On the Security of Rate-limited Privacy Pass

被引:0
|
作者
Chu, Hien [1 ]
Do, Khue [2 ]
Hanzlik, Lucjan [2 ]
机构
[1] Friedrich Alexander Univ Erlangen Nurnberg, Erlangen, Germany
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
Security and Privacy; Cryptography;
D O I
10.1145/3576915.3616619
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The privacy pass protocol allows users to redeem anonymously issued cryptographic tokens instead of solving annoying CAPTCHAs. The issuing authority verifies the credibility of the user, who can later use the pass while browsing the web using an anonymous or virtual private network. Hendrickson et al. proposed an IETF draft (privacy pass-rate-limit-tokens-00) for a rate-limiting version of the privacy pass protocol, also called rate-limited Privacy Pass (RlP). Introducing a new actor called a mediator makes both versions inherently different. The mediator applies access policies to rate-limit users' access to the service while, at the same time, should be oblivious to the website/origin the user is trying to access. In this paper, we formally define the rate-limited Privacy Pass protocol and propose a game-based security model to capture the informal security notions introduced by Hendrickson et al.. We show a construction from simple building blocks that fulfills our security definitions and even allows for a post-quantum secure instantiation. Interestingly, the instantiation proposed in the IETF draft is a specific case of our construction. Thus, we can reuse the security arguments for the generic construction and show that the version used in practice is secure.
引用
收藏
页码:2871 / 2885
页数:15
相关论文
共 50 条
  • [41] Optimal switching between targets using rate-limited slews
    Tanygin, Sergei
    Woodburn, James
    ASTRODYNAMICS 2005, VOL 123, PTS 1-3, 2006, 123 : 1235 - +
  • [42] Implications of rate-limited mass transfer for aquifer storage and recovery
    Culkin, Sean L.
    Singha, Kamini
    Day-Lewis, Frederick D.
    GROUND WATER, 2008, 46 (04) : 591 - 605
  • [43] The Secrecy Capacity of Gaussian Wiretap Channels with Rate-Limited Help at the Encoder
    Loyka, Sergey
    Merhav, Neri
    2023 IEEE INFORMATION THEORY WORKSHOP, ITW, 2023, : 198 - 202
  • [44] A STUDY OF THE DISSOLUTION RATE-LIMITED BIOREMEDIATION OF SOILS CONTAMINATED BY RESIDUAL HYDROCARBONS
    YANG, XQ
    ERICKSON, LE
    FAN, LT
    JOURNAL OF HAZARDOUS MATERIALS, 1995, 41 (2-3) : 299 - 313
  • [45] Coding Schemes for Discrete Memoryless Broadcast Channels with Rate-Limited Feedback
    Wu, Youlong
    Wigger, Michele
    2014 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY (ISIT), 2014, : 2127 - 2131
  • [46] mBBR - Improving BBR Performance Over Rate-Limited Mobile Networks
    Zhu, Shengtong
    Liu, Yan
    Guo, Lingfeng
    Ngan, Rudolf K. H.
    Lee, Jack Y. B.
    2023 IEEE 31ST INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS, ICNP, 2023,
  • [47] On the multiple-access channel with rate-limited state information at the encoders
    Cemal, Y
    Steinberg, Y
    2004 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY, PROCEEDINGS, 2004, : 106 - 106
  • [48] The Secrecy Capacity of the Wiretap Channel With Additive Noise and Rate-Limited Help
    Loyka, Sergey
    Merhav, Neri
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2024, 70 (01) : 189 - 205
  • [49] Coding Schemes for Discrete Memoryless Multicast Networks with Rate-limited Feedback
    Wu, Youlong
    2015 IEEE INFORMATION THEORY WORKSHOP - FALL (ITW), 2015, : 197 - 201
  • [50] The Gaussian Diamond-Wiretap Channel With Rate-Limited Relay Cooperation
    Lee, Si-Hyeon
    Khisti, Ashish
    IEEE COMMUNICATIONS LETTERS, 2017, 21 (02) : 338 - 341