Perfecting email security

Sep 10, 2012

Millions of us send billions of emails back and forth each day without much concern for their security. On the whole, security is not a primary concern for most day-to-day emails, but some emails do contain personal, proprietary and sensitive information, documents, media, photos, videos and sound files. Unfortunately, the open nature of email means that they can be intercepted and if not encrypted easily read by malicious third parties. Even with the PGP - pretty good privacy - encryption scheme first used in 1995, if a sender's private "key" is compromised all their previous emails encrypted with that key can be exposed.

Writing in the International Journal of Security and Networks, Duncan Wong and Xiaojian Tian of City University of Hong Kong, explain how previous researchers had attempted to define perfect privacy that utilizes PGP by developing a technique that would preclude the of other emails should a private key be compromised. Unfortunately, say Wong and Tian this definition fails if one allows the possibility that the email server itself may be compromised, by hackers or other .

The team has now defined perfect forward secrecy for email as follows and suggested a technical solution to enable email security to be independent of the server used to send the message:

"An e-mail system provides perfect forward secrecy if any third party, including the e-, cannot recover previous session keys between the sender and the recipient even if the long-term secret keys of the sender and the recipient are compromised."

By building a new email protocol on this principle, the team suggests that it is now possible to exchange emails with almost zero risk of interference from third parties. "Our protocol provides both confidentiality and message authentication in addition to perfect forward secrecy," they explain.

The team's protocol involves Alice sending Bob an encrypted email with the hope that Charles will not be able to intercept and decrypt the message. Before the email is encrypted and sent the protocol suggested by Wong and Tian has Alice's computer send an identification code to the email server. The server creates a random session "hash" that is then used to encrypt the actual encryption key for the email Alice is about to send. Meanwhile, Bob as putative recipient receives the key used to create the hash and bounces back an identification tag. This allows Alice and Bob to verify each other's identity.

These preliminary steps are all automatically and without Alice or Bob needing to do anything in advance. Now, Alice writes her email, encrypts it using PGP and then "hashes" it using the random key from the server. When Bob receives the encrypted message he uses his version of the hash to unlock the container within which the PGP-encrypted email sits. Bob then uses Alice's public PGP key to decrypt the message itself. No snoopers on the internet between Alice and Bob, not even the email server ever have access to the PGP encrypted email in the open. Moreover, because a different key is used to lock up the PGP encrypted email with a second one-time layer, even if the PGP security is compromised past emails created with the same cannot be unlocked.

Explore further: Twitter tightens security after high-profile breaches (Update)

More information: "E-mail protocols with perfect forward secrecy" in Int. J. Security and Networks, 2012, 7, 1-5

add to favorites email to friend print save as pdf

Related Stories

'Dead time' limits quantum cryptography speeds

Sep 28, 2007

Quantum cryptography is potentially the most secure method of sending encrypted information, but does it have a speed limit" According to a new paper by researchers at the National Institute of Standards and Technology and ...

US banks, companies issue warning after email hack

Apr 04, 2011

Computer hackers gained access to the email addresses of customers of several large US banks and other companies in a potentially huge data breach at US online marketing firm Epsilon. ...

Recommended for you

Facebook joins Web freedom group

16 hours ago

Facebook on Wednesday became a full member of the Global Network Initiative, a non-governmental organization promoting Internet freedom and privacy rights.

Big Data—for better or worse

21 hours ago

A full 90% of all the data in the world has been generated over the last two years. The internet companies are awash with data that can be grouped and utilised. Is this a good thing?

Risky behaviour starts young on social media: survey

22 hours ago

Australian children are accessing social media websites at an increasingly younger age, a new survey suggests, with one in five "tweens" admitting they have chatted to someone online they do not know.

Poll: Teens migrating to Twitter (Update)

May 21, 2013

Twitter is booming as a social media destination for teenagers who complain about too many adults and too much drama on Facebook, according to a new study published Tuesday about online behavior. It said ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

kevinrtrs
1.5 / 5 (4) Sep 10, 2012
THis is a much needed facility as more and more insurance, investment and banking companies want to save money by sending clients accounts and other confidential documents via email. This is already critical in fact.

More news stories

NASA: Austin, calling Austin. 3-D pizzas to go

(Phys.org) —The idea of living with 3-D printed food is neither unthinkable nor new; designers and futurists have been looking to 3-D printing as food's next frontier. In 2012, there was news that the Thiel ...

Scientists announce Top 10 New Species from 2012

An amazing glow-in-the-dark cockroach, a harp-shaped carnivorous sponge and the smallest vertebrate on Earth are just three of the newly discovered top 10 species selected by the International Institute for ...