Experiences Building Security Applications on DHTs
Roxana GeambasuJarret FalknerPaul Gardner, Tadayoshi Kohno, Arvind Krishnamurthy, Henry M. Levy · 2009
In the recent past we introduced two new security applications built on peer-to-peer systems and distributed hashtables (DHTs). First, we designed Adeona [18], which leverages DHTs to provide a privacy-preserving laptop tracking solution. Second, we designed the Vanish [10] selfdestructing data system, which uses DHTs to protect against retroactive attacks on archived data in the cloud. Both systems exploit intuitive properties of DHTs that dierentiate them from centralized solutions: e.g., complete or partial decentralization, giant scale, and geographic distribution. We implemented and made publicly available research prototypes of both Adeona and Vanish; the Adeona prototype uses OpenDHT as its underlying DHT and the Vanish prototype uses the Vuze DHT. While the properties of DHTs make them a tempting environment for new security-based systems, existing DHTs were never designed to support security or privacy applications, and such applications therefore stress DHTs in new ways. This paper provides a retrospective from our collective experience both designing and prototyping the two DHT-based security/privacy applications, and operating and designing deployed DHTs (OpenDHT and Vuze). We discuss limitations and vulnerabilities of modern DHTs for security applications and propose very simple defenses that — perhaps surprisingly — greatly raise the bar for existing DHTs against certain privacy attacks. We also advocate for a hybrid approach that combines the best of both decentralized DHTs and centralized services for new security applications. Our goal is to inform the design of future DHTs and to strengthen the applicability of existing DHTs for supporting applications such as Adeona and Vanish.