Paper published in a book (Scientific congresses, symposiums and conference proceedings)
PakeMail: Authentication and Key Management in Decentralized Secure Email and Messaging via PAKE
Vazquez Sandoval, Itzel; Atashpendar, Arash; Lenzini, Gabriele et al.
2021In Obaidat, Mohammad S.; Ben-Othman, Jalel (Eds.) E-Business and Telecommunications - 17th International Conference on E-Business and Telecommunications, ICETE 2020, Online Event, July 8-10, 2020, Revised Selected Papers.
Peer reviewed
 

Files


Full Text
PakeMail_decentralized_auth_via_PAKE.pdf
Author preprint (280.24 kB)
Download

The final authenticated version is available online at https://doi.org/10.1007/978-3-030-90428-9_5


All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Password-authenticated key exchange; Public key authentication; Key management; Secure email; Decentralized trust model; Implementation
Abstract :
[en] We propose the use of password-authenticated key exchange (PAKE) for achieving and enhancing entity authentication (EA) and key management (KM) in the context of decentralized end-to-end encrypted email and secure messaging, i.e., without a public key infrastructure or a trusted third party. This not only simplifies the EA process by requiring users to share only a low-entropy secret such as a memorable word, but it also allows us to establish a high-entropy secret key. This approach enables a series of cryptographic enhancements and security properties, which are hard to achieve using out-of-band (OOB) authentication. We first study a few vulnerabilities in voice-based OOB authentication, in particular a combinatorial attack against lazy users, which we analyze in the context of a secure email solution. We then propose tackling public key authentication by solving the problem of secure equality test using PAKE and discuss various protocols and their properties. This method enables the automation of important KM tasks such as key renewal and future key pair authentications, reduces the impact of human errors and lends itself to the asynchronous nature of email and modern messaging. It also provides cryptographic enhancements including multi-device synchronization, and secure secret storage/retrieval, and paves the path for forward secrecy, deniability and post-quantum security.We also discuss the use of auditable PAKEs for mitigating a class of online guess and abort attacks in authentication protocols. We present an implementation of our proposal, called PakeMail, to demonstrate the feasibility of the core idea and discuss some of its cryptographic details, implemented features and efficiency aspects. We conclude with some design and security considerations, followed by future lines of work.
Disciplines :
Computer science
Author, co-author :
Vazquez Sandoval, Itzel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > IRiSC
Atashpendar, Arash
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > IRiSC
Ryan, Peter Y A ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
External co-authors :
no
Language :
English
Title :
PakeMail: Authentication and Key Management in Decentralized Secure Email and Messaging via PAKE
Publication date :
October 2021
Event name :
17th International Joint Conference on e-Business and Telecommunications, ICETE 2020
Event date :
July 2020
Main work title :
E-Business and Telecommunications - 17th International Conference on E-Business and Telecommunications, ICETE 2020, Online Event, July 8-10, 2020, Revised Selected Papers.
Editor :
Obaidat, Mohammad S.
Ben-Othman, Jalel
Publisher :
Springer
Collection name :
Communications in Computer and Information Science, vol. 1484
Pages :
102-128
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Available on ORBilu :
since 03 December 2021

Statistics


Number of views
160 (6 by Unilu)
Number of downloads
108 (2 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
1
OpenCitations
 
1

Bibliography


Similar publications



Contact ORBilu