Authentication and Key Management Automation in Decentralized Secure Email and Messaging via Low-Entropy Secrets
Itzel Vazquez Sandoval, Arash Atashpendar, Gabriele Lenzini

TL;DR
This paper introduces a practical cryptographic method using password-authenticated key exchange (PAKE) for secure, automated, and user-friendly entity authentication in decentralized encrypted email and messaging systems, eliminating the need for public key infrastructure.
Contribution
It presents a novel PAKE-based solution for entity authentication that supports automation, enhances security, and is suitable for asynchronous communication without relying on trusted third parties.
Findings
Identified vulnerabilities in voice-based out-of-band authentication.
Proposed PAKE-based secure equality test for entity authentication.
Enables features like automated key renewal, multi-device sync, and post-quantum security.
Abstract
We revisit the problem of entity authentication in decentralized end-to-end encrypted email and secure messaging to propose a practical and self-sustaining cryptographic solution based on password-authenticated key exchange (PAKE). This not only allows users to authenticate each other via shared low-entropy secrets, e.g., memorable words, without a public key infrastructure or a trusted third party, but it also paves the way for automation and a series of cryptographic enhancements; improves security by minimizing the impact of human error and potentially improves usability. First, we study a few vulnerabilities in voice-based out-of-band authentication, in particular a combinatorial attack against lazy users, which we analyze in the context of a secure email solution. Next, we propose solving the problem of secure equality test using PAKE to achieve entity authentication and to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Authentication Protocols Security · Cryptography and Data Security
