The Experts below are selected from a list of 249 Experts worldwide ranked by ideXlab platform

Thomas Long - One of the best experts on this subject based on the ideXlab platform.

  • ICPADS - P2P Email Encryption by an identity-based one-way group key agreement protocol
    2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014
    Co-Authors: Fiona Zeng, Thomas Long
    Abstract:

    As a result of high-tech companies such as Google, Yahoo, and Microsoft offering free Email services, Email has become a primary channel of communication. However, Email service providers have traditionally offered little in the way of message privacy protection. This has made Emails, of which billions are sent around the world on any day, an attractive data source for personal identity information thieves. Google was one of the first companies to provide substantial Email privacy protection when they began using the HTTPS always-on option to encrypt messages sent through their Email service, Gmail. Unfortunately, Gmail's Encryption option does not offer true point-to-point Encryption since the encrypted Emails are decrypted and stored in plaintext form on Google's servers. This type of approach poses a security vulnerability which is unacceptable to security-minded users such as highly sensitive government agencies and private companies. For these users, true point-to-point Encryption is needed. This paper introduces an identity-based one-way group key agreement protocol and describes a point-to-point Email Encryption scheme based on the protocol. Both the security proofs and the efficiency analysis, with experimental results, of the new scheme are provided.

  • P2P Email Encryption by an identity-based one-way group key agreement protocol
    2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014
    Co-Authors: Fiona Zeng, Thomas Long
    Abstract:

    As a result of high-tech companies such as Google, Yahoo, and Microsoft offering free Email services, Email has become a primary channel of communication. However, Email service providers have traditionally offered little in the way of message privacy protection. This has made Emails, of which billions are sent around the world on any day, an attractive data source for personal identity information thieves. Google was one of the first companies to provide substantial Email privacy protection when they began using the HTTPS always-on option to encrypt messages sent through their Email service, Gmail. Unfortunately, Gmail's Encryption option does not offer true point-to-point Encryption since the encrypted Emails are decrypted and stored in plaintext form on Google's servers. This type of approach poses a security vulnerability which is unacceptable to security-minded users such as highly sensitive government agencies and private companies. For these users, true point-to-point Encryption is needed. This paper introduces an identity-based one-way group key agreement protocol and describes a point-to-point Email Encryption scheme based on the protocol. Both the security proofs and the efficiency analysis, with experimental results, of the new scheme are provided.

Lars Eilebrecht - One of the best experts on this subject based on the ideXlab platform.

  • ciphire mail Email Encryption and authentication
    Financial Cryptography, 2005
    Co-Authors: Lars Eilebrecht
    Abstract:

    Ciphire Mail is cryptographic software that provides Email Encryption and digital signatures. The Ciphire Mail client resides on the user’s computer between the Email client and the Email server, intercepting, encrypting, decrypting, signing, and authenticating Email communication. During normal operation, all operations are performed in the background, making it very easy to use even for non-technical users. Ciphire Mail provides automated secure public-key exchange using an automated fingerprinting system. It uses cryptographic hash values to identify and validate certificates, thus enabling clients to detect malicious modification of certificates. This data is automatically circulated among clients, making it impossible to execute fraud without alerting users. The Ciphire system is a novel concept for making public-key cryptography and key exchange usable for Email communication. It is the first transparent Email Encryption system that allows everyone to secure their communications without a steep learning curve.

  • Financial Cryptography - Ciphire mail Email Encryption and authentication
    Financial Cryptography and Data Security, 2005
    Co-Authors: Lars Eilebrecht
    Abstract:

    Ciphire Mail is cryptographic software that provides Email Encryption and digital signatures. The Ciphire Mail client resides on the user’s computer between the Email client and the Email server, intercepting, encrypting, decrypting, signing, and authenticating Email communication. During normal operation, all operations are performed in the background, making it very easy to use even for non-technical users. Ciphire Mail provides automated secure public-key exchange using an automated fingerprinting system. It uses cryptographic hash values to identify and validate certificates, thus enabling clients to detect malicious modification of certificates. This data is automatically circulated among clients, making it impossible to execute fraud without alerting users. The Ciphire system is a novel concept for making public-key cryptography and key exchange usable for Email communication. It is the first transparent Email Encryption system that allows everyone to secure their communications without a steep learning curve.

Franziska Roesner - One of the best experts on this subject based on the ideXlab platform.

  • Confidante: Usable Encrypted Email: A Case Study with Lawyers and Journalists
    2017 IEEE European Symposium on Security and Privacy (EuroS&P), 2017
    Co-Authors: Ada Lerner, Eric Zeng, Franziska Roesner
    Abstract:

    Email Encryption tools remain underused, even by people who frequently conduct sensitive business over Email, such as lawyers and journalists. Usable encrypted Email has remained out of reach largely because key management and verification remain difficult. However, key management has evolved in the age of social media: Keybase is a service that allows users to cryptographically link public keys to their social media accounts (e.g., Twitter), enabling key trust without out-of-band communication. We design and prototype Confidante, an encrypted Email client that uses Keybase for automatic key management. We conduct a user study with 15 people (8 U. S. lawyers and 7 U. S. journalists) to evaluate Confidante's design decisions. We find that users complete an encrypted Email task more quickly and with fewer errors using Confidante than with an existing Email Encryption tool, and that many users report finding Confidante comparable to using ordinary Email. However, we also find that lawyers and journalists have diverse operational constraints and threat models, and thus that there may not be a one-size-fits-all solution to usable encrypted Email. We reflect on our findings - both specifically about Confidante and more generally about the needs and constraints of lawyers and journalists - to identify lessons and remaining security and usability challenges for encrypted Email.

  • EuroS&P - Confidante: Usable Encrypted Email: A Case Study with Lawyers and Journalists
    2017 IEEE European Symposium on Security and Privacy (EuroS&P), 2017
    Co-Authors: Ada Lerner, Eric Zeng, Franziska Roesner
    Abstract:

    Email Encryption tools remain underused, even by people who frequently conduct sensitive business over Email, such as lawyers and journalists. Usable encrypted Email has remained out of reach largely because key management and verification remain difficult. However, key management has evolved in the age of social media: Keybase is a service that allows users to cryptographically link public keys to their social media accounts (e.g., Twitter), enabling key trust without out-of-band communication. We design and prototype Confidante, an encrypted Email client that uses Keybase for automatic key management. We conduct a user study with 15 people (8 U. S. lawyers and 7 U. S. journalists) to evaluate Confidante's design decisions. We find that users complete an encrypted Email task more quickly and with fewer errors using Confidante than with an existing Email Encryption tool, and that many users report finding Confidante comparable to using ordinary Email. However, we also find that lawyers and journalists have diverse operational constraints and threat models, and thus that there may not be a one-size-fits-all solution to usable encrypted Email. We reflect on our findings — both specifically about Confidante and more generally about the needs and constraints of lawyers and journalists—to identify lessons and remaining security and usability challenges for encrypted Email.

Fiona Zeng - One of the best experts on this subject based on the ideXlab platform.

  • ICPADS - P2P Email Encryption by an identity-based one-way group key agreement protocol
    2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014
    Co-Authors: Fiona Zeng, Thomas Long
    Abstract:

    As a result of high-tech companies such as Google, Yahoo, and Microsoft offering free Email services, Email has become a primary channel of communication. However, Email service providers have traditionally offered little in the way of message privacy protection. This has made Emails, of which billions are sent around the world on any day, an attractive data source for personal identity information thieves. Google was one of the first companies to provide substantial Email privacy protection when they began using the HTTPS always-on option to encrypt messages sent through their Email service, Gmail. Unfortunately, Gmail's Encryption option does not offer true point-to-point Encryption since the encrypted Emails are decrypted and stored in plaintext form on Google's servers. This type of approach poses a security vulnerability which is unacceptable to security-minded users such as highly sensitive government agencies and private companies. For these users, true point-to-point Encryption is needed. This paper introduces an identity-based one-way group key agreement protocol and describes a point-to-point Email Encryption scheme based on the protocol. Both the security proofs and the efficiency analysis, with experimental results, of the new scheme are provided.

  • P2P Email Encryption by an identity-based one-way group key agreement protocol
    2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014
    Co-Authors: Fiona Zeng, Thomas Long
    Abstract:

    As a result of high-tech companies such as Google, Yahoo, and Microsoft offering free Email services, Email has become a primary channel of communication. However, Email service providers have traditionally offered little in the way of message privacy protection. This has made Emails, of which billions are sent around the world on any day, an attractive data source for personal identity information thieves. Google was one of the first companies to provide substantial Email privacy protection when they began using the HTTPS always-on option to encrypt messages sent through their Email service, Gmail. Unfortunately, Gmail's Encryption option does not offer true point-to-point Encryption since the encrypted Emails are decrypted and stored in plaintext form on Google's servers. This type of approach poses a security vulnerability which is unacceptable to security-minded users such as highly sensitive government agencies and private companies. For these users, true point-to-point Encryption is needed. This paper introduces an identity-based one-way group key agreement protocol and describes a point-to-point Email Encryption scheme based on the protocol. Both the security proofs and the efficiency analysis, with experimental results, of the new scheme are provided.

Jason Nieh - One of the best experts on this subject based on the ideXlab platform.

  • why joanie can encrypt easy Email Encryption with easy key management
    European Conference on Computer Systems, 2019
    Co-Authors: Steven M Bellovin, Jason Nieh
    Abstract:

    Email privacy is of crucial importance. Existing Email Encryption approaches are comprehensive but seldom used due to their complexity and inconvenience. We take a new approach to simplify Email Encryption and improve its usability by implementing receiver-controlled Encryption: newly received messages are transparently downloaded and encrypted to a locally-generated key; the original message is then replaced. To avoid the problem of moving a single private key between devices, we implement per-device key pairs: only public keys need be synchronized via a simple verification step. Compromising an Email account or server only provides access to encrypted Emails. We implemented this scheme on several platforms, showing it works with PGP and S/MIME, is compatible with widely used mail clients and Email services including Gmail, has acceptable overhead, and that users consider it intuitive and easy to use.

  • EuroSys - Why Joanie Can Encrypt: Easy Email Encryption with Easy Key Management
    Proceedings of the Fourteenth EuroSys Conference 2019 CD-ROM on ZZZ - EuroSys '19, 2019
    Co-Authors: Steven M Bellovin, Jason Nieh
    Abstract:

    Email privacy is of crucial importance. Existing Email Encryption approaches are comprehensive but seldom used due to their complexity and inconvenience. We take a new approach to simplify Email Encryption and improve its usability by implementing receiver-controlled Encryption: newly received messages are transparently downloaded and encrypted to a locally-generated key; the original message is then replaced. To avoid the problem of moving a single private key between devices, we implement per-device key pairs: only public keys need be synchronized via a simple verification step. Compromising an Email account or server only provides access to encrypted Emails. We implemented this scheme on several platforms, showing it works with PGP and S/MIME, is compatible with widely used mail clients and Email services including Gmail, has acceptable overhead, and that users consider it intuitive and easy to use.