Decoupling Network Layer Location and Transport Layer Identity for Communication Flow Privacy
Gregor Tamati Haywood, Saleem Noel BhattiAlthough the tracking of a user’s network location is often considered a violation of privacy, building technical guarantees of topological location privacy (and geolocation by inference) is difficult: topological location information is encoded in the Internet Protocol (IP) address, and is necessarily exposed both to endpoints and along the communication path, for correct packet forwarding. Existing defences either extend the trust boundary to a third party (e.g., Virtual Private Networks (VPNs)), or operate at the application layer (e.g., Tor), and do not provide a general defence for all protocols and applications. In all cases, these defences use encrypted tunnels, which require processing overheads on top of the cryptographic protections that are now ubiquitous for end-to-end communication. We show that the Identifier-Locator Network Protocol’s (ILNP) mutable locator values can be used to implement locator rewriting, a location privacy defence similar to Tor’s chain of relays but at the network layer and without cryptographic overheads. Further, we demonstrate that not only is this defence compatible with other ILNP-based privacy enhancements–specifically ephemeral NIDs and multipath evasion–but synergises well with them to provide a stronger defence for identity, location, and data privacy than is possible when using these techniques in isolation. Looking beyond our proof-of-concept implementation, we also outline the design criteria for the secure control protocol necessary when deploying this defence over the Internet.