首页> 外文期刊>Procedia Computer Science >Design and Implementation of an End-to-End Web based Trusted Email System
【24h】

Design and Implementation of an End-to-End Web based Trusted Email System

机译:设计与实现端到端基于Web的可信电子邮件系统

获取原文
       

摘要

Web based email systems are important services on internet that store and route emails between senders and recipients. In principle, these are intermediate systems that have the potential of intercepting the end user’s emails. Privacy of emails is often compromised by law enforcement agencies as well as by email service providers for user profiling and targeted advertisements. Many solutions have been proposed to solve such privacy concerns by means of end-to-end email encryption. However, these solutions pose other challenges to maintain usability, portability and trusted key management on web. These systems maintain and distribute end-user cryptographic keys through their web application. Unfortunately, key generation and sharing mechanism is often un-trusted and kept hidden. Trust is directly dependent on web application implementation and can be manipulated by means of key modification through unannounced change of source code (backdoors) on server. In order to address these issues, we propose a new PKI based architecture for a trusted web-based email system. It offers significant usability and portability. Moreover, all the cryptographic operations are open and transparent to end users.
机译:基于Web的电子邮件系统是在互联网上存储和路由发送者和收件人的电子邮件的重要服务。原则上,这些是具有拦截最终用户电子邮件的潜力的中间系统。电子邮件的隐私通常由执法机构以及通过电子邮件服务提供商来损害用户分析和针对性广告。已经提出了许多解决方案来通过端到端的电子邮件加密来解决此类隐私问题。但是,这些解决方案对Web上的可用性,可移植性和可信赖的密钥管理构成了其他挑战。这些系统通过其Web应用程序维护和分发最终用户加密密钥。不幸的是,关键一代和共享机制通常是不可信任的,并保持隐藏。信任直接依赖于Web应用程序实现,并且可以通过通过在服务器上的源代码(后门)的未经打成的更改来操作来操纵。为了解决这些问题,我们提出了一种新的PKI基于PKI的基于网络的电子邮件系统的架构。它提供了显着的可用性和可移植性。此外,所有加密操作都是对最终用户打开且透明的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号