment in the next generation Tor network. We start off by presenting a security definition (an ideal functionality) for the OR methodology in the universal compos ability (UC) framework. We then determine the exact security properties required for OR cryptographic primitives (onion construction and processing algorithms, and a key exchange protocol) to achieve a provably secure OR protocol. We show that the currently deployed onion algorithms with slightly strengthened integrity properties can be used in a provably secure OR construction. In the process, we identify the concept of predictably malleable symmetric encryptions, which might be of independent interest. On the other hand, we find the currently deployed key exchange protocol to be inefficient and difficult to analyze and instead show that a recent, significantly more efficient, key exchange protocol can be used in a provably secure OR construction. In addition, our definition greatly simplifies the process of analyzing OR anonymity metrics. We define and prove forward secrecy for the OR protocol, and realize our (white-box) OR definition from an OR black-box model assumed in a recent anonymity analysis. This realization not only makes the analysis formally applicable to the OR protocol but also identifies the exact adversary and network assumptions made by the black box model. Michael Backes 0001, Ian Goldberg 0001, Aniket Kate, Esfandiar Mohammadi |
CSF | 2 |
| 2012 | Optimally Robust Private Information Retrieval
Casey Devet, Ian Goldberg 0001, Nadia Heninger |
USENIX Security Symposium | 2 |
| 2011 | Practical PIR for electronic commerceabstractWe extend Goldberg's multi-server information-theoretic private information retrieval (PIR) with a suite of protocols for privacy-preserving e-commerce. Our first protocol adds support for single-payee tiered pricing, wherein users purchase database records without revealing the indices or prices of those records. Tiered pricing lets the seller set prices based on each user's status within the system; e.g., non-members may pay full price while members may receive a discounted rate. We then extend tiered pricing to support group-based access control lists with record-level granularity; this allows the servers to set access rights based on users' price tiers. Next, we show how to do some basic bookkeeping to implement a novel top-K replication strategy that enables the servers to construct bestsellers lists, which facilitate faster retrieval for these most popular records. Finally, we build on our bookkeeping functionality to support multiple payees, thus enabling several sellers to offer their digital goods through a common database while enabling the database servers to determine to what portion of revenues each seller is entitled. Our protocols maintain user anonymity in addition to query privacy; that is, queries do not leak information about the index or price of the record a user purchases, the price tier according to which the user pays, the user's remaining balance, or even whether the user has ever queried the database before. No other priced PIR or oblivious transfer protocol supports tiered pricing, access control lists, multiple payees, or top-K replication, whereas ours supports all of these features while preserving PIR's sublinear communication complexity. We have implemented our protocols as an add-on to Percy++, an open source implementation of Goldberg's PIR scheme. Measurements indicate that our protocols are practical for deployment in real-world e-commerce applications. Ryan Henry, Femi G. Olumofin, Ian Goldberg 0001 |
CCS | 3 |
| 2011 | DefenestraTor: Throwing Out Windows in Tor
Mashael Al Sabah, Kevin S. Bauer, Ian Goldberg 0001, Dirk Grunwald, Damon McCoy, Stefan Savage, Geoffrey M. Voelker |
PETS | 3 |
| 2011 | Formalizing Anonymous Blacklisting SystemsabstractAnonymous communications networks, such as Tor, help to solve the real and important problem of enabling users to communicate privately over the Internet. However, in doing so, anonymous communications networks introduce an entirely new problem for the service providers - such as websites, IRC networks or mail servers - with which these users interact, in particular, since all anonymous users look alike, there is no way for the service providers to hold individual misbehaving anonymous users accountable for their actions. Recent research efforts have focused on using anonymous blacklisting systems (which are sometimes called anonymous revocation systems) to empower service providers with the ability to revoke access from abusive anonymous users. In contrast to revocable anonymity systems, which enable some trusted third party to deanonymize users, anonymous blacklisting systems provide users with a way to authenticate anonymously with a service provider, while enabling the service provider to revoke access from any users that misbehave, without revealing their identities. In this paper, we introduce the anonymous blacklisting problem and survey the literature on anonymous blacklisting systems, comparing and contrasting the architecture of various existing schemes, and discussing the tradeoffs inherent with each design. The literature on anonymous blacklisting systems lacks a unified set of definitions, each scheme operates under different trust assumptions and provides different security and privacy guarantees. Therefore, before we discuss the existing approaches in detail, we first propose a formal definition for anonymous blacklisting systems, and a set of security and privacy properties that these systems should possess. We also outline a set of new performance requirements that anonymous blacklisting systems should satisfy to maximize their potential for real-world adoption, and give formal definitions for several optional features already supported by some schemes in the literature. Ryan Henry, Ian Goldberg 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2011 | Extending Nymble-like SystemsabstractWe present several extensions to the Nymble framework for anonymous blacklisting systems. First, we show how to distribute the Verinym Issuer as a threshold entity. This provides liveness against a threshold Byzantine adversary and protects against denial-of-service attacks. Second, we describe how to revoke a user for a period spanning multiple link ability windows. This gives service providers more flexibility in deciding how long to block individual users. We also point out how our solution enables efficient blacklist transferability among service providers. Third, we augment the Verinym Acquisition Protocol for Tor-aware systems (that utilize IP addresses as a unique identifier) to handle two additional cases: 1) the operator of a Tor exit node wishes to access services protected by the system, and 2) a user's access to the Verinym Issuer (and the Tor network) is blocked by a firewall. Finally, we revisit the objective blacklisting mechanism used in Jack, and generalize this idea to enable objective blacklisting in other Nymble-like systems. We illustrate the approach by showing how to implement it in Nymble and Nymbler. Ryan Henry, Ian Goldberg 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2011 | PIR-Tor: Scalable Anonymous Communication Using Private Information Retrieval
Prateek Mittal, Femi G. Olumofin, Carmela Troncoso, Nikita Borisov, Ian Goldberg 0001 |
USENIX Security Symposium | 5 |
| 2011 | Telex: Anticensorship in the Network Infrastructure
Eric Wustrow, Scott Wolchok, Ian Goldberg 0001, J. Alex Halderman |
USENIX Security Symposium | 3 |
| 2010 | Constant-Size Commitments to Polynomials and Their Applications
Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
ASIACRYPT | 3 |
| 2010 | An improved algorithm for tor circuit schedulingabstractTor is a popular anonymity-preserving network, consisting of routers run by volunteers all around the world. It protects Internet users' privacy by relaying their network traffic through a series of routers, thus concealing the linkage between the sender and the recipient. Despite the advantage of Tor's anonymizing capabilities, it also brings extra latency, which discourages more users from joining the network. Can Tang, Ian Goldberg 0001 |
CCS | 2 |
| 2010 | Practical Robust Communication in DHTs Tolerating a Byzantine AdversaryabstractThere are several analytical results on distributed hash tables (DHTs) that can tolerate Byzantine faults. Unfortunately, in such systems, operations such as data retrieval and message sending incur significant communication costs. For example, a simple scheme used in many Byzantine fault-tolerant DHT constructions of n nodes requires O(log3n) messages, this is likely impractical for real-world applications. The previous best known message complexity is O(log2n) in expectation, however, the corresponding protocol suffers from prohibitive costs owing to hidden constants in the asymptotic notation and setup costs. In this paper, we focus on reducing the communication costs against a computationally bounded adversary. We employ threshold cryptography and distributed key generation to define two protocols both of which are more efficient than existing solutions. In comparison, our first protocol is deterministic with O(log3n) message complexity and our second protocol is randomized with expected O(log n) message complexity. Further, both the hidden constants and setup costs for our protocols are small and no trusted third party is required. Finally, we present results from micro benchmarks conducted over PlanetLab showing that our protocols are practical for deployment under significant levels of churn and adversarial behaviour. Maxwell Young, Aniket Kate, Ian Goldberg 0001, Martin Karsten |
ICDCS | 3 |
| 2010 | Making a Nymbler Nymble Using VERBS
Ryan Henry, Kevin J. Henry, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 3 |
| 2010 | Privacy-Preserving Queries over Relational Databases
Femi G. Olumofin, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 2 |
| 2010 | Achieving Efficient Query Privacy for Location Based Services
Femi G. Olumofin, Piotr K. Tysowski, Ian Goldberg 0001, Urs Hengartner |
Privacy Enhancing Technologies | 3 |
| 2010 | Pairing-Based Onion Routing with Improved Forward SecrecyabstractThis article presents new protocols for onion routing anonymity networks. We define a provably secure privacy-preserving key agreement scheme in an identity-based infrastructure setting, and use it to design new onion routing circuit constructions. These constructions, based on a user’s selection, offer immediate or eventual forward secrecy at each node in a circuit and require significantly less computation and communication than the telescoping mechanism used by the Tor project. Further, the use of an identity-based infrastructure also leads to a reduction in the required amount of authenticated directory information. Therefore, our constructions provide practical ways to allow onion routing anonymity networks to scale gracefully. Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2009 | A New Message Recognition Protocol with Self-recoverability for Ad Hoc Pervasive Networks
Ian Goldberg 0001, Atefeh Mashatan, Douglas Robert Stinson |
ACNS | 1 |
| 2009 | Multi-party off-the-record messagingabstractMost cryptographic algorithms provide a means for secret and authentic communication. However, under many circumstances, the ability to repudiate messages or deny a conversation is no less important than secrecy and authenticity. For whistleblowers, informants, political dissidents and journalists --- to name a few --- it is most important to have means for deniable conversation, where electronic communication must mimic face-to-face private meetings. Off-the-Record Messaging, proposed in 2004 by Borisov, Goldberg and Brewer, and its subsequent improvements, simulate private two-party meetings. Despite some attempts, the multi-party scenario remains unresolved. Ian Goldberg 0001, Berkant Ustaoglu, Matthew Van Gundy, Hao Chen 0003 |
CCS | 1 |
| 2009 | Distributed Key Generation for the InternetabstractAlthough distributed key generation (DKG) has been studied for some time, it has never been examined outside of the synchronous setting. We present the first realistic DKG architecture for use over the Internet. We propose a practical system model and define an efficient verifiable secret sharing scheme in it. We observe the necessity of Byzantine agreement for asynchronous DKG and analyze the difficulty of using a randomized protocol for it. Using our verifiable secret sharing scheme and a leader-based agreement protocol, we then design a DKG protocol for public-key cryptography. Finally, along with traditional proactive security, we also introduce group modification primitives in our system. Aniket Kate, Ian Goldberg 0001 |
ICDCS | 2 |
| 2009 | Sphinx: A Compact and Provably Secure Mix FormatabstractSphinx is a cryptographic message format used to relay anonymized messages within a mix network. It is more compact than any comparable scheme, and supports a full set of security features: indistinguishable replies, hiding the path length and relay position, as well as providing unlinkability for each leg of the message's journey over the network. We prove the full cryptographic security of Sphinx in the random oracle model, and we describe how it can be used as an efficient drop-in replacement in deployed remailer systems. George Danezis, Ian Goldberg 0001 |
SP | 2 |
| 2009 | Improving Tor using a TCP-over-DTLS Tunnel
Joel Reardon, Ian Goldberg 0001 |
USENIX Security Symposium | 2 |
| 2008 | A user study of off-the-record messagingabstractInstant messaging is a prevalent form of communication across the Internet, yet most instant messaging services provide little security against eavesdroppers or impersonators. There are a variety of existing systems that aim to solve this problem, but the one that provides the highest level of privacy is Off-the-Record Messaging (OTR), which aims to give instant messaging conversations the level of privacy available in a face-to-face conversation. In the most recent redesign of OTR, as well as increasing the security of the protocol, one of the goals of the designers was to make OTR easier to use, without users needing to understand details of computer security such as keys or fingerprints. Ryan Stedman, Kayo Yoshida, Ian Goldberg 0001 |
SOUPS | 3 |
| 2007 | Pairing-Based Onion Routing
Aniket Kate, Gregory M. Zaverucha, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 3 |
| 2007 | Louis, Lester and Pierre: Three Protocols for Location Privacy
Ge Zhong, Ian Goldberg 0001, Urs Hengartner |
Privacy Enhancing Technologies | 2 |
| 2007 | Improving the Robustness of Private Information RetrievalabstractSince 1995, much work has been done creating protocols for private information retrieval (PIR). Many variants of the basic PIR model have been proposed, including such modifications as computational vs. information-theoretic privacy protection, correctness in the face of servers that fail to respond or that respond incorrectly, and protection of sensitive data against the database servers themselves. In this paper, we improve on the robustness of PIR in a number of ways. First, we present a Byzantine-robust PIR protocol which provides information-theoretic privacy protection against coalitions of up to all but one of the responding servers, improving the previous result by a factor of 3. In addition, our protocol allows for more of the responding servers to return incorrect information while still enabling the user to compute the correct result. We then extend our protocol so that queries have information-theoretic protection if a limited number of servers collude, as before, but still retain computational protection if they all collude. We also extend the protocol to provide information-theoretic protection to the contents of the database against collusions of limited numbers of the database servers, at no additional communication cost or increase in the number of servers. All of our protocols retrieve a block of data with communication cost only O(lscr) times the size of the block, where lscr is the number of servers. Finally, we discuss our implementation of these protocols, and measure their performance in order to determine their practicality. Ian Goldberg 0001 |
S&P | 1 |
| 2001 | Intercepting mobile communications: the insecurity of 802.11abstractThe 802.11 standard for wireless networks includes a Wired Equivalent Privacy (WEP) protocol, used to protect link-layer communications from eavesdropping and other attacks. We have discovered several serious security flaws in the protocol, stemming from mis-application of cryptographic primitives. The flaws lead to a number of practical attacks that demonstrate that WEP fails to achieve its security goals. In this paper, we discuss in detail each of the flaws, the underlying security principle violations, and the ensuing attacks. Nikita Borisov, Ian Goldberg 0001, David A. Wagner 0001 |
MobiCom | 2 |
| 2000 | Proofs of Security for the Unix Password Hashing Algorithm
David A. Wagner 0001, Ian Goldberg 0001 |
ASIACRYPT | 2 |
| 1999 | Reaction Attacks against several Public-Key Cryptosystems
Chris Hall, Ian Goldberg 0001, Bruce Schneier |
ICICS | 2 |
| 1996 | A Secure Environment for Untrusted Helper Applications
Ian Goldberg 0001, David A. Wagner 0001, Randi Thomas, Eric A. Brewer |
USENIX Security Symposium | 1 |