首页> 外文期刊>Computer Communications >Some common attacks against certified email protocols and the countermeasures
【24h】

Some common attacks against certified email protocols and the countermeasures

机译:针对认证电子邮件协议的一些常见攻击及对策

获取原文
获取原文并翻译 | 示例
           

摘要

Certified email is a value-added service for standard email systems, which guarantees the fairness, i.e., the intended recipient gets the mail content if and only if the mail originator receives a non-repudiation receipt showing that the message has been received by the recipient. As far as security is concerned, fairness is the most important requirements, though some other properties are also desirable in practice. Recently, a number of certified email protocols have been proposed. However, most of those schemes have more or less weaknesses and/or security flaws. In the worst case, fairness cannot be achieved since one dishonest party can mount some attacks to cheat the honest party such that the latter cannot get the expected items. In this paper, we analyze two latest certified email protocols to demonstrate some common attacks, and then propose some improvements to avoid those security problems. We further give several informal but useful guidelines to counter those common attacks in the design of certified email protocols.
机译:认证电子邮件是标准电子邮件系统的一项增值服务,可保证公平性,即,当且仅当邮件发件人收到表明收件人已收到该邮件的不可否认收据时,预期收件人才能获得邮件内容。就安全性而言,公平是最重要的要求,尽管在实践中还需要其他一些属性。最近,已经提出了许多认证的电子邮件协议。但是,这些方案中的大多数都有或多或少的弱点和/或安全缺陷。在最坏的情况下,由于一个不诚实的政党可以发动攻击来欺骗诚实的政党,从而使诚实的政党无法获得期望的东西,因此无法实现公平。在本文中,我们分析了两种最新的认证电子邮件协议,以演示一些常见的攻击,然后提出了一些改进措施来避免这些安全问题。我们还提供了一些非正式但有用的准则来应对认证电子邮件协议设计中的那些常见攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号