Enforcing End-to-end Security for Remote Conference Applications
Yuelin Liu, Huangxun Chen, Zhice Yang
Abstract
Remote conference applications are increasingly widely used, but currently, their improper data encryption methods, proprietary implementations, and dial-in access cause concerns about privacy breaches. As such, there is a need for trustworthy and secure solutions for these production tools. In this paper, we present mTunnel, a transparent software layer in the host system for securing conference applications without sacrificing the key functionalities and convenience. The basic idea of mTunnel is to encrypt sensitive data, such as audio, video, text, etc., before it is obtained by untrusted application clients. mTunnel leverages the audio and video streaming capabilities of the conference applications to tunnel the encrypted content to the remote end. mTunnel involves a software framework to accommodate the media interception and representation through I/O virtualization based on virtual drivers. Moreover, mTunnel supports complete E2EE group conversations even in a mixed IP and public switched telephone network (PSTN). We implement mTunnel and evaluate it with several commercial products. Results show its feasibility and overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0540c32e-fa93-4f15-b940-4a0216b7c8dbCited by top-tier papers1
Ask how each one uses itBuilds on5
- A First Look at ZoombombingChen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca StringhiniS&P 2021 · 51 citations
- AuthLoop: End-to-End Cryptographic Authentication for Telephony over Voice ChannelsBradley Reaves, Logan Blue, Patrick TraynorUSENIX Security 2016 · 40 citations
- Sonar: Detecting SS7 Redirection Attacks with Audio-Based Distance BoundingChristian Peeters, Hadi Abdullah, Nolen Scaife, Jasmine D. Bowers et al.S&P 2018 · 20 citations
- Automatic Detection of Fake Key Attacks in Secure MessagingTarun Kumar Yadav, Devashish Gosain, Amir Herzberg, Daniel Zappala et al.CCS 2022 · 6 citations
- Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat SystemsMingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang et al.NDSS 2022
Related papers
- Poking a Hole in the Wall: Efficient Censorship-Resistant Internet Communications by Parasitizing on WebRTCDiogo Barradas, Nuno Santos, Luís E. T. Rodrigues, Vítor NunesCCS 2020 · 41 citations
- PQConnect: Automated Post-Quantum End-to-End TunnelsDaniel J. Bernstein, Tanja Lange, Jonathan Levin, Bo-Yin YangNDSS 2025
- NetShaper: A Differentially Private Network Side-Channel Mitigation SystemAmir Sabzi, Rut Vora, Swati Goswami, Margo I. Seltzer et al.USENIX Security 2024 · 7 citations
- maTLS: How to Make TLS middlebox-aware?Hyunwoo Lee, Zach Smith, Junghwan Lim, Gyeongjae Choi et al.NDSS 2019 · 38 citations
- End-to-End Encrypted Zoom Meetings: Proving Security and Strengthening LivenessYevgeniy Dodis, Daniel Jost, Balachandar Kesavan, Antonio MarcedoneEUROCRYPT 2023 · 7 citations
