Lightweight Authentication for Email (and Web?)
Ben Adida
ben@mit.edu
PAW/DIG Meeting June 30th, 2005
(joint work with Susan Hohenberger and Ronald L. Rivest)
Lightweight Authentication for Email (and Web?) Ben Adida - - PowerPoint PPT Presentation
Lightweight Authentication for Email (and Web?) Ben Adida ben@mit.edu PAW/DIG Meeting June 30th, 2005 (joint work with Susan Hohenberger and Ronald L. Rivest) Distributed Phishing Friends and Colleagues Jakobsson & Young 2005
ben@mit.edu
PAW/DIG Meeting June 30th, 2005
(joint work with Susan Hohenberger and Ronald L. Rivest)
DNS
foo.com MX Record mail.foo.com Alice Bob
wonderland.com
mail server
mail.foo.com
incoming mail server MX
2 1 3 4
Alice Bob
wonderland.com
mail server
mail.foo.com
incoming mail server
phish.com
keyserver
Alice Bob
MSK MPK "bob@foo.com" PKbob SKbob
Bob Alice
SKalice@wonderland.com SKbob@foo.com MPKwonderland.com MPKfoo.com
wonderland.com
keyserver
MSKwonderland.com
foo.com
keyserver
MSKfoo.com
wonderland.com key server
MSKwonderland.com DNS
wonderland.com foo.com
MPKwonderland.com MPKfoo.com
Publish
Alice
wonderland.com
incoming mail server
wonderland.com
keyserver
MSKwonderland.com SKalice@wonderland.com
Bob Alice
Eve
From: Alice To: Bob Subject: Account Your monthly balance is available at: http://wonderbank.com Signed:
Alice or Bob
foo.com Network
foo.com
key server
Bob
Wonderbank.com Network
wonderbank.com
key server
Alice
MPKfoo
3 4
"bob@foo.com" PKB
SKA
2
From: Alice To: Bob Subject: Account Your monthly balance is available at: http://wonderbank.com Signed:
Alice or Bob
5
PUBLISH
DNS
wonderbank.com foo.com
MPKbank
PUBLISH
MPKfoo
1 1
MPKbank
6 7
"alice@wonderbank.com" PKA
8
9
Web Server PK
Alice Request for Authentication Request for Resource Signature on Nonce, Repudiable Against PK