Genuine onion: Simple, Fast, Flexible, and Cheap Website Authentication
Paul Syverson a
U.S. Naval Research Laboratory f
joint work with
Genuine onion: Simple, Fast, Flexible, and Cheap Website - - PowerPoint PPT Presentation
Genuine onion: Simple, Fast, Flexible, and Cheap Website Authentication Paul Syverson a U.S. Naval Research Laboratory f joint work with Griffin Boyce Open Internet Tools Project IEEE Web 2.0 Security and
Paul Syverson a
joint work with
2
3
4
5
6
7
8
9
10
(All routes in these pictures are onion routed through Tor) Bob's Server Introduction Points
The image cannot be displayed. Your computer may not have enough memory to open the image, or the image may have been corrupted. Restart your computer, and then open the file again. If the red x still appears, you may have to delete the image and then insert it again.11
Alice's Client
Bob's Server Introduction Points Service Lookup Server
XYZ Service
12
Alice's Client 2'. Alice uses xyz.onion to get Service Descriptor (including Intro Pt. address and Publlic Key) at Lookup Server Alice checks XYZ = H( PK( )) Service Lookup Server Bob's Server Introduction Points
XYZ Service
2'
13
Alice's Client 2'. Alice uses xyz.onion to get Service Descriptor (including Intro Pt. address and Publlic Key) at Lookup Server Alice checks XYZ = H( PK( ))
T h e i m a g e c a n nService Lookup Server Bob's Server Introduction Points
XYZ Service
2'
14
Alice's Client
Bob's Server Introduction Points Rendezvous Point Service Lookup Server 3 2'
15
Alice's Client
Bob's Server Introduction Points Rendezvous Point Service Lookup Server 4 2'
3
16
Alice's Client
Bob's Server Introduction Points Rendezvous Point Service Lookup Server 6 5
2' 4
3
17
Alice's Client Bob's Server Rendezvous Point Final resulting communication channel
The image cannot be18
19
20
21
22
23
24
25
26
27
28
– Might or might not be identical site or even on single
29
30
31
– Seymour’s Bay Chamber of Commerce signs Bob’s
32
– should be straightforward to do so (Monkeysphere) – Ahmia (onionsite search engine) suggests providing
– could support both X.509 certs and GPG certs
33
– post signed onion address on Facebook Page,
– Facebook’s Cert not much use here for personal
– personal (or minimally shared) cloud services – Integrity protection for personal RSS feeds
34
– to a meaningful name – backed by existing human trust relations – avoids problems of existing TLS Cert infrastructure – available to use right now
35