Chaum’s 1981 design uses layered encryption and message mixing. An honest mix can hide its input-output mapping but does not alone guarantee anonymity against timing correlations or active attacks.
David Chaum proposed mixes to protect the relationship between sender and recipient of electronic mail. Encrypting message content alone does not conceal that relationship. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms] [ACM — Chaum's 1981 mix-network paper]
The sender selects a route and adds encryption layers in reverse traversal order. Removing one layer reveals the address needed for onward delivery and the inner packet. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms]
A classical batch mix waits for a group of messages. Uniform packet lengths and group processing limit immediate matching of one input to one output. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms] [The Loopix Anonymity System]
The mix removes its layer, rejects messages already processed, shuffles the batch and forwards it. The next mix performs a similar step; exact rules depend on the protocol. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms] [The Loopix Anonymity System]
At least one honest mix and a secret permutation protect the internal mapping in the relevant model. Overall anonymity also depends on other traffic, observation of endpoints and the adversary’s ability to interfere. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms] [The Loopix Anonymity System] [Nym Mixnet architecture]
Traffic size, timing and volume can reveal relationships despite secure encryption. Padding, random delays, batches and cover traffic consume bandwidth and time in exchange for resistance to correlation. [The Loopix Anonymity System] [Tor: The Second-Generation Onion Router] [Nym Mixnet architecture]
An attacker can replay, tag messages by changing content or timing, or drop them. Over time, it can compare who was online together. Integrity checks, replay records and cover traffic help under specific models; they are not universal guarantees. [The Loopix Anonymity System] [Nym Mixnet architecture]
Chaum also described return addresses and digital pseudonyms. They enable replies without publishing the recipient’s ordinary address; retaining a pseudonym can still link its individual messages. [David Chaum — Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms]
Classical mixnets often sacrifice interactivity for mixing. Loopix uses short random delays and cover traffic. Tor prioritizes low latency; an observer of both ends can correlate timing. These are different tradeoffs, not a universal security ranking. [The Loopix Anonymity System] [Tor: The Second-Generation Onion Router] [Nym Mixnet architecture]
A mixnet can limit exposure of the network origin of Bitcoin traffic, but it does not erase public ledger links. BIP 324 encrypted transport is not an anonymizing mixnet either. Network and transaction privacy are separate layers. [Bitcoin.org — Protect your privacy] [BIP 324 — Version 2 P2P Encrypted Transport Protocol]
For the clearest picture, read this entry together with David Chaum, Bitcoin Privacy, Pseudonymity, Bitcoin. The reverse links also lead from David Chaum, Len Sassaman.