Skip to content

Commit a8b53b7

Browse files
authored
Merge pull request #55 from intarchboard/tfpauly-patch-7
Explain timing separation of privacy pass contexts
2 parents ef019ad + f23e53c commit a8b53b7

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

draft-iab-privacy-partitioning.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -489,6 +489,22 @@ revealed during the redemption context.
489489
~~~
490490
{: #diagram-privacypass title="Diagram of contexts in Privacy Pass"}
491491

492+
Since the redemption context and issuance context are separate connections
493+
that involve separate entities, they can also be further decoupled by
494+
running those parts of the protocols at different times. Clients can
495+
fetch tokens through the issuance context early, and cache the tokens
496+
to later use in redemption contexts. This can aid in partitioning identifiers
497+
and data.
498+
499+
{{PRIVACYPASS}} describes different deployment models for which entities operate
500+
origins, attesters, and issuers; in some models, they are all separate
501+
entities, but in others, they can be operated by the same entity. The
502+
model impacts the effectiveness of partitioning, and some models
503+
(such as when all three are operated by the same entity) only provide
504+
effective partitioning when the timing of connections on the two
505+
contexts are not correlated, and when the client uses different
506+
identifiers (such as different IP addresses) on each context.
507+
492508
## Privacy Preserving Measurement
493509

494510
The Privacy Preserving Measurement (PPM) working group is chartered to develop protocols and systems

0 commit comments

Comments
 (0)