{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T18:44:27Z","timestamp":1746297867750,"version":"3.37.3"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2022,6,18]],"date-time":"2022-06-18T00:00:00Z","timestamp":1655510400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,6,18]],"date-time":"2022-06-18T00:00:00Z","timestamp":1655510400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100007826","name":"Technische Universit\u00e4t Ilmenau","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100007826","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Protecting communications\u2019 metadata can be as important as protecting their content, i.e., recognizing someone contacting a medical service may already allow to infer sensitive information. There are numerous proposals to implement anonymous communications, yet none provides it in a strong (but feasible) threat model in an efficient way. We propose Hydra, an anonymity system that is able to efficiently provide metadata security for a wide variety of applications. Main idea is to use latency-aware, padded, and onion-encrypted circuits even for connectionless applications. This allows to implement strong metadata security for contact discovery and text-based messages with relatively low latency. Furthermore, circuits can be upgraded to support voice calls, real-time chat sessions, and file transfers\u2014with slightly reduced anonymity in presence of global observers. We evaluate Hydra using an analytical model as well as call simulations. Compared to other systems for text-based messaging, Hydra is able to decrease end-to-end latencies by an order of magnitude without degrading anonymity. Using a dataset generated by performing latency measurements in the Tor network, we further show that Hydra is able to support anonymous voice calls with acceptable quality of service in real scenarios. A first prototype of Hydra is published as open source.<\/jats:p>","DOI":"10.1007\/s42979-022-01231-9","type":"journal-article","created":{"date-parts":[[2022,6,18]],"date-time":"2022-06-18T15:02:32Z","timestamp":1655564552000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Hydra: Practical Metadata Security for Contact Discovery, Messaging, and Voice Calls"],"prefix":"10.1007","volume":"3","author":[{"given":"David","family":"Schatz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Rossberg","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guenter","family":"Schaefer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,6,18]]},"reference":[{"issue":"20","key":"1231_CR1","doi-asserted-by":"publisher","first-page":"5536","DOI":"10.1073\/pnas.1508081113","volume":"113","author":"J Mayer","year":"2016","unstructured":"Mayer J, Mutchler P, Mitchell JC. Evaluating the privacy properties of telephone metadata. Proc Nat Acad Sci. 2016;113(20):5536\u201341. https:\/\/doi.org\/10.1073\/pnas.1508081113.","journal-title":"Proc Nat Acad Sci"},{"issue":"2","key":"1231_CR2","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1145\/358549.358563","volume":"24","author":"D Chaum","year":"1981","unstructured":"Chaum D. Untraceable electronic mail, return addresses, and digital pseudonyms. Commun ACM. 1981;24(2):84\u201390. https:\/\/doi.org\/10.1145\/358549.358563.","journal-title":"Commun ACM"},{"key":"1231_CR3","doi-asserted-by":"publisher","unstructured":"Pham DV, Wright J, Kesdogan D. A practical complexity-theoretic analysis of mix systems. In: European Symposium on Research in Computer Security; 2011. pp. 508\u2013527. https:\/\/doi.org\/10.1007\/978-3-642-23822-2_28.","DOI":"10.1007\/978-3-642-23822-2_28"},{"key":"1231_CR4","doi-asserted-by":"publisher","unstructured":"Oya S, Troncoso C, P\u00e9rez-Gonz\u00e1lez F. Do dummies pay off? Limits of dummy traffic protection in anonymous communications. In: International Symposium on Privacy Enhancing Technologies; 2014. pp. 204\u2013223. https:\/\/doi.org\/10.1007\/978-3-319-08506-7_11. Springer.","DOI":"10.1007\/978-3-319-08506-7_11"},{"key":"1231_CR5","unstructured":"Lazar D, Gilad Y, Zeldovich N. Karaoke: distributed private messaging immune to passive traffic analysis. In: 13th USENIX OSDI; 2018. pp. 711\u2013725."},{"issue":"2","key":"1231_CR6","first-page":"1","volume":"2016","author":"N Gelernter","year":"2016","unstructured":"Gelernter N, Herzberg A, Leibowitz H. Two cents for strong anonymity: the anonymous post-office protocol. PETS. 2016;2016(2):1\u201320.","journal-title":"PETS"},{"key":"1231_CR7","unstructured":"Kwon A, Lu D, Devadas S. XRD: Scalable messaging system with cryptographic privacy. In: 17th USENIX NSDI; 2020. pp. 759\u2013776."},{"key":"1231_CR8","doi-asserted-by":"publisher","unstructured":"Wang X, Chen S, Jajodia S. Tracking anonymous peer-to-peer VoIP calls on the internet. In: ACM CCS; 2005. pp. 81\u201391. https:\/\/doi.org\/10.1145\/1102120.1102133.","DOI":"10.1145\/1102120.1102133"},{"key":"1231_CR9","doi-asserted-by":"crossref","unstructured":"Dingledine R, Mathewson N, Syverson P. Tor: The second-generation onion router. In: 13th USENIX Security; 2004.","DOI":"10.21236\/ADA465464"},{"key":"1231_CR10","doi-asserted-by":"publisher","unstructured":"Chen C, Asoni DE, Perrig A, Barrera D, Danezis G, Troncoso C. TARANET: Traffic-analysis resistant anonymity at the network layer. In: IEEE EuroS &P; 2018. pp. 137\u2013152. https:\/\/doi.org\/10.1109\/EuroSP.2018.00018.","DOI":"10.1109\/EuroSP.2018.00018"},{"issue":"4","key":"1231_CR11","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1145\/2829988.2787491","volume":"45","author":"S Le Blond","year":"2015","unstructured":"Le Blond S, Choffnes D, Caldwell W, Druschel P, Merritt N. Herd: a scalable, traffic analysis resistant anonymity network for VoIP systems. ACM SIGCOMM. 2015;45(4):639\u201352. https:\/\/doi.org\/10.1145\/2829988.2787491.","journal-title":"ACM SIGCOMM"},{"key":"1231_CR12","doi-asserted-by":"publisher","unstructured":"Lazar D, Gilad Y, Zeldovich N. Yodel: Strong metadata security for voice calls. In: 27th ACM SOSP; 2019. pp. 211\u2013224. https:\/\/doi.org\/10.1145\/3341301.3359648.","DOI":"10.1145\/3341301.3359648"},{"key":"1231_CR13","doi-asserted-by":"publisher","unstructured":"Schatz D, Rossberg M, Schaefer G. Optimizing packet scheduling and path selection for anonymous voice calls. In: ARES; 2021. https:\/\/doi.org\/10.1145\/3465481.3465768.","DOI":"10.1145\/3465481.3465768"},{"key":"1231_CR14","doi-asserted-by":"publisher","unstructured":"Schatz D, Rossberg M, Schaefer G. Hydra: Practical metadata security for contact discovery, messaging, and dialing. In: ICISSP; 2021. pp. 191\u2013203. https:\/\/doi.org\/10.5220\/0010262201910203.","DOI":"10.5220\/0010262201910203"},{"key":"1231_CR15","unstructured":"International Telecommunication Union. One-way Transmission Time, ITU-T recommendation G.114 edn; 2003. International Telecommunication Union."},{"issue":"1","key":"1231_CR16","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1049\/iet-com.2011.0701","volume":"8","author":"Y Jung","year":"2014","unstructured":"Jung Y, Manzano C. Burst packet loss and enhanced packet loss-based quality model for mobile voice-over Internet protocol applications. IET Commun. 2014;8(1):41\u20139. https:\/\/doi.org\/10.1049\/iet-com.2011.0701.","journal-title":"IET Commun"},{"issue":"2","key":"1231_CR17","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev D, Yao A. On the security of public key protocols. IEEE Trans Info Theory. 1983;29(2):198\u2013208. https:\/\/doi.org\/10.1109\/TIT.1983.1056650.","journal-title":"IEEE Trans Info Theory"},{"issue":"1","key":"1231_CR18","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/BF00206326","volume":"1","author":"D Chaum","year":"1988","unstructured":"Chaum D. The dining cryptographers problem: unconditional sender and recipient untraceability. J Cryptol. 1988;1(1):65\u201375. https:\/\/doi.org\/10.1007\/BF00206326.","journal-title":"J Cryptol"},{"key":"1231_CR19","unstructured":"Chor B, Goldreich O, Kushilevitz E, Sudan M. Private information retrieval. In: Proceedings of IEEE 36th Annual Foundations of Computer Science; 1995. pp. 41\u201350. IEEE"},{"key":"1231_CR20","doi-asserted-by":"publisher","unstructured":"Corrigan-Gibbs H, Boneh D, Mazi\u00e8re, D. Riposte: An anonymous messaging system handling millions of users. In: IEEE SP; 2015. pp. 321\u2013338. https:\/\/doi.org\/10.1109\/SP.2015.27.","DOI":"10.1109\/SP.2015.27"},{"key":"1231_CR21","unstructured":"Ahmad I, Yang Y, Agrawal D, El Abbadi A, Gupta T. Addra: Metadata-private voice communication over fully untrusted infrastructure. In: 15th USENIX OSDI; 2021."},{"key":"1231_CR22","unstructured":"Franck C, Sorger U. Untraceable voip communication based on dc-nets. arXiv preprint arXiv:1610.06549; 2016."},{"key":"1231_CR23","doi-asserted-by":"publisher","unstructured":"Van Den Hooff J, Lazar D, Zaharia M, Zeldovich N. Vuvuzela: Scalable private messaging resistant to traffic analysis. In: 25th ACM SOSP; 2015. pp. 137\u2013152. https:\/\/doi.org\/10.1145\/2815400.2815417","DOI":"10.1145\/2815400.2815417"},{"key":"1231_CR24","doi-asserted-by":"publisher","unstructured":"Tyagi N, Gilad Y, Leung D, Zaharia M, Zeldovich N. Stadium: A distributed metadata-private messaging system. In: 26th ACM SOSP; 2017. pp. 423\u2013440. https:\/\/doi.org\/10.1145\/3132747.3132783.","DOI":"10.1145\/3132747.3132783"},{"key":"1231_CR25","doi-asserted-by":"publisher","unstructured":"Kwon A, Corrigan-Gibbs H, Devadas S, Ford B. Atom: Horizontally scaling strong anonymity. In: 26th ACM SOSP; 2017. pp. 406\u2013422. https:\/\/doi.org\/10.1145\/3132747.3132755.","DOI":"10.1145\/3132747.3132755"},{"key":"1231_CR26","doi-asserted-by":"publisher","unstructured":"Chaum D, Das D, Javani F, Kate A, Krasnova A, De Ruiter J, Sherman AT. cMix: Mixing with minimal real-time asymmetric cryptographic operations. In: International Conference on Applied Cryptography and Network Security; 2017. pp. 557\u2013578. https:\/\/doi.org\/10.1007\/978-3-319-61204-1_28.","DOI":"10.1007\/978-3-319-61204-1_28"},{"issue":"2","key":"1231_CR27","first-page":"115","volume":"2016","author":"A Kwon","year":"2016","unstructured":"Kwon A, Lazar D, Devadas S, Ford B. Riffle: an efficient communication system with strong anonymity. PETS. 2016;2016(2):115\u201334.","journal-title":"PETS"},{"key":"1231_CR28","unstructured":"Piotrowska AM, Hayes J, Elahi T, Meiser S, Danezis G. The Loopix anonymity system. In: 26th USENIX Security; 2017. pp. 1199\u20131216."},{"issue":"4","key":"1231_CR29","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1145\/2534169.2486002","volume":"43","author":"S Le Blond","year":"2013","unstructured":"Le Blond S, Choffnes D, Zhou W, Druschel P, Ballani H, Francis P. Towards efficient traffic-analysis resistant anonymity networks. ACM SIGCOMM. 2013;43(4):303\u201314. https:\/\/doi.org\/10.1145\/2534169.2486002.","journal-title":"ACM SIGCOMM"},{"key":"1231_CR30","doi-asserted-by":"crossref","unstructured":"Traudt M, Jansen R, Johnson A. FlashFlow: A secure speed test for Tor. arXiv preprint arXiv:2004.09583; 2020.","DOI":"10.1109\/ICDCS51616.2021.00044"},{"key":"1231_CR31","doi-asserted-by":"crossref","unstructured":"Chan-Tin E, Hopper N. Accurate and provably secure latency estimation with Treeple. In: NDSS; 2011.","DOI":"10.1145\/1866307.1866389"},{"key":"1231_CR32","doi-asserted-by":"publisher","unstructured":"Patarin J, Gittins B, Treger J. Increasing Block Sizes Using Feistel Networks: The Example of the AES. In: Cryptography and Security: From Theory to Applications, Springer; 2012. pp. 67\u201382. https:\/\/doi.org\/10.1007\/978-3-642-28368-0_8.","DOI":"10.1007\/978-3-642-28368-0_8"},{"key":"1231_CR33","unstructured":"Tor Project. Tor Directory Protocol, Version 3. https:\/\/gitweb.torproject.org\/torspec.git\/tree\/dir-spec.txt, Accessed 19 May 2022."},{"key":"1231_CR34","doi-asserted-by":"publisher","unstructured":"Schatz D, Rossberg M, Schaefer G. Large-scale Latency Measurements in the Tor Network (v1.0); 2021. https:\/\/doi.org\/10.5281\/zenodo.4911583.","DOI":"10.5281\/zenodo.4911583"},{"key":"1231_CR35","unstructured":"Gurobi Optimization, LLC. Gurobi Optimizer Homepage. https:\/\/www.gurobi.com, Accessed 19 May 2022."}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-022-01231-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-022-01231-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-022-01231-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,19]],"date-time":"2022-09-19T19:07:47Z","timestamp":1663614467000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-022-01231-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,18]]},"references-count":35,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2022,9]]}},"alternative-id":["1231"],"URL":"https:\/\/doi.org\/10.1007\/s42979-022-01231-9","relation":{},"ISSN":["2661-8907"],"issn-type":[{"type":"electronic","value":"2661-8907"}],"subject":[],"published":{"date-parts":[[2022,6,18]]},"assertion":[{"value":"5 October 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 May 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 June 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"On behalf of all authors, the corresponding author states that there is no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"341"}}