论文标题

在我的朋友的一点帮助下:即时消息传递的运输可否认性

With a Little Help from My Friends: Transport Deniability for Instant Messaging

论文作者

Nelson, Boel, Askarov, Aslan

论文摘要

即时消息传递(IM)应用程序的流量分析继续构成重要的隐私挑战。特别是,运输级数据可能会泄露有关IM的无意信息 - 例如与谁交流。现有的用于元数据隐私的工具具有采用障碍,包括因安装特定应用程序而受到审查的风险以及与移动设备不相容的性能开销。 我们认为,对流量分析的韧性必须由主要IM服务本身直接支持,并且必须以低成本的方式进行,而不会破坏现有功能。作为朝这个方向发展的第一步,我们提出了一个结合了常规和拒绝消息的混合消息模型。我们为拒绝即时消息传递提供了一种新颖的协议,我们称之为牛仔布。牛仔布是建立在以下原则的基础上,即在用户朋友的一些帮助下,可以与常规消息无法区分拒绝消息。然后可以通过合理的封面故事来解释可拒绝消息的网络流量。牛仔布与发送的消息成正比,而不是按时间或用户数量扩展。为了显示牛仔布的有效性,我们实施了痕量模拟器,并表明牛仔布对互联网服务提供商等强大对手的可否认性保证。

Traffic analysis for instant messaging (IM) applications continues to pose an important privacy challenge. In particular, transport-level data can leak unintentional information about IM -- such as who communicates with whom. Existing tools for metadata privacy have adoption obstacles, including the risks of being scrutinized for having a particular app installed, and performance overheads incompatible with mobile devices. We posit that resilience to traffic analysis must be directly supported by major IM services themselves, and must be done in a low-cost manner without breaking existing features. As a first step in this direction, we propose a hybrid messaging model that combines regular and deniable messages. We present a novel protocol for deniable instant messaging, which we call DenIM. DenIM is built on the principle that deniable messages can be made indistinguishable from regular messages with a little help from a user's friends. Deniable messages' network traffic can then be explained by a plausible cover story. DenIM achieves overhead proportional to the messages sent, as opposed to scaling with time or number of users. To show the effectiveness of DenIM, we implement a trace simulator, and show that DenIM's deniability guarantees hold against strong adversaries such as internet service providers.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源