DocumentCode :
2967872
Title :
Design and implementation of smartcard-based secure e-mail communication
Author :
Chen, Hsien-Hau ; Chen, Yung-Sheng ; Chiang, Hsia-Ling ; Yang, Chung-Hnang
Author_Institution :
Div. of Res. & Develop., NexSmart Technol. Inc., Taipei, Taiwan
fYear :
2003
fDate :
14-16 Oct. 2003
Firstpage :
225
Lastpage :
231
Abstract :
E-mail system is by far the most widely used application in the Internet. However, mainly due to the lack of communication security, sensitive messages could not transmit securely over open networks using off-the-shell e-mail systems. A new secure e-mail system is proposed and implemented to extend the popular Microsoft Outlook e-mail software with flexible security services and to combine these services tightly with smartcards. The enhanced security services include data confidentiality, authentication of message originator and recipient, data integrity, and nonrepudiation. The proposed system provides two approaches for secure e-mail communication, one is base on the certification authority (CA) and the other is base on the keys distribution center (KDC), such that a complete solution may be satisfied for both open public and private enterprise. Windows-based smart cards, NexCard 2.0, is adopted as portable security tokens to store private key for generating digital signature, to store multiple digital certificates issued from the CAs and to store the master key shared with the KDC. We also designed and implemented cryptographic libraries, CSP 2.0 and PKCS#11, which is need for secure interaction of smartcard module with applications.
Keywords :
Internet; certification; data integrity; electronic mail; message authentication; public key cryptography; smart cards; telecommunication security; 11cryptographic library; CSP 2.0 cryptographic library; Internet; Microsoft Outlook e-mail software; NexCard 2.0; PKCS; certification authority; data confidentiality; data integrity; digital certificate; digital signature; e-mail system; encryption; keys distribution center; message authentication; secure e-mail communication; smartcard; telecommunication security service; Application software; Authentication; Certification; Communication system security; Content addressable storage; Data security; Digital signatures; Electronic mail; Internet; Smart cards;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security Technology, 2003. Proceedings. IEEE 37th Annual 2003 International Carnahan Conference on
Print_ISBN :
0-7803-7882-2
Type :
conf
DOI :
10.1109/CCST.2003.1297564
Filename :
1297564
Link To Document :
بازگشت