On the security of a certified e-mail scheme with temporal authentication

  • Authors:
  • Min-Hua Shao;Jianying Zhou;Guilin Wang

  • Affiliations:
  • Institute of Information Management, National Chiao Tung University, Hsinchu, Taiwan;Infocomm Security Department, Institute for Infocomm Research, Singapore;Infocomm Security Department, Institute for Infocomm Research, Singapore

  • Venue:
  • ICCSA'05 Proceedings of the 2005 international conference on Computational Science and Its Applications - Volume Part III
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Certified e-mail is a value-added service for standard e-mail systems, in which the intended recipient gets the mail content if and only if the mail originator receives a non-repudiation evidence that the message has been received by the recipient. As far as security is concerned, fairness is one of the most important requirements. Recently, Galdi and Giordano (2004) presented an optimistic protocol for certified e-mail with temporal authentication. In this paper, we analyze their protocol and demonstrate that it cannot achieve true fairness and has some other weaknesses. We further propose the improvements to avoid those security problems.