Current e-mail security systems base their security on the secrecy of the long-term private key. If this private key is ever compromised, an attacker can decrypt any messages-past, present or future-encrypted with the corresponding public key. The system described in this paper uses short-term private-key/public-key key pairs to reduce the magnitude of this vulnerability.
Index Terms:
electronic mail; electronic mail security protocol; secrecy; long-term private key; message decryption; encryption; short-term private-key/public-key key pairs; vulnerability
Citation:
B. Schneier, C. Hall, "An improved e-mail security protocol," acsac, pp.227, 13th Annual Computer Security Applications Conference (ACSAC '97), 1997