Title :
Trusted Email protocol: Dealing with privacy concerns from malicious email intermediaries
Author :
Jang, Julian ; Nepal, Surya ; Zic, John
Author_Institution :
ICT Centre, Sydney, NSW
Abstract :
It is well-known that intermediate mediums that route emails between senders and recipients can be a real threat to privacy as these intermediaries can easily intercept and tamper with email messages. Many software-based solutions have been proposed to solve such privacy concerns by means of end-to-end data encryption such as PGP, OpenPGP, and S/MIME. These solutions pose yet another challenging issue for the secure and trusted management of cryptographic keys they utilize. To address this issue, we propose a new protocol for a Trusted Email System using hardware-based cryptographic functionality of Trusted Platform Module (TPM) and the Ephemerizer concept. By leveraging the advantages of these two technologies, our protocol provides a safeguard to cryptographic keys so that only designated email senders and recipients can read email messages. Furthermore, our protocol guarantees that nobody can read email messages that have expired or have been securely deleted. In this paper, we first describe the protocol of our Trusted Email System and then verify the security aspects of the protocol using a popular cryptographic verification tool, ProVerif.
Keywords :
cryptographic protocols; data privacy; electronic mail; formal verification; open systems; Ephemerizer concept; OpenPGP; ProVerif; S/MIME; cryptographic keys; cryptographic verification tool; data privacy; email messages; email recipients; email senders; end-to-end data encryption; hardware-based cryptographic functionality; malicious email; software-based solutions; trusted email protocol; trusted email system; trusted management; trusted platform module; Australia; Business communication; Cryptographic protocols; Cryptography; Data privacy; Electronic mail; Internet; Postal services; Protection; Web server;
Conference_Titel :
Computer and Information Technology, 2008. CIT 2008. 8th IEEE International Conference on
Conference_Location :
Sydney, NSW
Print_ISBN :
978-1-4244-2357-6
Electronic_ISBN :
978-1-4244-2358-3
DOI :
10.1109/CIT.2008.4594709