{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/122555"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/122555","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Towards anonymous and metadata private communication at Internet scale","abstract":"As the world becomes more connected, privacy is becoming harder to maintain. From social media services to Internet service providers to state-sponsored mass-surveillance programs, many outlets collect sensitive information about the users and the communication between them - often without the users ever knowing about it. In response, many Internet users have turned to end-to-end encryption, like Signal and TLS, to protect the content of the communication. Unfortunately, these works do little to hide the metadata of the communication, such as when and with whom a user is communicating. In scenarios where the metadata are sensitive, encryption alone is not sufficient to ensure users' privacy. Most prior communication systems that provide metadata privacy fall into one of two categories: (1) systems that provide formal privacy guarantees against global adversaries but do not scale to large numbers of users, or (2) systems that scale easily to a large user base but do not provide strong guarantees against global adversaries. In this thesis, I will present three systems that aim to bridge the gap between the two categories to enable private communication with strong guarantees for many millions of users. First, I will present Atom, a horizontally scalable anonymous broadcast system for short messages that defends against a global adversary who monitors the entire network and controls a significant fraction of the servers while scaling easily by adding more servers to its network. Then, I will present Quark, another horizontally scalable anonymous broadcast system that trades bandwidth for latency to achieve more than an order of magnitude speed-up over Atom under the same threat model. Finally, I will present XRD, which provides metadata private communication between two honest users against the same adversary using a novel cryptographic primitive called aggregate hybrid shuffle.","abstract_html":"As the world becomes more connected, privacy is becoming harder to maintain. From social media services to Internet service providers to state-sponsored mass-surveillance programs, many outlets collect sensitive information about the users and the communication between them - often without the users ever knowing about it. In response, many Internet users have turned to end-to-end encryption, like Signal and TLS, to protect the content of the communication. Unfortunately, these works do little to hide the metadata of the communication, such as when and with whom a user is communicating. In scenarios where the metadata are sensitive, encryption alone is not sufficient to ensure users&#x27; privacy. Most prior communication systems that provide metadata privacy fall into one of two categories: (1) systems that provide formal privacy guarantees against global adversaries but do not scale to large numbers of users, or (2) systems that scale easily to a large user base but do not provide strong guarantees against global adversaries. In this thesis, I will present three systems that aim to bridge the gap between the two categories to enable private communication with strong guarantees for many millions of users. First, I will present Atom, a horizontally scalable anonymous broadcast system for short messages that defends against a global adversary who monitors the entire network and controls a significant fraction of the servers while scaling easily by adding more servers to its network. Then, I will present Quark, another horizontally scalable anonymous broadcast system that trades bandwidth for latency to achieve more than an order of magnitude speed-up over Atom under the same threat model. Finally, I will present XRD, which provides metadata private communication between two honest users against the same adversary using a novel cryptographic primitive called aggregate hybrid shuffle.","abstract_has_math":false,"creators":["Kwon, Young Hyun."],"institution":"Massachusetts Institute of Technology","degree_name":"Doctoral","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","school":null,"contributors":[],"advisors":["Srinivas Devadas."],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019","date_published":"2019","updated_at":"2026-07-22T22:22:02Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/122555","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Srinivas Devadas."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","EECS"]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Kwon, Young Hyun."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2019-10-11T22:11:51Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2019-10-11T22:11:51Z"]},{"key":"dc:date.issued","label":"Date","values":["2019"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctoral"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/122555"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis: Ph. D., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019","Cataloged from PDF version of thesis.","Includes bibliographical references (pages 111-121)."]},{"key":"dc:description.abstract","label":"Abstract","values":["As the world becomes more connected, privacy is becoming harder to maintain. From social media services to Internet service providers to state-sponsored mass-surveillance programs, many outlets collect sensitive information about the users and the communication between them - often without the users ever knowing about it. In response, many Internet users have turned to end-to-end encryption, like Signal and TLS, to protect the content of the communication. Unfortunately, these works do little to hide the metadata of the communication, such as when and with whom a user is communicating. In scenarios where the metadata are sensitive, encryption alone is not sufficient to ensure users' privacy. Most prior communication systems that provide metadata privacy fall into one of two categories: (1) systems that provide formal privacy guarantees against global adversaries but do not scale to large numbers of users, or (2) systems that scale easily to a large user base but do not provide strong guarantees against global adversaries. In this thesis, I will present three systems that aim to bridge the gap between the two categories to enable private communication with strong guarantees for many millions of users. First, I will present Atom, a horizontally scalable anonymous broadcast system for short messages that defends against a global adversary who monitors the entire network and controls a significant fraction of the servers while scaling easily by adding more servers to its network. Then, I will present Quark, another horizontally scalable anonymous broadcast system that trades bandwidth for latency to achieve more than an order of magnitude speed-up over Atom under the same threat model. Finally, I will present XRD, which provides metadata private communication between two honest users against the same adversary using a novel cryptographic primitive called aggregate hybrid shuffle."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Ph. D."]},{"key":"dc:title","label":"Title","values":["Towards anonymous and metadata private communication at Internet scale"]}]}],"canonical_facts":{"dc:contributor.advisor":["Srinivas Devadas."],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","EECS"],"dc:contributor.other":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:creator":["Kwon, Young Hyun."],"dc:date.accessioned":["2019-10-11T22:11:51Z"],"dc:date.available":["2019-10-11T22:11:51Z"],"dc:date.issued":["2019"],"dc:description":["Thesis: Ph. D., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019","Cataloged from PDF version of thesis.","Includes bibliographical references (pages 111-121)."],"dc:description.abstract":["As the world becomes more connected, privacy is becoming harder to maintain. From social media services to Internet service providers to state-sponsored mass-surveillance programs, many outlets collect sensitive information about the users and the communication between them - often without the users ever knowing about it. In response, many Internet users have turned to end-to-end encryption, like Signal and TLS, to protect the content of the communication. Unfortunately, these works do little to hide the metadata of the communication, such as when and with whom a user is communicating. In scenarios where the metadata are sensitive, encryption alone is not sufficient to ensure users' privacy. Most prior communication systems that provide metadata privacy fall into one of two categories: (1) systems that provide formal privacy guarantees against global adversaries but do not scale to large numbers of users, or (2) systems that scale easily to a large user base but do not provide strong guarantees against global adversaries. In this thesis, I will present three systems that aim to bridge the gap between the two categories to enable private communication with strong guarantees for many millions of users. First, I will present Atom, a horizontally scalable anonymous broadcast system for short messages that defends against a global adversary who monitors the entire network and controls a significant fraction of the servers while scaling easily by adding more servers to its network. Then, I will present Quark, another horizontally scalable anonymous broadcast system that trades bandwidth for latency to achieve more than an order of magnitude speed-up over Atom under the same threat model. Finally, I will present XRD, which provides metadata private communication between two honest users against the same adversary using a novel cryptographic primitive called aggregate hybrid shuffle."],"dc:description.degree":["Ph. D."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/122555"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["Towards anonymous and metadata private communication at Internet scale"],"dc:type":["Thesis"],"thesis:degree_name":["Doctoral"]},"updated_at":"2026-07-22T22:22:02Z"}