To reiterate:
1. Get the Tor user in question to visit a website controlled by you ( or at least a site where you can cause JS to run; such as an advertisement )
2. Know which ISP the user is on, and be allowed to install a high speed device watching all traffic for a sequence of specific sized packets.
3. Use the JS to send a specifically crafted sequence of sized packets with specific time periods in between them. After sending this preamble, send sized packets to send the 'pseudo identity' of the user ( whatever pseudonym you wish to attach back to their real IP )
4. Use your monitored ISP device to detect the preamble, then log IP and the data.
Note this method could be done en-masse and would only require high speed FPGA devices at each ISP "trunk". Inject JS code correlating users back for any system which you wish to identify the users.
Done. Whichever Russian demonstrates this and wins the $100k; throw me a bone please. :)