Onion Franking: Abuse Reports for Mix-Based Private Messaging
Matthew Gregoire, Margaret Pierce, Saba Eskandarian
Abstract
—The fast-paced development and deployment of private messaging applications demands mechanisms to protect against the concomitant potential for abuse. While widely used end-to-end encrypted (E2EE) messaging systems have deployed mechanisms for users to verifiably report abusive messages without compromising the privacy of unreported messages, abuse reporting schemes for systems that additionally protect message metadata are still in their infancy. Existing solutions either focus on a relatively small portion of the design space or incur much higher communication and computation costs than their E2EE brethren. This paper introduces new abuse reporting mechanisms that work for any private messaging system based on onion encryption. This includes low-latency systems that employ heuristic or opportunistic mixing of user traffic, as well as schemes based on mixnets. Along the way, we show that design decisions and abstractions that are well-suited to the E2EE setting may actually impede security and performance improvements in the metadata-hiding setting. We also explore stronger threat models for abuse reporting and moderation not explored in prior work, showing where prior work falls short and how to strengthen both our scheme and others’ – including deployed E2EE messaging platforms – to achieve higher levels of security. We implement a prototype of our scheme and find that it outperforms the best known solutions in this setting by well over an order of magnitude for each step of the message delivery and reporting process, with overheads almost matching those of message franking techniques used by E2EE encrypted messaging apps today.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4460692b-c1a4-4e23-8142-281f3398ac23Cited by top-tier papers1
Ask how each one uses itBuilds on9
- The Loopix Anonymity SystemAnia M. Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser et al.USENIX Security 2017 · 214 citations
- XRD: Scalable Messaging System with Cryptographic PrivacyAlbert Kwon, David Lu, Srinivas DevadasNSDI 2020 · 87 citations
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 54 citations
- Traceback for End-to-End Encrypted MessagingNirvan Tyagi, Ian Miers, Thomas RistenpartCCS 2019 · 39 citations
- Secure Complaint-Enabled Source-Tracking for Encrypted MessagingCharlotte Peale, Saba Eskandarian, Dan BonehCCS 2021 · 12 citations
Related papers
- Abuse Reporting for Metadata-Hiding Communication Based on Secret SharingSaba EskandarianUSENIX Security 2024 · 9 citations
- Abuse Reporting and Enforcement for Third Party Moderators in Private MessagingMatthew Gregoire, Jade Keegan, Saba EskandarianCCS 2026
- Boomerang: Metadata-Private Messaging under Hardware TrustPeipei Jiang, Qian Wang, Jianhao Cheng, Cong Wang et al.NSDI 2023 · 13 citations
- Private Hierarchical Governance for Encrypted MessagingArmin Namavari, Barry Wang, Sanketh Menda, Ben Nassi et al.S&P 2024 · 1 citation
- Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging SystemsZhongming Wang, Tao Xiang, Xiaoguo Li, Guomin Yang et al.NDSS 2026
