Paper 2003/256

On the Security of a Multi-Party Certified Email Protocol

Jianying Zhou

Abstract

As a value-added service to deliver important data over the Internet with guaranteed receipt for each successful delivery, certified email has been discussed for years and a number of research papers appeared in the literature. But most of them deal with the two-party scenarios, i.e., there are only one sender and one recipient. In some applications, however, the same certified message may need to be sent to a set of recipients. In ISC'02, Ferrer-Gomila et. al. presented a multi-party certified email protocol~\cite{FPH02}. It has two major features. A sender could notify multiple recipients of the same information while only those recipients who acknowledged are able to get the information. In addition, its exchange protocol is optimized, which has only three steps. In this paper, we demonstrate some flaws and weaknesses in that protocol, and propose an improved version which is robust against the identified attacks while preserving the features of the original protocol.

Metadata
Available format(s)
-- withdrawn --
Category
Applications
Publication info
Published elsewhere. Unknown where it was published
Keywords
certified emailnon-repudiationsecurity protocol
Contact author(s)
jyzhou @ i2r a-star edu sg
History
2004-08-11: withdrawn
2003-12-20: received
See all versions
Short URL
https://ia.cr/2003/256
License
Creative Commons Attribution
CC BY
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.