Mitigating TLS compromise with ECDHE and SRP

05/28/2020
by   Aron Wussler, et al.
0

The paper reviews an implementation of an additional encrypted tunnel within TLS to further secure and authenticate the traffic of personal information between ProtonMail's frontends and the backend, implementing its key exchange, symmetric packet encryption, and validation. Technologies such as Secure Remote Password (SRP) and the Elliptic Curves Diffie Hellman Ephemeral (ECDHE) exchange are used for the key exchange, verifying the public parameters through PGP signatures. The data is then transferred encrypted with AES-128-GCM. This project is meant to integrate TLS security for high security data transfer, offering a flexible model that is easy to implement in the frontends by reusing part of the standard already existing in the PGP libraries.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/22/2017

Meta-Key: A Secure Data-Sharing Protocol under Blockchain-Based Decentralised Storage Architecture

In this paper a secure data-sharing protocol under blockchain-based dece...
research
08/30/2022

AuthROS: Secure Data Sharing Among Robot Operating Systems Based on Ethereum

Robot Operating System (ROS) has brought the excellent potential for aut...
research
01/07/2020

Towards Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes

Network Function Virtualisation (NFV) advances the development of compos...
research
05/09/2020

Lattice-based public key encryption with equality test supporting flexible authorization in standard model

Public key encryption with equality test (PKEET) supports to check wheth...
research
01/29/2019

Secure selections on encrypted multi-writer streams

Performing searches over encrypted data is a very current and active are...
research
09/27/2021

Experimental symmetric private information retrieval with measurement-device-independent quantum network

Secure information retrieval is an essential task in today's highly digi...
research
11/07/2017

Pre-shared Key Agreement for Secure Public Wi-Fi

This paper presents a novel pre-shared key (PSK) agreement scheme to est...

Please sign up or login with your details

Forgot password? Click here to reset