SoK: Securing Email -- A Stakeholder-Based Analysis (Extended Version)
Jeremy Clark, P.C. van Oorschot, Scott Ruoti, Kent Seamons, Daniel, Zappala

TL;DR
This paper analyzes the complex landscape of secure email solutions by examining stakeholder interests, evaluating cryptographic components, and highlighting the challenges in achieving universal, secure, and interoperable email communication.
Contribution
It provides a stakeholder-based analysis of secure email evolution, evaluates cryptographic building blocks, and discusses why a universal solution remains elusive.
Findings
Current solutions are fragmented and stakeholder-specific.
Vulnerable users are poorly served by existing secure email methods.
Secure messaging is complementary but not a substitute for secure email.
Abstract
While email is the most ubiquitous and interoperable form of online communication today, it was not conceived with strong security guarantees, and the ensuing security enhancements are, by contrast, lacking in both ubiquity and interoperability. This situation motivates our research. We begin by identifying a variety of stakeholders who have an interest in the current email system and in efforts to provide secure solutions. We then use the tussle among stakeholders to explain the evolution of fragmented secure email solutions undertaken by industry, academia, and independent developers. We also evaluate the building blocks of secure email -- cryptographic primitives, key management schemes, and system designs -- to identify their support for stakeholder properties. From our analysis, we conclude that a one-size-fits-all solution is unlikely. Furthermore, we highlight that vulnerable…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Privacy, Security, and Data Protection · Spam and Phishing Detection
