Beaver: A Decentralized Anonymous Marketplace with Secure Reputation Kyle Soska∗ Albert Kwon∗ Nicolas Christin Srinivas Devadas CMU MIT CMU MIT
[email protected] [email protected] [email protected] [email protected] Abstract—Amid growing concerns of government surveillance they strive to avail reputation systems with strong privacy and and corporate data sharing, web users increasingly demand tools anonymity guarantees, and have proven to be economically for preserving their privacy without placing trust in a third viable. To achieve the desired anonymity properties, online party. Unfortunately, existing centralized reputation systems need anonymous marketplaces build on a combination of network- to be trusted for either privacy, correctness, or both. Existing level anonymity—often running as Tor hidden services [20] decentralized approaches, on the other hand, are either vulner- or i2p “eep sites” [3]—and payment-level anonymity, using able to Sybil attacks, present inconsistent views of the network, or leak critical information about the actions of their users. pseudonymous digital payment systems such as Bitcoin [36]. In this paper, we present Beaver, a decentralized anonymous However, similar to “traditional” online marketplaces such marketplace that is resistant against Sybil attacks on vendor as eBay, an online anonymous marketplace remains a cen- reputation, while preserving user anonymity. Beaver allows its tralized service. It thus needs to be trusted for availability as participants to enjoy open enrollment, and provides every user customers cannot query item listings or reviews if it is not with the same global view of the reputation of other users through online; it needs to be trusted for correctness, i.e., not inject fake public ledger based consensus.