首页> 外文会议>International Conference on Systems, Man, and Cybernetics >S3Email: A method for securing emails from service providers
【24h】

S3Email: A method for securing emails from service providers

机译:S3Email:一种保护来自服务提供商的电子邮件的方法

获取原文

摘要

We often send our confidential information such as passport, credit card, social security numbers over email without concern about the security of email services. Existing network security mechanisms provide adequate security from external malicious adversaries and eavesdroppers, but they don't guarantee that the email service providers (ESPs) wouldn't or can't access our email data themselves, which in some cases could be highly confidential. One of the ways to protect email data from ESPs is to use Pretty Good Privacy (PGP) that has many limitations including key storage problem and dependability on third party services, making it cumbersome to use in practice. In this paper, we present S3Email method that provides email security against ESPs. The proposed method uses a cryptographic secret sharing technique in a novel way and encrypts the email metadata, body and attachments before the email is sent. In the proposed solution, the email sender and receiver must have at least two email accounts on the existing ESPs, which is not unusual today. Experiments and analysis show that the S3Email method provides information theoretic security with minimal computational overhead.
机译:我们通常通过电子邮件发送我们的机密信息,例如护照,信用卡,社会安全号码,而无需担心电子邮件服务的安全性。现有的网络安全机制可为外部恶意攻击者和窃听者提供足够的安全性,但它们不能保证电子邮件服务提供商(ESP)不会或不能自己访问我们的电子邮件数据,在某些情况下这可能是高度机密的。保护电子邮件数据免受ESP侵扰的一种方法是使用“相当不错的隐私”(PGP),它具有许多限制,包括密钥存储问题和对第三方服务的依赖性,因此在实践中使用起来很麻烦。在本文中,我们提出了S3Email方法,该方法提供针对ESP的电子邮件安全性。所提出的方法以新颖的方式使用密码秘密共享技术,并在发送电子邮件之前对电子邮件元数据,正文和附件进行加密。在建议的解决方案中,电子邮件发送者和接收者必须在现有的ESP上至少具有两个电子邮件帐户,这在当今并不罕见。实验和分析表明,S3Email方法以最小的计算开销提供了信息理论安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号