利用客户端 WebAssembly 防御 EFail 攻击:以瑞士邮政 IncaMail 为例
密码学与安全
2023-06-26 v1
摘要
传统邮件加密方案易受 EFail 攻击,其利用缺乏消息认证的漏洞,通过操纵密文并经由 HTML 回传通道外泄明文。瑞士邮政的 IncaMail 是一项用于传输具有法律约束力、加密且可验证邮件的安全电子邮件服务,它使用带关联数据的认证加密(AEAD)方案来抵御 EFail 攻击,以确保服务器间的消息隐私与认证。IncaMail 依赖可信基础设施后端并按用户策略加密消息。本文提出一种改进的 IncaMail 架构,将大部分密码学操作卸载至客户端,带来诸如降低计算负载与能耗、放宽信任假设以及逐消息加密密钥策略等益处。我们的概念验证原型与基准测试证明了所提方案的鲁棒性,基于客户端 WebAssembly 的密码学操作相较传统 JavaScript 实现取得了显著性能提升(高达约 14 倍)。
引用
@article{arxiv.2306.13388,
title = {Preventing EFail Attacks with Client-Side WebAssembly: The Case of Swiss Post's IncaMail},
author = {Pascal Gerig and Jämes Ménétrey and Baptiste Lanoix and Florian Stoller and Pascal Felber and Marcelo Pasin and Valerio Schiavoni},
journal= {arXiv preprint arXiv:2306.13388},
year = {2023}
}
备注
This publication incorporates results from the VEDLIoT project, which received funding from the European Union's Horizon 2020 research and innovation programme under grant agreement No 957197