Probabilistic Anonymity and Admissible Schedulers

dc.creatorGarcia, Flavio D.
dc.creatorvan Rossum, Peter
dc.creatorSokolova, Ana
dc.date2007-06-07
dc.date.accessioned2026-07-07T08:04:30Z
dc.date.available2026-07-07T08:04:30Z
dc.descriptionWhen studying safety properties of (formal) protocol models, it is customary to view the scheduler as an adversary: an entity trying to falsify the safety property. We show that in the context of security protocols, and in particular of anonymizing protocols, this gives the adversary too much power; for instance, the contents of encrypted messages and internal computations by the parties should be considered invisible to the adversary. We restrict the class of schedulers to a class of admissible schedulers which better model adversarial behaviour. These admissible schedulers base their decision solely on the past behaviour of the system that is visible to the adversary. Using this, we propose a definition of anonymity: for all admissible schedulers the identity of the users and the observations of the adversary are independent stochastic variables. We also develop a proof technique for typical cases that can be used to proof anonymity: a system is anonymous if it is possible to `exchange' the behaviour of two users without the adversary `noticing'.
dc.identifierhttps://arxiv.org/abs/0706.1019
dc.identifierhttp://arxiv.org/abs/0706.1019
dc.identifier.urihttp://salesiana.dossiersoluciones.com/handle/123456789/129984
dc.subjectCryptography and Security
dc.titleProbabilistic Anonymity and Admissible Schedulers
dc.typetext

Files

Collections