TL;DR
ClaimChain enhances in-band email key distribution by providing a cryptographic, privacy-preserving, and decentralized system for authenticating and managing public keys and claims, mitigating man-in-the-middle attacks.
Contribution
It introduces ClaimChain, a novel cryptographic structure that securely stores and authenticates user claims and keys in a decentralized, encrypted manner with non-equivocation guarantees.
Findings
Provides privacy-preserving key authentication
Offers low-overhead, practical implementation
Ensures strong non-equivocation properties
Abstract
The social demand for email end-to-end encryption is barely supported by mainstream service providers. Autocrypt is a new community-driven open specification for e-mail encryption that attempts to respond to this demand. In Autocrypt the encryption keys are attached directly to messages, and thus the encryption can be implemented by email clients without any collaboration of the providers. The decentralized nature of this in-band key distribution, however, makes it prone to man-in-the-middle attacks and can leak the social graph of users. To address this problem we introduce ClaimChain, a cryptographic construction for privacy-preserving authentication of public keys. Users store claims about their identities and keys, as well as their beliefs about others, in ClaimChains. These chains form authenticated decentralized repositories that enable users to prove the authenticity of both…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
