Trellis: Robust and Scalable Metadata-private Anonymous Broadcast
Simon Langowski, Sacha Servan-Schreiber, Srinivas Devadas
Abstract
—Trellis is a mix-net based anonymous broadcast system with cryptographic security guarantees. Trellis can be used to anonymously publish documents or communicate with other users, all while assuming full network surveillance. In Trellis, users send messages through a set of servers in successive rounds. The servers mix and post the messages to a public bulletin board, hiding which users sent which messages. Trellis hides all network-level metadata, remains robust to changing network conditions, guarantees availability to honest users, and scales with the number of mix servers. Trellis provides three to five orders of magnitude faster performance and better network robustness compared to Atom, the state-of-the-art anonymous broadcast system with a similar threat model. In achieving these guarantees, Trellis contributes: (1) a simpler theoretical mixing analysis for a routing mix network constructed with a fraction of malicious servers, (2) anonymous routing tokens for verifiable random paths, and (3) lightweight blame protocols built on top of onion routing to identify and eliminate malicious parties. We implement and evaluate Trellis in a networked deployment. With 64 servers located across four geographic regions, Trellis achieves a throughput of 220 bits per second with 100,000 users. With 128 servers, Trellis achieves a throughput of 320 bits per second. Trellis’s throughput is only 100 to 1000 × slower compared to Tor (which has 6,000 servers and 2M daily users) and is therefore potentially deployable at a smaller “enterprise” scale. Our implementation is open-source.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e1401f8-d787-453e-be5e-893436c9aa36Cited by top-tier papers5
- Protection against Source Inference Attacks in Federated LearningAndreas Athanasiou, Kangsoo Jung, Catuscia PalamidessiICLR 2026 · 1 citation
- Oblivious SignalingMirza Kamrul Bashar Shuhan, Foteini Baldimtsi, Giuseppe AtenieseUSENIX Security 2026
- Myco: Unlocking Polylogarithmic Accesses in Metadata-Private MessagingDarya Kaviani, Deevashwer Rathee, Bhargav Annem, Raluca Ada PopaS&P 2025
- Remise: Authorized Anonymous Communication SystemsRohan Ravi, Paritosh Shukla, Adithya VadapalliUSENIX Security 2026
- Ring of Gyges: Accountable Anonymous Broadcast via Secret-Shared ShuffleWentao Dong, Peipei Jiang, Huayi Duan, Cong Wang et al.NDSS 2025
Builds on15
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 268 citations
- The Loopix Anonymity SystemAnia M. Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser et al.USENIX Security 2017 · 214 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
- CHURP: Dynamic-Committee Proactive Secret SharingSai Krishna Deepak Maram, Fan Zhang, Lun Wang, Andrew Low et al.CCS 2019 · 106 citations
Related papers
- LAMP: Lightweight Approaches for Latency Minimization in Mixnets with Practical Deployment ConsiderationsMahdi Rahimi, Piyush Kumar Sharma, Claudia DíazNDSS 2025
- OptiMix: Scalable and Distributed Approaches for Latency Optimization in Modern MixnetsMahdi RahimiNDSS 2026 · 3 citations
- Periscoping: Private Key Distribution for Large-Scale MixnetsShuhao Liu, Li Chen, Yuanzhong FuINFOCOM 2024 · 1 citation
- XRD: Scalable Messaging System with Cryptographic PrivacyAlbert Kwon, David Lu, Srinivas DevadasNSDI 2020 · 87 citations
- Rollercoaster: An Efficient Group-Multicast Scheme for Mix NetworksDaniel Hugenroth, Martin Kleppmann, Alastair R. BeresfordUSENIX Security 2021 · 5 citations
