Wink: Deniable Secure Messaging

07/18/2022
by   Anrin Chakraborti, et al.
0

End-to-end encrypted (E2EE) messaging is an essential first step towards combating increasingly privacy-intrusive laws. Unfortunately, it is vulnerable to compelled key disclosure – law-mandated, coerced, or simply by device compromise. This work introduces Wink, the first plausibly-deniable messaging system protecting message confidentiality even when users are coerced to hand over keys/passwords. Wink can surreptitiously inject hidden messages in the standard random coins (e.g., salt, IVs) used by existing E2EE protocols. It does so as part of legitimate secure cryptographic functionality deployed inside widely-available trusted execution environments (TEEs) such as TrustZone. This provides a powerful mechanism for hidden untraceable communication using virtually unchanged unsuspecting existing E2EE messaging apps, as well as strong plausible deniability. Wink has been demonstrated with multiple existing E2EE applications (including Telegram and Signal) with minimal (external) instrumentation, negligible overheads, and crucially without changing on-wire message formats.

READ FULL TEXT

page 7

page 10

page 14

research
11/18/2020

Experimental implementation of secure anonymous protocols on an eight-user quantum network

Anonymity in networked communication is vital for many privacy-preservin...
research
10/08/2020

Partitioned Private User Storages in End-to-End Encrypted Online Social Networks

In secure Online Social Networks (OSN), often end-to-end encryption appr...
research
03/06/2019

A Secure Communication Scheme for Corporate and Defense Community

Security is one of the major concerns of modern communication systems. U...
research
05/16/2023

Poster: No safety in numbers: traffic analysis of sealed-sender groups in Signal

Secure messaging applications often offer privacy to users by protecting...
research
02/11/2020

Session: A Model for End-To-End Encrypted Conversations With Minimal Metadata Leakage

Session is an open-source, public-key-based secure messaging application...
research
09/29/2022

Hidden in Plain Sight: Exploring Encrypted Channels in Android apps

As privacy features in Android operating system improve, privacy-invasiv...
research
09/09/2021

Fighting Fake News in Encrypted Messaging with the Fuzzy Anonymous Complaint Tally System (FACTS)

Recent years have seen a strong uptick in both the prevalence and real-w...

Please sign up or login with your details

Forgot password? Click here to reset