Boomerang: Metadata-Private Messaging under Hardware Trust
Peipei Jiang, Qian Wang, Jianhao Cheng, Cong Wang, Lei Xu, Xinyu Wang, Yihao Wu, Xiaoyuan Li, Kui Ren
Abstract
In end-to-end encrypted (E2EE) messaging systems, protecting communication metadata, such as who is communicating with whom, at what time, etc., remains a challenging problem. Existing designs mostly fall into the balancing act among security, performance, and trust assumptions: 1) designs with cryptographic security often use hefty operations, incurring performance roadblocks and expensive operational costs for large-scale deployment; 2) more performant systems often follow a weaker security guarantee, like differential privacy, and generally demand more trust from the involved servers. So far, there has been no dominant solution. In this paper, we take a different technical route from prior art, and propose Boomerang, an alternative metadata-private messaging system leveraging the readily available trust assumption on secure enclaves (as those emerging in the cloud). Through a number of carefully tailored oblivious techniques on message shuffling, workload distribution, and proactive patching of the communication pattern, Boomerang brings together low latency, horizontal scalability, and cryptographic security, without prohibitive extra cost. With 32 machines, Boomerang achieves 99th percentile latency of 7.76 seconds for 2 20 clients. We hope Boomerang offers attractive alternative options to the current landscape of metadata-private messaging designs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c426fa88-5af2-4e46-b6bb-85429b42256cCited by top-tier papers1
Ask how each one uses itBuilds on26
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta et al.USENIX Security 2016 · 594 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- PIR with Compressed Queries and Amortized Query ProcessingSebastian Angel, Hao Chen, Kim Laine, Srinath T. V. SettyS&P 2018 · 353 citations
Related papers
- XRD: Scalable Messaging System with Cryptographic PrivacyAlbert Kwon, David Lu, Srinivas DevadasNSDI 2020 · 87 citations
- Groove: Flexible Metadata-Private MessagingLudovic Barman, Moshe Kol, David Lazar, Yossi Gilad et al.OSDI 2022 · 17 citations
- Myco: Unlocking Polylogarithmic Accesses in Metadata-Private MessagingDarya Kaviani, Deevashwer Rathee, Bhargav Annem, Raluca Ada PopaS&P 2025
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman et al.OSDI 2024 · 19 citations
- Onion Franking: Abuse Reports for Mix-Based Private MessagingMatthew Gregoire, Margaret Pierce, Saba EskandarianNDSS 2025
