Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. ClaimChain: Improving the Security and Privacy of In-band Key Distribution for Messaging
 
conference paper

ClaimChain: Improving the Security and Privacy of In-band Key Distribution for Messaging

Kulynych, Bogdan  
•
Lueks, Wouter  
•
Isaakidis, Marios
Show more
January 1, 2018
Proceedings of the 2018 Workshop on Privacy in the Electronic Society (Wpes'18)
17th ACM Workshop on Privacy in the Electronic Society (WPES)

The social demand for email end-to-end encryption is barely supported by mainstream service providers. Autocrypt is a new community -driven open specification for e-mail encryption that attempts to respond to this demand. In Autocrypt the encryption keys are attached directly to messages, and thus the encryption can be implemented by email clients without any collaboration of the providers. The decentralized nature of this in-band key distribution, however, makes it prone to man-in-the-middle attacks and can leak the social graph of users. To address this problem we introduce ClaimChain, a cryptographic construction for privacy-preserving authentication of public keys. Users store claims about their identities and keys, as well as their beliefs about others, in ClaimChains. These chains form authenticated decentralized repositories that enable users to prove the authenticity of both their keys and the keys of their contacts. ClaimChains are encrypted, and therefore protect the stored information, such as keys and contact identities, from prying eyes. At the same time, ClaimChain implements mechanisms to provide strong non-equivocation properties, discouraging malicious actors from distributing conflicting or inauthentic claims. We implemented ClaimChain and we show that it offers reasonable performance, low overhead, and authenticity guarantees.

  • Details
  • Metrics
Type
conference paper
DOI
10.1145/3267323.3268947
Web of Science ID

WOS:000458177600010

Author(s)
Kulynych, Bogdan  
Lueks, Wouter  
Isaakidis, Marios
Danezis, George
Troncoso, Carmela  
Date Issued

2018-01-01

Publisher

ACM

Publisher place

New York

Published in
Proceedings of the 2018 Workshop on Privacy in the Electronic Society (Wpes'18)
ISBN of the book

978-1-4503-5989-4

Start page

86

End page

103

Subjects

Computer Science, Theory & Methods

•

Engineering, Electrical & Electronic

•

Computer Science

•

Engineering

•

e-mail encryption

•

decentralization

•

key distribution

•

privacy

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
SPRING  
Event nameEvent placeEvent date
17th ACM Workshop on Privacy in the Electronic Society (WPES)

Toronto, CANADA

Oct 15, 2018

Available on Infoscience
June 18, 2019
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/157301
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés