Automatic Detection of Fake Key Attacks in Secure Messaging
Tarun Kumar Yadav, Devashish Gosain, Amir Herzberg, Daniel Zappala, Kent E. Seamons
摘要
Popular instant messaging applications such as WhatsApp and Signal provide end-to-end encryption for billions of users. They rely on a centralized, application-specific server to distribute public keys and relay encrypted messages between the users. Therefore, they prevent passive attacks but are vulnerable to some active attacks. A malicious or hacked server can distribute fake keys to users to perform man-in-the-middle or impersonation attacks. While typical secure messaging applications provide a manual method for users to detect these attacks, this burdens users, and studies show it is ineffective in practice. This paper presents KTACA, a completely automated approach for key verification that is oblivious to users and easy to deploy. We motivate KTACA by designing two approaches to automatic key verification. One approach uses client auditing (KTCA) and the second uses anonymous key monitoring (AKM). Both have relatively inferior security properties, leading to KTACA, which combines these approaches to provide the best of both worlds. We provide a security analysis of each defense, identifying which attacks they can automatically detect. We implement the active attacks to demonstrate they are possible, and we also create a prototype implementation of all the defenses to measure their performance and confirm their feasibility. Finally, we discuss the strengths and weaknesses of each defense, the overhead on clients and service providers, and deployment considerations. CCS CONCEPTS • Security and privacy → Key management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 被引用 5 次
- SOAP: A Social Authentication ProtocolFelix Linker, David A. BasinUSENIX Security 2024 · 被引用 4 次
- ADEM: An Authentic Digital EMblemFelix Linker, David A. BasinCCS 2023
- Parakeet: Practical Key Transparency for End-to-End Encrypted MessagingHarjasleen Malvai, Lefteris Kokoris-Kogias, Alberto Sonnino, Esha Ghosh 等NDSS 2023
它引用的顶会 Paper2
- SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustMelissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen MalvaiCCS 2019 · 被引用 69 次
- The Signal Private Group System and Anonymous Credentials Supporting Efficient Verifiable EncryptionMelissa Chase, Trevor Perrin, Greg ZaveruchaCCS 2020 · 被引用 5 次
相关 Paper
- Practical Traffic Analysis Attacks on Secure Messaging ApplicationsAlireza Bahramali, Amir Houmansadr, Ramin Soltani, Dennis Goeckel 等NDSS 2020
- ELEKTRA: Efficient Lightweight multi-dEvice Key TRAnsparencyJulia Len, Melissa Chase, Esha Ghosh, Daniel Jost 等CCS 2023 · 被引用 4 次
- Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with AutoethnographyMatthias Fassl, Katharina KrombholzCHI 2023 · 被引用 18 次
- Message Injection Attacks Against SignalKien Tuong Truong, Noemi Terzo, Kenneth G. PatersonUSENIX Security 2026
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) 等CCS 2026
