On the security of a certified E-mail scheme

被引:0
|
作者
Wang, GL [1 ]
Bao, F [1 ]
Zhou, JY [1 ]
机构
[1] Inst Infocomm Res, Infocomm Secur Dept, Singapore 119613, Singapore
关键词
certified e-mail; fair exchange; non-repudiation;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As a value-added service for standard e-mail systems, a certified e-mail scheme allows a sender to deliver a message to a receiver in a fair way in the sense that either the sender obtains a receipt from the receiver and the receiver accesses the content of the e-mail simultaneously, or neither party gets the expected item. In 2000, Ferrer-Gomila et al. [11] proposed a novel certified e-mail protocol. Their scheme is both efficient and optimistic, since it has only three steps and a trusted third party is not involved in normal cases. Later, Monteiro and Dahab [16] identified an attack on Ferrer-Gomila et al.'s scheme, and further presented a modified scheme. In this paper, we show that their improvement is still insecure by successfully identifying several weaknesses and security flaws. Our attacks also apply to Ferrer-Gomila et al.'s original scheme.
引用
收藏
页码:48 / 60
页数:13
相关论文
共 50 条
  • [1] On the security of a certified e-mail scheme with temporal authentication
    Shao, MH
    Zhou, JY
    Wang, GL
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2005, PT 3, 2005, 3482 : 701 - 710
  • [2] A certified e-mail protocol
    Schneier, B
    Riordan, J
    [J]. 14TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 1998, : 347 - 352
  • [3] SECURITY OF E-MAIL
    DUBB, HE
    [J]. SCIENCE, 1993, 262 (5135) : 827 - 827
  • [4] An Optimistic Certified E-mail Protocol for the Current Internet E-mail Architecture
    Draper-Gil, Gerard
    Ferrer-Gomila, Josep L.
    Hinarejos, M. Francisca
    Tauber, Arne
    [J]. 2014 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2014, : 382 - 390
  • [5] The Analysis and Improvement of the Certified E-Mail Protocol
    Ye, Junyao
    Wang, Yinglian
    [J]. APPLIED SCIENCE, MATERIALS SCIENCE AND INFORMATION TECHNOLOGIES IN INDUSTRY, 2014, 513-517 : 1305 - 1308
  • [6] AnZenMail: A secure and certified e-mail system
    Shibayama, E
    Hagihara, S
    Kobayashi, N
    Nishizaki, SY
    Taura, K
    Watanabe, T
    [J]. SOFTWARE SECURITY - THEORIES AND SYSTEMS, 2003, 2609 : 201 - 216
  • [7] An Efficient and Lightweight Deniably Authenticated Encryption Scheme for e-Mail Security
    Kar, Jayaprakash
    Naik, Kshirasagar
    Abdelkader, Tamer
    [J]. IEEE ACCESS, 2019, 7 : 184207 - 184220
  • [8] A Source Sender Verification Scheme for E-mail and Its Security Analysis
    Ao Tenghe
    Li Dayong
    [J]. EBM 2010: INTERNATIONAL CONFERENCE ON ENGINEERING AND BUSINESS MANAGEMENT, VOLS 1-8, 2010, : 5410 - +
  • [9] A proxy approach to e-mail security
    Brown, I
    Snow, CR
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 1999, 29 (12): : 1049 - 1060
  • [10] Distributed certified e-mail system for mobile users
    Yang, JP
    Sur, C
    Rhee, KH
    [J]. DISTRIBUTED COMPUTING: IWDC 2003, 2003, 2918 : 194 - 204