{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/106446"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/106446","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"A distributed metadata-private messaging system","abstract":"Private communication over the Internet continues to be a difficult problem. Even if messages are encrypted, it is hard to deliver them without revealing metadata about which pairs of users are communicating. Scalable systems such as Tor are susceptible to traffic analysis. In contrast, the largest-scale systems with metadata privacy require passing all messages through a single server, which places a hard cap on their scalability. This paper presents Stadium, the first system to protect both messages and metadata while being able to scale its work efficiently across multiple servers. Stadium uses the same differential privacy definition for metadata privacy as Vuvuzela, the currently highest-scale system. However, providing privacy in Stadium is significantly more challenging because distributing users' traffic across servers creates more opportunities for adversaries to observe it. To solve this challenge, Stadium uses a novel verifiable mixnet design. We use a verifiable shuffle scheme that we extend to allow for efficient group verification, and present a verifiable distribution primitive to check message transfers across servers. We show that Stadium can scale to use hundreds of servers, support an order of magnitude more users than Vuvuzela, and cut the costs of operating each server.","abstract_html":"Private communication over the Internet continues to be a difficult problem. Even if messages are encrypted, it is hard to deliver them without revealing metadata about which pairs of users are communicating. Scalable systems such as Tor are susceptible to traffic analysis. In contrast, the largest-scale systems with metadata privacy require passing all messages through a single server, which places a hard cap on their scalability. This paper presents Stadium, the first system to protect both messages and metadata while being able to scale its work efficiently across multiple servers. Stadium uses the same differential privacy definition for metadata privacy as Vuvuzela, the currently highest-scale system. However, providing privacy in Stadium is significantly more challenging because distributing users&#x27; traffic across servers creates more opportunities for adversaries to observe it. To solve this challenge, Stadium uses a novel verifiable mixnet design. We use a verifiable shuffle scheme that we extend to allow for efficient group verification, and present a verifiable distribution primitive to check message transfers across servers. We show that Stadium can scale to use hundreds of servers, support an order of magnitude more users than Vuvuzela, and cut the costs of operating each server.","abstract_has_math":false,"creators":["Tyagi, Nirvan"],"institution":"Massachusetts Institute of Technology","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science.","school":null,"contributors":[],"advisors":["Matei Zaharia."],"committee_chairs":[],"committee_members":[],"year":2016,"date_issued":"2016","date_published":"2016","updated_at":"2026-07-22T22:21:51Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/1721.1/106446","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Matei Zaharia."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Tyagi, Nirvan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2017-01-12T18:33:50Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2017-01-12T18:33:50Z"]},{"key":"dc:date.issued","label":"Date","values":["2016"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/1721.1/106446"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2016.","Cataloged from PDF version of thesis.","Includes bibliographical references (pages 61-63)."]},{"key":"dc:description.abstract","label":"Abstract","values":["Private communication over the Internet continues to be a difficult problem. Even if messages are encrypted, it is hard to deliver them without revealing metadata about which pairs of users are communicating. Scalable systems such as Tor are susceptible to traffic analysis. In contrast, the largest-scale systems with metadata privacy require passing all messages through a single server, which places a hard cap on their scalability. This paper presents Stadium, the first system to protect both messages and metadata while being able to scale its work efficiently across multiple servers. Stadium uses the same differential privacy definition for metadata privacy as Vuvuzela, the currently highest-scale system. However, providing privacy in Stadium is significantly more challenging because distributing users' traffic across servers creates more opportunities for adversaries to observe it. To solve this challenge, Stadium uses a novel verifiable mixnet design. We use a verifiable shuffle scheme that we extend to allow for efficient group verification, and present a verifiable distribution primitive to check message transfers across servers. We show that Stadium can scale to use hundreds of servers, support an order of magnitude more users than Vuvuzela, and cut the costs of operating each server."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M. Eng."]},{"key":"dc:title","label":"Title","values":["A distributed metadata-private messaging system"]}]}],"canonical_facts":{"dc:contributor.advisor":["Matei Zaharia."],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:contributor.other":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:creator":["Tyagi, Nirvan"],"dc:date.accessioned":["2017-01-12T18:33:50Z"],"dc:date.available":["2017-01-12T18:33:50Z"],"dc:date.issued":["2016"],"dc:description":["Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2016.","Cataloged from PDF version of thesis.","Includes bibliographical references (pages 61-63)."],"dc:description.abstract":["Private communication over the Internet continues to be a difficult problem. Even if messages are encrypted, it is hard to deliver them without revealing metadata about which pairs of users are communicating. Scalable systems such as Tor are susceptible to traffic analysis. In contrast, the largest-scale systems with metadata privacy require passing all messages through a single server, which places a hard cap on their scalability. This paper presents Stadium, the first system to protect both messages and metadata while being able to scale its work efficiently across multiple servers. Stadium uses the same differential privacy definition for metadata privacy as Vuvuzela, the currently highest-scale system. However, providing privacy in Stadium is significantly more challenging because distributing users' traffic across servers creates more opportunities for adversaries to observe it. To solve this challenge, Stadium uses a novel verifiable mixnet design. We use a verifiable shuffle scheme that we extend to allow for efficient group verification, and present a verifiable distribution primitive to check message transfers across servers. We show that Stadium can scale to use hundreds of servers, support an order of magnitude more users than Vuvuzela, and cut the costs of operating each server."],"dc:description.degree":["M. Eng."],"dc:identifier.uri":["http://hdl.handle.net/1721.1/106446"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["A distributed metadata-private messaging system"],"dc:type":["Thesis"]},"updated_at":"2026-07-22T22:21:51Z"}