Improving Email Trustworthiness through Social-Group Key Authentication.
Vivek Pathak, Liviu Iftode, Danfeng Daphne Yao · 2008
The increasing use of email for phishing and unso-licited marketing has reduced the trustworthiness of email as a communication medium. Sender authenti-cation is a known defense against these attacks. Exist-ing proposals for sender authentication either require infrastructural support or break compatibility with ex-isting email infrastructure. We propose, implement, and evaluate social-group key authentication, an incre-mentally deployable and backward compatible sender authentication mechanism for email. Our solution re-quires honest majority instead of trust infrastructure or human input for correctness. In accordance with the end-to-end principle, authentication is implemented at the mail client by executing our previously proposed Byzantine fault tolerant public key authentication pro-tocol [12] as an overlay on top of the mail trans-port protocol. We evaluated the authentication over-head by instrumenting our Thunderbird authentication plugin with synthetic data and found a user visible la-tency increase of about 200ms. Real life usability of the authentication mechanism is investigated with two anonymized email traces. Our results show that about 40 % of the peers can be authenticated over the 92 day trace period without adding any new messages to the email network. Adding a small fraction of extra email messages permits more than 90 % of the peers to be authenticated within a week. 1