<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
<ListRecords>
<oai_dc:dc xmlns="http://www.openarchives.org/OAI/2.0/oai_dc/"
           xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/"
           xmlns:dc="http://purl.org/dc/elements/1.1/"
           xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
           xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
   	<dc:title>Mitigation of Attacks on Email End-to-End Encryption</dc:title>
   	<dc:creator>Schwenk, Jörg</dc:creator>
   	<dc:creator>Brinkmann, Marcus</dc:creator>
   	<dc:creator>Poddebniak, Damian</dc:creator>
   	<dc:creator>Müller, Jens</dc:creator>
   	<dc:creator>Somorovsky, Juraj</dc:creator>
   	<dc:creator>Schinzel, Sebastian</dc:creator>
   	<dc:subject>decryption contexts</dc:subject>
   	<dc:subject>EFAIL</dc:subject>
   	<dc:subject>OpenPGP</dc:subject>
   	<dc:subject>S/MIME</dc:subject>
   	<dc:subject>AEAD</dc:subject>
   	<dc:description>OpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem.We present the first generic countermeasure against both REPLY and EFAIL-DE attacks by checking the decryption context including SMTP headers and MIME structure during decryption. The decryption context is encoded into a string DC and used as Associated Data (AD) in the AEAD encryption. Thus the proposed solution seamlessly extends the EFAIL-MG countermeasures. The decryption context changes whenever an attacker alters the email source code in a critical way, for example, if the attacker changes the MIME structure or adds a new Reply-To header. The proposed solution does not cause any interoperability problems and legacy emails can still be decrypted. We evaluate our approach by implementing the decryption contexts in Thunderbird/Enigmail and by verifying their correct functionality after the email has been transported over all major email providers, including Gmail and iCloud Mail.</dc:description>
   	<dc:publisher>Association for Computing Machinery</dc:publisher>
   	<dc:date>2020</dc:date>
   	<dc:type>info:eu-repo/semantics/conferenceObject</dc:type>
   	<dc:type>doc-type:conferenceObject</dc:type>
   	<dc:type>text</dc:type>
   	<dc:type>http://purl.org/coar/resource_type/c_5794</dc:type>
   	<dc:identifier>https://ris.uni-paderborn.de/record/25336</dc:identifier>
   	<dc:source>Schwenk J, Brinkmann M, Poddebniak D, Müller J, Somorovsky J, Schinzel S. Mitigation of Attacks on Email End-to-End Encryption. In: &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;. CCS ’20. Association for Computing Machinery; 2020:1647–1664. doi:&lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;10.1145/3372297.3417878&lt;/a&gt;</dc:source>
   	<dc:language>eng</dc:language>
   	<dc:relation>info:eu-repo/semantics/altIdentifier/doi/10.1145/3372297.3417878</dc:relation>
   	<dc:relation>info:eu-repo/semantics/altIdentifier/isbn/9781450370899</dc:relation>
   	<dc:rights>info:eu-repo/semantics/closedAccess</dc:rights>
</oai_dc:dc>
</ListRecords>
</OAI-PMH>
