In this paper we propose a protocol that can be used to covertly send a distress signal through a seemingly normal webserver, even if the adversary is monitoring both the network and the user's device. This allows a user to call for help even when they are in the same physical space as their adversaries. We model such a scenario by introducing a strong adversary model that captures a high degree of access to the user's device and full control over the network. Our model fits into scenarios where a user is under surveillance and wishes to inform a trusted party of the situation. To do this, our method uses existing websites to act as intermediaries between the user and a trusted backend; this enables the user to initiate the distress signal without arousing suspicion, even while being actively monitored. We accomplish this by utilising the TLS handshake to convey additional information; this means that any website wishing to participate can do so with minimal effort and anyone monitoring the traffic will just see common TLS connections. In order for websites to be willing to host such a functionality the protocol must coexist gracefully with users who use normal TLS and the computational overhead must be minimal. We provide a full security analysis of the architecture and prove that the adversary cannot distinguish between a set of communications which contains a distress call and a normal communication.
翻译:本文提出一种协议,可在攻击者同时监控网络与用户设备的情况下,通过看似正常的网页服务器隐蔽发送求救信号。即使用户与攻击者处于同一物理空间,该协议仍能帮助其向外求助。我们通过引入一个强大的攻击者模型来模拟此类场景:该模型假定攻击者能深度访问用户设备并完全控制网络。该模型适用于用户遭受监控、希望向可信方告知自身处境的情景。为此,我们的方法利用现有网站作为用户与可信后端之间的中介,使得用户即便在实时监控下也能发起求救信号而不引起怀疑。我们通过利用TLS握手传输额外信息实现这一目标:任何希望参与该功能的网站只需付出极少代价,而监控网络流量的观察者只能看到普通的TLS连接。为使网站愿意托管此类功能,协议必须与使用正常TLS的用户和谐共存,且计算开销需降至最低。我们对该架构进行了完整的安全分析,证明攻击者无法区分包含求救信号的一组通信与正常通信。