Lightweight Signatures for Email

Ben AdidaDavid ChauSusan Hohenberger, Ronald L. Rivest · 2005

We present the design and prototype implementation of a new public key infrastucture for email authentication. Our approach applies recent developments in identity-based cryptography and observations concerning the role of DNS and email servers in the current email architecture to produce end-to-end email signatures with no infrastructure change or new security assumption. Like current email signature proposals, this solution prevents email spoofing attacks such as phishing and, to some degree, spam. Unlike prior proposals, it conserves all current legitimate uses of email, transparently protects average Internet users, and optionally provides privacy-preserving repudiability. In other words, assuming today’s email infrastructure, we provide the best possible email signature scheme with the smallest possible side-effect. We call this approach Lightweight Signatures.

Read the paper · More papers on PaperTik