<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>conference paper</genre>

<titleInfo><title>Mitigation of Attacks on Email End-to-End Encryption</title></titleInfo>


<note type="publicationStatus">published</note>



<name type="personal">
  <namePart type="given">Jörg</namePart>
  <namePart type="family">Schwenk</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Marcus</namePart>
  <namePart type="family">Brinkmann</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Damian</namePart>
  <namePart type="family">Poddebniak</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Jens</namePart>
  <namePart type="family">Müller</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Juraj</namePart>
  <namePart type="family">Somorovsky</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">83504</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0002-3593-7720</description></name>
<name type="personal">
  <namePart type="given">Sebastian</namePart>
  <namePart type="family">Schinzel</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">632</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>








<abstract lang="eng">OpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem.We present the first generic countermeasure against both REPLY and EFAIL-DE attacks by checking the decryption context including SMTP headers and MIME structure during decryption. The decryption context is encoded into a string DC and used as Associated Data (AD) in the AEAD encryption. Thus the proposed solution seamlessly extends the EFAIL-MG countermeasures. The decryption context changes whenever an attacker alters the email source code in a critical way, for example, if the attacker changes the MIME structure or adds a new Reply-To header. The proposed solution does not cause any interoperability problems and legacy emails can still be decrypted. We evaluate our approach by implementing the decryption contexts in Thunderbird/Enigmail and by verifying their correct functionality after the email has been transported over all major email providers, including Gmail and iCloud Mail.</abstract>

<originInfo><publisher>Association for Computing Machinery</publisher><dateIssued encoding="w3cdtf">2020</dateIssued>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>

<subject><topic>decryption contexts</topic><topic>EFAIL</topic><topic>OpenPGP</topic><topic>S/MIME</topic><topic>AEAD</topic>
</subject>


<relatedItem type="host"><titleInfo><title>Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security</title></titleInfo>
  <identifier type="isbn">9781450370899</identifier><identifier type="doi">10.1145/3372297.3417878</identifier>
<part><extent unit="pages">1647–1664</extent>
</part>
</relatedItem>


<extension>
<bibliographicCitation>
<ieee>J. Schwenk, M. Brinkmann, D. Poddebniak, J. Müller, J. Somorovsky, and S. Schinzel, “Mitigation of Attacks on Email End-to-End Encryption,” in &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;, 2020, pp. 1647–1664, doi: &lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;10.1145/3372297.3417878&lt;/a&gt;.</ieee>
<apa>Schwenk, J., Brinkmann, M., Poddebniak, D., Müller, J., Somorovsky, J., &amp;#38; Schinzel, S. (2020). Mitigation of Attacks on Email End-to-End Encryption. &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;, 1647–1664. &lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;https://doi.org/10.1145/3372297.3417878&lt;/a&gt;</apa>
<chicago>Schwenk, Jörg, Marcus Brinkmann, Damian Poddebniak, Jens Müller, Juraj Somorovsky, and Sebastian Schinzel. “Mitigation of Attacks on Email End-to-End Encryption.” In &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;, 1647–1664. CCS ’20. New York, NY, USA: Association for Computing Machinery, 2020. &lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;https://doi.org/10.1145/3372297.3417878&lt;/a&gt;.</chicago>
<short>J. Schwenk, M. Brinkmann, D. Poddebniak, J. Müller, J. Somorovsky, S. Schinzel, in: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery, New York, NY, USA, 2020, pp. 1647–1664.</short>
<mla>Schwenk, Jörg, et al. “Mitigation of Attacks on Email End-to-End Encryption.” &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;, Association for Computing Machinery, 2020, pp. 1647–1664, doi:&lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;10.1145/3372297.3417878&lt;/a&gt;.</mla>
<bibtex>@inproceedings{Schwenk_Brinkmann_Poddebniak_Müller_Somorovsky_Schinzel_2020, place={New York, NY, USA}, series={CCS ’20}, title={Mitigation of Attacks on Email End-to-End Encryption}, DOI={&lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;10.1145/3372297.3417878&lt;/a&gt;}, booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}, publisher={Association for Computing Machinery}, author={Schwenk, Jörg and Brinkmann, Marcus and Poddebniak, Damian and Müller, Jens and Somorovsky, Juraj and Schinzel, Sebastian}, year={2020}, pages={1647–1664}, collection={CCS ’20} }</bibtex>
<ama>Schwenk J, Brinkmann M, Poddebniak D, Müller J, Somorovsky J, Schinzel S. Mitigation of Attacks on Email End-to-End Encryption. In: &lt;i&gt;Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security&lt;/i&gt;. CCS ’20. Association for Computing Machinery; 2020:1647–1664. doi:&lt;a href=&quot;https://doi.org/10.1145/3372297.3417878&quot;&gt;10.1145/3372297.3417878&lt;/a&gt;</ama>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>25336</recordIdentifier><recordCreationDate encoding="w3cdtf">2021-10-04T18:58:37Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2022-08-03T09:57:27Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
