Show simple item record

dc.contributor.author
Dowling, Benjamin
dc.contributor.author
Hale, Britta
dc.date.accessioned
2022-03-18T13:15:25Z
dc.date.available
2021-06-07T08:27:20Z
dc.date.available
2021-06-16T06:03:22Z
dc.date.available
2021-10-26T07:41:55Z
dc.date.available
2022-03-18T13:15:25Z
dc.date.issued
2021-09
dc.identifier.isbn
978-1-6654-1491-3
en_US
dc.identifier.isbn
978-1-6654-3048-7
en_US
dc.identifier.other
10.1109/EuroSP51992.2021.00015
en_US
dc.identifier.uri
http://hdl.handle.net/20.500.11850/488520
dc.description.abstract
Modern messaging applications often rely on out-of-band communication to achieve entity authentication, with human users verifying and attesting to long-term public keys. This is done primarily to reduce reliance on trusted third parties by replacing that role with the user. Despite a great deal of research focusing on analyzing the confidentiality aspect of secure messaging, the entity authenticity aspect of it, which relies on the user mediation, has been largely assumed away. Consequently, while many existing protocols provide some confidentiality guarantees after a compromise, such as post-compromise security (PCS), authenticity guarantees are generally lost, especially against an active attacker. This leads to potential man-in-the-middle (MitM) attacks. In this work, we address this gap by proposing a model to formally capture user-mediated entity authentication, as used by real-world protocols, that can be composed with any ratcheted key exchange. Our threat model captures active post-compromise entity authentication security. We demonstrate that the Signal application's user-mediated authentication protocol cannot be proven secure in this model and suggest a straightforward fix for Signal that allows the detection of an active adversary. Our results have direct implications for other existing and future ratcheted secure messaging applications.
en_US
dc.language.iso
en
en_US
dc.publisher
IEEE
en_US
dc.subject
Secure Messaging
en_US
dc.subject
Ratcheted Authentication
en_US
dc.subject
Signal
en_US
dc.subject
User-Mediated Authentication
en_US
dc.subject
Ceremonies
en_US
dc.title
Secure Messaging Authentication against Active Man-in-the-Middle Attacks
en_US
dc.type
Conference Paper
dc.date.published
2021-11-13
ethz.book.title
2021 IEEE European Symposium on Security and Privacy (EuroS&P)
en_US
ethz.pages.start
54
en_US
ethz.pages.end
70
en_US
ethz.event
6th IEEE European Symposium on Security and Privacy (EuroS&P 2021)
en_US
ethz.event.location
Online
en_US
ethz.event.date
September 6-10, 2021
en_US
ethz.identifier.wos
ethz.identifier.scopus
ethz.publication.place
Piscataway, NJ
en_US
ethz.publication.status
published
en_US
ethz.leitzahl
ETH Zürich::00002 - ETH Zürich::00012 - Lehre und Forschung::00007 - Departemente::02150 - Dep. Informatik / Dep. of Computer Science::02660 - Institut für Informationssicherheit / Institute of Information Security::09653 - Paterson, Kenneth / Paterson, Kenneth
en_US
ethz.leitzahl.certified
ETH Zürich::00002 - ETH Zürich::00012 - Lehre und Forschung::00007 - Departemente::02150 - Dep. Informatik / Dep. of Computer Science::02660 - Institut für Informationssicherheit / Institute of Information Security::09653 - Paterson, Kenneth / Paterson, Kenneth
en_US
ethz.date.deposited
2021-06-07T08:27:30Z
ethz.source
FORM
ethz.eth
yes
en_US
ethz.availability
Metadata only
en_US
ethz.rosetta.installDate
2022-03-18T13:15:32Z
ethz.rosetta.lastUpdated
2023-02-07T00:25:12Z
ethz.rosetta.versionExported
true
ethz.COinS
ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.atitle=Secure%20Messaging%20Authentication%20against%20Active%20Man-in-the-Middle%20Attacks&rft.date=2021-09&rft.spage=54&rft.epage=70&rft.au=Dowling,%20Benjamin&Hale,%20Britta&rft.isbn=978-1-6654-1491-3&978-1-6654-3048-7&rft.genre=proceeding&rft_id=info:doi/10.1109/EuroSP51992.2021.00015&rft.btitle=2021%20IEEE%20European%20Symposium%20on%20Security%20and%20Privacy%20(EuroS&P)
 Search print copy at ETH Library

Files in this item

FilesSizeFormatOpen in viewer

There are no files associated with this item.

Publication type

Show simple item record