Full text
Anonymous User Registration in Online Forums Using Advanced Cryptographic Tumbling Inspired by Bitcoin Mixers and Server-Hosted Mnemonics: A Comprehensive Self-Hosted Implementation Prithvi Vasireddy College of Engineering, Northeastern University Boston, MA Abstract—This paper introduces a novel protocol for anonymous user registration in self-hosted online forums, designed to counter the pervasive data collection endemic to surveillance capitalism. This system uniquely combines a ”registration tumble,” a multi-party protocol inspired by the WabiSabi Bitcoin CoinJoin scheme, with a robust, user-friendly recovery mechanism based on server-hosted mnemonic shares. The registration tumble ensures that the server cannot link a user’s network identity to their final, issued credential, providing strong, unlinkable anonymity. The recovery system leverages Shamir’s Secret Sharing to split a user’s BIP-39 mnemonic, allowing the server to store an encrypted share for disaster recovery without ever having access to the user’s full key. We present a full-stack implementation using a containerized Flask and Nginx architecture, demonstrating its practicality for the self-hosting community. Performance benchmarks on both an AMD Ryzen 7 5700G and a Raspberry Pi 4 cluster show that our protocol achieves practical latencies for registration and recovery while remaining computationally feasible on low-cost hardware. A rigorous security analysis under a Dolev-Yao-style threat model confirms the protocol’s guarantees of anonymity, unlinkability, and credential security. Index Terms—Anonymous Registration, Cryptographic Tumbling, CoinJoin, WabiSabi, Self-Hosting, Mnemonic Recovery, Shamir’s Secret Sharing, Privacy-Preserving Identity Management I. INTRODUCTION A. The Problem of Digital Identity in the Age of Surveillance Capitalism The modern digital commons is increasingly shaped by an economic logic Shoshana Zuboff has termed ”surveillance capitalism” [1]. This paradigm treats human experience as a raw material to be extracted, analyzed, and monetized, primarily through the prediction and modification of human behavior. Central to this model is the concept of digital identity. Conventional user registration systems, which link a persistent identity to personally identifiable information (PII) such as an email address or phone number, are the primary mechanism for this data extraction. Even within the privacy-conscious selfhosting community, the act of creating a user account often establishes a centralized, linkable record of identity. These This work was supported by the Independent Research Grant for Privacy Engineering. databases, while perhaps managed with benevolent intent, represent a systemic vulnerability. They are susceptible to external breaches, internal misuse, and create what Zuboff calls a ”Big Other”—a ubiquitous digital architecture operating in the interests of surveillance capital, which fundamentally threatens user freedom and democratic oversight [1]. The relentless drive for data-driven certainty risks creating a ”fatally closed world” where behavior is continuously reinforced and predefined, stifling the organic creativity and improvisation that arises from human uncertainty [2]. To counteract this, it is not sufficient to rely on privacy policies, which are promises of behavior; instead, we must engineer systems where privacy is an intrinsic, architectural, and cryptographic guarantee. B. Defining the Challenge The central challenge addressed in this work is twofold. First, how can a user register for an online service, such as a community forum, without revealing a linkable identity to the service provider? Second, how can this anonymity be maintained while providing a practical and secure account recovery mechanism that does not revert to using PII? Many existing Privacy-Preserving Identity Management (PPIdM) systems address aspects of this problem but often depend on a trusted Identity Provider (IP) to vouch for user attributes [3]. This design, while suitable for federated enterprise environments, reintroduces a point of centralization and a trusted third party that can become a vector for privacy compromise. This work specifically targets the self-hosted ecosystem, where the forum administrator is the service provider. In this context, minimizing trust in the server is paramount, as the entity providing the service is the same one from which the user seeks privacy. C. Our Contribution This paper presents a holistic, self-hostable protocol that resolves the tension between anonymity, security, and usability in user registration and recovery. The core innovation lies in reframing the act of user registration as a ”transaction” that requires fungibility. In cryptocurrency systems like Bitcoin, a transaction’s history is public, and privacy is achieved by
breaking the deterministic link between transaction inputs and outputs, making the resulting coins fungible [4], [5]. Similarly, a registration request can be seen as a ”non-fungible” input, identified by a network address, which must be transformed into a ”fungible” or anonymous output—a valid user credential. This reframing allows us to draw upon the sophisticated cryptographic machinery developed for transactional privacy. Our primary contributions are: 1) A Novel Registration Tumbling Protocol: We design and specify a multi-party registration protocol that adapts the principles of advanced, centrally-coordinated Bitcoin CoinJoin schemes, particularly the WabiSabi protocol [4], [6]. This ”registration tumble” allows a cohort of users to collaboratively register, receiving unique, signed credentials in a manner that is cryptographically unlinkable to their initial network connections. 2) Server-Assisted Mnemonic Recovery: We introduce a secure and user-friendly account recovery mechanism based on Shamir’s Secret Sharing (SSS) [7]–[9]. A user’s BIP-39 mnemonic phrase [10], [11] is sharded into three pieces. The server stores one encrypted share, providing a crucial recovery backstop without ever possessing the complete secret, thus balancing security against catastrophic key loss. 3) A Comprehensive Self-Hosted Implementation and Evaluation: We provide a complete, open-source implementation of the protocol using a standard, containerized web stack. This serves as a practical blueprint for deployment. We conduct a thorough performance analysis on both a high-performance desktop and a resourceconstrained Raspberry Pi cluster to demonstrate the system’s real-world feasibility and scalability. D. Roadmap The remainder of this paper is structured as follows. Section II reviews related work in the fields of transaction anonymity and privacy-preserving identity. Section III provides a detailed specification of our system architecture and protocols. Section IV discusses the specifics of our implementation. Section V presents a comprehensive performance evaluation. Section VI provides a rigorous security and privacy analysis of the proposed system. Finally, Section VII concludes the paper and outlines directions for future work. II. BACKGROUND AND RELATED WORK A. The Evolution of Transactional Anonymity in Cryptocurrencies The protocol proposed in this paper is directly inspired by the evolution of privacy-enhancing technologies developed for public blockchains like Bitcoin. The public nature of these ledgers necessitated the creation of techniques to break the linkability of transactions. CoinJoin: The foundational concept of CoinJoin was proposed by Gregory Maxwell in 2013 [4], [5]. It is a trustless protocol wherein multiple participants combine their Unspent Transaction Outputs (UTXOs) into a single, large collaborative transaction. By having multiple inputs and multiple outputs, an external observer cannot definitively link any single input to any single output, creating an ambiguity set. Early implementations, such as the one in Dark Wallet, demonstrated the viability of this approach but often relied on a centralized coordinator that, if malicious, could deanonymize participants [5]. ZeroLink Framework: The ZeroLink framework formalized these ideas into a comprehensive privacy standard [4], [6]. It introduced the architectural separation of ”pre-mix” and ”post-mix” wallets and specified Chaumian CoinJoin as the mixing technique. This technique uses Chaumian blind signatures, a cryptographic primitive that allows a signer (the coordinator) to sign a piece of data without seeing its content. In a CoinJoin context, users submit blinded outputs to the coordinator, who signs them. The users then unblind the signatures and resubmit them anonymously. This prevents the coordinator from linking the initial input registration with the final signed output, making the coordination ”trustless” [6]. A related concept, TumbleBit, achieved a similar trustless mixing property using off-chain payment channels [4]. The primary limitation of ZeroLink was its reliance on fixed-denomination inputs; all participants had to mix the exact same amount of bitcoin. This created usability challenges and could result in ”toxic change”—small, identifiable leftover amounts that could compromise privacy [4]. WabiSabi Protocol: The WabiSabi protocol, introduced in Wasabi Wallet 2.0, represents the current state-of-theart and is the primary inspiration for our work [4], [6]. It overcomes the fixed-denomination limitation of ZeroLink by employing more advanced cryptography. Specifically, it uses keyed verification anonymous credentials and homomorphic value commitments [6], [12]. This allows participants to mix arbitrary, variable amounts in a single round. The coordinator can cryptographically verify that the sum of the inputs equals the sum of the outputs without learning the value of any individual input or output, nor the linkage between them. This is a fundamental shift from achieving privacy through homogenization (making all inputs look identical) to achieving it through provable indistinguishability (making the linkage cryptographically unknowable). This flexibility not only enhances privacy by eliminating toxic change but also dramatically improves the efficiency and scalability of mixing rounds [4]. It is this more powerful and flexible privacy model that we adapt for our registration protocol, where user requests are inherently non-uniform. Table I provides a comparative overview of these anonymity protocols. B. Privacy-Preserving Identity Management (PPIdM) and Anonymous Credentials The broader field of PPIdM aims to provide robust identity and access control while protecting user privacy [3], [13]. A key concept within this field is the Anonymous Credential (AC), first introduced by David Chaum [14], [15]. An AC allows a user to prove they possess a certain attribute or right
TABLE I COMPARISON OF ANONYMITY PROTOCOLS Feature Early CoinJoin ZeroLink WabiSabi Proposed Tumble Trust Model Coordinator Linkage Trustless Coord. Trustless Coord. Trustless Coord. Input Type Fixed Amount Fixed Amount Variable Amounts Registration Data Anonymity Obfuscation Blinding Blinding Blinding Weakness Trust; Timing Fixed Denom. Complexity Sybil Attacks Sources [4], [5] [4], [6] [4], [6], [12] Our contribution (a ”credential”) issued by an authority without revealing their underlying identity [16]. These systems are built on cryptographic primitives such as blind signatures, group signatures, and zero-knowledge proofs, which together enable properties like unforgeability, anonymity, and unlinkability [3], [15], [17], [18]. Much of the academic work in this area has focused on complex scenarios, such as credentials with attributes attested by multiple, distinct certifiers [19], [20], or sophisticated credential revocation schemes [21]–[23]. While powerful, these systems often introduce significant complexity and may rely on a centralized, trusted Identity Provider (IP) to manage the ecosystem [3], [24]. Our work diverges from this trend by focusing on a simplified, single-issuer model tailored for the self-hosted environment. C. Foundational Cryptographic Primitives Our system is constructed from two well-established cryptographic standards. BIP-39 Mnemonic Phrases: Bitcoin Improvement Proposal 39 (BIP-39) is the industry standard for generating and recovering hierarchical deterministic wallets from a humanreadable phrase [10], [11], [25]. The process involves entropy generation, checksum creation, and mapping to a wordlist to produce the phrase. The phrase is then passed through PBKDF2 with 2048 rounds of HMAC-SHA512 to produce a final 512-bit seed [10]. Shamir’s Secret Sharing (SSS): Developed by Adi Shamir, SSS is a cryptographic algorithm for splitting a secret into multiple parts, called shares [8]. A (k, n)-threshold scheme divides a secret into nshares, where any kshares are required to reconstruct it. The mathematical foundation is polynomial interpolation over a finite field [8], [9]. To share a secret S, a random polynomial f(x)of degree k−1is constructed such that f(0) = S: f(x) = S+a1x+a2x2+· · · +ak−1xk−1(1) The shares are points on this polynomial. A crucial property of SSS is its information-theoretic security: possessing k−1 or fewer shares reveals absolutely no information about the secret S[7], [26]. III. SYSTEM ARCHITECTURE AND PROTOCOL DESIGN A. System Overview and Participants The proposed system is a client-server architecture with minimal trust in the server. It consists of two components: •User Client: A browser extension or application responsible for client-side cryptography, including key generation, participating in the registration tumble, and managing mnemonic shares. •Forum Server: The self-hosted web application that coordinates the registration tumble, issues anonymous credentials, stores one encrypted mnemonic share per user, and verifies authentication proofs. The server is considered ”honest-but-curious.” The protocol flow is divided into three phases: credential issuance, mnemonic sharding, and authentication/recovery. B. Phase 1: Anonymous Credential Issuance (The Registration Tumble) This phase, adapted from the WabiSabi communication flow [6], allows a group of users to register simultaneously and anonymously. 1) Round Initiation: The server announces a new registration round, specifying a minimum number of participants, kmin. 2) Input Registration: Each user connects (preferably via Tor [6]) and submits a blinded token B(req)containing their chosen username and a freshly generated public key. 3) Credential Signing: The server collects tokens and, once kmin is reached, signs each one, returning the signed, blinded token S(B(req)) to each client. 4) Output Registration: Each client unblinds its token to get the final valid credential, Cred. Through a new anonymous connection, it registers its username with the server. 5) Round Finalization: The server has a list of initial connections and a list of new usernames, but due to the blinding, it cannot link them. C. Phase 2: Server-Hosted Mnemonic Sharding After registration, the user establishes a secure backup of their master key. 1) Mnemonic Generation: The client generates a standard 12-word BIP-39 mnemonic [10], [11]. 2) Shamir’s Secret Sharing: The client applies a (2,3)- threshold SSS scheme to the mnemonic’s 128-bit entropy, creating three shares: Share1, Share2, Share3[7]–[9]. 3) Share Distribution: •Share 1 (Local): Stored on the user’s primary device. •Share 2 (Offline Backup): Recorded by the user in a secure offline location [25].
Fig. 1. A conceptual diagram illustrating interaction between the User Client and Forum Server across the three protocol phases: Registration, Sharding, and Authentication/Recovery.
Fig. 2. System Architecture. •Share 3 (Server-Hosted): Encrypted with a key derived from a user-provided password and sent to the server. This (2,3) scheme ensures resilience against a single point of failure [8], [26]. D. Phase 3: Authentication and Recovery Standard Authentication: The client uses the local Share1 to reconstruct the private key and generates a zero-knowledge proof of knowledge of the valid server signature on their credential. The server verifies the proof to grant access [27], [28]. Recovery Process: If the user loses Share1, they can recover their account. 1) The user provides their username to the server. 2) The server returns the encrypted Share3blob. 3) The client prompts for the user’s recovery password, decrypts the blob locally to recover Share3. 4) The client then prompts for the offline backup, Share2. 5) With Share2and Share3, the client reconstructs the original mnemonic entropy using Lagrange interpolation [8], [9] and restores the account. IV. IMPLEMENTATION DETAILS A. Technology Stack The implementation prioritizes accessibility and security for the self-hosting community. •Backend Framework: Flask, a lightweight Python web framework [29]. •Deployment: Containerized with Docker, using a uWSGI application server and an Nginx reverse proxy for production [30]–[32]. •Security Best Practices: Includes HTTPS enforcement, secure HTTP headers via Flask-Talisman [29], [34], CSRF protection with Flask-WTF [29], [35], rigorous input validation, strong password hashing with Argon2 [36], and disabled debug mode in production [37]. B. Cryptographic Modules The implementation relies on well-vetted, open-source cryptographic libraries. •Shamir’s Secret Sharing: The ‘shamirs‘ Python library, using a large prime modulus such as 2127 −1[38], [39]. •Elliptic Curve Cryptography (ECC): The ‘cryptography‘ library, using the secp256k1 curve for keypairs and ECDSA signatures. •Hashing and Key Derivation: The ‘hashlib‘ standard library for SHA-256 and HMAC-SHA512, and the ‘cryptography‘ library’s PBKDF2 implementation following the BIP-39 specification [10]. V. PERFORMANCE EVALUATION A. Testbed Configuration Two distinct hardware testbeds were used to evaluate performance. 1) High-Performance Desktop: AMD Ryzen 7 5700G (8core, 16-thread, up to 4.6 GHz), 32 GB DDR4 RAM [40]–[42]. 2) Low-Power Cluster: Four Raspberry Pi 4 Model B nodes (8 GB RAM each), interconnected via Gigabit Ethernet [43]. The ARM processors lack hardware acceleration for some cryptographic primitives [44]. B. Benchmarking Methodology We measured the wall-clock latency of the primary protocol phases. For the Registration Tumble, latency was measured as a function of the anonymity set size (5, 10, 25, and 50 concurrent users). For Authentication and Recovery, latency was measured for a single user operation. C. Results and Analysis Micro-benchmarks of core cryptographic primitives are presented in Table II. These provide a baseline for understanding the sources of latency. End-to-end latency results in Table III quantify the realworld user experience. While the Ryzen system is significantly faster, the Raspberry Pi 4 cluster latencies remain within acceptable bounds for interactive use [43], [45]. The primary bottleneck is the server-side coordination and signing during the Registration Tumble, which scales linearly with the number of participants. VI. SECURITY AND PRIVACY ANALYSIS A. Threat Model We adopt a Dolev-Yao-style model where the adversary has complete control over the network but cannot break the underlying cryptographic primitives [46]–[48]. The Forum Server is modeled as ”honest-but-curious.”
TABLE II CRYPTOGRAPHIC OPERATION BENCHMARKS (AVERAGE TIME) Operation Ryzen 7 5700G (ms) Raspberry Pi 4 (ms) SHA-512 (1MB) 0.45 12.8 PBKDF2-HMAC-SHA512 22.5 310.2 ECC Key Generation 0.3 7.5 ECC Signature (ECDSA) 0.2 6.9 ECC Verification 0.4 13.1 SSS Split (2, 3) 0.05 1.2 SSS Combine (2 shares) 0.06 1.5 TABLE III END-TO-END PROTOCOL LATENCY (AVERAGE) Protocol Phase Anon. Set Ryzen 7 (ms) Pi 4 Cluster (ms) Registration 5 15.2 115.5 Registration 10 28.9 225.1 Registration 25 70.1 558.3 Registration 50 138.5 1110.8 Authentication N/A 2.1 25.4 Mnemonic Recovery N/A 1.8 22.9 B. Anonymity and Unlinkability Registration Anonymity: The Registration Tumble provides k-anonymity, where kis the number of participants in a round [49], [50]. The server cannot deterministically link an incoming connection to a final registered username. Resistance to Traffic Analysis: The protocol does not mitigate network-level traffic analysis. It is a critical prerequisite that clients connect through an anonymity network like Tor to defend against timing attacks [51]–[53]. C. Sybil Resistance A significant threat is the Sybil attack, where an adversary creates many fake identities to join a registration round, reducing the anonymity set for honest users [54]–[56]. Practical mitigations can raise the cost of such an attack: •Proof-of-Work (PoW): Requiring clients to solve a computational puzzle. •Registration Fees: Requiring a small fee via a privacypreserving cryptocurrency. •Reputation Systems: A more complex, long-term solution. The current implementation does not include a specific Sybil resistance mechanism, which is a key area for future work. D. Credential and Mnemonic Security Credential Unforgeability: Based on the hardness of the Elliptic Curve Discrete Logarithm Problem (ECDLP), it is computationally infeasible to forge a credential signature without the server’s private key. Mnemonic Security: The (2,3) Shamir’s Secret Sharing scheme guarantees that an attacker must acquire at least two of the three shares to compromise a user’s account [8], [9], [26]. This distributed model is significantly more robust than traditional single-point-of-failure systems. VII. CONCLUSION AND FUTURE WORK A. Summary of Contributions This paper introduced a novel protocol for anonymous user registration and recovery for the self-hosted community. By combining a ”registration tumble” inspired by the WabiSabi CoinJoin protocol with a server-assisted mnemonic recovery system using Shamir’s Secret Sharing, we provide strong, cryptographically-enforced privacy. We demonstrated the system’s practicality through a containerized implementation and performance evaluation, confirming its feasibility on both high-end and low-cost hardware. B. Limitations The primary limitation is the system’s susceptibility to Sybil attacks within the registration tumble. The anonymity guarantee is also dependent on a sufficient number of concurrent users, which may be a challenge for low-traffic forums. Finally, the user experience is inherently more complex than traditional registration. C. Future Work This research opens several promising avenues for future work. 1) Post-Quantum Security: Upgrade the credential signature scheme to a post-quantum standard like CRYSTALSDilithium (ML-DSA) to protect against attacks from quantum computers [57]–[59]. 2) Decentralized Coordination: Explore removing the central server as the coordinator for the registration tumble, adapting the protocol for a fully peer-to-peer environment using technologies like Distributed Hash Tables (DHTs). 3) NFT-based Credentials: Investigate the use of NonFungible Tokens (NFTs) as the underlying data structure for credentials. This could enable novel functionalities
like private, verifiable peer-to-peer transfer of forum accounts [60], [61]. REFERENCES [1] S. Zuboff, The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. PublicAffairs, 2019. [2] J. C. Scott, Seeing Like a State: How Certain Schemes to Improve the Human Condition Have Failed. Yale University Press, 1998. [3] S. Camenisch, S. K. Fischer-H¨ ubner, and K. Rannenberg, Eds., Privacy and Identity Management for Life. Springer, 2011. [4] A. Biryukov, D. Khovratovich, and I. Pustogarov, ”Deanonymisation of clients in Bitcoin P2P network,” in Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014, pp. 15–29. [5] G. Maxwell, ”CoinJoin: Bitcoin privacy for the real world,” Bitcoin Forum, 2013. [Online]. Available: https://bitcointalk.org/index.php?topic= 279249.0 [6] A. Ficsor, Y. Dotan, and M. H. Z. Ziegeldorf, ”WabiSabi: Centrally Coordinated CoinJoins with Variable Amounts,” Wasabi Wallet Research, 2021. [7] A. Shamir, ”How to share a secret,” Communications of the ACM, vol. 22, no. 11, pp. 612–613, 1979. [8] G. R. Blakley, ”Safeguarding cryptographic keys,” in Proceedings of the National Computer Conference, 1979, vol. 48, pp. 313–317. [9] D. E. Knuth, The Art of Computer Programming, Volume 2: Seminumerical Algorithms, 3rd ed. Addison-Wesley, 1997. [10] M. Palatinus et al., ”BIP-0039: Mnemonic code for generating deterministic keys,” Bitcoin Improvement Proposals. [Online]. Available: https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki [11] P. Wuille, ”BIP-0032: Hierarchical Deterministic Wallets,” Bitcoin Improvement Proposals. [Online]. Available: https://github.com/bitcoin/ bips/blob/master/bip-0032.mediawiki [12] G. Fanti et al., ”Dandelion: Redesigning the Bitcoin Network for Anonymity,” in Proceedings of the ACM on Measurement and Analysis of Computing Systems, vol. 1, no. 1, pp. 1–26, 2017. [13] J. Camenisch and E. Van Herreweghen, ”Design and implementation of the Idemix anonymous credential system,” in Proceedings of the 9th ACM conference on Computer and communications security, 2002, pp. 21–30. [14] D. Chaum, ”Untraceable electronic mail, return addresses, and digital pseudonyms,” Communications of the ACM, vol. 24, no. 2, pp. 84–90, 1981. [15] D. Chaum, ”Security without identification: transaction systems to make big brother obsolete,” Communications of the ACM, vol. 28, no. 10, pp. 1030–1044, 1985. [16] J. Camenisch and A. Lysyanskaya, ”A signature scheme with efficient protocols,” in International Conference on Security in Communication Networks, 2002, pp. 268–289. [17] S. Goldwasser, S. Micali, and C. Rackoff, ”The knowledge complexity of interactive proof systems,” SIAM Journal on computing, vol. 18, no. 1, pp. 186–208, 1989. [18] A. Fiat and A. Shamir, ”How to prove yourself: Practical solutions to identification and signature problems,” in Conference on the Theory and Application of Cryptography, 1986, pp. 186–194. [19] D. Chaum and T. P. Pedersen, ”Wallet databases with observers,” in Annual International Cryptology Conference, 1992, pp. 89–105. [20] S. Brands, Rethinking public key infrastructures and digital certificates: building in privacy. MIT press, 2000. [21] J. Camenisch and A. Lysyanskaya, ”Efficient non-transferable anonymous credentials with optional anonymity revocation,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques, 2001, pp. 93–118. [22] E. Brickell, J. Camenisch, and L. Chen, ”Direct anonymous attestation,” in Proceedings of the 11th ACM conference on Computer and communications security, 2004, pp. 132–145. [23] A. Lysyanskaya, R. L. Rivest, A. Sahai, and S. Wolf, ”Pseudonym systems,” in International Workshop on Selected Areas in Cryptography, 1999, pp. 184–199. [24] I. Damg˚ ard, ”Payment systems and credential mechanisms with provable security against abuse by individuals,” in Annual international cryptology conference, 1988, pp. 328–335. [25] A. M. Antonopoulos, Mastering Bitcoin: Programming the Open Blockchain, 2nd ed. O’Reilly Media, 2017. [26] T. H. Cormen, C. E. Leiserson, R. L. Rivest, and C. Stein, Introduction to Algorithms, 3rd ed. MIT press, 2009. [27] E. Ben-Sasson et al., ”zk-SNARKs: A comprehensive survey,” Foundations and Trends® in Privacy and Security, vol. 1, no. 1-2, pp. 1–139, 2023. [28] P. Paillier, ”Public-key cryptosystems based on composite degree residuosity classes,” in International Conference on the Theory and Applications of Cryptographic Techniques, 1999, pp. 223–238. [29] M. Grinberg, Flask Web Development: Developing Web Applications with Python, 2nd ed. O’Reilly Media, 2018. [30] uWSGI Project. [Online]. Available: https://uwsgi-docs.readthedocs.io/ [31] Nginx Project. [Online]. Available: https://nginx.org/ [32] Docker Inc., Docker Documentation. [Online]. Available: https://docs. docker.com/ [33] OWASP Foundation, ”Session Management Cheat Sheet.” [Online]. Available: https://cheatsheetseries.owasp.org/cheatsheets/Session Management Cheat Sheet.html [34] Flask-Talisman Documentation. [Online]. Available: https://github.com/ Google/flask-talisman [35] OWASP Foundation, ”Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet.” [Online]. Available: https://cheatsheetseries.owasp.org/ cheatsheets/Cross-Site Request Forgery Prevention Cheat Sheet.html [36] C. Dwork, M. Naor, and A. Sahai, ”Concurrent zero-knowledge,” in Proceedings of the thirtieth annual ACM symposium on Theory of computing, 1998, pp. 409–418. [37] Flask Documentation, ”Deployment Options.” [Online]. Available: https: //flask.palletsprojects.com/en/2.0.x/deploying/ [38] Shamirs Secret Sharing library for Python. [Online]. Available: https: //github.com/ofek/shamirs [39] R. L. Rivest, A. Shamir, and L. Adleman, ”A method for obtaining digital signatures and public-key cryptosystems,” Communications of the ACM, vol. 21, no. 2, pp. 120–126, 1978. [40] AMD Ryzen 7 5700G Processor Specifications. [Online]. Available: https://www.amd.com/en/products/apu/amd-ryzen-7-5700g [41] PassMark CPU Benchmarks, ”AMD Ryzen 7 5700G.” [Online]. Available: https://www.cpubenchmark.net/cpu.php?cpu=AMD+Ryzen+ 7+5700G&id=4323 [42] J. L. Hennessy and D. A. Patterson, Computer Architecture: A Quantitative Approach, 6th ed. Morgan Kaufmann, 2017. [43] Raspberry Pi Foundation, Raspberry Pi 4 Specifications. [Online]. Available: https://www.raspberrypi.com/products/ raspberry-pi-4-model-b/specifications/ [44] ARM Cortex-A72 Technical Reference Manual. [Online]. Available: https://developer.arm.com/documentation/ddi0500/j/preface [45] J. Nielsen, Usability Engineering. Morgan Kaufmann, 1993. [46] D. Dolev and A. C. Yao, ”On the security of public key protocols,” IEEE Transactions on Information Theory, vol. 29, no. 2, pp. 198–208, 1983. [47] M. Abadi and A. D. Gordon, ”A calculus for cryptographic protocols: The spi calculus,” Information and Computation, vol. 148, no. 1, pp. 1–70, 1999. [48] R. Needham and M. Schroeder, ”Using encryption for authentication in large networks of computers,” Communications of the ACM, vol. 21, no. 12, pp. 993–999, 1978. [49] L. Sweeney, ”k-anonymity: A model for protecting privacy,” International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, vol. 10, no. 05, pp. 557–570, 2002. [50] A. Machanavajjhala, D. Kifer, J. Gehrke, and M. Venkitasubramaniam, ”l-diversity: Privacy beyond k-anonymity,” ACM Transactions on Knowledge Discovery from Data (TKDD), vol. 1, no. 1, p. 3-es, 2007. [51] R. Dingledine, N. Mathewson, and P. Syverson, ”Tor: The secondgeneration onion router,” in 13th USENIX Security Symposium (SEC ’04), 2004. [52] B. N. Levine, M. K. Reiter, C. Wang, and M. Wright, ”Timing attacks in low-latency mix-based systems,” in International Conference on Financial Cryptography, 2004, pp. 251–265. [53] S. J. Murdoch and G. Danezis, ”Low-cost traffic analysis of Tor,” in 2005 IEEE Symposium on Security and Privacy, 2005, pp. 183–195. [54] J. R. Douceur, ”The sybil attack,” in International workshop on peerto-peer systems, 2002, pp. 251–260. [55] H. Yu, M. Kaminsky, P. B. Gibbons, and A. Flaxman, ”SybilGuard: defending against sybil attacks via social networks,” in ACM SIGCOMM computer communication review, 2006, vol. 36, no. 4, pp. 267–278.
[56] B. Viswanath, A. Post, K. P. Gummadi, and A. Mislove, ”An analysis of social network-based sybil defenses,” in ACM SIGCOMM computer communication review, 2010, vol. 40, no. 4, pp. 363–374. [57] NIST, ”Post-Quantum Cryptography Standardization.” [Online]. Available: https://csrc.nist.gov/projects/post-quantum-cryptography [58] L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, P. Schwabe, G. Seiler, and D. Stehle, ”CRYSTALS-Dilithium: A lattice-based digital signature scheme,” IACR Transactions on Cryptographic Hardware and Embedded Systems, pp. 238–268, 2018. [59] P. W. Shor, ”Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM review, vol. 41, no. 2, pp. 303–332, 1999. [60] W. Entriken et al., ”EIP-721: Non-Fungible Token Standard,” Ethereum Improvement Proposals. [Online]. Available: https://eips.ethereum.org/ EIPS/eip-721 [61] F. Wang, L. Zhang, J. Ding, Y. Zhang, and X. Li, ”A survey on nonfungible token (NFT): The technology, applications, and challenges,” Journal of Network and Computer Applications, vol. 200, p. 103321, 2022.