rearrange and clean up sec1
[tor.git] / doc / tor-design.bib
blob0a65b28f990d7acfc8a9e7af85985d79ecebfeed
1 @article{ meadows96,
2 author = "Catherine Meadows",
3 title = "The {NRL} Protocol Analyzer: An Overview",
4 journal = "Journal of Logic Programming",
5 volume = "26",
6 number = "2",
7 pages = "113--131",
8 year = "1996",
10 @inproceedings{kesdogan:pet2002,
11 title = {Unobservable Surfing on the World Wide Web: Is Private Information Retrieval an
12 alternative to the MIX based Approach?},
13 author = {Dogan Kesdogan and Mark Borning and Michael Schmeink},
14 booktitle = {Privacy Enhancing Technologies (PET 2002)},
15 year = {2002},
16 month = {April},
17 editor = {Roger Dingledine and Paul Syverson},
18 publisher = {Springer-Verlag, LNCS 2482},
21 @inproceedings{statistical-disclosure,
22 title = {Statistical Disclosure Attacks},
23 author = {George Danezis},
24 booktitle = {Security and Privacy in the Age of Uncertainty ({SEC2003})},
25 organization = {{IFIP TC11}},
26 year = {2003},
27 month = {May},
28 address = {Athens},
29 pages = {421--426},
30 publisher = {Kluwer},
33 @inproceedings{limits-open,
34 title = {Limits of Anonymity in Open Environments},
35 author = {Dogan Kesdogan and Dakshi Agrawal and Stefan Penz},
36 booktitle = {Information Hiding Workshop (IH 2002)},
37 year = {2002},
38 month = {October},
39 editor = {Fabien Petitcolas},
40 publisher = {Springer-Verlag, LNCS 2578},
43 @inproceedings{isdn-mixes,
44 title = {{ISDN-mixes: Untraceable communication with very small bandwidth overhead}},
45 author = {Andreas Pfitzmann and Birgit Pfitzmann and Michael Waidner},
46 booktitle = {GI/ITG Conference on Communication in Distributed Systems},
47 year = {1991},
48 month = {February},
49 pages = {451-463},
52 @inproceedings{tarzan:ccs02,
53 title = {Tarzan: A Peer-to-Peer Anonymizing Network Layer},
54 author = {Michael J. Freedman and Robert Morris},
55 booktitle = {9th {ACM} {C}onference on {C}omputer and {C}ommunications
56 {S}ecurity ({CCS 2002})},
57 year = {2002},
58 month = {November},
59 address = {Washington, DC},
62 @inproceedings{cebolla,
63 title = {{Cebolla: Pragmatic IP Anonymity}},
64 author = {Zach Brown},
65 booktitle = {Ottawa Linux Symposium},
66 year = {2002},
67 month = {June},
70 @misc{eax,
71 author = "M. Bellare and P. Rogaway and D. Wagner",
72 title = "A conventional authenticated-encryption mode",
73 howpublished = {Manuscript},
74 month = {April},
75 year = {2003},
78 @misc{darkside,
79 title = {{The Dark Side of the Web: An Open Proxy's View}},
80 author = {Vivek S. Pai and Limin Wang and KyoungSoo Park and Ruoming Pang and Larry Peterson},
81 note = {Submitted to HotNets-II. \url{http://codeen.cs.princeton.edu/}},
84 @Misc{anonymizer,
85 key = {anonymizer},
86 title = {The {Anonymizer}},
87 note = {\url{http://anonymizer.com/}}
90 @Misc{privoxy,
91 key = {privoxy},
92 title = {{Privoxy}},
93 note = {\url{http://www.privoxy.org/}}
96 @inproceedings{anonnet,
97 title = {{Analysis of an Anonymity Network for Web Browsing}},
98 author = {Marc Rennhard and Sandro Rafaeli and Laurent Mathy and Bernhard Plattner and
99 David Hutchison},
100 booktitle = {{IEEE 7th Intl. Workshop on Enterprise Security (WET ICE
101 2002)}},
102 year = {2002},
103 month = {June},
104 address = {Pittsburgh, USA},
105 pages = {49--54},
108 @inproceedings{econymics,
109 title = {On the Economics of Anonymity},
110 author = {Alessandro Acquisti and Roger Dingledine and Paul Syverson},
111 booktitle = {Financial Cryptography},
112 year = {2003},
113 editor = {Rebecca N. Wright},
114 publisher = {Springer-Verlag, LNCS 2742},
117 @inproceedings{defensive-dropping,
118 title = {Stopping Timing Attacks in Low-Latency Mix-Based Systems},
119 author = {Matthew Wright and Brian N. Levine and Michael K. Reiter and Chenxi Wang},
120 booktitle = {Financial Cryptography},
121 year = {2004},
122 editor = {Ari Juels},
123 publisher = {Springer-Verlag, LNCS (forthcoming)},
126 @inproceedings{morphmix:fc04,
127 title = {Practical Anonymity for the Masses with MorphMix},
128 author = {Marc Rennhard and Bernhard Plattner},
129 booktitle = {Financial Cryptography},
130 year = {2004},
131 editor = {Ari Juels},
132 publisher = {Springer-Verlag, LNCS (forthcoming)},
135 @inproceedings{eternity,
136 title = {The Eternity Service},
137 author = {Ross Anderson},
138 booktitle = {Pragocrypt '96},
139 year = {1996},
141 %note = {\url{http://www.cl.cam.ac.uk/users/rja14/eternity/eternity.html}},
144 @inproceedings{minion-design,
145 title = {Mixminion: Design of a Type {III} Anonymous Remailer Protocol},
146 author = {George Danezis and Roger Dingledine and Nick Mathewson},
147 booktitle = {2003 IEEE Symposium on Security and Privacy},
148 year = {2003},
149 month = {May},
150 publisher = {IEEE CS},
151 pages = {2--15},
153 %note = {\url{http://mixminion.net/minion-design.pdf}},
155 @inproceedings{ rao-pseudonymity,
156 author = "Josyula R. Rao and Pankaj Rohatgi",
157 title = "Can Pseudonymity Really Guarantee Privacy?",
158 booktitle = "Proceedings of the Ninth USENIX Security Symposium",
159 year = {2000},
160 month = Aug,
161 publisher = {USENIX},
162 pages = "85--96",
164 %note = {\url{http://www.usenix.org/publications/library/proceedings/sec2000/
165 %full_papers/rao/rao.pdf}},
167 @InProceedings{pfitzmann90how,
168 author = "Birgit Pfitzmann and Andreas Pfitzmann",
169 title = "How to Break the Direct {RSA}-Implementation of {MIXes}",
170 booktitle = {Eurocrypt 89},
171 publisher = {Springer-Verlag, LNCS 434},
172 year = {1990},
173 note = {\url{http://citeseer.nj.nec.com/pfitzmann90how.html}},
176 % author = {Roger Dingledine and Nick Mathewson},
177 @Misc{tor-spec,
178 author = {Anonymized},
179 title = {Tor Protocol Specifications},
180 note = {\url{http://freehaven.net/tor/tor-spec.txt}},
183 @InProceedings{BM:mixencrypt,
184 author = {M{\"o}ller, Bodo},
185 title = {Provably Secure Public-Key Encryption for Length-Preserving Chaumian Mixes},
186 booktitle = {{CT-RSA} 2003},
187 publisher = {Springer-Verlag, LNCS 2612},
188 year = 2003,
191 @InProceedings{back01,
192 author = {Adam Back and Ulf M\"oller and Anton Stiglic},
193 title = {Traffic Analysis Attacks and Trade-Offs in Anonymity Providing Systems},
194 booktitle = {Information Hiding (IH 2001)},
195 pages = {245--257},
196 year = 2001,
197 editor = {Ira S. Moskowitz},
198 publisher = {Springer-Verlag, LNCS 2137},
200 %note = {\newline \url{http://www.cypherspace.org/adam/pubs/traffic.pdf}},
202 @InProceedings{rackoff93cryptographic,
203 author = {Charles Rackoff and Daniel R. Simon},
204 title = {Cryptographic Defense Against Traffic Analysis},
205 booktitle = {{ACM} Symposium on Theory of Computing},
206 pages = {672--681},
207 year = {1993},
209 %note = {\url{http://research.microsoft.com/crypto/dansimon/me.htm}},
211 @InProceedings{freehaven-berk,
212 author = {Roger Dingledine and Michael J. Freedman and David Molnar},
213 title = {The Free Haven Project: Distributed Anonymous Storage Service},
214 booktitle = {Designing Privacy Enhancing Technologies: Workshop
215 on Design Issue in Anonymity and Unobservability},
216 year = {2000},
217 month = {July},
218 editor = {H. Federrath},
219 publisher = {Springer-Verlag, LNCS 2009},
221 %note = {\url{http://freehaven.net/papers.html}},
223 @InProceedings{raymond00,
224 author = {J. F. Raymond},
225 title = {{Traffic Analysis: Protocols, Attacks, Design Issues,
226 and Open Problems}},
227 booktitle = {Designing Privacy Enhancing Technologies: Workshop
228 on Design Issue in Anonymity and Unobservability},
229 year = 2000,
230 month = {July},
231 pages = {10-29},
232 editor = {H. Federrath},
233 publisher = {Springer-Verlag, LNCS 2009},
236 @InProceedings{sybil,
237 author = "John Douceur",
238 title = {{The Sybil Attack}},
239 booktitle = "Proceedings of the 1st International Peer To Peer Systems Workshop (IPTPS 2002)",
240 month = Mar,
241 year = 2002,
244 @InProceedings{trickle02,
245 author = {Andrei Serjantov and Roger Dingledine and Paul Syverson},
246 title = {From a Trickle to a Flood: Active Attacks on Several
247 Mix Types},
248 booktitle = {Information Hiding (IH 2002)},
249 year = {2002},
250 editor = {Fabien Petitcolas},
251 publisher = {Springer-Verlag, LNCS 2578},
254 @InProceedings{langos02,
255 author = {Oliver Berthold and Heinrich Langos},
256 title = {Dummy Traffic Against Long Term Intersection Attacks},
257 booktitle = {Privacy Enhancing Technologies (PET 2002)},
258 year = {2002},
259 editor = {Roger Dingledine and Paul Syverson},
260 publisher = {Springer-Verlag, LNCS 2482}
264 @InProceedings{hintz-pet02,
265 author = {Andrew Hintz},
266 title = {Fingerprinting Websites Using Traffic Analysis},
267 booktitle = {Privacy Enhancing Technologies (PET 2002)},
268 pages = {171--178},
269 year = 2002,
270 editor = {Roger Dingledine and Paul Syverson},
271 publisher = {Springer-Verlag, LNCS 2482}
274 @InProceedings{or-discex00,
275 author = {Paul Syverson and Michael Reed and David Goldschlag},
276 title = {{O}nion {R}outing Access Configurations},
277 booktitle = {DARPA Information Survivability Conference and
278 Exposition (DISCEX 2000)},
279 year = {2000},
280 publisher = {IEEE CS Press},
281 pages = {34--40},
282 volume = {1},
284 %note = {\newline \url{http://www.onion-router.net/Publications.html}},
286 @Inproceedings{or-pet00,
287 title = {{Towards an Analysis of Onion Routing Security}},
288 author = {Paul Syverson and Gene Tsudik and Michael Reed and
289 Carl Landwehr},
290 booktitle = {Designing Privacy Enhancing Technologies: Workshop
291 on Design Issue in Anonymity and Unobservability},
292 year = 2000,
293 month = {July},
294 pages = {96--114},
295 editor = {H. Federrath},
296 publisher = {Springer-Verlag, LNCS 2009},
298 %note = {\url{http://www.onion-router.net/Publications/WDIAU-2000.ps.gz}},
300 @Inproceedings{freenet-pets00,
301 title = {Freenet: A Distributed Anonymous Information Storage
302 and Retrieval System},
303 author = {Ian Clarke and Oskar Sandberg and Brandon Wiley and
304 Theodore W. Hong},
305 booktitle = {Designing Privacy Enhancing Technologies: Workshop
306 on Design Issue in Anonymity and Unobservability},
307 year = 2000,
308 month = {July},
309 pages = {46--66},
310 editor = {H. Federrath},
311 publisher = {Springer-Verlag, LNCS 2009},
313 %note = {\url{http://citeseer.nj.nec.com/clarke00freenet.html}},
315 @InProceedings{or-ih96,
316 author = {David M. Goldschlag and Michael G. Reed and Paul
317 F. Syverson},
318 title = {Hiding Routing Information},
319 booktitle = {Information Hiding, First International Workshop},
320 pages = {137--150},
321 year = 1996,
322 editor = {R. Anderson},
323 month = {May},
324 publisher = {Springer-Verlag, LNCS 1174},
326 %note = {\url{http://www.onion-router.net/Publications/IH-1996.ps.gz}}
328 @Article{or-jsac98,
329 author = {Michael G. Reed and Paul F. Syverson and David
330 M. Goldschlag},
331 title = {Anonymous Connections and Onion Routing},
332 journal = {IEEE Journal on Selected Areas in Communications},
333 year = 1998,
334 volume = 16,
335 number = 4,
336 pages = {482--494},
337 month = {May},
339 %note = {\url{http://www.onion-router.net/Publications/JSAC-1998.ps.gz}}
341 @Misc{TLS,
342 author = {T. Dierks and C. Allen},
343 title = {The {TLS} {P}rotocol --- {V}ersion 1.0},
344 howpublished = {IETF RFC 2246},
345 month = {January},
346 year = {1999},
347 note = {\url{http://www.rfc-editor.org/rfc/rfc2246.txt}},
350 @Misc{SMTP,
351 author = {J. Postel},
352 title = {Simple {M}ail {T}ransfer {P}rotocol},
353 howpublished = {IETF RFC 2821 (also STD0010)},
354 month = {April},
355 year = {2001},
356 note = {\url{http://www.rfc-editor.org/rfc/rfc2821.txt}},
359 @Misc{IMAP,
360 author = {M. Crispin},
361 title = {Internet {M}essage {A}ccess {P}rotocol --- {V}ersion 4rev1},
362 howpublished = {IETF RFC 2060},
363 month = {December},
364 year = {1996},
365 note = {\url{http://www.rfc-editor.org/rfc/rfc2060.txt}},
368 @misc{pipenet,
369 title = {PipeNet 1.1},
370 author = {Wei Dai},
371 year = 1996,
372 month = {August},
373 howpublished = {Usenet post},
374 note = {\url{http://www.eskimo.com/~weidai/pipenet.txt} First mentioned
375 in a post to the cypherpunks list, Feb.\ 1995.},
379 @Misc{POP3,
380 author = {J. Myers and M. Rose},
381 title = {Post {O}ffice {P}rotocol --- {V}ersion 3},
382 howpublished = {IETF RFC 1939 (also STD0053)},
383 month = {May},
384 year = {1996},
385 note = {\url{http://www.rfc-editor.org/rfc/rfc1939.txt}},
389 @InProceedings{shuffle,
390 author = {C. Andrew Neff},
391 title = {A Verifiable Secret Shuffle and its Application to E-Voting},
392 booktitle = {8th ACM Conference on Computer and Communications
393 Security (CCS-8)},
394 pages = {116--125},
395 year = 2001,
396 editor = {P. Samarati},
397 month = {November},
398 publisher = {ACM Press},
400 %note = {\url{http://www.votehere.net/ada_compliant/ourtechnology/
401 % technicaldocs/shuffle.pdf}},
403 @InProceedings{dolev91,
404 author = {Danny Dolev and Cynthia Dwork and Moni Naor},
405 title = {Non-Malleable Cryptography},
406 booktitle = {23rd ACM Symposium on the Theory of Computing (STOC)},
407 pages = {542--552},
408 year = 1991,
409 note = {Updated version at
410 \url{http://citeseer.nj.nec.com/dolev00nonmalleable.html}},
413 @TechReport{rsw96,
414 author = {Ronald L. Rivest and Adi Shamir and David A. Wagner},
415 title = {Time-lock puzzles and timed-release Crypto},
416 year = 1996,
417 type = {MIT LCS technical memo},
418 number = {MIT/LCS/TR-684},
419 month = {February},
420 note = {\newline \url{http://citeseer.nj.nec.com/rivest96timelock.html}},
423 @InProceedings{web-mix,
424 author = {Oliver Berthold and Hannes Federrath and Stefan K\"opsell},
425 title = {Web {MIX}es: A system for anonymous and unobservable
426 {I}nternet access},
427 booktitle = {Designing Privacy Enhancing Technologies: Workshop
428 on Design Issue in Anonymity and Unobservability},
429 editor = {H. Federrath},
430 publisher = {Springer-Verlag, LNCS 2009},
431 pages = {115--129},
432 year = {2000},
435 @InProceedings{disad-free-routes,
436 author = {Oliver Berthold and Andreas Pfitzmann and Ronny Standtke},
437 title = {The disadvantages of free {MIX} routes and how to overcome
438 them},
439 booktitle = {Designing Privacy Enhancing Technologies: Workshop
440 on Design Issue in Anonymity and Unobservability},
441 pages = {30--45},
442 year = 2000,
443 editor = {H. Federrath},
444 publisher = {Springer-Verlag, LNCS 2009},
446 %note = {\url{http://www.tik.ee.ethz.ch/~weiler/lehre/netsec/Unterlagen/anon/
447 % disadvantages_berthold.pdf}},
449 @InProceedings{boneh00,
450 author = {Dan Boneh and Moni Naor},
451 title = {Timed Commitments},
452 booktitle = {Advances in Cryptology -- {CRYPTO} 2000},
453 pages = {236--254},
454 year = 2000,
455 publisher = {Springer-Verlag, LNCS 1880},
456 note = {\newline \url{http://crypto.stanford.edu/~dabo/abstracts/timedcommit.html}},
459 @InProceedings{goldschlag98,
460 author = {David M. Goldschlag and Stuart G. Stubblebine},
461 title = {Publicly Verifiable Lotteries: Applications of
462 Delaying Functions},
463 booktitle = {Financial Cryptography},
464 pages = {214--226},
465 year = 1998,
466 publisher = {Springer-Verlag, LNCS 1465},
467 note = {\newline \url{http://citeseer.nj.nec.com/goldschlag98publicly.html}},
470 @InProceedings{syverson98,
471 author = {Paul Syverson},
472 title = {Weakly Secret Bit Commitment: Applications to
473 Lotteries and Fair Exchange},
474 booktitle = {Computer Security Foundations Workshop (CSFW11)},
475 pages = {2--13},
476 year = 1998,
477 address = {Rockport Massachusetts},
478 month = {June},
479 publisher = {IEEE CS Press},
480 note = {\newline \url{http://chacs.nrl.navy.mil/publications/CHACS/1998/}},
483 @Misc{shoup-iso,
484 author = {Victor Shoup},
485 title = {A Proposal for an {ISO} {S}tandard for Public Key Encryption (version 2.1)},
486 note = {Revised December 20, 2001. \url{http://www.shoup.net/papers/}},
489 @Misc{shoup-oaep,
490 author = {Victor Shoup},
491 title = {{OAEP} Reconsidered},
492 howpublished = {{IACR} e-print 2000/060},
493 note = {\newline \url{http://eprint.iacr.org/2000/060/}},
496 @Misc{oaep-still-alive,
497 author = {E. Fujisaki and D. Pointcheval and T. Okamoto and J. Stern},
498 title = {{RSA}-{OAEP} is Still Alive!},
499 howpublished = {{IACR} e-print 2000/061},
500 note = {\newline \url{http://eprint.iacr.org/2000/061/}},
503 @misc{echolot,
504 author = {Peter Palfrader},
505 title = {Echolot: a pinger for anonymous remailers},
506 note = {\url{http://www.palfrader.org/echolot/}},
509 @Misc{mixmaster-attacks,
510 author = {Lance Cottrell},
511 title = {Mixmaster and Remailer Attacks},
512 note = {\url{http://www.obscura.com/~loki/remailer/remailer-essay.html}},
515 @Misc{mixmaster-spec,
516 author = {Ulf M{\"o}ller and Lance Cottrell and Peter
517 Palfrader and Len Sassaman},
518 title = {Mixmaster {P}rotocol --- {V}ersion 2},
519 year = {2003},
520 month = {July},
521 howpublished = {Draft},
522 note = {\url{http://www.abditum.com/mixmaster-spec.txt}},
525 @InProceedings{puzzles-tls,
526 author = "Drew Dean and Adam Stubblefield",
527 title = {{Using Client Puzzles to Protect TLS}},
528 booktitle = "Proceedings of the 10th USENIX Security Symposium",
529 year = {2001},
530 month = Aug,
531 publisher = {USENIX},
534 @InProceedings{breadpudding,
535 author = {Markus Jakobsson and Ari Juels},
536 title = {Proofs of Work and Bread Pudding Protocols},
537 booktitle = {Proceedings of the IFIP TC6 and TC11 Joint Working
538 Conference on Communications and Multimedia Security
539 (CMS '99)},
540 year = 1999,
541 month = {September},
542 publisher = {Kluwer}
545 @Misc{hashcash,
546 author = {Adam Back},
547 title = {Hash cash},
548 note = {\newline \url{http://www.cypherspace.org/~adam/hashcash/}},
551 @InProceedings{oreilly-acc,
552 author = {Roger Dingledine and Michael J. Freedman and David Molnar},
553 title = {Accountability},
554 booktitle = {Peer-to-peer: Harnessing the Benefits of a Disruptive
555 Technology},
556 year = {2001},
557 publisher = {O'Reilly and Associates},
561 @InProceedings{han,
562 author = {Yongfei Han},
563 title = {Investigation of non-repudiation protocols},
564 booktitle = {ACISP '96},
565 year = 1996,
566 publisher = {Springer-Verlag},
570 @Misc{socks5,
571 key = {socks5},
572 title = {{SOCKS} {P}rotocol {V}ersion 5},
573 howpublished= {IETF RFC 1928},
574 month = {March},
575 year = 1996,
576 note = {\url{http://www.ietf.org/rfc/rfc1928.txt}}
579 @InProceedings{abe,
580 author = {Masayuki Abe},
581 title = {Universally Verifiable {MIX} With Verification Work Independent of
582 The Number of {MIX} Servers},
583 booktitle = {{EUROCRYPT} 1998},
584 year = {1998},
585 publisher = {Springer-Verlag, LNCS 1403},
588 @InProceedings{desmedt,
589 author = {Yvo Desmedt and Kaoru Kurosawa},
590 title = {How To Break a Practical {MIX} and Design a New One},
591 booktitle = {{EUROCRYPT} 2000},
592 year = {2000},
593 publisher = {Springer-Verlag, LNCS 1803},
594 note = {\url{http://citeseer.nj.nec.com/447709.html}},
597 @InProceedings{mitkuro,
598 author = {M. Mitomo and K. Kurosawa},
599 title = {{Attack for Flash MIX}},
600 booktitle = {{ASIACRYPT} 2000},
601 year = {2000},
602 publisher = {Springer-Verlag, LNCS 1976},
603 note = {\newline \url{http://citeseer.nj.nec.com/450148.html}},
606 @InProceedings{hybrid-mix,
607 author = {M. Ohkubo and M. Abe},
608 title = {A {L}ength-{I}nvariant {H}ybrid {MIX}},
609 booktitle = {Advances in Cryptology - {ASIACRYPT} 2000},
610 year = {2000},
611 publisher = {Springer-Verlag, LNCS 1976},
614 @InProceedings{PShuffle,
615 author = {Jun Furukawa and Kazue Sako},
616 title = {An Efficient Scheme for Proving a Shuffle},
617 editor = {Joe Kilian},
618 booktitle = {CRYPTO 2001},
619 year = {2001},
620 publisher = {Springer-Verlag, LNCS 2139},
624 @InProceedings{jakobsson-optimally,
625 author = "Markus Jakobsson and Ari Juels",
626 title = "An Optimally Robust Hybrid Mix Network (Extended Abstract)",
627 booktitle = {Principles of Distributed Computing - {PODC} '01},
628 year = "2001",
629 publisher = {ACM Press},
630 note = {\url{http://citeseer.nj.nec.com/492015.html}},
633 @InProceedings{kesdogan,
634 author = {D. Kesdogan and M. Egner and T. B\"uschkes},
635 title = {Stop-and-Go {MIX}es Providing Probabilistic Anonymity in an Open
636 System},
637 booktitle = {Information Hiding (IH 1998)},
638 year = {1998},
639 publisher = {Springer-Verlag, LNCS 1525},
641 %note = {\url{http://www.cl.cam.ac.uk/~fapp2/ihw98/ihw98-sgmix.pdf}},
643 @InProceedings{socks4,
644 author = {David Koblas and Michelle R. Koblas},
645 title = {{SOCKS}},
646 booktitle = {UNIX Security III Symposium (1992 USENIX Security
647 Symposium)},
648 pages = {77--83},
649 year = 1992,
650 publisher = {USENIX},
653 @InProceedings{flash-mix,
654 author = {Markus Jakobsson},
655 title = {Flash {M}ixing},
656 booktitle = {Principles of Distributed Computing - {PODC} '99},
657 year = {1999},
658 publisher = {ACM Press},
659 note = {\newline \url{http://citeseer.nj.nec.com/jakobsson99flash.html}},
662 @InProceedings{SK,
663 author = {Joe Kilian and Kazue Sako},
664 title = {Receipt-Free {MIX}-Type Voting Scheme - A Practical Solution to
665 the Implementation of a Voting Booth},
666 booktitle = {EUROCRYPT '95},
667 year = {1995},
668 publisher = {Springer-Verlag},
671 @InProceedings{OAEP,
672 author = {M. Bellare and P. Rogaway},
673 year = {1994},
674 booktitle = {EUROCRYPT '94},
675 title = {Optimal {A}symmetric {E}ncryption {P}adding : How To Encrypt With
676 {RSA}},
677 publisher = {Springer-Verlag},
678 note = {\newline \url{http://www-cse.ucsd.edu/users/mihir/papers/oaep.html}},
680 @inproceedings{babel,
681 title = {Mixing {E}-mail With {B}abel},
682 author = {Ceki G\"ulc\"u and Gene Tsudik},
683 booktitle = {{Network and Distributed Security Symposium (NDSS 96)}},
684 year = 1996,
685 month = {February},
686 pages = {2--16},
687 publisher = {IEEE},
689 %note = {\url{http://citeseer.nj.nec.com/2254.html}},
691 @Misc{rprocess,
692 author = {RProcess},
693 title = {Selective Denial of Service Attacks},
694 note = {\newline \url{http://www.eff.org/pub/Privacy/Anonymity/1999\_09\_DoS\_remail\_vuln.html}},
697 @Article{remailer-history,
698 author = {Sameer Parekh},
699 title = {Prospects for Remailers},
700 journal = {First Monday},
701 volume = {1},
702 number = {2},
703 month = {August},
704 year = {1996},
705 note = {\url{http://www.firstmonday.dk/issues/issue2/remailers/}},
708 @Article{chaum-mix,
709 author = {David Chaum},
710 title = {Untraceable electronic mail, return addresses, and digital pseudo-nyms},
711 journal = {Communications of the ACM},
712 year = {1981},
713 volume = {4},
714 number = {2},
715 month = {February},
717 %note = {\url{http://www.eskimo.com/~weidai/mix-net.txt}},
719 @InProceedings{nym-alias-net,
720 author = {David Mazi\`{e}res and M. Frans Kaashoek},
721 title = {{The Design, Implementation and Operation of an Email
722 Pseudonym Server}},
723 booktitle = {$5^{th}$ ACM Conference on Computer and
724 Communications Security (CCS'98)},
725 year = 1998,
726 publisher = {ACM Press},
728 %note = {\newline \url{http://www.scs.cs.nyu.edu/~dm/}},
730 @InProceedings{tangler,
731 author = {Marc Waldman and David Mazi\`{e}res},
732 title = {Tangler: A Censorship-Resistant Publishing System
733 Based on Document Entanglements},
734 booktitle = {$8^{th}$ ACM Conference on Computer and
735 Communications Security (CCS-8)},
736 pages = {86--135},
737 year = 2001,
738 publisher = {ACM Press},
740 %note = {\url{http://www.scs.cs.nyu.edu/~dm/}}
742 @misc{neochaum,
743 author = {Tim May},
744 title = {Payment mixes for anonymity},
745 howpublished = {E-mail archived at
746 \url{http://\newline www.inet-one.com/cypherpunks/dir.2000.02.28-2000.03.05/msg00334.html}},
749 @misc{helsingius,
750 author = {J. Helsingius},
751 title = {{\tt anon.penet.fi} press release},
752 note = {\newline \url{http://www.penet.fi/press-english.html}},
755 @InProceedings{garay97secure,
756 author = {J. Garay and R. Gennaro and C. Jutla and T. Rabin},
757 title = {Secure distributed storage and retrieval},
758 booktitle = {11th International Workshop, WDAG '97},
759 pages = {275--289},
760 year = {1997},
761 publisher = {Springer-Verlag, LNCS 1320},
762 note = {\newline \url{http://citeseer.nj.nec.com/garay97secure.html}},
765 @InProceedings{PIK,
766 author = {C. Park and K. Itoh and K. Kurosawa},
767 title = {Efficient anonymous channel and all/nothing election scheme},
768 booktitle = {Advances in Cryptology -- {EUROCRYPT} '93},
769 pages = {248--259},
770 publisher = {Springer-Verlag, LNCS 765},
773 @Misc{pgpfaq,
774 key = {PGP},
775 title = {{PGP} {FAQ}},
776 note = {\newline \url{http://www.faqs.org/faqs/pgp-faq/}},
779 @Article{riordan-schneier,
780 author = {James Riordan and Bruce Schneier},
781 title = {A Certified E-mail Protocol with No Trusted Third Party},
782 journal = {13th Annual Computer Security Applications Conference},
783 month = {December},
784 year = {1998},
785 note = {\newline \url{http://www.counterpane.com/certified-email.html}},
789 @Article{crowds-tissec,
790 author = {Michael K. Reiter and Aviel D. Rubin},
791 title = {Crowds: Anonymity for Web Transactions},
792 journal = {ACM TISSEC},
793 year = 1998,
794 volume = 1,
795 number = 1,
796 pages = {66--92},
797 month = {November},
799 %note = {\url{http://citeseer.nj.nec.com/284739.html}}
801 @Article{crowds-dimacs,
802 author = {Michael K. Reiter and Aviel D. Rubin},
803 title = {Crowds: Anonymity for Web Transactions},
804 journal = {{DIMACS} Technical Report (Revised)},
805 volume = {97},
806 number = {15},
807 month = {August},
808 year = {1997},
811 @Misc{advogato,
812 author = {Raph Levien},
813 title = {Advogato's Trust Metric},
814 note = {\newline \url{http://www.advogato.org/trust-metric.html}},
817 @InProceedings{publius,
818 author = {Marc Waldman and Aviel Rubin and Lorrie Cranor},
819 title = {Publius: {A} robust, tamper-evident, censorship-resistant and
820 source-anonymous web publishing system},
821 booktitle = {Proc. 9th USENIX Security Symposium},
822 pages = {59--72},
823 year = {2000},
824 month = {August},
826 %note = {\newline \url{http://citeseer.nj.nec.com/waldman00publius.html}},
828 @Misc{freedom-nyms,
829 author = {Russell Samuels},
830 title = {Untraceable Nym Creation on the {F}reedom {N}etwork},
831 year = {1999},
832 month = {November},
833 day = {21},
834 note = {\newline \url{http://www.freedom.net/products/whitepapers/white11.html}},
837 @techreport{freedom2-arch,
838 title = {Freedom Systems 2.0 Architecture},
839 author = {Philippe Boucher and Adam Shostack and Ian Goldberg},
840 institution = {Zero Knowledge Systems, {Inc.}},
841 year = {2000},
842 month = {December},
843 type = {White Paper},
844 day = {18},
847 @techreport{freedom21-security,
848 title = {Freedom Systems 2.1 Security Issues and Analysis},
849 author = {Adam Back and Ian Goldberg and Adam Shostack},
850 institution = {Zero Knowledge Systems, {Inc.}},
851 year = {2001},
852 month = {May},
853 type = {White Paper},
856 @inproceedings{cfs:sosp01,
857 title = {Wide-area cooperative storage with {CFS}},
858 author = {Frank Dabek and M. Frans Kaashoek and David Karger and Robert Morris and Ion Stoica},
859 booktitle = {18th {ACM} {S}ymposium on {O}perating {S}ystems {P}rinciples ({SOSP} '01)},
860 year = {2001},
861 month = {October},
862 address = {Chateau Lake Louise, Banff, Canada},
865 @inproceedings{SS03,
866 title = {Passive Attack Analysis for Connection-Based Anonymity Systems},
867 author = {Andrei Serjantov and Peter Sewell},
868 booktitle = {Computer Security -- ESORICS 2003},
869 publisher = {Springer-Verlag, LNCS (forthcoming)},
870 year = {2003},
871 month = {October},
873 %note = {\url{http://www.cl.cam.ac.uk/users/aas23/papers_aas/conn_sys.ps}},
875 @Misc{pk-relations,
876 author = {M. Bellare and A. Desai and D. Pointcheval and P. Rogaway},
877 title = {Relations Among Notions of Security for Public-Key Encryption
878 Schemes},
879 howpublished = {
880 Extended abstract in {\em Advances in Cryptology - CRYPTO '98}, LNCS Vol. 1462.
881 Springer-Verlag, 1998.
882 Full version available from \newline \url{http://www-cse.ucsd.edu/users/mihir/}},
886 @InProceedings{mix-acc,
887 author = {Roger Dingledine and Michael J. Freedman and David
888 Hopwood and David Molnar},
889 title = {{A Reputation System to Increase MIX-net
890 Reliability}},
891 booktitle = {Information Hiding (IH 2001)},
892 pages = {126--141},
893 year = 2001,
894 editor = {Ira S. Moskowitz},
895 publisher = {Springer-Verlag, LNCS 2137},
897 %note = {\url{http://www.freehaven.net/papers.html}},
899 @InProceedings{casc-rep,
900 author = {Roger Dingledine and Paul Syverson},
901 title = {{Reliable MIX Cascade Networks through Reputation}},
902 booktitle = {Financial Cryptography},
903 year = 2002,
904 editor = {Matt Blaze},
905 publisher = {Springer-Verlag, LNCS 2357},
907 %note = {\newline \url{http://www.freehaven.net/papers.html}},
909 @InProceedings{zhou96certified,
910 author = {Zhou and Gollmann},
911 title = {Certified Electronic Mail},
912 booktitle = {{ESORICS: European Symposium on Research in Computer
913 Security}},
914 publisher = {Springer-Verlag, LNCS 1146},
915 year = {1996},
916 note = {\newline \url{http://citeseer.nj.nec.com/zhou96certified.html}},
919 @Misc{realtime-mix,
920 author = {Anja Jerichow and Jan M\"uller and Andreas Pfitzmann and
921 Birgit Pfitzmann and Michael Waidner},
922 title = {{Real-Time MIXes: A Bandwidth-Efficient Anonymity Protocol}},
923 howpublished = {IEEE Journal on Selected Areas in Communications, 1998.},
924 note = {\url{http://www.zurich.ibm.com/security/publications/1998.html}},
927 @InProceedings{danezis-pets03,
928 author = {George Danezis},
929 title = {Mix-networks with Restricted Routes},
930 booktitle = {Privacy Enhancing Technologies (PET 2003)},
931 year = 2003,
932 editor = {Roger Dingledine},
933 publisher = {Springer-Verlag LNCS 2760}
936 @InProceedings{gap-pets03,
937 author = {Krista Bennett and Christian Grothoff},
938 title = {{GAP} -- practical anonymous networking},
939 booktitle = {Privacy Enhancing Technologies (PET 2003)},
940 year = 2003,
941 editor = {Roger Dingledine},
942 publisher = {Springer-Verlag LNCS 2760}
945 @Article{hordes-jcs,
946 author = {Brian Neal Levine and Clay Shields},
947 title = {Hordes: A Multicast-Based Protocol for Anonymity},
948 journal = {Journal of Computer Security},
949 year = 2002,
950 volume = 10,
951 number = 3,
952 pages = {213--240}
955 @TechReport{herbivore,
956 author = {Sharad Goel and Mark Robson and Milo Polte and Emin G\"{u}n Sirer},
957 title = {Herbivore: A Scalable and Efficient Protocol for Anonymous Communication},
958 institution = {Cornell University Computing and Information Science},
959 year = 2003,
960 type = {Technical Report},
961 number = {TR2003-1890},
962 month = {February}
965 @InProceedings{p5,
966 author = {Rob Sherwood and Bobby Bhattacharjee and Aravind Srinivasan},
967 title = {$P^5$: A Protocol for Scalable Anonymous Communication},
968 booktitle = {2002 IEEE Symposium on Security and Privacy},
969 pages = {58--70},
970 year = 2002,
971 publisher = {IEEE CS}
974 @phdthesis{ian-thesis,
975 title = {A Pseudonymous Communications Infrastructure for the Internet},
976 author = {Ian Goldberg},
977 school = {UC Berkeley},
978 year = {2000},
979 month = {December},
982 @Article{taz,
983 author = {Ian Goldberg and David Wagner},
984 title = {TAZ Servers and the Rewebber Network: Enabling
985 Anonymous Publishing on the World Wide Web},
986 journal = {First Monday},
987 year = 1998,
988 volume = 3,
989 number = 4,
990 month = {August},
991 note = {\url{http://www.firstmonday.dk/issues/issue3_4/goldberg/}}
994 @Misc{tcp-over-tcp-is-bad,
995 key = {tcp-over-tcp-is-bad},
996 title = {Why TCP Over TCP Is A Bad Idea},
997 author = {Olaf Titz},
998 note = {\url{http://sites.inka.de/sites/bigred/devel/tcp-tcp.html}}
1001 @inproceedings{wright02,
1002 title = {An Analysis of the Degradation of Anonymous Protocols},
1003 author = {Matthew Wright and Micah Adler and Brian Neil Levine and Clay Shields},
1004 booktitle = {{Network and Distributed Security Symposium (NDSS 02)}},
1005 year = {2002},
1006 month = {February},
1007 publisher = {IEEE},
1010 @inproceedings{wright03,
1011 title = {Defending Anonymous Communication Against Passive Logging Attacks},
1012 author = {Matthew Wright and Micah Adler and Brian Neil Levine and Clay Shields},
1013 booktitle = {IEEE Symposium on Security and Privacy},
1014 pages= {28--41},
1015 year = {2003},
1016 month = {May},
1017 publisher = {IEEE CS},
1020 @Misc{jap-backdoor,
1021 author={The AN.ON Project},
1022 howpublished={Press release},
1023 year={2003},
1024 month={September},
1025 day={2},
1026 title={German Police proceeds against anonymity service},
1027 note={\url{http://www.datenschutzzentrum.de/material/themen/presse/anon-bka_e.htm}}
1031 %%% Local Variables:
1032 %%% mode: latex
1033 %%% TeX-master: "tor-design"
1034 %%% End: