On the Security of Rate-limited Privacy Pass

被引:0
|
作者
Chu, Hien [1 ]
Do, Khue [2 ]
Hanzlik, Lucjan [2 ]
机构
[1] Friedrich Alexander Univ Erlangen Nurnberg, Erlangen, Germany
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
Security and Privacy; Cryptography;
D O I
10.1145/3576915.3616619
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The privacy pass protocol allows users to redeem anonymously issued cryptographic tokens instead of solving annoying CAPTCHAs. The issuing authority verifies the credibility of the user, who can later use the pass while browsing the web using an anonymous or virtual private network. Hendrickson et al. proposed an IETF draft (privacy pass-rate-limit-tokens-00) for a rate-limiting version of the privacy pass protocol, also called rate-limited Privacy Pass (RlP). Introducing a new actor called a mediator makes both versions inherently different. The mediator applies access policies to rate-limit users' access to the service while, at the same time, should be oblivious to the website/origin the user is trying to access. In this paper, we formally define the rate-limited Privacy Pass protocol and propose a game-based security model to capture the informal security notions introduced by Hendrickson et al.. We show a construction from simple building blocks that fulfills our security definitions and even allows for a post-quantum secure instantiation. Interestingly, the instantiation proposed in the IETF draft is a specific case of our construction. Thus, we can reuse the security arguments for the generic construction and show that the version used in practice is secure.
引用
收藏
页码:2871 / 2885
页数:15
相关论文
共 50 条
  • [21] Dissolution rate-limited absorption and complete bioavailability of roquinimex in man
    Strandgården, K
    Höglund, P
    Nordle, Ö
    Polacek, J
    Wännman, H
    Gunnarsson, PO
    BIOPHARMACEUTICS & DRUG DISPOSITION, 1999, 20 (07) : 347 - 354
  • [22] Stabilization and regulation of linear systems with saturated and rate-limited actuators
    Saberi, A
    Stoorvogel, AA
    PROCEEDINGS OF THE 1997 AMERICAN CONTROL CONFERENCE, VOLS 1-6, 1997, : 3920 - 3921
  • [23] EFFECTS OF RATE-LIMITED DESORPTION ON THE FEASIBILITY OF IN-SITU BIOREMEDIATION
    FRY, VA
    ISTOK, JD
    WATER RESOURCES RESEARCH, 1994, 30 (08) : 2413 - 2422
  • [24] Mathematical modeling of rate-limited transport and biotransformation in the vadose zone
    Rathfelder, KM
    Lang, JR
    Abriola, LM
    COMPUTATIONAL METHODS IN WATER RESOURCES XI, VOL 1: COMPUTATIONAL METHODS IN SUBSURFACE FLOW AND TRANSPORT PROBLEMS, 1996, : 135 - 144
  • [25] The State-Dependent Channel with a Rate-Limited Cribbing Helper
    Lapidoth, Amos
    Steinberg, Yossef
    ENTROPY, 2024, 26 (07)
  • [26] RATE-DISTORTION WITH COMMON RATE-LIMITED SIDE INFORMATION TO THE ENCODER AND DECODER
    Permuter, Haim
    Steinberg, Yossi
    Weissman, Tsachy
    2008 IEEE 25TH CONVENTION OF ELECTRICAL AND ELECTRONICS ENGINEERS IN ISRAEL, VOLS 1 AND 2, 2008, : 777 - 779
  • [27] An analysis of the destabilizing effect of daisy chained rate-limited actuators
    Berg, JM
    Hammett, KD
    Schwartz, CA
    Banda, SS
    IEEE TRANSACTIONS ON CONTROL SYSTEMS TECHNOLOGY, 1996, 4 (02) : 171 - 176
  • [28] Achievable Rate Regions for Cooperative Relay Broadcast Channels with Rate-limited Feedback
    Wu, Youlong
    2016 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY, 2016, : 1660 - 1664
  • [29] Achievable Error Exponents in the Gaussian Channel With Rate-Limited Feedback
    Mirghaderi, Reza
    Goldsmith, Andrea
    Weissman, Tsachy
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2013, 59 (12) : 8144 - 8156
  • [30] USE OF A RATE-LIMITED ULTRAFILTRATION CIRCUIT WITH CENTRIFUGAL VENTRICULAR ASSIST
    CURTIS, JJ
    DEESE, LR
    WALLS, JT
    BOLEY, TM
    ARTIFICIAL ORGANS, 1994, 18 (06) : 465 - 466