A Proposal for an Improved Distributed Architecture for OpenPGP's Web of Trust

Daniel Maldonado-Ruiz, Edison Loza-Aguirre, Jenny Torres · 2018

Security and authenticity issues were never considered when e-mail was originally designed and implemented. Along the time, most of electronic mails have been sent between users in a way that any user, intended or not, could read the message or impersonate a sender. To resolve all these issues and maintain the privacy of e-mails was the reason for the creation of PGP and its complements. However, over the years, PGP revealed unexpected security issues when faced to mistrusted environments where we do not know if someone is who claims to be. To overcome this problem, we propose a trust solution for OpenPGP that improves trust relationships between users and the public key distribution network. Our proposal could be implemented in a system using cryptographic technology efficiently in OpenPGP over an all-new trust approach.

Read the paper · More papers on PaperTik