Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Authentication and Key Management Automation in Decentralized Secure Email and Messaging via Low-Entropy Secrets
Vazquez Sandoval, Itzel; Atashpendar, Arash; Lenzini, Gabriele
2020In Proceedings of the 17th International Joint Conference on e-Business and Telecommunications
Peer reviewed
 

Files


Full Text
Authentication_and_key_management_in_secure_email_via_low-entropy_secrets.pdf
Author preprint (248.52 kB)
Download

Published in the proceedings of SECRYPT 2020 (http://www.secrypt.icete.org/)


All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
entity authentication; secure email; decentralized key management; password authenticated key exchange; automation; secure messaging
Abstract :
[en] We revisit the problem of entity authentication in decentralized end-to-end encrypted email and secure messaging to propose a practical and self-sustaining cryptographic solution based on password-authenticated key exchange (PAKE). This not only allows users to authenticate each other via shared low-entropy secrets, e.g., memorable words, without a public key infrastructure or a trusted third party, but it also paves the way for automation and a series of cryptographic enhancements; improves security by minimizing the impact of human error and potentially improves usability. First, we study a few vulnerabilities in voice-based out-of-band authentication, in particular a combinatorial attack against lazy users, which we analyze in the context of a secure email solution. Next, we propose solving the problem of secure equality test using PAKE to achieve entity authentication and to establish a shared high-entropy secret key. Our solution lends itself to offline settings, compatible with the inherently asynchronous nature of email and modern messaging systems. The suggested approach enables enhancements in key management such as automated key renewal and future key pair authentications, multi-device synchronization, secure secret storage and retrieval, and the possibility of post-quantum security as well as facilitating forward secrecy and deniability in a primarily symmetric-key setting. We also discuss the use of auditable PAKEs for mitigating a class of online guess and abort attacks in authentication protocols.
Disciplines :
Computer science
Author, co-author :
Vazquez Sandoval, Itzel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Atashpendar, Arash;  itrust consulting
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
Authentication and Key Management Automation in Decentralized Secure Email and Messaging via Low-Entropy Secrets
Publication date :
2020
Event name :
SECRYPT 2020 - 17th International Conference on Security and Cryptography
Event date :
from 08-07-2020 to 10-07-2020
Audience :
International
Main work title :
Proceedings of the 17th International Joint Conference on e-Business and Telecommunications
ISBN/EAN :
978-989-758-446-6
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Available on ORBilu :
since 28 May 2020

Statistics


Number of views
233 (23 by Unilu)
Number of downloads
109 (1 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
0
OpenCitations
 
1
WoS citations
 
0

Bibliography


Similar publications



Contact ORBilu