Distributed Storage of Tor Hidden Service Descriptors

Karsten Loesing · 2007

Tor provides a mechanism for responder anonymity via hidden services. As a part of these, Tor provides storage on its central directory servers to allow pub-lishing and retrieving rendezvous service descriptors. This proposal suggests to replace the centralized ap-proach by a distributed storage of descriptors to the larger set of onion routers. Benefits include (1) better load balancing which is vital for the further growing of the network, (2) a more scalable way to publish descriptors, and (3) extensibility of hidden services to features like human-readable names or client au-thentication. As possible drawback can be seen that new threats arise due to decentralization that need to be discussed and handled. In this project a structure is applied to the network of onion routers, based on concepts known from dis-tributed hash tables and consistent hashing systems. Every participating router is made responsible for a limited set of descriptors. It is not necessary to main-tain an own routing table, but possible to rely on the router list managed by the Tor directory. Some amount of replication needs to be added to overcome node failures and untrustworthy routers. This pre-vents the worst security threats, as descriptors are signed and have a limited time-to-live. Thus, they cannot be forged or replayed. Preliminary measure-ments show that routers exhibit a very low churn rate which makes them a perfect field for consistent hash-ing. The purpose of this project is to extend the cur-rent Tor sources to a running prototype that contains a distributed storage of rendezvous service descriptor. 1

Read the paper · More papers on PaperTik