Wang Changji, Shi Dongyuan, Xu Xilei
National Pilot School of Software, Yunnan University, Kunming, China; Yunnan Key Laboratory of Software Engineering, Yunnan University, Kunming, China; Guangdong Key Laboratory of Information Security Technology, Sun Yat-sen University, Guangzhou 510275, China.
School of Information Science and Technology, Sun Yat-sen University, Guangzhou, China; Guangdong Key Laboratory of Information Security Technology, Sun Yat-sen University, Guangzhou 510275, China.
PLoS One. 2015 Mar 27;10(3):e0121226. doi: 10.1371/journal.pone.0121226. eCollection 2015.
The rapid growth of Internet applications has made communication anonymity an increasingly important or even indispensable security requirement. Onion routing has been employed as an infrastructure for anonymous communication over a public network, which provides anonymous connections that are strongly resistant to both eavesdropping and traffic analysis. However, existing onion routing protocols usually exhibit poor performance due to repeated encryption operations. In this paper, we first present an improved anonymous multi-receiver identity-based encryption (AMRIBE) scheme, and an improved identity-based one-way anonymous key agreement (IBOWAKE) protocol. We then propose an efficient onion routing protocol named AIB-OR that provides provable security and strong anonymity. Our main approach is to use our improved AMRIBE scheme and improved IBOWAKE protocol in onion routing circuit construction. Compared with other onion routing protocols, AIB-OR provides high efficiency, scalability, strong anonymity and fault tolerance. Performance measurements from a prototype implementation show that our proposed AIB-OR can achieve high bandwidths and low latencies when deployed over the Internet.
互联网应用的迅速发展使通信匿名性成为一项日益重要甚至不可或缺的安全要求。洋葱路由已被用作在公共网络上进行匿名通信的基础设施,它提供了对窃听和流量分析都具有强大抵抗力的匿名连接。然而,由于重复的加密操作,现有的洋葱路由协议通常表现出较差的性能。在本文中,我们首先提出一种改进的基于身份的多接收者匿名加密(AMRIBE)方案和一种改进的基于身份的单向匿名密钥协商(IBOWAKE)协议。然后,我们提出一种名为AIB-OR的高效洋葱路由协议,该协议提供可证明的安全性和强大的匿名性。我们的主要方法是在洋葱路由电路构建中使用我们改进的AMRIBE方案和改进的IBOWAKE协议。与其他洋葱路由协议相比,AIB-OR具有高效性、可扩展性、强大的匿名性和容错性。来自原型实现的性能测量表明,我们提出的AIB-OR在互联网上部署时可以实现高带宽和低延迟。