Michael J. Freedman

dblp:65/1370 · DBLP profile ↗
← Back
60ranked-venue papers
8as first author
4since 2021 · last 2025
0000-0002-5305-2395ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 24 · 4 first-authorSystems, architecture and hardware · 15 · 4 since 2021Security and privacy · 12 · 4 first-authorSoftware engineering, systems software and programming languages · 8 · 2 since 2021Theory of computation · 2 · 1 first-authorArtificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Fusion: An Analytics Object Store Optimized for Query Pushdown
abstract
The prevalence of disaggregated storage in public clouds has led to increased latency in modern OLAP cloud databases, particularly when handling ad-hoc and highly-selective queries on large objects. To address this, cloud databases have adopted computation pushdown, executing query predicates closer to the storage layer. However, existing pushdown solutions are inefficient in erasure-coded storage. Cloud storage employs erasure coding that partitions analytics file objects into fixed-sized blocks and distributes them across storage nodes. Consequently, when a specific part of the object is queried, the storage system must reassemble the object across nodes, incurring significant network latency.
Jianan Lu, Ashwini Raina, Asaf Cidon, Michael J. Freedman
ASPLOS (1)4
2023 Efficient Compactions between Storage Tiers with PrismDB
abstract
In recent years, emerging storage hardware technologies have focused on divergent goals: better performance or lower cost-per-bit. Correspondingly, data systems that employ these technologies are typically optimized either to be fast (but expensive) or cheap (but slow). We take a different approach: by architecting a storage engine to natively utilize two tiers of fast and low-cost storage technologies, we can achieve a Pareto efficient balance between performance and cost-per-bit.
Ashwini Raina, Jianan Lu, Asaf Cidon, Michael J. Freedman
ASPLOS (3)4
2023 VectorVisor: A Binary Translation Scheme for Throughput-Oriented GPU Acceleration
Samuel Ginzburg, Mohammad Shahrad, Michael J. Freedman
USENIX ATC3
2022 Speculative Recovery: Cheap, Highly Available Fault Tolerance with Disaggregated Storage
Nanqinqin Li, Anja Kalaba, Michael J. Freedman, Wyatt Lloyd, Amit Levy 0001
USENIX ATC3
2019 ReLAQS: Reducing Latency for Multi-Tenant Approximate Queries via Scheduling
abstract
Approximate Query Processing has become increasingly popular as larger data sizes have increased query latency in distributed query processing systems. To provide such approximate results, systems return intermediate results and iteratively update these approximations as they process more data. In shared clusters, however, these systems waste resources by directing resources to queries that are no longer improving the results given to users.
Logan Stafman, Andrew Or, Michael J. Freedman
Middleware3
2019 Who's Afraid of Uncorrectable Bit Errors? Online Recovery of Flash Errors with Distributed Redundancy
Amy Tai, Andrew Kryczka, Shobhit O. Kanaujia, Kyle Jamieson, Michael J. Freedman, Asaf Cidon
USENIX ATC5
2018 Riffle: optimized shuffle service for large-scale data analytics
abstract
The rapidly growing size of data and complexity of analytics present new challenges for large-scale data processing systems. Modern systems keep data partitions in memory for pipelined operators, and persist data across stages with wide dependencies on disks for fault tolerance. While processing can often scale well by splitting jobs into smaller tasks for better parallelism, all-to-all data transfer---called shuffle operations---become the scaling bottleneck when running many small tasks in multi-stage data analytics jobs. Our key observation is that this bottleneck is due to the superlinear increase in disk I/O operations as data volume increases.
Ergin Seyfe, Avery Ching, Michael J. Freedman
EuroSys5
2017 SLAQ: quality-driven scheduling for distributed machine learning
abstract
Training machine learning (ML) models with large datasets can incur significant resource contention on shared clusters. This training typically involves many iterations that continually improve the quality of the model. Yet in exploratory settings, better models can be obtained faster by directing resources to jobs with the most potential for improvement. We describe SLAQ, a cluster scheduling system for approximate ML training jobs that aims to maximize the overall job quality.
Logan Stafman, Andrew Or, Michael J. Freedman
SoCC4
2017 vCorfu: A Cloud-Scale Object Store on a Shared Log
Michael Wei, Amy Tai, Christopher J. Rossbach, Ittai Abraham, Maithem Munshed, Medhavi Dhawan, Jim Stabile, Udi Wieder, Scott Fritchie, Steven Swanson, Michael J. Freedman, Dahlia Malkhi
NSDI11
2017 Live Video Analytics at Scale with Approximation and Delay-Tolerance
Ganesh Ananthanarayanan, Peter Bodík, Matthai Philipose, Paramvir Bahl, Michael J. Freedman
NSDI6
2017 Hyperbolic Caching: Flexible Caching for Web Applications
Aaron Blankstein, Siddhartha Sen 0001, Michael J. Freedman
USENIX ATC3
2016 Be Fast, Cheap and in Control with SwitchKV
Raghav Sethi, Michael Kaminsky, David G. Andersen, Michael J. Freedman
NSDI5
2016 Blockstack: A Global Naming and Storage System Secured by Blockchains
Muneeb Ali, Jude C. Nelson, Ryan Shea, Michael J. Freedman
USENIX ATC4
2016 Replex: A Scalable, Highly Available Multi-Index Data Store
Amy Tai, Michael Wei, Michael J. Freedman, Ittai Abraham, Dahlia Malkhi
USENIX ATC3
2016 Efficient Set Intersection with Simulation-Based Security
Michael J. Freedman, Carmit Hazay, Kobbi Nissim, Benny Pinkas
J. Cryptol.1
2015 CONIKS: Bringing Key Transparency to End Users
Marcela S. Melara, Aaron Blankstein, Joseph Bonneau, Edward W. Felten, Michael J. Freedman
USENIX Security Symposium5
2014 Algorithmic improvements for fast concurrent Cuckoo hashing
abstract
Fast concurrent hash tables are an increasingly important building block as we scale systems to greater numbers of cores and threads. This paper presents the design, implementation, and evaluation of a high-throughput and memory-efficient concurrent hash table that supports multiple readers and writers. The design arises from careful attention to systems-level optimizations such as minimizing critical section length and reducing interprocessor coherence traffic through algorithm re-engineering. As part of the architectural basis for this engineering, we include a discussion of our experience and results adopting Intel's recent hardware transactional memory (HTM) support to this critical building block. We find that naively allowing concurrent access using a coarse-grained lock on existing data structures reduces overall performance with more threads. While HTM mitigates this slowdown somewhat, it does not eliminate it. Algorithmic optimizations that benefit both HTM and designs for fine-grained locking are needed to achieve high performance.
David G. Andersen, Michael Kaminsky, Michael J. Freedman
EuroSys4
2014 From application requests to virtual IOPs: provisioned key-value storage with Libra
abstract
Achieving predictable performance in shared cloud storage services is hard. Tenants want reservations in terms of system-wide application-level throughput, but the provider must ultimately deal with low-level IO resources at each storage node where contention arises. Such a guarantee has thus proven elusive, due to the complexities inherent to modern storage stacks: non-uniform IO amplification, unpredictable IO interference, and non-linear IO performance.
David Shue, Michael J. Freedman
EuroSys2
2014 Aggregation and Degradation in JetStream: Streaming Analytics in the Wide Area
Ariel Rabkin, Matvey Arye, Siddhartha Sen 0001, Vivek S. Pai, Michael J. Freedman
NSDI5
2014 Automating Isolation and Least Privilege in Web Services
abstract
In many client-facing applications, a vulnerability in any part can compromise the entire application. This paper describes the design and implementation of Passe, a system that protects a data store from unintended data leaks and unauthorized writes even in the face of application compromise. Passe automatically splits (previously shared-memory-space) applications into sandboxed processes. Passe limits communication between those components and the types of accesses each component can make to shared storage, such as a backend database. In order to limit components to their least privilege, Passe uses dynamic analysis on developer-supplied end-to-end test cases to learn data and control-flow relationships between database queries and previous query results, and it then strongly enforces those relationships. Our prototype of Passe acts as a drop-in replacement for the Django web framework. By running eleven unmodified, off-the-shelf applications in Passe, we demonstrate its ability to provide strong security guarantees-Passe correctly enforced 96% of the applications' policies-with little additional overhead. Additionally, in the web-specific setting of the prototype, we also mitigate the cross-component effects of cross-site scripting (XSS) attacks by combining browser HTML5 sandboxing techniques with our automatic component separation.
Aaron Blankstein, Michael J. Freedman
IEEE Symposium on Security and Privacy2
2013 Scaling IP multicast on datacenter topologies
abstract
IP multicast would reduce significantly both network and server overhead for many datacenter applications' communication. Unfortunately, traditional protocols for managing IP multicast, designed for arbitrary network topologies, do not scale with aggregate hardware resources in the number of supported multicast groups. Prior attempts to scale multicast in general settings are all bottlenecked by the forwarding table capacity of a single switch.
Michael J. Freedman
CoNEXT2
2013 Scalable, optimal flow routing in datacenters via local link balancing
abstract
Datacenter networks should support high network utilization. Yet today's routing is typically load agnostic, so large flows can starve other flows if routed through overutilized links. Even recent proposals like centralized scheduling or end-host multi-pathing give suboptimal throughput, and they suffer from poor scalability and other limitations.
Siddhartha Sen 0001, David Shue, Sunghwan Ihm, Michael J. Freedman
CoNEXT4
2013 Making Every Bit Count in Wide-Area Analytics
Ariel Rabkin, Matvey Arye, Siddhartha Sen 0001, Vivek S. Pai, Michael J. Freedman
HotOS5
2013 Stronger Semantics for Low-Latency Geo-Replicated Storage
Wyatt Lloyd, Michael J. Freedman, Michael Kaminsky, David G. Andersen
NSDI2
2012 Unsupervised Conversion of 3D Models for Interactive Metaverses
abstract
A virtual-world environment becomes a truly engaging platform when users have the ability to insert 3D content into the world. However, arbitrary 3D content is often not optimized for real-time rendering, limiting the ability of clients to display large scenes consisting of hundreds or thousands of objects. We present the design and implementation of an automatic, unsupervised conversion process that transforms 3D content into a format suitable for real-time rendering while minimizing loss of quality. The resulting progressive format includes a base mesh, allowing clients to quickly display the model, and a progressive portion for streaming additional detail as desired. Sirikata, an open virtual world platform, has processed over 700 models using this method.
Jeff Terrace, Ewen Cheslack-Postava, Philip Alexander Levis, Michael J. Freedman
ICME4
2012 A formally-verified migration protocol for mobile, multi-homed hosts
abstract
Modern consumer devices, like smartphones and tablets, have multiple interfaces (e.g., WiFi and 4G) that attach to new access points as users move. These mobile, multi-homed computers are a poor match with an Internet architecture that binds connections to fixed endpoints with topology-dependent addresses. As a result, hosts typically cannot spread a connection over multiple interfaces or paths, or change locations without breaking existing connections. In this paper, we create an end-to-end connection control protocol (ECCP) that allows hosts to communicate over multiple interfaces with dynamically-changing IP addresses and works with multiple data-delivery protocols (i.e., reliable or unreliable transport). Each ECCP connection consists of one or more flows, each associated with an interface or path. Through end-to-end signaling, a host can move an existing flow from one interface to another, or change its IP address, without any support from the underlying network. We develop formal models to verify that ECCP works correctly in the presence of packet loss, out-of-order delivery, and frequent mobility, and to identify bugs and design limitations in earlier mobility protocols.
Matvey Arye, Erik Nordström, Robert Kiefer, Jennifer Rexford, Michael J. Freedman
ICNP5
2012 Scalable Inference of Overlapping Communities
abstract
We develop a scalable algorithm for posterior inference of overlapping communities in large networks. Our algorithm is based on stochastic variational inference in the mixed-membership stochastic blockmodel. It naturally interleaves subsampling the network with estimating its community structure. We apply our algorithm on ten large, real-world networks with up to 60,000 nodes. It converges several orders of magnitude faster than the state-of-the-art algorithm for MMSB, finds hundreds of communities in large real-world networks, and detects the true communities in 280 benchmark networks with equal or better accuracy compared to other scalable algorithms.
Prem Gopalan, David M. Mimno, Sean Gerrish, Michael J. Freedman, David M. Blei
NIPS4
2012 Serval: An End-Host Stack for Service-Centric Networking
Erik Nordström, David Shue, Prem Gopalan, Robert Kiefer, Matvey Arye, Steven Y. Ko, Jennifer Rexford, Michael J. Freedman
NSDI8
2012 Performance Isolation and Fairness for Multi-Tenant Cloud Storage
David Shue, Michael J. Freedman, Anees Shaikh
OSDI2
2012 A Scalable Server for 3D Metaverses
Ewen Cheslack-Postava, Tahir Azim, Behram F. T. Mistree, Daniel Reiter Horn, Jeff Terrace, Philip Alexander Levis, Michael J. Freedman
USENIX ATC7
2012 Social Networking with Frientegrity: Privacy and Integrity with an Untrusted Provider
Ariel J. Feldman, Aaron Blankstein, Michael J. Freedman, Edward W. Felten
USENIX Security Symposium3
2011 Coercing clients into facilitating failover for object delivery
abstract
Application-level protocols used for object delivery, such as HTTP, are built atop TCP/IP and inherit its host-to-host abstraction. Given that these services are replicated for scalability, this unnecessarily exposes failures of individual servers to their clients. While changes to both client and server applications can be used to mask such failures, this paper explores the feasibility of transparent recovery for unmodified object delivery services (TRODS). The key insight in TRODS is cross-layer visibility and control: TRODS carefully derives reliable storage for application-level state from the mechanics of the transport layer. This state is used to reconstruct object delivery sessions, which are then transparently spliced into the client's ongoing connection. TRODS is fully backwards-compatible, requiring no changes to the clients or server applications. Its performance is competitive with unmodified HTTP services, providing nearly identical throughput while enabling timely failover.
Wyatt Lloyd, Michael J. Freedman
DSN2
2011 Frenetic: a network programming language
abstract
Modern networks provide a variety of interrelated services including routing, traffic monitoring, load balancing, and access control. Unfortunately, the languages used to program today's networks lack modern features - they are usually defined at the low level of abstraction supplied by the underlying hardware and they fail to provide even rudimentary support for modular programming. As a result, network programs tend to be complicated, error-prone, and difficult to maintain.
Nate Foster, Rob Harrison, Michael J. Freedman, Christopher Monsanto, Jennifer Rexford, Alec Story, David Walker 0001
ICFP3
2011 Going viral: flash crowds in an open CDN
abstract
Handling flash crowds poses a difficult task for web services. Content distribution networks (CDNs), hierarchical web caches, and peer-to-peer networks have all been proposed as mechanisms for mitigating the effects of these sudden spikes in traffic to under-provisioned origin sites. Other than a few anecdotal examples of isolated events to a single server, however, no large-scale analysis of flash-crowd behavior has been published to date.
Patrick Wendell, Michael J. Freedman
Internet Measurement Conference2
2011 Don't settle for eventual: scalable causal consistency for wide-area storage with COPS
abstract
Geo-replicated, distributed data stores that support complex online applications, such as social networks, must provide an "always-on" experience where operations always complete with low latency. Today's systems often sacrifice strong consistency to achieve these goals, exposing inconsistencies to their clients and necessitating complex application logic. In this paper, we identify and define a consistency model---causal consistency with convergent conflict handling, or causal+---that is the strongest achieved under these constraints.
Wyatt Lloyd, Michael J. Freedman, Michael Kaminsky, David G. Andersen
SOSP2
2011 Brief Announcement: Bridging the Theory-Practice Gap in Multi-commodity Flow Routing
Siddhartha Sen 0001, Sunghwan Ihm, Kay Ousterhout, Michael J. Freedman
DISC4
2011 Bilateral and Multilateral Exchanges for Peer-Assisted Content Distribution
abstract
Users of the BitTorrent file-sharing protocol and its variants are incentivized to contribute their upload capacity in a bilateral manner: Downloading is possible in return for uploading to the same user. An alternative is to use multilateral exchange to match user demand for content to available supply at other users in the system. We provide a formal comparison of peer-to-peer system designs based on bilateral exchange with those that enable multilateral exchange via a price-based market mechanism to match supply and demand. First, we compare the two types of exchange in terms of the equilibria that arise. A multilateral equilibrium allocation is Pareto-efficient, while we demonstrate that bilateral equilibrium allocations are not Pareto-efficient in general. We show that Pareto efficiency represents the “gap” between bilateral and multilateral equilibria: A bilateral equilibrium allocation corresponds to a multilateral equilibrium allocation if and only if it is Pareto-efficient. Our proof exploits the fact that Pareto efficiency implies reversibility of an appropriately constructed Markov chain. Second, we compare the two types of exchange through the expected percentage of users that can trade in a large system, assuming a fixed file popularity distribution. Our theoretical results as well as analysis of a BitTorrent dataset provide quantitative insight into regimes where bilateral exchange may perform quite well even though it does not always give rise to Pareto-efficient equilibrium allocations.
Christina Aperjis, Ramesh Johari, Michael J. Freedman
IEEE/ACM Trans. Netw.3
2010 Experiences with CoralCDN: A Five-Year Operational View
Michael J. Freedman
NSDI1
2010 Prophecy: Using History for High-Throughput Fault Tolerance
Siddhartha Sen 0001, Wyatt Lloyd, Michael J. Freedman
NSDI3
2010 SPORC: Group Collaboration using Untrusted Cloud Resources
Ariel J. Feldman, William P. Zeller, Michael J. Freedman, Edward W. Felten
OSDI3
2010 Collaborative, Privacy-Preserving Data Aggregation at Scale
Benny Applebaum, Haakon Ringberg, Michael J. Freedman, Matthew Caesar 0001, Jennifer Rexford
Privacy Enhancing Technologies3
2010 DONAR: decentralized server selection for cloud services
abstract
Geo-replicated services need an effective way to direct client requests to a particular location, based on performance, load, and cost. This paper presents DONAR, a distributed system that can offload the burden of replica selection, while providing these services with a sufficiently expressive interface for specifying mapping policies. Most existing approaches for replica selection rely on either central coordination (which has reliability, security, and scalability limitations) or distributed heuristics (which lead to suboptimal request distributions, or even instability). In contrast, the distributed mapping nodes in DONAR run a simple, efficient algorithm to coordinate their replica-selection decisions for clients. The protocol solves an optimization problem that jointly considers both client performance and server load, allowing us to show that the distributed algorithm is stable and effective. Experiments with our DONAR prototype--providing replica selection for CoralCDN and the Measurement Lab--demonstrate that our algorithm performs well "in the wild." Our prototype supports DNS- and HTTP-based redirection, IP anycast, and a secure update protocol, and can handle many customer services with diverse policy objectives.
Patrick Wendell, Wenjie Jiang 0001, Michael J. Freedman, Jennifer Rexford
SIGCOMM3
2010 Scalable flow-based networking with DIFANE
abstract
Ideally, enterprise administrators could specify fine-grain policies that drive how the underlying switches forward, drop, and measure traffic. However, existing techniques for flow-based networking rely too heavily on centralized controller software that installs rules reactively, based on the first packet of each flow. In this paper, we propose DIFANE, a scalable and efficient solution that keeps all traffic in the data plane by selectively directing packets through intermediate switches that store the necessary rules. DIFANE relegates the controller to the simpler task of partitioning these rules over the switches. DIFANE can be readily implemented with commodity switch hardware, since all data-plane functions can be expressed in terms of wildcard rules that perform simple actions on matching packets. Experiments with our prototype on Click-based OpenFlow switches show that DIFANE scales to larger networks with richer policies.
Minlan Yu, Jennifer Rexford, Michael J. Freedman, Jia Wang 0001
SIGCOMM3
2009 Comparing multilateral and bilateral exchange models for content distribution
abstract
Users of peer-to-peer systems are often incentivized to contribute their upload capacity in a bilateral manner: downloading is possible in return for uploading to the same peer (e.g., BitTorrent). An alternative is to use multilateral exchange to match user demand for content to available supply at other peers in the system. Multilateral exchange can be enabled through prices and a virtual currency. Monetary incentives have been previously proposed to incentivize uploading in P2P systems. We provide a formal comparison of P2P system designs based on bilateral exchange with those that enable multilateral exchange via a price-based market mechanism to match supply and demand.
Christina Aperjis, Michael J. Freedman, Ramesh Johari
ITW2
2009 Object Storage on CRAQ: High-Throughput Chain Replication for Read-Mostly Workloads
Jeff Terrace, Michael J. Freedman
USENIX ATC2
2009 Rethinking enterprise network control
Martín Casado, Michael J. Freedman, Justin Pettit, Jianying Luo, Natasha Gude, Nick McKeown, Scott Shenker
IEEE/ACM Trans. Netw.2
2008 Peer-assisted content distribution with prices
abstract
Peer-assisted content distribution matches user demand for content with available supply at other peers in the network. Inspired by this supply-and-demand interpretation of the nature of content sharing, we employ price theory to study peer-assisted content distribution. The market-clearing prices are those which align supply and demand, and the system is studied through the characterization of price equilibria. We discuss the efficiency and robustness gains of price-based multilateral exchange, and show that simply maintaining a single price per peer (even across multiple files) suffices to achieve these benefits.
Christina Aperjis, Michael J. Freedman, Ramesh Johari
CoNEXT2
2007 Peering Through the Shroud: The Effect of Edge Opacity on IP-Based Client Identification
Martín Casado, Michael J. Freedman
NSDI2
2007 Ethane: taking control of the enterprise
abstract
This paper presents Ethane, a new network architecture for the enterprise. Ethane allows managers to define a single network-wide fine-grain policy, and then enforces it directly. Ethane couples extremely simple flow-based Ethernet switches with a centralized controller that manages the admittance and routing of flows. While radical, this design is backwards-compatible with existing hosts and switches.
Martín Casado, Michael J. Freedman, Justin Pettit, Jianying Luo, Nick McKeown, Scott Shenker
SIGCOMM2
2006 OASIS: Anycast for Any Service
Michael J. Freedman, Karthik Lakshminarayanan, David Mazières
NSDI1
2006 RE: Reliable Email
Scott Garriss, Michael Kaminsky, Michael J. Freedman, Brad Karp, David Mazières
NSDI3
2006 SANE: A Protection Architecture for Enterprise Networks
Martín Casado, Tal Garfinkel, Aditya Akella, Michael J. Freedman, Dan Boneh, Nick McKeown
USENIX Security Symposium4
2005 Geographic Locality of IP Prefixes
Michael J. Freedman, Mythili Vutukuru, Nick Feamster, Hari Balakrishnan
Internet Measurement Conference1
2005 Shark: Scaling File Servers via Cooperative Caching
Siddhartha Annapureddy, Michael J. Freedman, David Mazières
NSDI2
2005 Keyword Search and Oblivious Pseudorandom Functions
Michael J. Freedman, Yuval Ishai, Benny Pinkas, Omer Reingold
TCC1
2004 Versatile padding schemes for joint signature and encryption
abstract
We propose several highly-practical and optimized constructions for joint signature and encryption primitives often referred to as signcryption. All our signcryption schemes, built directly from trapdoor permutations such as RSA, share features such as simplicity, efficiency, generality, near-optimal exact security, flexible and ad-hoc key management, key reuse for sending/receiving data, optimally-low message expansion, "backward" use for plain signature/encryption, long message and associated data support, the strongest-known qualitative security and, finally, complete compatibility with the PKCS#1 infrastructure.
Yevgeniy Dodis, Michael J. Freedman, Stanislaw Jarecki, Shabsi Walfish
CCS2
2004 Efficient Private Matching and Set Intersection
Michael J. Freedman, Kobbi Nissim, Benny Pinkas
EUROCRYPT1
2004 Democratizing Content Publication with Coral
Michael J. Freedman, Eric Freudenthal, David Mazières
NSDI1
2004 On-the-Fly Verification of Rateless Erasure Codes for Efficient Content Distribution
abstract
The quality of peer-to-peer content distribution can suffer when malicious participants intentionally corrupt content. Some systems using simple block-by-block downloading can verify blocks with traditional cryptographic signatures and hashes, but these techniques do not apply well to more elegant systems that use rateless erasure codes for efficient multicast transfers. This paper presents a practical scheme, based on homomorphic hashing, that enables a downloader to perform on-the-fly verification of erasure-encoded blocks.
Maxwell N. Krohn, Michael J. Freedman, David Mazières
S&P2
2002 Tarzan: a peer-to-peer anonymizing network layer
abstract
Tarzan is a peer-to-peer anonymous IP network overlay. Because it provides IP service, Tarzan is general-purpose and transparent to applications. Organized as a decentralized peer-to-peer overlay, Tarzan is fault-tolerant, highly scalable, and easy to manage.Tarzan achieves its anonymity with layered encryption and multi-hop routing, much like a Chaumian mix. A message initiator chooses a path of peers pseudo-randomly through a restricted topology in a way that adversaries cannot easily influence. Cover traffic prevents a global observer from using traffic analysis to identify an initiator. Protocols toward unbiased peer-selection offer new directions for distributing trust among untrusted entities.Tarzan provides anonymity to either clients or servers, without requiring that both participate. In both cases, Tarzan uses a network address translator (NAT) to bridge between Tarzan hosts and oblivious Internet hosts.Measurements show that Tarzan imposes minimal overhead over a corresponding non-anonymous overlay route.
Michael J. Freedman, Robert Morris 0005
CCS1