Overlay for communication anonymity and privacy in a computer network
A plurality of nodes connected to the plurality of servers that form a broadcasting overlay over a network for performing best effort broadcasting of data through the broadcasting overlay, may receive, from a first computing device of a plurality of computing devices connected to the broadcasting overlay, a first encrypted message and may perform best effort broadcasting of the first encrypted message through the broadcasting overlay to send, in an end-to-end encrypted manner, the first encrypted message to a first service of a plurality of services. The plurality of nodes may also receive, from the plurality of services, a second encrypted message, and may perform best effort broadcasting of the second encrypted message to propagate the second encrypted message through the broadcasting overlay to send, in the end-to-end encrypted manner, the second encrypted message to a second computing device of the plurality of computing devices.
1 . A method comprising:
periodically receiving, by a computing device associated with a user and from a broadcasting overlay that includes a dynamic topology of a plurality of nodes in a network, an announcement from a plurality of services at a plurality of servers connected to the broadcasting overlay, wherein the announcement indicates a plurality of roles associated with the plurality of services and information associated with a plurality of encryption keys that are associated with the plurality of services;
determining, by the computing device and based at least in part on the announcement, a service associated with a specified role;
encrypting, by the computing device and using an encryption key associated with the service that is derived from at least the information associated with the plurality of encryption keys as indicated by the announcement, a message to be sent to the service to generate an encrypted message; and
sending, by the computing device, the encrypted message to one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the encrypted message to propagate the encrypted message throughout the broadcasting overlay to the service.
2 . The method of claim 1 , wherein:
determining the service associated with the specified role further includes determining, by the computing device and based at least in part on the announcement, the service associated with the specified role of storing messages intended for a second user associated with a second computing device; and
encrypting the message to be sent to the service to generate the encrypted message further includes encrypting, by the computing device and using at least an encryption key associated with the second user, the message to generate the encrypted message.
3 . The method of claim 1 , wherein:
determining the service associated with the specified role further includes determining, by the computing device and based at least in part on the announcement, one or more services associated with a role of mixing messages received by the broadcasting overlay; and
encrypting the message to be sent to the service to generate the encrypted message further includes encrypting, by the computing device and using each of one or more encryption keys associated with the one or more services, the message to generate the encrypted message to enable the one or more services to each perform mixing of messages including the encrypted message.
4 . The method of claim 1 , wherein sending the encrypted message to one or more of the plurality of nodes further includes:
generating, by the computing device, a second message that includes the encrypted message and an indication of a number of mixing services of the plurality of services that are to perform mixing of messages;
encrypting, by the computing device, the second message to generate a second encrypted message; and
sending, by the computing device, the second encrypted message to the one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the second encrypted message to propagate the second encrypted message throughout the broadcasting overlay to the service and to enable the number of mixing services to each perform mixing of messages including the second encrypted message.
5 . The method of claim 1 , further comprising:
determining, by the computing device and based at least in part on the announcement, a second service of the plurality of services associated with a role of storing messages intended for the user;
periodically polling, by the computing device via the broadcasting overlay, the second service for the messages intended for the user sent by one or more other entities; and
in response to polling the second service, receiving, by the computing device and from the second service via the broadcasting overlay, one or more messages intended for the user.
6 . The method of claim 5 , further comprising:
registering, by the computing device, the user with a pseudonymous offline directory (POD) service; and
in response to registering the user with the POD service, receiving an indication of an identity-based encryption key for the user.
7 . The method of claim 6 , further comprising:
decrypting, by the computing device and using the identity-based encryption key for the user, the one or more messages intended for the user.
8 . The method of claim 6 , wherein receiving the identity-based encryption key for the user further comprises:
in response to registering the user with the POD service, receiving, by the computing device and from the POD service, a random identifier;
encrypting, by the computing device using a one-time response key, the random identifier to generate an encrypted random identifier;
sending, by the computing device to the POD service, the encrypted random identifier;
in response to sending the encrypted random identifier, receiving, by the computing device and from the POD service, an encrypted identity-based encryption key for the user; and
decrypting, by the computing device using the one-time response key, the encrypted identity-based encryption key for the user to determine the identity-based encryption key for the user.
9 . The method of claim 2 , wherein encrypting, using at least the encryption key associated with the second user, the message to generate the encrypted message further comprises:
determining, by the computing device, the encryption key associated with the second user based at least in part on a pseudonym associated with the second user; and
encrypting, by the computing device and using at least the encryption key associated with the second user, the message to generate the encrypted message.
10 . The method of claim 1 , wherein sending the encrypted message to one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the encrypted message to propagate the encrypted message throughout the broadcasting overlay to the service further comprises:
sending, by the computing device, the encrypted message via one or more proxy front-ends that interface, via an associated proxy back-end, with the broadcasting overlay to the one or more of the plurality of nodes.
11 . The method of claim 10 , further comprising:
sending, by the computing device, a proxy setup request through the broadcasting overlay to a storage service of the plurality of services that is periodically polled by a proxy setup fulfiller;
in response to sending the proxy setup request, receiving, by the computing device and from the proxy setup fulfiller, indications of a sequence of the one or more proxy front-ends that interface, via the associated proxy back-end, with the broadcasting overlay; and
creating, by the computing device, one or more tunnels between the computing device and the one or more proxy front-ends to communicate over the broadcasting overlay.
12 . The method of claim 10 , further comprising:
sending, by the computing device to one or more computing devices associated with one or more contacts of the user, indications of the one or more proxy front-ends that interface with the broadcasting overlay to enable the one or more computing devices to use the one or more proxy front-ends to communicate with the broadcasting overlay.
13 . The method of claim 10 , further comprising:
receiving, by the computing device from another computing device associated with a contact of the user, an indication of the one or more proxy front-ends that interface, via the associated proxy back-end, with the broadcasting overlay to enable the one or more computing devices to use the one or more proxy front-ends to communicate with the broadcasting overlay.
14 . A computing device comprising:
memory; and
processing circuitry operably coupled to the memory and configured to:
periodically receive, from a broadcasting overlay that includes a dynamic topology of a plurality of nodes in a network, an announcement from a plurality of services at a plurality of servers connected to the broadcasting overlay, wherein the announcement indicates a plurality of roles associated with the plurality of services and information associated with a plurality of encryption keys that are associated with the plurality of services;
determine, based at least in part on the announcement, a service associated with a specified role;
encrypt, using an encryption key associated with the service that is derived from at least the information associated with the plurality of encryption keys as indicated by the announcement, a message to be sent to the service to generate an encrypted message; and
send the encrypted message to one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the encrypted message to propagate the encrypted message throughout the broadcasting overlay to the service.
15 . The computing device of claim 14 , wherein:
to determine the service associated with the specified role, the processing circuitry is further configured to determine, based at least in part on the announcement, the service associated with the specified role of storing messages intended for a second user associated with a second computing device; and
to encrypt the message to be sent to the service to generate the encrypted message, the processing circuitry is further configured to encrypt, using at least an encryption key associated with the second user, the message to generate the encrypted message.
16 . The computing device of claim 14 , wherein:
to determine the service associated with the specified role, the processing circuitry is further configured to determine, based at least in part on the announcement, one or more services associated with a role of mixing messages received by the broadcasting overlay; and
to encrypt the message to be sent to the service to generate the encrypted message, the processing circuitry is further configured to encrypt, using each of one or more encryption keys associated with the one or more services, the message to generate the encrypted message to enable the one or more services to each perform mixing of messages including the encrypted message.
17 . The computing device of claim 14 , wherein to send the encrypted message to one or more of the plurality of nodes, the processing circuitry is further configured to:
generate a second message that includes the encrypted message and an indication of a number of mixing services of the plurality of services that are to perform mixing of messages;
encrypt the second message to generate a second encrypted message; and
send the second encrypted message to the one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the second encrypted message to propagate the second encrypted message throughout the broadcasting overlay to the service and to enable the number of mixing services to each perform mixing of messages including the second encrypted message.
18 . The computing device of claim 14 , wherein the processing circuitry is further configured to:
determine, based at least in part on the announcement, a second service of the plurality of services associated with a role of storing messages intended for a user of the computing device;
periodically poll, via the broadcasting overlay, the second service for the messages intended for the user sent by one or more other entities; and
in response to polling the second service, receive, from the second service via the broadcasting overlay, one or more messages intended for the user of the computing device.
19 . The computing device of claim 18 , wherein the processing circuitry is further configured to:
register the user with a pseudonymous offline directory (POD) service;
in response to registering the user with the POD service, receive an indication of an identity-based encryption key for the user; and
decrypt, using the identity-based encryption key for the user, the one or more messages intended for the user.
20 . A computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to:
periodically receive, from a broadcasting overlay that includes a dynamic topology of a plurality of nodes in a network, an announcement from a plurality of services at a plurality of servers connected to the broadcasting overlay, wherein the announcement indicates a plurality of roles associated with the plurality of services and information associated with a plurality of encryption keys that are associated with the plurality of services;
determine, based at least in part on the announcement, a service associated with a specified role;
encrypt, using an encryption key associated with the service that is derived from at least the information associated with the plurality of encryption keys as indicated by the announcement, a message to be sent to the service to generate an encrypted message; and
send the encrypted message to one or more of the plurality of nodes to enable the broadcasting overlay to perform best effort broadcasting of the encrypted message to propagate the encrypted message throughout the broadcasting overlay to the service.