Breaking and (Partially) Fixing Provably Secure Onion Routing
Christiane Kuhn, Martin Beck, Thorsten Strufe
Abstract
After several years of research on onion routing, Camenisch and Lysyanskaya, in an attempt at rigorous analysis, defined an ideal functionality in the universal composability model, together with properties that protocols have to meet to achieve provable security. A whole family of systems based their security proofs on this work. However, analyzing HORNET and Sphinx, two instances from this family, we show that this proof strategy is broken. We discover a previously unknown vulnerability that breaks anonymity completely, and explain a known one. Both should not exist if privacy is proven correctly. In this work, we analyze and fix the proof strategy used for this family of systems. After proving the efficacy of the ideal functionality, we show how the original properties are flawed and suggest improved, effective properties in their place. Finally, we discover another common mistake in the proofs. We demonstrate how to avoid it by showing our improved properties for one protocol, thus partially fixing the family of provably secure onion routing protocols. ‡ This work in parts was carried out while affiliated with TU Dresden. 1 according to https://metrics.torproject.org/userstats-relay-country.html 2 Understanding of OR varied in the field. To be compliant with the terms of [8], we understand OR in this work as a free-route Chaumian MixNet [10] without requiring that messages are delayed. This conforms with the understanding of [21] and [16] except that circuits are excluded.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Express: Lowering the Cost of Metadata-hiding Communication with Cryptographic PrivacySaba Eskandarian, Henry Corrigan-Gibbs, Matei Zaharia, Dan BonehUSENIX Security 2021 · 98 citations
- Rollercoaster: An Efficient Group-Multicast Scheme for Mix NetworksDaniel Hugenroth, Martin Kleppmann, Alastair R. BeresfordUSENIX Security 2021 · 5 citations
- Walking Onions: Scaling Anonymity Networks while Protecting UsersChelsea Komlo, Nick Mathewson, Ian GoldbergUSENIX Security 2020
Related papers
- Minimal and Fastest Anonymous Communication against Colluding Passive AdversariesYutaro Yoshinaka, Junji Takemasa, Yuki Koizumi, Toru HasegawaINFOCOM 2025
- Shaken, not Stirred - Automated Discovery of Subtle Attacks on Protocols using Mix-NetsJannik Dreier, Pascal Lafourcade, Dhekra MahmoudUSENIX Security 2024 · 2 citations
- How Do Tor Users Interact With Onion Services?Philipp Winter, Anne Edmundson, Laura M. Roberts, Agnieszka Dutkowska-Zuk et al.USENIX Security 2018 · 42 citations
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
- OptiMix: Scalable and Distributed Approaches for Latency Optimization in Modern MixnetsMahdi RahimiNDSS 2026 · 3 citations
