Onion messages (OMs) are private messages sent between nodes in the Lightning Network (LN) using onion routing. While they are intended to enable interesting applications such as static invoices, refunds, and asynchronous payments, onion messages may also be used for unintended applications such as streaming or spam. To mitigate this, LN nodes can impose a rate limit on forwarding onion messages. However, if not carried out carefully, the rate limit can expose the network to a denial of service (DoS) attack, where an adversary may disrupt or degrade the OM service by flooding the network. This DoS threat is particularly concerning because, under current specifications, a single OM can traverse through hundreds of nodes, affecting all the nodes on its way. In addition, the adversary can hide their true identity thanks to the privacy-preserving feature of onion routing. To address this threat, we propose a simple solution with two main components. The first component limits the distance over which OMs can travel. For this purpose, we propose two methods: a hard leash and a soft leash. The hard leash imposes a strict limit on how far OMs can travel, while the soft leash makes it exponentially more difficult for OMs to traverse long distances. While the first method requires changes in the message format, the second method can easily be adopted without altering OMs. The second component of our solution consists of a set of simple yet effective forwarding and routing rules. We demonstrate that when these rules and the proposed leashes are applied, an adversary cannot degrade the onion messaging service, assuming that the adversary does not control a significant fraction of funds in the network.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Short Paper: Onion Messages on Leash

  • Amin Bashiri,
  • Majid Khabbazian

摘要

Onion messages (OMs) are private messages sent between nodes in the Lightning Network (LN) using onion routing. While they are intended to enable interesting applications such as static invoices, refunds, and asynchronous payments, onion messages may also be used for unintended applications such as streaming or spam. To mitigate this, LN nodes can impose a rate limit on forwarding onion messages. However, if not carried out carefully, the rate limit can expose the network to a denial of service (DoS) attack, where an adversary may disrupt or degrade the OM service by flooding the network. This DoS threat is particularly concerning because, under current specifications, a single OM can traverse through hundreds of nodes, affecting all the nodes on its way. In addition, the adversary can hide their true identity thanks to the privacy-preserving feature of onion routing. To address this threat, we propose a simple solution with two main components. The first component limits the distance over which OMs can travel. For this purpose, we propose two methods: a hard leash and a soft leash. The hard leash imposes a strict limit on how far OMs can travel, while the soft leash makes it exponentially more difficult for OMs to traverse long distances. While the first method requires changes in the message format, the second method can easily be adopted without altering OMs. The second component of our solution consists of a set of simple yet effective forwarding and routing rules. We demonstrate that when these rules and the proposed leashes are applied, an adversary cannot degrade the onion messaging service, assuming that the adversary does not control a significant fraction of funds in the network.