Abstract:
this paper we introduce a system called Crowds for protecting users' anonymity on the world-wide-web. Crowds, named for the notion of "blending into a crowd," operates by grouping users into a large and geographically diverse group (crowd) that collectively issues requests on behalf of its members. Web servers are unable to learn the true source of a request because it is equally likely to have originated from any member of the crowd, and even collaborating crowd members cannot distinguish the originator of a request from a member who is merely forwarding the request on behalf of another. We describe the design, implementation, security, performance, and scalability of our system. Our security analysis introduces degrees of anonymity as an important tool for describing and proving anonymity properties.
Citations
|
1876
|
New directions in cryptogra-phy
– Diffie, Hellman
- 1976
|
|
1309
|
Randomized algorithms
– Motwani, Raghavan
- 1995
|
|
809
|
Untraceable electronic mail, return addresses, and digital pseudonyms
– Chaum
- 1981
|
|
257
|
Fail-Stop Processors: an Approach to Designing Faulttolerant
– Schlichting, Schneider
- 1983
|
|
173
|
Anonymous connections and onion routing
– Syverson, Goldschlag, et al.
- 1997
|
|
169
|
Firewalls and Internet Security: Repelling the Wily Hacker
– Cheswick, Bellovin
- 1994
|
|
153
|
Using process groups to implement failure detection in asynchronous environments
– Ricciardi, Birman
- 1991
|
|
125
|
Mixing E-mail with Babel
– Gülcü, Tsudik
- 1996
|
|
123
|
Reaching agreement on processor group membership in synchronous distributed systems
– Cristian
- 1991
|
|
82
|
ISDNmixes: Untraceable communication with very small bandwidth overhead
– Pfitzmann, Pfitzmann, et al.
- 1991
|
|
68
|
Intrusion Tolerance in Distributed Computing Systems
– Deswarte, Blain, et al.
- 1991
|
|
68
|
A Secure Group Membership Protocol
– Reiter
- 1996
|
|
59
|
How to make personalized web browsing simple, secure, and anonymous
– Gabber, Gibbons, et al.
|
|
43
|
Increasing Availability and Security of an Authentication Service
– Gong
- 1993
|
|
41
|
Network without User Observability
– Pfitzmann, Waidner
- 1987
|
|
38
|
Distributing trust with the Rampart Toolkit
– Reiter
- 1996
|
|
32
|
A Pfitzmann. How to break the direct rsa-implementation of mixes
– Pfitzmann
- 1989
|
|
28
|
Membership algorithms for asynchronous distributed systems
– Moser, Melliar-Smith, et al.
- 1991
|
|
25
|
Renesse, A Security Architecture for Fault-Tolerant Systems
– Reiter, Birman, et al.
- 1993
|
|
7
|
Web Security and Commerce. O’Reilly and Associates
– Garfinkel
- 1997
|
|
5
|
How to keep your privacy: Battle lines get clearer
– Brier
- 1997
|
|
5
|
Mixing e-mail with
– Gulcu, Tsudik
- 1996
|
|
2
|
The SSL protocol. Internet draft drafthickman -netscape-ssl-01.txt
– Hickman, Elgamal
- 1995
|
|
1
|
No solitude in cyberspace
– Miller
- 1997
|
|
1
|
Crowds: Anonymity for Web Transactions • 91
– BRIER
- 1997
|
|
1
|
and Taher Elgamal.The SSL Protocol. Internet draft draft-hickman-netscapessl -01.txt
– Hickman
- 1995
|